Skip to content

Governance tracker

Federal cybersecurity, privacy, and technology governance

Every federal cybersecurity, privacy, and information technology (IT) governance document from the Privacy Act of 1974 to today: laws, executive orders, memoranda, directives, standards, and contract rules.

FedXchange's watch checks the Cybersecurity and Infrastructure Security Agency (CISA), the Office of Management and Budget (OMB), the National Archives (NARA), and the Federal Register every day, and the National Institute of Standards and Technology (NIST) every week. New finds appear here the day they are found. The tracker lists public documents only.

Get new governance by emailWhat the statuses meanNames on this page

Found in the last 7 days

Nothing new in the last 7 days.

Skip to the results

Filters

Results

Showing 51 to 100.

Governance documents, sorted by date issued, oldest first. Page 2 of 13.

The table scrolls sideways. Each title opens the document's page.

Governance documents, sorted by date issued, oldest first. Page 2 of 13.
Number, sort A to ZTitle, sort A to ZIssuer, sort A to ZTypeIssued, sort newest firstStatus, sort A to Z
SP 800-34Contingency Planning Guide for Information Technology SystemsNISTNIST Special PublicationJune 13, 2002Withdrawn
SP 800-30Risk Management Guide for Information Technology SystemsNISTNIST Special PublicationJuly 2002Withdrawn
M-02-09Reporting Instructions for the Government Information Security Reform Act and Updated Guidance on Security Plans of Action and MilestonesOMBOMB memorandumJuly 2, 2002Rescinded
Pub. L. 107-296Homeland Security Act of 2002CongressLawNovember 25, 2002In effect
Pub. L. 107-305Cyber Security Research and Development ActCongressLawNovember 27, 2002In effect
Pub. L. 107-347E-Government Act of 2002CongressLawDecember 17, 2002In effect
Pub. L. 107-347, Title IIIFederal Information Security Management Act of 2002CongressLawDecember 17, 2002Superseded
Pub. L. 107-347, Title VConfidential Information Protection and Statistical Efficiency Act of 2002CongressLawDecember 17, 2002Superseded
EO 13292Further Amendment to Executive Order 12958, as Amended, Classified National Security InformationWhite HouseExecutive orderMarch 25, 2003Superseded
M-03-14Reducing Cost and Improving Quality in Federal Purchases of Commercial SoftwareOMBOMB memorandumJune 2, 2003Rescinded
M-03-18Implementation Guidance for the E-Government Act of 2002OMBOMB memorandumAugust 1, 2003In effect
M-03-19Reporting Instructions for the Federal Information Security Management Act and Updated Guidance on Quarterly IT Security ReportingOMBOMB memorandumAugust 6, 2003Rescinded
NoneEmployees Responsible for the Management or Use of Federal Computer SystemsOPMProposed ruleSeptember 4, 2003Superseded
M-03-22OMB Guidance for Implementing the Privacy Provisions of the E-Government Act of 2002OMBOMB memorandumSeptember 26, 2003In effect
SP 800-50Building an Information Technology Security Awareness and Training ProgramNISTNIST Special PublicationOctober 2003Withdrawn
M-04-04E-Authentication Guidance for Federal AgenciesOMBOMB memorandumDecember 16, 2003Rescinded
HSPD-7Critical Infrastructure Identification, Prioritization, and ProtectionWhite HousePresidential directiveDecember 17, 2003Superseded
SP 800-61Computer Security Incident Handling GuideNISTNIST Special PublicationJanuary 16, 2004Withdrawn
FIPS 199Standards for Security Categorization of Federal Information and Information SystemsNISTFIPS standardFebruary 2004In effect
SP 800-37Guide for the Security Certification and Accreditation of Federal Information SystemsNISTNIST Special PublicationMay 20, 2004Withdrawn
SP 800-60 Vol. 1Guide for Mapping Types of Information and Information Systems to Security CategoriesNISTNIST Special PublicationJune 10, 2004Withdrawn
5 CFR 930.301Information Security Responsibilities for Employees who Manage or Use Federal Information SystemsOPMRegulationJune 14, 2004In effect
SP 800-63Electronic Authentication GuidelineNISTNIST Special PublicationJune 30, 2004Withdrawn
M-04-16Software AcquisitionOMBOMB memorandumJuly 1, 2004In effect
M-04-25FY 2004 Reporting Instructions for the Federal Information Security Management ActOMBOMB memorandumAugust 23, 2004Rescinded
HSPD-12Policy for a Common Identification Standard for Federal Employees and ContractorsWhite HousePresidential directiveAugust 27, 2004In effect
M-04-26Personal Use Policies and "File Sharing" TechnologyOMBOMB memorandumSeptember 8, 2004Rescinded
M-05-04Policies for Federal Agency Public WebsitesOMBOMB memorandumDecember 17, 2004Rescinded
M-05-05Electronic Signatures: How to Mitigate the Risk of Commercial Managed ServicesOMBOMB memorandumDecember 20, 2004Rescinded
M-05-08Designation of Senior Agency Officials for PrivacyOMBOMB memorandumFebruary 11, 2005Rescinded
FIPS 201Personal Identity Verification (PIV) of Federal Employees and ContractorsNISTFIPS standardFebruary 25, 2005Withdrawn
SP 800-53Recommended Security Controls for Federal Information SystemsNISTNIST Special PublicationFebruary 28, 2005Withdrawn
M-05-15FY 2005 Reporting Instructions for the Federal Information Security Management Act and Agency Privacy ManagementOMBOMB memorandumJune 13, 2005Rescinded
M-05-22Transition Planning for Internet Protocol Version 6 (IPv6)OMBOMB memorandumAugust 2, 2005Rescinded
M-05-24Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and ContractorsOMBOMB memorandumAugust 5, 2005In effect
FAR 52.204-9Personal Identity Verification of Contractor PersonnelFAR CouncilContract clauseJanuary 3, 2006In effect
SP 800-18 Rev. 1Guide for Developing Security Plans for Federal Information SystemsNISTNIST Special PublicationFebruary 24, 2006Withdrawn
FIPS 200Minimum Security Requirements for Federal Information and Information SystemsNISTFIPS standardMarch 2006In effect
FIPS 201-1Personal Identity Verification (PIV) of Federal Employees and ContractorsNISTFIPS standardMarch 31, 2006Withdrawn
EO 13402Strengthening Federal Efforts To Protect Against Identity TheftWhite HouseExecutive orderMay 10, 2006In effect
M-06-15Safeguarding Personally Identifiable InformationOMBOMB memorandumMay 22, 2006Rescinded
M-06-16Protection of Sensitive Agency InformationOMBOMB memorandumJune 23, 2006Rescinded
M-06-18Acquisition of Products and Services for Implementation of HSPD-12OMBOMB memorandumJune 30, 2006Rescinded
M-06-19Reporting Incidents Involving Personally Identifiable Information and Incorporating the Cost for Security in Agency Information Technology InvestmentsOMBOMB memorandumJuly 12, 2006Rescinded
M-06-20FY 2006 Reporting Instructions for the Federal Information Security Management Act and Agency Privacy ManagementOMBOMB memorandumJuly 17, 2006Rescinded
NoneRecommendations for Identity Theft Related Data Breach NotificationOMBOMB memorandumSeptember 20, 2006Rescinded
SP 800-53 Rev. 1Recommended Security Controls for Federal Information SystemsNISTNIST Special PublicationDecember 19, 2006Withdrawn
M-07-06Validating and Monitoring Agency Issuance of Personal Identity Verification CredentialsOMBOMB memorandumJanuary 11, 2007Rescinded
M-07-11Implementation of Commonly Accepted Security Configurations for Windows Operating SystemsOMBOMB memorandumMarch 22, 2007Rescinded
M-07-16Safeguarding Against and Responding to the Breach of Personally Identifiable InformationOMBOMB memorandumMay 22, 2007Rescinded

What the statuses mean

In effect
Still in force, possibly with amendments.
Proposed
A proposed rule or draft. It may change before it takes effect.
Superseded
Replaced by a newer document or edition.
Rescinded
Cancelled by its issuer.
Withdrawn
Withdrawn by its issuer (NIST's term).
Retired
Closed by its issuer (CISA's term for a directive that has done its job).
Expired
Lapsed on its own terms.

Names on this page

AI
Artificial intelligence
BOD
Binding Operational Directive, issued by CISA
CISA
Cybersecurity and Infrastructure Security Agency
CUI
Controlled Unclassified Information
DFARS
Defense Federal Acquisition Regulation Supplement, the Department of Defense's additions to the FAR
DoD
Department of Defense
ED
Emergency Directive, issued by CISA
EO
Executive order
FAR
Federal Acquisition Regulation, the rules for federal contracts
FASC
Federal Acquisition Security Council
FedRAMP
Federal Risk and Authorization Management Program, run by GSA
FIPS
Federal Information Processing Standard, published by NIST
FISMA
Federal Information Security Modernization Act
GSA
General Services Administration
ISOO
Information Security Oversight Office, part of NARA
IT
Information technology
MFA
Multifactor authentication
NARA
National Archives and Records Administration
NIST
National Institute of Standards and Technology
OMB
Office of Management and Budget
OPM
Office of Personnel Management
PIV
Personal Identity Verification, the federal employee ID card
SBOM
Software bill of materials: a list of the parts in a piece of software

Get new governance by email

A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.

Send me

We use your address only to send what you choose, and every email has a one-click unsubscribe. Read the privacy notice.