Skip to content

Governance tracker

Federal cybersecurity, privacy, and technology governance

Every federal cybersecurity, privacy, and information technology (IT) governance document from the Privacy Act of 1974 to today: laws, executive orders, memoranda, directives, standards, and contract rules.

FedXchange's watch checks the Cybersecurity and Infrastructure Security Agency (CISA), the Office of Management and Budget (OMB), the National Archives (NARA), and the Federal Register every day, and the National Institute of Standards and Technology (NIST) every week. New finds appear here the day they are found. The tracker lists public documents only.

Get new governance by emailWhat the statuses meanNames on this page

Found in the last 7 days

Nothing new in the last 7 days.

Skip to the results

Filters

Results

Showing 101 to 150.

Governance documents, sorted by date issued, oldest first. Page 3 of 13.

The table scrolls sideways. Each title opens the document's page.

Governance documents, sorted by date issued, oldest first. Page 3 of 13.
Number, sort A to ZTitle, sort A to ZIssuer, sort A to ZTypeIssued, sort newest firstStatus, sort A to Z
M-07-18Ensuring New Acquisitions Include Common Security ConfigurationsOMBOMB memorandumJune 1, 2007In effect
M-07-19FY 2007 Reporting Instructions for the Federal Information Security Management Act and Agency Privacy ManagementOMBOMB memorandumJuly 25, 2007Rescinded
M-08-01HSPD-12 Implementation StatusOMBOMB memorandumOctober 23, 2007Rescinded
M-08-05Implementation of Trusted Internet Connections (TIC)OMBOMB memorandumNovember 20, 2007Rescinded
SP 800-53 Rev. 2Recommended Security Controls for Federal Information SystemsNISTNIST Special PublicationDecember 19, 2007Withdrawn
SP 800-61 Rev. 1Computer Security Incident Handling GuideNISTNIST Special PublicationMarch 7, 2008Withdrawn
M-08-16Guidance for Trusted Internet Connection Statement of Capability Form (SOC)OMBOMB memorandumApril 4, 2008Rescinded
NoneDesignation and Sharing of Controlled Unclassified Information (CUI)White HousePresidential directiveMay 7, 2008Superseded
EO 13467Reforming Processes Related to Suitability for Government Employment, Fitness for Contractor Employees, and Eligibility for Access to Classified National Security InformationWhite HouseExecutive orderJune 30, 2008In effect
SP 800-53AGuide for Assessing the Security Controls in Federal Information Systems and Organizations: Building Effective Security Assessment PlansNISTNIST Special PublicationJuly 2008Withdrawn
M-08-21FY 2008 Reporting Instructions for the Federal Information Security Management Act and Agency Privacy ManagementOMBOMB memorandumJuly 14, 2008Rescinded
SP 800-55 Rev. 1Performance Measurement Guide for Information SecurityNISTNIST Special PublicationJuly 16, 2008Withdrawn
SP 800-60 Vol. 1 Rev. 1Guide for Mapping Types of Information and Information Systems to Security CategoriesNISTNIST Special PublicationAugust 2008In effect
M-08-22Guidance on the Federal Desktop Core Configuration (FDCC)OMBOMB memorandumAugust 11, 2008Rescinded
M-08-23Securing the Federal Government's Domain Name System InfrastructureOMBOMB memorandumAugust 22, 2008Rescinded
M-08-27Guidance for Trusted Internet Connection (TIC) ComplianceOMBOMB memorandumSeptember 30, 2008Rescinded
ISOO Notice 2009-01Use of Standard Form 715, "Declassification Review Tab"NARAISOO noticeOctober 10, 2008In effect
ISOO Notice 2009-02Initial Instructions on the Use of the SF 715, "Declassification Review Tab"NARAISOO noticeOctober 10, 2008In effect
ISOO Notice 2009-03Notification, Coordination, and Documentation Related to Subsequent Reviews Conducted by Primary Reviewing Agencies [Related to Automatic Declassification]NARAISOO noticeOctober 10, 2008In effect
ISOO Notice 2009-04"Best Practices" for Declassification Review Record KeepingNARAISOO noticeOctober 10, 2008In effect
ISOO Notice 2009-05Agencies Ineligible to Receive Referrals Identified by Primary Reviewing Agencies Amongst Records Subject to Automatic Declassification on December 31st of 2006, 2007, and 2008NARAISOO noticeOctober 10, 2008Rescinded
M-09-02Information Technology Management Structure and Governance FrameworkOMBOMB memorandumOctober 21, 2008Rescinded
EO 13478Amendments to Executive Order 9397 Relating to Federal Agency Use of Social Security NumbersWhite HouseExecutive orderNovember 18, 2008In effect
ISOO Notice 2009-06Handling NATO Information Identified during Automatic Declassification ProcessingNARAISOO noticeDecember 12, 2008Rescinded
ISOO Notice 2009-07Mandatory Declassification Review – Inappropriate Citation of Section 6.2(d) of E.O. 13526NARAISOO noticeJanuary 8, 2009In effect
ISOO Notice 2009-08Utilization of Classified AddendaNARAISOO noticeJanuary 8, 2009Rescinded
ISOO Notice 2009-09Derivative Classification – Identification of Multiple SourcesNARAISOO noticeJanuary 9, 2009Rescinded
NoneTransparency and Open GovernmentWhite HousePresidential directiveJanuary 21, 2009In effect
ISOO Notice 2009-10Security Violation Reporting to ISOONARAISOO noticeApril 28, 2009Rescinded
ISOO Notice 2009-11Prohibited Use of the Markings "MR" (Manual Review) and "Source Marked MR, date of source [date]"NARAISOO noticeMay 8, 2009Rescinded
ISOO Notice 2009-12Prohibited Use of the Marking "OADR"NARAISOO noticeMay 8, 2009Rescinded
ISOO Notice 2009-13Prohibited Use of X1-X8 MarkingsNARAISOO noticeMay 8, 2009Rescinded
NoneClassified Information and Controlled Unclassified InformationWhite HousePresidential directiveMay 27, 2009In effect
ISOO Notice 2009-14Corrections to Citations in 32 C.F.R. Part 2001 Referencing Open Storage AreasNARAISOO noticeJune 9, 2009Rescinded
ISOO Notice 2009-15Further Definition of "Comparable Media" as it Relates to Delays in the Onset of Automatic DeclassificationNARAISOO noticeJuly 16, 2009Rescinded
SP 800-53 Rev. 3Recommended Security Controls for Federal Information Systems and OrganizationsNISTNIST Special PublicationAugust 3, 2009Withdrawn
M-09-29FY 2009 Reporting Instructions for the Federal Information Security Management Act and Agency Privacy ManagementOMBOMB memorandumAugust 20, 2009Rescinded
M-09-32Update on the Trusted Internet Connections InitiativeOMBOMB memorandumSeptember 17, 2009Rescinded
M-10-06Open Government DirectiveOMBOMB memorandumDecember 8, 2009In effect
EO 13526Classified National Security InformationWhite HouseExecutive orderDecember 29, 2009In effect
SP 800-37 Rev. 1Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle ApproachNISTNIST Special PublicationFebruary 22, 2010Withdrawn
NoneFederal Data Center Consolidation InitiativeOMBOMB memorandumFebruary 26, 2010Superseded
SP 800-122Guide to Protecting the Confidentiality of Personally Identifiable Information (PII)NISTNIST Special PublicationApril 6, 2010In effect
M-10-15FY 2010 Reporting Instructions for the Federal Information Security Management Act and Agency Privacy ManagementOMBOMB memorandumApril 21, 2010Rescinded
SP 800-34 Rev. 1Contingency Planning Guide for Federal Information SystemsNISTNIST Special PublicationMay 31, 2010In effect
M-10-22Guidance for Online Use of Web Measurement and Customization TechnologiesOMBOMB memorandumJune 25, 2010In effect
M-10-23Guidance for Agency Use of Third-Party Websites and ApplicationsOMBOMB memorandumJune 25, 2010In effect
M-10-25Reforming the Federal Government's Efforts to Manage Information Technology ProjectsOMBOMB memorandumJune 28, 2010Rescinded
SP 800-53A Rev. 1Guide for Assessing the Security Controls in Federal Information Systems and Organizations: Building Effective Security Assessment PlansNISTNIST Special PublicationJune 29, 2010Withdrawn
M-10-28Clarifying Cybersecurity Responsibilities and Activities of the Executive Office of the President and the Department of Homeland Security (DHS)OMBOMB memorandumJuly 6, 2010Rescinded

What the statuses mean

In effect
Still in force, possibly with amendments.
Proposed
A proposed rule or draft. It may change before it takes effect.
Superseded
Replaced by a newer document or edition.
Rescinded
Cancelled by its issuer.
Withdrawn
Withdrawn by its issuer (NIST's term).
Retired
Closed by its issuer (CISA's term for a directive that has done its job).
Expired
Lapsed on its own terms.

Names on this page

AI
Artificial intelligence
BOD
Binding Operational Directive, issued by CISA
CISA
Cybersecurity and Infrastructure Security Agency
CUI
Controlled Unclassified Information
DFARS
Defense Federal Acquisition Regulation Supplement, the Department of Defense's additions to the FAR
DoD
Department of Defense
ED
Emergency Directive, issued by CISA
EO
Executive order
FAR
Federal Acquisition Regulation, the rules for federal contracts
FASC
Federal Acquisition Security Council
FedRAMP
Federal Risk and Authorization Management Program, run by GSA
FIPS
Federal Information Processing Standard, published by NIST
FISMA
Federal Information Security Modernization Act
GSA
General Services Administration
ISOO
Information Security Oversight Office, part of NARA
IT
Information technology
MFA
Multifactor authentication
NARA
National Archives and Records Administration
NIST
National Institute of Standards and Technology
OMB
Office of Management and Budget
OPM
Office of Personnel Management
PIV
Personal Identity Verification, the federal employee ID card
SBOM
Software bill of materials: a list of the parts in a piece of software

Get new governance by email

A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.

Send me

We use your address only to send what you choose, and every email has a one-click unsubscribe. Read the privacy notice.