Skip to content

Governance tracker

Federal cybersecurity, privacy, and technology governance

Every federal cybersecurity, privacy, and information technology (IT) governance document from the Privacy Act of 1974 to today: laws, executive orders, memoranda, directives, standards, and contract rules.

FedXchange's watch checks the Cybersecurity and Infrastructure Security Agency (CISA), the Office of Management and Budget (OMB), the National Archives (NARA), and the Federal Register every day, and the National Institute of Standards and Technology (NIST) every week. New finds appear here the day they are found. The tracker lists public documents only.

Get new governance by emailWhat the statuses meanNames on this page

Found in the last 7 days

Nothing new in the last 7 days.

Skip to the results

Filters

Results

Showing 551 to 600.

Governance documents, sorted by date issued, newest first. Page 12 of 13.

The table scrolls sideways. Each title opens the document's page.

Governance documents, sorted by date issued, newest first. Page 12 of 13.
Number, sort A to ZTitle, sort A to ZIssuer, sort A to ZTypeIssued, sort oldest firstStatus, sort A to Z
M-05-08Designation of Senior Agency Officials for PrivacyOMBOMB memorandumFebruary 11, 2005Rescinded
M-05-05Electronic Signatures: How to Mitigate the Risk of Commercial Managed ServicesOMBOMB memorandumDecember 20, 2004Rescinded
M-05-04Policies for Federal Agency Public WebsitesOMBOMB memorandumDecember 17, 2004Rescinded
M-04-26Personal Use Policies and "File Sharing" TechnologyOMBOMB memorandumSeptember 8, 2004Rescinded
HSPD-12Policy for a Common Identification Standard for Federal Employees and ContractorsWhite HousePresidential directiveAugust 27, 2004In effect
M-04-25FY 2004 Reporting Instructions for the Federal Information Security Management ActOMBOMB memorandumAugust 23, 2004Rescinded
M-04-16Software AcquisitionOMBOMB memorandumJuly 1, 2004In effect
SP 800-63Electronic Authentication GuidelineNISTNIST Special PublicationJune 30, 2004Withdrawn
5 CFR 930.301Information Security Responsibilities for Employees who Manage or Use Federal Information SystemsOPMRegulationJune 14, 2004In effect
SP 800-60 Vol. 1Guide for Mapping Types of Information and Information Systems to Security CategoriesNISTNIST Special PublicationJune 10, 2004Withdrawn
SP 800-37Guide for the Security Certification and Accreditation of Federal Information SystemsNISTNIST Special PublicationMay 20, 2004Withdrawn
FIPS 199Standards for Security Categorization of Federal Information and Information SystemsNISTFIPS standardFebruary 2004In effect
SP 800-61Computer Security Incident Handling GuideNISTNIST Special PublicationJanuary 16, 2004Withdrawn
HSPD-7Critical Infrastructure Identification, Prioritization, and ProtectionWhite HousePresidential directiveDecember 17, 2003Superseded
M-04-04E-Authentication Guidance for Federal AgenciesOMBOMB memorandumDecember 16, 2003Rescinded
SP 800-50Building an Information Technology Security Awareness and Training ProgramNISTNIST Special PublicationOctober 2003Withdrawn
M-03-22OMB Guidance for Implementing the Privacy Provisions of the E-Government Act of 2002OMBOMB memorandumSeptember 26, 2003In effect
NoneEmployees Responsible for the Management or Use of Federal Computer SystemsOPMProposed ruleSeptember 4, 2003Superseded
M-03-19Reporting Instructions for the Federal Information Security Management Act and Updated Guidance on Quarterly IT Security ReportingOMBOMB memorandumAugust 6, 2003Rescinded
M-03-18Implementation Guidance for the E-Government Act of 2002OMBOMB memorandumAugust 1, 2003In effect
M-03-14Reducing Cost and Improving Quality in Federal Purchases of Commercial SoftwareOMBOMB memorandumJune 2, 2003Rescinded
EO 13292Further Amendment to Executive Order 12958, as Amended, Classified National Security InformationWhite HouseExecutive orderMarch 25, 2003Superseded
Pub. L. 107-347E-Government Act of 2002CongressLawDecember 17, 2002In effect
Pub. L. 107-347, Title IIIFederal Information Security Management Act of 2002CongressLawDecember 17, 2002Superseded
Pub. L. 107-347, Title VConfidential Information Protection and Statistical Efficiency Act of 2002CongressLawDecember 17, 2002Superseded
Pub. L. 107-305Cyber Security Research and Development ActCongressLawNovember 27, 2002In effect
Pub. L. 107-296Homeland Security Act of 2002CongressLawNovember 25, 2002In effect
M-02-09Reporting Instructions for the Government Information Security Reform Act and Updated Guidance on Security Plans of Action and MilestonesOMBOMB memorandumJuly 2, 2002Rescinded
SP 800-30Risk Management Guide for Information Technology SystemsNISTNIST Special PublicationJuly 2002Withdrawn
SP 800-34Contingency Planning Guide for Information Technology SystemsNISTNIST Special PublicationJune 13, 2002Withdrawn
FIPS 197Advanced Encryption Standard (AES)NISTFIPS standardNovember 26, 2001In effect
M-02-01Guidance for Preparing and Submitting Security Plans of Action and MilestonesOMBOMB memorandumOctober 17, 2001In effect
EO 13231Critical Infrastructure Protection in the Information AgeWhite HouseExecutive orderOctober 16, 2001In effect
M-01-24Reporting Instructions for the Government Information Security Reform ActOMBOMB memorandumJune 22, 2001Rescinded
FIPS 140-2Security Requirements for Cryptographic ModulesNISTFIPS standardMay 25, 2001Superseded
M-01-08Guidance on Implementing the Government Information Security Reform ActOMBOMB memorandumJanuary 16, 2001Rescinded
M-01-05Guidance on Inter-Agency Sharing of Personal Data - Protecting Personal PrivacyOMBOMB memorandumDecember 20, 2000In effect
Circular A-130Management of Federal Information ResourcesOMBOMB circularNovember 28, 2000Superseded
Pub. L. 106-398, Title X, Subtitle GGovernment Information Security ReformCongressLawOctober 30, 2000Superseded
M-00-15OMB Guidance on Implementing the Electronic Signatures in Global and National Commerce ActOMBOMB memorandumSeptember 25, 2000In effect
M-00-13Privacy Policies and Data Collection on Federal Web SitesOMBOMB memorandumJune 22, 2000Rescinded
M-00-10OMB Procedures and Guidance on Implementing the Government Paperwork Elimination ActOMBOMB memorandumApril 25, 2000In effect
M-00-07Incorporating and Funding Security in Information Systems InvestmentsOMBOMB memorandumFebruary 28, 2000Rescinded
NoneMemorandum on Electronic GovernmentWhite HousePresidential directiveDecember 17, 1999In effect
EO 13130National Infrastructure Assurance CouncilWhite HouseExecutive orderJuly 14, 1999Superseded
M-99-20Security of Federal Automated Information ResourcesOMBOMB memorandumJune 23, 1999Rescinded
M-99-18Privacy Policies on Federal Web SitesOMBOMB memorandumJune 2, 1999Superseded
M-99-05Instructions on Complying with President's Memorandum of May 14, 1998, "Privacy and Personal Information in Federal Records"OMBOMB memorandumJanuary 7, 1999Superseded
Pub. L. 105-277, Div. C, Title XVIIGovernment Paperwork Elimination ActCongressLawOctober 21, 1998In effect
EO 13103Computer Software PiracyWhite HouseExecutive orderSeptember 30, 1998In effect

What the statuses mean

In effect
Still in force, possibly with amendments.
Proposed
A proposed rule or draft. It may change before it takes effect.
Superseded
Replaced by a newer document or edition.
Rescinded
Cancelled by its issuer.
Withdrawn
Withdrawn by its issuer (NIST's term).
Retired
Closed by its issuer (CISA's term for a directive that has done its job).
Expired
Lapsed on its own terms.

Names on this page

AI
Artificial intelligence
BOD
Binding Operational Directive, issued by CISA
CISA
Cybersecurity and Infrastructure Security Agency
CUI
Controlled Unclassified Information
DFARS
Defense Federal Acquisition Regulation Supplement, the Department of Defense's additions to the FAR
DoD
Department of Defense
ED
Emergency Directive, issued by CISA
EO
Executive order
FAR
Federal Acquisition Regulation, the rules for federal contracts
FASC
Federal Acquisition Security Council
FedRAMP
Federal Risk and Authorization Management Program, run by GSA
FIPS
Federal Information Processing Standard, published by NIST
FISMA
Federal Information Security Modernization Act
GSA
General Services Administration
ISOO
Information Security Oversight Office, part of NARA
IT
Information technology
MFA
Multifactor authentication
NARA
National Archives and Records Administration
NIST
National Institute of Standards and Technology
OMB
Office of Management and Budget
OPM
Office of Personnel Management
PIV
Personal Identity Verification, the federal employee ID card
SBOM
Software bill of materials: a list of the parts in a piece of software

Get new governance by email

A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.

Send me

We use your address only to send what you choose, and every email has a one-click unsubscribe. Read the privacy notice.