Skip to content

Governance tracker

Federal cybersecurity, privacy, and technology governance

Every federal cybersecurity, privacy, and information technology (IT) governance document from the Privacy Act of 1974 to today: laws, executive orders, memoranda, directives, standards, and contract rules.

FedXchange's watch checks the Cybersecurity and Infrastructure Security Agency (CISA), the Office of Management and Budget (OMB), the National Archives (NARA), and the Federal Register every day, and the National Institute of Standards and Technology (NIST) every week. New finds appear here the day they are found. The tracker lists public documents only.

Get new governance by emailWhat the statuses meanNames on this page

Found in the last 7 days

Nothing new in the last 7 days.

Skip to the results

Filters

Results

95 documents match these filters

Filters: Risk management and controls.

Showing 51 to 95.

Governance documents, sorted by date issued, newest first. Page 2 of 2.

The table scrolls sideways. Each title opens the document's page.

Governance documents, sorted by date issued, newest first. Page 2 of 2.
Number, sort A to ZTitle, sort A to ZIssuer, sort A to ZTypeIssued, sort oldest firstStatus, sort A to Z
EO 13636Improving Critical Infrastructure CybersecurityWhite HouseExecutive orderFebruary 12, 2013In effect
SP 800-30 Rev. 1Guide for Conducting Risk AssessmentsNISTNIST Special PublicationSeptember 17, 2012In effect
NoneFederal Acquisition Regulation; Basic Safeguarding of Contractor Information SystemsFAR CouncilProposed ruleAugust 24, 2012Superseded
NoneFedRAMP becomes operationalGSA and FedRAMPFedRAMP policyJune 2012In effect
NoneSecurity Authorization of Information Systems in Cloud Computing EnvironmentsOMBOMB memorandumDecember 8, 2011Rescinded
EO 13587Structural Reforms To Improve the Security of Classified Networks and the Responsible Sharing and Safeguarding of Classified InformationWhite HouseExecutive orderOctober 7, 2011In effect
SP 800-137Information Security Continuous Monitoring (ISCM) for Federal Information Systems and OrganizationsNISTNIST Special PublicationSeptember 30, 2011In effect
SP 800-128Guide for Security-Focused Configuration Management of Information SystemsNISTNIST Special PublicationAugust 12, 2011In effect
M-11-27Implementing the Telework Enhancement Act of 2010: Security GuidelinesOMBOMB memorandumJuly 15, 2011In effect
SP 800-39Managing Information Security Risk: Organization, Mission, and Information System ViewNISTNIST Special PublicationMarch 2011In effect
SP 800-53A Rev. 1Guide for Assessing the Security Controls in Federal Information Systems and Organizations: Building Effective Security Assessment PlansNISTNIST Special PublicationJune 29, 2010Withdrawn
SP 800-34 Rev. 1Contingency Planning Guide for Federal Information SystemsNISTNIST Special PublicationMay 31, 2010In effect
SP 800-37 Rev. 1Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle ApproachNISTNIST Special PublicationFebruary 22, 2010Withdrawn
M-09-32Update on the Trusted Internet Connections InitiativeOMBOMB memorandumSeptember 17, 2009Rescinded
SP 800-53 Rev. 3Recommended Security Controls for Federal Information Systems and OrganizationsNISTNIST Special PublicationAugust 3, 2009Withdrawn
M-08-27Guidance for Trusted Internet Connection (TIC) ComplianceOMBOMB memorandumSeptember 30, 2008Rescinded
M-08-22Guidance on the Federal Desktop Core Configuration (FDCC)OMBOMB memorandumAugust 11, 2008Rescinded
SP 800-60 Vol. 1 Rev. 1Guide for Mapping Types of Information and Information Systems to Security CategoriesNISTNIST Special PublicationAugust 2008In effect
SP 800-53AGuide for Assessing the Security Controls in Federal Information Systems and Organizations: Building Effective Security Assessment PlansNISTNIST Special PublicationJuly 2008Withdrawn
M-08-16Guidance for Trusted Internet Connection Statement of Capability Form (SOC)OMBOMB memorandumApril 4, 2008Rescinded
SP 800-53 Rev. 2Recommended Security Controls for Federal Information SystemsNISTNIST Special PublicationDecember 19, 2007Withdrawn
M-08-05Implementation of Trusted Internet Connections (TIC)OMBOMB memorandumNovember 20, 2007Rescinded
M-07-18Ensuring New Acquisitions Include Common Security ConfigurationsOMBOMB memorandumJune 1, 2007In effect
M-07-11Implementation of Commonly Accepted Security Configurations for Windows Operating SystemsOMBOMB memorandumMarch 22, 2007Rescinded
SP 800-53 Rev. 1Recommended Security Controls for Federal Information SystemsNISTNIST Special PublicationDecember 19, 2006Withdrawn
FIPS 200Minimum Security Requirements for Federal Information and Information SystemsNISTFIPS standardMarch 2006In effect
SP 800-18 Rev. 1Guide for Developing Security Plans for Federal Information SystemsNISTNIST Special PublicationFebruary 24, 2006Withdrawn
SP 800-53Recommended Security Controls for Federal Information SystemsNISTNIST Special PublicationFebruary 28, 2005Withdrawn
SP 800-60 Vol. 1Guide for Mapping Types of Information and Information Systems to Security CategoriesNISTNIST Special PublicationJune 10, 2004Withdrawn
SP 800-37Guide for the Security Certification and Accreditation of Federal Information SystemsNISTNIST Special PublicationMay 20, 2004Withdrawn
FIPS 199Standards for Security Categorization of Federal Information and Information SystemsNISTFIPS standardFebruary 2004In effect
Pub. L. 107-347, Title IIIFederal Information Security Management Act of 2002CongressLawDecember 17, 2002Superseded
Pub. L. 107-305Cyber Security Research and Development ActCongressLawNovember 27, 2002In effect
M-02-09Reporting Instructions for the Government Information Security Reform Act and Updated Guidance on Security Plans of Action and MilestonesOMBOMB memorandumJuly 2, 2002Rescinded
SP 800-30Risk Management Guide for Information Technology SystemsNISTNIST Special PublicationJuly 2002Withdrawn
SP 800-34Contingency Planning Guide for Information Technology SystemsNISTNIST Special PublicationJune 13, 2002Withdrawn
M-02-01Guidance for Preparing and Submitting Security Plans of Action and MilestonesOMBOMB memorandumOctober 17, 2001In effect
Circular A-130Management of Federal Information ResourcesOMBOMB circularNovember 28, 2000Superseded
Pub. L. 106-398, Title X, Subtitle GGovernment Information Security ReformCongressLawOctober 30, 2000Superseded
FAR 52.239-1Privacy or Security SafeguardsFAR CouncilContract clauseAugust 1996In effect
Circular A-130Management of Federal Information ResourcesOMBOMB circularFebruary 8, 1996Superseded
NSD-42National Policy for the Security of National Security Telecommunications and Information SystemsWhite HousePresidential directiveJuly 5, 1990Superseded
Pub. L. 100-235Computer Security Act of 1987CongressLawJanuary 8, 1988Superseded
Circular A-130Management of Federal Information ResourcesOMBOMB circularDecember 24, 1985Superseded
NSDD-145National Policy on Telecommunications and Automated Information Systems SecurityWhite HousePresidential directiveSeptember 17, 1984Superseded

What the statuses mean

In effect
Still in force, possibly with amendments.
Proposed
A proposed rule or draft. It may change before it takes effect.
Superseded
Replaced by a newer document or edition.
Rescinded
Cancelled by its issuer.
Withdrawn
Withdrawn by its issuer (NIST's term).
Retired
Closed by its issuer (CISA's term for a directive that has done its job).
Expired
Lapsed on its own terms.

Names on this page

AI
Artificial intelligence
BOD
Binding Operational Directive, issued by CISA
CISA
Cybersecurity and Infrastructure Security Agency
CUI
Controlled Unclassified Information
DFARS
Defense Federal Acquisition Regulation Supplement, the Department of Defense's additions to the FAR
DoD
Department of Defense
ED
Emergency Directive, issued by CISA
EO
Executive order
FAR
Federal Acquisition Regulation, the rules for federal contracts
FASC
Federal Acquisition Security Council
FedRAMP
Federal Risk and Authorization Management Program, run by GSA
FIPS
Federal Information Processing Standard, published by NIST
FISMA
Federal Information Security Modernization Act
GSA
General Services Administration
ISOO
Information Security Oversight Office, part of NARA
IT
Information technology
MFA
Multifactor authentication
NARA
National Archives and Records Administration
NIST
National Institute of Standards and Technology
OMB
Office of Management and Budget
OPM
Office of Personnel Management
PIV
Personal Identity Verification, the federal employee ID card
SBOM
Software bill of materials: a list of the parts in a piece of software

Get new governance by email

A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.

Send me

We use your address only to send what you choose, and every email has a one-click unsubscribe. Read the privacy notice.