Are women uniquely qualified to answer "why?" and "do I have to?"

Maybe so.

Yes, because it's the law.

I like to start with review of  Federal Register :: Revision of OMB Circular No. A-130, “Managing Information as a Strategic Resource”, which is beautifully summarized by Carol Bales This email address is being protected from spambots. You need JavaScript enabled to view it. Office of Management and Budget Circular A-130 "Managing Information as a Strategic Resource" (nist.gov).

I always follow A-130 with a briefing on Appendix I to OMB Circular No 108 (whitehouse.gov). When a control says it complies with privacy laws, I like to begin with a paragraph-by-paragraph alignment to the 108.OMB-108 Privacy ACT FISMA OMB A-130 and more

44 USC 31 Title 44 Public Printing and Documents; Chapter 31 Records Management by Federal Agencies; Sections 3101 through 3107
5 USC 552a Title 5 Government Organization and Employees; Chapter 5 Administrative Procedure; Section 552a Records maintained on individuals
HSPD-12 Homeland Security Presidential Directive 12: Policy for a Common Identification Standard for Federal Employees and Contractors
HSPD-7 Homeland Security Presidential Directive 7: Critical Infrastructure Identification, Prioritization, and Protection
OMB A-108 Federal Agency Responsibilities for Maintaining Records About Individuals (Reissuance)
OMB A-123 Management’s Responsibility for Enterprise Risk Management and Internal Control
OMB A-130 Managing Information as a Strategic Resource
OMB M-01-05 Guidance on Inter-Agency Sharing of Personal Data – Protecting Personal Privacy
OMB M-03-22 OMB Guidance for Implementing the Privacy Provisions of the E-Government Act of 2002
OMB M-17-12 Preparing for and Responding to a Breach of Personally Identifiable Information (PII)
OMB M-10-23 Guidance for Agency Use of Third-Party Websites and Applications
OMB M-99-18 Privacy Policies on Federal Web Sites
PL 99-474 Computer Fraud and Abuse Act of 1986, 18 USC 1030
PL 100-503 Computer Matching and Privacy Protection Act of 1988
PL 104-191 Health Insurance Portability and Accountability Act of 1996 (HIPAA)
PL 104-231 Electronic Freedom of Information Act Amendments of 1996
PL 107-56 USA Patriot Act (Uniting and Strengthening America by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism)
PL 107-347 E-Government Act of 2002 - Federal Information Security Management Act (FISMA) of 2002, Title III
PL 107-347 E-Government Act of 2002 - Section 208. Privacy provisions.
PL 107-347 E-Government Act of 2002 - Confidential Information Protection and Statistical Efficiency Act of 2002 (CIPSEA), Title V
PL 108-447 Consolidated Appropriations Act, 2005, Section 522, a-e
PL 113-187 The Presidential and Federal Records Act Amendments of 2014
PL 113-283 Federal Information Security Modernization Act (FISMA) of 2014
NARA 44 USC 44 U.S.C. Federal Records Act, Chapters 21, 29, 31, 33 (see Public Law 113-187)
FTC Sec-5 Federal Trade Commission Act Section 5: Unfair or Deceptive Acts or Practices
e-CFR data Title 36, Code of Federal Regulations, Chapter XII, Subchapter B
NCSL State Laws Related to Internet Privacy

 

Why isn't it good enough? Because you didn't do it like this. Let me show you.

FIPS 140-2 Security Requirements for Cryptographic Modules
FIPS 140-3 Security Requirements for Cryptographic Modules (supersedes FIPS PUB 140-2). This standard becomes effective six months after approval.
FIPS 199 Standards for Security Categorization of Federal Information and Information Systems
FIPS 200 Minimum Security Requirements for Federal Information and Information Systems
FIPS 201-2 Personal Identity Verification (PIV) of Federal Employees and Contractors
SP 800-18 Guide for Developing Security Plans for Federal Information Systems, Revision 1
SP 800-30 Guide for Conducting Risk Assessments, Revision 1
SP 800-34 Contingency Planning Guide for Federal Information Systems, Revision 1 [includes updates as of 11-11-10]
SP 800-37 Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy, Revision 2
SP 800-39 Managing Information Security Risk: Organization, Mission, and Information System View
SP 800-47 Security Guide for Interconnecting Information Technology Systems
SP 800-53 Security and Privacy Controls for Federal Information Systems and Organizations, Revision 4 [includes updates as of 1/22/2015]
SP 800-53A Assessing Security and Privacy Controls in Federal Information Systems and Organizations: Building Effective Assessment Plans, Revision 4 [includes updates as of 12/18/2014]
SP 800-60 Vol I Volume I: Guide for Mapping Types of Information Systems to Security Categories, Revision 1
SP 800-60 Vol II Volume II: Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories, Revision 1
SP 800-61 Computer Security Incident Handling Guide, Revision 2
SP 800-63-3 Digital Identity Guidelines, Revision 3 [includes updates as of 12/1/2017]
SP 800-115 Technical Guide to Information Security Testing and Assessment
SP 800-122 Guide to Protecting the Confidentiality of Personally Identifiable Information (PII)
SP 800-128 Guide for Security-Focused Configuration Management of Information Systems
SP 800-137 Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations
SP 800-144 Guidelines on Security and Privacy in Public Cloud Computing
SP 800-145 The NIST Definition of Cloud Computing
SP 800-160 Vol I Systems Security Engineering, Considerations for a Multidisciplinary Approach in the Engineering of Trustworthy Secure Systems [updated March 2018]
FTC Privacy Online Privacy Online: Fair Information Practices in the Electronic Marketplace: A Federal Trade Commission Report to Congress
NARA 2010-05 Guidance on Managing Records in Cloud Computing Environments

 

Main Menu