Are women uniquely qualified to answer "why?" and "do I have to?"
Maybe so.
Yes, because it's the law.
I like to start with review of Federal Register :: Revision of OMB Circular No. A-130, “Managing Information as a Strategic Resource”, which is beautifully summarized by Carol Bales
I always follow A-130 with a briefing on Appendix I to OMB Circular No 108 (whitehouse.gov). When a control says it complies with privacy laws, I like to begin with a paragraph-by-paragraph alignment to the 108.
| 44 USC 31 | Title 44 Public Printing and Documents; Chapter 31 Records Management by Federal Agencies; Sections 3101 through 3107 |
| 5 USC 552a | Title 5 Government Organization and Employees; Chapter 5 Administrative Procedure; Section 552a Records maintained on individuals |
| HSPD-12 | Homeland Security Presidential Directive 12: Policy for a Common Identification Standard for Federal Employees and Contractors |
| HSPD-7 | Homeland Security Presidential Directive 7: Critical Infrastructure Identification, Prioritization, and Protection |
| OMB A-108 | Federal Agency Responsibilities for Maintaining Records About Individuals (Reissuance) |
| OMB A-123 | Management’s Responsibility for Enterprise Risk Management and Internal Control |
| OMB A-130 | Managing Information as a Strategic Resource |
| OMB M-01-05 | Guidance on Inter-Agency Sharing of Personal Data – Protecting Personal Privacy |
| OMB M-03-22 | OMB Guidance for Implementing the Privacy Provisions of the E-Government Act of 2002 |
| OMB M-17-12 | Preparing for and Responding to a Breach of Personally Identifiable Information (PII) |
| OMB M-10-23 | Guidance for Agency Use of Third-Party Websites and Applications |
| OMB M-99-18 | Privacy Policies on Federal Web Sites |
| PL 99-474 | Computer Fraud and Abuse Act of 1986, 18 USC 1030 |
| PL 100-503 | Computer Matching and Privacy Protection Act of 1988 |
| PL 104-191 | Health Insurance Portability and Accountability Act of 1996 (HIPAA) |
| PL 104-231 | Electronic Freedom of Information Act Amendments of 1996 |
| PL 107-56 | USA Patriot Act (Uniting and Strengthening America by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism) |
| PL 107-347 | E-Government Act of 2002 - Federal Information Security Management Act (FISMA) of 2002, Title III |
| PL 107-347 | E-Government Act of 2002 - Section 208. Privacy provisions. |
| PL 107-347 | E-Government Act of 2002 - Confidential Information Protection and Statistical Efficiency Act of 2002 (CIPSEA), Title V |
| PL 108-447 | Consolidated Appropriations Act, 2005, Section 522, a-e |
| PL 113-187 | The Presidential and Federal Records Act Amendments of 2014 |
| PL 113-283 | Federal Information Security Modernization Act (FISMA) of 2014 |
| NARA 44 USC | 44 U.S.C. Federal Records Act, Chapters 21, 29, 31, 33 (see Public Law 113-187) |
| FTC Sec-5 | Federal Trade Commission Act Section 5: Unfair or Deceptive Acts or Practices |
| e-CFR data | Title 36, Code of Federal Regulations, Chapter XII, Subchapter B |
| NCSL | State Laws Related to Internet Privacy |
Why isn't it good enough? Because you didn't do it like this. Let me show you.
| FIPS 140-2 | Security Requirements for Cryptographic Modules |
| FIPS 140-3 | Security Requirements for Cryptographic Modules (supersedes FIPS PUB 140-2). This standard becomes effective six months after approval. |
| FIPS 199 | Standards for Security Categorization of Federal Information and Information Systems |
| FIPS 200 | Minimum Security Requirements for Federal Information and Information Systems |
| FIPS 201-2 | Personal Identity Verification (PIV) of Federal Employees and Contractors |
| SP 800-18 | Guide for Developing Security Plans for Federal Information Systems, Revision 1 |
| SP 800-30 | Guide for Conducting Risk Assessments, Revision 1 |
| SP 800-34 | Contingency Planning Guide for Federal Information Systems, Revision 1 [includes updates as of 11-11-10] |
| SP 800-37 | Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy, Revision 2 |
| SP 800-39 | Managing Information Security Risk: Organization, Mission, and Information System View |
| SP 800-47 | Security Guide for Interconnecting Information Technology Systems |
| SP 800-53 | Security and Privacy Controls for Federal Information Systems and Organizations, Revision 4 [includes updates as of 1/22/2015] |
| SP 800-53A | Assessing Security and Privacy Controls in Federal Information Systems and Organizations: Building Effective Assessment Plans, Revision 4 [includes updates as of 12/18/2014] |
| SP 800-60 Vol I | Volume I: Guide for Mapping Types of Information Systems to Security Categories, Revision 1 |
| SP 800-60 Vol II | Volume II: Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories, Revision 1 |
| SP 800-61 | Computer Security Incident Handling Guide, Revision 2 |
| SP 800-63-3 | Digital Identity Guidelines, Revision 3 [includes updates as of 12/1/2017] |
| SP 800-115 | Technical Guide to Information Security Testing and Assessment |
| SP 800-122 | Guide to Protecting the Confidentiality of Personally Identifiable Information (PII) |
| SP 800-128 | Guide for Security-Focused Configuration Management of Information Systems |
| SP 800-137 | Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations |
| SP 800-144 | Guidelines on Security and Privacy in Public Cloud Computing |
| SP 800-145 | The NIST Definition of Cloud Computing |
| SP 800-160 Vol I | Systems Security Engineering, Considerations for a Multidisciplinary Approach in the Engineering of Trustworthy Secure Systems [updated March 2018] |
| FTC Privacy Online | Privacy Online: Fair Information Practices in the Electronic Marketplace: A Federal Trade Commission Report to Congress |
| NARA 2010-05 | Guidance on Managing Records in Cloud Computing Environments |

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics