External Resources

This page contains links to the reference materials that guide the federal government's physical and cyber-security standards.

Presidential Directives
Homeland Security Presidential Directive 12 (HSPD-12) – A policy requiring an interoperable identification standard for federal employees and contractors.

Legislation
Federal Information Security Management Act of 2002 (FISMA) – Mandates protection of federal information through a comprehensive framework with strict controls and oversight.

Health Insurance Portability and Accountability Act of 1996 (HIPPA) – This act mandates protection of confidentiality and security of health data through establishing and enforcing standards.

Office of Management and Budget (OMB) Guidance
OMB Memorandum M-05-24 OMB HSPD-12 – Implementation guidance relating to GSA and FIPS 201.

OMB Memo M-07-04 – Use of Commercial Credit Monitoring Services Blanket Purchase Agreements (BPA) Additional information on BPAs can also be obtained from GSA.

OMB Memo M-08-10 – Use of Commercial Independent Risk Analysis Services Blanket Purchase Agreements (BPA) Additional information on BPAs can also be obtained from GSA.

Standards
National Institute of Standard Computer Resource Center Library – Includes links to legislation, directives, policies, standards and guidelines, tutorials, presentations and papers on cyber-security and HSPD-12.

Department of Commerce Federal Information Processing Standard (FIPS) 201 – Issued by the National Institute of Science and Technology. This memo specifies HSPD-12 compliant architecture and technical requirements.

FIPS 201 Evaluation Program – Implementation of FIPS 201 architecture in the evaluation of products. This includes the Approved Products List.

International CIIP Handbook 2008/2009 - An Inventory of twenty-five (25) National and seven (7) International Critical Information Infrastructure Protection Policies

Working Groups and Committees
Federal Identity Credentialing Committee – Provides recommendations for the development of an interoperable identity management-infrastructure for federal organizations in accordance with HSPD 12.

Last Reviewed 1/16/2009