Federal Policies and Guidance
Information about the federal agencies, laws, and policies that govern security and privacy activities at CMS
At ISPG, our work to protect the security and privacy of CMS end users is directly influenced by several federal sources. Laws passed by Congress, Executive Orders from the White House, and regulations from other federal agencies must be referenced regularly to ensure that we're operating effectively. These federal policies impact how we manage FISMA systems, what tools we use, how we protect personal information, and the steps we take to keep our systems compliant.
As our government continues to modernize its systems and change the way it does business, it's important for CMS staff and contractors to stay updated with the latest federal policies and guidance, provided below.
For a handy reference guide to the specific federal laws that shape security and privacy at CMS, check out the CMS Guide to Federal Laws, Regulations, and Policies -- a centralized repository you can reference anytime in your compliance-related work.
- #ispg-sec_privacy-policy
- #cms_fed_laws_policies
HHS OCIO policies
The majority of information security and privacy policies at CMS originate from the Department of Health and Human Services (HHS) Office of the Chief Information Officer (OCIO). You can access these policies at the link below if you are logged into the CMS/HHS intranet.
Top documents and resources
A comprehensive list of the federal laws, regulations, and policies that shape how information security and privacy are managed at CMS
FISMA is federal legislation that defines a framework of guidelines and security standards to protect government information and operations
Information about NIST and how the agency's policies and guidance relate to security and privacy at CMS
Summary of HIPAA and its policies, and their implications for ISPG
Executive Order that requires the continuous verification of system users to promote system security
Provides a federally-recognized and standardized security framework for all cloud products and services
Filtered view of related content using CyberGeek Search