Laws, Regulations & Policies
Federal regulations, public laws, and other mandates form the foundation of the IHS information security program. The major regulations to which IHS must adhere are listed below. Please note that the list is not all inclusive.
- E-Government Act of 2002 : Establishes policies to support IT standards and guidelines and encouras collaboration and enhancws understanding of best practices.
- Federal Information Security Modernization Act of 2014 (FISMA) : Codifies the Department of Homeland Security's role in administering the implementation of information security policies for federal Executive Branch civilian agencies, overseeing agencies' compliance with those policies, and assisting the Office of Management and Budget in developing those policies.
- Federal Information Processing Standards (FIPS) : These standards establish US Government security requirements for data and its encryption.
- Health Insurance Portability and Accountability Act of 1996 (HIPAA) : Designed to protect confidential healthcare information through improved security standards and federal privacy legislation.
- HIPAA Administration Simplification : Required the Department of Health and Human Services (HHS) to establish national standards for electronic health care transactions and national identifiers for providers, health plans, and employers. It also addressed the security and privacy of health data.
- NIST Special Regulations : Also known as the "800 Series," these regulations provide a separate identity for information technology security publications.
- Homeland Security Presidential Directive/HSPD-12 : Policy for Common Identification Standard for Federal Employees and Contractors. This directive establishes a mandatory, government-wide standard for secure and reliable forms of identification issued by the federal government to its employees and contractors.
- Homeland Security Presidential Directive/HSPD-7 : Policy for Critical Infrastructure Identification, Prioritization, and Protection. This directive establishes a national policy for federal departments and agencies to identify and prioritize critical infrastructure and to protect them from terrorist attacks.
- OMB Circular, A-123, Management Accountability and Control : Implements the Federal Managers Financial Integrity Act of 1982 by providing guidance to federal managers on improving accountability and effectiveness of federal programs and operations.
- Privacy Act of 1974 : Establishes a code of fair information practice that governs federal agencies’ collection, maintenance, use, and dissemination of individuals’ personally identifiable information.
- HHS Security and Privacy Policies : Establish department-wide information security policy for HHS and its operating divisions, including IHS.
- IHS Security and Privacy Policies: Establishes IHS-wide information security policies.
Useful References
- Area IT Service Desk
Links to local IT support. - Training Resources
Documents, infographics, websites, and videos created by DIS to help users learn more about cybersecurity. - ISSA Training Site
A direct link to IHS's mandatory security training site. - NIST Glossary
A link to a glossary of terms from NIST's cybersecurity- and privacy-related publications.