Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Feature/ritm1290567 #875

Merged
merged 2 commits into from
Feb 3, 2025
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -135,7 +135,7 @@ <h3>Related Policies, Priorities, and Resources</h3>
<span class="card-tag">Policy</span>
<p class="title-resources">
<a
href="https://www.whitehouse.gov/wp-content/uploads/2019/06/M-19-19-Data-Centers.pdf?"
href="https://trumpwhitehouse.archives.gov/wp-content/uploads/2019/06/M-19-19-Data-Centers.pdf?"
target="_blank"
style="text-decoration: none; color: black"
>OMB Memo M-19-19</a
Expand Down
2 changes: 1 addition & 1 deletion _policies/DCOI.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ related-filters: 'data-center-consolidation'
date: August 1, 2016
---
## Policy Overview ##
The [Data Center Optimization Initiative (DCOI)](https://datacenters.cio.gov/) was established in [OMB Memorandum M-19-19](https://www.whitehouse.gov/wp-content/uploads/2019/06/M-19-19-Data-Centers.pdf) in August 2016. It supercedes the Federal Data Center Consolidation Initiative (FDCCI) and fulfills the data center requirements of the [Federal Information Technology Acquisition Reform Act (FITARA)]({{ site.baseurl }}/policies-and-priorities/FITARA/). M-19-19 rescinds and replaces M-16-19 Data Center Optimization Initiative.
The [Data Center Optimization Initiative (DCOI)](https://datacenters.cio.gov/) was established in [OMB Memorandum M-19-19](https://trumpwhitehouse.archives.gov/wp-content/uploads/2019/06/M-19-19-Data-Centers.pdf) in August 2016. It supercedes the Federal Data Center Consolidation Initiative (FDCCI) and fulfills the data center requirements of the [Federal Information Technology Acquisition Reform Act (FITARA)]({{ site.baseurl }}/policies-and-priorities/FITARA/). M-19-19 rescinds and replaces M-16-19 Data Center Optimization Initiative.

The DCOI requires agencies to develop and report on data center strategies to consolidate inefficient infrastructure, optimize existing facilities, improve security posture, achieve cost savings, and transition to more efficient infrastructure, such as cloud services and inter-agency shared services
&nbsp;
Expand Down
2 changes: 1 addition & 1 deletion _policies/Data.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ date: June 4, 2019
## Policy Overview ##
The use of data is transforming society, business, and the economy. Data provided by the Federal Government have a unique place in society and maintaining trust in Federal data is pivotal to a democratic process. The Federal Government needs a robust, integrated approach to using data to deliver on mission, serve customers, and steward resources while respecting privacy and confidentiality.

The [Federal Data Strategy](https://strategy.data.gov/) consists of Principles and Practices to leverage the value of the entire Federal Government data asset portfolio while protecting security, privacy, and confidentiality. Defined in memorandum [M-19-18](https://www.whitehouse.gov/wp-content/uploads/2019/06/M-19-18.pdf) in June 2019, the principles and practices deliver a more consistent approach to federal data stewardship, use, and access.
The [Federal Data Strategy](https://strategy.data.gov/) consists of Principles and Practices to leverage the value of the entire Federal Government data asset portfolio while protecting security, privacy, and confidentiality. Defined in memorandum [M-19-18](https://trumpwhitehouse.archives.gov/wp-content/uploads/2019/06/M-19-18.pdf) in June 2019, the principles and practices deliver a more consistent approach to federal data stewardship, use, and access.

The four areas of Federal Data Strategy are:
- Enterprise Data Governance,
Expand Down
2 changes: 1 addition & 1 deletion _policies/FISMA.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ related-filters: 'cybersecurity'
date: April 26, 2019
---
## Policy Overview ##
[Federal Information Security Modernization Act of 2014 (FISMA)](https://www.whitehouse.gov/wp-content/uploads/2018/10/M-19-02.pdf), dating back to 2002, requires agencies to report the status of their information security programs to OMB and requires Inspectors General (IG) to conduct annual independent assessments of those programs. OMB and the Department of Homeland Security (DHS) collaborate with interagency partners to develop the Chief Information Officer (CIO) FISMA metrics, and with IG partners to develop the IG FISMA metrics to facilitate these processes. OMB also works with the Federal privacy community to develop Senior Agency Official for Privacy (SAOP) metrics. These three sets of metrics together provide a more comprehensive picture of an agency’s cybersecurity performance.
[Federal Information Security Modernization Act of 2014 (FISMA)](https://trumpwhitehouse.archives.gov/wp-content/uploads/2018/10/M-19-02.pdf), dating back to 2002, requires agencies to report the status of their information security programs to OMB and requires Inspectors General (IG) to conduct annual independent assessments of those programs. OMB and the Department of Homeland Security (DHS) collaborate with interagency partners to develop the Chief Information Officer (CIO) FISMA metrics, and with IG partners to develop the IG FISMA metrics to facilitate these processes. OMB also works with the Federal privacy community to develop Senior Agency Official for Privacy (SAOP) metrics. These three sets of metrics together provide a more comprehensive picture of an agency’s cybersecurity performance.
&nbsp;

{% assign related-tiles = page.related-filters %}
Expand Down
2 changes: 1 addition & 1 deletion _policies/ICAM.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ date: May 21, 2019

---
## Policy Overview ##
The memorandum OMB M-19-17 in May 2019, [Identity, Credentialing, and Access Management (ICAM)](https://www.whitehouse.gov/wp-content/uploads/2019/05/M-19-17.pdf), sets forth the Federal Government's latest ICAM policy and overrides a number of prior OMB memos dating to 2004.
The memorandum OMB M-19-17 in May 2019, [Identity, Credentialing, and Access Management (ICAM)](https://trumpwhitehouse.archives.gov/wp-content/uploads/2018/10/M-19-02.pdf), sets forth the Federal Government's latest ICAM policy and overrides a number of prior OMB memos dating to 2004.

Generally speaking, ICAM comprises the tools, policies, and systems that allow an organization to manage, monitor, and secure access to protected resources. To ensure secure and efficient operations, agencies of the Federal Government must be able to identify, credential, monitor, and manage subjects that access Federal resources. This includes information, information systems, facilities, and secured areas across their respective enterprises. In particular, how agencies conduct identity proofing, establish enterprise digital identities, and adopt sound processes for authentication and access control significantly affects the security and delivery of their services, as well as individuals' privacy.

Expand Down
2 changes: 1 addition & 1 deletion _policies/Management-of-Federal-High-Value-Assets.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ date: December 10, 2018
## Policy Overview ##
With the creation of the High Value Asset (HVA) initiative in 2015, the Federal Government’s CFO Act agencies took a pivotal step toward the identification of its most critical assets. DHS, in coordination with OMB, established a capability to assess agency HVAs, resulting in the identification of critical areas of weakness and plans to remediate those areas of weakness.

As of memorandum M-19-03 in December 2018, [Management of High Value Assets](https://www.whitehouse.gov/wp-content/uploads/2018/12/M-19-03.pdf) provides agencies with an updated approach to identifying HVAs. It established three possible categories for designating Federal information or a Federal information system as an HVA: Informational Value, Mission Essential, or Federal Civilian Enterprise Essential (FCEE). It also updates the require approach for agencies to report, assess, and remediate HVAs to protect against cyberattacks.
As of memorandum M-19-03 in December 2018, [Management of High Value Assets](https://trumpwhitehouse.archives.gov/wp-content/uploads/2018/12/M-19-03.pdf) provides agencies with an updated approach to identifying HVAs. It established three possible categories for designating Federal information or a Federal information system as an HVA: Informational Value, Mission Essential, or Federal Civilian Enterprise Essential (FCEE). It also updates the require approach for agencies to report, assess, and remediate HVAs to protect against cyberattacks.

This memorandum rescinds M-16-04, Cybersecurity Strategy and Implementation Plan (CSIP) for the Federal Civilian Government, and M-17-09, Management of Federal High Value Assets.
&nbsp;
Expand Down
2 changes: 1 addition & 1 deletion _policies/Shared-Services.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ related-filters: 'shared-services'
date: April 26, 2019
---
## Policy Overview ##
The [Centralized Mission Support Capabilities for the Federal Government](https://www.whitehouse.gov/wp-content/uploads/2019/04/M-19-16.pdf) memorandum, as of April 2019, is a strategy based on industry experiences and lessons learned from other central governments. Its goal is to reduce duplication, improve accountability, and improve Federal shared services. This updated strategy enables the delivery of an innovative, flexible, and competitive set of solutions and services.
The [Centralized Mission Support Capabilities for the Federal Government](https://trumpwhitehouse.archives.gov/wp-content/uploads/2019/04/M-19-16.pdf) memorandum, as of April 2019, is a strategy based on industry experiences and lessons learned from other central governments. Its goal is to reduce duplication, improve accountability, and improve Federal shared services. This updated strategy enables the delivery of an innovative, flexible, and competitive set of solutions and services.

Overseeing implementation of this strategy requires strong government-wide governance. Over time, the Shared Solutions Governance Board, Quality Service Management Offices, and customer agencies will continually refresh the Government’s shared services strategy to improve service delivery and performance, enhance customer satisfaction, and reduce costs to agency customers. Immediate implementation of this strategy requires the Government to define and execute an integrated approach to shared services, including:

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
title: Administration Cybersecurity Priorities for the FY 2024 Budget
subtitle: Administration Cybersecurity Priorities for the FY 2024 Budget
external-link: https://www.whitehouse.gov/wp-content/uploads/2022/07/M-22-16.pdf
external-link: https://bidenwhitehouse.archives.gov/wp-content/uploads/2023/12/M-24-04-FY24-FISMA-Guidance.pdf
filters: fed-policy cybersecurity
---
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
title: Administration Cybersecurity Priorities for the FY 2025 Budget
subtitle: Administration Cybersecurity Priorities for the FY 2025 Budget
external-link: https://www.whitehouse.gov/wp-content/uploads/2023/06/M-23-18-Administration-Cybersecurity-Priorities-for-the-FY-2025-Budget-s.pdf
external-link: https://bidenwhitehouse.archives.gov/wp-content/uploads/2023/06/M-23-18-Administration-Cybersecurity-Priorities-for-the-FY-2025-Budget-s.pdf
filters: fed-policy cybersecurity
---
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
title: Administration Cybersecurity Priorities for the FY 2026 Budget 
subtitle: Administration Cybersecurity Priorities for the FY 2026 Budget 
external-link: https://www.whitehouse.gov/wp-content/uploads/2024/07/FY26-Cybersecurity-Priorities-Memo_Signed.pdf
external-link: https://bidenwhitehouse.archives.gov/wp-content/uploads/2024/07/FY26-Cybersecurity-Priorities-Memo_Signed.pdf
filters: fed-policy cybersecurity
---
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
title: Advancing Governance, Innovation, and Risk Management for Agency Use of Artificial Intelligence
subtitle: Advancing Governance, Innovation, and Risk Management for Agency Use of Artificial Intelligence
external-link: https://www.whitehouse.gov/wp-content/uploads/2024/03/M-24-10-Advancing-Governance-Innovation-and-Risk-Management-for-Agency-Use-of-Artificial-Intelligence.pdf
external-link: https://bidenwhitehouse.archives.gov/wp-content/uploads/2024/03/M-24-10-Advancing-Governance-Innovation-and-Risk-Management-for-Agency-Use-of-Artificial-Intelligence.pdf
filters: fed-policy artificial-intelligence governance
---
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
title: Advancing the Responsible Acquisition of Artificial Intelligence in Government
subtitle: Advancing the Responsible Acquisition of Artificial Intelligence in Government
external-link: https://www.whitehouse.gov/wp-content/uploads/2024/10/M-24-18-AI-Acquisition-Memorandum.pdf
external-link: https://bidenwhitehouse.archives.gov/wp-content/uploads/2024/10/M-24-18-AI-Acquisition-Memorandum.pdf
filters: fed-policy artificial-intelligence acquisition
---
2 changes: 1 addition & 1 deletion _policies/delivering_a_digital-first_public_experience.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
title: Delivering a Digital-First Public Experience
subtitle: Delivering a Digital-First Public Experience
external-link: https://www.whitehouse.gov/omb/management/ofcio/delivering-a-digital-first-public-experience/
external-link: https://bidenwhitehouse.archives.gov/wp-content/uploads/2023/09/M-23-22-Delivering-a-Digital-First-Public-Experience.pdf
filters: fed-policy cx
---
2 changes: 1 addition & 1 deletion _policies/electronic_records.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
title: Electronic Records
subtitle: Electronic Records
external-link: https://www.whitehouse.gov/wp-content/uploads/2022/12/M_23_07-M-Memo-Electronic-Records_final.pdf
external-link: https://bidenwhitehouse.archives.gov/wp-content/uploads/2022/12/M_23_07-M-Memo-Electronic-Records_final.pdf
filters: fed-policy it-modernization
---
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
title: Enhancing the Security of the Software Supply Chain through Secure Software Development Practices
subtitle: Enhancing the Security of the Software Supply Chain through Secure Software Development Practices
external-link: https://www.whitehouse.gov/wp-content/uploads/2022/09/M-22-18.pdf
external-link: https://bidenwhitehouse.archives.gov/wp-content/uploads/2022/09/M-22-18.pdf
filters: fed-policy cybersecurity
---
2 changes: 1 addition & 1 deletion _policies/eo-ai-use-case-inventories-reference.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ The Director of the Office of Management and Budget (OMB) is charged with issuin

The consolidated 2024 Federal AI Use Case Inventory, current as of December 16, 2024, is available for download [here](https://github.com/ombegov/2024-Federal-AI-Use-Case-Inventory).

This year’s inventory significantly expands on prior years’ reporting, demonstrating transparency in how the United States is investing in AI for the public good. Agencies are required to identify whether their use of AI impacts the public’s rights or safety per [OMB Memorandum M-24-10](https://www.whitehouse.gov/wp-content/uploads/2024/03/M-24-10-Advancing-Governance-Innovation-and-Risk-Management-for-Agency-Use-of-Artificial-Intelligence.pdf) and how they are implementing safeguards to mitigate the relevant risks. Per M-24-10, after December 1, 2024, if the required safeguards are not adopted for a given AI system, agencies must stop using it. The inventory offers visibility into whether agencies are still working on actions to manage risks from the use of AI by identifying where agencies have received an extension of the December 1 deadline or have granted a waiver of particular requirements.
This year’s inventory significantly expands on prior years’ reporting, demonstrating transparency in how the United States is investing in AI for the public good. Agencies are required to identify whether their use of AI impacts the public’s rights or safety per [OMB Memorandum M-24-10](https://bidenwhitehouse.archives.gov/wp-content/uploads/2024/03/M-24-10-Advancing-Governance-Innovation-and-Risk-Management-for-Agency-Use-of-Artificial-Intelligence.pdf) and how they are implementing safeguards to mitigate the relevant risks. Per M-24-10, after December 1, 2024, if the required safeguards are not adopted for a given AI system, agencies must stop using it. The inventory offers visibility into whether agencies are still working on actions to manage risks from the use of AI by identifying where agencies have received an extension of the December 1 deadline or have granted a waiver of particular requirements.

As of December 16, 2024, agencies have reported over 1700 AI use cases.
* The top 3 categories for AI use cases are: mission-enabling (internal agency support), health and medical, and government services (includes benefits and service delivery).
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
title: Fiscal Year 2021-2022 Guidance on Federal Information Security and Privacy Management Requirements
subtitle: Fiscal Year 2021-2022 Guidance on Federal Information Security and Privacy Management Requirements
external-link: https://www.whitehouse.gov/wp-content/uploads/2021/12/M-22-05-FY22-FISMA-Guidance.pdf
external-link: https://bidenwhitehouse.archives.gov/wp-content/uploads/2021/12/M-22-05-FY22-FISMA-Guidance.pdf
filters: fed-policy cybersecurity
---
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
title: Fiscal Year 2024 Guidance on Federal Information Security and Privacy Management Requirements
subtitle: Fiscal Year 2024 Guidance on Federal Information Security and Privacy Management Requirements
external-link: https://www.whitehouse.gov/wp-content/uploads/2023/12/M-24-04-FY24-FISMA-Guidance.pdf
external-link: https://bidenwhitehouse.archives.gov/wp-content/uploads/2023/12/M-24-04-FY24-FISMA-Guidance.pdf
filters: fed-policy cybersecurity
---
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
title: Improving Detection of Cybersecurity Vulnerabilities and Incidents on Federal Government Systems through Endpoint Detection and Response
subtitle: Improving Detection of Cybersecurity Vulnerabilities and Incidents on Federal Government Systems through Endpoint Detection and Response
external-link: https://www.whitehouse.gov/wp-content/uploads/2021/10/M-22-01.pdf
external-link: https://bidenwhitehouse.archives.gov/wp-content/uploads/2021/10/M-22-01.pdf
filters: fed-policy cybersecurity
---
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
title: Improving the Federal Government’s Investigative and Remediation Capabilities Related to Cybersecurity Incident
subtitle: Improving the Federal Government’s Investigative and Remediation Capabilities Related to Cybersecurity Incident
external-link: https://www.whitehouse.gov/wp-content/uploads/2021/08/M-21-31-Improving-the-Federal-Governments-Investigative-and-Remediation-Capabilities-Related-to-Cybersecurity-Incidents.pdf
external-link: https://bidenwhitehouse.archives.gov/wp-content/uploads/2021/08/M-21-31-Improving-the-Federal-Governments-Investigative-and-Remediation-Capabilities-Related-to-Cybersecurity-Incidents.pdf
filters: fed-policy cybersecurity
---
2 changes: 1 addition & 1 deletion _policies/migrating_to_post-quantum_cryptography.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
title: Migrating to Post-Quantum Cryptography
subtitle: Migrating to Post-Quantum Cryptography
external-link: https://www.whitehouse.gov/wp-content/uploads/2022/11/M-23-02-M-Memo-on-Migrating-to-Post-Quantum-Cryptography.pdf
external-link: https://bidenwhitehouse.archives.gov/wp-content/uploads/2023/09/M-23-22-Delivering-a-Digital-First-Public-Experience.pdf
filters: fed-policy cybersecurity
---
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
title: Modernizing the Federal Risk and Authorization Management Program (FedRAMP)
subtitle: Modernizing the Federal Risk and Authorization Management Program (FedRAMP)
external-link: https://www.whitehouse.gov/omb/management/ofcio/m-24-15-modernizing-the-federal-risk-and-authorization-management-program-fedramp/
external-link: https://bidenwhitehouse.archives.gov/omb/management/ofcio/m-24-15-modernizing-the-federal-risk-and-authorization-management-program-fedramp/
filters: fed-policy cloud cybersecurity
---
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
title: Moving the U.S. Government Toward Zero Trust Cybersecurity Principles
subtitle: Moving the U.S. Government Toward Zero Trust Cybersecurity Principles
external-link: https://www.whitehouse.gov/wp-content/uploads/2022/01/M-22-09.pdf
external-link: https://bidenwhitehouse.archives.gov/wp-content/uploads/2022/01/M-22-09.pdf
filters: fed-policy cybersecurity
---
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
title: OMB Circular A-11 - Preparation, Submission, and Execution of the Budget
subtitle: OMB Circular A-11 - Preparation, Submission, and Execution of the Budget
external-link: https://www.whitehouse.gov/wp-content/uploads/2018/06/a11.pdf
external-link: https://bidenwhitehouse.archives.gov/wp-content/uploads/2018/06/a11.pdf
filters: fed-policy it-spending
---
Loading