Don’t do SECURITY. Do business SECURELY.

US Government publishes revised OMB Circular A-130

The revised OMB Circular A-130 updates how US federal agencies and their contractors must manage information security and privacy.

The US Office of Management and Budget has today published a revised Circular A-130, Managing Information as a Strategic Resource, the first major update in more than 15 years to the core policy for federal information management.

Key points

  • Agencies must manage information security and privacy risk continuously, using the NIST Risk Management Framework.
  • Senior agency officials for privacy are given a stronger role, alongside Privacy Act and E-Government Act obligations.
  • Privacy impact assessments and privacy controls must be integrated into the system lifecycle.
  • Requirements apply to information systems operated by contractors on behalf of agencies.

UK organisations providing IT or data services to US federal agencies should expect contracts to reflect these security and privacy requirements.

Source: OMB Circular A-130, Managing Information as a Strategic Resource (White House archives)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights