The US Office of Management and Budget has today published a revised Circular A-130, Managing Information as a Strategic Resource, the first major update in more than 15 years to the core policy for federal information management.
Key points
- Agencies must manage information security and privacy risk continuously, using the NIST Risk Management Framework.
- Senior agency officials for privacy are given a stronger role, alongside Privacy Act and E-Government Act obligations.
- Privacy impact assessments and privacy controls must be integrated into the system lifecycle.
- Requirements apply to information systems operated by contractors on behalf of agencies.
UK organisations providing IT or data services to US federal agencies should expect contracts to reflect these security and privacy requirements.
Source: OMB Circular A-130, Managing Information as a Strategic Resource (White House archives)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.