OMB Flashcards

1
Q

M-96-20

A

Implementation of the Information Technology Management Reform Act of 1996

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

M-97-02

A

Funding Information Systems Investments

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

M-97-16

A

Information Technology Architecture

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

M-09-32

A

Update on the Trusted Internet Connections Initiative

  • Inventory external connections
  • Required agencies to submit POAM for meeting TIC requirements
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

M-09-02

A

Information Technology Management Structure and Governance Framework

-Heads of agencies to consult with the Director of the OMB prior to appointing a CIO, and to advise the Director on matters regarding the authority, responsibilities and organizational resources of the CIO, per OMB Circular A-130

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

M-08-27

A

Guidance for Trusted Internet Connection (TIC) Compliance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

M-08-23

A

Securing the Federal Government’s Domain Name System Infrastructure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

M-08-22

A

Guidance on the Federal Desktop Core Configuration (FDCC)

-Agencies will use SCAP tools to scan for both FDCC configurations and configuration deviations approved by the AO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

M-08-16

A

Guidance for Trusted Internet Connection Statement of Capability Form (SOC)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

M-08-05

A

Implementation of Trusted Internet Connections (TIC)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

M-08-01

A

HSPD-12 Implementation Status

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

M-07-18

A

Ensuring New Acquisitions Include Common Security Configurations

-Provides recommended language to ensure new acquisitions include common security configurations and vendors certify their products operate effectively using these configurations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

M-07-16

A

Safeguarding Against and Responding to the Breach of Personally Identifiable Information

  • Safeguarding PII
  • Breach notification policy
  • SAOP reporting metrics
  • Requires agency-based incident reporting policy
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

M-07-11

A

Implementation of Commonly Accepted Security Configurations for Windows Operating Systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

M-07-06

A

Validating and Monitoring Agency Issuance of Personal Identity Verification Credentials

-Ensure agency credentials meet FIPS 201 requirements

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

M-06-19

A

Reporting Incidents Involving Personally Identifiable Information and Incorporating the Cost for Security in Agency Information Technology Investments

-Requires reporting of potential PII data breach events to CERT within 1 hour of discovery

17
Q

M-06-18

A

Acquisition of Products and Services for Implementation of HSPD-12

18
Q

M-06-16

A

Protection of Sensitive Agency Information

19
Q

M-06-15

A

Safeguarding Personally Identifiable Information

-Requires privacy policies and public release of policies

20
Q

M-06-06

A

Sample Privacy Documents for Agency Implementation of Homeland Security Presidential
Directive (HSPD) 12

21
Q

M-05-24

A

Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors

22
Q

M-05-08

A

Designation of Senior Agency Officials for Privacy

23
Q

M-04-16

A

Software Acquisition

24
Q

M-04-15

A

Development of Homeland Security Presidential Directive (HSPD) - 7 Critical Infrastructure Protection Plans to Protect Federal Critical Infrastructures and Key Resources

25
Q

M-04-04

A

E-Authentication Guidance for Federal Agencies

  • Requires eRA for all electronic transactions
  • Defines criteria for access to Federal services online
26
Q

M-03-22

A

OMB Guidance for Implementing the Privacy Provisions of the E-Government Act of 2002

-Provides PIA guidance and requirements for all federal agencies

27
Q

M-03-18

A

Implementation Guidance for the E-Government Act of 2002

28
Q

M-02-09

A

Reporting Instructions for the Government Information Security Reform Act and Updated Guidance on Security Plans of Action and Milestones

29
Q

M-02-09

A

Guidance for Preparing and Submitting Security Plans of Action and Milestones

30
Q

M-01-05

A

Guidance on Inter-Agency Sharing of Personal Data - Protecting Personal Privacy

31
Q

M-00-13

A

Privacy Policies and Data Collection on Federal Web Sites

32
Q

M-99-18

A

Privacy Policies on Federal Web Sites

33
Q

M-10-28

A

Clarifying Cybersecurity Responsibilities and Activities of the Executive Office of the President and DHS

  • Set OMB as reporting agency and DHS and Gathering agency for cybersecurity data and events
  • Updated by FISMA 2014
34
Q

M-14-03

A

Enhancing the Security of Federal Information and Information Systems

-Established continuous monitoring under DHS control

35
Q

M-14-04

A

Fiscal Year 2013 Reporting Instructions for the Federal Information Security Management Act and Agency Privacy Management

  • Made 800-53 privacy controls mandatory
  • SAOP approval required for ATO