Skip Navigation

HHS OCIO Policies, Standards and Charters

Policies, Standards, and Charters - Categories

Link to Historical Policies, Standards, Charters



POLICIES

Description

Number

Date Issued

HTML Document

Word Document

Capital Planning and Investment Control [4 Policies]

HHS OCIO Policy for Information Technology (IT) Enterprise Performance Life Cycle (EPLC)

2008-0004.001

10/06/2008

HTML

[ DOC - 206KB]

HHS Policy for IT Capital Planning and Investment Control (CPIC)

See Procedures Section for CPIC Procedures Document and its related Appendices Document

2005-0005.001

12/30/2005

HTML

[ DOC - 153KB]

HHS IRM Policy for Conducting Information Technology Alternatives Analysis

2003-0002

06/13/2003

HTML

[ DOC - 121KB]

HHS-OCIO Policy for IT Earned Value Management  

See Procedures Section for EVM Procedures Document

2007-0001

 

06/11/2007

 

HTML

[ DOC - 272 KB]

 

HHS-OCIO Policy for IT Earned Value Management – superseded by Policy 2007-00012005-0004.00112/30/2005HTML [ DOC - 237 KB]

Enterprise Architecture [2 Policies]

HHS-OCIO IT Policy for Enterprise Architecture (EA)

2008-0003.001

08/07/2008

HTML

 

CIO Roles and Responsibilities – Circular No. IRM-101 03/1999HTML[ DOC - 495KB]

Information Collection (TBD)

IT Enterprise Solutions [6 Policies]

HHS-OCIO IT Policy for HHS Mail Change Management

2006-0002

03/02/2006

HTML 

[ DOC - 700KB]

HHS IRM Policy for Government Emergency Telecommunication System Cards Ordering, Usage and Termination

2002-0001

11/25/2002

HTML

[ DOC - 146KB]

HHS IRM Policy for Active Directory

2000-0010

01/08/2001

HTML

[ DOC - 75KB]

HHS IRM Policy for Public Key Infrastructure (PKI); Certification Authority (CA)

2000-0011

01/08/2001

HTML

[ DOC - 92KB]

HHS IRM Policy for Directory Services Using LDAP

2000-0012

01/08/2001

HTML

[ DOC - 84KB]

Use of Broadcast Messages, Spamming and Targeted Audiences

2000-0004

01/08/2001

HTML

[ DOC - 103KB]

OCIO Policy Development and Review Process [4 Policies]

HHS Policy for IT Policy Development

2006-0004

11/28/2006

HTML 

[ DOC - 224KB]

HHS OCIO Policy for E-Gov Forms

2006-0003

06/07/2006

HTML

[ DOC - 700KB]

HHS IRM Policy for Personal Use of Information Technology Resources

2006-0001

02/17/2006

HTML

[ DOC - 156KB]

HHS IRM Policy For Comments From And Responses To Operating Divisions On Newly Developed Policies and CIO Council and ITIRB Clearance Documents

2003-0001

02/14/2003

HTML

[ DOC - 92KB]

IT Security and Privacy [7 Policies]

HHS Policy for Responding to Breaches of Personally Identifiable Information (PII)2008-0001.00204/15/2008HTML[ DOC - 160KB]
HHS Policy for Department-wide Information Security2007-000209/24/2007HTML[ DOC - 168KB]

HHS IRM Information Security Program Policy

2004-0002.001

12/15/2004

HTML

[ DOC - 461KB]

Usage of Persistent Cookies

2000-0009

01/08/2001

HTML

[ DOC - 79KB]

HHS IRM Policy for Prevention, Detection, Removal and Reporting of Malicious Software

2000-0007

01/08/2001

HTML

[ DOC - 125KB]

HHS IRM Policy for Establishing an Incident Response Capability

2000-0006

01/08/2001

HTML

[ DOC - 111KB]

HHS IRM Policy for IT Security for Remote Access

2000-0005

01/08/2001

HTML

[ DOC - 96KB]

Mail Management (TBD) 

 Printing Management

 

 

 

 

 

Records Management [2 Policies]

HHS Policy for Records Management

2007-0004.001

01/30/2008

HTML

 

HHS Policy for Records Management for Emails2008-0002.00105/15/2008HTML 

Section 508 [TBD)

Web Policies [1 Policy]

HHS Policy for Internet Domain Names

WEB-2005-01

06/13/2005

HTML

 

Domain Names – superseded by Policy WEB-2005-01

2000-0008

01/08/2001

HTML

[ DOC - 79KB]

       

 

PROCEDURES AND APPENDICES

Description

Number

Date Issued

HTML Document

Word Document

Capital Planning and Investment Control

HHS-OCIO CPIC Procedures

2005-0005P

12/30/2005

 HTML

[DOC - 153KB]

 HHS-OCIO CPIC Procedure-Appendix

2005-0005P-A

12/30/2005

 

[DOC - 153KB]

Earned Value Management

HHS-OCIO EVM Procedures

2005-0004P

12/30/2005

 

[DOC - 1.2 MB]

  Information Quality Guidelines

 

STANDARDS [5 Total]

Description

Number

Date Issued

HTML Document

Word Document

IT Security and Privacy

HHS-OCIO Standard for Security Configurations Language in HHS Contracts

2008-0004.001S09/11/2008HTML 
HHS Standard for the Segregation of Development/Test Environments from Production2008-0003.002S08/07/2008HTML[DOC - 40KB]
HHS Standard for Managing Outbound Web Traffic2008-0002.003S06/06/2008HTML 
HHS Rules of Behavior (For Use of Technology Resources and Information)2008-0001.003S02/12/2008HTML 
HHS Encryption Standard for Mobile Devices and Portable Media2007-0001.001S08/21/2007HTML[ DOC - 38KB]
Enterprise Systems

CHARTERS [4 Total]

Description

Number

Date Issued

HTML Document

Word Document

Enterprise Architecture

CIO Council Charter

2007-0001.001C

  06/27/2007

 HTML[ DOC - 463KB]
Records Management
Personally Identifiable Information (PII) Breach Response Team (BRT) Charter2008.0001.002C04/15/2008HTML[DOC- 161 KB]
IT Security and Privacy
Personally Identifiable Information (PII) Breach Response Team (BRT) Charter2008.0001.002C04/15/2008HTML[DOC- 161 KB]
Enterprise Systems
HHS Trusted Internet Connection Access Provider (TICAP) Steering Committee Charter2008.0002.001C 06/23/2008HTML