itlaw

Overview

The Office of Management and Budget (OMB)[1] is a U.S. Executive Branch agency that assists the President in overseeing the preparation of the federal budget and supervises its administration in Executive Branch agencies. The OMB evaluates the effectiveness of agency programs, policies, and procedures, assesses competing funding demands among agencies, and sets funding priorities. OMB ensures that agency reports, rules, testimony, and proposed legislation are consistent with the President's Budget and with Administration policies.

In addition, OMB oversees and coordinates the Administration's procurement, financial management, information, and regulatory policies. In each of these areas, OMB's role is to help improve administrative management, to develop better performance measures and coordinating mechanisms, and to reduce any unnecessary burdens on the public.

Information security

The Federal Information Security Management Act of 2002 (FISMA) states that the Director of the OMB shall oversee agency information security policies and practices, including:

FISMA also requires OMB to report to Congress no later than March 1 of each year on agency compliance with the requirements of the Act.

Privacy

OMB is tasked with providing guidance to agencies on how to implement the provisions of the Privacy Act of 1974 and the E-Government Act of 2002 and has done so, beginning with guidance on the Privacy Act, issued in 1975. The guidance provides explanations for the various provisions of the law as well as detailed instructions on how to comply. OMB’s guidance on implementing the privacy provisions of the E-Government Act of 2002 identifies circumstances under which agencies must conduct PIAs and explains how to conduct them.

OMB Privacy Memoranda

A number of OMB memoranda have also addressed the roles and responsibilities of senior privacy officials.

OMB Privacy Guidance

Since its 1975 OMB Privacy Act Implementation, Guidelines and Responsibilities, OMB has periodically issued guidance related to privacy addressing specific issues as they have arisen.[5]

Beginning in 2005, OMB has also issued guidance significantly enhancing longstanding requirements for agencies to report on their compliance with privacy laws.[6]

OMBGuidance

Senior Office Privacy Responsibilities

These laws and guidance set a variety of requirements for senior officials to carry out specific privacy responsibilities. These responsibilities can be grouped into the following six key functions:

In addition to performing key privacy functions, requirements in laws include responsibilities to ensure adequate security safeguards to protect against unauthorized access, use, disclosure, and destruction of sensitive personal information. Generally, this is provided through agency information security programs established under FISMA, and overseen by agency CIOs and chief information security officers (CISO). Moreover, OMB has issued guidance instructing agency heads to establish appropriate administrative, technical, and physical safeguards to ensure the security and confidentiality of records.

References

  1. The OMB was known as the "Bureau of the Budget" prior to July 1, 1970.
  2. Office of Management and Budget, OMB Instructions on Complying with President’s Memorandum of May 14, 1998, “Privacy and Personal Information in Federal Records”, OMB Memorandum M-99-05 (Jan. 7, 1999).
  3. Office of Management and Budget, OMB Guidance for Implementing the Privacy Provisions of the E-Government Act of 2002, OMB Memorandum M-03-22 (Sept. 26, 2003).
  4. Office of Management and Budget, Designation of Senior Agency Officials for Privacy, OMB Memorandum M-05-08 (Feb. 11, 2005).
  5. Nearly all of this guidance can be found on the OMB website, www.whitehouse.gov/omb, by searching in the “Agency Information” and “Information and Regulatory Affairs” sections of the website.
  6. Office of Management and Budget, FY 2005 Reporting Instructions for the Federal Information Security Management Act and Agency Privacy Management, OMB Memorandum M-05-15 (June 13, 2005).
  7. FISMA, Title III, E-Government Act of 2002, Pub. L. No. 107-347 (Dec. 17, 2002).
  8. Office of Management and Budget, FY 2006 Reporting Instructions for the Federal Information Security Management Act and Agency Privacy Management, OMB Memorandum M-06-20 (July 17, 2006).
  9. Office of Management and Budget, FY 2007 Reporting Instructions for the Federal Information Security Management Act and Agency Privacy Management, OMB Memorandum M-07-19 (July 25, 2007).

See also