{"abstract":"The Office of Management and Budget (OMB) is revising Appendix III, ``Security of Federal Information Systems,'' of Circular No. A- 130, ``Management of Federal Automated Information Resources.'' This is the third stage of planned revisions to Circular A-130. Enactment of the Information Technology Management Reform Act of 1996 (Division E of the National Defense Authorization Act for Fiscal Year 1996) will require OMB to issue additional guidance on capital planning, investment control, and the management of information technology. A plan for those revisions will be announced in the Spring. Transmittal 1 to Circular A-130, effective June 25, 1993, and published on July 2, 1993 (58 FR 36068) addressed the Information Management Policy section of the Circular (Section 8a), as well as Appendix I, ``Federal Agency Responsibilities for Maintaining Records About Individuals.'' That issuance dealt primarily with how the Federal government manages its information holdings, particularly information exchange with the public. Transmittal 2 to Circular A-130, effective July 15, 1994, and published on July 25, 1994 (59 FR 37906) addressed agency management practices for information systems and information technology (Section 8b). That issuance was intended to (1) promote agency investments in information technology that improve service delivery to the public, reduce burden on the public, and lower the cost of Federal programs administration, and (2) encourage agencies to use information technology as a strategic resource to improve Federal work processes and organization. This Transmittal 3 is intended to guide agencies in securing government information resources as they increasingly rely on an open and interconnected National Information Infrastructure. It stresses management controls, such as individual responsibility, awareness and training, and accountability, and explains how they can be supported by technical controls. Among other things, it requires agencies to assure that risk-based rules of behavior are established, that employees are trained in them, and that the rules are enforced. The revision also integrates security into program and mission goals, reduces the centralized reporting of security plans, emphasizes the management of risk rather than its measurement, and revises government-wide security responsibilities to be consistent with the Computer Security Act and the Paperwork Reduction Act of 1995. This transmittal also makes minor technical revisions to Section 9 (``Assignment of Responsibilities'') and Section 10 (``Oversight'') to reflect the Paperwork Reduction Act of 1995 (Pub. L. 104-13). One substantive change has been made to Appendix I in Section 3.a. changing the annual requirement to review recordkeeping practices, training, violations, and notices to a biennial review, in accordance with other regular agency reviews not required by statute. Several minor changes have been made, none of which are intended to be substantive. In Section 2.c., a portion of the definition of ``nonfederal agency'' which has been inadvertently omitted has been added to reflect the current practice in state-federal matching programs. In Section 3.a., extraneous and confusing language referring to source or matching agencies was removed because the provision applies to any agency that participates in a matching program. The example's in 4.c.(1) were updated for clarity. Other editorial and organizational changes were made throughout the appendix. Appendix IV has been changed to include material from OMB Memorandum M-95-22, ``Implementing the Information Dissemination Provisions of the Paperwork Reduction Act of 1995'' (September 29, 1995), and to delete some outdated or otherwise already implemented guidance from the discussion of Sections 9 and 10.","action":"Revision of OMB Circular No. A-130, Transmittal No. 3, Appendix III, ``Security of Federal Automated Information Resources.''","agencies":[{"raw_name":"OFFICE OF MANAGEMENT AND BUDGET","name":"Management and Budget Office","id":280,"url":"https://www.federalregister.gov/agencies/management-and-budget-office","json_url":"https://www.federalregister.gov/api/v1/agencies/280","parent_id":null,"slug":"management-and-budget-office"}],"body_html_url":"https://www.federalregister.gov/documents/full_text/html/1996/02/20/96-3645.html","cfr_references":[],"citation":"61 FR 6428","comment_url":null,"comments_close_on":null,"correction_of":null,"corrections":[],"dates":"OMB will review this Circular three years from the date of issuance to ascertain its effectiveness.","disposition_notes":null,"docket_ids":[],"dockets":[],"document_number":"96-3645","effective_on":null,"end_page":6453,"executive_order_notes":null,"executive_order_number":null,"full_text_xml_url":null,"html_url":"https://www.federalregister.gov/documents/1996/02/20/96-3645/management-of-federal-information-resources","images":{},"images_metadata":{},"json_url":"https://www.federalregister.gov/api/v1/documents/96-3645?publication_date=1996-02-20","mods_url":"https://www.govinfo.gov/metadata/granule/FR-1996-02-20/96-3645/mods.xml","not_received_for_publication":null,"page_length":26,"page_views":{"count":249,"last_updated":"2026-07-25 20:15:03 -0400"},"pdf_url":"https://www.govinfo.gov/content/pkg/FR-1996-02-20/pdf/96-3645.pdf","presidential_document_number":null,"proclamation_number":null,"public_inspection_pdf_url":null,"publication_date":"1996-02-20","raw_text_url":"https://www.federalregister.gov/documents/full_text/text/1996/02/20/96-3645.txt","regulation_id_number_info":{},"regulation_id_numbers":[],"regulations_dot_gov_info":{"checked_regulationsdotgov_at":"2011-09-21T00:18:13Z"},"regulations_dot_gov_url":null,"significant":null,"signing_date":null,"start_page":6428,"subtype":null,"title":"Management of Federal Information Resources","toc_doc":null,"toc_subject":null,"topics":[],"type":"Notice","volume":61}