Skip to main content
U.S. flag

An official website of the United States government

Here’s how you know

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

HTTPS

Secure .gov websites use HTTPS
A lock (LockA locked padlock) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

    • Environmental Topics
    • Air
    • Bed Bugs
    • Cancer
    • Chemicals, Toxics, and Pesticide
    • Emergency Response
    • Environmental Information by Location
    • Health
    • Land, Waste, and Cleanup
    • Lead
    • Mold
    • Radon
    • Research
    • Science Topics
    • Water Topics
    • A-Z Topic Index
    • Laws & Regulations
    • By Business Sector
    • By Topic
    • Compliance
    • Enforcement
    • Laws and Executive Orders
    • Regulations
    • Report a Violation
    • Environmental Violations
    • Fraud, Waste or Abuse
    • About EPA
    • Our Mission and What We Do
    • Headquarters Offices
    • Regional Offices
    • Labs and Research Centers
    • Planning, Budget, and Results
    • Organization Chart
    • EPA History

Breadcrumb

  1. Home
  2. IM/IT Directives

Office of Mission Support Policies: Security & Privacy


CIO Number Title Related Documents
CIO 2150.6 Information Security Policy

Procedures

  • Information Security – Access Control Procedures
  • Information Security – Awareness and Training Procedures
  • Information Security – Audit and Accountability Procedures
  • Information Security – Assessment, Authorization and Monitoring (CA) Procedure
  • Information Security – Configuration Management (CM) Procedure
  • Information Security – Contingency Planning (CP) Procedure
  • Information Security – Identification and Authentication (IA) Procedure
  • Information Security – Incident Response (IR) Procedures
  • Information Security – Maintenance (MA) Procedure
  • Information Security – Media Protection (MP) Procedure
  • Information Security – Physical and Environmental Protection (PE) Procedure
  • Information Security – Planning (PL) Procedure
  • Information Security – Personnel Security (PS) Procedure
  • Information Security – Risk Assessment (RA) Procedure
  • Information Security – System and Services Acquisition (SA) Procedure
  • Information Security – System and Communications Protection (SC) Procedure
  • Information Security – System and Information Integrity (SI) Procedure
  • Information Security – Roles and Responsibilities Procedures
  • Spillage of Classified Information onto Unclassified Systems Procedure
  • Information Security – Privacy Procedures
  • Information Security – Program Management (PM) Procedure
  • Information Security - Data Loss Prevention Procedure
  • Information Security – Supply Chain Risk Management (SR) Procedure
  • Information Security – Detecting Counterfeit Information and Communications Technology Products Procedure

Standards

  • Information Security – EPA National Rules of Behavior

Guidance

  • Information Security – Guidance for Manually Completing the Information Security Awareness Training
CIO 2151.1 Privacy Policy

Procedures

  • Responding to Personally Identifiable Information (PII) Breach Procedure
  • Systems of Records Notices (SORN) Privacy Act Procedure
  • Procedures for Preparing Privacy Act Statements
  • Personally Identifiable Information (PII) Incident Handling & Response Procedure
  • Conducting Privacy On-Site Reviews Procedure
  • Processing Privacy Act Requests Procedure
  • Computer Matching Agreement Procedure
  • Protecting Sensitive Personally Identifiable Information (SPII)
CIO 2154.4 Mobile Computing Policy

Procedures

  • International Travel Procedures for Mobile Devices
    • Mobile Computing Management Procedure
CIO 2158.2 Controlled Unclassified Information (CUI) Policy

Procedures

  • Controlled Unclassified Information (CUI) Procedure

IM/IT Directives

  • Information Access
  • Information Management
  • IT/IM Program Management
  • Records
  • Security & Privacy
  • Web
Contact Us About Information Management and Information Technology Directives
Contact Us to ask a question, provide feedback, or report a problem.
Last updated on February 3, 2025
  • Assistance
  • Spanish
  • Arabic
  • Chinese (simplified)
  • Chinese (traditional)
  • French
  • Haitian Creole
  • Korean
  • Portuguese
  • Russian
  • Tagalog
  • Vietnamese
United States Environmental Protection Agency

Discover.

  • Accessibility Statement
  • Budget & Performance
  • Contracting
  • EPA www Web Snapshot
  • Grants
  • No FEAR Act Data
  • Plain Writing
  • Privacy
  • Privacy and Security Notice

Connect.

  • Data
  • Inspector General
  • Jobs
  • Newsroom
  • Regulations.gov
  • Subscribe
  • USA.gov
  • White House

Ask.

  • Contact EPA
  • EPA Disclaimers
  • Hotlines
  • FOIA Requests
  • Frequent Questions
  • Site Feedback

Follow.