Skip to Main Content
October 3, 2022

Highlights of EOTSS IS.000 Enterprise Information Security Policy and IS.001 Organization of Information Security Standard

Cybersecurity Awareness Month / Enterprise Information Security

The Executive Office of Technology Services and Security (EOTSS) publishes Enterprise Information Security Policies and Standards which must be included in a Department’s Internal Control Plan, implemented, tested, and included in staff training. These standards apply to all Executive Department offices and agencies and are the default standard for non-Executive Departments who have not adopted comparable cyber and data security standards as part of their Internal Control Plan.