Skip to main content
Content Starts Here GSA Federal Advisory Committee Act (FACA) Database Skip to main content //01/02/24 SFGEO-3418: Commenting out font-awesome due to issues with USWDS. Changed By Linh Nguyen.

Committee Detail

Note: An Annual Comprehensive Review, as required by §7 of the Federal Advisory Committee Act, is conducted each year on committee data entered for the previous fiscal year (referred to as the reporting year). The data for the reporting year is not considered verified until this review is complete and the data is moved to history for an agency/department. See the Data From Previous Years section at the bottom of this page for the committee’s historical, verified data.

Details on agency responses to committee recommendations can be found under the Performance Measures section for each committee in the fields “Agency Feedback” and “Agency Feedback Comment.”


DOC - 324 - Information Security and Privacy Advisory Board - Statutory (Congress Created)
Hide Section - GENERAL INFORMATION

GENERAL INFORMATION

Committee NameInformation Security and Privacy Advisory BoardAgency NameDepartment of Commerce
Fiscal Year2025Committee Number324
Original Establishment Date1/8/1988Committee StatusChartered
Actual Termination Date Committee URLhttp://csrc.nist.gov/groups/SMA/ispab/index.html
Actual Merged Date Presidential Appointments*No
New Committee This FYNoMax Number of Members*13
Terminated This FYNoDesignated Fed Officer Position Title*DFO
Merged This FY Designated Federal Officer PrefixMr.
Current Charter Date2/23/2024Designated Federal Officer First Name*Jeff
Date Of Renewal Charter2/23/2026Designated Federal Officer Middle Name
Projected Termination Date Designated Federal Officer Last Name*Brewer
Exempt From Renewal*NoDesignated Federal Officer Suffix
Specific Termination AuthorityDesignated Federal Officer Phone*(301) 975-2489
Establishment Authority*Statutory (Congress Created)Designated Federal Officer Fax*(301) 975-8670
Specific Establishment Authority*15 U.S.C. 278g-4Designated Federal Officer Email*jeffrey.brewer@nist.gov
Effective Date Of Authority*1/8/1988
Exempt From EO 13875 Discretionary CmteNot Applicable
Committee Type*Continuing
Presidential*No
Committee Function*Scientific Technical Program Advisory Board
Hide Section - RECOMMENDATION/JUSTIFICATIONS

RECOMMENDATION/JUSTIFICATIONS

Agency Recommendation*Continue
Legislation to Terminate RequiredNot Applicable
Legislation StatusNot Applicable
How does cmte accomplish its purpose?*The Information Security and Privacy Advisory Board's (Board or Advisory Board) advises the Director of the National Institute of Standards and Technology (NIST), the Secretary of the Department of Homeland Security (DHS), and the Director of the Office of Management and Budget (OMB) on information security and privacy related issues. The Board accomplishes this through informational briefings and presentations by NIST staff and external presenters at regular open meetings. Presenters often include program stakeholders and government/industry partners as well as experts in the information technology field, discussing trends, challenges, and potential solutions. These meetings, held 3 times a year, provide the opportunity for the Board to interact with subject matter experts and key stakeholders, combined with the Member's diverse perspective, offers a valued forum for discussing and proposing solutions to the U.S. Governments- and industry-related issues.
How is membership balanced?*The Board is comprised of members from academia, industry, expert advisors representing small businesses, and pertinent U.S. Government departments and agencies. Presently, the membership consists of nine members including the Chairperson, and is currently in the process of vetting additional members. Current membership can be viewed at: https://csrc.nist.gov/Projects/ispab/members.
How frequent & relevant are cmte mtgs?*The Board holds open, public meetings 3-4 times a year. At the first meeting of every fiscal year, the Board reviews and updates its work plan items for fiscal year. Topics include NIST publications and guidance, research and development, NIST's Cybersecurity and Privacy Programs and Frameworks, Cybersecurity challenges and threats facing the U.S. Government and small businesses, NIST's National Vulnerability Database (NVD) Program, Artificial Intelligence, and Software Metrics and Measurement.
Why advice can't be obtained elsewhere?*In drafting the Computer Security Act of 1987, which created this Advisory Board, we understand that Congress saw a need for an independent, non-federally dominated group of computer security experts to offer its advice to senior government officials on emerging computer security areas. The Board members, with their individual and collective skills, responsibilities and experiences fulfill this requirement. No other similar group of experts meet regularly to review information security issues involved in unclassified Federal Government computer systems and networks. In today's emerging technology, privacy is ever moving into prominent importance, not just for security, but it instills confidence from industry and consumers. Also, Title III of the E-Government Act of 2002 reaffirmed the need for this Board by giving it additional responsibilities.
Why close or partially close meetings?N/A
Recommendation RemarksOver the course of this fiscal year, the Board did not present letters of recommendation. The Board's emphasis was on information collection, with scheduled updates and follow-up briefings that may lead to formal decision-making and consensus recommendations, which are considered more appropriate at later stages following initial discussions and analyses.
Hide Section - PERFORMANCE MEASURES

PERFORMANCE MEASURES

Outcome Improvement To Health Or Safety*NoAction Reorganize Priorities*Yes
Outcome Trust In GovernmentYesAction Reallocate ResourcesYes
Outcome Major Policy ChangesNoAction Issued New RegulationsNo
Outcome Advance In Scientific ResearchYesAction Proposed LegislationNo
Outcome Effective Grant MakingNoAction Approved Grants Or Other PaymentsNo
Outcome Improved Service DeliveryYesAction OtherYes
Outcome Increased Customer SatisfactionYesAction CommentNIST continues to refine their strategy based on objective feedback related to presentations and submissions of the Board.
Outcome Implement Laws/Reg RequirementsNoGrants Review*No
Outcome OtherNoNumber Of Grants Reviewed0
Outcome CommentNANumber Of Grants Recommended0
Cost Savings*Unable to DetermineDollar Value Of Grants Recommended$0.00
Cost Savings CommentMany of the recommendations address information security and privacy policy government-wide. Cost savings would vary based on agency-specific implementation.Grants Review CommentNA
Number Of Recommendations*56Access Contact Designated Fed. Officer*Yes
Number Of Recommendations CommentFor fiscal year 2025, the Board did not formally make any recommendations.Access Agency WebsiteYes
% of Recs Fully Implemented*30.00%Access Committee WebsiteYes
% of Recs Fully Implemented CommentAll recommendations do not address the agency. They may be directed to OMB for government-wide impact, which is difficult to report or monitor percentage of implementation. Those time lines are driven by the OMB directives. Board recommendations specific to NIST have been or will be addressed and implemented.Access GSA FACA WebsiteYes
% of Recs Partially Implemented*0.00%Access PublicationsYes
% of Recs Partially Implemented CommentNAAccess OtherYes
Agency Feedback*YesAccess CommentInformation is published in the FEDERAL REGISTER announcing the meetings and agendas and announcing an annual request for nomination consideration to the membership of the Board.
Agency Feedback Comment*Feedback to the Advisory Board are filtered in several ways: through email to the DFO and members; formal statements during the public opening session in meetings; or the dedicated ISPAB website.Narrative Description*The Board advises NIST, the Secretary of Commerce and the Director of OMB on information security and privacy issues pertaining to Federal government unclassified information systems. This includes through review of proposed standards and guidelines developed under Section 20 of the National Institute of Standards and Technology Act (15 U.S.C. 278g-3) as amended by Title III of the E-Government Act of 2002.
Hide Section - COSTS

COSTS

1. Payments to Non-Federal Members*$0.001. Est Paymnts to Non-Fed Membrs Nxt FY*$0.00
2. Payments to Federal Members*$9,300.002. Est. Payments to Fed Members Next FY*$16,000.00
3. Payments to Federal Staff*$41,000.003. Estimated Payments to Federal Staff*$50,000.00
4. Payments to Consultants*$0.004. Est. Payments to Consultants Next FY*$0.00
5. Travel Reimb. For Non-Federal Membrs*$0.005. Est Travel Reimb Non-Fed Membr nxtFY*$18,000.00
6. Travel Reimb. For Federal Members*$0.006. Est Travel Reimb For Fed Members*$1,000.00
7. Travel Reimb. For Federal Staff*$0.007. Est. Travel Reimb to Fed Staf Nxt FY*$1,000.00
8. Travel Reimb. For Consultants*$0.008. Est Travel Reimb to Consltnts Nxt FY*$0.00
10. Other Costs$0.0010. Est. Other Costs Next FY*$0.00
11. Total Costs$61,900.0011. Est. Total Next FY*$86,000.00
Date Cost Last Modified8/28/2025 5:43 AMEst. Fed Staff Support Next FY* 
Federal Staff Support (FTE)*0.30Est Cost RemarksCost estimates for Fiscal Year 2026 are expected to be lower than previous years as planned meetings will be held on NIST campus; reducing meeting space, AV support costs, and travel for federal staff.
Cost RemarksCosts were reduced for fiscal year 2025 as we held only two meetings virtually. No travel or meeting space cost incurred. Contract ended for transcription support after first meeting (November 2024).  
Hide Section - Interest Areas

Interest Areas

Category
Area
Business
Industry
Manufacturing
Small Business
Computer Technology
Technology
Applications
Computers
Information Technology
Internet
Semiconductors
Systems Engineering
Data
Data Integrity
Data Quality
Privacy
Government
Federal Government
Internal Federal Government
Research
Research and Development
Science and Technology
Innovation
Science and Technology
Hide Section - MEMBERS,MEETINGS AND ADVISORY REPORTS

MEMBERS,MEETINGS AND ADVISORY REPORTS

To View all the members, meetings and advisory reports for this committee please click here
Hide Section - CHARTERS AND RELATED DOCS

CHARTERS AND RELATED DOCS

No Documents Found
Hide Section - DATA FROM PREVIOUS YEARS

DATA FROM PREVIOUS YEARS

Committee

Data from Previous Years

 
ActionCommittee System IDCommittee NameFiscal Year
 COM-046128Information Security and Privacy Advisory Board2024
 COM-044075Information Security and Privacy Advisory Board2023
 COM-042523Information Security and Privacy Advisory Board2022
 COM-040149Information Security and Privacy Advisory Board2021
 COM-037928Information Security and Privacy Advisory Board2020
 COM-035849Information Security and Privacy Advisory Board2019
 COM-034277Information Security and Privacy Advisory Board2018
 COM-001306Information Security and Privacy Advisory Board2017
 COM-002928Information Security and Privacy Advisory Board2016
 COM-003498Information Security and Privacy Advisory Board2015
 COM-005061Information Security and Privacy Advisory Board2014
 COM-005566Information Security and Privacy Advisory Board2013
 COM-007236Information Security and Privacy Advisory Board2012
 COM-007662Information Security and Privacy Advisory Board2011
 COM-009393Information Security and Privacy Advisory Board2010
 COM-009749Information Security and Privacy Advisory Board2009
 COM-011327Information Security and Privacy Advisory Board2008
 COM-011591Information Security and Privacy Advisory Board2007
 COM-013142Information Security and Privacy Advisory Board2006
 COM-013487Information Security and Privacy Advisory Board2005
 COM-015066Information Security and Privacy Advisory Board2004
 COM-015372Information Security and Privacy Advisory Board2003
 COM-017027Computer System Security and Privacy Advisory Board2002
 COM-017315Computer System Security and Privacy Advisory Board2001
 COM-019016Computer System Security and Privacy Advisory Board2000
 COM-019230Computer System Security and Privacy Advisory Board1999
 COM-020934Computer System Security and Privacy Advisory Board1998
 COM-021157Computer System Security and Privacy Advisory Board1997