- CSRC Home
- Projects / Research
- news & events
In January 1988, the Congress enacted the Computer Security Act of 1987 (Public Law 100-235). A provision of that law called for the establishment of the Computer System Security and Privacy Advisory Board (CSSPAB) within the Department of Commerce. In accordance with the Federal Advisory Committee Act, as amended, 5 U.S.C., App., the Board was chartered in May 1988. In December 2002, Public Law 107-347, The E-Government Act of 2002, Title III, the Federal Information Security Management Act of 2002, amended Section 21 of the National Institute of Standards and Technology Act (15 U.S.C. 278g-4), the charter statutory authority of the Board, and renamed it the Information Security and Privacy Advisory Board (ISPAB). Section 21 of the National Institute of Standards and Technology Act was amended again in December 2014 by the Federal Information Security Modernization Act of 2014, Public Law 113-283, to specify that the ISPAB should advise the Secretary of Homeland Security in addition to NIST and the Director of the Office of Management and Budget
The Board's authority does not extend to private sector systems or federal systems which process classified information.
The membership of the Board consists of twelve members and a Chairperson. The Secretary of Commerce appoints the Chairperson, and the Director of NIST will appoint all Board members. The Board meets quarterly throughout the year and all meetings are open to the public. The Board invites public comments on its activities and the objectives the Board should undertake. Comments can be directed to Matthew Scholl.
The following are congressional oversight committees for ISPAB:
For further information on the activities of the Board, Donna Kimball.