Coordination positions IRS Pub 1075 within the broader US federal + state + and industry security landscape. (1) NIST Standards: NIST SP 800-53 Rev 5 (primary control set incorporated by reference Section 9.3) + NIST SP 800-53A (assessment methodology) + NIST SP 800-53B (control baselines) + NIST SP 800-37 Rev 2 Risk Management Framework (RMF) + NIST SP 800-30 Risk Assessment + NIST SP 800-18 Security Plan + NIST SP 800-60 Mapping Information Types to Security Categories + NIST SP 800-88 Media Sanitization + NIST SP 800-122 PII + NIST SP 800-171 CUI + NIST SP 800-145 Cloud Computing Definition + FIPS 199 Categorisation + FIPS 200 Minimum Security Requirements + FIPS 140-3 Cryptographic Modules + FIPS 201 PIV + NIST Cybersecurity Framework (CSF) v2.0. (2) Federal Information Security: FISMA Federal Information Security Modernization Act 2014 (and 2002 predecessor) + OMB Circular A-130 Managing Information as a Strategic Resource + OMB M-22-09 Federal Zero Trust + OMB M-21-31 Improving Detection + OMB M-22-18 Software Bill of Materials (SBOM) + CISA Continuous Monitoring + CISA Binding Operational Directives (BOD) + Federal Information Processing Standards Publications (FIPS PUBS). (3) FedRAMP: FedRAMP Low/Moderate/High Baseline + FedRAMP Continuous Monitoring + FedRAMP+ Plus + IRS-specific tailoring per Office of Safeguards Cloud Computing Notification + JAB Joint Authorization Board + 3PAO Third Party Assessment Organizations. (4) Federal Information Sharing Statutes: IRC 26 USC 6103 (FTI authorisation framework) + 6103(p)(4) (safeguard requirements) + 6103(j) (joint board federal/state) + 6103(l) (state and local tax administration) + 6103(m) (federal employee compensation) + 6103(n) (federal employee tax administration) + Privacy Act of 1974 (5 USC 552a) + Tax Information Authorization (TIA) Form 8821 + Power of Attorney (POA) Form 2848 + Computer Matching and Privacy Protection Act (CMPPA). (5) Sister Programs: FBI Criminal Justice Information Services (CJIS) Security Policy + Social Security Administration (SSA) Computer Data Security (CDS) Procedures Manual + CMS ARS (Acceptable Risk Safeguards) + DoD Cybersecurity Maturity Model Certification (CMMC) + State Revenue Agency safeguard procedures. (6) Industry Frameworks: SOC 2 Type II + ISO 27001 + ISO 27017 (cloud) + ISO 27018 (cloud privacy) + CIS Controls v8 + CIS Benchmarks + ISA/IEC 62443 (ICS) + NIST CSF v2.0 + ISACA CMMI + ITIL 4 + COBIT 2019 + PCI DSS (where relevant for payment processing) + HIPAA (where overlapping with health agencies). (7) Federal Sectoral Carve-Outs: where FTI is also subject to other federal laws (e.g. SSA-shared data subject to Social Security Act + CMS shared data subject to HIPAA + state-shared subject to state laws) + agencies must implement stricter of applicable requirements. (8) State and Local Agency Coordination: National Association of State Auditors Comptrollers and Treasurers (NASACT) + Federation of Tax Administrators (FTA) Information Security + state revenue agency Safeguards Coordinators network + Office of Safeguards quarterly newsletter + annual conference. Coordinates with all aforementioned federal + state + industry frameworks + sister programs + sectoral statutes. IRS Pub 1075 Coordination applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.