Skip to main content
Category: Laws & Executive Orders

44 U.S.C. Chapter 35

Also known as: Coordination of Federal Information Policy, Title 44, Chapter 35
Simply put

44 U.S.C. Chapter 35 is the part of the United States Code, titled 'Coordination of Federal Information Policy,' that establishes how federal agencies manage, protect, and use government information. It brings together several related bodies of law, including federal information policy, information security requirements, and rules for handling statistical and confidential information. Readers should confirm the current text and section boundaries directly against official sources, because the chapter has been amended and reorganized over time.

Formal definition

44 U.S.C. Chapter 35, codified under Title 44 of the U.S. Code and maintained through the Office of the Law Revision Counsel (uscode.house.gov), is captioned 'Coordination of Federal Information Policy' and is organized into subchapters. Subchapter I, Federal Information Policy addresses federal information resources management and related agency responsibilities; based on the evidence packet, the exact current section range should be verified against the official codified text, as prior verification indicated the active range differs from historically cited ranges and certain sections were repealed. Subchapter II, Information Security establishes risk-based information-security management and oversight obligations for federal agencies. An additional subchapter addresses confidential information protection and statistical matters (with provisions associated with evidence-related amendments). Because subchapter headings, section numbering, and effective provisions in this chapter have changed through amendment and repeal, practitioners should confirm the current subchapter titles, section ranges, and text against the authoritative U.S. Code before relying on any specific citation; this entry does not resolve the precise current section boundaries and does not cover implementing regulations, agency-specific interpretations, or contractual obligations.

Why it matters

44 U.S.C. Chapter 35 supplies the statutory foundation for how the federal government manages and protects information as a resource. Its Subchapter II, Information Security is the codified home of the Federal Information Security Modernization Act framework that obligates agencies to run risk-based information-security programs and to provide oversight of those programs. For compliance officers, ISSMs, and authorizing officials, this chapter is where much of the authority behind agency security policy, control implementation, and reporting ultimately traces, even though the operative technical requirements are typically expressed through downstream guidance such as NIST publications and OMB direction rather than the statute itself.

Who it's relevant to

Compliance officers and ISSMs
Those responsible for agency security programs benefit from understanding that Subchapter II is the statutory basis for the risk-based information-security management and oversight obligations they operationalize. The statute itself does not specify implementation details; practitioners should map any given requirement back through the applicable NIST guidance and OMB direction, and confirm the current section text against the official U.S. Code before citing it.
Authorizing officials
Authorizing officials making risk-acceptance decisions operate within the oversight structure that Subchapter II establishes for federal agencies. Understanding the chapter helps distinguish statutory obligations from the agency-specific policies and control baselines used to satisfy them. Note that this entry does not resolve the precise current section boundaries or address implementing regulations and agency interpretations.
Auditors and oversight staff
Auditors assessing agency information-security and information-management practices should trace requirements to the correct subchapter and confirm the current codified text, because section numbering and subchapter contents in this chapter have shifted through amendment and repeal. Relying on historically cited section ranges without verifying against the authoritative U.S. Code can produce inaccurate citations.
Government contractors and program staff
Contractors supporting federal information systems may encounter obligations that ultimately derive from this chapter, but the statute does not itself impose contractual terms. Applicable requirements typically reach contractors through contract clauses, agency policy, and referenced standards, which should be confirmed against the governing contract and current official sources.

Inside 44 U.S.C. Chapter 35

Subchapter I, Paperwork Reduction Act (§§ 3501-3521)
Codified generally at 44 U.S.C. §§ 3501-3521, this subchapter contains the Paperwork Reduction Act provisions, which govern federal agency collection of information from the public, information resources management, and the oversight role of the Office of Management and Budget (OMB). Practitioners should verify the current codified section range against the official U.S. Code text, as codification can change across editions.
Subchapter II, Federal Information Security Modernization Act (FISMA) (§§ 3551-3559)
Codified generally at 44 U.S.C. §§ 3551-3559, this subchapter establishes the framework for risk-based information-security management across federal agencies and related oversight responsibilities. Its stated statutory purposes concern risk-based information-security management and oversight of agency information systems. Readers should confirm the exact scope and current text against the authoritative U.S. Code.
Subchapter III, Confidential Information Protection and Statistical Efficiency (CIPSEA)
This subchapter, associated with provisions added by the Foundations for Evidence-Based Policymaking Act of 2018, carries the official heading 'Confidential Information Protection and Statistical Efficiency.' It addresses the protection of confidential information collected for statistical purposes and related efficiency measures. Verify the current section range and text against the official U.S. Code, as this component is more recent than the other subchapters.
OMB oversight authority
Across the Paperwork Reduction Act provisions in Subchapter I, the Office of Management and Budget holds oversight responsibilities for federal information resources management and information collection review. The precise scope of this authority should be confirmed against the current statutory text and applicable OMB guidance.

Common questions

Answers to the questions practitioners most commonly ask about 44 U.S.C. Chapter 35.

Does Subchapter I of 44 U.S.C. Chapter 35 run through Section 3531?
No. Subchapter I (the Paperwork Reduction Act provisions) is currently codified at approximately §§ 3501-3521. It does not extend to § 3531. Sections in the 3531-3549 range formed the former information-security subchapters and were later repealed; they were not active provisions of Subchapter I. When citing a specific section, verify the current range and text against the official U.S. Code, because section boundaries have shifted over time.
Do the stated purposes of the information security subchapter include 'defending vital institutions that underpin the American way of life'?
No. The purposes stated in Subchapter II (FISMA, generally §§ 3551-3559) concern risk-based information security management, agency-wide security programs, and oversight of federal information and information systems. Language about defending vital institutions or the American way of life does not appear in the statutory purposes of this subchapter. Readers should confirm the exact purpose language against the current text of § 3551 and related sections rather than relying on paraphrase.
How do I determine which subchapter of Chapter 35 applies to my compliance obligation?
Identify the nature of the obligation. Paperwork and information collection burden requirements generally fall under Subchapter I (Paperwork Reduction Act). Federal information security management, agency security programs, and reporting obligations generally fall under Subchapter II (FISMA). Confidential information protection and statistical data efficiency matters fall under Subchapter III (Confidential Information Protection and Statistical Efficiency). Confirm the applicable subchapter and section against the current codified text, since scope and structure can change across revisions.
How does FISMA in Subchapter II relate to the security control frameworks my agency uses?
Subchapter II establishes the statutory requirement for agencies to implement risk-based information security programs, but the statute itself does not prescribe the detailed control catalogs. Implementation guidance and standards are developed by other bodies, such as NIST publications and OMB direction. In practice, agencies map their FISMA obligations to those frameworks, but the statute and the implementing guidance are distinct sources. Verify current implementing guidance separately from the statutory text.
Does complying with Chapter 35 requirements mean my system is authorized to operate?
No. Meeting statutory information security obligations under Subchapter II is not the same as holding an authorization. Authorization is a distinct, time-bound decision by an authorizing official that is subject to continuous monitoring, and assessment is separate from authorization. Compliance with the statute also does not by itself establish that a system is secure. Confirm authorization status and monitoring requirements through your agency's applicable process.
Where should I confirm the current section numbers and headings when citing Chapter 35?
Cite from the current official U.S. Code rather than from summaries, because section ranges, headings, and subchapter structure have changed over time, including the addition of provisions in later years. Confirm the exact subchapter heading, section number, and text against the authoritative published version applicable on your date of use, and note that agency-specific interpretations and implementing guidance may add requirements beyond the statutory text.

Common misconceptions

44 U.S.C. Chapter 35 is solely an information-security statute (i.e., it is 'the FISMA chapter').
FISMA occupies only Subchapter II (generally §§ 3551-3559). The chapter also contains the Paperwork Reduction Act in Subchapter I (generally §§ 3501-3521) and the Confidential Information Protection and Statistical Efficiency provisions in Subchapter III. Treating the entire chapter as an information-security authority overlooks its broader information-management and statistical-confidentiality scope.
Former sections in the §§ 3531-3549 range were once active provisions of Subchapter I.
Those sections formed the former information-security subchapters and were never active provisions of Subchapter I. Citing them as part of Subchapter I's current range blurs the boundary between the Paperwork Reduction Act provisions and the later FISMA framework in Subchapter II. Confirm the present codified ranges against the official U.S. Code.
Subchapter III concerns 'federal evidence-building' as its statutory subject.
The official heading of Subchapter III is 'Confidential Information Protection and Statistical Efficiency.' While it is associated with the Foundations for Evidence-Based Policymaking Act of 2018, its codified subject matter is the protection of confidential statistical information and statistical efficiency, not a general evidence-building mandate.

Best practices

Cite the specific subchapter and current codified section range when referencing Chapter 35, distinguishing Subchapter I (Paperwork Reduction Act, generally §§ 3501-3521) from Subchapter II (FISMA, generally §§ 3551-3559) and Subchapter III (Confidential Information Protection and Statistical Efficiency).
Verify current section ranges and headings against the official U.S. Code (uscode.house.gov) rather than relying on memory or secondary summaries, because codification can shift across editions and prior sections have been repealed or renumbered.
Do not treat the whole chapter as an information-security authority; scope your compliance analysis to the relevant subchapter for the obligation at hand.
When addressing FISMA obligations, work from Subchapter II's risk-based information-security management and oversight provisions and confirm the exact statutory text, as agency implementation and OMB guidance may add detail beyond the statute.
For statistical-confidentiality questions, reference Subchapter III under its correct heading ('Confidential Information Protection and Statistical Efficiency') and confirm the applicable current provisions.
Avoid citing former sections in the §§ 3531-3549 range as active Subchapter I provisions; check repeal and renumbering history in the authoritative source before relying on any such reference.