IT Policy and Security

Explore NIH IT policies, cybersecurity guidance, and technology standards that support secure, compliant, and effective use of NIH information systems and services.

NIH Enterprise Architecture Policy
Portfolio management framework and requirements
NIH Enterprise Architecture Policy
NIH Smart Card Authentication
Portfolio management framework and requirements
NIH Smart Card Authentication
NIH Network Device Standard
Requirements for PIV card access and authentication
NIH Network Device Standard

NIH security training

Access NIH's official Information Security Training portal to complete required cybersecurity and privacy awareness courses. Find training resources for NIH staff, contractors, and public users to help protect sensitive information and support a secure research environment.

Explore tools and platforms
HHS Policy for Information Technology Portfolio Management
Portfolio management framework and requirements
HHS Policy for Information Technology Portfolio Management
HHS Enterprise Performance Life Cycle (EPLC) Policy
IT project lifecycle management standards
HHS Enterprise Performance Life Cycle (EPLC) Policy
HHS Policy for Rules of Behavior for Use of Information and IT Resources
Acceptable use and behavior standards
HHS Policy for Rules of Behavior for Use of Information and IT Resources
Accessibility Standards
Section 508: Digital accessibility at NIH
Accessibility Standards
HHS Section 508 and Accessibility of Technology Policy
Resources and guidance for Section 508 compliance
HHS Section 508 and Accessibility of Technology Policy

Contact Us

General IT Policy

Email: nihciocommunications@mail.nih.gov 
Phone: 301-496-1168

Information Security Policy


Email: nihisaopolicy@mail.nih.gov