{"data":{"id":"us/32-cfr-2004.11","jurisdiction":"us","citation":"32 CFR 2004.11","heading":"CSA and agency implementing regulations, internal rules, or guidelines.","body":"(a) Each CSA implements NISP practices in part through policies and guidelines that are consistent with this regulation, so that agencies for which it serves as the CSA are aware of appropriate security standards, engage in consistent practices with entities, and so that practices effectively protect classified information those entities receive (including foreign government information that the U.S. Government must protect in the interest of national security).\n(b) Each CSA must also routinely review and update its NISP policies and guidelines and promptly issue revisions when needed (including when a change in national policy necessitates a change in agency NISP policies and guidelines).\n(c) Non-CSA agencies may choose to augment CSA NISP policies or guidelines as long as the agency policies or guidelines are consistent with the CSA's policies or guidelines and this regulation.","path":["Title 32—National Defense","Subtitle B—Other Regulations Relating to National Defense","CHAPTER XX—INFORMATION SECURITY OVERSIGHT OFFICE, NATIONAL ARCHIVES AND RECORDS ADMINISTRATION","PART 2004—NATIONAL INDUSTRIAL SECURITY PROGRAM (NISP)","Subpart A—Implementation and Oversight"],"source_url":"https://www.ecfr.gov/api/versioner/v1/full/2026-08-25/title-32.xml","current_through":"2026-08-25","vintage":"","retrieved_at":"2026-08-27T02:25:30Z","sha256":"d819f415008f890b617acb47a02e38b4829599dc3f654b8abc6c6477b91f39f1","source_id":"us-cfr","stale":true,"prev":"us/32-cfr-2004.10","next":"us/32-cfr-2004.12"},"notice":"GroundRules: Original legal text. Not legal advice."}
