Overview#

Federal Information Security and Management Act is a United States Federal Law of 2002 (FISMA), 44 U.S.C. ยง 3544 (2006) and the Federal Information Security Modernization Act (Still FISMA)

Federal Information Security and Management Act assigns responsibilities to various agencies to ensure the security of data in the federal government. The act requires program officials, and the head of each agency, to conduct annual reviews of information security programs, with the intent of keeping risks at or below specified acceptable levels in a cost-effective, timely and efficient manner.

The National Institute of Standards and Technology (NIST) outlines nine steps toward compliance with FISMA:

  • Categorize the information to be protected.
  • Select minimum baseline controls.
  • Refine controls using a risk assessment procedure.
  • Document the controls in the system security plan.
  • Implement security controls in appropriate information systems.
  • Assess the effectiveness of the security controls once they have been implemented.
  • Determine agency-level risk to the mission or business case.
  • Authorize the information system for processing.
  • Monitor the security controls on a continuous basis.

More Information#

There might be more information for this subject on one of the following:

Add new attachment

Only authorized users are allowed to upload new attachments.
« This page (revision-4) was last changed on 26-Aug-2016 12:30 by jim