Skip to content

Evidence request lists

FISMA

Evidence request list. 12 controls, 12 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

FISMA: Annual Independent Evaluation (IG Audit) and OMB FISMA Report

FISMA-3555-Annual-IG-Evaluation
Annual Independent Evaluation by Inspector General (44 USC 3555)

44 USC 3555 - Annual Independent Evaluation. EACH AGENCY MUST have an ANNUAL INDEPENDENT EVALUATION of agency information security program + practices by: (1) the AGENCY INSPECTOR GENERAL (IG) for non-NSS systems; OR (2) an INDEPENDENT EVALUATOR designated by the OMB + ed when an IG does not exist. EVALUATION SCOPE: agency-wide information security program effectiveness + selected agency systems (sample-based) + agency progress against PRIOR YEAR'S findings + Maturity-Model assessment against the IG FISMA Reporting Metrics (annually updated by the Council of Inspectors General on Integrity and Efficiency, CIGIE). MATURITY RATINGS: Level 1 Ad Hoc + Level 2 Defined + Level 3 Consistently Implemented + Level 4 Managed and Measurable + Level 5 Optimized. REPORTING: (a) the IG submits a report to the agency head; (b) the agency submits its FISMA REPORT to OMB + CISA via the CYBERSCOPE PORTAL

Artefacts an auditor will ask for
  • IG annual FISMA report
  • CyberScope submission evidence
  • Maturity-model assessment + improvement plan
  • OMB FISMA Report inclusion
Where this commonly fails
  • Annual IG evaluation skipped
  • CyberScope submission overdue
  • Maturity rating Ad Hoc / Defined without improvement
  • Congressional report missing or unread

FISMA: Coordination with FedRAMP, EO 14028, OMB Memoranda and Status

FISMA-Coord-NIST-CSF-ISO27001-SOC2
Coordination with NIST CSF 2.0, ISO 27001, SOC 2 and Industry Frameworks

FISMA coordination with industry security frameworks. NIST CSF 2.0 (February 2024): voluntary framework + 6 functions (Govern + Identify + Protect + Detect + Respond + Recover); cross-references NIST 800-53 + NIST 800-171 + applicable to federal + state + local + tribal + private sector; useful for agencies to align FISMA program with private-sector + critical-infrastructure expectations. ISO/IEC 27001:2022 + ISO/IEC 27002:2022: voluntary ISMS standard + 93 Annex A controls; FedRAMP + NIST 800-53 cover ISO 27001 conceptually but require additional ISO-specific evidence for ISO certification; some agencies pursue ISO 27001 certification for cross-border + international operations. SOC 2 (Service Organization Control 2 - AICPA TSP Section 100): voluntary attestation for service organizations on Security + Availability + Processing Integrity + Confidentiality + Privacy; complements FISMA fo

Artefacts an auditor will ask for
  • NIST CSF mapping document
  • ISO 27001/SOC 2 cross-reference
  • PCI DSS scope + compliance evidence
Where this commonly fails
  • Industry framework alignment skipped
  • Cross-mapping not maintained
  • Sector-specific frameworks ignored
FISMA-FedRAMP-Cloud-Coordination
FedRAMP for Cloud Services + 800-37 ATO Integration

FISMA + FedRAMP coordination for cloud services. FEDRAMP (Federal Risk and Authorization Management Program) operationalizes FISMA for CLOUD SERVICES used by federal agencies (established by OMB Memorandum M-11-30 + modernized by M-24-15 of July 2024). FedRAMP baselines (Low + Moderate + High + LI-SaaS) align with FIPS 199 + NIST 800-53 Rev 5 + FedRAMP-specific overlay parameters. FedRAMP authorization paths: JAB AUTHORIZATION (DOD + DHS + GSA P-ATO); AGENCY AUTHORIZATION (individual agency ATO); FedRAMP Marketplace + 3PAO accreditation. CLOUD-FIRST POLICY: agencies should prefer cloud services for new IT investments + use FedRAMP-authorized CSPs. CMMC (Cybersecurity Maturity Model Certification) Programme for DOD contractors: 3 levels + 3rd-party assessment + integration with NIST SP 800-171 Rev 3. FedRAMP Moderate + High frameworks VERIFIED separately in the graph against NIST 800-53 R

Artefacts an auditor will ask for
  • FedRAMP authorization status per cloud service
  • ConMon + 3PAO integration into agency CM
  • CMMC Level + 3PAO if applicable
  • Cloud-First policy alignment
Where this commonly fails
  • Federal cloud use without FedRAMP authorization (PROHIBITED)
  • FedRAMP ConMon not integrated into agency CM
  • CMMC requirements not flowed to subcontractors
FISMA-Reform-Pipeline
FISMA 2.0 Reform Pipeline, Legislative Activity and Future State

FISMA 2.0 reform pipeline + legislative activity. PROPOSED LEGISLATION: (a) FISMA REFORM ACT OF 2023 (S.2251 + H.R.6395 of the 118th Congress) introduced by Senators Peters (D-MI) + Lankford (R-OK) + bipartisan support; would: (i) ELEVATE CISA authority + consolidate federal cybersecurity oversight; (ii) extend FISMA-like reporting to CRITICAL INFRASTRUCTURE entities beyond federal agencies; (iii) align incident-reporting timelines with CIRCIA; (iv) require AGENCY VULNERABILITY DISCLOSURE POLICIES + bug bounty programs (mandatory); (v) strengthen SUPPLY CHAIN RISK MANAGEMENT requirements per EO 14017 + the 2024 OMB ICT supply chain guidance; (vi) align with the NATIONAL CYBERSECURITY STRATEGY (March 2023); (b) NCD AUTHORIZATION ACT - codifies the National Cyber Director role + budget oversight; (c) FEDERAL CYBERSECURITY VULNERABILITY REDUCTION ACT - mandates federal vulnerability disclos

Artefacts an auditor will ask for
  • Legislative tracking + readiness plan
  • Critical-infrastructure status assessment if applicable
  • Executive Order + OMB Memo compliance
Where this commonly fails
  • FISMA 2.0 reform not tracked
  • Critical-infrastructure obligations missed
  • Executive Order coordination ad-hoc
FISMA-Status-2024-2025
FISMA Status, 2024-2025 Modernization, OMB FISMA Report and Reform Proposals

FISMA status + 2024-2025 modernization + reform proposals. STATUS: FISMA 2014 (Public Law 113-283) remains in force; codified at 44 USC Chapter 35 Subchapter II; primary implementing documents OMB Circular A-130 + the annual OMB Memorandum on FISMA Reporting Guidance (M-24-04 most recent). ANNUAL FISMA REPORT: Joint OMB + DHS submission to Congress (typically February-April for the prior fiscal year); covers agency information security program effectiveness + maturity ratings + incidents + spending + emerging-threat coverage. 2024-2025 MODERNIZATION + REFORM: (a) FISMA 2.0 LEGISLATIVE PROPOSALS - bipartisan FISMA Reform Act of 2023 (Senator Peters / Senator Lankford) + 2024 reintroductions seeking to (i) elevate the National Cyber Director (NCD) authority; (ii) consolidate federal cybersecurity oversight; (iii) extend FISMA to civilian critical infrastructure beyond federal agencies; (iv

Artefacts an auditor will ask for
  • FISMA reporting + CyberScope submission
  • OMB Memo M-24-04 compliance
  • FISMA 2.0 reform tracking
  • Annual FISMA Report inclusion + agency score
  • IG FISMA Metrics maturity tracking
Where this commonly fails
  • FISMA reporting overdue or incomplete
  • OMB Memo guidance not implemented
  • FISMA 2.0 reform not tracked
  • Agency FISMA score low without improvement plan
FISMA-Status-RefArchitecture
FISMA-Status-Reference-Architecture - Operationalisation Map

FISMA Reference Architecture - operationalisation map across the federal cyber regime. (a) STATUTORY AUTHORITY = FISMA 2014 (44 USC 3551-3559) + Public Law 113-283; (b) POLICY OVERSIGHT = OMB Circular A-130 + OMB Memoranda; (c) AGENCY-LEVEL = Agency Head + CIO + CISO + Senior Agency Official for Privacy (SAOP); (d) GOVERNMENT-WIDE OVERSIGHT = OMB Director + CISA Director + NCD + NSC Cyber Director; (e) STANDARDS DEVELOPMENT = NIST (SP 800-53 + 800-37 + 800-171 + 800-218 SSDF + FIPS 199/200/140) + CNSS (national security systems); (f) CLOUD AUTHORIZATION = FedRAMP PMO + JAB + Agency ATOs + 3PAO assessment + Marketplace; (g) INCIDENT RESPONSE = CISA US-CERT (federal civilian) + CYBERCOM (DOD) + IC-CIRC (intelligence community); (h) BINDING DIRECTIVES = CISA BODs (mandatory) + EDs (Emergency Directives); (i) AUDIT + EVALUATION = Agency IGs + CIGIE + GAO + Congressional oversight; (j) PARTNE

Artefacts an auditor will ask for
  • FISMA Reference Architecture map
  • Role inventory + RACI matrix
  • Standards-version tracking
  • Threat-environment briefings
Where this commonly fails
  • Reference architecture incomplete or stale
  • Role inventory missing
  • Standards updates not tracked
  • Threat-environment awareness poor

FISMA: Federal Agency Responsibilities (CIO, CISO, Program, Reporting)

FISMA-3554-Agency-Responsibilities
Federal Agency Responsibilities (44 USC 3554) - CIO + CISO + Program + Reporting

44 USC 3554 - Federal Agency Responsibilities. EACH AGENCY HEAD must: (a) ensure compliance with FISMA + with policies + procedures + standards developed by OMB + CISA + NIST + CNSS; (b) DESIGNATE A SENIOR INFORMATION SECURITY OFFICIAL (the CIO + with CISO support); (c) ensure that the AGENCY CHIEF INFORMATION SECURITY OFFICER (CISO) + AGENCY CHIEF INFORMATION OFFICER (CIO) work in COORDINATION on information security program execution; (d) develop + maintain an AGENCY-WIDE INFORMATION SECURITY PROGRAM including: (i) RISK ASSESSMENTS of agency information systems; (ii) POLICIES + PROCEDURES based on the risk assessments + that cost-effectively reduce risks; (iii) plans for providing adequate information security for networks + facilities + information systems + groups of information systems; (iv) SECURITY AWARENESS TRAINING for all personnel; (v) PERIODIC TESTING + EVALUATION of effectiv

Artefacts an auditor will ask for
  • CIO + CISO designation evidence
  • Agency-wide info security program
  • Annual testing + POA&M tracking
  • Incident reporting per Federal Incident Notification Guidelines
  • Contractor + supplier FISMA flow-down
Where this commonly fails
  • CISO not designated or under CIO
  • Agency-wide program incomplete
  • Annual testing skipped
  • Incident reporting > 1-hour SLA for high severity
  • Contractor flow-down missing

FISMA: National Security Systems Exclusion + CIRCIA + Zero Trust

FISMA-3556-FederalCIRC-3557-NSS
Federal Information Security Incident Center (44 USC 3556) + National Security Systems Exclusion (44 USC 3557)

44 USC 3556 - Federal Information Security Incident Center (FedCIRC, now CISA US-CERT). The CISA Director operates the federal information security incident center providing: (a) timely warnings on emerging threats; (b) technical assistance to agencies in incident response; (c) consolidated central incident reporting + tracking; (d) coordination with private sector + sector ISACs + international partners; (e) information sharing under FISMA + CISA's Cybersecurity Information Sharing Act 2015 (CISA 2015) authorities. THE FEDERAL INCIDENT NOTIFICATION GUIDELINES require: (a) AGENCY HOTLINE notification within 1 HOUR for high-severity incidents (e.g. nation-state activity + significant data exfiltration + critical-infrastructure impact); (b) 4-HOUR notification for moderate-severity incidents; (c) WEEKLY status updates during open incidents; (d) FINAL REPORT within 30 days of closure. 44 US

Artefacts an auditor will ask for
  • Incident response procedure with 1-hour SLA
  • CISA US-CERT engagement records
  • NSS / FISMA boundary documentation
  • CUI classification + handling per NSS scope
Where this commonly fails
  • 1-hour SLA missed
  • NSS / FISMA boundary unclear
  • CUI mis-classified
  • CNSS coordination skipped for mixed systems
FISMA-CIRCIA-ZTA-EO14028
CIRCIA, Zero Trust Architecture, EO 14028 + 14110 + OMB Memoranda

FISMA coordination with CIRCIA + Zero Trust + Executive Orders + OMB Memoranda. CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act of 2022): Final Rule effective 2026; expands incident reporting beyond FISMA-covered agencies to CRITICAL INFRASTRUCTURE entities; covered entities must report cyber incidents within 60 HOURS + ransom payments within 24 HOURS; supervised by CISA. ZERO TRUST ARCHITECTURE (ZTA): OMB MEMORANDUM M-22-09 (January 2022) - Moving the US Government Toward Zero Trust Cybersecurity Principles - sets federal Zero Trust strategy + 5 pillars (Identity + Devices + Network + Applications + Data) + mandates FY24 ZTA targets + 2024 ZTA STRATEGY update; CISA ZERO TRUST MATURITY MODEL v2 (2023) + provides 5-pillar + 3-maturity-level framework; phishing-resistant authentication mandatory; least-privilege + micro-segmentation expected. EXECUTIVE ORDERS: EO 14028 (Ma

Artefacts an auditor will ask for
  • CIRCIA covered-entity assessment
  • ZTA maturity self-assessment + 5-pillar plan
  • SBOM Producer Attestation + EDR deployment
  • OMB Memo + EO tracking + compliance
Where this commonly fails
  • CIRCIA covered-entity status unconfirmed
  • ZTA maturity Ad Hoc / Defined
  • SBOM not produced or EDR partial
  • OMB Memo + EO not tracked or implemented

FISMA: OMB + CISA Authority + Binding Operational Directives

FISMA-3553-OMB-CISA-BOD
OMB and CISA Authority and Binding Operational Directives (44 USC 3553)

44 USC 3553 - Authority and Functions of the Director of OMB + the CISA Director. OMB DIRECTOR AUTHORITY: (a) overseeing agency information security policies + practices; (b) requiring agencies + contractors to identify + provide information security protections commensurate with the risk + magnitude of harm; (c) coordinating the development of standards + guidelines + with NIST + CNSS; (d) overseeing AGENCY COMPLIANCE with the requirements of this subchapter; (e) reviewing + approving + disapproving (within the OMB process) at least annually + the information security activities of agencies including the budget for information security; (f) coordinating Federal information security policy with related information resources management policies including the CLOUD-FIRST + SHARED SERVICES policies. CISA DIRECTOR AUTHORITY (transferred from DHS NPPD by the Cybersecurity and Infrastructure S

Artefacts an auditor will ask for
  • BOD implementation evidence per BOD
  • KEV remediation log + 15-day SLA
  • NCPS / EINSTEIN deployment evidence
  • OMB FISMA submission tracking
Where this commonly fails
  • BOD missed implementation deadline
  • KEV remediation > 15-day SLA
  • NCPS / EINSTEIN gaps
  • OMB FISMA submission incomplete or late

FISMA: Operationalisation via NIST 800-53 RMF + 800-171 + FIPS 199/200

FISMA-NIST-800-53-RMF-800-171-FIPS
Operationalisation via NIST 800-53 + 800-37 RMF + 800-171 + FIPS 199 + FIPS 200

FISMA is operationalized through NIST publications (mandatory per 44 USC 3553(e) + NIST FISMA Implementation Project). NIST SP 800-53 REV 5 (Security and Privacy Controls): 1,189 controls + control enhancements across 20 families (AC + AT + AU + CA + CM + CP + IA + IR + MA + MP + PE + PL + PM + PS + PT + RA + SA + SC + SI + SR); VERIFIED separately in the graph as the canonical control catalog. NIST SP 800-37 REV 2 (Risk Management Framework, RMF): 7-step process (Prepare + Categorize + Select + Implement + Assess + Authorize + Monitor); the AUTHORIZATION TO OPERATE (ATO) is the formal RMF Step 6 acceptance of residual risk by an authorizing official + may be unconditional + conditional + revocable. NIST SP 800-171 REV 3 (Protecting Controlled Unclassified Information in Nonfederal Systems): 110 controls applying to contractor systems processing CUI (Controlled Unclassified Information);

Artefacts an auditor will ask for
  • System categorization records
  • NIST 800-53 control implementation evidence
  • RMF ATO documentation
  • NIST 800-171 + DFARS 7012 compliance for contractors
Where this commonly fails
  • FIPS 199 categorization missing
  • NIST 800-53 controls partially implemented
  • ATO expired or conditional without remediation
  • NIST 800-171 + DFARS 7012 not flowed to subcontractors

FISMA: Statutory Structure (44 USC 3551-3559) and Definitions

FISMA-3551-3552-Purposes-Defs
Purposes and Definitions (44 USC 3551-3552)

44 USC 3551 + 3552. SECTION 3551 PURPOSES: (a) the purposes of FISMA are to (1) provide a comprehensive framework for ensuring the effectiveness of information security controls over information resources that support Federal operations + assets; (2) recognize the highly networked nature of the current Federal computing environment + provide effective government-wide management + oversight of the related information security risks; (3) provide for development + maintenance of minimum controls required to protect Federal information + information systems; (4) provide a mechanism for improved oversight of Federal agency information security programs including reports to Congress; (5) acknowledge that commercially developed information security products offer advanced + dynamic security solutions; (6) recognize that the selection of specific technical hardware + software for information sec

Artefacts an auditor will ask for
  • FISMA applicability assessment
  • Federal contract identification
  • NSS exclusion classification
Where this commonly fails
  • FISMA applied without distinguishing federal vs NSS
  • Contractor systems missed
  • CIA triad not aligned with FISMA definitions
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the FISMA framework page.