Skip to content

FISMA

What is FISMA?

The Federal Information Security Modernization Act requires federal agencies to implement comprehensive security programs for their information systems.

Compliance and Regulatory

Each of these is named in at least one of the same controls as fisma. The number is how many controls name both.

What the standards actually require on fisma

Requirements naming fisma across 4 standards, quoted from the control text.

FISMA11 controls

FISMA Reference Architecture - operationalisation map across the federal cyber regime. (a) STATUTORY AUTHORITY = FISMA 2014 (44 USC 3551-3559) + Public Law 113-283; (b) POLICY OVERSIGHT = OMB Circular A-130 + OMB Memoranda;

FISMA-Status-RefArchitecture · FISMA-Status-Reference-Architecture - Operationalisation Map

Coordination positions IRS Pub 1075 within the broader US federal + state + and industry security landscape. (1) NIST Standards: NIST SP 800-53 Rev 5 (primary control set incorporated by reference Section 9.3) + NIST SP 800-53A (assessment methodology) + NIST...

IRSPub1075-CoordNIST80053-FedRAMP-FISMA-CJIS-SSACDS-StateRevAgencies-PrivacyAct-SOC2-Industry · IRS Pub 1075 Coordination - NIST SP 800-53 Rev 5 + FedRAMP + FISMA + 26 USC 6103 + FBI CJIS + SSA CDS + State Revenue Agencies + Privacy Act + SOC 2 + Industry Frameworks + Federal Sectoral
FedRAMP Rev 52 controls

FedRAMP incident-reporting regime: CSPs must report incidents to: (a) the FedRAMP PMO; (b) agency customer points-of-contact; (c) US-CERT (CISA) per the FISMA incident-reporting requirements.

FedRAMP-IncidentReporting · FedRAMP incident reporting to PMO and US-CERT

Provide security status reporting per Section 3.6 to System Owners + ISSO + AO + CISO + senior leadership. Apply risk score aggregation including: vulnerability scoring (CVSS v4.0 + EPSS + KEV catalog) + asset criticality scoring + threat intelligence overlay...

NISTSP137-4 · Security Status Reporting and Risk Score Aggregation

Questions people ask about fisma

What is FISMA?
The Federal Information Security Modernization Act requires federal agencies to implement comprehensive security programs for their information systems.
Why is FISMA important for compliance?
FISMA is a key concept in Compliance and Regulatory. Understanding fisma helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address FISMA?
FISMA appears in the requirement text of FISMA, IRS Publication 1075, FedRAMP Rev 5, NIST SP 800-137. Across these standards we have identified 17 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about FISMA?
Explore our compliance framework pages to see how fisma applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how FISMA applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.