FISMA-3551-3552-Purposes-Defs | Purposes and Definitions (44 USC 3551-3552) | 0 |
FISMA-3553-OMB-CISA-BOD | OMB and CISA Authority and Binding Operational Directives (44 USC 3553) | 0 |
FISMA-3554-Agency-Responsibilities | Federal Agency Responsibilities (44 USC 3554) - CIO + CISO + Program + Reporting | 60 |
FISMA-3555-Annual-IG-Evaluation | Annual Independent Evaluation by Inspector General (44 USC 3555) | 0 |
FISMA-3556-FederalCIRC-3557-NSS | Federal Information Security Incident Center (44 USC 3556) + National Security Systems Exclusion (44 USC 3557) | 0 |
FISMA-CIRCIA-ZTA-EO14028 | CIRCIA, Zero Trust Architecture, EO 14028 + 14110 + OMB Memoranda | 69 |
FISMA-Coord-NIST-CSF-ISO27001-SOC2 | Coordination with NIST CSF 2.0, ISO 27001, SOC 2 and Industry Frameworks | 0 |
FISMA-FedRAMP-Cloud-Coordination | FedRAMP for Cloud Services + 800-37 ATO Integration | 0 |
FISMA-NIST-800-53-RMF-800-171-FIPS | Operationalisation via NIST 800-53 + 800-37 RMF + 800-171 + FIPS 199 + FIPS 200 | 73 |
FISMA-Reform-Pipeline | FISMA 2.0 Reform Pipeline, Legislative Activity and Future State | 0 |
FISMA-Status-2024-2025 | FISMA Status, 2024-2025 Modernization, OMB FISMA Report and Reform Proposals | 0 |
FISMA-Status-RefArchitecture | FISMA-Status-Reference-Architecture - Operationalisation Map | 0 |
3551 | Section 3551 Purposes | 0 |
3552 | Section 3552 Definitions | 0 |
3553 | Section 3553 Authority and functions of the Director and the Secretary | 0 |
3554(a)(1)(A) | 3554(a)(1)(A) Protections commensurate with risk | 0 |
3554(a)(1)(B) | 3554(a)(1)(B) Compliance with standards, directives, OMB policy and NSS guidance | 0 |
3554(a)(1)(C) | 3554(a)(1)(C) Security integrated with strategic, operational and budgetary planning | 0 |
3554(a)(2)(A) | 3554(a)(2)(A) Senior officials assess risk and magnitude of harm | 0 |
3554(a)(2)(B) | 3554(a)(2)(B) Senior officials determine appropriate security levels | 0 |
3554(a)(2)(C) | 3554(a)(2)(C) Senior officials implement cost-effective risk reduction | 0 |
3554(a)(2)(D) | 3554(a)(2)(D) Senior officials periodically test controls | 0 |
3554(a)(3)(A) | 3554(a)(3)(A) CIO authority and a qualified senior agency information security officer | 0 |
3554(a)(3)(B)-(C) | 3554(a)(3)(B)-(C) CIO maintains the agency-wide program and its policies and controls | 0 |
3554(a)(3)(D)-(E) | 3554(a)(3)(D)-(E) CIO trains and oversees security personnel and assists senior officials | 0 |
3554(a)(4) | 3554(a)(4) Sufficient trained personnel | 0 |
3554(a)(5) | 3554(a)(5) CIO annual report to the agency head | 0 |
3554(a)(6) | 3554(a)(6) Senior and component officials carry out their responsibilities | 0 |
3554(a)(7) | 3554(a)(7) All personnel accountable for the program | 0 |
3554(b) | 3554(b) An agency-wide information security program | 0 |
3554(b)(1) | 3554(b)(1) Periodic risk assessments | 0 |
3554(b)(2) | 3554(b)(2) Risk-based policies and procedures across the life cycle | 0 |
3554(b)(3) | 3554(b)(3) Subordinate security plans | 0 |
3554(b)(4) | 3554(b)(4) Security awareness training for all users | 0 |
3554(b)(5) | 3554(b)(5) Testing and evaluation at least annually with automated tools | 0 |
3554(b)(6) | 3554(b)(6) Remedial action process | 0 |
3554(b)(7) | 3554(b)(7) Incident detection, reporting and response, with seven-day major incident notice to Congress | 0 |
3554(b)(8) | 3554(b)(8) Continuity of operations plans | 0 |
3554(c)(1)(A) | 3554(c)(1)(A) Annual report to OMB, DHS, Congress and GAO | 0 |
3554(c)(1)(B) | 3554(c)(1)(B) Unclassified report with maximum content | 0 |
3554(c)(2) | 3554(c)(2) Security addressed in management plans and reports | 0 |
3554(d) | 3554(d) Security resources in the performance plan | 0 |
3554(e) | 3554(e) Public notice and comment on policies affecting the public | 0 |
3555(a) | 3555(a) Annual independent evaluation of the program | 0 |
3555(b) | 3555(b) Evaluation by the Inspector General or an independent external auditor | 0 |
3555(c) | 3555(c) National security systems evaluated by a designated entity | 0 |
3555(d) | 3555(d) Reliance on existing audits and evaluations | 0 |
3555(e) | 3555(e) Evaluation results submitted to OMB | 0 |
3555(f) | 3555(f) Protection of evaluation information | 0 |
3555ghij | Sections 3555(g) to (j): OMB, GAO and guidance duties | 0 |
3556(b) | 3556(b) National security system agencies share incident information with the center | 0 |
3556a | Section 3556(a) The Federal information security incident center | 0 |
3557 | 3557 Agency head responsibilities for national security systems | 0 |
3558 | Section 3558 Effect on existing law | 0 |
B | Data breach notification (section 2(d) of the Act) | 0 |
E | Annual independent evaluation (44 U.S.C. 3555) | 0 |
FISMA | FISMA 2014: the Act, its structure and its status | 0 |
H | Agency head responsibilities (44 U.S.C. 3554(a)) | 0 |
N | National security systems and incident information sharing (44 U.S.C. 3556(b), 3557) | 0 |
P | Agency-wide information security program (44 U.S.C. 3554(b)) | 0 |
R | Agency reporting, performance plan and public notice (44 U.S.C. 3554(c) to (e)) | 0 |
S2(d)(1)(A) | S2(d)(1)(A) Breach notice to Congress within 30 days | 0 |
S2(d)(1)(B) | S2(d)(1)(B) Breach notice to affected individuals without unreasonable delay | 0 |
S2bcef | Sections 2(b), 2(c), 2(e) and 2(f) of the Act: major-incident guidance, continuous diagnostics, conforming amendments, Circular A-130 | 0 |
S2d-omb | Section 2(d) breach provisions addressed to OMB, the Attorney General, the intelligence community and DHS | 0 |