United States federal government

FISMA

65 controls. 89 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

65 controls 89 frameworks share controls with it United States federal government verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

FISMA Evidence & Implementation Kit

65 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
FISMA-3551-3552-Purposes-DefsPurposes and Definitions (44 USC 3551-3552)0
FISMA-3553-OMB-CISA-BODOMB and CISA Authority and Binding Operational Directives (44 USC 3553)0
FISMA-3554-Agency-ResponsibilitiesFederal Agency Responsibilities (44 USC 3554) - CIO + CISO + Program + Reporting60
FISMA-3555-Annual-IG-EvaluationAnnual Independent Evaluation by Inspector General (44 USC 3555)0
FISMA-3556-FederalCIRC-3557-NSSFederal Information Security Incident Center (44 USC 3556) + National Security Systems Exclusion (44 USC 3557)0
FISMA-CIRCIA-ZTA-EO14028CIRCIA, Zero Trust Architecture, EO 14028 + 14110 + OMB Memoranda69
FISMA-Coord-NIST-CSF-ISO27001-SOC2Coordination with NIST CSF 2.0, ISO 27001, SOC 2 and Industry Frameworks0
FISMA-FedRAMP-Cloud-CoordinationFedRAMP for Cloud Services + 800-37 ATO Integration0
FISMA-NIST-800-53-RMF-800-171-FIPSOperationalisation via NIST 800-53 + 800-37 RMF + 800-171 + FIPS 199 + FIPS 20073
FISMA-Reform-PipelineFISMA 2.0 Reform Pipeline, Legislative Activity and Future State0
FISMA-Status-2024-2025FISMA Status, 2024-2025 Modernization, OMB FISMA Report and Reform Proposals0
FISMA-Status-RefArchitectureFISMA-Status-Reference-Architecture - Operationalisation Map0
3551Section 3551 Purposes0
3552Section 3552 Definitions0
3553Section 3553 Authority and functions of the Director and the Secretary0
3554(a)(1)(A)3554(a)(1)(A) Protections commensurate with risk0
3554(a)(1)(B)3554(a)(1)(B) Compliance with standards, directives, OMB policy and NSS guidance0
3554(a)(1)(C)3554(a)(1)(C) Security integrated with strategic, operational and budgetary planning0
3554(a)(2)(A)3554(a)(2)(A) Senior officials assess risk and magnitude of harm0
3554(a)(2)(B)3554(a)(2)(B) Senior officials determine appropriate security levels0
3554(a)(2)(C)3554(a)(2)(C) Senior officials implement cost-effective risk reduction0
3554(a)(2)(D)3554(a)(2)(D) Senior officials periodically test controls0
3554(a)(3)(A)3554(a)(3)(A) CIO authority and a qualified senior agency information security officer0
3554(a)(3)(B)-(C)3554(a)(3)(B)-(C) CIO maintains the agency-wide program and its policies and controls0
3554(a)(3)(D)-(E)3554(a)(3)(D)-(E) CIO trains and oversees security personnel and assists senior officials0
3554(a)(4)3554(a)(4) Sufficient trained personnel0
3554(a)(5)3554(a)(5) CIO annual report to the agency head0
3554(a)(6)3554(a)(6) Senior and component officials carry out their responsibilities0
3554(a)(7)3554(a)(7) All personnel accountable for the program0
3554(b)3554(b) An agency-wide information security program0
3554(b)(1)3554(b)(1) Periodic risk assessments0
3554(b)(2)3554(b)(2) Risk-based policies and procedures across the life cycle0
3554(b)(3)3554(b)(3) Subordinate security plans0
3554(b)(4)3554(b)(4) Security awareness training for all users0
3554(b)(5)3554(b)(5) Testing and evaluation at least annually with automated tools0
3554(b)(6)3554(b)(6) Remedial action process0
3554(b)(7)3554(b)(7) Incident detection, reporting and response, with seven-day major incident notice to Congress0
3554(b)(8)3554(b)(8) Continuity of operations plans0
3554(c)(1)(A)3554(c)(1)(A) Annual report to OMB, DHS, Congress and GAO0
3554(c)(1)(B)3554(c)(1)(B) Unclassified report with maximum content0
3554(c)(2)3554(c)(2) Security addressed in management plans and reports0
3554(d)3554(d) Security resources in the performance plan0
3554(e)3554(e) Public notice and comment on policies affecting the public0
3555(a)3555(a) Annual independent evaluation of the program0
3555(b)3555(b) Evaluation by the Inspector General or an independent external auditor0
3555(c)3555(c) National security systems evaluated by a designated entity0
3555(d)3555(d) Reliance on existing audits and evaluations0
3555(e)3555(e) Evaluation results submitted to OMB0
3555(f)3555(f) Protection of evaluation information0
3555ghijSections 3555(g) to (j): OMB, GAO and guidance duties0
3556(b)3556(b) National security system agencies share incident information with the center0
3556aSection 3556(a) The Federal information security incident center0
35573557 Agency head responsibilities for national security systems0
3558Section 3558 Effect on existing law0
BData breach notification (section 2(d) of the Act)0
EAnnual independent evaluation (44 U.S.C. 3555)0
FISMAFISMA 2014: the Act, its structure and its status0
HAgency head responsibilities (44 U.S.C. 3554(a))0
NNational security systems and incident information sharing (44 U.S.C. 3556(b), 3557)0
PAgency-wide information security program (44 U.S.C. 3554(b))0
RAgency reporting, performance plan and public notice (44 U.S.C. 3554(c) to (e))0
S2(d)(1)(A)S2(d)(1)(A) Breach notice to Congress within 30 days0
S2(d)(1)(B)S2(d)(1)(B) Breach notice to affected individuals without unreasonable delay0
S2bcefSections 2(b), 2(c), 2(e) and 2(f) of the Act: major-incident guidance, continuous diagnostics, conforming amendments, Circular A-1300
S2d-ombSection 2(d) breach provisions addressed to OMB, the Attorney General, the intelligence community and DHS0

Tell me when FISMA files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • contingency and continuity plans per system
  • backup and recovery test records
  • plan exercise results
  • Continuity of operations / disaster recovery plans
  • Recovery objectives (RTO/RPO) and backups
  • Continuity testing records
  • FISMA Reference Architecture map
  • Role inventory + RACI matrix
  • Standards-version tracking
  • Threat-environment briefings

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for FISMA, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition