It requires risk-appropriate agency security programs, assigns government-wide and agency responsibilities, and addresses systems used or operated by agencies or by others on their behalf.
Public Law 113-283 is principally codified at 44 United States Code §§3551–3558. The Office of Management and Budget sets policy and oversight, the Department of Homeland Security administers implementation activities, and the National Institute of Standards and Technology develops supporting standards and guidelines; agency heads remain responsible.
Key points
Determine scopeIdentify federal information, agency systems, contractor-operated systems acting on an agency’s behalf, responsible officials, and the distinct provisions that apply to national security systems.
Operate a risk programMaintain inventories, assess risk, implement policies and controls, plan for continuity, train personnel, test effectiveness, remediate weaknesses, and detect, report, and respond to incidents.
Support oversightProduce required reports and metrics, conduct annual independent evaluations, maintain evidence for authorization and continuous monitoring, and follow current government-wide and agency-specific direction.
Important limitationFISMA does not create a universal “FISMA certification,” and a control checklist or authorization does not guarantee security. Duties depend on current statute, policy, standards, directives, system scope, and contracts; specific applicability requires qualified federal legal and acquisition review.