# What is the Federal Information Security Modernization Act (FISMA)?

> The Federal Information Security Modernization Act of 2014 (FISMA) is a United States law that establishes a government-wide framework for managing information-security risk to federal operations, assets, information, and systems.

- Canonical URL: https://yellowcube.eu/glossary/federal-information-security-modernization-act/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

It requires risk-appropriate agency security programs, assigns government-wide and agency responsibilities, and addresses systems used or operated by agencies or by others on their behalf.

Public Law 113-283 is principally codified at 44 United States Code §§3551–3558. The Office of Management and Budget sets policy and oversight, the Department of Homeland Security administers implementation activities, and the National Institute of Standards and Technology develops supporting standards and guidelines; agency heads remain responsible.

### Key points

- **Determine scope:** Identify federal information, agency systems, contractor-operated systems acting on an agency’s behalf, responsible officials, and the distinct provisions that apply to national security systems.
- **Operate a risk program:** Maintain inventories, assess risk, implement policies and controls, plan for continuity, train personnel, test effectiveness, remediate weaknesses, and detect, report, and respond to incidents.
- **Support oversight:** Produce required reports and metrics, conduct annual independent evaluations, maintain evidence for authorization and continuous monitoring, and follow current government-wide and agency-specific direction.
- **Important limitation:** FISMA does not create a universal “FISMA certification,” and a control checklist or authorization does not guarantee security. Duties depend on current statute, policy, standards, directives, system scope, and contracts; specific applicability requires qualified federal legal and acquisition review.

### Related terms

[Federal Risk and Authorization Management Program (FedRAMP)](<https://yellowcube.eu/glossary/federal-risk-and-authorization-management-program/>) · [National Institute of Standards and Technology Special Publication (NIST SP) 800-53](<https://yellowcube.eu/glossary/national-institute-of-standards-and-technology-special-publication-800-53/>) · [Security audit](<https://yellowcube.eu/glossary/security-audit/>) · [Information security policy](<https://yellowcube.eu/glossary/information-security-policy/>) · [Cyber risk](<https://yellowcube.eu/glossary/cyber-risk/>)

### Sources

[Congress.gov, Federal Information Security Modernization Act of 2014, Public Law 113-283](https://www.congress.gov/bill/113th-congress/senate-bill/2521/text/pl) · [GovInfo, 44 U.S.C. §3554 — Federal Agency Responsibilities](https://www.govinfo.gov/link/uscode/44/3554) · [NIST, FISMA Background](https://csrc.nist.gov/Projects/risk-management/fisma-background)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

