What is the main purpose of FISMA?
FISMA (Federal Information Security Modernization Act of 2014) establishes a comprehensive framework for protecting the effectiveness of information security controls over Federal operations and assets. Specifically, it provides governmentwide management of information security risks while explicitly recognizing the highly networked nature of the Federal computing environment. Moreover, it mandates minimum controls to protect Federal information and systems from unauthorized access, use, disclosure, disruption, modification, or destruction. As a result, FISMA guarantees the integrity, confidentiality, and availability of Federal information systems.
Who are the key federal entities responsible for FISMA compliance?
FISMA distributes oversight responsibilities across three levels of federal authority. Specifically, each entity plays a distinct role in building and maintaining governmentwide information security. Moreover, the framework creates accountability at both the policy and operational levels.
In practice, the three key entities are:
- Office of Management and Budget (OMB): the OMB Director oversees agency information security policies and practices, including developing standards, principles, and guidelines
- Department of Homeland Security (DHS): the DHS Secretary administers implementation of agency policies, issues binding operational directives, provides technical assistance, and operates the central Federal information security incident center
- Agency Heads: federal agency leaders provide security protections commensurate with risk and magnitude of harm, comply with all requirements and directives, and delegate authority to their Chief Information Officer (CIO) to ensure agency-wide compliance
How do agencies evaluate FISMA compliance and security effectiveness?
FISMA requires every federal agency to complete an annual independent evaluation to determine the effectiveness of its information security program and practices. Specifically, for agencies with an Inspector General (IG), the IG or an independent external auditor the IG selects must lead this evaluation. Furthermore, the process must include testing the effectiveness of security policies, procedures, and practices on a representative subset of the agency’s information systems. In fact, this annual rhythm is what keeps security programs honest rather than static.
What maturity model do Inspectors General use for FISMA evaluations?
Inspectors General assess information security programs using a five-level maturity model. Specifically, the foundational levels ensure agencies develop sound policies. Moreover, the advanced levels capture the extent to which those policies are institutionalized across the organization. Importantly, OMB guidance sets a clear bar: an agency must reach Level 4 or above for its security to be considered effective.
In practice, the five levels are:
- Level 1 – Ad Hoc: security activities are informal and inconsistent
- Level 2 – Defined: the agency documents and approves policies and procedures
- Level 3 – Consistently Implemented: teams apply defined practices consistently across the organization
- Level 4 – Managed and Measurable: the agency measures and manages security activities, and this is the minimum level OMB considers effective
- Level 5 – Optimized: the agency continuously improves security based on metrics, lessons learned, and emerging threats
Which cybersecurity domains does the annual FISMA IG evaluation cover?
The FY 2025 IG FISMA evaluation framework divides metrics into two categories. Specifically, Core metrics cover high-impact security processes and assessors evaluate them annually. Furthermore, Supplemental metrics capture important activities that contribute to overall program effectiveness. Together, these metrics evaluate capabilities across 10 distinct cybersecurity domains:
- Cybersecurity Governance
- Cybersecurity Supply Chain Risk Management (C-SCRM)
- Risk and Asset Management (RAM)
- Configuration Management
- Identity and Access Management (IDAM)
- Data Protection and Privacy
- Security Training
- Information Security Continuous Monitoring (ISCM)
- Incident Response (IR)
- Contingency Planning (CP)