Complying With The Federal Information Security Act (Fisma)
Complying With The Federal Information Security Act (Fisma)
Complying With The Federal Information Security Act (Fisma)
What is FISMA?
FISMA
Congress included the FISMA as part of the EGovernment Act of 2002
http://thomas.loc.gov/bss/d107/d107laws.html
Purpose of FISMA
Bringing Standardization to security control selection
FISMA Requirements
Federal agencies are required to establish an integrated,
FISMA Dictates
and in-depth
NIST guidance includes:
Standards for categorizing information and information systems
by mission impact.
Standards for minimum security requirements for information and
information systems.
Guidance for selecting appropriate security controls for
information systems.
Guidance for assessing security controls in information systems
and determining security control effectiveness.
Guidance for certifying and accrediting information systems.
Security Controls)
NIST Special Publication 800-53A Rev 1(Security Control
Assessment)
NIST Special Publication 800-60 (Security Category Mapping)
requirements
Delineating responsibilities and expected behavior of all
individuals who access the system
Documenting the structured process of planning adequate, costeffective security protection for the system
organizational information;
enabling management to make well-informed risk management
decisions to justify the expenditures
assisting management in authorizing (or accrediting) the IT
systems
SUMMARY
Key activities in managing enterprise-level riskrisk
QUESTIONS?
LARRY CHMIEL