✳ US-federal · FISMA

FISMA: federal agency information security management (not FedRAMP, not CMMC)

An educational overview of FISMA as the statutory backdrop for federal agency information security management, including systems operated on an agency's behalf. Not FedRAMP, and not CMMC.

US-federal · FISMAProgram explainerLast reviewed

What category of obligation this is

The Federal Information Security Management Act (FISMA 2002), part of the E-Government Act, required each federal agency to develop, document, and implement an agency-wide information security program. The program covers information and systems that support the agency's operations and assets, including those provided or managed by another agency, a contractor, or another source.

The Federal Information Security Modernization Act of 2014 amends FISMA 2002. NIST's background page describes the modernization themes as less overall reporting, stronger use of continuous monitoring, and reporting that focuses more on issues caused by security incidents. FISMA 2014 also required OMB to amend Circular A-130. This page teaches those names. It does not assign statute-section homework.

Who it frames

FISMA frames federal agencies, and people who use or operate a federal information system. NIST quotes the FISMA 2002 definition: a federal information system is an information system used or operated by an executive agency, by a contractor of an executive agency, or by another organization on behalf of an executive agency.

A system a contractor runs on an agency's behalf can still be a federal information system. That lane is not the same sentence as CUI on a nonfederal system. The Public sector path already says federal FISMA obligations do not automatically cover every state or local agency. A city or state program is not auto-FISMA.

Risk-based protections, at literacy depth

NIST's background page says federal agencies need information security protections commensurate with the risk and magnitude of harm from unauthorized access, use, disclosure, disruption, modification, or destruction of agency information and of information systems used or operated by an agency, a contractor, or another organization on behalf of an agency.

OMB Circular A-130, as summarized on that page, requires executive agencies to plan for security, assign security responsibility to appropriate officials, periodically review security controls, and authorize system processing before operations and periodically after that. Those are themes. This page is not an A-130 dump, and it is not an authorization worksheet.

The NIST suite is not a FISMA compliance checklist

NIST states this directly: the suite of NIST information security risk management standards and guidelines is not a "FISMA Compliance checklist." Agencies, contractors, and other sources that use or operate a federal information system use that suite to develop and implement a risk-based approach. NIST describes compliance with applicable laws, regulations, executive orders, and directives as a byproduct of a robust risk-based program.

Reading SP 800-53, or SP 800-171, does not issue a FISMA result. The publications support risk management. They are not a seal, and they are not this page's homework list.

RMF is where agencies often operationalize

The NIST Risk Management Framework (RMF) is the flexible 7-step process that links to the NIST suite in support of FISMA programs. The steps are Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor.

This page only names that process. The publication and the step literacy live on the SP 800-37 explainer (/learn/explainers/sp-800-37/). This page does not walk the seven steps as homework, and it does not merge FISMA with the process.

Three federal-sounding lanes

FISMA is the statutory backdrop for federal agency information security management, including systems operated on an agency's behalf. FedRAMP is the standardized, reusable cloud product and service assessment and Authorization program for federal agency adoption. The customer still configures. CMMC is the DoD/DoW contractor assessment program for FCI and CUI in the Defense Industrial Base.

SP 800-171 sits next to CMMC: it is NIST guidance for protecting CUI in nonfederal systems. That adjacency is not "FISMA done." The FedRAMP, CMMC, and SP 800-171 explainers are the other cards. This page does not merge them.

CSF is not automatic FISMA

The Public sector path already labels NIST CSF 2.0 as a risk-management framework usable by government agencies and organizations of any size. The framework itself is not a law, a certification, or a blanket FISMA requirement. CISA Cross-Sector Cybersecurity Performance Goals stay voluntary prioritized practices. They are not a universal legal mandate for public agencies.

Using CSF 2.0 does not finish a FISMA program. This page does not redefine the CSF card. The path standards stay the soft links.

Rewrite the one-line claim

Replace "we are FISMA, FedRAMP, and CMMC compliant" with the lane that matches the system. An agency federal information system is a FISMA question. A cloud offering on a Marketplace Authorization path is a FedRAMP question, and the agency still has system duties. A Defense Industrial Base contractor environment that holds CUI is a CMMC and SP 800-171 question, not a FISMA seal.

At work, privately label one system the team touches: agency federal system, cloud offering Authorization, or contractor CUI. Escalate to the authorizing official or the contracts owner. Do not paste sensitive system detail into Atlas.

FISMA is not FedRAMP, and not CMMC

Teaching table only. It does not assign an Authorization to Operate, a FedRAMP Authorization, or CMMC Status.

Three lanes people fold into one federal badge. Not a FISMA compliance seal.
LaneWhat it is
FISMAStatutory backdrop for federal agency information security management, for federal information and systems, including operation on an agency's behalf. This explainer.
FedRAMPStandardized, reusable cloud product and service assessments and Authorizations for federal agency adoption. The customer still configures. Atlas card: /learn/explainers/fedramp/.
CMMCDoD/DoW contractor assessment program for FCI and CUI safeguarding in the Defense Industrial Base. Atlas card: /learn/explainers/cmmc/.

Claims to retire

FISMA, FedRAMP, and CMMC are the same federal badge.

FISMA is the federal agency information security program backdrop. FedRAMP is cloud offering Authorization reuse. CMMC is the contractor assessment program for FCI and CUI. Three lanes.

We implemented CSF 2.0, so we are FISMA done.

CSF 2.0 is a framework. It is not a law, a certification, or a blanket FISMA requirement. CPGs remain voluntary prioritized practices.

A state or city agency is automatically FISMA.

FISMA frames federal agencies and federal information systems. It does not automatically cover every state or local agency.

A FedRAMP Authorized SaaS means the agency finished FISMA and has no remaining system duty.

A cloud Authorization path is the FedRAMP lane. The agency still owns the federal information system, including how that offering is configured and used.

Reading SP 800-53, or SP 800-171, means the system is FISMA certified.

NIST says the risk-management suite is not a FISMA compliance checklist. SP 800-171 is the CUI-on-nonfederal publication next to CMMC, not a FISMA seal.

Finishing this lesson is an Authorization to Operate.

Atlas does not issue Authorizations to Operate or FISMA compliance seals. Completing the lesson is not an Authorization.

Sort three synthetic cases

Teaching sort only. It does not decide that a real system is a federal information system, and it does not issue an Authorization.

Three cases people fold into one badge. Not a determination.
CaseLaneAtlas card
An executive agency system, including one a contractor operates on the agency's behalf.FISMAFederal agency information security management. This explainer. Not a state or local program by default.
A cloud product or service on a Marketplace Authorization path that an agency adopts.FedRAMPReusable cloud Authorization. The agency still configures. Card: /learn/explainers/fedramp/.
A Defense Industrial Base contractor environment that safeguards CUI on nonfederal systems.CMMCContractor assessment program. SP 800-171 is the adjacent CUI publication, not FISMA done. Card: /learn/explainers/cmmc/.

CHECK THE CATEGORY

Which sentence matches this page?

Glossary and nearby pages

Use the agency page in the sources for the authoritative text. This page has no figure.

Find your next idea.

Tip: press / to open search. Escape closes this window.