home/glossary/Federal Information Security Management Act

Federal Information Security Management Act

nounverified·updated May 9, 2026

A statute (Title III, P.L. 107-347) that requires agencies to assess risk to information systems and provide information security protections commensurate with the risk. FISMA also requires that agencies integrate information security into their capital planning and enterprise architecture processes, conduct annual information systems security reviews of all programs and systems, and report the results of those reviews to OMB.

polysemousMWENISTIR 7298: Glossary of Key Information Security Terms, Revision 2

Senses

NISTIR 7298: Glossary of Key Information Security Terms, Revision 2sense 2 pending review

Title III of the E-Government Act requiring each federal agency to develop, document, and implement an agency-wide program to provide information security for the information and information systems that support the operations and assets of the agency, including those provided or managed by another agency, contractor, or other source.

Classifications

Entity Type

Framework95%llm-generatedllm:claude-haiku-4-5
?unassignedlast reviewed

Sensitivity

Regulated90%rule-basedr:sens.regulated.framework.v1
?unassignedlast reviewed

Information Class

unclassified

Variants

acronym
FISMA
synonym
Federal Information Security Modernization Act
plural
Federal Information Security Management Acts
possessive
Federal Information Security Management Act's
pluralpossessive
Federal Information Security Management Acts'