home/glossary/Federal Information Security Management Act

Federal Information Security Management Act

nounid 2571·updated May 9, 2026
verified

A statute (Title III, P.L. 107-347) that requires agencies to assess risk to information systems and provide information security protections commensurate with the risk. FISMA also requires that agencies integrate information security into their capital planning and enterprise architecture processes, conduct annual information systems security reviews of all programs and systems, and report the results of those reviews to OMB.

polysemousMWE

Attested in

No recorded attestations. They are written when an MWE tagging stage is completed, stamped with the pack version and the document’s digest.

Classifications

Entity Type

Framework95%llm-generatedllm:claude-haiku-4-5

Sensitivity

Regulated90%rule-basedr:sens.regulated.framework.v1

Information Class

unclassified

Variants

acronym
FISMA
synonym
Federal Information Security Modernization Act
plural
Federal Information Security Management Acts
possessive
Federal Information Security Management Act's
pluralpossessive
Federal Information Security Management Acts'

Framework definitions

NISTIR 7298: Glossary of Key Information Security Terms, Revision 22 sensesview framework →
§1
A statute (Title III, P.L. 107-347) that requires agencies to assess risk to information systems and provide information security protections commensurate with the risk. FISMA also requires that agencies integrate information security into their capital planning and enterprise architecture processes, conduct annual information systems security reviews of all programs and systems, and report the results of those reviews to OMB.
§2 · sense_2_pending_review
Title III of the E-Government Act requiring each federal agency to develop, document, and implement an agency-wide program to provide information security for the information and information systems that support the operations and assets of the agency, including those provided or managed by another agency, contractor, or other source.
CNSSI-4009 (Glossary of Information Assurance Terms)1 senseview framework →
§1
A statute (Title III, P.L. 107-347) that requires agencies to assess risk to information systems and provide information security protections commensurate with the risk. FISMA also requires that agencies integrate information security into their capital planning and enterprise architecture processes, conduct annual information systems security reviews of all programs and systems, and report the results of those reviews to OMB.
NIST SP 800-631 senseview framework →
§1
Title III of the E-Government Act requiring each federal agency to develop, document, and implement an agency-wide program to provide information security for the information and information systems that support the operations and assets of the agency, including those provided or managed by another agency, contractor, or other source.
Legacy lexicon import1 senseview framework →
§1 · legacy_primary
A statute (Title III, P.L. 107-347) that requires agencies to assess risk to information systems and provide information security protections commensurate with the risk. FISMA also requires that agencies integrate information security into their capital planning and enterprise architecture processes, conduct annual information systems security reviews of all programs and systems, and report the results of those reviews to OMB.
DR-088 backfill from the noun definition column

Outgoing relationships

Incoming relationships