home/thesaurus/Federal Information Security Management Act

Federal Information Security Management Act

nounverified·updated May 9, 2026

A statute (Title III, P.L. 107-347) that requires agencies to assess risk to information systems and provide information security protections commensurate with the risk. FISMA also requires that agencies integrate information security into their capital planning and enterprise architecture processes, conduct annual information systems security reviews of all programs and systems, and report the results of those reviews to OMB.

Outgoing relationships

Incoming relationships