Federal Information Security Management Act of 2002
E390179
The Federal Information Security Management Act of 2002 is a U.S. federal law that establishes a comprehensive framework for protecting government information systems and managing information security risks across federal agencies.
All labels observed (5)
| Label | Occurrences |
|---|---|
| FISMA | 4 |
| Federal Information Security Management Act of 2002 canonical | 4 |
| FISMA 2002 | 1 |
| Federal Information Security Management Act | 1 |
| Title III – Federal Information Security Management Act | 1 |
Statements (50)
| Predicate | Object |
|---|---|
| instanceOf |
United States federal law
ⓘ
information security law ⓘ |
| alsoKnownAs |
Federal Information Security Management Act of 2002
ⓘ
surface form:
FISMA 2002
|
| appliesTo |
federal executive agencies
ⓘ
federal information systems ⓘ |
| assignsRoleTo |
Chief Information Officers of federal agencies
ⓘ
Director of the Office of Management and Budget (Cabinet-level) ⓘ
surface form:
Director of the Office of Management and Budget
Inspectors General of federal agencies ⓘ National Institute of Standards and Technology ⓘ Secretary of Commerce of the United States ⓘ
surface form:
Secretary of Commerce
agency heads ⓘ |
| authorizes |
National Institute of Standards and Technology
ⓘ
surface form:
National Institute of Standards and Technology to develop information security standards and guidelines
|
| basisFor |
Federal Information Processing Standards
ⓘ
surface form:
NIST Federal Information Processing Standards for security
NIST Risk Management Framework ⓘ |
| codifiedIn |
Title 44 of the United States Code
ⓘ
surface form:
44 U.S. Code
44 U.S.C. § 3541 et seq. (original codification) ⓘ |
| country | United States of America ⓘ |
| designates |
Office of Management and Budget for federal information security policy
ⓘ
surface form:
Office of Management and Budget as responsible for oversight of federal information security policies
|
| enactedBy | United States Congress ⓘ |
| exempts | national security systems (with separate requirements) ⓘ |
| focusesOn |
availability of federal information
ⓘ
confidentiality of federal information ⓘ integrity of federal information ⓘ |
| influenced | development of federal cybersecurity policies ⓘ |
| jurisdiction |
United States government
ⓘ
surface form:
federal government of the United States
|
| objective |
to provide a comprehensive framework for ensuring the effectiveness of information security controls over information resources
ⓘ
to provide effective government-wide management and oversight of information security risks ⓘ |
| partOf | E-Government Act of 2002 ⓘ |
| publicLawNumber |
Public Law 107-347
ⓘ
surface form:
Public Law 107-347 (Title III)
|
| relatedTo |
Clinger–Cohen Act of 1996
ⓘ
surface form:
Clinger-Cohen Act of 1996
E-Government Act of 2002 ⓘ Federal Information Security Modernization Act of 2014 ⓘ |
| replacedBy | Federal Information Security Modernization Act of 2014 ⓘ |
| requires |
annual independent evaluation of agency information security programs
ⓘ
annual reporting to Congress on information security ⓘ annual reporting to the Office of Management and Budget ⓘ development of agency-wide information security programs ⓘ implementation of security controls commensurate with risk ⓘ incident detection and response procedures ⓘ periodic risk assessments of information systems ⓘ periodic testing and evaluation of information security controls ⓘ plans for continuity of operations ⓘ security awareness training for agency personnel ⓘ |
| shortName |
Federal Information Security Management Act of 2002
self-linksurface differs
ⓘ
surface form:
FISMA
|
| signedBy | George W. Bush ⓘ |
| subjectMatter |
federal information systems
ⓘ
information security ⓘ risk management ⓘ |
| title |
E-Government Act of 2002
ⓘ
surface form:
Title III of the E-Government Act of 2002
|
| yearEnacted | 2002 ⓘ |
Referenced by (11)
Full triples — surface form annotated when it differs from this entity's canonical label.
Federal Information Security Modernization Act of 2014
→
amends
→
Federal Information Security Management Act of 2002
ⓘ
Federal Information Security Modernization Act of 2014
→
relatedTo
→
Federal Information Security Management Act of 2002
ⓘ
this entity surface form:
Federal Information Security Management Act
this entity surface form:
FISMA
Federal Information Processing Standards
→
relatedTo
→
Federal Information Security Management Act of 2002
ⓘ
this entity surface form:
FISMA
E-Government Act of 2002
→
containsProvision
→
Federal Information Security Management Act of 2002
ⓘ
this entity surface form:
FISMA
this entity surface form:
Title III – Federal Information Security Management Act
Federal Information Security Management Act of 2002
→
shortName
→
Federal Information Security Management Act of 2002
self-linksurface differs
ⓘ
this entity surface form:
FISMA
Federal Information Security Management Act of 2002
→
alsoKnownAs
→
Federal Information Security Management Act of 2002
ⓘ
this entity surface form:
FISMA 2002
Office of Management and Budget for federal information security policy
→
legalBasis
→
Federal Information Security Management Act of 2002
ⓘ