ASOM-Fedv6.1Open the explorer
Statute · United States statute · 44 U.S.C. ch. 35

Federal Information Security Modernization Act

The statutory basis for federal information security programs: the elements an agency-wide program must contain, the annual independent evaluation, and the reporting that follows from both.

8/8Obligations addressedEvery one of them carries a stated gap; none of them is claimed as satisfied.
21Controls carrying itEach with an evidence artifact and an assessment procedure
4Stated boundariesWhat this framework does not do for this regime
The Claim

What This Framework Contributes.

The framework supplies substance against most of the statutory program elements and none of the reporting the statute is enforced through. Both halves of that sentence matter.

The Boundary

What it does not do for FISMA.

Read this before the crosswalk, not after it. A reader who takes the mappings below as coverage of FISMA will be wrong in a way that is expensive to discover later.

Obligation by Obligation

8 elements, each with what is missing.

FISMA publishes no control-level index for a catalog to be turned round against, so these edges are authored rather than derived. Each one is stated as a citation and resolved against the real catalog when the site is built: the prose can go stale, the links cannot go dead.

An inventory of major information systems

3 controls

The agency maintains an inventory of its major information systems, including identification of the interfaces between each system and other systems or networks.

What the framework supplies

The overlay is an inventory with position attached, and the connection register states the interfaces as declared paths and denied paths rather than as a list of links.

What it does not

The system-of-record inventory remains the agency’s. The overlay reconciles against it and does not replace it, and nothing here assigns a system identifier.

Periodic risk assessments

4 controls

Periodic assessments of the risk and magnitude of harm that could result from unauthorized access, use, disclosure, disruption, modification or destruction.

What the framework supplies

Reachability assessment is the part usually missing from a periodic risk assessment: not whether a weakness exists, but whether an adversary can get from where they are to the thing that matters.

What it does not

The framework computes residual risk against its own coverage model. That number is not an agency risk determination and does not feed one without the agency’s own impact analysis.

Risk-based policies and procedures

3 controls

Policies and procedures that cost-effectively reduce risk to an acceptable level, ensure security is addressed throughout the life cycle, and ensure compliance with applicable requirements.

What the framework supplies

Defensive intent forces the acceptable-risk statement to be written and signed while nothing is happening, which is the only time it can be written honestly. The rules of engagement are the procedure half.

What it does not

The agency’s security policy set is far wider than intent and engagement rules. The framework governs the defensive operation, not the program’s policy corpus.

Security awareness training

1 controls

Security awareness training to inform personnel — including contractors and other users of systems that support agency operations — of the risks and their responsibilities.

What the framework supplies

Readiness is scored by role against the moves that role has to be able to execute, so the measure is capability to act rather than completion of a course.

What it does not

General awareness training for the whole workforce is not what role-based readiness measures, and the framework produces no training content, no completion record and no curriculum.

Periodic testing and evaluation

3 controls

Periodic testing and evaluation of the effectiveness of information security policies, procedures and practices, performed with a frequency depending on risk, but no less than annually.

What the framework supplies

Effectiveness validation and the reconstitution exercise are tests with pass conditions. The cadence control makes “periodic” a declared interval that the cycle record can be measured against.

What it does not

Testing here covers the defensive scheme and the recovery path. It is not a test of the agency’s full control set, and it is not the annual independent evaluation.

A remedial action process

2 controls

A process for planning, implementing, evaluating and documenting remedial action to address deficiencies in information security policies, procedures and practices.

What the framework supplies

Findings are dispositioned rather than admired, and the backlog is ordered by defensive weight — so the queue reduces risk rather than reducing count.

What it does not

The plan of action and milestones is a required artifact with a required schema. The backlog is not in that schema and does not substitute for it.

Incident detection, reporting and response

3 controls

Procedures for detecting, reporting and responding to security incidents, including mitigating risks before substantial damage is done and notifying the appropriate authorities.

What the framework supplies

Decision-loop measurement makes “before substantial damage” a number with a threshold, and pre-authorized response is what lets the number be met without an approval cycle in the middle of it.

What it does not

Notification of authorities is a statutory obligation on its own clock to its own recipients. The framework measures the defender’s loop and takes no part in the reporting.

Continuity of operations

4 controls

Plans and procedures to ensure continuity of operations for information systems that support the operations and assets of the agency.

What the framework supplies

Recovery is held as a rehearsed capability outside the blast radius and is required to be proven rather than planned. The statutory availability floor names which availability commitments are legal rather than aspirational.

What it does not

The agency’s continuity-of-operations plan and its disaster recovery documentation are not produced here. The framework tests the recovery path; it does not write the plan.

Authored edges, derived resolution. Each statutory program element cites control ids; the controls, their families and their accountable roles are read from the catalog. What the framework takes from this source and what it declines to take is set out in sources and provenance; the controls named on this page each carry their full lineage on their own sheet.