Federal Information Security Modernization Act
The statutory basis for federal information security programs: the elements an agency-wide program must contain, the annual independent evaluation, and the reporting that follows from both.
What This Framework Contributes.
The framework supplies substance against most of the statutory program elements and none of the reporting the statute is enforced through. Both halves of that sentence matter.
- A control family — Federal Obligations — that exists because a federal estate carries ground a commercial one does not: privacy, controlled unclassified information, shared tenancy, operational technology, statutory availability and the supply chain.
- Periodic testing and evaluation that is genuinely periodic, because the operating cycle has a declared cadence and a record that shows whether it turned.
- A remedial-action process whose queue is ordered by defensive weight rather than by finding date, which is the difference between a backlog that reduces risk and one that reduces count.
What it does not do for FISMA.
Read this before the crosswalk, not after it. A reader who takes the mappings below as coverage of FISMA will be wrong in a way that is expensive to discover later.
- The FISMA metrics submission.No CIO metrics response, no IG evaluation score, no annual report to OMB or Congress. The framework produces none of these and is not a substitute for any of them.
- Incident reporting to CISA.The statutory reporting obligations run on their own clocks to their own recipients. The framework measures the defender’s decision loop, which is a different clock for a different purpose, and confusing the two would put an operational number where a statutory deadline belongs.
- The independent evaluation.An assessment run by the program being assessed is not independent, whatever its procedure. The evidence artifacts here are built to be handed to an evaluator, not to replace one.
- Compliance as the objective.A compliant estate can still be lost. Statutory obligation sets a floor the framework treats as ground to be defended, not as the definition of a successful defense.
8 elements, each with what is missing.
FISMA publishes no control-level index for a catalog to be turned round against, so these edges are authored rather than derived. Each one is stated as a citation and resolved against the real catalog when the site is built: the prose can go stale, the links cannot go dead.
An inventory of major information systems
3 controlsThe agency maintains an inventory of its major information systems, including identification of the interfaces between each system and other systems or networks.
The overlay is an inventory with position attached, and the connection register states the interfaces as declared paths and denied paths rather than as a list of links.
The system-of-record inventory remains the agency’s. The overlay reconciles against it and does not replace it, and nothing here assigns a system identifier.
Periodic risk assessments
4 controlsPeriodic assessments of the risk and magnitude of harm that could result from unauthorized access, use, disclosure, disruption, modification or destruction.
Reachability assessment is the part usually missing from a periodic risk assessment: not whether a weakness exists, but whether an adversary can get from where they are to the thing that matters.
The framework computes residual risk against its own coverage model. That number is not an agency risk determination and does not feed one without the agency’s own impact analysis.
Risk-based policies and procedures
3 controlsPolicies and procedures that cost-effectively reduce risk to an acceptable level, ensure security is addressed throughout the life cycle, and ensure compliance with applicable requirements.
Defensive intent forces the acceptable-risk statement to be written and signed while nothing is happening, which is the only time it can be written honestly. The rules of engagement are the procedure half.
The agency’s security policy set is far wider than intent and engagement rules. The framework governs the defensive operation, not the program’s policy corpus.
Security awareness training
1 controlsSecurity awareness training to inform personnel — including contractors and other users of systems that support agency operations — of the risks and their responsibilities.
Readiness is scored by role against the moves that role has to be able to execute, so the measure is capability to act rather than completion of a course.
General awareness training for the whole workforce is not what role-based readiness measures, and the framework produces no training content, no completion record and no curriculum.
Periodic testing and evaluation
3 controlsPeriodic testing and evaluation of the effectiveness of information security policies, procedures and practices, performed with a frequency depending on risk, but no less than annually.
Effectiveness validation and the reconstitution exercise are tests with pass conditions. The cadence control makes “periodic” a declared interval that the cycle record can be measured against.
Testing here covers the defensive scheme and the recovery path. It is not a test of the agency’s full control set, and it is not the annual independent evaluation.
A remedial action process
2 controlsA process for planning, implementing, evaluating and documenting remedial action to address deficiencies in information security policies, procedures and practices.
Findings are dispositioned rather than admired, and the backlog is ordered by defensive weight — so the queue reduces risk rather than reducing count.
The plan of action and milestones is a required artifact with a required schema. The backlog is not in that schema and does not substitute for it.
Incident detection, reporting and response
3 controlsProcedures for detecting, reporting and responding to security incidents, including mitigating risks before substantial damage is done and notifying the appropriate authorities.
Decision-loop measurement makes “before substantial damage” a number with a threshold, and pre-authorized response is what lets the number be met without an approval cycle in the middle of it.
Notification of authorities is a statutory obligation on its own clock to its own recipients. The framework measures the defender’s loop and takes no part in the reporting.
Continuity of operations
4 controlsPlans and procedures to ensure continuity of operations for information systems that support the operations and assets of the agency.
Recovery is held as a rehearsed capability outside the blast radius and is required to be proven rather than planned. The statutory availability floor names which availability commitments are legal rather than aspirational.
The agency’s continuity-of-operations plan and its disaster recovery documentation are not produced here. The framework tests the recovery path; it does not write the plan.
Authored edges, derived resolution. Each statutory program element cites control ids; the controls, their families and their accountable roles are read from the catalog. What the framework takes from this source and what it declines to take is set out in sources and provenance; the controls named on this page each carry their full lineage on their own sheet.