Federal Information Security Modernization Act (FISMA)

Introduction

The Federal Information Security Modernization Act of 2014 (FISMA 2014) updates the Federal Government's cybersecurity practices by:

  • Codifying Department of Homeland Security (DHS) authority to administer the implementation of information security policies for non-national security federal Executive Branch systems, including providing technical assistance and deploying technologies to such systems;
  • Amending and clarifying the Office of Management and Budget's (OMB) oversight authority over federal agency information security practices; and by
  • Requiring OMB to amend or revise OMB A-130 to "eliminate inefficient and wasteful reporting."

Overview

FISMA 2014 codifies the Department of Homeland Security’s role in administering the implementation of information security policies for federal Executive Branch civilian agencies, overseeing agencies’ compliance with those policies, and assisting OMB in developing those policies.

The legislation provides the Department authority to develop and oversee the implementation of binding operational directives to other agencies, in coordination and consistent with OMB policies and practices. It also:

  • Authorizes DHS to provide operational and technical assistance to other federal Executive Branch civilian agencies at the agency’s request;
  • Places the federal information security incident center within DHS by law;
  • Authorizes DHS technology deployments to other agencies' networks (upon those agencies' request);
  • Directs OMB to revise policies regarding notification of individuals affected by federal agency data breaches;
  • Requires agencies to report major information security incidents as well as data breaches to Congress as they occur and annually; and
  • Simplifies existing FISMA reporting to eliminate inefficient or wasteful reporting while adding new reporting requirements for major information security incidents.
  • The Federal Information Security Modernization Act of 2014 amends the Federal Information Security Management Act of 2002 (FISMA).

Actions Taken by InEvent

InEvent ensures compliance with the Federal Information Security Modernization Act (FISMA) through a comprehensive approach to cybersecurity, aligning with federal standards for information security management.

InEvent follows strict security policies and procedures that adhere to guidance from the Office of Management and Budget (OMB) and the Department of Homeland Security (DHS). These include risk management strategies, data protection protocols, and incident response mechanisms that meet FISMA’s stringent requirements. In the event of a security breach or incident, InEvent has an incident management process in place, ensuring prompt reporting, mitigation, and compliance with FISMA’s mandate for notifying Congress and relevant authorities.

The platform also provides operational and technical support that aligns with DHS’s role in assisting federal agencies in cybersecurity. InEvent incorporates advanced encryption, access control, and real-time monitoring to help federal agencies safeguard their systems. Additionally, the platform enables continuous monitoring and risk assessments, ensuring compliance with FISMA’s emphasis on regular evaluations of system vulnerabilities and proactive security measures.

InEvent is committed to following binding operational directives issued by DHS, ensuring that its security practices meet federal standards for non-national security systems. Data privacy is a key focus, and InEvent complies with FISMA’s requirements for notifying affected individuals in the event of a data breach, providing clear and timely communication.

Finally, InEvent simplifies the reporting process for federal agencies, automating compliance reporting to meet FISMA standards. This reduces the burden of inefficient reporting while ensuring that all major incidents and compliance statuses are accurately reported in accordance with federal guidelines.

Governing Contracts

CISA Cyber Threats and Advisories

https://www.cisa.gov/topics/cyber-threats-and-advisories/federal-information-security-modernization-act

M-24-04 Fiscal Year 2024 Guidance on Federal Information Security and Privacy Management Requirements

https://www.whitehouse.gov/wp-content/uploads/2023/12/M-24-04-FY24-FISMA-Guidance.pdf

Die komplette Plattform für alle Ihre Veranstaltungen

Pedro Goes

goes@inevent.com

+1 470 751 3193

InEvent InEvent InEvent InEvent

Wir nutzen Cookies, um Ihr Website-Erlebnis zu verbessern und Ihnen auf unserer Plattform personalisierte Dienste anzubieten.

Um mehr über die von uns verwendeten Cookies zu erfahren, lesen Sie unsere Datenschutzrichtlinie.