Federal Information Security Management Act of 2002

Federal Information Security Management Act of 2002
Great Seal of the United States
Long titleAn Act to strengthen Federal Government information security, including through the requirement for the development of mandatory information security risk management standards.
Acronyms (colloquial)FISMA
NicknamesE-Government Act of 2002
Enacted bythe 107th United States Congress
EffectiveDecember 17, 2002
Citations
Public law107-347
Statutes at Large116 Stat. 2899 aka 116 Stat. 2946
Codification
Titles amended
U.S.C. sections created44 U.S.C. ch. 35, subch. III § 3541 et seq.
U.S.C. sections amended
Legislative history
Major amendments
Replaced by the Federal Information Security Modernization Act of 2014

The Federal Information Security Management Act of 2002 (FISMA, 44 U.S.C. § 3541, et seq.) is a United States federal law enacted in 2002 as Title III of the E-Government Act of 2002 (Pub. L. 107–347 (text) (PDF), 116 Stat. 2899). The act recognized the importance of information security to the economic and national security interests of the United States.[1] The act requires each federal agency to develop, document, and implement an agency-wide program to provide information security for the information and information systems that support the operations and assets of the agency, including those provided or managed by another agency, contractor, or other source.[1]

FISMA has brought attention within the federal government to cybersecurity and explicitly emphasized a "risk-based policy for cost-effective security."[1] FISMA requires agency program officials, chief information officers, and inspectors general (IGs) to conduct annual reviews of the agency's information security program and report the results to Office of Management and Budget (OMB). OMB uses this data to assist in its oversight responsibilities and to prepare this annual report to Congress on agency compliance with the act.[2] In FY 2008, federal agencies spent $6.2 billion securing the government's total information technology investment of approximately $68 billion or about 9.2 percent of the total information technology portfolio.[3] This law has been amended by the Federal Information Security Modernization Act of 2014 (Pub. L. 113–283 (text) (PDF)), sometimes known as FISMA2014 or FISMA Reform. FISMA2014 struck subchapters II and III of chapter 35 of title 44, United States Code, amending it with the text of the new law in a new subchapter II (44 U.S.C. § 3551).

  1. ^ a b c "NIST: FISMA Overview". Csrc.nist.gov. Retrieved April 27, 2012.
  2. ^ FY 2005 Report to Congress on Implementation of The Federal Information Security Management Act of 2002
  3. ^ FY 2008 Report to Congress on Implementation of The Federal Information