FISMA
The Federal Information Security Modernization Act of 2014 — the statutory authority a federal RFP names, implemented operationally through NIST SP 800-53 and the NIST Cybersecurity Framework, both already tracked as their own registry entries.
Federal Information Security Modernization Act of 2014 · Cybersecurity and Infrastructure Security Agency · published 2014-12-18
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
FISMA is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
Statutory authority only; implemented through NIST SP 800-53 and the NIST Cybersecurity Framework, both already tracked separately. No FISMA-specific control catalog exists to ingest.
02Registry record
- Registry status
- Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Agency information security programs · OMB oversight · Annual independent evaluation · Incident reporting
- Applies to
- federal · federal contractors · US
- Verification
- Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-09-06
- Pending change
- No modernization bill has passed since 2014. A 2023 reform bill advanced through Senate committee markup but did not become law; no equivalent bill has been tracked in the current Congress as of this check.Expected: No pending legislation identified
03Version ledger
| Federal Information Security Management Act of 2002 | Superseded | 2002-12-17 |
| Federal Information Security Modernization Act of 2014 | Current edition · supersedes Federal Information Security Management Act of 2002 | 2014-12-18 |
05Change history
06Related frameworks
- GAO Green Book2025 Revision
Also applies to federal · The federal internal-control standard for designing, implementing, operating, and evaluating controls over operations, reporting, and compliance. It supplies auditable criteria for federal entities; it is not an organizational certification.
- ARC-AMPEv1.02
Also applies to federal · CMS's NIST-aligned security and privacy framework for ACA administering entities and applicable partner entities. Volume II supplies tailored control baselines and system security and privacy plan templates; applicability depends on entity type, law, regulation, or contract.
- GAO FISCAMJune 2026 (GAO-26-108633)
Also applies to federal · The federal audit methodology for assessing the design, implementation, and operating effectiveness of information-system controls under generally accepted government auditing standards. It is audit guidance, not an agency authorization or certification.
- NIST SP 800-171Rev. 3
Also applies to federal contractors · NIST's current recommended security requirements for Controlled Unclassified Information in non-federal systems. Contractual applicability is agreement-specific; CMMC Phase I continues to use Rev. 2 rather than automatically inheriting Rev. 3.