Federal Information Security Management Act (FISMA)
FISMA is a United States federal law that requires government agencies to establish programs to protect their information and information systems against security threats. It also extends to organizations that create, store, or access sensitive government data on behalf of a federal agency. Because it is legislation rather than a voluntary standard, covered entities are legally obligated to comply.
FISMA is U.S. federal legislation, originally enacted as the Federal Information Security Management Act of 2002 and subsequently updated by the Federal Information Security Modernization Act of 2014, that establishes a framework of guidelines and security standards for protecting federal government information, operations, and assets. FISMA 2002 requires each federal agency to develop, document, and implement an agency-wide information security program, and its obligations generally extend to contractors and other entities handling information on behalf of a federal agency. It is a binding U.S. federal law, distinct from voluntary frameworks; note that the associated implementation guidance and control standards (developed through the NIST Risk Management Framework) are periodically revised, and readers should verify the current statutory text and applicable NIST publications against authoritative sources. Application to particular systems or organizations depends on facts such as the sensitivity of the data and the nature of any federal relationship, and requires professional judgment.
Why it matters
FISMA establishes information security as a legal obligation rather than a discretionary practice for United States federal agencies. Because it is binding federal legislation and not a voluntary standard, agencies covered by it must develop, document, and implement agency-wide programs to protect government information and information systems. This distinction matters: unlike frameworks that an organization may adopt at its discretion, FISMA imposes statutory duties, and the associated implementation guidance—developed through the NIST Risk Management Framework—shapes how those duties are met in practice.
FISMA's reach extends beyond agencies themselves. Its obligations generally apply to contractors and other entities that create, store, or access sensitive government data on behalf of a federal agency. For private-sector organizations, this means that entering into certain federal relationships can bring their systems within scope, so understanding whether FISMA applies is often a threshold question in federal contracting and data-handling arrangements.
The statute has evolved over time. The original Federal Information Security Management Act of 2002 was updated by the Federal Information Security Modernization Act of 2014, which revised federal cybersecurity practices. Both the statutory text and the applicable NIST publications are periodically revised, so covered entities should verify current requirements against authoritative sources rather than treating any single description as fixed.
Who it's relevant to
Inside FISMA
Common questions
Answers to the questions practitioners most commonly ask about FISMA.
