FISMA
FISMA: Federal Agency Responsibilities (CIO, CISO, Program, Reporting)

FISMA FISMA-3554-Agency-Responsibilities: Federal Agency Responsibilities (44 USC 3554) - CIO + CISO + Program + Reporting

44 USC 3554 - Federal Agency Responsibilities. EACH AGENCY HEAD must: (a) ensure compliance with FISMA + with policies + procedures + standards developed by OMB + CISA + NIST + CNSS; (b) DESIGNATE A SENIOR INFORMATION SECURITY OFFICIAL (the CIO + with CISO support); (c) ensure that the AGENCY CHIEF INFORMATION SECURITY OFFICER (CISO) + AGENCY CHIEF INFORMATION OFFICER (CIO) work in COORDINATION on information security program execution; (d) develop + maintain an AGENCY-WIDE INFORMATION SECURITY PROGRAM including: (i) RISK ASSESSMENTS of agency information systems; (ii) POLICIES + PROCEDURES based on the risk assessments + that cost-effectively reduce risks; (iii) plans for providing adequate information security for networks + facilities + information systems + groups of information systems; (iv) SECURITY AWARENESS TRAINING for all personnel; (v) PERIODIC TESTING + EVALUATION of effectiveness of information security policies + procedures + practices including controls testing + management testing + operational testing + technical testing (typically at least annually + after significant change); (vi) PROCESS for planning + implementing + evaluating + documenting REMEDIAL ACTION (POA&M - Plan of Action and Milestones) to address deficiencies; (vii) INCIDENT REPORTING per Section 3556 + the Federal Incident Notification Guidelines (1-hour notification for high-severity + 4-hour for lesser-severity); (viii) PLANS for INFORMATION SECURITY CONTINUITY OF OPERATIONS for systems supporting agency operations + assets; (ix) PROCEDURES for detecting + reporting + responding to security incidents; (x) ENSURE that contractors operating systems on behalf of the agency comply with FISMA + NIST SP 800-171; (xi) PROVIDE AN ANNUAL REPORT to Congress + OMB + CISA + GAO on the agency information security program.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.