44 USC 3555 - Annual Independent Evaluation. EACH AGENCY MUST have an ANNUAL INDEPENDENT EVALUATION of agency information security program + practices by: (1) the AGENCY INSPECTOR GENERAL (IG) for non-NSS systems; OR (2) an INDEPENDENT EVALUATOR designated by the OMB + ed when an IG does not exist. EVALUATION SCOPE: agency-wide information security program effectiveness + selected agency systems (sample-based) + agency progress against PRIOR YEAR'S findings + Maturity-Model assessment against the IG FISMA Reporting Metrics (annually updated by the Council of Inspectors General on Integrity and Efficiency, CIGIE). MATURITY RATINGS: Level 1 Ad Hoc + Level 2 Defined + Level 3 Consistently Implemented + Level 4 Managed and Measurable + Level 5 Optimized. REPORTING: (a) the IG submits a report to the agency head; (b) the agency submits its FISMA REPORT to OMB + CISA via the CYBERSCOPE PORTAL (annual); (c) OMB submits a CONSOLIDATED FISMA REPORT TO CONGRESS via the Annual FISMA Report (Joint OMB + DHS submission since 2014); (d) summaries are made available to GAO + the public per FOIA. The annual report is a primary instrument of congressional + executive oversight + may trigger remediation requirements + funding implications.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.