FISMA
FISMA: National Security Systems Exclusion + CIRCIA + Zero Trust

FISMA FISMA-CIRCIA-ZTA-EO14028: CIRCIA, Zero Trust Architecture, EO 14028 + 14110 + OMB Memoranda

FISMA coordination with CIRCIA + Zero Trust + Executive Orders + OMB Memoranda. CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act of 2022): Final Rule effective 2026; expands incident reporting beyond FISMA-covered agencies to CRITICAL INFRASTRUCTURE entities; covered entities must report cyber incidents within 60 HOURS + ransom payments within 24 HOURS; supervised by CISA. ZERO TRUST ARCHITECTURE (ZTA): OMB MEMORANDUM M-22-09 (January 2022) - Moving the US Government Toward Zero Trust Cybersecurity Principles - sets federal Zero Trust strategy + 5 pillars (Identity + Devices + Network + Applications + Data) + mandates FY24 ZTA targets + 2024 ZTA STRATEGY update; CISA ZERO TRUST MATURITY MODEL v2 (2023) + provides 5-pillar + 3-maturity-level framework; phishing-resistant authentication mandatory; least-privilege + micro-segmentation expected. EXECUTIVE ORDERS: EO 14028 (May 2021 Improving the Nation Cybersecurity) - federal SBOM + Zero Trust + EDR + cloud security baselines; EO 14110 (October 2023 AI Executive Order - revoked January 2025 + replaced by 2025 EO on AI in Government) - federal AI safety + bias testing + watermarking + critical-infrastructure-AI; EO 14117 (February 2024 Cross-Border Data Transfer) - restrictions on data flows to countries of concern. OMB MEMORANDA: M-22-09 ZTA; M-22-18 SBOM Producer Attestation; M-23-02 Cybersecurity Information Sharing; M-24-15 FedRAMP Modernization; M-24-04 Annual FISMA Reporting Guidance.

What else in your programme already covers this

This control maps to 196 controls across 73 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

BSI IT-Grundschutz · 9 controls

  • BSI-01 Account management and provisioning
  • BSI-02 Access enforcement and least privilege
  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions
  • BSI-13 Risk assessment procedures
  • BSI-14 Vulnerability scanning and management
  • BSI-15 Security categorization
  • BSI-17 Continuous monitoring strategy

ISO/IEC 29147:2018 · 5 controls

API 1164 · 4 controls

ISO/IEC 29134:2023 · 4 controls

  • 3.10 Encrypt Sensitive Data in Transit
  • 3.11 Encrypt Sensitive Data at Rest
  • 3.7 Establish and Maintain a Data Classification Scheme
  • 3.7.1 Key-management policies and procedures are implemented to include generation of strong cryptographic keys used to protect stored account data

OWASP Top 10:2025 · 4 controls

  • ASD37-18 Restrict administrative privileges (Essential)
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-23 Protect authentication credentials (Excellent)

ISO/IEC 27011:2024 · 3 controls

ISO/IEC 30111:2019 · 3 controls

  • OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA
  • OWASPAPI-2 Broken Authentication and Token Management
  • OWASPAPI-3 Broken Object Property Level Authorization (BOPLA)

OWASP ASVS · 3 controls

  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing
  • CH-FADP-15 Cooperation with the FDPIC
  • CH-FADP-21 Data protection impact assessments
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)

Bahrain PDPL · 2 controls

  • 6.4 Logging and Monitoring
  • 6.5 Preparing and Distributing Audit Report

ISO 19011 · 2 controls

  • 6.4 Logging and Monitoring
  • 6.5 Preparing and Distributing Audit Report

ISO/IEC 27010:2015 · 2 controls

ISO/IEC 27014:2020 · 2 controls

India DPDP Act · 2 controls

  • ASTWO-1 Audit Planning, Scaling, Risk Assessment, and Integration
  • ASTWO-3 Entity-Level Controls and Period-End Financial Reporting Process
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • PSPF24-4 Physical Security
  • 2.4.4 Hazard Analysis and Risk Assessment
  • 2.7.2 Food Fraud Plan
  • CRM-1 AML/CFT Compliance
  • CRM-4 Business Risk Assessment

APPI · 1 control

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • CPS230-11 Identification, Assessment and Management of Operational Risk
  • 4.3.1 Risk Assessment and Impact Analysis
  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities

FIDO2 / WebAuthn · 1 control

  • 62351-8 Role-based access control (RBAC)

ISO 13485 · 1 control

  • 6.4 Logging and Monitoring
  • 23837-1.7.3 Authentication and classical post-processing

ISO/IEC 27031:2011 · 1 control

ISO/IEC 27400:2022 · 1 control

MITRE D3FEND · 1 control

MiFID II / MiFIR · 1 control

  • RUSPD-2 Lawful Basis, Consent, Notice

SWIFT CSCF · 1 control

South Korea PIPA · 1 control

  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • USMCADIGITAL-2 Personal Information Protection and Consumer Protection

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in FISMA: National Security Systems Exclusion + CIRCIA + Zero Trust

Query this from an agent

The graph holds this control, the 196 it maps to, and the evidence behind each claim, over MCP and REST.