FISMA
FISMA: Coordination with FedRAMP, EO 14028, OMB Memoranda and Status

FISMA FISMA-Status-2024-2025: FISMA Status, 2024-2025 Modernization, OMB FISMA Report and Reform Proposals

FISMA status + 2024-2025 modernization + reform proposals. STATUS: FISMA 2014 (Public Law 113-283) remains in force; codified at 44 USC Chapter 35 Subchapter II; primary implementing documents OMB Circular A-130 + the annual OMB Memorandum on FISMA Reporting Guidance (M-24-04 most recent). ANNUAL FISMA REPORT: Joint OMB + DHS submission to Congress (typically February-April for the prior fiscal year); covers agency information security program effectiveness + maturity ratings + incidents + spending + emerging-threat coverage. 2024-2025 MODERNIZATION + REFORM: (a) FISMA 2.0 LEGISLATIVE PROPOSALS - bipartisan FISMA Reform Act of 2023 (Senator Peters / Senator Lankford) + 2024 reintroductions seeking to (i) elevate the National Cyber Director (NCD) authority; (ii) consolidate federal cybersecurity oversight; (iii) extend FISMA to civilian critical infrastructure beyond federal agencies; (iv) align with CIRCIA + the National Cybersecurity Strategy; (v) update incident-notification timelines + technical baselines; NOT enacted as of early 2026; (b) OMB M-24-04 FISMA REPORTING GUIDANCE: revised metrics + ZTA + AI + supply chain emphasis; (c) IG FISMA METRICS V2 (CIGIE 2024) - revised maturity-model assessment; (d) ANNUAL FISMA REPORT FY24 (April 2025) - the most recent published report; tracks federal cybersecurity posture + agency-by-agency scores. CRITICAL AREAS: ZTA implementation + AI safety + critical-infrastructure protection + cross-border data + ransomware + nation-state activity.

Maintained by Gerard BlokdykControl text last updated

Other controls in FISMA: Coordination with FedRAMP, EO 14028, OMB Memoranda and Status

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.