FISMA
FISMA: Coordination with FedRAMP, EO 14028, OMB Memoranda and Status

FISMA FISMA-Status-RefArchitecture: FISMA-Status-Reference-Architecture - Operationalisation Map

FISMA Reference Architecture - operationalisation map across the federal cyber regime. (a) STATUTORY AUTHORITY = FISMA 2014 (44 USC 3551-3559) + Public Law 113-283; (b) POLICY OVERSIGHT = OMB Circular A-130 + OMB Memoranda; (c) AGENCY-LEVEL = Agency Head + CIO + CISO + Senior Agency Official for Privacy (SAOP); (d) GOVERNMENT-WIDE OVERSIGHT = OMB Director + CISA Director + NCD + NSC Cyber Director; (e) STANDARDS DEVELOPMENT = NIST (SP 800-53 + 800-37 + 800-171 + 800-218 SSDF + FIPS 199/200/140) + CNSS (national security systems); (f) CLOUD AUTHORIZATION = FedRAMP PMO + JAB + Agency ATOs + 3PAO assessment + Marketplace; (g) INCIDENT RESPONSE = CISA US-CERT (federal civilian) + CYBERCOM (DOD) + IC-CIRC (intelligence community); (h) BINDING DIRECTIVES = CISA BODs (mandatory) + EDs (Emergency Directives); (i) AUDIT + EVALUATION = Agency IGs + CIGIE + GAO + Congressional oversight; (j) PARTNERSHIPS = sector ISACs + state + local + tribal (CISA SLTT) + international (CSIRTs Network + ENISA + Five Eyes + Quad). The Reference Architecture is dynamic + evolves through OMB Memoranda + EOs + CISA BODs + NIST publications + agency-specific policies. Agencies must operate within this ecosystem + maintain situational awareness of policy updates + standards revisions + threat-environment changes.

Maintained by Gerard BlokdykControl text last updated

Other controls in FISMA: Coordination with FedRAMP, EO 14028, OMB Memoranda and Status

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.