Back to Frameworks
United States
v2014
7 domains
12 controls

FISMA is the Federal Information Security Modernization Act of 2014 (Public Law 113-283), amending the Federal Information Security Management Act of 2002 + codified at 44 USC Chapter 35 Subchapter II (sections 3551-3559). FISMA is the US federal statutory framework for information security applying to all federal agencies (excluding national-security systems covered separately) + contractors operating systems on behalf of federal agencies. STATUTORY STRUCTURE: (a) Section 3551 PURPOSES; (b) Section 3552 DEFINITIONS; (c) Section 3553 AUTHORITY AND FUNCTIONS OF THE DIRECTOR OF OMB + CISA (Cybersecurity and Infrastructure Security Agency, at DHS) including BINDING OPERATIONAL DIRECTIVES (BODs) for federal civilian agencies; (d) Section 3554 FEDERAL AGENCY RESPONSIBILITIES - including agency CIO + CISO designations + agency-wide information security programs + risk assessments + incident reporting; (e) Section 3555 ANNUAL INDEPENDENT EVALUATION by agency Inspector General (IG); (f) Section 3556 FEDERAL INFORMATION SECURITY INCIDENT CENTER (US-CERT now CISA); (g) Section 3557 NATIONAL SECURITY SYSTEMS (NSS) - exclusion from FISMA + governed separately by CNSS + Intelligence Community Directive 503; (h) Section 3558 EFFECT ON EXISTING LAW; (i) Section 3559 SAVINGS PROVISIONS. OPERATIONALISATION: FISMA is implemented through: (1) NIST SP 800-53 Rev 5 (Security and Privacy Controls - 1,189 controls) - VERIFIED separately in graph; (2) NIST SP 800-37 Rev 2 (Risk Management Framework - Categorize + Select + Implement + Assess + Authorize + Monitor); (3) NIST SP 800-171 Rev 3 (Protecting Controlled Unclassified Information in Nonfederal Systems) for contractor systems; (4) FIPS 199 (system categorization Low + Moderate + High); (5) FIPS 200 (minimum security requirements); (6) FedRAMP (Federal Risk and Authorization Management Program for cloud) - VERIFIED separately in graph as FedRAMP Moderate + High + Rev 5 Program reference; (7) CISA Binding Operational Directives (BODs - e.g. BOD 22-01 KEV Catalog, BOD 23-01 Asset Visibility, BOD 23-02 Internet-Accessible Networking Devices); (8) OMB Memoranda (M-22-09 Zero Trust + M-22-18 SBOM + M-24-15 FedRAMP modernization). 2024-2025 PRIORITIES: ZERO TRUST ARCHITECTURE per OMB M-22-09 + CISA Zero Trust Maturity Model v2 + the National Cybersecurity Strategy + CIRCIA Final Rule 2026 alignment.

Unverified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (7)

FISMA: Annual Independent Evaluation (IG Audit) and OMB FISMA Report

1 controls
Controls in the FISMA: Annual Independent Evaluation (IG Audit) and OMB FISMA Report domain of FISMA1 controls
CodeTitle
FISMA-3555-Annual-IG-EvaluationAnnual Independent Evaluation by Inspector General (44 USC 3555)

FISMA: Coordination with FedRAMP, EO 14028, OMB Memoranda and Status

5 controls
Controls in the FISMA: Coordination with FedRAMP, EO 14028, OMB Memoranda and Status domain of FISMA5 controls
CodeTitle
FISMA-Coord-NIST-CSF-ISO27001-SOC2Coordination with NIST CSF 2.0, ISO 27001, SOC 2 and Industry Frameworks
FISMA-FedRAMP-Cloud-CoordinationFedRAMP for Cloud Services + 800-37 ATO Integration
FISMA-Reform-PipelineFISMA 2.0 Reform Pipeline, Legislative Activity and Future State
FISMA-Status-2024-2025FISMA Status, 2024-2025 Modernization, OMB FISMA Report and Reform Proposals
FISMA-Status-RefArchitectureFISMA-Status-Reference-Architecture - Operationalisation Map

FISMA: Federal Agency Responsibilities (CIO, CISO, Program, Reporting)

1 controls
Controls in the FISMA: Federal Agency Responsibilities (CIO, CISO, Program, Reporting) domain of FISMA1 controls
CodeTitle
FISMA-3554-Agency-ResponsibilitiesFederal Agency Responsibilities (44 USC 3554) - CIO + CISO + Program + Reporting

FISMA: National Security Systems Exclusion + CIRCIA + Zero Trust

2 controls
Controls in the FISMA: National Security Systems Exclusion + CIRCIA + Zero Trust domain of FISMA2 controls
CodeTitle
FISMA-3556-FederalCIRC-3557-NSSFederal Information Security Incident Center (44 USC 3556) + National Security Systems Exclusion (44 USC 3557)
FISMA-CIRCIA-ZTA-EO14028CIRCIA, Zero Trust Architecture, EO 14028 + 14110 + OMB Memoranda

FISMA: OMB + CISA Authority + Binding Operational Directives

1 controls
Controls in the FISMA: OMB + CISA Authority + Binding Operational Directives domain of FISMA1 controls
CodeTitle
FISMA-3553-OMB-CISA-BODOMB and CISA Authority and Binding Operational Directives (44 USC 3553)

FISMA: Operationalisation via NIST 800-53 RMF + 800-171 + FIPS 199/200

1 controls
Controls in the FISMA: Operationalisation via NIST 800-53 RMF + 800-171 + FIPS 199/200 domain of FISMA1 controls
CodeTitle
FISMA-NIST-800-53-RMF-800-171-FIPSOperationalisation via NIST 800-53 + 800-37 RMF + 800-171 + FIPS 199 + FIPS 200

FISMA: Statutory Structure (44 USC 3551-3559) and Definitions

1 controls
Controls in the FISMA: Statutory Structure (44 USC 3551-3559) and Definitions domain of FISMA1 controls
CodeTitle
FISMA-3551-3552-Purposes-DefsPurposes and Definitions (44 USC 3551-3552)

Your Compliance Coverage

If you comply with FISMA, you already cover:

Maps to 99 other frameworks

12 total controls
BSI IT-Grundschutz
3 source controls mapped|20 target controls covered
25%
Vietnam Law on Cybersecurity (No. 24/2018/QH14)
3 source controls mapped|2 target controls covered
25%
Vermont Artificial Intelligence and Consumer Data Act (AICDA)
3 source controls mapped|2 target controls covered
25%
US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule
3 source controls mapped|3 target controls covered
25%
US EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements
3 source controls mapped|1 target controls covered
25%
UK Defence Standard 05-138 - Cyber Security for Defence Suppliers
3 source controls mapped|1 target controls covered
25%
TEFCA - Trusted Exchange Framework and Common Agreement
3 source controls mapped|1 target controls covered
25%
Protective Security Policy Framework (PSPF) Release 2024
3 source controls mapped|3 target controls covered
25%
Privacy Act 1988 (Australia)
3 source controls mapped|3 target controls covered
25%
PCAOB AS 2201 - Audit of Internal Control Over Financial Reporting (ICFR)
3 source controls mapped|2 target controls covered
25%
OWASP Top 10:2025
3 source controls mapped|6 target controls covered
25%
OWASP DevSecOps Maturity Model (DSOMM)
3 source controls mapped|5 target controls covered
25%
OWASP API Security Top 10 - 2023
3 source controls mapped|4 target controls covered
25%
Ley Orgánica de Protección de Datos Personales (LOPDP)
3 source controls mapped|2 target controls covered
25%
Law No. 172-13 on the Protection of Personal Data
3 source controls mapped|2 target controls covered
25%
South Korea PIPA
3 source controls mapped|1 target controls covered
25%
India DPDP Act
3 source controls mapped|3 target controls covered
25%
India CERT-In Cyber Security Directions 2022
3 source controls mapped|1 target controls covered
25%
HKMA Cyber Resilience Assessment Framework (C-RAF)
3 source controls mapped|3 target controls covered
25%
Florida Digital Bill of Rights (FDBR)
3 source controls mapped|1 target controls covered
25%
ISO/IEC 30111:2019
3 source controls mapped|4 target controls covered
25%
ISO/IEC 29147:2018
3 source controls mapped|5 target controls covered
25%
ISO/IEC 27400:2022
3 source controls mapped|5 target controls covered
25%
APRA CPS 230 Operational Risk Management
3 source controls mapped|3 target controls covered
25%
Azure Security Benchmark
3 source controls mapped|12 target controls covered
25%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
3 source controls mapped|13 target controls covered
25%
Annex 11 to EU GMP - Computerised Systems
3 source controls mapped|5 target controls covered
25%
AWS Well-Architected Security Pillar
3 source controls mapped|12 target controls covered
25%
API 1164
3 source controls mapped|12 target controls covered
25%
ISO/IEC 27010:2015
3 source controls mapped|5 target controls covered
25%
ASD Strategies to Mitigate Cyber Security Incidents
3 source controls mapped|11 target controls covered
25%
ISO/IEC 27557:2022 - Organisational Privacy Risk Management
3 source controls mapped|3 target controls covered
25%
FFIEC Cybersecurity Assessment Tool (CAT)
3 source controls mapped|9 target controls covered
25%
NIST AI Risk Management Framework (AI RMF 1.0)
3 source controls mapped|3 target controls covered
25%
Barbados Data Protection Act 2019
3 source controls mapped|1 target controls covered
25%
Bahrain PDPL
3 source controls mapped|5 target controls covered
25%
APPI
3 source controls mapped|5 target controls covered
25%
25%
AML/CTF Act 2006 (Australia)
3 source controls mapped|2 target controls covered
25%
Canada ITSG-33 - IT Security Risk Management
3 source controls mapped|1 target controls covered
25%
ISO/IEC 29134:2023
3 source controls mapped|4 target controls covered
25%
ISO/IEC 27031:2011
3 source controls mapped|1 target controls covered
25%
ASIS SPC.1-2009 - Organizational Resilience Standard
3 source controls mapped|2 target controls covered
25%
ISO/IEC 27014:2020
3 source controls mapped|2 target controls covered
25%
FBI CJIS Security Policy
3 source controls mapped|4 target controls covered
25%
OWASP ASVS
2 source controls mapped|7 target controls covered
17%
MITRE D3FEND
2 source controls mapped|3 target controls covered
17%
HL7 FHIR Security Framework
2 source controls mapped|3 target controls covered
17%
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
2 source controls mapped|8 target controls covered
17%
ISO/IEC 27011:2024
2 source controls mapped|6 target controls covered
17%
ISO/IEC 29115:2023 - Entity Authentication Assurance Framework
2 source controls mapped|4 target controls covered
17%
IEC 62351 - Power Systems Communication Security
2 source controls mapped|3 target controls covered
17%
FIDO2 / WebAuthn
2 source controls mapped|1 target controls covered
17%
ISO 19011
2 source controls mapped|4 target controls covered
17%
17%
ISO/IEC 23837 - Security Requirements for Quantum Key Distribution
2 source controls mapped|4 target controls covered
17%
Singapore Cybersecurity Act 2018
2 source controls mapped|1 target controls covered
17%
Pakistan Personal Data Protection Bill 2023
2 source controls mapped|1 target controls covered
17%
NIST SP 800-171
2 source controls mapped|2 target controls covered
17%
APRA CPS 234
2 source controls mapped|5 target controls covered
17%
FFIEC IT Examination Handbook
2 source controls mapped|5 target controls covered
17%
COSO Internal Control - Integrated Framework (2013)
2 source controls mapped|1 target controls covered
17%
AS9100D:2016 - Quality Management Systems for Aviation, Space, and Defence
2 source controls mapped|2 target controls covered
17%
AS9100D - Aerospace Quality Management System
2 source controls mapped|1 target controls covered
17%
ISO/IEC 27003:2017
2 source controls mapped|1 target controls covered
17%
USMCA Chapter 19 - Digital Trade (United States-Mexico-Canada Agreement)
1 source controls mapped|1 target controls covered
8%
Tennessee Information Protection Act (TIPA)
1 source controls mapped|1 target controls covered
8%
SWIFT CSCF
1 source controls mapped|1 target controls covered
8%
Regulation on the European Health Data Space (EHDS)
1 source controls mapped|1 target controls covered
8%
Russia Federal Law on Personal Data (152-FZ)
1 source controls mapped|1 target controls covered
8%
MiFID II / MiFIR
1 source controls mapped|1 target controls covered
8%
ICAO Annex 17 - Aviation Security (AVSEC)
1 source controls mapped|2 target controls covered
8%
Illinois Biometric Information Privacy Act (BIPA)
1 source controls mapped|2 target controls covered
8%
DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition)
1 source controls mapped|2 target controls covered
8%
Bank Secrecy Act / Anti-Money Laundering (BSA/AML)
1 source controls mapped|1 target controls covered
8%
ISO 13485
1 source controls mapped|1 target controls covered
8%
Armenia Law on Protection of Personal Data (2015)
1 source controls mapped|1 target controls covered
8%
US NRC 10 CFR 73.54 - Cyber Security for Nuclear Power Plants
1 source controls mapped|1 target controls covered
8%
NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205)
1 source controls mapped|1 target controls covered
8%
ICH E6(R3) - Good Clinical Practice
1 source controls mapped|1 target controls covered
8%
FDA Quality Management System Regulation (QMSR)
1 source controls mapped|1 target controls covered
8%
21 CFR Part 211 - Current Good Manufacturing Practice
1 source controls mapped|3 target controls covered
8%
ISO 31000:2018
1 source controls mapped|2 target controls covered
8%
IEC 60601-1 - Medical Electrical Equipment Safety
1 source controls mapped|1 target controls covered
8%
ISO 27005
1 source controls mapped|1 target controls covered
8%
ISO 20000-1
1 source controls mapped|1 target controls covered
8%
UAE Virtual Asset Regulatory Authority (VARA) Regulations
1 source controls mapped|1 target controls covered
8%
ISO/IEC 27006:2024
1 source controls mapped|1 target controls covered
8%
Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018)
1 source controls mapped|1 target controls covered
8%
FedRAMP High
1 source controls mapped|1 target controls covered
8%
NIST SP 800-53 Revision 5.1 HIGH
1 source controls mapped|1 target controls covered
8%
FedRAMP Moderate
1 source controls mapped|1 target controls covered
8%

Frequently Asked Questions

What is FISMA?

FISMA is a compliance framework from United States with 7 domains and 12 controls. FISMA is the Federal Information Security Modernization Act of 2014 (Public Law 113-283), amending the Federal Information Security Management Act of 2002 + codified at 44 USC Chapter 35 Subchapter II (sections 3551-3559). FISMA is the US federal statutory framework for information security applying to all federal agencies (excluding national-security systems covered separately) + contractors operating systems on behalf of federal agencies. STATUTORY STRUCTURE: (a) Section 3551 PURPOSES; (b) Section 3552 DEFINITIONS; (c) Section 3553 AUTHORITY AND FUNCTIONS OF THE DIRECTOR OF OMB + CISA (Cybersecurity and Infrastructure Security Agency, at DHS) including BINDING OPERATIONAL DIRECTIVES (BODs) for federal civilian agencies; (d) Section 3554 FEDERAL AGENCY RESPONSIBILITIES - including agency CIO + CISO designations + agency-wide information security programs + risk assessments + incident reporting; (e) Section 3555 ANNUAL INDEPENDENT EVALUATION by agency Inspector General (IG); (f) Section 3556 FEDERAL INFORMATION SECURITY INCIDENT CENTER (US-CERT now CISA); (g) Section 3557 NATIONAL SECURITY SYSTEMS (NSS) - exclusion from FISMA + governed separately by CNSS + Intelligence Community Directive 503; (h) Section 3558 EFFECT ON EXISTING LAW; (i) Section 3559 SAVINGS PROVISIONS. OPERATIONALISATION: FISMA is implemented through: (1) NIST SP 800-53 Rev 5 (Security and Privacy Controls - 1,189 controls) - VERIFIED separately in graph; (2) NIST SP 800-37 Rev 2 (Risk Management Framework - Categorize + Select + Implement + Assess + Authorize + Monitor); (3) NIST SP 800-171 Rev 3 (Protecting Controlled Unclassified Information in Nonfederal Systems) for contractor systems; (4) FIPS 199 (system categorization Low + Moderate + High); (5) FIPS 200 (minimum security requirements); (6) FedRAMP (Federal Risk and Authorization Management Program for cloud) - VERIFIED separately in graph as FedRAMP Moderate + High + Rev 5 Program reference; (7) CISA Binding Operational Directives (BODs - e.g. BOD 22-01 KEV Catalog, BOD 23-01 Asset Visibility, BOD 23-02 Internet-Accessible Networking Devices); (8) OMB Memoranda (M-22-09 Zero Trust + M-22-18 SBOM + M-24-15 FedRAMP modernization). 2024-2025 PRIORITIES: ZERO TRUST ARCHITECTURE per OMB M-22-09 + CISA Zero Trust Maturity Model v2 + the National Cybersecurity Strategy + CIRCIA Final Rule 2026 alignment. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does FISMA have?

FISMA has 12 controls organised across 7 domains. The largest domains are FISMA: Coordination with FedRAMP, EO 14028, OMB Memoranda and Status (5 controls), FISMA: National Security Systems Exclusion + CIRCIA + Zero Trust (2 controls), FISMA: Annual Independent Evaluation (IG Audit) and OMB FISMA Report (1 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does FISMA map to?

FISMA maps to 99 other compliance frameworks. The top mapping partners are BSI IT-Grundschutz (25% coverage), Vietnam Law on Cybersecurity (No. 24/2018/QH14) (25% coverage), Vermont Artificial Intelligence and Consumer Data Act (AICDA) (25% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with FISMA compliance?

Start your FISMA compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about FISMA requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 12 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.

Get Started Free →

Free forever — no credit card required