The Federal Information Security Management Act (FISMA) of 2002, approved by the U.S. Congress, requires federal organizations to implement comprehensive information and data security programs, with the purpose of identifying and solving IT failures and risks.
FISMA also requires federal organizations to send annual reports to the Office of Management and Budget (OMB) on the security situation of their IT departments, with the support and supervision of internal and external independent auditors.
The National Institute of Standards and Technology (NIST) is the organization responsible for defining the compliance process and for creating the security standards and controls established by FISMA. NIST periodically launches special publications with compliance instructions for federal organizations.
Microsoft
"Modulo Risk Manager was used as a solution to speed up our risk assessments."