EspañolPortuguês

IT Governance, Risk and Compliance Management

Solutions > Compliance Management > FISMA

FISMA

The Federal Information Security Management Act (FISMA) of 2002, approved by the U.S. Congress, requires federal organizations to implement comprehensive information and data security programs, with the purpose of identifying and solving IT failures and risks.

FISMA also requires federal organizations to send annual reports to the Office of Management and Budget (OMB) on the security situation of their IT departments, with the support and supervision of internal and external independent auditors.

The National Institute of Standards and Technology (NIST) is the organization responsible for defining the compliance process and for creating the security standards and controls established by FISMA. NIST periodically launches special publications with compliance instructions for federal organizations.

How can Modulo Risk Manager™ help your business?

  • Automating the application of the controls and specifications established by the NIST, including NIST 800-53 - Special Publication 800-53 - Recommended Security Controls for Federal Information Systems, which outlines the security protections that should be put in place in federal information systems. ;
  • Supplying managerial reports that allow assessment of the risk level to which the IT department is exposed;
  • Providing technical advice on implementation of the controls and minimization of security risks and failures - a permanently-updated knowledge base allows the dissemination of knowledge throughout the organization;
  • Automating the issue of reports to support planning of security actions;
  • Providing an action plan and action priorities, as defined in the "Plan of Action and Milestone" model - POA&M.
Modulo © Copyright - All rights reserved.