go to NIST home page go to CSRC home page go to Focus Areas page go to Publications page go to Advisories page go to Events page go to Site Map page go to ITL home page CSRC home page link
header image with links

Dept. of Commerce Building

CSRC Homepage
 
FISMA Homepage
 
FISMA NEWS
 
BACKGROUND
 
PROJECT PHASES
 
SCHEDULE
 
FAQs
 
RISK MANAGEMENT
FRAMEWORK

 
SECURITY
CATEGORIZATION

 
SECURITY
CONTROLS

 
ASSESSMENT
PROCEDURES

 
CERTIFICATION &
ACCREDITATION

 
SUPPORT TOOLS
& APPLICATIONS

 
INDUSTRIAL CONTROL
SYSTEM SECURITY

 
COMPLIANCE
 
LIBRARY
 
EVENTS
 
CONTACTS
 
MAILING
LIST

 

  FISMA Implementation Project

Protecting the Nation's Critical Information Infrastructure
 

Frequently Asked Questions
_____________________________

  • Is the Federal Information Security Management Act (FISMA) mentioned in the Federal Acquisition Regulations?
  • Yes. There is a strong reference to FISMA in the FAR. The FAR link is provided at: http://www.acquisition.gov/far. Page 7.1-2, FAR Section 7.103 states:

    "Agency-head responsibilities---
    The agency head or a designee shall prescribe procedures for ensuring that agency planners on information technology acquisitions comply with the information technology security requirements in the Federal Information Security Management Act (44 U.S.C. 3544), OMB’s implementing policies including Appendix III of OMB Circular A-130, and guidance and standards from the Department of Commerce’s National Institute of Standards and Technology."

    Therefore, the FAR points to FISMA, OMB Circular A-130, and the security standards and guidance developed by the National Institute of Standards and Technology at the Department of Commerce. The NIST security standards and guidance can be found on the Computer Security Division web site at http://csrc.nist.rip with specific information on the FISMA Implementation Project at http://csrc.nist.rip/sec-cert.

     

 

Last updated: December 29, 2006
Page created: December 29, 2006

Disclaimer Notice & Privacy Policy
Comments and suggestions should go to: sec-cert@nist.gov
NIST is an Agency of the U.S. Commerce Department's
Technology Administration