Federal Information Security Management Act (Fisma)
About Fisma the Federal Information Security Management Act of 2002 (Fisma) Is a Law Requiring Protection of the Sensitive Data Created, Stored, or Accessed by...
About FISMA
The Federal Information Security Management Act of 2002 (FISMA) is a law requiring protection of the sensitive data created, stored, or accessed by the Federal Government or any entity on behalf of the Federal Government. The law established a formal Certification and Accreditation (C&A) process that requires a minimum set of security controls and a formal audit prior to obtaining an "Authority to Operate", or ATO. In April 2010, the Office of Management and Budget issued a Memorandum requiring each Federal Agency to report its FISMA activities to Congress. This memo also reiterated the requirement that Agencies include FISMA requirements in ALL contracts involving sensitive data, as well as grants where sensitive information is created, accessed, or stored on behalf of the Federal Government. Compliance with FISMA may be a requirement of a government contract and possibly a grant. The FISMA process recognizes that not all sensitive information has the same level of risk and has identified three security categories to identify systems: Low, Moderate, and High.
Guidance Statement
In the course of preparing grant applications or conducting a sponsored project, Dartmouth's faculty, staff and students may plan to collect information that may include both academic, research, protected health or personal related data. Dartmouth and its employees, under U.S federal and state data privacy and security laws, have an obligation to implement appropriate safeguards to protect such confidential information residing both inside and outside of the United States. For a particular sponsored project, there may be requirements placed by external entities on the use of their data and data sets for the protection of human subject research. In addition, certain funding announcements may include complex terms such as Federal Information Security Management Act (FISMA), NIST 800-53, and the Family Educational Rights and Privacy Act (FERPA).