While many agencies struggle to comply with Federal Information Security Management Act (FISMA) regulations, those that have embraced its requirements have found that their comprehensive and flexible nature provides a sound security risk management framework for the implementation of essential system security controls. Detailing a proven appro
Introduction. Analysis of the Federal Information Security Management Act (FISMA). Principles of FISMA Reporting. Managing FISMA Compliance. Management Support. The Information Security Organization. Staffing Considerations. Program Planning. Developing Policy and Guidance. Training and Awareness. Audit Liaison. Monitoring Mechanisms. Life-Cycle Issues. Outreach. Summary. Appendices: The FISMA Legislation. OMB FISMA Reporting Guidelines. OMB FISMA FY10 Reporting Questionnaires. Consensus Audit Guidelines. Bibliography. Index.