CAP Federal Information Security Laws, Policies & the Legislative Framework — Questions and Answers
Question 1: Which U.S. federal law established the requirement for federal agencies to develop, document, and implement an information security program, and made NIST responsible for developing security standards and guidelines?
- The Computer Fraud and Abuse Act (CFAA) of 1986
- The Federal Information Security Management Act (FISMA) of 2002 (Correct answer)
- The Sarbanes-Oxley Act (SOX) of 2002
- The Gramm-Leach-Bliley Act (GLBA) of 1999
Correct answer: The Federal Information Security Management Act (FISMA) of 2002
FISMA 2002 (part of the E-Government Act) is the foundational federal law requiring agencies to implement agency-wide information security programs. It mandated NIST to develop standards (FIPS) and guidelines (SP 800-series) for federal information security.
Question 2: The Federal Information Security Modernization Act (FISMA) of 2014 made which significant change to the original 2002 law?
- It removed the requirement for annual security assessments.
- It shifted FISMA oversight from OMB to DHS for operational civilian agency oversight, and emphasized continuous monitoring over periodic assessments. (Correct answer)
- It made NIST standards optional rather than mandatory for federal agencies.
- It extended FISMA requirements to all private sector companies with federal contracts.
Correct answer: It shifted FISMA oversight from OMB to DHS for operational civilian agency oversight, and emphasized continuous monitoring over periodic assessments.
FISMA 2014 modernized the 2002 law by giving DHS a more active role in operational oversight of civilian agencies (while OMB retained policy authority), strengthening continuous monitoring requirements, and increasing incident reporting obligations — reflecting the shift away from compliance-driven point-in-time assessments.
Question 3: OMB Circular A-130 is significant to the CAP domain because it:
- Establishes the federal budget process for IT security spending.
- Sets policy for managing federal information resources and requires agencies to implement NIST-based security controls. (Correct answer)
- Defines the minimum clearance level required for federal IT security personnel.
- Mandates specific penetration testing frequencies for all federal systems.
Correct answer: Sets policy for managing federal information resources and requires agencies to implement NIST-based security controls.
OMB Circular A-130 ('Managing Information as a Strategic Resource') establishes government-wide policy for the management of federal information resources, including a requirement to implement security controls consistent with NIST standards. It is the policy backbone that makes the RMF mandatory for federal civilian agencies.
Question 4: Under FISMA, which official has the authority to grant an Authorization to Operate (ATO) for a federal information system?
- The Chief Information Officer (CIO)
- The Information System Security Officer (ISSO)
- The Authorizing Official (AO), also known as the Designated Accrediting Authority (DAA) (Correct answer)
- The Director of the Office of Management and Budget (OMB)
Correct answer: The Authorizing Official (AO), also known as the Designated Accrediting Authority (DAA)
The Authorizing Official (AO) — historically called the Designated Accrediting Authority (DAA) — is the senior federal official with the authority and accountability to grant an ATO. The AO accepts the residual risk of operating a system based on the authorization package and current security posture.
Question 5: Which federal agency is responsible for developing mandatory standards (FIPS) and voluntary guidelines (SP 800-series) for federal information systems under FISMA?
- The Department of Homeland Security (DHS)
- The Office of Management and Budget (OMB)
- The National Institute of Standards and Technology (NIST) (Correct answer)
- The Government Accountability Office (GAO)
Correct answer: The National Institute of Standards and Technology (NIST)
FISMA explicitly tasks NIST with developing FIPS (Federal Information Processing Standards, which are mandatory) and Special Publications in the 800-series (which are guidelines). DHS handles operational oversight; OMB handles policy; GAO audits compliance — but only NIST creates the technical standards.
Question 6: A federal contractor operating an information system that processes, stores, or transmits federal data on behalf of a federal agency is subject to FISMA requirements under which mechanism?
- Contractors are never subject to FISMA — it applies only to federal employees.
- The federal agency includes FISMA and NIST control requirements in the contract, making the contractor's system subject to the same security requirements. (Correct answer)
- Contractors must self-certify FISMA compliance annually to the Department of Commerce.
- Only contractors with SECRET clearances are subject to FISMA.
Correct answer: The federal agency includes FISMA and NIST control requirements in the contract, making the contractor's system subject to the same security requirements.
FISMA applies to federal agencies and extends to contractors through contractual requirements. Federal agencies must include information security requirements (aligned to NIST standards) in contracts with third-party providers who handle federal information, making those systems subject to the same RMF-based requirements as agency-owned systems.
Which U.S. federal law established the requirement for federal agencies to develop, document, and implement an information security program, and made NIST responsible for developing security standards and guidelines?