Federal Information Security Management Act
U.S. law requiring federal agencies to develop, document, and implement information security programs. Mandates NIST standards for all federal information systems.
What FISMA draws on
This framework pulls on all three pillars — which is why running them as three separate tools means reconciling three sets of evidence at audit time.
Compliance
- Sensitive Data DiscoveryFinds and classifies the regulated data, so everything downstream knows what is in scope.
- Policy & ComplianceTurns the captured activity into the report shape the framework asks for.
- Compliance Advisory ServicesOrganises the gap register, the remediation roadmap, and the auditor-ready pack.
Security
What your auditor cites,
and what produces the evidence
The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.
Audit Events
Federal systems MUST audit: successful/failed account logons, account management, object access, policy changes, privilege functions.
Authorisation is configured in the database; proving it holds is what this requirement actually needs. Vulnerability scanning surfaces excessive privilege and role sprawl, default and weak credentials, and stale or orphaned accounts — including privilege inherited through nested roles, which is where least-privilege reviews usually go wrong. Real-time SQL auditing then shows which of those grants were exercised, so an access review reflects observed use rather than intent.
Ongoing Assessment
Agencies MUST implement continuous monitoring programs for security controls.
Framework audits do not ask whether you own a tool; they ask you to demonstrate that a named control operated over a period. Access reviews, privileged activity, change monitoring, and audit-log integrity are produced from the activity already being captured and mapped to the control they satisfy, with dashboards showing posture over the audit window rather than at a single point. Our evidence-pack engagement formats it the way assessors expect and answers the database-controls questions on the call.
System Monitoring
Organizations MUST monitor systems to detect attacks and indicators of potential attacks.
Rules catch what you already thought of. Behavioural models baseline every user and application against their own history and their peer group, then score deviations in real time — so a service account reading tables it has never touched surfaces without anyone having written a rule for it first. That is what makes monitoring hold up as access patterns change, instead of decaying into a ruleset nobody maintains.
Security Reviews
Systems MUST undergo annual security assessments with documented evidence.
A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.
What FISMA covers
This instrument defines no data category of its own. Same structure as FedRAMP: the unit is the FIPS 199 impact level of the information system, categorised under FIPS 199 and NIST SP 800-60, not a class of data named by the Act.
How FISMA is enforced
Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by OMB, agency Inspectors General, and Congress through the appropriations process.
FISMA obliges agencies rather than firms, so its teeth are administrative. Annual Inspector General assessments and OMB scorecards are public, and a system that cannot sustain its authorisation to operate is taken out of service. Contractors feel it through the contract clauses that flow the obligations down.
For a contractor the practical exposure is contractual and, where compliance was misrepresented, the False Claims Act.
Uncapped exposure that sits outside this instrument
These come from company law rather than from FISMA, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.
Duty of oversight
Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.
Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.
Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.
This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.
In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).
Enforcement data reviewed August 2026. Several figures are indexed annually and move.
Built for FISMA,
not configured for it afterwards
Federal System Audit Policy
All NIST 800-53 required audit events pre-configured
FISMA Annual Assessment Report
Audit control evidence for annual security reviews
Continuous Monitoring Dashboard
Real-time security posture visibility
Attack Pattern Detection
SI-4 compliant monitoring with threat detection
Other Government frameworks
Walk into the FISMA audit knowing the answer
228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.