The Federal Information Security Modernization Act (FISMA) was created in 2014 to establish rules and regulations that hold federal and civilian agencies accountable for the federal and personal information they store. It also acts as an update to the previous iteration from 2002, the Federal Information Security Management Act, which stated, “All information systems, electronic or hard copy, which contain Federal data need to be protected from unauthorized access.” The primary aim of the 2014 version was to build Americans’ trust in the federal government, while pressuring agencies to comply with the new standards set forth. In today’s society, there has been a mass adoption and implementation of artificial intelligence into every part of our lives, and since there is “no federal legislation…or prohibitions” on AI, FISMA (2014) is very vital to the safety of America’s data.
Key Provisions
FISMA requires that all federal agencies and other entities, including civilian agencies and private government contractors, establish extensive security programs to ensure the protection of federal information and personally identifiable information (PII) like SSNs or biometric records. This is achieved primarily by promoting accountability among agencies through regulations such as requiring Congress to be notified within seven days of major security incidents, directing agencies to submit detailed annual reports regarding major incidents, and notifying affected individuals as expeditiously as possible of their compromised data.
Arguments in Favor of FISMA
The 2014 iteration of FISMA addresses major concerns regarding government unease and fatigue with the nation’s cybersecurity health. Senator Tom Carper, in regard to the 2002 version, stated, “They have not kept up with the cyber threat that has grown even faster and larger than Congress could have foreseen in 2002.” This is further supported by reports that spending under the old policy was increasing dramatically, with the cost rising from $6.8 billion to $12 billion between the fiscal years of 2009 and 2010. To distribute the workload more effectively, FISMA (2014) divided oversight responsibilities between the Office of Management and Budget (OMB) and the Department of Homeland Security (DHS), ensuring that no single agency was overwhelmed by the growing scope of cyber threats.
With FISMA (2014), agencies are held responsible for creating and implementing plans for security, in order to ensure the correct measures are in place if a breach occurs. This emphasis on accountability requires agencies to promptly update data breach notifications and keep Congress informed as incidents occur. Compliance also gives agencies the ability to be more effective with mitigation techniques, as well as giving them a better edge when compared to other non-compliant agencies for business opportunities. FISMA’s regulations also closely relate to the National Institute of Standards and Technology (NIST) standards, which can add to an agency’s compliance record and reliability. The NIST standards include enhanced incident response techniques, dynamic system monitoring processes, and sophisticated security controls to ensure that the confidentiality, availability, and integrity of information systems are maintained.
Arguments in Opposition to FISMA
FISMA’s compliance rates have been shown as “mostly ineffective” from 2017-2022. This is in part due to the unrealistic expectations that it puts on agencies with fewer resources. Financial constraints and workforce shortages have hindered the ability of civilian agencies and private contractors to maintain compliance, a problem worsened by the backlash they face when compliance lapses occur. This backlash could be in the form of lost government funding, plummeting public trust, or a tainted reputation.
Another shortcoming of FISMA is the universality of its security measures, which can create easy targets if agencies do not differ in some way from the established baseline. This was most notably an issue during the SolarWinds Orion incident, where numerous federal agencies were given software updates containing malicious code while trying to comply with FISMA standards.
FISMA has also struggled with addressing the concerns outlined in its audits and implementation trackers. According to a report done on FISMA’s effectiveness by the Office of the Inspector General, the audit for the fiscal year of 2023 found only two out of twenty-three recommendations being implemented, with all the rest either being closed or waiting for overdue updates.
Future Prospects
Recently, there have been calls for an update to FISMA, as it has been nearly twelve years since the previous update, which matches the gap between the 2002 and 2014 dates from before. As cyber threats increase in sophistication, so does the cost to remedy them. FISMA-compliant agencies have reported 32 percent fewer security breaches and saved an average of $3.8 million in potential breach costs annually. Therefore, if compliance was not met, there could have been severe breaches similar to the SolarWinds Orion incident.
For the next implementation of FISMA, it has also been said there will be updates to the threat briefing process to further enhance public trust, as well as surprise inspections, continuous updates to improve consistency, and expanded management into the private sector. However, these changes could create more financial hardship for smaller agencies, as constant updates become hard to manage with a diminishing workforce and a lack of economic stability. It may very well create a dilemma where agencies will have to choose whether compliance is worth the initial hit to profit or the potential detriment to their agency’s reputation.