NIST rewrites FISMA standards as cyber threats evolve

The National Institute of Standards and Technology has issued a major revision to the Federal Information Security Management Act, which governs agency information...

The National Institute of Standards and Technology has issued major revisions to the Federal Information Security Management Act, which governs agency information security policies.

The revamped FISMA includes new guidance for insider-threat management, supply-chain risk and mobile security.

“The changes we propose … are directly linked to the current state of the threat space — the capabilities, intentions and targeting activities of adversaries — and analysis of attack data over time,” said Ron Ross, a NIST fellow and the agency’s FISMA implementation project leader.

Ross joined In Depth with Francis Rose to discuss the FISMA additions.

“This has been a really big update for us,” Ross said. “It’s been a year in the making, and we took a complete scrub of the entire security-control catalogue looking at the current threat space.”

There is also the addition of a new appendix on privacy and privacy controls to better balance security needs and the privacy of individual users, he added.

“The threat space continues to move forward,” Ross said. “We’re looking at a lot of data on cyber attacks, capabilities, intentions, targeting by adversaries. All that information is used in a cycle to update our documents … So, we’re always going to be trying to bring the best defenses to our customer we possibly can.”

This story is part of Federal News Radio’s daily Cybersecurity Update. For more cybersecurity news, click here.

RELATED STORIES:

Senate begins work on FISMA update

Agencies must use Cyberscope tool for FISMA reports

Copyright © 2025 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.

    Getty Images/Vadym PastukhA friendly office environment is depicted where a team greets each other and shaking hands

    Best practices for developing soft skills in the federal workforce in 2025

    Read more
    Graphic By: Derace LauderdaleDefense Pentagon Graphic

    DoD advisory board calls on the Pentagon to expand DIU

    Read more
    Courtesy of: https://www.justice.gov/archives/olp/staff-profile/former-assistant-attorney-general-office-legal-policy-hampton-y-dellingerHampton Yeats Dellinger

    Office of Special Counsel has ‘growing staffing concerns’ amid record caseload

    Read more