An official website of the United States government
Here's how you know
Official websites use .gov A .gov website belongs to an official government organization in the United States.
Secure .gov websites use HTTPS A lock () or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.
A volunteer board comprised of ISPG staff and the ISSO community designed to promote collaboration on cybersecurity and privacy issuesWhat is the CMS Information Security Advisory Board (CISAB)? The …
Supporting the continuous compliance and safety of FISMA systems through proactive, ongoing monitoring activitiesWhat is Ongoing Authorization (OA)? All FISMA systems must be …
ISPG program that provides skilled Information System Security Officers (ISSOs) to CMS components in need of professional security and privacy supportWhat is ISSO As A Service (ISSOaaS)? Information System Security …
A process to determine the effect(s) a change can cause to the security posture of a FISMA systemWhat is a Security Impact Analysis (SIA) A Security Impact …
An official document that outlines the responsibilities to be completed by the ISSO on behalf of a specific FISMA SystemWhat is the ISSO Appointment Letter? The Information System Security …
Automated scanning and risk analysis to strengthen the security posture of CMS FISMA systemsWhat is Continuous Diagnostics and Mitigation (CDM)? Continuous Diagnostics and …
Documentation of a FISMA system’s features and security requirements, along with controls and procedures for information protectionWhat is a System Security and Privacy Plan (SSPP)? The …
Defining the relationship between CMS information systems and external systemsWhat is an Interconnection Security Agreement (ISA)? An Interconnection Security …
A compliance-based assessment to determine if a system's security and privacy controls are implemented correctlyWhat is a Security Control Assessment (SCA)? The Security Control …
RMH Chapter 12 provides information about the Security & Privacy Planning (PL) control family for use during a new ATO cycleIntroduction This Handbook outlines procedures to help CMS staff and …