Tap any paragraph to write a margin note. Your notes collect in the Desk below the text and file under cases with @. The side-by-side margin rail opens on a larger screen.

Code · BILL · 117th Congress · S. 2902 (Introduced in Senate) — To modernize Federal information security management, and for other purposes. · Sec. 104

Sec. 104. Additional guidance to agencies on FISMA updates

267 words·~1 min read·/bill/117/s/2902/is/section-104

A research copy — for the controlling text, always check the official state or federal source. Not legal advice.

Not later than 1 year after the date of enactment of this Act, the Director, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency, shall issue guidance for agencies on— completing the agency system risk assessment required under section 3554(a)(1)(A) of title 44, United States Code, as amended by this Act; implementing additional cybersecurity procedures, which shall include resources for shared services; establishing a process for providing the status of each remedial action under section 3554(b)(7) of title 44, United States Code, as amended by this Act, to the Director and the Cybersecurity and Infrastructure Security Agency using automation and machine-readable data, as practicable, which shall include— specific standards for the automation and machine-readable data; and templates for providing the status of the remedial action; interpreting the definition of high value asset in section 3552 of title 44, United States Code, as amended by this Act; implementing standards in agency authorization processes to encourage the tailoring of processes to agency and system risk that are proportionate to the sensitivity of systems, which shall include— a clarification of— the acceptable use and development of customization of standards promulgated under section 11331 of title 40, United States Code; and the acceptable use of risk-based authorization procedures authorized on the date of enactment of this Act; and a requirement to coordinate with Inspectors Generals of agencies to ensure consistent understanding and application of agency policies for the purpose of Inspector General audits; and requiring, as practicable and pursuant to section 203, an evaluation of agency cybersecurity using metrics that are— based on outcomes; and based on time.
★   the supreme law of the land   ★
Don't Tread on Me
E Pluribus Unum — out of many, one

"If you don't know your rights, you don't have any."

Marginalia · a citizen's law index
A research desk, not legal advice. Always read the cited source before relying on a summary.
Questions or an issue? support@self-law.org
disclaimerMarginalia is a research index, not a law firm. Nothing on this site is legal, tax, or financial advice and no attorney–client relationship is formed by using it. Statutes, regulations, and case law change; summaries, search results, AI output, and member posts may be incomplete, out of date, or wrong. Any interpretation drawn from material on this site should be validated by a licensed attorney in your jurisdiction before you act on it.