What is FISMA?
“FISMA” stands for Federal Information Security Management Act (PDF file) and is the primary set of regulations regarding the implementation of various information security measures on IT systems used by the US Federal Government. FISMA classifies all Federal IT systems into 3 categories of severity based on importance: Low, Medium, and High. IT administrators must then deploy a range of IT security controls for each system based on which category a system is placed. The document that lays out the classification levels and means is FIPS 199 and NIST Special Publication 800-53r1 contains the security controls for each security classification.