FISMA Act of 2008
Have a question about what this bill does? Ask in plain English; the answer is drawn from the bill's actual text and official record, and it'll tell you when something isn't in the text rather than guess.
(This measure has not been amended since it was introduced. The summary of that version is repeated here.)
Federal Information Security Management Act of 2008 or the FISMA Act of 2008 - Amends federal law relating to information security to require federal agencies to perform an independent audit of their information security programs to determine their effectiveness (current law requires an independent evaluation).
Requires each federal agency to designate a Chief Information Security Officer to protect the agency's information security network. Establishes a Chief Information Security Officers Council to assist such Officers in developing best practices and performance measures for agency information security.
Requires the Director of the Office of Management and Budget (OMB) to promulgate information security regulations governing contracts between the federal government and private entities.
Requires the Department of Homeland Security (DHS) to report annually to specified congressional committees on operational evaluations and testing protocols relating to information security networks.
Placed on Senate Legislative Calendar under General Orders. Calendar No. 1105.
- Introduced in Senate Formatted Text PDF Formatted XML
- Reported to Senate Formatted Text PDF Formatted XML
Cite this page
U.S. Congress. (2026). S. 3474: FISMA Act of 2008. 110th Congress. Open America. https://openamerica.io/bill/110-S-3474/
"S. 3474: FISMA Act of 2008." 110th Congress, 2026, Open America, https://openamerica.io/bill/110-S-3474/.
S. 3474, 110th Cong. (2026), https://openamerica.io/bill/110-S-3474/.
[S. 3474: FISMA Act of 2008](https://openamerica.io/bill/110-S-3474/)