Skip to main content
S 3474 110th Congress Senate Government Operations and Politics Administrative procedure Auditing Chief information officers Computer security measures Congress Congressional reporting requirements Executive reorganization Federal officials Government contractors Governmental investigations Law Office of Management and Budget Science, Technology, Communications

FISMA Act of 2008

Introduced: September 11, 2008 See on congress.gov
This bill died when the 110th Congress ended
It never became law before the 110th Congress (2007–2008) adjourned, and bills don't carry over to the next Congress. It would have to be reintroduced. You can still save it for reference, but it won't receive updates.
 Everywhere this bill has been 6 steps
Introduced
In committee
Reported out
Passed House
Passed Senate
To President
Became law
Oct 1, 2008
Placed on Senate Legislative Calendar under General Orders. Calendar No. 1105.
Oct 1, 2008
Committee on Homeland Security and Governmental Affairs. Reported by Senator Lieberman without amendment. Without written report.
Sep 23, 2008
Committee on Homeland Security and Governmental Affairs. Ordered to be reported without amendment favorably.
Sep 11, 2008
Read twice and referred to the Committee on Homeland Security and Governmental Affairs. (text of measure as introduced: CR S8389-8391)
Sep 11, 2008
Sponsor introductory remarks on measure. (CR S8388-8389)
Sep 11, 2008
Introduced in Senate
 Ask about this bill AI · grounded in the bill text

Have a question about what this bill does? Ask in plain English; the answer is drawn from the bill's actual text and official record, and it'll tell you when something isn't in the text rather than guess.

AI answers can be imperfect; always confirm against the full bill text.

 Plain-English summary Congressional Research Service

(This measure has not been amended since it was introduced. The summary of that version is repeated here.)

Federal Information Security Management Act of 2008 or the FISMA Act of 2008 - Amends federal law relating to information security to require federal agencies to perform an independent audit of their information security programs to determine their effectiveness (current law requires an independent evaluation).

Requires each federal agency to designate a Chief Information Security Officer to protect the agency's information security network. Establishes a Chief Information Security Officers Council to assist such Officers in developing best practices and performance measures for agency information security.

Requires the Director of the Office of Management and Budget (OMB) to promulgate information security regulations governing contracts between the federal government and private entities.

Requires the Department of Homeland Security (DHS) to report annually to specified congressional committees on operational evaluations and testing protocols relating to information security networks.

What's happening now October 1, 2008

Placed on Senate Legislative Calendar under General Orders. Calendar No. 1105.

 Bill text 2 versions

Source documents hosted by congress.gov.

 Committees of jurisdiction 1
Cite this page click to expand
APA
U.S. Congress. (2026). S. 3474: FISMA Act of 2008. 110th Congress. Open America. https://openamerica.io/bill/110-S-3474/
MLA
"S. 3474: FISMA Act of 2008." 110th Congress, 2026, Open America, https://openamerica.io/bill/110-S-3474/.
Bluebook (legal)
S. 3474, 110th Cong. (2026), https://openamerica.io/bill/110-S-3474/.
Markdown link
[S. 3474: FISMA Act of 2008](https://openamerica.io/bill/110-S-3474/)
Report a problem