Federal Information Security Management Act (FISMA) Compliance

Developing and maintaining a complete and cost-effective Federal Information Security Management Act (FISMA) compliance program presents unique challenges. At McGladrey, our approach provides a clear correlation with the applicable National Institute of Standards and Technology (NIST), Office of Management and Budget (OMB) and Department of Defense (DoD) standards, regulations, publications and manuals governing FISMA independent evaluations.

We base our security evaluation framework on the Information Technology Committee of the Federal Audit Executive Council guidance and structure the framework into the following areas:

  • Program controls (strategic policies, procedures and plans)
  • System controls (tactical implementation)
  • Management controls
  • Technical controls
  • Operational controls

Our security certification assessment approach is based on a deep understanding of the federal government’s operating environment and your organization’s system security plans. We’re also well versed on accreditation boundaries and implementation of applicable security controls required by NIST special publications, Federal Information Processing Standard Publications (FIPS) and other agency-specific requirements.