Skip to main content
Federal Information Security Management Act of 2002

Federal Information Security Management Act of 2002

Search complete. 12 mentions across 6 episodes found for "Federal Information Security Management Act of 2002".

Sep 28, 2026

Gerald AugerHOST
18:12
It's the CISO who owns that.
Gerald AugerHOST
18:15
Now, if they don't get exploited, it may come up during a FISMA audit.
Gerald AugerHOST
18:21
As someone who has done FISMA audits in the past, I don't necessarily know if a obscure SharePoint vulnerability is going to bubble to the surface enough to warrant you know the executive report of a fisma audit but but the tldr is if it gets exploited that's when you're running uh you're you're gonna be it's a resume generating event essentially okay so consider that update binding operational directive all right bruising hacks very very strongly stating its binding operational directive get it right jerry is effectively what all caps means to me
Steve PrenticeSOUNDBITE_SPEAKER
19:06
details and doubts emerge regarding open ai hack of australian health portal oh gosh This is a follow-up to a story we covered on Friday regarding claims that an OpenAI agent hacked an Australian government Medicare statistics portal in June.
Steve PrenticeSOUNDBITE_SPEAKER
19:22
Australian officials, including the Prime Minister Anthony Albanese, said the agent bypassed access controls and reached non-public files, although no personal Medicare information was accessed.
Gerald AugerHOST
79:16
But a more meaningful solution would be to take those skills that you've developed and then apply them in a project that you can disclose publicly.
Gerald AugerHOST
79:27
A very simple one that I always like to say is like, Say you're going to do a risk assessment, like a NIST 853 moderate baseline, full top-down FISMA audit with a risk assessment and a polium afterwards.
Gerald AugerHOST
79:42
You can do that on your home network, right? And I know you're like, oh, that sounds lame.
Gerald AugerHOST
79:47
Dude, you have a wireless network likely in your environment.
AamirGUEST
4:21
So what, uh, like who owns that proof? What are the proofs that you need? So regulatory pressures is one thing that, uh, keeps you on your toes to be compliant.
AamirGUEST
4:34
If I talk about the regulatory pressures like FISMA, GDPR, HIPAA, UAI Act, CMMC, lots of other regulations as well.
AamirGUEST
4:46
Again, regulation is providing the pressure on the organizations, but audit is something that is coming from long time.
AamirGUEST
4:57
We hear about audit every day in organizations.

5 MINS LATER

AamirGUEST
10:26
Like you see, it is not only NIST.
AamirGUEST
10:29
They are talking about COBIT also.
AamirGUEST
10:30
They are talking about ISO 7001, 27002, 3100, FISMA, GDPR, HIPAA, STLC.
AamirGUEST
10:39
In the domain three, they talk about the audit planning penetration testing risk response then again pom pom is is is the heart of of this uh why
George HoffmanGUEST
26:08
Let's make sure that it's still utilized.
George HoffmanGUEST
26:11
We do a system census every year where there's a call and response to every business unit for every FISMA system that we have and all the components that are part of that FISMA system.
George HoffmanGUEST
26:22
So in addition to what the tools are telling us, let's make sure that we have some street level Intel that people can share.
George HoffmanGUEST
26:28
And I think again, that, that having some legislation kind of backing us up saying, yes, this is important.
Robert JohnsonGUEST
4:56
and then provide you with detailed information on exactly what you need to do to fix it.
Robert JohnsonGUEST
5:00
And also map that information back to a variety of compliance standards so you can see how am I doing in terms of 853, FISMA? How am I doing in terms of PCI? We use it all as evidence to drive that.
Tom TittermaryHOST
5:13
Yeah, I think just from my perspective, right, we've all been doing security for a very long time.
Tom TittermaryHOST
5:18
I think that the two main categories of what I would call security events or meaningful security events, you know, in the red, yellow, greens, these are the reds, they fall into exactly two categories.

5 MINS LATER

Robert JohnsonGUEST
10:55
Is this system in the same state it was yesterday? Yes or no? That's it.
Robert JohnsonGUEST
11:01
Then it gets more complex than that.
Robert JohnsonGUEST
11:03
Is it exactly how I expect? And I think that's the intent with the, say, 853 FISMA.
Robert JohnsonGUEST
11:12
It has a section there, SI, for system integrity, that really says that you must have this baseline, this authoritative baseline, and measure the integrity of your systems.
Sarbari GuptaGUEST
7:01
It was laid out more clearly and it was more obvious how to achieve authorizations required to operate government systems.
Sarbari GuptaGUEST
7:09
And so over the years, the FISMA burden of authorization to operate that has continued.
Sarbari GuptaGUEST
7:14
There's been a lot of pushback on how much documentation, it's a paper pushing exercise, et cetera.
Sarbari GuptaGUEST
7:20
So some of that has caused a lot of automation and tool-based compliance to be implemented as well.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.