
Federal Information Security Management Act of 2002
12
MENTIONS
6
EPISODES
5
PODCASTS
Search complete. 12 mentions across 6 episodes found for "Federal Information Security Management Act of 2002".
Sep 28, 2026
🔴 Sep 28's Top Cyber News NOW! - Ep 1253
G
18:12Gerald AugerHOST
It's the CISO who owns that.
G
18:15Gerald AugerHOST
Now, if they don't get exploited, it may come up during a FISMA audit.
G
18:21Gerald AugerHOST
As someone who has done FISMA audits in the past, I don't necessarily know if a obscure SharePoint vulnerability is going to bubble to the surface enough to warrant you know the executive report of a fisma audit but but the tldr is if it gets exploited that's when you're running uh you're you're gonna be it's a resume generating event essentially okay so consider that update binding operational directive all right bruising hacks very very strongly stating its binding operational directive get it right jerry is effectively what all caps means to me
S
19:06Steve PrenticeSOUNDBITE_SPEAKER
details and doubts emerge regarding open ai hack of australian health portal oh gosh This is a follow-up to a story we covered on Friday regarding claims that an OpenAI agent hacked an Australian government Medicare statistics portal in June.
S
19:22Steve PrenticeSOUNDBITE_SPEAKER
Australian officials, including the Prime Minister Anthony Albanese, said the agent bypassed access controls and reached non-public files, although no personal Medicare information was accessed.
🔴 Sep 25's Top Cyber News NOW! - Ep 1252
G
79:16Gerald AugerHOST
But a more meaningful solution would be to take those skills that you've developed and then apply them in a project that you can disclose publicly.
G
79:27Gerald AugerHOST
A very simple one that I always like to say is like, Say you're going to do a risk assessment, like a NIST 853 moderate baseline, full top-down FISMA audit with a risk assessment and a polium afterwards.
G
79:42Gerald AugerHOST
You can do that on your home network, right? And I know you're like, oh, that sounds lame.
G
79:47Gerald AugerHOST
Dude, you have a wireless network likely in your environment.
How to Prepare for CGRC Certification in 2026
A
4:21AamirGUEST
So what, uh, like who owns that proof? What are the proofs that you need? So regulatory pressures is one thing that, uh, keeps you on your toes to be compliant.
A
4:34AamirGUEST
If I talk about the regulatory pressures like FISMA, GDPR, HIPAA, UAI Act, CMMC, lots of other regulations as well.
A
4:46AamirGUEST
Again, regulation is providing the pressure on the organizations, but audit is something that is coming from long time.
A
4:57AamirGUEST
We hear about audit every day in organizations.
5 MINS LATER
A
10:26AamirGUEST
Like you see, it is not only NIST.
A
10:29AamirGUEST
They are talking about COBIT also.
A
10:30AamirGUEST
They are talking about ISO 7001, 27002, 3100, FISMA, GDPR, HIPAA, STLC.
A
10:39AamirGUEST
In the domain three, they talk about the audit planning penetration testing risk response then again pom pom is is is the heart of of this uh why
Ep. 264 Software Assessment and Asset Management: Critical Tool for Agencies
G
26:08George HoffmanGUEST
Let's make sure that it's still utilized.
G
26:11George HoffmanGUEST
We do a system census every year where there's a call and response to every business unit for every FISMA system that we have and all the components that are part of that FISMA system.
G
26:22George HoffmanGUEST
So in addition to what the tools are telling us, let's make sure that we have some street level Intel that people can share.
G
26:28George HoffmanGUEST
And I think again, that, that having some legislation kind of backing us up saying, yes, this is important.
The Missing Piece of Zero Trust: System Integrity
R
4:56Robert JohnsonGUEST
and then provide you with detailed information on exactly what you need to do to fix it.
R
5:00Robert JohnsonGUEST
And also map that information back to a variety of compliance standards so you can see how am I doing in terms of 853, FISMA? How am I doing in terms of PCI? We use it all as evidence to drive that.
T
5:13Tom TittermaryHOST
Yeah, I think just from my perspective, right, we've all been doing security for a very long time.
T
5:18Tom TittermaryHOST
I think that the two main categories of what I would call security events or meaningful security events, you know, in the red, yellow, greens, these are the reds, they fall into exactly two categories.
5 MINS LATER
R
10:55Robert JohnsonGUEST
Is this system in the same state it was yesterday? Yes or no? That's it.
R
11:01Robert JohnsonGUEST
Then it gets more complex than that.
R
11:03Robert JohnsonGUEST
Is it exactly how I expect? And I think that's the intent with the, say, 853 FISMA.
R
11:12Robert JohnsonGUEST
It has a section there, SI, for system integrity, that really says that you must have this baseline, this authoritative baseline, and measure the integrity of your systems.
Never Just a Business Leader | Dr. Sarbari Gupta
S
7:01Sarbari GuptaGUEST
It was laid out more clearly and it was more obvious how to achieve authorizations required to operate government systems.
S
7:09Sarbari GuptaGUEST
And so over the years, the FISMA burden of authorization to operate that has continued.
S
7:14Sarbari GuptaGUEST
There's been a lot of pushback on how much documentation, it's a paper pushing exercise, et cetera.
S
7:20Sarbari GuptaGUEST
So some of that has caused a lot of automation and tool-based compliance to be implemented as well.