Home / News / OMB Sets 2018 Deadline for Annual FISMA Reports

OMB Sets 2018 Deadline for Annual FISMA Reports

The Office of Management and Budget has released a memorandum that requires federal civilian agencies to submit their annual Federal Information Security Modernization Act reports to OMB and the Department of Homeland Security by March 1, 2018, MeriTalk reported Wednesday.

Agencies should also file their FISMA reports with the Government Accountability Office and Congress, OMB Director Mick Mulvaney wrote in the memo published Monday.

The document directs agency heads to submit to OMB chief and DHS secretary letters that include a detailed assessment of their organization’s data security policies and practices; number of cyber incidents reported through DHS’ U.S. Computer Emergency Readiness Team Incident Reporting System; and each incident’s description that includes vulnerabilities and threats.

Agencies should also report through the CyberScope online platform their breach response plans; privacy plans; continuous monitoring strategies for privacy; and written policies to justify that any new effort to collect Social Security numbers is needed.

The memo also requires agencies to inform inspector generals and Congress of any cyber breach within seven days through reports that contain information on threat actors, risk assessments performed on affected data infrastructure and remediation measures.

Check Also

GAO: Air Force to Deploy New Combat Rescue Helicopters to Active Component by FY 2020

The Government Accountability Office has found that the U.S. Air Force intends to start fielding in fiscal 2020 new Combat Rescue Helicopters to replace aging HH-60G Pave Hawk helicopters that have recorded the most flight time when it comes to staff recovery missions. GAO said in a report published Thursday the service will initially deploy the new helicopters to the active component six years ahead of the reserve component and to the Air National Guard by 2027.

Leave a Reply

Your email address will not be published. Required fields are marked *