// Cloud
FISMA Compliance Software
US federal information security requirements, implemented via NIST 800-53.
Framework at a glance
Short name
FISMA
Version
2014
Category
Cloud
Controls
59
What FISMA covers
59 controls across 2 domains — every one tracked, owned and evidenced in Cyber Horizon.
NIST SP 800-53 Rev 5 (Moderate Baseline)
51 controls- AC-2 Account Management
- AC-3 Access Enforcement
- AC-6 Least Privilege
- AT-2 Literacy Training and Awareness
- AT-3 Role-Based Training
FISMA / NIST Risk Management Framework
8 controls- FISMA-01 FIPS 199 System Categorization
- FISMA-02 Security Authorization (Authority to Operate)
- FISMA-03 Continuous Monitoring Program
- FISMA-04 Annual Security Assessment
- FISMA-05 Plan of Action and Milestones (POA&M)
How Cyber Horizon automates FISMA
Every FISMA control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.
Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.
Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.
Frequently asked questions
What is FISMA?
US federal information security requirements, implemented via NIST 800-53.
How many controls does FISMA have?
FISMA (2014) has 59 controls in Cyber Horizon's catalogue, organised across 2 domains.
How does Cyber Horizon help with FISMA?
Cyber Horizon maps FISMA into a shared control library alongside every other framework you run, so evidence collected once counts towards FISMA and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.
More Cloud frameworks
See FISMA mapped to your environment
Start with the free 20-question readiness check — no signup — or get a personal walkthrough of FISMA in Cyber Horizon.