The Federal Information Security and Management Act of 2002, as amended, (FISMA) does not directly create liability for private sector IT security professionals or their companies. However, IT security professionals should be aware of this law, because it:
- Legally mandates the process by which information security requirements for federal government departments and agencies must be developed and implemented
- Directs the federal government to look to the private sector for applicable gbest practicesh and to provide assistance to the private sector (if requested) with regard to information security
- Contributes to the developing gstandard of careh for information security by mandating a number of specific procedures and policies