#FISMA
Your job is also to obey the law. I’m pretty sure signal isn’t a FISMA approved app.
March 26, 2025 at 9:19 PM
"This violates guidelines laid out by the Federal Information Security Management Act (FISMA)."
June 11, 2025 at 8:26 PM
They treated the Provisional ATO like a blank check. DOGE is now "holding a copy of the American public's social security data in a potentially unsecured cloud environment."

This is illegal under a federal law called FISMA. Everyone I know in government takes this law very seriously, except DOGE.
August 27, 2025 at 4:54 AM
FISMA was enacted before he took the job, however to prosecute violations it requires a DOJ.
July 21, 2026 at 2:08 PM
Same experience that me and my colleagues at 18F had with Musk's people. Like the SSA staff, we warned DOGE that the things they were trying to do violated FISMA and the Privacy Act. They weren't "innovative ideas," they were crimes. DOGE went ahead and did the crimes.
August 27, 2025 at 5:18 AM
Pendleton Act, FISMA, HIPAA, Privacy Act, Antideficiency Act.
February 25, 2025 at 1:29 AM
“Legal experts say granting Musk and his team access to such sensitive government data potentially contravenes multiple federal statutes, including the Privacy Act of 1974, the FISMA and the CFAA, as well as strict taxpayer privacy provisions under the Internal Revenue Code”
time.com/7212753/trum...
Is Trump Breaking Federal Laws? We Asked Legal Experts
Is Trump Breaking Federal Laws? We Asked Legal Experts
time.com
February 4, 2025 at 10:14 PM
So -- and I'll say it again -- FISMA violations
March 4, 2025 at 10:29 PM
As a former information security professional who worked with PII (personally identifiable information) on a govt contract, I can say that this is sickening.
Even for the data that we ourselves collected (no access to central systems) we were subject to FISMA laws.
Putin and black market rejoices.
March 10, 2025 at 5:56 AM
More needs to be said about FISMA bsky.app/profile/ceca...
"The Federal Information Security Modernization Act of 2014 ( #FISMA 2014) updates the Federal Government's #cybersecurity practices" www.cisa.gov/topics/cyber... #OPM #Treasury #SSA #Coup #Law
February 2, 2025 at 4:22 PM
FISMA violations anyone?
September 26, 2026 at 1:21 AM
They broke FISMA AND FEDRAMP too. ATO required to connect to secure gov systems even to other secure government systems and especially to non gov systems
February 2, 2025 at 1:47 PM
IRS cybersecurity overhaul falls short of effectiveness despite upgrades, leaving sensitive taxpayer data at risk, federal watchdog warns.

https://fedscoop.com/irs-cybersecurity-fisma-tigta-report/

#govtech #cybersecurity
September 26, 2026 at 8:30 AM
Look over there.

Hackers compromised swathes of sensitive data stored directly on FBI systems, a major counterintel coup for China. FISMA requires agencies report any digital intrusion that is “likely to result in demonstrable harm” to US national security.
www.politico.com/news/2026/04...
FBI declares suspected Chinese hack of US surveillance system a ‘major cyber incident’
The designation suggests the hackers successfully compromised swathes of sensitive data stored directly on FBI systems.
www.politico.com
April 2, 2026 at 2:19 AM
Like Severance but my innie just does FISMA compliance paperwork
January 15, 2025 at 12:03 PM
Cool, was this a sole-source procurement? Or a micro-purchase thing? Or did they give services for free because let’s add the Antideficiency Act to the list of violations?

Did they go through an ATO process? Yes, it’s probably FISMA low but good job on the integrity component there…
Via @zlz.bsky.social on X:
"The DOGE website appears to be developed and hosted by Outburst Data, run by current DOGE employee Kyle Schutt.

If you view the source of any page on the DOGE website, you'll see that the images are proxied through Cloudflare's ImageDelivery service.
February 14, 2025 at 12:11 PM
5. SEND REQUESTS TO OIGs TO OPEN INVESTIGATIONS.

Bessent has violated the Privacy Act and FISMA, and now there's this guy.

Yes, IGs were canned, but the offices still exist.

bsky.app/profile/phil...
This is Leland Dudek, acting commissioner of the Social Security Administration, and he has a message for SSA employees: We don't work for anyone other than President Trump. "Elections have consequences.... Only the Courts or Congress can intervene." 1/
March 5, 2025 at 1:28 PM
Everything’s fine.

‘The government has defined a ‘major incident’ under FISMA as ‘any incident that is likely to result in demonstrable harm to the national security interests, foreign relations, or economy of the United States.’”
April 3, 2026 at 7:55 PM
Hold up. This is a government server, how did this change get past FISMA controls? There's either an audit trail (if it did) or y'all should be reporting a security breach to your ISSO's.
Just saying.
We should FOIA the change control board results and change logs.
February 14, 2025 at 10:23 AM
If you type HIPPA you have to take the Medicare Fraud, Waste, and Abuse training while I hit you in the junk with printouts of the FISMA+HITECH Acts.
July 20, 2024 at 6:48 PM
There is so much wrong with DOJ's campaign to collect state voter rolls from across the country. Here's yet another thing: it likely violates a key federal law--FISMA--governing the information security measures required for sensitive data. www.brennancenter.org/our-work/ana...
The Justice Department’s Security Measures for Collecting Voter Rolls Are Inadequate
Federal and state law requires that sensitive voter registration information be kept secure.
www.brennancenter.org
February 25, 2026 at 11:13 PM
The Federal Information Security Modernization Act (FISMA) governs the security of federal information systems.

The Privacy Act of 1978 protects personal data maintained by federal agencies.
February 2, 2025 at 11:20 PM
Privacy Act of 1974, the Federal Information Security Modernization Act (FISMA), and the Computer Fraud and Abuse Act (CFAA), as well as strict taxpayer privacy provisions under the Internal Revenue Code.
February 24, 2025 at 3:04 PM
The DOGE team at SSA might have violated FISMA and other laws by not following security protocols as spelled out in NIST's SP 800-53, which are mandatory for all government agencies. 1/2
www.csoonline.com/article/4046...
Whistleblower: DOGE put Social Security database covering 300 million Americans on insecure cloud
The complaint accuses DOGE of bypassing security protocols to move Americans’ sensitive personal data outside federal oversight and onto an insecure AWS cloud instance, potentially violating establish...
www.csoonline.com
August 27, 2025 at 6:29 PM