{"id":1043,"date":"2015-06-01T23:19:15","date_gmt":"2015-06-02T06:19:15","guid":{"rendered":"https:\/\/www.microsoft.com\/industry\/blog\/uncategorized\/government-mandates\/"},"modified":"2023-07-18T09:03:37","modified_gmt":"2023-07-18T16:03:37","slug":"government-mandates","status":"publish","type":"post","link":"https:\/\/www.microsoft.com\/en-us\/industry\/blog\/government\/2015\/06\/01\/government-mandates\/","title":{"rendered":"Government mandates"},"content":{"rendered":"

Applying technology to address Federal Mandates and Executive Orders<\/h2>\n
\n

Technology is key to many of the Mandates and Executive Orders that apply to your organization. Microsoft is here to help with information and links to details and solutions that help you address requirements and achieve the level of compliance you need.<\/p>\n<\/div>\n

\n

IT Security<\/h3>\n<\/div>\n
\n

Federal Information Security Management Act (FISMA)<\/h4>\n

The E-Government Act passed in 2002 recognized the importance of information security to the economic and national security interests of the United States. As Title III of this act, FISMA requires each federal agency to develop, document and implement an agency-wide program to provide information security that supports the operations and assets of the agency and related agencies and sources.<\/p>\n

Office 365 implements security processes that adhere to the standards required by U.S. federal agencies, and it has acquired FISMA Authority to Operate (ATO) from a federal agency.<\/p>\n

Visit the CRSC site for more detail on FISMA<\/a><\/p>\n

Federal Mandate: Common Criteria Evaluation and Validation Scheme for IT Security<\/h4>\n

Under the National Information Assurance Partnership (NIAP), the National Institute of Standards and Technology (NIST) and the National Security Agency (NSA) established the Common Criteria Evaluation and Validation Scheme for IT Security (CCEVS). The goals, per the Federal Mandate, are to ensure that security evaluations of IT products are performed to consistent standards, encourage the formation of commercial security testing laboratories, meet the needs of government and industry for cost-effective evaluation of IT products, and improve the availability of those products.<\/p>\n