FISCAM - Federal Information System
Controls Audit Manual

NNT Change Tracker’s real-time, non-stop approach to compliance, configuration drift reporting, and breach detection present an ideal solution to demonstrating compliance with FISCAM requirements.

FISCAM is a manual developed by the Government Accountability Office intended to provide auditors with specific guidance for evaluating the confidence, integrity, and availability of information systems. FISCAM is consistent with the National Institute of Standards and Technology (NIST SP 800-53) guidelines for complying with the Federal Information Security Modernization Act of 2014 (FISMA).

GAO

FISCAM

FISCAM Overview
FISCAM focuses on 5 key areas: Security Management, Access Controls, Configuration Management, Contingency Planning, and Segregation of Duties.

Security Management
Controls provide reasonable assurance that security management is effective, including effective:

  • Remediation of information security weaknesses
  • Periodic assessments and validation of risk
  • Security awareness and security training
  • Security control policies & procedures

FISCAM Controls
The FISCAM is organized to facilitate effective and efficient IS control audits by incorporating the following controls:

  • A top-down, risk-based approach that considers materiality and significance in determining effective and efficient audit procedures
  • Evaluation of entity-wide controls and their effect on audit risk
  • Evaluation of general controls and their pervasive impact on business process application controls
  • Evaluation of security management at all levels (entity-wide, system, and business process application levels)
  • A control hierarchy (control categories, critical elements, and control activities) to assist in evaluating the significance of identified IS control weaknesses
  • Groupings of control categories consistent with the nature of the risk
  • Experience gained in GAO's performance and review of IS control audits, including field testing the concepts in this revised FISCAM

Register for a free trial and automate FISCAM compliance

NNT Suite of Products

change tracker gen7r2 logo

Combine industry leading Device Hardening, File Integrity Monitoring, Change Control, Configuration Management & Compliance Management into one easy to use solution that can scale to the most demanding environments!

fastcloud logo

Automatically evaluate and verify the authenticity of file changes in real-time with NNT FAST™ (File Approved-Safe Technology) Integrity Assurance.

log tracker logo logo

Comprehensive and easy to use security information & event log management with intelligent & self-learning correlation technology to highlight potentially harmful activity in seconds.

vulnerability tracker logo

Continuously scan and identify vulnerabilities with unparalleled accuracy and efficiency, protecting your IT assets on premises, in the cloud and mobile endpoints.

USA Offices
New Net Technologies LLC
Naples
Suite #10115, 9128 Strada Place
Naples, Florida, 34108
Atlanta
1175 Peachtree St NE
Atlanta, Georgia, 30361.
Portland
4145 SW Watson, Suite 350
Beaverton, Oregon, 97005.

Tel: (844) 898-8358
email [email protected]
UK Office
New Net Technologies Ltd
Rivers Lodge, West Common
Harpenden, Hertfordshire
AL5 2JD

Tel: 01582 287310
email [email protected]
CIS benchmarking SEWP Cybersecurity 500Sans Institute Now Certified
Copyright 2019, New Net Technologies LLC. All rights reserved. 
NNT and Change Tracker are registered trademarks of New Net Technologies LLC.
All other product, company names and trademarks are the property of their respective owners.