The Federal Information Security Modernization Act, or FISMA governs how the Department of Homeland Security (DHS) administers information security policies for US Government Executive Branch agencies.
FISMA was first codified in 2002, and has been updated nearly every year since in order to keep pace with an ever-changing cybersecurity landscape. FISMA compliance is evaluated on different system categorization levels (Low, Moderate, High) as determined by the Standards for Security Categorization of Federal Information and Information Systems (FIPS-199).
Once a system categorization is determined, organizations implement the appropriate controls detailed in NIST 800-53.
The FISMA compliance process is relatively straightforward, but typically it is quite difficult to fully achieve given its level of depth.