32 CFR 2004.40
§ 2004.40 Information system security.
United States · 32 CFR — National Defense · Status: effective
Cite this
- Citation
- 32 CFR 2004.40, § 2004.40 Information system security, United States, version 1 as recorded 2026-07-09, yourstate.us, https://yourstate.us/provision/148933
- Permanent ID
ys:prov:148933@1- SHA-256
be7b2e993a77521b01657d8f78b9818bbb2d74bfcecf0fb63a7511961206a751
The hash is SHA-256 of this version's text, with every run of whitespace collapsed to a single space and the ends trimmed. The ID always leads back here, and checking it says whether the text you cited is still the current version.
Full text
(a) The responsible CSA must authorize an entity information system before the entity can use it to process classified information. The CSA must use the most complete, accurate, and trustworthy information to make a timely, credible, and risk-based decision whether to authorize an entity's system.
(b) The responsible CSA issues to entities guidance that establishes protection measures for entity information systems that process classified information. The responsible CSA must base the guidance on standards applicable to Federal systems, which must include the Federal Information Security Modernization Act of 2014 (FISMA), Public Law 113-283, and may include National Institute of Standards and Technology (NIST) publications, Committee on National Security Systems (CNSS) publications, and Federal information processing standards (FIPS).
Legislative history
This is a federal regulation, adopted through agency rulemaking under the Administrative Procedure Act — not enacted by a recorded vote of Congress.