{"data":{"id":"us/32-cfr-2004.40","jurisdiction":"us","citation":"32 CFR 2004.40","heading":"Information system security.","body":"(a) The responsible CSA must authorize an entity information system before the entity can use it to process classified information. The CSA must use the most complete, accurate, and trustworthy information to make a timely, credible, and risk-based decision whether to authorize an entity's system.\n(b) The responsible CSA issues to entities guidance that establishes protection measures for entity information systems that process classified information. The responsible CSA must base the guidance on standards applicable to Federal systems, which must include the Federal Information Security Modernization Act of 2014 (FISMA), Public Law 113-283, and may include National Institute of Standards and Technology (NIST) publications, Committee on National Security Systems (CNSS) publications, and Federal information processing standards (FIPS).","path":["Title 32—National Defense","Subtitle B—Other Regulations Relating to National Defense","CHAPTER XX—INFORMATION SECURITY OVERSIGHT OFFICE, NATIONAL ARCHIVES AND RECORDS ADMINISTRATION","PART 2004—NATIONAL INDUSTRIAL SECURITY PROGRAM (NISP)","Subpart C—Operations"],"source_url":"https://www.ecfr.gov/api/versioner/v1/full/2026-08-25/title-32.xml","current_through":"2026-08-25","vintage":"","retrieved_at":"2026-08-27T02:25:30Z","sha256":"b29ec495a095512a0ddad9e2823e13652cd7463dd040ffd6a42a65b83a02b3ab","source_id":"us-cfr","stale":true,"prev":"us/32-cfr-2004.38","next":"us/32-cfr-2004.42"},"notice":"GroundRules: Original legal text. Not legal advice."}
