This article explores the relationship between NIST and FISMA, their roles in information security, and the guidelines and standards developed by NIST for FISMA compliance. It discusses the importance of information security, the laws enacted by the US government to protect personal non-public data, and the role of FISMA in ensuring the protection of information and information systems of the US federal government. It also explains how FISMA assigned the responsibility to NIST to develop guidelines and publications for implementing information security by federal agencies. The article further discusses the three categories of NIST standards, the NIST SP 800 series publications, and the nine-step process outlined by NIST for implementing a secure and cost-effective information security control. It concludes by highlighting the wide acceptance of NIST guidelines as a reliable information security framework worldwide.