FISMA requires federal agencies to comply with eight categories related to information security: 1) conducting risk assessments, 2) establishing policies and procedures, 3) creating security plans, 4) providing security awareness training, 5) performing annual security testing, 6) developing remediation procedures, 7) implementing incident response procedures, and 8) creating contingency plans. Agencies must address these areas to detect and respond to security incidents, report attacks to US-CERT, and ensure system continuity through documented contingency plans tested annually. Risk assessments allow agencies to determine appropriate security based on potential harm from disrupted services.