Cyber Security Requirements For Government Contractors
Federal government contractors especially those who do business with the department of defense dod should expect cybersecurity to continue to be an area of great concern to the federal government.
Cyber security requirements for government contractors. At the end of the last year the department of defense dod issued six guidance memoranda aimed at assisting acquisition personnel in developing what has been described as effective cybersecurity strategies to enhance existing protection requirements this included a mandate for the defense contract management agency to ensure that cybersecurity compliance will be a part of a contractor. Provides the policies and requirements of the transportation security administration tsa management directive md 1400 3 information technology security by establishing guidance applicable to the use development and maintenance of tsa information technology it assets networks and systems. Nist handbook 162 nist mep cybersecurity self assessment handbook for assessing nist sp 800 171 security requirements in response to dfars cybersecurity requirements the handbook provides a step by step guide to assessing a manufacturer s information systems against the security requirements in nist sp 800 171 rev 1. Federal government information technology it contracts must include requirements and clauses that address the cybersecurity and privacy controls that are specified in a number of publicly available guidance documents standards and laws.
If they anticipate using cloud computing they should ensure the cloud service meets fedramp moderate security requirements and complies with incident. Tsa information assurance ia handbook. By the end of september the defense department will require at least some companies bidding on defense contracts to certify that they meet at least a basic level of cybersecurity standards. Contractors may use subcontractors and or outsource information technology requirements but they are responsible for ensuring that the entities they use meet the cybersecurity standards.
The new york department of financial services for example developed a cybersecurity regulation available at 23 nycrr part 500 that garnered widespread attention. Contractors remain responsible for implementing critical cybersecurity requirements but the cmmc changes this paradigm by requiring third party assessments of contractors compliance with certain. Like the federal government states and localities are increasingly imposing cybersecurity requirements on their contractors.