Top Banner
1 government contracting DoD Cybersecurity Rules: Government Contractors Need to Know Bill Walter, DHG Jermaine Stanley, DHG Tom Tollerton, DHG
27

DoD Cybersecurity Rules: Government Contractors Need to Kno · NIST SP 800-171 ‘Tailoring Criteria' SP 800-171 guidelines are tailored for nonfederal information systems that contactors

May 30, 2020

Download

Documents

dariahiddleston
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: DoD Cybersecurity Rules: Government Contractors Need to Kno · NIST SP 800-171 ‘Tailoring Criteria' SP 800-171 guidelines are tailored for nonfederal information systems that contactors

1government contracting

DoD Cybersecurity Rules:Government Contractors Need to KnowBill Walter, DHGJermaine Stanley, DHGTom Tollerton, DHG

Page 2: DoD Cybersecurity Rules: Government Contractors Need to Kno · NIST SP 800-171 ‘Tailoring Criteria' SP 800-171 guidelines are tailored for nonfederal information systems that contactors

2government contracting

Speaker Information

TomTollerton,ManagerDixonHughesGoodman,LLP(704)[email protected]

JermaineStanley,ManagerDixonHughesGoodman,LLP(703)[email protected]

@DHG_GovCon@DHG_Cyber

BillWalter,PartnerDixonHughesGoodman,LLP(703)[email protected]

Page 3: DoD Cybersecurity Rules: Government Contractors Need to Kno · NIST SP 800-171 ‘Tailoring Criteria' SP 800-171 guidelines are tailored for nonfederal information systems that contactors

3government contracting

Topics for Today

• Introductions• BackgroundofDoDCybersecurityRules• UpdatestoComplianceRequirements• NISTSP800-171Overview• KeyDates• WhatShouldGovernmentContractorsBeDoing?

@DHG_GovCon@DHG_Cyber

Page 4: DoD Cybersecurity Rules: Government Contractors Need to Kno · NIST SP 800-171 ‘Tailoring Criteria' SP 800-171 guidelines are tailored for nonfederal information systems that contactors

4government contracting

DoD Cybersecurity Rules

Page 5: DoD Cybersecurity Rules: Government Contractors Need to Kno · NIST SP 800-171 ‘Tailoring Criteria' SP 800-171 guidelines are tailored for nonfederal information systems that contactors

5government contracting

DoD Cybersecurity Rules

InterimRule#1…RequirescontractorreportingofnetworkpenetrationsandimplementedtheDoDCIOCloudComputingSecurityRequirementsGuide(SRG)Version1,Release1onJanuary13,2015.1

ThisruleisintendedtostreamlinethereportingprocessforDoDcontractorsandminimizeduplicativereportingprocesses.2

InterimRule#2ExtendedtimelineforcompliancetoprovidecontractorswithadditionaltimetoimplementsecurityrequirementsspecifiedbyaNISTSpecialPublication(SP)800-171.3

@DHG_GovCon@DHG_Cyber

Page 6: DoD Cybersecurity Rules: Government Contractors Need to Kno · NIST SP 800-171 ‘Tailoring Criteria' SP 800-171 guidelines are tailored for nonfederal information systems that contactors

6government contracting

DoD Cybersecurity Rules

InterimRule#1…Setforth(i)informationsystemsecurityrequirements;(ii)mandatorycyberbreachreporting;and(iii)cloudcomputingstandardsandprocedures.

Expandedsafeguardingrequirementstocoverthesafeguardingofcovereddefenseinformation(CDI)residingincontractorinformationsystems,andrequiredcompliancewiththesecurityrequirementsintheNationalInstituteofStandardsandTechnology(NIST)SpecialPublication(SP)800–171,‘‘ProtectingControlledUnclassifiedInformationinNonfederalInformationSystemsandorganizations

@DHG_GovCon@DHG_Cyber

Page 7: DoD Cybersecurity Rules: Government Contractors Need to Kno · NIST SP 800-171 ‘Tailoring Criteria' SP 800-171 guidelines are tailored for nonfederal information systems that contactors

7government contracting

DoD Cybersecurity Rules

(ii)MandatoryCyberIncidentReporting§ Increasednumberofcircumstanceswherecontractorsmustreportincidents.

§ IncidentsmustbereportedtoDoDwithin72hours.§ Howdowedefineanincident?

‒ Incidentvs.Compromise‒ Event?

@DHG_GovCon@DHG_Cyber

Page 8: DoD Cybersecurity Rules: Government Contractors Need to Kno · NIST SP 800-171 ‘Tailoring Criteria' SP 800-171 guidelines are tailored for nonfederal information systems that contactors

8government contracting

DoD Cybersecurity Rules

(iii)CloudComputerStandardsandProcedures§ EnforcespreviousguidanceissuedbyDoDCIOoncontractingcloudservices

§ Enforces“CloudComputingSecurityRequirementsGuide”‒ FedRAMPcompliancestillrequired,butadditionalcontrolsfor“moresensitiveinformation”

‒ DefinesseveraladditionalclassesofSensitiveData

@DHG_GovCon@DHG_Cyber

Page 9: DoD Cybersecurity Rules: Government Contractors Need to Kno · NIST SP 800-171 ‘Tailoring Criteria' SP 800-171 guidelines are tailored for nonfederal information systems that contactors

9government contracting

DoD Cybersecurity Rules

NewDefinitions…§ CUIvs.UCTIvs.CDI§ 800-171refersto“ControlledUnclassifiedInformation”

‒ Wasdatedbeforethenewruleswereputinplace§ “UnclassifiedControlledTechnicalInformation”wastheoriginalterminDFARS252.204-7012

§ CoveredDefenseInformation– newtermthatencompassesalloftheabove,aswellasnewtypesofinformation

@DHG_GovCon@DHG_Cyber

Page 10: DoD Cybersecurity Rules: Government Contractors Need to Kno · NIST SP 800-171 ‘Tailoring Criteria' SP 800-171 guidelines are tailored for nonfederal information systems that contactors

10government contracting

DoD Cybersecurity Rules

CoveredDefenseInformation(CDI)§ UnclassifiedinformationprovidedtothecontractorbyoronbehalfofDoDinconnectionwiththeperformanceofthecontract;or

§ Unclassifiedinformationwhichiscollected,developed,received,transmitted,used,orstoredbyoronbehalfofthecontractorinsupportoftheperformanceofthecontract

@DHG_GovCon@DHG_Cyber

Page 11: DoD Cybersecurity Rules: Government Contractors Need to Kno · NIST SP 800-171 ‘Tailoring Criteria' SP 800-171 guidelines are tailored for nonfederal information systems that contactors

11government contracting

DoD Cybersecurity Rules

CoveredDefenseInformation(CDI)is…§ Controlledtechnicalinformation(Military)§ Exportcontrolledinformation(commodities,tech,softwareetc.)

§ Criticalinformation(DoDDirective,OPEC,etc.)§ ‘CatchAll’(privacyorproprietarybusinessinformation)

@DHG_GovCon@DHG_Cyber

Page 12: DoD Cybersecurity Rules: Government Contractors Need to Kno · NIST SP 800-171 ‘Tailoring Criteria' SP 800-171 guidelines are tailored for nonfederal information systems that contactors

12government contracting

DoD Cybersecurity Rules

CoveredContractorSystems§ ContractorownedInformationSystem§ Processes,stores,ortransmitsCDI§ Properscopingiskey

‒ Serversandworkstations‒ Networkdevices‒ Storagesystems

@DHG_GovCon@DHG_Cyber

Page 13: DoD Cybersecurity Rules: Government Contractors Need to Kno · NIST SP 800-171 ‘Tailoring Criteria' SP 800-171 guidelines are tailored for nonfederal information systems that contactors

13government contracting

Updates to Compliance Requirements

Page 14: DoD Cybersecurity Rules: Government Contractors Need to Kno · NIST SP 800-171 ‘Tailoring Criteria' SP 800-171 guidelines are tailored for nonfederal information systems that contactors

14government contracting

Updated Requirements

Remember…DoDissuedInterimRule#2amendingtheDefenseFederalAcquisitionRegulationSupplement(DFARS)toprovidecontractorswithadditionaltimetoimplementsecurityrequirementsspecifiedinNISTSP800-171.

@DHG_GovCon@DHG_Cyber

Page 15: DoD Cybersecurity Rules: Government Contractors Need to Kno · NIST SP 800-171 ‘Tailoring Criteria' SP 800-171 guidelines are tailored for nonfederal information systems that contactors

15government contracting

Additional Updated Requirements § DFARSclause252.204–7012wasamendedtorequirenotificationtheDoDCIO

ofanyNISTSP800–171requirementsthatarenotimplementedatthetimeofcontractaward,within30daysofcontractaward(Doesnotexemptorganizationsfromworkingtoward100%compliance)

§ DFRSprovision252.204–7009andclause252.204–7012wereamendedtorequire,whenapplicable,inclusionoftheclausewithoutalteration,excepttoidentifytheparties.

§ DFARSclause252.204–7012wasfurtheramendedtolimittherequirementtoflowdowntheclauseonlytosubcontractorswheretheireffortswillinvolvecovereddefenseinformationorwheretheywillprovideoperationallycriticalsupport.

§ DFARSclause252.204–7012wasamendedtoremovetherequirementforDoDCIOacceptanceofalternativebutequallyeffectivesecuritymeasurespriortoaward.

@DHG_GovCon@DHG_Cyber

Page 16: DoD Cybersecurity Rules: Government Contractors Need to Kno · NIST SP 800-171 ‘Tailoring Criteria' SP 800-171 guidelines are tailored for nonfederal information systems that contactors

16government contracting

NIST SP 800-171

Page 17: DoD Cybersecurity Rules: Government Contractors Need to Kno · NIST SP 800-171 ‘Tailoring Criteria' SP 800-171 guidelines are tailored for nonfederal information systems that contactors

17government contracting

NIST SP 800-171

ProvidesfederalagencieswithrecommendedrequirementsforprotectingtheconfidentialityofCUI:(i)whentheCUIisresidentinnonfederalinformationsystemsandorganizations;

(ii)whentheinformationsystemswheretheCUIresidesarenotusedoroperatedbycontractorsoffederalagenciesorotherorganizationsonbehalfofthoseagencies;and

(iii)wheretherearenospecificsafeguardingrequirementsforprotectingtheconfidentialityofCUI

@DHG_GovCon@DHG_Cyber

Page 18: DoD Cybersecurity Rules: Government Contractors Need to Kno · NIST SP 800-171 ‘Tailoring Criteria' SP 800-171 guidelines are tailored for nonfederal information systems that contactors

18government contracting

NIST SP 800-171

‘TailoringCriteria'

SP800-171guidelinesaretailoredfornonfederalinformationsystemsthatcontactorsalreadyhaveinplace,withagoalofattemptingtoavoidrequiringcontractorstocompletelyreplacelegacyinformationsystems.

ProvidesacompletelistingofthesecuritycontrolsintheNISTSpecialPublication800-53moderatebaselineandthetailoringactions(byfamily)thathavebeencarriedoutonthesecuritycontrolsinthemoderatebaseline.

– ThetailoringactionsfacilitatethedevelopmentoftheCUIderivedsecurityrequirements

@DHG_GovCon@DHG_Cyber

Page 19: DoD Cybersecurity Rules: Government Contractors Need to Kno · NIST SP 800-171 ‘Tailoring Criteria' SP 800-171 guidelines are tailored for nonfederal information systems that contactors

19government contracting

NIST SP 800-171

Threeprimarycriteriaforeliminatingasecuritycontrolorcontrolenhancementsfromthemoderatebaselineincluding:§ Thecontrolorcontrolenhancementisuniquely

federal(i.e.,primarilytheresponsibilityofthefederalgovernment);

§ ThecontrolorcontrolenhancementisnotdirectlyrelatedtoprotectingtheconfidentialityofCUI;or

§ Thecontrolorcontrolenhancementisexpectedtoberoutinelysatisfiedbynonfederalorganizationswithoutspecification.

@DHG_GovCon@DHG_Cyber

Page 20: DoD Cybersecurity Rules: Government Contractors Need to Kno · NIST SP 800-171 ‘Tailoring Criteria' SP 800-171 guidelines are tailored for nonfederal information systems that contactors

20government contracting

Key Dates

August26,2015-expanded

safeguardingrequirementstocovercovered

defenseinformation(CDI)

Dec.14,2015–Publicmeeting

withDoDcontractors

Dec.30,2015–DoDissues

interimruletograntadditional

timeforcontractorstoimplementNISTSP800-171

Dec.31,2017-Contractorsmustcomplywiththe

requirementsofNISTSP800-

171

@DHG_GovCon@DHG_Cyber

Page 21: DoD Cybersecurity Rules: Government Contractors Need to Kno · NIST SP 800-171 ‘Tailoring Criteria' SP 800-171 guidelines are tailored for nonfederal information systems that contactors

21government contracting

What Should Government Contractors Be Doing?

Page 22: DoD Cybersecurity Rules: Government Contractors Need to Kno · NIST SP 800-171 ‘Tailoring Criteria' SP 800-171 guidelines are tailored for nonfederal information systems that contactors

22government contracting

What Should We Do?

ExpectationsofContractors§ UnderstandstatusofcompliancewithSP800-171

‒ Beabletocommunicategaps‒ HaveaplanforremediationbyDec.31,2017

§ Haveasystembreachreportingplan‒ Howquicklyareweabletoperformaninvestigation?

@DHG_GovCon@DHG_Cyber

Page 23: DoD Cybersecurity Rules: Government Contractors Need to Kno · NIST SP 800-171 ‘Tailoring Criteria' SP 800-171 guidelines are tailored for nonfederal information systems that contactors

23government contracting

What Should We Do?

CurrentPriorities…§ Understandcompliancerequirements

§ Thetimetobeginreviewingcontrolcompliancestatusisnow!

§ Breachnotificationrequirementswithin72hours‒ Howdowereport?‒ What’sinvolved?

@DHG_GovCon@DHG_Cyber

Page 24: DoD Cybersecurity Rules: Government Contractors Need to Kno · NIST SP 800-171 ‘Tailoring Criteria' SP 800-171 guidelines are tailored for nonfederal information systems that contactors

24government contracting

What Should We Do?

CriticalQuestions…§ Doweknowthenatureofourin-scopesystem?

‒ Doweknowexactlywhatdatawehave?‒ Dataflows‒ Systemsthat“transmit,process,orstore”relevantdata

§ Needtoproperlyscopeour“coveredinformationsystem.”‒ Segmentationcandramaticallyreduceorexpandthescopeofcompliancerequirements

@DHG_GovCon@DHG_Cyber

Page 25: DoD Cybersecurity Rules: Government Contractors Need to Kno · NIST SP 800-171 ‘Tailoring Criteria' SP 800-171 guidelines are tailored for nonfederal information systems that contactors

25government contracting

What Should We Do?

CriticalQuestions…§ Areweeffectivelypushingandenforcingcompliancerequirementswithoursubs?

§ Howareweperformingourcomplianceassessment?‒ Areweusingobjectiveanalysis?‒ Tabletopexerciseorin-depthassessment?‒ Areweusingtoolstoconducttechnicalreviews?‒ Areweimplementingadequateplantoremediategaps?

@DHG_GovCon@DHG_Cyber

Page 26: DoD Cybersecurity Rules: Government Contractors Need to Kno · NIST SP 800-171 ‘Tailoring Criteria' SP 800-171 guidelines are tailored for nonfederal information systems that contactors

26government contracting

Questions?@DHG_GovCon@DHG_Cyber

Page 27: DoD Cybersecurity Rules: Government Contractors Need to Kno · NIST SP 800-171 ‘Tailoring Criteria' SP 800-171 guidelines are tailored for nonfederal information systems that contactors

27government contracting

Join Us Next Month @DHG_GovCon@DHG_Cyber

DCMAGuidanceUponCompensationBlendingClarifications,Questions,andConcerns

Wednesday,March9th,11:00am