ARTICLE
20 December 2017

NIST's Highly-Anticipated Security Requirements Draft Impacts Government Contractors' Treatment Of CUI

SM
Sheppard, Mullin, Richter & Hampton LLP

Contributor

Businesses turn to Sheppard to deliver sophisticated counsel to help clients move ahead. With more than 1,200 lawyers located in 16 offices worldwide, our client-centered approach is grounded in nearly a century of building enduring relationships on trust and collaboration. Our broad and diversified practices serve global clients—from startups to Fortune 500 companies—at every stage of the business cycle, including high-stakes litigation, complex transactions, sophisticated financings and regulatory issues. With leading edge technologies and innovation behind our team, we pride ourselves on being a strategic partner to our clients.
Government contractors have until December 31 to implement security requirements from NIST Special Publication (SP) 800-171 (here) as mandated by the Defense Federal Acquisition ...
United States Government, Public Sector
Sheppard, Mullin, Richter & Hampton LLP are most popular:
  • within Cannabis & Hemp and Insolvency/Bankruptcy/Re-Structuring topic(s)

Government contractors have until December 31 to implement security requirements from NIST Special Publication (SP) 800-171 (here) as mandated by the Defense Federal Acquisition Regulation Supplement (DFARS). The requirements include provisions for protecting Controlled Unclassified Information (CUI) (government sensitive but unclassified information; see the CUI Registry here) in nonfederal systems and compliance is expected soon to be required under civilian agency contracts through a forthcoming FAR case. How to implement these requirements has caused some confusion. In response, on November 28, 2017, NIST released its highly-anticipated draft publication providing assessment procedures.

As we reported on in more detail in our GovCon blog, NIST states that its draft publication – NIST SP 800-171A on "Assessing Security Requirements for Controlled Unclassified Information" – will "help organizations develop assessment plans and conduct efficient, effective, and cost-effective assessments of the security requirements in Special Publication 800-171." The draft special publication includes assessment procedures relating to each of the security requirements in the fourteen families included in NIST SP 800-171. These include requirements for limiting access to controlled information, tracking and reporting cyber incidents, and employee training. The draft publication also describes methods by which companies can "generate evidence to support the assertion that the security requirements have been satisfied." Thus, it appears an organization that conducts the suggested assessments in the draft publication and generates supporting documentation can present this to its agency customer as proof of compliance with NIST SP 800-171.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

[View Source]
See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More