From: Holland & Knight
Two Recent Executive Agency Actions Lay the Groundwork for a FAR Cybersecurity Clause in 2016
- Government contractors should expect an amendment to the Federal Acquisition Regulation in 2016 that mandates cybersecurity clauses and standards.
- Companies can prepare now by comparing new government standards to their existing system protections.
- As part of this process, companies should not just be reviewing the capabilities of their information systems, but also their written information assurance policies, training materials, and employment and third-party agreements.
Federal government contractors handling Controlled Unclassified Information (CUI) should take notice of two recent executive agency actions. Combined, they lay the groundwork for a new cybersecurity clause to be added to the Federal Acquisition Regulation (FAR) in 2016.
The National Archives and Record Administration (NARA) is the Executive Agent for handling CUI. In May, NARA proposed a rule (the NARA CUI regulation) to establish policies for federal agencies on designating, safeguarding, disseminating, marking and disposing of CUI. The proposal requires agencies whose contractors handle CUI to impose contractual requirements that are consistent with the new NARA policies. Importantly for government contractors, NARA announced that in 2016, it will sponsor a single FAR clause that will apply specific information security requirements to contractors handling CUI.
Leave a Reply