From: Lexology
On August 26, 2015, the U.S. Department of Defense (“DoD”) published an interim rule entitled Defense Federal Acquisition Regulation Supplement: Network Penetration Reporting and Contracting for Cloud Services (DFARS Case 2013–D018) (the “Interim Rule”), that streamlines the obligations for contractors to report network penetrations and establishes DoD requirements for contracting with cloud computing service providers. The Interim Rule amends the information security contracting framework set forth in the Defense Federal Acquisition Regulation Supplement (“DFARS”) to implement section 941 of the National Defense Authorization Act (“NDAA”) for Fiscal Year (“FY”) 2013 and section 1632 of the NDAA for FY 2015, both of which impose cyber incident reporting obligations on contractors.
The Interim Rule requires DoD contractors and subcontractors to report cyber incidents that result in a compromise or have an actual or potentially adverse effect on a covered contractor information system or the covered defense information residing therein. Covered defense information includes controlled technical information, export controlled information, critical information and other information requiring protection by law, regulation or government-wide policy. Pursuant to the Interim Rule, contractors and subcontractors will be contractually obligated to report such cyber incidents to the DoD within 72 hours of discovery.
Leave a Reply