From: Government Contracts Insider
Clarification is called for in the Regulations
As you know, I have written three different posts on cyber security as it relates to Government Contracting in the last few months as this has topic has moved quickly in response to breaches that were taking place. What is interesting is the comments coming in from industry about clarifications and now the American Bar Association making the same type of clarification needed comments. Generally, a rule/regulation will have a comment period before it becomes effective. In this case, the “interim” rule on cyber breaches, what was covered, and how to report (what was mandatory, discretionary, should do, etc.), was effective immediately. This immediacy may have resulted in clarifications to the rule as goes into effect and the operational aspects of the regulation come into play. In this regard, short comings of regulations can be seen more clearly when the application of the rule takes effect in the field. I would expect this set of rules/regulations to have clarifications and will keep you posted.
International Cyber Breach Agreements
In September of this year, China and the US reached a cyber security/breach agreement. UK and Germany followed shortly thereafter. Now, four of the five top economies of the world have reached agreements on not engaging in commercially motivated cyber espionage. It will be interesting to watch as this trend develops and the true teeth of the agreements if breached.
The Yates Memorandum and the Department of Justice
Leave a Reply