Presentation is loading. Please wait.

Presentation is loading. Please wait.

Of XX Cybersecurity in Government Contracting David Z. Bodenheimer, Partner, Crowell & Moring LLP ©2015 PubKLearning. All rights reserved.1 The Federal.

Similar presentations


Presentation on theme: "Of XX Cybersecurity in Government Contracting David Z. Bodenheimer, Partner, Crowell & Moring LLP ©2015 PubKLearning. All rights reserved.1 The Federal."— Presentation transcript:

1 of XX Cybersecurity in Government Contracting David Z. Bodenheimer, Partner, Crowell & Moring LLP ©2015 PubKLearning. All rights reserved.1 The Federal Cybersecurity Forest: Statutes, Regulations & Standards Federal Statutes –FISMA (44 USC §§ 3551-58) –Privacy Act (5 USC § 552a) –HIPAA (42 USC § 1320d-2(d) Federal Regulations –FAR §§ 7.103 & 39.101(d) (information security) & § 24.102 (privacy) –Agency regulations (information security, privacy, & healthcare) Federal & International Standards –NIST FIPS & Special Publications (40 USC § 11331(b)(1)(C) –Other Standards (ISO, COBIT, PCI, etc.)

2 of XX Cybersecurity in Government Contracting David Z. Bodenheimer, Partner, Crowell & Moring LLP ©2015 PubKLearning. All rights reserved.2 Cyber Statutes FAR Rules Agency Rules

3 of XX Cybersecurity in Government Contracting David Z. Bodenheimer, Partner, Crowell & Moring LLP ©2015 PubKLearning. All rights reserved.3 Federal Harmonization Imperative Cybersecurity Executive Order 13636 –“The report shall address what steps can be taken to harmonize and make consistent existing procurement requirements related to cybersecurity.” FAR Policy on Uniformity –FAR seeks “uniform policies and procedures for acquisition by all executive agencies.” FAR § 1.101. Cost-Effective Cybersecurity –Agency cybersecurity programs and risk analyses must consider cost-effectiveness. 44 USC § 3554 Better Cybersecurity –DoD/GSA Report acknowledged that harmonized acquisition regulations would enhance cybersecurity. See Final Report of the Department of Defense and General Services Administration, Improving Cybersecurity & Resilience through Acquisition (Nov. 2013)

4 of XX Cybersecurity in Government Contracting David Z. Bodenheimer, Partner, Crowell & Moring LLP ©2015 PubKLearning. All rights reserved.4 FAR Rules Agency Rules

5 of XX Cybersecurity in Government Contracting David Z. Bodenheimer, Partner, Crowell & Moring LLP ©2015 PubKLearning. All rights reserved.5 Agency Rules & Variations

6 of XX Cybersecurity in Government Contracting David Z. Bodenheimer, Partner, Crowell & Moring LLP ©2015 PubKLearning. All rights reserved.6 DoD Cyber Rules: Changes at Speed of Cyber DIACAP (2007) –DoD Instruction 8510.01 Shift to NIST (2012) –DoD Instruction 8582.01 (tasking DoD Undersecretary to consider NIST) DoD Safeguarding Unclassified Controlled Technical Information (2013) –DFARS § 204.73 –NIST 800-53 security controls DoD Network Penetration Reporting & Contracting for Cloud Services (2015) –DFARS § 204.73 (safeguarding “covered defense information”) –NIST 800-171 security controls

7 of XX Cybersecurity in Government Contracting David Z. Bodenheimer, Partner, Crowell & Moring LLP ©2015 PubKLearning. All rights reserved.7 DHS Cyber Regulations Acquisition Deviation

8 of XX Cybersecurity in Government Contracting David Z. Bodenheimer, Partner, Crowell & Moring LLP ©2015 PubKLearning. All rights reserved.8 GSA Cyber Audit Clause GSA Cyber Audits (GSAM 552.239-71(k) –“The Contractor shall afford GSA access to the Contractor’s and subcontractors’ facilities, installations, operations, documentation, databases, IT systems and devices, and personnel used in performance of the contract, regardless of the location. Access shall be provided to the extent required, in GSA’s judgment, to conduct an inspection, evaluation, investigation or audit, including vulnerability testing to safeguard against threats and hazards to the integrity, availability and confidentiality of GSA data or to the function of information technology systems operated on behalf of GSA, and to preserve evidence of computer crime. This information shall be available to GSA upon request.” Conflict with Commerciality –Commercial Terms: list of clauses (FAR §§ 12.302(b) & 52.212-4) –Commercial Practices: “consistent with customary commercial practices” (FAR § 12.301(a)) –Order of Precedence: FAR Part 12 takes precedence (FAR §§ 12.102(c))

9 of XX Cybersecurity in Government Contracting David Z. Bodenheimer, Partner, Crowell & Moring LLP ©2015 PubKLearning. All rights reserved.9 NASA Cyber Clause: NASA FARS 1852.204-76(b) “Applicable Document List”


Download ppt "Of XX Cybersecurity in Government Contracting David Z. Bodenheimer, Partner, Crowell & Moring LLP ©2015 PubKLearning. All rights reserved.1 The Federal."

Similar presentations


Ads by Google