The Department of Justice’s increased enforcement of cybersecurity regulations leaves government contractors with two options: Comply fully with cybersecurity guidelines, or risk penalties such as expensive legal cases and debarment.
Government contracts typically include a specific set of cybersecurity rules meant to protect controlled unclassified information (“CUI”), which includes technical data, research, and sensitive project information. Although unclassified, CUI can nonetheless pose risks to national security if hackers use the information to gain insight into other classified projects.
Government agencies, therefore, require contractors to comply with rules such as the Federal Acquisition Regulations (“FAR”) or the Cybersecurity Maturing Model Certification (“CMMC”) program. But the foundation for most Government-imposed guidelines was first created by the National Institute of Standards and Technology (“NIST”), an agency under the U.S. Department of Commerce.
The NIST framework for protecting CUI includes detailed technical recommendations to secure information systems and manage cybersecurity risks. It was developed in response to several high-profile data breaches in the 2010s when hackers realized it was easier to access sensitive information through private companies with less secure systems than directly through government systems.
The framework was initially released in 2015 as NIST Special Publication 800-171. It has since been revised multiple times and was supplemented by the 2021 release of NIST Special Publication 800-172.
The NIST publications are not in themselves a law but a detailed security guideline. However, the NIST framework forms the core and defines key terms for various mandatory regulations, including the CMMC, the FAR, and the Department of Defense Federal Acquisition Regulation Supplement (“DFARS”).
NIST Special Publication 800-171: The Foundation
It’s imperative for organizations handling CUI to comply with the NIST framework. This applies regardless of contract size and includes defense contractors, research institutions, and healthcare providers. Any vulnerabilities in cybersecurity systems can harm national interests.
At first glance, the NIST framework can seem like a complicated, endless list, but it is essentially a commonsense outline of already existing industry standards. NIST 800-171 outlines 110 security requirements to protect CUI in non-federal systems and organizations.
Those requirements are organized into 14 control families:
-
- Access Control: Controlling who can access systems and data, limiting access to authorized individuals, imposing strong password policies, and automatically locking sessions after a period of inactivity.
- Awareness and Training: Training all employees to understand the security risks associated with their jobs and be able to recognize potential threats (such as phishing emails).
- Audit and Accountability: Creating automatic logs of who did what and when throughout the system. Logs are critical when investigating a breach.
- Configuration Management: Controlling what can be downloaded to a device connected to the system, which prevents the inadvertent introduction of unauthorized software or malware.
- Identification Authentication: Utilizing passwords and multi-factor authentication to verify user identities prior to granting access.
- Incident Response: Creating a plan for when a breach occurs. Security incidents are inevitable, no matter how strong your systems are. You need to have a plan to detect, analyze, contain, eradicate, recover, and properly report an attack.
- Maintenance: Ensuring maintenance is performed regularly and by authorized personnel.
- Media Protection: Properly destroying any media that contains CUI once it is no longer needed. Media is anything that can store data, such as a thumb-drive, external hard drive, and even CDs or printed hard copies.
- Personal Security: Thoroughly screening individuals prior to granting them access to CUI and disabling access immediately upon de-authorization of an individual.
- Physical and Environmental Protection: Restricting physical access to server rooms by locking doors, controlling access to workstations and printers, and maintaining visitor logs.
- Risk Assessment: Regularly monitoring systems for new vulnerabilities and taking steps to address them once identified.
- Security Assessment: Testing your own security plans to ensure they stay up to date and effective.
- System and Communications Protection: Protecting the flow of information over and out of the network with firewalls and encryption and insulating your private network from the public internet.
- System and Information Integrity: Utilizing anti-virus and anti-malware software, monitoring systems for indications of an attack or breach, and having a plan for security patches if necessary.
All 110 requirements and associated objectives need to be implemented for a company to be compliant with NIST 800-171.
NIST Special Publication 800-172: The Expansion
NIST 800-172 added 35 additional requirements to the NIST 800-171 in 2021, expanding 10 of the control families outlined above. The supplemental requirements include proactively hunting for cyber threats, rotating passwords, using two-person access controls, and more.
Companies hoping to snag top priority contracts with the U.S. Department of Defense must meet the heightened security requirements of the NIST 800-172, otherwise they’ll fall short of the necessary CMMC trust level.
This alert is part four of an ongoing series through which Leech Tishman will track developments in the DOJ’s Cybersecurity Fraud Enforcement program and issue continuing legal updates addressing compliance obligations, impacted industries, and the relevant regulatory requirements. View the previous alert in the series here.
Leech Tishman’s Labor & Employment attorneys regularly counsel clients on compliance with statutory and common law requirements. Our team is prepared to assist your company in understanding and implementing the obligations and compliance measures required under the DOJ’s Cybersecurity Fraud Enforcement program. For assistance or additional information, please contact Lydia A. Pappas at lpappas@leechtishman.com, attorney in Leech Tishman’s Labor & Employment Practice Group.