The rise of cyberattacks has compelled the U.S. Government to be increasingly vigilant in guarding information stored not only on its own systems but on the systems of its contractors. As the saying goes, you’re only as strong as your weakest link.
The Government thus mandated a baseline for cybersecurity infrastructure to lower the chances of contractors being the weak link and compromising sensitive information. Rules such as the Federal Acquisition Regulations (“FAR”) and the Department of Defense Federal Acquisition Regulation Supplement (“DFARS”) were among the first cybersecurity authorities developed — both incorporating the previously discussed NIST guidelines into law.
The provision FAR 52.204-21 lists 15 basic safeguarding controls for all contractor information systems that process, store, or transmit Federal Contract Information (“FCI”). The requirements include:
- Verification and control of all connections to external information systems,
- Limitations on system access,
- Malicious code protection, and
- Monitoring of system security.
As indicated, the FAR’s requirements go beyond implementing basic protocols such as securing and controlling access to the network or utilizing intrusion detection systems. Companies must actively monitor their network security and promptly report and address any attacks or breaches.
Companies that are already complying with the NIST framework are off to a good start, considering this provision of the FAR is largely based on the NIST guidelines.
The same can be said for the DFARS, which incorporates compliance with the NIST risk assessment guidelines and expands upon them with provisions imposing assessment and reporting requirements on companies. (See DFARS 252.204-7019 & DFARS 252.204-7020.)
With the provision DFARS 252.204-7012, the Department of Defense (“DOD”) further implemented a mandatory contract clause that requires contractors to protect sensitive defense information on their networks.
This applies to all prime and sub-contractors that handle, process, store, or transmit covered defense information (“CDI”). All entities that perform work under Government contracts are obligated to follow the same FAR and DFARS standards to ensure there are no weak links in any part of the chain touching CDI.
The aforementioned DFARS provision is clear on two obligations:
- Contractors must implement the cybersecurity controls outlined in NIST SP 800-171, and
- Contractors must promptly report any cyber incidents to the DOD within 72 hours of discovery.
The emphasis on incident reports is present in both the DFARS and FAR, signaling that the Government finds reporting cyberattacks to be as important as implementing proper security protocols in the first place. Security incidents are inevitable because no system is perfect.
Failing to report those incidents, however, generally can’t be passed off as an honest mistake. The False Claims Act doesn’t just come into play if a contractor doesn’t comply with regulations. Contractors who don’t report cyberattacks can also find themselves with a lawsuit on their hands.
The FAR and DFARS represent different levels of compliance in the Cybersecurity Maturity Model Certification (“CMMC”) program, which determines whether contractors can be trusted with sensitive information and work with the DOD. The next alert in this series will discuss the CMMC program in depth.
This alert is part five of an ongoing series through which Leech Tishman will track developments in the DOJ’s Cybersecurity Fraud Enforcement program and issue continuing legal updates addressing compliance obligations, impacted industries, and the relevant regulatory requirements. View the previous alert in the series here.
Leech Tishman’s Labor & Employment attorneys regularly counsel clients on compliance with statutory and common law requirements. Our team is prepared to assist your company in understanding and implementing the obligations and compliance measures required under the DOJ’s Cybersecurity Fraud Enforcement program. For assistance or additional information, please contact Lydia A. Pappas at lpappas@leechtishman.com, attorney in Leech Tishman’s Labor & Employment Practice Group.