250 likes | 296 Views
NIST SP 800-171, Compliance for DoD Contractors. Cybersecurity. Over 53,000 incidents in 2018 Cyber criminals don’t have to steal data to make money. What is NIST?. N ational I nstitute of S tandards and T echnology
E N D
NIST SP 800-171, Compliance for DoD Contractors
Cybersecurity • Over 53,000 incidents in 2018 • Cyber criminals don’t have to steal data to make money
What is NIST? National Institute of Standards and Technology Special Publications: developed and issued by NIST as recommendations and guidance documents. SP 800-series: information system security
DFARS Clauses • DFARS 252.204-7008: Compliance with Safeguarding Covered Defense Information Controls • DFARS 252.204-7012: Safeguarding Covered Defense Information and Cyber Incident Reporting
CUI and CDI? Controlled Unclassified Information Covered Defense Information
The Threat • Outside Attacks • Insider Threat • Environmental Disruptions
Risk of Non-Compliance • Audits • DCAA compliance • Random contract-specific • Incident-triggered • Subcontractors
Cybersecurity Certification • DoD recently announced forthcoming CMMC • Cybersecurity Maturity Model Certification • Requiring 3rd party certification • Cyber Levels will begin appearing in Sections L & M • Your Cyber Level will determine “go/no go”
NIST SP 800-171 Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
Awareness and Training 3.2.1 Ensure that … users of organizational systems are made aware of the security risks associated with their activities ...
Access Control 3.1.6 Use non-privileged accounts or roles when accessing nonsecurity functions.
What Now? • Assess Your System • System Security Plan (SSP) • Plan of Actions and Milestones (PoAM) • Monitor - Monitor - Monitor
Thank you! Lori Jackson Manager, Strategy and Planning Division ljackson@zapatainc.com (980) 277-1131