THE SBDC NATIONAL INFORMATION CLEARINGHOUSE SERVING THE SMALL BUSINESS DEVELOPMENT CENTER NETWORK AND AMERICA’S SMALL BUSINESS COMMUNITY.

Follow Us:

Cybersecurity & Government Contracting

Cybersecurity & Government Contracting

Cybersecurity & Government Contracting

Cybersecurity is critical to all businesses, especially those engaging in government contracting. Manufacturing and construction business are particularly significant in government contracting, where companies may serve as prime contractors or subcontractors supporting federal, state, and local government projects. Continuing from our previous section, Cybersecurity Plans, this section explains how cybersecurity expectations work in government contracting, with a focus on defense contracting. These requirements are contractual, so what you must do depends on the solicitation/contract, the type of information involved, including Controlled Unclassified Information (CUI), and whether requirements are flowed down to you as a subcontractor. Whether you pursue government work or not, these standards provide a solid benchmark for building a defensible security program.

Government Contracting Cybersecurity Standards

The Department of Defense (DoD) requires small business contractors to comply with their cybersecurity standards for the protection of unclassified data. These requirements are outlined through several regulations, covered comprehensively by the DoD and summarized below for your convenience:

Defense Federal Acquisition Regulation Supplement (DFARS)

The Defense Federal Acquisition Regulation Supplement Part 252Solicitation Provisions and Contact Clauses” (DFARS 252.204) governs cybersecurity requirements for federal contractors. Additional requirements vary by contract, data type, and flowdowns. It requires that contractors provide adequate security, report cyber incidents, submit any malicious software discovered and submit media to support damage assessment.

  • Multi-factor authentication of local and network access
  • FIPS-validated cryptography to protect CUI when transmitted or stored externally
  • Implement the NIST SP 800-171 System Security Plan
  • Possess External Certificate Authority (ECA) as verified by DCMA
  • Report cyber incidents within 72 hours to DoD. Submit an incident report, any malicious software, and provide access to information systems.
  • Certain solicitations require a current NIST SP 800-171 DoD assessment score in the Supplier Performance Risk System (SPRS).

DFARS further requires that contractors implement the National Institute for Standards and Technology (NIST) Special Publication 800-171 “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations” (NIST SP 800-171):

  • Access Control – Limit information systems access to authorized users and permitted transactions.
  • Awareness and Training – Ensure personnel are aware of policies, standards and procedures.
  • Audit and Accountability – Create, protect, and retain information system audit records that allow the actions of individual users to be uniquely traced to those users.
  • Configuration Management – Establish inventory systems and enforce security configurations.
  • Identification and Authentication –Authenticate the identities users and devices prior to allowing access.
  • Incident Response – Establish an incident-handling capacity for detection, containment, recovery and user response. Track, document and report incidents to appropriate officials and/or authorities.
  • Maintenance – Perform maintenance on organizational information systems. Provide controls on the tools, techniques, mechanisms and personnel conducting maintenance.
  • Media Protection – Protect information system media containing CUI, whether in paper or digital form, by limiting access to authorized users and sanitizing or destroying the media before disposal or release for reuse.
  • Personnel Security – Screen individuals prior to authorizing access to information systems containing CUI. Ensure that CUI are protected during and after termination and transfers.
  • Physical Protection – Limit and monitor physical access to information systems, equipment, and the respective operating environments.
  • Risk Assessment – Periodically assess and manage the risks to operation, assets, individuals, and information systems associated with the processing, storing, and transmitting of CUI.
  • Security Assessment and Monitoring – Periodically assess the security controls of information systems. Implement a plan of action to correct deficiencies and reduce or eliminate vulnerabilities. Monitor information system security controls on an ongoing basis. Develop, document, and periodically update security system plans. Ensure that security system plans describe system boundaries, operational environments, implementation of security requirements, and relationships or connections to other systems.
  • Systems and Communications Protection – Monitor, control, and protect communications at the internal and external boundaries.
  • System and Information Integrity – Identify, report, and correct information and system flaws in a timely manner.
  • Planning – Develop, document, and communicate policies, procedures, roles, and responsibilities necessary to protect CUI, including requirements for external system services. Identify risk mitigation options or alternative sources of support for unsupported components that cannot be replaced and clearly define shared responsibilities with external service providers.
  • System and Services Acquisition – Replace unsupported system components and continuously monitor external service providers for compliance with security requirements.
  • Supply Chain Risk Management – Develop and implement a supply chain risk management plan that addresses risks throughout the system lifecycle. Establish processes to identify and address supply chain deficiencies.

For more information on government contracting visit:

Cybersecurity Maturity Model Certification (CMMC)

The Cybersecurity Maturity Model Certification is a jointly-developed model for assessing and certifying organizations’ cybersecurity readiness and hygiene. Overseen by the Department of War, the CMMC reviews and combines various cybersecurity standards and best practices and maps these controls and processes across several maturity levels. For a given CMMC level, the associated controls and processes, when implemented, will reduce risk against a specific set of cyber threats.

To determine whether your business has met the requirements for government contracting visit:

APEX Accelerators

APEX Accelerators, formerly known as Procurement Technical Assistance Centers, provide no-cost assistance to businesses seeking to sell to federal, state, and local governments, as well as to prime contractors. More than 90 APEX Accelerators operate nationwide, offering one-on-one guidance on registrations, certifications, finding opportunities, and responding to government solicitations. Find an APEX Accelerator.

More on Cybersecurity for Small Businesses

To continue learning about Cybersecurity for Small Businesses, view our next section:

Additional Small Business Resources

Already in business or thinking about starting your own small business? Check out our various small business resources:

Remember, you can also receive free professional business advice and free or low-cost business training from your local Small Business Development Center!

Categories
Archives

Business
Advising?

Economic
Study?

We can help....

GIS
Maps?

Learn more...

Market
Research?

Get started...