Request Demo

DFARS, Cybersecurity Frameworks

Reading Between the Lines of NIST SP 800-171 Rev 2 and 800-171B Drafts

down-arrow

On June 19th, the National Institute of Standards and Technology (NIST) released the much anticipated Rev 2 of SP 800-171 and the working draft of supplement SP 800-171B. As the core part of the Defense Federal Acquisition Regulation Supplement (DFARS) cybersecurity requirements, SP 800-171 focuses on protecting controlled unclassified information (CUI) for Department of Defense contractors. For some contractor information systems managers, these are the minimum security standards and for some, SP 800-171 is bringing the organization up to adequate security to secure DoD contracts.

The Changing Landscape of DoD Cybersecurity

For especially the lower subcontractors, the DFARS requirements required the establishment of systems security operations to reach compliance. To date, DFARS cyber compliance has been a self-certification process, with representatives signing off on their compliance with SP 800-171 with little activity from the DoD to assess compliance. However, as we’ve seen, the self-certification model has proved untenable from a security perspective and the DoD is in the process of developing a new process that does not rely on self-certification. These new revisions, especially SP 800-171B are indicators of that shift. The supplement to the core SP 800-171 that all contractors must follow, 800-171B appears to be the first indicator or a tiered system between levels of security for contractors.

The Cybersecurity Maturity Model Certification

While we have yet to see concrete documentation on the DoD’s new certification, the Cybersecurity Maturity Model Certification (CMMC), CyberSaint CPO Padraic O’Reilly predicts that SP 800-171B is the precursor to the four-tiered model: “The SP 800-171B is a precursor to the upcoming CMMC that the Department of Defense is currently working on - this supplement, though, appears to be targeted at primes and high-level subcontractors given the specificity of certain aspects.” said O’Reilly of the draft supplement. The higher levels of the certification would certainly point to contractors higher on the supply chain while the more easily achievable levels are more focused on the lower levels of the DoD supply chain.

Where We Go From Here

NIST SP 800-171 V2 was one of the most widely anticipated publications from the National Institute of Standards and Technology in 2019 and given the changing tune of the DoD on the merits (or lack thereof) of compliance self-certification the DFARS mandate specifically related to the security of CUI is up for a serious change in 2020 and beyond. While the specifics are yet to be seen, Rev 2 of SP 800-171 certainly gives insight into the early stages of these new processes and requirements.

You may also like

What is the CCPA and Who Must ...
on August 30, 2019

Following the European Union's General Data Protection Regulation (GDPR), and falling in line with the privacy laws of Massachusetts, Vermont, Ohio and many others, California's ...

Alison Furneaux
CISOs in the Boardroom: ...
on September 3, 2019

This week, I had the opportunity to speak at the ISACA 2019 Governance Risk and Control Conference in Ft. Lauderdale, FL. Having spent a career as both a cybersecurity ...

George Wrenn
Why GRC Needs IRM
on September 3, 2019

Today, every organization strives to optimize the speed with which they access information. Data is being stored, processed, transmitted and utilized in almost every day-to-day ...

Alison Furneaux
SSP and POAM Guidance for DFARS ...
on August 29, 2019

Defense federal acquisition regulation supplement (DFARS) Compliance has been top of mind for Prime contractors as well as Department of Defense (DoD) suppliers since before the ...

Alison Furneaux
Integrated Risk Management Magic ...
on September 3, 2019

It has been roughly one year since Gartner released the 2018 Magic Quadrant for Integrated Risk Management, the first of its kind, and as of this week the second Integrated Risk ...

Alison Furneaux
"Glass-box" Solutions Are Critical ...
on September 3, 2019

With the likes of Equifax and Marriott, it is no secret that cybersecurity has made its way into the Boardroom. While many executives are experienced in managing myriad business ...