Part Three: FAR Ruling 52.204-21 Definitions

By Eric Noonan • July 19, 2016

This is part three of a continuing series on the Federal Acquisition Register ruling 52.204-21, Basic Safeguarding of Covered Contractor Information Systems.  If you haven’t read part one or part two,  please take a few minutes to read it before continuing.

The recent FAR ruling, released with input from the General Services Administration (GSA) and the National Aeronautics and Space Administration (NASA), have expanded on definitions that affect contractor organizations that process or store Federal contract information on behalf of the federal government in support of government contracts.  This post with explore the definitions in an attempt to bring a little clarity to the vague terms that apply to these systems.

Covered contractor information system:  This is an umbrella term covering unclassified information systems that are owned or operated by a contractor.   A covered contractor information system can apply to a single system, or multiple systems networked together.  File servers, data backup systems, desktop, and mobile endpoints can be considered a covered contractor information system if it processes, stores or transmits Federal contract information.

Federal contract information: This means information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government. This does not include information provided by the Government to the public (such as that on public web sites) or simple transactional information, such as that necessary to process payments.

Information system: This term as defined by FAR clause 52.204-21, is a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information.  The traditional definition of an information system is any organized system for the collection, organization, processing, storage, and communication of information.  Organizations and people use information systems to collect, filter, process, create and distribute data often times using networked computers.  A typical information system is made up of hardware, software, data, policies and procedures, people, and feedback.

Information: Traditionally, information is defined as facts provided about something or someone or something that is conveyed or represented by a particular arrangement.  In the context defined by FAR clause 52.204-21, this term means any communication or representation of knowledge such as facts, data or opinions in any medium or form, including textual, numerical, graphic, cartographic, narrative, or audiovisual.  It is important to note that any medium is covered under this definition, so the focus will not just be electronic systems, but also safeguarding digital and non-digital media.

Whether your organization is just learning about the new FAR ruling for the first time, or you are updating your security controls to be compliant, CyberSheath can help you.  Don’t wait to begin your path to compliance.

CyberSheath Blog

Dr. Robert Spalding to Address Nation-State Attacks at CMMC Con 2021

Since the inaugural CMMC Con, we’ve seen some of the most malicious attacks on American infrastructure ever executed. The SolarWinds attack reverberated across the entire government as agencies scrambled to discover what nation-state attackers had accessed and stolen. The Colonial Pipeline, shut down by a ransomware attack, led to fuel…

CMMCEnclave: Add Versatility with a More Flexible Approach

The enclave approach to CMMC compliance is one of the most cost effective and least disruptive ways to safeguard CUI. You can maintain high-value custodial security of CUI without upending your existing processes, procedures, and people. That way, you can maintain the proper level of CMMC compliance and remain eligible…

CMMC Con 2021 Opens Registration, Reveals Theme and Speakers

CMMC compliance stands in the way of revenue for every defense contractor in the supply chain. Now that CMMC is a reality for the Defense Industrial Base (DIB), learn how contractors — primes and subs, large and small, foreign-owned — are handling the standards and requirements, as well as the…

Our Trusted Partners

Cyberark McAfee Thycotic RSA Tenable Alien Vault Alert Logic Microsoft

CMMC Con 2021 is here! Save your spot to hear the latest on CMMC from our expert speakers across the government and Defense Industrial Base.