Safeguarding of Contractor Information Systems Expands Beyond DFARS 252-204.7012

By Eric Noonan • June 1, 2016

 * This is the first in a multi-part series on the new FARS 4.19 clause.

Recently, the US Government issued a final rule to the Federal Acquisition Regulations (FAR) to “add a new subpart and contract clause for the basic safeguarding of contractor information systems that process, store, or transmit Federal contract information”.  This is a new mandatory regulation, similar to the requirements established by the US Department of Defense with the Defense Federal Acquisition Regulation Supplement (DFARS).

On May 16, 2016, the final FAR ruling was issued, 48 C.F.R. Part 4.19 establishing minimum safeguarding requirements for federal contractor information systems and expressly provide that Federal agencies and departments may impose additional specific requirements.  The new FAR regulation goes into effect on June 16, 2016.  DoD, as mentioned in previous blogs has already amended its regulations to require covered contractors to comply with DFARS 252.204-7012. The new FAR 4.19 clause applies to all federal contractor information systems that are owned or operated by a contractor that processes, stores, or transmits Federal contract information.  While the new regulation does not require compliance with any specific NIST standards, unlike the DFARS regulation that requires NIST SP 800-171 compliance, the new regulation lists many of the same 14 control families detailed in 800-171.

CyberSheath can help you meet your compliance objectives and requirements, contact us today.

Cybersheath Blog

3 Reasons Why You Need a Privileged Access Risk Assessment

A privileged account is one used by administrators to log in to servers, networks, firewalls, databases, applications, cloud services and other systems used by your organization. These accounts give enhanced permissions that allow the privileged user to access sensitive data or modify key system functions, among other things. You can…

Incident Response – Learning the Lesson of Lessons Learned

“Those who do not learn from history are condemned to repeat it.” Over the years, variations of this famous quote have been spoken by everyone from philosophers to world leaders. The message — that we must learn from our mistakes or continue to repeat them — is also highly relevant…

What is DFARS 252.204-7012 and NIST SP 800-171?

With the Department of Defense (DoD) promising the release of an update to NIST Special Publication 800-171, it is imperative defense contractors understand what DFARS 252.204-7012 and NIST SP 800-171 Clause is and how noncompliance with the Clause will impact their business.  Compliance is mandatory for contractors doing business with…

Our Trusted Partners

Cyberark McAfee Thycotic RSA Tenable Alien Vault Alert Logic Trace Security