Cybersecurity, Privacy, & AI

Trending Now
OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns • Cyber-attacks Against State Water Supplies Continue—12 to Date • A Crucial Cybersecurity System Is Getting a Closer Look From Congress • Why Federal AI Governance Must Be Built for Continuous Change • NATO and an AI Startup Can Now Name and Track Software Vulnerabilities

Contractors: Get Ready for Tighter DOD Supply Chain Enforcement

The Defense Department has been ramping up efforts to quash supply chain vulnerabilities with enhanced cybersecurity guidance that gives the organization greater access to contractors’ security protocols and controls, even before awarding a contract.

A set of guidance documents released in November gave contractors a new urgency when considering security and partnering with the DoD. One requires self-attestation to comply with DFARS and the NIST Cybersecurity Framework, as well as on-site assessments and “enhanced cybersecurity measures in addition to the security requirements in NIST SP 800-171 to safeguard information stored on the contractor’s internal unclassified information system” before an award is made.

DOD expects contractors to already have a system security plan, along with plans of action and milestones, in place and outlines the consequences to the government if the security standards are not met.

Stay compliant and protected with daily updates on cybersecurity, data privacy, and federal oversight with our Cyber & Privacy newsletter, delivering up-to-the-minute intelligence Monday–Saturday — Subscribe here.