Cybersecurity, Privacy, & AI

Trending Now
Anthropic’s Reported $30B Funding Talks Spotlight AI’s Growing Role in Cybersecurity, Defense • DC3 Seeks New Contractors for DCISE Voluntary Cyber Information-Sharing Program • Pentagon Cyber Official Calls Advanced AI ‘Revolutionary Warfare’ • NIST Aims for Summer Release of AI Cyber Guidelines • President Trump’s Cyber Strategy: Cross-Sector Implications for U.S. and UK Businesses

Findings of DoD Audit and Recommendations for Cyber Enforcement

Olivier Le Moal | Shutterstock

In an article published by Law360, Bass Berry & Sims examined a report issued by the U.S. Department of Defense (DoD) Inspector General on July 23, which summarizes the findings of an audit into the protection of controlled unclassified information (CUI) on contractor networks.

The DoD reviewed nine contractors’ information systems and revealed some deficiencies that do not meet the standards set forth in National Institute of Standards and Technology (NIST) Special Publication 800-171. The exposed deficiencies include: not mitigating vulnerabilities on their networks and systems, not scanning their network for vulnerabilities, not mitigating high vulnerabilities identified in the contractor’s management programs and more.

To address these deficiencies, the report contained multiple recommendations for the DoD to better validate and enforce compliance with NIST standards. In response, the DoD has already agreed to implement many of the recommendations listed in the report, including a pilot program to establish a department-wide approach for assessing contractor compliance with NIST standards.

“How the planned pilot program will interact with the DoD’s announced plans for the cybersecurity maturity model certification and the shift to third party certifiers is an open question but should serve as another signal that the DoD is ramping up its oversight and enforcement efforts. Indeed, contractors who fail to comply with NIST standards may soon find themselves at a significant competitive disadvantage,” we explained in the article.

Stay compliant and protected with daily updates on cybersecurity, data privacy, and federal oversight with our Cyber & Privacy newsletter, delivering up-to-the-minute intelligence Monday–SaturdaySubscribe here.