Cybersecurity, Privacy, & AI

Trending Now
Agriculture Department Kicks Off $300M Palantir Deal on IT, National Security Work • Vercel Attack Fallout Expands to More Customers and Third-Party Systems • Seeing the Cyber in Economic Statecraft • Responding to a Data Breach: How to Preserve the Attorney-Client Privilege • NIST Cyber Center to Launch OT ‘Visibility’ Project

Five Compliance Challenges Clients Face When Implementing NIST 800-171

Wiley Rein LLP highlights five key questions that have emerged in companies’ efforts to comply with the “adequate security” standard in NIST Special Publication 800-171, “Protecting Unclassified Information in Nonfederal Information Systems and Organizations.”

  • Can I Segregate My Covered DOD Information System from my Commercial Systems? This is possible and may be a viable way to harden a system used for DOD contracting while avoiding a complete redesign of other existing commercial systems.
  • What Information Systems Are Covered? Determining which systems handle Covered Defense Information begins with data identified as such in the contract, but extends to data handled in support of performing the contract.
  • How Do I Determine If I Have Complied With NIST 800-171? Structured internal audits and consulting with outside vendors can overcome the intentional ambiguity in the security controls.
  • What Do I Do If I Have Identified Gaps? Creating a System Security Plan that documents any gaps in Plans of Action and Milestones will buy a company time.
  • How Do I Address Ambiguities in the Security Controls? Documenting the good-faith steps taken to comply is the best defense.

More at Wiley Rein

Stay compliant and protected with daily updates on cybersecurity, data privacy, and federal oversight with our Cyber & Privacy newsletter, delivering up-to-the-minute intelligence Monday–SaturdaySubscribe here.