Cybersecurity, Privacy, & AI

Trending Now
CMMC Compliance as a Service: A New Model for DOW Contractors • GSA Announces a Fresh Cohort of Presidential Innovation Fellows • Supreme Court Justices Skeptically Question Both Sides in Geofence Surveillance Case • Pentagon Workers Vibe-Code 100,000 AI ‘Agents’ to Use on Unclassified Networks • CISA, UK NCSC Warn of China-Linked Covert Cyber Networks in New Advisory

Parsing the Meaning of Performance Risk Scores

Travel mania | Shutterstock

Under a new interim rule, Defense Department contractors must have a current assessment on file of their compliance with the security controls in NIST SP 800-171, to be considered for an award. The department has recently taken two little-noticed actions that may provide some insight into how it plans to use these assessment scores.

  • First, DoD added to a FAQ list a note that such scores were intended to be used to support “basic,” “medium,” and “high” assessments and to provide “an objective assessment of a contractor’s NIST 800-171 implementation status.” The department also clarified that there will not be a score threshold for “passing.”
  • A proposed rule makes these summary scores a required evaluation factor for all solicitations for supplies and services, including those for commercial items, and amends DFARS by requiring contracting officers to use them as a factor in determining responsibility to “reduce supply chain risk.”

Stay compliant and protected with daily updates on cybersecurity, data privacy, and federal oversight with our Cyber & Privacy newsletter, delivering up-to-the-minute intelligence Monday–SaturdaySubscribe here.