Cybersecurity, Privacy, & AI

Trending Now
Anthropic’s Reported $30B Funding Talks Spotlight AI’s Growing Role in Cybersecurity, Defense • DC3 Seeks New Contractors for DCISE Voluntary Cyber Information-Sharing Program • Pentagon Cyber Official Calls Advanced AI ‘Revolutionary Warfare’ • NIST Aims for Summer Release of AI Cyber Guidelines • President Trump’s Cyber Strategy: Cross-Sector Implications for U.S. and UK Businesses

Parsing the Meaning of Performance Risk Scores

Travel mania | Shutterstock

Under a new interim rule, Defense Department contractors must have a current assessment on file of their compliance with the security controls in NIST SP 800-171, to be considered for an award. The department has recently taken two little-noticed actions that may provide some insight into how it plans to use these assessment scores.

  • First, DoD added to a FAQ list a note that such scores were intended to be used to support “basic,” “medium,” and “high” assessments and to provide “an objective assessment of a contractor’s NIST 800-171 implementation status.” The department also clarified that there will not be a score threshold for “passing.”
  • A proposed rule makes these summary scores a required evaluation factor for all solicitations for supplies and services, including those for commercial items, and amends DFARS by requiring contracting officers to use them as a factor in determining responsibility to “reduce supply chain risk.”

Stay compliant and protected with daily updates on cybersecurity, data privacy, and federal oversight with our Cyber & Privacy newsletter, delivering up-to-the-minute intelligence Monday–SaturdaySubscribe here.