Cybersecurity, Privacy, & AI

Trending Now
OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns • Cyber-attacks Against State Water Supplies Continue—12 to Date • A Crucial Cybersecurity System Is Getting a Closer Look From Congress • Why Federal AI Governance Must Be Built for Continuous Change • NATO and an AI Startup Can Now Name and Track Software Vulnerabilities

Show Me Your SSPs: DOD to Begin Requesting and Assessing Contractors’ System Security Plans

Den Rise | Shutterstock

At a recent Town Hall Meeting hosted by the CMMC Accreditation Body, a Defense Contract Management Agency representative announced that they will begin assessing contractors’ compliance against NIST SP 800-171 security controls through the “Medium Assessment” process that the DoD prescribed in the interim rule that created Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7020. In a Medium Assessment, the Government reviews the contractor’s current documentation (primarily the System Security Plan) and the contractor’s previous self-assessment, which contractors were required to complete by November 2020. The representative explained that he expects these assessments to begin in “a couple months.”

Source:

Stay compliant and protected with daily updates on cybersecurity, data privacy, and federal oversight with our Cyber & Privacy newsletter, delivering up-to-the-minute intelligence Monday–SaturdaySubscribe here.