SlideShare ist ein Scribd-Unternehmen logo
1 von 28
Downloaden Sie, um offline zu lesen
Federal Government Contracting
CYBERSECURITY REQUIREMENTS
hello@JenniferSchaus.com
Cybersecurity Compliance & Enforcement for Federal Contractors
Cybersecurity Compliance &
Enforcement for Federal Contractors
Friday, September 30, 2022
12pm EST
Federal Government Contracting
CYBERSECURITY REQUIREMENTS
hello@JenniferSchaus.com
Cybersecurity Compliance & Enforcement for Federal Contractors
About Jschaus & Associates:
Ø Washington DC based
Ø Consulting firm working with established Federal Contractors;
Ø Webinars, Events, Conferences;
Ø Newsletter – reaching 23K Federal Contractors;
Ø 500+ Webinars on YouTube;
Ø Advertising & Sponsor Opportunities
Federal Government Contracting
CYBERSECURITY REQUIREMENTS
hello@JenniferSchaus.com
Cybersecurity Compliance & Enforcement for Federal Contractors
About Arnold & Porter:
Ø Top-ranked Government Contracts practice
Ø Represent the entire spectrum of domestic and international government
contractors: start-ups, Fortune 100 companies, and non-profits
Ø Help address the increasingly complex cyber issues confronting
commercial businesses, government contractors, and the special concerns
associated with work for DoD and intelligence agencies
Federal Government Contracting
CYBERSECURITY REQUIREMENTS
hello@JenniferSchaus.com
Cybersecurity Compliance & Enforcement for Federal Contractors
MEET OUR SPEAKERS
Federal Government Contracting
CYBERSECURITY REQUIREMENTS
hello@JenniferSchaus.com
Cybersecurity Compliance & Enforcement for Federal Contractors
Sonia Tabriz
sonia.tabriz@arnoldporter.com
202.942.6574
Federal Government Contracting
CYBERSECURITY REQUIREMENTS
hello@JenniferSchaus.com
Cybersecurity Compliance & Enforcement for Federal Contractors
Tom Pettit
thomas.pettit@arnoldporter.com
202.942.6075
Federal Government Contracting
CYBERSECURITY REQUIREMENTS
hello@JenniferSchaus.com
Cybersecurity Compliance & Enforcement for Federal Contractors
Agenda
• Cybersecurity Requirements
• CMMC Overview and Updates
• Enforcement
7
Federal Government Contracting
CYBERSECURITY REQUIREMENTS
hello@JenniferSchaus.com
Cybersecurity Compliance & Enforcement for Federal Contractors
CYBERSECURITY REQUIREMENTS
8
Federal Government Contracting
CYBERSECURITY REQUIREMENTS
hello@JenniferSchaus.com
Cybersecurity Compliance & Enforcement for Federal Contractors
FAR 52.204-21, Basic Safeguarding of Covered Contractor Information
Systems
• Applies to any information system “owned or operated by a contractor that processes,
stores, or transmits” “federal contract information” (FCI)
• FCI is any information “not intended for public release” obtained from or developed for the
Government in the performance of a contract
• Establishes baseline security standards, such as:
• Identifying users, processes, and devices (e.g., personal identity verification (PIV))
• Limiting access to information systems to only authorized users, processes, and devices (e.g., mandating passwords,
managing group policies, and maintaining the Windows Registry)
• Installing and updating antivirus software and other protections against malicious code; scanning for malware
• Regulating physical access to information systems and facilities
9
Federal Government Contracting
CYBERSECURITY REQUIREMENTS
hello@JenniferSchaus.com
Cybersecurity Compliance & Enforcement for Federal Contractors
DFARS 252.204-7012, Safeguarding Covered Defense Information and
Cyber Incident Reporting
• Applies to DoD contractors with information systems that will store, process, or transmit controlled
unclassified information (CUI) collected, developed, received, transmitted, used, or stored by or on
behalf of the contractors in support of the performance of the contract
• Two key elements: security controls and cyber incident reporting
• Security Controls
• Implement security controls in NIST SP 800-171
• Document security controls in system security plan
• Develop plan of action for any controls not implemented
10
Federal Government Contracting
CYBERSECURITY REQUIREMENTS
hello@JenniferSchaus.com
Cybersecurity Compliance & Enforcement for Federal Contractors
DFARS 252.204-7012, Safeguarding Covered Defense Information and
Cyber Incident Reporting
• Security Controls
• NIST SP 800-171 compliance is generally a self-assessment system with a few caveats:
• System security plans and plans of action can be (but typically are not) formal contract deliverables
• Contractor must submit requests to vary from NIST SP 800-171 to the contracting officer for review by the DoD
CIO
• DIBCAC Assessments, DFARS 252.204-7019, and DFARS 252.204-7020
• Cloud Services
• CSPs must meet security requirements equivalent to the Federal Risk and Authorization Management Program
(FedRAMP) Moderate baseline
11
Federal Government Contracting
CYBERSECURITY REQUIREMENTS
hello@JenniferSchaus.com
Cybersecurity Compliance & Enforcement for Federal Contractors
DFARS 252.204-7012, Safeguarding Covered Defense Information and
Cyber Incident Reporting
• Cyber Incident Reporting
• Cyber Incident: Actions taken through the use of computer networks that result in a compromise
or an actual or potentially adverse effect on an information system and/or the information
residing therein
• Compromise: Disclosure of information to unauthorized persons or a violation of the security policy
of a system and unauthorized intentional or unintentional disclosure, modification, destruction, or
loss of an object or the copying of information to unauthorized media may have occurred
• Adverse Effect: Not defined, but it could include, among other things, exfiltration, malware, DDoS
attack, ransomware attack
• Conduct a review, including assessing scope of cyber incident and impact on covered defense
information as well as ability to provide operationally critical support
• Must “rapidly” report cyber incidents through DIBNet
12
Federal Government Contracting
CYBERSECURITY REQUIREMENTS
hello@JenniferSchaus.com
Cybersecurity Compliance & Enforcement for Federal Contractors
DFARS 252.204-7012, Safeguarding Covered Defense Information and
Cyber Incident Reporting
• Cyber Incident Reporting
• Submit malicious software to the DoD Cyber Crime Center
• Preserve information (images of information systems and monitoring/packet capture data) for at
least 90 days after reporting cyber incident
• DoD has right to perform forensic analysis and damage assessment, and contractor must
cooperate
• Subcontract flow down
13
Federal Government Contracting
CYBERSECURITY REQUIREMENTS
hello@JenniferSchaus.com
Cybersecurity Compliance & Enforcement for Federal Contractors
DFARS 252.204-7019 & -7020, NIST SP 800-171 Assessments
• Apply to all solicitations and contracts that exceed the micro-purchase threshold and are not
exclusively for the acquisition of commercially available off-the-shelf (COTS) items
• Four Components:
• Weighted Score
• 110-point, weighted scoring system that measures the extent to which an offeror or contractor has implemented
the NIST SP 800-171 security controls.
• Standardized scoring methodology that assigns greater points to requirements that have greater impact on the
security of the network and its data than others.
• Confidence Levels
• Basic Assessment/Low Confidence: Self-assessment and self-generated score
• Medium Assessment/Confidence: DoD reviews Basic Assessment and associated documentation and discusses
any concerns with the contractor
• High Assessment/Confidence: Medium Assessment + verification, examination, and demonstration of SSP
14
Federal Government Contracting
CYBERSECURITY REQUIREMENTS
hello@JenniferSchaus.com
Cybersecurity Compliance & Enforcement for Federal Contractors
DFARS 252.204-7019 & -7020, NIST SP 800-171 Assessments
• Four Components:
• Rebuttal and Adjudication: Contractor may, within 14 days, dispute any aspect of a DoD assessment
• Reporting: Contractor must enter data into the Supplier Performance Risk System (summary level score,
type of assessment, description of the SSP architecture, assessment date, and date when contractor will
achieve perfect score)
• American Fuel Cell & Coated Fabrics Co., B-420551, B-420551.2, June 2, 2022, 2022 CPD ¶ 139
15
Federal Government Contracting
CYBERSECURITY REQUIREMENTS
hello@JenniferSchaus.com
Cybersecurity Compliance & Enforcement for Federal Contractors
CMMC OVERVIEW AND UPDATES
16
Federal Government Contracting
CYBERSECURITY REQUIREMENTS
hello@JenniferSchaus.com
Cybersecurity Compliance & Enforcement for Federal Contractors
Why CMMC?
• DFARS 252.204-7012 relies on contractor self-assessments
• There is no mandatory government oversight
• DoD concluded that the “Scout’s Honor” system was ineffective
• A 2018 National Defense Industrial Association (NDIA) survey revealed that 36% of contractors who responded were
not aware of DFARS 252.204-7012, and 45% of the respondents admitted that they had never read NIST SP 800-171
• A 2019 NDIA survey revealed that only 56% of defense contractors were prepared for a DCMA assessment of NIST SP
800-171 compliance
17
Federal Government Contracting
CYBERSECURITY REQUIREMENTS
hello@JenniferSchaus.com
Cybersecurity Compliance & Enforcement for Federal Contractors
CMMC Overview and Updates
• DoD determined that more must be done to harden the DIB's and defense supply chain's
cyber infrastructure
• Verification is not required
• Industry surveys have indicated that many contractors are noncompliant
• Cyber incidents have increased
• CMMC 1.0
• Released in January 2020
• Five maturity levels (two transitional) and would have to be certified to be eligible for contracts
incorporating CMMC requirements
18
Federal Government Contracting
CYBERSECURITY REQUIREMENTS
hello@JenniferSchaus.com
Cybersecurity Compliance & Enforcement for Federal Contractors
CMMC Overview and Updates
• CMMC 2.0
• “Announced” in November 2021
• Streamlined requirements
• CMMC-unique security practices removed
• New iteration will have three maturity levels instead of five (CMMC 1.0 Levels 2 and 3 removed)
• Level 1: Security controls for FCI
• Level 2: 110 NIST SP 800-171 security controls for CUI
• Level 3: 110 NIST SP 800-171 security controls for CUI, plus some subset of NIST SP 800-172
• Plans of action generally not allowed, with exceptions only for minor noncompliance
19
Federal Government Contracting
CYBERSECURITY REQUIREMENTS
hello@JenniferSchaus.com
Cybersecurity Compliance & Enforcement for Federal Contractors
CMMC Overview and Updates
• Assessments
• Level 1 is achieved through a self assessment and attestation of compliance
• Level 2 generally requires third-party assessments through accredited CMMC Third Party
Assessment Organizations (C3PAOs), but self-assessments are permitted if contract
requirements do not involve information critical to national security
• Level 3 must be assessed by USG officials
• Interim rule is expected around March 2023, and CMMC may be incorporated into
solicitations and RFIs shortly thereafter
20
Federal Government Contracting
CYBERSECURITY REQUIREMENTS
hello@JenniferSchaus.com
Cybersecurity Compliance & Enforcement for Federal Contractors
ENFORCEMENT
21
Federal Government Contracting
CYBERSECURITY REQUIREMENTS
hello@JenniferSchaus.com
Cybersecurity Compliance & Enforcement for Federal Contractors
Contract-Based Remedies
• In June 2022, DoD issued a memorandum reminding Contracting Officers of available contract-based
remedies for noncompliance with DFARS 252.204-7012 and the corresponding NIST SP 800-171 requirements
22
Federal Government Contracting
CYBERSECURITY REQUIREMENTS
hello@JenniferSchaus.com
Cybersecurity Compliance & Enforcement for Federal Contractors
Civil Cyber-Fraud Initiative
• In October 2021, the Department of Justice (DoJ) announced a new Civil Cyber-Fraud Initiative that leverages
the False Claims Act (FCA) to combat cyber threats
• Deputy Attorney General Lisa O. Monaco stated:
• “For too long, companies have chosen silence under the mistaken belief that it is less risky to hide a breach than to
bring it forward and to report it. Well that changes today. We are announcing today that we will use our civil
enforcement tools to pursue companies, those who are government contractors who receive federal funds, when
they fail to follow required cybersecurity standards — because we know that puts all of us at risk. This is a tool that
we have to ensure that taxpayer dollars are used appropriately and guard the public fisc and public trust.”
• In a recent Comprehensive Cyber Review report, DOJ confirmed that it plans to “lead the effort to enforce
cybersecurity requirements on federal contractors and grantees” and further announced its desire to
participate in developing those requirements
23
Federal Government Contracting
CYBERSECURITY REQUIREMENTS
hello@JenniferSchaus.com
Cybersecurity Compliance & Enforcement for Federal Contractors
Civil Cyber-Fraud Initiative
• DoJ has identified the following benefits of the Civil Cyber-Fraud Initiative:
• Building broad resiliency against cybersecurity intrusions across the government, the public sector and key industry
partners
• Holding contractors and grantees to their commitments to protect government information and infrastructure
• Supporting government experts’ efforts to timely identify, create and publicize patches for vulnerabilities in
commonly-used information technology products and services
• Ensuring that companies that follow the rules and invest in meeting cybersecurity requirements are not at a
competitive disadvantage
• Reimbursing the government and the taxpayers for the losses incurred when companies fail to satisfy their
cybersecurity obligations
• Improving overall cybersecurity practices that will benefit the government, private users and the American public
24
Federal Government Contracting
CYBERSECURITY REQUIREMENTS
hello@JenniferSchaus.com
Cybersecurity Compliance & Enforcement for Federal Contractors
Civil Cyber-Fraud Initiative
• DoJ has stated that the following types of contracts will be the focus of its enforcement efforts:
• Software and hardware procurement
• Developing, implementing or maintaining IT systems owned by the federal government
• Use of the contractor’s IT systems, especially if the systems maintain government data
• Cloud services
• Contracts that incorporate a regulatory, statutory or contractual requirement to monitor and report a cyber
breach or incident
• DoJ has also stated that it expects qui tam relators to play a significant role in implementing the
Civil Cyber-Fraud Initiative
• DoJ has already announced results of its enforcement efforts
25
Federal Government Contracting
CYBERSECURITY REQUIREMENTS
hello@JenniferSchaus.com
Cybersecurity Compliance & Enforcement for Federal Contractors
Other Potential Risks
• Bid protest litigation
• Subcontract flow down negotiations and disputes
• Suspension and debarment
26
Federal Government Contracting
CYBERSECURITY REQUIREMENTS
hello@JenniferSchaus.com
Cybersecurity Compliance & Enforcement for Federal Contractors
QUESTIONS?
Please Contact Our Speakers:
Sonia Tabriz
sonia.tabriz@arnoldporter.com
202.942.6574
Tom Pettit
thomas.pettit@arnoldporter.com
202.942.6574
27
Federal Government Contracting
CYBERSECURITY REQUIREMENTS
hello@JenniferSchaus.com
Cybersecurity Compliance & Enforcement for Federal Contractors
THANK YOU FOR ATTENDING
28

Weitere ähnliche Inhalte

Was ist angesagt?

SubContracting Opportunities - Department Of the Interior
SubContracting Opportunities - Department Of the InteriorSubContracting Opportunities - Department Of the Interior
SubContracting Opportunities - Department Of the InteriorJSchaus & Associates
 
2022 Procurement Playbook - DHS - (07/01/2022)
2022 Procurement Playbook - DHS - (07/01/2022)2022 Procurement Playbook - DHS - (07/01/2022)
2022 Procurement Playbook - DHS - (07/01/2022)JSchaus & Associates
 
GSA Schedules - Top To Bottom - 12/08/2022
GSA Schedules - Top To Bottom - 12/08/2022GSA Schedules - Top To Bottom - 12/08/2022
GSA Schedules - Top To Bottom - 12/08/2022JSchaus & Associates
 
Top 40 Federal Contractors - PROFILE #1 - Lockheed Martin
Top 40 Federal Contractors - PROFILE #1 - Lockheed MartinTop 40 Federal Contractors - PROFILE #1 - Lockheed Martin
Top 40 Federal Contractors - PROFILE #1 - Lockheed MartinJSchaus & Associates
 
2024: The FAR, Federal Acquisition Regulations - Part 6
2024: The FAR, Federal Acquisition Regulations - Part 62024: The FAR, Federal Acquisition Regulations - Part 6
2024: The FAR, Federal Acquisition Regulations - Part 6JSchaus & Associates
 
Marketing to The Federal Government
Marketing to The Federal Government Marketing to The Federal Government
Marketing to The Federal Government JSchaus & Associates
 
Marketing Basics For US Federal Government Contractors
Marketing BasicsFor US Federal Government ContractorsMarketing BasicsFor US Federal Government Contractors
Marketing Basics For US Federal Government ContractorsJSchaus & Associates
 
Landing Links on Top Tier Press - what you should be doing in a competitive s...
Landing Links on Top Tier Press - what you should be doing in a competitive s...Landing Links on Top Tier Press - what you should be doing in a competitive s...
Landing Links on Top Tier Press - what you should be doing in a competitive s...Carrie Rose
 
SEO Success in 2021 - #IWES2021
SEO Success in 2021 - #IWES2021SEO Success in 2021 - #IWES2021
SEO Success in 2021 - #IWES2021Aleyda Solís
 
SEOWars: Rstudio aplicado a SEO #sob22
SEOWars: Rstudio aplicado a SEO #sob22SEOWars: Rstudio aplicado a SEO #sob22
SEOWars: Rstudio aplicado a SEO #sob22MJ Cachón Yáñez
 
Winning SEO when doing Web Migrations #SMSSYD19
Winning SEO when doing Web Migrations #SMSSYD19Winning SEO when doing Web Migrations #SMSSYD19
Winning SEO when doing Web Migrations #SMSSYD19Aleyda Solís
 
Identifying Top Converting Queries at Every Stage of the Customer Journey #SM...
Identifying Top Converting Queries at Every Stage of the Customer Journey #SM...Identifying Top Converting Queries at Every Stage of the Customer Journey #SM...
Identifying Top Converting Queries at Every Stage of the Customer Journey #SM...Aleyda Solís
 
Growing energy crops in Eastern Europe -
Growing energy crops in Eastern Europe - Growing energy crops in Eastern Europe -
Growing energy crops in Eastern Europe - Haim R. Branisteanu
 
BrightonSEO Slides April 2023
BrightonSEO Slides April 2023BrightonSEO Slides April 2023
BrightonSEO Slides April 2023Cheryl Luzet
 
Winning SEO when doing Web Migrations #SEO4Life
Winning SEO when doing Web Migrations #SEO4LifeWinning SEO when doing Web Migrations #SEO4Life
Winning SEO when doing Web Migrations #SEO4LifeAleyda Solís
 
7 E-Commerce SEO Mistakes & How to Fix Them #DeepSEOCon
7 E-Commerce SEO Mistakes & How to Fix Them #DeepSEOCon7 E-Commerce SEO Mistakes & How to Fix Them #DeepSEOCon
7 E-Commerce SEO Mistakes & How to Fix Them #DeepSEOConAleyda Solís
 
Web Server SEO: Make your TTFB faster!
Web Server SEO: Make your TTFB faster!Web Server SEO: Make your TTFB faster!
Web Server SEO: Make your TTFB faster!Ash New
 
10 Mistakes in 10 Years in SEO - Patrick Langridge
10 Mistakes in 10 Years in SEO - Patrick Langridge10 Mistakes in 10 Years in SEO - Patrick Langridge
10 Mistakes in 10 Years in SEO - Patrick LangridgePatrick Langridge
 
The Ultimate SEO Guide for Successful Web Migrations at #DigitalOlympus
The Ultimate SEO Guide for Successful Web Migrations at #DigitalOlympusThe Ultimate SEO Guide for Successful Web Migrations at #DigitalOlympus
The Ultimate SEO Guide for Successful Web Migrations at #DigitalOlympusAleyda Solís
 

Was ist angesagt? (20)

SubContracting Opportunities - Department Of the Interior
SubContracting Opportunities - Department Of the InteriorSubContracting Opportunities - Department Of the Interior
SubContracting Opportunities - Department Of the Interior
 
2022 Procurement Playbook - DHS - (07/01/2022)
2022 Procurement Playbook - DHS - (07/01/2022)2022 Procurement Playbook - DHS - (07/01/2022)
2022 Procurement Playbook - DHS - (07/01/2022)
 
GSA Schedules - Top To Bottom - 12/08/2022
GSA Schedules - Top To Bottom - 12/08/2022GSA Schedules - Top To Bottom - 12/08/2022
GSA Schedules - Top To Bottom - 12/08/2022
 
Top 40 Federal Contractors - PROFILE #1 - Lockheed Martin
Top 40 Federal Contractors - PROFILE #1 - Lockheed MartinTop 40 Federal Contractors - PROFILE #1 - Lockheed Martin
Top 40 Federal Contractors - PROFILE #1 - Lockheed Martin
 
2024: The FAR, Federal Acquisition Regulations - Part 6
2024: The FAR, Federal Acquisition Regulations - Part 62024: The FAR, Federal Acquisition Regulations - Part 6
2024: The FAR, Federal Acquisition Regulations - Part 6
 
Marketing to The Federal Government
Marketing to The Federal Government Marketing to The Federal Government
Marketing to The Federal Government
 
Marketing Basics For US Federal Government Contractors
Marketing BasicsFor US Federal Government ContractorsMarketing BasicsFor US Federal Government Contractors
Marketing Basics For US Federal Government Contractors
 
Landing Links on Top Tier Press - what you should be doing in a competitive s...
Landing Links on Top Tier Press - what you should be doing in a competitive s...Landing Links on Top Tier Press - what you should be doing in a competitive s...
Landing Links on Top Tier Press - what you should be doing in a competitive s...
 
SEO Success in 2021 - #IWES2021
SEO Success in 2021 - #IWES2021SEO Success in 2021 - #IWES2021
SEO Success in 2021 - #IWES2021
 
SEOWars: Rstudio aplicado a SEO #sob22
SEOWars: Rstudio aplicado a SEO #sob22SEOWars: Rstudio aplicado a SEO #sob22
SEOWars: Rstudio aplicado a SEO #sob22
 
Cable electrical drawing
Cable electrical drawingCable electrical drawing
Cable electrical drawing
 
Winning SEO when doing Web Migrations #SMSSYD19
Winning SEO when doing Web Migrations #SMSSYD19Winning SEO when doing Web Migrations #SMSSYD19
Winning SEO when doing Web Migrations #SMSSYD19
 
Identifying Top Converting Queries at Every Stage of the Customer Journey #SM...
Identifying Top Converting Queries at Every Stage of the Customer Journey #SM...Identifying Top Converting Queries at Every Stage of the Customer Journey #SM...
Identifying Top Converting Queries at Every Stage of the Customer Journey #SM...
 
Growing energy crops in Eastern Europe -
Growing energy crops in Eastern Europe - Growing energy crops in Eastern Europe -
Growing energy crops in Eastern Europe -
 
BrightonSEO Slides April 2023
BrightonSEO Slides April 2023BrightonSEO Slides April 2023
BrightonSEO Slides April 2023
 
Winning SEO when doing Web Migrations #SEO4Life
Winning SEO when doing Web Migrations #SEO4LifeWinning SEO when doing Web Migrations #SEO4Life
Winning SEO when doing Web Migrations #SEO4Life
 
7 E-Commerce SEO Mistakes & How to Fix Them #DeepSEOCon
7 E-Commerce SEO Mistakes & How to Fix Them #DeepSEOCon7 E-Commerce SEO Mistakes & How to Fix Them #DeepSEOCon
7 E-Commerce SEO Mistakes & How to Fix Them #DeepSEOCon
 
Web Server SEO: Make your TTFB faster!
Web Server SEO: Make your TTFB faster!Web Server SEO: Make your TTFB faster!
Web Server SEO: Make your TTFB faster!
 
10 Mistakes in 10 Years in SEO - Patrick Langridge
10 Mistakes in 10 Years in SEO - Patrick Langridge10 Mistakes in 10 Years in SEO - Patrick Langridge
10 Mistakes in 10 Years in SEO - Patrick Langridge
 
The Ultimate SEO Guide for Successful Web Migrations at #DigitalOlympus
The Ultimate SEO Guide for Successful Web Migrations at #DigitalOlympusThe Ultimate SEO Guide for Successful Web Migrations at #DigitalOlympus
The Ultimate SEO Guide for Successful Web Migrations at #DigitalOlympus
 

Ähnlich wie Arnold & Porter Cybersecurity Compliance and Enforcement for Federal Contractors

Cybersecurity Maturity Model Certification
Cybersecurity Maturity Model CertificationCybersecurity Maturity Model Certification
Cybersecurity Maturity Model CertificationMurray Security Services
 
MCGlobalTech CMMC Managed Compliance Service
MCGlobalTech CMMC Managed Compliance ServiceMCGlobalTech CMMC Managed Compliance Service
MCGlobalTech CMMC Managed Compliance ServiceWilliam McBorrough
 
A Clear Path to NIST & CMMC Compliance - 2023 Cleveland Security Summit.pdf
A Clear Path to NIST & CMMC Compliance - 2023 Cleveland Security Summit.pdfA Clear Path to NIST & CMMC Compliance - 2023 Cleveland Security Summit.pdf
A Clear Path to NIST & CMMC Compliance - 2023 Cleveland Security Summit.pdfJack Nichelson
 
Cybersecurity for GovCons - DFARS 252.204-7012 Latest Updates and Last Call
Cybersecurity for GovCons - DFARS 252.204-7012 Latest Updates and Last CallCybersecurity for GovCons - DFARS 252.204-7012 Latest Updates and Last Call
Cybersecurity for GovCons - DFARS 252.204-7012 Latest Updates and Last CallUnanet
 
Laying the Foundation: The Need for Cybersecurity in U.S. Manufacturing
Laying the Foundation:  The Need for  Cybersecurity in  U.S. ManufacturingLaying the Foundation:  The Need for  Cybersecurity in  U.S. Manufacturing
Laying the Foundation: The Need for Cybersecurity in U.S. ManufacturingIgnyte Assurance Platform
 
MYTHBUSTERS: Can You Secure Payments in the Cloud?
MYTHBUSTERS: Can You Secure Payments in the Cloud?MYTHBUSTERS: Can You Secure Payments in the Cloud?
MYTHBUSTERS: Can You Secure Payments in the Cloud?Kurt Hagerman
 
Cybersecurity 101: Government Contracts
Cybersecurity 101: Government ContractsCybersecurity 101: Government Contracts
Cybersecurity 101: Government ContractsPatton Boggs LLP
 
New York Cybersecurity Requirements for Financial Services Companies
New York Cybersecurity Requirements for Financial Services CompaniesNew York Cybersecurity Requirements for Financial Services Companies
New York Cybersecurity Requirements for Financial Services CompaniesCitrin Cooperman
 
Cybersecurity: More than A DoD Issue
Cybersecurity: More than A DoD IssueCybersecurity: More than A DoD Issue
Cybersecurity: More than A DoD IssueRobert E Jones
 
The CMMC Has Arrived. Are You Ready?
The CMMC Has Arrived. Are You Ready?The CMMC Has Arrived. Are You Ready?
The CMMC Has Arrived. Are You Ready?Unanet
 
Government Contracting - DFARS Part 252 - Clauses - Win Federal Contracts
Government Contracting - DFARS Part 252 - Clauses - Win Federal ContractsGovernment Contracting - DFARS Part 252 - Clauses - Win Federal Contracts
Government Contracting - DFARS Part 252 - Clauses - Win Federal ContractsJSchaus & Associates
 
Cybersec Supply Chain Risks and Governance v0.1.pdf
Cybersec Supply Chain Risks and Governance v0.1.pdfCybersec Supply Chain Risks and Governance v0.1.pdf
Cybersec Supply Chain Risks and Governance v0.1.pdfDaveNjoga1
 
Webinar: Critical Steps For NIST Compliance
Webinar: Critical Steps For NIST ComplianceWebinar: Critical Steps For NIST Compliance
Webinar: Critical Steps For NIST ComplianceWithum
 
How CMMC Auditors Recommend You Defend Your Organization - Completed March, 2...
How CMMC Auditors Recommend You Defend Your Organization - Completed March, 2...How CMMC Auditors Recommend You Defend Your Organization - Completed March, 2...
How CMMC Auditors Recommend You Defend Your Organization - Completed March, 2...Ignyte Assurance Platform
 
Cyber security for manufacturers umuc cadf-ron mcfarland
Cyber security for manufacturers umuc cadf-ron mcfarlandCyber security for manufacturers umuc cadf-ron mcfarland
Cyber security for manufacturers umuc cadf-ron mcfarlandHighervista
 
A Clear Path to NIST & CMMC Compliance - 2022 Summit.pptx
A Clear Path to NIST & CMMC Compliance - 2022 Summit.pptxA Clear Path to NIST & CMMC Compliance - 2022 Summit.pptx
A Clear Path to NIST & CMMC Compliance - 2022 Summit.pptxJack Nichelson
 

Ähnlich wie Arnold & Porter Cybersecurity Compliance and Enforcement for Federal Contractors (20)

Robert Nichols: Cybersecurity for Government Contractors
Robert Nichols: Cybersecurity for Government ContractorsRobert Nichols: Cybersecurity for Government Contractors
Robert Nichols: Cybersecurity for Government Contractors
 
DFARS & CMMC Overview
DFARS & CMMC Overview DFARS & CMMC Overview
DFARS & CMMC Overview
 
Key Cyber Security Issues for Government Contractors
Key Cyber Security Issues for Government ContractorsKey Cyber Security Issues for Government Contractors
Key Cyber Security Issues for Government Contractors
 
Cybersecurity Maturity Model Certification
Cybersecurity Maturity Model CertificationCybersecurity Maturity Model Certification
Cybersecurity Maturity Model Certification
 
MCGlobalTech CMMC Managed Compliance Service
MCGlobalTech CMMC Managed Compliance ServiceMCGlobalTech CMMC Managed Compliance Service
MCGlobalTech CMMC Managed Compliance Service
 
A Clear Path to NIST & CMMC Compliance - 2023 Cleveland Security Summit.pdf
A Clear Path to NIST & CMMC Compliance - 2023 Cleveland Security Summit.pdfA Clear Path to NIST & CMMC Compliance - 2023 Cleveland Security Summit.pdf
A Clear Path to NIST & CMMC Compliance - 2023 Cleveland Security Summit.pdf
 
Cybersecurity for GovCons - DFARS 252.204-7012 Latest Updates and Last Call
Cybersecurity for GovCons - DFARS 252.204-7012 Latest Updates and Last CallCybersecurity for GovCons - DFARS 252.204-7012 Latest Updates and Last Call
Cybersecurity for GovCons - DFARS 252.204-7012 Latest Updates and Last Call
 
Laying the Foundation: The Need for Cybersecurity in U.S. Manufacturing
Laying the Foundation:  The Need for  Cybersecurity in  U.S. ManufacturingLaying the Foundation:  The Need for  Cybersecurity in  U.S. Manufacturing
Laying the Foundation: The Need for Cybersecurity in U.S. Manufacturing
 
MYTHBUSTERS: Can You Secure Payments in the Cloud?
MYTHBUSTERS: Can You Secure Payments in the Cloud?MYTHBUSTERS: Can You Secure Payments in the Cloud?
MYTHBUSTERS: Can You Secure Payments in the Cloud?
 
Cybersecurity 101: Government Contracts
Cybersecurity 101: Government ContractsCybersecurity 101: Government Contracts
Cybersecurity 101: Government Contracts
 
New York Cybersecurity Requirements for Financial Services Companies
New York Cybersecurity Requirements for Financial Services CompaniesNew York Cybersecurity Requirements for Financial Services Companies
New York Cybersecurity Requirements for Financial Services Companies
 
Cybersecurity: More than A DoD Issue
Cybersecurity: More than A DoD IssueCybersecurity: More than A DoD Issue
Cybersecurity: More than A DoD Issue
 
The CMMC Has Arrived. Are You Ready?
The CMMC Has Arrived. Are You Ready?The CMMC Has Arrived. Are You Ready?
The CMMC Has Arrived. Are You Ready?
 
Government Contracting - DFARS Part 252 - Clauses - Win Federal Contracts
Government Contracting - DFARS Part 252 - Clauses - Win Federal ContractsGovernment Contracting - DFARS Part 252 - Clauses - Win Federal Contracts
Government Contracting - DFARS Part 252 - Clauses - Win Federal Contracts
 
Cybersec Supply Chain Risks and Governance v0.1.pdf
Cybersec Supply Chain Risks and Governance v0.1.pdfCybersec Supply Chain Risks and Governance v0.1.pdf
Cybersec Supply Chain Risks and Governance v0.1.pdf
 
Webinar: Critical Steps For NIST Compliance
Webinar: Critical Steps For NIST ComplianceWebinar: Critical Steps For NIST Compliance
Webinar: Critical Steps For NIST Compliance
 
How CMMC Auditors Recommend You Defend Your Organization - Completed March, 2...
How CMMC Auditors Recommend You Defend Your Organization - Completed March, 2...How CMMC Auditors Recommend You Defend Your Organization - Completed March, 2...
How CMMC Auditors Recommend You Defend Your Organization - Completed March, 2...
 
Cyber security for manufacturers umuc cadf-ron mcfarland
Cyber security for manufacturers umuc cadf-ron mcfarlandCyber security for manufacturers umuc cadf-ron mcfarland
Cyber security for manufacturers umuc cadf-ron mcfarland
 
CMMC 2.0 Explained: Impact for SMBs
CMMC 2.0 Explained:  Impact for SMBsCMMC 2.0 Explained:  Impact for SMBs
CMMC 2.0 Explained: Impact for SMBs
 
A Clear Path to NIST & CMMC Compliance - 2022 Summit.pptx
A Clear Path to NIST & CMMC Compliance - 2022 Summit.pptxA Clear Path to NIST & CMMC Compliance - 2022 Summit.pptx
A Clear Path to NIST & CMMC Compliance - 2022 Summit.pptx
 

Mehr von JSchaus & Associates

2024: The FAR, Federal Acquisition Regulations, Part 30
2024: The FAR, Federal Acquisition Regulations, Part 302024: The FAR, Federal Acquisition Regulations, Part 30
2024: The FAR, Federal Acquisition Regulations, Part 30JSchaus & Associates
 
2024: The FAR, Federal Acquisition Regulations - Part 29
2024: The FAR, Federal Acquisition Regulations - Part 292024: The FAR, Federal Acquisition Regulations - Part 29
2024: The FAR, Federal Acquisition Regulations - Part 29JSchaus & Associates
 
2024: The FAR, Federal Acquisition Regulations - Part 28
2024: The FAR, Federal Acquisition Regulations - Part 282024: The FAR, Federal Acquisition Regulations - Part 28
2024: The FAR, Federal Acquisition Regulations - Part 28JSchaus & Associates
 
2024: The FAR, Federal Acquisition Regulations - Part 27
2024: The FAR, Federal Acquisition Regulations - Part 272024: The FAR, Federal Acquisition Regulations - Part 27
2024: The FAR, Federal Acquisition Regulations - Part 27JSchaus & Associates
 
2024: The FAR, Federal Acquisition Regulations - Part 26
2024: The FAR, Federal Acquisition Regulations - Part 262024: The FAR, Federal Acquisition Regulations - Part 26
2024: The FAR, Federal Acquisition Regulations - Part 26JSchaus & Associates
 
2024: The FAR, Federal Acquisition Regulations - Part 25
2024: The FAR, Federal Acquisition Regulations - Part 252024: The FAR, Federal Acquisition Regulations - Part 25
2024: The FAR, Federal Acquisition Regulations - Part 25JSchaus & Associates
 
2024: The FAR, Federal Acquisition Regulations - Part 24
2024: The FAR, Federal Acquisition Regulations - Part 242024: The FAR, Federal Acquisition Regulations - Part 24
2024: The FAR, Federal Acquisition Regulations - Part 24JSchaus & Associates
 
2024: The FAR, Federal Acquisition Regulations - Part 23
2024: The FAR, Federal Acquisition Regulations - Part 232024: The FAR, Federal Acquisition Regulations - Part 23
2024: The FAR, Federal Acquisition Regulations - Part 23JSchaus & Associates
 
2024: The FAR, Federal Acquisition Regulations - Part 19
2024: The FAR, Federal Acquisition Regulations - Part 192024: The FAR, Federal Acquisition Regulations - Part 19
2024: The FAR, Federal Acquisition Regulations - Part 19JSchaus & Associates
 
2024: The FAR, Federal Acquisition Regulations - Part 22
2024: The FAR, Federal Acquisition Regulations - Part 222024: The FAR, Federal Acquisition Regulations - Part 22
2024: The FAR, Federal Acquisition Regulations - Part 22JSchaus & Associates
 
GSA Schedules - Requirements And Reality
GSA Schedules - Requirements And  RealityGSA Schedules - Requirements And  Reality
GSA Schedules - Requirements And RealityJSchaus & Associates
 
2024: The FAR, Federal Acquisition Regulations - Part 18
2024: The FAR, Federal Acquisition Regulations - Part 182024: The FAR, Federal Acquisition Regulations - Part 18
2024: The FAR, Federal Acquisition Regulations - Part 18JSchaus & Associates
 
SPONSORED CONTENT - MyGovWatch - RFP Cliches Debunked: What Government Buyers...
SPONSORED CONTENT - MyGovWatch - RFP Cliches Debunked: What Government Buyers...SPONSORED CONTENT - MyGovWatch - RFP Cliches Debunked: What Government Buyers...
SPONSORED CONTENT - MyGovWatch - RFP Cliches Debunked: What Government Buyers...JSchaus & Associates
 
2024: The FAR, Federal Acquisition Regulations - Part 17
2024: The FAR, Federal Acquisition Regulations - Part 172024: The FAR, Federal Acquisition Regulations - Part 17
2024: The FAR, Federal Acquisition Regulations - Part 17JSchaus & Associates
 
2024: The FAR, Federal Acquisition Regulations - Part 16
2024: The FAR, Federal Acquisition Regulations - Part 162024: The FAR, Federal Acquisition Regulations - Part 16
2024: The FAR, Federal Acquisition Regulations - Part 16JSchaus & Associates
 
2024: The FAR, Federal Acquisition Regulations - Part 15
2024: The FAR, Federal Acquisition Regulations - Part 152024: The FAR, Federal Acquisition Regulations - Part 15
2024: The FAR, Federal Acquisition Regulations - Part 15JSchaus & Associates
 
SPONSORED CONTENT - AGILE ATS - Recruiting Strategies Systems & Tactics For G...
SPONSORED CONTENT - AGILE ATS - Recruiting Strategies Systems & Tactics For G...SPONSORED CONTENT - AGILE ATS - Recruiting Strategies Systems & Tactics For G...
SPONSORED CONTENT - AGILE ATS - Recruiting Strategies Systems & Tactics For G...JSchaus & Associates
 
SPONSORED CONTENT - DV Solutions - Building Relationships With The Federal Fo...
SPONSORED CONTENT - DV Solutions - Building Relationships With The Federal Fo...SPONSORED CONTENT - DV Solutions - Building Relationships With The Federal Fo...
SPONSORED CONTENT - DV Solutions - Building Relationships With The Federal Fo...JSchaus & Associates
 
2024: The FAR, Federal Acquisiton Regulations - Part 14
2024: The FAR, Federal Acquisiton Regulations - Part 142024: The FAR, Federal Acquisiton Regulations - Part 14
2024: The FAR, Federal Acquisiton Regulations - Part 14JSchaus & Associates
 
2024: The FAR, Federal Acquisition Regulations - Part 13
2024: The FAR, Federal Acquisition Regulations - Part 132024: The FAR, Federal Acquisition Regulations - Part 13
2024: The FAR, Federal Acquisition Regulations - Part 13JSchaus & Associates
 

Mehr von JSchaus & Associates (20)

2024: The FAR, Federal Acquisition Regulations, Part 30
2024: The FAR, Federal Acquisition Regulations, Part 302024: The FAR, Federal Acquisition Regulations, Part 30
2024: The FAR, Federal Acquisition Regulations, Part 30
 
2024: The FAR, Federal Acquisition Regulations - Part 29
2024: The FAR, Federal Acquisition Regulations - Part 292024: The FAR, Federal Acquisition Regulations - Part 29
2024: The FAR, Federal Acquisition Regulations - Part 29
 
2024: The FAR, Federal Acquisition Regulations - Part 28
2024: The FAR, Federal Acquisition Regulations - Part 282024: The FAR, Federal Acquisition Regulations - Part 28
2024: The FAR, Federal Acquisition Regulations - Part 28
 
2024: The FAR, Federal Acquisition Regulations - Part 27
2024: The FAR, Federal Acquisition Regulations - Part 272024: The FAR, Federal Acquisition Regulations - Part 27
2024: The FAR, Federal Acquisition Regulations - Part 27
 
2024: The FAR, Federal Acquisition Regulations - Part 26
2024: The FAR, Federal Acquisition Regulations - Part 262024: The FAR, Federal Acquisition Regulations - Part 26
2024: The FAR, Federal Acquisition Regulations - Part 26
 
2024: The FAR, Federal Acquisition Regulations - Part 25
2024: The FAR, Federal Acquisition Regulations - Part 252024: The FAR, Federal Acquisition Regulations - Part 25
2024: The FAR, Federal Acquisition Regulations - Part 25
 
2024: The FAR, Federal Acquisition Regulations - Part 24
2024: The FAR, Federal Acquisition Regulations - Part 242024: The FAR, Federal Acquisition Regulations - Part 24
2024: The FAR, Federal Acquisition Regulations - Part 24
 
2024: The FAR, Federal Acquisition Regulations - Part 23
2024: The FAR, Federal Acquisition Regulations - Part 232024: The FAR, Federal Acquisition Regulations - Part 23
2024: The FAR, Federal Acquisition Regulations - Part 23
 
2024: The FAR, Federal Acquisition Regulations - Part 19
2024: The FAR, Federal Acquisition Regulations - Part 192024: The FAR, Federal Acquisition Regulations - Part 19
2024: The FAR, Federal Acquisition Regulations - Part 19
 
2024: The FAR, Federal Acquisition Regulations - Part 22
2024: The FAR, Federal Acquisition Regulations - Part 222024: The FAR, Federal Acquisition Regulations - Part 22
2024: The FAR, Federal Acquisition Regulations - Part 22
 
GSA Schedules - Requirements And Reality
GSA Schedules - Requirements And  RealityGSA Schedules - Requirements And  Reality
GSA Schedules - Requirements And Reality
 
2024: The FAR, Federal Acquisition Regulations - Part 18
2024: The FAR, Federal Acquisition Regulations - Part 182024: The FAR, Federal Acquisition Regulations - Part 18
2024: The FAR, Federal Acquisition Regulations - Part 18
 
SPONSORED CONTENT - MyGovWatch - RFP Cliches Debunked: What Government Buyers...
SPONSORED CONTENT - MyGovWatch - RFP Cliches Debunked: What Government Buyers...SPONSORED CONTENT - MyGovWatch - RFP Cliches Debunked: What Government Buyers...
SPONSORED CONTENT - MyGovWatch - RFP Cliches Debunked: What Government Buyers...
 
2024: The FAR, Federal Acquisition Regulations - Part 17
2024: The FAR, Federal Acquisition Regulations - Part 172024: The FAR, Federal Acquisition Regulations - Part 17
2024: The FAR, Federal Acquisition Regulations - Part 17
 
2024: The FAR, Federal Acquisition Regulations - Part 16
2024: The FAR, Federal Acquisition Regulations - Part 162024: The FAR, Federal Acquisition Regulations - Part 16
2024: The FAR, Federal Acquisition Regulations - Part 16
 
2024: The FAR, Federal Acquisition Regulations - Part 15
2024: The FAR, Federal Acquisition Regulations - Part 152024: The FAR, Federal Acquisition Regulations - Part 15
2024: The FAR, Federal Acquisition Regulations - Part 15
 
SPONSORED CONTENT - AGILE ATS - Recruiting Strategies Systems & Tactics For G...
SPONSORED CONTENT - AGILE ATS - Recruiting Strategies Systems & Tactics For G...SPONSORED CONTENT - AGILE ATS - Recruiting Strategies Systems & Tactics For G...
SPONSORED CONTENT - AGILE ATS - Recruiting Strategies Systems & Tactics For G...
 
SPONSORED CONTENT - DV Solutions - Building Relationships With The Federal Fo...
SPONSORED CONTENT - DV Solutions - Building Relationships With The Federal Fo...SPONSORED CONTENT - DV Solutions - Building Relationships With The Federal Fo...
SPONSORED CONTENT - DV Solutions - Building Relationships With The Federal Fo...
 
2024: The FAR, Federal Acquisiton Regulations - Part 14
2024: The FAR, Federal Acquisiton Regulations - Part 142024: The FAR, Federal Acquisiton Regulations - Part 14
2024: The FAR, Federal Acquisiton Regulations - Part 14
 
2024: The FAR, Federal Acquisition Regulations - Part 13
2024: The FAR, Federal Acquisition Regulations - Part 132024: The FAR, Federal Acquisition Regulations - Part 13
2024: The FAR, Federal Acquisition Regulations - Part 13
 

Kürzlich hochgeladen

↑VVIP celebrity ( Pune ) Serampore Call Girls 8250192130 unlimited shot and a...
↑VVIP celebrity ( Pune ) Serampore Call Girls 8250192130 unlimited shot and a...↑VVIP celebrity ( Pune ) Serampore Call Girls 8250192130 unlimited shot and a...
↑VVIP celebrity ( Pune ) Serampore Call Girls 8250192130 unlimited shot and a...ranjana rawat
 
PPT Item # 4 - 231 Encino Ave (Significance Only)
PPT Item # 4 - 231 Encino Ave (Significance Only)PPT Item # 4 - 231 Encino Ave (Significance Only)
PPT Item # 4 - 231 Encino Ave (Significance Only)ahcitycouncil
 
Election 2024 Presiding Duty Keypoints_01.pdf
Election 2024 Presiding Duty Keypoints_01.pdfElection 2024 Presiding Duty Keypoints_01.pdf
Election 2024 Presiding Duty Keypoints_01.pdfSamirsinh Parmar
 
Just Call Vip call girls Wardha Escorts ☎️8617370543 Starting From 5K to 25K ...
Just Call Vip call girls Wardha Escorts ☎️8617370543 Starting From 5K to 25K ...Just Call Vip call girls Wardha Escorts ☎️8617370543 Starting From 5K to 25K ...
Just Call Vip call girls Wardha Escorts ☎️8617370543 Starting From 5K to 25K ...Dipal Arora
 
2024 Zoom Reinstein Legacy Asbestos Webinar
2024 Zoom Reinstein Legacy Asbestos Webinar2024 Zoom Reinstein Legacy Asbestos Webinar
2024 Zoom Reinstein Legacy Asbestos WebinarLinda Reinstein
 
Get Premium Budhwar Peth Call Girls (8005736733) 24x7 Rate 15999 with A/c Roo...
Get Premium Budhwar Peth Call Girls (8005736733) 24x7 Rate 15999 with A/c Roo...Get Premium Budhwar Peth Call Girls (8005736733) 24x7 Rate 15999 with A/c Roo...
Get Premium Budhwar Peth Call Girls (8005736733) 24x7 Rate 15999 with A/c Roo...MOHANI PANDEY
 
(NEHA) Bhosari Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts
(NEHA) Bhosari Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts(NEHA) Bhosari Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts
(NEHA) Bhosari Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escortsranjana rawat
 
Regional Snapshot Atlanta Aging Trends 2024
Regional Snapshot Atlanta Aging Trends 2024Regional Snapshot Atlanta Aging Trends 2024
Regional Snapshot Atlanta Aging Trends 2024ARCResearch
 
VIP Russian Call Girls in Indore Ishita 💚😋 9256729539 🚀 Indore Escorts
VIP Russian Call Girls in Indore Ishita 💚😋  9256729539 🚀 Indore EscortsVIP Russian Call Girls in Indore Ishita 💚😋  9256729539 🚀 Indore Escorts
VIP Russian Call Girls in Indore Ishita 💚😋 9256729539 🚀 Indore Escortsaditipandeya
 
Incident Command System xxxxxxxxxxxxxxxxxxxxxxxxx
Incident Command System xxxxxxxxxxxxxxxxxxxxxxxxxIncident Command System xxxxxxxxxxxxxxxxxxxxxxxxx
Incident Command System xxxxxxxxxxxxxxxxxxxxxxxxxPeter Miles
 
Akurdi ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...
Akurdi ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...Akurdi ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...
Akurdi ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...tanu pandey
 
Postal Ballots-For home voting step by step process 2024.pptx
Postal Ballots-For home voting step by step process 2024.pptxPostal Ballots-For home voting step by step process 2024.pptx
Postal Ballots-For home voting step by step process 2024.pptxSwastiRanjanNayak
 
Item # 4 - 231 Encino Ave (Significance Only).pdf
Item # 4 - 231 Encino Ave (Significance Only).pdfItem # 4 - 231 Encino Ave (Significance Only).pdf
Item # 4 - 231 Encino Ave (Significance Only).pdfahcitycouncil
 
Junnar ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...
Junnar ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...Junnar ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...
Junnar ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...tanu pandey
 
Call On 6297143586 Yerwada Call Girls In All Pune 24/7 Provide Call With Bes...
Call On 6297143586  Yerwada Call Girls In All Pune 24/7 Provide Call With Bes...Call On 6297143586  Yerwada Call Girls In All Pune 24/7 Provide Call With Bes...
Call On 6297143586 Yerwada Call Girls In All Pune 24/7 Provide Call With Bes...tanu pandey
 
Top Rated Pune Call Girls Hadapsar ⟟ 6297143586 ⟟ Call Me For Genuine Sex Se...
Top Rated  Pune Call Girls Hadapsar ⟟ 6297143586 ⟟ Call Me For Genuine Sex Se...Top Rated  Pune Call Girls Hadapsar ⟟ 6297143586 ⟟ Call Me For Genuine Sex Se...
Top Rated Pune Call Girls Hadapsar ⟟ 6297143586 ⟟ Call Me For Genuine Sex Se...Call Girls in Nagpur High Profile
 
Human-AI Collaboration for Virtual Capacity in Emergency Operation Centers (E...
Human-AI Collaborationfor Virtual Capacity in Emergency Operation Centers (E...Human-AI Collaborationfor Virtual Capacity in Emergency Operation Centers (E...
Human-AI Collaboration for Virtual Capacity in Emergency Operation Centers (E...Hemant Purohit
 
Global debate on climate change and occupational safety and health.
Global debate on climate change and occupational safety and health.Global debate on climate change and occupational safety and health.
Global debate on climate change and occupational safety and health.Christina Parmionova
 
WORLD DEVELOPMENT REPORT 2024 - Economic Growth in Middle-Income Countries.
WORLD DEVELOPMENT REPORT 2024 - Economic Growth in Middle-Income Countries.WORLD DEVELOPMENT REPORT 2024 - Economic Growth in Middle-Income Countries.
WORLD DEVELOPMENT REPORT 2024 - Economic Growth in Middle-Income Countries.Christina Parmionova
 

Kürzlich hochgeladen (20)

↑VVIP celebrity ( Pune ) Serampore Call Girls 8250192130 unlimited shot and a...
↑VVIP celebrity ( Pune ) Serampore Call Girls 8250192130 unlimited shot and a...↑VVIP celebrity ( Pune ) Serampore Call Girls 8250192130 unlimited shot and a...
↑VVIP celebrity ( Pune ) Serampore Call Girls 8250192130 unlimited shot and a...
 
PPT Item # 4 - 231 Encino Ave (Significance Only)
PPT Item # 4 - 231 Encino Ave (Significance Only)PPT Item # 4 - 231 Encino Ave (Significance Only)
PPT Item # 4 - 231 Encino Ave (Significance Only)
 
Election 2024 Presiding Duty Keypoints_01.pdf
Election 2024 Presiding Duty Keypoints_01.pdfElection 2024 Presiding Duty Keypoints_01.pdf
Election 2024 Presiding Duty Keypoints_01.pdf
 
Just Call Vip call girls Wardha Escorts ☎️8617370543 Starting From 5K to 25K ...
Just Call Vip call girls Wardha Escorts ☎️8617370543 Starting From 5K to 25K ...Just Call Vip call girls Wardha Escorts ☎️8617370543 Starting From 5K to 25K ...
Just Call Vip call girls Wardha Escorts ☎️8617370543 Starting From 5K to 25K ...
 
2024 Zoom Reinstein Legacy Asbestos Webinar
2024 Zoom Reinstein Legacy Asbestos Webinar2024 Zoom Reinstein Legacy Asbestos Webinar
2024 Zoom Reinstein Legacy Asbestos Webinar
 
Get Premium Budhwar Peth Call Girls (8005736733) 24x7 Rate 15999 with A/c Roo...
Get Premium Budhwar Peth Call Girls (8005736733) 24x7 Rate 15999 with A/c Roo...Get Premium Budhwar Peth Call Girls (8005736733) 24x7 Rate 15999 with A/c Roo...
Get Premium Budhwar Peth Call Girls (8005736733) 24x7 Rate 15999 with A/c Roo...
 
(NEHA) Bhosari Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts
(NEHA) Bhosari Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts(NEHA) Bhosari Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts
(NEHA) Bhosari Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts
 
Regional Snapshot Atlanta Aging Trends 2024
Regional Snapshot Atlanta Aging Trends 2024Regional Snapshot Atlanta Aging Trends 2024
Regional Snapshot Atlanta Aging Trends 2024
 
VIP Russian Call Girls in Indore Ishita 💚😋 9256729539 🚀 Indore Escorts
VIP Russian Call Girls in Indore Ishita 💚😋  9256729539 🚀 Indore EscortsVIP Russian Call Girls in Indore Ishita 💚😋  9256729539 🚀 Indore Escorts
VIP Russian Call Girls in Indore Ishita 💚😋 9256729539 🚀 Indore Escorts
 
Incident Command System xxxxxxxxxxxxxxxxxxxxxxxxx
Incident Command System xxxxxxxxxxxxxxxxxxxxxxxxxIncident Command System xxxxxxxxxxxxxxxxxxxxxxxxx
Incident Command System xxxxxxxxxxxxxxxxxxxxxxxxx
 
Akurdi ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...
Akurdi ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...Akurdi ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...
Akurdi ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...
 
Postal Ballots-For home voting step by step process 2024.pptx
Postal Ballots-For home voting step by step process 2024.pptxPostal Ballots-For home voting step by step process 2024.pptx
Postal Ballots-For home voting step by step process 2024.pptx
 
(NEHA) Call Girls Nagpur Call Now 8250077686 Nagpur Escorts 24x7
(NEHA) Call Girls Nagpur Call Now 8250077686 Nagpur Escorts 24x7(NEHA) Call Girls Nagpur Call Now 8250077686 Nagpur Escorts 24x7
(NEHA) Call Girls Nagpur Call Now 8250077686 Nagpur Escorts 24x7
 
Item # 4 - 231 Encino Ave (Significance Only).pdf
Item # 4 - 231 Encino Ave (Significance Only).pdfItem # 4 - 231 Encino Ave (Significance Only).pdf
Item # 4 - 231 Encino Ave (Significance Only).pdf
 
Junnar ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...
Junnar ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...Junnar ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...
Junnar ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...
 
Call On 6297143586 Yerwada Call Girls In All Pune 24/7 Provide Call With Bes...
Call On 6297143586  Yerwada Call Girls In All Pune 24/7 Provide Call With Bes...Call On 6297143586  Yerwada Call Girls In All Pune 24/7 Provide Call With Bes...
Call On 6297143586 Yerwada Call Girls In All Pune 24/7 Provide Call With Bes...
 
Top Rated Pune Call Girls Hadapsar ⟟ 6297143586 ⟟ Call Me For Genuine Sex Se...
Top Rated  Pune Call Girls Hadapsar ⟟ 6297143586 ⟟ Call Me For Genuine Sex Se...Top Rated  Pune Call Girls Hadapsar ⟟ 6297143586 ⟟ Call Me For Genuine Sex Se...
Top Rated Pune Call Girls Hadapsar ⟟ 6297143586 ⟟ Call Me For Genuine Sex Se...
 
Human-AI Collaboration for Virtual Capacity in Emergency Operation Centers (E...
Human-AI Collaborationfor Virtual Capacity in Emergency Operation Centers (E...Human-AI Collaborationfor Virtual Capacity in Emergency Operation Centers (E...
Human-AI Collaboration for Virtual Capacity in Emergency Operation Centers (E...
 
Global debate on climate change and occupational safety and health.
Global debate on climate change and occupational safety and health.Global debate on climate change and occupational safety and health.
Global debate on climate change and occupational safety and health.
 
WORLD DEVELOPMENT REPORT 2024 - Economic Growth in Middle-Income Countries.
WORLD DEVELOPMENT REPORT 2024 - Economic Growth in Middle-Income Countries.WORLD DEVELOPMENT REPORT 2024 - Economic Growth in Middle-Income Countries.
WORLD DEVELOPMENT REPORT 2024 - Economic Growth in Middle-Income Countries.
 

Arnold & Porter Cybersecurity Compliance and Enforcement for Federal Contractors

  • 1. Federal Government Contracting CYBERSECURITY REQUIREMENTS hello@JenniferSchaus.com Cybersecurity Compliance & Enforcement for Federal Contractors Cybersecurity Compliance & Enforcement for Federal Contractors Friday, September 30, 2022 12pm EST
  • 2. Federal Government Contracting CYBERSECURITY REQUIREMENTS hello@JenniferSchaus.com Cybersecurity Compliance & Enforcement for Federal Contractors About Jschaus & Associates: Ø Washington DC based Ø Consulting firm working with established Federal Contractors; Ø Webinars, Events, Conferences; Ø Newsletter – reaching 23K Federal Contractors; Ø 500+ Webinars on YouTube; Ø Advertising & Sponsor Opportunities
  • 3. Federal Government Contracting CYBERSECURITY REQUIREMENTS hello@JenniferSchaus.com Cybersecurity Compliance & Enforcement for Federal Contractors About Arnold & Porter: Ø Top-ranked Government Contracts practice Ø Represent the entire spectrum of domestic and international government contractors: start-ups, Fortune 100 companies, and non-profits Ø Help address the increasingly complex cyber issues confronting commercial businesses, government contractors, and the special concerns associated with work for DoD and intelligence agencies
  • 4. Federal Government Contracting CYBERSECURITY REQUIREMENTS hello@JenniferSchaus.com Cybersecurity Compliance & Enforcement for Federal Contractors MEET OUR SPEAKERS
  • 5. Federal Government Contracting CYBERSECURITY REQUIREMENTS hello@JenniferSchaus.com Cybersecurity Compliance & Enforcement for Federal Contractors Sonia Tabriz sonia.tabriz@arnoldporter.com 202.942.6574
  • 6. Federal Government Contracting CYBERSECURITY REQUIREMENTS hello@JenniferSchaus.com Cybersecurity Compliance & Enforcement for Federal Contractors Tom Pettit thomas.pettit@arnoldporter.com 202.942.6075
  • 7. Federal Government Contracting CYBERSECURITY REQUIREMENTS hello@JenniferSchaus.com Cybersecurity Compliance & Enforcement for Federal Contractors Agenda • Cybersecurity Requirements • CMMC Overview and Updates • Enforcement 7
  • 8. Federal Government Contracting CYBERSECURITY REQUIREMENTS hello@JenniferSchaus.com Cybersecurity Compliance & Enforcement for Federal Contractors CYBERSECURITY REQUIREMENTS 8
  • 9. Federal Government Contracting CYBERSECURITY REQUIREMENTS hello@JenniferSchaus.com Cybersecurity Compliance & Enforcement for Federal Contractors FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems • Applies to any information system “owned or operated by a contractor that processes, stores, or transmits” “federal contract information” (FCI) • FCI is any information “not intended for public release” obtained from or developed for the Government in the performance of a contract • Establishes baseline security standards, such as: • Identifying users, processes, and devices (e.g., personal identity verification (PIV)) • Limiting access to information systems to only authorized users, processes, and devices (e.g., mandating passwords, managing group policies, and maintaining the Windows Registry) • Installing and updating antivirus software and other protections against malicious code; scanning for malware • Regulating physical access to information systems and facilities 9
  • 10. Federal Government Contracting CYBERSECURITY REQUIREMENTS hello@JenniferSchaus.com Cybersecurity Compliance & Enforcement for Federal Contractors DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting • Applies to DoD contractors with information systems that will store, process, or transmit controlled unclassified information (CUI) collected, developed, received, transmitted, used, or stored by or on behalf of the contractors in support of the performance of the contract • Two key elements: security controls and cyber incident reporting • Security Controls • Implement security controls in NIST SP 800-171 • Document security controls in system security plan • Develop plan of action for any controls not implemented 10
  • 11. Federal Government Contracting CYBERSECURITY REQUIREMENTS hello@JenniferSchaus.com Cybersecurity Compliance & Enforcement for Federal Contractors DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting • Security Controls • NIST SP 800-171 compliance is generally a self-assessment system with a few caveats: • System security plans and plans of action can be (but typically are not) formal contract deliverables • Contractor must submit requests to vary from NIST SP 800-171 to the contracting officer for review by the DoD CIO • DIBCAC Assessments, DFARS 252.204-7019, and DFARS 252.204-7020 • Cloud Services • CSPs must meet security requirements equivalent to the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline 11
  • 12. Federal Government Contracting CYBERSECURITY REQUIREMENTS hello@JenniferSchaus.com Cybersecurity Compliance & Enforcement for Federal Contractors DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting • Cyber Incident Reporting • Cyber Incident: Actions taken through the use of computer networks that result in a compromise or an actual or potentially adverse effect on an information system and/or the information residing therein • Compromise: Disclosure of information to unauthorized persons or a violation of the security policy of a system and unauthorized intentional or unintentional disclosure, modification, destruction, or loss of an object or the copying of information to unauthorized media may have occurred • Adverse Effect: Not defined, but it could include, among other things, exfiltration, malware, DDoS attack, ransomware attack • Conduct a review, including assessing scope of cyber incident and impact on covered defense information as well as ability to provide operationally critical support • Must “rapidly” report cyber incidents through DIBNet 12
  • 13. Federal Government Contracting CYBERSECURITY REQUIREMENTS hello@JenniferSchaus.com Cybersecurity Compliance & Enforcement for Federal Contractors DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting • Cyber Incident Reporting • Submit malicious software to the DoD Cyber Crime Center • Preserve information (images of information systems and monitoring/packet capture data) for at least 90 days after reporting cyber incident • DoD has right to perform forensic analysis and damage assessment, and contractor must cooperate • Subcontract flow down 13
  • 14. Federal Government Contracting CYBERSECURITY REQUIREMENTS hello@JenniferSchaus.com Cybersecurity Compliance & Enforcement for Federal Contractors DFARS 252.204-7019 & -7020, NIST SP 800-171 Assessments • Apply to all solicitations and contracts that exceed the micro-purchase threshold and are not exclusively for the acquisition of commercially available off-the-shelf (COTS) items • Four Components: • Weighted Score • 110-point, weighted scoring system that measures the extent to which an offeror or contractor has implemented the NIST SP 800-171 security controls. • Standardized scoring methodology that assigns greater points to requirements that have greater impact on the security of the network and its data than others. • Confidence Levels • Basic Assessment/Low Confidence: Self-assessment and self-generated score • Medium Assessment/Confidence: DoD reviews Basic Assessment and associated documentation and discusses any concerns with the contractor • High Assessment/Confidence: Medium Assessment + verification, examination, and demonstration of SSP 14
  • 15. Federal Government Contracting CYBERSECURITY REQUIREMENTS hello@JenniferSchaus.com Cybersecurity Compliance & Enforcement for Federal Contractors DFARS 252.204-7019 & -7020, NIST SP 800-171 Assessments • Four Components: • Rebuttal and Adjudication: Contractor may, within 14 days, dispute any aspect of a DoD assessment • Reporting: Contractor must enter data into the Supplier Performance Risk System (summary level score, type of assessment, description of the SSP architecture, assessment date, and date when contractor will achieve perfect score) • American Fuel Cell & Coated Fabrics Co., B-420551, B-420551.2, June 2, 2022, 2022 CPD ¶ 139 15
  • 16. Federal Government Contracting CYBERSECURITY REQUIREMENTS hello@JenniferSchaus.com Cybersecurity Compliance & Enforcement for Federal Contractors CMMC OVERVIEW AND UPDATES 16
  • 17. Federal Government Contracting CYBERSECURITY REQUIREMENTS hello@JenniferSchaus.com Cybersecurity Compliance & Enforcement for Federal Contractors Why CMMC? • DFARS 252.204-7012 relies on contractor self-assessments • There is no mandatory government oversight • DoD concluded that the “Scout’s Honor” system was ineffective • A 2018 National Defense Industrial Association (NDIA) survey revealed that 36% of contractors who responded were not aware of DFARS 252.204-7012, and 45% of the respondents admitted that they had never read NIST SP 800-171 • A 2019 NDIA survey revealed that only 56% of defense contractors were prepared for a DCMA assessment of NIST SP 800-171 compliance 17
  • 18. Federal Government Contracting CYBERSECURITY REQUIREMENTS hello@JenniferSchaus.com Cybersecurity Compliance & Enforcement for Federal Contractors CMMC Overview and Updates • DoD determined that more must be done to harden the DIB's and defense supply chain's cyber infrastructure • Verification is not required • Industry surveys have indicated that many contractors are noncompliant • Cyber incidents have increased • CMMC 1.0 • Released in January 2020 • Five maturity levels (two transitional) and would have to be certified to be eligible for contracts incorporating CMMC requirements 18
  • 19. Federal Government Contracting CYBERSECURITY REQUIREMENTS hello@JenniferSchaus.com Cybersecurity Compliance & Enforcement for Federal Contractors CMMC Overview and Updates • CMMC 2.0 • “Announced” in November 2021 • Streamlined requirements • CMMC-unique security practices removed • New iteration will have three maturity levels instead of five (CMMC 1.0 Levels 2 and 3 removed) • Level 1: Security controls for FCI • Level 2: 110 NIST SP 800-171 security controls for CUI • Level 3: 110 NIST SP 800-171 security controls for CUI, plus some subset of NIST SP 800-172 • Plans of action generally not allowed, with exceptions only for minor noncompliance 19
  • 20. Federal Government Contracting CYBERSECURITY REQUIREMENTS hello@JenniferSchaus.com Cybersecurity Compliance & Enforcement for Federal Contractors CMMC Overview and Updates • Assessments • Level 1 is achieved through a self assessment and attestation of compliance • Level 2 generally requires third-party assessments through accredited CMMC Third Party Assessment Organizations (C3PAOs), but self-assessments are permitted if contract requirements do not involve information critical to national security • Level 3 must be assessed by USG officials • Interim rule is expected around March 2023, and CMMC may be incorporated into solicitations and RFIs shortly thereafter 20
  • 21. Federal Government Contracting CYBERSECURITY REQUIREMENTS hello@JenniferSchaus.com Cybersecurity Compliance & Enforcement for Federal Contractors ENFORCEMENT 21
  • 22. Federal Government Contracting CYBERSECURITY REQUIREMENTS hello@JenniferSchaus.com Cybersecurity Compliance & Enforcement for Federal Contractors Contract-Based Remedies • In June 2022, DoD issued a memorandum reminding Contracting Officers of available contract-based remedies for noncompliance with DFARS 252.204-7012 and the corresponding NIST SP 800-171 requirements 22
  • 23. Federal Government Contracting CYBERSECURITY REQUIREMENTS hello@JenniferSchaus.com Cybersecurity Compliance & Enforcement for Federal Contractors Civil Cyber-Fraud Initiative • In October 2021, the Department of Justice (DoJ) announced a new Civil Cyber-Fraud Initiative that leverages the False Claims Act (FCA) to combat cyber threats • Deputy Attorney General Lisa O. Monaco stated: • “For too long, companies have chosen silence under the mistaken belief that it is less risky to hide a breach than to bring it forward and to report it. Well that changes today. We are announcing today that we will use our civil enforcement tools to pursue companies, those who are government contractors who receive federal funds, when they fail to follow required cybersecurity standards — because we know that puts all of us at risk. This is a tool that we have to ensure that taxpayer dollars are used appropriately and guard the public fisc and public trust.” • In a recent Comprehensive Cyber Review report, DOJ confirmed that it plans to “lead the effort to enforce cybersecurity requirements on federal contractors and grantees” and further announced its desire to participate in developing those requirements 23
  • 24. Federal Government Contracting CYBERSECURITY REQUIREMENTS hello@JenniferSchaus.com Cybersecurity Compliance & Enforcement for Federal Contractors Civil Cyber-Fraud Initiative • DoJ has identified the following benefits of the Civil Cyber-Fraud Initiative: • Building broad resiliency against cybersecurity intrusions across the government, the public sector and key industry partners • Holding contractors and grantees to their commitments to protect government information and infrastructure • Supporting government experts’ efforts to timely identify, create and publicize patches for vulnerabilities in commonly-used information technology products and services • Ensuring that companies that follow the rules and invest in meeting cybersecurity requirements are not at a competitive disadvantage • Reimbursing the government and the taxpayers for the losses incurred when companies fail to satisfy their cybersecurity obligations • Improving overall cybersecurity practices that will benefit the government, private users and the American public 24
  • 25. Federal Government Contracting CYBERSECURITY REQUIREMENTS hello@JenniferSchaus.com Cybersecurity Compliance & Enforcement for Federal Contractors Civil Cyber-Fraud Initiative • DoJ has stated that the following types of contracts will be the focus of its enforcement efforts: • Software and hardware procurement • Developing, implementing or maintaining IT systems owned by the federal government • Use of the contractor’s IT systems, especially if the systems maintain government data • Cloud services • Contracts that incorporate a regulatory, statutory or contractual requirement to monitor and report a cyber breach or incident • DoJ has also stated that it expects qui tam relators to play a significant role in implementing the Civil Cyber-Fraud Initiative • DoJ has already announced results of its enforcement efforts 25
  • 26. Federal Government Contracting CYBERSECURITY REQUIREMENTS hello@JenniferSchaus.com Cybersecurity Compliance & Enforcement for Federal Contractors Other Potential Risks • Bid protest litigation • Subcontract flow down negotiations and disputes • Suspension and debarment 26
  • 27. Federal Government Contracting CYBERSECURITY REQUIREMENTS hello@JenniferSchaus.com Cybersecurity Compliance & Enforcement for Federal Contractors QUESTIONS? Please Contact Our Speakers: Sonia Tabriz sonia.tabriz@arnoldporter.com 202.942.6574 Tom Pettit thomas.pettit@arnoldporter.com 202.942.6574 27
  • 28. Federal Government Contracting CYBERSECURITY REQUIREMENTS hello@JenniferSchaus.com Cybersecurity Compliance & Enforcement for Federal Contractors THANK YOU FOR ATTENDING 28