Ahead of the upcoming December 31, 2017 deadline for federal defense contractors to implement National Institute of Standards and Technology (“NIST”) Special Publication 800-171 (“SP 800-171”), NIST has released a new draft publication designed to assist organizations in assessing compliance under SP 800-171, Draft Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information (“CUI”) (“SP 800-171A”).

Currently, there is no regulation or statute that imposes SP 800-171A on contractors. Rather, SP 800-171A is intended as guidance for organizations in developing assessment plans and conducting “efficient, effective, and cost-effective” assessments of the implementation of security controls required by SP 800-171. Similar to SP 800-171, SP 800-171A does not prescribe specific, required assessment procedures. Instead, SP 800-171A provides a series of “flexible and tailorable” procedures that organizations could use for conducting assessments with each security control in SP 800-171. SP 800-171A specifically recognizes three distinct methods for conducting assessments: examining and interviewing to facilitate understanding, achieve clarification, or obtain evidence and testing to compare actual results with expectations.

Requirements of SP 800-171A:

Following the format of SP 800-171, SP 800-171A groups its assessment procedures by the fourteen families of CUI security control requirements, and highlights how an assessor could examine, interview, or test each particular control at issue. Although SP 800-171A suggests a majority of the controls could be evaluated using all three methods, it does recognize that some of the controls can only be effectively assessed using a subset of the three methods. SP 800-171A also recognizes that organizations may not need to test every control – controls that are not applicable to a particular organization should not be tested in the assessment, but should instead be documented as non-applicable in the organization’s System Security Plan (“SSP”).

Consistent with its recent update to NIST Special Publication 800-53, Security and Privacy Controls for Federal Information Systems and Organizations (“SP 800-53”), in creating this publication, NIST used the term “system” rather than “information system” to reflect that CUI needs to be safeguarded on a broader array of contractor information systems such as industrial and process control systems, cyber-physical systems, and individual devices that are part of the Internet of Things.

Impact on Contractors:

Although there is currently no requirement that defense contractors follow the procedures in SP 800-171A, the draft publication was designed as “a starting point” for organizations to use in developing assessment plans and determining compliance with NIST SP 800-171. In particular, SP 800-171A notes that “[o]rganizations can use the assessment procedures to generate evidence to support the assertion that the security requirements have been satisfied.” Such evidence could be used in a variety of ways, such as the basis for identifying security related weaknesses in a system, as an aid in source selection, or by the Defense Contract Management Agency (“DCMA”) when auditing contractor compliance with Defense Federal Acquisition Regulation Supplement (“DFARS”) clause 252.204-7012.

Attached to SP 800-171 is an appendix that provides supplemental guidance for implementing and assessing the CUI security requirements in SP 800-171. As currently drafted, many of the SP 800-171 security controls are only a sentence or two long. The supplemental guidance is based on the more fulsome “security controls in NIST Special Publication 800-53 and is provided to give assessors a better understanding of the mechanisms and procedures used to implement the safeguards employed to protect CUI.” NIST states that this supplemental guidance will be included in the next update to SP 800-171.

As noted in a previous blog post, NIST is in the process of revising SP 800-53, which only applies to federal systems. One of the stated objectives of the revised version, however, is to make SP 800-53’s cybersecurity and privacy standards and guidelines accessible to non-federal and private sector organizations for voluntary use on their systems.  As a result, because NIST is incorporating this guidance more explicitly, defense contractors may ultimately see a blurring of some of the requirements of SP 800-171 versus SP 800-53.

NIST is seeking comment on draft publication SP 800-171A no later than December 27, 2017. Comments can be emailed to sec-cert@nist.gov.

Print:
EmailTweetLikeLinkedIn
Susan B. Cassidy

Ms. Cassidy represents clients in the defense, intelligence, and information technologies sectors.  She works with clients to navigate the complex rules and regulations that govern federal procurement and her practice includes both counseling and litigation components.  Ms. Cassidy conducts internal investigations for government…

Ms. Cassidy represents clients in the defense, intelligence, and information technologies sectors.  She works with clients to navigate the complex rules and regulations that govern federal procurement and her practice includes both counseling and litigation components.  Ms. Cassidy conducts internal investigations for government contractors and represents her clients before the Defense Contract Audit Agency (DCAA), Inspectors General (IG), and the Department of Justice with regard to those investigations.  From 2008 to 2012, Ms. Cassidy served as in-house counsel at Northrop Grumman Corporation, one of the world’s largest defense contractors, supporting both defense and intelligence programs. Previously, Ms. Cassidy held an in-house position with Motorola Inc., leading a team of lawyers supporting sales of commercial communications products and services to US government defense and civilian agencies. Prior to going in-house, Ms. Cassidy was a litigation and government contracts partner in an international law firm headquartered in Washington, DC.

Photo of Ashden Fein Ashden Fein

Ashden Fein advises clients on cybersecurity and national security matters, including crisis management and incident response, risk management and governance, government and internal investigations, and regulatory compliance.

For cybersecurity matters, Mr. Fein counsels clients on preparing for and responding to cyber-based attacks, assessing…

Ashden Fein advises clients on cybersecurity and national security matters, including crisis management and incident response, risk management and governance, government and internal investigations, and regulatory compliance.

For cybersecurity matters, Mr. Fein counsels clients on preparing for and responding to cyber-based attacks, assessing security controls and practices for the protection of data and systems, developing and implementing cybersecurity risk management and governance programs, and complying with federal and state regulatory requirements. Mr. Fein frequently supports clients as the lead investigator and crisis manager for global cyber and data security incidents, including data breaches involving personal data, advanced persistent threats targeting intellectual property across industries, state-sponsored theft of sensitive U.S. government information, and destructive attacks.

Additionally, Mr. Fein assists clients from across industries with leading internal investigations and responding to government inquiries related to the U.S. national security. He also advises aerospace, defense, and intelligence contractors on security compliance under U.S. national security laws and regulations including, among others, the National Industrial Security Program (NISPOM), U.S. government cybersecurity regulations, and requirements related to supply chain security.

Before joining Covington, Mr. Fein served on active duty in the U.S. Army as a Military Intelligence officer and prosecutor specializing in cybercrime and national security investigations and prosecutions — to include serving as the lead trial lawyer in the prosecution of Private Chelsea (Bradley) Manning for the unlawful disclosure of classified information to Wikileaks.

Mr. Fein currently serves as a Judge Advocate in the U.S. Army Reserve.