ARTICLE
16 January 2015

Government Releases New Guidelines For Protecting Controlled Unclassified Information On Contractors’ Systems

B
BakerHostetler

Contributor

BakerHostetler logo
Recognized as one of the top firms for client service, BakerHostetler is a leading national law firm that helps clients around the world address their most complex and critical business and regulatory issues. With five core national practice groups — Business, Labor and Employment, Intellectual Property, Litigation, and Tax — the firm has more than 970 lawyers located in 14 offices coast to coast. BakerHostetler is widely regarded as having one of the country’s top 10 tax practices, a nationally recognized litigation practice, an award-winning data privacy practice and an industry-leading business practice. The firm is also recognized internationally for its groundbreaking work recovering more than $13 billion in the Madoff Recovery Initiative, representing the SIPA Trustee for the liquidation of Bernard L. Madoff Investment Securities LLC. Visit bakerlaw.com
Government has struggled to adopt a unified approach to contractor data security.
United States Government, Public Sector

Although the Government has long recognized the need for security measures to protect sensitive government information residing on contractor information systems, it has struggled to adopt a unified approach to contractor data security. In recent years, guidance for securing "sensitive but unclassified" information on non-federal information systems has been inconsistent, with multiple agencies addressing the protection of federal information in materially different and sometimes conflicting ways.

On November 18, 2014, the U.S. Department of Commerce's National Institute of Standards and Technology ("NIST") released a draft version of NIST Special Publication 800-171, Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations ("SP 800-171"). As part of a larger initiative to comply with Executive Order 13556, the new publication aims to provide clear, government-wide security requirements for "controlled unclassified information," primarily by implementing security requirements and controls from prior NIST guidance and tailoring them specifically for nonfederal entities. The Government also anticipates establishing a single FAR clause that will apply the requirements of SP 800-171 to contractors. In exigent circumstances, agencies are permitted to reference SP 800-171 in a contract-specific requirement until promulgation of a final FAR clause. NIST is accepting comments on the draft document through January 16, 2015.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More