With the administration’s push toward cloud and as-a-service IT models, many agencies have concerns about the security of government data on third-party systems.
The Federal CIO Council, CAO Council and Office of Management and Budget released draft guidance this week on how agencies should write acquisition policies and contracts to ensure the best levels of protection and define who is responsible in the event of a breach.
Guidance: Improving Cybersecurity Protections in Federal Acquisitions
“The intent of the proposed guidance is to take major steps toward implementing strengthened cybersecurity protections in federal acquisitions and therefore mitigating the risk of potential incidents in the future,” according to the guidance.
The documents outline the required security controls for companies operating systems “on behalf of the government,” how incidents should be reported and how those systems should be assessed and monitored.
The draft documents are currently posted on GitHub for comment through Sept. 10.
More: IGs say cloud contracts lack security, assessment clauses
The General Services Administration also has 90 days to review the guidance and make recommendations on a baseline for business due diligence so agencies can do the necessary research during the acquisition process.
The National Institute for Science and Technology released similar standards on securing government data on non-federal networks in June – one of several NIST documents used as a basis for the new guidance.




