The Civilian Agency Acquisition Council and Defense Acquisition Regulations Council released the final rule for a minimum level of information security for contractors dealing with sensitive federal data, making a few significant changes over prior drafts.
The rule — written jointly by the Department of Defense, General Services Administration and NASA, all three of which manage broad, multi-agency IT contracts — was finalized on May 16 and will be applied to all acquisitions involving the generation, use or transmission of government data that would not otherwise be made public.
Federal Register: Basic Safeguarding of Contractor Information Systems
The new rule “focuses on ensuring a basic level of safeguarding for any contractor system with federal information, reflective of actions a prudent business person would employ,” according to a post in the Federal Register. The rule is based on security controls and best practices compiled by the National Institute of Standards and Technology, as well as an extensive public comment process that has been ongoing since 2012.
The notice adds this is “just one step in a series of coordinated regulatory actions being taken or planned to strengthen protections of information systems,” including guidance issued by the Office of Management and Budget last year that outlines how agencies and contractors should handle controlled unclassified information (CUI).
The final rule includes a number of revisions over previous drafts.
For instance, initial drafts called for securing government information on contractor systems, whereas the final rule focuses on protecting the system itself. While this might seem like a cosmetic change on its face, the broader focus takes into account the many ways in which a system can be compromised and the full scope of protections needed.
Other amendments include making sure the rule applies below the simplified acquisition threshold; clarifying that it does not apply to commercial off-the-shelf products; and reiterates that these regulations do not “relieve the contractor” of any other security requirements specified by the contracting agency.
During the public comment process, industry representatives and other stakeholders cautioned that the definitions and scope were too broad, with one arguing the rule could encompass all information owned by a company with just a single government contract.
“The intent is that the scope and applicability of this rule be very broad,” the acquisition council wrote in response, noting, “This rule requires only the most basic level of safeguarding.”
The council also noted the rule only covers systems that manage or transmit federal data, which it defines as “information — not intended for public release — that is provided by or generated for the government under a contract to develop or deliver a product or service to the government.”




