Showing posts with label DFARS. Show all posts
Showing posts with label DFARS. Show all posts

Thursday, May 16, 2024

DOD Sends CMMC DFARS NPRM to OMB

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a notice of proposed rulemaking from the DOD’s Defense Acquisition Regulatory Council (DARC) on “Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041)”. An interim final rule on this issue was published on September 29th, 2020.

According to the Fall 2023 Unified Agenda entry for this rulemaking:

“DoD is amending an interim rule to implement the CMMC framework 2.0 in order to protect against the theft of intellectual property and sensitive information from the Defense Industrial Base (DIB) sector. The CMMC framework, as defined in Title 32 of the Code of Federal Regulations (CFR), assesses compliance with applicable information security requirements. This rule provides the Department with assurances that a DIB contractor can adequately protect sensitive unclassified information at a level commensurate with the risk, accounting for information flow down to its subcontractors in a multi-tier supply chain.”

 That Agenda entry also notes that:

“The theft of intellectual property and sensitive information from all U.S. industrial sectors due to malicious cyber activity threatens economic security and national security.  Malicious cyber actors have and continue to target the DIB sector and the supply chain of the Department of Defense. These attacks not only focus on the large prime contractors, but also target subcontractors that make up the lower tiers of the DoD supply chain. Many of these subcontractors are small entities that provide critical support and innovation. The aggregate loss of intellectual property and certain unclassified information from the DoD supply chain can undercut U.S. technical advantages and innovation, as well as significantly increase risk to national security.”

Tuesday, October 4, 2022

OMB Approves DOD/DFARS Cyber Reporting ICR Revision

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a revision of the DOD’s information collection request (ICR) for “Safeguarding Covered Defense Information, Cyber Incident Reporting, and Cloud Computing”. The ICR covers Defense Acquisition Regulation Supplement (DFARS) reporting requirements. The revision included decreasing the number of annual responses by 18,214 and decreasing the estimated number of burden hours for the ICR by 2,376.

Change in ICR Burden

The supporting document breaks down the decrease in responses in more detail, noting that there was:

• A decrease in the number of estimated respondents under DFARS clause 252.239-7009, Representation of Use of Cloud Computing, from 34,684 to 16,108,

• An increase in the number of respondents estimated to report cyber incidents under DFARS clause 252.239-7010, Cloud Computing Services, from 10 to 32; and

• An increase in the number of respondents estimated to report cyber incidents under DFARS clause 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, from 200 to 580.

The first item is not strictly related to cybersecurity, it is merely a requirement to report an intent to use cloud computing resources in support of a DFARS contract. So this ICR is announcing that, based upon recent historical DFARS data, DOD is expecting to see its covered contractors report 612 cybersecurity incidents per year, a 191% increase in the number of expected cyberattacks being reported.

Commentary

That 612 number seems awfully lite considering the ongoing news reporting (see here, here and here for example) about cyberattacks against defense contractors. Either the news is blowing things out of proportion (and that is always possible) or contractors are not reporting according to their DFARS requirements. Or, to be fair, there is a combination of the two. In any case, perhaps CISA and DOD should investigate the apparent discrepancy while CISA is trying to formulate their cyber incident reporting rule. That way, maybe CISA can get more accurate data when their rule goes into effect.


Tuesday, March 1, 2016

DOD Sends Counterfeit Parts Rule to OMB

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received from the DOD a draft DFARS notice of proposed rulemaking for “Costs Related to Counterfeit Electronic Parts”. This was not listed in the Fall 2015 Unified Agenda, but it is related to DFARS Case 2016-D010.

According to the Counterfeit Parts web site this NPRM would “Implements section 885(a) of the NDAA for FY 2016 (Pub. L. 112-81)”. Actually that should be PL 114-92 which has not been printed yet (it was only signed in November, give the GPO a break – Sarcasm Alert). The enrolled version of S 1356 shows that §885 actually amended §818 of the FY 2012 NDAA which was PL 112-81. No wonder things get confusing.


If you are not a DOD supplier, then you will probably be able to ignore this rule when it does finally come out. I’ll be briefly looking at it to see if it really provides any in-sight into dealing with counterfeit electronic components that might affect cybersecurity efforts, but I’m not going to be holding my breath.
 
/* Use this with templates/template-twocol.html */