{"id":5077,"date":"2017-12-14T09:04:14","date_gmt":"2017-12-14T17:04:14","guid":{"rendered":"https:\/\/origin-www.parsons.com\/?page_id=5077"},"modified":"2023-05-23T15:24:16","modified_gmt":"2023-05-23T19:24:16","slug":"us-department-defense-regulations","status":"publish","type":"page","link":"https:\/\/www.parsons.com\/suppliers\/us-department-defense-regulations\/","title":{"rendered":"US Department of Defense Regulations"},"content":{"rendered":"\n

DFARS Covered Defense Information Final Rule<\/h3>\n\n\n\n

On October 21, 2016, the U.S. Department of Defense (DoD) published the Final Rule<\/a> as Defense Federal Acquisition Regulation Supplement (DFARS) Case 2013-018, entitled \u201cNetwork Penetration Reporting and Contracting for Cloud Services<\/em>.\u201d This rule contains solicitation provisions and contract clauses for contract flow downs, safeguarding and disseminating Covered Defense Information (CDI) and reporting on cyber incidents related to that information. As the requirements, have evolved and changed since the November 2013 version, first draft, please be aware of the subtle differences in your active contracts.<\/p>\n\n\n\n

The Oct 21, 2016 Final Rule follows several interim rules published in August 26, 2015 Interim Rule<\/a>, and December 30, 2015 Interim Rule<\/a>. Those were preceded by DFARS Case 2011-D039 titled Safeguarding of Unclassified Controlled Technical Information<\/em>, released on November 18, 2013, which addressed the security requirements for safeguarding unclassified, controlled technical information (UCTI) on contractor systems. DFARS Case 2013-D018 amends the previous regulations and expands requirements specified in DFARS Case 2011-D039 and includes several amended and new clauses and provisions, one of which is DFARS Clause 252.204\u20137012<\/a>.<\/p>\n\n\n\n

Requirements<\/h3>\n\n\n\n

DFARS Clause 252.204-7012 flows down in all new solicitations and contracts, including those using FAR <\/a>part <\/a>12 procedures<\/a> for acquisition of commercial items. The references below highlight the changes and new requirements.<\/p>\n\n\n\n

Definitions<\/h3>\n\n\n\n

(1) Covered defense information<\/em> means unclassified controlled technical information<\/a> (UCTI) or other information (as described in the Controlled Unclassified Information (CUI) Registry<\/a>) that requires safeguarding or dissemination controls pursuant to and consistent with law, regulations, and Governmentwide policies, and is\u2014<\/p>\n\n\n\n