“Defense contractors routinely process, store and transmit sensitive federal information to assist federal agencies in carrying out their core missions and business operations. Federal information is also shared with state and local governments, universities and independent research organizations.
To keep this information secure, Executive Order 13556 established the Controlled Unclassified Information (CUI) Program to standardize the way the executive branch handles unclassified information that requires protection, such as personally identifiable information.” [1]
“NIST Special Publication 800-171: Protecting Controlled Unclassified Information (CUI) in Nonfederal Information Systems and Organizations” (DFARS 252.204-7008) [2]
Compliance deadline: December 31, 2017.
The requirements focus in on these 15 key components:
- Access Control
- Limit system access to authorized users. Separate the access of standard users vs. administrators, and document your processes.
- Limit the number of logon attempts.
- Provide privacy and security notices to users entering the system.
- Encrypt communications via internet, W-Fi, or on any mobile devices.
- Awareness and Training
- Ensure that managers, systems administrators, and users of organizational information systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of organizational information systems.
- Ensure that organizational personnel are adequately trained to carry out their assigned information security-related duties and responsibilities.
- Audit and Accountability
- Create, protect, and retain information system audit records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful, unauthorized, or inappropriate information system activity.
- Ensure that the actions of individual information system users can be uniquely traced to those users so they can be held accountable for their actions.
- Configuration Management
- Establish and maintain baseline configurations and inventories of organizational information systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.
- Establish and enforce security configuration settings for information technology products employed in organizational information systems.
- Contingency Planning
- Refers to interim measures to recover information system services after a disruption. Interim measures may include relocation of information systems and operations to an alternate site, recovery of information system functions using alternate equipment, or performance of information system functions using manual methods.
- Identification and Authentication
- Identify information system users, processes acting on behalf of users, or devices.
- Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.
- Incident Response
- Establish an operational incident-handling capability for organizational information systems that includes adequate preparation, detection, analysis, containment, recovery, and user response activities.
- Track, document, and report incidents to appropriate organizational officials and/or authorities.
- Maintenance
- Perform maintenance on organizational information systems.
- Provide effective controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.
- Media Protection
- Protect (i.e., physically control and securely store) information system media containing CUI, both paper and digital.
- Limit access to CUI on information system media to authorized users.
- Sanitize or destroy information system media containing CUI before disposal or release for reuse.
- Personnel Security
- Screen individuals prior to authorizing access to information systems containing CUI.
- Ensure that CUI and information systems containing CUI are protected during and after personnel actions such as terminations and transfers.
- Physical Protection
- Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.
- Protect and monitor the physical facility and support infrastructure for those information systems.
- Risk Assessment
- Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational information systems and the associated processing, storage, or transmission of CUI.
- Security Assessment
- Periodically assess the security controls in organizational information systems to determine if the controls are effective in their application.
- Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational information systems.
- Monitor information system security controls on an ongoing basis to ensure the continued effectiveness of the controls.
- System and Communications Protection
- Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.
- Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational information systems.
- Protect the confidentiality of CUI at rest (“data at rest”).
- System and Information Integrity.
- Identify, report, and correct information and information system flaws in a timely manner.
- Provide protection from malicious code at appropriate locations within organizational information systems.
- Monitor information system security alerts and advisories and take appropriate actions in response.
To find out more about how JAMIS Cloud Services can help your organization prepare for these challenging federal compliance standards, contact us today at info@jamis.com.
[1] NIST Tech Beat – June 19, 2015: NIST Publishes Final Guidelines for Protecting Sensitive Government Information Held by Contractors
[2] NIST Special Publication 800-171: Protecting Controlled Unclassified Information (CUI) in Nonfederal Information Systems and Organizations