Skip to main content (Press Enter).
U.S. Air Force Logo
Home
About Us
Units
History
Leadership
Fact Sheets
Media
News
Features
Commentaries
Resources
Airman & Family Readiness
Chaplain
Director of Psychological Health
Employment
Environmental Safety
Freedom of Information Act
ID Card Office
Personal Financial Counselor
Sexual Assault and Response
Contact Us
FAQs
Sexual-Misconduct-Disciplinary-Actions
106th Rescue Wing
Contact Us
DVIDSVideoPlayer
Playlist:
Search Results
Video by Michael Dunbar, Chad Hilton, Douglas Key
Player Embed Code:
Download
Embed
Share
Cybersecurity Compliance: An Introduction to DFARS 252.204-7012 and NIST SP 800-171 Requirements
Defense Contract Management Agency
July 20, 2021 | 6:29
A presentation of the concepts related to the regulatory requirements governing contractor cybersecurity and the handling of Controlled Unclassified Information, as well as the process of attaining and demonstrating compliance through assessment.
Glossary of Terms:
DCMA
Defense Contract Management Agency; administrating agency of the Defense Industrial Base Cybersecurity Assessment Center
Prime
Prime contractor; works directly with the government, manages any subcontractors, and are responsible for ensuring that the work is completed as defined in the contract
Sub
Subcontractor; supplier, distributor, vendor, or firm that furnishes supplies or services to or for a prime contractor or another subcontractor
Enclave
Section of an internal network that is subdivided from the rest of the network which operates in the same security domain and shares the protection of a single, common, continuous security perimeter
Basic (Contractor Self-Assessment) NIST SP 800-171 DoD Assessment (also referred to as ‘Basic’ or ‘Basic Assessment’)
The Basic Assessment is the Contractor’s self-assessment of NIST SP 800-171 implementation status, based on a review of the system security plan(s) associated with covered contractor information system(s), and conducted in accordance with NIST SP 800-171A….and Section 5 and Annex A of [the NIST SP 800-171 DoD Assessment Methodology].
Medium NIST SP 800-171 Assessment (also referred to as ‘Medium’ or ‘Medium Assessment’)
The Medium Assessment is conducted by DoD personnel who have been trained in accordance with DoD policy and procedures to conduct the assessment...will consist of a review of the system security plan description of how each requirement is met to identify any descriptions which may not properly address the security requirement. (see NIST SP 800-171 DoD Assessment Methodology)
High (On-Site or Virtual) NIST SP 800-171 DoD Assessment (also referred to as ‘High’ or ‘High Assessment’)
The High Assessment, conducted by DoD personnel who have been trained in accordance with DoD policy and procedures to conduct the assessment, requires a thorough on-site or virtual verification/examination/demonstration of the Contractor’s system security plan and implementation of the NIST SP 800-171 security requirements. (see NIST SP 800-171 DoD Assessment Methodology)
Resources:
Supplier Performance Risk System (SPRS)
https://www.sprs.csd.disa.mil/
OUSD(A&S) Strategically Assessing Contractor Implementation of NIST SP 800-171 site
https://www.acq.osd.mil/dpap/pdi/cyber/strategically_assessing_contractor_implementation_of_NIST_SP_800-171.html
NIST SP 800-171 Rev. 2
https://csrc.nist.gov/publications/detail/sp/800-171/rev-2/final
NIST SP 800-171A
https://csrc.nist.gov/publications/detail/sp/800-171a/final
DoD Procurement Toolbox – Cybersecurity in DoD Acquisition Regulations
https://dodprocurementtoolbox.com/site-pages/cybersecurity-dod-acquisition-regulations
**LATEST VERSIONS AS OF THE TIME OF VIDEO PUBLICATION.**
More
Tags
Defense Contract Management Agency
dcma
DIBCAC
Defense Industrial Base Cybersecurity Assessment Center
NIST SP 800-171
More
Up Next
10:28
Where to Begin with NIST SP 800-171 Implementation
1:48
ANG Strategic Planning System
Now Playing
Cybersecurity Compliance: An Introduction to DFARS 252.204-7012 and NIST SP 800-171 Requirements
2:16
U.S. Navy Completes Medical SMEEs, Training in Peru
4:24
SPS 19 Wrap-Up Video
0:59
Marine Minute: Spaghetti and MAGTFs
1:49
U.S. Navy Conducts Mass Casualty Drill with Peruvian Military
1:29
Honduran Service Members Speak About SMEEs with U.S. Counterparts
2:36
U.S. Navy Promotes Medical Readiness in Honduras
2:01
U.S. Navy Builds School for Indigenous Colombians
1:58
NATO Experts – How does NATO improve the quality of human life? (WITH SUBS)
1:57
NATO Experts – How does NATO improve the quality of human life? (International Version)
2:05
U.S. and Guatemalan Military Medical Personnel Conduct Mass Casualty Drill
1:07
U.S. Navy Supports Medical Readiness in Guatemala
1:27
Integration
More Videos