The Department of Defense (DoD) on October 4, 2016, issued a
rule finalizing cyber reporting regulations applicable to DoD
contractors and subcontractors set forth in 32 CFR Part 236.
The rule finalizes an interim rule DoD issued on October 2, 2015
and addresses cyber incident reporting obligations for DoD
prime contractors and subcontractors.
Notably, the final rule clarifies the by now well-known
definition of the term 'covered defense information'
("CDI"). This same term is used in DFARS
252.204-7012. This DFARS clause defines CDI to include four
different categories: (1) covered technical information
("CTI"); (2) operations security; (3) export controlled
information; and (4) any other information, marked or otherwise
identified in the contract, that requires safeguarding or
dissemination controls pursuant to and consistent with law,
regulations, and government-wide policies.
Given the similarities of this final category to the definition
of controlled unclassified information ("CUI")
promulgated in connection with the National Archives and Records
Administration's (NARA) rule, we have understood this
latter category to include CUI identified by NARA pursuant to its
efforts under EO 13556. The DoD's new final rule provides
support for this understanding because it narrows the definition of
CDI to only two categories: (1) CTI and (2) CUI. This
modification accordingly appears to make clear that the
"catch-all" category of CDI contained in DFARS
252.204-7012 was intended to align with NARA's CUI efforts.
Importantly, this final rule makes no changes to the DFARS
clause itself, and it is likely that conforming changes will
be made to the DFARS clause in a future revision. The
December 2015 version of the DFARS clause remains effective.
Nevertheless, in light of the final rule contractors and
subcontractors seeking to understand the scope of the CDI
under the DFARS clause should include CUI in their review as they
await further revision to the clause.
Dentons is the world's first polycentric global law firm. A
top 20 firm on the Acritas 2015 Global Elite Brand Index, the Firm
is committed to challenging the status quo in delivering consistent
and uncompromising quality and value in new and inventive ways.
Driven to provide clients a competitive edge, and connected to the
communities where its clients want to do business, Dentons knows
that understanding local cultures is crucial to successfully
completing a deal, resolving a dispute or solving a business
challenge. Now the world's largest law firm, Dentons'
global team builds agile, tailored solutions to meet the local,
national and global needs of private and public clients of any size
in more than 125 locations serving 50-plus countries.
The content of this article is intended to provide a general
guide to the subject matter. Specialist advice should be sought
about your specific circumstances.
To print this article, all you need is to be registered on Mondaq.com.
Click to Login as an existing user or Register so you can print this article.
Join Dentons government contracts lawyers for a Public Contracting Institute (PCI) webinar series involving the most current industry analysis in government contract cost accounting from a team of leaders in the field with unparalleled experience
On September 30, 2016, the Federal Acquisition Regulation Councils issued 10 FAR amendments on a broad range of topics. One rule imposes new risks for contractors with delinquent taxes or felony convictions.
On September 7, 2015, President Barack Obama signed Executive Order 13706, Establishing Paid Sick Leave for Federal Contractors (EO). After months of comments on the proposed rules, on September 30, 2016, the U.S. Department of Labor (DOL) issued a Final Rule to implement Executive Order (EO) 13706.
Register for Access and our Free Biweekly Alert for
This service is completely free. Access 250,000 archived articles from 100+ countries and get a personalised email twice a week covering developments (and yes, our lawyers like to think you’ve read our Disclaimer).