ARTICLE
1 June 2023

Adam Briscoe Outlines Updated NIST Security Guidelines For Contractors Handling Confidential Unclassified Information

BB
Bass, Berry & Sims

Contributor

Bass, Berry & Sims is a national law firm with nearly 350 attorneys dedicated to delivering exceptional service to numerous publicly traded companies and Fortune 500 businesses in significant litigation and investigations, complex business transactions, and international regulatory matters. For more than 100 years, our people have served as true partners to clients, working seamlessly across substantive practice disciplines, industries and geographies to deliver highly-effective legal advice and innovative, business-focused solutions. For more information, visit www.bassberry.com.
Bass, Berry & Sims attorney Adam Briscoe authored an article for Law360 outlining the set of updated guidelines issued by the National Institute of Standards and Technology (NIST) intended to guide...
United States Government, Public Sector

Bass, Berry & Sims attorney Adam Briscoe authored an article for Law360 outlining the set of updated guidelines issued by the National Institute of Standards and Technology (NIST) intended to guide government contractors that handle confidential unclassified information (CUI). As Adam points out, these new guidelines are an "ongoing effort to clarify specific technical and nontechnical requirements, increase flexibility for federal contractors implementing cyber programs, and strengthen defenses as the cyber threat environment rapidly evolves."

Some of the new changes that will help contractors deal with the rapidly evolving landscape of cybersecurity include:

  1. Three new families of security requirements: planning, system and services acquisition, and supply chain risk management.
  2. Tailoring category reassignments: Tailoring is the process by which a set of baseline security controls are modified to better fit a certain system or environment.
  3. Introduction of organization-defined parameters (ODP): ODPs allow for the customization of designated parameters by federal organizations to support specific organizational missions or business functions, and to manage risk.

Adam summarized the new guidelines by saying "the overhaul been a very intentional and iterative process aimed at increasing the understanding, ease of compliance and conciseness of security requirements to protect CUI in nonfederal systems and organizations."

The full article, " What's New In NIST Revised Sensitive Info Security Guidelines," was published by Law360 on May 26 and is available online (subscription required). Adam also wrote on this topic for the firm's GovCon & Trade blog on May 12 and that content is available here.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More