Skip to main content (Press Enter).
U.S. Air Force Logo
Home
Environment
Community Engagement
Honorary Commanders
About Us
Biographies
Emergency Management
CAF
SAPR
ADAPT
Helping Matrix
Base Directory
Questions
We Care
Home Life
Victim Support Services
Mental Wellness
Workplace
Physical Wellness
Financial Wellness
Units
Honor Guard Requests
Contact Us
Visitor Control Center
CAC/ID Card & DEERS Updates
Sexual Misconduct Disciplinary Actions
Dover AFB'S Area Defense Council
Dover Air Force Base
DAF EXECUTIVE ORDER IMPLEMENTATION
Public Affairs Support
News
Team Dover Newcomers
About Us
DVIDSVideoPlayer
Playlist:
Search Results
Video by Michael Dunbar, Chad Hilton, Douglas Key
Player Embed Code:
Download
Embed
Share
Cybersecurity Compliance: An Introduction to DFARS 252.204-7012 and NIST SP 800-171 Requirements
Defense Contract Management Agency
July 20, 2021 | 6:29
A presentation of the concepts related to the regulatory requirements governing contractor cybersecurity and the handling of Controlled Unclassified Information, as well as the process of attaining and demonstrating compliance through assessment.
Glossary of Terms:
DCMA
Defense Contract Management Agency; administrating agency of the Defense Industrial Base Cybersecurity Assessment Center
Prime
Prime contractor; works directly with the government, manages any subcontractors, and are responsible for ensuring that the work is completed as defined in the contract
Sub
Subcontractor; supplier, distributor, vendor, or firm that furnishes supplies or services to or for a prime contractor or another subcontractor
Enclave
Section of an internal network that is subdivided from the rest of the network which operates in the same security domain and shares the protection of a single, common, continuous security perimeter
Basic (Contractor Self-Assessment) NIST SP 800-171 DoD Assessment (also referred to as ‘Basic’ or ‘Basic Assessment’)
The Basic Assessment is the Contractor’s self-assessment of NIST SP 800-171 implementation status, based on a review of the system security plan(s) associated with covered contractor information system(s), and conducted in accordance with NIST SP 800-171A….and Section 5 and Annex A of [the NIST SP 800-171 DoD Assessment Methodology].
Medium NIST SP 800-171 Assessment (also referred to as ‘Medium’ or ‘Medium Assessment’)
The Medium Assessment is conducted by DoD personnel who have been trained in accordance with DoD policy and procedures to conduct the assessment...will consist of a review of the system security plan description of how each requirement is met to identify any descriptions which may not properly address the security requirement. (see NIST SP 800-171 DoD Assessment Methodology)
High (On-Site or Virtual) NIST SP 800-171 DoD Assessment (also referred to as ‘High’ or ‘High Assessment’)
The High Assessment, conducted by DoD personnel who have been trained in accordance with DoD policy and procedures to conduct the assessment, requires a thorough on-site or virtual verification/examination/demonstration of the Contractor’s system security plan and implementation of the NIST SP 800-171 security requirements. (see NIST SP 800-171 DoD Assessment Methodology)
Resources:
Supplier Performance Risk System (SPRS)
https://www.sprs.csd.disa.mil/
OUSD(A&S) Strategically Assessing Contractor Implementation of NIST SP 800-171 site
https://www.acq.osd.mil/dpap/pdi/cyber/strategically_assessing_contractor_implementation_of_NIST_SP_800-171.html
NIST SP 800-171 Rev. 2
https://csrc.nist.gov/publications/detail/sp/800-171/rev-2/final
NIST SP 800-171A
https://csrc.nist.gov/publications/detail/sp/800-171a/final
DoD Procurement Toolbox – Cybersecurity in DoD Acquisition Regulations
https://dodprocurementtoolbox.com/site-pages/cybersecurity-dod-acquisition-regulations
**LATEST VERSIONS AS OF THE TIME OF VIDEO PUBLICATION.**
More
Tags
Defense Contract Management Agency
dcma
DIBCAC
Defense Industrial Base Cybersecurity Assessment Center
NIST SP 800-171
More
Up Next
10:28
Where to Begin with NIST SP 800-171 Implementation
1:48
ANG Strategic Planning System
Now Playing
Cybersecurity Compliance: An Introduction to DFARS 252.204-7012 and NIST SP 800-171 Requirements
4:24
SPS 19 Wrap-Up Video
2:16
U.S. Navy Completes Medical SMEEs, Training in Peru
0:59
Marine Minute: Spaghetti and MAGTFs
1:49
U.S. Navy Conducts Mass Casualty Drill with Peruvian Military
1:29
Honduran Service Members Speak About SMEEs with U.S. Counterparts
2:36
U.S. Navy Promotes Medical Readiness in Honduras
2:01
U.S. Navy Builds School for Indigenous Colombians
1:57
NATO Experts – How does NATO improve the quality of human life? (International Version)
1:58
NATO Experts – How does NATO improve the quality of human life? (WITH SUBS)
2:05
U.S. and Guatemalan Military Medical Personnel Conduct Mass Casualty Drill
1:07
U.S. Navy Supports Medical Readiness in Guatemala
1:27
Integration
More Videos