|
DoD User Agreements and Splash pages –
Read these slowly and with purpose. If you are the account owner, DIBBS Super User, provide training to your subusers or have them read these requirements. Don’t just read them superficially. Read them as if the success of your business depends on understanding and complying with them. It does! Take time to learn about VPNs and VPN-like devices. Also learn about how to properly handle Export Controlled information.
Why are these actions important? Violation of these Terms and Conditions can impact National Security. The result of violation of DLA’s Terms and Conditions can be permanent denied access to DIBBS as a Prime Contractor. There can also be other consequences. All the terms and conditions are important. The following are two which if violated will result in DLA terminating your access to DIBBS. DLA’s letter will specify what is required to request reinstatement. If DLA agrees to reinstating the company, DLA will provide a new agreement for review and signature.
Super User Terms and Conditions for Access to the DLA Internet Bid Board (DIBBS) – effective 28 OCT 2024
Item #8: I agree that no user account will use any means to mask their internet usage/access to DIBBS (for example, a Virtual Private Network (VPN)). The cFolder splash page also provides this alert.
Does DLA/DoD actively monitor these sites. YES! There have been several businesses whose DIBBS access has been terminated for violating this requirement.
The critical idea behind item #8 is that the IP identify of the user cannot be masked. VPNs exist as software to help protect against cyber threats. To accomplish this, they mask the user’s IP address. Proxy servers and dynamic IP allocation are two other ways in which a user’s IP is cloaked. There may be other methods.
It doesn’t matter whether the use of one of these masking tools was intentional or innocent. If a DIBB’s user’s IP is masked DLA will Flag it, remove DIBB’s access and inform the user. In one instance, the user’s business installed a VPN on all machines. The user didn’t know they were using a VPN. In another case, a user accessed DIBBS from a UW-System campus and didn’t realize that the access point functioned as a Proxy Server. More recently, a business used their phone as an access point. The phone service provider utilized dynamic IP assignment.
The bottom line is that in each of the above scenarios, DLA identified a violation and acted to protect sensitive information. It is possible, that DLA will not agree with the company’s explanation. Access may not be reinstated.
Item 11 is also noteworthy. It states - If the address of this company, as registered in the U.S. Government System for Award Management (SAM), is a U.S. address, I agree that I will not access DIBBS outside the United States or U.S. territories without prior approval from DLA.
There have been at least three companies which have accessed DIBBS from outside the U.S. The foreign access was identified, and DLA took appropriate action.
These are very serious matters and accessing DIBBS is just one issue.
If your laptop contains Export Controlled information in an unencrypted form or using encryption that does not meet the requirements, that can be another issue. This is especially true if the laptop or phone contains ITAR information. In this case, there would most likely be a reportable Export violation.
|