|
Controlled Unclassified Information (CUI) associated with the Department of Defense (DoD) is well-known due to the DoD’s cybersecurity requirements and the soon-to-be fully implemented Cybersecurity Maturity Model Certification (CMMC) program. However, many agencies besides the DoD create, use, and share information that qualifies as CUI. The scope of information qualifying as CUI is extremely broad. A list of the categories of CUI can be viewed at: CUI Registry Category List.
See: https://www.archives.gov/cui/registry/category-list
Cybersecurity requirements apply to both agencies and contractors that handle and store CUI. However, implementation requirements are not uniform across all agencies. On January 15, 2025, a proposed rule was published in the Federal Register. This rule addresses the handling of CUI by both Federal agencies and contractors.
This proposed rule will likely impact a larger number of federal contractors than the DoD rule does. The resulting requirements may affect costs, compliance requirements, and other business activities. As with all proposed rules, companies are offered the opportunity to review the rule and submit comments. All comments are read and can alter the final rule.
Actions to Take:
- Companies should review the above link to see if the type or expected types of information they may handle qualify as CUI and determine if this new rule will affect them.
- Companies that handle or may handle CUI should then review the Proposed Rule. See: Federal Acquisition Regulation: Controlled Unclassified Information.
See: https://www.federalregister.gov/documents/2025/01/15/2024-30437/federal-acquisition-regulation-controlled-unclassified-information
- Comments are welcome but need to be submitted by March 17, 2025, to be considered for the final rule.
To discuss this proposed rule or the comment submission process, please contact WPI at 414-270-3600 or email: APEXAccelerator@wispro.org.
A summary of the proposed rule can be viewed at: FAR Council Publishes Proposed Rule Imposing New Security Requirements on Contractors Handling CUI.
See: FAR Council Publishes Proposed Rule Imposing New Security Requirements on Contractors Handling CUI | Woods Rogers - JDSupra
The following article is from December 2024.
Just because we turned the page on the calendar doesn’t mean that hackers discarded their old book of cyber-hacks and are using a new playbook. The article mentions two weaknesses: outdated systems that do not receive security updates and systems that increase the attack surface. Note that in 2025, Microsoft will stop supporting Windows 10 on October 14, 2025. See: see: https://www.microsoft.com/en-us/windows/end-of-support. This includes providing both system and security updates. As the saying goes – Wait! There is more. Take a few minutes to review the following article. It is short but addresses several items that deserve both mention and attention. Below the article are questions that apply and links that help to answer the questions. One such question is – How do industrial control systems increase the attack surface for cybercriminals?
See: https://www.csoonline.com/article/3618133/8-biggest-cybersecurity-threats-manufacturers-face.html
|