DOD wants vendor cyber reports
The Defense Department issued an interim rule guiding their contractors and subcontractors on how to report cyber incidents involving unclassified data.
The rule puts into effect requirements written into the national defense authorization bill of 2015. Comments are due by Oct. 26.
Under the rule, the vendors must report cyber incidents that result in an actual or potentially adverse effect on a covered system or set of information, or on a contractor’s ability to provide critical support.
“DoD is working to establish a single reporting mechanism for DoD contractor reporting of cyber incidents on unclassified information systems. This rule is intended to streamline the reporting process for DoD contractors and minimize duplicative reporting processes.
The rule also implements policies and procedures for use when contracting for cloud computing services.
More information: Federal register notice:
http://goo.gl/eRWlZN