Call Us Today! (256) 704-0234 |

UPDATE: Final Publication of NIST SP 800-171, Revision #1

|, Techni-Core Blog|UPDATE: Final Publication of NIST SP 800-171, Revision #1

UPDATE: Final Publication of NIST SP 800-171, Revision #1

29 Dec 2016 — we were recently notified of an update to (ever-changing) NIST 800-171. As is the norm with regulations like this, regular updates are to be expected, but an update this late in the game is something you should be aware of and planning for.

NIST released the summary of changes and final version of SP 800-171, Revision #1 on December 20th.  SP 800-171 – Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, is the significant NIST Special Publication document regarding implementation of DFARS (252.204-7012) requirements for defense contractors, mandated by December 31st 2017.  The draft version of this document was released in August of 2016 for comments.  The first version of SP 800-171 was released in June of 2015 and updated in January of 2016.  While many changes to this latest version are simple verbiage changes, a major addition in the draft, and now final publication, is the requirement for System Security Plans (SSP).

SSPs are a common artifact on contractor and government classified networks, but they have never been mandated on the unclassified networks.

While this is certainly good from a holistic IT security perspective, it will be an additional burden for organizations of any size.  The format and level of detail is not specified in the requirement, but it is noted that the plan should include…:

Descriptions of system boundaries, nature and operation of the system(s), how security is implemented, and connections to other systems.

As you are well aware by now, the deadline for compliance is Dec. 2017. If you haven’t started thinking about and planning for your DFARS compliance process by now, it is a very good time to start. Techni-Core’s team of engineers are primed and ready for your questions about this update and the DFARS compliance process.

Give use a call to get your process started, today! (256) 704-0234

By |2018-06-02T17:58:49+00:00December 29th, 2016|News, Techni-Core Blog|0 Comments

About the Author:

Hi, everyone! My name is Jana Abbott Ricchetti, and I serve as Techni-Core's Team Lead, Project Manager for all IT and Cyber Security services, and Marketing/Business Development Manager. I am a graduate of Mississippi State University (Hail State!) with a degree in Communication Studies. I joined Techni-Core about four years ago. Over that time, I have worked with executive leadership to rebrand TCNS, expand service offerings, structure more successful and efficient compliance projects, and foster vendor relationships to serve all of our customers. The best part of my job is the reward of knowing that our services directly support the success of our customers - there is no better feeling! My customers are the bomb, and I am so honored that they trust me to manage their IT, Compliance, and Cyber services. I LOVE phone calls from customers, so give me a call any time you need anything - I am always happy to help.

Leave A Comment