Previous PageTable Of ContentsNext Page

DFARS PGI 204_73



(Revised December 1, 2017)

PGI 204.73—SAFEGUARDING COVERED DEFENSE INFORMATION AND CYBER INCIDENT REPORTING

PGI 204.7303 Procedures.

PGI 204.7303-1 General.

is expected to result in a contract, task order, or delivery order that will involve—

order includes the requirement (such as a contract data requirements list), as provided by the requiring activity, for the contractor to apply markings, when appropriate, on

covered defense information.

PGI 204.7303-2 Safeguarding controls and requirements.

provision at DFARS 252.204-7008, or in accordance with paragraphs (b)(2)(ii)(B) of DFARS clause 252.204-7012, the contracting officer shall submit the offeror’s

explanation of the proposed variance to the DoD Chief Information Officer via email at osd.dibcsia@mail.mil for adjudication.

the Frequently Asked Questions document at http://www.acq.osd.mil/dpap/pdi/network_penetration_reporting_and_contracting.html.

PGI 204.7303-3 Cyber incident and compromise reporting.

components will collaboratively designate a single contracting officer to coordinate additional actions required of the contractor, on behalf of the affected DoD components.

The requiring activity will notify the contracting officer once a lead is designated.

(3) If the requiring activity requests an assessment of compliance with the requirements of the clause at DFARS 252.204-7012 related to the cyber incident, the

contracting officer shall—

requirements in NIST SP 800-171, “Protecting Controlled Unclassified Information in

Nonfederal Information Systems and Organizations” (see

http://dx.doi.org/10.6028/NIST.SP.800-171) in order to support evaluation of whether any of the controls were inadequate, or if any of the controls were not implemented at the time of the incident; and

requiring activity, the DoD CIO at osd.dibcsia@mail.mil, and the other contracting

officers listed in the cyber incident report.

PGI 204.7303-4 DoD damage assessment activities.

(see 204.7303-3(a)(2)).

defined in DFARS 252.204-7012, from the contractor, the contracting officer shall—

document available at

http://www.acq.osd.mil/dpap/dars/pgi/docs/Instructions_for_Submitting_Media.docx;

and

are complete, the requiring activity will provide the contracting officer with a report

documenting the actions taken to close out the cyber incident.

Previous PageTop Of PageTable Of ContentsNext Page