By Jeffrey W. Bennett, ISOC, ISP, SAPPC, SFPC
Protecting CUI is a security manager's job. However, because of confusing or lacking NISPOM guidance, defense contractors for the most part have relegated an important task to cyber security or IT professionals. This is not good. It's similar to a bank relying on alarms to protect the gold instead of adding the additional task of documenting the value and locking it in a vault. The alarms don't stop the intruders and when the gold is just sitting there, the thieves take it without fuss and no one knows what was taken or the value it held.
The issue is lack of consistency in identifying, marking and protecting sensitive information in the contractor's workflow.
I recently spoke at several NCMS events on data protection. Well, in our terms it's Controlled Unclassified Information (CUI) and other sensitive information as identified by the federal government. Those in the defense industry should understand the responsibility of protection sensitive information at all locations and formats. Whether prime contractors or lower tier subcontractors, the requirement to protect sensitive information consistently. Classified, OPSEC, personal Identifiable information, CUI and other sensitive information protection is a defense contracting and acquisitions requirement.
This is a job for security professionals and not cybersecurity or IT professionals. While they understand how to build the network and store the CUI, they may not put the effort into the analysis, training and documenting required. They understand NIST, but may not understand what performing on the contract looks like nor what the government contracting activity or program manager requires.
Again, the protection of this information has been rejected by security professionals and relegated to the cyber and IT community. Why do I say this?
- NISPOM does not address CUI and FSOs may view it as out of scope
- CUI protection is required in CMMC and NIST
- Security community is not proactive on protecting CUI
- All CUI discussions occur in CMMC communities and when many FSOs discuss it, it's from a CMMC concern
- Just follow social media CUI discussions none are led by security professionals unless focused on CMMC
I get that these are broad generalizations, but they are prevalent. While I believe CMMC has an important role, It is only part of the solution. The missing part is the contractor's proactive task of identifying, marking and protecting CUI in their workflow. This is not IT or Cyber's job, it's the program managers job and security professionals have transferrable skills that can help.
The application here is that once the GCA identifies CUI in source documents, the prime contractor should identify it in their workflow and delegate it to subs. The same sensitive information should be protected with equally effective countermeasures, training, and awareness no matter where it resides.
Facility Security Officers and program manager teams should review contracts and performance requirements imposed by customers to determine protection requirements. As such, don't just read the DD Forms 254 (especially since unclassified contracts don't use them) but engage the entire contract, presentations, engineer design documents, statements of work for all acquisition transactions, etc. This includes design, engineer and security specifications. How else will one truly understand what is required by the customer? At the same time, what requirements does the organization flow down to teaming vendors and subcontractors?
Analyzing all protection requirements leaves less to chance. Until each teaming unit analyzes the CUI identification, marking and protection requirements and employs the consistent protection measures, there will always be a weaker link.Â
For more ways of setting up a security system in a Cleared Defense Contractor, see Red Bike Publishing's book, Get U.S. Government Contracts and Classified Work
https://www.thriveanalysis.com/ - Consulting
https://www.nispomcentral.com/ - Books and training
