State pushing for IT contractors to monitor security

Rule Proposal

Related Links

The State Department has proposed a new rule that would make information technology contractors take more responsibility for the security of unclassified information.

Under the new requirement, IT contractors would be responsible for the security of systems that access the department's mission-related information. The proposed rule also mandates that all winning contractors develop an IT security plan and submit it within 30 days of a contract award.

The new provisions are meant to ensure that the Department of State Acquisition Regulation meets the standards outlined in the Federal Acquisition Regulation, which was amended in 2005 to meet the requirements of the Federal Information Security Management Act of 2002.

Under State’s proposal, contractors would also need to receive the IT certification and accreditation required by National Institute of Standards and Technology guidelines and the relevant executive branch directives and congressional acts.

Vendors would also be responsible for monitoring the security of their projects, beyond State’s monitoring programs. Furthermore, they would need to provide yearly proof that their IT security plans remain valid.

State will be accepting comments on the proposal for 60 days beginning today.

About the Author

Ben Bain is a reporter for Federal Computer Week.

Featured

  • Defense
    Ryan D. McCarthy being sworn in as Army Secretary Oct. 10, 2019. (Photo credit: Sgt. Dana Clarke/U.S. Army)

    Army wants to spend nearly $1B on cloud, data by 2025

    Army Secretary Ryan McCarthy said lack of funding or a potential delay in the JEDI cloud bid "strikes to the heart of our concern."

  • Congress
    Rep. Jim Langevin (D-R.I.) at the Hack the Capitol conference Sept. 20, 2018

    Jim Langevin's view from the Hill

    As chairman of of the Intelligence and Emerging Threats and Capabilities subcommittee of the House Armed Services Committe and a member of the House Homeland Security Committee, Rhode Island Democrat Jim Langevin is one of the most influential voices on cybersecurity in Congress.

Stay Connected

FCW INSIDER

Sign up for our newsletter.

I agree to this site's Privacy Policy.