Basic Safeguarding of Contractor Information Systems – May 2016

Final Rule on Basic Safeguarding of Contractor Information Systems Issued 16 May 2016

The Department of Defense, General Services Administration, and NASA issued a final rule on 16 May 2016 that amended the Federal Acquisition Regulation (FAR) to add a new subpart and contract clause for the basic safeguarding of contractor information systems that process, store or transmit Federal contract information. This rule is just one step in a series of coordinated regulatory actions being taken or planned to strengthen protections of information systems. The final rule can be viewed at


Effective June 15, 2016, requirements and procedures for basic safeguarding of covered contractor information systems shall include, at a minimum, the following security controls:

·         Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).

·         Limit information system access to the types of transactions and functions that authorized users are permitted to execute.

·         Verify and control/limit connections to and use of external information systems.

·         Control information posted or processed on publicly accessible information systems.

·         Identify information system users, processes acting on behalf of users, or devices.

·         Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.

·         Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse.

·         Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.

·         Escort visitors and monitor visitor activity; maintain audit logs of physical access; and control and manage physical access devices.

·         Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.

·         Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.

·         Identify, report, and correct information and information system flaws in a timely manner.

·         Provide protection from malicious code at appropriate locations within organizational information systems.

·         Update malicious code protection mechanisms when new releases are available.

·         Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.

·         Other requirements. This clause does not relieve the Contractor of any other specific safeguarding requirements specified by Federal agencies and departments relating to covered contractor information systems generally or other Federal safeguarding requirements for controlled unclassified information (CUI) as established by Executive Order 13556.

·         Subcontracts. The Contractor shall include the substance of this clause, including this paragraph (c), in subcontracts under this contract (including subcontracts for the acquisition of commercial items, other than commercially available off-the-shelf items), in which the subcontractor may have Federal contract information residing in or transiting through its information system.