Amendment Of Solicitation/modification Of Contract Page 34

ADVERTISEMENT

CONTRACT NO.
DELIVERY ORDER NO.
AMENDMENT/MODIFICATION NO.
PAGE
FINAL
N00178-14-D-7823
EX01
04
32 of 38
“Security and Privacy Controls for Federal Information Systems and Organizations”
(
/publications/PubsSPs.html).)
Identification and
System & Comm
Access Control
Audit & Accountability
Authentication
Media Protection
Protection
AC-2
AU-2
IA-2
MP-4
SC-2
AC-3(4)
AU-3
IA-4
MP-6
SC-4
AC-4
AU-6(1)
IA-5(1)
SC-7
Physical and
Environmental
AC-6
AU-7
Protection
SC-8(1)
AC-7
AU-8
Incident Response
PE-2
SC-13
AC-11(1)
AU-9
IR-2
PE-3
AC-17(2)
IR-4
PE-5
SC-15
Configuration
AC-18(1)
Management
IR-5
SC-28
Program
AC-19
CM-2
IR-6
Management
System &
Information
AC-20(1)
CM-6
PM-10
Integrity
AC-20(2)
CM-7
Maintenance
SI-2
AC-22
CM-8
MA-4(6)
Risk Assessment
SI-3
MA-5
RA-5
SI-4
Awareness &
Training
Contingency Planning
MA-6
AT-2
CP-9
Legend:
AC: Access Control MA: Maintenance
AT: Awareness and Training MP: Media Protection
AU: Auditing and Accountability PE: Physical & Environmental Protection
CM: Configuration Management PM: Program Management
CP: Contingency Planning RA: Risk Assessment
IA: Identification and Authentication SC: System & Communications Protection
IR: Incident Response SI: System & Information Integrity
(c) Other requirements. This clause does not relieve the Contractor of the requirements specified by applicable
statutes or other Federal and DoD safeguarding requirements for Controlled Unclassified Information (CUI) as
established by Executive Order 13556, as well as regulations and guidance established pursuant thereto.
(d) Cyber incident and compromise reporting.
(1) Reporting requirement. The Contractor shall report as much of the following information as can be obtained to
the Department of Defense via ( ) within 72 hours of discovery of any cyber incident, as
described in paragraph (d)(2) of this clause, that affects unclassified controlled technical information resident on or
transiting through the Contractor’s unclassified information systems:
(i) Data Universal Numbering System (DUNS).
(ii) Contract numbers affected unless all contracts by the company are affected.
(iii) Facility CAGE code if the location of the event is different than the prime Contractor location.

ADVERTISEMENT

00 votes

Related Articles

Related forms

Related Categories

Parent category: Business