<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/" >

<channel>
	<title>NIST SP 800-171 &#8211; SolvereOne</title>
	<atom:link href="https://www.solvereone.com/tag/nist-sp-800-171/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.solvereone.com</link>
	<description>SolvereOne Site</description>
	<lastBuildDate>Tue, 08 Aug 2023 20:31:53 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>
	<item>
		<title>Benefits of 800-171 Support In Northern Virginia</title>
		<link>https://www.solvereone.com/benefits-800-171-support-northern-virginia/</link>
		
		<dc:creator><![CDATA[solvereone]]></dc:creator>
		<pubDate>Wed, 09 Aug 2023 11:30:29 +0000</pubDate>
				<category><![CDATA[Homepage Slider]]></category>
		<category><![CDATA[Managed IT]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[it support]]></category>
		<category><![CDATA[NIST SP 800-171]]></category>
		<category><![CDATA[northern virginia]]></category>
		<guid isPermaLink="false">https://www.solvereone.com/pages/?p=5716</guid>

					<description><![CDATA[Benefits of 800-171 Support in Northern Virginia When the National Institute of Standards and Technology (NIST) released their special publication (SP) 800-171, they took an important step to prevent security breaches for government contractors. If you’re a non-federal agency that works with government data, you’re required to comply with the regulations this publication outlines. NIST [&#8230;]]]></description>
										<content:encoded><![CDATA[<div>
<h1>Benefits of 800-171 Support in Northern Virginia</h1>
<p>When the National Institute of Standards and Technology (NIST) released their special publication (SP) 800-171, they took an important step to prevent security breaches for government contractors.</p>
<p>If you’re a non-federal agency that works with government data, you’re required to comply with the regulations this publication outlines. <strong>NIST SP 800-171 applies to Controlled Unclassified Information (CUI),</strong> so any devices or systems that house or transfer this information need to maintain compliance.</p>
<p>When you work with an <a href="https://www.solvereone.com/it-compliance-northern-virginia.html">experienced consultant to provide NIST 800-171 support</a>, <em>your business in Northern Virginia benefits</em>. Here’s how.</p>
</div>
<div class="mt-30">
<h2>Protect Your Data</h2>
<p>800-171 requirements outline basic security measures to protect CUI, but in doing so, help <strong>protect your own data</strong> as well.</p>
<p>Most companies should already have procedures such as those outlined in 800-171 in place. Without these measures, you increase your risk for cyberattacks in addition to legal ramifications from non-compliance for your government contracts.</p>
<p>800-171 protects sensitive information by requiring fundamental controls such as:</p>
<ul class="mb-20" style="font-size: 18px;">
<li>Allowing only authorized users access to systems and devices that contain CUI.</li>
<li>Conducting security awareness trainings so employees better understand their role in network protection.</li>
<li>Mandating regular system maintenance that could resolve existing security issues.</li>
</ul>
<p>These are steps any smart <em>business in Northern VA</em> would take to secure their networks!</p>
</div>
<div class="mt-30">
<p><img decoding="async" src="https://www.solvereone.com/wp-content/uploads/800-171-support-benefits.jpg" alt="Northern VA 800-171" width="100%" height="auto" /></p>
<h2>Build Customer Trust</h2>
<p>In the event of a security breach, you may be found to be in non-compliance if you neglected the measures outlined in the publication to prevent such an infraction. You could lose your funding, not to mention your customers and your reputation.</p>
<p><strong>Taking advantage of 800-171 support</strong> can keep your reputation secure by preventing data breaches. A strong reputation can help you build relationships with your clients and keep your business moving forward.</p>
<p>Customers lose trust if you’ve sustained a cyberattack that’s compromised their information, not to mention onboarding new customers will be particularly difficult.</p>
<p>By maintaining compliance, you can not only keep your funding but <em>keep your customers and your reputation</em> as well.</p>
</div>
<div class="mt-30">
<h2>Prevent Costly Downtime</h2>
<p>A cyberattack could <strong>render your networks inoperable</strong> until you can appropriately respond to the incident. By applying NIST 800-171 controls, you can prevent such an attack in the first place.</p>
<p>In the event that the attack was unavoidable, <em>800-171 controls can minimize the impact</em> and help you be more prepared to handle and recover from a breach.</p>
<p>By regularly scanning for vulnerabilities and assessing the effectiveness of your implemented controls, you can patch holes with the support of an experienced provider in Northern VA and prevent downtime, ultimately saving your company money.</p>
</div>
<div class="mt-30">
<p><img decoding="async" src="https://www.solvereone.com/wp-content/uploads/800-171-northern-va.jpg" alt="800-171 Support Experts" width="100%" height="auto" /></p>
<h2>Market Your Security as an Asset</h2>
<p>It’s no secret that companies both large and small have experienced data breaches.</p>
<p>With <strong>800-171 measures in place</strong>, you can market your business by showing that you take your customers’ data seriously. Clients will be more likely to do business with you knowing that you’ve fulfilled and maintain requirements that help protect sensitive information.</p>
<p>Being security conscious is absolutely an asset. Letting your <em>customers know that their information is safe</em> with you can increase conversions and build loyalty.</p>
</div>
<div class="mt-30">
<h2>Working with a Provider</h2>
<p>Maintaining compliance with <strong>800-171 support from a provider in Northern Virginia</strong> is highly recommended in the event that you aren’t sure how to implement or maintain these controls.</p>
<p>A consultant who’s <a href="https://www.ncms.org/7-key-steps-help-achieve-nist-800-171-compliance/" target="_blank" rel="noopener">experienced with the 800-171 standards</a> can help you successfully meet the requirements. Working with a professional is often the most comprehensive and cost-effective way to be sure your security measures align with those of the publication.</p>
<p>Contact us at Solvere One today to learn more about <em>how our team can help your business</em> see the benefits of 800-171 compliance with the right support!</p>
</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>NIST SP 800-171 Compliance Solution Northern Virginia, DC, MD (Updated 2021)</title>
		<link>https://www.solvereone.com/nist-sp-800-171-compliance-va-dc-md/</link>
		
		<dc:creator><![CDATA[solvereone]]></dc:creator>
		<pubDate>Thu, 14 Jan 2021 12:45:11 +0000</pubDate>
				<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[DFARS]]></category>
		<category><![CDATA[NIST SP 800-171]]></category>
		<guid isPermaLink="false">https://www.solvereone.com/pages/?p=4845</guid>

					<description><![CDATA[NIST SP 800-171 Compliance Solution DC, MD &#38; Northern Virginia Federal contractors, subcontractors, and service providers in Northern Virginia, DC and Maryland doing business with the Department of Defense face a looming December 2017 deadline to meet NIST SP 800-171 compliance regarding their information systems. NIST designed that standard to protect from public disclosure all [&#8230;]]]></description>
										<content:encoded><![CDATA[<h1>NIST SP 800-171 Compliance Solution DC, MD &amp; Northern Virginia</h1>
<p><a href="https://www.solvereone.com/wp-content/uploads/compliance-solution-NIST-SP-800-171.jpg"><img fetchpriority="high" decoding="async" class="alignleft size-full wp-image-4851" src="https://www.solvereone.com/wp-content/uploads/compliance-solution-NIST-SP-800-171.jpg" alt="NIST SP 800-171 Compliance" width="350" height="250" srcset="https://www.solvereone.com/wp-content/uploads/compliance-solution-NIST-SP-800-171.jpg 350w, https://www.solvereone.com/wp-content/uploads/compliance-solution-NIST-SP-800-171-300x214.jpg 300w" sizes="(max-width: 350px) 100vw, 350px" /></a><strong>Federal contractors, subcontractors, and service providers in Northern Virginia, DC and Maryland</strong> doing business with the Department of Defense face a looming December 2017 deadline to meet <a href="https://www.nist.gov/news-events/news/2015/06/nist-publishes-final-guidelines-protecting-sensitive-government-information" target="_blank" rel="noopener">NIST SP 800-171 compliance</a> regarding their information systems.</p>
<p>NIST designed that standard to protect from public disclosure all <em>controlled unclassified information (CUI)</em> and <em>DoD Covered Defense Information (CDI)</em> generated by the Federal government.  CUI and CDI include any information that law, regulation, or government-wide policy requires be secured through safeguarding or disseminating controls.  For DoD purposes, that information encompasses, “[n]ewly created, revised, or previously unmarked unclassified technical documents generated or managed by all DoD-funded research, development, test, and evaluation (RDT&amp;E) programs.”  It likewise involves “any recorded information related to experimental, developmental, or engineering works that can be used to define an engineering or manufacturing process or can be used to design, procure, produce, support, maintain, operate, repair, or overhaul program material.”  <strong>Regarding NIST SP 800-171 compliance,</strong> there are several examples of information that fall within scope: research and engineering data, engineering drawings, computer software documentation, data sets, studies and analyses, specifications, standards, and related performance and/or design documents.</p>
<p>&nbsp;</p>
<h2>Federal Contractors, Subcontractors, and Service Providers</h2>
<p><a href="https://www.solvereone.com/wp-content/uploads/federal-contractors-subcontractors-NIST-DFARS.jpg"><img decoding="async" class="alignright size-full wp-image-4852" src="https://www.solvereone.com/wp-content/uploads/federal-contractors-subcontractors-NIST-DFARS.jpg" alt="NIST SP 800-171 Northern Virginia, DC, Maryland" width="350" height="250" srcset="https://www.solvereone.com/wp-content/uploads/federal-contractors-subcontractors-NIST-DFARS.jpg 350w, https://www.solvereone.com/wp-content/uploads/federal-contractors-subcontractors-NIST-DFARS-300x214.jpg 300w" sizes="(max-width: 350px) 100vw, 350px" /></a><strong>Pursuant to DFARS 225.204-7012</strong>, private sector organizations <em>that process, store, or transmit CUI and CDI must implement NIST SP 800-171 by year’s end</em>.  This is no small feat.  The standard consists of 110 security practices that accord with 14 separate categories of confidentiality-focused security requirements.  They cover access control, awareness and training, audit and accountability, configuration management (baselines for security of hardware and software), identification and authentication (of users and devices), incident response, maintenance, media protection, personnel security, physical protection, risk assessment, <a href="https://www.solvereone.com/it-compliance-northern-virginia.html">security assessment</a>, system and communications protection, and system and information integrity.  Adopting controls to successfully satisfy each of these obligations requires significant amounts of time, money, and know-how.</p>
<p>&nbsp;</p>
<h2>DFARS 252.204-7012 and NIST 800-171</h2>
<p><a href="https://www.solvereone.com/wp-content/uploads/northern-virginia-defense-contractors-NIST.jpg"><img decoding="async" class="alignleft size-full wp-image-4853" src="https://www.solvereone.com/wp-content/uploads/northern-virginia-defense-contractors-NIST.jpg" alt="DFARS 225.204-7012" width="350" height="250" srcset="https://www.solvereone.com/wp-content/uploads/northern-virginia-defense-contractors-NIST.jpg 350w, https://www.solvereone.com/wp-content/uploads/northern-virginia-defense-contractors-NIST-300x214.jpg 300w" sizes="(max-width: 350px) 100vw, 350px" /></a><em>Unfortunately, many small businesses lack all three. </em> One Federal effort to verify an <strong>OPM contractor’s compliance</strong> with NIST SP 800-171, for example, involved the efforts of 10 employees over a two-week period.  It cost the government some $150,000.  Current bids from large consulting firms for a NIST SP 800-171 compliance work package typically start at $160,000.  While effective security should be everyone’s goal, pursuing traditional compliance approach such as these are akin to a mom-and-pop enterprise hiring a major accounting firm to do its taxes when all it really needs is TurboTax<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" />.  Without a better alternative, small businesses are at serious risk of being shut out of <strong>contract opportunities with DoD</strong> altogether.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<h3>Solvere One ASSET<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Making Compliance Affordable</h3>
<p><a href="https://www.solvereone.com/wp-content/uploads/DFARS-NIST-contractors.jpg"><img loading="lazy" decoding="async" class="alignright size-full wp-image-4854" src="https://www.solvereone.com/wp-content/uploads/DFARS-NIST-contractors.jpg" alt="DFARS NIST Contractors" width="350" height="250" srcset="https://www.solvereone.com/wp-content/uploads/DFARS-NIST-contractors.jpg 350w, https://www.solvereone.com/wp-content/uploads/DFARS-NIST-contractors-300x214.jpg 300w" sizes="(max-width: 350px) 100vw, 350px" /></a><strong>ASSET<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /></strong> is the TurboTax<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /> equivalent for NIST SP 800-171 compliance.  It is an affordable, easy-to-use software solution that provides truly automated, continuous, and real-time awareness of an organization’s compliance and security status.  <em>It makes NIST SP 800-171 implementation a snap for businesses of every size and specialty at a fraction of the cost. </em> Solvere One experts are highly knowledgeable and well-trained in ASSET<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /> deployments.  They can help small businesses not only rapidly meet their NIST SP 800-151 compliance requirements, but also establish themselves as best-in-class security performers over the long term.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Everything You Need to Know About 800-171 Compliance</title>
		<link>https://www.solvereone.com/everything-you-need-to-know-about-800-171-compliance/</link>
		
		<dc:creator><![CDATA[solvereone]]></dc:creator>
		<pubDate>Mon, 15 Apr 2019 15:49:37 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Homepage Slider]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[NIST SP 800-171]]></category>
		<guid isPermaLink="false">https://www.solvereone.com/pages/?p=6035</guid>

					<description><![CDATA[Everything You Need to Know About 800-171 Compliance Don’t risk losing your contract! Department of Defense (DoD) contractors that work with Controlled Unclassified Information (CUI) are required to meet the security actions outlined by the National Institute of Standards and Technology (NIST). NIST’s Special Publication (SP) 800-171 is required for both contractors and subcontractors of [&#8230;]]]></description>
										<content:encoded><![CDATA[<h1>Everything You Need to Know About 800-171 Compliance</h1>
<p>Don’t risk losing your contract! Department of Defense (DoD) contractors that work with <strong>Controlled Unclassified Information (CUI)</strong> are required to meet the security actions outlined by the National Institute of Standards and Technology (NIST).</p>
<p>NIST’s Special Publication <strong>(SP) 800-171</strong> is required for both contractors and subcontractors of the DoD to keep sensitive information safe. Here’s everything you need to know about implementing 800-171 for your networks.</p>
<h2 class="mt-30">Who Needs to Comply with 800-171?</h2>
<p>NIST generated its 800-171 publication for non-federal organizations that house, transmit, or access CUI. This means any systems that contain or handle CUI need to <em>apply the processes detailed in 800-171</em>.</p>
<p>However, any systems that don’t apply these <strong>basic security measures</strong> have the potential to be at risk. Whether or not you work for the DoD, businesses everywhere can benefit from <a href="https://www.solvereone.com/it-compliance-northern-virginia.html">800-171 compliance</a>.<br />
<img decoding="async" class="mt-30" src="https://www.solvereone.com/wp-content/uploads/everything-800-171-compliance-wide-1.jpg" alt="" width="100%" height="auto" /></p>
<h2 class="mt-30">Exactly What Information Needs to Be Protected?</h2>
<p>NIST 800-171 applies specifically to CUI. Its goal is to <strong>minimize vulnerabilities</strong> that could compromise data, including network risks as well as actions of employees.</p>
<p>Unfortunately, security breaches for businesses and freelancers alike are common. In many of these cases, it’s difficult to control the damage because the problem is only identified after it’s happened.</p>
<p>By taking advantage of 800-171 support, you have the opportunity to <em>reduce risk and keep your networks and CUI secure</em>.</p>
<h2 class="mt-30">When Do I Need to Fulfill the Requirements?</h2>
<p>The deadline for 800-171 compliance was December 31, 2017. However, if you’ve yet to <strong>meet the requirements</strong>, you not only jeopardize your contract’s standing, but leave your networks vulnerable to malicious hackers.</p>
<p>Implementing the security measures in NIST’s publication is a long-term investment that will benefit you well into the future. Delaying compliance for your systems becomes riskier as time goes on and cyberattacks continue to evolve, so plan to complete the procedures in 800-171 as soon as possible.<br />
<img decoding="async" class="mt-30" src="https://www.solvereone.com/wp-content/uploads/everything-800-171-compliance-wide-3.jpg" alt="" width="100%" height="auto" /></p>
<h2 class="mt-30">Why Is 800-171 Important?</h2>
<p>One of the major <strong>benefits of 800-171 support</strong> is that it implements fundamental protection that any reputable business that works with sensitive information would have in place.</p>
<p>These procedures—such as controlling access, having a plan in the event of a breach, and properly disposing of CUI—are meant to reduce your risk and protect your organization’s data.</p>
<p>NIST’s publication isn’t just important for contractors of the DoD. Effective security measures are hugely relevant for today’s online businesses. Employing these methods is smart for any company that handles material that isn’t meant to be public knowledge.</p>
<h2 class="mt-30">How Can I Gain Compliance?</h2>
<p>Undertaking the controls detailed in <strong>800-171 can feel overwhelming</strong> for organizations that don’t already have at least some of these procedures in place for their networks.</p>
<p>However, executing the controls is designed to provide peace of mind and strengthen your network security. With enhanced protection and best employee practices, you can provide better services.</p>
<p>By working with an experienced IT provider for 800-171 support, you can <em>maintain compliance and keep your contracts</em> and your funding safe. You may also choose to follow NIST’s handbook for evaluating your systems for 800-171 controls to get an idea of the scope of work to be done.<br />
<img decoding="async" class="mt-30" src="https://www.solvereone.com/wp-content/uploads/everything-800-171-compliance-wide-2.jpg" alt="" width="100%" height="auto" /></p>
<h2 class="mt-30">The Benefits of 800-171 Compliance</h2>
<p>Don’t overlook the <strong>significance of 800-171</strong> and the impact it can have on your business.</p>
<p>Whether you’re a non-federal organization working with the DoD or a small business that handles confidential data, NIST 800-171 compliance can provide long-term security benefits.</p>
<p>By leveraging expertise from an IT partner that’s well-versed in 800-171, you can <em>help prevent a security breach</em> that could have serious consequences for your business and its reputation.</p>
<p>Do you still need a strategy for meeting NIST’s requirements? Don’t delay in making a plan to get in compliance!</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Benefits of 800-171 for Small and Medium Businesses</title>
		<link>https://www.solvereone.com/benefits-800-171-small-and-medium-businesses/</link>
		
		<dc:creator><![CDATA[solvereone]]></dc:creator>
		<pubDate>Fri, 18 Jan 2019 15:08:49 +0000</pubDate>
				<category><![CDATA[Homepage Slider]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Managed IT]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[NIST SP 800-171]]></category>
		<category><![CDATA[northern virginia]]></category>
		<category><![CDATA[small business]]></category>
		<guid isPermaLink="false">https://www.solvereone.com/pages/?p=5746</guid>

					<description><![CDATA[The Benefits of 800-171 for Small and Medium Businesses Having the right security for your small or medium-sized business in Northern Virginia allows you to provide better services and peace of mind to your clients. Businesses that choose to follow the safety controls in the National Institute of Standards and Technology (NIST) Special Publication (SP) [&#8230;]]]></description>
										<content:encoded><![CDATA[<div>
<h1>The Benefits of 800-171 for Small and Medium Businesses</h1>
<p>Having the right security for your <strong>small or medium-sized business in Northern Virginia</strong> allows you to provide better services and peace of mind to your clients.</p>
<p>Businesses that choose to follow the safety controls in the <em>National Institute of Standards and Technology (NIST)</em> Special Publication (SP) 800-171 are doing more than keeping their eligibility for funding. They’re keeping their information—and their reputation—safe.</p>
<p>Small- and medium-sized organizations that implement security <a href="https://www.solvereone.com/it-compliance-northern-virginia.html">best practices with 800-171 support</a> gain the following advantages that extend beyond merely gaining compliance.</p>
</div>
<div class="mt-30">
<h2>Strengthen Security</h2>
<p>You can never be too safe against a cyberattack that could liquidate your finances. When protecting your information is of the utmost importance, <strong>the right security measures</strong> go a long way towards preventing disaster.</p>
<p><em>Cyberattacks can easily bankrupt smaller businesses</em> in Northern VA that don’t have the resources to financially recover from a data breach. When you consider that a single infringement could cost tens of thousands of dollars—and potentially much more—adopting practical, relevant security measures just makes sense.</p>
<p>When you understand how to keep your information secure and train your employees to do so as well, you can minimize the chances that hackers will gain access to sensitive information.</p>
<p>By proactively following the <strong>controls outlined in 800-171</strong>, you can also identify certain security risks and know when data has been jeopardized to make the next step count.</p>
</div>
<div class="mt-30">
<p><img decoding="async" src="https://www.solvereone.com/wp-content/uploads/800-171-business-support.jpg" alt="Northern VA 800-171" width="100%" height="auto" /></p>
<h2>Grow Customer Trust and Loyalty</h2>
<p>You can show customers that you’re committed to <em>protecting their data with NIST 800-171 support</em> from a trusted provider in Northern Virginia.</p>
<p>In the event of a security breach, customers are quick to distrust a company and take their business elsewhere. Clients want to see that you’re committed to keeping their information safe. You can show customers that you’re making active, <strong>conscious steps to protect their data</strong> with 800-171 because you value their trust and their business.</p>
<p>Adopting the 800-171 framework can help you stand out from your competitors as well. When you’re able to show specific security measures taken, you tell customers that you’re serious about keeping their data safe and make them confident about doing business with you in the future.</p>
</div>
<div class="mt-30">
<h2>Increase Eligibility for Future Work</h2>
<p>If you do contract work for the Department of Defense, you’re required to <a href="https://www.cmu.edu/iso/compliance/800-171/" target="_blank" rel="noopener">comply with 800-171 regulations</a>. However, even if you’re not a government contractor, you can increase your chances of getting funding in the future.</p>
<p>If you plan on doing work for the government that involves <strong>Controlled Unclassified Information (CUI)</strong>, getting in compliance now may help you be eligible for funding later on. Plus, applying the basic measures in 800-171 can only be helpful to a business that wants to enhance their IT security.</p>
</div>
<div class="mt-30">
<p><img decoding="async" src="https://www.solvereone.com/wp-content/uploads/800-171-small-business-support.jpg" alt="800-171 Support Experts" width="100%" height="auto" /></p>
<h2>Maximize Uptime</h2>
<p>Recovering from a security breach takes time and money. When <em>your Northern VA business suffers downtime</em>, you’re losing revenue for every second you can’t serve customers.</p>
<p>However, with NIST 800-171 support, your firm will be able to respond faster to an incident that jeopardizes data and keep downtime to a minimum. You can get your business and your revenue back on track as quickly as possible to limit damage.</p>
<p>Customers are more likely to continue doing business with you when you <strong>provide dependable services</strong> with the assurance of IT security.</p>
</div>
<div class="mt-30">
<h2>Let’s Talk 800-171</h2>
<p>Is it time for your small or medium-sized business to consider applying 800-171 measures? With all the benefits these security controls can provide, there’s no reason not to take the next step to keep your data safe.</p>
<p>Consider working with a provider that’s well-versed in 800-171 and can help you get in compliance to <strong>improve your operations</strong> and build your customer base!</p>
</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Are You Prepared For Upcoming DOD Requirements?</title>
		<link>https://www.solvereone.com/the-upcoming-dod-requirements/</link>
		
		<dc:creator><![CDATA[solvereone]]></dc:creator>
		<pubDate>Wed, 20 Dec 2017 20:06:30 +0000</pubDate>
				<category><![CDATA[Homepage Slider]]></category>
		<category><![CDATA[Resources]]></category>
		<category><![CDATA[NIST SP 800-171]]></category>
		<guid isPermaLink="false">https://www.solvereone.com/pages/?p=5063</guid>

					<description><![CDATA[Is Your Business Prepared for the Upcoming DoD Requirements?  If you’re a contractor or even a vendor of the Department of Defense (DoD), you’re affected by the Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012. This is a cyber clause called “Safeguarding Covered Defense Information and Cyber Incident Reporting” which goes into effect on December 31, [&#8230;]]]></description>
										<content:encoded><![CDATA[<h1>Is Your Business Prepared for the Upcoming DoD Requirements?</h1>
<p><strong> </strong>If you’re a contractor or even a vendor of the <strong>Department of Defense (DoD)</strong>, you’re affected by the <a href="https://www.lockheedmartin.com/us/suppliers/cybersecurity/dfars.html" target="_blank" rel="noopener">Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012</a>. This is a cyber clause called “Safeguarding Covered Defense Information and Cyber Incident Reporting” which goes into effect on December 31, 2017.</p>
<p>The goal of this cyber clause is to protect covered defense information (CDI), which applies to nearly all potentially sensitive nonpublic information. Based on this clause, you’re required to have adequate <em>security measures in place</em> before the deadline.</p>
<p>Is your business prepared for these upcoming requirements? Here’s what needs to happen before the deadline.</p>
<p><strong> </strong></p>
<h2>Operating as an IT Service or System for the Government</h2>
<p><a href="https://www.solvereone.com/wp-content/uploads/defense-federal-acquisition-regulation.jpg"><img loading="lazy" decoding="async" class="alignleft wp-image-5065 size-full" src="https://www.solvereone.com/wp-content/uploads/defense-federal-acquisition-regulation.jpg" alt="federal acquistior" width="300" height="201" /></a>If you provide IT services or operate as an IT system for the government, any cloud computing services need to be in accordance with cyber clause 252.239-7010, titled “Cloud Computing Services.” If you’re not part of an <strong>IT service or system</strong>, you’ll still be required to implement security requirements under National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, Revision 1, better known as <a href="https://www.solvereone.com/it-compliance-northern-virginia.html">NIST SP 800-171</a>.</p>
<p>This cyber clause, titled “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations”, outlines the requirements that need to be in place by December 31, 2017. If your contract was awarded before October 1, 2017, you need to notify DoD Chief Information Officer (CIO) within 30 days of your contract award of any<em> security requirements</em> that have not been implemented at the time of your award.</p>
<p><strong> </strong>Based on the DFARS cyber clause, any company that has access to or transmits CDI must address their compliance in numerous areas in order to meet the new security objectives.</p>
<p><strong> </strong></p>
<h2>The Areas That Need to Be Addressed</h2>
<p><strong> </strong>If you’re a company directly impacted by DFARS 252.204-7012, your information systems that contain any CDI need to be in compliance with NIST SP 800-171 Revision 1. This <strong>cyber clause outlines 14 different areas</strong> that need to be assessed in order to meet the mandatory security regulations.</p>
<p>These areas include:</p>
<ul>
<li><strong>Access Control. </strong>Limit access to CDI to authorized users or devices.</li>
<li><strong>Awareness and Training. </strong>Ensure that users of your information systems are aware of security risks and properly trained to carry out duties.</li>
<li><strong>Audit and Accountability. </strong>Ensure actions of users can be appropriately traced; create audit records to appropriately monitor and investigate information system activity.</li>
<li><strong>Configuration Management. </strong>Apply security configuration settings to the system.</li>
<li><strong>Identification and Authentication. </strong>Identify users and authenticate identity.</li>
<li><strong>Incident Response. </strong>Establish incident-handling protocol.</li>
<li>Perform maintenance on the system.</li>
<li><strong>Media Protection. </strong>Protect system media containing CDI.</li>
<li><strong>Personnel Security. </strong>Properly screen individuals before allowing access.</li>
<li><strong>Physical Protection. </strong>Limit and monitor physical access.</li>
<li><strong>Risk Assessment. </strong>Assess risk to operations, individuals, and assets as needed.</li>
<li><strong>Security Assessment. </strong>Assess security controls to ensure efficacy.</li>
<li><strong>System and Communications Protection. </strong>Monitor and protect communications at the appropriate boundaries.</li>
<li><strong>System and Information Integrity. </strong>Identify and <em>correct system information</em> flaws; report in a timely manner.</li>
</ul>
<p>In accordance with this cyber clause, you must also report any cyber security attack that impacts CDI within 72 hours.</p>
<p><strong> </strong></p>
<h3>What Your Next Steps Are</h3>
<p>Unless you’re an IT company, you’ll likely need to work with an IT expert to implement these new security regulations. It’s imperative to determine whether your contract includes CDI as soon as possible so that you know whether or not the requirements affect you.</p>
<p>Once you determine the identified CDI, you can evaluate which <strong>steps to take for your compliance measures</strong>. To bring your entire system into compliance will be the costliest method, but it may also be the most necessary. In nearly every situation, compliance is going to be costly and will take time, but it’s imperative that you don’t incur the costs of non-compliance.</p>
<p>You can also establish segregated systems and ensure that your information system that contains CDI is compliant with the DFARS cyber clause. You may also choose to adapt your rates to account for the new cost of this compliance.</p>
<p>This cyber clause is intended to <em>address vulnerabilities and reduce the chances of cyber attacks</em>. Don’t risk your contract just because you can’t keep up with compliance demands. Your business can be prepared for the deadline by assessing and implementing security measures now with the help of security professionals!</p>
<p><strong> </strong></p>
<p><strong> </strong></p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
