SDMmag logo
search
Go to Ask SDM AI
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
SDMmag logo
  • NEWS
  • PRODUCTS
  • TOPICS
    • Access Control & Identification
    • Integration & Network Solutions
    • Life Safety & Fire Alarm
    • Monitoring
    • Smart Home
    • Trends & Industry Issues
    • Video Solutions
  • COLUMNS
    • Digital Shuffle
    • Editor's Angle
    • Insider News & Business
    • Integration Spotlight
    • Marketing Madmen
    • Security & the Law
    • Security Comings & Goings
    • Security Networkings
    • Technology @ Work
    • Technology Solutions & Skills
    • SIA Waypoints
    • Cybersecurity Chronicle
  • EXCLUSIVES
    • Annual Industry Forecast
    • Dealer of the Year
    • Project of the Year
    • SDM 100
    • State of the Market Series
    • Systems Integrator of the Year
    • Top Systems Integrator Report
    • TMA Excellence Awards
  • BLOG
  • MEDIA
    • Videos
    • Podcasts
    • Polls
    • White Papers
  • EVENTS
    • Industry Calendar
    • Webinars
  • MORE
    • Classified Ads
    • Newsletters
    • SDM Store
    • State of Security eBook
    • Sponsored Insights
  • BUYERS GUIDE
    • Buyers Guide
    • Take a Tour
  • EMAG
    • eMagazine
    • Archive Issues
    • Monitoring Today
    • Advertise
  • SIGN UP!
Standards, Regulations & Legislation

Uncle Sam Wants to Standardize Cyber Requirements for Federal Contractors

Cybersecurity Requirements
Getty Images
SmileStudioAP/iStock / Getty Images Plus via Getty Images
October 11, 2023

Almost 10 years after the Department of Defense (DoD) established rules that require mandatory reporting of cyber incidents, the Federal Acquisition Regulation (FAR) Council recently released a pair of proposed rules: The first rule imposes security incident reporting requirements on federal contractors, whereas the second aims to standardize cybersecurity contractual requirements for unclassified Federal Information Systems (FIS).

The rules could have significant implications for both government prime and subcontractors.

When enacted, these rules could implement new security measures and incident reporting requirements via FAR clauses for contractors across the entire federal government. The Cyber Threat and Incident Reporting and Information Sharing proposed rule focuses on increasing the sharing of information about cyber threats between government and private industry, while the Standardizing Cybersecurity Requirements for Unclassified Federal Information Systems proposed rule focuses on implementing policies, procedures and requirements for contractors maintaining an FIS. 

Issued on Oct. 3, the proposed rules partially implement President Biden’s Executive Order 14028 (signed in May 2021) on “Improving the Nation’s Cybersecurity.” The proposed rules, as drafted, will have a major impact on federal contractors and come at a time when cybersecurity concerns are top of mind for the government.

By example, one section particularly germane to security integrators states: 

“The Government has a responsibility to protect and secure its computer systems, whether they are cloud-based, on-premises, or a hybrid of the two. The scope of that protection and security must encompass the systems that process data (e.g., information technology (IT)) and those that run the vital machinery that ensures its safety (e.g., operational technology (OT)). The Government contracts with IT and OT service providers to conduct an array of day-to-day functions on Federal Information Systems (FIS).”

Operational technology is defined in the rules as: [P]rogrammable systems or devices that interact with the physical environment (or manage devices that interact with the physical environment). These systems or devices detect or cause a direct change through the monitoring and/or control of devices, processes, and events. Examples of operational technology include industrial control systems, building management systems, fire control systems, and physical access control mechanisms (NIST SP 800–160 vol 2).

Looking for quick answers on security topics? Try Ask SDM, our new smart AI search tool. Ask SDM →

“By standardizing a set of minimum cybersecurity standards to be applied consistently to FISs, the proposed rule would ensure that such systems are better positioned in advance to protect from cyber threats,” the rule proposal states. 

As part of this new rule, contractors would be required to provide access to the Cybersecurity and Infrastructure Security Agency (CISA) as well as collaborate with them on incident response initiatives.

“If the contractor receives a request for access from CISA, the contractor must confirm the validity of the request by contacting CISA and notifying the contracting officer in writing of the request for access,” the proposal states.

The government is accepting comments from the public until Dec. 4 prior to issuing a final rule, a process which typically takes about one year. 


KEYWORDS: cybersecurity

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Recommended Content

JOIN TODAY
to unlock your recommendations.

Already have an account? Sign In

  • SDM 100

    SDM 100: Top 100 Security Dealers of 2026

    The top 100 security dealers navigated a complex...
    SDM 100 Report
    By: Karyn Hodgson
  • Security camera

    State of the Market: Video Surveillance

    As video surveillance shifts from siloed systems to...
    Exclusives
    By: Brianna Wilson
  • 2026 Industry Forecast

    SDM 2026 INDUSTRY FORECAST

    Rapid technology advances meet shifting economic...
    Trends & Industry Issues
    By: Karyn Hodgson
Manage My Account
  • SDM Newsletters
  • Online Registration
  • eMagazine Subscriptions
  • Subscription Customer Service
  • Manage My Preferences

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the SDM audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of SDM or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Doctor examining child patient with mother present in medical clinic
    Sponsored byHID

    The Human Side of Hospital Security: How Modern Visitor Management Protects People First

Popular Stories

ESA Board of Directors Q2 26 Elections

Electronic Security Association Announces 2026 Board of Directors Election Results

TMA & SDM Logos

Becklar, Elite & Puget Win 2026 TMA/SDM Monitoring Center Excellence Awards

SDM 100 of 2026

The 2026 SDM 100 Top Brand Choices

SDM Dealer of the Year 2026 Promotion

Poll

What’s the most promising trend in the industry?

What’s the most promising trend in the industry?
View Results Poll Archive

Products

Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

See More Products
SDM 100 2026 Rankings

Related Articles

  • Image of the Cyber Trust Mark logo.

    White House Launches U.S. Cyber Trust Mark, Cybersecurity Label for Internet-Connected Devices

    See More
  • CYBER MARK

    New 'Cyber Trust Mark' Label to Promote Secure Smart Devices

    See More
  • image of Z-Wave Alliance logo

    Z-Wave Alliance Announces Support & Compliance for U.S. Cyber Trust Mark

    See More
×

Be in the forefront of security intelligence when you receive SDM.

Join over 10,000+ professionals when you subscribe today.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Directories
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing