Standards and Regulations Flashcards
32 CFR Part 2002
Governs handling of CUI.
CERT RMM
Provides supporting materials for the processes in the CMMC Model.
DFARS 252.204-7012
Regulates how contractors handle CUI and cyber incident reporting.
DFARS 252.204-7019
Requires DIB contractors to submit a summary score of their NIST SP 800-171 compliance.
DFARS 252.204-7020
Defines how the DoD will conduct different types of NIST SP 800-171 assessments.
DFARS 252.204-7021
Enacts the Cybersecurity Maturity Model Certification framework.
DoD Instruction 5200.48
Establishes policy for CUI throughout the DoD.
DFARS 252.227-7013
Defines the Rights in Technical Data — Noncommercial Items.
Executive Order 13556
Establishes need to protect CUI.
FAR 52 (48 CFR § 52.204-21)
Safeguarding requirements and procedures for FCI.
FedRAMP
Provides a certification program for Cloud Service Providers (CSPs) who provide the federal government cloud services.
FISMA
Regulates how federal executive agencies plan and implement security controls to protect sensitive information.
NIST SP 800-37 (RMF)
Provides a standardized process to secure, authorize, and manage IT systems. Used in conjunction with NIST SP 800-53 to meet FISMA requirements.
NIST SP 800-53
Provides security and privacy controls for federal information systems.
Used in conjunction with NIST SP 800-37 to meet FISMA requirements.
NIST SP 800-171 Revision 2
Provides the security controls for protecting CUI in nonfederal systems.