DFARS Cyber Safeguarding · 2 of 3
Reporting a cyber incident under DFARS
In short
- Rapidly report means within 72 hours of discovery.
- Images of affected systems are preserved for at least 90 days.
- A report is not, by itself, evidence of inadequate security.
1. What counts as a cyber incident
The Defense Federal Acquisition Regulation Supplement (DFARS) clause at 252.204-7012 defines the key terms for incident reporting (DFARS 252.204-7012(a)). A cyber incident means actions taken through computer networks that result in a compromise, or an actual or potentially adverse effect on an information system or the information in it (DFARS 252.204-7012(a)). A compromise is disclosure of information to unauthorized persons, or a violation of a system’s security policy. In a compromise, unauthorized disclosure, modification, destruction or loss of an object, or copying of information to unauthorized media, may have occurred.
Rapidly report means within 72 hours of discovery of any cyber incident (DFARS 252.204-7012(a)). Operationally critical support means supplies or services the Government designates as critical for airlift, sealift, intermodal transportation or logistical support. That support must be essential to the mobilization, deployment or sustainment of the Armed Forces in a contingency operation.
2. The review and the 72-hour report
The duty applies when the contractor discovers a cyber incident that affects a covered contractor information system or the covered defense information in it (DFARS 252.204-7012(c)(1)). It also applies to an incident that affects the contractor’s ability to perform contract requirements designated as operationally critical support and identified in the contract. The contractor must review for evidence of compromise of covered defense information, including identifying compromised computers, servers, specific data and user accounts. The review also covers other systems on the contractor’s networks that may have been accessed as a result of the incident.
The contractor must rapidly report cyber incidents to the Defense Department at the DIBNet portal (DFARS 252.204-7012(c)(1)(ii)). The report is treated as information created by or for the Department and must include, at a minimum, the elements required at that portal (DFARS 252.204-7012(c)(2)). To report, the contractor or subcontractor must have or acquire a Department-approved medium assurance certificate (DFARS 252.204-7012(c)(3)).
3. Subcontractors in the chain
Contractors and subcontractors report cyber incidents directly to the Department (DFARS 204.7302(b)). Subcontractors give the prime contractor the incident report number automatically assigned by the Department. Lower-tier subcontractors pass the number to their higher-tier subcontractor, until the prime contractor is reached. The contractor must require subcontractors to provide that number to the prime contractor, or next higher-tier subcontractor, as soon as practicable (DFARS 252.204-7012(m)(2)(ii)).
4. Malicious software, images and forensic access
If a cyber incident occurs, contractors and subcontractors submit to the Department a cyber incident report and any malicious software detected and isolated (DFARS 204.7302(b)(1)). On request, they also submit media, or access to covered contractor information systems and equipment. Contracting officers refer to the Procedures, Guidance and Information (PGI) at 204.7303-4(c) for instructions on submissions of media and malicious software (DFARS 204.7302(b)(2)).
Malicious software discovered and isolated in connection with a reported incident is submitted to the Department of Defense Cyber Crime Center (DC3), under instructions from DC3 or the contracting officer (DFARS 252.204-7012(d)). It must not be sent to the contracting officer. Malicious software means software or firmware intended to perform an unauthorized process with an adverse impact on the confidentiality, integrity or availability of an information system (DFARS 252.204-7012(a)).
The contractor must preserve and protect images of all known affected information systems and all relevant monitoring and packet capture data (DFARS 252.204-7012(e)). It keeps them for at least 90 days from submission of the incident report, to allow the Department to request the media or decline interest. Forensic analysis means gathering, retaining and analyzing computer-related data for investigative purposes in a way that maintains the integrity of the data (DFARS 252.204-7012(a)). On request, the contractor must give the Department access to added information or equipment necessary for a forensic analysis (DFARS 252.204-7012(f)). If the Department conducts a damage assessment, the contracting officer will request all the damage assessment information gathered under the preservation duty (DFARS 252.204-7012(g)).
5. A report is not, by itself, evidence of failure
A cyber incident reported by a contractor or subcontractor is not, by itself, evidence that it failed to provide adequate security or failed to meet the clause (DFARS 204.7302(d)). When an incident is reported, the contracting officer consults the component Chief Information Officer or cyber security office before assessing compliance. The incident is considered in the context of an overall assessment of the contractor’s compliance with the clause.
6. How reported information is protected and used
Shared information may include contractor attributional or proprietary information whose unauthorized use or disclosure could cause substantial competitive harm (DFARS 204.7302(c)). That information identifies the contractor directly or indirectly, or includes trade secrets or commercially sensitive information not customarily shared outside the company (DFARS 204.7301). The Government protects it against unauthorized use or release, and the contractor must identify and mark it to the maximum extent practicable (DFARS 252.204-7012(h)). In an authorized release, the Government seeks to include only the information necessary for the authorized purpose.
Information not created by or for the Department is authorized for release outside the Department for listed purposes (DFARS 252.204-7012(i)). These include entities whose missions may be affected and those assisting with diagnosis, detection or mitigation of cyber incidents. They also include counterintelligence and law enforcement investigations, and national security purposes. A support services contractor working under the clause at 252.204-7009 may also receive it. Information created by or for the Department, including the incident report, may also be used for any other lawful Government purpose, subject to all applicable statutory, regulatory and policy restrictions on its use and release (DFARS 252.204-7012(j)).
Support services contractors that assist with forensic analysis or damage assessment are subject to restrictions on use and disclosure of reported information (DFARS 204.7302(e)). The clause at 252.204-7009 goes in solicitations and contracts for services that support the Government’s safeguarding and incident reporting activities (DFARS 204.7304(b)). The underlying safeguarding duties are covered in covered defense information and adequate security.
Key terms
| Cyber incident | Network actions resulting in a compromise or an adverse effect on a system or its information. |
|---|---|
| Rapidly report | Report within 72 hours of discovering a cyber incident. |
| Medium assurance certificate | The Department-approved certificate needed to submit a report. |
| Media preservation | Keeping system images and packet capture data for at least 90 days. |
| DC3 | The Department of Defense Cyber Crime Center, which receives malicious software. |
Every statement above links to the document behind it. The full source list for this piece is on the sources page.
This page describes public United States government programs for general information. It is not legal, regulatory or procurement advice, and it does not address the facts of any particular case.
How Sentfore supports this
Incidents abroad follow the same clock as at home. Sentfore works at the delivery end of defense programs in difficult environments, providing secure movement, protective security, facilities and life support. Requirements can be sent through the contact page.