Photo of Lauren Weiss

Lauren Weiss is an associate in the Governmental Practice in the firm's Washington, D.C. office. She is also a member of the Privacy and Cybersecurity Team.

The National Institute of Standards and Technology (NIST) has released an initial public draft of NIST SP 800-171, Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations. Compliance with the security controls in NIST SP 800-171 is required for Department of Defense contractors and is expected to be incorporated into a new Federal Acquisition Regulation (FAR) clause and required for all federal contractors that process, store, or transmit Controlled Unclassified Information (CUI). 

Continue Reading NIST Releases Initial Public Draft of NIST SP 800-171, Revision 3 for Protection of Sensitive Government Information

The Cybersecurity and Infrastructure Security Agency (CISA) is seeking public comment on the secure software development common self-attestation form to be completed by software producers that sell software to the federal government. Federal agencies are scheduled to begin collecting attestation forms for critical software by June 2023 and for all other software by September 2023.

Continue Reading CISA Releases Proposed Security Attestation Form for Software Producers

On March 2, 2023, the Biden Administration released its National Cybersecurity Strategy. The Strategy represents the latest push by the Administration to focus on cybersecurity concerns, following the release of Executive Order 14028, Improving the Nation’s Cybersecurity in May 2021. The Strategy lays out the cybersecurity goals and objectives for the federal government and outlines a fundamental change in how the federal government wishes to allocate roles, responsibilities, and resources for cybersecurity. It contemplates placing greater responsibility on industry, particularly owners and operators of systems that hold personal data and technology providers. 

Continue Reading Biden Administration Releases Highly Anticipated National Cybersecurity Strategy

We all know that failure to submit your bid proposal on time typically results in rejection. And the list of exceptions to this “late is late” rule is very short, providing only four notable exceptions: (1) an offeror has acceptable evidence of government control of a proposal; (2) an offeror can establish a systemic failure of government procedures resulting in multiple instances of lost information; (3) if electronically submitted, a proposal was received by government infrastructure by 5:00 p.m. one working day prior to the proposal submission date; and (4) if there is only one offeror. But what if you submitted your proposal on time and the agency’s server rejects the submission without bothering to inform you? And what if the basis for rejection was an undisclosed limitation within a server on email size? Does such delay qualify as an exception to the “late is late” rule? The answer depends on which forum you ask.

Continue Reading The Gap Widens Between COFC and GAO on Late is Late Rule

Per Executive Order 14028, Improving the Nation’s Cybersecurity, the Office of Management and Budget (OMB) issued a memorandum on September 14, 2022 requiring federal agencies to only use software from software producers that attest compliance with secure software development guidance issued by the National Institute of Standards and Technology (NIST).

Continue Reading Federal Government Outlines New Security and Attestation Requirements for Software

On Wednesday, October 6, 2021, the Department of Justice (“DOJ”) announced a new Civil Cyber-Fraud Initiative to enforce cybersecurity standards and reporting requirements. The Initiative will use DOJ’s civil enforcement mechanisms, namely the False Claims Act, to pursue government contractors and federal grant recipients that “knowingly provid[e] deficient cybersecurity products or services, knowingly misrepresent[] their cybersecurity practices or protocols, or knowingly violat[e] obligations to monitor and report cybersecurity incidents and breaches.” DOJ will not limit enforcement to entities; individuals also can be held accountable for cybersecurity-related fraud. Under the False Claims Act, penalties for such violations could be substantial, including treble damages.

Continue Reading DOJ Announces Civil Cyber-Fraud Initiative To Enforce Contractor Cybersecurity Compliance