This site uses cookies to improve your experience. To help us insure we adhere to various privacy regulations, please select your country/region of residence. If you do not select a country, we will assume you are from the United States. Select your Cookie Settings or view our Privacy Policy and Terms of Use.
Cookie Settings
Cookies and similar technologies are used on this website for proper function of the website, for tracking performance analytics and for marketing purposes. We and some of our third-party providers may use cookie data for various purposes. Please review the cookie settings below and choose your preference.
Used for the proper function of the website
Used for monitoring website traffic and interactions
Cookie Settings
Cookies and similar technologies are used on this website for proper function of the website, for tracking performance analytics and for marketing purposes. We and some of our third-party providers may use cookie data for various purposes. Please review the cookie settings below and choose your preference.
Strictly Necessary: Used for the proper function of the website
Performance/Analytics: Used for monitoring website traffic and interactions
The subject of the hearing was “Safeguarding the Federal Software SupplyChain.” Thank you for the opportunity to appear before you to address the federal software supplychain. As such, they are well-aware of the challenges involved in addressing vulnerabilities in the federal software supplychain.
We remain committed to this mission at the upcoming Spring Training Conference, ensuring that attendees leave with comprehensive updates on acquisition policies, programs, and initiatives in subjects like artificial intelligence (AI), cybersecurity, the medical supplychain, and much more. We look forward to seeing you in May!
He oversees riskmanagement and cybersecurity accountability for information systems, weapon systems and operational technology supporting military cyberspace operations. His portfolio includes policy and governance of the defense industrial base, cyber supplychainriskmanagement, compliance and cybersecurity capabilities.
In the complex world of governmentcontracting, managingrisks associated with subcontractors is a critical skill that can make or break your project’s success. At Public Contracting Institute , we understand the challenges contractors face when dealing with subcontractors.
Supplier collaboration goes well beyond the sharing of product design documents, extending into initiatives involving product innovation, supplychain visibility, compliance, target cost programs, demand and capacity planning, and riskmanagement. You Appreciate the Real Impact of a Successful Supplier Diversity Program.
‘Ask the PMO Tables:’ One-on-One Sessions with Government Officials As part of our efforts to facilitate engagement between government and industry, we are excited to announce that the popular “Ask the PMO” Tables will return for both days of the Fall Training Conference! James Peake , M.D., James Peake , M.D.,
3 to maintain consistency with the SP 800-53B moderate control baseline: Planning (PL), System and Services Acquisition (SA), and SupplyChainRiskManagement (SR). The post NIST Releases Final Version of NIST SP 800-171, Revision 3 appeared first on GovernmentContracts Legal Forum. 2 to 97 in the Rev.
Non-compliance with DFARS can result in serious ramifications for defense contractors, including contract issues, legal action, financial penalties, and reputational damage, emphasizing the importance of leveraging expert guidance and ensuring compliance across the supplychain.
GSA Requesting Feedback on Draft SupplyChainRiskManagement Questionnaire The General Services Administration’s (GSA) Office of Information Technology Category has developed a supplier assurance questionnaire to gather information regarding cybersecurity supplychainriskmanagement (C-SCRM).
Williams, and Mickey Liebner; Mayer Brown Bipartisan, bicameral legislation in the US Congress would mandate the use of the National Institute of Standards and Technology’s (“NIST”) Artificial Intelligence RiskManagement Framework (“Framework”) by federal agencies.
To view this webinar: How to Fight Threats to the Software SupplyChain. As DCISO, Nate assists in the development, implementation, and oversight of comprehensive information security strategies, riskmanagement, agency incident response plans, and programs. Immigration and Customs Enforcement.
Williams, and Mickey Liebner; Mayer Brown Bipartisan, bicameral legislation in the US Congress would mandate the use of the National Institute of Standards and Technology’s (“NIST”) Artificial Intelligence RiskManagement Framework (“Framework”) by federal agencies.
During the training, Jason, Liam, and Alex will cover the following topics and more: Pricing – Transactional Data Reporting (TDR)/Commercial Sales Practices (CSP); Domestic Preferences; SupplyChain; Enforcement/Mandatory Disclosure/Ethics; Sustainability Requirements/Policy; and Bid Protests Update. James Peake , M.D.,
These efforts send a strong signal to companies interested in the federal contracting space: For those hoping to tap into the $700 billion market, cyber supplychainriskmanagement (C-SCRM) must be a priority. The key is to start by making the effort and investments necessary to secure your cyber supplychain.
NIST has an AI riskmanagement framework now, and some other publications, that are guidance for the development of AI. All companies are dealing with this now, but particularly government contractors, I think need to think specifically about their AI use when it’s supporting a governmentcontract.
Agrees to Pay $5.325 Million to Resolve Allegations of False Claims for Overcharging Federal Agencies and Allegations of DEA Violations and Lack of Compliance as to Listed Chemicals Administrator Guzman Announces Transformation of Customer Experience for Federal Contracting Certifications The post SmallGovCon Week in Review: July 29-Aug.
The Software Acquisition Guide for Government Enterprise Consumers was created by the Information and Communications Technology SupplyChainRiskManagement Task Force, a group co-led by CISA and industry representatives.
The document, officially titled “Incident Response Recommendations and Considerations for Cybersecurity RiskManagement: A CSF 2.0 The new draft guidance also shifts the focus away from “detecting, analyzing, prioritizing, and handling incidents” to incorporating incident response into overall cybersecurity riskmanagement activities.
Contractors should also be aware of the following opportunities that the Government is considering to reduce plastics in the Federal supplychain: The fact sheet touts past Federal accomplishments, including the FSS Single Use Plastics Final Rule that the Coalition commented on in February.
The RFI included 13 questions on infrastructure/supplychain resilience, workforce, innovation, acquisition, policy, and regulatory environment. The AISI will create evaluation tools, test AI models and safeguards, issue guidance on AI safety and riskmanagement, and conduct technical research.
This bipartisan bill would focus government resources on increasing transparency, oversight, and responsible use of federal AI systems and centrally codifying federal governance of agency AI systems. participation from stakeholders, such as government contractors, in critical AI-based activities. View the full article
Government contractors may benefit from an “Official business” exemption which would except otherwise covered transactions performed pursuant to a governmentcontract or grant. The guide provides an overview of UFDUR, important definitions and terms, and tips on how to navigate the report.
Accordingly, contractors competing under OT solicitations (as well as governmentcontracting personnel) should be aware of the potential for judicial review of these kinds of acquisitions.
We remain committed to this mission at the upcoming Spring Training Conference, ensuring that attendees leave with comprehensive updates on acquisition policies, programs, and initiatives in subjects like artificial intelligence (AI), cybersecurity, the medical supplychain, and much more. We look forward to seeing you in May!
These requirements include the SupplyChainRiskManagement control family, identifying where CUI is located, and who can access CUI within a covered network. The post The Holidays Come Early: NIST Unwraps Final Draft Revision 3 to NIST SP 800-171 appeared first on GovernmentContracts Legal Forum.
ManagingRisks and Ensuring Compliance in Sole Source Procurements While sole source procurement can be an effective solution for specific procurement challenges, it is not without its risks. Therefore, procurement teams must implement strategies to manage these risks effectively.
The priority areas are: Asset Management Vulnerability Management Defensible Architecture Cyber SupplyChainRiskManagement (C-SCRM) Incident Detection & Response Each priority area includes further alignment goals to address these variations.
For example, the Roadmap notes that CISA will aim to “develop open source program office guidance for federal agencies” and to continue to advance software bills of material (“SBOMs”) within OSS supplychains.
percent of all contracting dollars and was a $7.5 Seeking Member Feedback on GSA C-SCRM Questionnaire GSA’s Federal Acquisition Service is developing a voluntary Cyber SupplyChainRiskManagement (C-SCRM) Assurance Questionnaire for information and communications technology vendors.
Seeking Member Feedback on GSA C-SCRM Questionnaire GSA’s Federal Acquisition Service is developing a voluntary Cyber SupplyChainRiskManagement (C-SCRM) Assurance Questionnaire for information and communications technology vendors.
This report builds upon the three volumes of recommended practices for software supplychain developers, suppliers, and customers issued by the ESF in 2022. It also builds upon and supports OMB Memorandum M-22-18. The draft guidance would implement many of the provisions of the AI EO.
In addition, for certain systems, contractors will be required to develop a System Security Plan, implement and maintain extensive security controls, conduct annual security assessments and cyber threat hunting and vulnerability assessments, and comply with continuous monitoring and supplychainriskmanagement requirements.
In addition, for certain systems, contractors will be required to develop a System Security Plan, implement and maintain extensive security controls, conduct annual security assessments and cyber threat hunting and vulnerability assessments, and comply with continuous monitoring and supplychainriskmanagement requirements.
The post FAR Council’s Cyber Harvest: New Incident Reporting and Federal Information System Requirements Await Government Contractors appeared first on GovernmentContracts Legal Forum. View the full article
Hope the federal contracting stories from this week aren’t too scary. But it’s also the last weekend to prepare and to stock up on candy for those trick or treaters.
FAR & Beyond: Coalition Testimony on Safeguarding the Federal Software SupplyChain The Coalition for Government Procurement was invited to testify before the House Committee on Oversight and Accountability’s Subcommittee on Cybersecurity, Information Technology, and Government Innovation on November 29.
The AISIC will develop guidelines for “red-teaming, capability evaluations, riskmanagement, safety and security, and watermarking synthetic content,” and will be housed within the U.S. The consortium is made up of over 200 organizations, including tech companies, startups, academia, state and local governments, and non-profits.
Public procurement is not just about ensuring a single contract; instead, it requires a long-term strategy to stay ahead of the competition. Success in this space requires more than just submitting bids; it demands strategy, consistency, riskmanagement, and a deep understanding of the ever-evolving rules. The secret?
In this capacity Kimberly served as the Chair for the Agency’s Procurement Equity Workgroup, the Agency’s Senior Accountable Official for SupplyChainRiskManagement, and the Senior Accountable Official for EPA’s Made-in-America implementation. Department of Labor (DOL) and the U.S.
Office of Management and Budget (“OMB”) Releases Implementation Guidance Following President Biden’s AI Executive Order On November 1, 2023, OMB released draft guidance on Advancing Governance, Innovation, and RiskManagement for Agency Use of Artificial Intelligence.
In addition, for certain systems, contractors will be required to develop a System Security Plan, implement and maintain extensive security controls, conduct annual security assessments and cyber threat hunting and vulnerability assessments, and comply with continuous monitoring and supplychainriskmanagement requirements.
We organize all of the trending information in your field so you don't have to. Join 5,000+ users and stay up to date on the latest articles your peers are reading.
You know about us, now we want to get to know you!
Let's personalize your content
Let's get even more personalized
We recognize your account from another site in our network, please click 'Send Email' below to continue with verifying your account and setting a password.
Let's personalize your content