252.204-7008.dita

Files changed (1) hide show
  1. dita/252.204-7008.dita +57 -41
dita/252.204-7008.dita CHANGED
@@ -1,47 +1,63 @@
1
1
  <?xml version="1.0" encoding="UTF-8"?>
2
- <!DOCTYPE dita
3
- PUBLIC "-//OASIS//DTD DITA Composite//EN" "ditabase.dtd">
4
- <dita xmlns:ditaarch="http://dita.oasis-open.org/architecture/2005/"
5
- domains="(topic task) (topic concept) (topic concept glossentry) (topic concept glossgroup) (topic reference) (topic troubleshooting++task) (topic task) (topic abbrev-d) a(props deliveryTarget) (topic equation-d) (topic hazard-d) (topic hi-d) (topic indexing-d) (topic markup-d) (topic mathml-d) (topic pr-d) (topic relmgmt-d) (topic sw-d) (topic svg-d) (topic ui-d) (topic ut-d) (topic markup-d xml-d) (topic task strictTaskbody-c) "
6
- ditaarch:DITAArchVersion="1.3">
7
- <concept id="DFARS_252.204-7008"
8
- ditaarch:DITAArchVersion="1.3"
9
- class="- topic/topic concept/concept ">
10
- <title class="- topic/title ">
11
- <ph props="autonumber" class="- topic/ph ">252.204-7008</ph> Compliance with Safeguarding Covered Defense Information Controls.</title>
12
- <conbody outputclass="provision" class="- topic/body concept/conbody ">
13
- <p class="- topic/p ">As prescribed in
14
- <xref outputclass="fm:ParaNumOnly"
15
- class="- topic/xref "
16
- base="DFARS-204.7304"
17
- href="204.7304.dita#DFARS_204.7304">204.7304</xref>
2
+ <!DOCTYPE dita PUBLIC "-//OASIS//DTD DITA Composite//EN" "ditabase.dtd">
3
+ <dita xmlns:ditaarch="http://dita.oasis-open.org/architecture/2005/" domains="(topic task) (topic concept) (topic concept glossentry) (topic concept glossgroup) (topic reference) (topic troubleshooting++task) (topic task) (topic abbrev-d) a(props deliveryTarget) (topic equation-d) (topic hazard-d) (topic hi-d) (topic indexing-d) (topic markup-d) (topic mathml-d) (topic pr-d) (topic relmgmt-d) (topic sw-d) (topic svg-d) (topic ui-d) (topic ut-d) (topic markup-d xml-d) (topic task strictTaskbody-c) " ditaarch:DITAArchVersion="1.3">
4
+ <concept id="DFARS_252.204-7008" ditaarch:DITAArchVersion="1.3" class="- topic/topic concept/concept ">
5
+ <title class="- topic/title "><ph props="autonumber" class="- topic/ph ">252.204-7008</ph> Compliance with Safeguarding Covered Defense Information Controls.</title>
6
+ <conbody outputclass="provision" class="- topic/body concept/conbody ">
7
+ <p class="- topic/p ">As prescribed in
8
+ <xref outputclass="fm:ParaNumOnly" class="- topic/xref " base="DFARS-204.7304" href="204.7304.dita#DFARS_204.7304">204.7304</xref>
18
9
  (a), use the following provision:</p>
19
- <p class="- topic/p " outputclass="Ctr_SmCaps">COMPLIANCE WITH SAFEGUARDING COVERED DEFENSE INFORMATION CONTROLS (OCT 2016)</p>
20
- <p outputclass="List1" class="- topic/p ">(a) <i class="+ topic/ph hi-d/i ">Definitions</i>. As used in this provision—</p>
21
- <p class="- topic/p ">“Controlled technical information,” “covered contractor information system,” “covered defense information,” “cyber incident,” “information system,” and “technical information” are defined in clause
22
- <xref outputclass="fm:ParaNumOnly"
23
- class="- topic/xref "
24
- base="i1380987"
25
- href="252.204-7012.dita#DFARS_252.204-7012">252.204-7012</xref>
10
+ <p class="- topic/p " outputclass="Ctr_SmCaps">COMPLIANCE WITH SAFEGUARDING COVERED DEFENSE INFORMATION CONTROLS (OCT 2016)</p>
11
+ <info li_elems="0"/>
12
+ <ol>
13
+ <li>
14
+ <p outputclass="List1" class="- topic/p "><ph props="autonumber" class="-topic/ph">(a)</ph><i class="+ topic/ph hi-d/i ">Definitions</i>. As used in this provision—</p>
15
+ <p class="- topic/p ">“Controlled technical information,” “covered contractor information system,” “covered defense information,” “cyber incident,” “information system,” and “technical information” are defined in clause
16
+ <xref outputclass="fm:ParaNumOnly" class="- topic/xref " base="i1380987" href="252.204-7012.dita#DFARS_252.204-7012">252.204-7012</xref>
26
17
  , Safeguarding Covered Defense Information and Cyber Incident Reporting.</p>
27
- <p outputclass="List1" class="- topic/p ">(b) The security requirements required by contract clause
28
- <xref outputclass="fm:ParaNumOnly"
29
- class="- topic/xref "
30
- base="i1380987"
31
- href="252.204-7012.dita#DFARS_252.204-7012">252.204-7012</xref>
18
+ </li>
19
+ <li>
20
+ <p outputclass="List1" class="- topic/p "><ph props="autonumber" class="-topic/ph">(b)</ph> The security requirements required by contract clause
21
+ <xref outputclass="fm:ParaNumOnly" class="- topic/xref " base="i1380987" href="252.204-7012.dita#DFARS_252.204-7012">252.204-7012</xref>
32
22
  , shall be implemented for all covered defense information on all covered contractor information systems that support the performance of this contract.</p>
33
- <p outputclass="List1" class="- topic/p ">(c) For covered contractor information systems that are not part of an information technology service or system operated on behalf of the Government (see
34
- <xref outputclass="fm:ParaNumOnly"
35
- class="- topic/xref "
36
- base="i1380987"
37
- href="252.204-7012.dita#DFARS_252.204-7012">252.204-7012</xref>
23
+ </li>
24
+ <li>
25
+ <p outputclass="List1" class="- topic/p "><ph props="autonumber" class="-topic/ph">(c)</ph> For covered contractor information systems that are not part of an information technology service or system operated on behalf of the Government (see
26
+ <xref outputclass="fm:ParaNumOnly" class="- topic/xref " base="i1380987" href="252.204-7012.dita#DFARS_252.204-7012">252.204-7012</xref>
38
27
  (b)(2)—</p>
39
- <p outputclass="List2" class="- topic/p ">(1) By submission of this offer, the Offeror represents that it will implement the security requirements specified by National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations” (see http://dx.doi.org/10.6028/NIST.SP.800-171) that are in effect at the time the solicitation is issued or as authorized by the contracting officer not later than December 31, 2017.</p>
40
- <p outputclass="List2" class="- topic/p ">(2)(i) If the Offeror proposes to vary from any of the security requirements specified by NIST SP 800-171 that are in effect at the time the solicitation is issued or as authorized by the Contracting Officer, the Offeror shall submit to the Contracting Officer, for consideration by the DoD Chief Information Officer (CIO), a written explanation of—</p>
41
- <p outputclass="List4" class="- topic/p ">(A) Why a particular security requirement is not applicable; or</p>
42
- <p outputclass="List4" class="- topic/p ">(B) How an alternative but equally effective, security measure is used to compensate for the inability to satisfy a particular requirement and achieve equivalent protection.</p>
43
- <p outputclass="List3" class="- topic/p ">(ii) An authorized representative of the DoD CIO will adjudicate offeror requests to vary from NIST SP 800-171 requirements in writing prior to contract award. Any accepted variance from NIST SP 800-171 shall be incorporated into the resulting contract.</p>
44
- <p outputclass="Endofprovision" class="- topic/p ">(End of provision)</p>
45
- </conbody>
46
- </concept>
28
+ <info li_elems="0"/>
29
+ <ol>
30
+ <li>
31
+ <p outputclass="List2" class="- topic/p "><ph props="autonumber" class="-topic/ph">(1)</ph> By submission of this offer, the Offeror represents that it will implement the security requirements specified by National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations” (see http://dx.doi.org/10.6028/NIST.SP.800-171) that are in effect at the time the solicitation is issued or as authorized by the contracting officer not later than December 31, 2017.</p>
32
+ </li>
33
+ <li>
34
+ <p outputclass="List2" class="- topic/p ">
35
+ <ph props="autonumber" class="-topic/ph">(2)</ph>
36
+ </p>
37
+ <info li_elems="0"/>
38
+ <ol>
39
+ <li>
40
+ <p outputclass="List3" class="- topic/p "><ph props="autonumber" class="-topic/ph">(i)</ph> If the Offeror proposes to vary from any of the security requirements specified by NIST SP 800-171 that are in effect at the time the solicitation is issued or as authorized by the Contracting Officer, the Offeror shall submit to the Contracting Officer, for consideration by the DoD Chief Information Officer (CIO), a written explanation of—</p>
41
+ <info li_elems="0"/>
42
+ <ol>
43
+ <li>
44
+ <p outputclass="List4" class="- topic/p "><ph props="autonumber" class="-topic/ph">(A)</ph> Why a particular security requirement is not applicable; or</p>
45
+ </li>
46
+ <li>
47
+ <p outputclass="List4" class="- topic/p "><ph props="autonumber" class="-topic/ph">(B)</ph> How an alternative but equally effective, security measure is used to compensate for the inability to satisfy a particular requirement and achieve equivalent protection.</p>
48
+ <info li_elems="2"/>
49
+ </li>
50
+ </ol>
51
+ </li>
52
+ <li>
53
+ <p outputclass="List3" class="- topic/p "><ph props="autonumber" class="-topic/ph">(ii)</ph> An authorized representative of the DoD CIO will adjudicate offeror requests to vary from NIST SP 800-171 requirements in writing prior to contract award. Any accepted variance from NIST SP 800-171 shall be incorporated into the resulting contract.</p>
54
+ </li>
55
+ </ol>
56
+ </li>
57
+ </ol>
58
+ </li>
59
+ </ol>
60
+ <p outputclass="Endofprovision" class="- topic/p ">(End of provision)</p>
61
+ </conbody>
62
+ </concept>
47
63
  </dita>