CUI Program Update to Stakeholders

EDIT: Slides for this briefing can be found here CUI Stakeholders Briefing 20190717

The Next CUI Program Update to Stakeholders is scheduled for July, 17 (1pm-3pm Eastern).

The briefing will be broken up into two parts:

  1. Update on CUI implementation.
  2. Q&A.

The conference begins at 1:00 PM Eastern Time on July 17, 2019; you may join the conference 10 minutes prior.

Step 1: Dial into the conference.
Dial-in: 1-877-369-5243 or 1-617-668-3633
Access Code: 0645584##
Need an international dial-in number?

Step 2: Join the conference on your computer.
Entry Link: http://ems8.intellor.com/login/813264

When you access the entry link above, you will be provided a choice – to install the WebEx plug-in for your preferred browser or to join the web conference using a temporary path. Either option is acceptable.

Need technical assistance? Call the AT&T Help Desk at 1-888-796-6118 or 1-847-562-7015.

Protecting Controlled Unclassified Information: Comment on Draft NIST SP 800-171 Rev. 2 and Draft NIST SP 800-171B (comment period ends July 19, 2019)

https://csrc.nist.gov/News/2019/draft-sp-800-171-rev-2-and-sp-800-171b

NIST is seeking comments on Draft NIST Special Publication (SP) 800-171 Revision 2Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, and Draft NIST SP 800-171BProtecting Controlled Unclassified Information in Nonfederal Systems and Organizations: Enhanced Security Requirements for Critical Programs and High Value Assets.

The public comment period for both publications ends on July 19, 2019. See the publication details for SP 800-171 Rev. 2 and SP 800-171B for document files and instructions on submitting comments.

Details

Draft NIST SP 800-171 Revision 2 provides minor editorial changes in Chapters One and Two, and in the Glossary, Acronyms, and References appendices. There are no changes to the basic and derived security requirements in Chapter Three. For ease of use, the Discussion sections, previously located in Appendix F (SP 800-171 Revision 1), have been relocated to Chapter Three to coincide with the basic and derived security requirements.

Draft NIST SP 800-171BProtecting Controlled Unclassified Information in Nonfederal Systems and Organizations: Enhanced Security Requirements for Critical Programs and High Value Assets, was developed in the spring of 2019 as a supplement to NIST SP 800-171. This new document offers additional recommendations for protecting Controlled Unclassified Information (CUI) in nonfederal systems and organizations where that information runs a higher-than-usual risk of exposure. When CUI is part of a critical program or a high value asset (HVA), it can become a significant target for high-end, sophisticated adversaries (i.e., the advanced persistent threat (APT)). In recent years, these critical programs and HVAs have been subjected to an ongoing barrage of serious cyberattacks, prompting the Department of Defense to request additional guidance from NIST.

The enhanced security requirements are to be implemented in addition to the basic and derived requirements in NIST SP 800-171, since the basic and derived requirements are not designed to address the APT. The enhanced security requirements apply only to components of nonfederal systems that process, store, or transmit CUI or that provide protection for such components when the designated CUI is contained in a critical program or HVA. The enhanced security requirements are only applicable for a nonfederal system or organization when mandated by a federal agency in a contract, grant, or other agreement.

2nd Industry Day Update

Industry clapart

 

June 21, 2019

10:00 a.m. – 2:00 p.m.

McGowan Theater + Presidential Conference rooms

National Archives Museum

701 Constitution Ave. NW

Washington, DC  20408

This event is FREE to all vendors and attendees!

ISOO is hosting it’s 2nd Industry Day for the Executive Branch entities or other stakeholders (i.e., Agencies, Industry, Non-federal Organizations) to learn about products and services that have been developed for the CUI Program.

The day will begin in the McGowan Theater at 10:00 a.m. with a brief presentation.  The presentation will give an update on the status of the CUI Program implementation, a quick CUI program overview, an update on the FAR (Federal Acquisitions Regulation), what CUI resources are offered, when we will be holding the next Stakeholders webex, and information about our CUI Blog.  Then we will convene to the Presidential conference rooms.

Below is a list of vendors that will have a booth at this event.

WE STILL HAVE 2 BOOTHS AVAILABLE 

     

OOAC   –   TITUS   –   CORE BUSINESS SOLUTIONS, INC. –

SYSARC   –    SERABRYNN   –   SEM   –   INFUSIONPOINTS,  LLC   –   DELOITTE   –   

ACTIVE NAVIGATION   –    COALFIRE   –   IVIS TECHNOLOGIES   –   

SECRESTRUX LLC   –   PKH ENTERPRISES   –   BRMI   –   ACVITS   –

SABINE SOLUTIONS INCORPORATED & ASSURED BRIDGE INCORPORATED    –

       PROTIVITI GOVERNMENT SERVICES   –  FEDERAL RECORDS CENTERS – 

INSIDER THREAT DEFENSE GROUP   –  171 COMPLY   –   

CENTER FOR DEVELOPMENT OF SECURITY EXCELLENCE

                                                         

 

 

 

 

 

 

 

 

 

 

Industry Day Reminder

 

Industry clapart

Industry Day

June 21, 2019

10:00 a.m. – 2:00 p.m.

McGowan Theater + Presidential Conference rooms

National Archives Museum

701 Constitution Ave. NW

Washington, DC  20408

ISOO is hosting our 2nd Industry Day for Executive Branch entities or other stakeholders (i.e., Agencies, Industry, Nonfederal Organizations) to learn about products and services that have been developed for the CUI Program.  If you would like to learn more about the CUI program prior to attending Please be sure to visit the CUI training page at: https://www.archives.gov/cui/traing.html

This event is FREE to all vendors and attendees.

If you are interested in attending please RSVP to CUI@NARA.GOV

If you are interested in a booth, please submit this form to CUI@NARA.GOV

Industry Day Reminder

 

Industry clapart

Industry Day

June 21, 2019

10:00 a.m. – 2:00 p.m.

McGowan Theater + Presidential Conference rooms

National Archives Museum

701 Constitution Ave. NW

Washington, DC  20408

ISOO is hosting our 2nd Industry Day for Executive Branch entities or other stakeholders (i.e., Agencies, Industry, Nonfederal Organizations) to learn about products and services that have been developed for the CUI Program.  If you would like to learn more about the CUI program prior to attending Please be sure to visit the CUI training page at: https://www.archives.gov/cui/training.html

This event is FREE to all vendors and attendees.

If you are interested in attending please RSVP to CUI@NARA.GOV

If you are interested in a booth, please submit this form to CUI@NARA.GOV

WE STILL HAVE BOOTHS AVAILABLE FOR VENDORS!

(Booths will be assigned on a first come, first serve basis)

Industry Day Reminder

 

 

Industry clapart

Industry Day

June 21, 2019

10:00 a.m. – 2:00 p.m.

McGowan Theater + Presidential Conference rooms

National Archives Museum

701 Constitution Ave. NW

Washington, DC  20408

ISOO is hosting our 2nd Industry Day for Executive Branch entities or other stakeholders (i.e., Agencies, Industry, Nonfederal Organizations) to learn about products and services that have been developed for the CUI Program.  If you would like to learn more about the CUI program prior to attending Please be sure to visit the CUI training page at: https://www.archives.gov/cui/traing.html

This event is FREE to all vendors and attendees.

If you are interested in attending please RSVP to CUI@NARA.GOV

If you are interested in a booth, please submit this form to CUI@NARA.GOV

WE STILL HAVE BOOTHS AVAILABLE FOR VENDORS!

(Booths will be assigned on a first come, first serve basis)

Director’s Corner

by Mark Bradley, Director, ISOO

The Wall Street Journal reported in its April 29, 2019, edition that American intelligence chiefs now believe that Chinese espionage is the most significant long-term threat facing the country. This threat encompasses traditional spy craft, which is aimed at stealing government secrets, and the theft of intellectual property and research from corporations and universities. China’s effort is being aided and abetted by oceans of stolen personal data, such as the heist in 2015 of more than 20 million files from the Office of Personnel Management. Counterintelligence experts believe that such grand scale thefts help Chinese intelligence officers pinpoint who may be the most vulnerable to recruitment.

The Information Security Oversight Office is the Executive Agent of the government’s Controlled Unclassified Information program. This program’s primary aim is to enhance the government’s protection of sensitive but unclassified information.

The Next CUI Program Update to Stakeholders and Slides from the last one.

Thank you to all those who attended, we had very good showing with lots of you logging in to our webinar yesterday and a lot of participation in the Q&A period.

The Next CUI Program Update to Stakeholders is scheduled for July, 17 (1pm-3pm EST).

  • The agenda and participation information will be provided here on the blog at a latter date.

Please see the attached slides from our last update: CUI Update to Stakeholders Apr, 17 2019

CUI Quarterly Update to Stakeholders

The webinar is tomorrow, April 17, 2019,  (1-3 EDT).

Topics include:

  • A brief overview of the CUI program;
  • An update on agency implementation efforts;
  • The status and plans for a CUI Federal Acquisition Regulation Rule;
  • CUI Industry Day; and,
  • Time for Questions and Answers.

Hosted by: Devin Casey and Charlene Wallace

Participant Instructions

The conference begins at 1:00 PM Eastern Time on April 17, 2019; you may join the conference 10 minutes prior.
Step 1: Dial into the conference.
Dial-in: 1-877-369-5243 or 1-617-668-3633
Access Code: 0506395##

Step 2: Join the conference on your computer.

Entry Link: http://ems8.intellor.com/login/812719

When you access the entry link above, you will be provided a choice – to install the WebEx plug-in for your preferred browser or to join the web conference using a temporary path. Either option is acceptable.

Need technical assistance? Call the AT&T Help Desk at 1-888-796-6118 or 1-847-562-7015.