Justin A. Chiarodo and Philip E. Beshara
As the federal government and contracting community near the end of a year filled with headline-grabbing cyber incidents, the Department of Defense (DoD) has recently issued interim cybersecurity and cloud computing regulations that amend the DFARS and impose important new information safeguarding, reporting, and cloud computing requirements. These are major changes that impact all DoD contractors, and if your company holds DoD contracts you should carefully review these new requirements and assess them as part of your broader corporate cybersecurity strategy.
This alert highlights the key requirements in the Interim Rule (available here).
Information Safeguarding and Cybersecurity Reporting
The Interim Rule expands DoD’s cybersecurity safeguarding and reporting requirements, including the types of information covered by the requirements, governing standards, and triggering events. Up until now, many of DoD’s cybersecurity requirements applied to select groups of defense contractors—those deemed “operationally critical” under the 2015 NDAA or “cleared defense contractors” under the 2013 NDAA, and contractors handling “unclassified controlled technical information,” or “UCTI,” under the DFARS. Continue reading “What DoD Contractors Need to Know: New Changes to Cybersecurity and Cloud Computing Regulations”


DOD, FYSA, SITREP – government contractors are familiar with the alphabet soup that goes hand-in-hand with doing business with the federal government as well as most common labor laws and their acronyms: Federal Labor Standards Act, (“FLSA”), the Family and Medical Leave Act (“FMLA”), or Occupational Safety and Health Act of 1971 (“OSHA”). Now, the question is whether contractors comply with these laws and recent developments in government contractor employment law. On July 31, 2014 the White House issued the 

With the potential for millions of dollars in withholdings on contract payments, Department of Defense (DoD) contractors have become all too familiar with the Business Systems Rule since it was first implemented in 2011. The Department of Energy (DoE) is now following in the steps of DoD and promulgating its own Business Systems Rule. On April 1, 2014, DoE issued a Notice of Proposed Rulemaking for its Business Systems Rule, which is largely modeled off of the DoD rule. This expansion of the Business Systems Rule beyond DoD warrants careful attention by contractors who may not have previously been covered, as effective and proactive compliance is essential to mitigating the risk of withholdings under the rule.
On Wednesday, March 12, 2014, the Department of Defense (DOD) and General Services Administration (GSA) Joint Working Group on Improving Cybersecurity and Resilience Through Acquisition (Working Group) requested
The American Arbitration Association (AAA) recently adopted optional Appellate Rules which significantly change the resolution of post-award issues. The new Appellate Rules, effective November 1, 2013, permit appeals of arbitration rulings directly to an AAA appellate panel. Given the difficulty in overturning traditional arbitration awards, these new rules could help protect against factually and legally flawed outcomes. However, they also could add both time and expense to an arbitration, limiting the efficiencies and cost savings that often lead contractors to use arbitration provisions in the first place. This alert discusses the new Appellate Rules, and some things to keep in mind when evaluating whether to use them.