Navy

RESOURCES

NIST SP 800-172 “Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171”

NIST 800-172 prescribes enhanced security requirements designed to further protect Controlled Unclassified Information (CUI) from advanced persistent threats by protecting the confidentiality, integrity, and availability of that information on nonfederal information systems associated with critical programs or high value assets.  This publication does not replace NIST SP 800-171, but creates additional security requirements that will need to be implemented for selected systems. Link | Download

Memorandum: Change 18-08 of the Navy Marine Corps Acquisition Regulation Supplement (NMCARS) (September 6, 2019)

This memo from the Deputy Assistant Secretary of the Navy (Acquisition and Procurement) announces immediate changes to the NMCARS, requiring the inclusion of Annex 16 in the statements of work of solicitations, contracts, and task or delivery orders when the DON Program Manager, Program Executive Officer, or Chief of Naval Research, in coordination with the Resource Sponsor, determines that the risk to a critical program and/or technology warrants its inclusion. Link | Download
    • Complete Updated NMCARS Incorporating Change 18-08 (September 6, 2019) Download
        • Excerpt from the NMCARS Change 18-08 describes potential penalties for cybersecurity non-compliance: Download
        • Annex 16 of the NMCARS adds enhanced cybersecurity requirements for selected programs: Download

Secretary of the Navy Cybersecurity Readiness Review (March 4, 2019)

The independent Cybersecurity Readiness Review, requested by The Secretary of the Navy, examined the Department of the Navy’s cybersecurity posture and identified five critical pillars key to cybersecurity readiness: culture, people, structure, processes, and resources. Link | Download