Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupport
Contact Us
Search
Close

Controversial Cyber Information Sharing Bill May Impact Government Contractors

By Alan Pemberton on March 12, 2015
Email this postTweet this postLike this postShare this post on LinkedIn

Following Obama’ s February 13, 2015 Executive Order to promote the sharing of cybersecurity risks and incidents between the federal government and the private sector, Congress has introduced a slew of information-sharing legislation.  Such legislation includes the Cybersecurity Information Sharing Act of 2015 (“CISA”), which was marked up and approved 14-1 by the Senate Intelligence Committee in a closed session on March 12.

CISA, which has been met with some criticism in the press, provides for the promulgation of policies and procedures for the voluntary sharing of “cyber threat indicators” among the federal government and the private sector.  The bill defines “cyber threat indicators” as “information necessary to describe or identify –

  • malicious reconnaissance . . .;
  • a method of defeating a security control or exploitation of a security vulnerability;
  • a security vulnerability;
  • a method of causing a user with legitimate access to an information system . . . to unwittingly enable the defeat of a security control or exploitation of a security vulnerability;
  • malicious cyber command and control;
  • the actual or potential harm cause by an incident . . .; or
  • any other attribute of a cybersecurity threat.”

As currently drafted, CISA would apply to contractors in two ways:

First, on the positive side, the bill explicitly states that it may not be construed to allow Federal agencies to condition the award of Government contracts on a contractor’s provision of cybersecurity information.  In other words, a contractor cannot be denied a Government contract for not participating in cybersecurity information-sharing with the Federal Government.

Second, the bill raises potential concerns for contractors as it would amend Section 941 of the National Defense Authorization Act (“NDAA”) of 2013, which required the Department of Defense (“DoD”) to promulgate regulations for the rapid reporting of data breaches.  Section 941 would be amended to allow the Secretary of Defense to share information reported under the rapid reporting regulations if that information “consists of cyber threat indicators and countermeasures” and is shared “consistent with the policies and procedures [promulgated under CISA]”.  Thus, DoD contractors subject to the forthcoming rapid reporting regulations will need to pay attention to any information policies and procedures ultimately promulgated under CISA to determine what type of information the Secretary of Defense  may share with federal agencies and the private sector.  If, for example, the contractor’s identity may be shared, contractors experiencing data breaches could find themselves receiving unexpected attention from federal agencies and the private sector.  Moreover, it remains unclear whether this information about cyber incidents and breaches of contractor information systems could be factors in agency responsibility and/or past performance determinations.

Photo of Alan Pemberton Alan Pemberton

Alan Pemberton has practiced in the government contracts area since 1982, and chaired or co-chaired Covington’s government contracts practice from 2000 to 2016. His practice includes the full range of government contracts matters, including bid protest and other procurement litigation before GAO, agency…

Alan Pemberton has practiced in the government contracts area since 1982, and chaired or co-chaired Covington’s government contracts practice from 2000 to 2016. His practice includes the full range of government contracts matters, including bid protest and other procurement litigation before GAO, agency boards, and federal and state courts and ADR tribunals. He advises large and small contractors and grantees about the full range of government proposal, performance, compliance, regulatory, suspension and debarment, transactional and legislative issues. He also directs the firm’s pro bono program as co-chair of the Public Service Committee.

Read more about Alan PembertonEmail
Show more Show less
  • Posted in:
    Government Contracts
  • Blog:
    Inside Government Contracts
  • Organization:
    Covington & Burling LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
  • About LexBlog
  • The Field We Built
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo