Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupport
Contact Us
Search
Close

Updated NIST Security Guidelines for Contractors Handling Confidential Unclassified Information

By Adam Briscoe on June 8, 2023
Email this postTweet this postLike this postShare this post on LinkedIn

I recently authored an article for Law360 outlining the set of updated guidelines issued by the National Institute of Standards and Technology (NIST) intended to guide government contractors that handle confidential unclassified information (CUI).

As I explained in the article, these new guidelines are an “ongoing effort to clarify specific technical and nontechnical requirements, increase flexibility for federal contractors implementing cyber programs, and strengthen defenses as the cyber threat environment rapidly evolves.”

Some of the new changes that will help contractors deal with the rapidly evolving landscape of cybersecurity include:

  1. Three new families of security requirements: planning, system and services acquisition, and supply chain risk management.
  2. Tailoring category reassignments: Tailoring is the process by which a set of baseline security controls are modified to better fit a certain system or environment.
  3. Introduction of organization-defined parameters (ODP): ODPs allow for the customization of designated parameters by federal organizations to support specific organizational missions or business functions, and to manage risk.

I summarized the new guidelines by saying “the overhaul been a very intentional and iterative process aimed at increasing the understanding, ease of compliance and conciseness of security requirements to protect CUI in nonfederal systems and organizations.” The full article, “What’s New In NIST Revised Sensitive Info Security Guidelines,” was published by Law360 on May 26 and is available online (subscription required). I also wrote on this topic for a previous blog post available here.

Photo of Adam Briscoe Adam Briscoe

Adam Briscoe advises companies as they navigate the contracting process with federal, state, and local governments. He counsels and represents clients on bid protests before the Government Accountability Office (GAO) and the U.S. Court of Federal Claims (COFC), contract claims and disputes, teaming…

Adam Briscoe advises companies as they navigate the contracting process with federal, state, and local governments. He counsels and represents clients on bid protests before the Government Accountability Office (GAO) and the U.S. Court of Federal Claims (COFC), contract claims and disputes, teaming and subcontracting issues, due diligence for mergers and acquisitions, data rights and intellectual property issues, and compliance with cybersecurity and Small Business Administration (SBA) regulations. He further represents nontraditional contractors that provide emerging technology solutions and innovative services to the federal government through nontraditional contracting vehicles.

Read more about Adam BriscoeEmailAdam's Linkedin Profile
Show more Show less
  • Posted in:
    Government Contracts
  • Blog:
    GovCon & Trade
  • Organization:
    Bass, Berry & Sims PLC
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
  • About LexBlog
  • The Field We Built
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo