Cybersecurity compliance requirements for contractors (e.g., FISMA1 and DFARS 252.204-70122) are not always clearly defined or consistently applied. Requirements often depend on a number of factors, including the agency data/systems being used, contractor services being provided, and contracting processes.

While compliance may prove to be challenging, noncompliance increases the risk of data being lost or improperly disclosed, leading to reputation damage, loss of contracts/business, regulatory penalties, legal actions, or preclusion from bidding on future contracts.

“Cybersecurity is a fundamental business issue, not a technical issue.”

Key learning objectives:

  • Current cybersecurity landscape
  • Existing laws and new developments
  • Who is impacted
  • Risks of not being compliant
  • Relevant information security frameworks – and how they fit together

1Federal Information Security Management Act

2Defense Federal Acquisition Regulation Supplement

For more information on this topic, or to learn how Baker Tilly specialists can help, contact our team.

Next up

Show me the money: Using data analytics to audit payroll