{"id":7532,"date":"2019-12-11T02:33:27","date_gmt":"2019-12-11T07:33:27","guid":{"rendered":"https:\/\/tsisupport.com\/?p=7532"},"modified":"2021-07-07T04:46:26","modified_gmt":"2021-07-07T08:46:26","slug":"why-contractors-with-cui-dont-really-need-govt-software-licensing-for-dfars-compliance","status":"publish","type":"post","link":"https:\/\/tsisupport.com\/tsistaging\/?p=7532","title":{"rendered":"How to Maintain NIST 800-171 &#038; DFARS Compliance as a Contractor With CUI"},"content":{"rendered":"<p>With the recent news that DFARS compliance requirements will start being enforced, we\u2019ve seen a significant increase of questions concerning the role and application of \u2018Government\u2019 licensing- such as Office 365 Government or AWS GovCloud- for contractors possessing Controlled Unclassified Information (CUI). Aside from adhering to DFARS compliance itself, Government licensing- notably for Office 365 Government- is extremely expensive from both a subscription and implementation standpoint, and in turn, an area of concern for many contractor organizations. However, we\u2019ve recently learned from Vicki Michetti- Director of the DoD\u2019s Defense Industrial Base (DIB) Cybersecurity (CS) program- that CUI contractors don\u2019t necessarily need these types of government licenses to comply with DFARS security controls because products like Office 365 Government and AWS GovCloud that have ATOs at the FedRAMP Moderate level. However, although CUI contractors can use these solutions, there are still factors to consider when evaluating these government level subscriptions and how they\u2019ll potentially impact your compliance posture.<\/p>\n<p><span style=\"color: #800000;\"><strong>The DFARS\/FedRAMP Security Requirements<\/strong><\/span><\/p>\n<p>Clause 252.204-7012 provides a degree of clarification regarding these security measures- including the required capabilities of the solution controls themselves- needed by contractors to adequately protect the DoD\u2019s CUI. The requirements outlined throughout paragraphs c through g of 252.204-7012 clarify that government edition subscription licensing- for any and all cloud service providers (CSPs)- isn\u2019t necessarily required if the non-government level software license is FedRAMP Moderate- such as the case with Office 365 Government and AWS GovCloud- and meets the outlined DFARS control and compliance requirements. So as long as your CSP\u2019s solution can provide the degree of incident reporting and forensic analysis required to meet these standards, it will be considered as an acceptable solution with the authorization to operate.<\/p>\n<p>As outlined within Section (c) (<em>Cyber Risk Reporting Requirement<\/em>), contractors must report- per the instructions from the DoD cyber incident reporting webpage http:\/\/dibnet.dod.mil &#8211; security incidents that affect an information system subject to DFARS and\/or those that impact a contractors\u2019 ability to meet the requirements specified within their contract. They must review the evidence that CUI was compromised, as well as disclose the compromised systems and the data and user accounts as well. This review must also include an analysis of any other information systems that may contain compromised information associated with the incident.<\/p>\n<p>Under Section (d) (<em>Malicious Software<\/em>), contractors must also submit any malicious software they discover and isolate during their investigation to the DoD Cyber Crime Center (DC3) in accordance with the instructions provided by DC3 or the Contracting Officer. Contractors must also preserve images of the information systems known to be infected in addition to all relevant data related to the monitoring and capture of malicious software. The contractor or subcontractor must also possess or acquire a DoD-approved medium assurance certificate to complete the report. For a more complete description of the process and attaining these certificates, simply refer to DoD\u2019 Cyber Exchange resource site for more specific insights;<\/p>\n<p>In addition to this, Section (e) <em>(Media Preservation and Protection) <\/em>contractors must also store the information pertaining to their cyber incident for at least 90 days after submitting the incident report to provide the DoD an opportunity to request the media. If the DoD does express interest in investigating a security incident further &#8211; Section (f) (<em>Access to Additional Information or Equipment Necessary for Forensic Analysis<\/em>)- the contractor must provide the DoD with the additional information or equipment needed to conduct a forensic analysis of the incident. If the investigation requires additional data or documentation, the contracting officer can also request the contractor to provide all the information on damage assessment that the contractor gathered during its investigation, according to Section (g) (Cyber Incident Damage Assessment Activities).<\/p>\n<p>For a more complete description of the requirements outlined within sections c through g, refer to Clause 252.204-7012 for the compliance requirements themselves as well as the chart below;<\/p>\n<p><a href=\"https:\/\/www.acq.osd.mil\/dpap\/dars\/dfars\/html\/current\/252204.htm#252.204-7012\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/www.acq.osd.mil\/dpap\/dars\/dfars\/html\/current\/252204.htm#252.204-7012<\/a><\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-8815\" src=\"https:\/\/tsisupport.com\/tsistaging\/wp-content\/uploads\/2019\/12\/DFARS-DoD.jpg\" alt=\"\" width=\"363\" height=\"273\" srcset=\"https:\/\/tsisupport.com\/tsistaging\/wp-content\/uploads\/2019\/12\/DFARS-DoD.jpg 363w, https:\/\/tsisupport.com\/tsistaging\/wp-content\/uploads\/2019\/12\/DFARS-DoD-300x226.jpg 300w\" sizes=\"(max-width: 363px) 100vw, 363px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"color: #800000;\"><strong>How Does This Impact your own Subs, Vendors, Partners and Non-Citizen Employees? <\/strong><\/span><\/p>\n<p>Essentially, contractors and all their sub-contractors, must have the DFARS compliance controls- and the considerations outlined within 252.204-7012- in place if they\u2019re managing CUI in any capacity. However, there are exceptions for Commercial-off-the-shelf (COTS) distributors where DFARS compliance may not necessarily be required, as long as their CUI isn\u2019t incorporated into the final product deliverable. However, it\u2019s important to note, that many of these organizations- despite not needing to adhere to these requirements- are doing so, due to their prime\u2019s own compliance requirements and\/or preference. Simply put, any contractors who are functioning as distributors by incorporating CUI into modified COTS technology must comply with DFARS requirements. Contractors who merely use unmodified COTS products don\u2019t need to be compliant, although DFARS compliance may be advantageous from a marketing or best practices standpoint- especially if their vendors or primes require or prefer that they do so. At the end of the day, DFARS compliance holds contractors accountable to adequately verify the compliance posture of their subcontractors- commonly known as &#8220;flow-down&#8221;- to ensure they comply with DFARS and Clause 252.204-7012 clauses. This requirement creates a trickle-down effect starting from the DoD, down to the subs of their prime contractors. Moving forward, if an organization\u2019s subcontractors are out of compliance, they will be held accountable and can be penalized by losing their contract or in more serious cases, subject to legal ramifications such as fraud.<\/p>\n<p>Another frequent question we receive pertains to a contractor\u2019s non-citizen employees with access to CUI. It\u2019s important to keep in mind that although non-citizens employed by contractors working with CUI do not conflict with your DFARS compliance posture, the prime contractors are free to make this a requirement within their contracts if they require specific citizenship or residency requirements, which could be outlined within section H of the contract itself.<\/p>\n<p>In the event that an organization must adhere to International Traffic in Arms Regulations (ITAR) or Export Administration Regulations (EAR) standards that control the export of defense and military related technologies, then this data can only be shared with US persons- as defined within the regulation-, citizens and in many cases includes US corporations to determine a contractor\u2019s \u2018citizenship\u2019 and eligibility requirements.<\/p>\n<p><span style=\"color: #800000;\"><strong>So, When Do You Actually Need Government Software Subscription Licensing?<\/strong><\/span><\/p>\n<p>Clause 252.204-7012 (b)(ii)(D) explains in further detail why Government level licensing isn\u2019t always required for contractors managing CUI but how it may be a requirement in instances when manage classified information and CUI that is owned and operated by federal agencies.<\/p>\n<p><em>\u201c(D)\u00a0 If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline and that the cloud service provider complies with requirements in paragraphs (c) through (g) of this clause for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.\u201d<\/em><\/p>\n<p>Unfortunately, we\u2019ve encountered a number of cases where IT leadership and\/or vendors mistakenly recommend these products to contractors managing CUI. Be aware that the most obvious reason to maintain this position- aside from simply misinterpreting these requirements- is that IT vendors stand to make a lot of money from Office 365 Government subscription sales and its very costly implementation due to not having a migration path. What does it mean to not have a migration path? Unlike a traditional migration to Office 365 where network settings, configurations and processes are simply transferred to the Office 365 cloud, migrating to Office365 Government will require you to rebuild your infrastructure from scratch which will amount to additional costs not including the implementation of the IT solutions addressing the DFARS controls.<\/p>\n<p><span style=\"color: #800000;\"><strong>Looking to the Future; The Importance of Strategic Partnerships<\/strong><\/span><\/p>\n<p>As these IT compliance requirements continue to evolve and with actual enforcement arriving in the near future, the role of IT professionals has expanded beyond the server room. In order to stay ahead of the curve, developing strategic partnerships with the government officials spearheading these DFARS initiatives will have to become an ongoing practice to ensure the successful strategic alignment between your IT compliance strategy and business objectives. Because both compliance requirements and business technologies are always changing, we encourage contractors to partner with service organizations that not only have in-house, IT compliance expertise but have a proactive, forward thinking, service model to accommodate today\u2019s fast changing IT compliance and regulatory landscapes. States like California, Maine and New York have recently led the way toward implementing both commercial and consumer IT protection requirements, and MA based small businesses will only find it increasingly challenging to comply with new regulations once they inevitably become a reality. Today\u2019s SME requires an IT partner that can forecast evolving IT compliance trends and their associated requirements, to ensure their successful continuity into the future and maintain industry competitiveness.<\/p>\n<p>Keeping in mind these increasingly complex compliance requirements, we highly encourage that you routinely assess these factors and actively collaborate with your IT and compliance partners to verify your posture as well as accurately measure your risks.<\/p>\n<p><em>\u201cIf you fail to plan, you are planning to fail.\u201d \u2013<\/em> Benjamin Franklin<\/p>\n<p><span style=\"color: #800000;\"><strong>Final Thoughts<\/strong><\/span><\/p>\n<p>In short, Government level licensing isn\u2019t required for CUI contractors unless specified in the contract or if the data the contractor has is classified or when a federal agency needs to store their own CUI or classified information with the CSP. This, alongside our other shared insights, are meant to help navigate these perceptibly convoluted requirements to help you more effectively address the IT security and compliance gaps within your strategy. If the stringent IT compliance requirements in states like California, Maine and New York are of any indication as to what may be coming to Massachusetts, this degree of collaboration will be needed to succeed within any industry and not just those that are DFARS required. Your security and compliance posture will become even more relevant as to how you\u2019re able to conduct day to day business and will affect how your vendors will engage you- or your competitors- in their vendor selection processes.<\/p>\n<p><em>Chris Souza is the CEO of Technical Support International (TSI), a New England-based IT support and cybersecurity compliance firm. He can be reached at: https:\/\/tsisupport.com\/tsistaging.<\/em><\/p>\n<div class=\"fl-builder-content fl-builder-content-8812 fl-builder-template fl-builder-row-template fl-builder-global-templates-locked\" data-post-id=\"8812\"><div class=\"fl-row fl-row-full-width fl-row-bg-color fl-node-5ecf58ce1fb07 fl-row-default-height fl-row-align-center BlogCTA\" data-node=\"5ecf58ce1fb07\">\n\t<div class=\"fl-row-content-wrap\">\n\t\t\t\t\t\t\t\t<div class=\"fl-row-content fl-row-fixed-width fl-node-content\">\n\t\t\n<div class=\"fl-col-group fl-node-5ecf58ce20b7b fl-col-group-equal-height fl-col-group-align-center fl-col-group-custom-width fl-col-group-responsive-reversed\" data-node=\"5ecf58ce20b7b\">\n\t\t\t<div class=\"fl-col fl-node-5ecf58ce21071 fl-col-bg-color fl-col-small-custom-width\" data-node=\"5ecf58ce21071\">\n\t<div class=\"fl-col-content fl-node-content\"><div class=\"fl-module fl-module-heading fl-node-5ecf59850c299\" data-node=\"5ecf59850c299\">\n\t<div class=\"fl-module-content fl-node-content\">\n\t\t<h2 class=\"fl-heading\">\n\t\t<span class=\"fl-heading-text\">It\u2019s Your Move!<\/span>\n\t<\/h2>\n\t<\/div>\n<\/div>\n<div class=\"fl-module fl-module-rich-text fl-node-5ecf59a4097b0\" data-node=\"5ecf59a4097b0\">\n\t<div class=\"fl-module-content fl-node-content\">\n\t\t<div class=\"fl-rich-text\">\n\t<p>At TSI we understand how important DFARS compliance is. If you're looking for a partner who has a proactive, forward thinking service model to accommodate today\u2019s fast changing IT compliance and regulatory landscapes, contact one of my colleagues at Technical Support International to schedule your introductory phone call.<\/p>\n<\/div>\n\t<\/div>\n<\/div>\n<div class=\"fl-module fl-module-button fl-node-5ecf599525d88 primary-btn\" data-node=\"5ecf599525d88\">\n\t<div class=\"fl-module-content fl-node-content\">\n\t\t<div class=\"fl-button-wrap fl-button-width-auto fl-button-left\">\n\t\t\t<a href=\"https:\/\/tsisupport.com\/tsistaging\/contact\/\"  target=\"_self\"  class=\"fl-button\" >\n\t\t\t\t\t\t\t<span class=\"fl-button-text\">Get in touch with tsi<\/span>\n\t\t\t\t\t<\/a>\n<\/div>\n\t<\/div>\n<\/div>\n<\/div>\n<\/div>\n\t\t\t<div class=\"fl-col fl-node-5ecf591e27959 fl-col-bg-color fl-col-small fl-col-small-custom-width\" data-node=\"5ecf591e27959\">\n\t<div class=\"fl-col-content fl-node-content\"><div class=\"fl-module fl-module-photo fl-node-5ecf595d82525\" data-node=\"5ecf595d82525\">\n\t<div class=\"fl-module-content fl-node-content\">\n\t\t<div role=\"figure\" class=\"fl-photo fl-photo-align-right\" itemscope itemtype=\"https:\/\/schema.org\/ImageObject\">\n\t<div class=\"fl-photo-content fl-photo-img-png\">\n\t\t\t\t<img loading=\"lazy\" decoding=\"async\" class=\"fl-photo-img wp-image-819 size-full\" src=\"https:\/\/tsisupport.com\/tsistaging\/wp-content\/uploads\/2020\/05\/blog-cta-building-upon-company-culture-remotely-img.png\" alt=\"blog-cta-building-upon-company-culture-remotely-img\" height=\"166\" width=\"206\" title=\"blog-cta-building-upon-company-culture-remotely-img\"  itemprop=\"image\" \/>\n\t\t\t\t\t<\/div>\n\t<\/div>\n\t<\/div>\n<\/div>\n<\/div>\n<\/div>\n\t<\/div>\n\t\t<\/div>\n\t<\/div>\n<\/div>\n<\/div><div class=\"uabb-js-breakpoint\" style=\"display: none;\"><\/div>\n","protected":false},"excerpt":{"rendered":"<p>With the recent news that DFARS compliance requirements will start being enforced, we\u2019ve seen a significant increase of questions concerning the role and application of \u2018Government\u2019 licensing- such as Office 365 Government or AWS GovCloud- for contractors possessing Controlled Unclassified Information (CUI). Aside from adhering to DFARS compliance itself, Government licensing- notably for Office 365&hellip;<\/p>\n","protected":false},"author":4,"featured_media":8814,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_links_to":"","_links_to_target":""},"categories":[7],"tags":[],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>How to Maintain DFARS Compliance as a Contractor With CUI | TSI<\/title>\n<meta name=\"description\" content=\"Read this post to learn whether contractors with CUI (Controlled Unclassified Information) need government software licensing to be DFARS compliant.\" \/>\n<meta name=\"robots\" content=\"noindex, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How to Maintain DFARS Compliance as a Contractor With CUI | TSI\" \/>\n<meta property=\"og:description\" content=\"Read this post to learn whether contractors with CUI (Controlled Unclassified Information) need government software licensing to be DFARS compliant.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/tsisupport.com\/tsistaging\/?p=7532\" \/>\n<meta property=\"og:site_name\" content=\"TSI Support\" \/>\n<meta property=\"article:published_time\" content=\"2019-12-11T07:33:27+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-07-07T08:46:26+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/tsisupport.com\/tsistaging\/wp-content\/uploads\/2019\/12\/DFARS-Compliance.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1140\" \/>\n\t<meta property=\"og:image:height\" content=\"380\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Chris Souza\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Chris Souza\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/tsisupport.com\/tsistaging\/?p=7532\",\"url\":\"https:\/\/tsisupport.com\/tsistaging\/?p=7532\",\"name\":\"How to Maintain DFARS Compliance as a Contractor With CUI | TSI\",\"isPartOf\":{\"@id\":\"https:\/\/tsisupport.com\/tsistaging\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/tsisupport.com\/tsistaging\/?p=7532#primaryimage\"},\"image\":{\"@id\":\"https:\/\/tsisupport.com\/tsistaging\/?p=7532#primaryimage\"},\"thumbnailUrl\":\"https:\/\/tsisupport.com\/tsistaging\/wp-content\/uploads\/2019\/12\/DFARS-Compliance.jpg\",\"datePublished\":\"2019-12-11T07:33:27+00:00\",\"dateModified\":\"2021-07-07T08:46:26+00:00\",\"author\":{\"@id\":\"https:\/\/tsisupport.com\/tsistaging\/#\/schema\/person\/91ba4bc98e1a6b903424252af609a9ed\"},\"description\":\"Read this post to learn whether contractors with CUI (Controlled Unclassified Information) need government software licensing to be DFARS compliant.\",\"breadcrumb\":{\"@id\":\"https:\/\/tsisupport.com\/tsistaging\/?p=7532#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/tsisupport.com\/tsistaging\/?p=7532\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/tsisupport.com\/tsistaging\/?p=7532#primaryimage\",\"url\":\"https:\/\/tsisupport.com\/tsistaging\/wp-content\/uploads\/2019\/12\/DFARS-Compliance.jpg\",\"contentUrl\":\"https:\/\/tsisupport.com\/tsistaging\/wp-content\/uploads\/2019\/12\/DFARS-Compliance.jpg\",\"width\":1140,\"height\":380},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/tsisupport.com\/tsistaging\/?p=7532#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/tsisupport.com\/tsistaging\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How to Maintain NIST 800-171 &#038; DFARS Compliance as a Contractor With CUI\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/tsisupport.com\/tsistaging\/#website\",\"url\":\"https:\/\/tsisupport.com\/tsistaging\/\",\"name\":\"TSI Support\",\"description\":\"TSI - Technical Support International\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/tsisupport.com\/tsistaging\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/tsisupport.com\/tsistaging\/#\/schema\/person\/91ba4bc98e1a6b903424252af609a9ed\",\"name\":\"Chris Souza\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/tsisupport.com\/tsistaging\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/d9e77a32df062fd4d46c61b29b00f1be?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/d9e77a32df062fd4d46c61b29b00f1be?s=96&d=mm&r=g\",\"caption\":\"Chris Souza\"},\"url\":\"https:\/\/tsisupport.com\/tsistaging\/?author=4\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How to Maintain DFARS Compliance as a Contractor With CUI | TSI","description":"Read this post to learn whether contractors with CUI (Controlled Unclassified Information) need government software licensing to be DFARS compliant.","robots":{"index":"noindex","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"en_US","og_type":"article","og_title":"How to Maintain DFARS Compliance as a Contractor With CUI | TSI","og_description":"Read this post to learn whether contractors with CUI (Controlled Unclassified Information) need government software licensing to be DFARS compliant.","og_url":"https:\/\/tsisupport.com\/tsistaging\/?p=7532","og_site_name":"TSI Support","article_published_time":"2019-12-11T07:33:27+00:00","article_modified_time":"2021-07-07T08:46:26+00:00","og_image":[{"width":1140,"height":380,"url":"https:\/\/tsisupport.com\/tsistaging\/wp-content\/uploads\/2019\/12\/DFARS-Compliance.jpg","type":"image\/jpeg"}],"author":"Chris Souza","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Chris Souza","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/tsisupport.com\/tsistaging\/?p=7532","url":"https:\/\/tsisupport.com\/tsistaging\/?p=7532","name":"How to Maintain DFARS Compliance as a Contractor With CUI | TSI","isPartOf":{"@id":"https:\/\/tsisupport.com\/tsistaging\/#website"},"primaryImageOfPage":{"@id":"https:\/\/tsisupport.com\/tsistaging\/?p=7532#primaryimage"},"image":{"@id":"https:\/\/tsisupport.com\/tsistaging\/?p=7532#primaryimage"},"thumbnailUrl":"https:\/\/tsisupport.com\/tsistaging\/wp-content\/uploads\/2019\/12\/DFARS-Compliance.jpg","datePublished":"2019-12-11T07:33:27+00:00","dateModified":"2021-07-07T08:46:26+00:00","author":{"@id":"https:\/\/tsisupport.com\/tsistaging\/#\/schema\/person\/91ba4bc98e1a6b903424252af609a9ed"},"description":"Read this post to learn whether contractors with CUI (Controlled Unclassified Information) need government software licensing to be DFARS compliant.","breadcrumb":{"@id":"https:\/\/tsisupport.com\/tsistaging\/?p=7532#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/tsisupport.com\/tsistaging\/?p=7532"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/tsisupport.com\/tsistaging\/?p=7532#primaryimage","url":"https:\/\/tsisupport.com\/tsistaging\/wp-content\/uploads\/2019\/12\/DFARS-Compliance.jpg","contentUrl":"https:\/\/tsisupport.com\/tsistaging\/wp-content\/uploads\/2019\/12\/DFARS-Compliance.jpg","width":1140,"height":380},{"@type":"BreadcrumbList","@id":"https:\/\/tsisupport.com\/tsistaging\/?p=7532#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/tsisupport.com\/tsistaging\/"},{"@type":"ListItem","position":2,"name":"How to Maintain NIST 800-171 &#038; DFARS Compliance as a Contractor With CUI"}]},{"@type":"WebSite","@id":"https:\/\/tsisupport.com\/tsistaging\/#website","url":"https:\/\/tsisupport.com\/tsistaging\/","name":"TSI Support","description":"TSI - Technical Support International","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/tsisupport.com\/tsistaging\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/tsisupport.com\/tsistaging\/#\/schema\/person\/91ba4bc98e1a6b903424252af609a9ed","name":"Chris Souza","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/tsisupport.com\/tsistaging\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/d9e77a32df062fd4d46c61b29b00f1be?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d9e77a32df062fd4d46c61b29b00f1be?s=96&d=mm&r=g","caption":"Chris Souza"},"url":"https:\/\/tsisupport.com\/tsistaging\/?author=4"}]}},"_links":{"self":[{"href":"https:\/\/tsisupport.com\/tsistaging\/index.php?rest_route=\/wp\/v2\/posts\/7532"}],"collection":[{"href":"https:\/\/tsisupport.com\/tsistaging\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/tsisupport.com\/tsistaging\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/tsisupport.com\/tsistaging\/index.php?rest_route=\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/tsisupport.com\/tsistaging\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=7532"}],"version-history":[{"count":0,"href":"https:\/\/tsisupport.com\/tsistaging\/index.php?rest_route=\/wp\/v2\/posts\/7532\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/tsisupport.com\/tsistaging\/index.php?rest_route=\/wp\/v2\/media\/8814"}],"wp:attachment":[{"href":"https:\/\/tsisupport.com\/tsistaging\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=7532"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/tsisupport.com\/tsistaging\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=7532"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/tsisupport.com\/tsistaging\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=7532"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}