Example: biology

September 6, 2017 Northrop Grumman …

September 6, 2017 . Northrop Grumman corporation 2980 fairview Park Drive Falls Church, VA 2204. Northrop Grumman Supplier, This correspondence provides information regarding the EXOSTAR platform supplier on- boarding, answers frequently asked supplier questions and emphasizes Northrop Grumman 's expectations that its suppliers have already implemented, at a minimum, the 17 Basic Safeguarding NIST SP 800-171 security controls contained in FAR The chart at the end of this document identifies which NIST 800-171 controls align to these basic controls. EXOSTAR On-Boarding Process: Below is a description of EXOSTAR-related process steps and the required actions for suppliers. 1. Supplier receives launch letter from EXOSTAR June 30, 2017 . a. Email contained educational information regarding the requirements b.

September 6, 2017 Northrop Grumman Corporation 2980 Fairview Park Drive Falls Church, VA 2204 Northrop Grumman Supplier, This correspondence provides information regarding the EXOSTAR platform supplier on-

Tags:

  2017, Corporation, Northrop, Northrop grumman, Grumman, 2890, 2017 northrop grumman, 2017 northrop grumman corporation 2980 fairview, Fairview

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of September 6, 2017 Northrop Grumman …

1 September 6, 2017 . Northrop Grumman corporation 2980 fairview Park Drive Falls Church, VA 2204. Northrop Grumman Supplier, This correspondence provides information regarding the EXOSTAR platform supplier on- boarding, answers frequently asked supplier questions and emphasizes Northrop Grumman 's expectations that its suppliers have already implemented, at a minimum, the 17 Basic Safeguarding NIST SP 800-171 security controls contained in FAR The chart at the end of this document identifies which NIST 800-171 controls align to these basic controls. EXOSTAR On-Boarding Process: Below is a description of EXOSTAR-related process steps and the required actions for suppliers. 1. Supplier receives launch letter from EXOSTAR June 30, 2017 . a. Email contained educational information regarding the requirements b.

2 Provided advance notification to enable suppliers to begin preparing for the assessment 2. EXOSTAR sent login information to their Managed Access Gateway (MAG) via email (NOTE: 30 days for submission starts upon receipt of this email.). a. At this point, suppliers should initiate first-time log in with credentials provided by EXOSTAR. b. Group 1: Issued June 30, 2017 . c. Group 2: Issued July 18, 2017 . d. Group 3: To be issued the beginning of September , 2017 . 3. Once logged in, suppliers must use a 2-factor authentication to gain access to EXOSTAR. Partner Information Manager (PIM) in order to complete their assessment. If the supplier has an existing token they can use that token; otherwise, a token must be purchased. a. Application usage terms and conditions will also need to be accepted before gaining access 4.

3 After gaining access to PIM, supplier will begin completing the questionnaire / self- assessment of the NIST SP 800-171 controls. 5. Supplier must also accept the pending sharing request to allow Northrop Grumman access to supplier's results Common Issues and Questions: If a supplier has not yet received EXOSTAR credentials, the supplier is more than likely in a future supplier grouping and will receive the email with login credentials no later than mid- September . What if a supplier chooses to opt out of the questionnaire? o Suppliers that elect not to complete the self-assessment may not be eligible for future subcontract awards from Northrop Grumman where there is Federal Contract Information (FCI), Covered Defense Information (CDI) or NG and/ or Customer proprietary information. An accepted status does not mean the questionnaire has been completed.

4 GUIDE to EXOSTAR process: Supplier should first and foremost reference this guide: UPDATE SUPPLIER CONTACT INFO: If supplier needs to update the contact they have with EXOSTAR: o Contact o SUBJECT of Email: Updated Supplier Contract Information. EXOSTAR system issues: o o Or call 703-793-7800. Supplier asserts NIST SP 800-171 controls are not applicable o Send email indicating the reason(s) to SUBJECT of Email: Non-Applicability of NIST SP 800-171. Supplier has additional systems to assess (More than one that is used on Northrop Grumman programs.). If a supplier needs to submit a second or additional, separate NIST form an additional Exostar account will be needed for the applicable system(s). Please use the following steps to request each additional account and submit to EXOSTAR: 1. Decide on a naming convention for the second account that will allow Northrop Grumman to distinguish between the two: a.

5 Examples: Acme LLC Atlanta, Acme LLC Chicago 2. Fill out the information below for the new organization as per the instructions: a. Organization Name (see #1 above). b. Organization Address (can be the same as the main network/headquarters address, or unique to this particular system/network). i. Street ii. City iii. State iv. Postal code v. Country c. Contact Information (the person who has detailed knowledge of the system/network). i. First Name ii. Last Name iii. Email Address iv. Phone Number 3. Submit the data to Exostar at using the following information: a. Related Buyer/Partner = Northrop Grumman b. Product = Managed Access Gateway (MAG). c. Issue = Create New Supplier Org d. Attach the information from #2 above to the case in a Word or Excel document Once the request is received by EXOSTAR, an email invitation will be sent to the above contact to complete registration for the new account, access Partner Information Manager (PIM) and fill out the NIST form.

6 Basic Safeguarding Controls The FAR Basic Safeguarding clause has been a mandatory flow down clause in new FAR-based solicitations and prime contracts (for other than commercial-off-the-shelf products) issued since June 15, 2016. It requires the implementation of the 17 specified basic security controls on any internal systems with federal contract information (FCI) upon award of the subcontract. Federal Contract Information is broadly defined to include information, not intended for public release, that is provided or generated for the Government under a contract to develop or deliver a product or service to the Government, but not including information provided by the Government to the public (such as on public Web sites) or simple transactional information, as necessary to process payments.

7 Northrop Grumman expects its suppliers to comply with these basic cybersecurity controls identified in the FAR. Suppliers that have not yet implemented the 17 basic safeguarding controls may not be in a position to accept any future subcontract awards and may be out of compliance with their current contractual obligations. The below chart identifies which NIST 800-171 controls align to the FAR basic safeguarding controls that Northrop Grumman expects all suppliers with FCI, CDI or proprietary information provided by Northrop Grumman to have implemented immediately! FAR CONTROLS TRACEABILITY TO NIST 800-171 CONTROLS. FAR MINIMUM CONTROLS NIST 800-171 CONTROL. (i) Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).

8 (ii) Limit information system access to the types of transactions and functions that authorized users are permitted to execute. (iii) Verify and control/limit connections to and use of external information systems. (iv) Control information posted or processed on publicly accessible information systems. (v) Identify information system users, processes acting on behalf of users, or devices. (vi) Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems. (vii) Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse. (viii) Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.

9 (ix) Escort visitors and monitor visitor activity; maintain , , audit logs of physical access; and control and manage physical access devices. (x) Monitor, control, and protect organizational communications ( , information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems. (xi) Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks. (xii) Identify, report, and correct information and information system flaws in a timely manner. (xiii) Provide protection from malicious code at appropriate locations within organizational information systems. (xiv) Update malicious code protection mechanisms when new releases are available. (xv) Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.

10 SPECIAL NOTE: To the extent your company performs work under DoD subcontracts with DFARS , don't forget the December 31, 2017 deadline to implement NIST 800-171 by, at a minimum, also having a system security plan ( ) and plan of action and milestones ( ) for any controls not yet implemented.


Related search queries