Cybersecurity Requirements and Frameworks

Common Cybersecurity Requirements and Frameworks

Controlled Unclassified Information is information that requires safeguarding or dissemination controls under federal law, regulation, or government-wide policy but is not classified information. CUI obligations usually appear in federal contracts, subcontracts, sponsor instructions, data use agreements, marked documents, or government-provided materials.

CUI is not the same as all sensitive data. Sensitive research data may still require protection, but CUI is a specific federal designation or contractual requirement.

Researchers should request a cybersecurity review if a project references CUI, controlled technical information, covered defense information, export-controlled information, or any restriction on how federal data may be accessed, stored, transmitted, or shared.

Additional resources:

  • SDSU CUI Policy (PDF)
  • NARA Controlled Unclassified Information Program
  • CUI Registry: Categories and Subcategories
  • 32 CFR Part 2002: Controlled Unclassified Information

Cybersecurity Maturity Model Certification (CMMC) is the U.S. Department of Defense cybersecurity program for contractors and subcontractors that handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). CMMC requirements are determined by the terms of DoD solicitations, contracts, or subcontracts.

It uses a tiered model with progressively advanced controls and assessment requirements, the level of which is determined by the contract. There are three levels in CMMC 2.0:

DFARS is the Defense Federal Acquisition Regulation Supplement. DFARS is the contract mechanism. CMMC is the verification program. NIST 800-171 is usually the control set for protecting CUI.

DFARS cybersecurity requirements are most relevant to research proposals, DoD contracts, and subawards.

DFARS 252.204-7012 — Safeguarding Covered Defense Information and Cyber Incident Reporting

Applies when the contract or subcontract requires protection of Covered Defense Information, which commonly includes DoD Controlled Unclassified Information (CUI).

Requires contractors to apply the security requirements in NIST SP 800-171 when CUI resides in or transits through contractor systems.

DFARS 252.204-7008 — Compliance with Safeguarding Covered Defense Information Controls

Requires the offeror to represent that it will implement the applicable safeguarding requirements for covered defense information.

Points back to the definitions and safeguarding framework in DFARS 252.204-7012.

DFARS 252.204-7019 — Notice of NIST SP 800-171 DoD Assessment Requirements

Usually appears in solicitations when NIST 800-171 may apply.

Puts the offeror on notice that DoD may require a current NIST 800-171 assessment before award.

DFARS 252.204-7020 — NIST SP 800-171 DoD Assessment Requirements

Applies to covered contractor information systems that must comply with NIST SP 800-171 under DFARS 252.204-7012.

Requires the contractor to have a current DoD NIST 800-171 assessment, often recorded in the Supplier Performance Risk System (SPRS).

Requires flow-down to subcontractors when applicable.

DFARS 252.204-7021 — Contractor Compliance with CMMC Level Requirements

The CMMC contract clause.

Requires the contractor to maintain the CMMC level required by the contract for the relevant systems.

CMMC is DoD’s method for validating that required cybersecurity controls are implemented.

CMMC Level 1 maps to FAR 52.204-21 for Federal Contract Information; Level 2 maps to NIST SP 800-171 for CUI; Level 3 adds selected NIST SP 800-172 enhanced requirements.

CMMC flow-down to subcontractors

CMMC requirements can apply to prime contractors and subcontractors at all tiers if they process, store, or transmit FCI or CUI on contractor information systems for the DoD contract or subcontract.

If CMMC, DFARS 252.204-7012, DFARS 252.204-7019, DFARS 252.204-7020, DFARS 252.204-7021, Covered Defense Information, Federal Contract Information (FCI), or related cybersecurity language appears in a solicitation, contract, or subcontract, contact Sponsored Research Administration and the Information Security Office before proposal submission or award acceptance. DFARS 252.204-7012 addresses safeguarding covered defense information and cyber incident reporting.

Researchers, departments, and project teams should not represent that SDSU is CMMC-ready, CMMC-certified, NIST SP 800-171-compliant, or eligible to process defense-related controlled data without prior institutional review.

Additional resources:

  • DoD CMMC Resources and Documentation
  • DFARS 252.204-7012: Safeguarding Covered Defense Information and Cyber Incident Reporting
  • DFARS 252.204-7020: NIST SP 800-171 DoD Assessment Requirements

The Federal Acquisition Regulation (FAR) is the principal set of rules governing government procurement in the United States and covers many of the contracts issued by the US military, NASA, and US civilian federal agencies. It contains standard provisions and contract clauses that may apply to federal research contracts that contain Federal Contract Information (FCI).

FAR 52.204-21 – Basic Safeguarding of Covered Contractor Information Systems includes 15 controls.

Research involving identifiable health information, electronic protected health information, health-system data, or HIPAA-regulated datasets may require coordination among the IRB, Privacy, Legal/Contracts, Sponsored Research Administration, and Information Security before data are accessed, stored, analyzed, or shared.

HIPAA’s Security Rule applies to electronic protected health information held or maintained by regulated entities and requires administrative, physical, and technical safeguards. NIST SP 800-66 provides implementation guidance for safeguarding ePHI under the HIPAA Security Rule.

Researchers should request a cybersecurity review if a project involves ePHI, health-system data, a HIPAA data use agreement, a business associate agreement, health data security terms, or sponsor-required safeguards for identifiable health information.

Additional resources:

  • SDSU HIPAA / ePHI Research Guidance [ADD SDSU LINK]
  • HHS Summary of the HIPAA Security Rule
  • NIST SP 800-66 Revision 2: Implementing the HIPAA Security Rule

NIH controlled-access data, including data from dbGaP and other NIH Controlled-Access Data Repositories, may require use of an approved environment that aligns with NIH security expectations and NIST SP 800-171. Researchers should request a cybersecurity review before submitting, renewing, or modifying a controlled-access data request.

Researchers should not download NIH controlled-access data to personal devices, lab-managed systems, unapproved cloud storage, or collaborator-managed platforms unless those environments have been reviewed and approved for the applicable requirements.

Additional resources:

NIST SP 800-53 is a comprehensive catalog of security and privacy controls used by federal agencies and many organizations to manage cybersecurity and privacy risk. Researchers may encounter NIST SP 800-53 when a sponsor requires FISMA-like controls, federal system authorization, agency security review, or use of a FedRAMP-authorized cloud service.

FedRAMP is a federal program that provides a standardized approach to security assessment and authorization for cloud products and services used by federal agencies. A sponsor, contract, or data provider may require use of a FedRAMP-authorized service for certain types of federal data or cloud workflows.

Researchers should request a cybersecurity review if project documents mention NIST SP 800-53, FISMA, FedRAMP, Authority to Operate (ATO), FIPS, or federal cloud security requirements.

Additional resources:

  • NIST SP 800-53 Revision 5: Security and Privacy Controls for Information Systems and Organizations
  • NIST Risk Management Framework / FISMA Background
  • FedRAMP Program
  • GSA FedRAMP Overview

NIST SP 800-171 is a federal cybersecurity standard commonly used to protect Controlled Unclassified Information (CUI) and certain federally regulated research data in nonfederal systems. It may be required by federal contracts, subcontracts, data use agreements, sponsor terms, or NIH controlled-access data requirements. The applicable version and assessment expectations depend on the sponsor, contract, DUA, or data access agreement.

For researchers, this usually means regulated data must be handled only in an approved computing environment with appropriate access controls, multifactor authentication, logging, encryption, incident reporting, and documented security practices.

Researchers should request a cybersecurity review before accepting, downloading, storing, processing, or sharing data that may require NIST SP 800-171 protections.

Additional resources:

Third-Party Platforms, Cloud Services, and Collaborator Systems

Some research workflows rely on third-party cloud platforms, vendor tools, collaborator-managed systems, lab servers, external file-sharing services, or specialized analysis environments. These systems may require cybersecurity, privacy, procurement, legal, vendor risk, or contract review before regulated data can be used.

Third-Party Platforms, Cloud Services, and Collaborator Systems

Some research workflows rely on third-party cloud platforms, vendor tools, collaborator-managed systems, lab servers, external file-sharing services, or specialized analysis environments. These systems may require cybersecurity, privacy, procurement, legal, vendor risk, or contract review before regulated data can be used. Researchers should request a cybersecurity review before using a non-SDSU or non-approved system for regulated, restricted, confidential, or sponsor-controlled research data. Examples include:

  • Commercial cloud environments;
  • External collaborator storage or computing platforms;
  • Vendor-hosted research tools;
  • Lab-managed servers;
  • Personal devices;
  • Non-SDSU file sharing tools;
  • Artificial intelligence, machine learning, or analytics platforms using regulated research data.