FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems
This clause is applicable to all solicitations and contracts when a contractor or subcontractor at any tier may have federal contract information residing in or transiting through its information systems, including commercial items other than commercially available off-the-shelf items (COTS).
Synopsis:
- Requires basic safeguarding requirements and procedures to protect covered contractor information systems
- Imposes 15 categories of security controls focused on safeguarding contractor systems that process, store or transmit Federal contract information
- Although not specifically stated, contractors in compliance with the more expansive NIST SP 800-171 security controls will presumably be in compliance with the FAR requirements
- Applicable to all solicitations and contracts when a contractor or subcontract at any tier may have federal contract information residing in or transiting through its information systems. Does not apply to contracts or subcontracts for COTS.