Uncle Sam wants full access to its suppliers IT systems — and unsurprisingly, they are not happy

us flag hero image
(Image credit: Bryn Colton/ Getty Images)

The rules applied to US government IT contractors and suppliers as part of the Federal Acquisition Regulation (FAR) are under review due to the increasing numbers of new and existing threats.

Under the drafted changes proposed to FAR, contractors would have to disclose detected incidents within eight hours to the Cybersecurity and Infrastructure Agency (CISA) with updates every 72 hours, and provide full access to all IT systems and employees.

Contractors and suppliers to the US government are not happy with the proposed changes, as it would effectively give federal authorities the keys to their networks and hinder their ability to operate.

 Industry Anger

A number of bodies that represent IT and cloud industry leaders have lodged numerous responses on the proposed draft which had its commenting period extended by an additional two months. 

These responses criticized the inefficiencies and potential bureaucracy of enforcing these guidelines upon companies, with HackerOne pointing out that providing total access to federal authorities could expose the data of non-federal customers.

As a result of this, HackerOne stated that “Non-federal customers may be reluctant to continue working with federal contractors, potentially forcing federal contractors to choose between selling to non-federal customers or the government.”

The Information Technology Industry Council (ITIC) which represents tech giants such as Apple, Samsung, and Microsoft, criticized the enforced disclosure deadline as “unduly burdensome” and stating that the 72 hour update frequency “does not reflect the shifting urgency throughout an incident response.”

Talking to TechRadar Pro, Dr Ilia Kolochenko, CEO and Chief Architect at ImmuniWeb and Adjunct Professor of Cybersecurity and Cyber Law at Capital Technology University, commented, “If the proposed amendment comes into force, it will likely bring more troubles than benefits. While the underlying concept of accelerating and solidifying incident response makes perfect sense, it seems to be abstracted from the operational environment.

“For instance, it is highly unlikely that the CISA will have enough personnel to review an avalanche of data breach submissions within the novel eight-hour deadline. Instead, snowballing data breach reports will be piling up, driving CISA’s analysts crazy with the insurmountable volume of work. Likewise, getting access to the breached companies may be a good idea subject to the availability of DFIR experts having enough time to perform investigations.

“Additionally, the CISA, as a nationwide collector of valuable cyber intelligence, will become a high-priority target for sophisticated state-backed cybercriminals. Therefore, unless the CISA and all other federal agencies are confident that they can properly address the new volume of information, as well as timely investigate and then prosecute most important security incidents, this amendment may rather create a huge mess and weaken national cybersecurity.”

Via TheRegister

More from TechRadar Pro

Benedict Collins
Staff Writer (Security)

Benedict has been writing about security issues for over 7 years, first focusing on geopolitics and international relations while at the University of Buckingham. During this time he studied BA Politics with Journalism, for which he received a second-class honours (upper division), then continuing his studies at a postgraduate level, achieving a distinction in MA Security, Intelligence and Diplomacy. Upon joining TechRadar Pro as a Staff Writer, Benedict transitioned his focus towards cybersecurity, exploring state-sponsored threat actors, malware, social engineering, and national security. Benedict is also an expert on B2B security products, including firewalls, antivirus, endpoint security, and password management.

Read more
AI security shield
The US wants security requirements as standard to stop sensitive data from falling into enemy hands
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
US government urges federal agencies to patch Microsoft 365 now
Eu
Is your business ready for DORA? Cisco ThousandEyes outlines the "three pillars" everyone needs to have in place to be resilient
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
NIS2: the GDPR of cybersecurity
Digital US flag
Biden orders review, new rules governing US national cybersecurity
EU
“Rehearse, rehearse, rehearse” - is your business doing enough on DORA compliance?
Latest in Pro
A graphic showing fleet tracking locations over a city.
Lost & Found tracking site hit by major data breach - over 800,000 could be affected
US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.
US set to pause cyber-offensive operations against Russia - but CISA says it won't stop
Web DDoS attacks see major surge as AI allows more powerful attacks
Polish space agency says it was hit by a cyberattack
Illustration of a hooked email hovering over a mobile phone
AWS misconfigurations reportedly used to launch phishing attacks
Hands typing on a keyboard surrounded by security icons
Your passwords aren't the key to protecting your online identity, your email address is
Latest in News
Michelle, Keats, and Doctor Amherst looking unimpressed and worried in The Electric State
Netflix drops trailer for The Electric State, and I'm getting serious District 9 vibes
YouTube TV
YouTube TV might be planning a big Netflix update that puts the best streaming services first
Google Pixel 9 Pro
Here are the 7 best Pixel 9 and Pixel Watch 3 features landing in March’s Pixel Feature Drop
Bang & Olufsen Beogram 4000C Saint Laurent Rive Droite Edition
Bang & Olufsen's latest reworked turntable is a masterpiece of retro revival, in a breathtaking wooden presentation box
Apple Watch Series 10
Apple unveils new Apple Watch bands – here's what's in the Spring 2025 collection
iPad Air M3
Apple makes one hardware change to the iPad Air that might be the best indicator of its true lightweight tablet intentions