Skip to content

Author Archives: stevebritt

DoD releases Version 1 of the Cybersecurity Maturity Model Certification Framework

On Behalf of Berenzweig Leonard, LLP | February 11, 2020 | Government Contracts

DoD Releases V1 of CMMC Framework On January 30, 2020, DoD released Version 1 of the Cybersecurity Maturity Model Certification Framework (CMMC v.1).  When fully implemented, this framework will create a unified standard by which all DoD contractors will be required to certify their ability to protect Federal Contract…

The FTC Will Clobber Facebook on Privacy

On Behalf of Berenzweig Leonard, LLP | April 26, 2019 | Business Litigation

The FTC is nearing completion of its 2018 investigation of Facebook resulting from the Cambridge Analytica debacle.  It is already clear that Facebook grossly violated its 2011 FTC Consent Decree. That Decree was based on broad violations of the government’s requirements for Facebook’s protection of user privacy.  It turned out…

The Drumbeat For Federal Privacy Law Grows

On Behalf of Berenzweig Leonard, LLP | March 11, 2019 | Cybersecurity & Data Privacy

Government contractors focused on DoD’s acquisition efforts and other businesses should keep an eye on the smoke signals in Washington rising on privacy.   From GDPR in Europe, to the draft new NIST Privacy Framework, to NTIA’s request for comments on privacy, the legal landscape on this…

DCMA To Audit Contractor Cyber Compliance

On Behalf of Berenzweig Leonard, LLP | February 11, 2019 | Cybersecurity & Data Privacy

Since December 31, 2017, DoD contractors are required to have “implemented” DFARs Clause 252.204-7012 (“Safeguarding Covered Defense Information and Cyber Incident Reporting”) by the implementation of NIST 800-171 on their covered information systems. For most of the past year, contractors have been told they mainly need to have System…

New U.S. Privacy Initiatives:  FTC & NTIA Privacy Initiatives

On Behalf of Berenzweig Leonard, LLP | January 15, 2019 | Business Litigation

  Last month, we looked at NIST’s efforts to develop a new Privacy Framework to supplement its widely used Cybersecurity Framework.  This month we review a couple of the Administration’s other data privacy initiatives, which reflect that further changes in data protection requirements are a…