← Back to list

Cyber Incident Reporting: A frequently overlooked DFARS requirement

An overlooked component of DFARS 252.207–7012 compliance is cyber incident reporting.

Lori J. · 2022-02-09 15:51 · 0 claps · 1.5 min read
#nist-800-171 #dfars-compliance
Open on Medium ↗

Cyber Incident Reporting: A frequently overlooked DFARS requirement

An overlooked component of DFARS 252.207–7012 compliance is cyber incident reporting.

Photo by Markus Winkler on Unsplash

Photo by Markus Winkler on Unsplash

Many companies become distracted by the list of 110 security controls in NIST SP 800–171 and they miss part (c ) of the DFARS clause.

(c ) Cyber Incident Reporting Requirement

(1)(ii) Rapidly report cyber incidents to DoD at https://dibnet.dod.mil.

-Excerpts from DFARS 252.204–7012, Safeguarding Covered Defense Information and Cyber Incident Reporting (DEC 2019)

Reporting a cyber incident is not a simple process. It requires careful preparation, time, and of course, money.

  • Investigate: determine affected parts of your system.
  • Register: registering with DIBNet requires a medium assurance certificate.
  • Report: report incidents within 72 hours.

Investigate.

Following an incident, you must investigate to find the affected part(s) of your system. Are computers compromised? Servers? Cloud resources?

This will take advanced preparation. Do you have someone with the right technical knowledge to do this?

Do you have an Incident Response Plan? If not, this is a good time to create one. It’s also required for NIST compliance (see section 3.6).

Investigating an incident will take time and money. It’s best to prepare ahead of time so you don’t miss the 72-hour reporting window.

Register.

Before you can report an incident to DIBNet, you must register your company. That process requires a medium assurance certificate from an External Certificate Authority (ECA). A third party must verify your identity and grant the certificate. After all, you wouldn’t want an adversary to impersonate you to the Government.

This process is important, but it also takes time and money. You will miss the 72-hour reporting window if you don’t register beforehand.

Report.

“Rapidly report” means within 72 hours of discovery of any cyber incident.

-Excerpts from DFARS 252.204–7012, Safeguarding Covered Defense Information and Cyber Incident Reporting (DEC 2019)

The clause requires that you report a cyber incident within 72 hours of discovery. Three days is not much time. Preparation is key. Develop an Incident Response Plan that makes sense for your company. Be sure to register with DIBNet. Otherwise, meeting the rapid report window will be impossible.


메타데이터
post_id
d027a7e33178
slug
cyber-incident-reporting-a-frequently-overlooked-dfars-requirement-d027a7e33178
url
https://medium.com/@ravensec/cyber-incident-reporting-a-frequently-overlooked-dfars-requirement-d027a7e33178
canonical_url
https://medium.com/@ravensec/cyber-incident-reporting-a-frequently-overlooked-dfars-requirement-d027a7e33178
author_url
https://medium.com/@ravensec
status
ok
fetched_at
2026-06-09 15:37:30