1. Home
  2. |Insights
  3. |National Archives Issues Non-FAR-Based Guidance for Controlled Unclassified Information

National Archives Issues Non-FAR-Based Guidance for Controlled Unclassified Information

Client Alert | 1 min read | 02.13.18

The Information Security Oversight Office (ISOO) within the National Archives and Records Administration (NARA) has issued guidance relevant to contractors and other non-executive branch entities concerning controlled unclassified information (CUI). Specifically, the ISOO issued CUI Notice 2018-01 regarding information sharing agreements with non-executive branch entities that are not governed by the forthcoming CUI Federal Acquisition Regulation (FAR) Clause, including certain contracts, grants, licenses, and memoranda of understanding. Importantly, the ISOO guidance provides both mandatory and recommended language for inclusion in future information sharing agreements to help ensure the appropriate handling and safeguarding of CUI. While we continue to await a proposed FAR Clause regarding CUI, contractors should benefit from the additional clarity that this ISOO guidance brings in standardizing CUI provisions for non-FAR based agreements.

Insights

Client Alert | 11 min read | 05.17.24

FTC Finalizes Modifications to Broaden the Applicability of the Health Breach Notification Rule

On April 26, 2024, the Federal Trade Commission (“FTC”) announced a final rule (“Final Rule”) modifying the Health Breach Notification Rule (“HBNR”). The Final Rule, which largely finalizes changes proposed in a Notice of Proposed Rulemaking published last year (“2023 NPRM”), broadens the scope of entities subject to the HBNR, including many mobile health applications (“apps”) and similar technologies, and clarifies that breaches subject to the HBNR include not only cybersecurity intrusions but also unauthorized disclosures, even those that are voluntary. The Final Rule will take effect 60 days after its publication in the Federal Register....