
The rules applied to US government IT contractors and suppliers as part of the Federal Acquisition Regulation (FAR) are under review due to the increasing numbers of new and existing threats.
Under the drafted changes proposed to FAR, contractors would have to disclose detected incidents within eight hours to the Cybersecurity and Infrastructure Agency (CISA) with updates every 72 hours, and provide full access to all IT systems and employees.