TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

DOJ suit claims Georgia Tech knowingly failed to meet cyber standards

15 pointsby WaitWaitWha9 months ago

1 comment

WaitWaitWha9 months ago
BLUF: unless there was gross negligence (meh, just put any score in there) that they can prove, a 98 can be explained very easily.<p>To give a bit of context, the score they are talking about (98) is an entry on DISA&#x27;s Supplier Performance Risk System (SPRS) score [0].<p>The score almost certainly is based on self-assessment using the NIST SP 800-171v2 (and 800-171a). This is a document that looks at 110 cybersecurity controls across 16 families. Comes out to be about 300 or so explicit items that needs to be looked at.<p>The score is from -203 (that is a minus) to 110. The scoring starts at 110, then deductions of 1, 3, or 5 points are made when a specific control audit fails.<p>This is only and only for the confidentiality of Controlled Unclassified Information(CUI).[1]<p>Because of this special carve out for just CUI, scoping what is and is not in scope is hard. I have heard audits where the auditor (DCMA DIBCAC) stated &quot;everything is in scope&quot;, and in an elsewhere the auditor stated &quot;only that is directly generated by the Government&quot;.<p>Not only this there is a feud amongst agencies who does what, where, and how, when it comes to cybersecurity.<p>[0] <a href="https:&#x2F;&#x2F;www.sprs.csd.disa.mil&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.sprs.csd.disa.mil&#x2F;</a><p>[1] <a href="https:&#x2F;&#x2F;www.archives.gov&#x2F;cui&#x2F;about" rel="nofollow">https:&#x2F;&#x2F;www.archives.gov&#x2F;cui&#x2F;about</a>
评论 #41374192 未加载