DFARS compliance
Can I use Encyro to store data subject to Defense Federal Acquisition Regulation Supplement (DFARS) compliance, or data security regulations subject to defense contracts, or related government data?
The requirements of DFARS compliance vary depending on the security level required, which depends on the sensitivity of data being secured.
If only encryption is needed (both for data at rest and for data in transit) Encyro Essentials membership (Free) provides that. However most DFARS compliance levels do require audit trails and so Encyro Pro is required.
Even Encyro Pro does not meet all levels of DFARS compliance. For certain types of data, it must be stored in a data center used only for government data. Encyro can provide a custom quote for you if this need applies to you. We will need to verify that your organization qualifies for hosting in the government-specific data center. To get started, please contact us for a quote. Our price is very likely to be much lower than the alternatives.
Resources
Many organizations are subject to DFARS compliance because they handle Controlled Unclassified Information (CUI). For these situations, the NIST provides a Security Systems Plan (SSP) template and a Plan of Action and Milestones (POA&M) template. Preparing these two documents using the templates linked above will help you demonstrate your organization’s compliance with DFARS for handling CUI. In situations where the government agency or the defense contractor you are serving requires you to obtain third party certification of your compliance, these two documents will both prepare you for the requirements and speed up the certification related audits.
Related articles
-
NIST 800-171 Compliance
National Institue of Standards and technology (NIST) Special Publication 800-171 or NIST-SP800-171, specifies requirements for non-Federal computer systems...
-
What country does Encyro operate from?
Encyro Inc is based in the United States of America, and is subject to US laws and regulations. Your data in your Encyro account is stored in our data cen...
-
Is Encyro HIPAA Compliant?
Can I use Encyro for HIPAA compliance? Can I store and send patient information using Encyro? Encyro complies with Health Insurance Portability and Account...
-
Configuring Compliance Settings
(If your Encyro account is part of an organization, see organizational compliance settings.) To enable or edit compliance settings, go to your account Sett...
-
PCI-DSS
PCI-DSS requires safeguarding credit card data that you receive. Email is not a secure way to ask a customer to provide their credit card information to se...
-
IRS Pub 4557 Compliance for Tax Practitioners
IRS Publication 4557 provides seven checklists for tax preparers to help protect tax clients' tax data. The safeguards also protect your business from a da...
-
Can I Avoid Having to Login Each Time?
If you are being asked to login every time you visit your Encyro account, it is likely that you or your organization's compliance settings have enforced au...