Cybersecurity rules in this supplement
The Department of Energy Acquisition Regulation (DEAR) addresses computer security and sensitive information at DOE sites:
DEAR clause 952.204-77 — Computer Security. Requires contractors using DOE computer systems or networks to comply with DOE computer-security requirements and protect DOE information.
DEAR Section 970.0370 / clauses 970.5203-1, 970.5204-1, 970.5204-3 — Management Controls, Counterintelligence, and Access to/Ownership of Records. Apply to DOE's management-and-operating (M&O) contractors at national laboratories and sites, covering security management, counterintelligence, and control of records.
DEAR Subsection 970.0371-5 — Use of Privileged Information. Restricts use of privileged or sensitive DOE information.
In plain terms
DOE's rules reflect its national-security mission. Anyone using DOE computer systems must follow DOE computer-security requirements, and the management-and-operating contractors that run DOE's national labs carry extra obligations for security management, counterintelligence, and records control.
Who it applies to
Contractors and subcontractors using DOE computer systems, and (for the Part 970 clauses) management-and-operating contractors at DOE laboratories and sites.
What it requires
Follow the FAR baseline, then: comply with DOE computer-security requirements, protect DOE and privileged information, and (for M&O contractors) meet the management-control, counterintelligence, and records requirements.
Why it matters
DOE work can involve nuclear and national-security information, so its computer-security and counterintelligence requirements carry heightened consequences for noncompliance.
Citation
Department of Energy Acquisition Regulation (DEAR), codified at 48 C.F.R. Chapter 9.