Cybersecurity rules in this supplement
The Justice Acquisition Regulation (JAR) addresses IT-acquisition risk and personnel security:
JAR Part 2839 — Acquisition of Information Technology (incl. 2839.101 Policy and 2839.102 Management of Risk). Sets DOJ policy for acquiring IT and managing IT/supply-chain risk.
JAR Subpart 2804.4 / 2804.402-70 — Safeguarding Classified Information Within Industry; Contractor Personnel Security Program. Governs personnel security and handling of classified information.
In plain terms
DOJ's rules focus on managing the risk of the IT it buys and on vetting the people who handle its information, including classified material.
Who it applies to
Contractors and subcontractors that provide IT to DOJ or whose personnel handle DOJ or classified information.
What it requires
Follow the FAR baseline, then: meet DOJ IT-acquisition and risk-management policy and satisfy personnel-security and classified-information-handling requirements.
Why it matters
DOJ handles law-enforcement and national-security information, so IT supply-chain risk and personnel vetting are central concerns.
Citation
Justice Acquisition Regulation (JAR), codified at 48 C.F.R. Chapter 28.