Cybersecurity rules in this supplement
The Department of State Acquisition Regulation (DOSAR) addresses IT security for unclassified systems:
DOSAR Part 639 — Acquisition of Information Technology. Sets State's policy for acquiring and securing IT.
DOSAR provision 652.239-70 — Information Technology Security Plan and Accreditation. Requires offerors to submit an IT security plan and obtain accreditation for systems used on the contract.
DOSAR clause 652.239-71 — Security Requirements for Unclassified Information Technology Resources. Requires contractors to secure unclassified IT resources to State and federal standards.
DOSAR clause 652.204-70 — Personal Identification Card Policy and Procedures. Governs identity credentials for contractor personnel.
In plain terms
State requires that any unclassified IT you use on its behalf be secured and formally accredited, with a security plan submitted up front, and that your personnel carry proper identity credentials.
Who it applies to
Contractors and subcontractors that provide or operate unclassified information technology for the Department of State.
What it requires
Follow the FAR baseline, then: submit an IT security plan and obtain accreditation, secure unclassified IT resources to State/federal standards, and meet personal-identity-credential requirements.
Why it matters
State's global IT footprint and sensitive diplomatic information make accreditation and IT-security compliance prerequisites for performance.
Citation
Department of State Acquisition Regulation (DOSAR), codified at 48 C.F.R. Chapter 6.