Most Commonly Failed Controls (DIBCAC Findings)
Top “Other Than Satisfied” Requirements
from DIBCAC High Assessments
The Defense Contract Management Agency (DCMA) conducted DIBCAC High Assessments between 2019–2022 to measure real-world adherence to NIST SP 800-171. The results revealed the most commonly failed requirements among contractors.
Presented By:
Defense Contract Management Agency (DCMA)
Defense Industrial Base Cybersecurity Assessment Center (DIBCAC)
December 2022
Top 10 Most Commonly Failed Controls
3.13.11, FIPS-validated cryptography [Systems and Communication Protection (SC)]
3.5.3, Multifactor Authentication [Identification and Authentication (IA)]
3.14.1, Identify, report, correct system flaws [System and Information Integrity (SI)]
3.11.1, Periodically assess risk [Risk Assessment (RA)]
3.11.2, Scan for vulnerabilities [Risk Assessment (RA)]
3.3.3, Review and update logged events [Audit and Accountability (AU)]
3.3.4, Audit logging process failure alerts [Audit and Accountability (AU)]
3.3.5, Audit record review, analysis, and reporting processes [Audit and Accountability (AU)]
3.6.3, Test incident response capability [Incident Response (IR)]
3.4.1, Establish/maintain baseline configuration [Configuration Management (CM)]
Top 10 OTS Requirements Breakdown
883 Total OTS DeficienciesData taken from 117 High Assessments (2019 – 2022) Total number of OTS = 883
NIST SP 800-171 → Other Than Satisfied (OTS) Controls Ranking
Comprehensive ranking of all 110 NIST SP 800-171 Rev 2 security requirements based on failure counts and percentages across 117 DIBCAC High Assessments[cite: 1].
Total Assessments
Total Controls Tracked
Total OTS Deficiencies
All OTS Requirements Ranking 110 Controls
-
#1
3.13.11
49.57% (58 / 117)
-
#2
3.5.3
38.46% (45 / 117)
-
#3
3.14.1
22.22% (26 / 117)
-
#4
3.11.1
17.95% (21 / 117)
-
#5
3.11.2
17.95% (21 / 117)
-
#6
3.3.3
16.24% (19 / 117)
-
#7
3.3.4
15.38% (18 / 117)
-
#8
3.3.5
15.38% (18 / 117)
-
#9
3.6.3
15.38% (18 / 117)
-
#10
3.4.1
14.53% (17 / 117)
-
#11
3.1.11
11.97% (14 / 117)
-
#12
3.1.3
11.97% (14 / 117)
-
#13
3.11.3
12.82% (15 / 117)
-
#14
3.12.1
11.97% (14 / 117)
-
#15
3.13.1
13.68% (16 / 117)
-
#16
3.13.16
13.68% (16 / 117)
-
#17
3.13.2
11.97% (14 / 117)
-
#18
3.13.9
11.11% (13 / 117)
-
#19
3.3.6
11.11% (13 / 117)
-
#20
3.4.2
11.11% (13 / 117)
-
#21
3.4.7
13.68% (16 / 117)
-
#22
3.4.8
11.11% (13 / 117)
-
#23
3.1.22
10.26% (12 / 117)
-
#24
3.13.13
10.26% (12 / 117)
-
#25
3.8.8
10.26% (12 / 117)
-
#26
3.13.7
9.40% (11 / 117)
-
#27
3.2.2
9.40% (11 / 117)
-
#28
3.3.1
9.40% (11 / 117)
-
#29
3.1.19
8.55% (10 / 117)
-
#30
3.1.7
8.55% (10 / 117)
-
#31
3.12.3
8.55% (10 / 117)
-
#32
3.12.4
8.55% (10 / 117)
-
#33
3.4.9
8.55% (10 / 117)
-
#34
3.5.6
7.69% (9 / 117)
-
#35
3.8.7
7.69% (9 / 117)
-
#36
3.1.18
6.84% (8 / 117)
-
#37
3.1.20
6.84% (8 / 117)
-
#38
3.1.21
6.84% (8 / 117)
-
#39
3.1.6
6.84% (8 / 117)
-
#40
3.14.2
6.84% (8 / 117)
-
#41
3.14.3
6.84% (8 / 117)
-
#42
3.6.1
6.84% (8 / 117)
-
#43
3.8.4
6.84% (8 / 117)
-
#44
3.1.5
5.98% (7 / 117)
-
#45
3.13.8
5.98% (7 / 117)
-
#46
3.14.6
5.98% (7 / 117)
-
#47
3.3.2
5.98% (7 / 117)
-
#48
3.8.1
5.98% (7 / 117)
-
#49
3.8.5
5.98% (7 / 117)
-
#50
3.1.4
5.13% (6 / 117)
-
#51
3.1.9
5.13% (6 / 117)
-
#52
3.10.2
5.13% (6 / 117)
-
#53
3.10.6
5.13% (6 / 117)
-
#54
3.13.15
5.13% (6 / 117)
-
#55
3.13.5
5.13% (6 / 117)
-
#56
3.13.6
5.13% (6 / 117)
-
#57
3.2.1
5.13% (6 / 117)
-
#58
3.7.5
5.13% (6 / 117)
-
#59
3.8.6
5.13% (6 / 117)
-
#60
3.1.12
4.27% (5 / 117)
-
#61
3.1.15
4.27% (5 / 117)
-
#62
3.14.5
4.27% (5 / 117)
-
#63
3.3.7
4.27% (5 / 117)
-
#64
3.4.3
4.27% (5 / 117)
-
#65
3.4.4
4.27% (5 / 117)
-
#66
3.4.5
4.27% (5 / 117)
-
#67
3.5.10
4.27% (5 / 117)
-
#68
3.5.4
4.27% (5 / 117)
-
#69
3.6.2
4.27% (5 / 117)
-
#70
3.1.1
3.42% (4 / 117)
-
#71
3.1.10
3.42% (4 / 117)
-
#72
3.1.2
3.42% (4 / 117)
-
#73
3.10.1
3.42% (4 / 117)
-
#74
3.13.10
3.42% (4 / 117)
-
#75
3.5.2
3.42% (4 / 117)
-
#76
3.5.7
3.42% (4 / 117)
-
#77
3.7.3
3.42% (4 / 117)
-
#78
3.8.9
3.42% (4 / 117)
-
#79
3.9.1
3.42% (4 / 117)
-
#80
3.1.8
2.56% (3 / 117)
-
#81
3.10.4
2.56% (3 / 117)
-
#82
3.12.2
2.56% (3 / 117)
-
#83
3.13.14
2.56% (3 / 117)
-
#84
3.13.3
2.56% (3 / 117)
-
#85
3.14.4
2.56% (3 / 117)
-
#86
3.14.7
2.56% (3 / 117)
-
#87
3.2.3
2.56% (3 / 117)
-
#88
3.4.6
2.56% (3 / 117)
-
#89
3.5.1
2.56% (3 / 117)
-
#90
3.5.5
2.56% (3 / 117)
-
#91
3.5.8
2.56% (3 / 117)
-
#92
3.7.2
2.56% (3 / 117)
-
#93
3.1.13
1.71% (2 / 117)
-
#94
3.10.5
1.71% (2 / 117)
-
#95
3.13.12
1.71% (2 / 117)
-
#96
3.3.8
1.71% (2 / 117)
-
#97
3.5.9
1.71% (2 / 117)
-
#98
3.7.4
1.71% (2 / 117)
-
#99
3.8.2
1.71% (2 / 117)
-
#100
3.1.16
0.85% (1 / 117)
-
#101
3.10.3
0.85% (1 / 117)
-
#102
3.13.4
0.85% (1 / 117)
-
#103
3.7.1
0.85% (1 / 117)
-
#104
3.9.2
0.85% (1 / 117)
-
#105
3.1.14
0.00% (0 / 117)
-
#106
3.1.17
0.00% (0 / 117)
-
#107
3.3.9
0.00% (0 / 117)
-
#108
3.5.11
0.00% (0 / 117)
-
#109
3.7.6
0.00% (0 / 117)
-
#110
3.8.3
0.00% (0 / 117)
DFARS 252.204-7012 and NIST SP 800-171 References
8 References| Topic | Website Link |
|---|---|
| DFARS Clause 252.204-7012, "Safeguarding Covered Defense Information and Cyber Incident Reporting" | https://www.acquisition.gov/dfars/part-252-solicitation-provisions-and-contract-clauses#DFARS-252-204-7012 |
| DFARS Cybersecurity FAQs | https://dodprocurementtoolbox.com/faqs/cybersecurity |
| NIST SP 800-171R2, "Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations" | https://csrc.nist.gov/publications/detail/sp/800-171/rev-2/final |
| NIST SP 800-171A, "Assessing Security Requirements for Controlled Unclassified Information" | https://csrc.nist.gov/publications/detail/sp/800-171a/final |
| NIST MEP CYBERSECURITY Self-Assessment Handbook for Assessing NIST SP 800-171 Security Requirements in Response to DFARS Cybersecurity Requirements | https://nist.gov/publications/nist-mep-cybersecurity-self-assessment-handbook-assessing-nist-sp-800-171-security |
| Supplier Performance Risk System (SPRS) | https://www.sprs.csd.disa.mil |
| DoD Assessment Methodology | https://www.acq.osd.mil/asda/dpc/cp/cyber/safeguarding.html#nistSP800171 |
| DCMA DIBCAC HIGH OTS | https://www.dcma.mil/Portals/31/Documents/DIBCAC/DIBCAC_Top_OTS_Reqts.pptx |
Frameworks & Controls