SaaS Procurement under FOCI: Navigating DCSA Guidelines episode artwork

EPISODE · May 15, 2025 · 23 MIN

SaaS Procurement under FOCI: Navigating DCSA Guidelines

from Ctrl✇Alt✇AnyKey · host 🅱🅴🅽🅹🅰🅼🅸🅽 🅰🅻🅻🅾🆄🅻 𝄟 🅽🅾🆃🅴🅱🅾🅾🅺🅻🅼

Address the complex challenges faced by U.S. companies under foreign ownership, control, or influence (FOCI) when procuring commercial Software-as-a-Service (SaaS) solutions, particularly those handling sensitive employee Personally Identifiable Information (PII). They explain how the Defense Counterintelligence and Security Agency (DCSA) regulates FOCI and its increasing scrutiny on unclassified contracts with sensitive data due to Section 847 of the FY20 NDAA. The text emphasizes the need for rigorous due diligence of SaaS providers, the adaptation of existing FOCI mitigation plans like Technology Control Plans (TCPs) and Electronic Communications Plans (ECPs) for cloud environments, and the crucial role of internal governance bodies like the Government Security Committee (GSC) in ensuring compliance to protect against foreign access and influence risks. Effective contractual safeguards with SaaS vendors are highlighted as vital tools in this complex regulatory landscape.

Episode metadata supplied by the publisher feed · Published May 15, 2025

Embed this episode

NOW PLAYING

SaaS Procurement under FOCI: Navigating DCSA Guidelines

0:00 23:33

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Ctrl✇Alt✇AnyKey?

This episode is 23 minutes long.

When was this Ctrl✇Alt✇AnyKey episode published?

This episode was published on May 15, 2025.

Can I download this Ctrl✇Alt✇AnyKey episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!