Defense contractors are subject to the Federal Information Security Management Act (FISMA) of 2002 since they are dealing with DoD information (or might be). “FISMA requires federal agencies to adequately protect their information and information systems against unauthorized access, use, disclosure, disruption, modification, or destruction” NIST SP-800-144 Cloud Computing page 15.