United States

NIST SP 800-171 Rev 3

97 controls. 41 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

97 controls 41 frameworks share controls with it United States verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

NIST SP 800-171 Rev 3 CUI Security Evidence & Implementation Kit

97 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
03.01.01Account Management27
03.01.02Access Enforcement25
03.01.03Information Flow Enforcement23
03.01.04Separation of Duties21
03.01.05Least Privilege27
03.01.06Least Privilege - Privileged Accounts24
03.01.07Least Privilege - Privileged Functions22
03.01.08Unsuccessful Logon Attempts18
03.01.09System Use Notification9
03.01.10Device Lock16
03.01.11Session Termination13
03.01.12Remote Access24
03.01.16Wireless Access16
03.01.18Access Control for Mobile Devices22
03.01.20Use of External Systems20
03.01.22Publicly Accessible Content12
03.02.01Literacy Training and Awareness29
03.02.02Role-Based Training28
03.03.01Event Logging26
03.03.02Audit Record Content20
03.03.03Audit Record Generation24
03.03.04Response to Audit Logging Process Failures13
03.03.05Audit Record Review, Analysis, and Reporting27
03.03.06Audit Record Reduction and Report Generation18
03.03.07Time Stamps14
03.03.08Protection of Audit Information19
03.04.01Baseline Configuration27
03.04.02Configuration Settings26
03.04.03Configuration Change Control23
03.04.04Impact Analyses19
03.04.05Access Restrictions for Change18
03.04.06Least Functionality24
03.04.08Authorized Software - Allow by Exception27
03.04.10System Component Inventory28
03.04.11Information Location22
03.04.12System and Component Configuration for High-Risk Areas9
03.05.01User Identification and Authentication27
03.05.02Device Identification and Authentication16
03.05.03Multi-Factor Authentication23
03.05.04Replay-Resistant Authentication16
03.05.05Identifier Management23
03.05.07Password Management22
03.05.11Authentication Feedback14
03.05.12Authenticator Management25
03.06.01Incident Handling30
03.06.02Incident Monitoring, Reporting, and Response Assistance29
03.06.03Incident Response Testing25
03.06.04Incident Response Training24
03.06.05Incident Response Plan29
03.07.04Maintenance Tools14
03.07.05Nonlocal Maintenance20
03.07.06Maintenance Personnel15
03.08.01Media Storage18
03.08.02Media Access18
03.08.03Media Sanitization24
03.08.04Media Marking18
03.08.05Media Transport17
03.08.07Media Use21
03.08.09System Backup - Cryptographic Protection25
03.09.01Personnel Screening25
03.09.02Personnel Termination and Transfer26
03.10.01Physical Access Authorizations22
03.10.02Monitoring Physical Access20
03.10.06Alternate Work Site15
03.10.07Physical Access Control21
03.10.08Access Control for Transmission18
03.11.01Risk Assessment31
03.11.02Vulnerability Monitoring and Scanning31
03.11.04Risk Response24
03.12.01Security Assessment30
03.12.02Plan of Action and Milestones28
03.12.03Continuous Monitoring31
03.12.05Information Exchange25
03.13.01Boundary Protection27
03.13.04Information in Shared System Resources16
03.13.06Network Communications - Deny by Default - Allow by Exception20
03.13.08Transmission Confidentiality and Integrity25
03.13.09Network Disconnect12
03.13.10Cryptographic Key Establishment and Management21
03.13.11Cryptographic Protection23
03.13.12Collaborative Computing Devices and Applications9
03.13.13Mobile Code18
03.13.15Session Authenticity18
03.14.01Flaw Remediation28
03.14.02Malicious Code Protection28
03.14.03Security Alerts, Advisories, and Directives25
03.14.06System Monitoring27
03.14.08Information Management and Retention22
03.15.01Policy and Procedures27
03.15.02System Security Plan28
03.15.03Rules of Behavior21
03.16.01Security Engineering Principles25
03.16.02Unsupported System Components21
03.16.03External System Services29
03.17.01Supply Chain Risk Management Plan23
03.17.02Acquisition Strategies, Tools, and Methods24
03.17.03Supply Chain Requirements and Processes25

Tell me when NIST SP 800-171 Rev 3 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • OT asset inventory
  • Zone and conduit diagram
  • Patch register
  • Remote access policy
  • Infrastructure/virtualization security policy
  • Network segmentation + defense architecture
  • IAM policy
  • MFA enforcement report
  • Federation configuration
  • API token inventory

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for NIST SP 800-171 Rev 3, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition