United States

NIST SP 800-171

88 controls. 10 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

88 controls 10 frameworks share controls with it United States verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

NIST SP 800-171 Rev 3 CUI Security Evidence & Implementation Kit

88 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
171-AC-1Access Control Policy and Procedures2
171-AC-2Least Privilege and Separation of Duties2
171-AC-3Remote Access and Mobile Devices1
171-AT-1Security Awareness and Role-Based Training0
171-AU-1Audit Event Capture0
171-AU-2Audit Review and Analysis0
171-CM-1Baseline Configuration and Inventory2
171-IA-1Identification and Authentication2
171-IA-2Multi-Factor Authentication2
171-IR-1Incident Handling Capability0
171-IR-2Incident Reporting0
171-MA-1Maintenance Authorisation and Control0
171-MP-1Media Protection0
171-PE-1Physical Access Authorisations0
171-RA-1Risk Assessment4
171-RA-2Vulnerability Scanning and Remediation2
171-SC-1Boundary Protection1
171-SC-2Encryption of Controlled Unclassified Information1
171-SI-1Flaw Remediation0
171-SI-2Malicious Code Protection0
3.1.20External Connections Control0
3.10.6Alternate Work Site Safeguards0
3.11.1Risk Assessments0
3.11.2Vulnerability Scanning0
3.12.1Security Control Assessment0
3.13.11Cryptographic Protection0
3.13.5Network Segmentation0
3.13.8Transmission Confidentiality0
3.14.1Flaw Remediation0
3.14.6Monitoring for Attacks0
3.4.6Least Functionality0
3.5.3Multi Factor Authentication0
3.8.3Media Sanitization0
3.9.2Personnel Transfer and Termination0
A.03.01.01Account Management Assessment0
A.03.01.05Least Privilege Assessment0
A.03.01.12Remote Access Assessment0
A.03.03.01Event Logging Assessment1
A.03.04.01Baseline Configuration Assessment0
A.03.04.02Configuration Settings Assessment0
A.03.05.03Multi Factor Authentication Assessment0
A.03.06.01Incident Handling Assessment0
A.03.07.04Maintenance Tools Assessment0
A.03.08.03Media Sanitization Assessment0
A.03.09.02Personnel Termination Assessment0
A.03.10.01Physical Access Authorization Assessment0
A.03.11.01Risk Assessment Process4
A.03.11.02Vulnerability Monitoring Assessment0
A.03.12.01Security Control Assessments0
A.03.13.11Cryptographic Protection of CUI at Rest0
A.03.14.01Flaw Remediation Assessment0
A.03.14.06System Monitoring Assessment0
A.03.15.01System Security Plan Assessment0
SP800-171-3.10.1Limit physical access1
SP800-171-3.10.3Escort and monitor visitors1
SP800-171-3.10.6Safeguard CUI at alternate work sites1
SP800-171-3.11.1Periodically assess risk1
SP800-171-3.11.2Scan for vulnerabilities1
SP800-171-3.11.3Remediate vulnerabilities1
SP800-171-3.12.1Periodically assess security controls1
SP800-171-3.12.2Plans of action for deficiencies1
SP800-171-3.12.3Continuously monitor controls1
SP800-171-3.13.1Monitor and protect communications at boundaries1
SP800-171-3.13.11Employ FIPS-validated cryptography1
SP800-171-3.13.16Protect confidentiality of CUI at rest1
SP800-171-3.13.6Deny network traffic by default1
SP800-171-3.13.8Encrypt CUI in transmission1
SP800-171-3.14.1Identify, report, and correct flaws1
SP800-171-3.14.2Malicious code protection1
SP800-171-3.14.3Monitor security alerts and advisories1
SP800-171-3.14.6Monitor systems and traffic for attacks1
SP800-171-3.5.1Identify system users, processes, and devices1
SP800-171-3.5.10Store and transmit only encrypted passwords1
SP800-171-3.5.2Authenticate identities before access1
SP800-171-3.5.3Multifactor authentication for privileged/network access1
SP800-171-3.5.4Replay-resistant authentication1
SP800-171-3.6.1Operational incident-handling capability1
SP800-171-3.6.2Track, document, and report incidents1
SP800-171-3.6.3Test incident response capability1
SP800-171-3.7.1Perform system maintenance1
SP800-171-3.7.2Control maintenance tools and personnel1
SP800-171-3.7.5MFA for nonlocal maintenance1
SP800-171-3.8.1Protect system media containing CUI1
SP800-171-3.8.3Sanitize or destroy media before disposal1
SP800-171-3.8.6Encrypt CUI on digital media during transport1
SP800-171-3.8.7Control removable media1
SP800-171-3.9.1Screen individuals before CUI access1
SP800-171-3.9.2Protect CUI during personnel actions1

Tell me when NIST SP 800-171 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • OT asset inventory
  • Zone and conduit diagram
  • Patch register
  • Remote access policy
  • Infrastructure/virtualization security policy
  • Network segmentation + defense architecture
  • ISMS scope statement
  • Statement of applicability
  • ISMS policy
  • Management review minutes

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for NIST SP 800-171, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition