United States

NIST SP 800-171A

97 controls. 19 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

97 controls 19 frameworks share controls with it United States verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
171A-03.01.01Account Management0
171A-03.01.02Access Enforcement0
171A-03.01.03Information Flow Enforcement0
171A-03.01.04Separation of Duties0
171A-03.01.05Least Privilege0
171A-03.01.06Least Privilege - Privileged Accounts0
171A-03.01.07Least Privilege - Privileged Functions0
171A-03.01.08Unsuccessful Logon Attempts0
171A-03.01.09System Use Notification0
171A-03.01.10Device Lock0
171A-03.01.11Session Termination0
171A-03.01.12Remote Access0
171A-03.01.16Wireless Access0
171A-03.01.18Access Control for Mobile Devices0
171A-03.01.20Use of External Systems0
171A-03.01.22Publicly Accessible Content0
171A-03.02.01Literacy Training and Awareness0
171A-03.02.02Role-Based Training0
171A-03.03.01Event Logging0
171A-03.03.02Audit Record Content0
171A-03.03.03Audit Record Generation0
171A-03.03.04Response to Audit Logging Process Failures0
171A-03.03.05Audit Record Review, Analysis, and Reporting0
171A-03.03.06Audit Record Reduction and Report Generation0
171A-03.03.07Time Stamps0
171A-03.03.08Protection of Audit Information0
171A-03.04.01Baseline Configuration0
171A-03.04.02Configuration Settings0
171A-03.04.03Configuration Change Control0
171A-03.04.04Impact Analyses0
171A-03.04.05Access Restrictions for Change0
171A-03.04.06Least Functionality0
171A-03.04.08Authorized Software - Allow by Exception0
171A-03.04.10System Component Inventory0
171A-03.04.11Information Location0
171A-03.04.12System and Component Configuration for High-Risk Areas0
171A-03.05.01User Identification, Authentication, and Re-Authentication0
171A-03.05.02Device Identification and Authentication0
171A-03.05.03Multi-Factor Authentication0
171A-03.05.04Replay-Resistant Authentication0
171A-03.05.05Identifier Management0
171A-03.05.07Password Management0
171A-03.05.11Authentication Feedback0
171A-03.05.12Authenticator Management0
171A-03.06.01Incident Handling0
171A-03.06.02Incident Monitoring, Reporting, and Response Assistance0
171A-03.06.03Incident Response Testing14
171A-03.06.04Incident Response Training0
171A-03.06.05Incident Response Plan0
171A-03.07.04Maintenance Tools0
171A-03.07.05Nonlocal Maintenance0
171A-03.07.06Maintenance Personnel0
171A-03.08.01Media Storage0
171A-03.08.02Media Access0
171A-03.08.03Media Sanitization0
171A-03.08.04Media Marking0
171A-03.08.05Media Transport0
171A-03.08.07Media Use0
171A-03.08.09System Backup - Cryptographic Protection0
171A-03.09.01Personnel Screening0
171A-03.09.02Personnel Termination and Transfer0
171A-03.10.01Physical Access Authorizations0
171A-03.10.02Monitoring Physical Access0
171A-03.10.06Alternate Work Site0
171A-03.10.07Physical Access Control0
171A-03.10.08Access Control for Transmission0
171A-03.11.01Risk Assessment0
171A-03.11.02Vulnerability Monitoring and Scanning0
171A-03.11.04Risk Response0
171A-03.12.01Security Assessment18
171A-03.12.02Plan of Action and Milestones12
171A-03.12.03Continuous Monitoring16
171A-03.12.05Information Exchange0
171A-03.13.01Boundary Protection0
171A-03.13.04Information in Shared System Resources0
171A-03.13.06Network Communications - Deny by Default - Allow by Exception0
171A-03.13.08Transmission and Storage Confidentiality0
171A-03.13.09Network Disconnect0
171A-03.13.10Cryptographic Key Establishment and Management0
171A-03.13.11Cryptographic Protection0
171A-03.13.12Collaborative Computing Devices and Applications0
171A-03.13.13Mobile Code0
171A-03.13.15Session Authenticity0
171A-03.14.01Flaw Remediation0
171A-03.14.02Malicious Code Protection0
171A-03.14.03Security Alerts, Advisories, and Directives0
171A-03.14.06System Monitoring0
171A-03.14.08Information Management and Retention0
171A-03.15.01Policy and Procedures0
171A-03.15.02System Security Plan0
171A-03.15.03Rules of Behavior0
171A-03.16.01Systems Security Engineering Principles0
171A-03.16.02Unsupported System Components0
171A-03.16.03External System Services0
171A-03.17.01Supply Chain Risk Management Plan0
171A-03.17.02Acquisition Strategies, Tools, and Methods0
171A-03.17.03Supply Chain Requirements and Processes0

Tell me when NIST SP 800-171A files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Screening criteria and procedure
  • Screening records for individuals granted access
  • Evidence screening precedes access authorization
  • Pre-access screening records
  • screening criteria and procedure
  • screening completion records for sampled individuals
  • Cybersecurity risk management policy approved by leadership
  • Policy linkage matrix to standards and procedures
  • Risk based rationale documented for policy positions
  • Policy distribution and acknowledgement records

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for NIST SP 800-171A, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition