FintastIQTrust Center
LoginBook a Consultation
Framework

NIST SP 800-171 Rev. 3

Version: Revision 3 (May 2024)

NIST requirements for protecting the confidentiality of Controlled Unclassified Information (CUI) in nonfederal systems and organizations, such as federal contractors and subcontractors. Revision 3 has 97 active requirements in 17 families, many with organization-defined parameters.

Official source

Summary

Where we stand

Controls
62%
Evidence
19%
Policies
19%

66 of 97 clauses mapped to adopted controls · 1 known gap

As of (just now)

Percentages are over clauses mapped to at least one adopted control. Unmapped clauses are listed below and never count as passing. A known gap is a clause that applies to us and that no control covers yet.

Clauses

Clause-by-clause readiness

ClauseTitleControlsEvidencePoliciesLast tested
03.01 Access Control
03.01.01Account Management
Controls: IAM-01, IAM-07, IAM-09
Not passingCurrentNot approved(29 d ago)
03.01.02Access Enforcement
Controls: IAM-01, IAM-04, IAM-05
PassingNot currentNot approved(29 d ago)
03.01.03Information Flow EnforcementUnmappedUnmappedUnmappedNot yet
03.01.04Separation of Duties
Controls: BIZ-15, PDP-05
PassingNot currentNot approved(29 d ago)
03.01.05Least Privilege
Controls: IAM-04, IAM-06, IAM-09
PassingNot currentNot approved(29 d ago)
03.01.06Least Privilege - Privileged Accounts
Controls: IAM-06
PassingCurrentNot approved(29 d ago)
03.01.07Least Privilege - Privileged Functions
Controls: IAM-05, IAM-06, MON-02
PassingNot currentNot approved(29 d ago)
03.01.08Unsuccessful Logon AttemptsUnmappedUnmappedUnmappedNot yet
03.01.09System Use NotificationKnown gapKnown gapKnown gapNot yet
03.01.10Device LockUnmappedUnmappedUnmappedNot yet
03.01.11Session TerminationUnmappedUnmappedUnmappedNot yet
03.01.12Remote Access
Controls: IAM-01, IAM-02
Not passingNot currentNot approved(8 h ago)
03.01.16Wireless AccessUnmappedUnmappedUnmappedNot yet
03.01.18Access Control for Mobile Devices
Controls: IT-02
Not passingNot currentApprovedNot yet
03.01.20Use of External Systems
Controls: VEND-03
PassingNot currentNot approvedNot yet
03.01.22Publicly Accessible Content
Controls: DATA-01
PassingNot currentNot approvedNot yet
03.02 Awareness and Training
03.02.01Literacy Training and Awareness
Controls: PEOPLE-06
Not passingCurrentApproved(8 h ago)
03.02.02Role-Based TrainingUnmappedUnmappedUnmappedNot yet
03.03 Audit and Accountability
03.03.01Event Logging
Controls: MON-01, MON-02
Not passingNot currentNot approved(3 mo ago)
03.03.02Audit Record ContentUnmappedUnmappedUnmappedNot yet
03.03.03Audit Record Generation
Controls: MON-01, MON-02
Not passingNot currentNot approved(3 mo ago)
03.03.04Response to Audit Logging Process FailuresUnmappedUnmappedUnmappedNot yet
03.03.05Audit Record Review, Analysis, and Reporting
Controls: MON-01, MON-03
Not passingNot currentNot approved(3 mo ago)
03.03.06Audit Record Reduction and Report Generation
Controls: MON-01, MON-03
Not passingNot currentNot approved(3 mo ago)
03.03.07Time StampsUnmappedUnmappedUnmappedNot yet
03.03.08Protection of Audit InformationUnmappedUnmappedUnmappedNot yet
03.04 Configuration Management
03.04.01Baseline Configuration
Controls: CLOUD-02
PassingCurrentApproved(29 d ago)
03.04.02Configuration Settings
Controls: CLOUD-04
PassingNot currentApprovedNot yet
03.04.03Configuration Change Control
Controls: PDP-02, PDP-03
Not passingNot currentNot approved(8 h ago)
03.04.04Impact Analyses
Controls: PDP-14
PassingCurrentApproved(4 mo ago)
03.04.05Access Restrictions for Change
Controls: PDP-05, PDP-06
PassingCurrentNot approved(29 d ago)
03.04.06Least Functionality
Controls: CLOUD-03, CLOUD-04
PassingNot currentApprovedNot yet
03.04.08Authorized Software - Allow by ExceptionUnmappedUnmappedUnmappedNot yet
03.04.10System Component Inventory
Controls: IT-04, IT-05
PassingNot currentNot approvedNot yet
03.04.11Information LocationUnmappedUnmappedUnmappedNot yet
03.04.12System and Component Configuration for High-Risk AreasUnmappedUnmappedUnmappedNot yet
03.05 Identification and Authentication
03.05.01User Identification and Authentication
Controls: IAM-01, IAM-02
Not passingNot currentNot approved(8 h ago)
03.05.02Device Identification and AuthenticationUnmappedUnmappedUnmappedNot yet
03.05.03Multi-Factor Authentication
Controls: IAM-02
Not passingNot currentNot approved(8 h ago)
03.05.04Replay-Resistant Authentication
Controls: IAM-02
Not passingNot currentNot approved(8 h ago)
03.05.05Identifier Management
Controls: IAM-07
Not passingCurrentNot approved(29 d ago)
03.05.07Password Management
Controls: IAM-01, IAM-03, IAM-08
PassingNot currentNot approved(8 h ago)
03.05.11Authentication Feedback
Controls: IAM-01
PassingCurrentNot approved(29 d ago)
03.05.12Authenticator Management
Controls: IAM-03, IAM-08
PassingNot currentNot approved(8 h ago)
03.06 Incident Response
03.06.01Incident Handling
Controls: BIZ-02, BIZ-03
PassingNot currentNot approved(8 h ago)
03.06.02Incident Monitoring, Reporting, and Response Assistance
Controls: BIZ-02, BIZ-03, BIZ-13
PassingNot currentNot approved(8 h ago)
03.06.03Incident Response Testing
Controls: BIZ-21
PassingCurrentApproved(4 mo ago)
03.06.04Incident Response Training
Controls: BIZ-21
PassingCurrentApproved(4 mo ago)
03.06.05Incident Response Plan
Controls: BIZ-02
PassingNot currentNot approved(3 mo ago)
03.07 Maintenance
03.07.04Maintenance ToolsUnmappedUnmappedUnmappedNot yet
03.07.05Nonlocal Maintenance
Controls: IAM-02, MON-02
Not passingNot currentNot approved(8 h ago)
03.07.06Maintenance PersonnelUnmappedUnmappedUnmappedNot yet
03.08 Media Protection
03.08.01Media Storage
Controls: IT-02
Not passingNot currentApprovedNot yet
03.08.02Media AccessUnmappedUnmappedUnmappedNot yet
03.08.03Media Sanitization
Controls: DATA-05
PassingNot currentNot approvedNot yet
03.08.04Media Marking
Controls: DATA-01
PassingNot currentNot approvedNot yet
03.08.05Media Transport
Controls: IT-02, IT-04
Not passingNot currentNot approvedNot yet
03.08.07Media UseUnmappedUnmappedUnmappedNot yet
03.08.09System Backup - Cryptographic Protection
Controls: DATA-02, DATA-13
PassingNot currentNot approved(29 d ago)
03.09 Personnel Security
03.09.01Personnel Screening
Controls: PEOPLE-01
Not passingCurrentNot approved(4 mo ago)
03.09.02Personnel Termination and Transfer
Controls: PEOPLE-03
PassingCurrentNot approved(8 h ago)
03.10 Physical Protection
03.10.01Physical Access Authorizations
Controls: PHYS-01
PassingNot currentNot approvedNot yet
03.10.02Monitoring Physical Access
Controls: PHYS-01
PassingNot currentNot approvedNot yet
03.10.06Alternate Work SiteUnmappedUnmappedUnmappedNot yet
03.10.07Physical Access Control
Controls: PHYS-01
PassingNot currentNot approvedNot yet
03.10.08Access Control for Transmission
Controls: PHYS-01
PassingNot currentNot approvedNot yet
03.11 Risk Assessment
03.11.01Risk Assessment
Controls: BIZ-04, BIZ-05
PassingNot currentNot approved(4 mo ago)
03.11.02Vulnerability Monitoring and Scanning
Controls: MON-05, MON-06
Not passingNot currentNot approved(3 mo ago)
03.11.04Risk Response
Controls: BIZ-04, BIZ-05, BIZ-09
PassingNot currentNot approved(4 mo ago)
03.12 Security Assessment and Monitoring
03.12.01Security Assessment
Controls: BIZ-08, MON-04
Not passingNot currentNot approved(8 h ago)
03.12.02Plan of Action and Milestones
Controls: BIZ-09
PassingNot currentApprovedNot yet
03.12.03Continuous Monitoring
Controls: MON-03
Not passingNot currentNot approved(3 mo ago)
03.12.05Information Exchange
Controls: CUST-02, VEND-02
PassingNot currentNot approvedNot yet
03.13 System and Communications Protection
03.13.01Boundary Protection
Controls: CLOUD-03
PassingNot currentApprovedNot yet
03.13.04Information in Shared System ResourcesUnmappedUnmappedUnmappedNot yet
03.13.06Network Communications - Deny by Default - Allow by Exception
Controls: CLOUD-03
PassingNot currentApprovedNot yet
03.13.08Transmission and Storage Confidentiality
Controls: CLOUD-01, DATA-02, DATA-03
PassingNot currentNot approved(8 h ago)
03.13.09Network DisconnectUnmappedUnmappedUnmappedNot yet
03.13.10Cryptographic Key Establishment and ManagementUnmappedUnmappedUnmappedNot yet
03.13.11Cryptographic Protection
Controls: DATA-06
Not passingNot currentNot approvedNot yet
03.13.12Collaborative Computing Devices and ApplicationsUnmappedUnmappedUnmappedNot yet
03.13.13Mobile CodeUnmappedUnmappedUnmappedNot yet
03.13.15Session Authenticity
Controls: DATA-03
PassingCurrentNot approved(8 h ago)
03.14 System and Information Integrity
03.14.01Flaw Remediation
Controls: CLOUD-05, IT-03, MON-06
Not passingNot currentNot approved(8 h ago)
03.14.02Malicious Code ProtectionUnmappedUnmappedUnmappedNot yet
03.14.03Security Alerts, Advisories, and DirectivesUnmappedUnmappedUnmappedNot yet
03.14.06System Monitoring
Controls: MON-01, MON-03
Not passingNot currentNot approved(3 mo ago)
03.14.08Information Management and Retention
Controls: DATA-04, DATA-05
PassingNot currentNot approvedNot yet
03.15 Planning
03.15.01Policy and Procedures
Controls: BIZ-14
PassingNot currentNot approvedNot yet
03.15.02System Security PlanUnmappedUnmappedUnmappedNot yet
03.15.03Rules of Behavior
Controls: IT-01, PEOPLE-04
PassingNot currentApproved(4 mo ago)
03.16 System and Services Acquisition
03.16.01Security Engineering PrinciplesUnmappedUnmappedUnmappedNot yet
03.16.02Unsupported System ComponentsUnmappedUnmappedUnmappedNot yet
03.16.03External System Services
Controls: VEND-02, VEND-03, VEND-04
Not passingNot currentNot approved(8 h ago)
03.17 Supply Chain Risk Management
03.17.01Supply Chain Risk Management PlanUnmappedUnmappedUnmappedNot yet
03.17.02Acquisition Strategies, Tools, and Methods
Controls: VEND-03
PassingNot currentNot approvedNot yet
03.17.03Supply Chain Requirements and Processes
Controls: VEND-02, VEND-04
Not passingNot currentNot approved(8 h ago)
NIST SP 800-171 Rev. 3 readiness · FintastIQ Trust Center