NIST SP 800-171 Rev. 3
Version: Revision 3 (May 2024)
NIST requirements for protecting the confidentiality of Controlled Unclassified Information (CUI) in nonfederal systems and organizations, such as federal contractors and subcontractors. Revision 3 has 97 active requirements in 17 families, many with organization-defined parameters.
Where we stand
Controls
62%
Evidence
19%
Policies
19%
66 of 97 clauses mapped to adopted controls · 1 known gap
As of (just now)
Percentages are over clauses mapped to at least one adopted control. Unmapped clauses are listed below and never count as passing. A known gap is a clause that applies to us and that no control covers yet.
Clause-by-clause readiness
| Clause | Title | Controls | Evidence | Policies | Last tested |
|---|---|---|---|---|---|
| 03.01 Access Control | |||||
| 03.01.01 | Account Management Controls: IAM-01, IAM-07, IAM-09 | Not passing | Current | Not approved | (29 d ago) |
| 03.01.02 | Access Enforcement Controls: IAM-01, IAM-04, IAM-05 | Passing | Not current | Not approved | (29 d ago) |
| 03.01.03 | Information Flow Enforcement | Unmapped | Unmapped | Unmapped | Not yet |
| 03.01.04 | Separation of Duties Controls: BIZ-15, PDP-05 | Passing | Not current | Not approved | (29 d ago) |
| 03.01.05 | Least Privilege Controls: IAM-04, IAM-06, IAM-09 | Passing | Not current | Not approved | (29 d ago) |
| 03.01.06 | Least Privilege - Privileged Accounts Controls: IAM-06 | Passing | Current | Not approved | (29 d ago) |
| 03.01.07 | Least Privilege - Privileged Functions Controls: IAM-05, IAM-06, MON-02 | Passing | Not current | Not approved | (29 d ago) |
| 03.01.08 | Unsuccessful Logon Attempts | Unmapped | Unmapped | Unmapped | Not yet |
| 03.01.09 | System Use Notification | Known gap | Known gap | Known gap | Not yet |
| 03.01.10 | Device Lock | Unmapped | Unmapped | Unmapped | Not yet |
| 03.01.11 | Session Termination | Unmapped | Unmapped | Unmapped | Not yet |
| 03.01.12 | Remote Access Controls: IAM-01, IAM-02 | Not passing | Not current | Not approved | (8 h ago) |
| 03.01.16 | Wireless Access | Unmapped | Unmapped | Unmapped | Not yet |
| 03.01.18 | Access Control for Mobile Devices Controls: IT-02 | Not passing | Not current | Approved | Not yet |
| 03.01.20 | Use of External Systems Controls: VEND-03 | Passing | Not current | Not approved | Not yet |
| 03.01.22 | Publicly Accessible Content Controls: DATA-01 | Passing | Not current | Not approved | Not yet |
| 03.02 Awareness and Training | |||||
| 03.02.01 | Literacy Training and Awareness Controls: PEOPLE-06 | Not passing | Current | Approved | (8 h ago) |
| 03.02.02 | Role-Based Training | Unmapped | Unmapped | Unmapped | Not yet |
| 03.03 Audit and Accountability | |||||
| 03.03.01 | Event Logging Controls: MON-01, MON-02 | Not passing | Not current | Not approved | (3 mo ago) |
| 03.03.02 | Audit Record Content | Unmapped | Unmapped | Unmapped | Not yet |
| 03.03.03 | Audit Record Generation Controls: MON-01, MON-02 | Not passing | Not current | Not approved | (3 mo ago) |
| 03.03.04 | Response to Audit Logging Process Failures | Unmapped | Unmapped | Unmapped | Not yet |
| 03.03.05 | Audit Record Review, Analysis, and Reporting Controls: MON-01, MON-03 | Not passing | Not current | Not approved | (3 mo ago) |
| 03.03.06 | Audit Record Reduction and Report Generation Controls: MON-01, MON-03 | Not passing | Not current | Not approved | (3 mo ago) |
| 03.03.07 | Time Stamps | Unmapped | Unmapped | Unmapped | Not yet |
| 03.03.08 | Protection of Audit Information | Unmapped | Unmapped | Unmapped | Not yet |
| 03.04 Configuration Management | |||||
| 03.04.01 | Baseline Configuration Controls: CLOUD-02 | Passing | Current | Approved | (29 d ago) |
| 03.04.02 | Configuration Settings Controls: CLOUD-04 | Passing | Not current | Approved | Not yet |
| 03.04.03 | Configuration Change Control Controls: PDP-02, PDP-03 | Not passing | Not current | Not approved | (8 h ago) |
| 03.04.04 | Impact Analyses Controls: PDP-14 | Passing | Current | Approved | (4 mo ago) |
| 03.04.05 | Access Restrictions for Change Controls: PDP-05, PDP-06 | Passing | Current | Not approved | (29 d ago) |
| 03.04.06 | Least Functionality Controls: CLOUD-03, CLOUD-04 | Passing | Not current | Approved | Not yet |
| 03.04.08 | Authorized Software - Allow by Exception | Unmapped | Unmapped | Unmapped | Not yet |
| 03.04.10 | System Component Inventory Controls: IT-04, IT-05 | Passing | Not current | Not approved | Not yet |
| 03.04.11 | Information Location | Unmapped | Unmapped | Unmapped | Not yet |
| 03.04.12 | System and Component Configuration for High-Risk Areas | Unmapped | Unmapped | Unmapped | Not yet |
| 03.05 Identification and Authentication | |||||
| 03.05.01 | User Identification and Authentication Controls: IAM-01, IAM-02 | Not passing | Not current | Not approved | (8 h ago) |
| 03.05.02 | Device Identification and Authentication | Unmapped | Unmapped | Unmapped | Not yet |
| 03.05.03 | Multi-Factor Authentication Controls: IAM-02 | Not passing | Not current | Not approved | (8 h ago) |
| 03.05.04 | Replay-Resistant Authentication Controls: IAM-02 | Not passing | Not current | Not approved | (8 h ago) |
| 03.05.05 | Identifier Management Controls: IAM-07 | Not passing | Current | Not approved | (29 d ago) |
| 03.05.07 | Password Management Controls: IAM-01, IAM-03, IAM-08 | Passing | Not current | Not approved | (8 h ago) |
| 03.05.11 | Authentication Feedback Controls: IAM-01 | Passing | Current | Not approved | (29 d ago) |
| 03.05.12 | Authenticator Management Controls: IAM-03, IAM-08 | Passing | Not current | Not approved | (8 h ago) |
| 03.06 Incident Response | |||||
| 03.06.01 | Incident Handling Controls: BIZ-02, BIZ-03 | Passing | Not current | Not approved | (8 h ago) |
| 03.06.02 | Incident Monitoring, Reporting, and Response Assistance Controls: BIZ-02, BIZ-03, BIZ-13 | Passing | Not current | Not approved | (8 h ago) |
| 03.06.03 | Incident Response Testing Controls: BIZ-21 | Passing | Current | Approved | (4 mo ago) |
| 03.06.04 | Incident Response Training Controls: BIZ-21 | Passing | Current | Approved | (4 mo ago) |
| 03.06.05 | Incident Response Plan Controls: BIZ-02 | Passing | Not current | Not approved | (3 mo ago) |
| 03.07 Maintenance | |||||
| 03.07.04 | Maintenance Tools | Unmapped | Unmapped | Unmapped | Not yet |
| 03.07.05 | Nonlocal Maintenance Controls: IAM-02, MON-02 | Not passing | Not current | Not approved | (8 h ago) |
| 03.07.06 | Maintenance Personnel | Unmapped | Unmapped | Unmapped | Not yet |
| 03.08 Media Protection | |||||
| 03.08.01 | Media Storage Controls: IT-02 | Not passing | Not current | Approved | Not yet |
| 03.08.02 | Media Access | Unmapped | Unmapped | Unmapped | Not yet |
| 03.08.03 | Media Sanitization Controls: DATA-05 | Passing | Not current | Not approved | Not yet |
| 03.08.04 | Media Marking Controls: DATA-01 | Passing | Not current | Not approved | Not yet |
| 03.08.05 | Media Transport Controls: IT-02, IT-04 | Not passing | Not current | Not approved | Not yet |
| 03.08.07 | Media Use | Unmapped | Unmapped | Unmapped | Not yet |
| 03.08.09 | System Backup - Cryptographic Protection Controls: DATA-02, DATA-13 | Passing | Not current | Not approved | (29 d ago) |
| 03.09 Personnel Security | |||||
| 03.09.01 | Personnel Screening Controls: PEOPLE-01 | Not passing | Current | Not approved | (4 mo ago) |
| 03.09.02 | Personnel Termination and Transfer Controls: PEOPLE-03 | Passing | Current | Not approved | (8 h ago) |
| 03.10 Physical Protection | |||||
| 03.10.01 | Physical Access Authorizations Controls: PHYS-01 | Passing | Not current | Not approved | Not yet |
| 03.10.02 | Monitoring Physical Access Controls: PHYS-01 | Passing | Not current | Not approved | Not yet |
| 03.10.06 | Alternate Work Site | Unmapped | Unmapped | Unmapped | Not yet |
| 03.10.07 | Physical Access Control Controls: PHYS-01 | Passing | Not current | Not approved | Not yet |
| 03.10.08 | Access Control for Transmission Controls: PHYS-01 | Passing | Not current | Not approved | Not yet |
| 03.11 Risk Assessment | |||||
| 03.11.01 | Risk Assessment Controls: BIZ-04, BIZ-05 | Passing | Not current | Not approved | (4 mo ago) |
| 03.11.02 | Vulnerability Monitoring and Scanning Controls: MON-05, MON-06 | Not passing | Not current | Not approved | (3 mo ago) |
| 03.11.04 | Risk Response Controls: BIZ-04, BIZ-05, BIZ-09 | Passing | Not current | Not approved | (4 mo ago) |
| 03.12 Security Assessment and Monitoring | |||||
| 03.12.01 | Security Assessment Controls: BIZ-08, MON-04 | Not passing | Not current | Not approved | (8 h ago) |
| 03.12.02 | Plan of Action and Milestones Controls: BIZ-09 | Passing | Not current | Approved | Not yet |
| 03.12.03 | Continuous Monitoring Controls: MON-03 | Not passing | Not current | Not approved | (3 mo ago) |
| 03.12.05 | Information Exchange Controls: CUST-02, VEND-02 | Passing | Not current | Not approved | Not yet |
| 03.13 System and Communications Protection | |||||
| 03.13.01 | Boundary Protection Controls: CLOUD-03 | Passing | Not current | Approved | Not yet |
| 03.13.04 | Information in Shared System Resources | Unmapped | Unmapped | Unmapped | Not yet |
| 03.13.06 | Network Communications - Deny by Default - Allow by Exception Controls: CLOUD-03 | Passing | Not current | Approved | Not yet |
| 03.13.08 | Transmission and Storage Confidentiality Controls: CLOUD-01, DATA-02, DATA-03 | Passing | Not current | Not approved | (8 h ago) |
| 03.13.09 | Network Disconnect | Unmapped | Unmapped | Unmapped | Not yet |
| 03.13.10 | Cryptographic Key Establishment and Management | Unmapped | Unmapped | Unmapped | Not yet |
| 03.13.11 | Cryptographic Protection Controls: DATA-06 | Not passing | Not current | Not approved | Not yet |
| 03.13.12 | Collaborative Computing Devices and Applications | Unmapped | Unmapped | Unmapped | Not yet |
| 03.13.13 | Mobile Code | Unmapped | Unmapped | Unmapped | Not yet |
| 03.13.15 | Session Authenticity Controls: DATA-03 | Passing | Current | Not approved | (8 h ago) |
| 03.14 System and Information Integrity | |||||
| 03.14.01 | Flaw Remediation Controls: CLOUD-05, IT-03, MON-06 | Not passing | Not current | Not approved | (8 h ago) |
| 03.14.02 | Malicious Code Protection | Unmapped | Unmapped | Unmapped | Not yet |
| 03.14.03 | Security Alerts, Advisories, and Directives | Unmapped | Unmapped | Unmapped | Not yet |
| 03.14.06 | System Monitoring Controls: MON-01, MON-03 | Not passing | Not current | Not approved | (3 mo ago) |
| 03.14.08 | Information Management and Retention Controls: DATA-04, DATA-05 | Passing | Not current | Not approved | Not yet |
| 03.15 Planning | |||||
| 03.15.01 | Policy and Procedures Controls: BIZ-14 | Passing | Not current | Not approved | Not yet |
| 03.15.02 | System Security Plan | Unmapped | Unmapped | Unmapped | Not yet |
| 03.15.03 | Rules of Behavior Controls: IT-01, PEOPLE-04 | Passing | Not current | Approved | (4 mo ago) |
| 03.16 System and Services Acquisition | |||||
| 03.16.01 | Security Engineering Principles | Unmapped | Unmapped | Unmapped | Not yet |
| 03.16.02 | Unsupported System Components | Unmapped | Unmapped | Unmapped | Not yet |
| 03.16.03 | External System Services Controls: VEND-02, VEND-03, VEND-04 | Not passing | Not current | Not approved | (8 h ago) |
| 03.17 Supply Chain Risk Management | |||||
| 03.17.01 | Supply Chain Risk Management Plan | Unmapped | Unmapped | Unmapped | Not yet |
| 03.17.02 | Acquisition Strategies, Tools, and Methods Controls: VEND-03 | Passing | Not current | Not approved | Not yet |
| 03.17.03 | Supply Chain Requirements and Processes Controls: VEND-02, VEND-04 | Not passing | Not current | Not approved | (8 h ago) |
