NIST SP 800-171 Rev 3
Protecting Controlled Unclassified Information (CUI) in non-federal systems. 14 control families with 110+ requirements.
Limit system access to authorized users and processes.
Ensure personnel are trained on CUI handling and security risks.
Create, protect, and review audit records.
Establish and maintain baseline configurations.
Identify users and authenticate identities.
Establish operational incident-handling capability.
Perform maintenance on organizational systems.
Protect CUI on system media, both digital and paper.
Screen individuals before granting access to CUI.
Limit physical access to systems handling CUI.
Periodically assess risks to CUI.
Periodically assess security controls.
Monitor and protect communications and system boundaries.
Identify and remediate flaws in a timely manner.