NIST 171 Compliance: The NIST Special Publication 171 series, (DFARS) 7012, and Cybersecurity Maturity Model Certification – Regulating Protected Controlled Unclassified Information

Suppose you are a nonfederal service provider whose offering might involve handling Controlled Unclassified Information (CUI). Up till now, it might not have been an issue. Still, suddenly either your Government Contract Management Officer or an upstream distributor for one of your products has informed you that your contracts and work orders won’t move forward till your offering is listed in the DoD Supplier Performance Review System as having passed NIST 171. Now what?

This paper explains what you need to know about the NIST SP 800-171 Assessment Methodology and its use in demonstrating adequate security as detailed in the recently updated DFARS clause 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting. [i]

Whether, for example, you manufacture a Cloud Product,[ii] or you develop software or architect any part of the environment that enables those products, you would most certainly want your offering to be listed with the Government Services Administration[iii] with access to GSA’s 30+ Billion dollar Federal Market Place.[iv] Among the many Agencies of the Federal Government, the Department of Defense (DoD) is the largest, having oversight to all contractors and acquisitions. All suppliers will engage in the DoD NIST 800-171 Assessment. Let’s talk about why that is and what that means.

There are misperceptions about what types of products and services present sufficient risk to mandate their participation in DoD NIST SP 800-171 Assessment Methodology. There are exceptions for COTS products, but DoD Cybersecurity Activities regulation has long established that “cyber threats to contractor unclassified information systems represent an unacceptable risk of compromise of DoD information and pose an imminent threat to U.S. national security and economic security interests.”[v] In other words, even when that information is unclassified, the breach of information causes significant harm and therefore must be that information must be controlled and protected.

Suppose you’ve already started a NIST 800-171 Compliance process. In that case, you likely know, depending on the scope of the data you might handle and the Federal v. Non-Federal Networks over which that data is transferred or stored, that earning a contract for your custom-built goods and services has become significantly more complicated. Before acquisition and throughout its use, any product or service used to process, store, or transmit Protected Controlled Unclassified Information (CUI) is subject to The Interim Defense Federal Acquisition Regulation Supplement (DFARS) Rule, 2019-D041Requirements. [ Assessing Contractor Implementation of Cybersecurity Requirements. [vi]

In short, DFARS Rule 2019-D041 means that US Federal Agencies cannot award your contract unless you’ve met with the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 DoD Assessment Methodology and have validated that assessment either by a Self-Reported, Supplier Performance Risk System (SPRS) score, or, as certified by a DoD accredited assessor (third party) using the prescribed Cybersecurity Maturity Model Certification (CMMC) Framework. [vii]

Government Files


To understand the elements covered by NIST 171, DFARS 252.204-7012, and CMMC, this article will cover three broad areas.

  • Part I: The history of CUI, regulatory bodies FARS, DFARS, and USD(A&S), recent changes to The Interim DFARS Rule, and DoD Certification guidance, now (CMMC 2.0).
  • Part II: NIST SP 800-171 includes NIST SP 800-171A, and NIST SP 800-172, related standards representing the foundation and methods for scoping, tailoring, and selection of NIST 171 security requirements. These related standards are FIPS PUB 199 & FIPS PUB 200, and NIST SP 800-53 & NIST SP 800-53B (soon to be 800-53C).
  • Part III: NIST 171 Assessment as mandated by DFARS and addressed by the Cybersecurity Maturity Model Certificate (CMMC) DoD certification, with model details to assist in building functional GRC to manage the data elements in the assessment.

You may be wondering if there's a cheat sheet based on your compliance role. I don't think so, but just to be certain, here's a summary of what I think you need to know based on the role you might play. If that's not a concern, go right ahead and jump to Part I.

Our Roles in Understanding What Seems to be Redundant

The proliferation of partially correct online information is confusing. If you’ve been researching this topic, the terms NIST SP 800-171 DoD Assessment Methodology, CMMC Certification, and DFARS 252.204-7012 Strategically Implementing Cybersecurity Contract Clauses are strewn about and used nearly interchangeably. Understanding the three main elements, the standards, the regulations, the governing audit body, and guidance, begins with defining our role as, for example, the Supplier’s Internal Compliance Professional, a DoD Assessor, as Legal or Executive Management for the Offering, or as DCMA contract administration.

Security and Compliance Professionals: For Security and Compliance Professionals, a challenge to anyone’s understanding of NIST SP 800- 171 compliance is the relationship it shares with several critical frameworks representing the Foundation of Assessment and the Catalog of Controls that feed into a broader spectrum of Federal compliances. Another challenge is if the Department of Defense (DoD) Cybersecurity Maturity Model Certification, CMMC, uses different words meant to connect and translate into a measurable program the array of NIST Special Publications 171r2, 171A, 172, and the NIST Handbook 162. Good News. It is.

DoD Contract Officer and DCMA: The multiple provisions and clauses in DFARS guidance mainly pertain to the responsibilities of the DoD Contract Officer, to Compliance Program Management, and for operations of the Defense Contract Management Agency. DFARS is written for those agencies and the assessors who oversee their implementation. Vendors should read and understand the clauses and provisions of DFARS to assure they are handled fairly.

DoD Certified Assessor: The current CMMC model is redundant and identical to NIST SP 800-171 Methodologies and serves as Audit Guidance for the DoD Certified Assessor. For professionals who are not required to use a CMMC third-party assessor, and where the Basic and Moderate Assessments only need them to self-report the Basic or Basic plus Derived 110 security requirements into the SPRS, their review of the CMMC 2.0 may be entirely bypassed. (See Table 1 – Minimum Knowledge)

Certified Assessors will reference the vendor-supplied information in the SPRS and interpret that content according to the DoD-certified Assessor guidance, as noted in the following table across rows for Compliance professionals for Medium and High Assessment.

Table 1- Minimum Knowledge Requirement Based on User Role – Note *CMMC Rule is due to reissue in 2022, CMMC Level 3 guidance to follow soon after. The generally accepted expectation is that CMMC Level 3 will implement NIST SP 800-172.

Domains of Knowledge to the Right

NIST Frameworks (The SP-800 series)

DFARS Guidance 

Certified Assessor Requirement Level

Use Case Below

NIST 171, 171A-Low, 171A-Medium, 171A-High, 172, DoD NIST 171 Assessment MethodologyNIST.HB.162 Assessors Handbook

DFARS 2019-D041, DFARS 252.204-7012, DFARS 252.204-7019, DFARS provision 252.204-7008, *CMMC Rule

CMMC L1, L2, L3, CMMC L1 Scoping Guide, CMMC L2 Scoping Guide, SPRS-Basic, SPRS-Derived, DoD NIST 171 Assessment Methodology, NIST.HB.162 Assessors Handbook

?‍?Compliance Professionals – Basic Assessment

NIST 171, 171A-Low, NIST.HB.162 Assessors Handbook (for low)

DFARS 252.204-7012

SPRS, DoD NIST 171 Assessment Methodology, NIST.HB.162 Assessors Handbook

?️‍♀️Compliance Professionals – Medium Assessment

NIST 171, 171A-Medium, NIST.HB.162 Assessors Handbook

DFARS 252.204-7012

SPRS, DoD NIST 171 Assessment Methodology, NIST.HB.162 Assessors Handbook, CMMC L2, CMMC Level 2 Scoping Guide

?‍?Compliance Professionals – High Assessment

NIST 171, 171A-High, 172, NIST.HB.162 Assessors Handbook

DFARS 252.204-7012, DFARS 252.204-7019, *CMMC Rule

CMMC L1, L2, L3 (content is the same as NIST 172), NIST.HB.162 Assessors Handbook

?‍?Assessors – externally accredited, DoD certified NIST

NIST 171, 171A-all, 172, NIST.HB.162 Assessors Handbook

DFARS 2019-D041, DFARS 252.204-7012, DFARS 252.204-7019, *CMMC Rule

CMMC L1, L2, L3, SPRS-Basic, and Derived, NIST.HB.162 Assessors Handbook

?‍♂️Executives / Legal

NIST 171 (Chapter 3)

DFARS 2019-D041, DFARS 252.204-7012

N/A

?‍⚖️DCMA (Contract Administrator)

DoD NIST 171 Assessment Methodology

DFARS 2019-D041, DFARS 252.204-7012 DFARS 252.204-7019

SPRS System – Review system results as provided by an assessor

 


Part I: The History of Protecting CUI

Understanding Controlled Unclassified Information

U.S. federal government agencies generate, use, store, and share Controlled Unclassified Information (CUI) that, while not meeting the threshold for classification as national security or atomic energy information, requires protection from unauthorized access and dissemination.

Organizations responsible for correctly managing CUI include:

  • Government contractors
  • Universities and research institutions
  • Consulting companies
  • Service providers
  • Manufacturing companies that work on contracts for government agencies

Protecting CUI that resides in nonfederal systems and organizations directly impacts the ability of the federal government to conduct essential missions and functions.

The security requirements are intended for use by federal agencies in contractual vehicles or other agreements established between those agencies and nonfederal vendors, consultants, or third parties.  The recommended protection requirements apply to all components of nonfederal systems and organizations that process, store, or transmit CUI or that safeguard such components.

The Problem: Lack of Standardization

Before establishing standards for Controlled Unclassified Information (CUI), more than 100 agencies across United States federal executive departments* evolved their practices for sensitive unclassified information. This multitude of different standards resulted in loosely and sometimes incoherently connected systems. The problems caused by inconsistent definitions and labeling, the lack of a consistent CUI program, and marking resulted in incorrect sharing and improper archiving of important information. Fortunately, the Final rule, 32 CFR Part 2002 Controlled Unclassified Information, came into effect November 14, 2016.

The Solution: Executive Order 13556 "Controlled Unclassified Information”

To address incorrect sharing and archiving of critical data, Final rule, 32 CFR Part 2002 Controlled Unclassified Information, came into effect November 14, 2016.

Executive Order 13556, Controlled Unclassified Information [viii] (the Order) establishes a program for managing CUI across the Executive branch and designates the National Archives and Records Administration (NARA) as Executive Agent to implement the Order and oversee agency actions to ensure compliance. The Archivist of the United States delegated these responsibilities to the Information Security Oversight Office (ISOO).

32 CFR Part 2002 Controlled Unclassified Information issued by ISOO to establish policy for agencies on designating, safeguarding, disseminating, marking, decontrolling, and disposing of CUI, self-inspection, and oversight requirements, and other facets of the Program. The rule affects Federal executive branch agencies that handle CUI and all organizations (sources) that handle, possess, use, share, or receive CUI—or operate, service, or have access to Federal information and information systems on behalf of an agency. Controlled Unclassified Information (CUI) is any (not already classified) information upon which law, regulation, or governmentwide policy requires safeguarding or disseminating controls.

OUS(A&D) Offices of Government

To learn more, visit DOD Mandatory Controlled Unclassified Information (CUI) Training (usalearning.gov) [ix]


Requirements for NIST 171 Assessments via SPRS and CMMC

The Defense Federal Acquisition Regulation Supplement, or DFARS, raises stakes on U.S. Department of Defense (DoD) contractors who must comply with NIST frameworks, including Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations. DFARS Clause 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, is DFARS' latest mandatory addition. DFARS Clause 252.204-7012 [DFARS 7012] requires government contractors and suppliers to comply with NIST SP 800-171 SP 800-171 and to Self-Report a compliance score via the Supplier Performance Risk System (SPRS) [x]

The DFARS interim rule went into effect on November 30th, 2020, implementing a five-year strategy intended to minimize the financial impacts to the Defense Industrial Base (DIB) and disruption to the existing DoD supply chain. [xi]

Per the DFARS Interim Rule DoD, all contracts require that contractors perform at least the NIST 800-171 Basic Assessment and submit a score to the Supplier Performance Risk System (SPRS), along with the required documents POA&MS and System Security Plan (SSP) [xii], as a condition for contract award. Once the initial SPRS record has undergone review, the DoD will ask some contractors to conduct a NIST 800-171 Medium Assessment or High Assessment, conducted with oversight by DoD-trained DoD personnel.

SPRS is a Web-enabled, Department of Defense enterprise-wide application, which operates as the Defense Federal Acquisition Regulation Supplement (DFARS) primary retrieval system for supplier performance information. To gain an understanding of the extended scope of entities identified as part of the Defense Industrial Base (DOB), visit Defense Primer: U.S. Defense Industrial Base (congress.gov)

Safeguarding Covered Defense Information (CDI)

Covered Defense Information (CDI): Is a term defined in the DFAR clause 252.204-7012 Safeguarding Covered Defense Information, as unclassified controlled technical information or other information, as described in the Controlled Unclassified Information (CUI) registry that requires safeguarding or dissemination controls under and consistent with law, regulations and government-wide policies and is (1) Marked or otherwise identified in a contract, task order or delivery order on behalf of the DoD in support of the performance of a contract or (2) collected, developed, received, transmitted, used or stored by or on behalf of the contractor in support of the performance of the contract.[xiii] To learn more, review Becoming DFARS/NIST Compliant (Cybersecurity) PowerPoint Presentation (defense.gov)

DFARS Clause 252.204-7012 requires contractors and subcontractors to

  1. Provide adequate security to safeguard covered defense information that resides on or is transiting through a contractor’s internal information system or network
  2. Report cyber incidents that affect a covered contractor information system or the covered defense information residing therein or that affect the contractor’s ability to perform requirements designated as operationally critical support
  3. Submit malicious software discovered and isolated in connection with a reported cyber incident to the DoD Cyber Crime Center
  4. Submit media (if requested) and additional information to support a damage assessment
  5. Flow down the clause in subcontracts for operationally critical support or for which subcontract performance will involve covered defense information. [xiv]

Cybersecurity Maturity Model Certification (CMMC) Program (U.S. Department of Defense)

Undersecretary of Defense for Acquisition and SustainmentCMMC stands for “Cybersecurity Maturity Model Certification.” The CMMC will encompass multiple maturity levels that range from “Basic Cybersecurity Hygiene” to “Advanced/Progressive.” The intent is to incorporate CMMC into Defense Federal Acquisition Regulation Supplement (DFARS) and use it as a requirement for contract award.

CMMC-AB stands for “Cybersecurity Maturity Model Certification Accreditation Body.” The CMMC-AB establishes and oversees a qualified, trained, high-fidelity community of assessors that can deliver consistent and informative assessments to participating organizations against a defined set of controls/best practices within the Cybersecurity Maturity Model Certification (CMMC) Program.

The CMMC program includes cyber protection standards for companies in the defense industrial base (DIB). By incorporating cybersecurity standards into acquisition programs, CMMC provides the Department with assurance that contractors and subcontractors meet DoD’s cybersecurity requirements. The DIB targets increasingly frequent and complex cyberattacks by adversaries and non-state actors. Dynamically enhancing DIB cybersecurity to meet these evolving threats and safeguarding the information that supports and enables our warfighters is a top priority for the Department. CMMC is a critical component of the Department’s extensive DIB cybersecurity effort. (Source Project Spectrum)

The Proposed Certification Standards or CMMC Levels and plans laid out by the CMMC Accreditation Body

The internal assessment of CMMC was co-chaired by: Mieke Eoyang, Deputy Assistant Secretary of Defense for Cyber Policy; David Frederick, Executive Director of U.S. Cyber Command; David McKeown, Deputy Chief Information Officer for Cybersecurity; and Jesse Salazar, Deputy Assistant Secretary of Defense for Industrial Policy; and included senior leaders from 18 components across the Department.[xiv] For up-to-the-minute information regarding CMMC approvals, visit https://www.acq.osd.mil/cmmc/index.html.

The CMMC-AB is an independent accreditation entity responsible for establishing, managing, controlling, and administering CMMC assessment, certification, training, and accreditation processes for the Defense Supply Chain according to a contract signed with the Department of Defense.

CMMC 2.0 has not released the Level Three requirement. Based on the November & December 2021 CMMC-AB Town Halls, the finalized certification is expected to appear in this graphic with one notable exception. [SP 800-171 has 31 “Basic Security Requirements” as opposed to the 17 “Practices” in CMMC 1.0. Based on the published standards for NIST SP 800-171 and 172, Figure 1 adjusts the totals for Basic and Derived to reflect the actual and current number of requirements relative to each level according to the DoD NIST 171 Assessment Methodology. A soon-to-release update to The Rule will enforce the CMMC 2.0 change.

The current DFARS CMMC Rule does not eliminate Self-Reported scoring via the Supplier Performance Risk System (SPRS). Presently, the minimum knowledge necessary to navigate the NIST 800 171 is the NIST SP 800-171 r2 plus its partner document NIST SP 800-171A, as measured according to the NIST SP 800-171 Assessment Methodology Version 1.2.1 6.24.2020.pdf (osd.mil) and reported to the SPRS.

CMMC Strategic Intent as of Dec 2021

Figure 1 Three Levels of CMMC now rely upon NIST 171 and NIST 172 Series

The Moving Target – CMMC Certifications and Securing the Defense Industrial Base CMMC 2.0

In response to the question, “What is the department’s intent regarding acceptance agreements between CMMC and other cybersecurity standards and assessments?” the answer from OUSD A&S - Cybersecurity Maturity Model Certification (CMMC) (osd.mil) [xiv]states:

“The Department is pursuing the development of acceptance standards between CMMC and other cybersecurity standards and assessments, including between CMMC Level 2 (Advanced) and the NIST SP 800-171 DoD Assessment Methodology for the high assessment confidence level, as well as CMMC Level 2 and the GSA Federal Risk and Authorization Management Program (FedRAMP) requirements for commercial cloud service offerings. Furthermore, DoD is working with international partners to coordinate potential agreements between CMMC and their respective cybersecurity programs.  Any such equivalencies or acceptance standards, if established, will be implemented as part of the rulemaking process.” [xvi]

The entirety of DFARS, CMMC, and NIST 171 is a lot to take in. Still, at its simplest, Vendors who handle CUI must understand that DFARS is a set of regulations that are satisfied by implementing a set of frameworks & standards (NIST 171 and 172 series) and are audited by a CMMC assessor according to the CMMC model that leverages all the parts of the NIST 800-171 Assessment Methodology. The Defense Federal Acquisition Regulation Supplement: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019–D041) added Subpart 204.75, Cybersecurity Maturity Model Certification (CMMC) to specify the policy and procedures for awarding a contract or exercising an option on a contract. This model includes determining the requirement (be it Level 1 - Basic or up to Level 3 - Expert) necessary for the Offeror’s CMMC certification. Specifically, this subpart directs contracting officers to verify in SPRS that the offeror’s CMMC certification is current and meets the required level before making the award.


Part II: Understanding NIST 171 - Protecting CUI

National Institute of Standards and Technology (NIST) Special Publication 800-171 Revision 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations SP 800-171 [xvii] and NIST SP 800-171A Assessing Security Requirements for Controlled Unclassified Information SP 800-171A [xviii] is the current prescribed program for working with nonfederal organizations and their data, or CUI.

They are Special Publications providing recommended requirements for protecting and assessing the confidentiality of controlled unclassified information (CUI) and are collectively considered the NIST 171 Assessment Methodology, which are

  • Created as part of NIST’s statutory responsibilities under the Federal Information Security Modernization Act (FISMA)[xix], 44 U.S.C. § 3551 et seq., Public Law (P.L.) 113-283 [xx]
  • Designed specifically for non-federal organizations that process, store, or transmit sensitive federal information.

NIST SP 800-171 Revision 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organization document should always be accessed from its corresponding NIST Computer Security Resource Center “CSRC” page. [xxi] When using the CSRC, give keen attention to the revision date, the related publications, and the other parts of this publication. Specifically, the NIST 171 has two parts, much like the SP 800-53 and its assessment model in [SP 800-53B]. Also highlighted are the Abstract, Keywords, and Control Families, important meta content used throughout the NIST OSCAL, and details necessary to automate any NIST content. [xxii]

Downloading current NIST 171

Figure 2 NIST SP 800-171 Rev 2 and Related NIST SP 800 172; Control Families FIPS PUB 200

Once downloaded, NIST documents follow a standard structure. The Requirements (Controls) are listed in section three. The following image (Figure 3) shows the NIST 171 security requirements, the necessary steps to prepare and manage a Plan of Action and Milestones (POA&M), and the System Security Plan (SSP). The POA&M and SSP, 3.12.4 and 3.12.2, are tested requirements and necessary processes to manage a CUI program. The image also shows conditions attributed as either a Basic Security Requirement or a Derived Security Requirement. Chapter Three introduces the relationship of NIST 171 to ISO 27001. This connection is critical to the SSP since the assessment package must include all related policies and procedures supporting the requirements. Still, NIST 171 is not a standard for developing an ISMS [xxiii] itself. (See Table 2 - Necessary Plans, Policies, and Procedures)

NIST SP 800 171R2 Chapter three

Figure 3- NIST 171r2 Requirements, POA&M and SSP, Mapping and Tailoring

NIST 171 Chapter Three explains that the standard derives controls from Special Publication 800-53 Revision 5, Security and Privacy Controls for Information Systems and Organizations [xxiv] and its accompanying assessment methodology, NIST Special Publication 800-53B, Control Baselines for Information Systems and Organizations.[xxv]  The relationships between these documents are noted within each requirement’s discussion and further detailed as the mapped controls in the Appendix Mapping Table. Note that the Mapping for this document preceded the final release of NIST 800-53r5 and the new FedRamp version 5 requirement. Companies should tailor their mapping with knowledge of the recommendations in Appendix E and authentic control selection based on their actual procedures and risk management. The mapping table is considered as a reference and starting point.

NIST 171 Mapping Table

Figure 4- NIST 171r2 Mapping Table: Appendix D

SP 800-171 and SP 800-171A comprise security requirements and related criteria for implementation and assessment. In addition to the NIST 171 series, NIST recently released the NIST Special Publication 800-172, Enhanced Security Requirements for Protecting Controlled Unclassified Information, A Supplement to NIST Special Publication 800-171.[xxvii] This standard addresses Expert requirements for Level 3 Cybersecurity Maturity Model Certificate (CMMC) DoD Certification.

NIST Compliance Standards and Their Relationship to Each Other

SP 800-171 comprises 31 Basic and 79 Derived Controls. Basic Requirements come from FIPS 200, Minimum Security Requirements for Federal Information and Information Systems, and the Derived Requirements come from NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations. Since the FIPS 200 requirements are fundamental, NIST refers to them as Basic. However, because FIPS 200 is a set of ‘minimum’ requirements, these are often insufficient to protect at the required “Moderate” impact level for covered defense information, CDI. When the Basic Requirement does not fully meet the “Moderate” requirement, related controls from the “Moderate” baseline in NIST SP 800-53 are specified and identified in NIST SP 800-171 as Derived Requirements (i.e., derived from NIST SP 800-53).[xxviii]

The [SP 800-53B] is an Assessment Model comprised of three baselines and a privacy baseline, with tailored recommendations according to the Standards for Security Categorization of Federal Information and Information Systems, [FIPS PUB 199] [xxviii] Using the FIPS 199, a low-impact, moderate impact, or high impact designation is assigned to each Control and Enhancement. Entities determine if their systems requirements align with completing a High, Medium, or Low baseline. [xxix]

The following figure shows the array of documents necessary to understand the NIST 171 Assessment Methodology, including the source of derived controls and the basis for tailoring and risk analysis.

NIST Documentation related to a NIST 171 Assessment

Figure 5 NIST Documentation for 800-53 and 800-171 series Supported by FIPS PUBS 199, 200, and NIST.HB-162 (Open in full window)

FIPS 199 and the Protection of Controlled Unclassified Information in Federal Systems

Per the federal CUI regulation, federal agencies using federal systems to process, store, or transmit CUI, at a minimum, must comply with the following standards. NIST 171 Assessment is tailored from this baseline of information.

Figure 6 FIPS Publication 199 Standards for Security Categorization, showing NIST 800-171 v NIST 800-53 and CMMC Level 3 for NIST 800-172


Control Families in Special Publications 800-171, 800-53 r5, 800-53B, and FIPS PUB 200

As the “minimum” security requirement for Federal Information and Information Systems, anyone who operates within compliance requires a general understanding of the FIPS PUB 200 control families. These are the “Minimum Requirements.” In comparison to the minimum requirements of FIPS 200, compliance professionals should compare these high-level control definitions with their evolution to [SP 800-53 r5] catalog, shown in Table 5 as the hyperlinked control family names that launch to their NIST online repository. Since 79 of the 110 controls are derived from [SP 800-53B Moderate], it is helpful to understand the full context of the NIST 171 requirement at its origin and with its relationships to other controls and reference materials.

The following 14 items are represented in NIST 800-171 control requirements. NIST continuously evolves its frameworks and related resources, so it is essential to use the online delivery mechanism when establishing your program. For example, as of April 2022, the [SP 800-53B moderate] is expected to modify again, adopting around 18 additional controls from the SP 800-53 r5 catalog. [xxx] Families introduced or significantly increased within Revision 5 of SP 800-53 include PM - PROGRAM MANAGEMENT, PT - PERSONALLY IDENTIFIABLE INFORMATION PROCESSING, AND TRANSPARENCY, and SR - SUPPLY CHAIN RISK MANAGEMENT.

AC – 3.1 ACCESS CONTROL
AT – 3.2 AWARENESS AND TRAINING
AU – 3.3 AUDIT AND ACCOUNTABILITY
CM – 3.4 CONFIGURATION MANAGEMENT
IA – 3.5 IDENTIFICATION AND AUTHENTICATION
IR – 3.6 INCIDENT RESPONSE
MA – 3.7 MAINTENANCE
MP – 3.8 MEDIA PROTECTION
PS – 3.9 PERSONNEL SECURITY
PE – 3.10 PHYSICAL AND ENVIRONMENTAL PROTECTION
RA – 3.11 RISK ASSESSMENT
CA – 3.12 SECURITY ASSESSMENT
SC – 3.13 SYSTEM AND COMMUNICATIONS PROTECTION
SI – 3.14 System and Information Integrity

Table 3 Control Families in NIST SP 800-171

FIPS PUB 200 Minimum Security Requirements

The following items are the FIPS 200 Control families are the Minimum-Security Requirements. There is an added note to indicate when the item is not called out as part of the NIST 171 CUI-based control requirements. <Read more: FIPS PUB 200 Minimum Security Requirements

800-53r5 Control Families

The following grid represents hyperlinked Control Families used for the NIST SP 800-53 Catalog and leveraged for the NIST SP 800-53B and NIST SP 800-171A assessment methodologies. Control Families CP Contingency Planning, PL Planning, PM Program Management, PT Personally Identifiable Information Processing and Transparency, SA System and Service Acquisition, and SR Supply Chain Risk Management are not directly mapped to the NIST 171 Assessment Methodology. It is recommended that anyone working with NIST Compliance familiarize themselves with all control families.

Table 4 Control Families in NIST 800-171 series and NIST 800-53 Series linked to CSRC NIST 800-53


SP 800-171 Tailoring Criteria as applied to SP 800-53 derived controls

“Tailoring” is most recognized about the scoping of FedRamp [SP 800-53B], however tailoring criteria used for SP 800-171 (listed below) accomplishes a different objective to tailor requirements exclusive necessary for CUI further. For Federal Information Systems, the [FIPS 199] impact assessment applied to the control families within [FIPS 200] and further elaborated as the catalog of SP 800-53 resulting in three “Baselines,” represented in [SP 800-53B] as “privacy,” “high,” “moderate,” and “low.” The design of the NIST 171 leverages the “moderate” control set with additional tailoring to exclude Integrity and Availability elements except where these principles would remove the system’s capability to protect the Confidentiality of Information.

One might ask why only 79 out 306 [SP 800-53B] moderate baseline controls and enhancements rated as “CUI, the basic or derived security requirement is reflected in and is traceable to the security control, control enhancement, or specific elements of the control/enhancement.” The summary and discussion about the selection of derived controls are shown in Appendix E Tailoring Criteria [SP 800-171r2]. The action of Tailoring does not endorse the elimination of controls. Tailoring prioritizes requirements based upon their suitability to the protection of CUI on non-federal systems from unauthorized disclosure.

The 14 out of 17 [FIPS 200] requirements each have one or more Basic security requirements assigned to them, notated as a triptych 3.#.#. However, because FIPS 200 is a set of “minimum” requirements, these are often insufficient to protect at the required “Moderate” impact level for covered defense information (CDI). Accordingly, when the Basic Requirement does not fully meet the “Moderate” requirement, related controls from the “Moderate” baseline in SP 800-53 are specified and identified in SP 800-171 as Derived Requirements (i.e., derived from SP 800-53).

All SP 800-171 requirements are required, expressed as Basic or Derived. DoD and Under Secretary of Defense for Acquisition and Sustainment OUSD(A&S) dictate each supplier’s required assessment level. For those organizations rated Level 1, compliance is achieved via annual Self-Reported SPRS, requiring a score for cybersecurity and adoption as sufficient to thwart cyber-attacks. The assessment aligns with all practices for organizations designated as Level 2 SP 800-171. Section 2.2 of SP 800-171 details the Basic Requirements from FIPS 200, Minimum Security Requirements for Federal Information and Information Systems, and the Derived requirements shaped from NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations. Tailoring notation for CUI is as follows.

TAILORING SYMBOL TAILORING CRITERIA
  • NCO not directly related to protecting the confidentiality of CUI.
  • FED is uniquely federal, primarily the responsibility of the federal government.
  • NFO is expected to be routinely satisfied by nonfederal organizations without specification.
  • CUI, the basic or derived security requirement is reflected in and is traceable to the security control, control enhancement, or specific elements of the control/enhancement.

The POA&M, and SSP

Maintaining a Plan of Action & Milestones (POA&M) and System Security Plan (SSP) is fundamental to all Federal Systems guidance. NIST 171 and CMMC require the POA&M, Plan of Action and Milestones, a document for a system that identifies tasks needing to be accomplished. Only recently associated with the DoD Assessment, the POA&M details resources required to achieve the plan’s elements, any milestones in meeting the tasks, and scheduled completion dates for the milestones. [xxxi]

Exclusive to Levels 2 and 3 of the CMMC, DoD, and the Office of the Under Secretary of Defense Acquisitions and Sustainment intend to allow companies to receive contract awards providing they have a Plan of Actions and Milestones (POA&M) in place, and it lists targets to complete any outstanding CMMC requirements. The Department intends to specify a baseline number of requirements that must be achieved before contract award and allow a remaining subset to be addressed in a POA&M within a clearly defined timeline. The Department also intends to specify a small subset of requirements that cannot be on a POA&M to achieve a CMMC certification. To learn more about the format and purpose of a POA&M, refer to the following guidelines and templates Integrating Cybersecurity and Enterprise Risk Management (ERM) (nist.gov) and CSP POAM Template Completion Guide (fedramp.gov). If designing an automated POA&M, use the NIST OSCAL Assessment Layer: Plan of Action and Milestones Model located at Plan of Action and Milestones Model (nist.gov).

The POA&M, as a control activity, is among the Derived security requirements. Whether the assessor is assigned internally to the organization or as a third party, the following elements are required to NIST SP 800-171 3.12.2, which is necessary to submit the assessment. This ongoing activity is part of a CUI program, and the POA&M is always required. (See Figure 10 Requirements for Scoring Guidance)

3.12.2

SECURITY REQUIREMENT

Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.

 

ASSESSMENT OBJECTIVE Determine if:

3.12.2[a]

deficiencies and vulnerabilities to be addressed by the plan of action are identified.

3.12.2[b]

a plan of action is developed to correct identified deficiencies and reduce or eliminate identified vulnerabilities.

3.12.2[c]

the plan of action is implemented to correct identified deficiencies and reduce or eliminate identified vulnerabilities.

POTENTIAL ASSESSMENT METHODS AND OBJECTS

Examine: [SELECT FROM: Security assessment and authorization policy; procedures addressing plan of action; system security plan; security assessment plan; security assessment report; security assessment evidence; plan of action; other relevant documents or records].

Interview: [SELECT FROM: Personnel with a plan of action development and implementation responsibilities; personnel with information security responsibilities].

Test: [SELECT FROM: Mechanisms for developing, implementing, and maintaining a plan of action].

Table 5 NIST 171A Assessment method for 3.12.2 POA&M requirement

The System Security Plan (SSP) is a part of the Derived Requirements, NIST 171 3.12.4, and it is a core component necessary to all forms of assessment from Low to High.  As both a sample control and an evaluation of whether the SSP is satisfactory as an element of the Assessment program itself, consider the flow of [a] through [h] in determining if the Vendor has satisfied the control. The evidence collected would include the completed plan. That plan would be given consideration relative to the associated POA&M, showing adherence to the policies and procedures necessary to maintain adequate security.

3.12.4

SECURITY REQUIREMENT

Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.

 

ASSESSMENT OBJECTIVE Determine if:

3.12.4[a]

a system security plan is developed.

3.12.4[b]

the system boundary is described and documented in the system security plan.

3.12.4[c]

the system environment of operation is described and documented in the system security plan.

3.12.4[d]

the security requirements identified and approved by the designated authority as non-applicable are identified.

3.12.4[e]

the method of security requirement implementation is described and documented in the system security plan.

3.12.4[f]

the relationship with or connection to other systems is described and documented in the system security plan.

3.12.4[g]

the frequency to update the system security plan is defined.

3.12.4[h]

system security plan is updated with the defined frequency. 

POTENTIAL ASSESSMENT METHODS AND OBJECTS

Examine: [SELECT FROM: Security planning policy; procedures addressing system security plan development and implementation; procedures addressing system security plan reviews and updates; enterprise architecture documentation; system security plan; records of system security plan reviews and updates; other relevant documents or records].

Interview: [SELECT FROM: Personnel with security planning and system security plan implementation responsibilities; personnel with information security responsibilities].

Test: [SELECT FROM: Organizational processes for system security plan development, review, update, and approval; mechanisms supporting the system security plan].

Table 6 - Sample Assessment Method for Security Requirement 3.12.4 System Security Plans

As explained by SP 800-18 Rev. 1, Guide for Developing Security Plans for Federal Information Systems[xxxii] “The objective of system security planning is to improve the protection of information system resources. [...] The protection of a system must be documented in a system security plan. The completion of system security plans is a requirement of the Office of Management and Budget (OMB) Circular A-130, "Management of Federal Information Resources," Appendix III, "Security of Federal Automated Information Resources," and Title III of the E-Government Act, entitled the Federal Information Security Management Act (FISMA), The purpose of the system security plan is to provide an overview of the security requirements of the system and describe the controls in place or planned for meeting those requirements. The system security plan also delineates the responsibilities and expected behavior of all individuals who access the system. The system security plan should be viewed as documentation of the structured planning process adequate, cost-effective security protection for a system. It should reflect input from various managers with responsibilities concerning the system, including information owners, the system owner, and the senior agency information security officer (SAISO). Additional information may be included in the basic plan and the structure and format organized according to agency needs, so long as the major sections described in this document are adequately covered and readily identifiable.

There are numerous resources to assist in creating the SSP, including the template provided within NIST SP800-18, Guide for Developing Security Plans for Federal Information Systems. [xxxii] One recent resource is the System Security Plan How to for CMMC and NIST SP 800-171 DoD self-assessment training video offered by CMMCaudit.org. [xxxiii]


Part III: The DoD NIST 171 Assessment as a GRC Schema

CMMC 2.0 Interim Final Rule maintains the established NIST 171 assessment cycle allowing most contractors associated with Foundational / Level 1 and a subset of Advanced / Level 2 programs to perform annual self-assessments. This means those contractors will continue to use the SPRS to upload their internally managed audit of the NIST 171 110 security requirements, NIST SP 800-171 (disa.mil). A portion of the Advanced / Level 2 programs will require triennial third-party assessments. Expert / Level 3 programs will require triennial assessments conducted by government officials.

All DoD NIST 171 Assessment begins with compliance program management organizing their strategy and work plan. This involves connecting all parts of the NIST 171, 171A, and 172, including each requirement’s assessment and implementation guidance, understanding the overall schema of records, and assigning the connected elements into some sort of GRC. Connecting these record elements facilitates the management of the NIST 171 assessment cycle. The GRC system needs to track each family, and requirements within that family, along with each requirement’s implementation guidance, assessment elements, scoring value, and associated tags for naming or calling it as part of either a NIST 171 low, medium, or high data set, or as part of a CMMC Level 1, Level 2 or Level 3 array for that level of Assessment. This is foundationally important because documenting and planning the assessment should be the easy part.

Regardless of whether the entity intends to complete a Self-Assessment, a Third-Party Assessment, or will be required to undergo a Government Assessment, program owners will need to organize a System Security Plan (SSP) and Plan of Action & Milestone (POA&M) that tracks their progress against their catalog of controls and requirements. The accompanying documentation for all levels of Assessment must include a moderately mature ISMS as shown in Table 7 and as suggested by the NIST.HB.162 Appendix of Useful Plans, Policies, and Procedures to have ready for submission during any audit. [xxxiv]

Beyond the scope of the assessment, it will be necessary to achieve and maintain a capacity to associate NIST 171 and CMMC practice/requirements tags to assets, programs, and policy, so the assessment lifecycle maintains visibility and consistency. Even though the NIST 171 is designed to keep the overall burden of testing within reasonable levels, tracking progress against certain types of controls, such as Encryption, MFA, Incident Response, or Vulnerability Management, involves a large amount of asset-specific evidence, procedures for response and follow-up, and continuous monitoring that aligns with a declared structure of risk management. To Assess the NIST 171, the entity must design a program that meets its requirements. That is the hard part.

Plans you should have in place:  Policies and Procedures you should have: 

Business Continuity Plans
Contingency Plans
Continuity of Operations Plans 
Critical Infrastructure Plans 
Crisis Communications Plan 
Disaster Recovery Plans 
Incident Response Plan 
Incident Response Testing Plan 
Occupant Emergency Plan
Physical/Environmental Protection Plan 
Plan of Action
Security Assessment Plan 
Security Plan
System Security Plan

Access Control
Audit and Accountability 
Configuration Management 
Configuration Planning
Incident Response
Identification and Authentication 
Information Flow Control 
Information Flow Enforcement 
Information System Maintenance 
Media Protection
Media Sanitization and Disposal 
Mobile Code Implementation 
Password
Personnel Security

Physical and Environmental Protection 
Portable Media
Risk Assessment
Security Assessment and Authorization 
Security Awareness and Training 
Security Planning
Separation of Duties
System and Information Integrity 
System and Services Acquisition 
System and Communication Protection 
System Use (Acceptable Use)

Table 7 - Necessary Plans, Policies, and Procedures as suggested in the NIST.HB.162 for NIST 171 DFARS Assessment readiness


Tracing levels of Assessment to the depth of the requirement

As of December 2021, the array of supporting documentation for CMMC Assessors includes Levels 1 and 2 scoping guidance, two assessment guides, and one technical document titled The Artifact Hashing Guide. DoD assessors are required to use this documentation.

CMMC 2.0 Guidelines

Figure 7 CMMC PMO CMMC 2.0 Documents

The Assessment Method for the NIST 171 series aligns with the levels of maturity applied to each requirement, organized as Basic, Focused, and Comprehensive. It is reasonable to expect that Basic compliance is necessary to Basic SPRS reporting, that Focused attributes would align with the entire Basic and Derived requirements, and that Comprehensive would support “Expert” and Level 3 assessments. For organizations determined to manage High-risk assets for the Federal Government, their controls would be assessed at the Comprehensive tier, including the additional 35 requirements from the NIST 172. Their assessment would be a Triennial or have its conclusion only once every three years. At Level 3, where there is an increased Cybersecurity requirement, including 35 NIST SP 800-172 requirements, one can also expect an increase in the derived controls requirement. The Level Three CMMC has not yet been published, so any organization identified as requiring Level 3 Assessment will likely have until 2026 to fully comply.

NIST171A Assessment Method

Figure 8 NIST 171A Assessment Methodology

The NIST SP 800-171 Assessment Methodology Version 1.2 6.24.2020.pdf (osd.mil) currently supports the scoring methodology used within the SPRS system. While additional Level 3 controls arrive soon - CMMC Interim Final Rule 2.0 · (cmmc-eu.com), the scoring for the 110 NIST 171 Level 1 and 2 requirements is unlikely to change.

The NIST SP 800-171 DoD Assessment consists of three levels of assessments. These three levels of reviews reflect the depth of the evaluation and the associated level of confidence in the assessment results. Evaluation of contractors with contracts containing DFARS clause 252.204-7012 is anticipated to be once every three years unless other factors, such as program criticality/risk or a security-relevant change, drive the need for a different assessment frequency.

The NIST SP 800-171 Assessment Methodology breaks out the exact steps for Basic, Medium, and High Assessment. The current level High is not associated with CMMC Level 3. The DCMA determines the risk rating. The result of a High-Level Assessment is to attain a DoD validated score of “High” confidence.


Scoring Methodology and the Need for a GRC

The NIST SP 800-171 DoD Assessment Methodology details the exact score allowed for each 110 security requirements. There’s a substantial discussion for methodology in accepting and evaluating acceptable artifacts and compensating controls as evidence of having met requirements and how to score items that are determined to be not applicable. The document serves as the proper scoring either via self-reporting or as validated by the DoD assessor. Everyone involved in NIST 171 needs to read and fully implement this guidance.

Scoring Requirements

Figure 9 NIST 171 Assessment Methodology Requirements scoring guidance (Open this image full screen.)

Compliance program management should have their scoring established before completing their SPRS. The process of reporting the Self-Assessment is simply the time spent selecting the correct response, rather than the act of evaluating and determining the right answer.

SPRS Scoring Values

Figure 10 NIST 171 Scoring values (Open this image full screen.)


Organizing NIST SP 800-171 Assessment Content in a personal GRC

The following are suggestions for visualizing and arranging content in a personal maturity model system or as facilitated by a GRC. Since the array of requirements will be organized under “Families,” which is the higher level or parent object, it makes sense to have two stories to view and summarize the Assessment. Rather than operating with multiple spreadsheets, this model proposes two-level for organizing the Control Families and a structure for managing the security requirements. This could be accomplished via pivot tables or using simple SQL and SharePoint as in Figure 11.

  • Editions
  • Domain / Family (Two letters)
  • Control Objective / Control Name / Control ID
  • Test / Enhancement / Requirement / Test ID

Families organize requirements from 171 and 172, testing approach from 171A and H.B.162

Figure 11 Visualizing the Requirements Across SP 800-171 and SP 800-172 as a single stack of Families and related Security Requirements.

The NIST 171 Mapping Model

It is not surprising that anyone would struggle to connect NIST SP 800-171r2, NIST SP 800171A, NIST SP 800-172, appendix for Tailoring Criteria, appendix for mapping to ISO/IEC 27001 & ISO/IEC 27002, and NIST SP 800-53. Each security requirement should account for its definition and discussion, its associated testing methodology, and the industry-recommended or company-specific control mappings that align the requirement to other standards and frameworks.

Connecting NIST 171 & 172 tailoring mapping

Figure 12 Suggested Approach to managing the combined content from NIST 171, 171A, and 172 security requirements, and their related mapping to other standards. There are 110 records from NIST 171 and 35 from NIST 172. (View this image full screen.)

NIST 172 Security Requirements

Figure 13 Expert and Level 3 requirements will utilize NIST SP 800-172 and will likely associate to a broader set of SP 800-53 requirements from SA, SR, PT domains.

For organizations required to conduct a Level 3 / Expert assessment, the [SP 800 172] and their associated SP 800-53 mapped requirements are likely to draw upon all domains, including some elements within SR Supply Chain Risk Management and parts of SA Systems & Services Acquisition, particularly SA-8 Security and Privacy Engineering Principles. The program owners should establish organic mapping to existing programs aligned with operations and controls.

Mapping the CMMC practice attributes and the SPRS scoring attributes facilitates assessment readiness and tracking. Although the SPRS and CMMC Level 3 requirements await the formal update of “The Rule,” the following image offers a model to organize all the data elements based on what's known. SPRS scoring establishes measurable criteria to use when asserting that the organization has implemented the necessary elements for each control. Some items are valued higher or lower, so the organization preparing to report on their achievements should have a complete understanding of the SPRS weights their accomplishments.


The following images represent a hypothetical view of NIST 171 Assessment elements. The images are a snapshot of Basic L1, Focused L2, and Comprehensive or Expert or L3. Note that the 35 Enhanced Security Controls are from NIST SP 800-172. 

NIST 171 Basic Security Requirements Level 1 Basic

NIST 171 Level 2 Derived RequirementsDerived, Advanced, Medium

NIST 172 CMMC L3 Expert RequirementsExpert, L3, High

171 and 172 Requirements with Levels Scores and CMMC TagsScoring, Protection Criteria, CMMC Practice ID

Figure (s)14 Attributes for 171 and 172 requirements include Protection Criteria, Scoring Penalty, associated CMMC practice, Control Families, Testing Procedure, and Mapped ISO/IEC and SP 800-53 security requirements.

Start Today

The NIST 171 DoD Assessment and Cybersecurity Maturity Model Certificate (CMMC) Framework Levels 1 & 2 requirements are mandatory under the FAR, Federal Acquisition Regulation, and Defense Federal Acquisition Regulation Supplement (DFARS). All Vendors should prepare or actively be in the process of their DoD Assessment and in the performance of reporting a Basic self-assessment to the Supplier Performance Risk System (SPRS). Notification of a Level 3 requirement is in short order, so it is prudent to begin working with the NIST SP 800-172 and fully understand practice requirements for maintaining a POA&M, SSP, and all necessary Plans, Policies, and Procedures to be DoD Assessment ready.


Resources

Critical Resource Website links

CUI Logo

CUI History | National Archives

NIST Logo

National Institute of Standards and Technology | NIST

DoD OOU(A&D) Logo

 

 

 

252.204-7020 NIST SP 800-171 DoD Assessment Requirements. | Acquisition.GOV

Acquisition.Gov

 

 

Acquisition.GOV | www.acquisition.gov Location for FARS and DFARS

SPRS Logo

 

 

 

Supplier Performance Risk System (disa.mil)

This site was particularly useful

Project Spectrum

Project Spectrum (Very useful resource - have a look at who they recommend)

Glossary Main Laws & Abbreviations

  • [32 CFR 2002]: 32 CFR Part 2002, Controlled Unclassified Information, September 2016. https://www.govinfo.gov/app/details/CFR-2017-title32-vol6/CFR-2017-title32-vol6-part2002/summary
  • [OMB A-130]: Office of Management and Budget (2016) Managing Information as a Strategic Resource. (The White House, Washington, DC), OMB Circular A-130, July 2016. https://www.whitehouse.gov/sites/whitehouse.gov/files/omb/circulars/A130/a130revised.pdf 
  • CUI categories: Those types of information for which laws, regulations, or governmentwide policies require or permit agencies to exercise safeguarding or dissemination controls and which the CUI Executive Agent has approved and listed in the CUI Registry.
  • CUI Executive Agent: The National Archives and Records Administration (NARA) implements the executive branch-wide CUI Program and oversees federal agency actions to comply with Executive Order 13556. NARA has delegated this authority to the Information Security Oversight Office (ISOO) Director.
  • CUI program: The executive branch-wide program to standardize CUI handling by all federal agencies. The program includes the rules, organization, and procedures for CUI, established by Executive Order 13556, 32 CFR Part 2002, and the CUI Registry.
  • FCI Federal Contract Information: FCI is data not intended for public release, provided by or generated by the Government under a contract to develop or deliver a product or service to the Government. FCI does not include information provided by the Government to the public, (FCI)
  • Covered Defense Information (CDI): The requiring activity is also responsible for determining the appropriate marking for the CDI by the procedures for applying distribution statements on technical documents found in DoDM 5200.01 Vol 4 and DoDI 5230.24, Distribution Statements on Technical Documents.
  • Defense Industrial Base (DIB): The DoD Defense Industrial Base (DIB) Collaborative Information Sharing Environment (DCISE) serves as the single DoD focal point for receiving all cyber incident reporting affecting unclassified networks of DoD contractors to safeguard DoD information.
  • Prime Contractor: A contractor responsible for design control, and delivery of a system or equipment such as aircraft, engines, ships, tanks, vehicles, guns and missiles, ground communications and electronic systems, ground support equipment, and test equipment.
  • Supplier Performance Risk System (SPRS): The Supplier Performance Risk System documents vendor self-assessment results for DOD Acquisition Professionals. SPRS is the Department of Defense’s single, authorized application to retrieve suppliers' performance information. SPRS is a web-enabled enterprise application that gathers, processes, and displays data about the performance of suppliers.
  • Office of the Under Secretary of Defense Acquisition and Sustainment OUSD(A&S).

Endnotes


[i] 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting. | Acquisition.GOV “Adequate security” means protective measures that are commensurate with the consequences and probability of loss, misuse, or unauthorized access to or modification of information. 
[ii] SP 800-145, The NIST Definition of Cloud Computing | CSRC
[iii] Why Sell to Government: GSA Benefits (and Drawbacks) - pricereporter.com
[iv] FAR | Acquisition.GOV
[v] Federal Register: Department of Defense (DoD)-Defense Industrial Base (DIB) Cybersecurity (CS) Activities
[vi] USA002524-20-DPC.pdf (osd.mil)
[vii] ModelOverview_V2.0_FINAL2_20211203.pdf (osd.mil)
[viii] Executive Order 13556 "Controlled Unclassified Information
[ix] DOD Mandatory Controlled Unclassified Information (CUI) Training (usalearning.gov)
[x] Supplier Performance Risk System (disa.mil)
[xi] Federal Register: Department of Defense (DoD)-Defense Industrial Base (DIB) Cybersecurity (CS) Activities
[xii] Policy templates and tools for CMMC and 800-171 (cmmcaudit.org)
[xiii] 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting. | Acquisition.GOV
[xiv] PowerPoint Presentation (defense.gov)
[xv] OUSD A&S - Cybersecurity Maturity Model Certification (CMMC) (osd.mil)
[xvi] OUSD A&S - Cybersecurity Maturity Model Certification (CMMC) (osd.mil)
[xvii] Protecting Controlled Unclassified Information in Nonfederal Systems (nist.gov)
[xi] Assessing Security Requirements for Controlled Unclassified Information (nist.gov)
[xviii] Federal Information Security Modernization Act | CISA
[xiv] 44 U.S. Code § 3551 - Purposes | U.S. Code | US Law | LII / Legal Information Institute (cornell.edu)
[xiv] SP 800-171 Rev. 2, Protecting CUI in Nonfederal Systems and Organizations | CSRC (nist.gov)
[xv] OSCAL (nist.gov) Open Security Controls Assessment Language. OSCAL is a set of formats expressed in XML, JSON, and YAML
[xvi] International Organization for Standardization/International Electrotechnical Commission (2013) Information Technology—Security techniques— Information security management systems—Requirements. (International Organization for Standardization, Geneva, Switzerland), ISO/IEC 27001:2013. https://www.iso.org/standard/54534.html
[xvii] Security and Privacy Controls for Information Systems and Organizations (nist.gov)
[xviii] Control Baselines for Information Systems and Organizations (nist.gov)
[xix] Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171
[xx] Q49: What is the difference between the Basic and Derived R | DoD Procurement Toolbox
[xxi] FIPS 199, Standards for Security Categorization of Federal Information and Information Systems (nist.gov)
[xxii] Understanding Baselines and Impact Levels in FedRAMP | FedRAMP.gov
[xxiii] FedRAMP Publishes Draft Rev. 5 Baselines | FedRAMP.gov
[xxiv] POA&M - Glossary | CSRC (nist.gov)
[xxv] SP 800-18 Rev. 1, Guide for Developing Security Plans for Federal Information Syst | CSRC (nist.gov)
[xxvi] CMMCAudit.org System Security Plan How to for CMMC and NIST SP 800-171 DoD self-assessment https://youtu.be/uUPB5vUl3ug
[xxvii] NIST MEP Cybersecurity Self-Assessment Handbook For Assessing NIST SP 800-171 Security Requirements in Response to DFARS Cybersecurity Requirements Appendix A: Useful Plans, Policies, and Procedures
[xxviii] FIPS 199, Standards for Security Categorization of Federal Information and Information Systems (nist.gov)
[xxiv] Understanding Baselines and Impact Levels in FedRAMP | FedRAMP.gov
[xxx] FedRAMP Publishes Draft Rev. 5 Baselines | FedRAMP.gov
[xxxi] POA&M - Glossary | CSRC (nist.gov)
[xxxii] SP 800-18 Rev. 1, Guide for Developing Security Plans for Federal Information Syst | CSRC (nist.gov)
[xxxiii] CMMCAudit.org System Security Plan How to for CMMC and NIST SP 800-171 DoD self-assessment https://youtu.be/uUPB5vUl3ug
[xxxiv] NIST MEP Cybersecurity Self-Assessment Handbook For Assessing NIST SP 800-171 Security Requirements in Response to DFARS Cybersecurity


Thanks to Security Compass for commissioning this research.

Also, please acknowledge the collaboration between members of Security Compass, Zscaler, Cloud Security Alliance, ISC2 East Bay, ISC2 Silicon Valley, ISC2 San Francisco, and ISACA Silicon Valley who met at least 30 times to present and collaborate throughout 2021 and without whom it would not be impossible to build out industry contributed mappings to NIST SP 800-171 and NIST SP 800-53.

Consensus Through NIST Community

Consensus Through NIST Community, UCF, Zscaler, CSA, and Security Compass

2022-01-11-csiac-dod-cybersecurity-policy-chart.pdf as of 22:48:20 2022-01-19

In case you felt this approach was too detailed, nope, it was not.

DoD Policy Chart from CSIAC

 

Main Menu