Organizing NIST SP 800-171 Assessment Content in a personal GRC
The following are suggestions for visualizing and arranging content in a personal maturity model system or as facilitated by a GRC. Since the array of requirements will be organized under “Families,” which is the higher level or parent object, it makes sense to have two stories to view and summarize the Assessment. Rather than operating with multiple spreadsheets, this model proposes two-level for organizing the Control Families and a structure for managing the security requirements. This could be accomplished via pivot tables or using simple SQL and SharePoint as in Figure 11.
- Editions
- Domain / Family (Two letters)
- Control Objective / Control Name / Control ID
- Test / Enhancement / Requirement / Test ID
Figure 11 Visualizing the Requirements Across SP 800-171 and SP 800-172 as a single stack of Families and related Security Requirements.
The NIST 171 Mapping Model
It is not surprising that anyone would struggle to connect NIST SP 800-171r2, NIST SP 800171A, NIST SP 800-172, appendix for Tailoring Criteria, appendix for mapping to ISO/IEC 27001 & ISO/IEC 27002, and NIST SP 800-53. Each security requirement should account for its definition and discussion, its associated testing methodology, and the industry-recommended or company-specific control mappings that align the requirement to other standards and frameworks.
Figure 12 Suggested Approach to managing the combined content from NIST 171, 171A, and 172 security requirements, and their related mapping to other standards. There are 110 records from NIST 171 and 35 from NIST 172. (View this image full screen.)
Figure 13 Expert and Level 3 requirements will utilize NIST SP 800-172 and will likely associate to a broader set of SP 800-53 requirements from SA, SR, PT domains.
For organizations required to conduct a Level 3 / Expert assessment, the [SP 800 172] and their associated SP 800-53 mapped requirements are likely to draw upon all domains, including some elements within SR Supply Chain Risk Management and parts of SA Systems & Services Acquisition, particularly SA-8 Security and Privacy Engineering Principles. The program owners should establish organic mapping to existing programs aligned with operations and controls.
Mapping the CMMC practice attributes and the SPRS scoring attributes facilitates assessment readiness and tracking. Although the SPRS and CMMC Level 3 requirements await the formal update of “The Rule,” the following image offers a model to organize all the data elements based on what's known. SPRS scoring establishes measurable criteria to use when asserting that the organization has implemented the necessary elements for each control. Some items are valued higher or lower, so the organization preparing to report on their achievements should have a complete understanding of the SPRS weights their accomplishments.




Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics