Part II: Understanding NIST 171 - Protecting CUI
National Institute of Standards and Technology (NIST) Special Publication 800-171 Revision 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations SP 800-171 [xvii] and NIST SP 800-171A Assessing Security Requirements for Controlled Unclassified Information SP 800-171A [xviii] is the current prescribed program for working with nonfederal organizations and their data, or CUI.
They are Special Publications providing recommended requirements for protecting and assessing the confidentiality of controlled unclassified information (CUI) and are collectively considered the NIST 171 Assessment Methodology, which are
- Created as part of NIST’s statutory responsibilities under the Federal Information Security Modernization Act (FISMA)[xix], 44 U.S.C. § 3551 et seq., Public Law (P.L.) 113-283 [xx]
- Designed specifically for non-federal organizations that process, store, or transmit sensitive federal information.
NIST SP 800-171 Revision 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organization document should always be accessed from its corresponding NIST Computer Security Resource Center “CSRC” page. [xxi] When using the CSRC, give keen attention to the revision date, the related publications, and the other parts of this publication. Specifically, the NIST 171 has two parts, much like the SP 800-53 and its assessment model in [SP 800-53B]. Also highlighted are the Abstract, Keywords, and Control Families, important meta content used throughout the NIST OSCAL, and details necessary to automate any NIST content. [xxii]
Figure 2 NIST SP 800-171 Rev 2 and Related NIST SP 800 172; Control Families FIPS PUB 200
Once downloaded, NIST documents follow a standard structure. The Requirements (Controls) are listed in section three. The following image (Figure 3) shows the NIST 171 security requirements, the necessary steps to prepare and manage a Plan of Action and Milestones (POA&M), and the System Security Plan (SSP). The POA&M and SSP, 3.12.4 and 3.12.2, are tested requirements and necessary processes to manage a CUI program. The image also shows conditions attributed as either a Basic Security Requirement or a Derived Security Requirement. Chapter Three introduces the relationship of NIST 171 to ISO 27001. This connection is critical to the SSP since the assessment package must include all related policies and procedures supporting the requirements. Still, NIST 171 is not a standard for developing an ISMS [xxiii] itself. (See Table 2 - Necessary Plans, Policies, and Procedures)
Figure 3- NIST 171r2 Requirements, POA&M and SSP, Mapping and Tailoring
NIST 171 Chapter Three explains that the standard derives controls from Special Publication 800-53 Revision 5, Security and Privacy Controls for Information Systems and Organizations [xxiv] and its accompanying assessment methodology, NIST Special Publication 800-53B, Control Baselines for Information Systems and Organizations.[xxv] The relationships between these documents are noted within each requirement’s discussion and further detailed as the mapped controls in the Appendix Mapping Table. Note that the Mapping for this document preceded the final release of NIST 800-53r5 and the new FedRamp version 5 requirement. Companies should tailor their mapping with knowledge of the recommendations in Appendix E and authentic control selection based on their actual procedures and risk management. The mapping table is considered as a reference and starting point.
Figure 4- NIST 171r2 Mapping Table: Appendix D
SP 800-171 and SP 800-171A comprise security requirements and related criteria for implementation and assessment. In addition to the NIST 171 series, NIST recently released the NIST Special Publication 800-172, Enhanced Security Requirements for Protecting Controlled Unclassified Information, A Supplement to NIST Special Publication 800-171.[xxvii] This standard addresses Expert requirements for Level 3 Cybersecurity Maturity Model Certificate (CMMC) DoD Certification.
NIST Compliance Standards and Their Relationship to Each Other
SP 800-171 comprises 31 Basic and 79 Derived Controls. Basic Requirements come from FIPS 200, Minimum Security Requirements for Federal Information and Information Systems, and the Derived Requirements come from NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations. Since the FIPS 200 requirements are fundamental, NIST refers to them as Basic. However, because FIPS 200 is a set of ‘minimum’ requirements, these are often insufficient to protect at the required “Moderate” impact level for covered defense information, CDI. When the Basic Requirement does not fully meet the “Moderate” requirement, related controls from the “Moderate” baseline in NIST SP 800-53 are specified and identified in NIST SP 800-171 as Derived Requirements (i.e., derived from NIST SP 800-53).[xxviii]
The [SP 800-53B] is an Assessment Model comprised of three baselines and a privacy baseline, with tailored recommendations according to the Standards for Security Categorization of Federal Information and Information Systems, [FIPS PUB 199] [xxviii] Using the FIPS 199, a low-impact, moderate impact, or high impact designation is assigned to each Control and Enhancement. Entities determine if their systems requirements align with completing a High, Medium, or Low baseline. [xxix]
The following figure shows the array of documents necessary to understand the NIST 171 Assessment Methodology, including the source of derived controls and the basis for tailoring and risk analysis.
Figure 5 NIST Documentation for 800-53 and 800-171 series Supported by FIPS PUBS 199, 200, and NIST.HB-162 (Open in full window)
FIPS 199 and the Protection of Controlled Unclassified Information in Federal Systems
Per the federal CUI regulation, federal agencies using federal systems to process, store, or transmit CUI, at a minimum, must comply with the following standards. NIST 171 Assessment is tailored from this baseline of information.
- Federal Information Processing Standards (FIPS) Publication 199, Standards for Security Categorization of Federal Information and Information Systems (moderate confidentiality)
- Federal Information Processing Standards (FIPS) Publication 200, Minimum Security Requirements for Federal Information and Information Systems.
- NIST Special Publication 800-53, Security and Privacy Controls for Federal Information Systems and Organizations Moderate baseline as Tailored to the NIST SP 800-171; and
- NIST SP 800-60 Volume I Revision 1, Volume I: Guide for Mapping Types of Information and Information Systems to Security Categories
- NIST SP 800-60 Volume II Revision 1, Volume II: Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories
Figure 6 FIPS Publication 199 Standards for Security Categorization, showing NIST 800-171 v NIST 800-53 and CMMC Level 3 for NIST 800-172





Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics