Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-172 Enhanced CUI Protection Center

Add an enhanced protection layer for critical CUI missions and advanced threats.

Navigate every NIST SP 800-172 Rev. 3 enhanced requirement, protection strategy, organization-defined parameter, source SP 800-53 control, and integrated SP 800-172A assessment procedure.

17Requirement families
103Active requirements
12Withdrawn records
199Assessment objectives

SP 800-172 Revision 3 · SP 800-172A assessment content · OSCAL v1.2.2

Open the official publication ↗
Applicability matters

SP 800-172 Rev. 3 provides recommended requirements for protecting the confidentiality of CUI in nonfederal systems and organizations. SP 800-172 Rev. 3 supplements SP 800-171 for CUI associated with a critical program or high-value asset and is intended to address advanced persistent threats. There is no expectation that every enhanced requirement will be selected; the responsible federal agency and governing contract or agreement determine applicability.

Seventeen requirement families

Start with the enhanced CUI protection area selected for the mission.

Each family groups active requirements and preserves withdrawn records so revisions, incorporation, and replacement relationships remain traceable.

Complete enhanced requirement catalog

Search enhanced requirements and assessment content.

Search by requirement number, title, family, source SP 800-53 control, organization-defined parameter, or assessment subject.

03.01.01EActive

Dual Authorization

Dual authorization is also known as two-person control. Dual authorization reduces risk related to insider threats, including adversaries who have obtained credentials. Dual authorization requires the approval of two authorized individuals to execute privileged commands and/or other organizational actions that may affect the protection of CUI. To reduce the risk of collusion, organizations consider rotating dual auth

03.01.02EActive

Non-Organizationally Owned Systems - Restricted Use

Non-organizationally owned systems or system components include systems or system components owned by other organizations as well as personally owned devices. These also include systems and system components that are leased, part of subscription services, government-furnished equipment, or "bring your own" devices. There are risks to using non-organizationally owned systems or components. In some cases, the risk is s

03.01.03EWithdrawn

Withdrawn requirement

Withdrawn NIST SP 800-172 Rev. 3 requirement 03.01.03E; use the recorded replacement relationships.

03.01.04EActive

Concurrent Session Control

Organizations may define the maximum number of concurrent sessions for system accounts globally, by account type, by account, or any combination thereof. For example, organizations may limit the number of concurrent sessions for system administrators or other individuals working in particularly sensitive domains or mission-critical applications. Concurrent session control addresses concurrent sessions for system acco

03.01.05EActive

Remote Access Monitoring and Control

Monitoring and controlling remote access methods allows organizations to detect attacks and ensure compliance with remote access policies. This is accomplished by auditing the connection activities of remote users on system components, including servers, notebook computers, workstations, smart phones, and tablets. This requirement enhances SP 800-171 requirement 03.01.02.

03.01.06EActive

Protection of Remote Access Mechanism Information

Access to organizational information about remote access mechanisms by non-organizational entities can increase the risk of unauthorized use and disclosure. The organization considers including remote access requirements in the information exchange agreements with other organizations, as applicable. Remote access requirements can also be included in rules of behavior and access agreements. This requirement enhances S

03.01.07EActive

Automated Audit Actions for Account Management

The use of automated mechanisms to audit account management activities provides more timely and comprehensive data to guide and inform needed actions by system administrators. Security information and event management (SIEM) tools can help automate account management audit activities. This requirement enhances SP 800-171 requirement 03.01.01.

03.01.08EActive

Account Monitoring for Atypical Usage

Atypical usage includes accessing systems at certain times of the day or from locations that are not consistent with the normal usage patterns of individuals. Monitoring for atypical usage may reveal rogue behavior by individuals or an attack in progress. This requirement enhances SP 800-171 requirement 03.01.01.

03.01.09EActive

Attribute-Based Access Control

Attribute-based access control is an access control policy that restricts system access to authorized users based on specified organizational attributes (e.g., job function, role, identity), action attributes (e.g., read, write, delete), environmental attributes (e.g., time of day, location), and resource attributes (e.g., document classification). Organizations can create rules based on specified attributes and the

03.01.10EActive

Object Security Attributes

Organizations implement information flow control policies and enforcement mechanisms to control the flow of CUI between designated sources and destinations within systems and between connected systems. Flow control is based on the characteristics of the information and/or the information path. Enforcement occurs, for example, in boundary protection devices that employ rule sets or establish configuration settings tha

03.01.11EActive

Role-Based Access Control

Role-based access control (RBAC) is an access control policy that enforces access to objects and system functions based on the defined role (i.e., job function) of the subject. Organizations can create specific roles based on job functions and the authorizations (i.e., privileges) to perform needed operations on the systems associated with the organization-defined roles. When users are assigned to specific roles, the

03.01.12EActive

Physical or Logical Separation of CUI Flows

Enforcing the separation of information flows associated with defined types of data can enhance protection by ensuring that CUI is not commingled while in transit and by enabling flow control by transmission paths that are not otherwise achievable. This requirement enhances SP 800-171 requirement 03.01.03.

03.01.13EActive

Metadata

Metadata is information that describes the characteristics of data. Metadata can include structural metadata that describes data structures or descriptive metadata that describes data content. The enforcement of allowed information flows based on metadata enables simpler and more effective flow control. Organizations consider the trustworthiness of metadata regarding data accuracy (i.e., knowledge that the metadata v

03.01.14EActive

Security Policy Filters

Security policy filters for data structures check for maximum file lengths, maximum field sizes, and data/file types for structured and unstructured data. Security policy filters for data content check for specific words, enumerated values or data value ranges, and hidden content. Structured data permits the interpretation of data content by applications. Unstructured data refers to digital information without a data

03.01.15EActive

Data Type Identifiers

Data type identifiers include filenames, file types, file signatures or tokens, and multiple internal file signatures or tokens. Systems only allow for the transfer of data that is compliant with data type format specifications. The identification and validation of data types is based on defined specifications associated with each allowed data format. The filename and number alone are not used for data type identific

03.01.16EActive

Decomposition Into Policy-Relevant Subcomponents

Decomposing CUI into policy-relevant subcomponents prior to information transfer facilitates policy decisions on source, destination, certificates, and other security-related component differentiators. Policy enforcement mechanisms apply filtering, inspection, and/or sanitization rules to the policy-relevant subcomponents of information to facilitate flow enforcement prior to transferring such information to differen

03.01.17EActive

Detection of Unsanctioned CUI

Unsanctioned information includes malicious code, information that is inappropriate for release from the source network, information that is not authorized to be stored or processed on the system, or executable code that could disrupt or harm services or systems on the destination network. This requirement enhances SP 800-171 requirement 03.01.03.

03.02.01EActive

Advanced Literacy and Awareness Training

An effective way to detect APTs, address the cyber threat environment, and preclude successful attacks is to provide specific literacy training for individuals. Threat literacy training includes educating individuals on the various ways that APTs can infiltrate the organization (e.g., through websites, emails, pop-ups, articles, and social engineering) and describes techniques for recognizing suspicious emails, the u

03.02.02EActive

Literacy and Awareness Training Practical Exercises

Practical exercises include no-notice social engineering attempts to collect information, gain unauthorized access, or simulate the adverse impact of opening malicious email attachments or invoking malicious web links via spear phishing attacks. This requirement enhances SP 800-171 requirement 03.02.01.

03.02.03EActive

Literacy and Awareness Training Feedback

Training feedback includes literacy and role-based training results, which can indicate a potentially serious problem, especially the failures of personnel in critical roles. Managers should be made aware of such situations so that they can respond accordingly. Training feedback supports the evaluation and update of organizational training content and methodology. This requirement does not enhance a specific requirem

03.02.04EActive

Anti-Counterfeit Training

System components include hardware, software, and firmware components as well as the documentation for those components. This requirement is sourced to a control tailored out of the SP 800-53B .13 moderate baseline in SP 800-171.

03.03.01EActive

Protection of Audit Record Storage in Separate Physical Systems or Components

Storing audit records in a repository that is separate from the audited system or system component helps to ensure that a compromise of the system being audited does not also result in a compromise of the audit records. Storing audit records on separate physical systems or components preserves the confidentiality, integrity, and availability of audit records and facilitates the management of audit records as an organ

03.03.02EActive

Real-Time Alerts for Audit Processing Failures

Alerts provide organizations with urgent messages. Real-time alerts provide these messages at information technology speed (i.e., the time from event detection to alert occurs in seconds or less). This requirement enhances SP 800-171 requirement 03.03.04.

03.03.03EActive

Dual Authorization for Audit Information and Actions

Dual authorization is also known as two-person control since it requires the approval of two authorized individuals to reduce the risk related to insider threat when executing audit functions. Dual authorization reduces risks related to insider threats, including adversaries who have obtained credentials. Organizations may choose different selection options for different types of audit information. To reduce the risk

03.03.04EActive

Integrated Analysis of Audit Records

Integrated analysis of audit records requires that the analysis of information generated by scanning, monitoring, or other data collection activities is integrated with the analysis of audit record information. Security information and event management (SIEM) tools can facilitate audit record aggregation or consolidation from multiple system components as well as audit record correlation and analysis. The use of stan

03.04.01EWithdrawn

Withdrawn requirement

Withdrawn NIST SP 800-172 Rev. 3 requirement 03.04.01E; use the recorded replacement relationships.

03.04.02EActive

Automated Unauthorized Component Detection

Monitoring for unauthorized or misconfigured components may be accomplished on an ongoing basis or by the periodic scanning of systems for that purpose. Automated mechanisms may also be used to prevent the connection of unauthorized or misconfigured system components. Automated mechanisms can be implemented in systems or in separate system components. When acquiring and implementing automated mechanisms, organization

03.04.03EActive

Automated Maintenance of System Component Inventory

The system component inventory includes system-specific information required for component accountability and to provide support to identify, control, monitor, and verify configuration items based on the authoritative source. The information necessary for the accountability of system components includes the system name, hardware and software component owners, hardware inventory specifications, software license inform

03.04.04EActive

Automation Support for Baseline Configuration

Automated mechanisms that help organizations maintain consistent baseline configurations for systems include configuration management tools; hardware, software, and firmware inventory tools; and network management tools. Automated tools can be used to track version numbers on operating systems, applications, the types of software installed, and current patch levels. Automation support for accuracy and currency can be

03.04.05EActive

Dual Authorization for System Changes

Dual authorization is also known as two-person control. Organizations employ dual authorization to help ensure that any changes to selected system components and system-level information cannot occur unless two qualified individuals approve and implement such changes. Requiring two individuals to implement system changes provides an increased level of assurance that the proposed changes are correct implementations of

03.04.06EActive

Retention of Previous Configurations

Retaining previous versions of baseline configurations to support rollback includes configuration files for hardware, software, and firmware, configuration records, and associated documentation. This requirement enhances SP 800-171 requirement 03.04.01.

03.04.07EActive

Testing, Validation, and Documentation of Changes

Changes to systems include modifications to hardware, software, or firmware components and defined configuration settings. Organizations ensure that testing does not interfere with system operations that support organizational missions and business functions. Individuals or groups that conduct the tests understand the system security policies and procedures associated with the specific facilities or processes. Operat

03.04.08EActive

Centralized Repository

Organizations may implement centralized system component inventories that include components from all organizational systems. Centralized repositories of component inventories provide opportunities for efficiencies in accounting for organizational hardware, software, and firmware assets. Such repositories can help organizations rapidly identify the location and responsible individuals of system components that have b

03.05.01EActive

Cryptographic Bidirectional Authentication

Bidirectional authentication provides stronger protection to validate the identity of other devices for connections that are of greater risk. This requirement enhances SP 800-171 requirement 03.05.02.

03.05.02EActive

Password Managers

A potential risk of using password managers is that adversaries can target the collection of passwords generated by the password manager. Therefore, the passwords require strong protection, including encrypting the passwords. This requirement enhances SP 800-171 requirement 03.05.07.

03.05.03EActive

Device Attestation

Device attestation refers to the identification and authentication of a device based on its configuration and known operating state. Device attestation can be determined via a cryptographic hash of the device. If device attestation is the means of identification and authentication, then it is important that patches and updates to the device are handled via a configuration management process such that the patches and

03.05.04EActive

No Embedded Unencrypted Static Authenticators

In addition to applications, other forms of static storage include access scripts and function keys. Organizations exercise caution when determining whether embedded or stored authenticators are encrypted or unencrypted. If authenticators are used in the manner stored, then those representations are considered unencrypted authenticators. This requirement enhances SP 800-171 requirement 03.05.07.

03.05.05EActive

Expiration of Cached Authenticators

Cached authenticators are used to authenticate to a local machine when the network is not available. If cached authentication information is out of date, the validity of the authentication information may be questionable. This requirement enhances SP 800-171 requirement 03.05.07.

03.05.06EActive

Identity Proofing

Identity proofing is the process of collecting, validating, and verifying user identity information to establish credentials for accessing a system. Identity proofing is intended to mitigate threats to the registration of users and the establishment of their accounts. Resolving user identities ensure each user identity belongs to a unique individual. Organizations may be subject to laws, Executive Orders, directives,

03.05.07EActive

Identity Providers and Authorization Servers

Identity providers (both internal and external to the organization) manage user, device, and non-person entity authenticators and issue statements (often called identity assertions) that attest to the identities of other systems or system components. Authorization servers create and issue access tokens to identified and authenticated users and devices that can be used to gain access to organizational systems or infor

03.06.01EActive

Security Operations Center

A security operations center (SOC) is the focal point for security operations and computer network defense for an organization. The purpose of the SOC is to defend and monitor an organization’s systems and networks on an ongoing basis. The SOC is also responsible for detecting, analyzing, and responding to security incidents in a timely manner. The SOC is staffed with skilled technical and operational personnel (e.g.

03.06.02EActive

Integrated Incident Response Team

An integrated incident response team is a group of individuals who assess, document, and respond to incidents so that organizational systems and networks can recover quickly and implement the necessary controls to avoid future incidents. Incident response team personnel include forensic and malicious code analysts, tool developers, systems security engineers, and real-time operations personnel. The incident handling

03.06.03EActive

Behavior Analysis

If the organization maintains a deception environment, an analysis of behaviors in that environment, including resources targeted by the adversary and the timing of the incident or event, can provide significant insights into adversarial tactics, techniques, and procedures. External to a deception environment, the analysis of anomalous behavior (e.g., changes in system performance or usage patterns) or suspected adve

03.07.01EActive

Software Updates and Patches for Maintenance Tools

Maintenance tools using outdated and/or unpatched software can provide a threat vector for adversaries and result in a significant vulnerability for organizations. This requirement enhances SP 800-171 requirement 03.07.04.

03.08.01EActive

Dual Authorization for Media Sanitization

Dual authorization is also known as two-person control. Dual authorization reduces risk related to insider threats, including adversaries who have obtained credentials. Organizations employ dual authorization to help ensure that the sanitization of system media cannot occur unless two technically qualified individuals conduct the designated task. Individuals who sanitize system media possess sufficient skills and exp

03.08.02EActive

Dual Authorization for System Backup Deletion and Destruction

Dual authorization is also known as two-person control. Dual authorization reduces risk related to insider threats, including adversaries who have obtained credentials. Dual authorization ensures that the deletion or destruction of backup information cannot occur unless two qualified individuals carry out the task. Individuals who delete or destroy backup information possess the knowledge, skills, or expertise to det

03.08.03EActive

Testing System Backups for Reliability and Integrity

Organizations need assurance that backup information can be reliably retrieved. Reliability pertains to the systems and system components in which the backup information is stored, the operations used to retrieve the information, and the integrity of the information being retrieved. Independent and specialized tests can be used for each of these aspects of reliability. For example, decrypting and transporting (or tra

03.08.04EActive

System Recovery and Reconstitution

Recovery is executing contingency plan activities to restore organizational mission and business functions. Reconstitution occurs following recovery operations and includes activities for returning systems to fully operational states. Recovery and reconstitution operations reflect mission and business priorities; recovery point, recovery time, and reconstitution objectives; and organizational metrics consistent with

03.09.01EWithdrawn

Withdrawn requirement

Withdrawn NIST SP 800-172 Rev. 3 requirement 03.09.01E; use the recorded replacement relationships.

03.09.02EWithdrawn

Withdrawn requirement

Withdrawn NIST SP 800-172 Rev. 3 requirement 03.09.02E; use the recorded replacement relationships.

03.09.03EActive

Access Agreements

Access agreements include nondisclosure agreements, acceptable use agreements, rules of behavior, and conflict-of-interest agreements. Signed access agreements include an acknowledgement that individuals have read, understand, and agree to abide by the constraints associated with systems processing, storing, or transmitting CUI to which they have authorized access. This requirement is sourced to a control tailored ou

03.09.04EActive

Citizenship Requirements

Organizations may determine that individuals who need access to CUI associated with a high value asset or critical program require U.S. citizenship status. This requirement enhances SP 800-171 requirement 03.09.01.

03.10.01EActive

Intrusion Alarms and Surveillance Equipment

Physical intrusion alarms can be used to alert security personnel when unauthorized access to the facility is attempted. Alarm systems work in conjunction with physical barriers, physical access control systems, and facility security guards by triggering a response when these other forms of security have been compromised or breached. Physical intrusion alarms can include different types of sensor devices, including m

03.10.02EActive

Delivery and Removal of System Components

Enforcing authorizations for the entry and exit of system components may require restricting access to delivery areas and isolating the areas from the system and media libraries. This requirement does not enhance a specific requirement in SP 800-171 but can be used to strengthen the protection of CUI associated with critical programs or high value assets.

03.11.01EActive

Threat Awareness Program

Because of the constantly changing and increasing sophistication of adversaries, especially the advanced persistent threat (APT), it may be likely that adversaries can successfully breach or compromise organizational systems. One of the techniques that organizations can use to address this concern is to share threat information. This can include the tactics, techniques, and procedures that organizations have experien

03.11.02EActive

Threat Hunting

Threat hunting is an active means of cyber defense in contrast to traditional protection measures, such as firewalls, intrusion detection and prevention systems, quarantining malicious code in sandboxes, and Security Information and Event Management (SIEM) technologies and systems. Cyber threat hunting involves proactively searching organizational systems, networks, and infrastructure for advanced threats. The object

03.11.03EActive

Predictive Cyber Analytics

A properly resourced security operations center (SOC) or computer incident response team (CIRT) may be overwhelmed by the volume of information generated by the proliferation of security tools and appliances unless it employs advanced automation and analytics to analyze the data. Advanced automation and predictive analytics capabilities are typically supported by artificial intelligence concepts and machine learning.

03.11.04EWithdrawn

Withdrawn requirement

Withdrawn NIST SP 800-172 Rev. 3 requirement 03.11.04E; use the recorded replacement relationships.

03.11.05EWithdrawn

Withdrawn requirement

Withdrawn NIST SP 800-172 Rev. 3 requirement 03.11.05E; use the recorded replacement relationships.

03.11.06EWithdrawn

Withdrawn requirement

Withdrawn NIST SP 800-172 Rev. 3 requirement 03.11.06E; use the recorded replacement relationships.

03.11.07EWithdrawn

Withdrawn requirement

Withdrawn NIST SP 800-172 Rev. 3 requirement 03.11.07E; use the recorded replacement relationships.

03.11.08EActive

Dynamic Threat Awareness

The threat awareness information that is gathered feeds into the organization’s security operations to ensure that procedures are updated in response to the changing threat environment. For example, at higher threat levels, organizations may change the privilege or authentication thresholds required to perform certain operations. This requirement enhances SP 800-171 requirement 03.11.01.

03.11.09EActive

Indicators of Compromise

Indicators of compromise (IOCs) are forensic artifacts from intrusions that are identified on organizational systems at the host or network level. IOCs provide valuable information on systems that have been compromised. IOCs can include the creation of registry key values. IOCs for network traffic include universal resource locator (URL) or protocol elements that indicate malicious code command and control servers. T

03.11.10EActive

Criticality Analysis

Organizations conduct a functional decomposition of a system to identify mission-critical functions and system components. The functional decomposition includes the identification of organizational missions supported by the system, the specific functions to perform those missions, and traceability to the hardware, software, and firmware components that implement those functions, including when the functions are share

03.11.11EActive

Discoverable Information

Discoverable information includes information that adversaries could obtain without compromising or breaching the system, such as by collecting information that the system is exposing or by conducting extensive web searches. Corrective actions include notifying organizational personnel, removing designated information, or changing the system to make the designated information less relevant or attractive to adversarie

03.11.12EActive

Automated Means for Sharing Threat Intelligence

To maximize the effectiveness of monitoring and sharing threat intelligence information, it is important to know what threat observables and indicators the sensors need to be searching for. By using well-established frameworks, services, and automated tools, organizations improve their ability to rapidly share and feed the relevant threat detection signatures into monitoring tools. This requirement does not enhance a

03.12.01EActive

Penetration Testing

Penetration testing is a specialized type of assessment conducted on systems or system components to identify vulnerabilities that could be exploited by adversaries. It is conducted by penetration testing agents and teams with particular skills and experience that include technical expertise in network, operating system, and application-level security. Penetration testing can be used to validate vulnerabilities or to

03.12.02EActive

Independent Assessors

Independent assessors or assessment teams are individuals or groups who conduct impartial assessments of systems. Impartiality means that assessors are free from any perceived or actual conflicts of interest regarding the development, operation, sustainment, or management of the systems under assessment or the determination of security requirement effectiveness. To achieve impartiality, assessors do not create a mutu

03.12.03EActive

Risk Monitoring

Risk monitoring is guided and informed by the established organizational risk tolerance. Effectiveness monitoring determines the ongoing effectiveness of the implemented risk response measures. Compliance monitoring verifies that required risk response measures are implemented. It also verifies that security requirements are satisfied. Change monitoring identifies changes to organizational systems and environments of

03.12.04EActive

Internal System Connections

Internal system connections are connections between organizational systems and separate constituent system components (i.e., connections between components that are part of the same system), including components that are used for system development. Intra-system connections include connections with mobile devices, notebook and desktop computers, tablets, printers, copiers, facsimile machines, scanners, sensors, and s

03.13.01EActive

Heterogeneity

Increasing the diversity of information technologies within organizational systems reduces the impact of exploitations or compromises of specific technologies. Such diversity protects against common mode failures, including those failures induced by supply chain attacks. Diversity in information technologies also reduces the likelihood that the means adversaries use to compromise one system component will be effectiv

03.13.02EActive

Randomness

Randomness introduces increased levels of uncertainty for adversaries regarding the actions that organizations take to defend their systems against attacks. Such actions may impede the ability of adversaries to correctly target organizational systems that support critical missions or business functions. Uncertainty may cause adversaries to hesitate before initiating or continuing attacks. Misdirection techniques that

03.13.03EActive

Concealment and Misdirection

Concealment and misdirection techniques can significantly reduce the targeting capabilities of adversaries (i.e., window of opportunity and available attack surface) to initiate and complete attacks. For example, virtualization techniques provide organizations with the ability to disguise systems, potentially reducing the likelihood of successful attacks without the cost of having multiple platforms. The increased us

03.13.04EActive

Isolation of System Components

Organizations can isolate system components that perform different mission or business functions. Isolating system components with boundary protection mechanisms provides the capability for increased protection of individual system components and to more effectively control information flows between those components. The degree of isolation varies depending on the mechanisms selected. Boundary protection mechanisms i

03.13.05EActive

Change Processing and Storage Locations

Adversaries target critical missions and business functions and the systems that support those missions and business functions while also trying to minimize the exposure of their existence and tradecraft. The static, homogeneous, and deterministic nature of organizational systems targeted by adversaries make such systems more susceptible to attacks with less adversary cost and effort to be successful. Changing proces

03.13.06EActive

Platform-Independent Applications

Platforms are the hardware, software, and firmware components used to execute the organization’s software applications. Platforms include operating systems, the underlying computer architectures, or both. Platform-independent applications are applications with the capability to execute on multiple platforms. Such applications promote portability and reconstitution on different platforms. The portability of applicatio

03.13.07EActive

Virtualization Techniques

While frequent changes to operating systems and applications can pose significant configuration management challenges, the changes can result in an increased work factor for adversaries to conduct successful attacks. Changing virtual operating systems or applications, as opposed to changing actual operating systems or applications, provides virtual changes that impede attacker success while reducing configuration man

03.13.08EActive

Decoys

Decoys (i.e., honeypots, honeynets, or deception nets) are established to attract adversaries and deflect attacks away from the operational systems that support organizational missions and business functions. The use of decoys requires some supporting isolation measures to ensure that any deflected malicious code does not infect organizational systems. This requirement does not enhance a specific requirement in SP 80

03.13.09EActive

Isolation of Security Tools, Mechanisms, and Support Components

Physically separate subnetworks with managed interfaces are useful for isolating computer network defenses from critical operational processing networks to prevent adversaries from discovering the analysis and forensics techniques employed by organizations. This requirement enhances SP 800-171 requirement 03.13.01.

03.13.10EActive

Separate Subnetworks

The decomposition of systems into subnetworks (i.e., subnets) helps to provide the appropriate level of protection for network connections to different security domains. This requirement enhances SP 800-171 requirement 03.13.01.

03.13.11EActive

Thin Nodes

The deployment of system components with minimal functionality reduces the need to secure every endpoint and may reduce the exposure of information, systems, and services to attacks. Reduced or minimal functionality includes diskless nodes and thin client technologies. This requirement does not enhance a specific requirement in SP 800-171 but can be used to strengthen the protection of CUI associated with critical pr

03.13.12EActive

Denial-of-Service Protection

Denial-of-service events may occur due to a variety of internal and external causes, such as an attack by an adversary or a lack of planning to support organizational needs with respect to capacity and bandwidth. Such attacks can occur across a wide range of network protocols (e.g., IPv4, IPv6). A variety of technologies are available to limit or eliminate the origination and effects of denial-of-service events. For

03.13.13EActive

Port and Input/Output Device Access

Connection ports include Universal Serial Bus (USB), Thunderbolt, and Firewire (IEEE 1394). Input/output (I/O) devices include optical drives (e.g., compact disc and digital versatile disc drives), printers, and network attached storage devices. Disabling or removing such connection ports and I/O devices helps prevent the exfiltration of information from systems and the introduction of malicious code from those ports

03.13.14EActive

Detonation Chambers

Detonation chambers (also known as dynamic execution environments) allow organizations to open email attachments, execute untrusted or suspicious applications, and execute URL requests in the safety of an isolated environment or a virtualized sandbox. Protected and isolated execution environments provide a means of determining whether the associated attachments or applications contain malicious code. While related to

03.13.15EActive

Separate Subnets to Isolate System Components and Functions

Separating critical system components and functions from other noncritical system components and functions through separate subnetworks may be necessary to reduce susceptibility to a catastrophic or debilitating breach or compromise that results in system failure. For example, physically separating the command-and-control function from the in-flight entertainment function through separate subnetworks in a commercial

03.13.16EActive

System Partitioning

System partitioning is part of a defense-in-depth protection strategy. Organizations determine the degree of physical separation of system components. Physical separation options include physically distinct components in separate racks in the same room, critical components in separate rooms, and geographical separation of critical components. Managed interfaces restrict or prohibit network access and information flow

03.14.01EActive

Software, Firmware, and Information Integrity

Verifying the integrity of security-critical or essential software is an important capability since corrupted software is the primary attack vector used by adversaries to undermine or disrupt the proper functioning of systems. Unauthorized changes to software, firmware, and information can occur due to errors or malicious activity. Software includes boot firmware, operating systems with key internal components (e.g.,

03.14.02EWithdrawn

Withdrawn requirement

Withdrawn NIST SP 800-172 Rev. 3 requirement 03.14.02E; use the recorded replacement relationships.

03.14.03EWithdrawn

Withdrawn requirement

Withdrawn NIST SP 800-172 Rev. 3 requirement 03.14.03E; use the recorded replacement relationships.

03.14.04EActive

Refresh From Trusted Sources

Trusted sources include software and data from write-once, read-only media or from selected offline secure storage facilities. This requirement does not enhance a specific requirement in SP 800-171 but can be used to strengthen the protection of CUI associated with critical programs or high value assets.

03.14.05EActive

Non-Persistent Information

Retaining information longer than is required makes that information a potential target for advanced adversaries searching for high value assets to compromise through unauthorized disclosure, unauthorized modification, or exfiltration. For system-related information, unnecessary retention provides adversaries with information that can assist in their reconnaissance and lateral movement through the system. This requir

03.14.06EWithdrawn

Withdrawn requirement

Withdrawn NIST SP 800-172 Rev. 3 requirement 03.14.06E; use the recorded replacement relationships.

03.14.07EWithdrawn

Withdrawn requirement

Withdrawn NIST SP 800-172 Rev. 3 requirement 03.14.07E; use the recorded replacement relationships.

03.14.08EActive

Integrity Checks

Security-relevant events include the identification of new threats to which organizational systems are susceptible and the installation of hardware, software, or firmware. Transitional states include system startup, restart, shutdown, and abort. This requirement is sourced to a control tailored out of the SP 800-53B .13 moderate baseline in SP 800-171.

03.14.09EActive

Cryptographic Protection

Cryptographic mechanisms used to protect integrity include digital signatures and the computation and application of signed hashes using asymmetric cryptography, protecting the confidentiality of the key used to generate the hash, and using the public key to verify the hash information. Organizations that use cryptographic mechanisms also consider cryptographic key management solutions. This requirement does not enha

03.14.10EActive

Protection of Boot Firmware

Unauthorized modifications to boot firmware may indicate a sophisticated, targeted attack. These types of targeted attacks can result in a permanent denial of service or a persistent malicious code presence. These situations can occur if the firmware is corrupted or malicious code is embedded in the firmware. System components can protect the integrity of boot firmware in organizational systems by verifying the integ

03.14.11EActive

Integration of Detection and Response

Integrating detection and response ensures that detected events are tracked, monitored, corrected, and available for historical purposes. Maintaining historical records is important to identify and discern adversary actions over an extended time period and for possible legal actions. Security-relevant changes include unauthorized changes to established configuration settings or the unauthorized elevation of system pr

03.14.12EActive

Information Input Validation

Checking the valid syntax and semantics of system inputs—including character set, length, numerical range, and acceptable values—verifies that inputs match specified definitions for format and content. Valid inputs are likely to vary from field to field within a software application. Applications typically follow well-defined protocols that use structured messages (i.e., commands or queries) to communicate between so

03.14.13EActive

Error Handling

Organizations consider the structure and content of error messages. The extent to which systems can handle error conditions is guided and informed by organizational policy and operational requirements. Exploitable information includes stack traces and implementation details; erroneous logon attempts with passwords mistakenly entered as the username; mission or business information that can be derived from, if not sta

03.14.14EActive

Memory Protection

Some adversaries launch attacks with the intent of executing code in non-executable regions of memory or in memory locations that are prohibited. The safeguards used to protect memory include data execution prevention and address space layout randomization (ASLR). Data execution prevention safeguards can be hardware- or software-enforced with hardware enforcement providing the greater strength of mechanism. This requ

03.14.15EActive

Non-Persistent System Components and Services

Implementation of non-persistent components and services mitigates risk from advanced persistent threats (APTs) by reducing the targeting capability of adversaries (i.e., window of opportunity and available attack surface) to initiate and complete attacks. By implementing the concept of non-persistence for selected system components and services, organizations can provide a trusted computing resource for a specific t

03.14.16EActive

Tainting

Many cyber-attacks target organizational information or information that the organization holds on behalf of other entities with the intent to exfiltrate that information. In addition, insider attacks and erroneous user procedures can remove information from the system in violation of organizational policies. Tainting approaches can range from passive to active. A passive tainting approach can be as simple as adding

03.14.17EActive

System-Generated Alerts

Alerts may be generated from different sources internal to the system, including audit records, inputs from malicious code protection mechanisms, intrusion detection or prevention mechanisms, or boundary protection devices such as firewalls, gateways, and routers. Compromise indicators could include CUI being accessed by unauthorized users or when CUI traverses architecture outside of defined data flows. Alerts can b

03.14.18EActive

Automated Organization-Generated Alerts

Organization-generated alerts are focused on information sources that are external to the system, such as suspicious activity reports and reports on potential insider threats. Organizational personnel on the system alert notification list include system administrators, mission or business owners, system owners, chief information security officers, and system security officers. This requirement enhances SP 800-171 req

03.14.19EActive

Wireless Intrusion Detection

Wireless signals may radiate beyond organizational facilities. Organizations proactively search for unauthorized wireless connections, including the conduct of thorough scans for unauthorized wireless access points. Wireless scans are not limited to those areas within facilities containing systems but also include areas outside of facilities to verify that unauthorized wireless access points are not connected to orga

03.15.01EActive

Security Architecture

The security architecture at the system level is consistent with the organization-wide security architecture, which is integral to and developed as part of the enterprise architecture. The security architecture includes an architectural description, the allocation of security functionality (i.e., safeguards and countermeasures), security-related information for external interfaces, information being exchanged across

03.15.02EActive

Defense In Depth

Organizations strategically allocate security requirements and the associated protection mechanisms in the security architecture so that adversaries must overcome multiple defensive layers to achieve their objective. Requiring adversaries to defeat multiple defensive layers makes it more difficult to attack systems by increasing the work factor of the adversary. It also increases the likelihood of detection. Defense-

03.15.03EActive

Supplier Diversity

Information technology products have different strengths and weaknesses. Providing a broad spectrum of products complements the individual offerings. For example, vendors that offer malicious code protection typically update their products at different times and develop solutions for known viruses, Trojans, or worms based on their priorities and development schedules. Deploying different types of products from a dive

03.16.01EActive

Specialization

Systems or system components that support mission-essential services or functions can be enhanced or strengthened to maximize the trustworthiness of the resource. Sometimes, this enhancement or strengthening is done at the design level. In other instances, it is done post-design, either through modifications of the system in question or by augmenting the system with additional components. For example, supplemental au

03.17.01EActive

Notification Agreements

Establishing agreements and procedures facilitates communications among supply chain entities. Early notification of compromises and potential compromises in the supply chain that may adversely affect or have adversely affected organizational systems or system components is essential for organizations to effectively respond to such incidents. The results of assessments or audits may include open-source information th

03.17.02EActive

Inspection of Systems or Components

Inspecting systems or systems components for evidence of tampering addresses physical and logical tampering and is applied to systems and system components that are removed from organization-controlled areas. Indications of a need for inspection include changes in packaging, specifications, factory location, or entity in which the part is purchased, and when individuals return from travel to high-risk locations. This

03.17.03EActive

Component Authenticity

Sources of counterfeit components include manufacturers, developers, vendors, and contractors. Anti-counterfeiting policies and procedures support tamper resistance and provide a level of protection against the introduction of malicious code. External reporting organizations include the Cybersecurity and Infrastructure Security Agency (CISA). This requirement is sourced to a control tailored out of the SP 800-53B .13

03.17.04EActive

Provenance

Every system and system component has a point of origin and may be changed throughout its existence. Provenance is the chronology of the origin, development, ownership, location, and changes to a system or system component and associated data. It may also include personnel and processes used to interact with or make modifications to the system, component, or associated data. Organizations have methods to document, mo

03.17.05EActive

Supply Chain Integrity – Pedigree

Authoritative information regarding the internal composition of system components and the provenance of technology, products, and services provides a strong basis for trust. The validation of the internal composition and provenance of technologies, products, and services is referred to as the pedigree. For microelectronics, this includes the material composition of components. For software this includes the compositi

Source and interpretation boundary

Official NIST requirement, discussion, parameter, source-control, and assessment content is labeled separately from original Bare Metal Cyber implementation guidance and learning recommendations.