NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI)
Evidence request list. 97 controls, 97 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
171A 03.01 Access Control
Determines whether account types are defined and bounded, whether accounts are created, modified, disabled and removed under a documented process, and whether account use is monitored and periodically re-authorized.
- account management policy and procedure
- system account inventory showing type, owner and authorizing manager
- joiner, mover and leaver tickets sampled across the period
- periodic account recertification output
- logs or reports showing account use monitoring
- shared and service accounts absent from the inventory
- no recertification evidence, only a policy that requires it
- accounts of departed staff still enabled at the time of test
Determines whether approved authorizations are actually enforced by the system rather than merely documented, by testing access decisions against the recorded entitlements.
- access control configuration or rule set export
- entitlement listings per system holding CUI
- test results showing an unauthorized attempt being denied
- mapping from role to permission
- policy states least privilege but the rule set grants broad access
- enforcement demonstrated on one system and assumed for the rest
- no negative test, only evidence that authorized access works
Determines whether approved rules governing where CUI may move, inside the system and to connected systems, are implemented and enforced at the enforcement points.
- documented CUI flow rules and approved flow paths
- firewall, proxy or data loss prevention rule sets implementing those flows
- network or data flow diagram identifying CUI paths
- test evidence of a disallowed flow being blocked
- flow diagram exists but does not match the deployed rule set
- egress paths such as webmail and cloud storage never assessed
- rules permit any-any within a zone that includes non-CUI systems
Determines whether duties that would allow one person to act without check have been identified and split, and whether system access reflects that split.
- documented duty separation analysis or conflict matrix
- role definitions and assignment listings
- evidence of compensating monitoring where separation is not practical
- exception approvals for combined duties
- conflict matrix never compared against actual assignments
- small teams claim impracticality with no compensating control
- developer and production approver held by the same identity
Determines whether authorizations granted are limited to what each user needs for assigned duties, and whether privilege grants are reviewed rather than left to accumulate.
- role to entitlement mapping
- privilege review records with dates and outcomes
- evidence of removals arising from review
- approval records for elevated grants
- review confirms accounts exist rather than testing whether privilege is still needed
- privilege creep after internal transfers
- broad administrative groups used as a default
Determines whether privileged accounts are restricted to named personnel with an authorized need and are separated from those users' ordinary accounts.
- list of privileged accounts and the individuals holding them
- authorization records for each privileged grant
- evidence that administrators hold separate ordinary accounts
- privileged session logs
- administrators browse and read mail from the privileged account
- privileged group membership never reconciled to the authorized list
- vendor or emergency accounts with standing privilege
Determines whether privileged functions are prevented from being executed by non-privileged users and whether such execution attempts are captured in the audit record.
- definition of privileged functions for each system type
- configuration preventing execution by non-privileged users
- audit records showing captured attempts
- test evidence of a blocked attempt
- no definition of what counts as a privileged function
- local administrator rights left with standard users
- attempts blocked but not logged
Determines whether a limit on consecutive failed logons is set and whether the defined response, such as lockout or delay, actually occurs when the limit is reached.
- configured attempt limit and lockout action per platform
- test evidence of lockout triggering
- records of lockout events and unlock procedure
- coverage list showing which systems enforce it
- setting applied to the domain but not to standalone or cloud systems
- lockout configured with an immediate automatic reset that defeats it
- no evidence the setting was tested, only a screenshot of policy
Determines whether the approved use notification is displayed before access is granted and remains until the user acknowledges it.
- approved banner text
- screenshots or test evidence from each access path including remote and console
- configuration setting deploying the banner
- banner present on workstations but absent on remote access and network devices
- text differs from the approved version
- banner shown after authentication rather than before
Determines whether sessions are locked after a defined period of inactivity or on user action, and whether the lock conceals what was on screen until the user re-authenticates.
- configured inactivity period per platform
- evidence that the lock hides displayed information
- test evidence of re-authentication being required
- coverage across laptops, servers and mobile
- timeout longer than the defined period on a subset of devices
- screen saver without a re-authentication requirement
- mobile devices excluded from the setting
Determines whether user sessions are terminated automatically when the defined conditions occur, rather than merely locked.
- defined termination conditions
- configuration implementing automatic termination
- test evidence that the session ends and cannot be resumed
- application and remote access session settings
- lock treated as termination
- conditions defined only for the operating system, not applications
- idle web sessions persist through cookies after termination
Determines whether remote access types are authorized in advance, routed through managed access points, and monitored and controlled while in use.
- inventory of permitted remote access methods
- authorization records per user or role
- configuration of managed access control points
- remote session logs and monitoring output
- unmanaged remote support tools installed by teams outside the inventory
- split tunnelling permits direct egress bypassing controls
- no monitoring of the remote access concentrator itself
Determines whether wireless access is authorized before connection is allowed and whether the wireless service is protected by authentication and encryption.
- wireless authorization records
- controller configuration showing authentication and encryption settings
- site survey or rogue access point detection output
- list of wireless networks carrying CUI
- guest and corporate wireless sharing an uncontrolled path
- pre-shared keys never rotated after staff departures
- rogue detection not run or its alerts unactioned
Determines whether mobile devices connecting to the system are authorized, controlled and protected, including encryption of CUI held on them.
- mobile device authorization records
- mobile device management enrolment and compliance report
- encryption status per device
- procedure for lost or stolen devices
- personally owned devices access CUI outside management
- encryption reported by policy rather than by device attestation
- devices out of compliance remain connected
Determines whether the terms on which external systems may access, process or store CUI are established and verified, rather than assumed.
- list of external systems used with CUI including cloud services
- agreements or terms setting the security conditions
- verification evidence such as an assessment report or attestation
- restrictions configured on external connections
- shadow cloud services never inventoried
- agreement exists but no verification that terms are met
- no restriction on portable storage used with external systems
Determines whether authorized publishers are designated, whether content is reviewed before publication, and whether published content is re-reviewed and corrected when CUI is found.
- list of designated publishers and their training records
- pre-publication review records
- periodic review of public sites
- records of removals where CUI was found
- review process covers the website but not public code repositories or file shares
- no periodic re-review after initial publication
- removal performed with no record of what was exposed
171A 03.02 Awareness and Training
Determines whether awareness training is provided at the defined points and frequency, covers recognition and reporting of relevant threats including insider threat, and is updated.
- training content or syllabus
- completion records against the current staff list
- schedule showing initial and recurring delivery
- evidence of content updates reflecting current threats
- completion percentages reported without a reconciled population
- contractors and temporary staff outside the tracking
- content unchanged for years despite changed threat
Determines whether personnel holding roles with security duties receive training specific to those duties before assuming them and at the defined frequency.
- mapping of security-relevant roles to required training
- completion records per role holder
- evidence training precedes assumption of duties
- refresher schedule
- general awareness training counted as role-based
- privileged administrators with no role-specific training
- role mapping not maintained after reorganizations
171A 03.03 Audit and Accountability
Determines whether the event types to be logged are defined, reviewed and updated, and whether the system logs those events.
- defined list of logged event types with rationale
- logging configuration per platform
- evidence of periodic review of the event list
- sample records showing the defined events present
- event list copied from a template and never tailored
- cloud and SaaS platforms outside the logging scope
- review of the event list never performed
Determines whether audit records carry enough detail to establish what happened, when, where, the source and the identity involved.
- sample audit records from each major platform
- field mapping showing the required elements are present
- configuration enabling the fields
- records lack user identity because a shared service account performs the action
- timestamps without a timezone or in local time only
- source host absent from forwarded records
Determines whether audit records are generated for the defined events across the components that require them, and whether generation is under controlled selection.
- component inventory mapped to logging coverage
- configuration showing generation enabled
- evidence of who may change what is logged
- sample records from each component class
- coverage list omits network devices or hypervisors
- any administrator can silently change logging selection
- generation enabled but records never leave the host
Determines whether logging failures raise an alert to defined personnel within a defined period and whether a defined response follows.
- configured alert on logging failure and its recipients
- records of failure alerts and the response taken
- defined response actions such as overwrite, shutdown or notify
- test evidence of an induced failure
- alerts route to an unmonitored mailbox
- storage exhaustion silently overwrites records
- no evidence that any failure alert has ever been actioned
Determines whether audit records are reviewed and analysed at a defined frequency for indications of unlawful or unauthorized activity, and whether findings are reported.
- review procedure with frequency and scope
- dated review records showing what was examined and by whom
- records of findings and their escalation
- correlation across sources where used
- tool alerts treated as the review with no human analysis
- review evidence exists for one month only
- findings recorded but never reported or closed
Determines whether the capability exists to reduce audit records and generate reports supporting on-demand review and investigation, without altering the original records.
- examples of generated reports and queries
- evidence that original records are preserved unchanged
- demonstration of on-demand search across the retention period
- search available only for a recent window shorter than retention
- reduction performed by deleting rather than summarizing
- no capability demonstrated, only a tool licence
Determines whether records carry timestamps from an authoritative source and meet the defined granularity, so events can be sequenced across systems.
- time source configuration and hierarchy
- evidence of synchronization status across components
- sample records showing timestamp format and granularity
- drift monitoring output
- devices synchronizing to differing or external sources
- synchronization unmonitored so drift goes unnoticed
- records in local time without offset, defeating correlation
Determines whether audit records and the logging tools are protected from unauthorized access, modification and deletion, and whether access to them is limited to authorized personnel.
- access control lists on log stores and logging tools
- evidence of write-once, forwarding or other tamper resistance
- list of personnel authorized to manage logs
- records of access to audit information
- local administrators can clear the logs of the system they administer
- forwarding exists but the local copy remains alterable and is the one retained
- no separation between those who act and those who review their actions
171A 03.04 Configuration Management
Determines whether a current baseline configuration is documented and maintained for the system, and whether it is reviewed and updated under change control.
- current baseline documents per platform type
- version history showing review and update
- evidence the baseline reflects deployed state
- change records driving baseline updates
- baseline drafted at build time and never updated
- no baseline for cloud or container images
- baseline exists but deployed systems were never compared to it
Determines whether secure settings are established, documented and applied, and whether deviations are identified and approved.
- documented setting standards and their source
- compliance scan or configuration report against those standards
- approved deviation records with rationale
- remediation records for non-compliant settings
- hardening standard adopted but never measured
- deviations tolerated informally with no approval
- scanning covers servers only, not network or endpoint
Determines whether changes are proposed, reviewed, approved or rejected, and recorded, and whether implemented changes match what was approved.
- change management procedure
- change records sampled across the period showing review and approval
- evidence linking implemented change to its approval
- emergency change handling records
- emergency changes never retrospectively approved
- approval by the same person who made the change
- changes made directly in cloud consoles outside the process
Determines whether the security impact of a change is analysed before implementation and whether the analysis informs the approval decision.
- impact analysis records attached to sampled changes
- criteria defining when analysis is required
- evidence the analysis influenced approval or rollback planning
- impact field completed as a formality with no content
- analysis performed after deployment
- no analysis for infrastructure-as-code changes
Determines whether physical and logical access to make changes is restricted to authorized personnel and whether the restriction is enforced and recorded.
- list of personnel authorized to change each environment
- access control configuration on repositories, pipelines and production
- records of change access being exercised
- separation between build and deploy authority
- broad developer access to production persists from an earlier migration
- pipeline service accounts hold unrestricted deployment rights
- no record of who executed a given change
Determines whether systems are configured to provide only essential capability, and whether non-essential functions, ports, protocols and services are disabled or restricted.
- definition of essential functions per system role
- port, protocol and service inventory with justification
- scan output showing what is actually listening
- records of disabling non-essential functions
- justification list not reconciled to scan results
- default services left enabled on appliances
- review performed at build only
Determines whether a deny-all, permit-by-exception policy for software execution is defined and enforced, and whether the authorized list is reviewed.
- authorized software list and its approval record
- execution control configuration and enforcement mode
- review records for the list
- test evidence that unauthorized software is blocked
- control deployed in audit mode only
- list maintained but enforcement excludes user-writable paths
- exceptions granted permanently without review
Determines whether an inventory of components is maintained at the defined granularity, kept current, and reconciled to what is actually connected.
- component inventory export with required attributes
- reconciliation between inventory and discovery scan
- procedure and frequency for update
- records of unauthorized components found and handled
- inventory maintained by hand and stale within weeks
- virtual, cloud and container assets excluded
- discovery finds assets absent from the inventory with no follow up
Determines whether the locations of CUI and the components processing or storing it are identified and documented, and kept current as systems change.
- record of where CUI is stored, processed and transmitted
- component list flagged for CUI handling
- procedure for updating on change
- evidence of discovery or scanning used to confirm
- location documented for primary systems while backups and file shares are omitted
- no re-check after migrations
- CUI in collaboration tools not recognised as a location
Determines whether components taken to high-risk areas receive the defined configuration and whether the defined controls are applied on return.
- defined high-risk areas and issue procedure
- configuration standard for travel devices
- records of devices issued and returned
- inspection, wipe or rebuild records on return
- policy exists but no record of any device being issued under it
- returned devices reconnected without inspection
- standard travel build identical to the ordinary build
171A 03.05 Identification and Authentication
Determines whether users and their processes are uniquely identified and authenticated before access, and whether re-authentication occurs under the defined circumstances.
- identity store showing unique identifiers
- authentication configuration per access path
- defined re-authentication triggers and evidence they fire
- test of access without authentication being refused
- shared accounts defeat unique identification
- re-authentication triggers defined but not configured
- service and machine identities unmanaged
Determines whether devices are uniquely identified and authenticated before connections are established, where required.
- defined device types requiring authentication
- network access control or certificate configuration
- enrolment records for authenticated devices
- test evidence of an unknown device being refused
- MAC filtering presented as device authentication
- policy covers wired but not wireless or VPN
- exception list large enough to defeat the control
Determines whether multi-factor authentication is implemented for the required access, including privileged and network access, and whether it cannot be bypassed.
- scope statement of where MFA is required
- configuration and enrolment reports
- evidence of bypass and exception handling
- test of access attempted without the second factor
- legacy protocols left open as an MFA bypass
- break-glass accounts exempt with no compensating monitoring
- MFA on the portal but not on direct or API access
Determines whether authentication mechanisms resist replay for the required access types.
- protocol and mechanism inventory for authentication paths
- configuration showing replay-resistant mechanisms in use
- evidence that weaker mechanisms are disabled
- deprecated protocols enabled for compatibility
- claim of resistance without identifying the mechanism
- only interactive logon considered, not service authentication
Determines whether identifiers are authorized before assignment, kept unique to an individual or device, and prevented from reuse for the defined period.
- identifier assignment authorization records
- evidence of uniqueness enforcement
- reuse prevention setting or procedure
- records of identifiers retired
- identifiers recycled for new starters with the same name
- no authorization step before creation
- device identifiers unmanaged
Determines whether password composition, protection and change requirements are implemented, including protection of stored and transmitted passwords and screening against compromised values.
- password policy configuration per platform
- evidence of cryptographic protection in storage and transit
- compromised password screening evidence
- procedure for initial and reset passwords
- policy set in the domain while applications keep their own weaker rules
- no screening against known-compromised passwords
- initial passwords predictable and not forced to change
Determines whether feedback during authentication is obscured so that it does not reveal information usable by an unauthorized person.
- test evidence from each authentication interface
- configuration masking entry and error detail
- review of error messages for account enumeration
- error messages distinguish unknown user from wrong password
- mobile or kiosk interfaces reveal entered characters
- password visible in a support tool
Determines whether authenticators are verified before issue, protected in use, changed at defined events, and revoked when no longer valid.
- issuance procedure including identity verification
- records of issue, change and revocation
- protection measures for authenticators in storage and transit
- evidence of revocation on termination
- certificates or tokens never revoked after departure
- default authenticators unchanged on appliances
- no verification of identity before reset
171A 03.06 Incident Response
Determines whether an incident handling capability covering preparation, detection and analysis, containment, eradication and recovery exists and is used.
- incident handling procedure
- incident records showing the phases applied
- roles and contact list
- evidence of lessons feeding back into the process
- records show detection and closure with no containment or eradication detail
- capability described but no incidents ever recorded
- handling documented only for major incidents
Determines whether incidents are tracked and documented, reported to the defined internal and external parties within required times, and whether response assistance is available to users.
- incident tracking records with timeline
- external reporting records and timing evidence
- defined reporting thresholds and recipients
- help desk or response assistance route and its use
- external reporting obligations not identified
- reporting timers measured from triage rather than detection
- users have no route to report suspected incidents
Determines whether the incident response capability is tested at the defined frequency and whether the results are used to improve it.
- test or exercise plan and scenario
- dated test records with participants
- findings register from the test
- evidence of changes made in response
- test is a document walkthrough only, never a live exercise
- findings recorded with no owner or due date
- test excludes third parties who would be involved in a real incident
Determines whether personnel are trained in their incident response roles at defined points and frequency, consistent with the assigned role.
- training content per incident response role
- completion records for role holders
- schedule showing initial and refresher delivery
- evidence of update after process changes
- only the security team trained while system owners hold response duties
- training predates a significant process change
- no record of who currently holds each role
Determines whether an incident response plan exists, is distributed to the personnel who need it, is reviewed and updated, and is protected from unauthorized disclosure.
- current incident response plan with version and approval
- distribution list and evidence of distribution
- review and update history
- access restrictions on the plan
- plan names people who have left
- no review since issue
- plan stored only on the system it would be needed to recover
171A 03.07 Maintenance
Determines whether maintenance tools are approved, controlled and monitored, and whether media brought in for maintenance is checked for malicious code.
- approved maintenance tool list
- records of tool entry and removal
- scan records for maintenance media
- controls preventing unauthorized tool removal with data
- vendor laptops connected with no inspection
- diagnostic media never scanned
- tools left installed after the maintenance ends
Determines whether nonlocal maintenance is approved and monitored, uses multi-factor authentication and strong protection, and is terminated when complete.
- approval records for nonlocal maintenance sessions
- authentication configuration for maintenance access
- session logs and monitoring evidence
- evidence sessions and accounts are terminated afterwards
- permanent vendor access rather than session-based enablement
- sessions unmonitored once approved
- maintenance accounts remain enabled between engagements
Determines whether maintenance personnel are authorized, whether an escort with the necessary skills supervises those without authorization, and whether the authorization list is maintained.
- authorized maintenance personnel list
- escort procedure and escort records
- evidence of identity verification on arrival
- records of unescorted access grants
- escort present but without the skill to judge what is being done
- list not updated when vendor staff change
- access granted on the basis of a company name rather than an individual
171A 03.08 Media Protection
Determines whether media containing CUI is physically controlled and stored securely until sanitized or destroyed.
- media inventory or register
- description and evidence of the controlled storage location
- access records for the storage area
- procedure for check-in and check-out
- backup tapes and drives held in unlocked areas
- no register so loss would go unnoticed
- paper output containing CUI excluded from scope
Determines whether access to CUI on media is restricted to authorized personnel.
- list of personnel authorized to access media
- access control evidence for storage and systems
- records of media access events
- everyone with facility access can reach the media store
- authorization list not reconciled to current staff
- no distinction between access for storage handling and access to read content
Determines whether media is sanitized using approved techniques before disposal or release for reuse, and whether the action is recorded.
- sanitization procedure naming technique per media type
- sanitization or destruction records with serial numbers
- certificates from any third party performing destruction
- verification step evidence
- reliance on a supplier certificate with no verification
- reformatting treated as sanitization
- solid state and embedded storage handled with methods intended for magnetic media
Determines whether media containing CUI is marked with the required markings and distribution limitations.
- marking standard in use
- sample of marked media and containers
- procedure for marking on creation
- exception handling for areas where marking is impractical
- electronic media unmarked because only paper was considered
- markings inconsistent between originator and recipient
- no marking on media leaving the facility
Determines whether media in transport is protected and controlled, transport activities are recorded, and accountability is maintained during transit.
- transport procedure including protection method
- transport logs showing custody and receipt
- evidence of encryption or physical protection in transit
- authorized courier arrangements
- courier receipts kept but no record of what was sent
- encryption assumed rather than verified for transported drives
- no accountability between handover points
Determines whether the use of defined media types is restricted or prohibited, and whether portable storage without an identifiable owner is prohibited.
- media use policy naming permitted and prohibited types
- technical enforcement configuration
- records of approved exceptions
- evidence of blocking unidentifiable portable storage
- policy prohibits use while ports remain open
- enforcement on managed endpoints only
- exceptions granted with no expiry
Determines whether the confidentiality of CUI in backups is protected by cryptographic means.
- backup encryption configuration and algorithm in use
- evidence covering all backup destinations including offsite and cloud
- key management arrangements for backup keys
- restore test evidence
- primary backups encrypted while archive copies are not
- keys stored with the backup they protect
- encryption claimed at the storage layer without evidence it applies to the backup set
171A 03.09 Personnel Security
Determines whether individuals are screened before being granted access to CUI and rescreened where the defined conditions require it.
- screening criteria and procedure
- screening completion records for sampled individuals
- evidence screening precedes access
- rescreening conditions and records
- access granted before screening completes
- contractors screened by their employer with no verification
- no rescreening condition defined for role changes
Determines whether access is removed on termination and adjusted on transfer within the defined periods, and whether property and credentials are recovered.
- termination and transfer checklist
- records showing access removal timing against the defined period
- property and credential recovery records
- evidence of review after internal transfer
- removal recorded for the primary directory only, leaving application accounts active
- transfers add access without removing the previous set
- timing not measurable because removal is undated
171A 03.10 Physical Protection
Determines whether a list of individuals authorized to enter facilities holding CUI is maintained, credentials are issued on authorization, and the list is reviewed and revoked as required.
- authorized access list with review dates
- credential issue and return records
- approval records for new access
- revocation records
- list not reconciled to the badge system
- reviews performed but with no removals ever resulting
- contractor badges not returned or deactivated
Determines whether physical access is monitored, access logs are reviewed, and apparent incidents are responded to.
- access control system logs
- review records showing dates and reviewer
- alarm and incident response records
- camera or intrusion detection coverage of CUI areas
- logs retained but never reviewed
- review covers entries only, not failed attempts or after-hours access
- incidents noted with no response recorded
Determines whether the security requirements applying at alternate work sites are defined and whether their use is assessed.
- defined controls for alternate work sites
- evidence of assessment or attestation of those controls
- agreements with personnel working remotely
- technical controls compensating for the site
- home working permitted with no defined requirements
- requirements defined but never assessed
- controls assume a corporate network that remote sites do not use
Determines whether physical access at entry and exit points is enforced and verified, visitors are controlled, and physical access devices are secured and inventoried.
- entry point control description and evidence
- visitor register and escort records
- key and access device inventory with issue records
- evidence of periodic device inventory and combination change
- tailgating uncontrolled at shared entrances
- visitor register incomplete or unescorted access common
- keys issued with no inventory or return process
Determines whether transmission lines and distribution points carrying CUI are protected from interception and damage.
- identification of transmission media and distribution points carrying CUI
- evidence of physical protection such as locked rooms, conduit or sealed enclosures
- inspection records
- comms rooms shared with other tenants and unsecured
- patch panels accessible from public areas
- protection considered for the data centre only, not the floor distribution
171A 03.11 Risk Assessment
Determines whether risk to operations, assets and individuals arising from the processing, storage or transmission of CUI is assessed and updated at the defined frequency and on significant change.
- risk assessment report with scope and date
- methodology defining likelihood and impact
- evidence of update on significant change
- register linking assessed risks to owners
- assessment covers the organization generally and never names CUI systems
- single assessment years old with no update trigger
- risks recorded without owners or decisions
Determines whether systems are scanned for vulnerabilities at the defined frequency and on new vulnerability reports, whether results are analysed, and whether findings are remediated within defined periods.
- scan schedule and coverage against the asset inventory
- scan reports across the period
- remediation records with dates against the defined periods
- evidence of authenticated scanning where applicable
- scans unauthenticated and so understate findings
- coverage misses cloud, container or network assets
- findings ageing past the defined period with no risk acceptance
Determines whether findings from risk assessments and vulnerability activity are responded to in accordance with the organizational risk tolerance, and whether decisions are recorded.
- risk response decisions with rationale and approver
- risk tolerance statement
- tracking of mitigation actions to closure
- records of formal risk acceptance
- acceptance implied by inaction rather than decided
- acceptance approved below the level authorized to accept it
- no follow up on mitigations once recorded
171A 03.12 Security Assessment and Monitoring
Determines whether the requirements are assessed at the defined frequency to establish whether they are implemented correctly and producing the intended outcome, and whether results are documented.
- assessment plan and scope
- assessment results per requirement
- assessor identity and independence where relevant
- evidence of frequency being met
- assessment records the requirement as met with no supporting evidence
- scope excludes systems that process CUI
- assessment performed by the person who implemented the control with no review
Determines whether a plan of action is developed and maintained to record deficiencies and the actions and milestones to correct them.
- current plan of action with deficiencies, owners and dates
- update history showing maintenance
- evidence linking entries to assessment findings
- closure evidence for completed items
- milestone dates repeatedly moved with no explanation
- deficiencies closed with no evidence of the fix
- plan not updated after the most recent assessment
Determines whether the requirements are monitored on an ongoing basis, so that changes in effectiveness are noticed between formal assessments.
- monitoring strategy naming what is monitored and how often
- monitoring output such as dashboards or periodic reports
- evidence that monitoring results are reviewed and acted on
- frequency definition per control area
- monitoring exists for infrastructure metrics but not for control effectiveness
- reports produced but never reviewed
- strategy documented with no operating evidence
Determines whether the exchange of CUI with other systems is approved and governed by documented terms, and whether the interfaces and controls are recorded and reviewed.
- inventory of information exchanges involving CUI
- agreements or documented terms per exchange
- technical interface description and protections
- review records for the exchanges
- exchanges established by projects without any agreement
- agreement in place but the interface has since changed
- cloud data sharing not treated as an exchange
171A 03.13 System and Communications Protection
Determines whether communications are monitored and controlled at external boundaries and key internal boundaries, and whether subnetworks for publicly accessible components are separated.
- network diagram identifying external and key internal boundaries
- boundary device rule sets
- evidence of monitoring at those boundaries
- separation of publicly accessible components
- flat internal network with the CUI environment unsegmented
- rule sets accumulate permissive rules never reviewed
- cloud boundaries not treated as boundaries
Determines whether unauthorized and unintended transfer of information through shared system resources is prevented.
- configuration preventing residual data exposure such as object reuse settings
- evidence for shared storage, memory and virtualization layers
- test or vendor attestation covering the mechanism
- multi-tenant platforms assumed safe with no evidence
- clipboard, temp and swap areas unconsidered
- control claimed at the operating system while applications share caches
Determines whether network traffic is denied by default and permitted only by exception, at both entry and exit.
- rule set showing an explicit default deny at the end of the chain
- documented exceptions with business justification
- egress rules as well as ingress
- review records for the exception list
- default deny on inbound only, with outbound any-any
- exceptions undocumented and unowned
- cloud security groups permissive by default
Determines whether cryptographic mechanisms protect the confidentiality of CUI during transmission and while stored, unless otherwise protected.
- inventory of CUI transmission paths and stores with the protection applied
- cipher and protocol configuration evidence
- evidence of alternative physical safeguards where cryptography is not used
- scan output confirming weak protocols are disabled
- internal traffic left unencrypted on the assumption the network is trusted
- at-rest encryption on the database but not on exports and backups
- deprecated protocol versions still accepted
Determines whether network connections associated with a session are terminated at the end of the session or after a defined period of inactivity.
- configured inactivity period per service
- evidence the connection is closed rather than idled
- coverage across VPN, remote desktop and application sessions
- timeout set on the application while the underlying tunnel persists
- period longer than defined on some services
- keepalives defeat the inactivity measure
Determines whether keys are established and managed in accordance with defined requirements covering generation, distribution, storage, access and destruction.
- key management procedure covering the full lifecycle
- key inventory with owners and rotation dates
- evidence of protected storage such as a key store or hardware module
- records of key rotation and destruction
- keys stored in configuration files or source repositories
- no rotation because no inventory exists
- destruction never recorded so old keys may remain usable
Determines whether the cryptography used is of the type required for the protection of CUI and is implemented as configured.
- list of cryptographic modules and their validation status
- configuration showing approved algorithms and modes in use
- evidence non-approved algorithms are disabled
- mapping of each CUI protection point to its module
- validated module installed but the system runs in a non-approved mode
- approved list documented while legacy ciphers stay enabled
- cloud service cryptography accepted without checking what it uses
Determines whether remote activation of collaborative computing devices is prohibited except where permitted, and whether an indication of use is provided to users present.
- policy on cameras, microphones and conferencing devices
- configuration preventing remote activation
- evidence of a use indicator for those present
- exceptions and their approvals
- conferencing platform settings allow silent remote start
- indicator suppressed by the platform
- meeting room devices excluded from the policy
Determines whether the use of mobile code is controlled, with permitted technologies defined and their use authorized and monitored.
- definition of permitted and prohibited mobile code technologies
- browser and endpoint configuration enforcing the definition
- authorization records for permitted use
- monitoring or blocking evidence
- policy names outdated technologies and ignores current ones
- enforcement relies on user instruction only
- no monitoring of what actually executes
Determines whether the authenticity of communications sessions is protected, so that sessions cannot be hijacked or forged.
- protocol configuration providing session authenticity
- session token handling evidence for applications
- test evidence covering session fixation or hijack resistance
- session tokens transmitted or stored insecurely
- tokens not invalidated at logout
- authenticity assumed from transport encryption alone
171A 03.14 System and Information Integrity
Determines whether flaws are identified, reported and corrected, whether corrections are tested before installation, and whether they are installed within defined periods.
- patch management procedure with defined periods
- patch deployment reports against the asset inventory
- test records before deployment to production
- exception and deferral records
- compliance reported by percentage with no view of what remains unpatched
- emergency patches deployed with no test record
- firmware, appliances and third-party software outside the process
Determines whether malicious code protection is implemented at the required points, kept current, and configured to scan and act on detection.
- deployment coverage report against the asset inventory
- signature or engine currency evidence
- scan configuration including real time and scheduled scans
- records of detections and the action taken
- coverage gaps on servers or non-standard platforms
- definitions stale on a subset of endpoints
- detections logged with no response recorded
Determines whether alerts and advisories are received from defined external sources, disseminated internally, and acted on.
- named external sources and subscription evidence
- records of alerts received and disseminated
- evidence of actions taken in response to specific advisories
- defined internal recipients
- alerts received into a mailbox nobody owns
- dissemination happens but no action is traceable
- sources cover the operating system only, not the applications in use
Determines whether the system is monitored to detect attacks and indicators of potential attacks, including unauthorized connections, and whether detections are acted on.
- monitoring architecture showing sensors and coverage
- detection rules or use cases in place
- alert records with triage and outcome
- evidence of monitoring inbound and outbound traffic
- monitoring covers the perimeter but not internal lateral movement
- alerts generated in volume with no triage capacity
- unauthorized device connection not detectable
Determines whether CUI is managed and retained within the system in accordance with the applicable requirements, and disposed of when retention ends.
- retention schedule applicable to CUI
- evidence of retention settings implemented in systems
- disposal records at end of retention
- identification of where retained CUI resides
- retention schedule exists on paper with no system implementation
- data kept indefinitely because deletion is unowned
- backups retained far beyond the schedule
171A 03.15 Planning
Determines whether policies and procedures covering the requirement families exist, are disseminated, are reviewed and updated at the defined frequency, and identify responsible roles.
- policy set covering each family with approval and version
- dissemination evidence
- review and update records against the defined frequency
- named responsible roles
- policies approved once and never reviewed
- procedures describe a process that has since changed
- responsibility assigned to a role that no longer exists
Determines whether a system security plan is developed, describes the system boundary, environment, requirements and their implementation, and is reviewed and updated.
- current system security plan with version and approval
- boundary and environment description
- implementation statement per requirement
- review and update history
- plan describes intended rather than implemented state
- boundary omits systems that process CUI
- implementation statements are restatements of the requirement
Determines whether rules describing responsibilities and expected behaviour for CUI use are established, acknowledged by users before access, and reviewed and updated.
- rules of behaviour document
- acknowledgement records reconciled to the user population
- evidence acknowledgement precedes access
- review and reissue records after updates
- acknowledgement collected at hire only and never renewed after rule changes
- contractors outside the acknowledgement population
- rules generic with nothing specific to CUI handling
171A 03.16 System and Services Acquisition
Determines whether security engineering principles are applied to the specification, design, development and modification of the system.
- stated engineering principles adopted
- design or architecture review records showing their application
- evidence in requirements and design artefacts
- records for modifications as well as new build
- principles adopted in policy with no evidence in any design record
- applied to new build only while legacy modification is exempt
- reviews performed after implementation
Determines whether components no longer supported by the developer or vendor are replaced, or whether documented approval and mitigation exist for continued use.
- inventory flagged with support status and end-of-support dates
- replacement plans and progress
- approvals and documented mitigations for continued use
- evidence of compensating controls where used
- support status not tracked so end of life is discovered late
- continued use tolerated without approval or mitigation
- mitigation described but not implemented or verified
Determines whether providers of external system services are required to meet the applicable requirements, and whether compliance is defined, documented and monitored.
- inventory of external system services touching CUI
- contract terms or agreements imposing the requirements
- evidence of monitoring such as assessments, attestations or reports
- defined roles and responsibilities between the parties
- requirements flowed down in contract but never monitored
- attestation accepted covering a different scope than the service used
- subcontracted services invisible to the assessment
171A 03.17 Supply Chain Risk Management
Determines whether a plan for managing supply chain risk to the system and its components exists, is reviewed and updated, and is protected from unauthorized disclosure.
- current supply chain risk management plan with approval
- review and update records
- evidence the plan covers the system and its components
- access restrictions on the plan
- plan is a generic procurement policy with no system-specific content
- never updated after supplier changes
- plan not linked to the risk register or to acquisition decisions
Determines whether acquisition strategies, contract tools and procurement methods are used to identify, protect against and mitigate supply chain risk.
- procurement templates carrying security and supply chain terms
- evidence of supplier selection criteria including security
- records of tailored terms for higher-risk acquisitions
- evidence of use in actual purchases
- standard terms exist but purchasing routinely bypasses them
- criteria applied to new suppliers only
- no differentiation between critical and routine acquisitions
Determines whether a process for identifying and addressing weaknesses or deficiencies in the supply chain is established, and whether security requirements are enforced on suppliers.
- defined supply chain security requirements imposed on suppliers
- records of supplier assessment or review
- register of identified supplier weaknesses and their treatment
- evidence of enforcement or escalation
- requirements sent to suppliers but responses never evaluated
- weaknesses identified with no owner or remediation date
- enforcement route exists in contract but has never been used
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI) framework page.