NIST Special Publication 800-171 Revision 2| 3.1.1 | Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems) |
| 3.1.2 | Limit system access to the types of transactions and functions that authorized users are permitted to execute |
| 3.1.5 | Employ the principle of least privilege, including for specific security functions and privileged accounts |
| 3.1.6 | Use non-privileged accounts or roles when accessing nonsecurity functions |
| 3.1.7 | Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs |
| 3.1.15 | Authorize remote execution of privileged commands and remote access to security-relevant information |
| 3.4.2 | Establish and enforce security configuration settings for information technology products employed in organizational systems |
| 3.7.2 | Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance |
| 3.7.4 | Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems |
| 3.11.2 | Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified |
| 3.11.3 | Remediate vulnerabilities in accordance with risk assessments |
| 3.13.2 | Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems |
| 3.13.3 | Separate user functionality from system management functionality |
| 3.14.1 | Identify, report, and correct system flaws in a timely manner |