NIST Special Publication 800-171 Revision 2
IDName
3.1.1Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems)
3.1.3Control the flow of CUI in accordance with approved authorizations
3.1.10Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity
3.1.13Employ cryptographic mechanisms to protect the confidentiality of remote access sessions
3.1.15Authorize remote execution of privileged commands and remote access to security-relevant information
3.1.17Protect wireless access using authentication and encryption
3.1.19Encrypt CUI on mobile devices and mobile computing platforms
3.1.20Verify and control/limit connections to and use of external systems
3.1.21Limit use of portable storage devices on external systems
3.1.22Control CUI posted or processed on publicly accessible systems
3.2.3Provide security awareness training on recognizing and reporting potential indicators of insider threat
3.5.10Store and transmit only cryptographically-protected passwords
3.5.11Obscure feedback of authentication information
3.7.3Ensure equipment removed for off-site maintenance is sanitized of any CUI
3.8.1Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
3.8.2Limit access to CUI on system media to authorized users
3.8.3Sanitize or destroy system media containing CUI before disposal or release for reuse
3.8.4Mark media with necessary CUI markings and distribution limitations
3.8.5Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas
3.8.6Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards
3.8.7Control the use of removable media on system components
3.8.8Prohibit the use of portable storage devices when such devices have no identifiable owner
3.8.9Protect the confidentiality of backup CUI at storage locations
3.9.1Screen individuals prior to authorizing access to organizational systems containing CUI
3.9.2Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers
3.10.1Limit physical access to organizational systems, equipment, and the respective operating environments to authorized individuals
3.10.6Enforce safeguarding measures for CUI at alternate work sites
3.13.1Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems
3.13.2Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems
3.13.4Prevent unauthorized and unintended information transfer via shared system resources
3.13.7Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling)
3.13.8Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
3.13.10Establish and manage cryptographic keys for cryptography employed in organizational systems
3.13.11Employ FIPS-validated cryptography when used to protect the confidentiality of CUI
3.13.12Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device
3.13.16Protect the confidentiality of CUI at rest