NIST Special Publication 800-171 Revision 2| 3.1.1 | Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems) |
| 3.1.3 | Control the flow of CUI in accordance with approved authorizations |
| 3.1.10 | Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity |
| 3.1.13 | Employ cryptographic mechanisms to protect the confidentiality of remote access sessions |
| 3.1.15 | Authorize remote execution of privileged commands and remote access to security-relevant information |
| 3.1.17 | Protect wireless access using authentication and encryption |
| 3.1.19 | Encrypt CUI on mobile devices and mobile computing platforms |
| 3.1.20 | Verify and control/limit connections to and use of external systems |
| 3.1.21 | Limit use of portable storage devices on external systems |
| 3.1.22 | Control CUI posted or processed on publicly accessible systems |
| 3.2.3 | Provide security awareness training on recognizing and reporting potential indicators of insider threat |
| 3.5.10 | Store and transmit only cryptographically-protected passwords |
| 3.5.11 | Obscure feedback of authentication information |
| 3.7.3 | Ensure equipment removed for off-site maintenance is sanitized of any CUI |
| 3.8.1 | Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital |
| 3.8.2 | Limit access to CUI on system media to authorized users |
| 3.8.3 | Sanitize or destroy system media containing CUI before disposal or release for reuse |
| 3.8.4 | Mark media with necessary CUI markings and distribution limitations |
| 3.8.5 | Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas |
| 3.8.6 | Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards |
| 3.8.7 | Control the use of removable media on system components |
| 3.8.8 | Prohibit the use of portable storage devices when such devices have no identifiable owner |
| 3.8.9 | Protect the confidentiality of backup CUI at storage locations |
| 3.9.1 | Screen individuals prior to authorizing access to organizational systems containing CUI |
| 3.9.2 | Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers |
| 3.10.1 | Limit physical access to organizational systems, equipment, and the respective operating environments to authorized individuals |
| 3.10.6 | Enforce safeguarding measures for CUI at alternate work sites |
| 3.13.1 | Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems |
| 3.13.2 | Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems |
| 3.13.4 | Prevent unauthorized and unintended information transfer via shared system resources |
| 3.13.7 | Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling) |
| 3.13.8 | Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards |
| 3.13.10 | Establish and manage cryptographic keys for cryptography employed in organizational systems |
| 3.13.11 | Employ FIPS-validated cryptography when used to protect the confidentiality of CUI |
| 3.13.12 | Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device |
| 3.13.16 | Protect the confidentiality of CUI at rest |