NIST Special Publication 800-171 Revision 2| 3.1.4 | Separate the duties of individuals to reduce the risk of malevolent activity without collusion |
| 3.3.8 | Protect audit information and audit logging tools from unauthorized access, modification, and deletion |
| 3.3.9 | Limit management of audit logging functionality to a subset of privileged users |
| 3.4.1 | Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles |
| 3.4.2 | Establish and enforce security configuration settings for information technology products employed in organizational systems |
| 3.4.3 | Track, review, approve or disapprove, and log changes to organizational systems |
| 3.4.5 | Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems |
| 3.7.2 | Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance |
| 3.7.6 | Supervise the maintenance activities of maintenance personnel without required access authorization |
| 3.8.1 | Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital |
| 3.10.1 | Limit physical access to organizational systems, equipment, and the respective operating environments to authorized individuals |
| 3.10.2 | Protect and monitor the physical facility and support infrastructure for organizational systems |
| 3.13.2 | Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems |
| 3.13.10 | Establish and manage cryptographic keys for cryptography employed in organizational systems |
| 3.13.13 | Control and monitor the use of mobile code |