Under active development Content is continuously updated and improved
Home / Frameworks / NIST SP 800-171 Rev 3

NIST SP 800-171 Rev 3 vRev 3

CUI Protection Requirements Rev 3

Framework data extracted from the Secure Controls Framework (SCF) v2025.4 Set Theory Relationship Mapping (STRM) files, licensed under CC BY-ND 4.0 . Attribution required per license terms.

382 All

03.01 Access Control (77 requirements)

03.01.01Account Management
03.01.01.aAccount Management a
03.01.01.bAccount Management b
03.01.01.cAccount Management c
03.01.01.c.01Account Management c.01
03.01.01.c.02Account Management c.02
03.01.01.c.03Account Management c.03
03.01.01.dAccount Management d
03.01.01.d.01Account Management d.01
03.01.01.d.02Account Management d.02
03.01.01.eAccount Management e
03.01.01.fAccount Management f
03.01.01.f.01Account Management f.01
03.01.01.f.02Account Management f.02
03.01.01.f.03Account Management f.03
03.01.01.f.04Account Management f.04
03.01.01.f.05Account Management f.05
03.01.01.gAccount Management g
03.01.01.g.01Account Management g.01
03.01.01.g.02Account Management g.02
03.01.01.g.03Account Management g.03
03.01.01.hAccount Management h
03.01.02Access Enforcement
03.01.03Information Flow Enforcement
03.01.04Separation of Duties
03.01.04.aSeparation of Duties a
03.01.04.bSeparation of Duties b
03.01.05Least Privilege
03.01.05.aLeast Privilege a
03.01.05.bLeast Privilege b
03.01.05.cLeast Privilege c
03.01.05.dLeast Privilege d
03.01.06Least Privilege - Privileged Accounts
03.01.06.aLeast Privilege - Privileged Accounts a
03.01.06.bLeast Privilege - Privileged Accounts b
03.01.07Least Privilege - Privileged Functions
03.01.07.aLeast Privilege - Privileged Functions a
03.01.07.bLeast Privilege - Privileged Functions b
03.01.08Unsuccessful Logon Attempts
03.01.08.aUnsuccessful Logon Attempts a
03.01.08.bUnsuccessful Logon Attempts b
03.01.09Privacy and Security Notices
03.01.10Session Lock
03.01.10.aSession Lock a
03.01.10.bSession Lock b
03.01.10.cSession Lock c
03.01.11Session Termination
03.01.12Remote Access
03.01.12.aRemote Access a
03.01.12.bRemote Access b
03.01.12.cRemote Access c
03.01.12.dRemote Access d
03.01.13Remote Access - Routing Through Managed Access Control Points
03.01.14Remote Access - Cryptographic Protection
03.01.15Remote Access - Managed Access Control Points
03.01.16Wireless Access
03.01.16.aWireless Access a
03.01.16.bWireless Access b
03.01.16.cWireless Access c
03.01.16.dWireless Access d
03.01.17Wireless Access - Authentication and Encryption
03.01.18Mobile Device Connection
03.01.18.aMobile Device Connection a
03.01.18.bMobile Device Connection b
03.01.18.cMobile Device Connection c
03.01.19Access Control for CUI on Public Systems
03.01.20Use of External Systems
03.01.20.aUse of External Systems a
03.01.20.bUse of External Systems b
03.01.20.cUse of External Systems c
03.01.20.c.01Use of External Systems c.01
03.01.20.c.02Use of External Systems c.02
03.01.20.dUse of External Systems d
03.01.21Portable Storage Devices
03.01.22Publicly Accessible Content
03.01.22.aPublicly Accessible Content a
03.01.22.bPublicly Accessible Content b