Blog

What is NIST 800-171?

Written by Waits Sharpe | Aug 8, 2022 6:35:58 PM

NIST, or The National Institute of Standards and Technology, is a federal agency responsible for ensuring the protection of classified information entrusted to private contractors or third party organizations. According to NIST their mission is to "promote U.S. innovation and industrial competitiveness by advancing measurement science, standards, and technology in ways that enhance economic security and improve our quality of life". One way that NIST promotes security is through the creation of frameworks such as NIST 800-171 to ensure the safety and handling of critical information.

Below is a Brief Description of What Is NIST 800-171 and What It Entails.

A Summary of NIST 800-171

NIST 800-171 was created by NIST to help defense contractors protect "controlled unclassified information(CUI)". CUI includes personal information, intellectual property, and other federally protected information that is entrusted to third party organization. The goal of NIST 800-171 is to create a standardized system of protecting CUI across all federal agencies as a direct response to President Obama's 2010 executive order mandating more strict protection of CUI. Today NIST 800-171 is still implemented and included other regulations including CMMC.

The NIST 800-171 framework contains 110 controls divided into 14 "control families" listed below:

  1. Access Control
  2. Awareness and Training
  3. Audit and Accountability
  4. Configuration Management
  5. Identification and Authentication
  6. Incident Response
  7. Maintenance
  8. Media Protection
  9. Personnel Security
  10. Physical Protection
  11. Risk Assessment
  12. Security Assessment
  13. System and Communications Protection
  14. System and Information

If you are a third-party contractor working with the federal government then you will have to comply with NIST 800-171 standards!

CorpInfoTech is ready and willing to help you on your compliance journey. Contact us today to see how you can begin implementing the required NIST 800-171 controls.

CorpInfoTech (Corporate Information Technologies) provides small to mid-market organizations with expert I.T. services including compliance assessment, cybersecurity penetration tests, and comprehensive business continuity planning services. CorpInfoTech can help organizations, quantify, create, refine, and mitigate the risks presented by business threatening disasters in whatever form they may be disguised.