All 110 security requirements
Each requirement has its own page: a plain-language version, the original wording, the assessment objectives an assessor checks, its scoring weight, and what changes in Rev. 3. The list is the whole NIST SP 800-171 Rev. 2 catalog; search and family filters narrow it.
- 3.1.1 Know who and what is allowed on your systems
- 3.1.2 Limit what each person can do once inside
- 3.1.3 Control where CUI is allowed to travel
- 3.1.4 Split duties so one person cannot do everything alone
- 3.1.5 Give people the least access they need
- 3.1.6 Do ordinary work from ordinary accounts
- 3.1.7 Stop and log privileged actions by non-admins
- 3.1.8 Lock accounts after repeated failed logins
- 3.1.9 Show a use notice at sign-in
- 3.1.10 Lock idle screens
- 3.1.11 End sessions automatically
- 3.1.12 Watch and control remote access
- 3.1.13 Encrypt remote access
- 3.1.14 Funnel remote access through known entry points
- 3.1.15 Approve remote admin work in advance
- 3.1.16 Approve wireless before it connects
- 3.1.17 Protect wireless with authentication and encryption
- 3.1.18 Control which mobile devices connect
- 3.1.19 Encrypt CUI on mobile devices
- 3.1.20 Verify and limit outside systems
- 3.1.21 Limit portable storage on outside systems
- 3.1.22 Review what goes on public sites
- 3.2.1 Make sure people know the risks
- 3.2.2 Train people for the security duties they hold
- 3.2.3 Cover insider threat
- 3.3.1 Keep logs, and keep them long enough
- 3.3.2 Tie actions to individuals
- 3.3.3 Revisit what you log
- 3.3.4 Get told when logging breaks
- 3.3.5 Correlate logs across systems
- 3.3.6 Be able to search and report on logs
- 3.3.7 Synchronize clocks
- 3.3.8 Protect the logs themselves
- 3.3.9 Restrict who manages logging
- 3.4.1 Know what you have and how it is set up
- 3.4.2 Enforce your settings
- 3.4.3 Track changes
- 3.4.4 Think before you change
- 3.4.5 Restrict who can change what
- 3.4.6 Turn off what you do not need
- 3.4.7 Close unnecessary ports and services
- 3.4.8 Decide what software may run
- 3.4.9 Control what users install
- 3.5.1 Give every user, process, and device an identity
- 3.5.2 Prove those identities
- 3.5.3 Require multi-factor authentication
- 3.5.4 Use replay-resistant authentication
- 3.5.5 Do not recycle identifiers
- 3.5.6 Disable dormant accounts
- 3.5.7 Set password rules
- 3.5.8 Block password reuse
- 3.5.9 Force a change after a temporary password
- 3.5.10 Never store or send passwords in the clear
- 3.5.11 Hide password entry
- 3.6.1 Have an incident response capability that works
- 3.6.2 Track and report incidents
- 3.6.3 Test the plan
- 3.7.1 Maintain your systems
- 3.7.2 Control maintenance tools and who uses them
- 3.7.3 Wipe gear before it leaves
- 3.7.4 Scan maintenance media
- 3.7.5 Require MFA for remote maintenance, and hang up after
- 3.7.6 Escort uncleared maintenance staff
- 3.8.1 Protect media holding CUI
- 3.8.2 Limit who can reach CUI on media
- 3.8.3 Destroy or wipe media properly
- 3.8.4 Mark media
- 3.8.5 Control media in transit
- 3.8.6 Encrypt media in transit
- 3.8.7 Control removable media
- 3.8.8 No anonymous USB drives
- 3.8.9 Protect your backups
- 3.9.1 Screen people before granting access
- 3.9.2 Close accounts when people move or leave
- 3.10.1 Limit physical access
- 3.10.2 Protect and monitor the facility
- 3.10.3 Escort visitors
- 3.10.4 Keep physical access logs
- 3.10.5 Manage keys and badges
- 3.10.6 Cover work-from-home
- 3.11.1 Assess your risk periodically
- 3.11.2 Scan for vulnerabilities
- 3.11.3 Fix what you find
- 3.12.1 Assess your own controls periodically
- 3.12.2 Write and work a POA&M
- 3.12.3 Monitor controls continuously
- 3.12.4 Keep a system security plan
- 3.13.1 Guard your boundaries
- 3.13.2 Design with security in mind
- 3.13.3 Separate admin interfaces from user interfaces
- 3.13.4 Prevent leakage through shared resources
- 3.13.5 Put public services in their own subnet
- 3.13.6 Deny by default
- 3.13.7 Block split tunneling
- 3.13.8 Encrypt CUI in transit
- 3.13.9 Drop connections when sessions end
- 3.13.10 Manage your encryption keys
- 3.13.11 Use FIPS-validated cryptography
- 3.13.12 Control cameras and microphones
- 3.13.13 Control mobile code
- 3.13.14 Control VoIP
- 3.13.15 Protect session authenticity
- 3.13.16 Encrypt CUI at rest
- 3.14.1 Find and fix flaws on a clock
- 3.14.2 Run malware protection
- 3.14.3 Act on advisories
- 3.14.4 Keep malware definitions current
- 3.14.5 Scan on schedule and in real time
- 3.14.6 Monitor traffic in and out
- 3.14.7 Notice unauthorized use
Nothing matches. Try the requirement number, such as 3.1.1, or a plainer word.