to move, Enter to open, Esc to close. Try 3.5.3, AC.L2-3.1.1, MFA or unmarked.

All 110 security requirements

Each requirement has its own page: a plain-language version, the original wording, the assessment objectives an assessor checks, its scoring weight, and what changes in Rev. 3. The list is the whole NIST SP 800-171 Rev. 2 catalog; search and family filters narrow it.

110 requirements

  1. 3.1.1 Know who and what is allowed on your systems AC Level 1 5 pt
  2. 3.1.2 Limit what each person can do once inside AC Level 1 5 pt
  3. 3.1.3 Control where CUI is allowed to travel AC Level 2 1 pt
  4. 3.1.4 Split duties so one person cannot do everything alone AC Level 2 1 pt
  5. 3.1.5 Give people the least access they need AC Level 2 3 pt
  6. 3.1.6 Do ordinary work from ordinary accounts AC Level 2 1 pt
  7. 3.1.7 Stop and log privileged actions by non-admins AC Level 2 1 pt
  8. 3.1.8 Lock accounts after repeated failed logins AC Level 2 1 pt
  9. 3.1.9 Show a use notice at sign-in AC Level 2 1 pt
  10. 3.1.10 Lock idle screens AC Level 2 1 pt
  11. 3.1.11 End sessions automatically AC Level 2 1 pt
  12. 3.1.12 Watch and control remote access AC Level 2 5 pt
  13. 3.1.13 Encrypt remote access AC Level 2 5 pt
  14. 3.1.14 Funnel remote access through known entry points AC Level 2 1 pt
  15. 3.1.15 Approve remote admin work in advance AC Level 2 1 pt
  16. 3.1.16 Approve wireless before it connects AC Level 2 5 pt
  17. 3.1.17 Protect wireless with authentication and encryption AC Level 2 5 pt
  18. 3.1.18 Control which mobile devices connect AC Level 2 5 pt
  19. 3.1.19 Encrypt CUI on mobile devices AC Level 2 3 pt
  20. 3.1.20 Verify and limit outside systems AC Level 1 1 pt
  21. 3.1.21 Limit portable storage on outside systems AC Level 2 1 pt
  22. 3.1.22 Review what goes on public sites AC Level 1 1 pt
  23. 3.2.1 Make sure people know the risks AT Level 2 5 pt
  24. 3.2.2 Train people for the security duties they hold AT Level 2 5 pt
  25. 3.2.3 Cover insider threat AT Level 2 1 pt
  26. 3.3.1 Keep logs, and keep them long enough AU Level 2 5 pt
  27. 3.3.2 Tie actions to individuals AU Level 2 3 pt
  28. 3.3.3 Revisit what you log AU Level 2 1 pt
  29. 3.3.4 Get told when logging breaks AU Level 2 1 pt
  30. 3.3.5 Correlate logs across systems AU Level 2 5 pt
  31. 3.3.6 Be able to search and report on logs AU Level 2 1 pt
  32. 3.3.7 Synchronize clocks AU Level 2 1 pt
  33. 3.3.8 Protect the logs themselves AU Level 2 1 pt
  34. 3.3.9 Restrict who manages logging AU Level 2 1 pt
  35. 3.4.1 Know what you have and how it is set up CM Level 2 5 pt
  36. 3.4.2 Enforce your settings CM Level 2 5 pt
  37. 3.4.3 Track changes CM Level 2 1 pt
  38. 3.4.4 Think before you change CM Level 2 1 pt
  39. 3.4.5 Restrict who can change what CM Level 2 5 pt
  40. 3.4.6 Turn off what you do not need CM Level 2 5 pt
  41. 3.4.7 Close unnecessary ports and services CM Level 2 5 pt
  42. 3.4.8 Decide what software may run CM Level 2 5 pt
  43. 3.4.9 Control what users install CM Level 2 1 pt
  44. 3.5.1 Give every user, process, and device an identity IA Level 1 5 pt
  45. 3.5.2 Prove those identities IA Level 1 5 pt
  46. 3.5.3 Require multi-factor authentication IA Level 2 3 or 5 pt
  47. 3.5.4 Use replay-resistant authentication IA Level 2 1 pt
  48. 3.5.5 Do not recycle identifiers IA Level 2 1 pt
  49. 3.5.6 Disable dormant accounts IA Level 2 1 pt
  50. 3.5.7 Set password rules IA Level 2 1 pt
  51. 3.5.8 Block password reuse IA Level 2 1 pt
  52. 3.5.9 Force a change after a temporary password IA Level 2 1 pt
  53. 3.5.10 Never store or send passwords in the clear IA Level 2 5 pt
  54. 3.5.11 Hide password entry IA Level 2 1 pt
  55. 3.6.1 Have an incident response capability that works IR Level 2 5 pt
  56. 3.6.2 Track and report incidents IR Level 2 5 pt
  57. 3.6.3 Test the plan IR Level 2 1 pt
  58. 3.7.1 Maintain your systems MA Level 2 3 pt
  59. 3.7.2 Control maintenance tools and who uses them MA Level 2 5 pt
  60. 3.7.3 Wipe gear before it leaves MA Level 2 1 pt
  61. 3.7.4 Scan maintenance media MA Level 2 3 pt
  62. 3.7.5 Require MFA for remote maintenance, and hang up after MA Level 2 5 pt
  63. 3.7.6 Escort uncleared maintenance staff MA Level 2 1 pt
  64. 3.8.1 Protect media holding CUI MP Level 2 3 pt
  65. 3.8.2 Limit who can reach CUI on media MP Level 2 3 pt
  66. 3.8.3 Destroy or wipe media properly MP Level 1 5 pt
  67. 3.8.4 Mark media MP Level 2 1 pt
  68. 3.8.5 Control media in transit MP Level 2 1 pt
  69. 3.8.6 Encrypt media in transit MP Level 2 1 pt
  70. 3.8.7 Control removable media MP Level 2 5 pt
  71. 3.8.8 No anonymous USB drives MP Level 2 3 pt
  72. 3.8.9 Protect your backups MP Level 2 1 pt
  73. 3.9.1 Screen people before granting access PS Level 2 3 pt
  74. 3.9.2 Close accounts when people move or leave PS Level 2 5 pt
  75. 3.10.1 Limit physical access PE Level 1 5 pt
  76. 3.10.2 Protect and monitor the facility PE Level 2 5 pt
  77. 3.10.3 Escort visitors PE Level 1 1 pt
  78. 3.10.4 Keep physical access logs PE Level 1 1 pt
  79. 3.10.5 Manage keys and badges PE Level 1 1 pt
  80. 3.10.6 Cover work-from-home PE Level 2 1 pt
  81. 3.11.1 Assess your risk periodically RA Level 2 3 pt
  82. 3.11.2 Scan for vulnerabilities RA Level 2 5 pt
  83. 3.11.3 Fix what you find RA Level 2 1 pt
  84. 3.12.1 Assess your own controls periodically CA Level 2 5 pt
  85. 3.12.2 Write and work a POA&M CA Level 2 3 pt
  86. 3.12.3 Monitor controls continuously CA Level 2 5 pt
  87. 3.12.4 Keep a system security plan CA Level 2 Not scored
  88. 3.13.1 Guard your boundaries SC Level 1 5 pt
  89. 3.13.2 Design with security in mind SC Level 2 5 pt
  90. 3.13.3 Separate admin interfaces from user interfaces SC Level 2 1 pt
  91. 3.13.4 Prevent leakage through shared resources SC Level 2 1 pt
  92. 3.13.5 Put public services in their own subnet SC Level 1 5 pt
  93. 3.13.6 Deny by default SC Level 2 5 pt
  94. 3.13.7 Block split tunneling SC Level 2 1 pt
  95. 3.13.8 Encrypt CUI in transit SC Level 2 3 pt
  96. 3.13.9 Drop connections when sessions end SC Level 2 1 pt
  97. 3.13.10 Manage your encryption keys SC Level 2 1 pt
  98. 3.13.11 Use FIPS-validated cryptography SC Level 2 3 or 5 pt
  99. 3.13.12 Control cameras and microphones SC Level 2 1 pt
  100. 3.13.13 Control mobile code SC Level 2 1 pt
  101. 3.13.14 Control VoIP SC Level 2 1 pt
  102. 3.13.15 Protect session authenticity SC Level 2 5 pt
  103. 3.13.16 Encrypt CUI at rest SC Level 2 1 pt
  104. 3.14.1 Find and fix flaws on a clock SI Level 1 5 pt
  105. 3.14.2 Run malware protection SI Level 1 5 pt
  106. 3.14.3 Act on advisories SI Level 2 5 pt
  107. 3.14.4 Keep malware definitions current SI Level 1 5 pt
  108. 3.14.5 Scan on schedule and in real time SI Level 1 3 pt
  109. 3.14.6 Monitor traffic in and out SI Level 2 5 pt
  110. 3.14.7 Notice unauthorized use SI Level 2 3 pt