3.1.3Control where CUI is allowed to travel
Decide which systems and paths CUI may move along, and enforce it rather than trusting habit.
The requirement, verbatim
NIST SP 800-171 Rev. 2 · 3.1.3Control the flow of CUI in accordance with approved authorizations.
NIST's discussion
Information flow control regulates where information can travel within a system and between systems (versus who can access the information) and without explicit regard to subsequent accesses to that information. Flow control restrictions include the following: keeping export-controlled information from being transmitted in the clear to the internet; blocking outside traffic that claims to be from within the organization; restricting requests to the internet that are not from the internal web proxy server; and limiting information transfers between organizations based on data structures and content.
Organizations commonly use information flow control policies and enforcement mechanisms to control the flow of information between designated sources and destinations (e.g., networks, individuals, and devices) within systems and between interconnected systems. Flow control is based on characteristics of the information or the information path. Enforcement occurs in boundary protection devices (e.g., gateways, routers, guards, encrypted tunnels, firewalls) that employ rule sets or establish configuration settings that restrict system services, provide a packet-filtering capability based on header information, or message-filtering capability based on message content (e.g., implementing key word searches or using document characteristics). Organizations also consider the trustworthiness of filtering and inspection mechanisms (i.e., hardware, firmware, and software components) that are critical to information flow enforcement.
Transferring information between systems representing different security domains with different security policies introduces risk that such transfers violate one or more domain security policies.
Organizations consider the shared nature of commercial telecommunications services in the implementation of security requirements associated with the use of such services. Commercial telecommunications services are commonly based on network components and consolidated management systems shared by all attached commercial customers and may also include third party-provided access lines and other service elements. Such transmission services may represent sources of increased risk despite contract security provisions. NIST SP 800-41 provides guidance on firewalls and firewall policy. SP 800-125B provides guidance on security for virtualization technologies.
In such situations, information owners or stewards provide guidance at designated policy enforcement points between interconnected systems. Organizations consider mandating specific architectural solutions when required to enforce specific security policies. Enforcement includes: prohibiting information transfers between interconnected systems (i.e., allowing access only); employing hardware mechanisms to enforce one-way information flows; and implementing trustworthy regrading mechanisms to reassign security attributes and security labels.
NIST SP 800-171 Rev. 2, discussion under 3.1.3. Whitespace normalised; wording unchanged.
Assessment objectives
An assessor decides each of these separately. The requirement is met only when every objective is.
- [a] information flow control policies are defined
- [b] methods and enforcement mechanisms for controlling the flow of CUI are defined
- [c] designated sources and destinations (e.g., networks, individuals, and devices) for CUI within the system and between interconnected systems are identified
- [d] authorizations for controlling the flow of CUI are defined
- [e] approved authorizations for controlling the flow of CUI are enforced
NIST SP 800-171A, determination statements for 3.1.3.
For assessors: examine, interview, test
NIST SP 800-171A names what an assessor may examine, whom they may interview, and what they may test for this requirement. Assessors select from these lists; they are not a checklist of everything you must produce.
Examine
- Access control policy
- information flow control policies
- procedures addressing information flow enforcement
- system security plan
- system design documentation
- system configuration settings and associated documentation
- system baseline configuration
- list of information flow authorizations
- system audit logs and records
- other relevant documents or records
Interview
- System or network administrators
- personnel with information security responsibilities
- system developers
Test
- Mechanisms implementing information flow enforcement policy
NIST SP 800-171A, potential assessment methods and objects for 3.1.3.
Evidence
No evidence examples are published for this requirement yet. The objectives above are what an assessor checks; evidence is whatever shows each one is true in your environment, dated and kept with your system security plan.
Scoring weight
Worth 1 point. Not meeting this requirement subtracts 1 from your 110-point SPRS score.
DoD NIST SP 800-171 Assessment Methodology v1.2.1 weighting, as carried in the Bedrock scoring table. The score starts at 110 and subtracts the weight of every requirement not met.
In Rev. 3
Rev. 2 is what your contract requires today. A standing DoD class deviation keeps Rev. 2 in force; NIST has published Rev. 3, but it is not adopted for contracts. In Rev. 3 this requirement is no significant change: 03.01.03 Information Flow Enforcement.
See the Rev. 2 and Rev. 3 wording word by word, or start with the status page.
Related requirements
Where this page's facts come from
- Requirement text
- bedrock-cmmc-api@89b8e8e:migrations/004_reference_requirements.sql#Requirement.basicRequirement@rev2
- Discussion
- bedrock-cmmc-api@89b8e8e:migrations/004_reference_requirements.sql#Requirement.discussion@rev2
- Practice name
- bedrock-cmmc-api@89b8e8e:migrations/004_reference_requirements.sql#Requirement.title@rev2 (CMMC Assessment Guide practice name)
- Objectives
- bedrock-cmmc-api@89b8e8e:migrations/005_reference_objectives.sql#AssessmentObjective.description@rev2
- Examine, interview, test
- bedrock-cmmc-api@89b8e8e:migrations/005_reference_objectives.sql#AssessmentObjective.description@rev2 ({examineGuidance, interviewGuidance, testGuidance})
- Level
- bedrock-cmmc-api@89b8e8e:migrations/021_fix_level1_requirements.sql#Requirement.cmmcLevel@rev2
- Weight
- bedrock-cmmc-api@89b8e8e:internal/cmmc/requirement_values.go#requirementValues (DoD AM v1.2.1 / eMASS L2 template v3.8)
- Rev. 3 mapping
- bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/r2_r3_transition_map.json#r2_to_r3
- Plain-language title and summary
- editorial/CMMC Navigator.dc.html#RAW (Foxx Cyber editorial)