NIST SP 800-171

External service providers that process, store or transmit Controlled Unclassified Information (CUI) or Covered Defense Information belonging to the U.S. federal government must safeguard that CUI. These nonfederal service providers include contractors, subcontractors and service providers. Additionally, CUI is often provided to, or shared with, state and local governments, colleges and universities, and independent research organizations. NIST Special Publication 800-171, Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations, defines the type of security requirements service providers are likely to be contractually obligated to meet to safeguard CUI confidentiality.

Download PDF

Download

Resources

Solution
Assured Compliance Assessment Solution (ACAS) Powered by Tenable
Analyst Research
IDC Info Snapshot: 应对制造业OT安全风险 - 构筑可视化IT/OT融合安全环境
Cyber exposure research
How Generative AI Is Changing Security Research