SLIDE 17 MEP Overview
What is NIST SP 800-171 and how does a manufacturer implement it?
17
- NIST Special Publication (SP) 800-171 developed by NIST to further its statutory responsibilities under Federal Information
Security Modernization Act (FISMA) of 2014, 44 U.S.C. § 3541 et seq., Public Law (P.L.) 113-283.
– Titled, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations” NIST SP 800-171 Revision 1
- NIST SP 800-171 provides federal agencies with recommended requirements for protecting the confidentiality of controlled
unclassified information (CUI):
– when the CUI is resident in nonfederal information systems and organizations; – when the information systems where the CUI resides are not used or operated by contractors of federal agencies or other organizations on behalf of those agencies; and – where there are no specific safeguarding requirements for protecting the confidentiality of CUI prescribed by the authorizing law, regulation, or governmentwide policy for the CUI category or subcategory listed in the CUI Registry.
- NIST SP 800-171 requirements apply to all components of nonfederal info systems and organizations that process, store, or
transmit CUI, or provide security protection for such components.
– A nonfederal info system is a system that does not meet the criteria for a federal system.
- CUI requirements are intended for use by federal agencies in contractual vehicles or other agreements established between those
agencies and nonfederal organizations. This includes DOD and is resident within DFARS clauses that apply to defense contracts.
- For ease of use, NIST SP 800-171 security requirements are organized into 14 families.