Skip to content
Cyber Horizon
All frameworks

// US Standards

NIST SP 800-171 Protecting CUI Compliance Software

Protecting Controlled Unclassified Information in non-federal systems. Aligned with NIST 800-53.

Framework at a glance

Short name

NIST 800-171

Version

Category

US Standards

Controls

110

What NIST 800-171 covers

110 controls across 63 domains — every one tracked, owned and evidenced in Cyber Horizon.

Access Control

7 controls
  • 3.1.1 Authorised access control
  • 3.1.2 Transaction and function control
  • 3.3.9 Limit audit management
  • 3.4.5 Access restrictions for change
  • 3.8.2 Limit media access

Data Flow

1 controls
  • 3.1.3 Control CUI flow

Separation of Duties

1 controls
  • 3.1.4 Separation of duties

Least Privilege

1 controls
  • 3.1.5 Least privilege

Privileged Access

2 controls
  • 3.1.6 Non-privileged account use
  • 3.1.7 Prevent privileged function execution

Authentication

5 controls
  • 3.1.8 Unsuccessful logon attempts
  • 3.5.2 User authentication
  • 3.5.4 Replay-resistant authentication
  • 3.5.11 Obscure authentication feedback
  • 3.13.15 Communications authenticity

Policy

1 controls
  • 3.1.9 Privacy and security notices

Session

3 controls
  • 3.1.10 Session lock
  • 3.1.11 Session termination
  • 3.13.9 Network disconnect

Remote Access

4 controls
  • 3.1.12 Remote access control
  • 3.1.15 Privileged remote access
  • 3.7.5 Remote maintenance MFA
  • 3.13.7 Split tunnelling prevention

Cryptography

3 controls
  • 3.1.13 Remote access cryptography
  • 3.5.10 Cryptographic passwords
  • 3.13.11 FIPS-validated cryptography

Network

3 controls
  • 3.1.14 Remote access routing
  • 3.1.20 External system connections
  • 3.13.1 Boundary protection

Wireless

2 controls
  • 3.1.16 Wireless access authorisation
  • 3.1.17 Wireless access protection

Mobile

1 controls
  • 3.1.18 Mobile device management

Encryption

4 controls
  • 3.1.19 Encrypt CUI on mobile
  • 3.8.6 Encrypt portable storage
  • 3.13.8 Data in transit encryption
  • 3.13.16 Data at rest

Media

5 controls
  • 3.1.21 Portable storage restriction
  • 3.7.4 Check media
  • 3.8.1 Protect media
  • 3.8.7 Control removable media
  • 3.8.8 Prohibit unidentified media

Data Handling

1 controls
  • 3.1.22 Control public CUI

Training

2 controls
  • 3.2.1 Role-based training
  • 3.2.2 Insider threat awareness

Insider Threat

1 controls
  • 3.2.3 Insider threat training

Logging

5 controls
  • 3.3.1 System auditing
  • 3.3.2 User accountability
  • 3.3.3 Review and update events
  • 3.3.6 Audit reduction
  • 3.10.4 Maintain access logs

Monitoring

6 controls
  • 3.3.4 Alert on audit failure
  • 3.10.2 Protect and monitor
  • 3.12.3 Monitor security controls
  • 3.14.3 Security alerts
  • 3.14.6 Monitor for attacks

SIEM

1 controls
  • 3.3.5 Correlate audit review

Time Sync

1 controls
  • 3.3.7 Authoritative time source

Log Integrity

1 controls
  • 3.3.8 Protect audit information

Baseline

1 controls
  • 3.4.1 Baseline configurations

Hardening

3 controls
  • 3.4.2 Configuration settings
  • 3.4.6 Least functionality
  • 3.4.7 Non-essential functionality

Change Management

2 controls
  • 3.4.3 Track configuration changes
  • 3.4.4 Security impact analysis

Application Control

1 controls
  • 3.4.8 Application execution policy

Software Control

1 controls
  • 3.4.9 User-installed software

Identity

2 controls
  • 3.5.1 User identification
  • 3.5.5 Identifier management

MFA

1 controls
  • 3.5.3 Multi-factor authentication

Credentials

1 controls
  • 3.5.6 Authenticator management

Passwords

3 controls
  • 3.5.7 Password complexity
  • 3.5.8 Password reuse
  • 3.5.9 Temporary passwords

IR Plan

1 controls
  • 3.6.1 Incident handling

Reporting

1 controls
  • 3.6.2 Incident reporting

Testing

1 controls
  • 3.6.3 Incident response testing

Operations

2 controls
  • 3.7.1 Maintenance
  • 3.7.2 Maintenance controls

Media Sanitisation

1 controls
  • 3.7.3 Equipment sanitisation

Personnel

1 controls
  • 3.7.6 Maintenance personnel

Disposal

1 controls
  • 3.8.3 Sanitise or destroy

Classification

1 controls
  • 3.8.4 Mark media

Backup

1 controls
  • 3.8.9 Protect backups

Screening

1 controls
  • 3.9.1 Screen individuals

HR

1 controls
  • 3.9.2 Personnel termination

Physical Access

1 controls
  • 3.10.1 Limit physical access

Visitors

1 controls
  • 3.10.3 Escort visitors

Remote Work

1 controls
  • 3.10.6 Alternate work sites

Risk Management

1 controls
  • 3.11.1 Risk assessment

Vulnerability Management

1 controls
  • 3.11.2 Vulnerability scan

Remediation

1 controls
  • 3.11.3 Remediate vulnerabilities

Assessment

1 controls
  • 3.12.1 Security control assessment

POA&M

1 controls
  • 3.12.2 Plan of action

Documentation

1 controls
  • 3.12.4 System security plan

Architecture

1 controls
  • 3.13.2 Architectural and design

Segregation

1 controls
  • 3.13.3 Role separation

Data Protection

1 controls
  • 3.13.4 Shared resource protection

Network Segmentation

1 controls
  • 3.13.5 Public access system separation

Firewall

1 controls
  • 3.13.6 Network communication deny-by-default

Key Management

1 controls
  • 3.13.10 Key management

Privacy

1 controls
  • 3.13.12 Collaborative device prohibition

Application Security

1 controls
  • 3.13.13 Mobile code

Communications

1 controls
  • 3.13.14 VoIP

Patch Management

1 controls
  • 3.14.1 Flaw remediation

Malware

3 controls
  • 3.14.2 Malicious code protection
  • 3.14.4 Update malware protection
  • 3.14.5 System scanning

How Cyber Horizon automates NIST 800-171

Every NIST 800-171 control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.

Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.

Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.

Frequently asked questions

What is NIST SP 800-171 Protecting CUI?

Protecting Controlled Unclassified Information in non-federal systems. Aligned with NIST 800-53.

How many controls does NIST SP 800-171 Protecting CUI have?

NIST SP 800-171 Protecting CUI has 110 controls in Cyber Horizon's catalogue, organised across 63 domains.

How does Cyber Horizon help with NIST SP 800-171 Protecting CUI?

Cyber Horizon maps NIST SP 800-171 Protecting CUI into a shared control library alongside every other framework you run, so evidence collected once counts towards NIST 800-171 and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.

See NIST 800-171 mapped to your environment

Start with the free 20-question readiness check — no signup — or get a personal walkthrough of NIST 800-171 in Cyber Horizon.