NIST 800-171 Tips and Tricks

Use this list to update controls in the Strike Graph Library for NIST 800-171 and for tips on what needs to be included in documentation.

Written By Micah

Asset Handling Procedures

Ensure that these procedures include "notice of security or privacy level is appropriately displayed.

Audit Trail

What is logged is determined by the organization. Logging can be used to address high-risk processes or to assist in meeting internal/external audit requirements.

NIST SP 800-92 provides guidance on security log management.

Authorized Software

Whitelisting is stronger, but blacklisting can also be used. NIST SO 800-167 provides guidance on whitelisting.

Change Management: Application/Software

Add: Security impact testing is conducted prior to implementation.

Collaborative Computing Devices

Collaborative computing devices include networked whiteboards, cameras, and microphones. Indication of use includes signals to users when collaborative computing devices are activated. Dedicated video conferencing systems, which rely on one of the participants calling or connecting to the other party to activate the video conference, are excluded.

Data Management Policy

Ensure that procedures for the handling of CUI are included within this policy.

Data Retention/Deletion

Add to the control description, after contract requirements: the sanitation of equipment when it is being sent off-site for maintenance.

Encryption Key Protection

NIST SP 800-56A and SP 800-57-1 provide guidance on cryptographic key management and key establishment. Cryptographic standards include FIPS-validated cryptography and/or NSA-approved cryptography. See NIST CRYPTO; NIST CAVP; and NIST CMVP.

Firewall Rules

NIST SP 800-41 provides guidance on firewalls and firewall policy.

Hardware & Media Accountability Policy

Update ePHI to CUI/FCI.

Internal Controls

This is the Strike Graph GRC platform. NIST SP 800-137 provides guidance on continuous monitoring.

Logical Access

This policy is also referred to as the Identification and Authentication Policy. Ensure it includes the topics of authenticator feedback and the procedures for the use of external systems.

Mobile Code Policy

Mobile code technologies include Java, JavaScript, ActiveX, Postscript, PDF, Flash animations, and VBScript. NIST SP 800-28 provides guidance on mobile code.

Organization Segregation of Duties

Per NIST 800-171: System management functionality includes functions necessary to administer databases, network components, workstations, or servers, and typically requires privileged user access. The separation of user functionality from system management functionality is physical or logical. Organizations can implement separation of system management functionality from user functionality by using different computers, different central processing units, different instances of operating systems, or different network addresses; virtualization techniques; or combinations of these or other methods, as appropriate. This type of separation includes web administrative interfaces that use separate authentication methods for users of any other system resources. Separation of system and user functionality may include isolating administrative interfaces on different domains and with additional access controls.

Password Requirements

If the Password setting requirements are outlined within a different Policy, then update the control language to reflect this. Include identifier management and account management within the Policy.

Publicly Accessible Systems

Include procedures addressing publicly accessible content

Secure Engineering Principles

NIST SP 800-160-1 provides guidance on systems security engineering.

Security Training

Add a link to the DoD training deck and specifically include training on insider threats.

Session Protections

For NIST 800-171, this requirement addresses communications protection at the session versus packet level.

System and Communications Protection Policy

NIST SP 800-125B provides guidance on security for virtualization technologies.

System and Information Integrity Policy

NIST SP 800-94 provides guidance on intrusion detection and prevention systems. Monitoring is achieved through a variety of tools and techniques (e.g., intrusion detection systems, intrusion prevention systems, malicious code protection software, scanning tools, audit record monitoring software, and network monitoring software). Output from system monitoring serves as input to continuous monitoring and incident response programs. Security-relevant updates include patches, service packs, hotfixes, and anti-virus signatures. CVE or CWE databases can be used to assist in monitoring.

System Security Plan

NIST SP 800-18 provides guidance on developing security plans.

Teleworking Policy

This may also be referred to as a Work From Home Policy or a Remote Work Policy. NIST SP 800-46 and SP 800-114 provide guidance on enterprise and user security when teleworking.

Visitor Escort

Add: This includes the supervision of maintenance personnel that do not have the required access authorization.

Voice over Internet Protocol

NIST SP 800-58 provides guidance on VoIP Systems.

Vulnerability Scan

NIST SP 800-40 provides guidance on vulnerability management.