NIST 800-171 Tips and Tricks
Use this list to update controls in the Strike Graph Library for NIST 800-171 and for tips on what needs to be included in documentation.
Written By Micah
Asset Handling Procedures
Ensure that these procedures include "notice of security or privacy level is appropriately displayed.
Audit Trail
What is logged is determined by the organization. Logging can be used to address high-risk processes or to assist in meeting internal/external audit requirements.
NIST SP 800-92 provides guidance on security log management.
Authorized Software
Whitelisting is stronger, but blacklisting can also be used. NIST SO 800-167 provides guidance on whitelisting.
Change Management: Application/Software
Add: Security impact testing is conducted prior to implementation.
Collaborative Computing Devices
Collaborative computing devices include networked whiteboards, cameras, and microphones. Indication of use includes signals to users when collaborative computing devices are activated. Dedicated video conferencing systems, which rely on one of the participants calling or connecting to the other party to activate the video conference, are excluded.
Data Management Policy
Ensure that procedures for the handling of CUI are included within this policy.
Data Retention/Deletion
Add to the control description, after contract requirements: the sanitation of equipment when it is being sent off-site for maintenance.
Encryption Key Protection
NIST SP 800-56A and SP 800-57-1 provide guidance on cryptographic key management and key establishment. Cryptographic standards include FIPS-validated cryptography and/or NSA-approved cryptography. See NIST CRYPTO; NIST CAVP; and NIST CMVP.
Firewall Rules
NIST SP 800-41 provides guidance on firewalls and firewall policy.
Hardware & Media Accountability Policy
Update ePHI to CUI/FCI.
Internal Controls
This is the Strike Graph GRC platform. NIST SP 800-137 provides guidance on continuous monitoring.
Logical Access
This policy is also referred to as the Identification and Authentication Policy. Ensure it includes the topics of authenticator feedback and the procedures for the use of external systems.
Mobile Code Policy
Mobile code technologies include Java, JavaScript, ActiveX, Postscript, PDF, Flash animations, and VBScript. NIST SP 800-28 provides guidance on mobile code.
Organization Segregation of Duties
Per NIST 800-171: System management functionality includes functions necessary to administer databases, network components, workstations, or servers, and typically requires privileged user access. The separation of user functionality from system management functionality is physical or logical. Organizations can implement separation of system management functionality from user functionality by using different computers, different central processing units, different instances of operating systems, or different network addresses; virtualization techniques; or combinations of these or other methods, as appropriate. This type of separation includes web administrative interfaces that use separate authentication methods for users of any other system resources. Separation of system and user functionality may include isolating administrative interfaces on different domains and with additional access controls.
Password Requirements
If the Password setting requirements are outlined within a different Policy, then update the control language to reflect this. Include identifier management and account management within the Policy.
Publicly Accessible Systems
Include procedures addressing publicly accessible content
Secure Engineering Principles
NIST SP 800-160-1 provides guidance on systems security engineering.
Security Training
Add a link to the DoD training deck and specifically include training on insider threats.
Session Protections
For NIST 800-171, this requirement addresses communications protection at the session versus packet level.
System and Communications Protection Policy
NIST SP 800-125B provides guidance on security for virtualization technologies.
System and Information Integrity Policy
NIST SP 800-94 provides guidance on intrusion detection and prevention systems. Monitoring is achieved through a variety of tools and techniques (e.g., intrusion detection systems, intrusion prevention systems, malicious code protection software, scanning tools, audit record monitoring software, and network monitoring software). Output from system monitoring serves as input to continuous monitoring and incident response programs. Security-relevant updates include patches, service packs, hotfixes, and anti-virus signatures. CVE or CWE databases can be used to assist in monitoring.
System Security Plan
NIST SP 800-18 provides guidance on developing security plans.
Teleworking Policy
This may also be referred to as a Work From Home Policy or a Remote Work Policy. NIST SP 800-46 and SP 800-114 provide guidance on enterprise and user security when teleworking.
Visitor Escort
Add: This includes the supervision of maintenance personnel that do not have the required access authorization.
Voice over Internet Protocol
NIST SP 800-58 provides guidance on VoIP Systems.
Vulnerability Scan
NIST SP 800-40 provides guidance on vulnerability management.