NIST 800-172 | A Useful Guide for CUI for Federal Contractors
While federal contractors are hopefully busying themselves with implementing comprehensive measures for the safeguarding of Controlled Unclassified Information (CUI), it’s important to take note of several helpful tools. A great reference for helping build and implement a structured and formalized CUI program is NIST Special Publication 800-172 - Enhanced Security Requirements for Protecting Controlled Unclassified Information. What makes NIST 800-172 such a great compliment to NIST 800-171 is that it lists each of the prescriptive security requirements, then provides an excellent ‘Discussion’ section for giving federal contractors much-needed information, examples, and clarity on how the control itself should be implemented in terms of CUI safeguarding.
Per NIST 800-172, “The purpose of this publication is to provide federal agencies with a set of enhanced security requirements for protecting the confidentiality, integrity, and availability of CUI: (1) when the CUI is resident in a nonfederal system and organization, (2) when the nonfederal organization is not collecting or maintaining information on behalf of a federal agency or using or operating a system on behalf of an agency, and (3) where there are no specific safeguarding requirements for protecting the CUI prescribed by the authorizing law, regulation, or government-wide policy for the CUI category listed in the CUI Registry.”
100 + NIST 800-53 Templates Available for Download for Cleared Industry
The solution for cleared industry is the Arlington Security Portal (ASP), an online repository of world-class, industry leading security and privacy policies & procedures, programs, plans – and other highly essential documents & templates developed specifically on NIST SP 800-53, Revision 5.
We are Arlington, a team of innovative, solution-oriented, highly agile, and well-versed professionals with decades of experience in working with America’s defense industry. From emerging cybersecurity regulations to helping our clients solve complex security & compliance solutions – and so much more – you can trust Arlington, the firm that’s Dedicated to Defense®. Learn more at arlingtonintel.com.