Edge Register
Regimes ยท SP 800-171

NIST SP 800-171 Rev 3

Attaches to the sites whose data flags include controlled unclassified information: physical access and its monitoring, the alternate work site, mobile devices, remote access, media transport and sanitization.

On the register, tick "NIST SP 800-171 Rev 3 (sites handling CUI)" and these rows appear on the sites whose data includes controlled unclassified information. Source framework: NIST SP 800-171 Rev 3.

How the duties attach

ReachesThe sites whose data includes controlled unclassified information.
every site03.10.02, 03.10.07
holds controlled data (CUI)03.08.03, 03.08.05
remote access named03.01.12
Home and remote worker03.10.06, 03.01.18
Field and temporary site03.10.06, 03.01.18
Vehicle, vessel and aircraft03.01.18, 03.08.05

The clauses, quoted

7 of 97 in the framework

Requirement text drawn from the compliance.theartofservice.com corpus, read against the held text of each standard: the corpus statement of each clause, not the instrument verbatim.

SP 800-171 03.01.12 Remote Access

Establish usage restrictions, configuration requirements, and authorize remote access; route remote access via managed access control points; permit only approved remote execution of privileged commands.

Evidence an auditor accepts: VPN configuration; ZTNA policy; remote access authorization records
Common gap: split tunneling enabled
Source framework: NIST SP 800-171 Rev 3
SP 800-171 03.01.18 Access Control for Mobile Devices

Establish configuration requirements, connection requirements, and implementation guidance for mobile devices; encrypt CUI on mobile devices.

Evidence an auditor accepts: MDM/UEM configuration; device encryption attestations; mobile device inventory
Common gap: BYOD without containers
Source framework: NIST SP 800-171 Rev 3
SP 800-171 03.08.03 Media Sanitization

Sanitize or destroy system media containing CUI before disposal, release, or reuse; verify sanitization actions.

Evidence an auditor accepts: certificates of destruction; sanitization log per NIST SP 800-88; verification reports
Common gap: drives donated without wipe
Source framework: NIST SP 800-171 Rev 3
SP 800-171 03.08.05 Media Transport

Protect and control system media during transport outside controlled areas; maintain accountability; document activities associated with transport.

Evidence an auditor accepts: chain of custody forms; courier service contracts; encryption attestations for transit
Common gap: unencrypted laptops in transit
Source framework: NIST SP 800-171 Rev 3
SP 800-171 03.10.02 Monitoring Physical Access

Monitor physical access to the facility where the system resides; review logs of physical access; coordinate review with incident response.

Evidence an auditor accepts: CCTV retention policy; badge reader logs; physical security incident reports
Common gap: CCTV not retained 90 days
Source framework: NIST SP 800-171 Rev 3
SP 800-171 03.10.06 Alternate Work Site

Determine and document alternate work sites allowed; employ controls at alternate work sites; assess feasibility of controls.

Evidence an auditor accepts: telework policy; home office security checklist; VPN required attestation
Common gap: no home office security baseline
Source framework: NIST SP 800-171 Rev 3
SP 800-171 03.10.07 Physical Access Control

Enforce physical access authorizations at entry/exit points; maintain visitor logs; control access to keys, combinations, and other physical access devices.

Evidence an auditor accepts: visitor logs; key/combination inventory; entry/exit access reports
Common gap: unsigned visitor logs
Source framework: NIST SP 800-171 Rev 3

See what it attaches to your list

Paste the site list, tick the regime, and every site it reaches carries these rows by its exposure, link, data and plant. Eight sites free, no account.

Build my edge register