NIST SP 800-171A
Front Matter
National Institute of Standards and Technology Special Publication 800-171A
Natl. Inst. Stand. Technol. Spec. Publ. 800-171A, 92 pages (June 2018)
CODEN: NSPUE2
This publication is available free of charge from: https://doi.org/10.6028/NIST.SP.800-171A
Comments on this publication may be submitted to:
National Institute of Standards and Technology
Attn: Computer Security Division, Information Technology Laboratory
100 Bureau Drive (Mail Stop 8930) Gaithersburg, MD 20899-8930
Email: sec-cert@nist.gov
All comments are subject to release under the Freedom of Information Act (FOIA).
Authority
This publication has been developed by the National Institute of Standards and Technology to further its statutory responsibilities under the Federal Information Security Modernization Act (FISMA) of 2014, 44 U.S.C. § 3551 et seq., Public Law (P.L.) 113-283. NIST is responsible for developing information security standards and guidelines, including minimum requirements for federal information systems, but such standards and guidelines shall not apply to national security systems without the express approval of appropriate federal officials exercising policy authority over such systems. This guideline is consistent with requirements of the Office of Management and Budget (OMB) Circular A-130.
Nothing in this publication should be taken to contradict the standards and guidelines made mandatory and binding on federal agencies by the Secretary of Commerce under statutory authority. Nor should these guidelines be interpreted as altering or superseding the existing authorities of the Secretary of Commerce, Director of OMB, or any other federal official. This publication may be used by nongovernmental organizations on a voluntary basis and is not subject to copyright in the United States. Attribution would, however, be appreciated by NIST.
Reports on Computer Systems Technology
The NIST Information Technology Laboratory (ITL) promotes the United States economy and public welfare by providing technical leadership for the Nation's measurement and standards infrastructure. ITL develops tests, test methods, reference data, proof of concept implementations, and technical analyses to advance the development and productive use of information technology.
ITL's responsibilities include the development of management, administrative, technical, and physical standards and guidelines for the cost-effective security of other than national security-related information and protection of individuals' privacy in federal information systems. The Special Publication 800-series reports on ITL's research, guidelines, and outreach efforts in information systems security and its collaborative activities with industry, government, and academic organizations.
Abstract
The protection of Controlled Unclassified Information (CUI) resident in nonfederal systems and organizations is of paramount importance to federal agencies and can directly impact the ability of the federal government to successfully conduct its assigned missions and business operations. This publication provides federal and nonfederal organizations with assessment procedures and a methodology that can be employed to conduct assessments of the CUI security requirements in NIST Special Publication 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations. The assessment procedures are flexible and can be customized to the needs of the organizations and the assessors conducting the assessments. Security assessments can be conducted as self-assessments; independent, third-party assessments; or government-sponsored assessments and can be applied with various degrees of rigor, based on customer-defined depth and coverage attributes. The findings and evidence produced during the security assessments can facilitate risk-based decisions by organizations related to the CUI requirements.
Keywords
Assessment; Assessment Method; Assessment Object; Assessment Procedure; Assurance; Basic Security Requirement; Controlled Unclassified Information; Coverage; CUI Registry; Depth; Derived Security Requirement; Executive Order 13556; FISMA; NIST Special Publication 800-53; NIST Special Publication 800-53A; Nonfederal Organization; Nonfederal System; Security Assessment; Security Control.
Acknowledgements
The authors gratefully acknowledge and appreciate the contributions from Jon Boyens, Devin Casey, Chris Enloe, Ned Goren, Gary Guissanie, Jody Jacobs, Jeff Marron, Vicki Michetti, Mark Riddle, Mary Thomas, Matt Scholl, Gary Stoneburner, Patricia Toth, and Patrick Viscuso whose thoughtful and constructive comments improved the quality, thoroughness, and usefulness of this publication. A special note of thanks goes to Jim Foti and Elizabeth Lennon for their superb administrative and technical editing support.
Table of Contents
- CHAPTER ONE Introduction ..... 1
- 1.1 Purpose and Applicability ..... 1
- 1.2 Target Audience ..... 2
- 1.3 Organization of this Special Publication ..... 2
- CHAPTER TWO The Fundamentals ..... 4
- 2.1 Assessment Procedures ..... 4
- 2.2 Assurance Cases ..... 6
- CHAPTER THREE The Procedures ..... 8
- 3.1 Access Control ..... 9
- 3.2 Awareness and Training ..... 19
- 3.3 Audit and Accountability ..... 21
- 3.4 Configuration Management ..... 26
- 3.5 Identification and Authentication ..... 31
- 3.6 Incident Response ..... 36
- 3.7 Maintenance ..... 38
- 3.8 Media Protection ..... 41
- 3.9 Personnel Security ..... 45
- 3.10 Physical Protection ..... 46
- 3.11 Risk Assessment ..... 49
- 3.12 Security Assessment ..... 51
- 3.13 System and Communications Protection ..... 53
- 3.14 System and Information Integrity ..... 61
- APPENDIX A References ..... 65
- APPENDIX B Glossary ..... 67
- APPENDIX C Acronyms ..... 75
- APPENDIX D Assessment Methods ..... 76
Errata
This table contains changes that have been incorporated into Special Publication 800-171A. Errata updates can include corrections, clarifications, or other minor changes in the publication that are either editorial or substantive in nature.
| Date | Type | Revision | Page |
|---|---|---|---|
| (No errata entries listed in source document) | |||
Chapter One: Introduction
The need to assess CUI security requirements
The protection of unclassified federal information in nonfederal systems and organizations is dependent on the federal government providing a process for identifying the different types of information that are used by federal agencies. Executive Order 13556 established a governmentwide Controlled Unclassified Information (CUI)[1] Program to standardize the way the executive branch handles unclassified information that requires protection. The implementing regulation for the CUI Program is 32 CFR part 2002, Controlled Unclassified Information. Only federal information that requires safeguarding or dissemination controls pursuant to federal law, regulation, or governmentwide policy may be designated as CUI.[2] NIST Special Publication 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, specifies the security requirements to ensure the confidentiality of CUI.
1.1 Purpose and Applicability
The purpose of this publication is to provide procedures for assessing the CUI requirements in NIST Special Publication 800-171. Compliance with the security requirements is addressed in CUI guidance and the CUI Federal Acquisition Regulation (FAR)[3] or as supplemented by federal agencies (e.g., Department of Defense Federal Acquisition Regulation). Organizations can use the assessment procedures to generate evidence to support the assertion that the security requirements have been satisfied.
The assessment process is an information-gathering and evidence-producing activity to determine the effectiveness of the safeguards intended to meet the set of security requirements specified in NIST Special Publication 800-171. In this context, the information gathered and the evidence produced can be used by an organization to:
- Identify potential problems or shortfalls in the organization's security and risk management programs;
- Identify security weaknesses and deficiencies in its systems and in the environments in which those systems operate;
- Prioritize risk mitigation decisions and activities;
- Confirm that identified security weaknesses and deficiencies in the system and in the environment of operation have been addressed; and
- Support continuous monitoring activities and provide information security situational awareness.
The assessment procedures in this publication offer the flexibility to customize assessments based on organizational policies and requirements, known threat and vulnerability information, system and platform dependencies, operational considerations, and tolerance for risk.[4]
1.2 Target Audience
This publication serves system, information security, and privacy[5] professionals including individuals with:
- System development responsibilities (e.g., program managers, system developers, system owners, systems integrators, system security engineers);
- Information security assessment and monitoring responsibilities (e.g., system evaluators, assessors, independent verifiers/validators, auditors, analysts, system owners);
- Information security, privacy, risk management, governance, and oversight responsibilities (e.g., authorizing officials, chief information officers, chief privacy officers, chief information security officers, system managers, information security managers); and
- Information security implementation and operational responsibilities (e.g., system owners, information owners/stewards, mission and business owners, systems administrators, system security officers).
1.3 Organization of this Special Publication
The remainder of this special publication is organized as follows:
- Chapter Two describes the fundamental concepts associated with assessments of CUI security requirements including assessment procedures, methods, objects, and assurance cases that can be created using evidence produced during assessments.
- Chapter Three provides a catalog of assessment procedures for the fourteen families of CUI security requirements in NIST Special Publication 800-171, including assessment objectives and potential assessment methods and objects for each procedure.
- Supporting appendices provide additional assessment-related information including general references; definitions and terms; acronyms; and a description of the assessment methods used in assessment procedures.
Chapter Two: The Fundamentals
Basic concepts for assessments of CUI security requirements
The CUI security requirements in NIST Special Publication 800-171 are organized into fourteen families. Each family contains the requirements related to the general security topic of the family. Table 1 lists the CUI security requirement families addressed in this publication. The assessment procedures in Chapter Three are grouped by family designations to help ensure completeness and consistency of assessments.
TABLE 1: CUI SECURITY REQUIREMENT FAMILIES
| Family | Family |
|---|---|
| Access Control | Media Protection |
| Awareness and Training | Personnel Security |
| Audit and Accountability | Physical Protection |
| Configuration Management | Risk Assessment |
| Identification and Authentication | Security Assessment |
| Incident Response | System and Communications Protection |
| Maintenance | System and Information Integrity |
2.1 Assessment Procedures
An assessment procedure consists of an assessment objective and a set of potential assessment methods and assessment objects that can be used to conduct the assessment. Each assessment objective includes a determination statement related to the CUI security requirement that is the subject of the assessment. The determination statements are linked to the content of the CUI security requirements to ensure traceability of the assessment results to the requirements. The application of an assessment procedure to a security requirement produces assessment findings. These findings reflect, or are subsequently used, to help determine if the security requirement has been satisfied.
Assessment objects identify the specific items being assessed and can include specifications, mechanisms, activities, and individuals. Specifications are the document-based artifacts (e.g., policies, procedures, security plans, security requirements, functional specifications, architectural designs) associated with a system. Mechanisms are the specific hardware, software, or firmware safeguards employed within a system. Activities are the protection-related actions supporting a system that involve people (e.g., conducting system backup operations, exercising a contingency plan, and monitoring network traffic). Individuals, or groups of individuals, are people applying the specifications, mechanisms, or activities described above.
The assessment methods define the nature and the extent of the assessor's actions. The methods include examine, interview, and test. The examine method is the process of reviewing, inspecting, observing, studying, or analyzing assessment objects (i.e., specifications, mechanisms, activities). The purpose of the examine method is to facilitate understanding, achieve clarification, or obtain evidence. The interview method is the process of holding discussions with individuals or groups of individuals to facilitate understanding, achieve clarification, or obtain evidence. And finally, the test method is the process of exercising assessment objects (i.e., activities, mechanisms) under specified conditions to compare actual with expected behavior. In all three assessment methods, the results are used in making specific determinations called for in the determination statements and thereby achieving the objectives for the assessment procedure.
The assessment methods described above have associated attributes of depth and coverage, which define the level of effort for the assessment. These attributes provide a means to define the rigor and scope of the assessment for the increased assurance of security requirements. A description of assessment methods and objects is provided in Appendix D.[6] Figure 1 illustrates an example of an assessment procedure for CUI security requirement 3.1.3 from NIST Special Publication 800-171.
FIGURE 1: ASSESSMENT PROCEDURE FOR CUI SECURITY REQUIREMENT
Organizations are not expected to employ all assessment methods and objects contained within the assessment procedures identified in this publication. Rather, organizations have the flexibility to determine the level of effort needed and the assurance required for an assessment (e.g., which assessment methods and assessment objects are deemed to be the most useful in obtaining the desired results). This determination is made based on how the organization can accomplish the assessment objectives in the most cost-effective manner and with sufficient confidence to support the determination that the CUI requirements have been satisfied.
2.2 Assurance Cases
Building an effective assurance case for determining compliance to CUI security requirements is a process that involves compiling evidence from a variety of sources and conducting different types of activities during an assessment. An assurance case is a body of evidence organized into an argument demonstrating that some claim about a system is true. For assessments conducted using the procedures in this publication, that claim is compliance with the security requirements specified in NIST Special Publication 800-171. Assessors gather evidence during the assessment process to allow designated officials[7] to make objective determinations about compliance to the CUI security requirements. The evidence needed to make such determinations can be obtained from various sources including self-assessments, independent third-party assessments, or other types of assessments, depending on the needs of the organization establishing the requirements and the organization conducting the assessments.
For example, many technical security requirements are satisfied by security capabilities that are built in to commercial information technology products and systems. Product assessments are typically conducted by independent, third-party testing organizations.[8] These assessments examine the security functions of products and established configuration settings. Assessments can also be conducted to demonstrate compliance to industry, national, or international security standards as well as developer and vendor claims. Since many information technology products are assessed by commercial testing organizations and then subsequently deployed in hundreds of thousands of systems, these types of assessments can be carried out at a greater level of depth and provide deeper insights into the security capabilities of the products.
Ultimately, evidence needed to determine compliance comes from the implementation of the selected safeguards to satisfy the CUI security requirements and from the assessments of that implementation. Assessors can build on previously developed materials that started with the specification of the organization's information security needs and is further developed during the design, development, and implementation of the system and system components. These materials, developed while implementing security throughout the life cycle of the system, provide the initial evidence for an assurance case.
Assessments can be conducted by systems developers, systems integrators, auditors, system owners, or the security staffs of organizations. The assessors or assessment teams bring together available information about the system such as the results from individual component product assessments. The assessors can conduct additional system-level assessments using the procedures and methods contained in this publication and based on the implementation information provided by the nonfederal organization in its system security plan. System assessments can be used to compile and evaluate the evidence needed by organizations to help determine the effectiveness of the safeguards implemented to protect CUI; the actions needed to mitigate security-related risks to the organization; and compliance to the CUI security requirements.
Chapter Three: The Procedures
Assessment procedures, methods, and objects for CUI security requirements
This chapter provides assessment procedures for all CUI security requirements defined in NIST Special Publication 800-171. The assessment procedures are organized into fourteen families. Organizations conducting CUI security requirement assessments can build their assessment plans using the information provided in the generic assessment procedures—selecting the specific assessment methods and objects that meet the organization's needs. Organizations also have flexibility in defining the level of rigor and detail associated with the assessment based on the assurance requirements of the organization. Appendix D provides additional information on the different levels of rigor and detail for assessments.
The assessment objective defined for each assessment procedure is achieved by applying the designated assessment methods to the selected assessment objects and compiling/producing the evidence necessary to make the determination associated with each assessment objective. Each determination statement contained within an assessment procedure produces one of the following findings: satisfied or other than satisfied. A finding of "satisfied" indicates that for the security requirement addressed by the determination statement, the assessment information obtained (i.e., the evidence collected) indicates that the assessment objective has been met producing a fully acceptable result. A finding of "other than satisfied" indicates that for the security requirement addressed by the determination statement, the assessment findings obtained indicate potential anomalies that may need to be addressed by the organization. A finding of "other than satisfied" may also indicate that for reasons specified in the assessment report, the assessor was unable to obtain sufficient information to make the determination called for in the determination statement.
For assessment findings that are other than satisfied, organizations may define subcategories of findings indicating the severity or criticality of the weaknesses or deficiencies discovered and the potential adverse effects of those weaknesses or deficiencies on organizational missions and/or business functions. Defining such subcategories can help to establish priorities for needed risk mitigation actions.
3.1 Access Control
3.2 Awareness and Training
3.3 Audit and Accountability
3.4 Configuration Management
3.5 Identification and Authentication
3.6 Incident Response
3.7 Maintenance
3.8 Media Protection
3.9 Personnel Security
3.10 Physical Protection
3.11 Risk Assessment
3.12 Security Assessment
3.13 System and Communications Protection
3.14 System and Information Integrity
Appendix A: References
Laws, Executive Orders, Regulations, Instructions, Standards, and Guidelines[9]
Legislation, Executive Orders, and Regulations
- Federal Information Security Modernization Act of 2014 (P.L. 113-283), December 2014. https://www.gpo.gov/fdsys/pkg/PLAW-113publ283/pdf/PLAW-113publ283.pdf
- Executive Order 13526, Classified National Security Information, December 2009. https://www.archives.gov/isoo/policy-documents/cnsi-eo.html
- Executive Order 13556, Controlled Unclassified Information, November 2010. https://www.gpo.gov/fdsys/pkg/FR-2010-11-09/pdf/2010-28360.pdf
- Executive Order 13636, Improving Critical Infrastructure Cybersecurity, February 2013. https://www.gpo.gov/fdsys/pkg/FR-2013-02-19/pdf/2013-03915.pdf
- 32 CFR Part 2002, Controlled Unclassified Information, September 2016. https://www.gpo.gov/fdsys/pkg/CFR-2017-title32-vol6/pdf/CFR-2017-title32-vol6-part2002.pdf
Standards, Guidelines, Interagency Reports, and Instructions
- National Institute of Standards and Technology Federal Information Processing Standards Publication 199, Standards for Security Categorization of Federal Information and Information Systems, February 2004. https://doi.org/10.6028/NIST.FIPS.199
- National Institute of Standards and Technology Federal Information Processing Standards Publication 200, Minimum Security Requirements for Federal Information and Information Systems, March 2006. https://doi.org/10.6028/NIST.FIPS.200
- National Institute of Standards and Technology Special Publication 800-39, Managing Information Security Risk: Organization, Mission, and Information System View, March 2011. https://doi.org/10.6028/NIST.SP.800-39
- National Institute of Standards and Technology Special Publication 800-53, Revision 4, Security and Privacy Controls for Federal Information Systems and Organizations, April 2013. https://doi.org/10.6028/NIST.SP.800-53r4
- National Institute of Standards and Technology Special Publication 800-53A, Revision 4, Assessing Security and Privacy Controls in Federal Information Systems and Organizations: Building Effective Security Assessment Plans, December 2014. https://doi.org/10.6028/NIST.SP.800-53Ar4
- National Institute of Standards and Technology Special Publication 171, Revision 1, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, December 2016. https://doi.org/10.6028/NIST.SP.800-171r1
- National Institute of Standards and Technology Special Publication 128, Guide for Security-Focused Configuration Management of Information Systems, August 2011. https://doi.org/10.6028/NIST.SP.800-128
- International Organization for Standardization/International Electrotechnical Commission (ISO/IEC) 27001:2013, Information technology -- Security techniques -- Information security management systems -- Requirements, September 2013.
- International Organization for Standardization/International Electrotechnical Commission (ISO/IEC) 27002:2013, Information technology -- Security techniques -- Code of practice for information security controls, September 2013.
- Committee on National Security Systems Instruction 4009, National Information Assurance Glossary, April 2015. https://www.cnss.gov
- National Institute of Standards and Technology Internal Report 8062, An Introduction to Privacy Engineering and Risk Management in Federal Systems, January 2017. https://doi.org/10.6028/NIST.IR.8062
Other Resources
- National Archives and Records Administration, Controlled Unclassified Information Registry. https://www.archives.gov/cui/registry/category-list
- National Institute of Standards and Technology Handbook 162, NIST MEP Cybersecurity Self-Assessment Handbook for Assessing NIST SP 800-171 Security Requirements in Response to DFARS Cybersecurity Requirements, November 2017. https://doi.org/10.6028/NIST.HB.162
Appendix B: Glossary
Common terms and definitions
Appendix B provides definitions for security terminology used within Special Publication 800-171. Unless specifically defined in this glossary, all terms used in this publication are consistent with the definitions contained in CNSS Instruction 4009, National Information Assurance Glossary.
| Term | Definition |
|---|---|
| agency | See executive agency. |
| assessment | See Security Control Assessment. |
| assessor | See Security Control Assessor. |
| audit log | A chronological record of system activities, including records of system accesses and operations performed in a given period. |
| audit record | An individual entry in an audit log related to an audited event. |
| authentication [FIPS 200, Adapted] | Verifying the identity of a user, process, or device, often as a prerequisite to allowing access to resources in a system. |
| availability [44 U.S.C., Sec. 3542] | Ensuring timely and reliable access to and use of information. |
| baseline configuration | A documented set of specifications for a system, or a configuration item within a system, that has been formally reviewed and agreed on at a given point in time, and which can be changed only through change control procedures. |
| blacklisting | A process used to identify software programs that are not authorized to execute on a system or prohibited Universal Resource Locators (URL)/websites. |
| confidentiality [44 U.S.C., Sec. 3542] | Preserving authorized restrictions on information access and disclosure, including means for protecting personal privacy and proprietary information. |
| configuration management | A collection of activities focused on establishing and maintaining the integrity of information technology products and systems, through control of processes for initializing, changing, and monitoring the configurations of those products and systems throughout the system development life cycle. |
| configuration settings | The set of parameters that can be changed in hardware, software, or firmware that affect the security posture and/or functionality of the system. |
| controlled area | Any area or space for which the organization has confidence that the physical and procedural protections provided are sufficient to meet the requirements established for protecting the information or system. |
| controlled unclassified information [E.O. 13556] | Information that law, regulation, or governmentwide policy requires to have safeguarding or disseminating controls, excluding information that is classified under Executive Order 13526, Classified National Security Information, December 29, 2009, or any predecessor or successor order, or the Atomic Energy Act of 1954, as amended. |
| CUI categories or subcategories [Title 32 CFR, Part 2002] | Those types of information for which laws, regulations, or governmentwide policies require or permit agencies to exercise safeguarding or dissemination controls, and which the CUI Executive Agent has approved and listed in the CUI Registry. |
| CUI Executive Agent [Title 32 CFR, Part 2002] | The National Archives and Records Administration (NARA), which implements the executive branch-wide CUI Program and oversees federal agency actions to comply with Executive Order 13556. NARA has delegated this authority to the Director of the Information Security Oversight Office (ISOO). |
| CUI program [Title 32 CFR, Part 2002] | The executive branch-wide program to standardize CUI handling by all federal agencies. The program includes the rules, organization, and procedures for CUI, established by Executive Order 13556, 32 CFR Part 2002, and the CUI Registry. |
| CUI registry [Title 32 CFR, Part 2002] | The online repository for all information, guidance, policy, and requirements on handling CUI, including everything issued by the CUI Executive Agent other than 32 CFR Part 2002. Among other information, the CUI Registry identifies all approved CUI categories and subcategories, provides general descriptions for each, identifies the basis for controls, establishes markings, and includes guidance on handling procedures. |
| environment of operation [NIST SP 800-37, Adapted] | The physical surroundings in which a system processes, stores, and transmits information. |
| executive agency [41 U.S.C., Sec. 403] | An executive department specified in 5 U.S.C., Sec. 105; a military department specified in 5 U.S.C., Sec. 102; an independent establishment as defined in 5 U.S.C., Sec. 104(1); and a wholly owned Government corporation fully subject to the provisions of 31 U.S.C., Chapter 91. |
| external system (or component) | A system or component of a system that is outside of the authorization boundary established by the organization and for which the organization typically has no direct control over the application of required security controls or the assessment of security control effectiveness. |
| external system service | A system service that is implemented outside of the authorization boundary of the organizational system (i.e., a service that is used by, but not a part of, the organizational system) and for which the organization typically has no direct control over the application of required security controls or the assessment of security control effectiveness. |
| external system service provider | A provider of external system services to an organization through a variety of consumer-producer relationships including but not limited to: joint ventures; business partnerships; outsourcing arrangements (i.e., through contracts, interagency agreements, lines of business arrangements); licensing agreements; and/or supply chain exchanges. |
| external network | A network not controlled by the organization. |
| federal agency | See executive agency. |
| federal information system [40 U.S.C., Sec. 11331] | An information system used or operated by an executive agency, by a contractor of an executive agency, or by another organization on behalf of an executive agency. See on behalf of (an agency) for additional information. |
| FIPS-validated cryptography | A cryptographic module validated by the Cryptographic Module Validation Program (CMVP) to meet requirements specified in FIPS Publication 140-2 (as amended). As a prerequisite to CMVP validation, the cryptographic module is required to employ a cryptographic algorithm implementation that has successfully passed validation testing by the Cryptographic Algorithm Validation Program (CAVP). See NSA-Approved Cryptography. |
| firmware | Computer programs and data stored in hardware - typically in read-only memory (ROM) or programmable read-only memory (PROM) - such that the programs and data cannot be dynamically written or modified during execution of the programs. |
| hardware | The physical components of a system. See Software and Firmware. |
| identifier | Unique data used to represent a person's identity and associated attributes. A name or a card number are examples of identifiers. A unique label used by a system to indicate a specific entity, object, or group. |
| impact | The effect on organizational operations, organizational assets, individuals, other organizations, or the Nation (including the national security interests of the United States) of a loss of confidentiality, integrity, or availability of information or a system. |
| impact value | The assessed potential impact resulting from a compromise of the confidentiality of information (e.g., CUI) expressed as a value of low, moderate, or high. |
| incident [FIPS 200, Adapted] | An occurrence that actually or potentially jeopardizes the confidentiality, integrity, or availability of a system or the information the system processes, stores, or transmits or that constitutes a violation or imminent threat of violation of security policies, security procedures, or acceptable use policies. |
| information | Any communication or representation of knowledge such as facts, data, or opinions in any medium or form, including textual, numerical, graphic, cartographic, narrative, or audiovisual. |
| information flow control | Procedure to ensure that information transfers within a system are not made in violation of the security policy. |
| information resources [44 U.S.C., Sec. 3502] | Information and related resources, such as personnel, equipment, funds, and information technology. |
| information security [44 U.S.C., Sec. 3542] | The protection of information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide confidentiality, integrity, and availability. |
| information system [44 U.S.C., Sec. 3502] | A discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information. |
| information technology [40 U.S.C., Sec. 1401] | Any equipment or interconnected system or subsystem of equipment that is used in the automatic acquisition, storage, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information by the executive agency. For purposes of the preceding sentence, equipment is used by an executive agency if the equipment is used by the executive agency directly or is used by a contractor under a contract with the executive agency which: (i) requires the use of such equipment; or (ii) requires the use, to a significant extent, of such equipment in the performance of a service or the furnishing of a product. The term information technology includes computers, ancillary equipment, software, firmware, and similar procedures, services (including support services), and related resources. |
| insider threat | The threat that an insider will use her/his authorized access, wittingly or unwittingly, to do harm to the security of the United States. This threat can include damage to the United States through espionage, terrorism, unauthorized disclosure, or through the loss or degradation of departmental resources or capabilities. |
| integrity [44 U.S.C., Sec. 3542] | Guarding against improper information modification or destruction, and includes ensuring information non-repudiation and authenticity. |
| internal network | A network where establishment, maintenance, and provisioning of security controls are under the direct control of organizational employees or contractors; or the cryptographic encapsulation or similar security technology implemented between organization-controlled endpoints, provides the same effect (with regard to confidentiality and integrity). An internal network is typically organization-owned, yet may be organization-controlled while not being organization-owned. |
| least privilege | The principle that a system security architecture is designed so that each entity is granted the minimum system resources and authorizations that the entity needs to perform its function. |
| local access | Access to an organizational system by a user (or process acting on behalf of a user) communicating through a direct connection without the use of a network. |
| malicious code | Software or firmware intended to perform an unauthorized process that will have adverse impact on the confidentiality, integrity, or availability of a system. A virus, worm, Trojan horse, or other code-based entity that infects a host. Spyware and some forms of adware are also examples of malicious code. |
| media [FIPS 200] | Physical devices or writing surfaces including, but not limited to, magnetic tapes, optical disks, magnetic disks, Large-Scale Integration (LSI) memory chips, and printouts (but not including display media) onto which information is recorded, stored, or printed within a system. |
| mobile code | Software programs or parts of programs obtained from remote systems, transmitted across a network, and executed on a local system without explicit installation or execution by the recipient. |
| mobile device | A portable computing device that has a small form factor such that it can easily be carried by a single individual; is designed to operate without a physical connection (e.g., wirelessly transmit or receive information); possesses local, non-removable/removable data storage; and includes a self-contained power source. Mobile devices may also include voice communication capabilities, on-board sensors that allow the devices to capture information, or built-in features that synchronize local data with remote locations. Examples include smartphones, tablets, and E-readers. |
| multifactor authentication | Authentication using two or more different factors to achieve authentication. Factors include something you know (e.g., PIN, password); something you have (e.g., cryptographic identification device, token); or something you are (e.g., biometric). See also Authenticator. |
| nonfederal organization | An entity that owns, operates, or maintains a nonfederal system. |
| nonfederal system | A system that does not meet the criteria for a federal system. |
| network | A system implemented with a collection of interconnected components. Such components may include routers, hubs, cabling, telecommunications controllers, key distribution centers, and technical control devices. |
| network access | Access to a system by a user (or a process acting on behalf of a user) communicating through a network (e.g., local area network, wide area network, Internet). |
| nonlocal maintenance | Maintenance activities conducted by individuals communicating through a network, either an external network (e.g., the Internet) or an internal network. |
| on behalf of (an agency) [32 CFR Part 2002] | A situation that occurs when: (i) a non-executive branch entity uses or operates an information system or maintains or collects information for the purpose of processing, storing, or transmitting Federal information; and (ii) those activities are not incidental to providing a service or product to the government. |
| organization [FIPS 200, Adapted] | An entity of any size, complexity, or positioning within an organizational structure. |
| portable storage device | A system component that can be inserted into and removed from a system, and that is used to store data or information (e.g., text, video, audio, and/or image data). Such components are typically implemented on magnetic, optical, or solid-state devices (e.g., floppy disks, compact/digital video disks, flash/thumb drives, external hard disk drives, and flash memory cards/drives that contain nonvolatile memory). |
| potential impact [FIPS 199] | The loss of confidentiality, integrity, or availability could be expected to have: (i) a limited adverse effect (FIPS Publication 199 low); (ii) a serious adverse effect (FIPS Publication 199 moderate); or (iii) a severe or catastrophic adverse effect (FIPS Publication 199 high) on organizational operations, organizational assets, or individuals. |
| privileged account | A system account with authorizations of a privileged user. |
| privileged user | A user that is authorized (and therefore, trusted) to perform security-relevant functions that ordinary users are not authorized to perform. |
| records | The recordings (automated and/or manual) of evidence of activities performed or results achieved (e.g., forms, reports, test results), which serve as a basis for verifying that the organization and the system are performing as intended. Also used to refer to units of related data fields (i.e., groups of data fields that can be accessed by a program and that contain the complete set of information on particular items). |
| remote access | Access to an organizational system by a user (or a process acting on behalf of a user) communicating through an external network (e.g., the Internet). |
| remote maintenance | Maintenance activities conducted by individuals communicating through an external network (e.g., the Internet). |
| replay resistance | Protection against the capture of transmitted authentication or access control information and its subsequent retransmission with the intent of producing an unauthorized effect or gaining unauthorized access. |
| risk [FIPS 200, Adapted] | A measure of the extent to which an entity is threatened by a potential circumstance or event, and typically a function of: (i) the adverse impacts that would arise if the circumstance or event occurs; and (ii) the likelihood of occurrence. System-related security risks are those risks that arise from the loss of confidentiality, integrity, or availability of information or systems. Such risks reflect the potential adverse impacts to organizational operations, organizational assets, individuals, other organizations, and the Nation. |
| risk assessment | The process of identifying risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of a system. Part of risk management, incorporates threat and vulnerability analyses, and considers mitigations provided by security controls planned or in place. Synonymous with risk analysis. |
| sanitization | Actions taken to render data written on media unrecoverable by both ordinary and, for some forms of sanitization, extraordinary means. Process to remove information from media such that data recovery is not possible. It includes removing all classified labels, markings, and activity logs. |
| security | A condition that results from the establishment and maintenance of protective measures that enable an enterprise to perform its mission or critical functions despite risks posed by threats to its use of systems. Protective measures may involve a combination of deterrence, avoidance, prevention, detection, recovery, and correction that form part of the enterprise's risk management approach. |
| security assessment | See Security Control Assessment. |
| security control [FIPS 199, Adapted] | A safeguard or countermeasure prescribed for a system or an organization designed to protect the confidentiality, integrity, and availability of its information and to meet a set of defined security requirements. |
| security control assessment [CNSSI 4009, Adapted] | The testing or evaluation of security controls to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for a system or organization. |
| security functionality | The security-related features, functions, mechanisms, services, procedures, and architectures implemented within organizational systems or the environments in which those systems operate. |
| security functions | The hardware, software, or firmware of the system responsible for enforcing the system security policy and supporting the isolation of code and data on which the protection is based. |
| security relevance | Functions or mechanisms that are relied upon, directly or indirectly, to enforce a security policy that governs confidentiality, integrity, and availability protections. |
| situational awareness [CNSSI 4009] | Within a volume of time and space, the perception of an enterprise's security posture and its threat environment; the comprehension/meaning of both taken together (risk); and the projection of their status into the near future. |
| split tunneling | The process of allowing a remote user or device to establish a non-remote connection with a system and simultaneously communicate via some other connection to a resource in an external network. This method of network access enables a user to access remote devices (e.g., a networked printer) at the same time as accessing uncontrolled networks. |
| supplemental guidance | Statements used to provide additional explanatory information for security controls or security control enhancements. |
| system | See Information System. |
| system component [NIST SP 800-128, Adapted] | A discrete, identifiable information technology asset (hardware, software, firmware) that represents a building block of a system. System components include commercial information technology products. |
| system security plan | A document that describes how an organization meets the security requirements for a system or how an organization plans to meet the requirements. The system security plan describes the system boundary; the environment in which the system operates; the relationships with or connections to other systems; and how the security requirements are implemented. |
| system service | A capability provided by a system that facilitates information processing, storage, or transmission. |
| threat [CNSSI 4009, Adapted] | Any circumstance or event with the potential to adversely impact organizational operations, organizational assets, individuals, other organizations, or the Nation through a system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service. |
| user [CNSSI 4009, Adapted] | Individual, or (system) process acting on behalf of an individual, authorized to access a system. |
| whitelisting | A process used to identify software programs that are authorized to execute on a system or authorized Universal Resource Locators (URL)/websites. |
| wireless technology | Technology that permits the transfer of information between separated points without physical connection. |
Appendix C: Acronyms
Common abbreviations
| Acronym | Meaning |
|---|---|
| CFR | Code of Federal Regulations |
| CIO | Chief Information Officer |
| CNSS | Committee on National Security Systems |
| CUI | Controlled Unclassified Information |
| FIPS | Federal Information Processing Standards |
| FISMA | Federal Information Security Modernization Act |
| ISO/IEC | International Organization for Standardization/International Electrotechnical Commission |
| ISOO | Information Security Oversight Office |
| ITL | Information Technology Laboratory |
| NARA | National Archives and Records Administration |
| NFO | Nonfederal Organization |
| NIST | National Institute of Standards and Technology |
| OMB | Office of Management and Budget |
| SP | Special Publication |
| SSP | System Security Plan |
Appendix D: Assessment Methods
Assessment method definitions, applicable objects, and attributes
This appendix defines three assessment methods that can be used to assess the CUI security requirements in NIST Special Publication 800-171: examine, interview, and test. Included in the definition of each assessment method are types of objects to which the method can be applied. The application of each method is described in terms of the attributes of depth and coverage, progressing from basic to focused to comprehensive. The attribute values correlate to the assurance requirements specified by the organization.
The depth attribute addresses the rigor and level of detail of the assessment. For the depth attribute, the focused attribute value includes and builds upon the assessment rigor and level of detail defined for the basic attribute value; the comprehensive attribute value includes and builds upon the assessment rigor and level of detail defined for the focused attribute value.
The coverage attribute addresses the scope or breadth of the assessment. For the coverage attribute, the focused attribute value includes and builds upon the number and type of assessment objects defined for the basic attribute value; the comprehensive attribute value includes and builds upon the number and type of assessment objects defined for the focused attribute value.
Tables D-1 through D-3 provide complete descriptions of the examine, interview, and test assessment methods. The use of bolded text in the assessment method description indicates the content that was added to and appears for the first time, in the description indicating greater rigor and level of detail for the attribute value.
Table D-1: Examine Assessment Method
| Method: EXAMINE | |
|---|---|
| The process of checking, inspecting, reviewing, observing, studying, or analyzing one or more assessment objects to facilitate understanding, achieve clarification, or obtain evidence. The results are used to support the determination of security safeguard existence, functionality, correctness, completeness, and potential for improvement over time. | |
| Objects | Description |
| Specifications | Examples: policies, plans, procedures, system requirements, designs. |
| Mechanisms | Examples: functionality implemented in hardware, software, firmware. |
| Activities | Examples: system operations, administration, management, exercises. |
| Attribute: Depth | Description |
| Basic | Examination that consists of high-level reviews, checks, observations, or inspections of the assessment object. This type of examination is conducted using a limited body of evidence or documentation. Examples include: functional-level descriptions for mechanisms; high-level process descriptions for activities; and documents for specifications. Basic examinations provide a level of understanding of the security safeguards necessary for determining whether the safeguards are implemented and free of obvious errors. |
| Focused | Examination that consists of high-level reviews, checks, observations, or inspections and more in-depth studies and analyses of the assessment object. This type of examination is conducted using a substantial body of evidence or documentation. Examples include: functional-level descriptions and where appropriate and available, high-level design information for mechanisms; high-level process descriptions and implementation procedures for activities; and documents and related documents for specifications. Focused examinations provide a level of understanding of the security safeguards necessary for determining whether the safeguards are implemented and free of obvious errors and whether there are increased grounds for confidence that the safeguards are implemented correctly and operating as intended. |
| Comprehensive | Examination that consists of high-level reviews, checks, observations, or inspections and more in-depth, detailed, and thorough studies and analyses of the assessment object. This type of examination is conducted using an extensive body of evidence or documentation. Examples include: functional-level descriptions and where appropriate and available, high-level design information, low-level design information, and implementation information for mechanisms; high-level process descriptions and detailed implementation procedures for activities; and documents and related documents for specifications.[10] Comprehensive examinations provide a level of understanding of the security safeguards necessary for determining whether the safeguards are implemented and free of obvious errors and whether there are further increased grounds for confidence that the safeguards are implemented correctly and operating as intended on an ongoing and consistent basis, and that there is support for continuous improvement in the effectiveness of the safeguards. |
| Attribute: Coverage | Description |
| Addresses the scope or breadth of the examination process and includes the types of assessment objects to be examined; the number of objects to be examined by type; and specific objects to be examined.[11] | |
| Basic | Examination that uses a representative sample of assessment objects (by type and number within type) to provide a level of coverage necessary for determining whether the security safeguards are implemented and free of obvious errors. |
| Focused | Examination that uses a representative sample of assessment objects (by type and number within type) and other specific assessment objects deemed particularly important to achieving the assessment objective to provide a level of coverage necessary for determining whether the security safeguards are implemented and free of obvious errors and whether there are increased grounds for confidence that the safeguards are implemented correctly and operating as intended. |
| Comprehensive | Examination that uses a sufficiently large sample of assessment objects (by type and number within type) and other specific assessment objects deemed particularly important to achieving the assessment objective to provide a level of coverage necessary for determining whether the security safeguards are implemented and free of obvious errors and whether there are further increased grounds for confidence that the safeguards are implemented correctly and operating as intended on an ongoing and consistent basis, and that there is support for continuous improvement in the effectiveness of the safeguards. |
| Discussion | |
| Typical assessor actions may include, for example: reviewing information security policies, plans, and procedures; analyzing system design documentation and interface specifications; observing system backup operations; reviewing training records; reviewing audit records; observing incident response activities; studying technical manuals and user/administrator guides; checking, studying, or observing the operation of an information technology mechanism in the system hardware or software; or checking, studying, or observing physical security measures related to the operation of a system. | |
Table D-2: Interview Assessment Method
| Method: INTERVIEW | |
|---|---|
| The process of conducting discussions with individuals or groups of individuals in an organization to facilitate understanding, achieve clarification, or lead to the location of evidence. The results are used to support the determination of security safeguard existence, functionality, correctness, completeness, and potential for improvement over time. | |
| Objects | Description |
| Individuals or Groups | Examples: Personnel with risk assessment responsibilities; personnel with information security responsibilities; system or network administrators; personnel with account management responsibilities. |
| Attribute: Depth | Description |
| Basic | Interview that consists of broad-based, high-level discussions with individuals or groups of individuals. This type of interview is conducted using a set of generalized, high-level questions. Basic interviews provide a level of understanding of the security safeguards necessary for determining whether the safeguards are implemented and free of obvious errors. |
| Focused | Interview that consists of broad-based, high-level discussions and more in-depth discussions in specific areas with individuals or groups of individuals. This type of interview is conducted using a set of generalized, high-level questions and more in-depth questions in specific areas where responses indicate a need for more in-depth investigation. Focused interviews provide a level of understanding of the security safeguards necessary for determining whether the safeguards are implemented and free of obvious errors and whether there are increased grounds for confidence that the safeguards are implemented correctly and operating as intended. |
| Comprehensive | Interview that consists of broad-based, high-level discussions and more in-depth, probing discussions in specific areas with individuals or groups of individuals. This type of interview is conducted using a set of generalized, high-level questions and more in-depth, probing questions in specific areas where responses indicate a need for more in-depth investigation. Comprehensive interviews provide a level of understanding of the security safeguards necessary for determining whether the safeguards are implemented and free of obvious errors and whether there are further increased grounds for confidence that the safeguards are implemented correctly and operating as intended on an ongoing and consistent basis, and that there is support for continuous improvement in the effectiveness of the safeguards. |
| Attribute: Coverage | Description |
| Addresses the scope or breadth of the interview process and includes the types of individuals to be interviewed by role and responsibility; the number of individuals to be interviewed by type; and specific individuals to be interviewed.[12] | |
| Basic | Interview that uses a representative sample of individuals in organizational roles to provide a level of coverage necessary for determining whether the security safeguards are implemented and free of obvious errors. |
| Focused | Interview that uses a representative sample of individuals in organizational roles and other specific individuals deemed particularly important to achieving the assessment objective to provide a level of coverage necessary for determining whether the security safeguards are implemented and free of obvious errors and whether there are increased grounds for confidence that the safeguards are implemented correctly and operating as intended. |
| Comprehensive | Interview that uses a sufficiently large sample of individuals in organizational roles and other specific individuals deemed particularly important to achieving the assessment objective to provide a level of coverage necessary for determining whether the security safeguards are implemented and free of obvious errors and whether there are further increased grounds for confidence that the safeguards are implemented correctly and operating as intended on an ongoing and consistent basis, and that there is support for continuous improvement in the effectiveness of the safeguards. |
| Discussion | |
| Typical assessor actions may include, for example, interviewing chief executive officers, chief information officers, senior information security officers, information owners, system and mission owners, system security officers, system security managers, personnel officers, human resource managers, network and system administrators, facilities managers, training officers, physical security officers, system operators, site managers, and users. | |
Table D-3: Test Assessment Method
| Method: TEST | |
|---|---|
| The process of exercising one or more assessment objects under specified conditions to compare actual with expected behavior. The results are used to support the determination of security safeguard existence, functionality, correctness, completeness, and potential for improvement over time.[13] | |
| Objects | Description |
| Mechanisms | Examples: hardware, software, firmware. |
| Activities | Examples: system operations, administration, management; exercises. |
| Attribute: Depth | Description |
| Basic | Test methodology (also known as black box testing) that assumes no knowledge of the internal structure and implementation detail of the assessment object. This type of testing is conducted using a functional specification for mechanisms and a high-level process description for activities. Basic testing provides a level of understanding of the security safeguards necessary for determining whether the safeguards are implemented and free of obvious errors. |
| Focused | Test methodology (also known as gray box testing) that assumes some knowledge of the internal structure and implementation detail of the assessment object. This type of testing is conducted using a functional specification and limited system architectural information (e.g., high-level design) for mechanisms and a high-level process description and high-level description of integration into the operational environment for activities. Focused testing provides a level of understanding of the security safeguards necessary for determining whether the safeguards are implemented and free of obvious errors and whether there are increased grounds for confidence that the safeguards are implemented correctly and operating as intended. |
| Comprehensive | Test methodology (also known as white box testing) that assumes explicit and substantial knowledge of the internal structure and implementation detail of the assessment object. This type of testing is conducted using a functional specification, extensive system architectural information (e.g., high-level design, low-level design) and implementation representation (e.g., source code, schematics) for mechanisms and a high-level process description and detailed description of integration into the operational environment for activities. Comprehensive testing provides a level of understanding of the security safeguards necessary for determining whether the safeguards are implemented and free of obvious errors and whether there are further increased grounds for confidence that the safeguards are implemented correctly and operating as intended on an ongoing and consistent basis, and that there is support for continuous improvement in the effectiveness of the safeguards. |
| Attribute: Coverage | Description |
| Addresses the scope or breadth of the testing process and includes the types of assessment objects to be tested; the number of objects to be tested by type; and specific objects to be tested. | |
| Basic | Testing that uses a representative sample of assessment objects by type and number within type, to provide a level of coverage necessary for determining whether the security safeguards are implemented and free of obvious errors. |
| Focused | Testing that uses a representative sample of assessment objects by type and number within type, and other specific assessment objects deemed particularly important to achieving the assessment objective to provide a level of coverage necessary for determining whether the security safeguards are implemented and free of obvious errors and whether there are increased grounds for confidence that the safeguards are implemented correctly and operating as intended. |
| Comprehensive | Testing that uses a sufficiently large sample of assessment objects by type and number within type, and other specific assessment objects deemed particularly important to achieving the assessment objective to provide a level of coverage necessary for determining whether the security safeguards are implemented and free of obvious errors and whether there are further increased grounds for confidence that the safeguards are implemented correctly and operating as intended on an ongoing and consistent basis, and that there is support for continuous improvement in the effectiveness of the safeguards. |
| Discussion | |
| Typical assessor actions may include, for example: testing access control, identification and authentication, and audit mechanisms; testing security configuration settings; testing physical access control devices; conducting penetration testing of key system components; testing system backup operations; testing incident response capability; and exercising vulnerability scanning capability. | |
Notes
- ↑ Controlled Unclassified Information is information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation, or governmentwide policy requires or permits an agency to handle using safeguarding or dissemination controls, excluding information that is classified under Executive Order 13526, Classified National Security Information, December 29, 2009, or any predecessor or successor order, or the Atomic Energy Act of 1954, as amended.
- ↑ The CUI Registry is the online repository for information, guidance, policy, and requirements on handling CUI.
- ↑ The CUI Executive Agent is actively engaged in the process of developing a FAR clause that will apply the requirements of the federal CUI regulation and NIST Special Publication 800-171 to contractors.
- ↑ The term risk is used to mean risk to organizational operations (i.e., mission, functions, image, and reputation), organizational assets, individuals, other organizations, and the Nation. See NIST Special Publication 800-39 for additional information on organizational risk management and risk tolerance.
- ↑ References to privacy in this publication are made only in the context of where security and privacy considerations overlap—that is, in the security objective of confidentiality, which generally supports privacy and the protection of personally identifiable information from unauthorized disclosure. NIST Internal Report 8062 provides additional information on the overlapping and complementary nature of security and privacy disciplines.
- ↑ Additional information on assessment methods and objects and the attributes of depth and coverage is provided in NIST Special Publication 800-53A.
- ↑ A designated official is an official, either internal or external to the nonfederal organization, with the responsibility to determine organizational compliance to CUI security requirements.
- ↑ Examples include Common Criteria Testing Laboratories evaluating commercial IT products in accordance with ISO/IEC 15408 and Cryptographic Module Validation Program Testing Laboratories evaluating cryptographic modules in accordance with Federal Information Processing Standard (FIPS) 140.
- ↑ References in this section without specific publication dates or revision numbers are assumed to refer to the most recent updates to those publications.
- ↑ While additional documentation is likely for mechanisms when moving from basic to focused to comprehensive examinations, the documentation associated with specifications and activities may be the same or similar for focused and comprehensive examinations, with the rigor of the examinations of these documents being increased at the comprehensive level.
- ↑ The organization, considering a variety of factors (e.g., available resources, importance of the assessment, the organization's overall assessment goals and objectives), confers with assessors and provides direction on the type, number, and specific objects to be examined for the attribute value described.
- ↑ The organization, considering a variety of factors (e.g., available resources, importance of the assessment, the organization's overall assessment goals and objectives), confers with assessors and provides direction on the type, number, and specific individuals to be interviewed for the attribute value described.
- ↑ Testing is typically used to determine if mechanisms or activities meet a set of predefined specifications. Testing can also be performed to determine characteristics of a security or privacy control that are not commonly associated with predefined specifications, with an example of such testing being penetration testing.