NIST Special Publication 800 -171
Revision 2
Protecting Controlled Unclassified
Information in Nonfederal Systems
and Organizations
RON ROSS
VICTORIA PILLITTERI
KELLEY DEMPSEY
MARK RIDDLE
GARY GUISSANIE
This publication is available free of charge from:
https://doi.org/10.6028/NIST.SP.800 -171r2
NIST Special Publication 800 -171
Revision 2
Protecting Controlled Unclassified
Information in Nonfederal Systems
and Organizations
RON ROSS
VICTORIA PILLITTERI
KELLEY DEMPSEY
Computer Security Division
National Institute of Standards and Technology
MARK RIDDLE
Information Security Oversight Office
National Archives and Records Administration
GARY GUISSANIE
Institute for Defense Analyses
This publication is available free of charge from:
https://doi.org/10.6028/NIST.SP.800 -171r2
February 2020
INCLUDES UPDATES AS OF 01- 28-2021; SEE PAGE X
U.S. Department of Commerce
Wilbur L. Ross, Jr., Secretary
National Institute of Standards and Technology
Walter Copan, NIST Director and Under Secretary of Commerce for Standards and Technology SP 800- 171, REVISION 2 PROTECTING CONTROLLED UNCLASSIFIED INFORMATION
_________________________________________________________________________________________________
PAGE i
This publication is available free of charge from: https://doi.org/10.6028/NIST.SP.800 -171r2
Authority
This publication has been developed by NIST to further its statutory responsibilities under the
Federal Information Security Modernization Act (FISMA), 44 U.S.C. § 3551 et seq. , Public Law
(P.L.) 113 -283. NIST is responsible for developing information security standards and guidelines,
including minimum requirements for federal information systems. Such information security
standards and guidelines shall not apply to national security systems without the express
approval of the ap propriate federal officials exercising policy authority over such systems. This
guideline is consistent with the requirements of the Office of Management and Budget (OMB)
Circular A-130.
Nothing in this publication should be taken to contradict the standar ds and guidelines made
mandatory and binding on federal agencies by the Secretary of Commerce under statutory
authority. Nor should these guidelines be interpreted as altering or superseding the existing
authorities of the Secretary of Commerce, OMB Direct or, or any other federal official. This
publication may be used by nongovernmental organizations on a voluntary basis, and is not
subject to copyright in the United States. Attribution would, however, be appreciated by NIST.
National Institute of Standar ds and Technology Special Publication 800 -171, Revision 2
Natl. Inst. Stand. Technol. Spec. Publ. 800 -171, Revision 2 , 113 pages (February 2020)
CODEN: NSPUE2
This publication is available free of charge from:
https://doi.org/10.6028/NIST.SP.800- 171r2
Comments on this publication may be submitted to:
National Institute of Standards and Technology
Attn: Computer Security Division, Information Technology Laboratory
100 Bureau Drive (Mail Stop 8930) Gaithersburg, MD 20899 -8930
Email:
[email protected]
All comments are subject to release under the Freedom of Informat ion Act (FOIA) [FOIA96 ] Certain commercial entities, equipment, or materials may be identified in this document to describe
an experimental procedure or concept adequately. Such identification is not intended to imply
recommendation or endorsement by NIST, nor is it intended to imply that the entities, materials, or
equipment are necessarily the best available for