NIST Special Publication 800 -171A
Assessing Security Requirements for
Controlled Unclassified Information
RON ROSS
KELLEY DEMPSEY
VICTORIA PILLITTERI
NIST Special Publication 800 -171A
Assessing Security Requirements for
Controlled Unclassified Information
RON ROSS
KELLEY DEMPSEY
VICTORIA PILLITTERI
Computer Security Division
National Institute of Standards and Technology
June 2018
U.S. Department of Commerce
Wilbur L. Ross, Jr., Secretary
National Institute of Standards and Technology
Walter Copan, NIST Director and Under Secretary of Commerce f or Standards and Technology NIST SP 800 -171A ASSESSING SECURITY REQUIREMENTS FOR CONTROLLED UNCLASSIFIED INFORMAT ION
________________________________________________________________________________________________
PAGE i
This publication is available free of charge from: http s://doi.org/10.6028/ NIST.SP.800 -171A
Authority
This publication has been developed by the National Institute of Standards and Technology to
further its statutory responsibilities under the Federal Information Security Modernization Act
(FISMA) of 2014, 44 U.S.C. § 3551 et seq. , Public Law (P.L.) 113- 283. NIST is responsible for
developing information security standards and guidelines, includi ng minimum requirements for
federal information systems, but such standards and guidelines shall not apply to national security
systems without the express approval of appropriate federal officials exercising policy authority
over such systems. This g uidel ine is consistent with requirements of the Office of Management
and Budget (OMB) Circular A -130.
Nothing in this publication should be taken to contradict the standards and guidelines made
mandatory and binding on federal agencies by the Secretary of Comme rce under statutory
authority. Nor should these guidelines be interpreted as altering or superseding the existing
authorities of the Secretary of Commerce, Director of OMB, or any other federal official. This
publication may be used by nongovernmental orga nizations on a voluntary basis and is not
subject to copyright in the United States. Attribution would, however, be appreciated by NIST.
National Institute of Standards and Technology Special Publication 800- 171A
Natl. Inst. Stand. Technol. Spec. Publ. 800- 171A , 92 pages (June 2018)
CODEN: NSPUE2
This publication is available free of charge from:
https://doi.org/10.6028/NIST.SP.800 -171A
Comments on this publication may be submitted to:
National Institute of Standards and Technology
Attn: Computer Security Division, Information Technology Laboratory
100 Bureau Drive (Mail Stop 8930) Gaithersburg, MD 20899- 8930
Email:
[email protected]
All comments are subject to release under the Freedom of Information Act (FOIA). Certain commercial entities, equipment, or materials may be identified in this document to
describe an experimental procedure or concept adequately. Such identification is not intended to
imply recommendation or endorsement by NIST, nor is it intended to i mply that the entities,
materials, or equipment are necessarily the best available for the purpose.
There may be references in this publication to other publications currently under development by
NIST in accordance with its assigned statutory responsibil ities. The information in this publication,
including concepts, practices, and methodologies, may be used by federal agencies even before
the completion of such companion publications. Thus, until each publication is completed, curren