Understanding NIST SP 800-171 Compliance
If your organization does any type of business with the Department of Defense (DoD), you must meet the IT security requirements outlined in the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, also known as NIST SP 800-171.
The increasing complexity and frequency of cybersecurity threats remain a top concern for businesses of all industries and sizes today. The DoD has taken its security measures a step further and mandated that all their contractors implement the basic IT security practices outlined in NIST SP 800-171.
So what exactly does NIST SP 800-171 compliance entail? We help you understand more about what’s required of your organization to continue working with the DoD and uphold your current contracts.
Minimum Security Requirements
The requirements include basic things such as establishing protocol for handling potential security breaches to screening employees before they have access to any type of covered defense information (CDI).
Depending on your organization as well as your field of expertise, you may or may not have many of these controls already in place. Some businesses may already be largely in NIST SP 800-171 compliance while others may need to work much harder to meet the requirements.
The Controls to Address
This means that in order to be in NIST SP 800-171 compliance, you must address the 14 control families outlined in Chapter Three of NIST SP 800-171 and have a security plan in place in the event that your Contract Officer requires you to detail your protocol.
Some of these control areas include access control, awareness and training, configuration management, incident response, system maintenance, physical protection, risk assessment, and reporting any cybersecurity attack that compromises CDI within 72 hours.
Many of these controls detail essential, such as assessing your current system’s risk, mandating training for all contractors and subcontractors, and performing regular system maintenance.
Addressing these controls in order to maintain compliance can be achieved through the help of IT security professionals familiar with NIST SP 800-171. An in-house IT team may or may not be able to help ensure compliance.
Your Responsibility to Ensure Compliance
Remember that if compliance is not met, you risk having your pay withheld, your contract suspended, or your contract terminated. Once you’ve met these requirements, you’ll need to continue to uphold them as you continue your work with the DoD to protect CDI as well as your own business.
Are You in Compliance?