Date Published: February 2020 (includes updates as of January 28, 2021)
Supersedes:
SP 800-171 Rev. 2 (02/21/2020)
Planning Note (3/9/2021):
NIST SP 800-171, Revision 2 issued on 1/28/2021 is an errata update. It is consistent with NIST procedures and criteria for errata updates, whereby a new copy of a final publication is issued to include corrections that do not alter existing or introduce new technical information or requirements. Such corrections are intended to remove ambiguity and improve interpretation of the work, and may also be used to improve readability or presentation (e.g., formatting, grammar, spelling). Specifically in SP 800-171, Revision 2, an existing paragraph was moved to an earlier section to emphasize existing relevant supplemental guidance about the applicability of the security requirements. The changes in the applicability paragraph are editorial in nature and do not impact the publication's scope or implementation, nor introduce new technical information. Documentation > Supplemental Material > CUI SSP template: ** There is no prescribed format or specified level of detail for system security plans. However, organizations ensure that the required information in [SP 800-171 Requirement] 3.12.4 is conveyed in those plans.
, , , ,
Access Control; Audit and Accountability; Awareness and Training; Configuration Management; Identification and Authentication; Maintenance; Media Protection; Personnel Security; Physical and Environmental Protection; System and Communications Protection; System and Information Integrity
Publication:
SP 800-171 Rev. 2 (DOI)
Local Download
Supplemental Material:
CUI Plan of Action template (word)
CUI SSP template **[see Planning Note] (word)
Mapping: Cybersecurity Framework v.1.0 to SP 800-171 Rev. 2 (xls)
Other Parts of this Publication:
SP 800-171A
Related NIST Publications:
Document History:
01/28/21: SP 800-171 Rev. 2 (Final)
Security and Privacy
audit & accountability; awareness training & education; maintenance; security controls; threats
Laws and Regulations
Federal Acquisition Regulation; Federal Information Security Modernization Act