800-171

NIST 800-171 3.5.10 Store and transmit only cryptographically-protected passwords.
Description:    Cryptographically-protected passwords use salted one-way cryptographic hashes of passwords. See [NIST CRYPTO].  Priority: High    C...
Tue, 11 Jul, 2023 at 6:57 AM
NIST 800-171 3.5.11 Obscure feedback of authentication information
Description:    The feedback from systems does not provide any information that would allow unauthorized individuals to compromise authentication mechanism...
Tue, 11 Jul, 2023 at 7:05 AM
NIST 800-171 3.6.1 Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.
Description:    Organizations recognize that incident handling capability is dependent on the capabilities of organizational systems and the mission/busine...
Wed, 12 Jul, 2023 at 8:55 AM
NIST 800-171 3.6.2 Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.
Description:    Tracking and documenting system security incidents includes maintaining records about each incident, the status of the incident, and other ...
Wed, 12 Jul, 2023 at 8:56 AM
NIST 800-171 3.6.3 Test the organizational incident response capability.
Description:    Organizations test incident response capabilities to determine the effectiveness of the capabilities and to identify potential weaknesses o...
Wed, 12 Jul, 2023 at 8:56 AM
NIST 800-171 3.7.1 Perform maintenance on organizational systems.[26].
Description:    This requirement addresses the information security aspects of the system maintenance program and applies to all types of maintenance to an...
Wed, 12 Jul, 2023 at 6:31 AM
NIST 800-171 3.7.2 Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.
Description:    This requirement addresses security-related issues with maintenance tools that are not within the organizational system boundaries that pro...
Wed, 12 Jul, 2023 at 6:28 AM
NIST 800-171 3.7.3 Ensure equipment removed for off-site maintenance is sanitized of any CUI.
Description:    This requirement addresses the information security aspects of system maintenance that are performed off-site and applies to all types of m...
Wed, 12 Jul, 2023 at 6:25 AM
NIST 800-171 3.7.4 Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.
Description:    Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.  Priority: ...
Wed, 12 Jul, 2023 at 6:20 AM
NIST 800-171 3.7.5 Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.
Description:    Nonlocal maintenance and diagnostic activities are those activities conducted by individuals communicating through an external network. The...
Wed, 12 Jul, 2023 at 6:17 AM