Compliance & Frameworks
NIST SP 800-171
Also known as: SP 800-171, NIST 800-171
Definition
A NIST publication defining security requirements for protecting Controlled Unclassified Information (CUI) stored or processed by non-federal organizations.
Examples
- A Department of Defense contractor implementing 800-171 to meet DFARS 252.204-7012.
- A research university handling federal CUI on grant-funded projects.
Related terms
NIST SP 800-53
A NIST publication providing a comprehensive catalog of security and privacy controls for U.S. federal information systems and many private-sector adopters.
CMMC
CMMC — definition coming soon.
NIST Cybersecurity Framework
A voluntary risk-based framework published by the U.S. National Institute of Standards and Technology that organizes cybersecurity outcomes into six core functions.
FISMA
FISMA — definition coming soon.
Compliance
The discipline of meeting legal, regulatory, contractual, and internal security requirements through documented controls, evidence collection, and ongoing assessment.
Security Controls
Safeguards or countermeasures — technical, administrative, or physical — used to prevent, detect, or respond to threats against information assets.