Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
OFFICIAL IDENTIFIERS & TITLESPENDING NIST SME REVIEW

NIST SP 800-171 Rev. 2 mapping — all 110 requirements

Every Rev. 2 requirement with its official statement, an independent plain-language explanation, and the practices that genuinely support it. The revision most current DIB contracts reference through DFARS 252.204-7012.

14 families

The families at a glance

3.18/22 MAPPED

Access Control

Who and what may reach the system, and what they may do once inside: account authorization, least privilege, remote and wireless pathways, mobile devices, external systems, and public content. The largest family in Rev. 2, and the one where most small-business gaps concentrate.

3.22/3 MAPPED

Awareness and Training

People know the risks their role carries and are trained for their security duties — including recognizing insider-threat indicators. Three requirements, all of which depend on records to demonstrate.

3.33/9 MAPPED

Audit and Accountability

Actions on the system can be reconstructed and attributed: logs exist, are reviewed, are protected from tampering, alert when logging fails, and rest on synchronized clocks.

3.45/9 MAPPED

Configuration Management

Systems are built from known baselines, changed only through review, and stripped to essential functions. Inventory and baseline discipline here is what most other families silently assume.

3.55/11 MAPPED

Identification and Authentication

Every user, process, and device is identified and authenticated before access — with multifactor and replay-resistant authentication for the accounts attackers actually target, and password handling that limits what a stolen credential is worth.

3.63/3 MAPPED

Incident Response

An operational capability to prepare for, detect, analyze, contain, and recover from incidents — tracked, reported to the right officials, and tested rather than merely written down.

3.72/6 MAPPED

Maintenance

System maintenance happens under control: tools and personnel are supervised, equipment leaving for service is sanitized, and nonlocal maintenance sessions authenticate strongly and end when the work does.

3.81/9 MAPPED

Media Protection

CUI on media — paper, drives, removable storage, backups — is stored, marked, transported, sanitized, and destroyed under control, with cryptography where physical safeguards are absent.

3.90/2 MAPPED

Personnel Security

People are screened before receiving access to systems containing CUI, and access is handled deliberately through terminations and transfers.

3.100/6 MAPPED

Physical Protection

Physical access to systems and facilities is limited, monitored, and logged — including visitor control, access devices, and safeguarding CUI at alternate work sites.

3.113/3 MAPPED

Risk Assessment

Risk is assessed periodically, vulnerabilities are scanned for on a cadence and on new disclosures, and remediation follows the risk — not the scanner's default severity order.

3.123/4 MAPPED

Security Assessment

Controls are assessed for effectiveness, deficiencies get plans of action, monitoring is continuous, and the system security plan describing boundaries and implementations stays current. The family where documentation and reality meet.

3.135/16 MAPPED

System and Communications Protection

Communications are monitored and protected at boundaries, networks deny by default, remote sessions are encrypted, cryptography is FIPS-validated where it protects CUI confidentiality, and CUI is protected at rest. The architectural heart of Rev. 2.

3.144/7 MAPPED

System and Information Integrity

Flaws are identified and corrected in a timely manner, malicious code is caught at designated locations, advisories are acted on, and systems are monitored for attack indicators and unauthorized use.

“Mapped” counts requirements with at least one genuine practice relationship. Families with low counts — personnel, physical, media — are not gaps in this site’s analysis: the campaign simply has no practice working that ground, and pretending otherwise would make every other mapping less trustworthy.

Requirement-level mapping

Every requirement, filterable

110 OF 110 REQUIREMENTS
RequirementFamilyMapped practices
3.1.1 Authorized access controlbasic3.1 Access ControlIT-01IT-02OT-01
3.1.2 Transaction and function controlbasic3.1 Access ControlOT-01
3.1.3 CUI flow controlderived3.1 Access ControlIT-05IT-08
3.1.4 Separation of dutiesderived3.1 Access ControlNo mapped practice
3.1.5 Least privilegederived3.1 Access ControlOT-01
3.1.6 Non-privileged account usederived3.1 Access ControlNo mapped practice
3.1.7 Privileged function controlderived3.1 Access ControlNo mapped practice
3.1.8 Unsuccessful logon attemptsderived3.1 Access ControlNo mapped practice
3.1.9 Privacy and security noticesderived3.1 Access ControlNo mapped practice
3.1.10 Session lockderived3.1 Access ControlNo mapped practice
3.1.11 Session terminationderived3.1 Access ControlNo mapped practice
3.1.12 Remote access monitoring and controlderived3.1 Access ControlIT-01OT-06
3.1.13 Remote access confidentialityderived3.1 Access ControlNo mapped practice
3.1.14 Managed access control pointsderived3.1 Access ControlOT-06
3.1.15 Privileged remote access authorizationderived3.1 Access ControlOT-06
3.1.16 Wireless access authorizationderived3.1 Access ControlNo mapped practice
3.1.17 Wireless access protectionderived3.1 Access ControlNo mapped practice
3.1.18 Mobile device connection controlderived3.1 Access ControlNo mapped practice
3.1.19 CUI encryption on mobilederived3.1 Access ControlNo mapped practice
3.1.20 External system connectionsderived3.1 Access ControlIT-08
3.1.21 Portable storage on external systemsderived3.1 Access ControlNo mapped practice
3.1.22 Publicly accessible content controlderived3.1 Access ControlNo mapped practice
3.2.1 Role-appropriate security awarenessbasic3.2 Awareness and TrainingIT-10
3.2.2 Security duty trainingbasic3.2 Awareness and TrainingIT-10
3.2.3 Insider-threat awarenessderived3.2 Awareness and TrainingNo mapped practice
3.3.1 Audit log creation and retentionbasic3.3 Audit and AccountabilityOT-07
3.3.2 Individual accountabilitybasic3.3 Audit and AccountabilityIT-02
3.3.3 Logged event reviewderived3.3 Audit and AccountabilityNo mapped practice
3.3.4 Audit failure alertingderived3.3 Audit and AccountabilityNo mapped practice
3.3.5 Audit correlationderived3.3 Audit and AccountabilityOT-07
3.3.6 Audit reduction and reportingderived3.3 Audit and AccountabilityNo mapped practice
3.3.7 Authoritative time sourcederived3.3 Audit and AccountabilityNo mapped practice
3.3.8 Audit information protectionderived3.3 Audit and AccountabilityNo mapped practice
3.3.9 Audit management restrictionderived3.3 Audit and AccountabilityNo mapped practice
3.4.1 Baseline configurations and inventoriesbasic3.4 Configuration ManagementIT-02OT-02IT-03
3.4.2 Security configuration enforcementbasic3.4 Configuration ManagementIT-04
3.4.3 Change tracking and approvalderived3.4 Configuration ManagementOT-10IT-07
3.4.4 Security impact analysisderived3.4 Configuration ManagementOT-10IT-07
3.4.5 Change access restrictionsderived3.4 Configuration ManagementOT-10
3.4.6 Least functionalityderived3.4 Configuration ManagementNo mapped practice
3.4.7 Nonessential functionality restrictionderived3.4 Configuration ManagementNo mapped practice
3.4.8 Software execution policyderived3.4 Configuration ManagementNo mapped practice
3.4.9 User-installed software controlderived3.4 Configuration ManagementNo mapped practice
3.5.1 User and device identificationbasic3.5 Identification and AuthenticationIT-02
3.5.2 Authentication before accessbasic3.5 Identification and AuthenticationIT-01
3.5.3 Multifactor authenticationderived3.5 Identification and AuthenticationIT-01
3.5.4 Replay-resistant authenticationderived3.5 Identification and AuthenticationIT-01
3.5.5 Identifier reuse preventionderived3.5 Identification and AuthenticationNo mapped practice
3.5.6 Inactive identifier handlingderived3.5 Identification and AuthenticationIT-02
3.5.7 Password complexityderived3.5 Identification and AuthenticationNo mapped practice
3.5.8 Password reuse prohibitionderived3.5 Identification and AuthenticationNo mapped practice
3.5.9 Temporary password handlingderived3.5 Identification and AuthenticationNo mapped practice
3.5.10 Cryptographic password protectionderived3.5 Identification and AuthenticationNo mapped practice
3.5.11 Authentication feedback obscuringderived3.5 Identification and AuthenticationNo mapped practice
3.6.1 Incident-handling capabilitybasic3.6 Incident ResponseOT-04IT-09
3.6.2 Incident tracking and reportingbasic3.6 Incident ResponseOT-04
3.6.3 Incident response testingderived3.6 Incident ResponseOT-04
3.7.1 System maintenancebasic3.7 MaintenanceNo mapped practice
3.7.2 Maintenance controlsbasic3.7 MaintenanceNo mapped practice
3.7.3 Off-site maintenance sanitizationderived3.7 MaintenanceNo mapped practice
3.7.4 Diagnostic media checkingderived3.7 MaintenanceNo mapped practice
3.7.5 Nonlocal maintenance authenticationderived3.7 MaintenanceOT-06IT-01
3.7.6 Maintenance personnel supervisionderived3.7 MaintenanceOT-06
3.8.1 Media protection and storagebasic3.8 Media ProtectionNo mapped practice
3.8.2 Media access limitationbasic3.8 Media ProtectionNo mapped practice
3.8.3 Media sanitizationbasic3.8 Media ProtectionNo mapped practice
3.8.4 Media markingderived3.8 Media ProtectionNo mapped practice
3.8.5 Media transport accountabilityderived3.8 Media ProtectionNo mapped practice
3.8.6 Media transport encryptionderived3.8 Media ProtectionNo mapped practice
3.8.7 Removable media controlderived3.8 Media ProtectionNo mapped practice
3.8.8 Ownerless storage prohibitionderived3.8 Media ProtectionNo mapped practice
3.8.9 Backup CUI confidentialityderived3.8 Media ProtectionIT-09OT-08
3.9.1 Personnel screeningbasic3.9 Personnel SecurityNo mapped practice
3.9.2 Personnel action safeguardsbasic3.9 Personnel SecurityNo mapped practice
3.10.1 Physical access limitationbasic3.10 Physical ProtectionNo mapped practice
3.10.2 Facility protection and monitoringbasic3.10 Physical ProtectionNo mapped practice
3.10.3 Visitor escort and monitoringderived3.10 Physical ProtectionNo mapped practice
3.10.4 Physical access logsderived3.10 Physical ProtectionNo mapped practice
3.10.5 Physical access device controlderived3.10 Physical ProtectionNo mapped practice
3.10.6 Alternate work site safeguardsderived3.10 Physical ProtectionNo mapped practice
3.11.1 Periodic risk assessmentbasic3.11 Risk AssessmentIT-06
3.11.2 Vulnerability scanningderived3.11 Risk AssessmentIT-06OT-05
3.11.3 Vulnerability remediationderived3.11 Risk AssessmentIT-06OT-05
3.12.1 Control effectiveness assessmentbasic3.12 Security AssessmentNo mapped practice
3.12.2 Plans of actionbasic3.12 Security AssessmentIT-06
3.12.3 Continuous control monitoringbasic3.12 Security AssessmentIT-02
3.12.4 System security planbasic3.12 Security AssessmentIT-02IT-05
3.13.1 Boundary communications protectionbasic3.13 System and Communications ProtectionIT-05OT-03
3.13.2 Secure engineering principlesbasic3.13 System and Communications ProtectionNo mapped practice
3.13.3 User / management functionality separationderived3.13 System and Communications ProtectionNo mapped practice
3.13.4 Shared resource information controlderived3.13 System and Communications ProtectionNo mapped practice
3.13.5 Public-access subnetworksderived3.13 System and Communications ProtectionIT-05OT-03
3.13.6 Deny-by-default network trafficderived3.13 System and Communications ProtectionOT-03IT-05
3.13.7 Split tunneling preventionderived3.13 System and Communications ProtectionNo mapped practice
3.13.8 Transmission confidentialityderived3.13 System and Communications ProtectionNo mapped practice
3.13.9 Network connection terminationderived3.13 System and Communications ProtectionNo mapped practice
3.13.10 Cryptographic key managementderived3.13 System and Communications ProtectionNo mapped practice
3.13.11 FIPS-validated cryptographyderived3.13 System and Communications ProtectionNo mapped practice
3.13.12 Collaborative device controlderived3.13 System and Communications ProtectionNo mapped practice
3.13.13 Mobile code controlderived3.13 System and Communications ProtectionNo mapped practice
3.13.14 VoIP controlderived3.13 System and Communications ProtectionNo mapped practice
3.13.15 Session authenticityderived3.13 System and Communications ProtectionIT-01
3.13.16 CUI at restderived3.13 System and Communications ProtectionIT-08
3.14.1 Flaw identification and remediationbasic3.14 System and Information IntegrityIT-06IT-03OT-05
3.14.2 Malicious code protectionbasic3.14 System and Information IntegrityNo mapped practice
3.14.3 Security alert monitoringbasic3.14 System and Information IntegrityIT-06
3.14.4 Malicious code protection updatesderived3.14 System and Information IntegrityNo mapped practice
3.14.5 Periodic and real-time scanningderived3.14 System and Information IntegrityNo mapped practice
3.14.6 Attack monitoringderived3.14 System and Information IntegrityOT-07IT-02
3.14.7 Unauthorized use identificationderived3.14 System and Information IntegrityOT-07

Filtering happens in this browser — nothing you type is sent anywhere. A requirement without a mapped practice is a deliberate editorial decision, not an omission: the campaign’s twenty practices do not cover every requirement, and this site does not manufacture coverage.

Relationship summary

How the 64 mappings distribute

Relationship typeMappingsMeaning
Direct implementation support10The practice's core activity works on the substance of the requirement. Implementing the practice well advances this requirement directly — it still does not, by itself, satisfy it.
Partial implementation support36The practice advances part of the requirement's scope; other parts are untouched by it and need separate work.
Operational support7The practice keeps the capability the requirement depends on running day to day, rather than establishing it.
Evidence support2The practice's normal operation produces records relevant to demonstrating this requirement; it does not implement the requirement itself.
Dependency3The practice is a prerequisite that makes implementing the requirement realistic — absent it, work on the requirement is built on sand.
Contextual relationship6The practice informs or constrains how an organization approaches the requirement without acting on its substance.