Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
3.8.9OFFICIAL STATEMENT BELOWDERIVED REQUIREMENTPENDING NIST SME REVIEW

3.8.9Backup CUI confidentiality

3.8 Media Protection · NIST SP 800-171 Rev. 2 · The heading label is this site's navigational shorthand; the official language is the statement below.

Official requirement statement (verbatim)

Protect the confidentiality of backup CUI at storage locations.

NIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

Backups are a complete copy of your CUI held somewhere less watched than production. This requirement is about confidentiality at the storage location — encryption and access limitation for the backup copies themselves — not about whether restores work.

Mapped practices

Brilliant at the Basics practices that support this requirement

Direct implementation supportHigh confidence

Why: Protecting the confidentiality of backup CUI at storage locations is this requirement, and the practice's architecture — encrypted backup sets, backup administration separated from production credentials, restricted read and export access — is how that protection is built in practice.

What this does not claim: The requirement's text is confidentiality at storage locations, not recovery: the availability, immutability, and tested-restore work that motivates the practice serves resilience, and only its encryption and access-limitation elements bear on this requirement. Every storage location counts — cloud and offsite copies included — and each needs the same protection and its own evidence.

Practice-side activities
  • Encrypt backup sets with keys managed separately from backup-administration credentials
  • Separate backup administration from production administration and enforce MFA on it
  • Restrict who can read, export, or restore backup data, and review that list
Evidence this produces
  • Backup encryption configuration per storage location
  • Access lists for the backup platform and storage targets
  • Key management records held apart from backup administration

Review status: Technical review complete · Reviewed by inDirectIT practitioner review — CUI security and NIST SP 800-171 engineering · updated 2026-08-06

Partial implementation supportLow confidence

Why: The practice's off-device stores of controller logic, configuration, and set points are backup media, and where historian data, engineering workstation images, or project files in those stores contain CUI, protecting the copies advances this requirement.

What this does not claim: Directional only: most controller backups contain no CUI, so this mapping rarely applies. The practice's aim is availability — recovering production fast — and confidentiality protection of the backup store is not its default posture; where CUI is present, encryption and access limitation must be added deliberately, and adding them must not leave the plant unable to reach its own recovery files during an outage.

Practice-side activities
  • Determine whether any OT backup content — historians, engineering workstations, project files — actually holds CUI
  • Where it does, encrypt those stores and restrict access, keeping a recovery path operations can exercise under failure conditions
Evidence this produces
  • The documented determination of CUI presence in OT backup content
  • Encryption and access configuration for the stores where CUI was found

Where this holds: Applies only where OT backup content genuinely contains CUI; for the typical controller logic and configuration store it does not, and the mapping lapses.

Review status: Technical review complete · Reviewed by inDirectIT practitioner review — CUI security and NIST SP 800-171 engineering · updated 2026-08-06

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Encrypt backup sets with keys managed separately from backup-administration credentials, so a compromised backup operator account does not read everything ever backed up.
  • Limit who can read or export backup data — the backup platform is a bulk-access path to CUI and deserves the same access discipline as the systems it copies.
  • Availability, immutability, and tested restores are resilience work worth doing anyway — but they answer a different question than this requirement's text; keep the confidentiality evidence distinct.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • Backup encryption configuration per storage location, cloud and offsite copies included
  • Access lists for the backup platform and its storage locations
  • Key management records separate from backup administration

Suggested owners, derived from the mapped practices and artifacts: IT leader · Plant / OT leader. Ownership is a named person in your organization, not a role on a website.

Artifacts

Templates and worksheets with a mapped relationship

The other revision

Where this lands in Rev. 3

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated