Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
03.08.09OFFICIAL TITLEPENDING NIST SME REVIEW

03.08.09System Backup — Cryptographic Protection

03.08 Media Protection · NIST SP 800-171 Rev. 3

Independent summary of the official requirement

Requires protecting the confidentiality of backup information at storage locations and implementing cryptographic mechanisms to prevent unauthorized disclosure of CUI at backup storage locations.

Rev. 3 requirement text is multi-part and parameterized with organization-defined values, so this site summarizes rather than reproduces it. The summary is independent — read the official publication for the binding wording.

NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

Backups are a complete copy of the data attackers want, usually watched less closely than production. Wherever backup copies rest — appliance, tape, cloud bucket — the CUI in them is encrypted and access to the store is restricted, so stealing the backup is not the easy route to the data.

Across revisions

Carried from Rev. 2's 3.8.9 with cryptographic protection now explicit in the requirement and its title, rather than one acceptable method of protecting confidentiality.

Mapped practices

Brilliant at the Basics practices that support this requirement

Direct implementation supportHigh confidence

Why: Protecting the confidentiality of backup information — with cryptographic mechanisms against unauthorized disclosure of CUI at backup storage locations — is what a resilient backup architecture configures as a matter of course: encrypted repositories, restricted access, separated administration.

What this does not claim: The requirement is specifically about confidentiality at backup storage locations; availability, immutability, and tested recovery are the practice's campaign intent, not this requirement's text. Encryption must also be verifiably configured with sound key handling at every storage location — cloud targets and legacy tape included — for the relationship to hold under assessment.

Practice-side activities
  • Enable encryption on every backup repository and record where the keys are held
  • Restrict backup-store access to a separated backup-administration role
  • Verify cloud backup targets' encryption and access policy rather than assuming provider defaults
Evidence this produces
  • Backup platform encryption configuration exports
  • Key-handling records
  • Access policy for backup storage locations

Review status: Technical review complete · Reviewed by inDirectIT practitioner review — CUI security and NIST SP 800-171 engineering · updated 2026-08-06

Partial implementation supportModerate confidence

Why: System resiliency for OT leans on maintained configuration and system backups for critical production assets, and those backup stores fall inside this requirement's scope the moment they contain CUI — protecting them is part of the practice's recovery posture.

What this does not claim: The practice's center of gravity is availability — keeping production running and restoring it fast — while this requirement is about the confidentiality of what the backups contain. Encrypting OT configuration backups and restricting access to the repository are additional steps the resiliency work does not automatically include, and older OT backup tooling may not support encryption at all, forcing compensating protection of the storage location itself.

Practice-side activities
  • Store OT configuration and system backups in an access-restricted repository rather than on engineering workstations
  • Encrypt OT backup stores where tooling allows; physically and logically restrict the store where it does not
Evidence this produces
  • The OT backup repository's access policy
  • Encryption settings or documented compensating physical protection

Where this holds: Applies where OT backups contain CUI — controlled technical data in PLC programs, drawings, or process recipes; weakens where OT backups hold none.

Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Turn on backup encryption in the platform and record where the keys live — keys stored alongside the backups defeat the point.
  • Treat cloud backup targets as storage locations under this requirement: bucket access policy, encryption settings, and provider responsibilities all in scope.
  • Separate backup administration from production administration so a compromised production admin cannot read or export the backup store.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • Backup platform encryption configuration and key-handling records
  • Access policy for backup storage locations

Suggested owners, derived from the mapped practices and artifacts: IT leader · Plant / OT leader. Ownership is a named person in your organization, not a role on a website.

Artifacts

Templates and worksheets with a mapped relationship

The other revision

Where this came from in Rev. 2

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated