Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
03.14.06OFFICIAL TITLEPENDING NIST SME REVIEW

03.14.06System Monitoring

03.14 System and Information Integrity · NIST SP 800-171 Rev. 3

Independent summary of the official requirement

Monitor the system — including inbound and outbound communications traffic — to detect attacks, indicators of potential attacks, and unauthorized connections, and identify unauthorized use of the system.

Rev. 3 requirement text is multi-part and parameterized with organization-defined values, so this site summarizes rather than reproduces it. The summary is independent — read the official publication for the binding wording.

NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

Watch the system well enough to notice an attack in progress and use that nobody authorized. Rev. 2 split the watching (attacks) from the noticing (unauthorized use); Rev. 3 treats them as one monitoring capability spanning network traffic, endpoints, and user behavior — and outbound traffic is named because command-and-control beacons and data theft are outbound phenomena.

Across revisions

Absorbs Rev. 2's 3.14.7 (identify unauthorized use) into the consolidated System Monitoring requirement alongside 3.14.6's attack detection.

Mapped practices

Brilliant at the Basics practices that support this requirement

Partial implementation supportModerate confidence

Why: Continuous OT monitoring watches control-network traffic and device behavior for the abnormal — the attack-indicator and unauthorized-use detection this requirement names, applied to the slice of the system that lives on the plant floor.

What this does not claim: May partially address the requirement for OT assets inside the assessed boundary; enterprise endpoints, identities, and cloud services — most of the requirement's scope — sit outside this practice entirely. Where OT itself sits outside the CUI system boundary, as much of it does, the relationship is informative rather than load-bearing.

Practice-side activities
  • Deploy passive monitoring on control networks to baseline traffic and alert on deviation
  • Route OT alerts to responders who understand process context, not a generic queue
Evidence this produces
  • OT monitoring coverage measured against the validated asset inventory
  • Alert and disposition records from control-network sensors

Where this holds: Holds where OT assets are within the assessed CUI boundary; weakens to background context everywhere else.

Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Give outbound traffic the attention inbound gets; egress monitoring is where compromise that slipped past prevention becomes visible.
  • Decide what 'unauthorized use' looks like before hunting it — sign-ins outside role, data access outside pattern, software nobody approved — because detection needs a definition to detect against.
  • Monitoring produces alerts, and the requirement's value depends on someone triaging them; staff the response before expanding the collection.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • The monitoring architecture: what is collected from network, endpoint, and identity layers, and where it flows
  • Alert and triage records for a sampled period, including dispositions
  • Detection content mapped to the attack indicators and unauthorized-use cases it covers

Suggested owners, derived from the mapped practices and artifacts: OT engineer · IT leader. Ownership is a named person in your organization, not a role on a website.

Artifacts

Templates and worksheets with a mapped relationship

The other revision

Where this came from in Rev. 2

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated