Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
03.14.08OFFICIAL TITLEPENDING NIST SME REVIEW

03.14.08Information Management and Retention

03.14 System and Information Integrity · NIST SP 800-171 Rev. 3

Independent summary of the official requirement

Manage and retain CUI within the system, and CUI output from the system, in accordance with applicable laws, executive orders, directives, regulations, policies, standards, operational requirements, and retention schedules.

Rev. 3 requirement text is multi-part and parameterized with organization-defined values, so this site summarizes rather than reproduces it. The summary is independent — read the official publication for the binding wording.

NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

CUI does not get to live everywhere forever. This requirement makes its lifecycle deliberate — where it is held, how long it is kept, when it is disposed of — governed by the records rules that already applied but that nobody previously had to demonstrate inside the system boundary. Keeping CUI you no longer need is not caution; it is accumulated exposure with no mission value.

Across revisions

New in Rev. 3 with no Rev. 2 counterpart — the first 800-171 requirement to govern the CUI lifecycle and its retention rather than only its protection in place.

Mapped practices

Brilliant at the Basics practices that support this requirement

Contextual relationshipModerate confidence

Why: Secure AI adoption forces the questions this requirement institutionalizes — what data an AI tool retains, for how long, and under whose terms — so the practice's data-protection decisions inform CUI retention management for one fast-growing class of services.

What this does not claim: The practice informs the requirement without acting on its substance: information management and retention spans every repository holding CUI, driven by records schedules and legal authorities, and the practice touches only the AI-tool slice of that landscape. Retention terms negotiated for AI services are a contribution to the requirement's implementation, not an implementation of it.

Practice-side activities
  • Record retention and training-use terms for each approved AI tool before any CUI-adjacent use
  • Prohibit CUI in tools whose retention terms cannot be verified
Evidence this produces
  • The approved AI tool register with data-retention terms per tool
  • Configuration showing retention limits or training-data opt-outs applied

Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Start from where CUI actually is — the information-location work under 03.04.11 — because retention rules cannot be applied to data nobody has found.
  • Translate the applicable records schedules and contract clauses into concrete retention periods per repository, then automate disposition where the platform allows it (retention labels, lifecycle policies).
  • Remember output: exports, reports, backups, and shadow copies carry CUI out of governed repositories and into ungoverned ones, and the requirement follows the data.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • Retention rules per repository, each traced to the schedule, clause, or regulation that drives it
  • Platform lifecycle or retention-policy configuration where automated
  • Dated disposition records showing that retention actually ends

Suggested owners, derived from the mapped practices and artifacts: Engineering lead. Ownership is a named person in your organization, not a role on a website.

Artifacts

Templates and worksheets with a mapped relationship

No artifact in the library names this requirement yet. The library index groups everything by category and practice.

The other revision

Where this came from in Rev. 2

No direct Rev. 2 counterpart — this requirement is new in Rev. 3. Open the transition crosswalk →

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated