MarketplaceCybersecurityNIST SP 800-172
CybersecurityGuideline

NIST SP 800-172

Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171

NIST SP 800-172 elaborates enhanced security requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems and organizations. It aims to mitigate risks posed by Advanced Persistent Threats (APT) through a defense-in-depth approach, building on the foundational requirements in NIST SP 800-171.

Overview

This document serves as a supplement to NIST SP 800-171, providing federal agencies with a model to establish enhanced security measures specifically aimed at protecting the confidentiality, integrity, and availability of Controlled Unclassified Information (CUI) in critical programs and high-value assets within nonfederal systems. Its requirements are tailored to address sophisticated Advanced Persistent Threats (APT), which employ cyber and physical attack vectors to breach defenses. The publication incorporates penetration-resistant architecture, damage-limiting operations, and cyber resiliency strategies to safeguard federal missions effectively. Key updates include revised scoping guidance, requirements flexibility, customization options, and threat modeling for defensive measures. The enhanced security measures must be implemented in addition to SP 800-171 requirements when specific safeguarding mandates are absent.

Related in Cybersecurity

CybersecurityRegulation

Dubai ISR — Dubai Government Information Security Regulation

The Dubai Government Information Security Regulation (ISR) provides standards to ensure the continuity of critical business processes and minimize information security risks for Dubai Government Entities. It defines minimum requirements for information security controls and aims to maintain confidentiality, integrity, and availability of government information.

Dubai Government • Dubai • v3

View details
CybersecurityFramework

DSPF — Defence Security Principles Framework

The Defence Security Principles Framework (DSPF) is the Australian Department of Defence's principles-based security framework that provides governance, security principles, and controls to help Defence personnel manage risks and protect Defence people, information, assets, and operations in alignment with the PSPF.

Australian Government • Australian • v2 July 2018

View details
CybersecurityStandard

FedRAMP Controls — FedRAMP Security Controls Baseline rev 5

The FedRAMP Security Controls Baseline is a standardized set of cloud security requirements based on NIST SP 800-53 that defines the minimum security controls cloud service providers must implement to protect federal data and achieve FedRAMP authorization.

US Government • USA • vrev 5

View details
CybersecurityFramework

CPG 1.0 — Cross-Sector Cybersecurity Performance Goals

The Cross-Sector Cybersecurity Performance Goals (CPGs) are a set of baseline cybersecurity practices developed by CISA to help organizations of all sizes and sectors strengthen their resilience against common cyber threats. They provide prioritized, actionable measures that align with the NIST Cybersecurity Framework and are designed to be achievable, cost-effective, and impactful.

Cybersecurity and Infrastructure Security Agency (CISA) • United States • v1.0.1

View details

Ready to manage these frameworks?

6clicks maps regulations to controls, evidence and risks — automatically.

Book your strategy call