- Put a scanning station or kiosk at the point where vendor media enters — common in OT environments — and make it the path of least resistance, or technicians will route around it.
- Prefer software fetched from the vendor's verified distribution point with checksum verification over media that traveled in someone's pocket.
3.7.4 — Diagnostic media checking
3.7 Maintenance · NIST SP 800-171 Rev. 2 · The heading label is this site's navigational shorthand; the official language is the statement below.
Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.
NIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal Systems ↗NIST SP 800-171A — Assessing Security Requirements for CUI ↗What this requirement is after
The vendor's USB stick with the firmware updater is untrusted media until it is checked. Diagnostic and test software arrives from outside the boundary and runs with high privilege — exactly the profile a supply-chain compromise wants.
Rev. 3 folds diagnostic-media checking into the consolidated Maintenance Tools requirement (03.07.04), alongside the tool oversight of 3.7.2 and the sanitization expectation of 3.7.3.
Brilliant at the Basics practices that support this requirement
The campaign’s twenty practices are a priority list, not a control catalog, and none of them works this requirement’s substance directly. It still applies to you if it is in your contract’s scope: address it through your own implementation and the related artifacts below, and treat the absence of a mapping here as honesty, not permission to skip it.
Implementation considerations and evidence
- Scan records or kiosk logs for media brought in for maintenance
- The written checking procedure technicians actually follow
Templates and worksheets with a mapped relationship
No artifact in the library names this requirement yet. The library index groups everything by category and practice.
Where this lands in Rev. 3
Sources and review status
| Primary sources | NIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A — Assessing Security Requirements for CUI |
|---|---|
| Review status | Pending NIST SME review |
| Content version | 1.0 |
| Updated |