Direct implementation supportHigh confidence
Why: Protecting the confidentiality of backup CUI at storage locations is this requirement, and the practice's architecture — encrypted backup sets, backup administration separated from production credentials, restricted read and export access — is how that protection is built in practice.
What this does not claim: The requirement's text is confidentiality at storage locations, not recovery: the availability, immutability, and tested-restore work that motivates the practice serves resilience, and only its encryption and access-limitation elements bear on this requirement. Every storage location counts — cloud and offsite copies included — and each needs the same protection and its own evidence.
Practice-side activities- Encrypt backup sets with keys managed separately from backup-administration credentials
- Separate backup administration from production administration and enforce MFA on it
- Restrict who can read, export, or restore backup data, and review that list
Evidence this produces- Backup encryption configuration per storage location
- Access lists for the backup platform and storage targets
- Key management records held apart from backup administration
Review status: Technical review complete · Reviewed by inDirectIT practitioner review — CUI security and NIST SP 800-171 engineering · updated 2026-08-06
Partial implementation supportLow confidence
Why: The practice's off-device stores of controller logic, configuration, and set points are backup media, and where historian data, engineering workstation images, or project files in those stores contain CUI, protecting the copies advances this requirement.
What this does not claim: Directional only: most controller backups contain no CUI, so this mapping rarely applies. The practice's aim is availability — recovering production fast — and confidentiality protection of the backup store is not its default posture; where CUI is present, encryption and access limitation must be added deliberately, and adding them must not leave the plant unable to reach its own recovery files during an outage.
Practice-side activities- Determine whether any OT backup content — historians, engineering workstations, project files — actually holds CUI
- Where it does, encrypt those stores and restrict access, keeping a recovery path operations can exercise under failure conditions
Evidence this produces- The documented determination of CUI presence in OT backup content
- Encryption and access configuration for the stores where CUI was found
Where this holds: Applies only where OT backup content genuinely contains CUI; for the typical controller logic and configuration store it does not, and the mapping lapses.
Review status: Technical review complete · Reviewed by inDirectIT practitioner review — CUI security and NIST SP 800-171 engineering · updated 2026-08-06