Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
OFFICIAL IDENTIFIERS & TITLESPENDING NIST SME REVIEW

NIST SP 800-171 Rev. 3 mapping — all 97 requirements

Every active Rev. 3 requirement with its official title, a labeled independent summary, and the practices that genuinely support it — including the three families that are new in this revision.

17 families

The families at a glance

03.017/16 MAPPED

Access Control

Account management, access enforcement, least privilege, remote and wireless access, mobile devices, external systems, and public content. Rev. 3 consolidates six Rev. 2 remote-access and device requirements into broader parents.

03.022/2 MAPPED

Awareness and Training

Security literacy for everyone and role-based training for people with security-relevant duties. Insider-threat awareness is folded into literacy training rather than standing alone.

03.031/8 MAPPED

Audit and Accountability

Which events are logged, what each record contains, how logs are generated, reviewed, protected, and time-stamped — with record content and generation now explicit requirements rather than implications.

03.048/10 MAPPED

Configuration Management

Baselines, settings, change control, impact analysis, least functionality, authorized-software-by-exception, and — new as standalone requirements — component inventory, information location, and configuration for high-risk travel.

03.055/8 MAPPED

Identification and Authentication

Identifying and authenticating users and devices, multi-factor and replay-resistant authentication, and consolidated identifier, password, and authenticator management aligned to current federal guidance.

03.064/5 MAPPED

Incident Response

Incident handling, monitoring, reporting, testing — and, new as standalone requirements in Rev. 3, incident response training and a written incident response plan.

03.071/3 MAPPED

Maintenance

Controlled maintenance tools, authenticated and terminated nonlocal maintenance sessions, and supervised maintenance personnel. Routine perform-maintenance expectations from Rev. 2 were recategorized rather than carried forward.

03.081/7 MAPPED

Media Protection

Storage, access, sanitization, marking, and transport of media holding CUI, plus removable-media use and cryptographic protection of backups. Transport encryption folds into the transport requirement.

03.090/2 MAPPED

Personnel Security

Screening before access, and deliberate handling of system access through terminations and transfers.

03.100/5 MAPPED

Physical Protection

Physical access authorization, monitoring, and control — with visitor handling, access logs, and access devices consolidated into a single physical access control requirement, plus alternate work sites and transmission-line access.

03.113/3 MAPPED

Risk Assessment

Assessing risk, monitoring and scanning for vulnerabilities, and — new as a standalone requirement — responding to findings from assessments and monitoring.

03.121/4 MAPPED

Security Assessment and Monitoring

Assessing control effectiveness, maintaining plans of action and milestones, continuous monitoring, and — new — information-exchange agreements. The system security plan moved to the new Planning family.

03.133/10 MAPPED

System and Communications Protection

Boundary protection, deny-by-default networking, cryptographic protection, session and key management. Rev. 3 merges transmission and at-rest confidentiality into one requirement and retires several technology-specific items.

03.143/5 MAPPED

System and Information Integrity

Flaw remediation, malicious code protection, advisories, and system monitoring — consolidated from seven Rev. 2 requirements — plus new information management and retention.

03.151/3 MAPPED

Planning

New family in Rev. 3: security policies and procedures, the system security plan, and rules of behavior. Governance documentation that Rev. 2 scattered or left implicit is now explicit.

03.163/3 MAPPED

System and Services Acquisition

New family in Rev. 3: security engineering principles, unsupported system components, and external system services. This is where technical-debt and third-party-service discipline get explicit requirement language.

03.173/3 MAPPED

Supply Chain Risk Management

New family in Rev. 3: a supply chain risk management plan, acquisition strategies and methods, and supply chain requirements and processes for the components and services the system depends on.

“Mapped” counts requirements with at least one genuine practice relationship. Families with low counts — personnel, physical, media — are not gaps in this site’s analysis: the campaign simply has no practice working that ground, and pretending otherwise would make every other mapping less trustworthy.

Requirement-level mapping

Every requirement, filterable

97 OF 97 REQUIREMENTS
RequirementFamilyMapped practices
03.01.01 Account Management03.01 Access ControlIT-02OT-01
03.01.02 Access Enforcement03.01 Access ControlOT-01
03.01.03 Information Flow Enforcement03.01 Access ControlIT-05
03.01.04 Separation of Duties03.01 Access ControlNo mapped practice
03.01.05 Least Privilege03.01 Access ControlOT-01
03.01.06 Least Privilege — Privileged Accounts03.01 Access ControlOT-01
03.01.07 Least Privilege — Privileged Functions03.01 Access ControlNo mapped practice
03.01.08 Unsuccessful Logon Attempts03.01 Access ControlNo mapped practice
03.01.09 System Use Notification03.01 Access ControlNo mapped practice
03.01.10 Device Lock03.01 Access ControlNo mapped practice
03.01.11 Session Termination03.01 Access ControlNo mapped practice
03.01.12 Remote Access03.01 Access ControlIT-01OT-06
03.01.16 Wireless Access03.01 Access ControlNo mapped practice
03.01.18 Access Control for Mobile Devices03.01 Access ControlNo mapped practice
03.01.20 Use of External Systems03.01 Access ControlIT-08
03.01.22 Publicly Accessible Content03.01 Access ControlNo mapped practice
03.02.01 Literacy Training and Awareness03.02 Awareness and TrainingIT-10
03.02.02 Role-Based Training03.02 Awareness and TrainingIT-10
03.03.01 Event Logging03.03 Audit and AccountabilityNo mapped practice
03.03.02 Audit Record Content03.03 Audit and AccountabilityNo mapped practice
03.03.03 Audit Record Generation03.03 Audit and AccountabilityNo mapped practice
03.03.04 Response to Audit Logging Process Failures03.03 Audit and AccountabilityNo mapped practice
03.03.05 Audit Record Review, Analysis, and Reporting03.03 Audit and AccountabilityOT-07
03.03.06 Audit Record Reduction and Report Generation03.03 Audit and AccountabilityNo mapped practice
03.03.07 Time Stamps03.03 Audit and AccountabilityNo mapped practice
03.03.08 Protection of Audit Information03.03 Audit and AccountabilityNo mapped practice
03.04.01 Baseline Configuration03.04 Configuration ManagementIT-02
03.04.02 Configuration Settings03.04 Configuration ManagementIT-04
03.04.03 Configuration Change Control03.04 Configuration ManagementOT-10
03.04.04 Impact Analyses03.04 Configuration ManagementOT-10
03.04.05 Access Restrictions for Change03.04 Configuration ManagementOT-10
03.04.06 Least Functionality03.04 Configuration ManagementIT-03
03.04.08 Authorized Software — Allow by Exception03.04 Configuration ManagementNo mapped practice
03.04.10 System Component Inventory03.04 Configuration ManagementIT-02OT-02
03.04.11 Information Location03.04 Configuration ManagementIT-08
03.04.12 System and Component Configuration for High-Risk Areas03.04 Configuration ManagementNo mapped practice
03.05.01 User Identification, Authentication, and Re-Authentication03.05 Identification and AuthenticationIT-01
03.05.02 Device Identification and Authentication03.05 Identification and AuthenticationNo mapped practice
03.05.03 Multi-Factor Authentication03.05 Identification and AuthenticationIT-01
03.05.04 Replay-Resistant Authentication03.05 Identification and AuthenticationIT-01
03.05.05 Identifier Management03.05 Identification and AuthenticationIT-02
03.05.07 Password Management03.05 Identification and AuthenticationNo mapped practice
03.05.11 Authentication Feedback03.05 Identification and AuthenticationNo mapped practice
03.05.12 Authenticator Management03.05 Identification and AuthenticationIT-01
03.06.01 Incident Handling03.06 Incident ResponseOT-04IT-09
03.06.02 Incident Monitoring, Reporting, and Response Assistance03.06 Incident ResponseOT-04
03.06.03 Incident Response Testing03.06 Incident ResponseOT-04
03.06.04 Incident Response Training03.06 Incident ResponseNo mapped practice
03.06.05 Incident Response Plan03.06 Incident ResponseOT-04
03.07.04 Maintenance Tools03.07 MaintenanceNo mapped practice
03.07.05 Nonlocal Maintenance03.07 MaintenanceOT-06IT-01
03.07.06 Maintenance Personnel03.07 MaintenanceNo mapped practice
03.08.01 Media Storage03.08 Media ProtectionNo mapped practice
03.08.02 Media Access03.08 Media ProtectionNo mapped practice
03.08.03 Media Sanitization03.08 Media ProtectionNo mapped practice
03.08.04 Media Marking03.08 Media ProtectionNo mapped practice
03.08.05 Media Transport03.08 Media ProtectionNo mapped practice
03.08.07 Media Use03.08 Media ProtectionNo mapped practice
03.08.09 System Backup — Cryptographic Protection03.08 Media ProtectionIT-09OT-08
03.09.01 Personnel Screening03.09 Personnel SecurityNo mapped practice
03.09.02 Personnel Termination and Transfer03.09 Personnel SecurityNo mapped practice
03.10.01 Physical Access Authorizations03.10 Physical ProtectionNo mapped practice
03.10.02 Monitoring Physical Access03.10 Physical ProtectionNo mapped practice
03.10.06 Alternate Work Site03.10 Physical ProtectionNo mapped practice
03.10.07 Physical Access Control03.10 Physical ProtectionNo mapped practice
03.10.08 Access Control for Transmission03.10 Physical ProtectionNo mapped practice
03.11.01 Risk Assessment03.11 Risk AssessmentIT-06
03.11.02 Vulnerability Monitoring and Scanning03.11 Risk AssessmentIT-06OT-05
03.11.04 Risk Response03.11 Risk AssessmentIT-06
03.12.01 Security Assessment03.12 Security Assessment and MonitoringNo mapped practice
03.12.02 Plan of Action and Milestones03.12 Security Assessment and MonitoringIT-06
03.12.03 Continuous Monitoring03.12 Security Assessment and MonitoringNo mapped practice
03.12.05 Information Exchange03.12 Security Assessment and MonitoringNo mapped practice
03.13.01 Boundary Protection03.13 System and Communications ProtectionIT-05OT-03
03.13.04 Information in Shared System Resources03.13 System and Communications ProtectionNo mapped practice
03.13.06 Network Communications — Deny by Default, Allow by Exception03.13 System and Communications ProtectionIT-05OT-03
03.13.08 Transmission and Storage Confidentiality03.13 System and Communications ProtectionIT-08
03.13.09 Network Disconnect03.13 System and Communications ProtectionNo mapped practice
03.13.10 Cryptographic Key Establishment and Management03.13 System and Communications ProtectionNo mapped practice
03.13.11 Cryptographic Protection03.13 System and Communications ProtectionNo mapped practice
03.13.12 Collaborative Computing Devices and Applications03.13 System and Communications ProtectionNo mapped practice
03.13.13 Mobile Code03.13 System and Communications ProtectionNo mapped practice
03.13.15 Session Authenticity03.13 System and Communications ProtectionNo mapped practice
03.14.01 Flaw Remediation03.14 System and Information IntegrityIT-06OT-05
03.14.02 Malicious Code Protection03.14 System and Information IntegrityNo mapped practice
03.14.03 Security Alerts, Advisories, and Directives03.14 System and Information IntegrityNo mapped practice
03.14.06 System Monitoring03.14 System and Information IntegrityOT-07
03.14.08 Information Management and Retention03.14 System and Information IntegrityIT-08
03.15.01 Policy and Procedures03.15 PlanningNo mapped practice
03.15.02 System Security Plan03.15 PlanningIT-02
03.15.03 Rules of Behavior03.15 PlanningNo mapped practice
03.16.01 Security Engineering Principles03.16 System and Services AcquisitionIT-07IT-04
03.16.02 Unsupported System Components03.16 System and Services AcquisitionIT-03
03.16.03 External System Services03.16 System and Services AcquisitionIT-04
03.17.01 Supply Chain Risk Management Plan03.17 Supply Chain Risk ManagementOT-09
03.17.02 Acquisition Strategies, Tools, and Methods03.17 Supply Chain Risk ManagementOT-09
03.17.03 Supply Chain Requirements and Processes03.17 Supply Chain Risk ManagementOT-09

Filtering happens in this browser — nothing you type is sent anywhere. A requirement without a mapped practice is a deliberate editorial decision, not an omission: the campaign’s twenty practices do not cover every requirement, and this site does not manufacture coverage.

Relationship summary

How the 57 mappings distribute

Relationship typeMappingsMeaning
Direct implementation support15The practice's core activity works on the substance of the requirement. Implementing the practice well advances this requirement directly — it still does not, by itself, satisfy it.
Partial implementation support29The practice advances part of the requirement's scope; other parts are untouched by it and need separate work.
Operational support2The practice keeps the capability the requirement depends on running day to day, rather than establishing it.
Governance support1The practice contributes ownership, review cadence, or decision records that the requirement's implementation relies on.
Evidence support2The practice's normal operation produces records relevant to demonstrating this requirement; it does not implement the requirement itself.
Dependency1The practice is a prerequisite that makes implementing the requirement realistic — absent it, work on the requirement is built on sand.
Contextual relationship7The practice informs or constrains how an organization approaches the requirement without acting on its substance.