Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
03.01.22OFFICIAL TITLEPENDING NIST SME REVIEW

03.01.22Publicly Accessible Content

03.01 Access Control · NIST SP 800-171 Rev. 3

Independent summary of the official requirement

Requires training authorized individuals to ensure that publicly accessible information does not contain CUI, and reviewing the content on publicly accessible systems for CUI on an organization-defined frequency, removing it if discovered (aligned to SP 800-53 AC-22).

Rev. 3 requirement text is multi-part and parameterized with organization-defined values, so this site summarizes rather than reproduces it. The summary is independent — read the official publication for the binding wording.

NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

Whoever can publish to your website, social channels, or public repositories is trained not to post CUI, and someone re-reads what is public on a schedule. Small contractors trip on the incidental leaks: a case-study photo with a controlled drawing in frame, a job posting describing a controlled program, an engineer's public GitHub.

Mapped practices

Brilliant at the Basics practices that support this requirement

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Keep the publisher list short, and train exactly those people on what CUI looks like in marketing, hiring, and code.
  • Add a pre-publication check for content that touches customer programs.
  • Sweep the public surfaces on the defined cadence — website, social accounts, code repositories — and record the sweep even when it finds nothing.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • Training records for the personnel authorized to publish
  • Dated public-content review records with any removals
Artifacts

Templates and worksheets with a mapped relationship

No artifact in the library names this requirement yet. The library index groups everything by category and practice.

The other revision

Where this came from in Rev. 2

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated