- Keep the publisher list short, and train exactly those people on what CUI looks like in marketing, hiring, and code.
- Add a pre-publication check for content that touches customer programs.
- Sweep the public surfaces on the defined cadence — website, social accounts, code repositories — and record the sweep even when it finds nothing.
03.01.22 — Publicly Accessible Content
03.01 Access Control · NIST SP 800-171 Rev. 3
Requires training authorized individuals to ensure that publicly accessible information does not contain CUI, and reviewing the content on publicly accessible systems for CUI on an organization-defined frequency, removing it if discovered (aligned to SP 800-53 AC-22).
Rev. 3 requirement text is multi-part and parameterized with organization-defined values, so this site summarizes rather than reproduces it. The summary is independent — read the official publication for the binding wording.
NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems ↗NIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI ↗What this requirement is after
Whoever can publish to your website, social channels, or public repositories is trained not to post CUI, and someone re-reads what is public on a schedule. Small contractors trip on the incidental leaks: a case-study photo with a controlled drawing in frame, a job posting describing a controlled program, an engineer's public GitHub.
Brilliant at the Basics practices that support this requirement
The campaign’s twenty practices are a priority list, not a control catalog, and none of them works this requirement’s substance directly. It still applies to you if it is in your contract’s scope: address it through your own implementation and the related artifacts below, and treat the absence of a mapping here as honesty, not permission to skip it.
Implementation considerations and evidence
- Training records for the personnel authorized to publish
- Dated public-content review records with any removals
Templates and worksheets with a mapped relationship
No artifact in the library names this requirement yet. The library index groups everything by category and practice.
Where this came from in Rev. 2
Sources and review status
| Primary sources | NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI |
|---|---|
| Review status | Pending NIST SME review |
| Content version | 1.0 |
| Updated |