Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
03.04.11OFFICIAL TITLEPENDING NIST SME REVIEW

03.04.11Information Location

03.04 Configuration Management · NIST SP 800-171 Rev. 3

Independent summary of the official requirement

Requires identifying and documenting the location of CUI and the system components on which the information is processed and stored, and documenting changes to those locations.

Rev. 3 requirement text is multi-part and parameterized with organization-defined values, so this site summarizes rather than reproduces it. The summary is independent — read the official publication for the binding wording.

NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

You cannot scope what you cannot locate. This requirement wants a documented answer to 'where is CUI processed and stored, and on which components?' — the map that boundary decisions, encryption choices, and half the other requirements quietly depend on.

Across revisions

New in Rev. 3 with no Rev. 2 counterpart, drawn from SP 800-53's CM-12: Rev. 2 assumed organizations knew where CUI lived; Rev. 3 makes documenting it a requirement of its own.

Mapped practices

Brilliant at the Basics practices that support this requirement

Partial implementation supportModerate confidence

Why: The practice's precondition is knowing what information is controlled and where it lives — a data classification staff can apply, discovery of where sensitive content already sits, and data-loss rules pointed at those places. That location knowledge is the substance this requirement wants identified and documented for CUI.

What this does not claim: May partially address the requirement: the practice reaches information location only as far as AI-exposure protection needs it, while the requirement wants CUI locations and their system components documented comprehensively and kept current through changes, whether or not AI is in use. An organization could run this practice well and still lack the component-level CUI location record an assessor asks for.

Practice-side activities
  • Classify data so controlled content is identifiable to people and tooling
  • Discover where controlled content sits before sanctioning tools that touch it
  • Point data-loss rules at the stores and flows where CUI lives
Evidence this produces
  • The data classification and the stores it was applied to
  • Discovery results identifying CUI locations
  • Data-loss policy scoped to the identified locations

Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Start from contracts and workflows — which programs bring CUI in, and where it lands: file shares, email, ERP and PLM systems, engineering workstations, backups.
  • Automated discovery helps the digital sweep — CAD files and scanned drawings hide CUI from naive scanners — but tooling supplements the interview-and-trace work rather than replacing it.
  • Keep the record change-aware: a new project share or SaaS tool that starts taking CUI should update the document, which is the part organizations most often miss.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • The documented CUI location record naming components and stores
  • Dated updates reflecting system and workflow changes

Suggested owners, derived from the mapped practices and artifacts: Engineering lead · IT leader or compliance lead · Contracts or compliance lead · IT leader. Ownership is a named person in your organization, not a role on a website.

Artifacts

Templates and worksheets with a mapped relationship

The other revision

Where this came from in Rev. 2

No direct Rev. 2 counterpart — this requirement is new in Rev. 3. Open the transition crosswalk →

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated