Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
03.13.13OFFICIAL TITLEPENDING NIST SME REVIEW

03.13.13Mobile Code

03.13 System and Communications Protection · NIST SP 800-171 Rev. 3

Independent summary of the official requirement

Requires defining acceptable and unacceptable mobile code and mobile code technologies, and authorizing, monitoring, and controlling the use of mobile code within the system.

Rev. 3 requirement text is multi-part and parameterized with organization-defined values, so this site summarizes rather than reproduces it. The summary is independent — read the official publication for the binding wording.

NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

Code that arrives over the network and executes locally — browser scripts, document macros, downloaded active content — runs with whatever trust the platform grants it. The organization defines which mobile code technologies are acceptable, forbids the rest, and authorizes and watches what runs, so 'the document ran a macro' is a governed event rather than the incident report's first line.

Mapped practices

Brilliant at the Basics practices that support this requirement

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Office macros are the mobile code that actually hurts contractors: block macros from internet-sourced documents by policy and allow signed, justified exceptions.
  • Constrain browser and endpoint execution through the platform's policy machinery rather than user discretion.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • The written definitions of acceptable and unacceptable mobile code
  • Policy configurations — macro restrictions, browser and endpoint execution policy — enforcing them
Artifacts

Templates and worksheets with a mapped relationship

No artifact in the library names this requirement yet. The library index groups everything by category and practice.

The other revision

Where this came from in Rev. 2

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated