NIST 800-171 v2

110 security requirements available

3.1.22Derived Requirement

Access Control

Security Requirement

Control CUI posted or processed on publicly accessible systems.

Discussion

In accordance with laws, Executive Orders, directives, policies, regulations, or standards, the public is not authorized access to nonpublic information (e.g., information protected under the Privacy Act, CUI, and proprietary information). This requirement addresses systems that are controlled by the organization and accessible to the public, typically without identification or authentication. Individuals authorized to post CUI onto publicly accessible systems are designated. The content of information is reviewed prior to posting onto publicly accessible systems to ensure that nonpublic information is not included.

Framework
NIST SP 800-171 Rev 2
Family
Access Control
Requirement Type
derived