Skip to content

NIST SP 800-171 Rev 2

The 14 requirement families

NIST SP 800-171 Rev 2 organizes 110 requirements into 14 families, numbered 3.1 through 3.14. Each requirement carries an identifier such as 3.1.1, and each has assessment objectives published separately in NIST SP 800-171A.

How to read a requirement identifier

An identifier like 3.5.3 reads as section 3, family 5 (Identification and Authentication), requirement 3. The family number never changes, so 3.1.x is always Access Control. That stability is what makes an identifier worth citing in an audit record.

3.1

Access Control

22 requirements

What this family asks you to show: Who can reach the system, what they can do once they are in, and how remote and wireless access is limited.

3.2

Awareness and Training

3 requirements

What this family asks you to show: That the people using the system know the risks their role carries and have been trained for it.

3.3

Audit and Accountability

9 requirements

What this family asks you to show: That system activity is recorded, kept, and reviewable back to an individual user.

3.4

Configuration Management

9 requirements

What this family asks you to show: A known baseline for systems and software, and control over what changes against it.

3.5

Identification and Authentication

11 requirements

What this family asks you to show: That users and devices are identified, and that authentication is strong enough for what they access.

3.6

Incident Response

3 requirements

What this family asks you to show: A working process to detect, report, and respond to incidents, tested rather than assumed.

3.7

Maintenance

6 requirements

What this family asks you to show: Control over who performs maintenance, with what tools, and what happens to media during it.

3.8

Media Protection

9 requirements

What this family asks you to show: Protection, marking, transport, and sanitization of media that holds regulated information.

3.9

Personnel Security

2 requirements

What this family asks you to show: Screening before access is granted, and removal of access when people leave or move.

3.10

Physical Protection

6 requirements

What this family asks you to show: Limits on physical access to systems, equipment, and the facilities holding them.

3.11

Risk Assessment

3 requirements

What this family asks you to show: Periodic assessment of risk, vulnerability scanning, and remediation of what the scans find.

3.12

Security Assessment

4 requirements

What this family asks you to show: Assessing controls, building plans of action, and keeping a system security plan current.

3.13

System and Communications Protection

16 requirements

What this family asks you to show: Boundary protection, separation of duties in the architecture, and cryptography in transit and at rest.

3.14

System and Information Integrity

7 requirements

What this family asks you to show: Flaw remediation, malicious code protection, and monitoring for attacks and indicators.

Requirement titles and text are published by NIST. Overwatch 7Six reproduces identifiers and titles from NIST SP 800-171 Rev 2 and adds plain-language intent for working use. Consult the published standard as the authority.