Skip to content

Free self-check

How many of the 110 could you prove this afternoon?

Answer for each NIST SP 800-171 Rev 2 requirement: can you put evidence in front of someone today, is the evidence thin or out of date, or is there nothing there. It takes about fifteen minutes. You will come out with a count, the families costing you the most, and a written copy if you want one.

  • No account, no payment, no sales call attached.
  • Your answers stay in your browser until you ask for the written copy.
  • We never receive the result unless you send it to yourself first.
  • This is a self-check, not an assessment, and not an SPRS score.

Family 1 of 14 · 0 of 110 answered

3.1

Access Control

0 of 22 answered in this family

Set all in this family
  • Requirement 3.1.1

    3.1.1

    Only approved people, service accounts, and devices can reach the system. Everyone else is kept out.

    Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems).

  • Requirement 3.1.2

    3.1.2

    Once inside, an account can run only the transactions and functions its role allows.

    Limit system access to the types of transactions and functions that authorized users are permitted to execute.

  • Requirement 3.1.3

    3.1.3

    CUI moves between systems and networks only along paths someone approved.

    Control the flow of CUI in accordance with approved authorizations.

  • Requirement 3.1.4

    3.1.4

    Duties are split so no single person can carry out a harmful action alone.

    Separate the duties of individuals to reduce the risk of malevolent activity without collusion.

  • Requirement 3.1.5

    3.1.5

    Each account holds the least access it needs, and privileged accounts are reserved for privileged work.

    Employ the principle of least privilege, including for specific security functions and privileged accounts.

  • Requirement 3.1.6

    3.1.6

    Routine work happens under a non-privileged account, not an administrator account.

    Use non-privileged accounts or roles when accessing nonsecurity functions.

  • Requirement 3.1.7

    3.1.7

    Non-privileged users cannot run privileged functions, and attempts land in the audit log.

    Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs.

  • Requirement 3.1.8

    3.1.8

    Repeated failed logon attempts are capped.

    Limit unsuccessful logon attempts.

  • Requirement 3.1.9

    3.1.9

    Users see the required privacy and security notice before they get in.

    Provide privacy and security notices consistent with applicable CUI rules.

  • Requirement 3.1.10

    3.1.10

    Screens lock after inactivity and hide what was on them.

    Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity.

  • Requirement 3.1.11

    3.1.11

    Sessions end on their own once a defined condition is met.

    Terminate (automatically) a user session after a defined condition.

  • Requirement 3.1.12

    3.1.12

    Remote access sessions are watched and controlled.

    Monitor and control remote access sessions.

  • Requirement 3.1.13

    3.1.13

    Remote access sessions are encrypted.

    Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.

  • Requirement 3.1.14

    3.1.14

    Remote access arrives through managed control points, not arbitrary paths.

    Route remote access via managed access control points.

  • Requirement 3.1.15

    3.1.15

    Remote privileged commands and remote access to security information are authorized in advance.

    Authorize remote execution of privileged commands and remote access to security-relevant information.

  • Requirement 3.1.16

    3.1.16

    Wireless connections are authorized before they are allowed.

    Authorize wireless access prior to allowing such connections.

  • Requirement 3.1.17

    3.1.17

    Wireless access uses both authentication and encryption.

    Protect wireless access using authentication and encryption.

  • Requirement 3.1.18

    3.1.18

    Connections from mobile devices are controlled.

    Control connection of mobile devices.

  • Requirement 3.1.19

    3.1.19

    CUI on mobile devices and mobile platforms is encrypted.

    Encrypt CUI on mobile devices and mobile computing platforms.

  • Requirement 3.1.20

    3.1.20

    Connections to outside systems are verified and limited.

    Verify and control/limit connections to and use of external systems.

  • Requirement 3.1.21

    3.1.21

    Use of portable storage on external systems is limited.

    Limit use of portable storage devices on external systems.

  • Requirement 3.1.22

    3.1.22

    Nothing containing CUI reaches a publicly accessible system without review.

    Control CUI posted or processed on publicly accessible systems.

Your answers stay in this browser until you ask for the written copy. Nothing is sent as you go, and Overwatch 7Six stores no part of this.