NIST 800-171 · Access Control

Requirement 3.1.22

SPRS weight
SPRS weight: 1
POA&M eligibility
Not POA&M-eligible
Assessment objectives
5 assessment objectives

Official requirement text

Control CUI posted or processed on publicly accessible systems.

Assessment objectives

Assessors don’t evaluate the requirement as one sentence; they walk these objectives one by one. Each must be met for the requirement to score.

  1. 3.1.22[a]individuals authorized to post or process information on publicly accessible systems are identified.
  2. 3.1.22[b]procedures to ensure CUI is not posted or processed on publicly accessible systems are identified.
  3. 3.1.22[c]a review process in in place prior to posting of any content to publicly accessible systems.
  4. 3.1.22[d]content on publicly accessible information systems is reviewed to ensure that it does not include CUI.
  5. 3.1.22[e]mechanisms are in place to remove and address improper posting of CUI.

Inside Valontir, this requirement carries a full plain-English guide: what it asks in normal words, what good looks like in a small shop, the evidence an assessor accepts, the common gaps that cost points, and a plain reading of every assessment objective shown above. See it in a demo.