NIST 800-171 · Access Control

Requirement 3.1.3

SPRS weight
SPRS weight: 1
POA&M eligibility
POA&M-eligible
Assessment objectives
5 assessment objectives

Official requirement text

Control the flow of CUI in accordance with approved authorizations.

Assessment objectives

Assessors don’t evaluate the requirement as one sentence; they walk these objectives one by one. Each must be met for the requirement to score.

  1. 3.1.3[a]information flow control policies are defined.
  2. 3.1.3[b]methods and enforcement mechanisms for controlling the flow of CUI are defined.
  3. 3.1.3[c]designated sources and destinations (e.g., networks, individuals, and devices) for CUI within systems and between interconnected systems are identified.
  4. 3.1.3[d]authorizations for controlling the flow of CUI are defined.
  5. 3.1.3[e]approved authorizations for controlling the flow of CUI are enforced.

Inside Valontir, this requirement carries a full plain-English guide: what it asks in normal words, what good looks like in a small shop, the evidence an assessor accepts, the common gaps that cost points, and a plain reading of every assessment objective shown above. See it in a demo.

NIST 800-171 3.1.3 explained — Access Control | Valontir