NIST 800-171 · System and Communications Protection
Requirement 3.13.1
- SPRS weight
- SPRS weight: 5
- POA&M eligibility
- Not POA&M-eligible
- Assessment objectives
- 8 assessment objectives
Official requirement text
Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems.
Assessment objectives
Assessors don’t evaluate the requirement as one sentence; they walk these objectives one by one. Each must be met for the requirement to score.
- 3.13.1[a]the external system boundary is defined.
- 3.13.1[b]key internal system boundaries are defined.
- 3.13.1[c]communications are monitored at the external system boundary.
- 3.13.1[d]communications are monitored at key internal boundaries.
- 3.13.1[e]communications are controlled at the external system boundary.
- 3.13.1[f]communications are controlled at key internal boundaries.
- 3.13.1[g]communications are protected at the external system boundary.
- 3.13.1[h]communications are protected at key internal boundaries.
Inside Valontir, this requirement carries a full plain-English guide: what it asks in normal words, what good looks like in a small shop, the evidence an assessor accepts, the common gaps that cost points, and a plain reading of every assessment objective shown above. See it in a demo.