NIST 800-171 · System and Communications Protection
Requirement 3.13.2
- SPRS weight
- SPRS weight: 5
- POA&M eligibility
- Not POA&M-eligible
- Assessment objectives
- 6 assessment objectives
Official requirement text
Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.
Assessment objectives
Assessors don’t evaluate the requirement as one sentence; they walk these objectives one by one. Each must be met for the requirement to score.
- 3.13.2[a]architectural designs that promote effective information security are identified.
- 3.13.2[b]software development techniques that promote effective information security are identified.
- 3.13.2[c]systems engineering principles that promote effective information security are identified.
- 3.13.2[d]identified architectural designs that promote effective information security are employed.
- 3.13.2[e]identified software development techniques that promote effective information security are employed.
- 3.13.2[f]identified systems engineering principles that promote effective information security are employed.
Inside Valontir, this requirement carries a full plain-English guide: what it asks in normal words, what good looks like in a small shop, the evidence an assessor accepts, the common gaps that cost points, and a plain reading of every assessment objective shown above. See it in a demo.