Protecting Controlled Unclassified Information in Nonfederal Systems
NIST SP 800-171
NIST Special Publication 800-171 defines security requirements that non-federal organizations — notably U.S. Department of Defense contractors and subcontractors — must implement to safeguard Controlled Unclassified Information (CUI). Its requirements are organized into families covering access control, audit and accountability, configuration management, identification and authentication, incident response, and system and communications protection.
For organizations processing CUI in AWS, Azure, GCP, or OCI, NIST 800-171 demands enforced least privilege, comprehensive audit logging, secure configuration baselines, and encryption. Cloudanix continuously assesses cloud environments against these requirement families and surfaces the evidence assessors expect.