Back to Frameworks

NIST SP 800-172

United States
v2020
17 domains
36 controls

Enhanced Security Requirements for Protecting CUI

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (17)

AC

3 controls
Controls in the AC domain of NIST SP 800-1723 controls
CodeTitle
3.1.1eDual Authorization for Sensitive System Operations
3.1.2eRestrict Access to Systems and System Components to Defined Security Domains
3.1.3eEmploy Secure Information Transfer Solutions

AT

2 controls
Controls in the AT domain of NIST SP 800-1722 controls
CodeTitle
3.2.1eProvide Awareness Training on Advanced Persistent Threat
3.2.2ePractical Exercises in Awareness Training

CA

1 controls
Controls in the CA domain of NIST SP 800-1721 controls
CodeTitle
3.12.1ePenetration Testing by Independent Agents

CM

3 controls
Controls in the CM domain of NIST SP 800-1723 controls
CodeTitle
3.4.1eAuthoritative Source for Software and Firmware
3.4.2eAutomated Detection and Remediation of Unauthorized Software
3.4.3eAutomated Inventory of System Components

IA

3 controls
Controls in the IA domain of NIST SP 800-1723 controls
CodeTitle
3.5.1eIdentification of Systems, Components, and Devices
3.5.2ePassword Manager Use
3.5.3eMultifactor Authentication for Local, Network, and Remote Access

IR

2 controls
Controls in the IR domain of NIST SP 800-1722 controls
CodeTitle
3.6.1eEstablish Security Operations Center (SOC)
3.6.2eEstablish and Maintain a Cyber Incident Response Team

MA

1 controls
Controls in the MA domain of NIST SP 800-1721 controls
CodeTitle
3.7.6eMaintenance Operations Performed by Authorized Personnel

NIST SP 800-172: Access Control & Identity

0 controls

Managing access to information systems (NIST SP 800-172)

NIST SP 800-172: Audit & Accountability

0 controls

Audit logging and accountability measures (NIST SP 800-172)

NIST SP 800-172: Configuration Management

0 controls

Managing system configurations securely (NIST SP 800-172)

NIST SP 800-172: Incident Response

0 controls

Detecting and responding to security incidents (NIST SP 800-172)

NIST SP 800-172: Risk Assessment & Management

0 controls

Identifying and managing cybersecurity risks (NIST SP 800-172)

NIST SP 800-172: System & Communications Protection

0 controls

Protecting systems and communications (NIST SP 800-172)

PS

2 controls
Controls in the PS domain of NIST SP 800-1722 controls
CodeTitle
3.9.1eEnhanced Personnel Screening
3.9.2eInsider Threat Program

RA

6 controls
Controls in the RA domain of NIST SP 800-1726 controls
CodeTitle
3.11.1eThreat-Aware Risk Assessment
3.11.2eThreat Hunting
3.11.3eAdvanced Automation and Analytics Capabilities
3.11.4eSecurity Solution Rationale Document
3.11.5eAssess Effectiveness of Security Solutions
3.11.7eSupply Chain Risk Management Plan

SC

6 controls
Controls in the SC domain of NIST SP 800-1726 controls
CodeTitle
3.13.1eNetwork Segmentation by Security Domain
3.13.2eConcept of Least Privilege in System Engineering
3.13.3eDiversification of System Components
3.13.4eUse Trusted Communications Paths for Privileged Access
3.13.5eRandomness in System Operations
3.13.6eVerify Identity of Endpoint Hardware

SI

7 controls
Controls in the SI domain of NIST SP 800-1727 controls
CodeTitle
3.14.1eVerify Integrity of Security Critical Software and Firmware
3.14.2eMonitor Organizational Systems with Specialized Capabilities
3.14.3eInformation Inputs Validation
3.14.4eRefresh Systems and Components from a Trusted Baseline
3.14.5eVerify Integrity After Reauthentication
3.14.6eUse Threat Indicator Information for Detection
3.14.7eVerify Correctness of Security Functions

Maps to 1 other framework

36 total controls
NIST SP 800-53 Rev 5
36 source controls mapped|24 target controls covered
100%

Frequently Asked Questions

What is NIST SP 800-172?

NIST SP 800-172 is a compliance framework from United States with 17 domains and 36 controls. Enhanced Security Requirements for Protecting CUI It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does NIST SP 800-172 have?

NIST SP 800-172 has 36 controls organised across 17 domains. The largest domains are SI (7 controls), RA (6 controls), SC (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does NIST SP 800-172 map to?

NIST SP 800-172 maps to 1 other compliance frameworks. The top mapping partners are NIST SP 800-53 Rev 5 (100% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with NIST SP 800-172 compliance?

Start your NIST SP 800-172 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST SP 800-172 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 36 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.

Get Started Free →

Free forever — no credit card required