NIST SP 800-172 enhanced requirements and the AIC Level 3 kit

National Institute of Standards and Technology (NIST) Special Publication 800-172 has 35 enhanced requirements for Controlled Unclassified Information (CUI). The Analog Informatics Corporation (AIC) Level 3 kit addresses 22 of them with a kit module. The other 13 stay with the organization: awareness exercises, personnel screening, supply chain, penetration testing, and selected resiliency practices. Cybersecurity Maturity Model Certification (CMMC) Level 3 selects 24 of the 35. See CMMC Level 3.

Level 3 kit around the Level 2 kitA large box labeled Level 3 kit contains a smaller box labeled Level 2 kit, plus labels for recorded Jump and the Assessment Binder.Level 3 kitLevel 2 kitRecorded Jump and Assessment Binder
The Level 3 kit includes the Level 2 kit and adds recorded Jump sessions and the 800-172 map in the Assessment Binder.

All 35 enhanced requirements

Requirement Short title Kit module
3.1.1e Dual authorization for critical or sensitive operations Approvals in Privileged Access Management
3.1.2e Restrict access to resources the organization owns or issues Configuration compliance for systems that connect
3.1.3e Secure information transfer between security domains Document sharing vault and Jump
3.2.1e Awareness training on social engineering and advanced threats Training and attestation assigns the material
3.2.2e Practical exercises in awareness training Training and attestation assigns the material
3.4.1e Authoritative repository of approved system components Inventory of enrolled systems
3.4.2e Automated detection of misconfigured or unauthorized components Configuration compliance with optional block
3.4.3e Automated discovery and inventory of system components Inventory of enrolled systems
3.5.1e Bidirectional cryptographic authentication before network connection Enrolled agent identity
3.5.2e Automated password generation, rotation, and management Privileged Identity Management
3.5.3e Block unknown or misconfigured components from connecting Configuration compliance with optional block
3.6.1e Security operations center capability Incident Response and continuous monitoring support the team
3.6.2e Cyber incident response team that deploys quickly Incident Response records and alerts support the team
3.9.1e Enhanced personnel screening Assessment Binder stores the record
3.9.2e Protect systems when adverse information develops about a person Account removal in the kit when the organization directs it
3.11.1e Threat intelligence to inform risk decisions Threat indicator feeds when a feed path exists
3.11.2e Cyber threat hunting Session records, audit, and indicator search
3.11.3e Advanced automation and analytics for risk Current State Compliance and Incident Response analytics
3.11.4e Document security solutions and rationale in the system security plan Assessment Binder
3.11.5e Assess effectiveness of security solutions Assessment Binder and Current State Compliance
3.11.6e Assess and monitor supply chain risk Assessment Binder stores the record
3.11.7e Supply chain risk management plan Assessment Binder stores the record
3.12.1e Penetration testing Assessment Binder stores the record
3.13.1e Diversity in systems to limit malicious code spread Assessment Binder stores the record
3.13.2e Unpredictability in operations Assessment Binder stores the record
3.13.3e Means to confuse and mislead adversaries Assessment Binder stores the record
3.13.4e Physical or logical isolation Isolated Jump and the secure enclave boundary
3.13.5e Distribute and relocate system functions Assessment Binder stores the record
3.14.1e Verify integrity of security-critical software Configuration compliance and signed update checks
3.14.2e Monitor continuously for anomalous or suspicious behavior Incident Response and continuous monitoring
3.14.3e Include specialized assets such as operational technology in scope Kit support for operational technology systems
3.14.4e Refresh systems from a known trusted state Assessment Binder stores the record
3.14.5e Review storage locations and remove information no longer needed Document sharing vault review
3.14.6e Use threat indicator information to guide detection and hunting Threat indicator feeds when a feed path exists
3.14.7e Verify correctness of security-critical components Assessment Binder stores the record

Short titles are plain-language summaries of the public NIST text.

Screenshots

Screenshots come from a demonstration system. Host names, account names, and network addresses are replaced with sample values.

Auditor playbooks load reusable binder text and steps for each assessment.

More on Product screenshots.