NIST SP 800-172 Enhanced Requirements and the AIC Level 3 Kit

National Institute of Standards and Technology (NIST) Special Publication 800-172 has 35 enhanced requirements for Controlled Unclassified Information (CUI). The Analog Informatics Corporation (AIC) Level 3 kit addresses 22 of them with a kit module. The other 13 stay with the organization: awareness exercises, personnel screening, supply chain, penetration testing, and selected resiliency practices. Cybersecurity Maturity Model Certification (CMMC) Level 3 selects 24 of the 35. See CMMC Level 3.

Layered protective infrastructure with separate inner and outer boundaries around a sensitive information vault
NIST SP 800-172 Enhanced Requirements and the AIC Level 3 Kit

What Availability Means

All 35 Enhanced Requirements

Requirement Short Title Kit Module
3.1.1e Dual authorization for critical or sensitive operations Approvals in Privileged Access Management
3.1.2e Restrict access to resources the organization owns or issues Configuration compliance for systems that connect
3.1.3e Secure information transfer between security domains Document sharing vault and Jump
3.2.1e Awareness training on social engineering and advanced threats Training and attestation assigns the material
3.2.2e Practical exercises in awareness training Training and attestation assigns the material
3.4.1e Authoritative repository of approved system components Inventory of enrolled systems
3.4.2e Automated detection of misconfigured or unauthorized components Configuration compliance with optional block
3.4.3e Automated discovery and inventory of system components Inventory of enrolled systems
3.5.1e Bidirectional cryptographic authentication before network connection Enrolled agent identity
3.5.2e Automated password generation, rotation, and management Privileged Identity Management
3.5.3e Block unknown or misconfigured components from connecting Configuration compliance with optional block
3.6.1e Security operations center capability Incident Response and continuous monitoring support the team
3.6.2e Cyber incident response team that deploys quickly Incident Response records and alerts support the team
3.9.1e Enhanced personnel screening Assessment Binder stores the record
3.9.2e Protect systems when adverse information develops about a person Account removal in the kit when the organization directs it
3.11.1e Threat intelligence to inform risk decisions Threat indicator feeds when a feed path exists
3.11.2e Cyber threat hunting Session records, audit, and indicator search
3.11.3e Advanced automation and analytics for risk Current State Compliance and Incident Response analytics
3.11.4e Document security solutions and rationale in the system security plan Assessment Binder
3.11.5e Assess effectiveness of security solutions Assessment Binder and Current State Compliance
3.11.6e Assess and monitor supply chain risk Assessment Binder stores the record
3.11.7e Supply chain risk management plan Assessment Binder stores the record
3.12.1e Penetration testing Assessment Binder stores the record
3.13.1e Diversity in systems to limit malicious code spread Assessment Binder stores the record
3.13.2e Unpredictability in operations Assessment Binder stores the record
3.13.3e Means to confuse and mislead adversaries Assessment Binder stores the record
3.13.4e Physical or logical isolation Isolated Jump and the secure enclave boundary
3.13.5e Distribute and relocate system functions Assessment Binder stores the record
3.14.1e Verify integrity of security-critical software Configuration compliance and signed update checks
3.14.2e Monitor continuously for anomalous or suspicious behavior Incident Response and continuous monitoring
3.14.3e Include specialized assets such as operational technology in scope Kit support for operational technology systems
3.14.4e Refresh systems from a known trusted state Assessment Binder stores the record
3.14.5e Review storage locations and remove information no longer needed Document sharing vault review
3.14.6e Use threat indicator information to guide detection and hunting Threat indicator feeds when a feed path exists
3.14.7e Verify correctness of security-critical components Assessment Binder stores the record

Short titles are plain-language summaries of the public NIST text.

Screenshots

Auditor playbooks load reusable binder text and steps for each assessment.

More on Product Screenshots.

An assessment organization, certification body, or regulator decides whether a requirement is satisfied.

See It on Your Use Case

A live demo of privileged access, compliance evidence, and deployment options for your environment.