Hi All,
The initial public draft of NIST Special Publication (SP) 800-171, Revision 3, Protecting Controlled Unclassified Information (CUI) in Nonfederal Systems and Organizations is available for public comment and review.
The updates in this draft publication have been guided and informed by the public comments received and NIST's responsibility to meet the requirements of the Federal Information Security Modernization Act, Executive Order (EO) 13556, the CUI federal regulation, and Office of Management and Budget (OMB) Circular A-130. Many trade-offs have been made to ensure that the technical and non-technical requirements have been stated clearly and concisely while also recognizing the specific needs of both federal and nonfederal organizations.
In addition to the draft publication, NIST has issued an FAQ, a detailed analysis of the changes between Revision 2 and Revision 3, and a prototype CUI Overlay. These supporting materials are available on the publication details page.
NIST will also host a webinar on June 6, 2023, to provide an overview of the significant changes made to NIST SP 800-171, Revision 3. Registration information will be announced separately through a GovDelivery announcement and on the Protecting CUI project site.
Submit Your Comments
The public comment period is open through July 14, 2023. See the publication details (https://csrc.nist.gov/publications/detail/sp/800-171/rev-3/draft) for a copy of the draft and instructions for submitting comments. Reviewers are encouraged to comment on all or parts of draft NIST SP 800-171, Revision 3.
------------------------------
Michael Roza CPA, CISA, CIA, CC, MBA, Exec MBA
------------------------------