{
  "node_id": "nist-sp-800-172a-assessment",
  "title": "Assessing Enhanced Security Requirements for Controlled Unclassified Information",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2022-03-01",
  "bluf": "This publication provides federal agencies and nonfederal organizations with assessment procedures to carry out assessments of the requirements in NIST Special Publication 800-172, Enhanced Security Requirements for Protecting Controlled Unclassified Information (CUI). The protection of CUI in nonfederal systems and organizations is important to federal agencies and can directly impact the ability of the Federal Government to successfully carry out its assigned missions. The purpose of this publication is to describe procedures for assessing these enhanced security requirements, which are designed to respond to the advanced persistent threat (APT) for CUI associated with a high value asset or critical program. The assessment procedures are flexible and can be tailored to the needs of organizations and assessors. Assessments can be conducted as self-assessments, independent third-party assessments, or government-sponsored assessments. The findings and evidence produced can be used to facilitate risk-based decisions, identify security weaknesses, prioritize risk mitigation, and support continuous monitoring.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "iso_standard"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-sp-800-172-enhanced-security",
    "nist-sp-800-53-r5"
  ],
  "primary_citations_count": 8
}