nist-800-171

Explains NIST SP 800-171 Rev. 3 CUI security requirements across 17 families.

5|1|Updated Jun 19, 2026
One-click install
npx skills add https://github.com/jgsystemsconsulting/jgs-se-knowledge-packs --skill nist-800-171-jgsystemsconsulting
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: nist-800-171
Source: https://github.com/jgsystemsconsulting/jgs-se-knowledge-packs/tree/main/packs/nist-800-171
Command: npx skills add https://github.com/jgsystemsconsulting/jgs-se-knowledge-packs --skill nist-800-171-jgsystemsconsulting

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve? Security engineers and contractors handling Controlled Unclassified Information struggle to recall and correctly apply the 17 requirement families of NIST SP 800-171 Rev. 3 mid-task, risking mis-scoped systems, unfilled ODPs, and failed assessments. ## Core Features & Use Cases - Requirement Family Reference: Synthesized chapter notes covering all 17 families from access control through supply chain risk management, with requirement anchors like 03.05.03 for MFA. - Implementation Guidance: Patterns, decision rules, glossary terms, and a cheatsheet mapping smells (e.g., shared admin passwords, unsanitized media) to likely control gaps. - Use Case: A contractor preparing for a CUI assessment asks about POA&M requirements and receives the 03.12.02 expectations, SSP documentation guidance, and scoping advice for isolating CUI into a dedicated enclave. ## Quick Start Ask the agent to explain the NIST 800-171 requirements for multi-factor authentication and remote access to systems storing CUI.

Frequently Asked Questions about nist-800-171

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I determine which systems are in scope for NIST 800-171?

NIST 800-171 applies only to components that process, store, or transmit CUI, or that protect those components. Isolating CUI into a separate security domain, physical or logical, lets you avoid applying controls enterprise-wide.

What are organization-defined parameters in NIST 800-171?

ODPs are assignment or selection values that complete flexible requirement statements. Agencies should set them; if left blank, the nonfederal organization must assign values so the requirement becomes complete and assessable.

Does NIST 800-171 cover CMMC assessment scoring?

No. This pack covers the 800-171 Rev. 3 requirements themselves, not CMMC level scoring mechanics, SP 800-171A assessment procedures, or DFARS contract clause interpretation.

What is the difference between SSP and POA&M documentation?

The system security plan (03.15.02) documents boundaries, implementations, and enduring exceptions. The POA&M (03.12.02) tracks temporary deficiencies with owners, resources, and scheduled completion dates.

When is FISMA applicable instead of NIST 800-171?

Organizations operating systems on behalf of a federal agency fall under FISMA and the full federal control sets. The 800-171 nonfederal CUI requirements apply to contractors and other nonfederal organizations handling CUI under contract.