Comprehensive
Evaluation Of
Compliance
With NIST
SP800-171
Protecting
Controlled
Unclassified
Information
In Non-Federal
Systems And
Organizations
Comprehensive
Evaluation Of
Compliance With
NIST SP800-171
Protecting Controlled Unclassified
Information in Non-Federal
Systems and Organizations
NIST SP 800-171, authored by the National Institute of Standards and Technology, serves as a comprehensive framework designed to safeguard Controlled Unclassified Information (CUI) within nonfederal systems and organizations. This critical set of guidelines is applicable to a diverse range of entities outside the federal sphere, including academic institutions, state and local governments, and private sector companies, particularly those managing or interacting with CUI under federal government contracts. The directive mandates these organizations to rigorously implement and maintain the security measures delineated in NIST SP 800-171. Compliance with these standards is integral to ensuring the secure handling of sensitive information, thereby fortifying the mutual trust and integrity essential in the collaborations between the federal government and its nonfederal partners.
Sigma Technology will undertake a comprehensive Gap Assessment for customers. This assessment strategically focuses on aligning the company’s existing cybersecurity practices with the stringent requirements set forth in NIST SP800-171. The objective is to meticulously identify and address any discrepancies or shortcomings in current security protocols. Furthermore, Sigma Technology will extend its expertise in aiding companies to develop a robust System Security Plan (SSP), conduct a thorough Gap Assessment, and systematically prioritize corrective actions.
⦁ Access Control Policy
⦁ Security Awareness and Training Policy
⦁ Audit and Accountability Policy
⦁ Configuration Management Plan
⦁ Identification and Authentication Policy
⦁ Incident Response Plan
⦁ Maintenance Policy
⦁ Media Protection Policy
⦁ Personnel Security
⦁ Physical Protection
⦁ Risk Assessment
⦁ Security Assessment Policy and Procedures
⦁ System and Communication Protection
⦁ System and Information Integrity
Services Brief
The Health Information Trust Alliance (HITRUST) is an organization governed by representatives from the healthcare industry. HITRUST created and maintains the Common Security Framework (CSF), a certifiable framework to help healthcare organizations and their providers demonstrate their security and compliance in a consistent and streamlined manner. The CSF builds on HIPAA and the HITECH Act, which are US healthcare laws that have established requirements for the use, disclosure, and safeguarding of individually identifiable health information, and that enforce noncompliance.
The readiness assessment is recommended prior to the validated assessment in order to identify control weaknesses that need correction. Sigma Technology’s deliverables from the readiness assessment include:
- Preliminary control discovery results that will assist in documenting process narratives and crafting the description of controls
- Control gaps and areas of improvement
- Prioritized observations and recommendations for remediation
- The advantage of performing a readiness assessment prior to a HITRUST assessment is to give management an opportunity to address control gaps prior to an inaugural examination as well as help with required risk assessment activities
Services Brief