NIST Special Publication 800-171 Revision 2

Date Published: January 28th, 2021

Withdrawn on May 14, 2024. Superseded by SP 800-171 Rev. 3

Author(s): Ron Ross (NIST), Victoria Pillitteri (NIST), Kelley Dempsey (NIST), Mark Riddle (NARA), Gary Guissanie (IDA)

Note: A Class Deviation is in effect as of May 2, 2024 (DEVIATION 2024O0013). The deviation clause requires contractors, who are subject to 252.204-7012, to comply with National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 Revision 2, instead of the version of NIST SP 800-171 in effect at the time the solicitation is issued or as authorized by the contracting officer. Click Here

Control Family: Access Control

Control Type: Derived

SPRS Value: 5

SPRS Supplemental Guidance:

Do not subtract points if wireless access not permitted

CMMC Level(s): AC.L2-3.1.14

Top Ten Failed Requirement: No

DIBCAC HIGH Failure Rate (OTS):

100th of 110

3.1.16 Authorize wireless access prior to allowing such connections.

Referenced in:

DFARS 252.204-7012

Derived From: NIST SP 800-53r4

  • AC-18

NIST Supplemental Guidance:

[SP 800-97]

CSF v1.1:

  • PR.PT-4

NIST 800-171 Control 3.1.16 MITRE ATT&CK 14.1 Sunburst

NIST SP 800-171r2 Control 3.1.16 → MITRE ATT&CK 14.1

Mapping note: MITRE ATT&CK 14.1 techniques are derived through the NIST SP 800-53 Rev. 4 controls mapped to each NIST SP 800-171 Rev. 2 requirement.

Summary

  • Total mappings: 24
  • Families: 1
  • Outer ring: Technique ID + name
  • MITRE ATT&CK version: 14.1

Family counts

  • Wireless Access: 24 techniques

Usage notes

  • Click a family or technique to zoom in.
  • Click the center to zoom back out.
  • Hover to view technique details.

Discussion:

Establishing usage restrictions and configuration/connection requirements for wireless access to the system provides criteria for organizations to support wireless access authorization decisions. Such restrictions and requirements reduce the susceptibility to unauthorized access to the system through wireless technologies. Wireless networks use authentication protocols which provide credential protection and mutual authentication. [SP 800-97] provide guidance on secure wireless networks.

Upon assessment, assessors must determine if-

3.1.16[a] wireless access points are identified.
3.1.16[b] wireless access is authorized prior to allowing such connections.

Assessors are instructed to-

Examine: [SELECT FROM: Access control policy; configuration management plan; procedures addressing wireless access implementation and usage (including restrictions); system security plan; system design documentation; system configuration settings and associated documentation; wireless access authorizations; system audit logs and records; other relevant documents or records].

Interview: [SELECT FROM: Personnel with responsibilities for managing wireless access connections; personnel with information security responsibilities].

Test: [SELECT FROM: Wireless access management capability for the system].

FURTHER DISCUSSION

Guidelines from management form the basis for the requirements that must be met prior to authorizing a wireless connection. These guidelines may include the following:

  • types of devices, such as corporate or privately owned equipment;

  • configuration requirements of the devices;

  • authorization requirements before granting such connections.

AC.L2-3.1.16, AC.L2-3.1.17, and AC.L2-3.1.18 are complementary requirements in that they all establish control for the connection of mobile devices and wireless devices through the use of authentication, authorization, and encryption mechanisms.

Example

Your company is implementing a wireless network at its headquarters. CUI may be transmitted on this network. You work with management to draft a policy about the use of the wireless network. The policy states that only company-approved devices that contain verified security configuration settings are allowed to connect. The policy also includes usage restrictions that must be followed for anyone who wants to use the wireless network. Authorization is required before devices are allowed to connect to the wireless network [b].

Potential Assessment Considerations

  • Is an updated list of approved network devices providing wireless access to the system maintained [a]?

  • Are network devices providing wireless access configured to require users or devices be authorized prior to permitting a wireless connection [b]?

  • Is wireless access to the system authorized and managed [b]?

ISO/IEC 27001:2013

A.6.2.1 Mobile device policy

A.13.1.1 Network controls

A.13.2.1 Information transfer policies and procedures

NIST SP 800-171r2 Control 3.1.16 → MITRE ATT&CK
MITRE ATT&CK v14.1

NIST SP 800-171r2 Control 3.1.16 → MITRE ATT&CK

Total Mappings

24
technique references

Families

1
Wireless Access

Control

3.1.16
AC.L2-3.1.16

Wireless Access 24 techniques

  • T1011Exfiltration Over Other Network Medium
  • T1011.001Exfiltration Over Bluetooth
  • T1020.001Traffic Duplication
  • T1040Network Sniffing
  • T1070Indicator Removal on Host
  • T1070.001Clear Windows Event Logs
  • T1070.002Clear Linux or Mac System Logs
  • T1070.008Clear Mailbox Data
  • T1119Automated Collection
  • T1530Data from Cloud Storage Object
  • T1552Unsecured Credentials
  • T1552.004Private Keys
  • T1557Adversary-in-the-Middle
  • T1557.002ARP Cache Poisoning
  • T1558Steal or Forge Kerberos Tickets
  • T1558.002Silver Ticket
  • T1558.003Kerberoasting
  • T1558.004AS-REP Roasting
  • T1565Data Manipulation
  • T1565.001Stored Data Manipulation
  • T1565.002Transmitted Data Manipulation
  • T1602Data from Configuration Repository
  • T1602.001SNMP (MIB Dump)
  • T1602.002Network Device Configuration Dump

Frameworks & Controls