NIST Special Publication 800-171 Revision 2

Date Published: January 28th, 2021

Withdrawn on May 14, 2024. Superseded by SP 800-171 Rev. 3

Author(s): Ron Ross (NIST), Victoria Pillitteri (NIST), Kelley Dempsey (NIST), Mark Riddle (NARA), Gary Guissanie (IDA)

Note: A Class Deviation is in effect as of May 2, 2024 (DEVIATION 2024O0013). The deviation clause requires contractors, who are subject to 252.204-7012, to comply with National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 Revision 2, instead of the version of NIST SP 800-171 in effect at the time the solicitation is issued or as authorized by the contracting officer. Click Here

3.1.3 Control the flow of CUI in accordance with approved authorizations.

Control Family: Access Control

Control Type: Derived

SPRS Value: 1

CMMC Level(s): AC.L2-3.1.3

Top Ten Failed Requirement: No

DIBCAC HIGH Failure Rate (OTS):

15th of 110

Referenced in:

DFARS 252.204-7012

Derived From: NIST SP 800-53r4

  • AC-4

CSF v1.1:

  • ID.AM-3

  • PR.AC-5

NIST 800-171 Control 3.1.3 MITRE ATT&CK Sunburst

NIST SP 800-171r2 Control 3.1.3 → MITRE ATT&CK 14.1

Mapping note: MITRE ATT&CK 14.1 techniques are derived through the NIST SP 800-53 Rev. 4 controls mapped to each NIST SP 800-171 Rev. 2 requirement.

Summary

  • Total mappings: 145
  • Families: 1
  • Outer ring: Technique ID + name

Family counts

  • Information Flow Enforcement: 145 techniques

Usage notes

  • Click a family or technique to zoom in.
  • Click the center to zoom back out.
  • Hover to view technique details.

Discussion:

Information flow control regulates where information can travel within a system and between systems (versus who can access the information) and without explicit regard to subsequent accesses to that information. Flow control restrictions include the following: keeping exportcontrolled information from being transmitted in the clear to the Internet; blocking outside traffic that claims to be from within the organization; restricting requests to the Internet that are not from the internal web proxy server; and limiting information transfers between organizations based on data structures and content. Organizations commonly use information flow control policies and enforcement mechanisms to control the flow of information between designated sources and destinations (e.g., networks, individuals, and devices) within systems and between interconnected systems. Flow control is based on characteristics of the information or the information path. Enforcement occurs in boundary protection devices (e.g., gateways, routers, guards, encrypted tunnels, firewalls) that employ rule sets or establish configuration settings that restrict system services, provide a packetfiltering capability based on header information, or message-filtering capability based on message content (e.g., implementing key word searches or using document characteristics). Organizations also consider the trustworthiness of filtering and inspection mechanisms (i.e., hardware, firmware, and software components) that are critical to information flow enforcement. Transferring information between systems representing different security domains with different security policies introduces risk that such transfers violate one or more domain security policies. In such situations, information owners or stewards provide guidance at designated policy enforcement points between interconnected systems. Organizations consider mandating specific architectural solutions when required to enforce specific security policies. Enforcement includes: prohibiting information transfers between interconnected systems (i.e., allowing access only); employing hardware mechanisms to enforce one-way information flows; and implementing trustworthy regrading mechanisms to reassign security attributes and security labels.

Determining Statements (NIST SP 800-171Ar2)

Upon assessment, assessors must determine if-

3.1.3[a] information flow control policies are defined.
3.1.3[b] methods and enforcement mechanisms for controlling the flow of CUI are
defined.
3.1.3[c] designated sources and destinations (e.g., networks, individuals, and devices)
for CUI within the system and between interconnected systems are identified.
3.1.3[d] authorizations for controlling the flow of CUI are defined.
3.1.3[e] approved authorizations for controlling the flow of CUI are enforced.3.1.2[a] the types of transactions and functions that authorized users are permitted to
execute are defined.
3.1.2[b] system access is limited to the defined types of transactions and functions for
authorized users.

Assessors are instructed to-

Examine: [SELECT FROM: Access control policy; information flow control policies; procedures addressing information flow enforcement; system security plan; system design documentation; system configuration settings and associated documentation; list of information flow authorizations; system baseline configuration; system audit logs and records; other relevant documents or records].

Interview: [SELECT FROM: System or network administrators; personnel with information security responsibilities; system developers].

Test: [SELECT FROM: Mechanisms implementing information flow enforcement policy].

FURTHER DISCUSSION

Typically, companies will have a firewall between the internal network and the internet. Often multiple firewalls or routing switches are used inside a network to create zones to separate sensitive data, business units, or user groups. Proxy servers can be used to break the connection between multiple networks. All traffic entering or leaving a network is intercepted by the proxy, preventing direct access between networks. Companies should also ensure by policy and enforcement mechanisms that all CUI allowed to flow across the internet is encrypted.

Example 1

You configure a proxy device on your company’s network. CUI is stored within this environment. Your goal is to better mask and protect the devices inside the network while enforcing information flow policies. After the device is configured, information does not flow AC.L2-3.1.3 – Control CUI Flow CMMC Assessment Guide – Level 2 | Version 2.13 21 directly from the internal network to the internet. The proxy device intercepts the traffic and analyzes it to determine if the traffic conforms to organization information flow control policies. If it does, the device allows the information to pass to its destination [b]. The proxy blocks traffic that does not meet policy requirements [e].

Example 2

As a subcontractor on a DoD contract, your organization sometimes needs to transmit CUI to the prime contractor. You create a policy document that specifies who is allowed to transmit CUI and that such transmission requires manager approval [a,c,d]. The policy instructs users to encrypt any CUI transmitted via email or to use a designated secure file sharing utility [b,d]. The policy states that users who do not follow appropriate procedures may be subject to disciplinary action [e].

Potential Assessment Considerations

  • Are designated sources of regulated data identified within the system (e.g., internal network and IP address) and between interconnected systems (e.g., external networks, IP addresses, ports, and protocols) [c]?

  • Are designated destinations of regulated data identified within the system (e.g., internal network and IP address) and between interconnected systems (external networks and IP addresses) [c]?

  • Are authorizations defined for each source and destination within the system and between interconnected systems (e.g., allow or deny rules for each combination of source and destination) [d]?

  • Are approved authorizations for controlling the flow of regulated data enforced within the system and between interconnected systems (e.g., traffic between authorized sources and destinations is allowed and traffic between unauthorized sources and destinations is denied) [e]?

ISO/IEC 27001:2013

A.13.1.3 Segregation in networks

A.13.2.1 Information transfer policies and procedures

A.14.1.2 Securing application services on public networks

A.14.1.3 Protecting application services transactions

NIST SP 800-171r2 Control 3.1.3 → MITRE ATT&CK

NIST SP 800-171r2 Control 3.1.3 → MITRE ATT&CK 14.1

Total Mappings

145
technique references

Families

1
Information Flow Enforcement

Control

3.1.3
AC.L2-3.1.3

Information Flow Enforcement 145 techniques

  • T1001Data Obfuscation
  • T1001.001Junk Data
  • T1001.002Steganography
  • T1001.003Protocol Impersonation
  • T1003OS Credential Dumping
  • T1003.001LSASS Memory
  • T1003.005Cached Domain Credentials
  • T1003.006DCSync
  • T1008Fallback Channels
  • T1020.001Traffic Duplication
  • T1021.001Remote Desktop Protocol
  • T1021.002SMB/Windows Admin Shares
  • T1021.003Distributed Component Object Model
  • T1021.005VNC
  • T1021.006Windows Remote Management
  • T1029Scheduled Transfer
  • T1030Data Transfer Size Limits
  • T1041Exfiltration Over C2 Channel
  • T1046Network Service Scanning
  • T1048Exfiltration Over Alternative Protocol
  • T1048.001Exfiltration Over Symmetric Encrypted Non-C2 Protocol
  • T1048.002Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
  • T1048.003Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • T1068Exploitation for Privilege Escalation
  • T1071Application Layer Protocol
  • T1071.001Web Protocols
  • T1071.002File Transfer Protocols
  • T1071.003Mail Protocols
  • T1071.004DNS
  • T1072Software Deployment Tools
  • T1090Proxy
  • T1090.001Internal Proxy
  • T1090.002External Proxy
  • T1090.003Multi-hop Proxy
  • T1095Non-Application Layer Protocol
  • T1098Account Manipulation
  • T1098.001Additional Cloud Credentials
  • T1102Web Service
  • T1102.001Dead Drop Resolver
  • T1102.002Bidirectional Communication
  • T1102.003One-Way Communication
  • T1104Multi-Stage Channels
  • T1105Ingress Tool Transfer
  • T1114Email Collection
  • T1114.001Local Email Collection
  • T1114.002Remote Email Collection
  • T1114.003Email Forwarding Rule
  • T1132Data Encoding
  • T1132.001Standard Encoding
  • T1132.002Non-Standard Encoding
  • T1133External Remote Services
  • T1134.005SID-History Injection
  • T1136Create Account
  • T1136.002Domain Account
  • T1136.003Cloud Account
  • T1187Forced Authentication
  • T1189Drive-by Compromise
  • T1190Exploit Public-Facing Application
  • T1197BITS Jobs
  • T1199Trusted Relationship
  • T1203Exploitation for Client Execution
  • T1204User Execution
  • T1204.001Malicious Link
  • T1204.002Malicious File
  • T1204.003Malicious Image
  • T1205Traffic Signaling
  • T1205.001Port Knocking
  • T1205.002Socket Filters
  • T1210Exploitation of Remote Services
  • T1211Exploitation for Defense Evasion
  • T1212Exploitation for Credential Access
  • T1213Data from Information Repositories
  • T1213.001Confluence
  • T1213.002Sharepoint
  • T1218.012Verclsid
  • T1219Remote Access Software
  • T1482Domain Trust Discovery
  • T1484Domain Policy Modification
  • T1489Service Stop
  • T1498Network Denial of Service
  • T1498.001Direct Network Flood
  • T1498.002Reflection Amplification
  • T1499Endpoint Denial of Service
  • T1499.001OS Exhaustion Flood
  • T1499.002Service Exhaustion Flood
  • T1499.003Application Exhaustion Flood
  • T1499.004Application or System Exploitation
  • T1505.004IIS Components
  • T1528Steal Application Access Token
  • T1530Data from Cloud Storage Object
  • T1537Transfer Data to Cloud Account
  • T1547.003Time Providers
  • T1552Unsecured Credentials
  • T1552.001Credentials In Files
  • T1552.005Cloud Instance Metadata API
  • T1552.007Container API
  • T1557Adversary-in-the-Middle
  • T1557.001LLMNR/NBT-NS Poisoning and SMB Relay
  • T1557.002ARP Cache Poisoning
  • T1557.003DHCP Spoofing
  • T1559Inter-Process Communication
  • T1559.001Component Object Model
  • T1559.002Dynamic Data Exchange
  • T1563Remote Service Session Hijacking
  • T1563.002RDP Hijacking
  • T1564.008Email Hiding Rules
  • T1565Data Manipulation
  • T1565.003Runtime Data Manipulation
  • T1566Phishing
  • T1566.001Spearphishing Attachment
  • T1566.002Spearphishing Link
  • T1566.003Spearphishing via Service
  • T1567Exfiltration Over Web Service
  • T1567.001Exfiltration to Code Repository
  • T1567.002Exfiltration to Cloud Storage
  • T1568Dynamic Resolution
  • T1568.002Domain Generation Algorithms
  • T1570Lateral Tool Transfer
  • T1571Non-Standard Port
  • T1572Protocol Tunneling
  • T1573Encrypted Channel
  • T1573.001Symmetric Cryptography
  • T1573.002Asymmetric Cryptography
  • T1574Hijack Execution Flow
  • T1574.004Dylib Hijacking
  • T1574.005Executable Installer File Permissions Weakness
  • T1574.007Path Interception by PATH Environment Variable
  • T1574.008Path Interception by Search Order Hijacking
  • T1574.009Path Interception by Unquoted Path
  • T1574.010Services File Permissions Weakness
  • T1598Phishing for Information
  • T1598.001Spearphishing Service
  • T1598.002Spearphishing Attachment
  • T1598.003Spearphishing Link
  • T1599Network Boundary Bridging
  • T1599.001Network Address Translation Traversal
  • T1601Modify System Image
  • T1601.001Patch System Image
  • T1601.002Downgrade System Image
  • T1602Data from Configuration Repository
  • T1602.001SNMP (MIB Dump)
  • T1602.002Network Device Configuration Dump
  • T1609Container Administration Command
  • T1611Escape to Host
  • T1622Debugger Evasion

Frameworks & Controls