NIST has published Special Publication 800-171, Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations.
SP 800-171 sets out security requirements, derived from the NIST SP 800-53 control catalogue, for contractors and other organisations that handle US Government Controlled Unclassified Information (CUI) on their own systems. Requirements are grouped into families such as access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response and system integrity.
Why it matters outside the US: requirements like these flow down supply chains. UK and European suppliers to US defence and government contractors should expect to see SP 800-171 referenced in contracts and security questionnaires.
Much of SP 800-171 maps closely to ISO/IEC 27001 Annex A controls, so an existing ISMS is an excellent foundation for demonstrating compliance.
Source: NIST SP 800-171 (2015) (NIST CSRC)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.