Templates
Information Security
NIST SP 800-171 Compliance Checklist
📋

NIST SP 800-171 Compliance Checklist

1
Establish a team responsible for NIST compliance
2
Identify Information Systems that store, process, or transmit Federal Contract Information
3
Perform a comprehensive inventory of data, applications, and hardware
4
Categorize the information system
5
Approval: Information System Categorization
6
Select baseline security controls from NIST SP 800-53
7
Implement the security controls
8
Assess the security controls effectiveness
9
Approval: Security Controls Effectiveness
10
Develop Plan of Action and Milestones (POAM) based on assessment findings
11
Implement action plan to remediate compliance gaps
12
Monitor the security controls on a continuous basis
13
Document system changes and reassess security controls
14
Perform annual system review
15
Approval: Annual System Review
16
Update the System Security Plan (SSP) as required
17
Prepare for independent audit of the compliance program
18
Review audit findings and develop a remediation plan
19
Approval: Audit Findings and Remediation Plan
20
Implement the remediation plan to address any compliance deficiencies