{"id":31845,"date":"2023-09-25T03:12:08","date_gmt":"2023-09-25T03:12:08","guid":{"rendered":"https:\/\/www.process.st\/templates\/nist-sp-800-171-compliance-checklist\/"},"modified":"2024-03-05T14:13:09","modified_gmt":"2024-03-05T14:13:09","slug":"nist-sp-800-171-compliance-checklist","status":"publish","type":"post","link":"https:\/\/www.process.st\/templates\/nist-sp-800-171-compliance-checklist\/","title":{"rendered":"NIST SP 800-171 Compliance Checklist"},"content":{"rendered":"\n<section id=\"establish-a-team-responsible-for-nist-compliance\"> \n <h2>Establish a team responsible for NIST compliance<\/h2>\n <div class=\"text-content\">\n   Assign a team to be responsible for ensuring compliance with the NIST SP 800-171 guidelines. This team will play a crucial role in implementing and maintaining the necessary security controls to protect Federal Contract Information (FCI). They will be responsible for coordinating with relevant stakeholders, conducting regular assessments, and making sure that all compliance requirements are met. \n <\/div> \n <div class=\"members-field-content form-field-content\"> \n  <div class=\"form-group\"> <label> Team Members <\/label> <select disabled class=\"form-control\"> <option value=\"A member or group will be selected here\">A member or group will be selected here<\/option> <\/select> \n  <\/div> \n <\/div> \n<\/section> \n<section id=\"identify-information-systems-that-store-process-or-transmit-federal-contract-information\"> \n <h2>Identify Information Systems that store, process, or transmit Federal Contract Information<\/h2>\n <div class=\"text-content\">\n   Determine the Information Systems within your organization that handle Federal Contract Information (FCI). Identify all the systems that store, process, or transmit FCI to ensure that they are included in the scope of NIST SP 800-171 compliance efforts. This task is critical to understanding the overall landscape and potential risks associated with FCI. \n <\/div> \n <div class=\"textarea-field-content form-field-content\"> \n  <div class=\"form-group\"> <label> Information Systems <\/label> <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea> \n  <\/div> \n <\/div> \n<\/section> \n<section id=\"perform-a-comprehensive-inventory-of-data-applications-and-hardware\"> \n <h2>Perform a comprehensive inventory of data, applications, and hardware<\/h2>\n <div class=\"text-content\">\n   Conduct a thorough inventory of all data, applications, and hardware assets related to the Information Systems identified in the previous task. This inventory will provide a detailed understanding of the assets that require protection and will help in establishing a baseline for security control implementation. \n <\/div> \n <div class=\"multi-select-content form-field-content\"> \n  <div class=\"form-group\"> <label> Inventory Checklist <\/label> \n  <\/div> \n  <ul class=\"items\"> \n   <li class=\"item\"> \n    <div class=\"step-number-container\"> \n     <div class=\"step-number\">\n       1 \n     <\/div> \n    <\/div> \n    <div class=\"step-checkbox-container\"> \n     <div class=\"step-checkbox\"><\/div> \n    <\/div> \n    <div class=\"item-name-static\">\n      Data \n    <\/div> <\/li>\n   <li class=\"item\"> \n    <div class=\"step-number-container\"> \n     <div class=\"step-number\">\n       2 \n     <\/div> \n    <\/div> \n    <div class=\"step-checkbox-container\"> \n     <div class=\"step-checkbox\"><\/div> \n    <\/div> \n    <div class=\"item-name-static\">\n      Applications \n    <\/div> <\/li>\n   <li class=\"item\"> \n    <div class=\"step-number-container\"> \n     <div class=\"step-number\">\n       3 \n     <\/div> \n    <\/div> \n    <div class=\"step-checkbox-container\"> \n     <div class=\"step-checkbox\"><\/div> \n    <\/div> \n    <div class=\"item-name-static\">\n      Hardware \n    <\/div> <\/li> \n  <\/ul> \n <\/div> \n<\/section> \n<section id=\"categorize-the-information-system\"> \n <h2>Categorize the information system<\/h2>\n <div class=\"text-content\">\n   Categorize each Information System based on its potential impact on the confidentiality, integrity, and availability of Federal Contract Information (FCI). This categorization will help in determining the appropriate set of security controls and their implementation requirements. \n <\/div> \n <div class=\"select-field-content form-field-content\"> \n  <div class=\"form-group\"> <label> Categorization <\/label> <select disabled class=\"form-control\"> <option value=\"An option will be selected here\">An option will be selected here<\/option> <\/select> \n  <\/div> \n  <ul class=\"items\"> \n   <li class=\"item\"> \n    <div class=\"step-number-container\"> \n     <div class=\"step-number\">\n       1 \n     <\/div> \n    <\/div> \n    <div class=\"step-checkbox-container\"> \n     <div class=\"step-checkbox\"><\/div> \n    <\/div> \n    <div class=\"item-name-static\">\n      Low \n    <\/div> <\/li>\n   <li class=\"item\"> \n    <div class=\"step-number-container\"> \n     <div class=\"step-number\">\n       2 \n     <\/div> \n    <\/div> \n    <div class=\"step-checkbox-container\"> \n     <div class=\"step-checkbox\"><\/div> \n    <\/div> \n    <div class=\"item-name-static\">\n      Moderate \n    <\/div> <\/li>\n   <li class=\"item\"> \n    <div class=\"step-number-container\"> \n     <div class=\"step-number\">\n       3 \n     <\/div> \n    <\/div> \n    <div class=\"step-checkbox-container\"> \n     <div class=\"step-checkbox\"><\/div> \n    <\/div> \n    <div class=\"item-name-static\">\n      High \n    <\/div> <\/li> \n  <\/ul> \n <\/div> \n<\/section> \n<section id=\"approval-information-system-categorization\"> \n <h2>Approval: Information System Categorization<\/h2>\n <div class=\"approval-content\"> \n  <div class=\"header\"> \n   <div class=\"list-title\">\n    Will be submitted for approval:\n   <\/div> \n  <\/div> \n  <div class=\"approval-rule-subject-tasks-list\"> \n   <ul class=\"list\"> \n    <li> \n     <div class=\"approval-rule-subject-tasks-list-item\"> \n      <div class=\"item\"> \n       <div class=\"container\"> <span class=\"title\">Categorize the information system<\/span> \n        <div class=\"body\">\n         Will be submitted\n        <\/div> \n       <\/div> \n      <\/div> \n     <\/div> <\/li> \n   <\/ul> \n  <\/div> \n <\/div> \n<\/section> \n<section id=\"select-baseline-security-controls-from-nist-sp-80053\"> \n <h2>Select baseline security controls from NIST SP 800-53<\/h2>\n <div class=\"text-content\">\n   Choose the baseline security controls from the NIST SP 800-53 publication that are applicable to the categorized Information Systems. Consider the impact of FCI and select the controls that provide adequate protection. The chosen controls will form the foundation for the overall security posture of the organization. \n <\/div> \n <div class=\"multi-choice-content form-field-content\"> \n  <div class=\"form-group\"> <label> Baseline Security Controls <\/label> <select disabled class=\"form-control\"> <option value=\"\">Multiple options can be selected from this list<\/option> <\/select> \n  <\/div> \n  <ul class=\"items\"> \n   <li class=\"item\"> \n    <div class=\"step-number-container\"> \n     <div class=\"step-number\">\n       1 \n     <\/div> \n    <\/div> \n    <div class=\"step-checkbox-container\"> \n     <div class=\"step-checkbox\"><\/div> \n    <\/div> \n    <div class=\"item-name-static\">\n      Access Control \n    <\/div> <\/li>\n   <li class=\"item\"> \n    <div class=\"step-number-container\"> \n     <div class=\"step-number\">\n       2 \n     <\/div> \n    <\/div> \n    <div class=\"step-checkbox-container\"> \n     <div class=\"step-checkbox\"><\/div> \n    <\/div> \n    <div class=\"item-name-static\">\n      Audit and Accountability \n    <\/div> <\/li>\n   <li class=\"item\"> \n    <div class=\"step-number-container\"> \n     <div class=\"step-number\">\n       3 \n     <\/div> \n    <\/div> \n    <div class=\"step-checkbox-container\"> \n     <div class=\"step-checkbox\"><\/div> \n    <\/div> \n    <div class=\"item-name-static\">\n      Configuration Management \n    <\/div> <\/li>\n   <li class=\"item\"> \n    <div class=\"step-number-container\"> \n     <div class=\"step-number\">\n       4 \n     <\/div> \n    <\/div> \n    <div class=\"step-checkbox-container\"> \n     <div class=\"step-checkbox\"><\/div> \n    <\/div> \n    <div class=\"item-name-static\">\n      Identification and Authentication \n    <\/div> <\/li>\n   <li class=\"item\"> \n    <div class=\"step-number-container\"> \n     <div class=\"step-number\">\n       5 \n     <\/div> \n    <\/div> \n    <div class=\"step-checkbox-container\"> \n     <div class=\"step-checkbox\"><\/div> \n    <\/div> \n    <div class=\"item-name-static\">\n      Incident Response \n    <\/div> <\/li> \n  <\/ul> \n <\/div> \n<\/section> \n<section id=\"implement-the-security-controls\"> \n <h2>Implement the security controls<\/h2>\n <div class=\"text-content\">\n   Implement the selected security controls to ensure the necessary safeguards are in place to protect Federal Contract Information (FCI). Assign responsible parties for each control and establish a clear timeline for implementation. Regularly review progress to identify any challenges and address them promptly. \n <\/div> \n <div class=\"multi-select-content form-field-content\"> \n  <div class=\"form-group\"> <label> Security Controls Checklist <\/label> \n  <\/div> \n  <ul class=\"items\"> \n   <li class=\"item\"> \n    <div class=\"step-number-container\"> \n     <div class=\"step-number\">\n       1 \n     <\/div> \n    <\/div> \n    <div class=\"step-checkbox-container\"> \n     <div class=\"step-checkbox\"><\/div> \n    <\/div> \n    <div class=\"item-name-static\">\n      Control 1 \n    <\/div> <\/li>\n   <li class=\"item\"> \n    <div class=\"step-number-container\"> \n     <div class=\"step-number\">\n       2 \n     <\/div> \n    <\/div> \n    <div class=\"step-checkbox-container\"> \n     <div class=\"step-checkbox\"><\/div> \n    <\/div> \n    <div class=\"item-name-static\">\n      Control 2 \n    <\/div> <\/li>\n   <li class=\"item\"> \n    <div class=\"step-number-container\"> \n     <div class=\"step-number\">\n       3 \n     <\/div> \n    <\/div> \n    <div class=\"step-checkbox-container\"> \n     <div class=\"step-checkbox\"><\/div> \n    <\/div> \n    <div class=\"item-name-static\">\n      Control 3 \n    <\/div> <\/li>\n   <li class=\"item\"> \n    <div class=\"step-number-container\"> \n     <div class=\"step-number\">\n       4 \n     <\/div> \n    <\/div> \n    <div class=\"step-checkbox-container\"> \n     <div class=\"step-checkbox\"><\/div> \n    <\/div> \n    <div class=\"item-name-static\">\n      Control 4 \n    <\/div> <\/li>\n   <li class=\"item\"> \n    <div class=\"step-number-container\"> \n     <div class=\"step-number\">\n       5 \n     <\/div> \n    <\/div> \n    <div class=\"step-checkbox-container\"> \n     <div class=\"step-checkbox\"><\/div> \n    <\/div> \n    <div class=\"item-name-static\">\n      Control 5 \n    <\/div> <\/li> \n  <\/ul> \n <\/div> \n<\/section> \n<section id=\"assess-the-security-controls-effectiveness\"> \n <h2>Assess the security controls effectiveness<\/h2>\n <div class=\"text-content\">\n   Evaluate the effectiveness of the implemented security controls by performing assessments. Identify any gaps or weaknesses and document them for further analysis. Use this assessment to ensure that the implemented controls are aligned with the desired security objectives specified by NIST SP 800-171. \n <\/div> \n <div class=\"text-field-content form-field-content\"> \n  <div class=\"form-group\"> <label> Assessment Results <\/label> \n   <input type=\"text\" placeholder=\"Something will be typed here...\" disabled class=\"form-control\"> \n  <\/div> \n <\/div> \n<\/section> \n<section id=\"approval-security-controls-effectiveness\"> \n <h2>Approval: Security Controls Effectiveness<\/h2>\n <div class=\"approval-content\"> \n  <div class=\"header\"> \n   <div class=\"list-title\">\n    Will be submitted for approval:\n   <\/div> \n  <\/div> \n  <div class=\"approval-rule-subject-tasks-list\"> \n   <ul class=\"list\"> \n    <li> \n     <div class=\"approval-rule-subject-tasks-list-item\"> \n      <div class=\"item\"> \n       <div class=\"container\"> <span class=\"title\">Implement the security controls<\/span> \n        <div class=\"body\">\n         Will be submitted\n        <\/div> \n       <\/div> \n      <\/div> \n     <\/div> <\/li> \n   <\/ul> \n  <\/div> \n <\/div> \n<\/section> \n<section id=\"develop-plan-of-action-and-milestones-poam-based-on-assessment-findings\"> \n <h2>Develop Plan of Action and Milestones (POAM) based on assessment findings<\/h2>\n <div class=\"text-content\">\n   Based on the assessment findings, create a Plan of Action and Milestones (POAM) that outlines the necessary steps to address identified security control gaps. The POAM should include specific actions, responsible parties, target completion dates, and resource requirements. This plan will serve as a roadmap for remediation efforts. \n <\/div> \n <div class=\"textarea-field-content form-field-content\"> \n  <div class=\"form-group\"> <label> POAM <\/label> <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea> \n  <\/div> \n <\/div> \n<\/section> \n<section id=\"implement-action-plan-to-remediate-compliance-gaps\"> \n <h2>Implement action plan to remediate compliance gaps<\/h2>\n <div class=\"text-content\">\n   Execute the action plan outlined in the POAM to address the identified compliance gaps. Allocate necessary resources, engage responsible parties, and ensure that the remediation efforts are properly documented. Monitor the progress closely to stay on track and achieve the desired compliance objectives. \n <\/div> \n <div class=\"multi-select-content form-field-content\"> \n  <div class=\"form-group\"> <label> Action Plan Checklist <\/label> \n  <\/div> \n  <ul class=\"items\"> \n   <li class=\"item\"> \n    <div class=\"step-number-container\"> \n     <div class=\"step-number\">\n       1 \n     <\/div> \n    <\/div> \n    <div class=\"step-checkbox-container\"> \n     <div class=\"step-checkbox\"><\/div> \n    <\/div> \n    <div class=\"item-name-static\">\n      Step 1 \n    <\/div> <\/li>\n   <li class=\"item\"> \n    <div class=\"step-number-container\"> \n     <div class=\"step-number\">\n       2 \n     <\/div> \n    <\/div> \n    <div class=\"step-checkbox-container\"> \n     <div class=\"step-checkbox\"><\/div> \n    <\/div> \n    <div class=\"item-name-static\">\n      Step 2 \n    <\/div> <\/li>\n   <li class=\"item\"> \n    <div class=\"step-number-container\"> \n     <div class=\"step-number\">\n       3 \n     <\/div> \n    <\/div> \n    <div class=\"step-checkbox-container\"> \n     <div class=\"step-checkbox\"><\/div> \n    <\/div> \n    <div class=\"item-name-static\">\n      Step 3 \n    <\/div> <\/li>\n   <li class=\"item\"> \n    <div class=\"step-number-container\"> \n     <div class=\"step-number\">\n       4 \n     <\/div> \n    <\/div> \n    <div class=\"step-checkbox-container\"> \n     <div class=\"step-checkbox\"><\/div> \n    <\/div> \n    <div class=\"item-name-static\">\n      Step 4 \n    <\/div> <\/li>\n   <li class=\"item\"> \n    <div class=\"step-number-container\"> \n     <div class=\"step-number\">\n       5 \n     <\/div> \n    <\/div> \n    <div class=\"step-checkbox-container\"> \n     <div class=\"step-checkbox\"><\/div> \n    <\/div> \n    <div class=\"item-name-static\">\n      Step 5 \n    <\/div> <\/li> \n  <\/ul> \n <\/div> \n<\/section> \n<section id=\"monitor-the-security-controls-on-a-continuous-basis\"> \n <h2>Monitor the security controls on a continuous basis<\/h2>\n <div class=\"text-content\">\n   Establish a process for ongoing monitoring of the implemented security controls. Regularly review the effectiveness and adequacy of controls to identify any changes or issues that may impact compliance. This continuous monitoring ensures that the security posture remains aligned with the evolving threat landscape and compliance requirements. \n <\/div> \n <div class=\"text-field-content form-field-content\"> \n  <div class=\"form-group\"> <label> Monitoring Process <\/label> \n   <input type=\"text\" placeholder=\"Something will be typed here...\" disabled class=\"form-control\"> \n  <\/div> \n <\/div> \n<\/section> \n<section id=\"document-system-changes-and-reassess-security-controls\"> \n <h2>Document system changes and reassess security controls<\/h2>\n <div class=\"text-content\">\n   Document any changes or updates made to the Information Systems and reassess the effectiveness of the implemented security controls. Evaluate whether the changes introduce new risks or require adjustments to the existing controls. It is essential to maintain an accurate record of system changes to ensure compliance and facilitate future assessments. \n <\/div> \n <div class=\"date-field-content form-field-content\"> \n  <div class=\"form-group\"> <label> Date of System Change <\/label> \n   <div class=\"date-container\"> <button type=\"button\" disabled class=\"btn btn-default\"> <i class=\"fa fa-calendar btn-icon\"><\/i> Date will be set here <\/button> \n   <\/div> \n  <\/div> \n <\/div> \n<\/section> \n<section id=\"perform-annual-system-review\"> \n <h2>Perform annual system review<\/h2>\n <div class=\"text-content\">\n   Conduct an annual review of the Information Systems and associated security controls to validate their ongoing effectiveness. Assess whether the controls are still aligned with NIST SP 800-171 requirements and adjust them as necessary. This review helps in identifying any emerging vulnerabilities or changes in the threat landscape. \n <\/div> \n <div class=\"text-field-content form-field-content\"> \n  <div class=\"form-group\"> <label> Review Findings <\/label> \n   <input type=\"text\" placeholder=\"Something will be typed here...\" disabled class=\"form-control\"> \n  <\/div> \n <\/div> \n<\/section> \n<section id=\"approval-annual-system-review\"> \n <h2>Approval: Annual System Review<\/h2>\n <div class=\"approval-content\"> \n  <div class=\"header\"> \n   <div class=\"list-title\">\n    Will be submitted for approval:\n   <\/div> \n  <\/div> \n  <div class=\"approval-rule-subject-tasks-list\"> \n   <ul class=\"list\"> \n    <li> \n     <div class=\"approval-rule-subject-tasks-list-item\"> \n      <div class=\"item\"> \n       <div class=\"container\"> <span class=\"title\">Monitor the security controls on a continuous basis<\/span> \n        <div class=\"body\">\n         Will be submitted\n        <\/div> \n       <\/div> \n      <\/div> \n     <\/div> <\/li> \n   <\/ul> \n  <\/div> \n <\/div> \n<\/section> \n<section id=\"update-the-system-security-plan-ssp-as-required\"> \n <h2>Update the System Security Plan (SSP) as required<\/h2>\n <div class=\"text-content\">\n   Update the System Security Plan (SSP) based on any changes made to the Information Systems or security controls. The SSP serves as the comprehensive documentation of the security controls and their implementation details. Ensure that the SSP accurately reflects the current state of the systems and adheres to the NIST SP 800-171 requirements. \n <\/div> \n <div class=\"date-field-content form-field-content\"> \n  <div class=\"form-group\"> <label> Date of SSP Update <\/label> \n   <div class=\"date-container\"> <button type=\"button\" disabled class=\"btn btn-default\"> <i class=\"fa fa-calendar btn-icon\"><\/i> Date will be set here <\/button> \n   <\/div> \n  <\/div> \n <\/div> \n<\/section> \n<section id=\"prepare-for-independent-audit-of-the-compliance-program\"> \n <h2>Prepare for independent audit of the compliance program<\/h2>\n <div class=\"text-content\">\n   Prepare the necessary documentation and evidence to undergo an independent audit of the compliance program. Ensure that all relevant records, reports, and certifications are readily available and organized. Thoroughly review the compliance program to identify any potential gaps or weaknesses before the audit takes place. \n <\/div> \n <div class=\"file-field-content form-field-content\"> \n  <div class=\"form-group\"> <label> Audit Documents <\/label> \n   <div class=\"file-container\"> <button type=\"button\" disabled class=\"btn btn-default\"> <i class=\"fa fa-upload btn-icon\"><\/i> File will be uploaded here <\/button> \n   <\/div> \n  <\/div> \n <\/div> \n<\/section> \n<section id=\"review-audit-findings-and-develop-a-remediation-plan\"> \n <h2>Review audit findings and develop a remediation plan<\/h2>\n <div class=\"text-content\">\n   Review the findings from the independent audit and assess any identified compliance deficiencies. Determine the impact of these deficiencies and develop a remediation plan to address them promptly. Consider the severity of each deficiency and allocate resources accordingly to ensure effective resolution. \n <\/div> \n <div class=\"text-field-content form-field-content\"> \n  <div class=\"form-group\"> <label> Audit Findings <\/label> \n   <input type=\"text\" placeholder=\"Something will be typed here...\" disabled class=\"form-control\"> \n  <\/div> \n <\/div> \n<\/section> \n<section id=\"approval-audit-findings-and-remediation-plan\"> \n <h2>Approval: Audit Findings and Remediation Plan<\/h2>\n <div class=\"approval-content\"> \n  <div class=\"header\"> \n   <div class=\"list-title\">\n    Will be submitted for approval:\n   <\/div> \n  <\/div> \n  <div class=\"approval-rule-subject-tasks-list\"> \n   <ul class=\"list\"> \n    <li> \n     <div class=\"approval-rule-subject-tasks-list-item\"> \n      <div class=\"item\"> \n       <div class=\"container\"> <span class=\"title\">Prepare for independent audit of the compliance program<\/span> \n        <div class=\"body\">\n         Will be submitted\n        <\/div> \n       <\/div> \n      <\/div> \n     <\/div> <\/li> \n   <\/ul> \n  <\/div> \n <\/div> \n<\/section> \n<section id=\"implement-the-remediation-plan-to-address-any-compliance-deficiencies\"> \n <h2>Implement the remediation plan to address any compliance deficiencies<\/h2>\n <div class=\"text-content\">\n   Execute the remediation plan developed in the previous task to resolve the identified compliance deficiencies. Allocate necessary resources, engage responsible parties, and monitor the progress closely to ensure timely and effective resolution. Document the steps taken and the outcomes achieved as part of the remediation efforts. \n <\/div> \n <div class=\"multi-select-content form-field-content\"> \n  <div class=\"form-group\"> <label> Remediation Plan Checklist <\/label> \n  <\/div> \n  <ul class=\"items\"> \n   <li class=\"item\"> \n    <div class=\"step-number-container\"> \n     <div class=\"step-number\">\n       1 \n     <\/div> \n    <\/div> \n    <div class=\"step-checkbox-container\"> \n     <div class=\"step-checkbox\"><\/div> \n    <\/div> \n    <div class=\"item-name-static\">\n      Compliance Deficiency 1 \n    <\/div> <\/li>\n   <li class=\"item\"> \n    <div class=\"step-number-container\"> \n     <div class=\"step-number\">\n       2 \n     <\/div> \n    <\/div> \n    <div class=\"step-checkbox-container\"> \n     <div class=\"step-checkbox\"><\/div> \n    <\/div> \n    <div class=\"item-name-static\">\n      Compliance Deficiency 2 \n    <\/div> <\/li>\n   <li class=\"item\"> \n    <div class=\"step-number-container\"> \n     <div class=\"step-number\">\n       3 \n     <\/div> \n    <\/div> \n    <div class=\"step-checkbox-container\"> \n     <div class=\"step-checkbox\"><\/div> \n    <\/div> \n    <div class=\"item-name-static\">\n      Compliance Deficiency 3 \n    <\/div> <\/li>\n   <li class=\"item\"> \n    <div class=\"step-number-container\"> \n     <div class=\"step-number\">\n       4 \n     <\/div> \n    <\/div> \n    <div class=\"step-checkbox-container\"> \n     <div class=\"step-checkbox\"><\/div> \n    <\/div> \n    <div class=\"item-name-static\">\n      Compliance Deficiency 4 \n    <\/div> <\/li>\n   <li class=\"item\"> \n    <div class=\"step-number-container\"> \n     <div class=\"step-number\">\n       5 \n     <\/div> \n    <\/div> \n    <div class=\"step-checkbox-container\"> \n     <div class=\"step-checkbox\"><\/div> \n    <\/div> \n    <div class=\"item-name-static\">\n      Compliance Deficiency 5 \n    <\/div> <\/li> \n  <\/ul> \n <\/div> \n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>Establish a team responsible for NIST compliance Assign a team to be responsible for ensuring compliance with the NIST SP 800-171 guidelines. This team will play a crucial role in implementing and maintaining the necessary security controls to protect Federal Contract Information (FCI). They will be responsible for coordinating with relevant stakeholders, conducting regular assessments, [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"ep_exclude_from_search":false,"cover_icon_emoji":"\ud83d\udccb","cover_icon_url":"","tasks_count":"20","template_description":"","template_id":"lqB1NHM5eLzFyKp1lclOSg","task_0":"Establish a team responsible for NIST compliance","task_slug_0":"establish-a-team-responsible-for-nist-compliance","task_1":"Identify Information Systems that store, process, or transmit Federal Contract Information","task_slug_1":"identify-information-systems-that-store-process-or-transmit-federal-contract-information","task_2":"Perform a comprehensive inventory of data, applications, and hardware","task_slug_2":"perform-a-comprehensive-inventory-of-data-applications-and-hardware","task_3":"Categorize the information system","task_slug_3":"categorize-the-information-system","task_4":"Approval: Information System Categorization","task_slug_4":"approval-information-system-categorization","task_5":"Select baseline security controls from NIST SP 800-53","task_slug_5":"select-baseline-security-controls-from-nist-sp-80053","task_6":"Implement the security controls","task_slug_6":"implement-the-security-controls","task_7":"Assess the security controls effectiveness","task_slug_7":"assess-the-security-controls-effectiveness","task_8":"Approval: Security Controls Effectiveness","task_slug_8":"approval-security-controls-effectiveness","task_9":"Develop Plan of Action and Milestones (POAM) based on assessment findings","task_slug_9":"develop-plan-of-action-and-milestones-poam-based-on-assessment-findings","task_10":"Implement action plan to remediate compliance gaps","task_slug_10":"implement-action-plan-to-remediate-compliance-gaps","task_11":"Monitor the security controls on a continuous basis","task_slug_11":"monitor-the-security-controls-on-a-continuous-basis","task_12":"Document system changes and reassess security controls","task_slug_12":"document-system-changes-and-reassess-security-controls","task_13":"Perform annual system review","task_slug_13":"perform-annual-system-review","task_14":"Approval: Annual System Review","task_slug_14":"approval-annual-system-review","task_15":"Update the System Security Plan (SSP) as required","task_slug_15":"update-the-system-security-plan-ssp-as-required","task_16":"Prepare for independent audit of the compliance program","task_slug_16":"prepare-for-independent-audit-of-the-compliance-program","task_17":"Review audit findings and develop a remediation plan","task_slug_17":"review-audit-findings-and-develop-a-remediation-plan","task_18":"Approval: Audit Findings and Remediation Plan","task_slug_18":"approval-audit-findings-and-remediation-plan","task_19":"Implement the remediation plan to address any compliance deficiencies","task_slug_19":"implement-the-remediation-plan-to-address-any-compliance-deficiencies","task_20":"","task_slug_20":"","task_21":"","task_slug_21":"","task_22":"","task_slug_22":"","task_23":"","task_slug_23":"","task_24":"","task_slug_24":"","task_25":"","task_slug_25":"","task_26":"","task_slug_26":"","task_27":"","task_slug_27":"","task_28":"","task_slug_28":"","task_29":"","task_slug_29":"","task_30":"","task_slug_30":"","task_31":"","task_slug_31":"","task_32":"","task_slug_32":"","task_33":"","task_slug_33":"","task_34":"","task_slug_34":"","task_35":"","task_slug_35":"","task_36":"","task_slug_36":"","task_37":"","task_slug_37":"","task_38":"","task_slug_38":"","task_39":"","task_slug_39":"","task_40":"","task_slug_40":"","task_41":"","task_slug_41":"","task_42":"","task_slug_42":"","task_43":"","task_slug_43":"","task_44":"","task_slug_44":"","task_45":"","task_slug_45":"","task_46":"","task_slug_46":"","task_47":"","task_slug_47":"","task_48":"","task_slug_48":"","task_49":"","task_slug_49":"","task_50":"","task_slug_50":"","task_51":"","task_slug_51":"","task_52":"","task_slug_52":"","task_53":"","task_slug_53":"","task_54":"","task_slug_54":"","task_55":"","task_slug_55":"","task_56":"","task_slug_56":"","task_57":"","task_slug_57":"","task_58":"","task_slug_58":"","task_59":"","task_slug_59":"","task_60":"","task_slug_60":"","task_61":"","task_slug_61":"","task_62":"","task_slug_62":"","task_63":"","task_slug_63":"","task_64":"","task_slug_64":"","task_65":"","task_slug_65":"","task_66":"","task_slug_66":"","task_67":"","task_slug_67":"","task_68":"","task_slug_68":"","task_69":"","task_slug_69":"","task_70":"","task_slug_70":"","task_71":"","task_slug_71":"","task_72":"","task_slug_72":"","task_73":"","task_slug_73":"","task_74":"","task_slug_74":"","task_75":"","task_slug_75":"","task_76":"","task_slug_76":"","task_77":"","task_slug_77":"","task_78":"","task_slug_78":"","task_79":"","task_slug_79":"","task_80":"","task_slug_80":"","task_81":"","task_slug_81":"","task_82":"","task_slug_82":"","task_83":"","task_slug_83":"","task_84":"","task_slug_84":"","task_85":"","task_slug_85":"","task_86":"","task_slug_86":"","task_87":"","task_slug_87":"","task_88":"","task_slug_88":"","task_89":"","task_slug_89":"","task_90":"","task_slug_90":"","task_91":"","task_slug_91":"","task_92":"","task_slug_92":"","task_93":"","task_slug_93":"","task_94":"","task_slug_94":"","task_95":"","task_slug_95":"","task_96":"","task_slug_96":"","task_97":"","task_slug_97":"","task_98":"","task_slug_98":"","task_99":"","task_slug_99":"","footnotes":""},"categories":[74,57],"tags":[],"class_list":["post-31845","post","type-post","status-publish","format-standard","hentry","category-compliance","category-information-security"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts\/31845","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/comments?post=31845"}],"version-history":[{"count":0,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts\/31845\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/media?parent=31845"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/categories?post=31845"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/tags?post=31845"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}