---
title: Tips on Tackling the 14 Requirements for Becoming NIST Compliant
description: Businesses that process, store, or transmit covered defense information are required to implement the NIST 800-171 security framework.
image: https://www.aemcorp.com/hubfs/AEM%20Micro%20website/Defense/Images/Blog/NIST-Compliant-preview.jpg
---

[![AEM Blue](https://www.aemcorp.com/hubfs/AEM_Corp_February2018_Theme%20/Images/98ebac2e-d85d-11e6-bb14-0242ac110005.AEM-Logo-Color-regular_image.png)](https://www.aemcorp.com/clients-defense-and-intelligence-agencies)

## BLOG POST

# Tips on Tackling the 14 Requirements for Becoming NIST Compliant

![](https://www.aemcorp.com/hubfs/AEM%20Micro%20website/Defense/Experts/Yong.O.jpg)

[Yong Oh](https://www.aemcorp.com/managedservices/blog/author/yong-oh)

### In October 2016, the Department of Defense (DoD) promulgated a final rule...

... implementing Defense Federal Acquisition Regulation Supplement (DFARS) clauses that apply to all contractors who process, store, or transmit “covered defense information.” As a result, many businesses are required to implement the NIST 800-171 security framework.

Adopting the defense-in-depth methodology requires the implementation of the 14 families of controls leveraging existing practices and infrastructure. In addition, this creates opportunities to implement advanced solutions such as privilege management and next generation firewalls.  

All requirements in the NIST 800-171 are traced to NIST 800-53 and most controls require both a procedural and technical control to implement the procedure. Here are some important considerations when investigating NIST compliant controls.

**Control 1: Access Control**

The Access Control requirement is the most salient control in the NIST 800-171. In general, this control family specifies limiting system access to authorized users and making sure those users are only able to do specified actions based on job functions (also known as the principle of least functionality). Separation of duties through security groups and Access Control Lists (ACLs) can be applied to meet this control.

**Control 2: Awareness and Training**

Leadership and employees should receive[ security and awareness training](http://www.mindsharp.com/) on secure usage of the information systems. This is essential to satisfying NIST 800-171 requirements. Conducting mandatory annual security training and exercises is necessary to keep employees lucid and vigilant.

One common example of recommended training in the Defense community includes the Cyber Awareness Challenge [accessible through the DISA website](https://iase.disa.mil/eta/Pages/online-catalog.aspx).

**Control 3: Audit and Accountability**

NIST 800-71 Audit and Accountability requirements focus specifically on ensuring that an organization’s audit generation and reporting capabilities sufficiently support proper security monitoring and management.

**Control 4: Configuration Management**

Change is defined as the addition, modification, or removal of configuration items.  Processes and standard configurations promote systematic changes to maintain integrity over time.

**Control 5: Identification and Authentication**

Identification and authentication requirements ensure systems are properly identifying users and verifying their identity prior to granting any access. Multi-Factor Authentication can be a key component to meeting this control.

**Control 6: Incident Response**

Organizations should have operational incident-handling capabilities that include adequate preparation, detection, analysis, containment, recovery, and user response activities.

**Control 7: Maintenance**

System maintenance should be performed at regular intervals to protect organizational information systems from zero-day attacks and other vulnerabilities.

**Control 8: Media Protection**

On-premise media should be physically protected and monitored to adequately prevent loss or theft.    

**Control 9: Personnel Security**

Verifying and validating personnel though background checks and other vetting processes are important steps to onboarding procedures.   

**Control 10: Physical Protection**

Physical protection can be enforced with alarm systems, locks, and security cameras.  

**Control 11: Risk Assessment**

Standard assessments are needed to identify risks related to procedures, functions, and information systems. Implementing standard controls and security scans can be used to stay abreast of system vulnerabilities.  

**Control 12: Security Assessment**

Auditing controls, processes, and procedures should be completed to validate that the security posture meets the NIST standards. An outside assessment can also be a validation of the security framework.    

**Control 13: System and Communications Protection**

Highly secure firewalls should guard the perimeter of your organization and provide intrusion prevention/detection capabilities. Segmented networks are another best practice for both security and performance.

**Control 14: System and Information Integrit****y**

Keeping antivirus signatures up to date while scanning for viruses and malware is an essential step in maintaining system and information integrity. Malicious websites should be filtered with access denied from corporate resources.    

[Let us know](mailto:managedservices@aemcorp.com) if we can help! Understanding the NIST compliance controls can be both challenging and daunting, but AEM can help interpret how these controls can be applied to your environment to create both a compliant and secure infrastructure.

---

[Meet Yong Oh ![](https://www.aemcorp.com/hubfs/AEM%20Micro%20website/Images/Homepage/right-arrow.svg) ![](https://www.aemcorp.com/hubfs/AEM%20Micro%20website/Images/Homepage/right-arrow%20-%20hover.svg) ](https://www.aemcorp.com/managedservices/blog/author/yong-oh)

## RECOMMENDED BLOG POSTS

[![](https://www.aemcorp.com/hubfs/Stylized%20computer%20security.jpg)](https://www.aemcorp.com/managedservices/blog/installing-oracle-access-management-12.2.1.4)

### [Installing Oracle Access Management 12.2.1.4](https://www.aemcorp.com/managedservices/blog/installing-oracle-access-management-12.2.1.4)

Oracle Access Management (OAM) is Oracle’s solution for user management. The software is part of the Fusion Middleware Infrastructure family and can be integrated with both Oracle and non-Oracle software. OAM provides an enterprise-level platform that delivers user authentication and single sign-on (SSO) capabilities in a simple web-based console. Access Manager SSO allows for entities to access multiple applications after authentication and reduces the need for multiple logins. 

---

[Read More ![](https://www.aemcorp.com/hubfs/AEM%20Micro%20website/Images/Homepage/right-arrow.svg) ![](https://www.aemcorp.com/hubfs/AEM%20Micro%20website/Images/Homepage/right-arrow%20-%20hover.svg) ](https://www.aemcorp.com/managedservices/blog/installing-oracle-access-management-12.2.1.4)

[![](https://www.aemcorp.com/hubfs/Technology%20touch%20screen.jpg)](https://www.aemcorp.com/managedservices/blog/5-lessons-for-finding-the-right-test-automation-software)

### [5 Lessons for Finding the Right Test Automation Software](https://www.aemcorp.com/managedservices/blog/5-lessons-for-finding-the-right-test-automation-software)

This is the second blog post in a two-part series examining test automation software. This blog post focuses on lessons learned for finding the right software product for your organization. We recommend you also read our first post, which is dedicated to [understanding the process for moving from manual to automated testing](https://www.aemcorp.com/managedservices/blog/5-keys-to-successful-test-automation).

---

[Read More ![](https://www.aemcorp.com/hubfs/AEM%20Micro%20website/Images/Homepage/right-arrow.svg) ![](https://www.aemcorp.com/hubfs/AEM%20Micro%20website/Images/Homepage/right-arrow%20-%20hover.svg) ](https://www.aemcorp.com/managedservices/blog/5-lessons-for-finding-the-right-test-automation-software)

[![](https://www.aemcorp.com/hubfs/Cartoon%20maze%20with%20small%20items.jpg)](https://www.aemcorp.com/managedservices/blog/5-keys-to-successful-test-automation)

### [5 Keys to Successful Test Automation](https://www.aemcorp.com/managedservices/blog/5-keys-to-successful-test-automation)

This blog post is the first in a two-part series on website testing automation that can help your organization better understand how to maximize the effectiveness of your tests and find the right tools to meet your needs. Below we offer insights that can help your organization improve its testing automation process. Our follow-on blog post will help your organization understand the [different software tools](https://www.aemcorp.com/managedservices/blog/5-lessons-for-finding-the-right-test-automation-software) available to begin automating your tests.

---

[Read More ![](https://www.aemcorp.com/hubfs/AEM%20Micro%20website/Images/Homepage/right-arrow.svg) ![](https://www.aemcorp.com/hubfs/AEM%20Micro%20website/Images/Homepage/right-arrow%20-%20hover.svg) ](https://www.aemcorp.com/managedservices/blog/5-keys-to-successful-test-automation)

[See All ![](https://www.aemcorp.com/hubfs/AEM%20Micro%20website/Images/Homepage/right-arrow%20-%20hover.svg) ![](https://www.aemcorp.com/hubfs/AEM%20Micro%20website/Images/Homepage/right-arrow%20-%20white.svg) ](https://www.aemcorp.com/managed-services/blog)

![Property 1=9001](https://www.aemcorp.com/hs-fs/hubfs/Property%201=9001.jpg?width=128&height=55&name=Property%201=9001.jpg)![Property 1=20000-1](https://www.aemcorp.com/hs-fs/hubfs/Property%201=20000-1.jpg?width=128&height=55&name=Property%201=20000-1.jpg)![Property 1=27001](https://www.aemcorp.com/hs-fs/hubfs/Property%201=27001.jpg?width=128&height=55&name=Property%201=27001.jpg)![AEM Corp-CMMI-SVC3-GrayBox](https://www.aemcorp.com/hs-fs/hubfs/Certification%20Logos/AEM%20Corp-CMMI-SVC3-GrayBox.png?width=187&name=AEM%20Corp-CMMI-SVC3-GrayBox.png)![AEM Corp-CMMI-Dev3-GrayBox](https://www.aemcorp.com/hs-fs/hubfs/Certification%20Logos/AEM%20Corp-CMMI-Dev3-GrayBox.png?width=188&name=AEM%20Corp-CMMI-Dev3-GrayBox.png)![Trustmark-Plus_Security_02](https://www.aemcorp.com/hs-fs/hubfs/Trustmark-Plus_Security_02.png?width=128&name=Trustmark-Plus_Security_02.png)![msep-logo-v2-300x249](https://www.aemcorp.com/hs-fs/hubfs/msep-logo-v2-300x249.webp?width=73&height=61&name=msep-logo-v2-300x249.webp)

 

![Aem](https://www.aemcorp.com/hs-fs/hubfs/AEM_Corp_February2018_Theme%20/Images/34c80814-c2eb-11e6-b351-0242ac110003.AEM-Logo-Color.png?width=285&name=34c80814-c2eb-11e6-b351-0242ac110003.AEM-Logo-Color.png)

© 2026 AEM Corporation