Skip to main content
Course

NIST 800-171 Controls in Depth

All 110 NIST 800-171 controls, in depth: scope the environment, assess each one against its objectives, and write the documents an assessor will accept.

Intermediate

Level

4

Modules

8

Lessons

4

Graded quizzes

2

Assignments

10 hours

Estimated time

What you will be able to do

  • Explain what Controlled Unclassified Information (CUI) is and why NIST SP 800-171 exists to protect it on nonfederal systems
  • Navigate all 110 controls across the 14 families and read a control's number, intent, and expected implementation
  • Scope a CUI environment and sort assets into the categories that decide where the controls apply
  • Break any control into its assessment objectives using NIST SP 800-171A and choose the evidence that proves it
  • Judge whether a control is met or not met using the Examine, Interview, and Test methods, and back the finding with the right evidence
  • Write System Security Plan (SSP) control statements that describe how each control is actually implemented, not just that it is
  • Build and manage a Plan of Action and Milestones (POA&M) for the gaps that remain, with realistic milestones and completion dates, and explain how each open gap weighs on the assessment score

What is inside

4 modules, 8 lessons. Each module ends in a graded quiz and most carry an assignment.

  1. 01

    The Control Set and the CUI It Protects

    Before you can assess a single control, you need to know what NIST SP 800-171 is really for and how it is organized. This module explains Controlled Unclassified Information (CUI), the Defense Federal Acquisition Regulation Supplement (DFARS) clause that puts the requirements on contractors, and the shape of the standard: 14 families, 110 controls, and the numbering you will use every day. You will also see how the controls trace back to NIST SP 800-53 and where the newer Revision 3 is heading.

    2 lessons · 5 quiz questions

  2. 02

    Scoping a CUI Environment

    A control only matters where Controlled Unclassified Information (CUI) actually lives, so scoping is the step that makes every later decision easier or harder. In this module you follow CUI through a contractor's people, processes, and systems, draw the assessment boundary, and sort assets into the categories that decide how each one is treated. Getting scope right is how consultants keep an assessment focused and affordable.

    2 lessons · 5 quiz questions · assignment

  3. 03

    The 110 Controls, Family by Family, and How They Are Assessed

    This is the heart of the course: a deep, working tour of all 14 families and the intent behind each control. You will study the controls in plain language, then learn to read any one of them through NIST SP 800-171A, which breaks each control into assessment objectives with clear determination statements. By the end you can pick the right evidence and judge a control as met or not met, exactly as an assessor does.

    2 lessons · 5 quiz questions

  4. 04

    Writing the SSP and the POA&M

    Everything you have learned now becomes the two documents an assessment runs on. You will write System Security Plan (SSP) statements that describe how each control is really implemented, not just that it is, and you will build a Plan of Action and Milestones (POA&M) for the gaps that remain. You will also see how open gaps weigh on the assessment score, so you can help a client prioritize the work that matters most.

    2 lessons · 5 quiz questions · assignment