Topic · 15 articles
NIST 800-171
Every MacZine article on NIST 800-171, newest first - written, reviewed and versioned in the open.
CUI Sprawl Is the Scope Creep Nobody Diagrams
A correctly scoped CUI enclave still leaks through tickets, meeting transcripts, and test copies. NIST 800-171 3.1.3 closes it - stricter marking can't.
Home Office CUI Scope Starts at the Kitchen Table
NIST 800-171 physical protection assumes an office, not a house. Keep CUI off the remote endpoint and most of the control problem disappears.
STIG, CIS, or Your Own Build: What Counts as a Baseline
A DISA STIG, a CIS Benchmark, or your own build standard satisfies NIST 800-171 3.4.1 - if it's applied, evidenced, and watched for drift.
3.5.3: The MFA Control Most Programs Think They Already Passed
NIST 800-171 3.5.3 requires MFA for three scopes, not one. Most programs cover network logins and miss privileged local access - the one assessors test first.
What You Can Put on a POA&M, and What You Cannot
A POA&M restores no SPRS points and cannot carry the highest-weight controls. Here are the rules that decide what actually belongs on one.
How Many Documents Does CMMC Level 2 Actually Require?
NIST 800-171 names 110 requirements but no document count. Scoping a CMMC Level 2 documentation set is a governance decision - here is what the 110 imply.
The CMMC Levels Are Not a Ladder, and Only One Requires a Pen Test
Level 1, 2, and 3 test different things on different clocks. Only one requires a penetration test - here is which, and why the other two do not.
Your Training Records Are Compliance Evidence. Are They?
Three CMMC controls turn security awareness training into an evidence problem. Most organizations do the training and fail the control anyway.
FIPS 140-3 Is the Control That Fails Quietly
Encryption that is strong is not the same as encryption that is validated. The distinction costs 5 SPRS points and it is invisible until an assessor looks.
RMF and CMMC Are Not the Same Program. Run Them as One.
RMF authorizes a system, CMMC certifies a contractor. They ask overlapping questions in different vocabularies - and paying twice is the mistake.
The System Security Plan an Assessor Actually Reads
Most SSPs are written to be filed, not read. Here is how a C3PAO assessor moves through the document, and what they are checking at each stop.
How Your SPRS Score Is Actually Calculated
The DoD Assessment Methodology scores 110 controls on a 5/3/1 weighting and bottoms out at -203. Here is the arithmetic, and how a CO reads it.
CMMC Phase 2 Is Paused. Your Compliance Clock Isn't.
DoD paused CMMC Phase 2 certification to review the program - the DFARS and NIST 800-171 obligations under it did not. What to do during the review.
Freehold: Secure Comms You Hold Outright
Peer-to-peer encrypted chat, calls and 2 GB file transfer for small DIB teams - post-quantum, air-gap ready, 800-171 evidence built in. Free, open source.
The First 90 Days of a CMMC Level 2 Program
A practitioner's sequence for the first 90 days of CMMC Level 2: scope the CUI boundary, baseline against NIST 800-171, and start evidence discipline early.