Jay Gallman
Risk Advisor
Duke University
Clifford Lynch
Executive Director
Coalition for Networked Information
The National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, outlines security standards for the protection of sensitive information. The publication “provides recommended security requirements for protecting the confidentiality of Controlled Unclassified Information (CUI) when the information is resident in nonfederal systems and organizations.”
A working group from the EDUCAUSE Higher Education Information Security Council (HEISC) 800-171 Compliance Community Group has published a toolkit to help higher education institutions cope with some of the challenges the publication poses.
In this conversation, CNI Executive Director Clifford Lynch and Duke University’s Jay Gallman (a toolkit author) discuss the implications of NIST SP-800 for higher education, how the toolkit was developed, who has contributed to it, and how institutions can best make use of it in their compliance efforts.
References:
NIST SP 800-171: What Is the NIST SP 800-171 and Who Needs to Follow It? | NIST
DoD CUI Program: Home (dodcui.mil)
CUI Awareness and Marking: CI Policy Publications Update (dodcui.mil)
Cybersecurity Maturity Model Certification: CMMC Model (defense.gov)
Federal Student Aid: Protecting Student Information – Compliance with CUI and GLBA | Knowledge Center
EDUCAUSE: HEISC 800-171 Community Group | EDUCAUSE – nearly 600 members
NIST SP 800-171 Toolkit | EDUCAUSE Library
Higher Education Regulated Research Workshop Series: A Collective Perspective | EDUCAUSE Library
EDUCAUSE and the Regulated Research Community of Practice SSP Workshop Regulated Research Community of Practice – SSP
NSPM 33 GUIDANCE FOR IMPLEMENTING NATIONAL SECURITY PRESIDENTIAL MEMORANDUM 33 (NSPM-33) ON NATIONAL SECURITY STRATEGY FOR UNITED STATES GOVERNMENT-SUPPORTED RESEARCH AND DEVELOPMENT (whitehouse.gov)
Fact Sheet: Office of the National Cyber Director Requests Public Comment on Harmonizing Cybersecurity Regulations | ONCD | The White House