This lesson offers an introduction to the material which is NIST SP 800-171. This course will cover the following: • What is CUI? • What is NIST SP 800-171? • Why do we need it? • What are the requirements?

All right, let's go ahead and get started. So we're gonna start off with the main one and go over just a little bit of preliminary information about 1 71 So, like we said, this comes to us from the National Institute of Standards and Technologies. It's a special publication 800-171
And in this section, we're gonna talk about what is C u Y. Which stands for controlled
but unclassified information. Then we're gonna talk about what Missed special publication 800-1 71 is and why we needed. And then we'll have a very high level move on to talking about the requirements.
All right, so what is C U I again? It is con controlled, but unclassified information. If you're remember a while back. S B u ah was very popular, sensitive, but unclassified information there were sort of various categories underneath that heading
so down. See why has replaced all of those elements of sensitive but unclassified. And ultimately, what it's gonna do is it's gonna deal with information that still has the need to be controlled, needs to be protected. We need to control how that information is disseminated,
making sure that it's in compliance with regulations and laws and any sort of policies along those lines.
Ultimately, it's going to be information that's in the best interest of the government to be protected, though it's not classified. So that's what See you, I is. It very much goes hand in hand with what used to be sensitive but unclassified information as you. And ultimately it's information the federal government
believe should be protected,
though not classified. Well, then, what is? Miss Special Publication 800-1 71 tells us how to safeguard that information. Okay, so ultimately, this focuses on protecting the confidentiality of see why
so when see why is resident in non federal information systems in organizations
so information still relevant to the government?
Those not specifically though, information that's not specifically house on a federal system.
Ah, when the information with see why resides eyes not operated by contractor. So again, really, this element of outside the federal agency, including contractors working for the federal agency and also in elements, were there no
specific requirements
that dictate how the information is safeguarded. So this is kind of the standard approach that we would take to protect that type of information.
All right, Why do we need it? Well, we have to figure out again how to provide for confidentiality of this information. So we're gonna talk about, you know, this is going to drive how developers produce the software,
how they implement security within the stages of the life cycle, how they designed in security.
It'll help project managers and program managers with their approach individuals that have toe act was it that are responsible for acquisition of certain systems or that are responsible for procurement, outsourcing,
um, individuals with information system or security or risk management responsibilities, which really, in a lot of ways,
cover so many of us. It's gonna help us provide and understand the guidelines.
And also, anyone responsible for securities has men's vulnerability assessments, pen testing, monitoring, auditing and assessors. So this covers a very wide group of people that can benefit from this special publication. 800-1 71
