When it comes to complying with NIST SP 800-171 Rev 3, it is important to understand that words have specific meanings:
A policy defines high-level management intent and governance expectations. This can be as simple as a few sentences.
A standard defines mandatory, measurable requirements that must be implemented (e.g., password length, initial training requirements, background checks, etc.).
A procedure describes the repeatable steps personnel use to perform the required activity (e.g., change management requests, password resets, log reviews, etc.).
For NIST SP 800-171, all three matter because assessors need to see that Controlled Unclassified Information (CUI) protection is governed, implemented and repeatable.
Relevant ComplianceForge Resources:
· ComplianceForge NIST 800-171 & CMMC Compliance Documentation: https://complianceforge.com/cybersecurity-templates/nist-800-171-compliance
· NIST 800-171 R2 to R3 Transition Guide: https://complianceforge.com/start-here/nist-800-171-cmmc---where-do-i-start/nist-800-171-r3-transition-guide
Authoritative Sources:
· NIST SP 800-171 Rev. 3: https://csrc.nist.gov/pubs/sp/800/171/r3/fina
· NIST SP 800-171A Rev. 3: https://csrc.nist.gov/pubs/sp/800/171/a/r3/final