NIST SP 800-171 Security Requirement Mapping

The same 134 settings read against NIST SP 800-171 Revision 2, the requirements CMMC Level 2 assesses. It is the companion to the 800-53 mapping, derived from its assignments, and organized by requirement.


What it finds:

32 settings close, narrow, or withhold a channel that can carry CUI on a current Windows 11 device. Each is listed, so it can be examined rather than a count taken on trust. Section 5.2 (opens in a new tab)

No requirement is MET on the strength of the baseline. The settings reach 19 of the 53 assessment objectives in the requirements they are first assigned to, and the other 34 remain the organization's to supply. Section 4 (opens in a new tab)

Every setting is traced through NIST's own tailoring tables. 84 carried forward directly, 14 through a second control, and 36 were re-read by judgment. Section 5.1 (opens in a new tab)

Three verdicts change from the 800-53 mapping. Defender cloud protection and Find My Device become the organization's decisions, and the tension in declining automatic updates moves from flaw remediation into change control. Section 6 (opens in a new tab) and Section 7 (opens in a new tab)

Read it on GitHub (opens in a new tab)