1Overview
SC.L2-3.13.16 closes the System and Communications Protection family by protecting CUI where it sits. It requires that the confidentiality of CUI at rest be protected, so that stored CUI, on servers, workstations, drives, and backups, is safeguarded against unauthorized disclosure. It is a one-point requirement and may be deferred on a plan of action.
Much of the family protects CUI in motion, at boundaries and in transit; this control protects it at rest. Stored CUI can be disclosed if a drive is stolen, a backup is lost, or storage is accessed without authorization, so its confidentiality has to be protected where it resides. This is commonly achieved through encryption of data at rest, though other protections may apply, so that stored CUI is not readable by those who should not have it. The single assessment objective is that the confidentiality of CUI at rest is protected.
Protect the confidentiality of CUI at rest.
The requirement is to protect the confidentiality of CUI at rest, wherever it is stored. In practice this most often means encrypting CUI on the media that hold it, servers, workstations, portable drives, and backups, so that access to the storage does not yield readable CUI. The single assessment objective is that this confidentiality is protected. Where encryption is used, its strength is governed by the FIPS-validation requirement.
2The Assessment Objective
NIST SP 800-171A frames 3.13.16 as a single objective: protect the confidentiality of CUI at rest.
The confidentiality of CUI at rest is protected. Stored CUI is safeguarded against unauthorized disclosure.
The single objective is protecting CUI at rest. The common gap is CUI stored on some media without protection, portable drives, backups, or workstations, even where servers are protected. The assessor looks for the confidentiality of CUI protected across the places it is stored.
3Failure Patterns
The failures are about stored CUI left readable.
Unencrypted storage
CUI stored without encryption is disclosed if the media is stolen or accessed. Encrypting the storage protects its confidentiality.
Backups and portable media overlooked
Protecting CUI on primary servers while leaving backups and portable drives unencrypted leaves those copies exposed. Protection has to cover all the places CUI is stored.
Non-validated encryption
Encrypting CUI at rest with cryptography that is not FIPS-validated does not fully satisfy the accompanying validation requirement. The encryption should be validated.
4Ownership
This is an IT and security-owned technical control.
| Role | Responsibility for this control |
|---|---|
| IT and security | Protects CUI at rest, typically by encrypting storage. Owns the encryption evidence. |
| System administrator | Applies storage encryption across servers, workstations, and media. |
| Security or compliance lead | Confirms CUI at rest is protected across all storage locations. |
5Tooling
The control is delivered by encryption of data at rest across storage.
| Objective | Tooling | What it provides |
|---|---|---|
| servers and workstations | Full-disk and file encryption | Protected CUI on primary storage. |
| media and backups | Encrypted portable media and backups | Protected CUI on secondary storage. |
The caveat is that protection has to cover all the places CUI is stored, and the encryption should be FIPS-validated. Encrypting servers while leaving backups or portable drives in the clear leaves those copies exposed. The assessor examines whether CUI at rest is protected, so coverage across storage has to hold.
6Evidence
The satisfied version of 3.13.16 shows CUI protected across storage.
| Evidence | What it demonstrates |
|---|---|
| Storage encryption configuration | The objective. CUI at rest protected on servers and workstations. |
| Media and backup encryption | The objective. CUI protected on portable media and backups. |
The evidence should show the confidentiality of CUI at rest protected across the media that hold it. The storage encryption configuration together with media and backup encryption is the clearest demonstration of the control.
A stolen drive discloses CUI as surely as an intercepted message
Stored CUI is easy to overlook but just as exposed if the media is lost or accessed, so this control asks that its confidentiality at rest be protected across all storage. Encrypting CUI where it sits is part of the onsite readiness work this practice does.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.13.16. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objective 3.13.16. csrc.nist.gov
- 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov