Compliance: NIST 800-171

Achieve NIST 800-171 compliance with Keeper

Protect Controlled Unclassified Information (CUI) with zero-knowledge encryption, identity-first access controls and auditable compliance aligned to NIST SP 800-171 requirements.

Need NIST 800-171 help?

carregando... carregando...
What is NIST 800-171?

What is NIST 800-171?

NIST SP 800-171 defines the security requirements for protecting Controlled Unclassified Information (CUI) in non-federal systems used by organizations that support U.S. government operations.

The standard outlines baseline controls, such as access control, authentication, auditing, incident response and encryption, to reduce cyber risk and prevent unauthorized access to sensitive information. By aligning with NIST 800-171, organizations can better protect CUI, strengthen their overall security posture and meet federal contract and compliance requirements.

How does Keeper help with NIST 800-171 compliance?

Zero-Trust Access Control for NIST 800-171

Keeper helps organizations support NIST 800-171 compliance by providing a zero-trust, identity-based security platform that protects Controlled Unclassified Information (CUI) through strong access control, authentication, encryption and auditing. Keeper enforces least privilege and separation of duties through role-based access controls (RBAC), centralized policy management and privileged access controls, ensuring only authorized users can access sensitive credentials and secrets used to protect or access CUI.

End-to-End Encryption and Auditable Access

All data stored in Keeper vaults is protected with end-to-end, zero-knowledge encryption using industry-standard cryptography, ensuring vault data is encrypted both at rest and in transit. Keeper integrates with enterprise identity providers to support Multi-Factor Authentication (MFA), replay-resistant authentication and centralized identity lifecycle management. Comprehensive audit logging, session controls and real-time security alerts provide accountability, traceability and monitoring aligned with NIST 800-171 requirements, while Keeper's cloud-based architecture helps reduce the attack surface and simplifies secure remote access without relying on traditional network perimeters.

Keeper features for NIST 800-171

Access Controls
Control Title
ID
Keeper Capability
Transaction & Function Control
3.1.2
Keeper's RBAC restricts access to CUI credentials and secrets by role, shared folder and administrative scope. Actions such as sharing, exporting or modifying secrets are explicitly controlled via policy enforcement.
Separation of Duties
3.1.4
Keeper supports administrative role separation so security administrators can manage users and policies without access to vault contents or encrypted data.
Least Privilege
3.1.5
Keeper enforces least privilege by granting users access only to required vault items and folders through granular permission controls.
Non-Privileged Account Use
3.1.6
Keeper enables standard user accounts for routine access and restricts elevated administrative functions to privileged roles assigned through RBAC.
Privileged Functions
3.1.7
Keeper restricts privileged functions such as policy enforcement, role assignment and vault administration to authorized users with administrative roles.
Session Termination
3.1.11
Keeper automatically terminates sessions after configurable inactivity timeouts and requires reauthentication when sessions expire.
Control Remote Access
3.1.12
Keeper provides secure remote access to credentials and secrets without exposing passwords, using identity verification and policy-based authorization.
Remote Access Confidentiality
3.1.13
Keeper protects remote access with end-to-end encryption, ensuring credentials and secrets are never transmitted or stored in plaintext.
Remote Access Routing
3.1.14
Keeper eliminates reliance on VPN-based routing by brokering access through encrypted vault retrieval, reducing unauthorized access paths.
Privileged Remote Access
3.1.15
KeeperPAM enables just-in-time access, approvals and automated credential rotation for privileged accounts.
Audit & Accountability
Control Title
ID
Keeper Capability
System Auditing
3.3.1
Keeper generates detailed, immutable audit logs for authentication events, vault access, session activity, sharing activity and administrative actions.
User Accountability
3.3.2
All actions in Keeper are uniquely attributable to individual users, providing full accountability for access to CUI.
Audit Correlation
3.3.5
Keeper audit logs can be exported or integrated with SIEM platforms to correlate events across enterprise security tools.
Reduction & Reporting
3.3.6
Keeper supports filtering, searching and reporting of audit logs to assist with incident investigation and compliance reporting.
Configuration Management (CM)
Control Title
ID
Keeper Capability
Security Configuration Enforcement
3.4.2
Keeper enforces centralized security policies such as MFA requirements, password complexity and sharing restrictions across the organization.
Access Restrictions for Change
3.4.5
Only authorized administrators can modify Keeper configurations, policies or integrations, with all changes fully logged.
Least Functionality
3.4.6
Keeper limits functionality to credential and secrets management and allows administrators to disable unnecessary features via policy controls.
Application Execution Policy
3.4.8
Keeper integrates with approved applications through APIs and SDKs, restricting secrets usage to authorized systems and workflows as defined by administrators.
Identification and Authentication (IA)
Control Title
ID
Keeper Capability
Identification [CUI Data]
3.5.1
Keeper ensures unique user identification through individual Keeper Vault accounts integrated with enterprise IdPs (SSO) and enforced MFA, providing auditable attribution of all access to CUI. Each access event is tied to a verified user identity, reducing shared credentials and strengthening accountability.
Authentication
3.5.2
Keeper enforces strong authentication using SSO integration, cryptographic key derivation, and policy-based access controls.
Multifactor Authentication
3.5.3
Keeper supports MFA using TOTP, push notifications, hardware security keys (FIDO2), and SSO-enforced MFA.
Replay-Resistant Authentication
3.5.4
Keeper uses encrypted challenge-response authentication and ephemeral session tokens resistant to replay attacks.
Password Complexity
3.5.7
Keeper enforces configurable password complexity policies and includes a built-in password and passphrase generator.
Password Reuse
3.5.8
Keeper reduces password reuse through visibility, reuse detection, and reporting across enterprise vaults.
Temporary Passwords
3.5.9
Keeper supports time-limited access through controlled sharing and just-in-time privileged access.
Cryptographically-Protected Passwords
3.5.10
All passwords and secrets are encrypted using zero-knowledge, client-side cryptography before storage or transmission.
Obscure Feedback
3.5.11
Keeper obscures sensitive authentication feedback and prevents password exposure on screen or in logs.
System & Communications Protection (SC)
Control Title
ID
Keeper Capability
Boundary Protection
3.13.1
Keeper enforces identity-based, zero-trust access controls instead of relying on traditional network boundaries.
Shared Resource Control
3.13.4
Keeper restricts access to shared vaults and folders to explicitly authorized users and roles.
Network Communication by Exception
3.13.6
Keeper requires explicit authorization for every access request and does not allow implicit network trust.
Data in Transit
3.13.8
Keeper encrypts all data in transit using TLS 1.2+ with strong cipher suites.
Connections Termination
3.13.9
Keeper automatically terminates sessions on logout, inactivity, or policy violations.
Key Management
3.13.10
Encryption keys are generated and managed client-side, ensuring Keeper cannot access customer keys.
CUI Encryption
3.13.11
Keeper encrypts vault data, including credentials used to access CUI using AES-256 and elliptic curve cryptography.
Data at Rest
3.13.16
All vault data is encrypted at rest with no plaintext storage.
System & Information Integrity (SI)
Control Title
ID
Keeper Capability
Security Alerts & Advisories
3.14.3
Keeper provides alerts for security events such as exposed credentials, weak passwords and high-risk privileged sessions.
Monitor Communications for Attacks
3.14.6
Keeper monitors for compromised credentials using dark web monitoring.
Identify Unauthorized Use
3.14.7
Keeper detects and logs anomalous access attempts and unauthorized activity within the vault environment.
Risk Assessment (RA)
Control Title
ID
Keeper Capability
Advanced Risk Identification
3.11.3e
Keeper identifies advanced risks by detecting credential exposure, anomalous access behavior, and indicators of compromise through monitoring and alerting.

Be ready for NIST 800-171 compliance

Secure your data and simplify compliance with Keeper

Retirar consentimento para cookiesValorizamos sua privacidade

Usamos cookies em nosso site para oferecer a melhor experiência de navegação, exibir anúncios personalizados sobre nossos produtos e conteúdo e analisar o tráfego do site. Para saber mais, consulte nossa Política de privacidade.

Registre-se para uma avaliação gratuita

Compre agora