How to read a requirement identifier
An identifier like 3.5.3 reads as section 3, family 5 (Identification and Authentication), requirement 3. The family number never changes, so 3.1.x is always Access Control. That stability is what makes an identifier worth citing in an audit record.
Access Control
22 requirementsWhat this family asks you to show: Who can reach the system, what they can do once they are in, and how remote and wireless access is limited.
Awareness and Training
3 requirementsWhat this family asks you to show: That the people using the system know the risks their role carries and have been trained for it.
Audit and Accountability
9 requirementsWhat this family asks you to show: That system activity is recorded, kept, and reviewable back to an individual user.
Configuration Management
9 requirementsWhat this family asks you to show: A known baseline for systems and software, and control over what changes against it.
Identification and Authentication
11 requirementsWhat this family asks you to show: That users and devices are identified, and that authentication is strong enough for what they access.
Incident Response
3 requirementsWhat this family asks you to show: A working process to detect, report, and respond to incidents, tested rather than assumed.
Maintenance
6 requirementsWhat this family asks you to show: Control over who performs maintenance, with what tools, and what happens to media during it.
Media Protection
9 requirementsWhat this family asks you to show: Protection, marking, transport, and sanitization of media that holds regulated information.
Personnel Security
2 requirementsWhat this family asks you to show: Screening before access is granted, and removal of access when people leave or move.
Physical Protection
6 requirementsWhat this family asks you to show: Limits on physical access to systems, equipment, and the facilities holding them.
Risk Assessment
3 requirementsWhat this family asks you to show: Periodic assessment of risk, vulnerability scanning, and remediation of what the scans find.
Security Assessment
4 requirementsWhat this family asks you to show: Assessing controls, building plans of action, and keeping a system security plan current.
System and Communications Protection
16 requirementsWhat this family asks you to show: Boundary protection, separation of duties in the architecture, and cryptography in transit and at rest.
System and Information Integrity
7 requirementsWhat this family asks you to show: Flaw remediation, malicious code protection, and monitoring for attacks and indicators.
Requirement titles and text are published by NIST. Overwatch 7Six reproduces identifiers and titles from NIST SP 800-171 Rev 2 and adds plain-language intent for working use. Consult the published standard as the authority.