Quick-reference card
| Field | Value |
|---|---|
| Control ID | PM-17 |
| Control Name | Protecting Controlled Unclassified Information on External Systems |
| Framework | NIST SP 800-53 Revision 5 |
| Control Family | Program Management |
| Baselines | PRIVACY |
| Relevance | Organization (First Party) |
| Risk Severity | Medium |
What this control requires
PM-17 requires your organization to create and enforce policy and procedures that protect controlled unclassified information (CUI) whenever it’s processed, stored, or transmitted on systems outside your direct control. This control addresses a gap many federal agencies and their contractors overlook: the moment CUI leaves your internal environment, you need formal governance ensuring that external systems meet the same protection standards mandated by law, executive orders, and federal regulations.
In practice, PM-17 demands two things. First, you must establish documented policy and procedures that align CUI handling on external systems with applicable legal and regulatory requirements, including the governing regulation 32 CFR 2002. Second, you must review and update those policies on a defined schedule. The control sits within the Program Management family of NIST SP 800-53, meaning it operates at the organizational level rather than the individual system level.
The underlying intent is accountability. Without a formal policy framework, CUI protection on external systems becomes ad hoc, dependent on informal agreements or assumptions about how contractors and partners handle sensitive information. PM-17 eliminates that ambiguity by requiring explicit, enforceable documentation that ties external system usage to the safeguarding and dissemination requirements defined by the National Archives and Records Administration (NARA). This is particularly important because the Program Management family sets the organizational baseline that all system-level controls build upon.
Why it matters
Most organizations that handle CUI focus their protection efforts on internal systems while treating external systems as someone else’s problem. PM-17 exists because that assumption creates a compliance gap, and auditors know it. When your CUI protection policy doesn’t extend to contractor laptops, cloud platforms, or partner environments, you’ve created an undocumented risk surface that no amount of technical controls can compensate for.
The compliance risk is direct. Federal agencies and defense contractors operating under DFARS clauses must demonstrate that CUI protections follow the data, not just the perimeter. A missing or outdated PM-17 policy can result in audit findings, corrective action plans, or loss of authorization to process CUI. For contractors pursuing Cybersecurity Maturity Model Certification (CMMC), the absence of documented CUI handling procedures for external systems is a clear deficiency.
Beyond audit exposure, the operational risk is significant. CUI categories span everything from law enforcement sensitive data to export-controlled technical information. When these categories land on external systems without formalized protections, the organization loses visibility into how that information is stored, shared, and eventually disposed of. The requirements in NIST SP 800-171 reinforce this point by specifying security controls for nonfederal systems that process CUI.
What attackers exploit
- Contractor and subcontractor systems with no formal CUI handling agreements, leaving sensitive data on endpoints with inconsistent security baselines
- Cloud storage services adopted by project teams without contractual CUI protections in place
- Gaps between policy review cycles, where external system configurations drift out of compliance without detection
- Shared collaboration platforms where CUI is uploaded alongside unclassified content, bypassing marking and dissemination requirements
- Terminated vendor relationships where CUI disposition procedures were never established or enforced
- Personal devices used for remote work that process CUI without documented authorization or minimum security baselines
How to implement
For your organization
The most common failure mode with PM-17 isn’t the absence of a CUI policy. It’s a policy that covers internal systems thoroughly while treating external systems as a footnote. Your implementation needs to treat external CUI handling as a first-class governance concern, not an appendix to your existing information security policy.
Step 1: Define scope and applicability. Identify every external system category where CUI is processed, stored, or transmitted. This includes contractor-owned endpoints, cloud service providers, collaboration tools, managed service providers, and partner-operated environments. Map each category against the CUI categories your organization handles, using the NARA CUI Registry as your reference taxonomy.
Step 2: Develop the CUI protection policy for external systems. Your policy must explicitly address the safeguarding and dissemination requirements codified in 32 CFR 2002, with specific attention to section 2002.14h, which governs CUI on systems external to the designating agency. The policy should define authorized external system categories, minimum security requirements for each category, and the approval process for CUI processing on new external systems.
Step 3: Establish contractual requirements. Every agreement with an external party that will handle CUI needs explicit contract language. This language should reference the applicable CUI categories, required security controls, incident notification timelines, and data disposition obligations. Your NIST 800-53 compliance checklist should include a review of these contractual provisions.
Step 4: Define procedures for ongoing compliance. Procedures should cover how external system operators demonstrate compliance, how your organization verifies their adherence, and how deviations are reported and remediated. Include specific guidance on CUI marking requirements, access controls, and transmission protections for external environments.
Step 5: Set and follow a review cadence. PM-17 requires periodic review and update of both the policy and procedures. Establish a review frequency that aligns with your organization’s risk posture. Annual reviews are common, but significant changes in your external system landscape or regulatory requirements should trigger off-cycle updates.
Common tooling categories that support PM-17 implementation include document management systems for policy version control, contract lifecycle management platforms for tracking CUI-related clauses, and governance, risk, and compliance (GRC) tools for monitoring review schedules and tracking policy acknowledgments.
Common mistakes to avoid:
- Writing a generic information security policy and assuming it covers CUI on external systems without specific provisions
- Failing to reference 32 CFR 2002 and applicable CUI category requirements in the policy
- Omitting disposition and data destruction requirements for CUI held on external systems
- Treating policy review as a calendar exercise without evaluating whether the external system landscape has changed
Evidence examples
| Evidence Type | Example Artifact |
|---|---|
| CUI protection policy | Organizational policy defining CUI safeguarding, dissemination, and handling requirements for external systems, aligned with 32 CFR 2002 |
| CUI handling procedures | Step-by-step procedures for authorizing, monitoring, and revoking CUI processing on contractor systems, cloud platforms, and partner environments |
| Contractual provisions | Sample contract language or FAR/DFARS clauses requiring external parties to implement CUI protections consistent with organizational policy |
| Policy review records | Dated review logs showing policy and procedure updates at the defined frequency, with approval signatures and change summaries |
| CUI category mapping | Inventory mapping CUI categories handled by the organization to the specific external systems authorized to process each category |
| External system authorization records | Approval documentation for each external system authorized to store or transmit CUI, including the security assessment basis |
Cross-framework mapping
No applicable cross-framework mappings for this control.
Related controls
- CA-06 — Authorization: Governs the formal authorization of systems, which is a prerequisite for processing CUI on external systems.
- PM-10 — Authorization Process: Defines the organizational authorization process that PM-17 policies must align with.
Frequently asked questions
What is NIST SP 800-53 PM-17?
PM-17 requires organizations to establish and maintain policy and procedures that protect controlled unclassified information processed, stored, or transmitted on external systems. The control operates at the organizational level within the Program Management family and applies to the PRIVACY baseline. It mandates alignment with applicable laws and regulations, particularly the safeguarding requirements in 32 CFR 2002, and requires periodic review of both the CUI protection policy and its associated procedures.
What happens if PM-17 is not implemented?
Without PM-17, your organization lacks documented governance over how CUI is protected on contractor systems, cloud platforms, and other external environments. This gap creates audit findings during NIST SP 800-53 assessments and can jeopardize your authorization to process CUI. For defense contractors, the absence of a CUI protection policy covering external systems directly impacts DFARS compliance and CMMC readiness, potentially affecting contract eligibility.
How do you audit PM-17?
Auditors verify PM-17 by confirming that a CUI protection policy and CUI handling procedures exist and address external system requirements consistent with 32 CFR 2002. They’ll check that the policy covers safeguarding and dissemination requirements for CUI categories processed on external systems. Auditors also examine review records to confirm that both the policy and procedures are updated at the organization-defined frequency, looking for dated approvals and documented change histories.
What is controlled unclassified information under NIST?
Controlled unclassified information is government-created or government-possessed information that requires safeguarding or dissemination controls under law, regulation, or government-wide policy, but isn’t classified. NARA maintains the CUI Registry, which defines the specific categories and subcategories of CUI along with their handling requirements. Under NIST SP 800-53, controls like PM-17 establish the policy framework ensuring these protections extend to systems outside the originating organization’s direct control.