Cyber Posture

NIST 800-53 r5 · Controls catalogue · Family PM

PM-17Protecting Controlled Unclassified Information on External Systems

Establish policy and procedures to ensure that requirements for the protection of controlled unclassified information that is processed, stored or transmitted on external systems, are implemented in accordance with applicable laws, executive orders, directives, policies, regulations, and standards; and Review and update the policy and procedures {{ insert: param, pm-17_prm_1 }}.

Last updated: 09 May 2026 03:25 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (0)

Weaknesses this control addresses (6)AI

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-200Exposure of Sensitive Information to an Unauthorized Actor10,204Policies mandate protection of CUI on external systems, directly reducing unauthorized exposure of sensitive information.
CWE-319Cleartext Transmission of Sensitive Information1,042Enforces safeguards against cleartext transmission of CUI when data leaves organizational boundaries to external systems.
CWE-668Exposure of Resource to Wrong Sphere779Drives controls that keep sensitive CUI from being exposed to external systems as an unintended sphere.
CWE-311Missing Encryption of Sensitive Data552Requires encryption and similar controls for CUI processed or stored externally, preventing missing encryption of sensitive data.
CWE-552Files or Directories Accessible to External Parties540Procedures ensure CUI files and resources are not made accessible to external parties without required protections.
CWE-922Insecure Storage of Sensitive Information421Policy explicitly addresses insecure storage of CUI on external systems, requiring compliant handling and protections.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
No CVEs annotated to this control yet — the per-CVE backfill is in progress.

Other controls in family PM

PM-1 PM-10 PM-11 PM-12 PM-13 PM-14 PM-15 PM-16 PM-18 PM-19 PM-2 PM-20 PM-21 PM-22 PM-23 PM-24 PM-25 PM-26 PM-27 PM-28 PM-29 PM-3 PM-30 PM-31 PM-32 PM-4 PM-5 PM-6 PM-7 PM-8 PM-9