NIST 800-171 Controls · System and Communications Protection
SC.2.016 — Protect Confidentiality of CUI at Rest
Protect the confidentiality of CUI at rest.
What SC.2.016 means in plain English
CUI sitting on a hard drive, USB stick, or file server must be encrypted even when nobody is actively using it. If someone steals a laptop, the encrypted hard drive is useless to them without the password. Use BitLocker to encrypt all hard drives on computers that store CUI. For removable media like USB drives, use BitLocker To Go. For cloud storage, ensure your provider encrypts data at rest (Microsoft 365 GCC does this by default). A stolen, unencrypted laptop with CUI is a reportable incident.
The assessment question
“Is CUI encrypted at rest on all storage media including workstation hard drives, server storage, removable media, and cloud storage using FIPS-validated encryption such as BitLocker?”
How to implement SC.2.016
- Enable BitLocker on all Windows workstations that store or process CUI: Control Panel > BitLocker Drive Encryption > Turn on BitLocker. Use AES-256 encryption.
- For USB drives used with CUI, enable BitLocker To Go: insert the USB, right-click in File Explorer > Turn on BitLocker. Require a password to unlock.
- Configure a Group Policy to require BitLocker on all fixed and removable drives: Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption.
- Verify cloud storage encryption: confirm your Microsoft 365 GCC or cloud provider encrypts data at rest (M365 uses AES-256 by default). Get a letter of attestation from the provider if possible.
- Store BitLocker recovery keys securely in Azure AD or a printed copy in a fire-safe. Never store recovery keys on the same machine that is encrypted.
Evidence your assessor will ask for
- BitLocker status report showing all CUI workstations are encrypted (manage-bde -status output)
- Group Policy configuration requiring BitLocker on fixed and removable drives
- BitLocker recovery key storage documentation (Azure AD or secure physical location)
- Cloud provider attestation of data-at-rest encryption
- Written policy requiring encryption of CUI at rest on all media
Does AI prompt monitoring help with this control? Honestly, no.
SC.2.016 is met through the remediation steps above, not through AI traffic controls — an AI prompt firewall neither satisfies nor substitutes for it. We map AI monitoring only to the controls it genuinely evidences (flow control, boundary protection, audit, and incident support); for the full picture of where it does help, see the mapping guide linked below.
Full mapping: which 800-171 controls AI prompt monitoring evidences →
More System and Communications Protection controls
Monitor and Protect Communications at Boundaries
SC.1.005Implement Subnetworks for Public Components
SC.2.002Employ Effective Security Architecture
SC.2.003Separate User and System Management Functionality
SC.2.004Prevent Unauthorized Info Transfer via Shared Resources
SC.2.006Deny Network Traffic by Default
Score yourself against all 110 controls
The free ShieldReady assessment walks every NIST 800-171 requirement, computes your SPRS score, and shows exactly which gaps cost the most points.