Talk to an Expert
Blog · May 9, 2023

Does NIST SP 800-171 Require Redundant Backups?

Further: Do All Online CUI Storage and Collaboration Companies Have This Feature?

NIST SP 800-171 requires storage backup as part of its security requirements for protecting Controlled Unclassified Information (CUI) in nonfederal information systems and organizations. Specifically, NIST SP 800-171 requires organizations to implement backup and recovery processes for information systems containing CUI, which includes regularly scheduled backups of system data and testing of the backups to ensure their effectiveness in restoring data.

NIST SP 800-171 does not explicitly require redundant storage backup, but it does require that organizations implement appropriate measures to ensure the confidentiality, integrity, and availability of CUI. This requirement includes implementing backup and recovery processes suitable for the organization’s risk management strategy.

In practice, best practices mandate redundant storage backup as part of the processes for backup and recovery of CUI. The best-run organizations view redundancy as reasonable and necessary to ensure that CUI is protected against data loss or system failures. It typically involves storing multiple copies of data in different geographic locations or on different types of storage media.

All online services that provide secure storage for CUI automatically include backup as part of their service. Some do offer customer data backup as part of their standard service offering. In contrast, others, particularly those that provide services based on encrypted email and file-sharing capabilities, may offer it as an optional add-on service for an additional fee.

Still, others say they do automatic backups but maintain backups for their customers only at the application level. Unlike RegDOX, they have no separately maintained network backup to protect against denial of service or ransom attacks.

So, regarding online CUI storage and collaboration companies, it’s important to note that only some provide backup capabilities, and only one is known for having redundant backups.

 

The bottom line is this:

Regulations require backups. Redundant backups, one at the application level and the other at the network level, reflect best practices. And only one online secure storage and collaboration solution for CUI – RegDOX – is known as having redundant backups.

 

To Try Out Our Solution For Free: Click Here

To Get in Contact with Us: Click Here or Reach us by:

Phone: (800) 517-3171

Email: sales@regdox.com

See the enclave in action.

The Compliant Computing Enclave keeps CUI inside one boundary, with your endpoints out of scope and the evidence trail already built.

Talk to an Expert
Keep reading

More from the blog

September 3, 2026

Week 6: Too Embedded to Reject

How GCC High vendor lock-in changes the decision Last week, we examined the assessor problem. This...

Read it →

August 26, 2026

Week 5: FedRAMP’s Assessor Problem

Why FedRAMP assessor independence matters Last week, we examined the larger architecture problem. This week, we...

Read it →

August 20, 2026

Week 4: The Problem Did Not Stop with Encryption

Why GCC High security architecture matters Last week, we focused on the encryption question. This week,...

Read it →