CUI Compliant

0 NIST 800-171 gaps detected. FedRAMP authorized at Moderate impact level. Approved for CUI handling in DoD environments.

Cybersecurity

Tenable Government

by Tenable

FedRAMP AuthorizedModerate Impact

FedRAMP Status

FedRAMP Authorized

Impact Level

Moderate

Category

Cybersecurity

Authorized: September 22, 2021

Overview

Tenable Government provides FedRAMP Moderate authorized vulnerability management and compliance scanning. It helps defense contractors identify and remediate security vulnerabilities across their CUI infrastructure.

CUI Risk Assessment

FedRAMP authorized at Moderate impact level. Approved for CUI handling in DoD environments.

Deployment & Architecture

Deployment Model: Government Cloud (FedRAMP boundary)

Tenable Government operates within a FedRAMP-authorized boundary. CUI can be processed within the authorization scope, but contractors must verify their specific use case falls within the system's security boundary as documented in the SSP.

Configuration Checklist

  1. 1ISSO must update the System Security Plan to include Tenable Government within the authorization boundary and document all data flows per NIST 800-171 CA-2 requirements.
  2. 2Network administrator must configure dedicated VLAN segments for vulnerability scanning traffic to ensure proper network segmentation per SC-7 controls.
  3. 3System administrator must install and configure Tenable Government agents on all CUI processing systems following vendor hardening guidelines.
  4. 4ISSO must establish role-based access controls within Tenable Government aligned with organizational need-to-know requirements per AC-2 and AC-3 controls.
  5. 5Security engineer must configure encrypted communication channels between Tenable Government and all scanned systems per SC-8 requirements.
  6. 6ISSO must integrate Tenable Government with existing SIEM solution for centralized audit log collection per AU-3 and AU-6 requirements.
  7. 7System administrator must configure automated vulnerability scan schedules to meet continuous monitoring requirements under SI-4 controls.
  8. 8ISSO must document vulnerability remediation workflows and timelines in accordance with DFARS 252.204-7012 incident response requirements.
  9. 9Security engineer must conduct validation testing of all scan configurations and document results in POA&M entries per CA-2 requirements.
  10. 10Training coordinator must complete user training on CUI data handling procedures specific to vulnerability scan results and remediation processes.

Frequently Asked Questions

Is Tenable Government FedRAMP authorized?

Yes. Tenable Government holds FedRAMP Moderate authorization for vulnerability management and compliance scanning.

Can I use Tenable Government to scan CUI systems?

Yes. Tenable Government is authorized to scan and assess the security posture of systems handling CUI.

Run a Full Tech Stack Audit

Check all your enterprise tools at once with our free CUI Compliance Auditor.

Launch CUI Auditor

Get a defensible CUI architecture

This Tenable Government CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.

Schedule architecture review

Related: how much CMMC certification costs — DoD’s own priced figures