This family of controls mandates various measures to achieve that protection. Organizations must implement general security practices like securing system boundaries, identifying and addressing security issues, protecting information at rest and in transit, controlling user access, and providing security awareness and training. Additionally, they are required to conduct risk assessments to pinpoint vulnerabilities in their systems and communication channels. Based on these assessments, they must create and implement security plans to mitigate those risks.
In essence, NIST 800-171's "3.13 System and Communications Protection" ensures that organizations have a solid foundation of security practices in place to safeguard CUI. This includes both general security measures and targeted actions based on identified vulnerabilities.