Controlled Unclassified Information · 2 of 3
Safeguarding CUI in practice
In short
- CUI Basic is protected at no less than moderate confidentiality.
- Non-federal systems are protected under NIST SP 800-171.
- Destroyed CUI must be unreadable, indecipherable and irrecoverable.
1. The baseline duty
The Controlled Unclassified Information (CUI) rule at 32 CFR part 2002 has the CUI Executive Agent issue safeguarding standards (32 CFR 2002.14(a)(1)). Those standards require agencies to safeguard CUI at all times in a manner that minimizes the risk of unauthorized disclosure while allowing timely access by authorized holders (32 CFR 2002.14(a)(1)). An authorized holder is an individual, agency, organization or group of users permitted to designate or handle CUI under part 2002 (32 CFR 2002.4(d)). Safeguarding measures that agencies are authorized or accredited to use for classified information and national security systems are also sufficient for CUI, in line with the organization’s management and acceptance of risk (32 CFR 2002.14(a)(2)).
Authorized holders must comply with the Executive Order, part 2002 and the CUI Registry, and review any applicable agency CUI policies for added instructions (32 CFR 2002.14(a)(4)). For CUI Specified, they must also follow the procedures in the underlying laws, regulations or Government-wide policies.
2. Basic and Specified standards
CUI Basic is the default set of standards authorized holders apply to all CUI, unless the CUI Registry annotates that CUI as CUI Specified (32 CFR 2002.14(b)(1)). CUI Specified is safeguarded under the requirements of the underlying authorities listed in the Registry (32 CFR 2002.14(b)(2)(i)). Where those authorities are silent on a safeguarding or dissemination control, agencies apply CUI Basic standards to that aspect, unless the result would not accord with the Specified authority (32 CFR 2002.14(b)(2)(ii)).
3. Reasonable precautions
Authorized holders must take reasonable precautions against unauthorized disclosure of CUI (32 CFR 2002.14(c)). They must establish and use controlled environments in which to protect CUI. A controlled environment is any area or space an authorized holder deems to have adequate physical or procedural controls, such as barriers or managed access controls (32 CFR 2002.4(f)).
Holders must reasonably ensure that unauthorized individuals cannot access or observe CUI, or overhear conversations discussing it (32 CFR 2002.14(c)(2)). CUI must stay under the holder’s direct control or be protected by at least one physical barrier, and outside a controlled environment the holder or barrier must reasonably protect it from unauthorized access or observation (32 CFR 2002.14(c)(3)). CUI processed, stored or transmitted on federal information systems is protected under Federal Information Processing Standards (FIPS) 199 and 200 and National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 (32 CFR 2002.14(c)(4)).
4. Shipping, copying and destruction
Authorized holders may use the United States Postal Service or any commercial delivery service to transport or deliver CUI to another entity (32 CFR 2002.14(d)). They should use in-transit automated tracking and accountability tools, and may use interoffice or interagency mail. Packages containing CUI must be marked under the marking requirements, which bar CUI markings on the outside of an envelope or package (32 CFR 2002.20(i)). CUI may be copied, scanned, printed or duplicated in furtherance of a lawful Government purpose (32 CFR 2002.14(e)). Printers, copiers, scanners and fax machines used for it must not retain data, or the agency must sanitize them under NIST SP 800-53.
Holders may destroy CUI when the agency no longer needs it and records disposition schedules published or approved by the National Archives allow (32 CFR 2002.14(f)(1)). Destruction, including of electronic CUI, must make it unreadable, indecipherable and irrecoverable (32 CFR 2002.14(f)(2)). Any method required by the governing authority must be used. Otherwise agencies use the guidance in NIST SP 800-53 and NIST SP 800-88, or any method approved for classified national security information under 32 CFR 2001.47.
5. Federal and non-federal systems
CUI Basic is categorized at no less than the moderate confidentiality impact level under FIPS 199 (32 CFR 2002.14(g)). Agencies may raise that level above moderate only internally or by agreement, and may not otherwise require higher or different controls when sharing CUI Basic outside the agency. A federal information system is one used or operated by an agency, or by a contractor or other organization on behalf of an agency (32 CFR 2002.14(h)(1)). Systems a non-executive branch entity operates on behalf of an agency are subject to part 2002 as though they were the agency’s own.
Acting on behalf of an agency means a non-executive branch entity using or operating a system, or maintaining or collecting information, to process, store or transmit federal information. The activity must not be incidental to providing a service or product (32 CFR 2002.4(hh)). Any other system is a non-federal information system, which agencies may not treat as their own (32 CFR 2002.14(h)(2)). Agencies must use NIST SP 800-171 when setting requirements to protect CUI’s confidentiality on non-federal systems. The exceptions are where the governing authority prescribes specific safeguarding requirements, or where an agreement sets protection of CUI Basic above moderate.
6. Sharing and agreements
Agencies should disseminate and permit access to CUI where it follows the governing authority and furthers a lawful Government purpose (32 CFR 2002.16(a)(1)). Access must also not be restricted by an approved limited dissemination control or otherwise prohibited by law. Before sharing with a non-executive branch entity, holders must reasonably expect that all intended recipients are authorized to receive the CUI and have a basic understanding of how to handle it (32 CFR 2002.16(a)(4)).
Agreements with non-executive branch entities must, at a minimum, require handling under the Executive Order, part 2002 and the Registry (32 CFR 2002.16(a)(6)). They must state that misuse of CUI is subject to penalties under applicable laws, regulations or Government-wide policies. They must also require the entity to report any non-compliance with handling requirements to the disseminating agency. Non-executive branch entities may receive CUI directly from the executive branch or as sub-recipients from other non-executive branch entities (32 CFR 2002.16(b)(3)). Agencies need not enter a written agreement when sharing CUI with Congress, a court of competent jurisdiction, the Comptroller General, or a requester under the Freedom of Information Act or Privacy Act (32 CFR 2002.16(a)(7)). Only the designating agency may apply limited dissemination controls (32 CFR 2002.16(b)(4)(iii)). The definition of CUI itself is covered in what counts as controlled unclassified information.
Key terms
| Authorized holder | An individual, agency, organization or group permitted under part 2002 to designate or handle CUI. |
|---|---|
| Controlled environment | A space with adequate physical or procedural controls against unauthorized access. |
| Moderate impact level | The minimum confidentiality level for CUI Basic under FIPS 199. |
| Non-federal system | A system not operated on behalf of an agency, for which agencies set requirements under NIST SP 800-171. |
| Limited dissemination control | An approved control that only the designating agency may apply. |
Every statement above links to the document behind it. The full source list for this piece is on the sources page.
This page describes public United States government programs for general information. It is not legal, regulatory or procurement advice, and it does not address the facts of any particular case.
How Sentfore supports this
Field sites need the same care for CUI as home offices. Sentfore works at the delivery end of defense programs in difficult environments, providing secure movement, protective security, facilities and life support. Requirements can be sent through the contact page.