CUI? What is it and why you should treat it differently? We're going to help explain what controlled Unclassified Information is, help you identify what is considered CUI, and some solutions you can use to protect your CUI.
CUI is a category of non-classified information that the U.S. federal Government creates or possesses, or that a non-federal entity (Defense Industrial Base (DIB) or other Federal contractor organizations) receives, possesses, or creates on behalf of the U.S. government. CUI is content that is not classified but is sensitive and requires safeguarding or dissemination controls pursuant to and consistent with applicable laws, regulations, and government-wide policies but is not classified. It can be anything from proprietary information, personal information, or any information that is considered critical to national security.
If your organization works with or has contracts with a federal agency like the Department of Defense (DoD), Department of Energy (DoE), or even the US Department of Agriculture (USDA). You may have CUI that needs to be protected!
You can find the complete list of CUI definitions found in the NARA CUI registry. Here are a few common examples of data your organization must protect under DFARS/CMMC as a federal DOD, DIB or Federal contractor:
For the more experienced DoD contractors and DIB suppliers identifying and protecting CUI should be a normal part of their security practices. But of those companies that may just be getting into government contracting, it might be overwhelming and not so clear-cut to identify. Here are some questions to ask to help identify CUI:
See the government archive handbook on Marking CUI here: Marking Controlled Unclassified (archives.gov)
The DoD will be working to finalize the rulemaking process, effectively putting the DFARS clause 252.204-7021 into the rotation of contract clauses that can be applied to DoD contracts. As a result, contracting officers and prime contracts will be able to attach this clause to the contract's flow-down Cybersecurity Maturity Model Certification (CMMC) requirements in their supply chains.