Knowledge Builders

what is the definition of controlled unclassified information

by Jason Kassulke Published 2 years ago Updated 2 years ago
image

Controlled Unclassified Information (CUI) is information that requires safeguarding or dissemination controls pursuant to and consistent with applicable law, regulations, and government-wide policies but is not classified under Executive Order 13526

Executive Order 13526

Executive Order 13526 was issued on December 29, 2009 by United States President Barack Obama. It is one of a series of executive orders from US Presidents outlining how classified information should be handled. It revokes and replaces the previous Executive Orders in effect f…

or the Atomic Energy Act

Atomic Energy Act of 1954

The Atomic Energy Act of 1954, 42 U.S.C. §§ 2011-2021, 2022-2286i, 2296a-2297h-13, is a United States federal law that covers for the development, regulation, and disposal of nuclear materials and facilities in the United States.

, as amended.

Full Answer

What is uncontrolled unclassified information?

Controlled Unclassified Information is basically any information that is owned by the government and not fit for general public consumption. Here’s a rule-of-thumb for CUI: if you wouldn’t publish the information publicly—say, post it on Facebook—it’s probably Controlled Unclassified Information.

What information is considered Cui?

CUI is information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a LRGWP requires or permits an agency to handle using safeguarding or dissemination controls. CUI does not include classified information or information a non-executive branch entity possesses and maintains in ...

Is ITAR considered Cui?

“Export control” includes any information that is subject to export control, such as International Traffic in Arms Regulations (ITAR) and the Export Administration Regulations (EAR)—this would be CUI.

What is DoD CUI?

DoD-related Controlled Unclassified Information (CUI) includes information types, such as Controlled Technical Information, as well as financial and contract information. Some of the many types of information that are considered CUI include: research and engineering data. engineering drawings & lists. specifications.

image

What is considered controlled unclassified information?

What is CUI? CUI is government created or owned information that requires safeguarding or dissemination controls consistent with applicable laws, regulations and government wide policies. CUI is not classified information.

What is the meaning of unclassified information?

Unclassified is a security classification assigned to official information that does not warrant the assignment of Confidential, Secret, or Top Secret markings but which is not publicly-releasable without authorization.

What is controlled unclassified information quizlet?

Controlled Unclassified Information (CUI) is unclassified information requiring safeguarding and dissemination controls, consistent with applicable law, regulation, or government-wide policy.

What is the purpose of CUI?

The CUI program is intended to standardize the way the executive branch handles unclassified information that, although unclassified, is still sensitive and merits special controls to prevent unauthorized access.

What are the 6 categories of CUI?

Categories, Markings and Controls: CUI markings. Limited dissemination controls. Decontrol. Registry change log.

What is not considered CUI?

Put simply, any information classified under Executive Order No. 13526 and the Atomic Energy Act cannot be considered CUI. In other words, any classified information labeled “classified,” “secret,” or “top-secret” cannot be designated as CUI.

What is CUI basic answer?

CUI Basic is the subset of CUI for which the authorizing law, regulation, or Government-wide policy does not have any specific handling or dissemination requirements. CUI Basic is handled according to the uniform set of controls set forth in the CFR and the CUI Registry.

What is the CUI basic quizlet?

What is CUI Basic? The subset of CUI for which the authorizing law, regulation, or Government-wide policy does not set out specific handling or dissemination controls.

What is the CUI specified?

CUI Specified is the subset of CUI in which the authorizing law, regulation, or Government-wide policy contains specific handling controls that it requires or permits agencies to use that differ from those for CUI Basic.

What are the two types of controlled unclassified information?

There are seven CUI information types, including Personally Identifiable Information (PII), Sensitive Personally Identifiable Information (SPII), Proprietary Business Information (PBI), Unclassified Controlled Technical Information (UCTI), Sensitive but Unclassified (SBU), For Official Use Only (FOUO) and Law ...

How do you handle CUI?

CUI must be stored or handled in controlled environments that prevent or detect unauthorized access. Limit and control access to CUI within the workforce by establishing electronic barriers. When Reproducing or Faxing CUI, you may use agency-approved equipment. Look for signs on approved equipment.

Can I share CUI information?

Sharing CUI is authorized for any Lawful Government Purpose, which is any activity, mission, function, or operation that the U.S. Government recognizes as within the scope of its legal authorities.

What is classified and unclassified data?

Answer: Unclassified is not technically a classification; this is the default and refers to information that can be released to individuals without a clearance. Information that is unclassified is sometimes restricted in its dissemination as Sensitive But Unclassified (SBU) or For Official Use Only (FOUO).

What is the difference between unclassified and CUI?

“Unclassified” when not used in a marking, indicates that the information being referred to is not classified, but does not indicate whether or not the information is controlled (CUI) or not.

What Does not classified mean?

Non-classified information or documents are not officially stated to be secret: The judge said that all non-classified information should be made public.

What does unclassified job mean?

Unclassified service includes positions that do not meet the criteria for academic faculty but which, based on professional job requirements and responsibilities. Positions that do not meet criteria as defined are deemed to be Classified positions and will be included in the collective bargaining unit.

What happens if a business doesn't comply with CUI?

In essence, any business that doesn’t comply with CUI requirements can be subject to criminal, civil, and administrative actions if that business fails to prevent a cybersecurity incident or fails to disclose an incident properly.

What is CUI basic?

CUI Basic is any CUI data where the authorizing law does not apply specific dissemination controls. CUI Specified does come with dissemination controls, which agencies must implement when handling that information. From a government contractor’s perspective, then: If the CUI concerning your business relationship requires dissemination controls, ...

Who is required to safeguard CUI?

Any contractor and subcontractor working with government organizations such as the Department of Defense (DOD) are required to safeguard CUI in the contractor’s possession, and to protect any IT systems that process CUI.

Who is responsible for regulating CUI?

As of 2018, the designated senior official responsible for regulating CUI was the Under Secretary of Defense for Intelligence (USDI).

How do you protect CUI?

If the scope of your business involves national security, it’s vital that you perform your due diligence to comply with all applicable regulations for federal information-sharing related to your defense contract. This will likely involve several compliance standards and regulations including NIST, DFARS, and CMMC, which all dictate what you must do to properly safeguard your CUI.

What does "unclassified" mean?

Definition (s): A categorical designation that refers to unclassified information that does not meet the standards for National Security Classification under Executive Order 12958, as amended, but is (i) pertinent to the national interests of the United States or to the important interests of entities outside the federal government, ...

What is CUI information?

Information that requires safeguarding or dissemination controls pursuant to and consistent with law, regulations, and government-wide policies, excluding information that is classified under Executive Order 13526, Classified National Security Information, December 29, 2009, or any predecessor or successor order, or the Atomic Energy Act of 1954, as amended. Note: The CUI categories and subcategories are listed in the CUI Registry, available at www.archives.gov/cui.

What is CUI in government?

Information that the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls. However, CUI does not include classified information or information a non-executive branch entity possesses and maintains in its own systems that did not come from, or was not created or possessed by or for, an executive branch agency or an entity acting for an agency.

What does CUI mean?

Henceforth, the designation CUI replaces Sensitive But Unclassified (SBU).

What if your agency has not implemented the CUI program?

If your agency has not yet implemented the CUI Program, but you receive CUI from an organization that has, then use your existing pre-CUI policies to safeguard according to the law, regulation, or government-wide policy that authorizes that CUI category.

Why do federal agencies need to protect information?

Federal agencies routinely generate, use, store, and share information that, while not classified, still requires some level of protection from unauthorized access and release. Protection may be required for privacy, law enforcement, contractual protections, or other reasons. Historically, each agency developed its own practices for sensitive ...

What happens if you receive legacy CUI?

If your agency has implemented the CUI Program, but received CUI marked with Legacy Markings from an organization that has not yet implemented, then use your existing CUI policies to safeguard according to the law, regulation, or government-wide policy that authorizes that CUI category.

What is the FAR rule for CUI?

A forthcoming Federal Acquisition Regulation (FAR) rule for CUI will require new contracts to include CUI terminology and practices.

What is the CUI program?

The CUI Program will enable timely and consistent information sharing while better protecting sensitive information throughout the Federal government and with non-Federal stakeholders.

When will the CUI program start?

Implementation of the CUI Program at GSA will begin July 1,2021.

What is the CUI registry?

The Federal CUI Registry , shows authorized categories and associated markings, as well as applicable safeguarding, dissemination, and decontrol procedures. The Registry is updated as agencies continue to submit governing authorities that authorize the protection and safeguarding of sensitive information.

What is a CUI?

CUI is an umbrella term that encompasses many different markings to identify information that is not classified but which should be protected. Some examples you may be familiar with:

Why was CUI established?

CUI was established to standardize the way the Executive branch handles sensitive information that requires dissemination controls.

When will the EPA start implementing CUI?

The EPA’s Controlled Unclassified Information (CUI) Program issued its Interim CUI Policy in December 2020. EPA anticipates beginning CUI practices (designating, marking, safeguarding, disseminating, destroying, and decontrolling) starting in Fall 2021. The date of full implementation of the CUI Program will be announced by the EPA’s CUI Senior Agency Official (CUI SAO) and updated here on EPA’s public web page. The EPA will phase out legacy markings and safeguarding practices as implementation proceeds.

What is the CUI program?

The CUI Program is an unprecedented initiative to standardize practices across more than 100 separate departments and agencies, as well as state, local, tribal and, private sector entities; academia; and industry. This will enable timely and consistent information sharing and increase transparency throughout the Federal government and with non-Federal stakeholders.

When was the NARA final rule issued?

On September 14, 2016, NARA issued a final rule amending 32 CFR Part 2002 to establish a uniform policy for all Federal agencies and prescribe Government-wide program implementation standards, including designating, safeguarding, disseminating, marking, decontrolling, and disposing of CUI; self-inspection and oversight requirements; and other facets of the CUI Program.

What is the NARA policy?

NARA issues policy directives and publishes an annual report to the President of the United States on the status of agency CUI Program implementation in accordance with Executive Order 13556, Controlled Unclassified Information.

What is CUI in DOD?

Aggregated Controlled Unclassified Information (CUI) may also constitute SECRET or TOP SECRET information. For instance, your organization may only process Controlled Unclassified Information of technical drawings so you can build widget X for a DoD weapons system. Another organization may only process different technical drawings (classified as Controlled Unclassified Information) so they can build widget Y for the same weapon. You build X, they build Y, and your organizations never interact or exchange information. Individually, the drawings for widget X and widget Y are considered Controlled Unclassified Information, but if those drawings are processed together, or aggregated, by the same organization, the DoD may consider that combination worthy of SECRET designation.

What is CUI in government?

So, what is CUI? Controlled Unclassified Information is basically any information that is owned by the government and not fit for general public consumption. Here’s a rule-of-thumb for CUI: if you wouldn’t publish the information publicly—say, post it on Facebook—it’s probably Controlled Unclassified Information.

What is CUI in the military?

DoD-related Controlled Unclassified Information (CUI) includes information types, such as Controlled Technical Information, as well as financial and contract information. Some of the many types of information that are considered CUI include: research and engineering data. engineering drawings & lists. specifications.

What is DFARS 7012?

The bottom line is most US Department of Defense (DoD) contractors and subcontractors must comply with DFARS 7012, because most of us operate and store Controlled Unclassified Information (CUI). The information that every defense contractor operates with what is considered a “covered contractor information system” (a subset of CUI) ...

What is a CDI?

CDI is a subset of what’s called Controlled Unclassified Information (CUI). Through experience or popular culture, most of us are familiar with well-known governmental information classifications of SECRET and TOP SECRET. This is the type of information the Mission Impossible or James Bond movie franchises deal with. Controlled Unclassified Information is not that type of information; it’s unclassified—in that it isn’t SECRET or TOP SECRET—but it is still sensitive and requires protection. If CUI makes its way into the adversary’s hands it could compromise the mission of the US or reduce our military competitive advantage. So, what is CUI? Controlled Unclassified Information is basically any information that is owned by the government and not fit for general public consumption. Here’s a rule-of-thumb for CUI: if you wouldn’t publish the information publicly—say, post it on Facebook—it’s probably Controlled Unclassified Information.

Can another organization process different technical drawings?

Another organization may only process different technical drawings (classified as Controlled Unclassified Information) so they can build widget Y for the same weapon. You build X, they build Y, and your organizations never interact or exchange information.

What is classified information?

Classified information means information that is classified as Restricted Data or Formerly Restricted Data under the Atomic Energy Act of 1954, or information determined to require protection against unauthorized disclosure under Executive Order 12958 , Classified National Security Information, as amended, or prior executive orders, which is identified as National Security Information.

What is criminal history?

Criminal history record information means information collected by state and federalcriminal justice agencies on individuals consisting of identifiable descriptions and notations of arrests, detentions, indictments, bills of information, or any formal criminal charges, and any disposition arising therefrom , including sentencing, criminal correctional supervision, and release, but does not include intelligence for investigatory purposes, nor does it include any identification information which does not indicate involvement of the individual in the criminal justice system.

What is CUI in government?

Controlled Unclassified Information (CUI) means unclassified Government Data, Information, or materials provided to or resulting from this Agreement to which access or distribution limitations are applicable in accordance with U.S. statutes, regulations, executive orders, and applicable security guidelines. CUI specifically includes (but is not ...

What is the CUI in Darpa?

Protection of Controlled Unclassified Information (CUI) and Controlled Technical Information (CTI) is of paramount importance to DARPA and can directly impact the ability of DARPA to successfully conduct its mission.

What does CUI stand for in advertising?

Remove Advertising. Controlled Unclassified Information (CUI) means official Information that requires the application of controls and protective measures in accordance with national laws, policies, and regulations and has not been approved for public release, to include technical information, proprietary data, ...

What is a CUI?

Controlled Unclassified Information (CUI) means Government Data, Information, or materials provided to or resulting from this Agreement that may be export controlled, sensitive, for official use only, or otherwise protected by law, ...

What is protected health information?

Protected Health Information or “PHI” means any information, whether oral or recorded in any form or medium that relates to the past, present, or future physical or mental condition of an individual, the provision of health and dental care to an individual, or the past, present, or future payment for the provision of health and dental care to an individual; and that identifies the individual or with respect to which there is a reasonable basis to believe the information can be used to identify the individual. PHI shall have the meaning given to such term under HIPAA and HIPAA regulations, as the same may be amended from time to time.

What is controlled unclassified information?

Controlled Unclassified Information means unclassified information to which access or distribution limitations have been applied in accordance with applicable national laws. Such information could include information that has been declassified but remains controlled. Sample 1.

What is CUI in law?

( CUI) shall mean unclassified information to which access or distribution limitations have been applied in accordance with national laws and regulations. It includes information that is exempt from public disclosure or that is subject to export controls. Sample 1.

What is NIST 800-171?

The security requirements in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations ,” http://dx.doi.org/10.6028/NIST.SP.800-171 that is in effect at the time the solicitation is issued or as authorized by the Contracting Officer, as soon as practical, but not later than December 31, 2017.

image

Purpose of The Cui Program

  • Federal agencies routinely generate, use, store, and share information that, while not classified, still requires some level of protection from unauthorized access and release. Protection may be required for privacy, law enforcement, contractual protections, or other reasons. Historically, each agency developed its own practices for sensitive infor...
See more on gsa.gov

Federally Mandated For Better Protections and Easier Sharing

  • Established by Executive Order 13556 [PDF], and implemented by 32 CFR part 2002, the CUI Program is now being implemented across Executive Branch agencies and departments. Sharing CUI is authorized for any Lawful Government Purpose, which is any activity, mission, function, or operation that the U.S. Government recognizes as within the scope of its legal authorities. The C…
See more on gsa.gov

Implementation Timeline

  1. Implementation of the CUI Program at GSA began July 1,2021.
  2. Awareness training for all employees is ongoing and specialized. Training/briefings are provided for those who create and manage CUI on a regular basis.
  3. A forthcoming Federal Acquisition Regulation (FAR) rule for CUI will require new contracts to include CUI terminology and practices.
See more on gsa.gov

Cui and Other Agencies

  • Executive Branch agencies will be moving to CUI at a different pace. During this transition time all agencies should follow these practices: 1. If your agency has not yet implemented the CUI Program, but you receive CUI from an organization that has, then use your existing pre-CUI policies to safeguard according to the law, regulation, or government-wide policy that authorize…
See more on gsa.gov

General Cui

  • What is CUI?
    Controlled Unclassified Information (CUI) is information that requires safeguarding or dissemination controls consistent with applicable laws, regulations, and Government-wide policies, but is not classified under Executive Order 13526 “Classified National Security Informati…
  • What are examples of CUI?
    CUI is an umbrella term that encompasses many different markings to identify information that is not classified but which should be protected. Some examples you may be familiar with: 1. Personally Identifiable Information (PII) 2. Sensitive Personally Identifiable Information (SPII) 3. …
See more on epa.gov

Program Background

  • What is the CUI Program?
    Executive Order 13556, Controlled Unclassified Information, requires the Executive Branch to “establish an open and uniform program for managing [unclassified] information that requires safeguarding or dissemination controls pursuant to and consistent with laws, regulations, and G…
  • Why was CUI established?
    Federal agencies routinely generate, use, store, and share information that, while not meeting the threshold for classification as national security or atomic energy information, requires some level of protection from unauthorized access and release. Historically, each agency developed its ow…
See more on epa.gov

Program Governance

  • What is the Federal CUI governance structure?
    The National Archives and Records Administration (NARA) serves as the Controlled Unclassified Information (CUI) Executive Agent (EA). NARA has the authority and responsibility to manage the CUI Program across the Federal government. NARA issues policy directives and publishes an an…
  • What is EPA’s CUI governance structure?
    At EPA, the CUI Program is housed in the Libraries and Accessibility Division (LAD) within the Office of Mission Support’s (OMS), Office of Enterprise Information Programs (OEIP). EPA’s CUI Program is responsible for issuing CUI policy, procedures, training, and guidance to program offi…
See more on epa.gov

EPA Implementation

  • When will EPA transition to CUI markings?
    The EPA’s Controlled Unclassified Information (CUI) Program issued its Interim CUI Policy in December 2020. EPA anticipates beginning CUI practices (designating, marking, safeguarding, disseminating, destroying, and decontrolling) starting in FY2023. The date of full implementatio…
  • What changes can be expected as a result of this transition to CUI markings?
    EPA changes may include: 1. Amendments to EPA regulations 2. Amendments to a variety of policy documents as well as others referencing Confidential Business Information (CBI) submissions or handling 3. Changes to paper and e-forms and instructions for their submission …
See more on epa.gov

Resources and Contacts

  • Who should I talk to regarding EPA CUI?
    For programmatic questions regarding Controlled Unclassified Information (CUI), including any challenges to CUI marked by EPA, please contact EPA's CUI Program Office.
See more on epa.gov

1.About Controlled Unclassified Information (CUI)

Url:https://www.archives.gov/cui/about

17 hours ago  · Controlled Unclassified Information (CUI) is information that requires safeguarding or dissemination controls pursuant to and consistent with applicable law, …

2.What Is Controlled Unclassified Information (CUI)?

Url:https://reciprocity.com/resources/what-is-controlled-unclassified-information-cui/

27 hours ago  · Controlled unclassified information is a category of information defined by the U.S. federal government. Abbreviated as CUI and often pronounced “kyooie” (rhymes with “phooey”), …

3.controlled unclassified information (CUI) - Glossary | CSRC

Url:https://csrc.nist.gov/glossary/term/controlled_unclassified_information

3 hours ago controlled unclassified information (CUI) Information that law, regulation, or governmentwide policy requires to have safeguarding or disseminating controls, excluding information that is …

4.Videos of What is The Definition Of Controlled Unclassified Inform…

Url:/videos/search?q=what+is+the+definition+of+controlled+unclassified+information&qpvt=what+is+the+definition+of+controlled+unclassified+information&FORM=VDRE

7 hours ago  · Controlled Unclassified Information is basically any information that is owned by the government and not fit for general public consumption. Here’s a rule-of-thumb for CUI: if …

5.Controlled Unclassified Information (CUI) | GSA

Url:https://www.gsa.gov/reference/controlled-unclassified-information-cui

16 hours ago Controlled Unclassified Information (CUI) refers to unclassified information that does not meet the standards for National Security Classification but is pertinent to the national interests of …

6.Controlled Unclassified Information (CUI) Program …

Url:https://www.epa.gov/cui/controlled-unclassified-information-cui-program-frequently-asked-questions-faqs

22 hours ago Controlled Unclassified Information means information that requires safeguarding or dissemination controls pursuant to and consistent with law, regulations, and Government …

7.What is CUI: Controlled Unclassified Information? - Totem

Url:https://www.totem.tech/controlled-unclassified-information/

1 hours ago What is controlled unclassified information (CUI)? Unclassified information requiring safeguarding and dissemination controls, pursuant to and consistent with applicable laws, …

8.Controlled Unclassified Information (CUI) Definition | Law …

Url:https://www.lawinsider.com/dictionary/controlled-unclassified-information-cui

27 hours ago  · Controlled Unclassified Information (CUI) What is CUI? Government created or owned UNCLASSIFIED information that must be safeguarded from unauthorized disclosure. …

9.Controlled Unclassified Information Definition | Law Insider

Url:https://www.lawinsider.com/dictionary/controlled-unclassified-information

7 hours ago

10.Controlled Unclassified Information Flashcards | Quizlet

Url:https://quizlet.com/549324840/controlled-unclassified-information-flash-cards/

8 hours ago

A B C D E F G H I J K L M N O P Q R S T U V W X Y Z 1 2 3 4 5 6 7 8 9