What constitutes controlled unclassified information?

Controlled Unclassified Information (CUI) is information that requires safeguarding or dissemination controls pursuant to and consistent with applicable law, regulations, and government-wide policies but is not classified under Executive Order 13526 or the Atomic Energy Act, as amended.

Examples

  • CUI Registry Categories.
  • Controlled technical information with military or space application.
  • Protected critical energy infrastructure information, including nuclear reactors and materials.
  • Export control information or materials.
  • Geodetic and geospatial information related to imagery intelligence.

Furthermore, what is the meaning of unclassified information? Unclassified is a security classification assigned to official information that does not warrant the assignment of Confidential, Secret, or Top Secret markings but which is not publicly-releasable without authorization. It was aimed primarily at protecting defense information of the United States.

Consequently, what is meant by controlled unclassified information CUI )?

Controlled Unclassified Information (CUI) is a category of unclassified information defined in a directive on May 9, 2008, by President George W. Bush. CUI replaces categories such as For Official Use Only (FOUO), Sensitive But Unclassified (SBU) and Law Enforcement Sensitive (LES) categories.

What is a CUI document?

CUI is unclassified information requiring protection as identified in a law, regulation, or government-wide policy. • The CUI Registry provides information on the specific categories and subcategories of. information that the Executive branch protects.

What are two types of Cui?

The following is a quick reference list of common categories of CUI Specified subsets: Agriculture. Critical Infrastructure. Emergency Management. Export Control. Financial. Geodetic Product Information. Immigration. Information Systems Vulnerability Information.

Who can access Cui?

Access to CUI is usually restricted to Non-U.S. persons, unless the sponsor has agreed to grant access to a Non-U.S. person under a fully executed non-disclosure agreement (NDA).

Who determines Cui status?

Whether CUI is Basic or Specified is determined by the applicable Safeguarding and/or Dissemination Authority for that CUI. Each “Safeguarding and/or Dissemination Authority” citation links to the statute, regulation or government-wide policy authorizing the control of that information as CUI.

What is controlled classified information?

Controlled Unclassified Information (CUI) is information that requires safeguarding or dissemination controls pursuant to and consistent with applicable law, regulations, and government-wide policies but is not classified under Executive Order 13526 or the Atomic Energy Act, as amended.

What is the type of Cui?

CUI is a broad category that encompasses many different types of sensitive, but not classified, information. For example, personally identifiable information such as health documents, proprietary material and information related to legal proceedings would all count as CUI.

Is PII considered Cui?

CUI Category: Sensitive Personally Identifiable Information. Category Description: A subset of PII that, if lost, compromised or disclosed without authorization could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual. Some forms of PII are sensitive as stand-alone elements.

What is NIST Cui?

NIST 800-171 refers to National Institute of Standards and Technology Special Publication 800-171, which governs Controlled Unclassified Information (CUI) in Non-Federal Information Systems and Organizations. Doing so helps the federal government “successfully carry out its designated missions and business operations.”

What is Cui data?

Established by Executive Order 13556, the Controlled Unclassified Information (CUI) program standardizes the way the Executive branch handles unclassified information that requires safeguarding or dissemination controls pursuant to and consistent with law, regulations, and Government-wide policies. Learn About CUI.

What is unclassified controlled technical information?

A: Controlled technical information is defined in the DFARS at 204.7301 as: technical information with military or space application that is subject to controls on the access, use, reproduction, modification, performance, display, release, disclosure, or dissemination.

Is ITAR data Cui?

Within the government’s Controlled Unclassified Information program, International Traffic in Arms Regulations (ITAR) data is what is known as a CUI Specified data type.

What is unclassified data?

(of data, documents, etc.) not belonging to a category that is restricted for reasons of security; not secret: unclassified plans; unclassified information.

How do you classify data?

There are 7 steps to effective data classification: Complete a risk assessment of sensitive data. Develop a formalized classification policy. Categorize the types of data. Discover the location of your data. Identify and classify data. Enable controls. Monitor and maintain.

What is an unclassified employee?

Typically classified workers are paid hourly, with the FLSA setting standards on the minimum hourly wage and the overtime rate of 1 1/2 times the hourly rate if the employee works more than 40 hours per week. Unclassified employees are typically salaried employees. However, these are broad definitions.

Is unclassified a classification?

Unclassified is not technically a classification; this is the default and refers to information that can be released to individuals without a clearance. Information that is unclassified is sometimes restricted in its dissemination as Sensitive But Unclassified (SBU) or For Official Use Only (FOUO).