Resources
Critical Resource Website links

CUI History | National Archives

National Institute of Standards and Technology | NIST

252.204-7020 NIST SP 800-171 DoD Assessment Requirements. | Acquisition.GOV
![]()
Acquisition.GOV | www.acquisition.gov Location for FARS and DFARS

Supplier Performance Risk System (disa.mil)
This site was particularly useful

Project Spectrum (Very useful resource - have a look at who they recommend)
Glossary Main Laws & Abbreviations
- [32 CFR 2002]: 32 CFR Part 2002, Controlled Unclassified Information, September 2016. https://www.govinfo.gov/app/details/CFR-2017-title32-vol6/CFR-2017-title32-vol6-part2002/summary
- [OMB A-130]: Office of Management and Budget (2016) Managing Information as a Strategic Resource. (The White House, Washington, DC), OMB Circular A-130, July 2016. https://www.whitehouse.gov/sites/whitehouse.gov/files/omb/circulars/A130/a130revised.pdf
- CUI categories: Those types of information for which laws, regulations, or governmentwide policies require or permit agencies to exercise safeguarding or dissemination controls and which the CUI Executive Agent has approved and listed in the CUI Registry.
- CUI Executive Agent: The National Archives and Records Administration (NARA) implements the executive branch-wide CUI Program and oversees federal agency actions to comply with Executive Order 13556. NARA has delegated this authority to the Information Security Oversight Office (ISOO) Director.
- CUI program: The executive branch-wide program to standardize CUI handling by all federal agencies. The program includes the rules, organization, and procedures for CUI, established by Executive Order 13556, 32 CFR Part 2002, and the CUI Registry.
- FCI Federal Contract Information: FCI is data not intended for public release, provided by or generated by the Government under a contract to develop or deliver a product or service to the Government. FCI does not include information provided by the Government to the public, (FCI)
- Covered Defense Information (CDI): The requiring activity is also responsible for determining the appropriate marking for the CDI by the procedures for applying distribution statements on technical documents found in DoDM 5200.01 Vol 4 and DoDI 5230.24, Distribution Statements on Technical Documents.
- Defense Industrial Base (DIB): The DoD Defense Industrial Base (DIB) Collaborative Information Sharing Environment (DCISE) serves as the single DoD focal point for receiving all cyber incident reporting affecting unclassified networks of DoD contractors to safeguard DoD information.
- Prime Contractor: A contractor responsible for design control, and delivery of a system or equipment such as aircraft, engines, ships, tanks, vehicles, guns and missiles, ground communications and electronic systems, ground support equipment, and test equipment.
- Supplier Performance Risk System (SPRS): The Supplier Performance Risk System documents vendor self-assessment results for DOD Acquisition Professionals. SPRS is the Department of Defense’s single, authorized application to retrieve suppliers' performance information. SPRS is a web-enabled enterprise application that gathers, processes, and displays data about the performance of suppliers.
- Office of the Under Secretary of Defense Acquisition and Sustainment OUSD(A&S).

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics