Part I: The History of Protecting CUI

Understanding Controlled Unclassified Information

U.S. federal government agencies generate, use, store, and share Controlled Unclassified Information (CUI) that, while not meeting the threshold for classification as national security or atomic energy information, requires protection from unauthorized access and dissemination.

Organizations responsible for correctly managing CUI include:

  • Government contractors
  • Universities and research institutions
  • Consulting companies
  • Service providers
  • Manufacturing companies that work on contracts for government agencies

Protecting CUI that resides in nonfederal systems and organizations directly impacts the ability of the federal government to conduct essential missions and functions.

The security requirements are intended for use by federal agencies in contractual vehicles or other agreements established between those agencies and nonfederal vendors, consultants, or third parties.  The recommended protection requirements apply to all components of nonfederal systems and organizations that process, store, or transmit CUI or that safeguard such components.

The Problem: Lack of Standardization

Before establishing standards for Controlled Unclassified Information (CUI), more than 100 agencies across United States federal executive departments* evolved their practices for sensitive unclassified information. This multitude of different standards resulted in loosely and sometimes incoherently connected systems. The problems caused by inconsistent definitions and labeling, the lack of a consistent CUI program, and marking resulted in incorrect sharing and improper archiving of important information. Fortunately, the Final rule, 32 CFR Part 2002 Controlled Unclassified Information, came into effect November 14, 2016.

The Solution: Executive Order 13556 "Controlled Unclassified Information”

To address incorrect sharing and archiving of critical data, Final rule, 32 CFR Part 2002 Controlled Unclassified Information, came into effect November 14, 2016.

Executive Order 13556, Controlled Unclassified Information [viii] (the Order) establishes a program for managing CUI across the Executive branch and designates the National Archives and Records Administration (NARA) as Executive Agent to implement the Order and oversee agency actions to ensure compliance. The Archivist of the United States delegated these responsibilities to the Information Security Oversight Office (ISOO).

32 CFR Part 2002 Controlled Unclassified Information issued by ISOO to establish policy for agencies on designating, safeguarding, disseminating, marking, decontrolling, and disposing of CUI, self-inspection, and oversight requirements, and other facets of the Program. The rule affects Federal executive branch agencies that handle CUI and all organizations (sources) that handle, possess, use, share, or receive CUI—or operate, service, or have access to Federal information and information systems on behalf of an agency. Controlled Unclassified Information (CUI) is any (not already classified) information upon which law, regulation, or governmentwide policy requires safeguarding or disseminating controls.

OUS(A&D) Offices of Government

To learn more, visit DOD Mandatory Controlled Unclassified Information (CUI) Training (usalearning.gov) [ix]

Main Menu