UCF STIG Viewer Logo

Controlled Unclassified Information (CUI) - Local Policy Procedure


Overview

Finding ID Version Rule ID IA Controls Severity
V-32156 IS-16.03.01 SV-42473r2_rule PEPF-1 PESP-1 Low
Description
Failure to handle CUI in an approved manner can result in the loss or compromise of sensitive information.
STIG Date
Traditional Security 2013-07-11

Details

Check Text ( C-40670r3_chk )
General Policy Guidance: All personnel of the Department of Defense are personally and individually responsible for properly protecting classified information and Controlled Unclassified Information (CUI) under their custody and control. All officials within the Department of Defense who hold command, management, or supervisory positions have specific, non-delegable responsibility for the quality of implementation and management of the information security program within their areas of responsibility.

Check:
This check is specifically to ensure there are local written procedures for handling, marking, storing, destroying and transmitting Controlled Unclassified Information.

TACTICAL ENVIRONMENT: The check is applicable for fixed (established) tactical processing environments where procedural documents (SOPs) should be in place. Not applicable to a field/mobile environment.
Fix Text (F-36080r1_fix)
General Policy Guidance: All personnel of the Department of Defense are personally and individually responsible for properly protecting classified information and Controlled Unclassified Information (CUI) under their custody and control. All officials within the Department of Defense who hold command, management, or supervisory positions have specific, non-delegable responsibility for the quality of implementation and management of the information security program within their areas of responsibility.

Fix:
Ensure there are local written procedures for handling, marking, storing, destroying and transmitting Controlled Unclassified Information.