Controlled unclassified information (CUI) refers to information that is sensitive but does not meet the criteria for classification as top secret, secret, or confidential. CUI can include information related to national security, law enforcement, privacy, and other sensitive areas. Proper handling procedures are necessary to protect CUI from unauthorized disclosure or access. In this article, we will discuss CUI and the proper handling procedures necessary to protect it.

What is Controlled Unclassified Information?

CUI is a category of sensitive but unclassified information that is protected by federal law, executive orders, and agency policies. CUI includes information that, if disclosed, could cause damage to national security, harm to individuals, or damage to the interests of the United States.

Examples of CUI include sensitive but unclassified information related to national security, law enforcement, privacy, and trade secrets. This information is not classified, but it requires protection because it is sensitive and can be harmful if disclosed.

Proper Handling Procedures for CUI

The following are proper handling procedures necessary to protect CUI:

  1. Marking: All CUI must be marked with appropriate CUI designations to ensure that it is treated appropriately. Marking should be consistent with agency policies and procedures.

  2. Access Control: Access to CUI must be limited to individuals who have a legitimate need to know. Access control measures should be implemented to ensure that only authorized personnel can access CUI.

  3. Storage: CUI should be stored in secure areas or containers, such as safes or locked cabinets. Access to these areas should be limited to authorized personnel.

  4. Transmission: CUI should only be transmitted through secure channels, such as encrypted email or secure file transfer protocols. CUI should not be sent through unsecured channels, such as regular email or unencrypted file transfer.

  5. Disposal: CUI should be disposed of appropriately. This may include shredding or burning documents, or deleting electronic files in a secure manner.

  6. Training: All personnel who handle CUI should receive training on the proper handling procedures. This training should include the importance of protecting CUI, the proper marking of CUI, access control measures, storage, transmission, and disposal.

Procedures for Emailing CUI

When sending CUI through email, it is important to take steps to ensure that the information is protected from unauthorized disclosure.

Here are some steps to consider when sending CUI through email:

  1. Use a Secure Email System: Use a secure email system that encrypts email messages and attachments. The secure email system should be able to encrypt emails in transit and at rest to ensure that the information is protected.

  2. Use Strong Passwords: Use strong passwords to protect the email account that is used to send CUI. The password should be complex and unique, and should be changed regularly.

  3. Mark the Email as CUI: Mark the email and any attachments with a clear and prominent CUI marking, such as “Controlled Unclassified Information” or “CUI.” This will help to ensure that recipients understand the sensitivity of the information and take appropriate precautions to protect it.

  4. Limit Access: Limit access to the email and any attachments to only those individuals who have a legitimate need to know the information. This can be done by using access controls or password-protected attachments.

  5. Consider Using a Digital Signature: Consider using a digital signature to verify the identity of the sender and to ensure that the email has not been altered in transit.

  6. Follow Agency-Specific Guidelines: Follow any agency-specific guidelines or policies regarding the handling of CUI. Each agency may have its own specific requirements for protecting CUI, so it is important to be familiar with these guidelines.

DoD SAFE

The Department of Defense (DoD) Secure Access File Exchange (SAFE) is a secure file transfer service developed by the DoD to allow authorized users to exchange files securely between DoD networks and external entities.

SAFE provides a web-based platform that allows DoD personnel, federal agencies, and other external organizations to exchange files that contain Controlled Unclassified Information (CUI), Personally Identifiable Information (PII), and other sensitive data. The service uses secure protocols such as Secure Sockets Layer (SSL) and Transport Layer Security (TLS) to protect the confidentiality and integrity of the data being transferred.

SAFE is intended to improve the security of file transfers, reduce the risk of data breaches, and ensure compliance with regulations governing the handling of sensitive information. The service is available to all DoD personnel and external organizations with valid DoD Common Access Cards (CAC), Personal Identity Verification (PIV) cards, or other approved credentials.

Conclusion

CUI is a category of sensitive but unclassified information that requires protection. Proper handling procedures are necessary to ensure that CUI is protected from unauthorized disclosure or access. Marking, access control, storage, transmission, disposal, and training are all essential components of protecting CUI. It is essential that individuals who handle CUI understand the importance of protecting this information and take the necessary steps to protect it. By following proper handling procedures, individuals and organizations can help prevent the unauthorized disclosure or access to sensitive information, which could cause significant harm to individuals and the interests of the United States.