What constitutes CUI?

old.reddit.com / @/u/ApprehensiveTree7184, https://old.reddit.com/user/ApprehensiveTree7184

Hey guys, I've seen some posts on this topic that are a few years old, but wondering if there is any more potential clarification...

I work with DIB subcontractors and we often struggle with identifying what is and isn't CUI. While anything marked CUI by our Prime is clearly CUI, we are unsure about data derived from CUI. For instance, if we receive a CUI-labeled drawing for a bolt, would a drawing we create for a nut that fits the bolt also be CUI? What about a work order with some specs about the bolt but without all the original information? How about a word doc merely summarizing the organization's work on the bolt? I've adopted an "if in doubt, treat it as CUI" approach, but it's been met with resistance for being too broad. Clarifying which items (e.g., work orders) are not CUI could significantly reduce our scope and improve control clarity.

How do you go about determining what is and isn't CUI if it is this sort of "derived data?"

submitted by /u/ApprehensiveTree7184
[link] [comments]

published 3 months ago




See all items from the same source