Due Diligence: Contractors’ Responsibility to Identify and Protect CUI and Sensitive Information
Jeff Bennett of Thrive Analysis Group and NISPOM Central argues that the common claim “contractors are not authorized to determine CUI” is bad advice that leads people to ignore their responsibility to identify, mark, and protect sensitive information in their work products. He says contractors are authorized to apply derivative markings based on government instructions and must exercise “presumption of care” (duty of care) to prevent applied research, controlled technologies, export-controlled information (EAR/ITAR), proprietary data, PII, and CUI from entering the public domain, which can harm warfighters and technology. Citing examples of ITAR data nearly published and CUI text copied into deliverables, he emphasizes repeatable processes, reasonable standards aligned to NISPOM, DD Form 254, DFARS, CMMC, and NIST SP 800-171, plus marking by default and reviewing materials before release.
00:00 Contractors Can Mark CUI
01:05 Stopping the Big Mouth
02:33 Bad Advice in Defense
03:41 Due Diligence Basics
05:55 When Research Turns Sensitive
06:57 Real World CUI Slipups
09:34 No CUI Police Myth
10:41 Presumption of Care
11:21 Derivative Marking Process
12:12 Protect Warfighters and Wrap Up
NISPOM Central Providing security clearance books, training, and resources for cleared defense contractors.
The Trusted Advisor for Technology Protection, FSO and NISPOM consulting.
After dialing in my craft and many years of honing program protection experiences, I became a trusted advisor. I am currently supporting customers with technology protection and NISPOM compliance topics.
INDUSTRIAL SECURITY TRUSTED ADVISOR
What Trusted Advisor Involves: I partner with executive leadership to design and operate security programs that meet and exceed NISPOM requirements.
Results you can measure immediately:
Prepared commercial organizations for defense contracting and NISPOM compliance
Designed ready to implement security programs before, during and after facility clearance award
Rescued high risk security programs with quick turnaround; usually within 30 days
Achieved Commendable and Superior DCSA review ratings
Developed compliant FOCI mitigation programs
SPEAKER_00
Welcome to NISPOM Central's podcast, and I'm your host, Jeff Bennett. Well, we're so glad you decided to join us. I know there's other places you can go to get exciting NISPOM content, but here at NISPPOM Central, we're going to provide you with what you need to know to be an excellent FSO security specialist or defense contractor. Now for our episode. The problem is with people telling you contractors are not authorized to determine CUI, usually people take that to mean I have no responsibility for identifying and protecting this information I'm providing to the government. Contractors are authorized to mark their information or mark their products that are derived from government instruction. We just have to do the due diligence to assess and determine what needs to be protected. We want to protect our warfare. Because if you're not applying this, the chances of your information getting in the public domain increase greatly. Even though you might be working for a customer who requires you to protect their items, you may not get adequate protection. So what do you do in that case? How do you determine if you have sensitive information that needs to be protected? I'm going to say, don't go back to the bad device. I showed up at a customer location and I asked them, What would you like to accomplish by me being here? And he said, We want to stop the big mouth. Who is this big mouth? He said, It's our employees, it's our supervisors, it's our politicians. I said, So the issue is you understand and can recognize when sensitive information is broadcast into the public domain. They said yes, absolutely. I said, the problem is for you to intuit and depict it in guidance so that people understand what not to say. And he said, yes, absolutely right. And I said, good, I'm glad I can help you. We have processes, procedures, and tools to help you do that consistently and effectively. So this is kind of some lessons learned. This guy was leaning forward, and we were able to join him and set up an opportunity to protect in sensitive information. But by leaning forward, I mean he was looking for a way to determine what needs to be protected in their raw data. In raw data, everybody has raw data, right? Whether you're commercial, university, or government, you're doing research and development or making products. And to be able to stay leading edge, you need to protect those products from going into the public domain. There's a lot of bad advice out there. And it exists in the defense space and in the commercial space. Here's where it exists in the defense space. There's a lot of advice out there that contractors are not authorized to determine controlled unclassified information. Now you can take out controlled unclassified information and put any type of protected information. I call this bit bad advice because these are answers when people are asking, how do I identify CY in my program? And then they get the response, you're not authorized to do so. But that comes from other consultants and not from the government. So when somebody says contractors are not authorized to blank, you need to explore that a little bit further. Because even if it's not a government contract, but you are working on any information that is protected under export compliance, either the EAR or the ITAR. I hope you are doing that due diligence to ensure that you are marking that information so you do not have an export compliance violation. Hi, I'm Jeff Finnett again with Thrive Analysis Group and NISPOM Central and NISPOM.com. Today we're going to talk about due diligence with identifying sensitive information. Yes, due diligence is required, and I'm going to set it up a little bit. So you're a defense contractor or you are even a commercial entity and you have sensitive information from your own research, could be proprietary information, controlled unclassified information, personal identifiable information, whatever it is. You have a due a responsibility to protect this information. What are the requirements? Well, in the Department of Defense, we're looking at NISPPOLM requirements to protect classified information and controlled unclassified information and information and guidance found on the DD Form 254. But also for defense contractors, we have DFARs and CMMC requirements. We've got to be aligned with them as we perform on our contracts. We also have NIST SP 800-171 expectations. We have government governance that we have to apply. We need repeatable processes, we need accountability. These are some things that we need to incorporate into our business and in the way we work our work products. And again, this applies to defense contractors as well as the commercial entities. So what I'm talking to you about today is your requirement to protect sensitive information. As I mentioned earlier, sensitive information can be classified, controlled, unclassified information, export compliance information or export controlled proprietary data, intellectual property. Unfortunately, you may get a lot of information that is not completely marked, which leaves you to the responsibility of marking that information. For example, you have basic research that anybody might do. You may be able to go online and get engineering drawings of how fans work, how washing machines work, how cars work. You can download those drawings all day long. But once those drawings have a military application or a functional application, they may require additional protections depending on the level of it. So you've got to do that assessment. Once basic research starts having a function, that either and for you commercial folks, if that function is something that you are developing and you don't want that to get out to your competitors, then that becomes applied research. For the government, once basic research, and for universities that are are on contract with the government, once basic research has a military application, it needs to be assessed for protection because now you have applied research. So here's a few examples of how contractors can get jammed up. And again, you can apply this to commercial as well. Now, an employee is required to write a white paper or provide images for pamphlets or technical drawings that may go into a booth, on a website, in a white paper, or otherwise be published in the public domain. Now, while that employee might be an expert on their technology and will gladly offer that technical drawing, somebody should be doing due diligence to ensure if that mark if that drawing is not marked properly, that it is evaluated before it goes into public domain. Those markings, drawings, and information should already be marked so folks can understand what they can release. Employees create work products, deliverables, or purchase orders based on a protected technical specification. In the first example of the drawings, that really happened. ITAR information almost got out into the public domain because nobody did the review. In the second one, this actually happened too when I went to a somebody called me in to assess their program to protect sensitive information. And they actually had technical specifications that were marked CUI. And while they were protecting it from unauthorized access, they kept it locked up, they signed it out to the people who need it. I asked the question, is any of this on your networks or servers? Or otherwise available to everyone? They said no, it stays right here. Then I asked the question, well, what do you do with this? What's the function of this specification? And they said, Well, we d develop instructions for producing this information, we write receipts based on it, and provide our clients deliverables. I said, Do these deliverables happen to have any of these this verbiage contained in this specification marked CUI? And said, Yeah, we copy and paste it. Now you get it. The information was carried over into products that were put into the public domain. Even though you might be working for a customer who requires you to protect their items, you may not get adequate protection. So, what do you do in that case? How do you determine if you have sensitive information that needs to be protected? I'm gonna say, don't go back to the bad device. The problem is with people telling you contractors are not authorized to determine CUI, usually people take that to mean I have no responsibility for identifying and protecting this information I'm providing to the government. For you commercial folks, I have no responsibility to determine what is proprietary information or belongs to my customer. It's not marked, so it's not my responsibility. That is bad advice. There are no CUI police. If you happen to get the marking wrong, nobody's gonna get you. Chances are you'll get it right, especially if you establish a good information control program, which I'll show you in my next video. I'll show you how to set those up. In the meantime, again, there are no CUI police telling you you're marking it incorrectly. The worst that can happen is you don't mark it, and technical information, controlled technologies, applied research gets in the public domain where it can be snatched out and duplicated, thus being harmful to our warfighter. Let me prove that you are authorized to determine sensitive information in your work products. It's called presumption of care. Presumption of care could also be called duty of care, and it's a principle surrounding the handling and marking of sensitive materials. If you are working on it, it is your job to provide that due diligence to make sure it does not get into the public domain. So, what does it require? Proactive protection. You've got to determine the countermeasures or the preventive measures to prevent this from going into the public domain. Reasonable standard. Your standards should be reasonable based on your customers' requirements. So if you work for the government and you have source documents, all the materials that you developed and all the research that you do, all your testing should be marked appropriately. So you're not really determining it, you're doing what we call in the classified side derivative classification. So you need to provide derivative CUI markings, derivative export control markings, derivative proprietary information markings, whatever the situation is. You need to put a process in place where your employees and leadership understand what should be protected and how to market. Of course, there's a final part called marking by default. Marking by default means carry over those markings that you got earlier. Assess whether your compilation is going to make it sensitive as well. You've got to really understand the situation so that you'll be able to protect it. So it is your responsibility to protect your information, your customers' information, and especially if you're a contractor, it's your responsibility to protect government information that resides in physical form or on your computer. Again, you can say you have IT, you can say you can have cybersecurity or you're CMMC compliant. But if your information that is protected on these systems is not marked properly, it can end up in the public domain. And I want to prevent that, right? We want to protect our warfare, we want to protect our technology. Because if you're not applying this, the chances of your information getting in the public domain increase greatly. I'm Jeff Bennett. I'm going to put a waste to contact me in the notes. Or you can just leave a message. You know, you can respond to this video or you leave a comment. Those are wide open. I hope you visit me and my website. And please, if you want to ask me questions, go to my website, thriveanalysis.com, and book time with me. I'll be happy to answer your questions. Again, you can reach me at thriveanalysis.com, mistpomcentral.com, or mispalm.com. Once again, I thank you for joining DOD Secure. This is your place to go for all things Nispalm, all things contract, requirement, and all things security clearance. We hope you've come back for another episode. And please look at our show notes, and you can find more resources that might answer your question. How do I perform once I win a classified contract? And what do I do once I get a security clearance? And the other question is how do I get a security clearance? We are here to help you out. And I hope you remember that when you visit our show notes, you will find those resources, as well as access to my other company, Thrive Analysis Group, where we actually perform NISPOM tasks and as well as FSO or NISPOM consulting in case you have that need. Wish you all the best and we'll see you next time.