Protecting CUI Beyond CMMC: Security Managers, Program Teams, and Consistent Marking
In this NISPOM Central episode, the host argues that protecting Controlled Unclassified Information (CUI) is primarily a security manager/FSO responsibility that requires active involvement from program managers, engineers, and contract staff to identify, mark, document, and protect CUI and all derived products throughout workflows and the supply chain. He warns against relying on CMMC or technical cyber/IT controls alone, comparing it to a bank that stores valuables without accounting for deposits or growth, and notes inconsistent CUI identification and marking as a common failure. He describes how CUI may arrive as marked source documents (designs, drawings, slides, reports, PII used for government purposes) without a marking guide, requiring contract review and requirement analysis. When CUI status is unclear or unmarked, he advises seeking clarification internally, then from primes or the government program office. He announces forthcoming training on his Teachable LMS.
00:00 Welcome to NISPOM Central 00:08 CMMC Fatigue and Focus 01:02 Bank Analogy for CUI 01:51 Ownership Beyond IT 02:31 Supply Chain Consistency 03:47 Why CUI Became Cyber 06:52 Wake Up Call on CUI 07:16 Define Roles and Accountability 07:54 How CUI Shows Up 08:52 Derived Products and Markings 11:04 When CUI Is Unclear 13:06 Wrap Up and Training Offer
The Trusted Advisor for Technology Protection, FSO and NISPOM consulting.
After dialing in my craft and many years of honing program protection experiences, I became a trusted advisor. I am currently supporting customers with technology protection and NISPOM compliance topics.
INDUSTRIAL SECURITY TRUSTED ADVISOR
What Trusted Advisor Involves: I partner with executive leadership to design and operate security programs that meet and exceed NISPOM requirements.
Results you can measure immediately:
Prepared commercial organizations for defense contracting and NISPOM compliance
Designed ready to implement security programs before, during and after facility clearance award
Rescued high risk security programs with quick turnaround; usually within 30 days
Achieved Commendable and Superior DCSA review ratings
Developed compliant FOCI mitigation programs
SPEAKER_00
Welcome to NISPOM Central. This is our podcast at our YouTube channel and of course information from here also goes on our newsletters. Well today I want to talk to you about CMMC. No, not really. I'm tired of reading about it. What I want to talk to you about is protecting CUI. Protecting CUI is a security manager's job. I want to emphasize that. It's the security manager's job, however, it requires input from the program managers and their personnel. For example, if somebody is developing a weapon system for a government customer, it is up to that, those employees in your organizations who are working on that system to identify, mark, and protect that CUI. It is not the cybersecurity professionals or the IT professionals. If we are relying totally on CMMC to protect our sensitive information, we're losing the battle. Why? It's just like starting a bank and putting money into the bank without accounting for how much money it is, or items in the bank without accounting for what the value is. We just put it in the bank, let it sit there, and hopefully everybody treats it right. But once it starts producing interest or growing in value, nobody's tracking it. Nobody's tracked what was put into the bank and nobody tracks the value afterwards. Whatever is derived off those original products that we put into that bank account or that bank vault is not being tracked. Who wants to go to a bank like that? Well, that's what I think we do when we relegate the protection of sensitive information to a cyber construct. Not that there's anything wrong with it. I think we do need a good cyber construct. I think we do need good banks, but we need people inside the organizations who can account for, document, mark, and derive products so that we can track how we are using that in our workflow. This is not being done. When it's relegated to cyber and IT professionals, they're going to do great at doing their job, but I've seen people step back from their responsibilities on identifying and protecting sensitive information. The issue is a lack of consistency in identifying and marking that sensitive information and working on it in that workflow that the organization is executing on. If it's in hard copy, soft copy, if it's a big thing, we've got to protect it. Whether the prime contractor or the subcontractors, wherever you are in that tier, whether government, prime, or sub, protection should be consistent all along that supply chain. Now, this I say again is a job for security professionals, but I believe we've relegated that job to those IT people. Why? I I've got a few ideas. One is in social media and online forums, the entire time that we talk about CUI is from the point of view of cybersecurity or IT or this CMMC construct that we're working with. I've got some things to say about CMMC, but I'll do that at another time. So I hope you'll come back. Again, this is a job for security professionals working in coordination with people, program managers, their employees, engineers, etc. Whoever's working on a contract. Again, if you're commercial, whatever your business is working on, you need to, the people who are working in the business need to understand what they're doing and how they're working on it. While it is important to understand how to build networks and store sensitive information, it may require additional efforts and analysis and training and documentation that is required to do this job. FSOs and security managers, risk managers, program managers understand how to do this. While cybersecurity professionals and CMMC professionals may understand the NIST, they may not understand the intimate details of performing on contract and what that looks like. I think we have relegated our responsibilities, and there's many ways I can prove it right now. One is when you read the NIST palm and it says DCSA will not be reviewing CUI unless it's a contract requirement. Many people had said, okay, CUI is out of my scope. But I'm going to tell you, it's going to come back to you, FSOs and security managers. We need to bring CUI into our scope and help our program managers with protecting it. CUI protection is required in CMMC and NIST. We hear that all the time in our social media posts. Security community is not proactive in protecting this CUI. We talk about it, but in terms of CMMC. And when I mean protecting CUI, I'm going to harp on this all the time. What is our organization doing with the CUI that is put under our control? A lot of people don't even recognize they're receiving CUI. CUI discussions occur in CMMC communities, and when many FSOs discuss it, it's from a CMMC point of view. We're trying to figure out how to work within CMMC instead of trying to figure out what exactly the CUI is and how we're using it within our organization. And you know, if you just follow all the social media and CUI discussions, there are very few that are led from this point of view. They're mostly led from a cyber protection point of view. I get what I'm saying is broad generalizations, but again, my observations are what is prevalent out there. It may be different in your organization, and if so, if you're doing what I'm saying or recommending, I applaud what you're doing. But this is kind of a wake-up call for our community. While CMMC is important, it may go away, requirements may change. I don't know what's going to look like a year from now. But realize that any type of technical solution is not the solution. We've got to still go in and do our part to identify how we're using it and if we're marking it and how we're protecting it. This is not specifically an IT or cyber job. They can do it, but I recommend whoever has this responsibility has a job title similar to this job title, which is CI CUI control officer or something like that. We have to understand from the top down, from the prime to the sub what the CUI is and how it's presented by our customers and what they expect us to do with it. And then what are we doing with that CUI once it's in our possession? The application here is that a government contracting activity identifies a CUI. You're not going to get a CUI marking guide, right? You're going to get source documents, you might get an item, you might get an engineering design document or software design document, kickoff slides, whatever. But these are going to be marked. And if you have these in your possession and you're working on that project, then consider what you are deriving and give it the appropriate markings. Facility security officers, program managers should team to review contracts, work performance statements, whatever that is imposed by the customer. You might be looking at the 254, but if you're on unclassified contracts, you won't have a 254. And again, your customer may not give you a guide, but they may give you guidance, and it's up to you to take that guidance and apply it to your workshop. You might be providing a service, you might be working a help desk, you might be working in healthcare, where you are accessing government systems and downloading them onto your corporate computers. Realizing that if you take something that is provided by the government and it's marked CUI and you bring it on your organization's computers, you must protect it as CUI. And if you use it in your products for reports or to provide customer service, you must protect that as CUI as well. You might consider what you upload to those government websites, those might be CUI as well. For example, PII, first of all, identifiable information that you might get from human resources might be PII. But if you use it for a government purpose, you might need to consider that CUI. It depends on what guidance that you get. Now, you also might get some written guidance, some technical guidance. You might get slides, presentations, engineering design documents, as I mentioned earlier, drawings, if it's marked, notice what the marking is and use it appropriately for all derived products and bring your teams in together, discuss it, and figure out what it is. Analyzing all the requirements and applying it to your workload is one of the least things, but most important things that you can do. Sure it'll take a lot of time, but if you continue to rely on technical countermeasures alone, such as what CMMC might bring in, you're going to lose it. Just like that bank that takes in all this information that they think is valuable, but don't track interest, don't track who deposited, how much was deposited, well that can walk out of your protected bank at any time without you even noticing it. If you're relying on CMMC and you have an enclave, sensitive information can be removed without your knowing it if it's not properly accounted for. Alright, one more thing before we go. Some FSOs and security managers have asked, what if we're working on something and we don't know whether or not it's CUI? Or what if the government gives us something that's not marked CUI? Where do we start? And I usually respond with, of course you don't know it's C UI. You don't work on it every day. The best thing to do is go to your program manager that is in your organization or the employees that are working on it and get clarification. Chances are they know what is CUI because they're working on it every day. They just need help with the accounting and the derivative part. Something that you can be control of. What do you do when you have CUI and you teach them what to do it? But if you want the CUI left and right guidelines or understand better what the CUI is, go to your program managers, your engineers. They know. If they don't know or if they understand what that guidance is, chances are they're sitting on it and you might have to help them with that part. However, if there is a chance that nobody in your organization knows what to do, the next best thing is go up the chain. If you're a subcontractor, you need to approach the program managers that are in the primes. They will know. If they don't know, or if you are the prime, you need to go to the government program office and negotiate that. Hey, this is marked as CUI and we don't understand why. Or this is not marked, we believe it is CUI. What can we do to resolve this problem? We're not going to do that internally because it's not available to us. We need to go to the source and request that for them. There's no way that I, as a compliance officer, an IT manager, or cybersecurity officer, or even an FSO can understand what is CY in my workload unless I'm intimately familiar with it. For that, I need to go to the source. Hey, if you have any questions, just let me know. And thanks for sticking around for this episode of NISPOM Central. Or from people within your organization. Just for that, I'm putting together a special lesson. And this lesson will be featured in my learning management system at called NISPOM Central, and it's on Teachable. Now I'll put a link to there in this, but you can also go to NISPOMCentral.com or NISPOM.com to find links to that training.