flow of CUI
The movement of Controlled Unclassified Information (CUI) as it transits within a system and between systems — distinct from the question of *who* may access that information — governed by policy-based controls at enforcement points. Organizations use information flow control policies and enforcement mechanisms to regulate movement between designated sources and destinations (e.g., networks, individuals, and devices) within systems and between interconnected systems. Enforcement occurs in boundary protection devices such as gateways, routers, guards, encrypted tunnels, and firewalls, which employ rule sets or configuration settings that restrict services, filter packets based on header information, or filter messages based on content. Identifying and controlling how CUI flows throughout an organization determines, in many ways, how all other security controls in a framework such as NIST SP 800-171 are implemented.
Framework senses
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 2 citations in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- The movement of Controlled Unclassified Information (CUI) as it transits within a system and between systems — distinct from the question of *who* may access that information — governed by policy-based controls at enforcement points. Organizations use information flow control policies and enforcement mechanisms to regulate movement between designated sources and destinations (e.g., networks, individuals, and devices) within systems and between interconnected systems. Enforcement occurs in boundary protection devices such as gateways, routers, guards, encrypted tunnels, and firewalls, which employ rule sets or configuration settings that restrict services, filter packets based on header information, or filter messages based on content. Identifying and controlling how CUI flows throughout an organization determines, in many ways, how all other security controls in a framework such as NIST SP 800-171 are implemented.DR-088 backfill from the noun definition column