home/dictionary/flow of CUI

flow of CUI

nounverified·updated Sep 1, 2026

The movement of Controlled Unclassified Information (CUI) as it transits within a system and between systems — distinct from the question of *who* may access that information — governed by policy-based controls at enforcement points. Organizations use information flow control policies and enforcement mechanisms to regulate movement between designated sources and destinations (e.g., networks, individuals, and devices) within systems and between interconnected systems. Enforcement occurs in boundary protection devices such as gateways, routers, guards, encrypted tunnels, and firewalls, which employ rule sets or configuration settings that restrict services, filter packets based on header information, or filter messages based on content. Identifying and controlling how CUI flows throughout an organization determines, in many ways, how all other security controls in a framework such as NIST SP 800-171 are implemented.

Framework senses

NIST SP 800-171r31 senseview framework →
§1 · attested_usage_reviewer_confirmed
No definition is given in NIST SP 800-171r3. The term is attested in use at 2 citations in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · web_lookup_draft
The movement of Controlled Unclassified Information (CUI) as it transits within a system and between systems — distinct from the question of *who* may access that information — governed by policy-based controls at enforcement points. Organizations use information flow control policies and enforcement mechanisms to regulate movement between designated sources and destinations (e.g., networks, individuals, and devices) within systems and between interconnected systems. Enforcement occurs in boundary protection devices such as gateways, routers, guards, encrypted tunnels, and firewalls, which employ rule sets or configuration settings that restrict services, filter packets based on header information, or filter messages based on content. Identifying and controlling how CUI flows throughout an organization determines, in many ways, how all other security controls in a framework such as NIST SP 800-171 are implemented.
DR-088 backfill from the noun definition column