home/glossary/flow of CUI

flow of CUI

nounid 163598·updated Sep 1, 2026
verified

The movement of Controlled Unclassified Information (CUI) as it transits within a system and between systems — distinct from the question of *who* may access that information — governed by policy-based controls at enforcement points. Organizations use information flow control policies and enforcement mechanisms to regulate movement between designated sources and destinations (e.g., networks, individuals, and devices) within systems and between interconnected systems. Enforcement occurs in boundary protection devices such as gateways, routers, guards, encrypted tunnels, and firewalls, which employ rule sets or configuration settings that restrict services, filter packets based on header information, or filter messages based on content. Identifying and controlling how CUI flows throughout an organization determines, in many ways, how all other security controls in a framework such as NIST SP 800-171 are implemented.

MWE

Source

document
NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems
found in
proposed during MWE review
element
e0177
proposed by
dorianc@moxywolf.com
discovery
ManualCuration
for controlling the flow ofthe sentence this term was read in
Where the definition came fromawaiting curator confirmation

generalized from a web lookup of the quoted expression at proposal time Verdict: compositional.

A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.

A web lookup ran when this term was proposed

The movement of Controlled Unclassified Information (CUI) across boundaries — within a system, between interconnected systems, and into or out of an organization — as a subject of policy-governed enforcement. It is distinguished from access control in that it regulates *where* CUI can transit within a system and between systems, rather than *who* is allowed to access the information, and without regard to subsequent accesses to that information. Organizations use information flow control policies and enforcement mechanisms to control the flow of information between designated sources and destinations — such as networks, individuals, and devices — within systems and between interconnected systems. In practice, identifying and controlling how CUI flows throughout an organization determines the manner in which all other protective controls will be implemented, with enforcement applied via boundary devices, encryption requirements, proxy routing, and data-transfer restrictions.

Advisory only. A term this product ships is defined by an authority document, not by a search result.

Proposed during multiword review of this document in the CKI mapping queue.

Attested in

NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems2 citations · 2 confirmed by a reviewer · observed 2026-09-01 under anchor/0.9/36451/2026-09-01
03.01.03 ¶ 103.01.03 ¶ 4

Classifications

Entity Type

Process85%manual reviewllm:claude-haiku-4-5

Sensitivity

Regulated95%rule-basedr:sens.regulated.framework.v1

Information Class

Cui95%rule-basedr:info.cui.named.v1

Variants

plural
flow of CUIs
possessive
flow of CUI's
pluralpossessive
flow of CUIs'

Framework definitions

NIST SP 800-171r31 senseview framework →
§1 · attested_usage_reviewer_confirmed
No definition is given in NIST SP 800-171r3. The term is attested in use at 2 citations in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · web_lookup_draft
The movement of Controlled Unclassified Information (CUI) as it transits within a system and between systems — distinct from the question of *who* may access that information — governed by policy-based controls at enforcement points. Organizations use information flow control policies and enforcement mechanisms to regulate movement between designated sources and destinations (e.g., networks, individuals, and devices) within systems and between interconnected systems. Enforcement occurs in boundary protection devices such as gateways, routers, guards, encrypted tunnels, and firewalls, which employ rule sets or configuration settings that restrict services, filter packets based on header information, or filter messages based on content. Identifying and controlling how CUI flows throughout an organization determines, in many ways, how all other security controls in a framework such as NIST SP 800-171 are implemented.
DR-088 backfill from the noun definition column

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.