Shadow AI is already using your data. Get the complimentary Gartner® report. Read the report

A Blueprint for CUI Security Compliance

PKWARE

By PKWAREProductivity Protected

Share on social media

The Department of Defense has rolled out a compliance certification regime using a cyber maturity model framework (CMMC). Vendors to the DoD will be required to have a third-party assessment of the company’s cyber controls that attest that the company is able to protect controlled unclassified information (CUI) under the CMMC guidelines. Vendors who are not assessed at a certain maturity level will not receive contract awards from the government.

Download this ebook to learn more about:

  • Easy and cost-effective methodology for protecting CUI
  • The key principles of CUI-centric security
  • How to build and implement the right security measures

What Is CUI-Centric Security?

CUI-centric security protects the file rather than the place the file happens to sit. Most security technology works the other way round, securing a laptop, a server or a network segment. That approach holds only while the data stays put. As soon as a file moves, it either needs a second control or it travels unprotected.

Protecting the data itself removes that dependency. Sensitive information is identified and classified as it enters the environment, and policy-based protection stays attached to it for the rest of its life. Authorized users still open the file normally. Everyone else cannot, including outside the company network.

What Counts as Controlled Unclassified Information?

CUI spans roughly 20 organizational index groupings, among them defense, intelligence, financial and law enforcement information. Four categories define the defense-related set.

Controlled Technical Information is technical data with military or space application, subject to controls on access, use, reproduction and release. DoD Critical Infrastructure Security Information would reveal vulnerabilities in DoD critical infrastructure if disclosed. Naval Nuclear Propulsion Information concerns reactor safety and radiation control in naval propulsion plants. Unclassified Controlled Nuclear Information covers DoD special nuclear material, equipment and facilities.

Why User-Applied Encryption Falls Short

Most organizations already have some file-level protection, usually employees encrypting files with passwords before sharing them. That habit creates three problems at once.

People forget, or choose a method that is not strong enough. Those who do encrypt then have to get the password to the recipient, which usually means unencrypted email. And because the employee holds the key, the organization can permanently lose access to its own data when someone forgets a password or leaves the company.

Centralized control removes all three. Access to protected data can be granted or revoked at any time, all activity is logged for auditing and reporting, and the ad hoc encryption that blinds a DLP system disappears.

The Four Principles of a CUI-Centric Program

Every organization needs a design of its own, tailored to its threat exposure and how it works. Successful implementations still share four characteristics.

Centralized control means policy is set and enforced in one place rather than by each employee in turn. Gapless protection means files stay protected across operating systems and platforms, closing the points where data is normally stripped of protection in order to move. Automation means classification and protection happen as files are created or changed, rather than asking people to judge sensitivity for themselves. Adaptability means the design absorbs new infrastructure, new processes and new partners without being rebuilt each time.

Policies, Rules and Workflows Are Not the Same Thing

The three terms are often used interchangeably and describe different layers. A policy is the written document stating what the organization requires. A rule is the software configuration that applies that policy to a specific use case. A workflow is the sequence the software actually performs, including monitoring file activity, scanning for sensitive data, applying classification tags and applying protection.

The distinction matters at assessment time, because a written policy with no matching rule protects nothing and an assessor will treat it accordingly.

Where to Start: A Data Risk Assessment

The assessment comes before the technology decision, and it should be repeated rather than reused. Infrastructure and business processes change between assessments, and data-specific issues rarely appear in an older review written for network and device controls.

A useful assessment establishes what data is being created and acquired, the use cases for each type and each user group, the risk attached to each of those, who should have access in each case, how well any existing protection actually works, and which standards apply, whether CMMC, GDPR or HIPAA. With those answers, written policies can guide the choice of technology instead of being written afterwards to match it.

PKWARE

PKWARE

Productivity Protected

PKWARE has been securing sensitive data for over 40 years. We’ve earned the trust of 21 of the 25 largest banks in the U.S. Our team delivers modern, data-centric security solutions organizations can rely on.