AC.L2-3.1.22Control Public Information [CUI Data]
Control CUI posted or processed on publicly accessible systems.
[a]
individuals authorized to post or process information on publicly accessible systems are identified;[b]
procedures to ensure CUI is not posted or processed on publicly accessible systems are identified;[c]
a review process is in place prior to posting of any content to publicly accessible systems;[d]
content on publicly accessible systems is reviewed to ensure that it does not include CUI; and[e]
mechanisms are in place to remove and address improper posting of CUI.
Public site and social: CUI review gate before publish
Implementation
AO coverage. Addresses all Control Public Information objectives for CUI posted or processed on public systems.
Process. Anything destined for the public website, social media, or public careers portal is reviewed by someone who did not author it, using a CUI/OPSEC checklist (no markings, no unpublished program detail, no CUI).
Technical. CMS publish rights are limited to marketing leads. Public forms do not accept file uploads that could contain CUI; careers resumes route to an HR system with restricted access, not the public CMS DB.
Maintenance. Quarterly sample of public posts against the checklist. After incidents industry-wide, refresh the checklist.
Accepted gap. Employees’ personal social media cannot be fully controlled. Annual training + reporting channel for suspected CUI exposure; takedown procedure documented.
What the evidence looks like
- Public-release checklist and sample completed reviews
- CMS role permissions
- Careers upload data-flow diagram
- Training completion report
Environment
Tools
Was this example useful?
Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.
Discussion(0)
No discussion on this example yet
Verdicts capture a conclusion. Use a thread when the interesting part is the argument.
Sign in to start a thread.