Skip to content
ControlVerdict
AC.L2-3.1.3addresses
AC.L2-3.1.3Control CUI Flow
Control the flow of CUI in accordance with approved authorizations.
  • [a]

    information flow control policies are defined;
  • [b]

    methods and enforcement mechanisms for controlling the flow of CUI are defined;
  • [c]

    designated sources and destinations (e.g., networks, individuals, and devices) for CUI within the system and between interconnected systems are identified;
  • [d]

    authorizations for controlling the flow of CUI are defined; and
  • [e]

    approved authorizations for controlling the flow of CUI are enforced.

View full control

CUI only in labeled libraries; DLP blocks unlabeled egress

ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
Community is just starting — add yours. No verdicts yet.

Implementation

AO coverage. Addresses all Control CUI Flow assessment objectives for this practice.

Authoritative store. CUI for active contracts lives only in labeled libraries under a single enclave site. Desktop sync is disabled for those libraries; access is browser or managed app with device compliance required.

Labeling. A mandatory Purview sensitivity label (“CUI”) applies encryption and blocks download to unmanaged devices. Users cannot save CUI to personal OneDrive locations: DLP policy detects the label (and common CUI marking strings in headers) and blocks the copy.

Egress. Outbound email with the CUI label requires encryption and an internal recipient domain allow-list, or encryption plus an approved external partner domain list maintained by contracts. USB write is blocked on enclave-compliant devices via Intune; exceptions are ticketed and time-bounded.

Maintenance. Quarterly label coverage report on the enclave libraries (unlabeled files become a remediation ticket). Monthly review of DLP false-positive suppressions. Contracts updates the external partner domain list; IT only applies the list.

Accepted gap. Plotters and one legacy CAD share cannot apply labels natively. Those systems sit on an isolated VLAN; export to the labeled library is a controlled job with dual review before release.

What the evidence looks like

  • Site / library configuration showing sync disabled and label default
  • Purview DLP policy export (conditions, actions, exceptions)
  • Intune device configuration profile blocking USB write for enclave devices
  • Sample blocked-egress incident ticket and remediation
  • Partner domain allow-list change ticket trail

Environment

Small supplier; CUI in one SharePoint Online site collection; email and unmanaged USB are the main leak paths of concern.

Tools

Was this example useful?

Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.

Discussion(0)

No discussion on this example yet

Verdicts capture a conclusion. Use a thread when the interesting part is the argument.

Sign in to start a thread.