Skip to content
ControlVerdict
AC.L2-3.1.22CMMC Level 2Level 2

Control Public Information [CUI Data]

Practice statement

Control CUI posted or processed on publicly accessible systems.

Quoted verbatim from NIST SP 800-171 Rev. 2 §3.1.22.Source

The source document’s non-normative “Discussion” section is not reproduced here. ControlVerdict quotes normative text verbatim or omits it — it never paraphrases a standard. Follow the source link above for the full context.

Assessment Objectives(5)

An assessor determines each objective separately. “Mostly implemented” is not a result — every objective below has to stand on its own.

  1. [a]

    individuals authorized to post or process information on publicly accessible systems are identified;

    1 example covers this

  2. [b]

    procedures to ensure CUI is not posted or processed on publicly accessible systems are identified;

    1 example covers this

  3. [c]

    a review process is in place prior to posting of any content to publicly accessible systems;

    1 example covers this

  4. [d]

    content on publicly accessible systems is reviewed to ensure that it does not include CUI; and

    1 example covers this

  5. [e]

    mechanisms are in place to remove and address improper posting of CUI.

    1 example covers this

Objective text quoted verbatim from NIST SP 800-171A via the CMMC Level 2 assessment guide.

Implementation examples(1)

Submit your own example
  • addresses
    AC.L2-3.1.22Control Public Information [CUI Data]
    Control CUI posted or processed on publicly accessible systems.
    • [a]

      individuals authorized to post or process information on publicly accessible systems are identified;
    • [b]

      procedures to ensure CUI is not posted or processed on publicly accessible systems are identified;
    • [c]

      a review process is in place prior to posting of any content to publicly accessible systems;
    • [d]

      content on publicly accessible systems is reviewed to ensure that it does not include CUI; and
    • [e]

      mechanisms are in place to remove and address improper posting of CUI.

    Public site and social: CUI review gate before publish

    ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
    Community is just starting — add yours. No verdicts yet.

    Implementation

    AO coverage. Addresses all Control Public Information objectives for CUI posted or processed on public systems.

    Process. Anything destined for the public website, social media, or public careers portal is reviewed by someone who did not author it, using a CUI/OPSEC checklist (no markings, no unpublished program detail, no CUI).

    Technical. CMS publish rights are limited to marketing leads. Public forms do not accept file uploads that could contain CUI; careers resumes route to an HR system with restricted access, not the public CMS DB.

    Maintenance. Quarterly sample of public posts against the checklist. After incidents industry-wide, refresh the checklist.

    Accepted gap. Employees’ personal social media cannot be fully controlled. Annual training + reporting channel for suspected CUI exposure; takedown procedure documented.

    What the evidence looks like

    • Public-release checklist and sample completed reviews
    • CMS role permissions
    • Careers upload data-flow diagram
    • Training completion report

    Environment

    Marketing site on public CMS; LinkedIn company page; careers portal.

    Tools

Discussion(0)

No discussion on this control yet

Edge cases, scoping questions, and “would this pass?” scenarios belong here.

Sign in to start a thread.