Control CUI Flow
Practice statement
Control the flow of CUI in accordance with approved authorizations.
Quoted verbatim from NIST SP 800-171 Rev. 2 §3.1.3.Source
The source document’s non-normative “Discussion” section is not reproduced here. ControlVerdict quotes normative text verbatim or omits it — it never paraphrases a standard. Follow the source link above for the full context.
Assessment Objectives(5)
An assessor determines each objective separately. “Mostly implemented” is not a result — every objective below has to stand on its own.
- [a]
information flow control policies are defined;
1 example covers this
- [b]
methods and enforcement mechanisms for controlling the flow of CUI are defined;
1 example covers this
- [c]
designated sources and destinations (e.g., networks, individuals, and devices) for CUI within the system and between interconnected systems are identified;
1 example covers this
- [d]
authorizations for controlling the flow of CUI are defined; and
1 example covers this
- [e]
approved authorizations for controlling the flow of CUI are enforced.
1 example covers this
Objective text quoted verbatim from NIST SP 800-171A via the CMMC Level 2 assessment guide.
Implementation examples(1)
Submit your own example- addresses
AC.L2-3.1.3Control CUI Flow
Control the flow of CUI in accordance with approved authorizations.
[a]
information flow control policies are defined;[b]
methods and enforcement mechanisms for controlling the flow of CUI are defined;[c]
designated sources and destinations (e.g., networks, individuals, and devices) for CUI within the system and between interconnected systems are identified;[d]
authorizations for controlling the flow of CUI are defined; and[e]
approved authorizations for controlling the flow of CUI are enforced.
CUI only in labeled libraries; DLP blocks unlabeled egress
ControlVerdict Corpus@cv-corpusOSCJul 31, 2026Community is just starting — add yours. No verdicts yet.Implementation
AO coverage. Addresses all Control CUI Flow assessment objectives for this practice.
Authoritative store. CUI for active contracts lives only in labeled libraries under a single enclave site. Desktop sync is disabled for those libraries; access is browser or managed app with device compliance required.
Labeling. A mandatory Purview sensitivity label (“CUI”) applies encryption and blocks download to unmanaged devices. Users cannot save CUI to personal OneDrive locations: DLP policy detects the label (and common CUI marking strings in headers) and blocks the copy.
Egress. Outbound email with the CUI label requires encryption and an internal recipient domain allow-list, or encryption plus an approved external partner domain list maintained by contracts. USB write is blocked on enclave-compliant devices via Intune; exceptions are ticketed and time-bounded.
Maintenance. Quarterly label coverage report on the enclave libraries (unlabeled files become a remediation ticket). Monthly review of DLP false-positive suppressions. Contracts updates the external partner domain list; IT only applies the list.
Accepted gap. Plotters and one legacy CAD share cannot apply labels natively. Those systems sit on an isolated VLAN; export to the labeled library is a controlled job with dual review before release.
What the evidence looks like
- Site / library configuration showing sync disabled and label default
- Purview DLP policy export (conditions, actions, exceptions)
- Intune device configuration profile blocking USB write for enclave devices
- Sample blocked-egress incident ticket and remediation
- Partner domain allow-list change ticket trail
Environment
Small supplier; CUI in one SharePoint Online site collection; email and unmanaged USB are the main leak paths of concern.Tools
Discussion(0)
No discussion on this control yet
Edge cases, scoping questions, and “would this pass?” scenarios belong here.
Sign in to start a thread.