2002.4 - Definitions Flashcards
Any “executive agency”, the USPS, and any other independent entity within the executive branch that designates or handles CUI.
Agency
An Agency is any “(a)_________ ______”, the (b)____, and any other (c)___________ ______ within the executive branch that designates or handles CUI.
(a) “executive agency”
(b) USPS
(c) independent entity
Policies the agency enacts to implement the CUI Program within the agency, in accordance with the EO 13556, 32 CFR Part 2002, and the CUI Registry and approved by the CUI EA.
Agency CUI policies
Any vehicle that sets out specific CUI handling requirements for contractors and other information-sharing partners when the arrangement with the other party involves CUI.
Agreements and arrangements
An individual, agency, organization, or group of users that is permitted to designate or handle CUI IAW 32 CFR Part 2002.
Authorized holder
Any area or space that an authorized holder deems to have adequate physical or procedural controls to protect CUI from unauthorized access or disclosure.
Controlled envrionment
A general term that indicates the safeguarding and disseminating requirements associated with CUI Basic and CUI Specified.
Control level
This is information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation, or policy requires or permits an agency to handle using safeguarding or dissemination controls.
Controlled Unclassified Information (CUI)
Controlled Unclassified Information (CUI) is information the (a)__________ _______ __ _________, or that an (b)______ _______ __ _________ ___ __ __ ______ __ __ __________ that a law, regulation, or policy requires or permits an agency to handle using safeguarding or dissemination controls.
(a) Government creates or possesses
(b) entity creates or possesses for or on behalf of the Government
Controlled Unclassified Information (CUI) is information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that ____, __________, or ________ _______ __ ______ an agency to handle using safeguarding or dissemination controls.
Laws, regulations, or policies require or permit
CUI includes classified information? T/F
False
CUI excludes information a non-executive branch entity possesses and maintains in its own systems that did not come from, or was not created or possessed by or for, an executive branch agency or an entity acting for an agency? T/F
True
Requiring or permitting agencies to control or protect the information but providing no specific controls makes the information ___ _____?
CUI Basic
CUI Basic requires or permits agencies to control or protect information, providing __ ________ controls.
No specific
Requiring or permitting agencies to control or protect the information and providing specific controls for doing so makes the information ___ __________.
CUI Specified
CUI Specified requires or permits agencies to control or protect information and provides ________ ________ for doing so.
Specific controls
Requiring or permitting agencies to control the information and specifying only some of those controls, which makes the information (a)___ __________, but with (b)___ _____ controls where the authority does not specify.
(a) CUI Specified
(b) CUI Basic
________ are safeguarding or dissemination controls that a law, regulation, or policy requires or permits agencies to use when handling CUI.
Controls
CUI Basic is the subset of CUI for which the authorizing law, regulation, or policy ____ ___ ___ ________ __________ __ _____________ ________.
Does not set out specific handling or dissemination controls
Agencies handle CUI Basic according to the uniform set of controls set forth in (a)__ __ ____ and the (b)___ ________.
(a) 32 CFR Part 2002
(b) CUI Registry
CUI Basic controls apply whenever ___ __________ ones do not cover the involved CUI.
CUI Specified
___ __________ are those types of information for which laws, regulations, or policies require or permit agencies to exercise safeguarding or dissemination controls, and which the CUI EA has approved and listed in the CUI Registry.
CUI categories
CUI categories are those types of information for which laws, regulations, or policies require or permit agencies to exercise safeguarding or dissemination controls, and which the (a)___ __ has approved and listed in the (b)___ ________.
(a) CUI EA
(b) CUI Registry
The markings approved by the CUI EA for the categories and subcategories listed in the CUI Registry.
CUI category or subcategory markings
___ _________ _____ (__) is the National Archives and Records Administration (NARA), which implements the executive branch-wide CUI Program and oversees Federal agency actions to comply with the EO 13356.
CUI Executive Agent (EA)
________ ________ ___ _______ ______________ (____) is the CUI Executive Agent (EA) which implements the executive branch-wide CUI Program and oversees Federal agency actions to comply with the EO 13556.
National Archives and Records Administration (NARA)
NARA has delegated CUI authority to the ________ __ ___ ___________ ________ _________ _______ (ISOO).
Director of the Information Security Oversight Office (ISOO)
___ _______ is the executive branch-wide program to standardize CUI handling by all Federal agencies.
CUI Program
___ _______ _______ is an agency official, designated by the agency head or CUI Senior Agency Official (SAO), to serve as the official representative to the CUI EA on the agency’s day-to-day CUI Program operations, both within the agency and in interagency contexts
CUI Program manager