ATT2 - CUI_Management_Plan.docx
DOCX document 42 KB Posted
- Attached to
- Environmental Microbes as a BioEngineering Resource (EMBER) Federal contract opportunity
- Solicitation number
- HR001121S0035
About this file
This Controlled Unclassified Information (CUI) Management Plan template outlines requirements for protecting CUI related to the Environmental Microbes as a BioEngineering Resource (EMBER) program. The template addresses who will have access to CUI and their training. It also provides guidance on information technology security in compliance with NIST SP 800-171, physical security, international traffic regulations, self-inspections, subcontractors, and destruction of CUI materials. Performers must complete the template or provide a detailed CUI Management Plan describing how they will meet all specified safeguarding requirements to protect CUI involved in the EMBER program from unauthorized access.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| ATT1 - CUI_Guide.pdf | ||
| ATT6 - MS Excel MS Excel Cost Proposal Template.xlsx | XLSX spreadsheet | |
| ATT5 - Executive_Summary_Proposal_Template.pptx | PPTX presentation | |
| ATT4 - Executive_Summary_Abstract_Template.pptx | PPTX presentation | |
| HR001121S0035.pdf | ||
| ATT3 - SOW_Template.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Insert Performer Name
CONTROLLED UNCLASSIFIED INFORMATION (CUI) MANAGEMENT PLAN
Insert H R#-EMBER
Insert Date The protection of Controlled Unclassified Information (CUI) is of paramount importance to federal agencies and can directly impact the ability of the federal government to successfully conduct its assigned missions and business operations. There are multiple types of CUI and the following documents should be referenced for the EMBER program:
· Controlled Unclassified Information and Controlled Technical Information DoDM 5200.01 Vol 4
· Guidance on networks: NIST SP 800-171 rev. 1
· Executive Oder 13556
· DoDI 5230.24, referencing section 133 of title 10, United States Code
· DoDD 5230.25 Withholding of Unclassified Technical Data From Public Disclosure
· International Traffic in Arms Regulations (ITAR): F.R. Vol. 79
· Export Administration Regulations (EAR) (15 CFR Parts 730-774)
· Federal Acquisition Regulation Supplement clauses 252.227-7013 and 7014
· 32 CFR Part 2002 “Controlled Unclassified Information (CUI)”
· DFARS 252-204-7012, “Safeguarding Covered Defense Information and Cyber Incident Reporting”
· DFARS 252.204-7000, “Disclosure of Information”
· DFARS 252.204-7008, “Compliance with Safeguarding Covered Defense Information Controls”
The Broad Area Announcement (BAA) and CUI Guide outline what information is considered CUI for this program. Performers must be able to meet all CUI safeguarding outlined in the above documents and not grant access of CUI to foreign nationals.
Researchers may be held personally liable for civil or criminal violations of the U.S. CUI Regulations. As a result, you should be clear on the requirements and exercise reasonable care in using and sharing CUI, technology, software, or items with others.
The designed security measures and implementation should be appropriate to the type, nature, CUI aspects and level of CUI information, technology, software, and/or items involved in the project.
Complete the CUI Management Plan template (provided below), or write out a detailed plan covering all of the areas outlined below, indicating how individuals who are not authorized to gain access to CUI will not be able to access it.
Your institutional or project’s CUI Manager will ensure that all laws and regulations pertaining to CUI are adhered to. Their responsibilities include, but are not limited to, verification of citizenship, providing CUI training and tracking, execution of non-disclosure agreements, coordination with State Department on International Traffic in Arms Regulations (ITAR) and Export Administrations Regulations (EAR), coordination with DARPA BTO on public release requests, etc.
Please see the appendix for additional guidance.
CUI Management Plan Template Part 1: Who will be working on CUI and who are the responsible POCs for each department?
1. List the individuals who will have access to CUI (add as many rows as needed). Include IT or physical security staff whom will be able to access, or grant access, to the spaces where material is stored, saved, or processed.
| Name |
| Title/role |
| Citizenship |
| Date NDA was signed |
| Date of CUI Training |
| Phone |
CUI Manager
Physical Security
IT Security
2. Who is primarily responsible for physical security?
3. Who is primarily responsible for IT security?
Part 2: Training:
1. Describe how new staff will be trained.
2. How will training be tracked?
3. For CUI training developed in house, what resources were used to develop the training?
4. For CUI training developed through an external resource, what was the source?
5. Please include a link to the training or a copy of the training.
Part 3: Information Technology:
1. Are all systems where CUI will be processed, or stored, NIST SP 800-171 compliant?
2. If any of the systems are not compliant, explain the following:
a. Has the request to vary from the NIST SP 800-171 been provided to the Contracting Officer (CO), or the DoD Chief Information Officer (CIO)? If so was an accepted variance granted and by whom? If CIO granted the variance please provide proof of the approval.
b. Why is the system not compliant?
c. What, if any, mitigating factors, are there for not being compliant? Is a particular security requirement not applicable or was equally effective, security measure used to compensate for the inability to satisfy a particular requirement and achieve equivalent protection, and if so what is that measure?
d. Will the system be compliant in the future, and if it will, what steps are being taken to make it compliant, and when will they be done?
Part 4: Physical Security
1. What is the plan to prevent individuals not approved to work on CUI from gaining physical access to any CUI material?
2. How will physical documents containing CUI be stored? What kind of containers will CUI materials be stored in? What kind of rooms will the containers be in? Who has access to the rooms and the containers and how is access provided?
3. How are visitors who are not approved to see CUI monitored when visiting locations where CUI is being stored or processed?
4. How will physical documents containing CUI be destroyed?
5. How will physical documents containing CUI be shipped or transported, if that is required?
Part 5: International Traffic in Arms Regulations (ITAR) and Export Administration Regulations (EAR) and if applicable:
1. If applicable, describe the procedure to ensure that no International Traffic in Arms Regulations (ITAR) or Export Administration Regulations (EAR) will be broken during the project and what ECCN or ITAR Category the technology falls under.
Part 6: Self-Inspections:
Describe the self-inspect process to include how often they are taking place, what is being examined and who are the individuals conducting the self-inspections.
Part 7: Tier 1 Suppliers If CUI is being passed to a 3rd party supplier, or a 3rd has access to your systems where CUI is being stored, how is verification being done to assure that they can properly protect CUI?
Part 8: Sub contractors
1. Please describe the work your subcontractor(s) will be doing.
2. Will subcontractors be conducting fundamental research, working with CUI or a combination of the two? Please answer this question, as well as the below questions, for every subcontract.
a. If subcontract will be working with CUI, have you required they provide a CUI Management plan?
i. If you have receive the CUI Management plan from your subcontract, have they verified that they will properly protect CUI, are compliant with NIST SP 800-171, and will adhere to publication review requirements?
ii. If you have not receive a CUI Management plan from the subcontractor(s) have they indicated they will provide a plan that indicated their compliance with CUI regulations prior to being authorized to have access to or produce of CUI.
Part 9: Demonstration Facility/Location:
Outline the relationship with the demonstration facility. Include what information will be shared with the facility, if they will be a full participating partner, or only a location where material and space is purchased from or some combination of the two? Prior the demonstration a demonstration plan template will be provided and must be completed by the performer and approved by DARPA.
Signature of individual who completed the form Date
Appendix
Handling Controlled Unclassified Information
This project involves the use of CUI information, technology, equipment, or software. As a result, U.S. Executive Orders and Federal Regulations apply to the project.
Researchers may be held personally liable for civil or criminal violations of the U.S. CUI Regulations. As a result, you should be clear on the requirements and exercise reasonable care in using and sharing CUI, technology, software, or items with others. This template is designed to help you assess, address, understand your obligations, and control access to the CUI of this project.
The designed security measures and implementation should be appropriate to the type, nature, CUI aspects and level of CUI information, technology, software, and/or items involved in the project.
Per Defense Federal Acquisition Regulation Supplement clauses 252.227-7013, "Rights in Technical Data - Noncommercial Items" and 252.227-7014 Rights in Noncommercial Computer Software and Noncommercial Computer Software Documentation DoD considers “technical information” to be technical data or computer software, as those terms. Specifically, “Technical data” means recorded information, regardless of the form or method of the recording, of a scientific or technical nature (including computer software documentation). “Computer software” means computer programs, source code, source code listings, object code listings, design details, algorithms, processes, flow charts, formulae and related material that would enable the software to be reproduced, recreated, or recompiled. Computer software does not include computer databases or computer software documentation. “Computer software documentation” means owner's manuals, user's manuals, installation instructions, operating instructions, and other similar items, regardless of storage medium, that explain the capabilities of the computer software or provide instructions for using the software. Examples of technical information that could be generated under this Contract include research and engineering data, engineering drawings, and associated lists, specifications, standards, process sheets, manuals, technical reports, technical orders, catalog-item identifications, data sets, studies and analyses and related information, and computer software code. Note that such technical information may or may not be controlled technical information (CTI), depending on whether it has military or space application.
CTI is a subset of CUI and is defined as technical information with military or space application that is subject to controls on its access, use, reproduction, modification, performance, display, release, disclosure, or dissemination. CUI is to be marked with one of the distribution statements B through F, in accordance with Department of Defense Instruction 5230.24, "Distribution Statements on Technical Documents." The term CUI and CTI do not apply to information that is lawfully publicly available without restrictions. All unclassified technical data with military or space application in the possession of, or under the control of, a DoD Component that may not be exported lawfully without an approval, authorization, or license under E.O. 12470 or the Arms Export Control Act and are considered CUI (FIOA Exemption 3 DODD 5230.25 cite 5 U.S.C. 522(b)(3)).
Per DoDD 5230.25 and DoDD 5230.20 CUI controlled by the DoD is only releasable to US citizens and permanent US resident aliens unless a formal agreement between the US government and the receiving foreign organization has been signed or an export license has been obtained. Per DoDM 5200.01 volume 4-CUI, prior to authorizing access to a green card holder the non US citizen must sign a non-disclosure agreement and have their access limited to information that is only within the scope of their assigned duties and only when access furthers the execution of a lawful and authorized DoD mission or purpose, and would not be detrimental to the interests of the Department of Defense or the U.S. Government. Prior to authorizing access to CUI for a green card holder provide a letter of compelling need to DARPA explaining why the proposed individual should be granted access, and why a comparable US citizen cannot be obtain without extensive effort. The letter should include the person’s full name, date of birth (DoB), place of birth (PoB) and citizenship.
The Contractor shall protect CUI in accordance with 32 CFR Part 2002 “Controlled Unclassified Information (CUI)” and the Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting (OCT 2016) and DoDD 5230.20 ” Visits and Assignments of Foreign Nationals.” Contractor information systems shall be subject to the security requirements in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations”. The Contractor must determine and assert appropriate NIST 800-171 ver. 1, DoD and Export Administration Regulations (EAR), International Traffic in Arms Regulations (ITAR) relevant to their project, and abide by DoDD 5230.25 Withholding of Unclassified Technical Data from Public Disclosure (see NIST, 800-171 rev. 1, DoDM 5200.01 volume 4-CUI, Federal Register/ Vol 79 ITAR, No. 126, p. 37542 Category XI for specifics and DoDD 5230.25).
Technical Updates, Reporting, & Deliverables
The recipient will distinguish and compartmentalize CUI from non-CUI information contained in submitted emails, documents, reports, publications and other deliverables. During periods where both non-CUI and CUI data are being generated, materials provided to DARPA must be reasonably dis-aggregated in order to protect CUI being accessed by and/or presented to unauthorized personnel; e.g., the recipient will submit and present both a non-CUI and a CUI monthly status report, as applicable, ensuring that when CUI is presented unauthorized personnel are not present.
(1) Non-CUI reports and deliverables: Non-CUI reports and/or deliverables to be publically released will be marked with Distribution Statement A - “Approved for Public Release-Distribution is Unlimited”. To ensure no CUI is inadvertently released, all papers and articles may be submitted to the DARPA Program Manager to process through DARPA Public Affairs. The request shall include the following information and the recipient shall allow 10 days for this review process:
a) Document information: document title, document author, short plain-language description of technology discussed in the material (approx. 30 words), number of pages (or minutes of video) and document type (briefing, report, abstract, article, or paper);
b) DARPA Sponsor: DARPA Program Manager, DARPA office, and cooperative agreement number; and
c) Recipient's Information: POC name, e-mail and phone.
(2) CUI reports and/or deliverables: Prior to submission of the first CUI report and/or deliverable, the recipient shall submit the documents to the DARPA Program Manager for coordination with the DARPA Security Office to receive proper review by the appropriate authority for Distribution Statement determination. The recipient shall apply this Distribution Statement to the initial and future distribution of these reports and/or deliverables, and these restrictions must be flowed down to all subcontractors.
Training
Training should take place prior to granting access to CUI to individuals. No cost trainings are available.
CUI trainings: http://cdse.adobeconnect.com/cuiv2/output/CUI_Brief.mp4Cyber security: https://cyber.mil/training/cyber-awareness-challenge-2019/ Security awareness / Insider threat: https://securityawareness.usalearning.gov/cybersecurity/index.htm
Public Release and Meetings
Consistent with DARPA Instruction 65 and DoDI 5230.24, the recipient will not share CUI at public meetings and conferences. All information that will be presented at conferences or published should be submitted to DARPA’s Program Manager (PM) for approval prior to release. Please provide a minimum of 15 working days prior to the date required or clearance may not be achieved. At DARPA-sponsored meetings CUI will not be shared beyond the performer team’s authorized personnel, the government team, and the government-selected independent validation & verification (IV&V) team, if applicable. If the performer wishes to present CUI at a DARPA sponsored meeting to all participants present verify with DARPA if the CUI content will be permitted and ensure the appropriate distribution statement is add in accordance with DoDI 5230.24. If CUI is approved for the meeting unsure that two presentations are prepared, one with CUI and one without, as additional individuals may be added to the meeting at the last minute who are not authorized to view the CUI.
Marking CUI
The CUI Banner Marking: The primary marking for all CUI is the CUI Banner Marking. This is the main marking that appears at the top and bottom of each page of any document that contains CUI. This marking is MANDATORY for all documents containing CUI. The content of the CUI Banner Marking must be inclusive of all CUI within the document and must be the same on each page. The Banner Marking should appear as bold capitalized black text and be centered when feasible.
If CUI is revealed anywhere in the document the Banner Marking is:
CUI
Any subject, title, and section, part, paragraph, or similar portion that contains CUI information will be conspicuously marked with a “(CTI)” notation.
Place the notation immediately before the text. This will alert the reader that the information requires protection.
Use of the unclassified marking “(U)” as a portion marking for unclassified information is required for any subject, title, and section, part, paragraph, or similar portion.
· The cover slide will include a CUI designation indicator which will include:
· The name of the DoD component determining the information is CUI (this may be omitted if letterhead or another standard indicator of origination is used.
· The second line must identify the office making the determination
· The third line must identify all types of CUI contained in the document.
· The fourth line must contain the applicable distribution statement or the dissemination controls.
· The fifth line must contain the phone number or office mailbox for the CUI holder.
Further guidance on marking may be found at DoDM 5200.48.
Data Sharing The recipient will enforce the CUI Management Plan that allows program research goals to be met while meeting CUI safeguarding requirements. Verify with the DARPA Program Manager what CUI can be shared with another performer prior to disclosure.
Physical Security
Facility Security Basic Practices – Plans to protect project data and materials from observation by unauthorized individuals. One example could include operating in secured laboratory spaces or during secure time blocks when observation by unauthorized persons is prevented.
Authorized holders must take reasonable precautions to guard against unauthorized disclosure of CUI. They must include the following measures among the reasonable precautions:
(1) Establish controlled environments in which to protect CUI from unauthorized access or disclosure and make use of those controlled environments.
(2) Compliance with DoDM 5200.48.
(3) Keep CUI under the authorized holder’s direct control or protect it with at least one physical barrier, and reasonably ensure that the authorized holder or the physical barrier protects the CUI from unauthorized access or observation when outside a controlled environment.
(4) Protect the confidentiality of CUI that agencies or authorized holders process, store, or transmit on information systems in accordance with the applicable security requirements and controls established in DoDM 5200.48, DFARS 252-204-7012 and NIST SP 800-171.
(5) The plan should provide that materials be physically secured from access when not in use per 5200.48 and NIST SP 800-171.
(6) Procedures to ensure that only project members are present in the secured areas when work on this project is being performed per NIST SP 800-171.
(7) Plans to prevent foreign nationals viewing or having access to any project data (physical or digital) or secured area (including maintenance, cleaning, and others) as specified in DoDM 5200.48.
Work Products – Paper data, lab notebooks, reports, and research materials are stored in in a secure location, preferably located in rooms with key-controlled access and in locked containers if access to the location where the material is being stored is not adequate per DoDM 5200.01 V4.
Conversations - Discussions about the project or work products are limited to the identified individuals above and are held only in areas where unauthorized personnel are not present. Discussions with third party sub-contractors are only to be conducted under signed agreements that fully respect the CUI security requirements for such disclosures.
Protecting CUI when shipping or mailing
When shipping or mailing CUI:
(1) Must mark packages that contain CUI according to marking requirements contained in DoDM 5200.48.
(2) Address packages that contain CUI for delivery only to a specific recipient
(3) DO NOT put CUI markings on the outside of an envelope or package
(4) Use in-transit automated tracking and accountability tools where possible
(5) FOUO information and material may be transmitted via first class mail, parcel post, or, for bulk shipments, via fourth class mail.
(6) May use interoffice or interagency mail systems to transport CUI
Reproducing CUI
Authorized holders may:
(1) Reproduce (e.g., copy, scan, print, electronically duplicate) CUI in furtherance of a lawful Government purpose
(2) Must ensure, when reproducing CUI documents on equipment such as printers, copiers, scanners, or fax machines, that the equipment does not retain data or the holder must otherwise sanitize it in accordance with DoDM 5200.48 and NIST 800-171.
Destruction
Authorized holders may destroy CUI when:
(1) The user no longer needs the information
(2) Records disposition schedules published or approved by NARA allow.
When destroying CUI, including in electronic form, holders of CUI must do so in a manner that makes it unreadable, indecipherable, and irrecoverable. If the authority does not specify a destruction method, holders must use one of the following methods: (i) Guidance for destruction in NIST SP 800–53, Security and Privacy Controls for Federal Information Systems and Organizations, and NIST SP 800–88, Guidelines for Media Sanitization (incorporated by reference, see §2002.2); or (ii) Any method of destruction approved for Classified National Security Information, as delineated in 32 CFR 2001.47, Destruction, or any implementing or guidance as provided in DoDM 5200.48.
Export Control / ITAR
Performers shall comply with all applicable laws and regulations regarding export-controlled items. It is in the interest of both the Government and the performer to be aware of export controls as they apply to the performance of specific DoD contracts. As a result, proposers shall identify export-controlled items subject to Export Administration Regulations (EAR) or the International Traffic in Arms Regulations (ITAR). All printed and electronic, including digital technical documents that are determined to contain export-controlled technical data shall be marked as follows:
WARNING - This document contains technical data whose export is restricted by the Arms Export Control Act (Title 22, U.S.C., Sec 2751, et seq.) or the Export Administration Act of 1979 (Title 50, U.S.C., App. 2401 et seq.), as amended. Violations of these export laws are subject to severe criminal penalties. Disseminate in accordance with provisions of DoD Directive 5230.25.
File details come from the government source that posted it. Updated .