Attach 9 - CUI Policy Guide (05.06.2016).pdf

PDF 1 MB Posted

Attached to
AOC MACC Onboarding Federal contract opportunity
Solicitation number
AOCACB25R0006
Issued by
Architect of the Capitol

About this file

This is an Architect of the Capitol (AOC) Order 42-4 establishing requirements for handling Controlled Unclassified Information (CUI). The policy, effective May 6, 2016, sets forth procedures for identifying, marking, protecting, and managing CUI within the AOC and applies to all employees, contractors, and subcontractors who have access to AOC information or resources.

The order details specific requirements for handling CUI, including marking procedures (using "CONTROLLED" at the top center of each page), transmission methods (sealed envelopes marked "TO BE OPENED BY ADDRESSEE ONLY"), storage requirements (locked cabinets or password-protected electronic systems), and destruction procedures (cross-shredding or secure bins). It establishes roles and responsibilities for various AOC officials, defines incident reporting requirements for potential compromises, and outlines disciplinary actions for non-compliance. The policy requires annual security awareness training for all covered persons and includes specific provisions for handling CUI during telework, such as using only AOC-approved devices and prohibiting the use of personal computers unless accessing through the AOC approved Virtual Desktop.

View the file

Other files for this federal contract opportunity

Show all 21

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

A fli!lnarm trillliiQ

ARCHITECT

OF THE CAPITOL

Architect of the Capitol U.S. Capitol, Room SB-16 Washington, DC 20515 202.228.1793 www.aoc.gov

EFFECTIVE DATE: May 6, 2016

SUBJECT: Security of Controlled Unclassified Information

SERIES: Security Programs

United States Government

ORDER 42-4

DESCRIPTION: This Order sets forth requirements within the Architect of the Capitol (AOC), to identify certain unclassified sensitive information as Controlled Unclassified Information (CUI) and to identify, mark and protect documents containing such information. This information has the potential to damage governmental, commercial or private interests if disseminated to persons who do not need to know the information to perform their jobs or other AOC-authorized activities.

SCOPE: This Order applies to all persons who have access to information or other resources under the authority or control of AOC. This includes AOC employees, contractors, subcontractors and the employees of contractors and subcontractors. For the purpose of this Order, those persons to whom this Order applies are referred to as "covered persons."

Compliance with this AOC Order shall commence within one year of this Order's effective date.

OPR: Office of Security Programs (OSP)

SUMMARY OF CHANGES: This policy shall balance the need to safeguard CUI with the need to ensure that authorized holders of CUI may disseminate it appropriately and are not unnecessarily burdened while doing so.

SUPERSEDES: This Order supersedes AOC Order 7-2-4: Data Sensitivity Policy dated September 8, 2008.

Stephen . Ayers, F AlA, L Architect of the Capitol

ORDER OF THE ARCHITECT OF THE CAPITOL 42-4

SECURITY OF CONTROLLED UNCLASSIFIED INFORMATION

Table of Contents

1. Purpose

1.1. Background

1.1.1. Scope

1.1.2. Definition of CUI

1.1.3. Identifying CUI

2. Policy

2.1. Information Designated as CUI .......................................................................................................................... S

2.2. Contractor Requirements ....................................................................................................................................... S

2.3. Designation Authority ............................................................................................................................................. S

2.4. Marking .......................................................................................................................................................................... s

2.5. Duration of Designation

2.6. Marking Exceptions ................................................................................................................................................. ?

2.7. Protection ofCUI

2.8. CUI Handling Procedures during Telework

2.9. CUI Dissemination and Access

2.1 0. CUI Transmission Procedures

2.11. CUI Destruction Procedures ........................................................................................................................... 1 0

2.12. CUI Incident Reporting

2.13. Security Policy Violation and Disciplinary Action

2.14. Deviation from Policy

3. Responsibilities

3 .1. Architect of the Capitol

3.2. Director, Office of Security Programs

3.3. Chiefinformation Officer

3.4. Chief Human Capital Officer

3.5. ChiefFinancial Officer

3 .6. AOC Security Officer

3.7. Office of Security Programs (OSP)

3.8. AOC Organizations

3.9. Acquisition and Material Management Division, Contracting Officers

3.1 0. CUI Custodian

3.11. Covered Person

4. Definitions

4.1. Access

4.2. AOC Security Officer

4.3. Classified Information

4.4. Authorized AOC Official

4.5. Controlled Unclassified Information

4.6. Controlled Environment

4.7. Covered Person

4.8. Document

4.9. Equivalent Markings

AOC Order 42-4, May 6, 2016

4.10. Information

4.11. Lawful Government Purpose

4.12. Originator

4.13. Page Marking

4.14. Safeguarding

4.15. Secure Storage

4.16. Unauthorized Disclosure

4.17. Unauthorized Person

5. Authority

ATTACHMENT A- COMPLIANCE CHECKLIST

1. Purpose

To establish a program within the Architect of the Capitol (AOC), to identify certain sensitive unclassified information as Controlled Unclassified Information (CUI) and to identify, mark, and protect documents containing such information. Documents are marked with the CUI label because the information within has the potential to damage governmental, commercial, or private interests if disseminated to persons who do not have lawful government purpose.

1.1. Background

1.1.1. Scope: CUI includes, but is not limited to: information related to personal and proprietary information, agency operations, security protected information, and records or sensitive information compiled for AOC-authorized activities. It is essential that this information be properly handled, stored and protected from the risk and magnitude of loss or harm that could result from inadvertent or deliberate disclosure, alteration or destruction. One of the Agency's primary responsibilities is to assure the security of the CUI it collects, produces and disseminates in the course of conducting its operations.

1.1.2. Definition of CUI: Controlled Unclassified Information (CUI) is unclassified information that is pertinent to the security of the Congress, the Supreme Court or the national interest of the United States or originated by entities outside the U.S.

Federal Government, and under law or policy requires special handling safeguards, protection from disclosure, and prescribed limits on exchange or dissemination.

1.1.3. Identifying CUI: Within AOC, the marking (label)"CONTROLLED" will be used to identify unclassified information that is pertinent to the security of Congress, the Supreme Court or the national interest of the United States or that which originates by entities outside the U.S. Federal Government under law or policy requiring special handling safeguards, protection from disclosure, and prescribed limits on exchange or dissemination. Markings or labels that are required by law, regulation and government wide policy must be used and not appear with CUI marking.

2. Policy

All AOC personnel, including government employees and contractors, have a duty to protect the Agency's CUI from improper disclosure. Persotmel with custody of CUI are responsible for taking reasonable steps to safeguard CUI and are under an affirmative duty to report any known security breaches to the AOC Security Officer as soon as practical. Jurisdictions will identify and categorize their types of CUI, and instruct employees and contractors on proper protection of sensitive data.

2.1. Information Designated as CUI:

2.1.1. The National Archives and Records Administration (NARA) has established and maintains a public CUI Registry to serve as the central repository for authorized CUI categories.

2.1.2. This registry can be found at: http://www.archives.gov/cui/

2.1.3. The NARA CUI Registry is the single Executive Branch authoritative repository for the types of information that are CUI. Although not applicable to the AOC by law, AOC shall adopt the NARA CUI Registry by policy for the purposes of this Order.

2.2. Contractor Requirements: When CUI is to be provided to or generated by AOC contractors, the controls and protective measures to be applied shall be described in the pertinent contract documents (e.g., contract clause or statement of work). Solicitations and contracts shall use a non-disclosure of information clause that prohibits releasing CUI without approval of the contracting jurisdiction. The clause shall also apply to subcontractors.

2.3. Designation Authority: All covered persons can use the categories cited in the National Archives and Records Administration (NARA) CUI registry to designate information as CUI. The registry can be found at: http://www.archives.gov/cui/. Jurisdiction heads are authorized to designate other information, not listed above and originating under their jurisdiction, as CUI. The Office of Security Programs (OSP) can designate any AOC originated or held information as CUI.

2.4. Marking: Information designated as CUI will be sufficiently marked so that persons having access to it are aware of its sensitivity and protection requirements. The lack of CUI markings on materials does not relieve the covered person from safeguarding responsibilities. Where the CUI marking is not present on materials known by the covered person to be CUI, the covered person will protect it as CUI. CUI documents do not require a document register.

2.4.1. Documents shall be marked "CONTROLLED" at the top center of each page containing CUI. For consistency with classified systems, the document may also be marked "//CONTROLLED//."

2.4.2. For consistency with classified systems, internal pages may be marked "//CONTROLLED II" or "//CUI//"; in such cases internal pages shall be marked at both the top and bottom.

2.4.3. Each part of electronically transmitted messages, including e-mail containing CUI shall be marked. Unclassified messages containing CUI shall be marked "CONTROLLED" (optionally "//CONTROLLED//" or "//CUI//") before the beginning of the text. The subject field of a CUI electronically transmitted message must contain the marking "(CUI)" positioning the CUI marking at the end of the Subject field to ensure message recipient(s) identify safeguarding responsibilities.

2.4.4. Transmittal documents that have CUI attachments shall be marked with the following statement or a similar one: "CONTROLLED ATTACHMENT."

2.4.5. Blueprints, engineering drawings, charts, maps, and similar items not contained within another document shall be marked with the CUI designation when applicable. The marking shall be unabbreviated, conspicuous and applied to the top and bottom, if possible, in such a manner as to ensure reproduction on any copies.

The legend or title shall also be marked. The parenthetical marking "(CUI)" following the legend or title may be used. If the blueprints, maps and other items are large enough that they are likely to be rolled or folded, additional CUI markings shall be placed to be visible when the item is rolled or folded.

2.4.6. Congressional Security Sensitive. Congressional Security Sensitive (CSS) is a marking sometimes applied, in addition to or in lieu of the marking "Controlled Unclassified Information," by the Capitol Police Board and select Member(s), officer(s), and committee(s) of either the House or Senate. It denotes information that is: (1) sensitive with respect to the policing, protection, physical security, intelligence, counterterrorism actions or emergency preparedness and response relating to Congress, any statutory protector of the Capitol Police and the Capitol buildings and grounds; and (2) is obtained by, on behalf of or concerning the Capitol Police Board, the Capitol Police or any incident command relating to emergency response.

2.4.6.1. Marking. In unclassified documents containing CSS information, the phrase "Congressional Security Sensitive" shall accompany the phrase "Controlled Unclassified Information" at the bottom of the outside front cover (if there is one), the title page (if there is one), and the outside back cover (if there is one). Each page containing this information shall be marked "Controlled Unclassified Information//Congressional Security Sensitive" or "(CUI-CSS)" at the bottom.

2.4.6.2. Access. Access to CSS information shall be granted only to persons who have a valid need to know the information.

2.4.6.3. Protection. Within the AOC, CUI-CSS information shall be safeguarded and destroyed as required for CUI pursuant to the applicable records management schedule, if any.

2.4.6.4. The originator of CSS is responsible for ensuring that it qualifies for CSS status and for applying the appropriate marking at the time of origination.

2.5. Duration of Designation: Information designated as CUI will retain its designation until determined otherwise by the jurisdiction head having program management responsibility over the information or the Office of Security Programs. The Director, Office of Security Programs (OSP) is the ultimate decision maker of CUI designation(s), unless otherwise exempted or excluded by the AOC. When CUI status is terminated, all known covered person( s) shall be notified, to the extent practical. Upon notification, covered person(s) shall efface or remove the markings. Records already in file or storage do not need to be retrieved to remove markings.

2.6. Marking Exceptions: Exceptions to applying CUI marking include:

2.6.1. Records in storage. Documents that may contain CUI that are maintained in files with restricted access (e.g., Records Management, personnel office files) do not need to be reviewed and marked. When retrieved for reference, inventory or other similar purposes from the files, CUI documents need not be reviewed or marked as long as the documents are returned to files and are inacces~ible to unauthorized individuals.

2.6.2. Sensitive information. Sensitive information already marked under another authority does not need to be remarked. This includes Personal Identifiable Information under AOC Order 4-16, Privacy Policy or information from contractors, businesses and regulated parties marked as business sensitive, confidential, proprietary, trade secret, etc. This information shall be safeguarded and destroyed as required for CUI. This section shall not detract from the applicable provisions of AOC Manual34-1, Contracting Manual; AOC Order 38- 1, Government Ethics, or similar.

2. 7. Protection of CUI: When outside of a Controlled Environment and under the direct control of an authorized holder, CUI shall be protected from unauthorized access or observation. When outside of a Controlled Environment and NOT under the direct control of an authorized holder, CUI shall be protected by at least one physical or electronic barrier. This requirement is satisfied by any one of the following:

2. 7 .1. Locking in a cabinet, drawer, office, office suite, briefcase or courier bag.

2. 7 .2. Storing within a password protected or segregated electronic storage device, email account, computer system or network drive.

2.7.3. Storing within a sealed envelope.

2.8. CUI Handling Procedures during Telework: CUI should only be accessed via AOC approved portable electronic devices (PEDs) such as laptops, USB flash drives and external hard drives all of which must be handled as noted in AOC Order 600-1, Telework Program. Personally owned computers should not be used to access, save, store or host CUI unless logged-in through the AOC approved Virtual Desktop. CUI will not be transferred to personal computer(s) or printed on personal printer(s). While teleworking CUI will be protected from unauthorized access, use, disclosure, disruption, modification or destruction as defined in the Order.

2.9. CUI Dissemination and Access: CUI must not be disseminated in any manner- orally, visually or electronically to unauthorized personnel.

2.9.1. Access to CUI is based on a Lawful Government Purpose as determined by the covered person( s) in possession of the information. Where there is uncertainty as to a person's Lawful Government Purpose, the covered person(s) in possession of the information will request dissemination instructions from their next-level supervisor or the information's originator.

2.9.2. The covered person(s) in possession of the information will comply with any access and dissemination restrictions.

2.9.3. A security clearance is not required for access to CUI.

2.9.4. When discussing or transferring CUI to another individual(s), ensure that the individual with whom the discussion is to be held or the information that is to be transferred has a Lawful Government Purpose. Also ensure that precautions are taken to prevent unauthorized individuals from overhearing the conversation, observing the materials, or otherwise obtaining the information.

2.9.5. CUI may be shared with other agencies, federal, state, tribal or local government and law enforcement officials, provided a specific Lawful Government Purpose has been established and the information is shared in furtherance of a coordinated and official governmental activity. Where CUI is requested by an official of another agency and there is no coordinated or other official governmental activity, a written request will be made from the requesting agency to the applicable AOC office providing the name(s) of personnel for whom access is requested, the specific information to which access is requested and basis for Lawful Government Purpose. The AOC office shall then release the information to the other agency official.

2.9.6. If the information requested or to be discussed belongs to another agency or organization, comply with that agency's policy concerning third party discussion and dissemination.

2.9.7. Due to the sensitive nature of this information, AOC IT systems associated with CUI shall comply with all applicable information security requirements defined in AOC Information Security Order 7-4 and its associated IT security standards.

2.9.8. When CUI is contained in media or material (including hardware and equipment) not commonly thought of as documents (e.g., computer files and other electronic media, audiovisual media, chart, maps, films, sound recordings), the requirement remains to identify, as clearly as possible, the information that requires protection.

The main concern is that covered person and users of the material are clearly notified of the presence of CUI. The markings required by this Order shall be applied either on the item or the documentation that accompanies it.

2.9.9. Individual portion markings on a document that contains no other designation are not required. Designator or originator information and markings, downgrading instructions, and date/event markings are not required.

2.1 0. CUI Transmission Procedures: When transmitting hard copy CUI, covered persons must take reasonable steps to minimize the risk of access by unauthorized persons. Such steps include:

2.10.1. By Mail- Outside of a Facility. CUI material will be placed in a sealed, opaque envelope or wrapping marked with the recipient's address, a return address and the words "TO BE OPENED BY ADDRESSEE ONLY."

2.10.1.1. Any of the following U.S. mail methods may be used: First Class, Express, Certified or Registered Mail.

2.10.1.2. Any commercial carrier (FedEx, UPS, DHL, etc.) may be used.

2.10.2. By Mail- Within a Facility. Use a sealed, opaque envelope with the recipient's address and the words "TO BE OPENED BY ADDRESSEE ONLY" on the front.

2.10.3. By Hand- Between Facilities or Within a Facility. A document marked as containing CUI may be hand carried between or within a facility as long as the person carrying the document can control access to the document.

2.10.4. Transmittal via Fax. Unless otherwise restricted by the originator, CUI information may be sent via non-secure fax. Where a non-secure fax is used, the sender will coordinate with the recipient to ensure that the materials faxed will not be left unattended or subjected to possible unauthorized disclosure on the receiving end. The covered person(s) in possession of the material will comply with any access, dissemination and transmittal restrictions cited by the originator.

2.10.5. Transmittal via E-Mail. CUI transmitted via email should be protected by encryption using AES-256 encryption. To do this, include the CUI in an attachment only (not in the text of the email), and encrypt the attachment with 7 Zip (software program) provided on all AOC workstations. The lTD Helpdesk (helpdesk@aoc.gov) can provide assistance with using 7 Zip. Recipients of CUI will comply with any email restrictions imposed by the originator. Email CUI within an encrypted attachment with the password provided separately (e.g., by phone, another email, or in person).

2.1 0.6. AOC lntranetllnternet. CUI will not be posted to intranet sites such as SharePoint collaboration sites, shared drives, multi-access calendars, or on the Internet (including social networking sites) that can be accessed by individuals who do not have a Lawful Government Purpose for the information. To control access to an AOC network shared drive and/or SharePoint collaboration site(s) contact the lTD Helpdesk (helpdesk@aoc.gov). Covered persons will ensure information posted to AOC Intranet/Intemet (public) website(s) does not violate any provisions of this order or any other AOC Order.

2.10.7. Secure File Transfer Systems. CUI delivered through a secure file transfer system must provide methods (e.g., authentication, file access controls, passwords) to prevent access to CUI stored on the system by persons who do not require the information to perform their jobs or other AOC-authorized activities.

Contact the lTD Helpdesk (202-225-4321 or helpdesk@aoc.gov) for an AOC approved secure file transfer tool. Materials being transmitted via secure file transfer (FTP) servers to recipients outside of AOC, for example, other federal agencies, state or local officials, contractor, etc. should be configured to the following requirements:

2.10.7.1. FTP transfers shall be performed over a secure SSH2 connection. This is commonly known as "SFTP".

2.10.7.2. FTP transfers shall be encrypted using FIPS 140-2 validated ciphers and 256-bit AES encryption. Transfers between AOC and the recipient server shall not be performed using any other method.

2.10.7.3. The FTP server shall use only the SHA-256 hash function for generating keyed-hash message authentication codes (HMAC).

2.11. CUI Destruction Procedures: CUI material will be destroyed when no longer needed pursuant to the applicable Records Management Schedule. The following shall serve as guidelines for destroying materials containing CUI:

2.11.1. "Hard Copy" materials will be destroyed by cross-shredding or placed in a secure bin designated for discarding sensitive documentation, when no longer needed. If there is not a cross-shredder or secure bin designated for discarding sensitive documentation in your organizational area, one may be ordered through Office Services, officeservices@aoc.gov, 202--228-1209. After destruction, materials may be disposed of with normal waste or recycled, as appropriate.

2.11.2. Electronic storage media [e.g., hard disks, floppy disks, zip drives, compact disks (CDs), thumb drives, pen drives, and similar USB storage devices] shall be sanitized appropriately by overwriting or degaussing. Contact the lTD Helpdesk at helpdesk@aoc.gov, 202-225-4321 for additional guidance.

2.11.3. Paper products containing CUI will not be disposed of in regular trash or recycling receptacles unless the materials have first been destroyed as specified above.

2.12. CUI Incident Reporting: The loss, compromise, suspected compromise or unauthorized disclosure of CUI will be reported.

2.12.1. Employees or contractors who observe or become aware of the loss, compromise, suspected compromise or unauthorized disclosure of CUI will report it immediately, but no later than the next duty day, to the AOC Security Officer.

2.12.2. Suspicious or inappropriate requests for information by any means, e.g., email or verbal, shall be reported to the AOC Security Officer immediately.

2.12.3. Additional notifications to appropriate AOC management personnel will be made immediately when the disclosure or compromise could result in physical harm to an individual( s) or the compromise of a planned or on-going operation.

2.12.4. Incidents involving CUI in AOC IT systems will be reported to the Information Security team by emailing INFOSEC@aoc.gov, or calling the Chief Information Security Officer (CISO) directly at 202.226.4744, as soon as possible. The CISO will notify the AOC Security Officer of any suspected incidents in a timely manner, but no later than the next duty day.

2.12.5. An inquiry will be conducted by the AOC Security Officer to determine the cause and effect of the incident and to provide guidance on the appropriateness of administrative or disciplinary action against the offender. Inquiries that develop possible indicators of criminal or civil violations, or gross abuse of authority by a contractor or AOC employee will be immediately reported to the AOC Office of Inspector General (OIG) for coordination.

2.13. Security Policy Violation and Disciplinary Action: Individual accountability is a cornerstone of an effective security policy. Jurisdiction heads are responsible for taking corrective actions whenever security incidents and violations occur and for holding personnel accountable. Each jurisdiction must determine how to best address each individual case.

2.13.1. AOC employees may be subject to disciplinary action in accordance with AOC Order 752-1 for failure to comply with AOC security policy.

2.13.2. Non-AOC Federal employees, contractors, or others working on behalf of AOC who fail to comply with AOC security policies are subject to having their access to AOC systems and facilities terminated.

2.13.3. Intentional or reckless disclosures of sensitive information will be immediately reported to the AOC OIG.

2.14. Deviation from Policy: Jurisdiction heads may propose a variance (i.e., an alternate or equivalent means of meeting a requirement) or request a waiver from a specific requirement in this Order. This proposal must (a) identify the Order requirement for which a variance or waiver is being requested (b) explain why a variance or waiver is needed and (c) if requesting a variance, describe the alternate or equivalent means for meeting the requirement. The proposal must be submitted to the Director, OSP for approval. OSP will review each approved variance or waiver periodically to ensure it is still needed.

3. Responsibilities

The following defines roles and responsibilities for providing CUI policy oversight.

3 .1. Architect of the Capitol: The Architect of the Capitol has sole approval authority and oversight of adherence to the security of CUI within the Agency except as indicated below.

3.2. Director, Office of Security Programs (OSP): The Director of OSP shall serve as the lead for all aspects of AOC security programs and operations. The Director of OSP is hereby delegated authority to grant variance and/or waiver(s) to this policy.

3.3. Chief Information Officer: In consultation with the Director of OSP, ensure the adequacy of AOC information technology security for CUI, as required by this Order.

3.4. Chief Human Capital Officer: The ChiefHuman Capital Officer (CHCO), Human Capital Management Division, in consultation with the Director of OSP, shall ensure the protection of CUI in employment-related actions, as required by this Order and AOC Human Capital Management policies and requirements. Consult OSP on CUI related disciplinary actions.

3.5. Chief Financial Officer: The Chief Financial Officer, in consultation with the Director of OSP, shall ensure the protection of CUI in AOC business activities.

3.6. AOC Security Officer: The AOC Security Officer will be designated by the OSP Director and serve as the Agency subject matter expert for security of CUI and as such shall provide associated guidance to AOC organizations. The AOC Security Officer will:

3.6.1. Consult and coordinate with other CUI custodians to ensure efficient and effective implementation of this Order.

3.6.2. Formulate, coordinate and conduct the CUI security education program.

3 .6.3. Collaborate with the AOC officials to ensure the adequacy of administrative, technical, and physical safeguards for protecting CUI, as required by this Order.

3.7. Office of Security Programs (OSP): OSP is responsible for providing the training program/materials/classes for covered person, including contractors.

3.8. AOC Organizations (Jurisdictions, Offices and Divisions): Jurisdiction heads of AOC divisions are responsible for:

3.8.1. Ensuring covered persons within organization adhere to CUI requirements of this Order.

3.8.2. Appointing a CUI custodian within 30 days of this Order's release. Note: This assignment is a collateral duty.

3.8.3. Establishing procedures to prevent unauthorized persons from accessing CUI.

3.8.4. Promptly addressing unauthorized disclosure of CUI, improper designation of CUI and violations of this Order.

3.8.5. Directing, administering and overseeing an ongoing oversight program to evaluate and assess the effectiveness and efficiency of the Organization's implementation of security for CUI.

3.8.6. Establishing procedures to prevent unauthorized persons from accessing CUI.

3.9. Acquisition and Material Management Division, Contracting Officers: Ensure contractors, subcontractors and the employees of contractors and subcontractors are aware of their responsibilities under this AOC Order. Contracting Officers must ensure that the contracts for which they are responsible include provisions requiring the contractor to instruct, train and supervise its personnel on safeguarding CUI. Contracting Officers must also monitor contractor performance to ensure compliance.

3.10. CUI Custodian: Jurisdictions shall cooperate with OSP to ensure sensitive but unclassified information is properly handled, stored and protected from the risk and magnitude of loss or harm that could result from inadvertent or deliberate disclosure, alteration or destruction. Each jurisdiction shall designate a CUI custodian to work with OSP. The duties of the custodian shall include coordinating and overseeing CUI functions.

3.1 0.1. The CUI custodian will ensure, in coordination with the OSP, completion of CUI management controls and inquiries for loss or compromised CUI in accordance with this Order.

3 .11. Covered Person: Covered persons will be trained on this policy and be engaged as partners involved in implementing the controls and protective measures developed for CUI. Non-compliance of this Order may result in disciplinary actions that are in accordance with established AOC policies and procedures. All authorized users of the AOC's CUI, including government employees and support contractors, either by direct or indirect connections, must:

3 .11.1. Complete annual CUI security awareness training.

3.11.2. Exercise c.are and judgment to ensure adequate protection of the AOC's sensitive information.

3.11.3. Notify the appropriate jurisdiction heads and the AOC Security Officer of any suspected incidents in a timely manner.

4. Definitions

The following terms are used in this document in the context described below.

4.1. Access: The ability or opportunity to obtain knowledge of Controlled Unclassified Information.

4.2. AOC Security Officer: Assists the Director, Office of Security Programs (OSP) with development, implementation, operation and oversight of AOC security policies and procedures.

4.3. Classified Information: As defined by the Classified Information Procedures Act (CIPA) of 1980, classified information is defined as official information that has been determined to require, in the interests of national security, protection against unauthorized disclosure and which has been so designated.

4.4. Authorized AOC Official: Jurisdiction head having program management responsibility over the information or the Office of Security Programs (OSP).

4.5. Controlled Unclassified Information (CUI): Unclassified information that is pertinent to the security of Congress, the Supreme Court or the national interest of the United States or originated by entities outside the U.S. Federal Government, and under law or policy requires special handling safeguards, prescribed limits on exchange or dissemination and protection from disclosure.

4.6. Controlled Environment: Any area or space for which the jurisdiction has confidence that the physical and procedural protections provide adequate barriers and managed access controls to meet the requirements established for protecting CUI and/or information systems containing CUI against unauthorized access or disclosure.

4.7. Covered Person: Any person who has been granted access to information or other resources under the authority or control of AOC. This includes AOC employees (also referred to as "AOC staff'), contractors, subcontractors, and the employees of contractors and subcontractors.

4.8. Document: Recorded information regardless of its medium or characteristics.

4.9. Equivalent Markings: Other-Agency information control markings that are equivalent to AOC Controlled Unclassified Information (CUI) including but not limited to the following: "For Official Use Only" (FOUO) from the Department of Defense and many other agencies, "Sensitive but Unclassified" (SBU) from the Department of State, and "Limited Official Use" (LOU) from the Department of Justice.

4.1 0. Information: Any documentary material or knowledge that can be communicated, regardless of its physical form or characteristics that is owned and/or produced by or for, or is under the control of the United States Government.

4.11. Lawful Government Purpose: The standard applied when determining whether individuals, organizations or groupings of users may receive or access CUI that is not marked with specific dissemination controls. Lawful Government Purpose means any activity, function, operation or other circumstance authorized by the United States Government.

4.12. Originator: The organization or individual that develop data. The organization or individual is responsible for determining when information requires protection against unauthorized disclosure).

4.13. Page Marking: Banner marking at top and/or bottom of an interior page of a document.

4.14. Safeguarding: Measures and controls that are prescribed to protect CUI.

4.15. Secure Storage: A storage device (e.g., file cabinet, safe, room with a safe room) with a resistance to forced penetration, with a lock and controlled access to keys or combinations.

4.16. Unauthorized Disclosure: Providing or making CUI available to individuals or entities who are not authorized to view or possess the information, pursuant to law, AOC Order or directives issued by the Architect of the Capitol.

4.17. Unauthorized Person: Individual(s) other than AOC staff acting within the scope of their employment relationship with the AOC, independent contractors and vendors conducting business within the scope of their engagement with the AOC and representatives of AOC partners conducting business within the scope of the entity's partnership with the AOC.

5. Authority: 2 U.S.C. § 1803 and 2 U.S.C. § 4101 give the Architect of the Capitol the general authority to carry out and delegate his powers and duties and includes the authority to promulgate orders such as these to regulate the AOC workforce.

JURISDICTIONAL RESPONSIBILITIES

1. Has the Superintendent/Director ensured covered persons within adhere to CUI uirements of this Order?

2. Has the Superintendent/Director appointed a CUI custodian within 30 of this Order's release?

3. Has the Superintendent/Director established procedures to prevent unauthorized from access· CUI?

4. Has the Superintendent/Director promptly addressed unauthorized disclosure of CUI, improper designation of CUI, and violations of the

· sions of this Order?

5. Has the Superintendent/Director developed an oversight program to evaluate and assess the effectiveness and efficiency of the organization's

· · of · for CUI?

EMPLOYEE RESPONSIBILITIES

1. Has the employee completed annual CUI security awareness training?

2. Has the employee exercised care and judgment to ensure adequate ....... r•"~-""'"'"~-'·on ofthe AOC's sensitive information?

3. Has the employee notified the appropriate jurisdiction heads and the AOC ....:.aro.,,.,., 1h" Officer of incidents in a · manner?

OPR RESPONSIBILITIES

1. Did the OSP provide training program/materials/classes for covered .... .a ... conn '"""""'ro • ..-.~ contractors?

2. Does the AOC Security Officer serve as the Agency subject matter expert for security of controlled unclassified information and provide associated

· to AOC or · · ?

3. Does the OPR consult and coordinate with CUI custodians to ensure efficient and effective · ementation of this Order?

4. Does the OPR formulate, coordinate, and conduct the CUI security education ?

5. Does the OPR collaborate with AOC officials to ensure the adequacy of administrative, technical, and physical safeguards for protecting CUI, as

· this Order?

CUI CUSTODIAN

1. Has the CUI custodian ensured, in coordination with the Office of

Security Programs, completion of CUI management controls and inquiries for loss or · CUI in accordance with this Order?

For each "No" answer, complete the following table.

Question JUSTIFICATION/RATIONALE

AOC Order 42-4, May 6, 2016

Responsible Person to Contact

Phone

I I I Comments:

OPR: Date:

File details come from the government source that posted it. Updated .