Attachment_J_MTO_General_Controlled_Unclassified_Information_Guide_CUIG.pdf
PDF 310 KB Posted
- Attached to
- Microsystems Technology Office (MTO) Office-wide Federal contract opportunity
- Solicitation number
- HR001124S0028
About this file
This document is a Controlled Unclassified Information (CUI) Guide for the Microsystems Technology Office (MTO) of the Defense Advanced Research Projects Agency (DARPA). It provides marking instructions and guidance for sensitive information associated with MTO solicitations or requests, including technical information with military or space applications, export-controlled research, and proprietary business information. The guide cites the relevant authorities, defines the applicable CUI categories, and outlines the protection requirements, disclosure procedures, and notification processes for unauthorized disclosures. It also includes information protection guidance charts to assist in identifying and properly marking sensitive elements of information. This CUI guide is intended to be used in conjunction with the related federal contract opportunity, Solicitation Number HR001124S0028, which seeks revolutionary research ideas for topics not being addressed by ongoing MTO programs or other published solicitations.
View the file
Other files for this federal contract opportunity
Show all 34
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DISTRIBUTION STATEMENT A
Approved for Public Release: Distribution Unlimited
Controlled Unclassified Information Guide
Program: Microsystems Technology Office (MTO) General CUI Program Manager: MTO Program Manager Group
Program Security Officer: James Persons
Date: November 3, 2023 Version: 2.0
Whitney Mason, Ph.D. James Persons MTO Director MTO Program Security Officer ii
FOREWORD
1. DESCRIPTION
2. AUTHORITY
3. DISTRIBUTION
GENERAL
1. PURPOSE
2. APPLICABILITY AND SCOPE
3. OFFICE OF PRIMARY RESPONSIBILITY
4. CONTROLLED UNCLASSIFIED INFORAMTION (CUI) CHALLENGES
5. OPERATION SECURITY (OPSEC)
6. CUI CATAGORIES
7. EXPORT CONTROL RESTRICTED INFORMATION
8. FREEDOM OF INFORMATION ACT (FOIA) EXEMPT INFORMATION
9. DISCLOSURE of CUI
10. CUI PROTECTION REQUIREMENTS
11. NOTIFICATION OF UNAUTHORIZED DISCLOSURE
12. INFORMATION PROTECTION GUIDANCE CHARTS
iii
FOREWORD
1. DESCRIPTION
This guide will provide marking instructions to all UNCLASSIFIED MTO solicitations or requests that do not issue program-specific Controlled Unclassified Information (CUI) guidance.
2. AUTHORITY
CUI elements referenced in this guide are under the authority of DoDI 5200.48, “Controlled Unclassified Information,” March 6, 2020.
3. DISTRIBUTION
Distribution unlimited, approved for public release.
GENERAL
1. PURPOSE
a. The purpose of this controlled unclassified information (CUI) guide is to ensure the protection of information IAW DoDI 5200.48. This information should be controlled and stored consistent with federal requirements and guidance from the National Institute for Standards and Technology (NIST). Sensitive information does not include information in the public domain.
b. This guide is not for classified national security information as defined in Executive Order 13526, but identifies specific elements of sensitive information that are unclassified in nature but still require protection. This information is not classified national security information, but it is covered by the legislation at large for the Freedom of Information Act (FOIA) and the exemptions therein, Patents filled under 35 U.S.C.
111(a), Export controlled International Traffic in Arms Regulations (ITAR) and Export Administration Regulations (EAR), Proprietary Manufacturer, and General Proprietary Business Information.
2. APPLICABILITY AND SCOPE
This guide applies to all DARPA personnel, support contractors, mission partners, and industrial performers who develop material in response to a MTO solicitation or request. This guide should be cited as the basis for identifying, protecting, and marking of information and material designated as a type of CUI associated with MTO solicitation or requests. As defined at 32 CFR Section 2002.4(h), CUI is information that the government creates or possesses – or that an entity creates or possesses on behalf of the government – that law, regulation or government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls. It is to be used in conjunction with related security classification guides and guidance documents associated with the overall effort of MTO solicitation or request, in compliance with Executive Orders and related DoD guidance. The scope of this guide is based on MTO solicitations or requests as planned at the date of this guide, and may expand or change as strategic decisions are made over the course of MTO solicitation or request.
3. OFFICE OF PRIMARY RESPONSIBILITY (OPR)
This CUI guide is issued by DARPA. All inquiries concerning content, interpretations, and clarification of this document should be addressed to DARPA at MTOSecurity@darpa.mil.
Approved for Public Release: Distribution Unlimited
4. (U) CONTROLLED UNCLASSIFIED INFORMATION (CUI) CHALLENGES
CUI Challenges: Authorized holders of CUI who, in good faith, believe that a designation of information as CUI within this guide is improper or incorrect, or who believe they have received unmarked CUI, should notify DARPA at MTOSecurity@darpa.mil. Until the challenge is resolved, the challenged CUI, including challenges to unmarked CUI, will continue to be safeguarded and disseminated at the appropriate control level indicated in the markings or presumed category.
5. OPERATIONS SECURITY (OPSEC)
a. OPSEC is a process that identifies and mitigates adversarial risk to our operations by looking at our operations through the eyes of our adversaries. The application of the OPSEC methodology includes identifying critical information, analyzing threats and vulnerabilities, analyzing and assessing adversarial risk, and implementing OPSEC measures that reduce this risk.
b. MTO solicitation or request critical information falls under general use the following index of CUI:
1) Defense
2) Export Controlled
3) Proprietary Business Information
6. CUI Categories
a. Defense: Controlled Technical Information (CTI). This category relates to technical information with military or space application that is subject to controls on the access, use, reproduction, modification, performance, display, release, disclosure, or dissemination. Controlled technical information would meet that criterion, if disseminated, for distribution statements B through F using the criteria set forth in DoD Instruction 5230.24, Distribution Statements on Technical Documents.
b. Export Controlled: Export Controlled Research (EXPT). Unclassified information concerning certain items, commodities, technology, software, or other information whose export could reasonably be expected to adversely affect the United States national security and nonproliferation objectives. Export-controlled information includes dual-use items; items identified in export administration regulations, international traffic in arms regulations, and the munitions list; license applications; and sensitive nuclear technology information. This category relates to the systematic investigation into and study of materials and sources in order to establish facts and reach new conclusions.
Approved for Public Release: Distribution Unlimited
c. Proprietary Business Information: General Proprietary Business Information (PROPIN). Material and information relating to, or associated with, a company's products, business, or activities, including but not limited to financial information;
data or statements; trade secrets; product research and development; existing and future product designs and performance specifications.
7. EXPORT CONTROL RESTRICTED INFORMATION
MTO solicitations or requests may contain export control restricted information which includes research information pertaining to Export Administration Regulations.
8. FREEDOM OF INFORMATION ACT (FOIA) EXEMPT INFORMATION
a. The Freedom of Information Act (FOIA), 5 U.S.C. § 552, is a federal law that defines agency records subject to public disclosure, outlines mandatory disclosure procedures, and defines nine exemptions that prohibit certain types of information from being released to the public. In addition to the FOIA, the Code of Federal Regulations (October 2016), 45 CFR § 5.31 specifies the type of information that falls under each of the nine exemptions that preclude release of information to the public under the FOIA. In accordance with 5 U.S.C. § 552(a)(8), DARPA will withhold records or information exempt from disclosure under the FOIA whenever disclosure would harm an interest protected by a FOIA exemption or disclosure is prohibited by law. The most relevant exemptions for MTO solicitation or requests are listed below; however other exemptions could apply:
1) Exemption 3 – Protects information exempted from release by statute.
2) Exemption 4: Trade secrets or commercial or financial information that is confidential or privileged.
9. DISCLOSURE of CUI.
a. Public Disclosure. Information from this CUI guide does not allow automatic public release of this information. DoD information requested by the media or members of the public or proposed for release to the public by DoD civilians or military personnel or their contractors will be processed in accordance with DARPA Instruction 65 and DoD Instructions 5230.09, 5230.29; Volume 3 of DoD Manual 5200.01; and DoD Manual 5400.07, as applicable. Proposed public disclosures of unclassified information shall be submitted using the public release form located at https://www.darpa.mil/work-with-us/contract-management/public-release.
b. Freedom of Information Act (FOIA) Requests. All personnel with knowledge of this Project must coordinate with the DARPA PSO prior to providing a response to requests for information under the provisions of the FOIA.
https://www.darpa.mil/work-with-us/contract-management/public-release https://www.darpa.mil/work-with-us/contract-management/public-release
Approved for Public Release: Distribution Unlimited
c. Proprietary Information. Additional safeguards may become necessary if a contract requires the transfer of PROPIN. The holder of the information must clearly identify any and all PROPIN prior to its disclosure and release. Release will be coordinated with the PROPIN owner.
d. Foreign Disclosure. Disclosure of DARPA CUI to foreign nationals will be coordinated with the PSO, International Security, and International Cooperation. Disclosure approval must be granted by the Director, SID, who is the Foreign Disclosure Officer for DARPA.
10. CUI PROTECTION REQUIREMENTS
a. CUI (e.g., General Proprietary Business Information and Export Controlled) received through any MTO solicitation or request, regardless of media or format, will be protected from disclosure to unauthorized persons or groups by properly storing in locked offices, cabinets, and drawers in accordance with DoDI 5200.48.
b. CUI may only be processed on DIB systems that are compliant with DFARS 252.204- 7012 requirements, as detailed in NIST 800-171.
11. NOTIFICATION OF UNAUTHORIZED DISCLOSURE
a. Personnel must immediately report all unauthorized disclosures or suspected and known security incidents, privacy breaches, and suspicious activities involving CUI to the MTO solicitation or request security team at MTOSecurity@darpa.mil.
b. Data breaches of DIB networks and systems involving MTO solicitation or request CUI material must be reported IAW DFARS 252.204-7012 requirements. In addition, all breaches must be reported to the DARPA Project contracting officer and MTO program security officer (PSO) upon discovery MTOSecurity@darpa.mil.
Approved for Public Release: Distribution Unlimited
12. INFORMATION PROTECTION GUIDANCE CHARTS
These charts are provided to assist in identifying what types of information associated with the MTO solicitation or request effort may be sensitive, provide guidance on the relevant markings for this information to control dissemination, and provide guidance on when these dissemination controls no longer apply. If at any time there are questions regarding which category of information something falls under, or what dissemination controls apply, individuals should request guidance from DARPA at MTOSecurity@darpa.mil.
Element of Information
Index Category Reason LDC or Distribution Statement
Remarks
Technical information regarding military or space applications.
Defense Controlled Technical Information
(CTI)
DFARS
252.204.7012 and DoDI 5230.24
DISTRIBUTION
STATEMENT C.
Distribution authorized to U.S. Government Agencies and their contractors, Export Controlled, (Date). Other requests shall be referred to DARPA, Microsystems Technology Office.
FOIA Exemption 3 may be applicable.
ITAR and EAR
Information or data defined within the Commerce Control List (CCL), United States Munitions List (USML), or applied license applications to control export.
Export Control
Export Controlled "50 USC 4614(c);
13 USC 301(g); 42
USC 2156; 42 USC
2168(a); 22 CFR 124.9(a)(5); 50 USC 4605(l)(5); 10 USC 130(a); 32 CFR 250.4(a) // 42 USC 2077(a); 15
CFR 718.3; 22 CFR
126.10(b); 15 CFR 748.1(c); 15 CFR
DISTRIBUTION
STATEMENT C.
Distribution authorized to U.S. Government Agencies and their contractors, Export Controlled, (Date). Other requests shall be referred to DARPA, Microsystems Technology Office.
FOIA Exemption 3 may be applicable.
ITAR and EAR
All material with export controls will also post the following notice:
("WARNING - This document contains technical data whose
Approved for Public Release: Distribution Unlimited
760.5(c); 32 CFR
250.9; 15 CFR 736,
Supplement No. 2" export is restricted by the Arms Export Control Act (Title 22, U.S.C., Sec 2751, et seq.) or the Export Control Reform Act of 2018 (Title 50, U.S.C., Chapter 58, Sec. 4801-4852).
Violations of these export laws are subject to severe criminal penalties.
Disseminate in accordance with provisions of DoD Directive 5230.25.")
Non-public data controlled by the a business or individual as proprietary
Proprietary Business Information
General Proprietary Business Information
(PROPIN)
18 USC 1905
29 USC 664
Federal Employees and Contractors Only
(FEDCON)
FOIA Exemption 4 may be applicable.
******Nothing Follows******
| Whitney Mason PhD: | |
| James Persons: | |
| Element of Information: | |
| Index: | |
| Category: | |
| Reason: | |
| Remarks: | |
| Technical information regarding military or space applications: | |
| Defense: | |
| Controlled Technical Information CTI: | |
| DFARS 2522047012 and DoDI 523024: | |
| FOIA Exemption 3 may be applicable ITAR and EAR: | |
| Information or data defined within the Commerce Control List CCL United States Munitions List USML or applied license applications to control export: | |
| Export Control: | |
| Export Controlled: | |
| 7605c 32 CFR 2509 15 CFR 736 Supplement No 2: | |
| Proprietary Business Information: | |
| General Proprietary Business Information PROPIN: | |
| 18 USC 1905 29 USC 664: | |
| Federal Employees and Contractors Only FEDCON: | |
| FOIA Exemption 4 may be applicable: | |
| 2023-11-07T13:09:24-0500 | |
| PERSONS.JAMES.KENNETH.1214880993 |
| 2023-11-07T13:46:36-0500 | |
| MASON.WHITNEY.E.1239575800 |
File details come from the government source that posted it. Updated .