W9124A21R0009.pdf
PDF 739 KB Posted
- Attached to
- Document Shredding Federal contract opportunity
- Solicitation number
- W9124A21R0009
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Questions with Answers.pdf | ||
| Chart from section 5.0 on PWS.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SEE ADDENDUM
(No Collect Calls)
W9124A21R0009 27-Jan-2021
b. TELEPHONE NUMBER
533-1037
8. OFFER DUE DATE/LOCAL TIME
11:00 AM 26 Feb 2021
5. SOLICITATION NUMBER 6. SOLICITATION ISSUE DATE
AUTHORIZED FOR LOCAL REPRODUCTION
PREVIOUS EDITION IS NOT USABLE
STANDARD FORM 1449 (REV. 2/2012)
Prescribed by GSA – FAR (48 CFR) 53.212
(TYPE OR PRINT)
(SIGNATURE OF CONTRACTING OFFICER)
ADDENDA ARE
26. TOTAL AWARD AMOUNT (For Gov t. Use Only )
23.
CODE 10. THIS ACQUISITION IS
SUCH ADDRESS IN OFFER
17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT
BELOW IS CHECKED
TELEPHONE NO.
W9124A9. ISSUED BY
18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a. UNLESS BLOCK
7. FOR SOLICITATION
INFORMATION CALL:
a. NAME
MONICA GJERDE
2. CONTRACT NO. 3. AWARD/EFFECTIVE DATE 4. ORDER NUMBER
(TYPE OR PRINT)
30b. NAME AND TITLE OF SIGNER 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER
30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a.UNITED STATES OF AMERICA
0 27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1. 52.212-4. FAR 52.212-3. 52.212-5 ARE ATTACHED.
25. ACCOUNTING AND APPROPRIATION DATA
1. REQUISITION NUMBER
20.
ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED.
OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, AND 30
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS
0011597417
ARE NOT ATTACHED
27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED
(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE
SET FORTH HEREIN, IS ACCEPTED AS TO ITEMS:
. YOUR OFFER ON SOLICITATION
28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN
% FOR:SET ASIDE:UNRESTRICTED OR X
SMALL BUSINESSX
17a.CONTRACTOR/ CODE FACILITY
OFFEROR CODE
ACC-APG
GARRISON COMMERCIAL ACQUISITION
BUILDING 22208
FT HUACHUCA AZ 85613
18a. PAYMENT WILL BE MADE BY CODE
RATED ORDER UNDER
DPAS (15 CFR 700)
13a. THIS CONTRACT IS A
13b. RATING
CODE15. DELIVER TO CODE W61DC6 16. ADMINISTERED BY
12. DISCOUNT TERMS11. DELIVERY FOR FOB DESTINA-
TION UNLESS BLOCK IS
MARKED
SEE SCHEDULE
14. METHOD OF SOLICITATION
RFQ IFB RFPX
RAYMOND W BLISS ARMY HEALTH CENTER
RAYMOND W BLISS ARMY HEALTH CENTER
2240 E WINROW AVE
FT HUACHUCA AZ AZ 85613
TEL: FAX:
(520) 538-6503FAX:
TEL: SERVICE-DISABLED
VETERAN-OWNED
SMALL BUSINESS
8(A)
HUBZONE SMALL
BUSINESS
SIZE STANDARD:
$12,000,000
NAICS:
561990
X
OFFER DATED
29. AWARD OF CONTRACT: REF.
DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY
COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND
EMAIL:
TEL:
31c. DATE SIGNED
SEE SCHEDULE
SCHEDULE OF SUPPLIES/ SERVICESITEM NO. QUANTITY UNIT UNIT PRICE AMOUNT
24.22.21.19.
WOMEN-OWNED SMALL BUSINESS (WOSB)
ELIGIBLE UNDER THE WOMEN-OWNED
SMALL BUSINESS PROGRAM
EDWOSB
32g. E-MAIL OF AUTHORIZED GOVERNMENT REPRESENTATIVE
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS
(CONTINUED)
PAGE 2 OF62
ACCEPTED, AND CONFORMS TO THE CONTRACT, EXCEPT AS NOTED: ______________________________________________________
32a. QUANTITY IN COLUMN 21 HAS BEEN
RECEIVED INSPECTED
32b. SIGNATURE OF AUTHORIZED GOVERNMENT
REPRESENTATIVE
32c. DATE 32d. PRINTED NAME AND TITLE OF AUTHORIZED GOVERNMENT
REPRESENTATIVE
32e. MAILING ADDRESS OF AUTHORIZED GOVERNMENT REPRESENTATIVE 32f . TELEPHONE NUMBER OF AUTHORIZED GOVERNMENT REPRESENTATIVE
37. CHECK NUMBER
FINALPARTIALCOMPLETE
36. PAYMENT35. AMOUNT VERIFIED
CORRECT FOR
34. VOUCHER NUMBER
FINAL
33. SHIP NUMBER
PARTIAL
38. S/R ACCOUNT NUMBER 39. S/R VOUCHER NUMBER 40. PAID BY
41a. I CERTIFY THIS ACCOUNT IS CORRECT AND PROPER FOR PAYMENT
41b. SIGNATURE AND TITLE OF CERTIFYING OFFICER 41c. DATE
42a. RECEIVED BY (Print)
42b. RECEIVED AT (Location)
42c. DATE REC'D (YY/MM/DD) 42d. TOTAL CONTAINERS
STANDARD FORM 1449 (REV. 2/2012) BACK
Prescribed by GSA – FAR (48 CFR) 53.212
AUTHORIZED FOR LOCAL REPRODUCTION
PREVIOUS EDITION IS NOT USABLE
SEE SCHEDULE
20.
SCHEDULE OF SUPPLIES/ SERVICES
21.
QUANTITY UNIT
22. 23.
UNIT PRICE
24.
AMOUNT
19.
ITEM NO.
W9124A21R0009
Section SF 1449 - CONTINUATION SHEET
SPECIAL INSTRUCTIONS
Award of this contract will be done using FAR Part 13 – Simplified Acquisition Procedures.
Any contract with the government requires registration in the System for Award Management (SAM) and must be registered in ORCA at website https://www.sam.gov.
Please provide you’re DUNs, Cage Code, and Tax ID number as part of your proposal.
Please total all CLIN’s on your quote/proposal to show total overall price and include the FOB destination lead time as well as any reinstatement charges that may apply.
Please provide detailed drawings or specification sheets with your proposal if appropriate.
Interested parties who need access to the military installation must come through the Main Gate (Van Deman) of Fort Huachuca, located at the corner of State Highway 90 Bypass and State Highway 90.
QUESTIONS:
Any questions must be submitted via e-mail by COB 8 February 2021. Questions submitted after this date will not be addressed. No questions will be answered telephonically. All questions must be submitted via e-mail to the Point of Contact listed below.
Please provide the applicable Performance Work Statement (PWS) paragraph number, page number, CLIN/ SubCLIN number, or other applicable location in the Solicitation for each question.
Evaluation Factors:
The Government will award a Firm Fixed-Price Contract on an all or none basis, to the lowest priced offer that meets all the terms and conditions of the solicitation.
Delivery Schedule: The vendor selected must be able to deliver to Ft. Huachuca by delivery date specified after contract award. Request that address labels contain the contract number on all shipping documents.
Point of Contract for this action is:
Monica Gjerde Phone: 520-533-1037 Fax: 520-533-5157 E-Mail: monica.a.gjerde.civ@mail.mil
1. Please provide a price for each CLIN and total all CLINs in your proposal to show the total overall price.
2. Complete the Price Summary below.
3. PRICE SUMMARY:
a. Base Year 0001_______________
b. Option Year One 1001 (+) _______________
c. Option Year Two 2001 (+) ______________
d. Option Year Three 3001 (+)________________
e. Option Year Four 4001 (+)________________
TOTAL PRICE (Please add a-e above.) (=)_______________
f. *Six Month Option Pricing (IAW FAR 52.217-8) (+) ________________
*Note: Six month Option pricing is ½ the Option Year Four price.
TOTAL PRICE (Please add a-f above.) (=)________________
ITEM NO SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
0001 12 Months Document Shredding
FFP
Base Year: 15 March 2021 to 14 March 2022
SEE PERFORMANCE WORK STATEMENT
FOB: Destination
PURCHASE REQUEST NUMBER: 0011597417
PSC CD: R706
NET AMT
1000 12 Months OY1 Document Shredding
FFP
Option Year 1: 15 March 2022 to 14 March 2023
SEE PERFORMANCE WORK STATEMENT
FOB: Destination
2000 12 Months OY2 Document Shredding
FFP
Option Year 2: 15 March 2023 to 14 March 2024
SEE PERFORMANCE WORK STATEMENT
FOB: Destination
3000 12 Months OY3 Document Shredding
FFP
Option Year 3: 15 March 2024 to 14 March 2025
SEE PERFORMANCE WORK STATEMENT
FOB: Destination
4000 12 Months OY4 Document Shredding
FFP
Option Year 4: 15 March 2025 to 14 March 2026
SEE PERFORMANCE WORK STATEMENT
FOB: Destination
INSPECTION AND ACCEPTANCE TERMS
Supplies/services will be inspected/accepted at:
CLIN INSPECT AT INSPECT BY ACCEPT AT ACCEPT BY
0001 Destination Government Destination Government 1000 Destination Government Destination Government 2000 Destination Government Destination Government 3000 Destination Government Destination Government 4000 Destination Government Destination Government
PERFORMANCE WORK STATEMENT
DOCUMENT DESTRUCTION SERVICE
RAYMOND W. BLISS ARMY HEALTH CENTER (RWBAHC)
FORT HUACHUCA, AZ
The contractor shall provide all labor, personnel, equipment including lockable confidential containers (console/bins), supplies, secured vehicles, materials, supervision and other related services necessary to provide on‐site document destruction services for the facilities with in RWBAHC.
Raymond W. Bliss Army Health Center (WBAHC) administers and manages patient privacy data that must be safeguarded to meet Health Insurance Portability Accounting Act (HIPPA) requirements.
RWBAHC personnel are well trained in the requirement to dispose of CONTROLLED UNCLASSIFIED INFORMATION (CUI), sensitive, or administrative documents, in locked containers located throughout RWBAHC facilities.
1.0 SCOPE OF WORK:
1.1. The Contractor will provide all bins required throughout the entire RWBAHC facility. The sizes shall be: 95 gallon tote, 64 gallon tote, 32 gallon tote, and console size. Lockable containers will placed as indicated below in 5.0
1.2 ESTIMATED QUANTITY AND FREQUENCY OF SERVICE.
1.3 The types of paper disposed of in the bins may include office paper of any color and type, post‐it notes, and carbon‐less form. This list is not all‐inclusive and may include limited quantities of staples, paper clips, envelopes, file folders, newspapers, rubber bands, and other types of paper.
1.4. Contractor will provide separate containers for MAGNETIC MEDIA ONLY; one to be placed in Information Management Division and one to be placed in the Radiology Clinic.
1.5. During each Service Visit the Contractor inspect each container to determine if the container is more or less than half‐full.
� Containers found to be half‐full or more will be removed from its designated location, taken each to the Contractors shredding vehicle, empty/destroy the contents and replace the container at its designated location.
� Containers found to be less than half‐full may be left for service at a future Service Visit when they have reached half‐full or more capacity.
1.6 Prior to leaving the main RWBAHC facility the contractor’s employee is required to check‐out with the Contracting Officer Representative (COR) (Bldg. 45001, Room 306) and provide documentation listing the location of bins serviced during the current Service Visit.
2.0 PLACE OF PERFORMANCE:
Raymond W. Bliss Army Health Center 2244 E. Winrow Ave.
Fort Huachuca, AZ. 85613 Satellite Clinic Pick‐ups will include:
� Military Intelligence Student Clinic (MISC) Bldg.80503 � Runion Dental Clinic (DENTAC) Bldg. 45005 � Veterinary Clinic Bldg. 30009
3.0 HOURS OF OPERATION:
Contractor shall provide the services between the hours of 8:00AM and 3:00 PM, Monday through Friday, excluding Government holidays. The holidays observed by the Federal government are:
New Year's Day Martin Luther King's Birthday President's Day Memorial Day Independence Day Labor Day Columbus Day Veteran's Day Thanksgiving Day Christmas New Year’s Day However, a designated bi‐monthly time‐frame for pick‐up will be coordinated with the contractor.
• If these holidays fall on Saturday, the preceding Friday will be observed. If these holidays fall on Sunday, the following Monday will be observed. If a holiday falls on a scheduled service day, the Contractor shall be responsible for rescheduling services for the first day post the holiday observance.
• Post Closure. Service scheduled but not accomplished because of post closure due to weather, exercises, or actual alert, will be accomplished as soon as possible after re‐opening the post.
• Contractor must notify the COR 2 business days prior to an interruption in the service schedule. At the time of notification, contractor must provide an alternate date of service for the interruption of service.
4.0 DESTRUCTION SPECIFICATIONS:
4.1. The shredding of all documents must meet the destruction requirements of DOD INSTRUCTION
5200.48 CONTROLLED UNCLASSIFIED INFORMATION (CUI), Section 4.5 DESTRUCTION, paragraphs a and b which state:
a. Record and non‐record copies of CUI documents will be disposed of in accordance with Chapter 33 of Title 44, U.S.C. and the DoD Components’ records management directives. When destroying CUI, including in electronic form, agencies must do so in a manner making it unreadable, indecipherable, and irrecoverable. If the law, regulation, or government‐wide policy specifies a method of destruction, agencies must use the method prescribed.
b. Record and non‐record CUI documents may be destroyed by means approved for destroying classified information or by any other means making it unreadable, indecipherable, and unrecoverable the original information such as those identified in NIST SP 800‐88 and in accordance with Section 2002.14 of Title
32, CFR.
4.2. DOD INSTRUCTION 5200.48 CONTROLLED UNCLASSIFIED INFORMATION (CUI) is attached to this PWS at Exhibit 1.
5.0 ESTIMATED QUANTITY AND FREQUENCY OF SERVICE:
Location 95 gal 64 gal Console Frequency of Service Command Suite ‐ Room 320 1 Bi‐monthly Operations ‐ Room 320 1 Bi‐monthly Pad Front Desk 1 2 Bi‐monthly Pharmacy 3 Bi‐monthly Preventive Med‐ Room El07 1 Bi‐monthly OCC Health‐Room El07 1 Bi‐monthly Radiology 1 1(CDs) Bi‐monthly Sports Medicine‐Break Room 1 Bi‐monthly Managed Care‐Room l‐K‐7 1 Bi‐monthly Coyote Creek Clinic‐A‐Reception Desk 1 Bi‐monthly Coyote Creek Clinic ‐A‐ 1‐L 51 2 Bi‐monthly Apache Ridge Clinic Reception Desk 1 Bi‐monthly Clinical Support ‐ Hallway 1‐COOR‐J 1 1 Bi‐monthly Coding RM l‐K‐39 1 Bi‐monthly HR ‐ Front Desk 1 Bi‐monthly IMD ‐ Room C‐8 1 Bi‐monthly Orderly Room ‐ RM ‐0‐C‐06 1 Bi‐monthly LAB 1 1 Bi‐monthly BH ‐ FL 2 ‐ Reception Desk 1 Bi‐monthly BH‐FL 2‐209 1 Bi‐monthly BH‐FL 2‐238 1 Bi‐monthly BH‐FL 2 ‐ 224 1 Bi‐monthly Vet Clinic ‐Bldg. 30009 2 Bi‐monthly MISC ‐ Bldg. 80503 2 Bi‐monthly Runion Dental Clinic ‐ Bldg. 45005 3 Bi‐monthly Over Flow Logistics Warehouse 4 As Needed
Magnetic Media Only/IMD 1 Bi‐monthly
TOTALS 12 15 15
6.0 CONTRACTOR'S QUALIFICATIONS:
• Contractor attests that their firm is regularly established in the business/service called for; they are financially responsible and have the necessary equipment and personnel to furnish RWBAHC with on‐ site document destruction/shredding services.
• The Contractor shall meet all federal, state, and local codes and all requirements for the operation of services provided.
• Materials collected for destruction shall be secured in contractor provided containers, until destroyed in accordance with DOD INSTRUCTION 5200.48 CONTROLLED UNCLASSIFIED INFORMATION (CUI), Section 4.5 DESTRUCTION, paragraphs a and b.
• The Contractor must be a licensed/certified Confidential Document Destruction Company and hold certification meeting all standards as mandated through HIPAA to provide sufficient reasonable safeguards to protect RWBAHC data until final destruction has been completed.
• All contractor’s employees who provide on‐site service under this contract must possess a valid driver's license.
• All contractor vehicles utilized in the performance of this contract shall maintain insurance (up to the minimum coverage by the State of Arizona) and current state vehicle registration for the duration of the contract. Proof of liability insurance shall be submitted with the submission of quote. Liability insurance must be current.
7.0 CONTRACTOR/EMPLOYEE SECURITY AND IDENTIFICATION:
• Contractor's employees shall wear either name tags identifying the company and employee or company provided uniforms containing the same information.
• Contractor shall insure the confidentiality of all patient and employee information and shall be held liable in the event of breach of confidentiality.
• Any person, who knowingly or willingly discloses confidential information from RWBAHC, may be subject to fines up to $20,000.00.
• Contractor personnel performing work under this contract shall satisfy all requirements for appropriate security eligibility in dealing with access to sensitive information and information systems belonging to or being used on behalf of RWBAHC.
8.0 ACCESS TO POST:
• Access and General Protection/Security Policy and Procedures. Contractor shall comply with MEDDAC Memorandum 380‐3, MEDDAC/Dental Activity (DENTAC) Security Program and MEDDAC Memorandum 640‐1 Identification (ID) Card Verification and Confiscation.
• The contractor shall also provide all information required for background checks to meet installation access requirements to be accomplished by installation Provost Marshall Office, Director of Emergency Services, or Security Office.
• Contractor workforce must comply with all personal identity verification requirements as directed by Department of Defense (DOD), HQDA and/or local policy.
• In addition to the changes otherwise authorized by the changes clause of this contract, should the Force Protection Condition at any individual facility or installation change, the Government may require changes in contractor security matters or processes.
• Contractor shall attain Contractor/Employee Post Passes to perform these services on Fort Huachuca Army Post.
• The Contractor and its employees shall comply with post traffic regulations. Contractor employees are prohibited from possessing weapons, firearms, or ammunition on themselves or within their Contractor owned or privately owned vehicle while on Fort Huachuca Army Post.
9.0 DOCUMENTATION:
• Certification of Destruction: A "Certificate of Destruction" shall be completed by the Contractor after completion of each Service Visit.
• Certificate of Destruction shall be submitted as an attachment to the invoice when submitting invoices via iRAPT (formerly Wide Are Work Flow (WAWF)) automated invoicing/payment system.
10.0 PAYMENTS:
Invoices for payment shall be submitted via iRAPT formerly Wide Area Work Flow (WAWF) System.
11.0 QUALITY CONTROL:
The Contractor shall develop and maintain a quality program to ensure services are satisfactorily performed in accordance with the terms and conditions specified herein. The contractor shall develop and implement procedures to identify and prevent defective services from recurring.
12.0 CONTRACTING OFFICER REPRESENTATIVE (COR):
The COR will be identified by separate letter. The COR monitors all technical aspects of the contract and assists in contract administration by monitoring the contractor's performance. The COR is not authorized to change any of the terms and conditions of the contract.
END OF PERFORMANCE WORK STATEMENT
ATTACHMENT 1
CERTIFICATE OF DESTRUCTION
This certifies that the following material was picked up from the RWBAHC at {facility named entered and building # if necessary):
On (Date):
Number of Containers Removed & sizes:
Estimated Weight of Sensitive Material:
Other info:
The material to be destroyed on:
Equipment used to destroy documents {make/model}:
Final destination of destroyed materials CONTRACTOR GUARANTEES THAT DATA, MATERIAL OR PRODUCTS PROCESSED FOR DESTRUCTION WILL
BE REDUCED TO PARTICLES AS SPECIFIED BY THE CONTRACT.
The material shall be protected from disclosure in accordance with the provision of the Privacy Act and Records Management Procedures. Release of the material or its contents prior to destruction is a violation of the Privacy Act of 1974 and could involve imposition of criminal penalties.
RELEASED BY: DESTRUCTION ACKNOWLEDGED BY:
{Signature) {Signature) {Print name & date) {Print name & date)
DOD INSTRUCTION 5200.48
CONTROLLED UNCLASSIFIED INFORMATION (CUI)
Originating Component: Office of the Under Secretary of Defense for Intelligence and Security Effective: March 6, 2020 Releasability: Cleared for public release. Available on the Directives Division Website at https://www.esd.whs.mil/DD/.
Cancels: DoD Manual 5200.01, Volume 4, “DoD Information Security Program: Controlled Unclassified Information,” February 24, 2012, as amended Approved by: Joseph D. Kernan, Under Secretary of Defense for Intelligence and Security (USD(I&S)) Purpose: In accordance with the authority in DoD Directive (DoDD) 5143.01 and the December 22, 2010 Deputy Secretary of Defense Memorandum, this issuance:
� Establishes policy, assigns responsibilities, and prescribes procedures for CUI throughout the DoD in accordance with Executive Order (E.O.) 13556; Part 2002 of Title 32, Code of Federal Regulations (CFR);
and Defense Federal Acquisition Regulation Supplement (DFARS) Sections 252.204‐7008 and 252.204‐ 7012.
� Establishes the official DoD CUI Registry.
DoDI 5200.48, March 6, 2020
TABLE OF CONTENTS
SECTION 1: GENERAL ISSUANCE INFORMATION 4
1.1. Applicability 4
1.2. Policy 4
SECTION 2: RESPONSIBILITIES 6
2.1. USD(I&S 6
2.2. Director for Defense Intelligence (Counterintelligence, Law Enforcement, and Security
(DDI(CL&S)) 6
2.3. Director, Defense Counterintelligence and Security Agency (DSCA) 7
2.4. Chief Management Officer of the Department of Defense (CMO) 8
2.5. PFPA 8
2.6. Under Secretary of Defense for Policy 8
2.7. USD(A&S) 8
2.8. USD(R&E) 9
2.9. DoD CIO 9
2.10. OSD and DoD Component Heads 10
2.11. Secretaries of the Military Departments 11
2.12. Chairman of the Joint Chiefs of Staff 11
SECTION 3: PROGRAMMATICS 12
3.1. Background 12
3.2. Legacy Information Requirements 12
3.3. Handling Requirements 13
3.4. Marking Requirements 14
3.5. General DoD CUI Administrative Requirements 17
3.6. General DoD CUI Procedures 17
3.7. General DoD CUI Requirements 19
3.8. OCA 23
3.9. General Release and Disclosure Requirements 23
3.10. General System and Network CUI Requirements 24
SECTION 4: DISSEMINATION, DECONTROLLING, AND DESTRUCTION OF CUI 27
4.1. General 27
4.2. Dissemination Requirements for DoD CUI 28
4.3. Legacy Distribution Statements 28
4.4. Decontrolling 29
4.5. Destruction 30
SECTION 5: APPLICATION OF DOD INDUSTRY 31
5.1. General 31
5.2. Misuse or UD of CUI 32
5.3. Requirements for DoD Contractors 32
GLOSSARY 33
G.1. Acronyms 33
G.2. Definitions 34
REFERENCES 38
DoDI 5200.48, March 6, 2020
TABLE OF CONTENTS 3
TABLES
Table 1. DoD CUI Registry Category Examples 22 Table 2. Dissemination Control and Distribution Statement Markings 29
FIGURES
Figure 1. CUI Warning Box for Classified Material 15 Figure 2. CUI Designation Indicator for All Documents and Material 16 Figure 3. Notice and Consent 26 DoDI 5200.48, March 6, 2020
SECTION 1: GENERAL ISSUANCE INFORMATION 4
SECTION 1: GENERAL ISSUANCE INFORMATION
1.1. APPLICABILITY.
This issuance applies to:
a. Office of the Secretary of Defense (OSD), the Military Departments, the Office of the Chairman of the Joint Chiefs of Staff and the Joint Staff, the Combatant Commands, the Office of the Inspector General of the Department of Defense (OIG DoD), the Defense Agencies, the DoD Field Activities, and all other organizational entities within the DoD (referred to collectively in this issuance as the “DoD Components”).
b. Arrangements, agreements, contracts, and other transaction authority actions requiring access to CUI according to terms and conditions of such documents, as defined in Clause 2.101 of the Federal Acquisition Regulation and Section 2002.4 of Title 32, CFR, including, but not limited to, grants, licenses, certificates, memoranda of agreement/arrangement or understanding, and information‐sharing agreements or arrangements.
1.2. POLICY.
It is DoD policy that:
a. As part of the phased DoD CUI Program implementation process endorsed by the CUI Executive Agent (EA) pursuant to Information Security Oversight Office (ISOO) Memorandum dated August 21, 2019, the designation, handling, and decontrolling of CUI (including CUI identification, sharing, marking, safeguarding, storage, dissemination, destruction, and records management) will be conducted in accordance with this issuance and Sections 252.204‐7008 and 252.204‐7012 of the DFARS when applied by a contract to non‐DoD systems.
b. All DoD CUI must be controlled until authorized for public release in accordance with DoD Instructions (DoDIs) 5230.09, 5230.29, and 5400.04, or DoD Manual (DoDM) 5400.07. Official DoD information that is not classified or controlled as CUI will also be reviewed prior to public release in accordance with DoDIs 5230.09 or5230.29.
c. Information will not be designated CUI in order to:
(1) Conceal violations of law, inefficiency, or administrative error.
(2) Prevent embarrassment to a person, organization, or agency.
(3) Prevent open competition.
(4) Control information not requiring protection under a law, regulation, or government wide policy, unless approved by the CUI EA at the National Archives and Records Administration (NARA), through the Under Secretary of Defense for Intelligence and Security
(USD(I&S)).
DoDI 5200.48, March 6, 2020
SECTION 1: GENERAL ISSUANCE INFORMATION 5
d. In accordance with the DoD phased CUI Program implementation, all documents containing CUI must carry CUI markings in accordance with this issuance.
e. Although DoD Components are not required to use the terms “Basic” or “Specified” to characterize CUI at this time, DoD Components will apply:
(1) At least the minimum safeguards required to protect CUI.
(2) Terms and specific marking requirements will be promulgated by the USD(I&S) in future guidance.
f. Nothing in this issuance alters or supersedes the existing authorities of the Director of National Intelligence (DNI) regarding CUI.
g. Nothing in this issuance will infringe on the OIG DoD’s statutory independence and authority, as articulated in the Inspector General Act of 1978 in the Title 5, United States Code (U.S.C.) Appendix. In the event of any conflict between this instruction and the OIG DoD’s statutory independence and authority, the Inspector General Act of 1978 in the Title 5, U.S.C. Appendix takes precedence.
DoDI 5200.48, March 6, 2020
SECTION 2: RESPONSIBILITIES 6
SECTION 2: RESPONSIBILITIES
2.1. USD(I&S)
The USD(I&S):
a. As the DoD Senior Agency Official for Security, establishes policy and oversees the DoD Information Security Program.
b. In coordination with the requesting DoD Component, submits changes to CUI categories on behalf of DoD Components to the CUI EA at NARA.
c. Provides reports to the CUI EA on the DoD CUI Program status, as described in Paragraph 3.6.c., in accordance with Part 2002 of Title 32, CFR.
d. Establishes protocol for resolving disputes about implementing or interpreting E.O. 13556, Part 2002 of Title 32, CFR, the CUI Registry, and this issuance, within and between the DoD Components.
e. Coordinates with the Department of Defense Chief Information Officer (DoD CIO) on CUI waiver requests for DoD information systems (IS) and networks.
f. Coordinates with the CUI EA on DoD Component CUI waiver requests.
2.2. DIRECTOR FOR DEFENSE INTELLIGENCE (COUNTERINTELLIGENCE, LAW ENFORCEMENT, AND
SECURITY (DDI(CL&S)).
The DDI(CL&S):
a. Oversees and manages the DoD CUI Program.
b. Reviews and signs all reports and other correspondence related to the DoD CUI Program.
c. Coordinates with the Secretaries of the Military Departments, Under Secretary of Defense for Research and Engineering (USD(R&E)), Under Secretary of Defense for Acquisition and Sustainment (USD(A&S)), and the DoD Component heads to:
(1) Recommend changes to national CUI policy relating to identifying, safeguarding, disseminating, marking, storing, transmitting, reviewing, transporting, re‐using, decontrolling, and destroying CUI, and responding to unauthorized disclosure (UD) of CUI.
(2) Review and provide guidance on DoD Component implementation policy and CUI related matters.
d. Assists the USD(I&S) with overseeing the CUI policy and program execution via the Defense Security Enterprise Executive Committee in accordance with DoDD 5200.43.
DoDI 5200.48, March 6, 2020
SECTION 2: RESPONSIBILITIES 7
e. In coordination with the DoD CIO, USD(A&S), and USD(R&E), provides guidance on implementing uniform standards to display TOP SECRET, SECRET, CONFIDENTIAL, and UNCLASSIFIED for CNSI and CUI controls and banners for DoD systems and networks.
2.3. DIRECTOR, DEFENSE COUNTERINTELLIGENCE AND SECURITY AGENCY (DSCA).
Under the authority, direction, and control of the USD(I&S) and in addition to the responsibilities in Paragraph 2.10., the Director, DCSA:
a. Administers the DoD CUI Program for contractually established CUI requirements for contractors in classified contracts in accordance with the May 17, 2018 Under Secretary of Defense for Intelligence Memorandum.
b. Assesses contractor compliance with contractually established CUI system requirements in DoD classified contracts associated with the National Industrial Security Program (NISP) in accordance with Part 2003 of Title 32, CFR and National Institute of Standards and Technology Special Publication (NIST SP) 800‐171 guidelines.
c. Establishes and maintains a process to notify the DoD CIO, USD(R&E), and USD(A&S) of threats related to CUI for further dissemination to DoD Components and contractors in accordance with the Section 252.204‐7012 of the DFARS.
d. Provides, in coordination with the USD(I&S), security education, training, and awareness on the required topics identified in Section 2002.30 of Title 32, CFR, including protection and management of CUI, to DoD personnel and contractors through the Center for Development of Security Excellence
(CDSE).
e. Provides security assistance and guidance to the DoD Components on the protection of CUI when DoD Components establish CUI requirements in DoD classified contracts for NISP contractors falling under DCSA security oversight.
f. Serves as the DoD‐lead to report UDs of CUI, except for the reporting of cyber incidents in accordance with Section 252.204‐7012 of the DFARS, associated with contractually established CUI system requirements in DoD classified contracts for NISP contractors falling under DCSA security oversight.
g. Coordinates with the DoD CIO to implement uniform security requirements when the IS or network security controls for unclassified and classified information are included in DoD classified contracts for NISP contractors falling under DCSA security oversight.
h. Consolidates DoD Component input on the oversight of CUI protection requirements in DoD classified contracts for NISP contractors under DCSA security oversight, as required by Information Security Oversight Office (ISOO) Notice 2016‐01.
DoDI 5200.48, March 6, 2020
SECTION 2: RESPONSIBILITIES 8
2.4. CHIEF MANAGEMENT OFFICER OF THE DEPARTMENT OF DEFENSE (CMO).
In addition to the responsibilities in Paragraph 2.10., the CMO:
a. Serves as the subject matter expert on CUI containing personally identifiable information and its release in accordance with Subsection 552 of Chapter 5 of Title 5, United States Code (U.S.C.), also known as and referred to in this issuance as the “Freedom of Information Act (FOIA),” implemented through DoDD 5400.07 and DoDI 5400.11, and Subsection 552a of Chapter 5 of Title 5, U.S.C., also known and referred to in the issuance as the “Privacy Act of 1974.”
b. Supports OSD with information security matters, as appropriate.
2.5. PFPA.
Under the authority, direction, and control of the CMO, through the Director for Administration and Organizational Policy, and in addition to the responsibilities in Paragraph 2.10., the Director, PFPA:
a. Provides information security administrative support to OSD.
b. Provides information on OSD CUI Program status and other formally requested assistance to the USD(I&S) to support the CUI Program.
c. Conducts CUI staff assistance visits to OSD in the National Capital Region.
2.6. UNDER SECRETARY OF DEFENSE FOR POLICY.
In addition to the responsibilities in Paragraph 2.10., the Under Secretary of Defense for Policy:
a. Establishes policy and procedures for disclosing DoD CUI to foreign governments, the North Atlantic Treaty Organization, and international organizations based on formally signed agreements and arrangements between the parties.
b. Requires CUI to be identified in international agreements, arrangements, and contracts having licensing export controls for foreign partners.
2.7. USD(A&S).
In addition to the responsibilities in Paragraph 2.10., pursuant to Section 133b of Title 10, U.S.C., and in coordination with the USD(I&S), DoD CIO, and USD(R&E), the USD(A&S): a. Maintains, in accordance with Section 252.204‐7012 of the DFARS, DoD acquisition contracting processes, policies, and procedures for safeguarding DoD CUI in DoD procurement arrangements, agreements, and contracts, including other transaction authority actions.
DoDI 5200.48, March 6, 2020
SECTION 2: RESPONSIBILITIES 9
b. Supports the development and implementation of a Federal Acquisition Regulation clause applying CUI requirements to defense contractors.
2.8. USD(R&E).
In addition to the responsibilities in Paragraph 2.10., pursuant to Section 133a of Title 10, U.S.C., and in coordination with USD(I&S), the USD(R&E):
a. Establishes DoD CUI processes, policies, and procedures for grants and cooperative research and development arrangements, agreements, and contracts involving controlled technical information (CTI).
b. Establishes a standard process to identify CTI; guidelines for sharing, marking, safeguarding, storing, disseminating, decontrolling, and destroying CTI; and CTI records management requirements contained in contracts, as appropriate.
c. Oversees and ensures DoD CUI guidelines and requirements for sharing, marking, safeguarding, storage, dissemination, decontrol, destruction, and records management of all research, development, test, and evaluation information are properly executed for all DoD owned records.
d. In coordination with the USD(A&S), ensures:
(1) Contracts, arrangements, and agreements for research, development, testing, and evaluation identify CUI at the time of award.
(2) USD(R&E) international agreements, arrangements, and contracts with foreign partners identify CUI within the documents.
(3) DoD Components concluding international agreements, arrangements, and contracts with foreign partners include U.S. Government‐approved text on CUI.
2.9. DOD CIO.
In addition to the responsibilities in Paragraph 2.10., the DoD CIO:
a. Oversees CUI metadata tagging standards, consistent with federal data tagging approaches in accordance with the National Strategy for Information Sharing and Safeguarding, to implement the marking requirements in Paragraph 3.4.c. and in accordance with DoDI 8320.07.
b. Integrates CUI metadata tagging standards into DoD information technology content management tools to support discovery, access, auditing, safeguarding, and records management decisions regarding CUI (including monitoring CUI data for visibility, accessibility, trust, interoperability, and comprehension).
c. Provides policy and standards recommendations to the USD(I&S) on updates for the sharing, marking, safeguarding, storage, dissemination, decontrol, destruction, and records DoDI 5200.48, March 6, 2020
SECTION 2: RESPONSIBILITIES 10
management of DoD CUI residing on both DoD and non‐DoD IS in accordance with DoDI 8582.01.
d. Oversees Defense Industrial Base Cybersecurity Activities, using the DoD Cyber Crime Center as the single DoD focal point for receiving and disseminating all cyber incident reports impacting unclassified networks of defense contractors.
e. Coordinates with the USD(I&S), USD(A&S), USD(R&E), and DoD Component heads to develop uniform security requirements for industry partners’ IS and network security controls adequate for the type of CUI identified in the contract in accordance with Part 2002 of Title 32, CFR, Section 252.204‐7012 of the DFARS, and NIST SP 800‐171.
f. Coordinates with the Director, DCSA to implement uniform security requirements when IS or network security controls for unclassified and classified information are included in DoD classified contracts of NISP contractors falling under DCSA security oversight.
g. Coordinates with the USD(I&S) to:
(1) Implement information security policy standards for markings to display, CUI for DoD classified and unclassified systems and networks.
(2) Integrate training on safeguarding and handling CUI into updates to initial and annual cybersecurity awareness training.
h. Notifies the CUI EA in coordination with the USD(I&S) of CUI waivers impacting IS or .networks in accordance with Title 32 of the CFR.
i. Oversees and ensures DoD Component‐ and National Archives‐approved disposition authorities for CUI are implemented for DoD records and information.
j. Oversees and ensures the Director, DoD Cyber Crime Center:
(1) Manages and updates, as necessary and in coordination with DoD CIO, the policies in Section 236.4 of Title 32, CFR and Section 252.204‐7012 of the DFARS.
(2) Maintains the website at https://dibnet.dod.mil to receive contractor mandatory incident reports in accordance with Paragraph 3.9.d(1).
2.10. OSD AND DOD COMPONENT HEADS.
OSD and DoD Component heads:
a. Identify, program, and commit the necessary resources to implement CUI Program requirements as part of their overall information security programs.
b. Designate in writing (with copy to the USD(I&S)):
DoDI 5200.48, March 6, 2020
SECTION 2: RESPONSIBILITIES 11
(1) A DoD Component senior agency official (CSAO) at the Senior Executive Service level or equivalent to implement their CUI Program and perform the duties in Paragraph 3.5.
(2) A DoD Component program manager (CPM) to manage their CUI Program.
c. Ensure their subordinate organizations comply with DoD CUI Program requirements.
d. Ensure their personnel receive initial and annual refresher CUI education and training, and maintain documentation of this training for audit purposes.
e. Report DoD Component training completion data to the USD(I&S) annually or as directed.
f. Provide an annual report to the USD(I&S) on CUI implementation status in accordance with Title 32, CFR, Part 2002.
g. Determine if any CUI documents or materials constitute permanently valuable records of the government, which require maintenance and disposal in accordance with DoDI 5015.02.
h. As the requiring activity, oversee CUI requirements for contractor implementation in partnership with the Defense Contract Management Agency, based on Defense Contract Management Agency responsibilities, or DCSA for cleared contractors in accordance with the NISP, as appropriate.
i. Ensure DoD Component‐ and National Archives‐approved disposition authorities are implemented for DoD records and information regardless of classification.
j. Manage their CUI programs in accordance with guidelines prescribed in this DoD issuance.
2.11. SECRETARIES OF THE MILITARY DEPARTMENTS.
In addition to the responsibilities in Paragraph 2.10., the Secretaries of the Military Departments oversee the implementation of their CUI programs.
2.12. CHAIRMAN OF THE JOINT CHIEFS OF STAFF.
In addition to the responsibilities in Paragraph 2.10., the Chairman of the Joint Chiefs of Staff oversees the implementation of the CUI programs in the Joint Staff organizations and Combatant Commands.
DoDI 5200.48, March 6, 2020
SECTION 3: PROGRAMMATICS 12
SECTION 3: PROGRAMMATICS
3.1. BACKGROUND.
The CUI EA at NARA, through the Information Security and Oversight Office (ISOO), published and released Part 2002 of Title 32, CFR, which provides implementing requirements for E.O. 13556.
a. Part 2002 of Title 32, CFR established a CUI EA office under NARA’s ISOO for implementing and overseeing the CUI Program.
b. Designed as a response to the information sharing challenges from inconsistent definitions and marking requirements applied to CUI, Part 2002 of Title 32 CFR standardized the definition of CUI and codified the identification, sharing, safeguarding, marking, storage, distribution, transmission, decontrol, destruction, training, monitoring, and reporting requirements across the Executive branch of government.
c. In accordance with Part 2002 of Title 32, CFR, CUI requires safeguarding or dissemination controls identified in a law, regulation, or government‐wide policy for information that does not meet the requirements for classification in accordance with E.O. 13526.
d. Unlike classified information, an individual or organization generally does not need to demonstrate a need‐to‐know to access CUI, unless required by a law, regulation, or governmentwide policy, but must have a lawful governmental purpose for such access. One example of a requirement for need‐to‐know established by law, regulation, or government‐wide policy is Section 223.6 of Title 32, CFR, which requires a person to have a need‐to‐know to be granted access to DoD Unclassified Nuclear Information
(UCNI).
3.2. LEGACY INFORMATION REQUIREMENTS.
This legacy information guidance applies to information contained across DoD in, among other ocuments, security classification guides (SCGs), various policies, and other legacy materials falling under the Science and Technology Information Program (DoDI 3200.12), in either electronic or hardcopy format. The CUI Program does not require the redacting or re‐marking of documents bearing legacy markings. However, any new document created with information derived from legacy material must be marked as CUI if the information qualifies as CUI.
a. DoD legacy material will not be required to be re‐marked or redacted while it remains under DoD control or is accessed online and downloaded for use within the DoD. However, any such document or new derivative document must be marked as CUI if the information qualifies as CUI and the document is being shared outside DoD. DoD legacy marked information stored on a DoD access‐controlled website or database does not need to be remarked as CUI, even if other agencies and contractors are granted access to such websites or databases.
b. DoD legacy information does not automatically become CUI. It must be reviewed by the owner of the information to determine if it meets the CUI requirements. If it is determined the DoDI 5200.48, March 6, 2020
SECTION 3: PROGRAMMATICS 13
specific legacy information meets the CUI requirements, it will be marked in accordance with this issuance and corresponding manual.
c. For federal systems, IS storing information identified as CUI must meet the minimum network security standard in Part 2002 of Title 32, CFR. For nonfederal systems, IS must meet the standards in the NIST SP 800‐171, when established by contract.
d. When DoD legacy information is incorporated into, or cited in, another document or material, it must be reviewed for CUI and marked in accordance with this issuance.
3.3. HANDLING REQUIREMENTS.
The DoD CUI Information Security Program will promote, to the maximum extent possible, information sharing, facilitate informed resource use, and simplify its management and implementation while maintaining required safeguarding and handling measures.
a. In accordance with DoDI 5230.09 and the August 14, 2014 Deputy Secretary of Defense Memorandum:
(1) The DoD originator or authorized CUI holder must ensure a prepublication and security policy review is conducted, pursuant to the standard DoD Component process, before CUI is approved for public release, which includes publication to a publicly accessible website.
(2) Decontrolling and releasing CUI records will be executed by the originator of the information, the original classification authority (OCA) if identified in a security classification guide, or designated offices for decontrolling CUI pursuant to the procedures for the review and release of information under the FOIA in accordance with the November 19, 2018 ISOO Notice. There are no specific timelines to decontrol CUI unless specifically required in a law, regulation, or government‐wide policy. Decontrol will occur when the CUI no longer requires safeguarding and will follow DoD records management procedures.
b. OCAs will determine if aggregated CUI under their control should be classified in accordance with Volume 1 of DoDM 5200.01 and will confirm the relevant SCGs address the compilation.
c. DoD information systems processing, storing, or transmitting CUI will be categorized at the “moderate” confidentiality impact level and follow the guidance in DoDIs 8500.01 and 8510.01. Non‐ DoD information systems processing, storing, or transmitting CUI will provide adequate security, and the appropriate requirements must be incorporated into all contracts, grants, and other legal agreements with non‐DoD entities in accordance with DoDI 8582.01. See Section 5 of this issuance for more information on CUI and its application to industry.
d. The DoD CUI Registry provides an official list of the Indexes and Categories used to identify the various types of DoD CUI. The DoD CUI Registry mirrors the National CUI Registry, but provides additional information on the relationships to DoD by aligning each Index and Category to DoD issuances.
DoDI 5200.48, March 6, 2020
SECTION 3: PROGRAMMATICS 14
(1) The official DoD CUI Registry of categories can be accessed on Intelink at https://intelshare.intelink.gov/sites/ousdi/hcis/sec/icdirect/information/CUI/Forms/AllItems.aspx.
(2) The site will be updated as changes to the DoD CUI Registry are made based on official notification from the CUI EA through the CUI Registry Working Group; changes to law,regulation, or government‐ wide policy; or notification that the information no longer meets therequirements for CUI.
3.4. MARKING REQUIREMENTS.
This paragraph covers the essential marking requirements for initial phased implementation of the DoD CUI Program.
a. At minimum, CUI markings for unclassified DoD documents will include the acronym “CUI” in the banner and footer of the document.
b. If portion markings are selected, then all document subjects and titles, as well as individual sections, parts, paragraphs, or similar portions of a CUI document known to contain CUI, will be portion marked with “(CUI).” Use of the unclassified marking “(U)” as a portion marking for unclassified information within CUI documents or materials is required.
(1) There is no requirement to add the “U,” signifying unclassified, to the banner and footer as was required with the old FOUO marking (i.e., U//FOUO).
(2) Banners, footers, and portion marking will only be marked “Unclassified” or “(U)” for unclassified information in accordance with the June 4, 2019 ISOO letter. If the document also contains CUI, it will be marked in accordance with Paragraph 3.4.a. and additional forthcoming guidance.
c. CUI markings in classified documents will appear in paragraphs or subparagraphs known to contain only CUI and must be portion marked with “(CUI).” “CUI” will not appear in the banner or footer.
(1) There will be an acknowledgement added to the warning box on the first page of multi‐page documents to alert readers to the presence of CUI in a classified DoD document, as shown in Figure 1.
DoDI 5200.48, March 6, 2020
SECTION 3: PROGRAMMATICS 15
Figure 1. CUI Warning Box for Classified Material This content is classified at the [insert highest classification level of the source data] level and may contain elements of controlled unclassified information (CUI), unclassified, or information classified at a lower level than the overall classification displayed. This content shall not be used as a source of derivative classification; refer instead to [cite specific reference, where possible, or state “the applicable classification guide(s)”]. It must be reviewed for both Classified National Security Information (CNSI) and CUI in accordance with DoDI 5230.09 prior to public release. [Add a point of contact when needed.]
(2) Volume 2 of DoDM 5200.01 requires DoD intelligence producers to follow DNI formats for intelligence production under the authority of the DNI. When DoD CUI is incorporated into a Digital Access Policy under the authority of the DNI, the information and the document will follow the Digital Access Policy standards established by the DNI.
d. The dissemination marking “not releasable to foreign nationals (NOFORN or NF)” is an intelligence control marking used to identify intelligence information an originator has determined meets the criteria of Intelligence Community Directive 710 and Intelligence Community Policy Guidance 403.1, which provides guidance for further dissemination control markings. It must be applied to controlled unclassified intelligence information that is properly characterized as CUI with appropriate CUI markings.
CUI identified with this marking will not be provided, in any form, to foreign governments (including coalition partners), international organizations, foreign nationals, or other non‐U.S. persons without the originator’s approval in accordance with E.O.s 13526 and 13556. If originator approval is required for further dissemination, the originator will mark the requirement on the information in accordance with Section 4.1(i)(1) of E.O. 13526.
(1) The application of the control marking “not releasable to foreign nationals” (NOFORN or NF) will only be applied, when warranted, to unclassified intelligence information properly categorized as CUI and reviewed by a Foreign Disclosure Officer to ensure there are no international agreements in place to prohibit its use and prohibiting sharing.
(2) The control marking NOFORN or NF will be applied to Naval Nuclear Propulsion Information (NNPI), Unclassified Controlled Nuclear Information (UCNI), National Disclosure Policy (NDP‐1), and cover and cover support information. When warranted, it can be applied to unclassified information properly categorized as CUI having a licensing or export control requirement. Before marking a document or material as NOFORN or NF, it will be reviewed by the Foreign Disclosure Officer to ensure there are no agreements in place to prohibit its use and sharing.
(3) The application of “Releasable to” (“REL TO”) can only be applied, when warranted and consistent with relevant law, regulation, or government‐wide policy or DoD policy, to information properly categorized as CUI with an export control or licensing requirement with a foreign disclosure agreement in place.
DoDI 5200.48, March 6, 2020
SECTION 3: PROGRAMMATICS 16
(a) Export‐controlled CUI transfers to foreign persons must be in accordance with the Arms Export Control Act, International Traffic in Arms Regulations, Export Control Reform Act, Export Administration Regulations, and DoDI 2040.02. In accordance with DoDDs 5230.11 and 5230.20, a positive foreign disclosure decision must be made before CUI is released to a foreign entity.
(b) DoD operational CUI (not related to intelligence) may be marked as REL TO.
e. All classified documents, including legacy documents will be reviewed for CUI and properly marked upon changes in the document’s classification level, particularly if the documents are to be completely declassified.
f. The first page or cover of any document or material containing CUI, including a document with commingled classified information, will include a CUI designation indicator, as shown in Figure 2.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .