Contractor Guidance on Protecting Federal Data

Repository of Tools to Protect our Supply Chain

cyberdi

FCI vs CUI

Two Types of Data Federal Contractors Must Protect

FCI

CUI

What is FCI?

Federal Contract Information. Any information included in or created for a government contract not meant for public release.

What is CUI?

Controlled Unclassifed Information. Information that requires safeguarding or dissemination controls required by law, regulation, or Govt-Wide Policy but not classifed and nuclear stuff

Who makes FCI?

FCI can be created by you or the government as a result of a contract

FCI is not meant for public release

Who Makes CUI?

Controlled Unclassified Information, as can be made by or on behalf of the DOD.

What types of FCI?

There is no classification system for FCI

All information not for public release is FCI

What types of CUI?

CUI-Basic: Follow rules for protecting

CUI-Specified: Spells out rules for protection

Controlled Technical Information, General Procurement & Acquisition, and Proprietary Information, among others.

The National Archives creates CUI categories. The DoD or CMMC-AB has no say

Who labels FCI?

FCI needs safeguarding

There is no classification system

Who labels CUI?

The entity that creates the CUI labels CUI

Authorized holders with a lawful government purpose mark CUI using agency/component guidance.

History of FCI?

Established by the Federal Acquisition Regulation Clause 52.204 - 21 Basic Safeguarding of Covered Contractor Information Systems.

History of CUI?

Created by EO 13556 after 9/11 to create a streamlined method for information sharing and safeguarding.

Safeguarding FCI?

FAR Clause 52.204-21 lays out basic safeguards for protection

Do not assume this is easy

Safeguarding CUI?

CUI requires physical and cybersecurity safeguards

CUI gets protected by NIST 800-171 using the 171a methodology

Hard and expensive. Plan on 6 months to a year

Is my IP FCI?

No. It is not FCI.

Only the Government can create FCI.

Is my IP CUI?

Yes, when created as a part of a government contract, unless mutually agreed between IP owner and Gov’t Contracting Agency.

Impact of CMMC on FCI?

Contractors who only touch or create FCI will need to pass a level one maturation assessment

By 2025 all contractors will be assessed using the CMMC Level 1 methodology

Impact of CMMC on CUI?

Contractors who touch, create, receive, transmit or destory CUI will need to pass a level three maturation assessment

By 2025(ish) all contractors will be assessed using the CMMC Level 3 methodology

{Insert Company Name} CUI Guide

Please review the below guidance to better understand Controlled Unclassified Information (CUI), what it looks like, and some general DO’s and DON’T’s. When in doubt, please contact your Supervisor and/or the {IT Department} for additional information.

{Insert Company logo by changing image link}

What is CUI?

CUI is Controlled Unclassified Information, a marking similar to For Official Use Only (FOUO). CUI is required to be protected in ac-cordance with NIST SP 800-171

What is CUI?

Controlled Unclassified Information. Contract information that needs additional safegaurding based on federal laws, classifed and nuclear stuff

What does CUI look like?

CUI may have a cover sheet with a purple bor-der. It may also be marked as CUI, (U) CUI, or specified-marked, for example:CUI//SP-PII//NOFORN

Who Makes CUI?

The DoD or contractors like {Company} may produce CUI. {Company} will only create CUI when in support of a DoD contract it meets types defined in the NARA CUI Registry.

{Insert Company Name} Proprietary Data?

{Insert Company Name} proprietary data is not CUI. IP pertaining to {Insert Company Name} employees is not CUI. There are many types of sensitive data that are not CUI.

Who labels CUI?

The person generating CUI is responsible for categorizing and marking the data. CUI today is often not labeled.

Classified Data?

{Insert Company Name} computers and networks are not equipped to handle classified data. All classified data must reside in SIPRnet.

Where can I store CUI?

{Insert Company Name} has provided {Insert software solution} as secure place to store and process CUI. CUI cannot be stored on your laptop, cloud drives, USB sticks. or in {Company} Email. Saving yourself a draft email is not secure.

How do I receive CUI?

You should direct the sender to send you CUI through DoD tools such as SAFE, or through {Insert Software Solution}. CUI should not be sent to your {Company Email} at this time.

How do I destroy CUI?

Given that most CUI is not lableled the company policy is to shred everything. Unless it carried food all paper gets shredded. Period. {Insert Software Solution} has guidance on destorying internal CUI. At no time should CUI be on any other external storage device.

Reporting Questions or Concerns?

Report any questions or concerns to your su-pervisor and the {IT Department}.

CUI Guidance for {Insert Company Name} subcontractors

Please review the below guidance to better understand Controlled Unclassified Information (CUI), what it looks like, and some general DO’s and DON’T’s. When in doubt, please contact your Supervisor and/or the {IT Department} for additional information.

{Insert Company logo by changing image link}

What is CUI?

CUI is Controlled Unclassified Information, a marking similar to For Official Use Only (FOUO). CUI is required to be protected in ac-cordance with NIST SP 800-171

What is CUI?

Controlled Unclassified Information. Contract information that needs additional safegaurding based on federal laws, classifed and nuclear stuff

What does CUI look like?

CUI may have a cover sheet with a purple bor-der. It may also be marked as CUI, (U) CUI, or specified-marked, for example:CUI//SP-PII//NOFORN

Who Makes CUI?

The DoD or contractors like {Company} may produce CUI. {Company} will only create CUI when in support of a DoD contract it meets types defined in the NARA CUI Registry.

{Insert Company Name} Proprietary Data?

{Insert Company Name} or your company's proprietary data is not CUI. IP pertaining to {Insert Company Name} employees is not CUI. There are many types of sensitive data that are not CUI.

Who labels CUI?

The person generating CUI is responsible for categorizing and marking the data. CUI today is often not labeled.

Classified Data?

{Insert Company Name} computers and networks are not equipped to handle classified data. All classified data must reside in SIPRnet.

Where can I store CUI?

Discuss with your information security manager where CUI may be stored on your net- work. {Company} allows CUI only in our {Software Solution} systems. {

How do I send CUI to {Company}?

You may send CUI to {Company} via {Internal Apps} or DoD SAFE.

How do I destroy CUI?

All CUI no longer in use gets destroyed. Discuss with your information security manager your policy on destroying CUI and media sanitization.

How do I receive CUI?

You should direct the sender to send you CUI through DoD tools such as SAFE. CUI must be encrypted in transit and when stored.

Reporting Questions or Concerns?

Report any questions or concerns to your su-pervisor and the {IT Department}.

FCI Cheat Sheet

A simplified guide to help you understand CMMC Maturation Level One

{Insert Company logo by changing image link}

Do you have a a federal contract?

If you do not have a contract from the government or a contract funded from a larger Government award you can not have FCI

If you do have federal funding you have FCI if you touch any information not meant for public release.

How big a solution do you need?

To meet the Safeguarding of Covered Contractor Information Systems required by FARS Clause 52.204-21. You can protect your entire network and company premise.

You may find it more affordable to sequester FCI to a specific device, like a company provided laptop and use a protected file sharing solution.

Do I even have FCI?

FCI is any data not meant for public release. So if you can download it from a public website, google it, or if the data is presently FOIable it is not FCI.

Do you have policies on employees accessing different parts of your company?

Level One Acess Control Practices 1.001

Much of your #cmmc level one compliance can be met with a well written access control policy. The FARS 21 Clause requires you to, " Limit information system access to authorized users, processes acting on behalf of authorized users, or devices"

These policie address your account management and describe how you identify users, and limit their authorization. You also have rules on how to add new equipment like printers.

A CMMC assessor will want to see an access control policy. They will want to talk to whoever manages the list and networks. This maybe an IT contractor. They may want to test how you add a new user or employee to the system.

A {company name}registered professional can help you write an access control policy.

Do you only give data to people who need it?

Level One Access Control 1.002

Much of your CMMC Level One compliance revolves around common sense. Only let people who need to use data have access to that data. The FARS 21 Clause requires you to, " Limit information system access to the types of transactions and functions that authorized users are permitted to execute."

Basically you need to define access priviledges. How you do this should be documented in your access control policy. If you use O365 or G Suite you have this ability to define groups and roles. If you want to share data outside your organization you may want to use a secure and encrypted file service.

Again contact {company name} if you need help crafting a an access control policy that has evidene of your compliance. Check out {company name} for an encrypted file sharing solution

What do I do with personal devices and home networks?

Level One Access Control AC.1.003

You will need to make decisions about personal devices. You either have to provide devices to employees like lap tops and cell phones or use mobild device management. The other solution is to allow no off site access or of the clock work. The Fars 21 clause requires you to limit,"use of external information systems"

Even if you provide devices you should use Mobile Device Management to protect FCI.

If you need employees to access FCI from home or remote you need a VPN. This is a virtual private network. You will need to document in your access control policy.

A CMMC assessor will want to see your access control policy, they will want talk your network adminstrator or IT consulantant and test your VPN

Can I use my IT Consulting Firm?

Level One Access Control AC.1.003

Many small businesses rely on IT firms. They often connect your network to their external systems. As the Government contractor iit is your responisbility to ensure any IT contractor protects your FCI.

Your CMMC assessor will want to see clear policies about FCI boundaries between yoru company and the IT contractor.

Many times IT contractors have full access to your network. For this reason CyberDI suggests only using vendors who hold a CMMC Level Three certificate. You could also sequester FCI in a file sharing system such as {company name} to only share FCI with authorized users.

Do you limit who can publish or make stuff public at your company?

Level One Acces Control AC1.004

Another common sense CMMC control. Would you let anyone just publish info on your website? The FARS 21 clause requires you to,"Control information posted or processed on publicly accessible information systems."

You have to be careful with stuff like websites and press releases when you touch FCI.

A CMMC assessor will want to see rules about who gets to publish data and information to public channels. A {Company Name} CMMC Registered Professional can help you write your Access Control policy so it contains the required observable evidence.

Does everyone have a unique username and password?

Level One Identification and Authentication IA. 1.076

Controlling data means knowing who logs in when. This begins by having unique user names and passwords. You can not save money by sharing credentials when it comes to FCI. The FARS-21 clause requires you to, "Authenticate (or verify) the identities of those users, processes, or devices." before they can touch sensitive data

It is important to know the difference between authentication and authorization. Authentication follows the Popeye (or Slim Shady) rule: I Am who I says I am. Authorization is the permissions assigned to an authenticated user.

A CMMC assessor will need to verify if every user has a unique identifier for all systems that touch FCI. This can include user names and stuff do identify computers like a MAc address or internet users thorugh Internet Protocol addresses. If you use software you may need to document the API token generation used for authentication. APIs are like secret handshakes between computers. They will only talk if tokens match.

You need to document your user authentication process. Much of this just needs to refer to your software such as Microsoft or Google documentation. A {company name] Registered Professional can help.

Do you know how to find records of who logged into what?

Level One Identification and Authentication IA. 1.077

One you know you authenticate each use you need to know when they log in and what device they are using. To cpmply with FARS 21 you need to have this information as a, " prerequisite to allowing access to organizational information system."

For many small businesses this maybe data kept by a IT consulting company. Once again we recommend using only IT consultants persuing a CMMC level Three certification

A CMMC assessor will look for a mchanism to support your authentication. It is important you use multifactor authentication and not just two factor authentication. Most modern computer systems support MFA. Ask your CMMC Level 3 Certified IT Company for help.

Do you shred everything that did not contain food or liquids?

Level One Media Protection MP.1.118

It is good company policy to err on the side of shred everything. If you have a locked room just for prining and storing FCI keep the shredder there.

Do you have a plan for destroying old electronic data?

What happens when employees leave? Do you erase usb thumb drives if they can transmit FCI?

It is good company policy to err on the side of shred everything. If you have a locked room just for prining and storing FCI keep the shredder there.

A {company name} Registered Professional can walk you through the NIST SP 800-88 guidance on destroying media.

Do you lock the doors?

Level One Physical Protection PE.1.131

Sounds silly but the CMMC Level one requires basic physical protections you may take for granted. The Fars 21 Basic safeguarding isn't safe if people have physical access to your site or your networks.

If you store FCI this needs to be in a place, such as a room or a locked cabinet where the public or unauthorized staff can not access.

Your physical access will require some advanced security such as electronically or visually checked badges and keycards.

A CMMC Level One Assessor will test your physical access authorizations and examine written policies.

Do you let the public wander around your company aimlessly without an escort?

Level One Physical Protection 1.1.32

Of course not. Just write this down in a policy as observable evidence for compliance. Keep visitor logs. There are plenty of fancy solutions but a paper sign in still works. Remember DFARS-21 requires you to, " Escort visitors and monitor visitor activity and maintain audit logs of physical access"

A CMMC assessor will look for your visitor escort policies. If you use electronic solutions they may test these.

Do you make vistors sign in?

Level One Physical Protection 1.133

Another common sense protection of the FARS 21 clause that requires you to, "maintain audit logs of physical access."

A CMMC assessor will look for your visitor logs. Even paper logs will do but you may want to consider a solution that captures a physical image.

Badges? Do we need stinkin' badges?

Level One Physical Protection 1.134

If you use access cards these need to get into spaces that protect FCI these need protection too. The DFARS 21 clause states, "Limit physical access to organizational information systems, equipment, and the respective operating environments." If you do not protect the tools that allow you to do this you have no protection.

So if you use badges or even use a photcopier code for machines authorized for FCI duplication you need to protect these and desascribe how you protect these in an access policy.

If you padlock access to the yard don't do dumb stuff like write the combo on the side of the wall are on the lock.

A CMMC Assessor will want to see an inventory of your access control devices. They may check your doors. In fact you should prepare an iventory of all your electronic dveices and have it ready for an assessment.

Do you have filters and tools to block and monitor stuff on your Internet?

Level One System and Communication Protection SC.1.1.175

Just like you need to lock and monitor your physical boundaries with doors and locks you also need to protect the boundaries of your networks and communication systems like email. In fact the FARS 21 clause requires you to monitor, "at the external boundaries and key internal boundaries of the information systems.""

A CMMC assessor will look for communication protection policies. You also should have a professional network expert diagram how FCI flos in your system. They will also want to know how your system is configured.

This is one of the most complicated of the Level One CMMC practices. You really should use a CyberDI Registered Professional to draw your network diagram. You can not do the monitoring on your own. {Company Nmane} recommends using a qualfied vendor a cybersecurity solution

Do you split your network servers so stuff for the public is in one place and private company stuff in another?

Level One System and Communication Protection SC.1.176

The cybersecurity world has a phrase for when we sepersate different types of data using the Demilitarized Zone (DMZ) as a metaphor. This just means having a system to meet the FARS 21 requirement of, "implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks"

A CMMC assessor will test many systems and hardware. if you use an IT consultant make sure they are on the pathway to achieving CMMC Level Three classification. This is not a requirement, but recommended as good practice when using vendors to protect FCI.

You will have to monitor these systems. Once again CyberDI recommends using {software solution} for system monitoring.

Can employees ignore the "Update Now" notification and click, "remind me tomorrow" forever?

Level One System and Information Integrity SI.1.210

Do not rely on humans to complete timely updates. You need to automate these systems so you can, "Identify, report, and correct information and information system flaws in a timely manner."

If a computer is not updated you can not identify flaws in a timely manner. You need to track updates and when you find flaws in your system there must be way to report these. flaws.

A CMMC assessor will want to see configuration management policies, device imaging policies, and they may test how you install and approve software You should document all of this with a {Company Name} Registered Professional.

Do you buy or pay for malware or virus protection?

Level One System and Information Integrity SI.1.211

You need protection from bad things on the web. In facts the FARS 21 clause calls for, "protection from malicious code at appropriate locations within organizational information systems."

Designate locations mean places where data enters and exits your system like email, servers, and firewalls. Most businesses can not do this on their own and use software solutions from enterprise software and third party IT consultants.

A CMMC assessor will want to test all the things. More things than we can fit here. You may want consider {company name} as a cybersecurity solution to help you out.

Do you know how your Enterprise Solutions update malware and virus protection?

Level One System and Information Integrity SI.1.212

No point in protecting boundaries, places that should block access, test the "DMZ," or designated locations of FCI without updates. In facts the FARS 21 clause declares, "Update malicious code protection mechanisms when new releases are available."

Configuration managment is hard. You can't do it. Even if you use commercial off the shelf solutions you should use an IT professional. In terms of Obervable Evidence work with the consulant to write policies.

A CMMC assessor will test information integrity policies, want to see network diagrams, see how you monitor false positives, meaning that important deal getting lost in your spam folder. You can not do this alone.

Do you use a major email Enterprise solution? Do you know where the spam and phishing policies live?

Level One System and Information Integrity SI.1.213

Almost all email tools have policies and systems that have enough observable evidence to meet the FARS 21 requirement of, "Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed."

You may have the tools, but do you know where to find them. The Enterprise solutions maybe enough for compliance but do not confuse compliance with security. If you care about protecting FCI we recommend using someone such as {company name}

Jargon Explained: Access Control

A simplified guide to help you understand Access Control.

{Insert Company logo by changing image link}

What is Access Control?

Cybersecurity begins and ends with access control. You must know who resides in your system and what stuff they can access. At home you keep track of who has keys, a cell phone account, and wifi password. Do the same at work with user names and passwords.

NIST SP 800-192 "Verfication and Test Methods for Access Control Policies/Moddels" defines access control polcies as:

high level requirements that specify how access is managed and who, under what circumstances, may access what information

Access policies can apply to specific users and roles, such as only giving accounting access to financials. Access control policies can also get assigned at the appliclation so you need to know a vendor's policy before buying any technology.

How do Access Control Policies Work?

Access control policies establish organizational boundaries that limit information based on units, need-to-know, authority or any number of business siutations that require the legal access to information

Inside your network or data flow, how information moves across physical and digital spaces, boundaries act as places to stop access. This also means boundaries by design can break. Protecting these weaknesses through access control policy builds a foundation of cybersecurity

Where do Access Control Policies Live?

You may create one document where all your access control policies live but focus on doing business better first. As you craft company training and documentation consider where your accesc control policies already live.

Employee handbooks will describe if people can bring devices to work or connect work devices to home networks. They will describe rules banning the sharing of credentials. Human resource onboarding and exiting documents contain your access control policy. You need to review how accounts get made and include rules about where data gets transfered when employees leave. Your privacy policy may explain the rules abotu who can release data to the public or how guests can connect to your network. Vendor agreements need to explain how FCI or CUI gets shared, encrypted, and destroyed.

Focus first on including access control policies into company cuture. Then when creating your overall Access Control Policy document refer back to these company policies. This will allow you to handle the dynamic nature of a changing business world.

Do differences in Access Control Policies matter?

Access control policies fall into two types of buckets: discretionary polices based on on identity and non-discretionary polcies based on rules

{Company Name} uses {type of access control poicy}

Why can I not use Discretionary Based Access Control Policy in Government Contracting

The Federal Government considers DBAC, Discretionary Based Access Control, policies too weak for the contracting community. If you assign access at the user level you can not control who copies the file. Other users could also transfer ownership. Finally other users could mess with the data and change stuff like publication dates.

What makes Non-Discretionary Access Control safer?

With NDAC, or non-discretionary access control, policies the user does not get rights over the object. The user can not change who has control of an object. This means NDAC policies rquire an Administrator to control access policies.

Can I control who has access?

In mandatory access control (MAC) policies a central authority, or scrutinizer, controls access. You get to decide who gets garage door openers. If you receieve CUI, for example, you not change the CUI category nor the specified regulations that protect the CUI.

What types of Non-Discretionary can I use?

NDAC controls can use static or dynamic rules. Static policies, which do not change include multi-level security, attrribute based access control, and rule based access control.

  • Multilevel Security-creates rules at the object level and user level. You may for example have a category of users called engineer. You then can then have file categorized by their tools. Only people in the engineering category can access the "tools" files. Multi-level security also arises as we adopt more and more cloud or software as a service solutions. You need to match your access policy with the different configurations of all your vendors.
  • Attribute Based-Create controls, or constraints that limit access based on both policies and rules together. Say you wanted to ensure people took the weekend off, or more likely did not access a file at home. You could set it so only complaince officers can see the document but ut can nto be opened after 5:00 on a Friday.
  • Role Based-RBAC policies assign access by users. Must businesses use role based access control polcies. Mandatory access control (MAC) assign the roles.

Under Seperation of Duty, a dynamic set of rules, you do not assign enough priviledges to anyone to misue the system on the own. One child may hold the garage door opener, but only parents have keys to the car. Dynamic seperatation of duties can include two people having to have a safety deposit box keys. In terms of data two people maybe required to release data publicly or to execute commands on a system.

What Constraints can I use under Seperation of Duty policies?

You can use a simple, or static, separation of duty that says no member can have two exclusive roles. So if a user gets marked as "Teacher" in a school they could not also get assigned to the "Principal" role

In terms of dynamic separation of duty policies NIST identifies four types:

  • Simple Dynamic Separation of Duties- A user can have two assigned exlusive roles but never at the same time.
  • Object-based Seperation of Duties-A user can have two exclusive roles but not share an object, or file between the roles
  • Operational Seperation of Duties A user can have access to exclusive roles but only for specific parts of a project or their job, and not for all workflows.
  • Historical Seperation of Duties.A user can have exclusive roles assigned over an entire workflow but can only use a specific role for anyone object. So an employee may access a document as a project manager but not a compliance officer

Where does Access Control Policy Go Wrong?

Access Control Faults, places where constraints fail to protect datas on the boundaried translate to people and bad policy. People will always find Access Control faults. Your new marketing hire, may want to play their Spotify list and they know their way around a network.

These faults fall along the following lines:

  • Priviledge Leakage-I see what I shouldn't
  • Priviledge Blocking-The email spam filter blocked me from getting what I need
  • Inheritence Leakage-I shared a CUI file with someone and they gave the file out to those without a reason for lawful access
  • Priviledge Conflict-I need access to an object but because I am assigned to these two roles I can not open it
  • Multi-policies-So many different apps with so many different rules. How do I keep the access control policies straight?

What is an Access Control Model

Time to Call a Professional

Access control models present the security policies you enforce through your access control mechanisms, the procedures and controls that limi who sees what.

ACM create a visual of the theoretical limitations and boundaries of your access control policies. You will want to include and ACM in your system security plan. You also will want to work with a professional to ensure an accurate model

How do I Instituionalize Access Control Policies.

You can adapt the Enterprise Considerations NIST suggests as part of the system development life cycle

Establish the business use case If you want to add a new tool that requries additional access policies make sure you really need the tool or you are not paying for similar functionality somewherre else. Every new software and policy introduces new faults.

Consider the Bigger Picture. What does your larger network look like? What does the new tool do to your access control model? How do you report security for compliance? What documents have to change? What training do employees require?

Refine Business Processes. You will ignore this advice but make the required changes before signing the purchasing order or moving the pilot from staging to deployment. Demand a sandbox from vendors sequestered from your network. Storage is cheap. You have leverage. You also need to consider and integrate how roles and attributes are assigned to users and data.

Test for Interoperability. Look for third party interoperability certifications. Do not trust a logo on a website. Test the interoperability with your system.

Feasability and Usability Does the cost of the tool, both price and long term compliance, bring enough value? Doe the tool work? What happens in low signal areas? Do my threat awareness tools integrate?

Refine Access Control Model You need to map the flow of access control between your system and the new tool and understand how different user attributes match.