CUI
Term · Cybersecurity · MLC-T-CYB-001131
1. A categorical designation that refers to unclassified information that does not meet the standards for National Security Classification under Executive Order 12958, as amended, but is (i) pertinent to the national interests of the United States or to the important interests of entities outside the federal government, and (ii) under law or policy requires protection from unauthorized disclosure, special handling safeguards, or prescribed limits on exchange or dissemination.
2. Information that law, regulation, or government-wide policy requires to have safeguarding or disseminating controls, excluding information that is classified under Executive Order 13526, Classified National Security Information, December 29, 2009, or any predecessor or successor order, or the Atomic Energy Act of 1954, as amended.
3. A categorical designation that refers to unclassified information that does not meet the standards for National Security Classification under Executive Order 12958, as amended, but is (i) pertinent to the national interests of the United States or to the important interests of entities outside the federal government, and (ii) under law or policy requires protection from unauthorized disclosure, special handling safeguards, or prescribed limits on exchange or dissemination. Henceforth, the designation CUI replaces Sensitive But Unclassified (SBU).
| Identifier | MLC-T-CYB-001131 |
|---|---|
| Field | Cybersecurity |
| Expansions | Controlled Unclassified Information; Controlled, Unclassified information |
| References | NIST SP 800-53 Rev. 4 [Superseded] from E.O. 13556; NIST SP 800-150 from NIST SP 800-171; NIST SP 800-53A Rev. 4 [Superseded]; NIST CSRC Glossary |
Record as JSON
{
"id": "MLC-T-CYB-001131",
"term": "CUI",
"field": "Cybersecurity",
"definition": "1. A categorical designation that refers to unclassified information that does not meet the standards for National Security Classification under Executive Order 12958, as amended, but is (i) pertinent to the national interests of the United States or to the important interests of entities outside the federal government, and (ii) under law or policy requires protection from unauthorized disclosure, special handling safeguards, or prescribed limits on exchange or dissemination.\n\n2. Information that law, regulation, or government-wide policy requires to have safeguarding or disseminating controls, excluding information that is classified under Executive Order 13526, Classified National Security Information, December 29, 2009, or any predecessor or successor order, or the Atomic Energy Act of 1954, as amended.\n\n3. A categorical designation that refers to unclassified information that does not meet the standards for National Security Classification under Executive Order 12958, as amended, but is (i) pertinent to the national interests of the United States or to the important interests of entities outside the federal government, and (ii) under law or policy requires protection from unauthorized disclosure, special handling safeguards, or prescribed limits on exchange or dissemination. Henceforth, the designation CUI replaces Sensitive But Unclassified (SBU).",
"expansions": [
"Controlled Unclassified Information",
"Controlled, Unclassified information"
],
"references": [
"NIST SP 800-53 Rev. 4 [Superseded] from E.O. 13556",
"NIST SP 800-150 from NIST SP 800-171",
"NIST SP 800-53A Rev. 4 [Superseded]",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/cui/"
}
Record 1,131 of 4,693 in Cybersecurity terminology (MLC-0102). Request the full dataset.