How should CUI be treated when stored or processed outside DoD networks?

Study for the DOD Instruction 5200.48 Controlled Unclassified Information (CUI) exam. Prepare with flashcards and multiple choice questions, each with detailed hints and explanations. Ensure success on your test day!

Multiple Choice

How should CUI be treated when stored or processed outside DoD networks?

Explanation:
CUI outside DoD networks must be protected with the same safeguards as inside. The reason is that the sensitivity of CUI requires consistent protections regardless of where it’s stored or processed. This means using encryption for data in transit and at rest, strong access controls that enforce least privilege and need-to-know, robust authentication, and ongoing monitoring with auditing and incident response capabilities. Reducing safeguards or relaxing access controls outside the network would create gaps for unauthorized access or disclosure, and storing CUI outside the DoD isn’t prohibited if those protections are maintained. Only encryption alone is not enough; a complete set of safeguards is required to keep the data secure.

CUI outside DoD networks must be protected with the same safeguards as inside. The reason is that the sensitivity of CUI requires consistent protections regardless of where it’s stored or processed. This means using encryption for data in transit and at rest, strong access controls that enforce least privilege and need-to-know, robust authentication, and ongoing monitoring with auditing and incident response capabilities. Reducing safeguards or relaxing access controls outside the network would create gaps for unauthorized access or disclosure, and storing CUI outside the DoD isn’t prohibited if those protections are maintained. Only encryption alone is not enough; a complete set of safeguards is required to keep the data secure.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy