Weekly CMMC Q&A: 4.3.26
Failed to add items
Add to basket failed.
Add to Wish List failed.
Remove from Wish List failed.
Follow podcast failed
Unfollow podcast failed
-
Narrated by:
-
By:
Summary
Just because something sounds like it should be CUI doesn't make it so.
Unclassified data is only controlled if a law, regulation, or government-wide policy specifically says that data must be, well, controlled.
Sometimes there are dozens of "authorities" related to the same type of data so the CUI Registry summarizes and describes each category very broadly.
Even though those descriptions might talk about "vulnerability information" in general, the summary doesn't make all vulnerability information controlled.
You have to read the specific details of the laws and regulations to know what's what.
It's tedious, but it can save you a ton of time and money when you find out that your customer is just being lazy and only reading category descriptions.
We answer CUI questions on the hotline every week.
Come hang out.