Make sure no CUI ends up on your public website or public-facing systems.
What it actually means
Control CUI posted or processed on publicly accessible systems — make sure CUI never gets published to your public website or other public systems. Designate who can post public content and review it to ensure no CUI slips out. This is also a Level 1 (FCI) requirement.
Pass or fail — an assessor needs a "yes" to each
- Is there a process ensuring CUI is never posted to publicly accessible systems?
- Are authorized individuals designated to manage public content?
What to have ready
- Policy and review process for public content
- List of authorized publishers
Where teams trip up
- No review before posting to the public site
- Anyone able to publish public content
Also a Level 1 (FCI) requirement.
See where this control puts your score
Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.
Calculate your SPRS score →Draft your SSP language →Connected requirements
More in Access Control (3.1)
3.1.1 — Limit who (and what) can get in3.1.2 — Limit what users can do3.1.3 — Control the flow of CUI3.1.4 — Separate duties3.1.5 — Least privilege (especially for admins)3.1.6 — Use non-privileged accounts for routine work3.1.7 — Restrict and log privileged functions3.1.8 — Limit failed logons3.1.9 — Show privacy and security notices3.1.10 — Lock idle screens3.1.11 — End sessions automatically3.1.12 — Monitor and control remote access3.1.13 — Encrypt remote access sessions3.1.14 — Funnel remote access through managed points3.1.15 — Authorize privileged remote actions3.1.16 — Authorize wireless access first3.1.17 — Protect wireless with authentication + encryption3.1.18 — Control mobile device connections3.1.19 — Encrypt CUI on mobile devices3.1.20 — Control connections to external systems3.1.21 — Limit portable storage on external systems