HomeControl Library › 3.1.3
3.1 Access Control1 ptPOA&M-eligible

3.1.3 — Control the flow of CUI

Control the flow of CUI in accordance with approved authorizations.

Make sure CUI only moves to places it's allowed to go.

What it actually means

Information-flow control means CUI moves only along approved paths. In practice that means restricting where CUI can be sent or copied — blocking it from personal email, unapproved cloud storage, or USB — and enforcing those rules with boundary controls, DLP, or tenant restrictions. The point is that the movement of CUI is governed by policy, not left to chance.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes.

Calculate your SPRS score →

Connected requirements

← Back to the Control Library