When non-federal systems handle CUI under a contract, which security guideline is referenced?

Prepare for the DOD Instruction 5200.48 Controlled Unclassified Information (CUI) Exam. Boost your knowledge with our engaging multiple-choice questions, hints, and explanations. Ace the test and enhance your understanding of CUI! Get ready now!

Multiple Choice

When non-federal systems handle CUI under a contract, which security guideline is referenced?

Explanation:
Handling CUI on non-federal systems that are under contract with a federal agency uses the NIST guideline specifically tailored for non-federal environments. NIST SP 800-171 provides the security requirements to protect CUI in information systems and organizations outside the federal civilian and defense spheres, and it is the standard invoked when a contract requires safeguarding CUI. While NIST SP 800-53 serves as the broader set of security controls for federal information systems, it isn’t the default baseline for non-federal contractors unless a contract explicitly calls for it. ISO/IEC 27001 and CIS Controls are important security frameworks, but they are not the contract-referenced standard for CUI protection in this context. Therefore, when the contract establishes it, NIST SP 800-171 is the guideline referenced.

Handling CUI on non-federal systems that are under contract with a federal agency uses the NIST guideline specifically tailored for non-federal environments. NIST SP 800-171 provides the security requirements to protect CUI in information systems and organizations outside the federal civilian and defense spheres, and it is the standard invoked when a contract requires safeguarding CUI. While NIST SP 800-53 serves as the broader set of security controls for federal information systems, it isn’t the default baseline for non-federal contractors unless a contract explicitly calls for it. ISO/IEC 27001 and CIS Controls are important security frameworks, but they are not the contract-referenced standard for CUI protection in this context. Therefore, when the contract establishes it, NIST SP 800-171 is the guideline referenced.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy