Control Statement
Elements processing, storing, or transmitting controlled unclassified information shall be identified on the terrain overlay, and the boundaries across which that information may move shall be declared.
Purpose. To make CUI movement declarable and therefore detectable, so that handling obligations attach to information rather than to systems.
Discussion
CUI is defined by the information, not by the system, which means it moves — into a spreadsheet, an email, a ticketing system, a contractor's environment — and each move takes the obligation with it. Marking elements is therefore only half the control; declaring permitted flows is what makes an undeclared movement a detectable event rather than an invisible one. The failure mode is a correctly marked estate with no declared flows, in which every element is compliant and the information is nonetheless everywhere.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Percentage of elements handling controlled information identified on the overlay
- Number of permitted flows crossing a boundary with no declared basis
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Consulted | Governance / RMF / ISSO: Responsible |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ConsultedPlatform and product owners
- ResponsibleGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- TM-1 Terrain Inventory and OverlayTerrain overlay
- TM-5 Connection and Denied-Path RegisterConnection register showing where information can move
- TM-4 Trust Zone DefinitionTrust zone boundaries
Produces
- TM-5 Connection and Denied-Path RegisterDenied paths required to enforce declared boundaries
- CG-5 Control Inheritance MappingControlled-information control inheritance
- LC-3 Supplier Access ConstraintConstraints on supplier access to controlled information
Activities
- L2Mark elements processing, storing or transmitting controlled unclassified information on the overlay.
- L2Declare the boundaries across which that information may move.
- L2Raise a finding for observed flows that were not declared.
- L3Reconcile marked elements against the agency's CUI categorization record.
- L3Declare flows by category where categories carry different handling requirements, rather than treating CUI as a single class.
- L3Extend declaration to flows leaving the authorization boundary — to contractors, to shared services, to other agencies — since those are where handling obligations most often lapse.
- L3Instrument the declared boundaries sufficiently that an undeclared flow can be observed rather than only prohibited.
- L4Measure observed flows against declared flows and trend the divergence.
- L4Measure the proportion of declared boundaries carrying detection, since an undeclared flow across an uninstrumented boundary is not a finding, it is an absence.
- L5Revise the declared flow set from observed legitimate movement, so the declaration reflects how the mission actually works rather than how it was designed to.
Measurement
Percentage of observed CUI flows that were declared.
Percentage of declared boundaries carrying detection.
Evidence and Assessment
Terrain overlay with marked elements and declared flows; the flow declaration itself; divergence findings.
Examine the marked elements against the categorization record; test observed flows against the declared set; test whether declared boundaries are instrumented.
Related Guidance
- MP-4
- SC-28
- AC-21
- PR.DS-01
- GV.OC-03
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Fed By
Nothing upstream — this control starts a chain.
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M2Defense in DepthEnsure no single failure is decisive.1 of 18 techniques — M2.09
Terrain It Is Named On
- T5DataControlled unclassified information handling sets what may be done with a large part of this layer’s contents, independent of its sensitivity to the agency.
Artifacts It Stands On
- producesPrivacy and controlled-information terrain registerWhere privacy holdings and controlled unclassified information sit, the authorities under which they are held, and the boundaries their handling requires — expressed as denied paths, not as policy statements.
- consumesCyber Terrain OverlayThe positional map of the estate: every element with a defensive layer, a defensive weight, a named accountable owner and its adjacencies. Not an asset inventory — an inventory enumerates, an overlay positions.
- consumesTrust zones and the connection registerThe zone boundaries and the permitted- and denied-path register — the graph reachability is actually walked over, reconciled against observed flow telemetry rather than against intended configuration.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsibleGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.
- ConsultedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- ConsultedPlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.
- InformedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- InformedHunt teamCounterattack. Works the hypotheses that Fuse raises.