Overview

Security Requirements for 03.01.22 Control Public Information

In accordance with laws, Executive Orders, directives, policies, regulations, or standards, the public is not authorized access to nonpublic information (e.g., information protected under the Privacy Act, CUI, and proprietary information). This requirement addresses systems that are controlled by the organization and accessible to the public, typically without identification or authentication. Individuals authorized to post CUI onto publicly accessible systems are designated. The content of information is reviewed prior to posting onto publicly accessible systems to ensure that nonpublic information is not included.

Assessment GuidanceExamine 0/10

How an assessor determines this requirement is met. Source: CMMC Assessment Guide – Level 2, Version 2.13 (NIST SP 800-171 Rev. 2).

Discussion

Only government officials can be authorized to release CUI to the public. Do not allow CUI to become public – always safeguard the confidentiality of CUI by controlling the posting of CUI on company-controlled websites or public forums, and the exposure of CUI in public presentations or on public displays. It is important to know which users are allowed to publish information on publicly accessible systems, like your company website, and implement a review process before posting such information. If CUI is discovered on a publicly accessible system, procedures should be in place to remove that information and alert the appropriate parties.

Examples

  1. Example 1

    Your company decides to start issuing press releases about its projects in an effort to reach more potential customers. Your company receives CUI from the government as part of its DoD contract. Because you recognize the need to manage controlled information, including CUI, you meet with the employees who write the releases and post information to establish a review process [c]. It is decided that you will review press releases for CUI before posting it on the company website [a, d]. Only certain employees will be authorized to post to the website [a].

Assessment Methods

Examine
The process of reviewing, inspecting, observing, studying, or analyzing assessment objects (e.g., policies, procedures, plans, system designs, mechanisms) to facilitate understanding, achieve clarification, or obtain evidence.Example: An assessor reads the access control policy and inspects system configuration settings to confirm they match.

Not all of the evidence listed is required to meet this requirement — check the items your organization has collected.

Interview
The process of holding discussions with individuals or groups within an organization to facilitate understanding, achieve clarification, or identify the location of evidence.Example: An assessor asks a system administrator to describe how user accounts are approved, reviewed, and disabled.
  • Personnel with responsibilities for managing publicly accessible information posted on organizational systems
  • Personnel with information security responsibilities
Test
The process of exercising assessment objects (e.g., activities, mechanisms) under specified conditions to compare actual behavior with expected behavior.Example: An assessor attempts to sign in with a disabled account to confirm that access is denied.
  • Mechanisms implementing management of publicly accessible content

Potential Assessment Considerations

  • Does information on externally facing systems (i.e., publicly accessible) have a documented approval chain for public release [c]?

Key References

NIST SP 800-171 Rev. 2 3.1.22FAR Clause 52.204-21 b.1.iv

Evidence

  1. 03.01.22.a

    Individuals authorized to post or process information on publicly accessible systems are identified

  1. 03.01.22.b

    Procedures to ensure cui is not posted or processed on publicly accessible systems are identified

  1. 03.01.22.c

    A review process is in place prior to posting of any content to publicly accessible systems

  1. 03.01.22.d

    Content on publicly accessible systems is reviewed to ensure that it does not include cui

  1. 03.01.22.e

    Mechanisms are in place to remove and address improper posting of cui