Overview

Security Requirements for 03.01.22 Control Public Information

In accordance with laws, Executive Orders, directives, policies, regulations, or standards, the public is not authorized access to nonpublic information (e.g., information protected under the Privacy Act, CUI, and proprietary information). This requirement addresses systems that are controlled by the organization and accessible to the public, typically without identification or authentication. Individuals authorized to post CUI onto publicly accessible systems are designated. The content of information is reviewed prior to posting onto publicly accessible systems to ensure that nonpublic information is not included.

Evidence

  1. 03.01.22.a

    Individuals authorized to post or process information on publicly accessible systems are identified

  1. 03.01.22.b

    Procedures to ensure cui is not posted or processed on publicly accessible systems are identified

  1. 03.01.22.c

    A review process is in place prior to posting of any content to publicly accessible systems

  1. 03.01.22.d

    Content on publicly accessible systems is reviewed to ensure that it does not include cui

  1. 03.01.22.e

    Mechanisms are in place to remove and address improper posting of cui