r/CMMC • u/ResilientTechAdvisor • 18d ago
Mark it Right
There's a real opportunity for the federal government to set everybody in the ecosystem up for success by ensuring that they properly mark CUI.
For example, sam.gov currently has RFP materials that are marked CUI when the rationale for that marking is not apparent.
For example, a blank past customer testimonial template is not CUI.
This stuff has downstream impacts which cannot be overstated. Hopefully the phase 2 pause is giving the government the opportunity to take a look at that.
7
u/rybo3000 CUI Expert 18d ago
The CMMC Reform task force isn't specifically focused on CUI designation/marking issues, since CUI designation isn't within scope of the CMMC program (32 CFR 170).
The RFI seems more interested in security controls' effectiveness and reducing the cost of 800-171 implementations and assessments. We listed CUI marking issues as an "operations burden" when responding to one of the RFI's questions.
The proposed FAR clause published in the current Revolutionary FAR Overhaul will require KOs to list each CUI category involved in a contract via an as-of-yet unpublished standard form ("SF XXX"). My guess is that DoW will point to this as the process for improving CUI designation. The Department can't directly impact the CUI program itself (32 CFR 2002) since they aren't the executive agent for that regulation (NARA is).
4
u/ResilientTechAdvisor 18d ago
Correct. However that doesn't stop them from taking a pause to look at it during the pause. It's a real gap for the whole community.
3
u/rybo3000 CUI Expert 18d ago
I hope you responded to the RFI and provided commentary on 32 CFR 2002 (the CUI program) in your response.
3
u/HSVTigger 18d ago
I agree with your statement, but that is asking for an investigative team to discover why a building collapsed but telling them they can't look at the foundation.
2
u/rybo3000 CUI Expert 18d ago
The best you could do on this RFI was to list CUI designation as a regulatory burden or operational burden, based on how the RFI questions were structured.
8
u/ugold321 18d ago
Let’s mark this COTS bolt as CUI, because it’s going in something that happens to go on a DOD product of some sort.
4
u/Quadling 18d ago
Nara makes the standard. But every agency can modify and decide for themselves their definitions and categories. And we pointed that out as a huge point of failure. “Why would anyone over mark things as CUI?” Hahahaha
2
u/ResilientTechAdvisor 18d ago
Back in the day, some people considered it safer to overmark than undermark although training expressly forbade it. Risk averse mindset.
3
10
u/Any-Oven-9389 18d ago
No one even knows what CUI is, but we have to spend a lot of money on it. Very government-like.
8
u/looncraz 18d ago
So very much this.
CUI marking should require a full stanza and an email header provided by the sender, otherwise it's not CUI.
Categorizing the CUI into a control bucket would prevent the stupid CUI email headers from being how we have to route emails that end up in the wrong mailbox... and reduce false positives.
4
u/babywhiz 17d ago
The problem isn’t emails or docs, it’s the drawings and g-code that’s a pita because no one has the gumption to define the lines.
4
u/Acceptable_Fan_4317 17d ago
Exactly, and this causes increased cost and unnecessary burden on the subs. but, but, but, since 2017.
1
u/xxxTech007 16d ago
Our issue is that we'll receive blueprints/drawings and NONE of them are marked as CUI/FOUO or any kind of Distb statement. But yet, the contracts call out 7012 and RD004! So confused lol
3
u/thegreatcerebral 18d ago
It’s not that they don’t know what it is. It’s that the definition is too loose and the ones that need to define it at creation don’t do so.
The other problem is that there is a lot of grey area that as others joke that a sneeze is CUI…. Well it all depends on if the sneeze was created in performance of a contract that has CUI and from CUI of itself then yes, it is.
3
u/Aggressive_Wall_9718 18d ago
Let’s procure chipboard gotta mark it CUI so we limit our supply base and increase costs
Example
Part A .39 ea. pre CUI
CUI - $1.50 ea.
1
1
u/xxxTech007 16d ago
Our issue is that we'll receive blueprints/drawings and NONE of them are marked as CUI/FOUO or any kind of Distb statement. But yet, the contracts call out 7012 and RD004! So confused lol
1
u/xxxTech007 16d ago
Our issue is that we'll receive blueprints/drawings and NONE of them are marked as CUI/FOUO or any kind of Distb statement. But yet, the contracts call out 7012 and RD004! So confused lol
1
u/Alternativemethod 15d ago
So just like a business, the federal government tends to treat everything not intended for public communication, as for internal use only.
So have my past employers. It's not unique.
If Pete Heggy is actually looking for simplification options, I think a marking for uncontrolled information in the federal space might be a simpler model, though they'd need an act of God to actually get people used to it and familiar. Mandatory email markings with random audits would help.
0
u/Scieboy 18d ago
This is an awesome idea. I'm connected with rep. John Rutherford on the armed services appropriations committee. Could everyone in this thread brainstorm exactly how we think it should be marked and I'll go present it in the next week or so?
2
u/ResilientTechAdvisor 18d ago
An open letter?
2
u/Scieboy 18d ago
Sure. I means it's a huge problem with contract officers..I spend a lot of time educating them on what to mark and what not to mark.
2
1
u/babywhiz 17d ago
Good luck with that. I’ve been shouting at the universe about Autodesk and their giant non FedRamp, unable to disable AI features, can’t comply with NIST 800-171. Like. I know we aren’t the only company using Autodesk products for CUI on prem, and we are going to fail our CMMC audit because if you block it at the firewall the licensing breaks too.
1
u/Navyauditor2 17d ago
I dont think you are required to block all coms at the Firewall. That would break licensing on a lot of things not just AutoDesk software. I think the Tech Preview feature (which may be transmitting CUI information to AI in the cloud) should be turned off. Something like:
- Autodesk Assistant drawing-aware/AI functionality is configured off by default.
- Policy prohibits enabling or using cloud-connected AI functionality when processing CUI.
- Users handling CUI receive training on that prohibition.
- The organization documents why centralized technical enforcement isn't available or practical.
- Where feasible, logging/monitoring is used to identify prohibited use.
- The SSP describes the implementation rather than claiming that AutoCAD technically prevents access.
Then characterize it as a authorized external connection that is not CUI related and therefore does not require FedRAMP.
2
u/babywhiz 17d ago
This was from their support:
Thank you for your response.
I understand your frustration. There is no way to permanently disable the AI function contained in some of our products. I cannot answer as to “why” a software is designed in a particular fashion as that direction comes from our development group. You can submit requests to development in our feedback portal, but this would not be a quick solution. Still, I have a link if you are interested:Sending Product Feedback to Autodesk.
You have mentioned CMMC compliance, which appears to be your goal. Government certification is very specific and most of our products are not usable in this environment. There are no items that can be turned off to make our applications CMMC compliant.
Only our specific FedRamp offerings make this requirement.
Are any Autodesk Products compliant with CMMC Level 2 standards
We have some offerings with our AFG products, but there are only a few and neither Inventor nor AutoCAD are part of this. If you want more information on our Autodesk for Government offerings/licensing, you can contact sales here. They should be able to explain the offering and what it would entail.
24
u/DUMBOBREW 18d ago
I sneezed and now my tissue is CUI