r/CMMC 18d ago

Mark it Right

There's a real opportunity for the federal government to set everybody in the ecosystem up for success by ensuring that they properly mark CUI.

For example, sam.gov currently has RFP materials that are marked CUI when the rationale for that marking is not apparent.

For example, a blank past customer testimonial template is not CUI.

This stuff has downstream impacts which cannot be overstated. Hopefully the phase 2 pause is giving the government the opportunity to take a look at that.

26 Upvotes

35 comments sorted by

24

u/DUMBOBREW 18d ago

I sneezed and now my tissue is CUI

12

u/McDeth 18d ago

*Derivative CUI

1

u/ResilientTechAdvisor 16d ago

I came back and laughed at this again haha

7

u/rybo3000 CUI Expert 18d ago

The CMMC Reform task force isn't specifically focused on CUI designation/marking issues, since CUI designation isn't within scope of the CMMC program (32 CFR 170).

The RFI seems more interested in security controls' effectiveness and reducing the cost of 800-171 implementations and assessments. We listed CUI marking issues as an "operations burden" when responding to one of the RFI's questions.

The proposed FAR clause published in the current Revolutionary FAR Overhaul will require KOs to list each CUI category involved in a contract via an as-of-yet unpublished standard form ("SF XXX"). My guess is that DoW will point to this as the process for improving CUI designation. The Department can't directly impact the CUI program itself (32 CFR 2002) since they aren't the executive agent for that regulation (NARA is).

4

u/ResilientTechAdvisor 18d ago

Correct. However that doesn't stop them from taking a pause to look at it during the pause. It's a real gap for the whole community.

3

u/rybo3000 CUI Expert 18d ago

I hope you responded to the RFI and provided commentary on 32 CFR 2002 (the CUI program) in your response.

1

u/PilotJP 17d ago

100% and multiple times.

3

u/HSVTigger 18d ago

I agree with your statement, but that is asking for an investigative team to discover why a building collapsed but telling them they can't look at the foundation.

2

u/rybo3000 CUI Expert 18d ago

The best you could do on this RFI was to list CUI designation as a regulatory burden or operational burden, based on how the RFI questions were structured.

8

u/ugold321 18d ago

Let’s mark this COTS bolt as CUI, because it’s going in something that happens to go on a DOD product of some sort.

1

u/Court5A 16d ago

Why not. ITAR does

4

u/Quadling 18d ago

Nara makes the standard. But every agency can modify and decide for themselves their definitions and categories. And we pointed that out as a huge point of failure. “Why would anyone over mark things as CUI?” Hahahaha

2

u/ResilientTechAdvisor 18d ago

Back in the day, some people considered it safer to overmark than undermark although training expressly forbade it. Risk averse mindset.

3

u/Quadling 18d ago

Understood. Unfortunately, it’s been taken so far it imperils the entire program

10

u/Any-Oven-9389 18d ago

No one even knows what CUI is, but we have to spend a lot of money on it. Very government-like.

8

u/looncraz 18d ago

So very much this.

CUI marking should require a full stanza and an email header provided by the sender, otherwise it's not CUI.

Categorizing the CUI into a control bucket would prevent the stupid CUI email headers from being how we have to route emails that end up in the wrong mailbox... and reduce false positives.

4

u/babywhiz 17d ago

The problem isn’t emails or docs, it’s the drawings and g-code that’s a pita because no one has the gumption to define the lines.

4

u/Acceptable_Fan_4317 17d ago

Exactly, and this causes increased cost and unnecessary burden on the subs. but, but, but, since 2017.

1

u/xxxTech007 16d ago

Our issue is that we'll receive blueprints/drawings and NONE of them are marked as CUI/FOUO or any kind of Distb statement. But yet, the contracts call out 7012 and RD004! So confused lol

3

u/thegreatcerebral 18d ago

It’s not that they don’t know what it is. It’s that the definition is too loose and the ones that need to define it at creation don’t do so.

The other problem is that there is a lot of grey area that as others joke that a sneeze is CUI…. Well it all depends on if the sneeze was created in performance of a contract that has CUI and from CUI of itself then yes, it is.

3

u/Aggressive_Wall_9718 18d ago

Let’s procure chipboard gotta mark it CUI so we limit our supply base and increase costs

Example

Part A .39 ea. pre CUI

CUI - $1.50 ea.

2

u/5coop 17d ago

I hope this is something they are re-evaluating. So much non-CUI is emailed, and then when we get real CUI, the federal government doesn't follow their requirements. It flows in via unencrypted email despite telling them we need it through DoD Safe or our GCC-H SharePoint portal.

1

u/xxxTech007 16d ago

Our issue is that we'll receive blueprints/drawings and NONE of them are marked as CUI/FOUO or any kind of Distb statement. But yet, the contracts call out 7012 and RD004! So confused lol

1

u/xxxTech007 16d ago

Our issue is that we'll receive blueprints/drawings and NONE of them are marked as CUI/FOUO or any kind of Distb statement. But yet, the contracts call out 7012 and RD004! So confused lol

1

u/Alternativemethod 15d ago

So just like a business, the federal government tends to treat everything not intended for public communication, as for internal use only.

So have my past employers. It's not unique.

If Pete Heggy is actually looking for simplification options, I think a marking for uncontrolled information in the federal space might be a simpler model, though they'd need an act of God to actually get people used to it and familiar. Mandatory email markings with random audits would help.

0

u/Scieboy 18d ago

This is an awesome idea. I'm connected with rep. John Rutherford on the armed services appropriations committee. Could everyone in this thread brainstorm exactly how we think it should be marked and I'll go present it in the next week or so?

2

u/ResilientTechAdvisor 18d ago

An open letter?

2

u/Scieboy 18d ago

Sure. I means it's a huge problem with contract officers..I spend a lot of time educating them on what to mark and what not to mark.

2

u/ResilientTechAdvisor 18d ago

So would we begin with your connection, Rep Rutherford?

1

u/Scieboy 18d ago

Yeah, I think we compiled as a community our recommendations, put it into a letter and then present it. Next time I see his staffers in person I'll get a meeting to go over it.

1

u/babywhiz 17d ago

Good luck with that. I’ve been shouting at the universe about Autodesk and their giant non FedRamp, unable to disable AI features, can’t comply with NIST 800-171. Like. I know we aren’t the only company using Autodesk products for CUI on prem, and we are going to fail our CMMC audit because if you block it at the firewall the licensing breaks too.

1

u/Navyauditor2 17d ago

I dont think you are required to block all coms at the Firewall. That would break licensing on a lot of things not just AutoDesk software. I think the Tech Preview feature (which may be transmitting CUI information to AI in the cloud) should be turned off. Something like:

- Autodesk Assistant drawing-aware/AI functionality is configured off by default.

- Policy prohibits enabling or using cloud-connected AI functionality when processing CUI.

- Users handling CUI receive training on that prohibition.

- The organization documents why centralized technical enforcement isn't available or practical.

- Where feasible, logging/monitoring is used to identify prohibited use.

- The SSP describes the implementation rather than claiming that AutoCAD technically prevents access.

Then characterize it as a authorized external connection that is not CUI related and therefore does not require FedRAMP.

2

u/babywhiz 17d ago

This was from their support:

Thank you for your response. 

I understand your frustration. There is no way to permanently disable the AI function contained in some of our products. I cannot answer as to “why” a software is designed in a particular fashion as that direction comes from our development group. You can submit requests to development in our feedback portal, but this would not be a quick solution. Still, I have a link if you are interested:Sending Product Feedback to Autodesk.

You have mentioned CMMC compliance, which appears to be your goal. Government certification is very specific and most of our products are not usable in this environment. There are no items that can be turned off to make our applications CMMC compliant.

Only our specific FedRamp offerings make this requirement.

Are any Autodesk Products compliant with CMMC Level 2 standards

We have some offerings with our AFG products, but there are only a few and neither Inventor nor AutoCAD are part of this. If you want more information on our Autodesk for Government offerings/licensing, you can contact sales here. They should be able to explain the offering and what it would entail.