2002.4 - Definitions Flashcards

1
Q

Any “executive agency”, the USPS, and any other independent entity within the executive branch that designates or handles CUI.

A

Agency

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

An Agency is any “(a)_________ ______”, the (b)____, and any other (c)___________ ______ within the executive branch that designates or handles CUI.

A

(a) “executive agency”

(b) USPS

(c) independent entity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Policies the agency enacts to implement the CUI Program within the agency, in accordance with the EO 13556, 32 CFR Part 2002, and the CUI Registry and approved by the CUI EA.

A

Agency CUI policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Any vehicle that sets out specific CUI handling requirements for contractors and other information-sharing partners when the arrangement with the other party involves CUI.

A

Agreements and arrangements

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

An individual, agency, organization, or group of users that is permitted to designate or handle CUI IAW 32 CFR Part 2002.

A

Authorized holder

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Any area or space that an authorized holder deems to have adequate physical or procedural controls to protect CUI from unauthorized access or disclosure.

A

Controlled envrionment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

A general term that indicates the safeguarding and disseminating requirements associated with CUI Basic and CUI Specified.

A

Control level

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

This is information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation, or policy requires or permits an agency to handle using safeguarding or dissemination controls.

A

Controlled Unclassified Information (CUI)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Controlled Unclassified Information (CUI) is information the (a)__________ _______ __ _________, or that an (b)______ _______ __ _________ ___ __ __ ______ __ __ __________ that a law, regulation, or policy requires or permits an agency to handle using safeguarding or dissemination controls.

A

(a) Government creates or possesses

(b) entity creates or possesses for or on behalf of the Government

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Controlled Unclassified Information (CUI) is information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that ____, __________, or ________ _______ __ ______ an agency to handle using safeguarding or dissemination controls.

A

Laws, regulations, or policies require or permit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

CUI includes classified information? T/F

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

CUI excludes information a non-executive branch entity possesses and maintains in its own systems that did not come from, or was not created or possessed by or for, an executive branch agency or an entity acting for an agency? T/F

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Requiring or permitting agencies to control or protect the information but providing no specific controls makes the information ___ _____?

A

CUI Basic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

CUI Basic requires or permits agencies to control or protect information, providing __ ________ controls.

A

No specific

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Requiring or permitting agencies to control or protect the information and providing specific controls for doing so makes the information ___ __________.

A

CUI Specified

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

CUI Specified requires or permits agencies to control or protect information and provides ________ ________ for doing so.

A

Specific controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Requiring or permitting agencies to control the information and specifying only some of those controls, which makes the information (a)___ __________, but with (b)___ _____ controls where the authority does not specify.

A

(a) CUI Specified

(b) CUI Basic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

________ are safeguarding or dissemination controls that a law, regulation, or policy requires or permits agencies to use when handling CUI.

A

Controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

CUI Basic is the subset of CUI for which the authorizing law, regulation, or policy ____ ___ ___ ________ __________ __ _____________ ________.

A

Does not set out specific handling or dissemination controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Agencies handle CUI Basic according to the uniform set of controls set forth in (a)__ __ ____ and the (b)___ ________.

A

(a) 32 CFR Part 2002

(b) CUI Registry

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

CUI Basic controls apply whenever ___ __________ ones do not cover the involved CUI.

A

CUI Specified

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

___ __________ are those types of information for which laws, regulations, or policies require or permit agencies to exercise safeguarding or dissemination controls, and which the CUI EA has approved and listed in the CUI Registry.

A

CUI categories

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

CUI categories are those types of information for which laws, regulations, or policies require or permit agencies to exercise safeguarding or dissemination controls, and which the (a)___ __ has approved and listed in the (b)___ ________.

A

(a) CUI EA

(b) CUI Registry

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

The markings approved by the CUI EA for the categories and subcategories listed in the CUI Registry.

A

CUI category or subcategory markings

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

___ _________ _____ (__) is the National Archives and Records Administration (NARA), which implements the executive branch-wide CUI Program and oversees Federal agency actions to comply with the EO 13356.

A

CUI Executive Agent (EA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

________ ________ ___ _______ ______________ (____) is the CUI Executive Agent (EA) which implements the executive branch-wide CUI Program and oversees Federal agency actions to comply with the EO 13556.

A

National Archives and Records Administration (NARA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

NARA has delegated CUI authority to the ________ __ ___ ___________ ________ _________ _______ (ISOO).

A

Director of the Information Security Oversight Office (ISOO)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

___ _______ is the executive branch-wide program to standardize CUI handling by all Federal agencies.

A

CUI Program

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

___ _______ _______ is an agency official, designated by the agency head or CUI Senior Agency Official (SAO), to serve as the official representative to the CUI EA on the agency’s day-to-day CUI Program operations, both within the agency and in interagency contexts

A

CUI Program manager

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

___ ________ is the online repository for all information, guidance, policy, and requirements on handling CUI, including everything issued by the CUI EA other than this part.

A

CUI Registry

31
Q

The CUI Registry identifies all approved CUI __________ ___ _____________, provides general descriptions for each, identifies the basis for controls, establishes markings, and includes guidance on handling procedures.

A

Categories and subcategories

32
Q

___ ______ ______ ________ (___) is a senior official designated in writing by an agency head and responsible to that agency head for implementation of the CUI Program within that agency. The ___ ______ ______ ________ (___) is the primary point of contact for official correspondence, accountability reporting, and other matters of record between the agency and the CUI EA.

A

CUI senior agency official (SAO)

33
Q

___ _________ is the subset of CUI in which the authorizing law, regulation, or Government-wide policy contains specific handling controls that it requires or permits agencies to use that differ from those for CUI Basic.

A

CUI Specified

34
Q

The CUI Registry indicates which ____, ___________, and ________ include such specific requirements.

A

Laws, regulations, and policies

35
Q

CUI Specified controls may be more (a)_________ than, or may simply (b)______ from, those required by CUI Basic; the distinction is that the underlying authority spells out specific controls for CUI Specified information and does not for CUI Basic information

A

(a) stringent

(b) differ

36
Q

_____________ occurs when an authorized holder, consistent with 32 CFR Part 2002 and the CUI Registry, removes safeguarding or dissemination controls from CUI that no longer requires such controls. _________ may occur automatically or through agency action.

A

(a) Decontrolling

(b) Decontrol

37
Q

___________ ___ occurs when an authorized holder, consistent with 32 CFR Part 2002 and the CUI Registry, determines that a specific item of information falls into a CUI category or subcategory.

A

Designating CUI

38
Q

The authorized holder who designates the CUI must ____ __________ _____ __ __ _____________ CUI status in accordance with 32 CFR Part 2002.

A

Make recipients aware of the information’s CUI status

39
Q

___________ ______ is the executive branch agency that designates or approves the designation of a specific item of information as CUI.

A

Designating agency

40
Q

_____________ occurs when authorized holders provide access, transmit, or transfer CUI to other authorized holders through any means, whether internal or external to an agency.

A

Disseminating

41
Q

Any tangible thing which constitutes or contains information, and means the original and any copies (whether different from the originals because of notes made on such copies or otherwise) of all writings of every kind and description over which an agency has authority is a ________.

A

Document

42
Q

Documents are any tangible thing which constitutes or contains information? T/F

A

True

43
Q

_______ ___________ ______ is an information system used or operated by an agency or by a contractor of an agency or other organization on behalf of an agency.

A

Federal information system

44
Q

Federal information systems exclude contractor or other organization information systems? T/F

A

False

45
Q

_______ _______ is a foreign government, an international organization of governments or any element thereof, an international or foreign public or judicial body, or an international or foreign private or non-governmental organization.

A

Foreign entity

46
Q

________ __________ ____ (___) is a type of information classified under the Atomic Energy Act, and defined in 10 CFR Part 1045, Nuclear Classification and Declassification.

A

Formerly Restricted Data (FRD)

47
Q

Handling is ___ ___ __ ___, including but not limited to marking, safeguarding, transporting, disseminating, re-using, and disposing of the information.

A

Any use of CUI

48
Q

______ __________ _______ is any activity, mission, function, operation, or endeavor that the U.S. Government authorizes or recognizes as within the scope of its legal authorities or the legal authorities of non-executive branch entities (such as state and local law enforcement).

A

Lawful Government purpose

49
Q

______ ________ is unclassified information that an agency marked as restricted from access or dissemination in some way, or otherwise controlled, prior to the CUI Program.

A

Legacy material

50
Q

_______ _____________ ______ is any CUI EA-approved control that agencies may use to limit or specify CUI dissemination.

A

Limited dissemination control

51
Q

______ __ ___ occurs when someone uses CUI in a manner not in accordance with the policy contained in EO13556, this part, the CUI Registry, agency CUI policy, or the applicable laws, regulations, and Government-wide policies that govern the affected information.

A

Misuse of CUI

52
Q

Misuse of CUI may include (a)___________ __________ or _____________ ______ in safeguarding or disseminating CUI.

A

(a) Intentional violations

(b) Unintentional errors

53
Q

Misuse of CUI may also include designating or marking information as CUI when __ ____ ___ _______ __ ___.

A

It does not qualify as CUI.

54
Q

________ ________ _______ is a special type of information system (including telecommunications systems) whose function, operation, or use is defined in National Security Directive 42 and 44 U.S.C. 3542(b)(2).

A

National Security System

55
Q

_____________ ______ ______ is a person or organization established, operated, and controlled by individual(s) acting outside the scope of any official capacity of the executive branch of the Federal Government.

A

Non-executive branch entity

56
Q

Non-executive branch entity includes foreign entities as defined in 32 CFR Part 2002? T/F

A

False

57
Q

Non-executive branch entity includes individuals or organizations when they receive CUI information pursuant to federal disclosure laws, including the Freedom of Information Act (FOIA) and the Privacy Act of 1974? T/F

A

False

58
Q

__ ______ __ __ ______ occurs when a non-executive branch entity uses or operates an information system or maintains or collects information for the purpose of processing, storing, or transmitting Federal information, and those activities are not incidental to providing a service or product to the Government.

A

On behalf of an agency

59
Q

_____ is Executive Order 13556, Controlled Unclassified Information, November 4, 2010 (3 CFR, 2011 Comp., p. 267), or any successor order.

A

Order

60
Q

The founding EO for the CUI Program is __ _____.

A

EO 13556

61
Q

_______ is ordinarily a section within a document, and may include subjects, titles, graphics, tables, charts, bullet statements, sub-paragraphs, bullets points, or other sections.

A

Portion

62
Q

__________ includes all controls an agency applies or must apply when handling information that qualifies as CUI.

A

Protection

63
Q

______ _______ occurs when the agency that originally designated particular information as CUI makes that information available to the public through the agency’s official ______ _______ processes

A

Public release

64
Q

Disseminating CUI to non-executive branch entities as authorized does not constitute public release? T/F

A

True

65
Q

Even though an agency may disclose some CUI to a member of the public pursuant to the Privact Act if 1974 or a FOIA request, the Government must still control that CUI unless the agency publicly releases it through its official public release processes? T/F

A

True

66
Q

_______ include Presidential papers or such items created or maintained by a Government contractor, licensee, certificate holder, or grantee that are subject to the sponsoring agency’s control under the terms of the entity’s agreement with the agency.

A

Records

67
Q

If a law, regulation, or policy (a)________ that agencies exercise safeguarding or dissemination controls over certain information, or specifically (b)_______ agencies the discretion to do so, then that information qualifies as CUI.

A

(a) requires

(b) permits

68
Q

__________ ____ (__) is a type of information classified under the Atomic Energy Act, defined in 10 CFR Part 1045, Nuclear Classification and Declassification.

A

Restricted Data (RD)

69
Q

______ means incorporating, restating, or paraphrasing information from its originally designated form into a newly created document.

A

Re-use

70
Q

________________ is an agency’s internally managed review and evaluation of its activities to implement the CUI Program.

A

Self-inspection

71
Q

________________ is an agency’s internally managed review and evaluation of its activities to implement the CUI Program.

A

Self-inspection

72
Q

Unauthorized disclosure occurs when an authorized holder of CUI _____________ __ _______________ _______ CUI without a lawful Government purpose, in violation of restrictions imposed by safeguarding or dissemination controls, or contrary to limited dissemination controls

A

Intentionally or unintentionally discloses

73
Q

____________ ____________ ___________ is information that neither the EO 13556 nor the authorities governing classified information cover as protected.

A

Uncontrolled unclassified information

74
Q

_______ ______ are documents or materials, regardless of form, that an agency or user expects to revise prior to creating a finished product.

A

Working papers