How to Deploy CUI in Nonfederal Systems and Organizations
Summary
If you provide services or products to the federal government, it’s essential to understand what qualifies as CUI data so that you can comply with the way it should be stored, processed, transmitted, and protected. Moderate Impact systems account for nearly 80% of CSP applications that receive FedRAMP authorization and is most appropriate for CSOs where the loss of confidentiality, integrity, and availability would result in serious adverse effects on an agency’s operations, assets, or individuals. Low Impact is most appropriate for CSOs where the loss of confidentiality, integrity, and availability would result in limited adverse effects on an agency’s operations, assets, or individuals. The LI-SaaS Baseline accounts for Low-Impact SaaS applications that do not store personal identifiable information (PII) beyond that generally required for login capability (i.e. username, password, and email address). Data in the TechnoMile system can be classified as “Metadata” and “Documents.” Most of this Metadata information and documents are gathered from publicly available sources, including websites, FBO / SAM.gov solicitations, newswires, and press releases.