3.4 Data Handling and Marking Requirements

Key Takeaways

  • Data handling and marking requirements are identified during control selection because markings must be applied at creation and persist for the life of the data.
  • The NARA CUI Registry under 32 CFR Part 2002 replaced the legacy agency-specific markings such as FOUO and SBU with a single government-wide category scheme.
  • CUI Basic follows the uniform handling rules of the CUI program, while CUI Specified follows the additional handling controls imposed by its underlying authority.
  • Marking obligations extend to derivative products, backups, exports, and every interconnection, which is why they are contractual requirements for external parties.
  • Access controls enforce who may reach data; markings communicate how it must be handled once lawfully reached, and the two are not interchangeable.
Last updated: August 2026

Data Handling and Marking Requirements

Within the control-selection task, the CGRC blueprint calls out one requirement explicitly: "Specific data handling/marking requirements identified." It sits in Domain 3 rather than in implementation or disposal for a structural reason — markings have to be applied when information is created and must survive every copy, export, and transfer thereafter. Deciding them late means unmarked copies already exist.


1. Marking and Access Control Solve Different Problems

These are routinely conflated, and the exam exploits it.

  • Access control answers "who is permitted to reach this data?" It is enforced by the system.
  • Marking answers "once someone lawfully has this data, how must they handle it?" It is enforced by the human or downstream process that reads the label.

A cleared analyst may be fully authorized to open a document — access control is satisfied. The marking is what tells them the document may not be emailed to a personal account, printed on an uncontrolled printer, or carried outside the facility. Remove markings and the authorized user has no way to know their obligations. This is why marking controls remain necessary in systems with flawless access control.


2. The CUI Program

Before 2010, agencies used dozens of incompatible labels — FOUO (For Official Use Only), SBU (Sensitive But Unclassified), LES (Law Enforcement Sensitive) — with no shared definitions, which made inter-agency sharing unreliable. Executive Order 13556 created the Controlled Unclassified Information (CUI) program to replace them with one government-wide scheme, implemented by 32 CFR Part 2002 and administered by the National Archives and Records Administration (NARA), which publishes the authoritative CUI Registry.

The Registry organizes CUI into categories grouped into organizational index groupings, each traceable to a law, regulation, or government-wide policy (LRGWP). This traceability requirement is the program's core discipline: information cannot be designated CUI simply because someone considers it sensitive. There must be a citable authority. Exam items describing a manager who marks a document CUI because it is "internal and embarrassing" are describing a misdesignation, not a control.

CUI Basic versus CUI Specified

CUI BasicCUI Specified
Handling rulesThe uniform baseline handling controls of the CUI programAdditional or different controls set by the underlying authority
Source of requirements32 CFR Part 2002The specific law or regulation that created the category
MarkingCUI bannerCUI//SP-<category> — the SP marker signals Specified
ExampleGeneral procurement-sensitive informationCategories whose statutes impose specific dissemination limits

The practical rule: for Basic, apply the standard CUI handling controls. For Specified, you must read the underlying authority, because it may impose stricter destruction, dissemination, or access requirements than the CUI baseline. Treating Specified as Basic is a compliance failure.

Marking Mechanics

A CUI banner marking appears at the top and bottom of each page and includes the CUI control marking, category markings where required, and any limited dissemination control (LDC) such as NOFORN or FED ONLY, separated by double forward slashes. The designating agency is identified so recipients know whom to contact about handling questions. Portion marking — labelling individual paragraphs — is permitted and is encouraged when it helps recipients extract releasable content without over-restricting the whole document.

[!IMPORTANT] Derivative products inherit markings. A briefing slide built from a CUI report, a spreadsheet exported from a CUI database, and a backup tape containing CUI records are all CUI and must be marked accordingly. The most common real-world failure is an analytics or reporting layer that reads from a marked source and emits unmarked outputs.


3. Implementing Handling and Marking in SP 800-53

ControlPurpose
MP-3 (Media Marking)Mark physical and digital media to identify handling caveats and distribution limits
MP-4 / MP-5 (Media Storage / Transport)Store and transport controlled media with defined protections and accountability
AC-16 (Security and Privacy Attributes)Bind attributes (labels) to information as it is stored, processed, and transmitted
AC-21 (Information Sharing)Ensure sharing decisions are authorized and consistent with dissemination restrictions
PT-2 / PT-3Establish the authority and specific purposes for processing PII
SI-12 (Information Management and Retention)Handle and retain information per applicable requirements
MP-6 (Media Sanitization)Apply the sanitization method appropriate to the media and the marking

AC-16 is the control that makes automated enforcement possible. Once security and privacy attributes are bound to data as machine-readable metadata rather than merely painted onto a rendered page, downstream systems — data loss prevention, email gateways, rights management — can enforce handling rules automatically instead of relying on a human reading a banner.


4. Handling Requirements Cross Boundaries

Marking requirements do not stop at the authorization boundary, which is why they surface again in interconnection and contract governance.

  • Interconnections. The Interconnection Security Agreement must state what data types traverse the connection and what handling and marking obligations bind the receiving party. A partner who receives CUI over an interconnection is obliged to protect it, and that obligation must be written down rather than assumed.
  • Contracts. For contractors, handling obligations arrive through contract clauses. In the defense supply chain, CUI in a contract drives DFARS safeguarding requirements, NIST SP 800-171, and CMMC Level 2. A CGRC professional reviewing a procurement checks whether CUI will flow to the vendor and whether the contract carries the corresponding clauses — a gap here is a governance defect discovered too late to fix cheaply.
  • Cloud and multi-tenant environments. Handling requirements may constrain where data may reside, including data-residency and personnel-citizenship restrictions. These constraints must be validated against the provider's authorization before selection, because they can eliminate a provider outright.

Decontrolling

CUI status is not permanent. Information is decontrolled when the underlying authority no longer requires protection, when a specified decontrol date or event arrives, or through a formal decision by the designating agency. Decontrol is a deliberate, documented act — markings are struck through or removed and the decontrol action is recorded. Data does not become uncontrolled merely because it is old, and unilateral removal of markings by a recipient is a violation regardless of how stale the information appears.

Loading diagram...
Determining Data Handling and Marking Requirements During Control Selection
Test Your Knowledge

A program manager marks an internal budget memorandum as CUI because its disclosure would be politically embarrassing to the office. How should a CGRC professional characterize this action?

A
B
C
D
Test Your Knowledge

An organization has implemented rigorous role-based access control so that only authorized analysts can open records in a controlled repository. Why does the control baseline still require media marking under MP-3?

A
B
C
D
Test Your Knowledge

A reporting service reads from a database containing CUI Specified records and generates weekly summary dashboards that are distributed by email. What is the primary marking obligation for the dashboards?

A
B
C
D