🌟 Referentia First Hawaii CMMC C3PAO – Featured in APSMĀ  Ā READ MORE

Tips for Identifying CDI

Does your organization handle CDI? These easy tips can help you understand what CDI is and how data is classified as CDI.

Where is CDI really defined?

DFARS 7012(a) defines CDI as unclassified controlled technical information or other Controlled Unclassified Information (CUI) that requires safeguarding or dissemination controls. This means you have to understand both Unclassified Controlled Technical Information (UCTI) and CUI.

What is Controlled Unclassified Information (CUI) and where is it defined?

Controlled Unclassified Information, or CUI, isĀ defined by the National ArchivesĀ as ā€œinformation that requires safeguarding or dissemination controls pursuant to and consistent with applicable law, regulations, and government-wide policies but is not classified under Executive Order 13526 or the Atomic Energy Act, as amended.ā€ See theĀ National Archives CUI RegistryĀ for more information about what is and is not CUI.

What is controlled technical information and where is it defined?

DFARS 7012(a) defines controlled technical information as technical information with military or space application that is subject to controls – assuming that it isn’t already lawfully publicly available without restrictions. The DFARS 7012 clause also says controlled technical information meets the criteria for distribution statements B through F in DoD Instruction 5230.24.

What is DoD Instruction 5230.24 and what are distribution statements B through F?

DoD Instruction 5230.24Ā provides the policies and rulesĀ for marking and managing technical documentsĀ toĀ denote the extent to which they are available for secondary distribution, release, andĀ dissemination without additional approvals or authorizations. It also establishes a standard framework and markings for managing, sharing, safeguarding, andĀ disseminating technical documents in accordance with policy and law.

Does CDI come from the government, or might I be creating it?

You might be creating it. TheĀ DFARS 7012 clause says CDI can be ā€œcollected, developed, received, transmitted, used, or stored by or on behalf of the contractor in support of the performance of the contract.ā€

Who determines what is and isn’t CDI?

The government’s contracting officer has the responsibility for determining what data is and isn’t CDI.