What DOD instruction implements the DOD CUI program?
(Select the best answer)
A DODI 5200.01, ROD Information Security Program and Protection of Sensitive Compartmented Information
B DODI 5200.48, Controlled Unclassified Information
C DODI 5205.08, Access to Classified Cryptographic Information
D DODI 5200.39, Critical Program Information Identification and Protection Within Research, Development, Test, and Evaluation
The correct answer and explanation is :
The correct answer is B: DODI 5200.48, Controlled Unclassified Information.
Explanation:
The Department of Defense Instruction (DODI) 5200.48 specifically addresses the implementation and management of the Controlled Unclassified Information (CUI) program. CUI refers to information that requires safeguarding or dissemination controls according to laws, regulations, or government-wide policies, but is not classified under Executive Order 13526 or the Atomic Energy Act of 1954.
DODI 5200.48 establishes the procedures for the handling, marking, and safeguarding of CUI within the Department of Defense (DoD). This instruction provides guidance on how to identify, mark, protect, and share unclassified information that falls under CUI categories, helping ensure consistency in how sensitive but unclassified information is managed across the DoD. The instruction aligns the DoD’s CUI practices with broader federal regulations set forth by the National Archives and Records Administration (NARA), which oversees the CUI program across the federal government.
CUI includes a wide range of information types such as personally identifiable information (PII), financial data, proprietary business information, and information relating to defense technology. The management of CUI is critical in protecting national security, privacy, and intellectual property, while ensuring that sensitive information is not improperly disclosed.
Other options are incorrect for the following reasons:
- A: DODI 5200.01 pertains to the overall information security program and the protection of classified information, not CUI.
- C: DODI 5205.08 relates to access control for classified cryptographic information and is unrelated to the CUI program.
- D: DODI 5200.39 addresses the identification and protection of critical program information (CPI) within research and development, not the broader CUI program.
Therefore, DODI 5200.48 is the governing instruction for the DoD’s Controlled Unclassified Information (CUI) program.