What is the policy on using unofficial or personal email for official business involving CUI?

Study for the DOD Instruction 5200.48 Controlled Unclassified Information (CUI) exam. Prepare with flashcards and multiple choice questions, each with detailed hints and explanations. Ensure success on your test day!

Multiple Choice

What is the policy on using unofficial or personal email for official business involving CUI?

Explanation:
Handling CUI requires using DoD-approved systems to ensure protection, proper storage, and auditable access. Unofficial or personal email for official business involving CUI bypasses these safeguards, increasing the risk of data leaks, improper disclosures, and noncompliance with safeguarding and retention rules. Personal accounts may be on non-DoD servers, outside monitoring, and not compatible with the required controls, making it easy for CUI to be exposed or mishandled. There are only limited exceptions when a contractor system has been explicitly approved or authorized to handle CUI, but even then that system must meet the applicable safeguarding standards and be specifically authorized for CUI use. In all other cases, unofficial or personal email should not be used for official CUI-related communications. Options that imply permissiveness or routine use of personal email for CUI neglect the essential need for controlled, auditable, and secure handling of sensitive information, which is why the correct policy aligns with using DoD-approved channels for CUI.

Handling CUI requires using DoD-approved systems to ensure protection, proper storage, and auditable access. Unofficial or personal email for official business involving CUI bypasses these safeguards, increasing the risk of data leaks, improper disclosures, and noncompliance with safeguarding and retention rules. Personal accounts may be on non-DoD servers, outside monitoring, and not compatible with the required controls, making it easy for CUI to be exposed or mishandled.

There are only limited exceptions when a contractor system has been explicitly approved or authorized to handle CUI, but even then that system must meet the applicable safeguarding standards and be specifically authorized for CUI use. In all other cases, unofficial or personal email should not be used for official CUI-related communications.

Options that imply permissiveness or routine use of personal email for CUI neglect the essential need for controlled, auditable, and secure handling of sensitive information, which is why the correct policy aligns with using DoD-approved channels for CUI.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy