STIGQter STIGQter: STIG Summary: Traditional Security Checklist Version: 2 Release: 9 Benchmark Date: 01 Jul 2026:

Controlled Unclassified Information - Handling, Storage and Controlling Access to Areas where CUI is Processed or Maintained

DISA Rule

SV-245845r1226309_rule

Vulnerability Number

V-245845

Group Title

IS-16.02.03

Rule Version

IS-16.02.03

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. During working hours, reasonable steps shall be taken to minimize the risk of access by unauthorized personnel. This would include things like placing cover sheets on CUI documents and allowing unescorted access to areas where CUI (documents and AIS storage media) is processed/handled to only those persons with at least a favorably adjudicated NAC.

2. After working hours, CUI information (documents and AIS storage media) may be stored in unlocked containers, desks, or cabinets if government or government-contract building security is provided. If such building security is not provided or is deemed inadequate, the information (documents and AIS storage media) must be stored in locked desks, file cabinets, bookcases, locked rooms, etc. In all cases, CUI must be placed out of sight during nonworking hours. While not required, implementation of a clean desk policy would be a good idea.

3. Unescorted access to computer rooms or areas containing major items of AIS equipment processing CUI information (servers and network components) must only be granted to persons with at least a favorable NAC. All others must be physically escorted. Access control measures such as reception personnel, guards, keyed locks, cipher locks, or automated access control systems may be used to control access to such areas.

Check Contents

1. During working hours, reasonable steps shall be taken to minimize the risk of access by unauthorized personnel. This would include things like placing cover sheets on CUI documents and allowing unescorted access to areas where CUI (documents and AIS storage media) is processed/handled to only those persons with at least a favorably adjudicated National Agency Check (NAC).

2. After working hours, CUI information (documents and removable media) may be stored in unlocked containers, desks, or cabinets if government or government-contract building security is provided. If such building security is not provided or is deemed inadequate, the information (documents and removable media) must be stored in locked desks, file cabinets, bookcases, locked rooms, etc. In all cases, CUI documents must be placed out of sight during nonworking hours. While not required, recommending implementation of a clean desk policy would be appropriate.

3. Unescorted access to computer rooms or areas containing major items of AIS equipment processing CUI information (servers and network components) must only be granted to persons with at least a favorable NAC. All others must be physically escorted. Access control measures such as reception personnel, guards, keyed locks, cipher locks, or automated access control systems may be used to control access to such areas.

TACTICAL ENVIRONMENT: The check is applicable for fixed (established) tactical processing environments where procedural documents (SOPs) should be in place. Not applicable to a field/mobile environment.

Vulnerability Number

V-245845

Documentable

False

Rule Version

IS-16.02.03

Severity Override Guidance

1. During working hours, reasonable steps shall be taken to minimize the risk of access by unauthorized personnel. This would include things like placing cover sheets on CUI documents and allowing unescorted access to areas where CUI (documents and AIS storage media) is processed/handled to only those persons with at least a favorably adjudicated National Agency Check (NAC).

2. After working hours, CUI information (documents and removable media) may be stored in unlocked containers, desks, or cabinets if government or government-contract building security is provided. If such building security is not provided or is deemed inadequate, the information (documents and removable media) must be stored in locked desks, file cabinets, bookcases, locked rooms, etc. In all cases, CUI documents must be placed out of sight during nonworking hours. While not required, recommending implementation of a clean desk policy would be appropriate.

3. Unescorted access to computer rooms or areas containing major items of AIS equipment processing CUI information (servers and network components) must only be granted to persons with at least a favorable NAC. All others must be physically escorted. Access control measures such as reception personnel, guards, keyed locks, cipher locks, or automated access control systems may be used to control access to such areas.

TACTICAL ENVIRONMENT: The check is applicable for fixed (established) tactical processing environments where procedural documents (SOPs) should be in place. Not applicable to a field/mobile environment.

Check Content Reference

M

Target Key

5410