STIGQter STIGQter: STIG Summary: Traditional Security Checklist Version: 2 Release: 9 Benchmark Date: 01 Jul 2026:

Controlled Unclassified Information - Transmission by either Physical or Electronic Means

DISA Rule

SV-245847r1226295_rule

Vulnerability Number

V-245847

Group Title

IS-16.02.05

Rule Version

IS-16.02.05

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. CUI information and material may be transmitted via first class mail, parcel post, or, for bulk shipments, via fourth class mail.

2. Electronic transmission of CUI information, e.g., email, shall be by approved secure communications systems or systems utilizing other protective measures such as Public Key Infrastructure (PKI) or transport layer security (e.g., https).

3. Use of wireless telephones (cellphones, wireless hand-held phones, Bluetooth, etc.) should be avoided when other options are available.

4. Transmission of CUI by facsimile machine (fax) is permitted; the sender is responsible for determining that appropriate protection will be available at the receiving location prior to transmission (e.g., machine attended by a person authorized to receive CUI; fax located in a controlled government environment).

Check Contents

1. CUI information and material may be transmitted via first class mail, parcel post, or, for bulk shipments, via fourth class mail.

2. Electronic transmission of CUI information, e.g., email, shall be by approved secure communications systems or systems utilizing other protective measures such as Public Key Infrastructure (PKI) or transport layer security (e.g., https).

3. Use of wireless telephones (cellphones, wireless hand-held phones, Bluetooth, etc.) should be avoided when other options are available.

4. Transmission of CUI by facsimile machine (fax) is permitted; the sender is responsible for determining that appropriate protection will be available at the receiving location prior to transmission (e.g., machine attended by a person authorized to receive CUI; fax located in a controlled government environment).

TACTICAL ENVIRONMENT: The check is applicable for fixed (established) tactical processing environments. Not applicable to a field/mobile environment.

Vulnerability Number

V-245847

Documentable

False

Rule Version

IS-16.02.05

Severity Override Guidance

1. CUI information and material may be transmitted via first class mail, parcel post, or, for bulk shipments, via fourth class mail.

2. Electronic transmission of CUI information, e.g., email, shall be by approved secure communications systems or systems utilizing other protective measures such as Public Key Infrastructure (PKI) or transport layer security (e.g., https).

3. Use of wireless telephones (cellphones, wireless hand-held phones, Bluetooth, etc.) should be avoided when other options are available.

4. Transmission of CUI by facsimile machine (fax) is permitted; the sender is responsible for determining that appropriate protection will be available at the receiving location prior to transmission (e.g., machine attended by a person authorized to receive CUI; fax located in a controlled government environment).

TACTICAL ENVIRONMENT: The check is applicable for fixed (established) tactical processing environments. Not applicable to a field/mobile environment.

Check Content Reference

M

Target Key

5410