VISIBLE SECURITY LANE
What can be shared through the public site?
Share only a high-level organization type, program stage, non-sensitive quantity range, delivery horizon, requirement categories, anticipated information category, and the decision the review should support. Do not share program names, customer names, solicitation numbers, platform identifiers, requirements text, drawings, credentials, or technical files.
Public intake lane
- Organization type
- Program stage
- High-level range
- Control categories
- Anticipated information category
- Unclassified decision statement
Approved exchange lane
- Established only after review
- Named parties and identities
- Authorized facility and system
- Defined account and access
- Approved storage and transmission
- Retention and incident responsibilities
Why is an NDA not the entire handling plan?
An NDA can define confidentiality duties between parties. It does not, by itself, determine whether information is classified, CUI, export controlled, customer restricted, or otherwise subject to facility, system, identity, access, storage, transmission, or reporting requirements.
The engagement owner should identify every anticipated information category and the authoritative requirement before choosing a transfer method. If the category is uncertain, the safe state is not to transmit it.
Handling-path decision register
| Decision | Questions to resolve | Release condition |
|---|---|---|
| Information category | What is public, proprietary, CUI, export controlled, classified, or uncertain? | Authorized owner confirms category |
| Legal and contractual basis | Which agreement, clause, law, regulation, or customer instruction applies? | Current source is identified |
| Parties and identity | Who may disclose, receive, administer, and approve access? | Named identities and roles are approved |
| Facility and system | Where may the information be accessed, processed, stored, and discussed? | Environment is approved for the category |
| Transmission | Which approved channel, account, encryption, and authentication apply? | End-to-end path is verified |
| Retention and incident | How long is data kept, how is it removed, and who handles an incident? | Responsibilities are documented |
Where should authoritative guidance come from?
For Controlled Unclassified Information definitions and federal-level guidance, consult the National Archives CUI Program and Registry. Agency personnel and contractors should also follow their agency implementation and program-management guidance.
For items subject to the Export Administration Regulations, the Bureau of Industry and Security licensing guidance explains classification, end-use, end-user, destination, and licensing considerations. The appropriate legal, export, security, and program authorities must determine the actual requirements.
This site does not provide legal, export, security, classification, or compliance advice. It defines a safe initial boundary for a production-fit conversation.