1Overview
AC.L2-3.1.22 is the last requirement in the Access Control family, and it sounds like the simplest: do not post CUI on public systems. It becomes real the moment a manufacturing shop photographs a finished part for its website and the part, or the fixture holding it, reveals something it should not. The control requires that the organization control what is posted on its publicly accessible systems and ensure CUI is not among it.
Publicly accessible systems are the ones anyone can reach: the company website, public social media, a public-facing file area. The risk is not usually a deliberate posting of a controlled document but an inadvertent one, a photograph on the website that shows a controlled drawing on a monitor in the background, a capabilities page that describes a controlled program, a proud post about a defense contract that includes more than it should. The control asks the organization to designate who may post to public systems, to review content for CUI before it is posted, and to remove any CUI discovered on those systems. It is a control about process and awareness more than technology, and its failures are quiet because no one intended them.
Control CUI posted or processed on publicly accessible systems.
The requirement covers CUI posted or processed on publicly accessible systems. "Posted" is the direct case of content placed on a public site; "processed" reaches systems that handle content bound for public release. The control expects that authorized individuals control what goes onto public systems, that a review process catches CUI before posting, and that any CUI found on a public system is removed. The recurring theme of this family, that a control depends on a defined process and not only a tool, is especially true here, because the safeguard is a human review informed by knowing what CUI looks like in the organization's own work.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.1.22 into five objectives: designate who may post, define the procedure to keep CUI off public systems, review content before posting, review already-published content to ensure it contains no CUI, and provide a mechanism to remove improperly posted CUI.
Individuals authorized to post or process information on publicly accessible systems are identified. The organization has designated who may place content on its public systems.
Procedures to ensure CUI is not posted or processed on publicly accessible systems are identified. The organization has a defined process for keeping CUI off its public systems.
A review process is in place prior to posting of any content to publicly accessible systems. Content is actually reviewed for CUI before it goes public.
Content on publicly accessible systems is reviewed to ensure that it does not include CUI. Content already on public systems is reviewed, so CUI that slipped through earlier is found rather than left standing.
Mechanisms are in place to remove and address improper posting of CUI. When CUI is found on a public system, there is a way to remove it and respond.
The five objectives cover who posts, the procedure, the pre-posting review, the review of already-published content, and the removal of what slips through. The control depends most on objective [c], the review before posting, because that is the safeguard that catches the inadvertent disclosure, and it depends on the reviewer knowing what CUI looks like in the organization's own products and programs.
3Failure Patterns
The failures are inadvertent disclosures through public content, and the absence of the review and removal processes that would catch them.
The photograph that shows too much
A marketing photo of the shop floor or a finished part captures a controlled drawing on a monitor, a marked document on a bench, or a fixture that reveals a controlled design detail. No one intended to post CUI, but the image carries it, and without a review that knows what to look for, it reaches the public site. This is the archetypal failure of this control and the reason it matters to manufacturers specifically.
The capabilities page that says too much
A website describing the organization's work in detail, naming controlled programs or describing controlled capabilities, can disclose CUI through description rather than document. The pride of a capabilities page and the caution the control requires pull in opposite directions, and the review has to reconcile them.
Unrestricted posting to public channels
Where anyone may post to the company's public social media or website, objective [a] fails and the review of objective [c] cannot be assured, because content reaches the public with no designated control. Limiting who may post is the precondition for reviewing what is posted.
No way to take it down
When CUI is discovered on a public system, the absence of a removal process, objective [e], means it stays up while people work out who is responsible. A defined mechanism to remove improperly posted CUI and address the cause is what turns a discovery into a correction.
4Ownership
This control is owned by whoever controls public communications, informed by whoever knows what the organization's CUI looks like, which makes it a rare access control led outside IT.
| Role | Responsibility for this control |
|---|---|
| Marketing or communications lead | Controls what is posted to public systems, holds the authorized-poster role, and runs the pre-posting review. Owns the process evidence, since public content is their domain. |
| Engineering or program staff | Inform the review with the knowledge of what CUI looks like in the organization's products and programs, since a communications reviewer cannot recognize a controlled drawing without that input. |
| Security or compliance lead | Defines the procedure, trains the authorized posters on what is not for public release, and owns the removal process for CUI found on public systems. |
| Executive sponsor | Reconciles the tension between showcasing capability and protecting CUI, setting the expectation that the review comes before the post. |
5Tooling
The control is mostly process rather than technology: a defined set of authorized posters, a review step, and a removal path. The tooling supports the process rather than replacing it.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a] | Restricted publishing access to website and public accounts | Limiting who can post to public systems to the designated, authorized individuals. |
| [b], [c] | A documented pre-posting review procedure and checklist | The defined review that content is checked for CUI before publication, informed by knowledge of the organization's CUI. |
| [c] support | Content approval workflow in the publishing platform | An approval step before content goes live, giving the review a place in the workflow rather than relying on memory. |
| [e] | A removal and response process for discovered CUI | The mechanism to take down improperly posted CUI and address how it was posted. |
The caveat is that this control cannot be automated into safety. A publishing workflow can enforce that a review happens, but only a person who knows what the organization's CUI looks like can recognize a controlled drawing in a photograph, so the review depends on awareness more than on any tool. The assessor tests the control by examining the review process and the designated posters, and often by looking at the public site itself for inadvertent disclosures, so the process has to be real and the public content actually clean.
6Evidence
The satisfied version of 3.1.22 shows the designated posters, the defined and operating review, and the removal process, with a public presence that is actually free of CUI.
| Evidence | What it demonstrates |
|---|---|
| Authorized poster designation | Objective [a]. The named individuals permitted to post to public systems. |
| Pre-posting review procedure | Objectives [b], [c]. The documented process for checking content for CUI before publication. |
| Review records | Objective [c]. Evidence the review actually occurs before content is posted. |
| Removal and response process | Objective [e]. The mechanism to take down CUI found on public systems. |
| Clean public presence | Objectives [d], [e]. The public site and channels themselves, free of inadvertent CUI disclosure. |
The evidence includes the public presence itself, because the most direct demonstration of the control is a public site that contains no CUI, backed by the review process that keeps it that way. Review records showing that content is checked before posting, paired with the designated posters and the removal process, demonstrate the control in operation rather than only on paper.
The proud photo is where CUI slips out
The shop wants to show its best work, and its best work is often the controlled work, so the review that catches a controlled drawing in a marketing photo has to be built by someone who knows what CUI looks like in your products. Standing up that review, designating who may post, and clearing the existing public presence is part of the onsite readiness work this practice does.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.1.22. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.1.22[a] through 3.1.22[e]. csrc.nist.gov
- 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov