Sensitive and Classified Information Policy
How Cotangent Tech Inc. protects federal contract information, controlled unclassified information, and classified information.
- We protect federal contract information under FAR 52.204-21, and controlled unclassified information (CUI) under 32 CFR Part 2002, NIST SP 800-171, and the clauses of each contract.
- We don't hold a facility security clearance, so we don't accept, store, discuss, or transmit classified information.
- CUI moves only through approved channels. Consumer messaging apps are never used for CUI or classified information.
1. Purpose and scope
This policy sets the minimum rules for handling sensitive government information at Cotangent Tech Inc. It applies to every officer, employee, and subcontractor, to every company system and device, and to all information received from or created for a government customer. When a contract imposes stricter requirements, the contract controls.
The President adopted this policy under Resolution 15(h) of the company's Organizational Minutes. Detailed technical procedures are kept in the company's internal System Security Plan and are not published.
2. Information categories
| Category | What it is | Governing rules |
|---|---|---|
| Public | Information approved for public release, such as this website | None beyond normal business care |
| Federal contract information (FCI) | Non-public information provided by or generated for the government under a contract | FAR 52.204-21 |
| Controlled unclassified information (CUI) | Information the government requires to be safeguarded under law, regulation, or policy, including export-controlled technical data | 32 CFR Part 2002; the CUI Registry; DoDI 5200.48; NIST SP 800-171; DFARS 252.204-7012 |
| Classified information | Information classified Confidential, Secret, or Top Secret | Executive Order 13526; 32 CFR Part 117 (NISPOM); the contract's DD Form 254 |
3. Current posture
- CUI: We don't store CUI on company systems today. We will accept CUI only through government-furnished systems, or after company systems implement NIST SP 800-171, a System Security Plan is in place, and our assessment score is posted in SPRS when the contract requires it.
- Classified: We don't hold a facility security clearance (FCL) and have no cleared personnel or approved storage. We will not bid on work that requires access to classified information unless a government agency or cleared prime contractor sponsors us for an FCL.
4. Roles and responsibilities
- President: senior official responsible for this policy, the System Security Plan, incident reporting, and training records. If the company is granted an FCL, the President will appoint a Facility Security Officer and an Insider Threat Program Senior Official as 32 CFR Part 117 requires.
- All personnel: handle information according to its category, complete required training, and report suspected incidents immediately.
- Subcontractors: receive CUI only when the contract allows it, and only after agreeing in writing to the same safeguarding clauses, including DFARS 252.204-7012 where it applies.
5. Federal contract information
Every system that stores or processes FCI meets the 15 basic safeguarding requirements of FAR 52.204-21. In summary, we:
- limit system access to authorized users, and the transactions they may perform;
- identify and authenticate every user and device before granting access;
- control what is posted on public systems, and verify connections to external systems;
- sanitize or destroy media before disposal or reuse;
- limit physical access to systems, escort visitors, and keep access logs;
- monitor and protect system boundaries, and separate public-facing systems from internal networks;
- fix system flaws promptly, and run current malware protection with regular and real-time scans.
6. Controlled unclassified information
Marking
We apply and preserve the markings required by the CUI Registry and, for DoD work, DoDI 5200.48. We never remove or alter a marking. If information appears to be CUI but isn't marked, we treat it as CUI and ask the contracting officer.
Access
Only people with a lawful government purpose and a need to know may access CUI. Export-controlled CUI is available only to U.S. persons unless an export authorization allows otherwise.
Storage
- Store CUI only on company-managed systems inside the System Security Plan boundary, or on government-furnished systems.
- Encrypt CUI on laptops, mobile devices, and removable media with FIPS 140-validated cryptography.
- Use a cloud service for CUI only if it meets the FedRAMP Moderate baseline or its equivalent, as DFARS 252.204-7012 requires.
- Never store CUI on personal devices, personal accounts, or consumer cloud storage.
- Keep printed CUI under the company's direct control, and in a locked container or office when it is not in use.
Destruction
Destroy CUI so that it is unreadable, indecipherable, and irrecoverable, as 32 CFR 2002.14 requires. Sanitize electronic media using NIST SP 800-88 methods, and cross-cut shred paper. Return or destroy CUI at the end of a contract as its terms direct.
7. Communication channels
Approved for CUI
- Systems and accounts the government customer provides for the contract
- Government file exchange services offered by the customer, such as DoD SAFE
- Company email, file sharing, and meeting services that are inside the System Security Plan boundary, use FIPS 140-validated encryption, and meet the FedRAMP Moderate baseline or its equivalent
- Telephone calls, only where the contract permits discussing CUI by phone, held in a private setting and never on speakerphone in shared spaces
- Any other method the contract or the contracting officer specifies in writing
- Consumer messaging and calling apps, including Signal, WhatsApp, iMessage, Telegram, and Facebook Messenger
- SMS and MMS text messages
- Personal email accounts and consumer file-sharing or cloud storage services
- Social media and public forums
- Generative AI tools, unless the contract authorizes the tool and it is inside the System Security Plan boundary
End-to-end encryption alone doesn't make a service acceptable. CUI requires managed systems, FIPS 140-validated cryptography, and the controls in NIST SP 800-171.
Consumer apps may be used only for public, non-sensitive business matters, such as scheduling a meeting, and never to discuss the substance of government work.
8. Classified information
- The company doesn't request, accept, store, process, discuss, or transmit classified information.
- Classified information may never be entered into, discussed on, or sent through any unclassified system or commercial application.
- If the company is granted an FCL, it will follow 32 CFR Part 117 and each contract's DD Form 254. Only cleared personnel with a need to know will have access. Classified material will be stored only in approved containers or areas, and communicated only over government-approved systems and equipment for its classification level.
If classified information is received by mistake
- Stop. Don't read further, copy, print, forward, or delete it.
- Disconnect the affected device from the network, but don't turn it off or wipe it.
- Notify the contracting officer, or the sender's security office, right away by phone, and follow their instructions.
- Record what happened, when, and who was notified, without restating any classified content.
9. Incident reporting
- Internal: report any suspected loss, unauthorized disclosure, or compromise of FCI, CUI, or classified information to the President immediately.
- DoD cyber incidents: report cyber incidents affecting covered defense information to DoD within 72 hours of discovery through DIBNet, as DFARS 252.204-7012 requires. Preserve images of affected systems for at least 90 days, and submit any malicious software found as directed.
- Other agencies: report as each contract's clauses require, and notify the contracting officer.
- Classified: report inadvertent receipt or spillage as described in Section 8.
10. Training, enforcement, and review
- Everyone completes CUI awareness training, such as the Center for Development of Security Excellence (CDSE) CUI course, before accessing CUI and every year after.
- Violations can lead to loss of access and termination of employment or subcontract, and will be reported to the government when law or contract requires.
- The President reviews this policy every year at the SAM.gov renewal, and whenever laws, regulations, or contract requirements change.
Questions or reports: security@cotangentinc.com. See also our security and vulnerability disclosure policy.
11. References
- CUI Registry, National Archives and 32 CFR Part 2002, Controlled Unclassified Information
- NIST SP 800-171, Protecting CUI in Nonfederal Systems and Organizations
- FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
- DoD Instruction 5200.48, Controlled Unclassified Information
- 32 CFR Part 117, National Industrial Security Program Operating Manual (NISPOM)
- Executive Order 13526, Classified National Security Information
- NIST SP 800-88, Guidelines for Media Sanitization