{
  "policy": {
    "id": "CTI-POL-001",
    "title": "Sensitive and Classified Information Policy",
    "version": "1.0",
    "status": "active",
    "effective_date": "2026-10-06",
    "review_cycle": "Annual, at SAM.gov registration renewal, and whenever requirements change",
    "authority": "Organizational Minutes of Cotangent Tech Inc., Resolution 15(h), September 24, 2026",
    "human_readable_url": "https://cotangentinc.com/information-handling.html",
    "precedence": "When a contract imposes stricter requirements, the contract controls."
  },
  "organization": {
    "legal_name": "Cotangent Tech Inc.",
    "entity_type": "Michigan for-profit corporation",
    "location": { "city": "Caro", "state": "MI", "country": "US" },
    "uei": null,
    "cage_code": null,
    "website": "https://cotangentinc.com/"
  },
  "owner": { "role": "President", "name": "Mitchell S. Aikens" },
  "contacts": {
    "security_email": "security@cotangentinc.com",
    "vulnerability_disclosure_policy": "https://cotangentinc.com/security.html"
  },
  "current_posture": {
    "facility_security_clearance": false,
    "accepts_classified_information": false,
    "stores_cui_on_company_systems": false,
    "cui_acceptance_conditions": [
      "Through government-furnished systems, or",
      "After company systems implement NIST SP 800-171, a System Security Plan is in place, and the assessment score is posted in SPRS when the contract requires it"
    ]
  },
  "information_categories": [
    {
      "id": "public",
      "name": "Public",
      "authorities": [],
      "handling": "Normal business care"
    },
    {
      "id": "fci",
      "name": "Federal contract information",
      "authorities": ["FAR 52.204-21"],
      "handling": "Systems meet the 15 basic safeguarding requirements of FAR 52.204-21"
    },
    {
      "id": "cui",
      "name": "Controlled unclassified information",
      "authorities": ["32 CFR Part 2002", "CUI Registry", "DoDI 5200.48", "NIST SP 800-171", "DFARS 252.204-7012"],
      "handling": {
        "marking": "Apply and preserve CUI Registry and DoDI 5200.48 markings; treat unmarked suspected CUI as CUI and ask the contracting officer",
        "access": "Lawful government purpose and need to know; export-controlled CUI limited to U.S. persons unless authorized",
        "storage": "Company-managed systems inside the System Security Plan boundary, or government-furnished systems",
        "encryption": "FIPS 140-validated cryptography on laptops, mobile devices, and removable media",
        "cloud": "FedRAMP Moderate baseline or equivalent only",
        "paper": "Under company control; locked container or office when not in use",
        "destruction": "Unreadable, indecipherable, and irrecoverable per 32 CFR 2002.14; NIST SP 800-88 media sanitization; cross-cut shredding",
        "subcontractors": "Only when the contract allows, after written flow-down of the same safeguarding clauses"
      }
    },
    {
      "id": "classified",
      "name": "Classified information",
      "authorities": ["Executive Order 13526", "32 CFR Part 117 (NISPOM)", "DD Form 254"],
      "handling": "Not accepted, stored, discussed, or transmitted. The company holds no facility security clearance."
    }
  ],
  "communication_channels": {
    "cui": {
      "approved": [
        "Government-furnished systems and accounts",
        "Government file exchange services offered by the customer, such as DoD SAFE",
        "Company email, file sharing, and meeting services inside the System Security Plan boundary that use FIPS 140-validated encryption and meet FedRAMP Moderate or equivalent",
        "Telephone calls, only where the contract permits, in a private setting",
        "Any other method the contract or contracting officer specifies in writing"
      ],
      "prohibited": [
        "Consumer messaging and calling apps, including Signal, WhatsApp, iMessage, Telegram, and Facebook Messenger",
        "SMS and MMS text messages",
        "Personal email accounts",
        "Consumer file-sharing and cloud storage services",
        "Social media and public forums",
        "Generative AI tools not authorized by the contract and not inside the System Security Plan boundary"
      ]
    },
    "classified": {
      "approved": [],
      "note": "No channel is approved while the company holds no facility security clearance. If one is granted, only government-approved systems and equipment for the classification level, as specified in the DD Form 254, may be used.",
      "prohibited": ["All unclassified systems", "All commercial applications and services, including Signal"]
    },
    "consumer_apps_permitted_for": "Public, non-sensitive business matters only, such as scheduling; never the substance of government work"
  },
  "incident_reporting": [
    {
      "event": "Suspected loss, unauthorized disclosure, or compromise of FCI, CUI, or classified information",
      "report_to": "President",
      "deadline": "Immediately"
    },
    {
      "event": "Cyber incident affecting covered defense information",
      "report_to": "Department of Defense via DIBNet",
      "url": "https://dibnet.dod.mil",
      "deadline_hours": 72,
      "authority": "DFARS 252.204-7012",
      "evidence_preservation_days": 90
    },
    {
      "event": "Incident under a non-DoD contract",
      "report_to": "As the contract's clauses require, and the contracting officer",
      "deadline": "As the contract requires"
    },
    {
      "event": "Inadvertent receipt or spillage of classified information",
      "report_to": "Contracting officer or the sender's security office, by phone",
      "deadline": "Immediately",
      "steps": [
        "Stop; do not read further, copy, print, forward, or delete",
        "Disconnect the device from the network without turning it off or wiping it",
        "Notify by phone and follow instructions",
        "Record what happened, when, and who was notified, without restating classified content"
      ]
    }
  ],
  "training": "CUI awareness training, such as the CDSE CUI course, before access and annually",
  "references": [
    { "name": "CUI Registry", "url": "https://www.archives.gov/cui" },
    { "name": "32 CFR Part 2002, Controlled Unclassified Information" },
    { "name": "NIST SP 800-171", "url": "https://csrc.nist.gov/pubs/sp/800/171/r2/upd1/final" },
    { "name": "FAR 52.204-21", "url": "https://www.acquisition.gov/far/52.204-21" },
    { "name": "DFARS 252.204-7012" },
    { "name": "DoD Instruction 5200.48" },
    { "name": "32 CFR Part 117 (NISPOM)" },
    { "name": "Executive Order 13526" },
    { "name": "NIST SP 800-88" }
  ]
}
