To ensure compliance with federal requirements for protecting Controlled Unclassified Information on non-federal systems and organizations.
July 1, 2025
June 25, 2025
Responsible OfficeResearch Services
Federal research agencies include stringent security requirements for data designated as Controlled Unclassified Information (CUI). CUI must be stored or handled in controlled environments that prevent or detect unauthorized access, and security controls must be compliant with federal regulations specified in 32 CFR Part 2002. The federal CUI regulations apply to federal executive branch agencies that handle CUI, and all organizations–including universities–that receive, possess, share, use, or create CUI.
CUI may only be stored and processed on designated Penn SRE systems in accordance with the specific System Security Plan.
This Policy is applicable to any faculty, staff, students, affiliates, contractors, or agents who handle, possess, use, share, create, or receive CUI.
Business Administrator
Principal Investigator
Personnel accessing an SRE
Office of Research Services, Research Security
Office of Information Security, Secure IT
Penn SRE Provider
Failure to comply will result in immediate revocation of SRE access.