Educause Security Discussion mailing list archives

NPRM, DFARS; Safeguarding Unclassified DoD Information (DFARS Case 2011-D039)


From: "pmorley () mcdaniel edu" <pmorley () MCDANIEL EDU>
Date: Fri, 15 Jul 2011 01:53:14 +0000

[   //UNCLASSIFIED//   ]

All Listserv Members,

In response to the below message/inquiry, because of former background I have with the DoD and specifically the NSA, 
anyone holding classified or unclassified information is required to append the appropriate classification level tags 
to the material. This includes electronic and hard copy.

I would have to further look into the exact policy or rule mentioned by Michelle to further clarify what is needed, etc.

For the specific purposes of unclassified or FOUO (For Official Use Only), the tags are [  //UNCLASSIFIED// and 
//FOUO//  ].

Additionally, you are required to also date stamp all material as it changes possession with your name or identifiable 
markings, along with a hard copy log and electronic log of all retained and maintained material, electronic and hard 
copy both.

Because I mention the NSA/DoD in this message, I'm now required to place classification tags on this message….

Phillip Morley
Jr. Systems Administrator | Information Technology
McDaniel College
2 College Hill
Westminster, MD 21157
• Office: (410) 857-2540
• E-mail: pmorley () mcdaniel edu<mailto:pmorley () mcdaniel edu>

[  //UNCLASSIFIED//  ]

Phillip Morley
Jr. Systems Administrator | Information Technology
McDaniel College
2 College Hill
Westminster, MD 21157
• Office: (410) 857-2540
• E-mail: pmorley () mcdaniel edu<mailto:pmorley () mcdaniel edu>

From: "Wisdom, Michelle M." <WisdomM () MISSOURI EDU<mailto:WisdomM () MISSOURI EDU>>
Reply-To: The EDUCAUSE Security Constituent Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () 
LISTSERV EDUCAUSE EDU>>
Date: Thu, 14 Jul 2011 15:33:06 -0500
To: <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>>
Subject: [SECURITY] NPRM, DFARS; Safeguarding Unclassified DoD Information (DFARS Case 2011-D039)

Has anyone taken an in-depth look at this proposed rule or know of any analysis of its potential impact on colleges and 
universities?  It was recently brought to my attention (I work in an IT security department for a state University 
system) and it’s beginning to generate some discussion.

I’m working on putting together a summary and discussion paper, but I’d like to sanity check my efforts against those 
of others who have also taken a look at this.

Thanks in advance for any information you can provide!

Michelle Wisdom, JD
Division of IT
University of Missouri
573-882-9275


Current thread: