# CUI Handling and Data Classification Course

Canonical URL: <https://www.graduateschool.edu/courses/cui-handling-and-data-classification>

## Overview

This course offers a government-wide, agency-neutral awareness course covering the full CUI lifecycle. It opens by placing CUI in the three-tier information framework, between classified national security information and uncontrolled public information, and makes the point that CUI status comes from law, regulation, or government-wide policy rather than from someone's judgment that information "seems sensitive." From there it is practical: learners work with the CUI Registry and the distinction between CUI Basic and CUI Specified, assemble a banner marking themselves rather than just recognizing one, and place markings correctly across documents, portions, removable media and email. Handling covers need-to-know, physical and electronic storage, transmission, remote work, and destruction and sanitization, built around the mistakes people actually make: documents left on printers, personal email "just this once", and CUI in the recycling.

The closing module is the most current material in the course. Alongside incident reporting and consequences, it covers using CUI with AI tools, grounded in ISOO Notice 2026-01 from March 2026 on the responsible use of classified information and CUI with artificial intelligence — guidance that is months old and very unlikely to appear in any competing CUI course. Interactive categorization exercises and scenario-based practice activities are used deliberately rather than everywhere, in the modules where the skill being built is categorization, marking assembly, or matching a scenario to a safeguard; the final module is procedural instead and carries a longer knowledge check.

## What you'll learn

- Explain what CUI is, how it differs from classified national security information and from public information, and why it must be protected
- Identify the government-wide legal and regulatory framework that governs CUI
- Distinguish CUI Basic from CUI Specified, and use the CUI Registry to check a category
- Recognize common CUI categories and realistic everyday examples
- Interpret and assemble the components of a CUI banner marking, and explain portion marking
- Apply need-to-know and safe handling practices across physical, electronic and verbal forms
- Identify approved methods for storing, transmitting, destroying and sanitizing CUI
- Describe the steps to take when CUI is lost, mishandled or improperly disclosed, and why speed matters
- Identify current government-wide expectations for using CUI with AI tools

## Curriculum

#### Module 1

- Introduction to CUI and the Federal Framework
- Defining CUI in plain language
- The three-tier framework of classified, CUI and public
- Where CUI comes from and why personal judgment does not create it
- Executive Order 13556 and 32 CFR Part 2002
- The roles across the CUI lifecycle. Includes a sort-the-information-tier activity.

#### Module 2

- CUI Categories and Recognizing CUI
- The CUI Registry as the single authoritative source
- CUI Basic versus CUI Specified
- Common category groupings covering privacy, procurement-sensitive, law-enforcement-sensitive and export-controlled or critical infrastructure information
- Everyday examples
- What CUI is not. Includes a CUI-or-not-CUI sorting activity.

#### Module 3

- Marking and Labeling CUI 
- Why markings are handling instructions rather than decoration
- Banner marking components
- Portion marking
- Marking email, removable media and file names
- What to do with unmarked or mismarked CUI. Includes a build-the-banner-marking assembly activity and a marking-location matching activity.

#### Module 4

- Safe Handling, Storage, Transmission, and Destruction
- Need-to-know
- Physical storage and visual access
- Authorized systems and approved storage locations
- Encrypted transmission and approved file transfer
- Remote work and travel
- Destruction and media sanitization
- The common mistakes that cause most incidents. Includes a scenario-to-safeguard matching activity.

#### Module 5

- Incident Reporting, Consequences, and Emerging Considerations
- What counts as a CUI incident
- Reporting promptly and to whom
- Why speed reduces harm
- What not to do
- The range of administrative, civil and criminal consequences
- CUI and artificial intelligence under current government-wide guidance

## Schedule
- Jan 18, 2027 1:00pm–5:00pm — Live Online
- Feb 24, 2027 1:00pm–5:00pm — Live Online
- Mar 3, 2027 1:00pm–5:00pm — Live Online
- Apr 19, 2027 1:00pm–5:00pm — Live Online
- May 14, 2027 1:00pm–5:00pm — Live Online
- Jun 4, 2027 1:00pm–5:00pm — Live Online
- Jul 16, 2027 1:00pm–5:00pm — Live Online

## Pricing

**Tuition:** $675
