Government Information

Overview

Research projects may involve information that is provided by, generated for, or otherwise controlled by the U.S. Government. Depending on the type of information involved, federal sponsors, award terms and conditions, contracts, regulations, or other requirements may establish specific requirements for the protection, storage, sharing, transmission, access, and dissemination of that information.

Government information is not a single category. Different types of government information may be subject to different safeguarding, dissemination, access, cybersecurity, and other requirements.

Federal contracts and certain subcontracts may also include cybersecurity and information protection requirements established through the Federal Acquisition Regulation (FAR), agency-specific acquisition regulations, contract clauses, and other federal requirements. Grants, cooperative agreements, and other federal awards may establish separate information protection or cybersecurity requirements through sponsor terms and conditions.

The Office of Research Security (ORS) assists faculty, staff, and students in identifying applicable requirements and coordinating with the appropriate University offices to support compliant research.

CONTACT ors


Common Types of Government Information

Information Type Description Learn More
Controlled Unclassified Information (CUI) Government information that requires safeguarding or dissemination controls pursuant to federal law, regulation, or government-wide policy, but is not classified. Controlled Unclassified Information (CUI)
Federal Contract Information (FCI) Information provided by or generated for the Government under a federal contract that is not intended for public release and requires basic safeguarding. Federal Contract Information (FCI)
Classified Information Information that has been determined pursuant to Executive Order to require protection against unauthorized disclosure in the interest of national security. Contact ORS
Government-Furnished Information (GFI) Information, software, technical data, equipment, or other materials provided by a federal agency for use in the performance of a research project or contract. Government-furnished information may also be designated as CUI, classified, or subject to other agency-specific handling requirements. Contact ORS

Important: These categories are not necessarily mutually exclusive. Government information may be subject to more than one regulatory, contractual, or sponsor requirement. ORS can assist researchers in determining which requirements apply.


Why Government Information Matters

Research involving government information may require protections beyond those normally applied to research data.

Depending on the project, requirements may include:

  • Controlled access to research information.
  • Cybersecurity safeguards.
  • Secure storage and transmission.
  • Restrictions on sharing or dissemination.
  • Personnel access restrictions.
  • Export control requirements.
  • Contractual confidentiality requirements.
  • Cyber incident reporting.
  • Specialized research computing environments.
  • Project-specific information protection or security plans.

Not every research project involving government information is subject to the same requirements. Applicable safeguards depend on the type of information involved, the sponsoring agency, award type, contractual obligations, and applicable federal requirements.


Federal Contract Cybersecurity Requirements

Federal procurement contracts and certain subcontracts may contain specific cybersecurity and information protection requirements that differ from requirements applicable to many federal grants and cooperative agreements.

These requirements may be established through:

  • Federal Acquisition Regulation (FAR) clauses.
  • Agency-specific acquisition regulations.
  • Defense Federal Acquisition Regulation Supplement (DFARS) clauses.
  • Contract terms and conditions.
  • Federal cybersecurity standards incorporated into an award.
  • Prime contractor requirements applicable to subcontractors.
  • Other agency-specific security or information protection requirements.

Depending on the contract and information involved, researchers may be required to implement specific administrative, physical, and technical safeguards before receiving, accessing, generating, storing, or transmitting protected government information.

ORS should be contacted when a federal contract or subcontract includes cybersecurity, information safeguarding, access, dissemination, or related security requirements.


Common Federal Contract Requirements

Federal contract cybersecurity requirements vary by agency and contract. Requirements researchers may encounter include:

Requirement or Framework Purpose
Federal Acquisition Regulation (FAR) Establishes government-wide acquisition requirements, including clauses addressing safeguarding and cybersecurity requirements applicable to federal contracts.
Defense Federal Acquisition Regulation Supplement (DFARS) Establishes Department of Defense-specific acquisition requirements, including requirements for safeguarding certain covered defense information and CUI.
Federal Contract Information (FCI) Federal contract information that may be subject to contractual safeguarding requirements.
Controlled Unclassified Information (CUI) Government information requiring safeguarding or dissemination controls pursuant to applicable law, regulation, or government-wide policy.
NIST SP 800-171 Establishes security requirements for protecting CUI in nonfederal systems and organizations when incorporated into applicable federal requirements.
Cybersecurity Maturity Model Certification (CMMC) Department of Defense program used to assess contractor implementation of specified cybersecurity requirements when applicable to a contract.

The presence of a federal contract does not mean that every requirement listed above applies. Applicability depends on the agency, contract clauses, information involved, and other project-specific requirements.


Federal Contract Information and CUI

Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) are distinct categories of government information.

FCI generally involves non-public information provided by or generated for the Federal Government in connection with performance of a federal contract.

CUI is government information that requires safeguarding or dissemination controls pursuant to applicable federal law, regulation, or government-wide policy.

Some projects may involve only FCI, while others may involve CUI or both FCI and CUI. The applicable cybersecurity and safeguarding requirements may differ.

Researchers should not assume that all non-public government information is CUI. ORS can assist in identifying the type of information involved and determining applicable requirements.


Department of Defense Requirements

Department of Defense (DoD) contracts and subcontracts may include additional cybersecurity and information protection requirements through the Defense Federal Acquisition Regulation Supplement (DFARS) and other DoD requirements.

Depending on the contract, requirements may address:

  • Protection of CUI or other covered information.
  • NIST SP 800-171 security requirements.
  • Cyber incident reporting.
  • Contractor cybersecurity assessments.
  • Cybersecurity Maturity Model Certification (CMMC).
  • Other DoD-specific safeguarding requirements.

Not all DoD research awards include the same requirements. Applicability depends on the solicitation, award instrument, contract clauses, information involved, and other project-specific requirements.

ORS should be contacted before accepting or beginning work subject to DoD cybersecurity or information protection requirements.


Grants, Cooperative Agreements & Other Federal Awards

Cybersecurity and information protection requirements are not limited to federal procurement contracts.

Federal grants, cooperative agreements, and other awards may establish requirements through:

  • Award terms and conditions.
  • Sponsor policies or instructions.
  • Data management or security requirements.
  • Research security requirements.
  • Information protection requirements.
  • Agency-specific cybersecurity requirements.
  • Requirements associated with particular types of federal information or data.

These requirements may differ from those imposed through the FAR or other federal acquisition regulations.

Researchers should review applicable sponsor and award requirements and contact ORS when an award includes information protection, cybersecurity, access, dissemination, or other security requirements.


Export-Controlled Government Information

Government information may also be subject to U.S. export control regulations.

Export-controlled information may include certain technical data, technology, software, source code, engineering information, or other technical information regulated under the Export Administration Regulations (EAR), International Traffic in Arms Regulations (ITAR), or other federal export control regulations.

Export control requirements may restrict access by foreign persons, international transfers, or other uses or disclosures of controlled information.

Government information may be both export controlled and subject to additional contractual or cybersecurity requirements.

Related Guide: Export-Controlled Information


Protecting Government Information

The safeguards required for government information depend on the information involved and applicable federal, sponsor, contractual, and institutional requirements.

Depending on the project, safeguards may include:

  • Limiting access to authorized personnel.
  • Secure storage of electronic and physical information.
  • Controlled transmission and sharing.
  • Research cybersecurity safeguards.
  • Specialized research computing environments.
  • Physical security measures.
  • Technology Control Plans.
  • Data Protection Plans or other project-specific safeguarding plans.
  • Training requirements.
  • Incident reporting requirements.

Researchers should not establish project-specific safeguarding requirements based solely on the perceived sensitivity of the information. ORS will assist in identifying applicable requirements and coordinating implementation with the appropriate University offices.


How ORS Can Help

ORS assists researchers by:

  • Identifying the type of government information involved in a project.
  • Reviewing sponsor, award, contract, and subcontract requirements.
  • Identifying applicable cybersecurity, research information protection, export control, and research security requirements.
  • Determining when project-specific safeguarding measures are required.
  • Coordinating Technology Control Plans, Data Protection Plans, and other project-specific safeguards, as applicable.
  • Coordinating with Research Computing & Informatics (RCI), the Information Security Office, the Office of Sponsored Programs, and other University offices, as appropriate.
  • Providing guidance throughout the proposal, award, and research lifecycle.

Related Guidance 

Reference Guide Description
Controlled Unclassified Information (CUI) Learn about federal safeguarding and dissemination requirements applicable to CUI used in research.
Federal Contract Information (FCI) Learn about Federal Contract Information and associated contractual safeguarding requirements.
Export-Controlled Information Learn about protecting technical data, technology, software, source code, and other information subject to U.S. export control regulations.
Research Information Protection Learn how administrative, physical, and technical safeguards are identified and applied to protect research information.
Research Cybersecurity Baseline Review baseline cybersecurity practices that support University research activities.

Need Assistance?

If your research project involves information provided by or generated for the U.S. Government, a federal contract or subcontract, or sponsor requirements related to cybersecurity or information protection, contact the Office of Research Security before beginning the research activity.

ORS will assist in identifying the type of government information involved, determining applicable sponsor, contractual, regulatory, cybersecurity, and information protection requirements, and coordinating with the appropriate University offices to support compliant research.

CONTACT ORS