Why: The practice's precondition is knowing what information is controlled and where it lives — a data classification staff can apply, discovery of where sensitive content already sits, and data-loss rules pointed at those places. That location knowledge is the substance this requirement wants identified and documented for CUI.
What this does not claim: May partially address the requirement: the practice reaches information location only as far as AI-exposure protection needs it, while the requirement wants CUI locations and their system components documented comprehensively and kept current through changes, whether or not AI is in use. An organization could run this practice well and still lack the component-level CUI location record an assessor asks for.
- Classify data so controlled content is identifiable to people and tooling
- Discover where controlled content sits before sanctioning tools that touch it
- Point data-loss rules at the stores and flows where CUI lives
- The data classification and the stores it was applied to
- Discovery results identifying CUI locations
- Data-loss policy scoped to the identified locations
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06