Sample scope package

Every obligation, traced to a boundary decision.

Unedited output from the ObligationIQ engine, rendered from the scope package. The subject is a fictional fabricator built to produce the findings a real engagement produces — including the two that make this boundary indefensible until they are resolved.

Fictional entity. Demonstration engagement. Not a real organization and not a real assessment.
Engagement
ENG-2026-0042
Source set
377bf777c160496e
Engine
v0.1.0 · ref b3f405ecd9472474

The boundary

An asset is in scope when it holds, processes, or transmits an information type that an obligation in the source set reaches.

In scope

7

assets holding regulated information

Excluded

2

each with a recorded basis

Undetermined

1

cannot be decided on current evidence

Boundary state

not defensible

2 finding(s) place covered information outside required protection. The boundary cannot be defended until they are resolved.

Defensibility here means the scope decisions are traceable and internally consistent. It is not an assessment result and not a compliance determination.

Security category (FIPS 199 high-water mark): C=high · I=moderate · A=low — overall high, driven by ITAR-TD. CLASSIFIED excluded: categorized under its own authority.

AssetDispositionInformation typesBasis
Engineering SharePoint site (TDP library)
M365 commercial tenant
In scopeCDI, CTI, ITAR-TDHolds CDI, CTI, ITAR-TD, reached by DFARS 252.204-7008, DFARS 252.204-7012, DFARS 252.239-7010, 22 CFR 120-130 (ITAR).
Engineering file server (FS-ENG-01)
Chesterfield, VA — on premises
In scopeCDI, CTIHolds CDI, CTI, reached by DFARS 252.204-7008, DFARS 252.204-7012, DFARS 252.239-7010.
CAM programming workstations (4 units, shop floor)
Chesterfield, VA — production floor
In scopeCTIHolds CTI, reached by DFARS 252.204-7012.
Exchange Online (corporate email)
M365 commercial tenant
In scopeCDI, CTIHolds CDI, CTI, reached by DFARS 252.204-7008, DFARS 252.204-7012, DFARS 252.239-7010.
Hosted ERP (production planning)
Vendor-hosted, region not stated
In scopeCDIHolds CDI, reached by DFARS 252.204-7008, DFARS 252.204-7012, DFARS 252.239-7010.
Supplier document exchange portal
EU region (vendor default)
In scopeCDI, CTIHolds CDI, CTI, reached by DFARS 252.204-7008, DFARS 252.204-7012, DFARS 252.239-7010.
Personal cloud drive (engineering manager)
Consumer cloud service
In scopeCTIHolds CTI, reached by DFARS 252.204-7012. Included despite not being a sanctioned location: the information is present regardless of approval.
Quality management system (certificates, calibration)
Chesterfield, VA — on premises
ExcludedHolds no information type reached by an obligation in the source set.
HR and payroll system
Chesterfield, VA — on premises
UndeterminedCannot be determined from current evidence: HR and payroll system declares information types no obligation in the source set reaches: PII.
Public marketing website
Shared hosting provider
ExcludedHolds no information type reached by an obligation in the source set.

Decision model

13 chains, each traced through all seven links.

The clause quote is lifted from the ingested document at the line shown. The first two chains are open; the rest expand.

22 CFR 120-130 (ITAR)ITAR-Controlled Technical Dataconfirmed
  1. Contract clause

    International Traffic in Arms RegulationsTask Order W58RGZ-25-C-0114 / TO-0003 (Army), line 14

    …data whose export is controlled under the International Traffic in Arms Regulations, 22 CFR 120-130. The Contractor shall not disclose, transfer, or otherwise release such tec…

  2. Obligation

    Control access to ITAR-controlled technical data, including preventing release to foreign persons without authorization (a deemed export), and maintain registration and licensing as applicable.

  3. Information type

    ITAR-Controlled Technical DataEXPTCUI specified

    Provisional FIPS 199 impact: C=high · I=moderate · A=low

  4. Classification rationale

    22 CFR 120-130 (ITAR) is incorporated in Task Order W58RGZ-25-C-0114 / TO-0003 (Army) at line 14, establishing an obligation over itar-controlled technical data. The information corresponds to the CUI Registry category Export Controlled (EXPT), which is CUI Specified and carries mandatory dissemination controls. Unauthorized release, including release to a foreign person inside the United States (a deemed export), is a regulatory violation with potential severe or catastrophic consequence, supporting a high confidentiality baseline. Access control is person-based as well as system-based. Organization-defined type derived from the CUI Registry Export Control grouping and 22 CFR 120.10 technical data.

  5. Data location

    Engineering SharePoint site (TDP library)

  6. System / user boundary

    AST-ENG-SP

    Users with access: A. Whitfield, L. Fontaine, R. Okonjo, S. Prakash

    Access restriction: us person or authorized

  7. Required safeguards

    NIST SP 800-171 Rev. 2 (110 requirements)

    Families: 3.1, 3.2, 3.3, 3.4, 3.5, 3.6, 3.7, 3.8, 3.9, 3.10, 3.11, 3.12, 3.13, 3.14

    72-hour cyber incident reporting90-day media preservationForeign-person access control (deemed export)CUI marking and dissemination controls

32 CFR 2002Controlled Unclassified Information (category not yet determined)confirmed
  1. Contract clause

    Controlled Unclassified Information (CUI) ProgramTask Order W58RGZ-25-C-0114 / TO-0003 (Army), line 28

    …and shall be marked, safeguarded, disseminated, and decontrolled in accordance with 32 CFR 2002 and the CUI Registry. 2.2 Deliverables containing controlled technical information…

  2. Obligation

    Mark, safeguard, disseminate, and decontrol CUI in accordance with the CUI Registry category authorities applicable to the information received or generated in performance.

  3. Information type

    Controlled Unclassified Information (category not yet determined)

    Provisional FIPS 199 impact: C=moderate · I=moderate · A=low

  4. Classification rationale

    32 CFR 2002 is incorporated in Task Order W58RGZ-25-C-0114 / TO-0003 (Army) at line 28, establishing an obligation over controlled unclassified information (category not yet determined). Moderate confidentiality is the CUI Basic default under 32 CFR 2002 absent a category authority specifying otherwise. Placeholder type used when a contract establishes CUI obligations but the specific Registry category has not yet been determined. It is a finding, not a classification. The specific Registry categories applicable to this engagement are established elsewhere in this package (CTI, EXPT); this entry carries the CUI Program marking and decontrol obligation rather than an undetermined category.

  5. Data location

    No declared asset holds this information type.

  6. System / user boundary

  7. Required safeguards

    NIST SP 800-171 Rev. 2 (110 requirements)

    Families: 3.1, 3.2, 3.3, 3.4, 3.5, 3.6, 3.7, 3.8, 3.9, 3.10, 3.11, 3.12, 3.13, 3.14

DD Form 254 / 32 CFR 117Classified National Security Informationconfirmed
  1. Contract clause

    Contract Security Classification Specification / NISPOMDD Form 254 for W58RGZ-25-C-0114, line 3

    DEPARTMENT OF DEFENSE CONTRACT SECURITY CLASSIFICATION SPECIFICATION DD FORM 254 CONTRACT NUMBER: W58RGZ-25-C-0114 CONTRACTOR: MERIDIAN FABRICATION & ENGINEERING, INC. (…

  2. Obligation

    Safeguard classified information per the NISPOM and the DD Form 254, including clearance requirements and any FOCI mitigation.

  3. Information type

    Classified National Security Information

  4. Classification rationale

    DD Form 254 / 32 CFR 117 is incorporated in DD Form 254 for W58RGZ-25-C-0114 at line 3, establishing an obligation over classified national security information. Out of scope. Presence is recorded because it constrains the unclassified boundary and the facility's clearance obligations. Recorded for boundary purposes only. Classified information is categorized and protected under the NISPOM and applicable security classification guidance, not under FIPS 199 or this engine.

  5. Data location

    No declared asset holds this information type.

  6. System / user boundary

  7. Required safeguards

    NISPOM (32 CFR 117)

DFARS 252.204-7008Covered Defense Informationconfirmed
  1. Contract clause

    Compliance with Safeguarding Covered Defense Information ControlsPrime Contract SPE4A7-26-D-0031 (DLA Aviation), line 42

    …contracts for Commercial Products and Commercial Services DFARS 252.204-7008 Compliance with Safeguarding Covered Defense Information Contro…

  2. Obligation

    Represent that the offeror will implement NIST SP 800-171, and identify any requirement not implemented at time of award for contracting officer consideration.

  3. Information type

    Covered Defense InformationCTICUI specified

    Provisional FIPS 199 impact: C=moderate · I=moderate · A=low

  4. Classification rationale

    DFARS 252.204-7008 is incorporated in Prime Contract SPE4A7-26-D-0031 (DLA Aviation) at line 42, establishing an obligation over covered defense information. The information corresponds to the CUI Registry category Controlled Technical Information (CTI), which is CUI Specified and carries mandatory dissemination controls. The clause requires NIST SP 800-171, which corresponds to a moderate confidentiality expectation for nonfederal systems. Integrity is moderate because the information supports defense system design and sustainment decisions. Contract-defined type from DFARS 252.204-7012, which reaches controlled technical information and other CUI marked or otherwise identified in the contract.

  5. Data location

    Engineering SharePoint site (TDP library), Engineering file server (FS-ENG-01), Exchange Online (corporate email), Hosted ERP (production planning), Supplier document exchange portal

  6. System / user boundary

    AST-ENG-SP, AST-FILE-01, AST-EMAIL, AST-ERP, AST-SUPPLIER-PORTAL

    Users with access: A. Whitfield, L. Fontaine, M. Delgado, R. Okonjo, S. Prakash, T. Brennan

  7. Required safeguards

    NIST SP 800-171 Rev. 2 (110 requirements)

    Families: 3.1, 3.2, 3.3, 3.4, 3.5, 3.6, 3.7, 3.8, 3.9, 3.10, 3.11, 3.12, 3.13, 3.14

    FedRAMP Moderate equivalent for external cloud services72-hour cyber incident reporting90-day media preservationUnited States data residencyCUI marking and dissemination controls

DFARS 252.204-7012Covered Defense Informationconfirmed
  1. Contract clause

    Safeguarding Covered Defense Information and Cyber Incident ReportingPrime Contract SPE4A7-26-D-0031 (DLA Aviation), line 25

    …s contract. The Contractor shall safeguard such information in accordance with DFARS 252.204-7012. H.2 The Contractor shall ensure that any subcontractor whose performance will inv…

  2. Obligation

    Provide adequate security for covered defense information on covered contractor information systems by implementing NIST SP 800-171; report cyber incidents to DoD within 72 hours; preserve and protect affected media for 90 days; use cloud services at a FedRAMP Moderate equivalent baseline; flow the clause down to subcontractors.

    Flows down to applicable subcontracts.

  3. Information type

    Covered Defense InformationCTICUI specified

    Provisional FIPS 199 impact: C=moderate · I=moderate · A=low

  4. Classification rationale

    DFARS 252.204-7008 is incorporated in Prime Contract SPE4A7-26-D-0031 (DLA Aviation) at line 42, establishing an obligation over covered defense information. The information corresponds to the CUI Registry category Controlled Technical Information (CTI), which is CUI Specified and carries mandatory dissemination controls. The clause requires NIST SP 800-171, which corresponds to a moderate confidentiality expectation for nonfederal systems. Integrity is moderate because the information supports defense system design and sustainment decisions. Contract-defined type from DFARS 252.204-7012, which reaches controlled technical information and other CUI marked or otherwise identified in the contract.

  5. Data location

    Engineering SharePoint site (TDP library), Engineering file server (FS-ENG-01), Exchange Online (corporate email), Hosted ERP (production planning), Supplier document exchange portal

  6. System / user boundary

    AST-ENG-SP, AST-FILE-01, AST-EMAIL, AST-ERP, AST-SUPPLIER-PORTAL

    Users with access: A. Whitfield, L. Fontaine, M. Delgado, R. Okonjo, S. Prakash, T. Brennan

  7. Required safeguards

    NIST SP 800-171 Rev. 2 (110 requirements)

    Families: 3.1, 3.2, 3.3, 3.4, 3.5, 3.6, 3.7, 3.8, 3.9, 3.10, 3.11, 3.12, 3.13, 3.14

    FedRAMP Moderate equivalent for external cloud services72-hour cyber incident reporting90-day media preservationUnited States data residencyCUI marking and dissemination controls

DFARS 252.204-7012Controlled Technical Informationconfirmed
  1. Contract clause

    Safeguarding Covered Defense Information and Cyber Incident ReportingPrime Contract SPE4A7-26-D-0031 (DLA Aviation), line 25

    …s contract. The Contractor shall safeguard such information in accordance with DFARS 252.204-7012. H.2 The Contractor shall ensure that any subcontractor whose performance will inv…

  2. Obligation

    Provide adequate security for covered defense information on covered contractor information systems by implementing NIST SP 800-171; report cyber incidents to DoD within 72 hours; preserve and protect affected media for 90 days; use cloud services at a FedRAMP Moderate equivalent baseline; flow the clause down to subcontractors.

    Flows down to applicable subcontracts.

  3. Information type

    Controlled Technical InformationCTICUI specified

    Provisional FIPS 199 impact: C=moderate · I=moderate · A=low

  4. Classification rationale

    DFARS 252.204-7012 is incorporated in Prime Contract SPE4A7-26-D-0031 (DLA Aviation) at line 25, establishing an obligation over controlled technical information. The information corresponds to the CUI Registry category Controlled Technical Information (CTI), which is CUI Specified and carries mandatory dissemination controls. Unauthorized disclosure of technical data with military application causes serious adverse effect on national security interests, and the category carries mandatory dissemination controls, supporting a moderate confidentiality baseline. Integrity is moderate because corrupted technical data propagates into manufactured articles. Availability is low where the contractor is not the authoritative custodian of record. Organization-defined type derived from the CUI Registry Defense grouping. The Volume II catalog has no contractor-held CTI entry; Volume I's method is applied to the category authority instead.

  5. Data location

    Engineering SharePoint site (TDP library), Engineering file server (FS-ENG-01), CAM programming workstations (4 units, shop floor), Exchange Online (corporate email), Supplier document exchange portal, Personal cloud drive (engineering manager)

  6. System / user boundary

    AST-ENG-SP, AST-FILE-01, AST-CAM-WS, AST-EMAIL, AST-SUPPLIER-PORTAL, AST-SHADOW-DRIVE

    Users with access: A. Whitfield, L. Fontaine, M. Delgado, R. Okonjo, S. Prakash, T. Brennan

  7. Required safeguards

    NIST SP 800-171 Rev. 2 (110 requirements)

    Families: 3.1, 3.2, 3.3, 3.4, 3.5, 3.6, 3.7, 3.8, 3.9, 3.10, 3.11, 3.12, 3.13, 3.14

    FedRAMP Moderate equivalent for external cloud services72-hour cyber incident reporting90-day media preservationUnited States data residencyCUI marking and dissemination controls

DFARS 252.204-7019No information typeconfirmed
  1. Contract clause

    Notice of NIST SP 800-171 DoD Assessment RequirementsPrime Contract SPE4A7-26-D-0031 (DLA Aviation), line 46

    …ered Defense Information and Cyber Incident Reporting DFARS 252.204-7019 Notice of NIST SP 800-171 DoD Assessment Requirements DFAR…

  2. Obligation

    Maintain a current NIST SP 800-171 DoD Assessment, not more than three years old, with results posted in SPRS as a condition of award.

  3. Information type

  4. Classification rationale

    Assessment or reporting obligation — no information type of its own; it attaches to the boundary established by other clauses.

  5. Data location

    Assessment or reporting obligation — no information type of its own; it attaches to the boundary established by other clauses.

  6. System / user boundary

  7. Required safeguards

    Assessment or reporting obligation — no information type of its own; it attaches to the boundary established by other clauses.

DFARS 252.204-7020No information typeconfirmed
  1. Contract clause

    NIST SP 800-171 DoD Assessment RequirementsPrime Contract SPE4A7-26-D-0031 (DLA Aviation), line 48

    …Notice of NIST SP 800-171 DoD Assessment Requirements DFARS 252.204-7020 NIST SP 800-171 DoD Assessment Requirements DFARS 252.239-7010 Cloud Computing Ser…

  2. Obligation

    Provide the Government access to facilities, systems, and personnel for Medium or High assessments, and ensure applicable subcontractors have a current assessment in SPRS before subcontract award.

    Flows down to applicable subcontracts.

  3. Information type

  4. Classification rationale

    Assessment or reporting obligation — no information type of its own; it attaches to the boundary established by other clauses.

  5. Data location

    Assessment or reporting obligation — no information type of its own; it attaches to the boundary established by other clauses.

  6. System / user boundary

  7. Required safeguards

    Assessment or reporting obligation — no information type of its own; it attaches to the boundary established by other clauses.

DFARS 252.204-7021Controlled Unclassified Information (category not yet determined)confirmed
  1. Contract clause

    Contractor Compliance with the Cybersecurity Maturity Model Certification Level RequirementTask Order W58RGZ-25-C-0114 / TO-0003 (Army), line 40

    …ents affecting covered defense information within 72 hours of discovery. 3.2 DFARS 252.204-7021 applies. The Contractor shall maintain the Cybersecurity Maturity Model Certificatio…

  2. Obligation

    Achieve and maintain the CMMC level specified in the contract for all information systems used in performance, and flow the requirement down to applicable subcontracts.

    Flows down to applicable subcontracts.

  3. Information type

    Controlled Unclassified Information (category not yet determined)

    Provisional FIPS 199 impact: C=moderate · I=moderate · A=low

  4. Classification rationale

    32 CFR 2002 is incorporated in Task Order W58RGZ-25-C-0114 / TO-0003 (Army) at line 28, establishing an obligation over controlled unclassified information (category not yet determined). Moderate confidentiality is the CUI Basic default under 32 CFR 2002 absent a category authority specifying otherwise. Placeholder type used when a contract establishes CUI obligations but the specific Registry category has not yet been determined. It is a finding, not a classification. The specific Registry categories applicable to this engagement are established elsewhere in this package (CTI, EXPT); this entry carries the CUI Program marking and decontrol obligation rather than an undetermined category.

  5. Data location

    No declared asset holds this information type.

  6. System / user boundary

  7. Required safeguards

    CMMC (800-171 based at Level 2)

    Families: 3.1, 3.2, 3.3, 3.4, 3.5, 3.6, 3.7, 3.8, 3.9, 3.10, 3.11, 3.12, 3.13, 3.14

DFARS 252.204-7021Federal Contract Informationconfirmed
  1. Contract clause

    Contractor Compliance with the Cybersecurity Maturity Model Certification Level RequirementTask Order W58RGZ-25-C-0114 / TO-0003 (Army), line 40

    …ents affecting covered defense information within 72 hours of discovery. 3.2 DFARS 252.204-7021 applies. The Contractor shall maintain the Cybersecurity Maturity Model Certificatio…

  2. Obligation

    Achieve and maintain the CMMC level specified in the contract for all information systems used in performance, and flow the requirement down to applicable subcontracts.

    Flows down to applicable subcontracts.

  3. Information type

    Federal Contract Information

    Provisional FIPS 199 impact: C=low · I=low · A=low

  4. Classification rationale

    DFARS 252.204-7021 is incorporated in Task Order W58RGZ-25-C-0114 / TO-0003 (Army) at line 40, establishing an obligation over federal contract information. Information not intended for public release that is provided by or generated for the Government under contract. Unauthorized disclosure causes limited adverse effect, supporting a low baseline. FCI is the floor beneath any CUI determination, not an alternative to it. Contract-defined type from FAR 52.204-21. FCI is not CUI; it carries the fifteen basic safeguarding requirements rather than 800-171.

  5. Data location

    No declared asset holds this information type.

  6. System / user boundary

  7. Required safeguards

    CMMC (800-171 based at Level 2)

    Families: 3.1, 3.2, 3.3, 3.4, 3.5, 3.6, 3.7, 3.8, 3.9, 3.10, 3.11, 3.12, 3.13, 3.14

DFARS 252.239-7010Covered Defense Informationconfirmed
  1. Contract clause

    Cloud Computing ServicesPrime Contract SPE4A7-26-D-0031 (DLA Aviation), line 49

    …uirements DFARS 252.204-7020 NIST SP 800-171 DoD Assessment Requirements DFARS 252.239-7010 Cloud Computing Services SECTION J — LIST OF ATTACHMENTS Attachment 1 Quality…

  2. Obligation

    Maintain Government data within the United States or outlying areas unless otherwise authorized, and meet the required cloud security requirements and incident reporting terms.

  3. Information type

    Covered Defense InformationCTICUI specified

    Provisional FIPS 199 impact: C=moderate · I=moderate · A=low

  4. Classification rationale

    DFARS 252.204-7008 is incorporated in Prime Contract SPE4A7-26-D-0031 (DLA Aviation) at line 42, establishing an obligation over covered defense information. The information corresponds to the CUI Registry category Controlled Technical Information (CTI), which is CUI Specified and carries mandatory dissemination controls. The clause requires NIST SP 800-171, which corresponds to a moderate confidentiality expectation for nonfederal systems. Integrity is moderate because the information supports defense system design and sustainment decisions. Contract-defined type from DFARS 252.204-7012, which reaches controlled technical information and other CUI marked or otherwise identified in the contract.

  5. Data location

    Engineering SharePoint site (TDP library), Engineering file server (FS-ENG-01), Exchange Online (corporate email), Hosted ERP (production planning), Supplier document exchange portal

  6. System / user boundary

    AST-ENG-SP, AST-FILE-01, AST-EMAIL, AST-ERP, AST-SUPPLIER-PORTAL

    Users with access: A. Whitfield, L. Fontaine, M. Delgado, R. Okonjo, S. Prakash, T. Brennan

  7. Required safeguards

    NIST SP 800-171 Rev. 2 (110 requirements)

    Families: 3.1, 3.2, 3.3, 3.4, 3.5, 3.6, 3.7, 3.8, 3.9, 3.10, 3.11, 3.12, 3.13, 3.14

    FedRAMP Moderate equivalent for external cloud services72-hour cyber incident reporting90-day media preservationUnited States data residencyCUI marking and dissemination controls

FAR 52.204-21Federal Contract Informationconfirmed
  1. Contract clause

    Basic Safeguarding of Covered Contractor Information SystemsPrime Contract SPE4A7-26-D-0031 (DLA Aviation), line 35

    …TION I — CONTRACT CLAUSES The following clauses are incorporated by reference: FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems (NOV…

  2. Obligation

    Apply the fifteen basic safeguarding requirements to covered contractor information systems that process, store, or transmit Federal contract information.

    Flows down to applicable subcontracts.

  3. Information type

    Federal Contract Information

    Provisional FIPS 199 impact: C=low · I=low · A=low

  4. Classification rationale

    DFARS 252.204-7021 is incorporated in Task Order W58RGZ-25-C-0114 / TO-0003 (Army) at line 40, establishing an obligation over federal contract information. Information not intended for public release that is provided by or generated for the Government under contract. Unauthorized disclosure causes limited adverse effect, supporting a low baseline. FCI is the floor beneath any CUI determination, not an alternative to it. Contract-defined type from FAR 52.204-21. FCI is not CUI; it carries the fifteen basic safeguarding requirements rather than 800-171.

  5. Data location

    No declared asset holds this information type.

  6. System / user boundary

  7. Required safeguards

    FAR 52.204-21 basic safeguarding (fifteen requirements)

    Families: 3.1, 3.5, 3.8, 3.10, 3.13, 3.14

FAR 52.204-25No information typeconfirmed
  1. Contract clause

    Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or EquipmentPrime Contract SPE4A7-26-D-0031 (DLA Aviation), line 37

    …arding of Covered Contractor Information Systems (NOV 2021) FAR 52.204-25 Prohibition on Contracting for Certain Telecommunications and Vide…

  2. Obligation

    Do not use or provide covered telecommunications or video surveillance equipment or services as a substantial or essential component of any system.

    Flows down to applicable subcontracts.

  3. Information type

  4. Classification rationale

    Prohibition — applies organization-wide rather than to a specific information type.

  5. Data location

    Prohibition — applies organization-wide rather than to a specific information type.

  6. System / user boundary

  7. Required safeguards

    Prohibition — applies organization-wide rather than to a specific information type.

Findings

Under-scoping and over-scoping are both reported.

Nothing here is applied silently. An asset the organization treats as out of scope while it holds covered information is a finding; so is an asset carried in scope that holds nothing regulated.

  1. 01

    Engineering SharePoint site (TDP library)

    criticalunder scope

    L. Fontaine (Senior Design Engineer (contract)) has access to ITAR-TD on Engineering SharePoint site (TDP library) and is recorded as a foreign person.

    Release of controlled technical data to a foreign person is an export requiring authorization. Restrict access or obtain a license, agreement, or exemption, and record the determination.

  2. 02

    Supplier document exchange portal

    criticalunder scope

    Supplier document exchange portal processes CDI, CTI with data residency recorded as eu.

    Covered defense information under DFARS 252.239-7010 must remain within the United States or outlying areas absent authorization.

  3. 03

    Tidewater Managed IT

    highunder scope

    Tidewater Managed IT participates in performance and no executed flow-down is on record.

    Execute the required flow-down or document why the provider does not handle covered information.

  4. 04

    Engineering SharePoint site (TDP library)

    highopen question

    S. Prakash has access to ITAR-TD on Engineering SharePoint site (TDP library) and person status is undetermined.

    Determine US-person status before relying on this access being authorized. Undetermined is not a yes.

  5. 05

    Hosted ERP (production planning)

    highopen question

    Hosted ERP (production planning) processes CDI and its data residency is not established.

    Confirm the service's data location and its FedRAMP Moderate equivalence before treating this path as compliant.

  6. 06

    Personal cloud drive (engineering manager)

    highopen question

    Personal cloud drive (engineering manager) processes CTI and its data residency is not established.

    Confirm the service's data location and its FedRAMP Moderate equivalence before treating this path as compliant.

  7. 07

    Personal cloud drive (engineering manager)

    highunder scope

    Personal cloud drive (engineering manager) holds CTI but is not an organizationally sanctioned location for it.

    Either bring the asset inside the boundary and apply the safeguards, or remove the information and document the removal. An unsanctioned location holding covered information is an unsupported exclusion.

  8. 08

    Exchange Online (corporate email)

    mediumopen question

    Exchange Online (corporate email) declares information types no obligation in the source set reaches: PROPIN.

    Either the source set is incomplete or the declaration is wrong. Resolve before relying on this boundary.

  9. 09

    Hosted ERP (production planning)

    mediumopen question

    Hosted ERP (production planning) declares information types no obligation in the source set reaches: PROPIN.

    Either the source set is incomplete or the declaration is wrong. Resolve before relying on this boundary.

  10. 10

    HR and payroll system

    mediumopen question

    HR and payroll system declares information types no obligation in the source set reaches: PII.

    Either the source set is incomplete or the declaration is wrong. Resolve before relying on this boundary.

  11. 11

    Public marketing website

    informationalover scope

    Public marketing website holds no information type that any obligation in the source set reaches.

    Excluding this asset is supportable on the current evidence. Record the exclusion and its basis rather than leaving it unstated.

  12. 12

    Quality management system (certificates, calibration)

    informationalover scope

    Quality management system (certificates, calibration) holds no information type that any obligation in the source set reaches.

    Excluding this asset is supportable on the current evidence. Record the exclusion and its basis rather than leaving it unstated.

Protection roadmap

Protect what the obligations require. Do not extend the boundary without a documented reason.

Every action traces to a finding, an unresolved question, a boundary decision, or a stated assumption. The roadmap is derived, not authored.

P12Covered information is outside required protection.
P27A missing determination blocks a defensible boundary.
P310Safeguards to apply across the established boundary.
P43Exclusions and assumptions to document and re-test.
  1. P1

    Release of controlled technical data to a foreign person is an export requiring authorization.

    Release of controlled technical data to a foreign person is an export requiring authorization. Restrict access or obtain a license, agreement, or exemption, and record the determination.

    because: L. Fontaine (Senior Design Engineer (contract)) has access to ITAR-TD on Engineering SharePoint site (TDP library) and is recorded as a foreign person. · traces to MAP-DEEMED-EXPORT::AST-ENG-SP

  2. P1

    Covered defense information under DFARS 252.

    Covered defense information under DFARS 252.239-7010 must remain within the United States or outlying areas absent authorization.

    because: Supplier document exchange portal processes CDI, CTI with data residency recorded as eu. · traces to MAP-RESIDENCY-FOREIGN::AST-SUPPLIER-PORTAL

  3. P2

    Execute the required flow-down or document why the provider does not handle covered information.

    Execute the required flow-down or document why the provider does not handle covered information.

    because: Tidewater Managed IT participates in performance and no executed flow-down is on record. · traces to MAP-FLOWDOWN-MISSING::PRV-MSP

  4. P2

    Determine US-person status before relying on this access being authorized.

    Determine US-person status before relying on this access being authorized. Undetermined is not a yes.

    because: S. Prakash has access to ITAR-TD on Engineering SharePoint site (TDP library) and person status is undetermined. · traces to MAP-PERSON-STATUS-UNKNOWN::AST-ENG-SP

  5. P2

    Confirm the service's data location and its FedRAMP Moderate equivalence before treating this path as compliant.

    Confirm the service's data location and its FedRAMP Moderate equivalence before treating this path as compliant.

    because: Hosted ERP (production planning) processes CDI and its data residency is not established. · traces to MAP-RESIDENCY-UNKNOWN::AST-ERP

  6. P2

    Confirm the service's data location and its FedRAMP Moderate equivalence before treating this path as compliant.

    Confirm the service's data location and its FedRAMP Moderate equivalence before treating this path as compliant.

    because: Personal cloud drive (engineering manager) processes CTI and its data residency is not established. · traces to MAP-RESIDENCY-UNKNOWN::AST-SHADOW-DRIVE

  7. P2

    Either bring the asset inside the boundary and apply the safeguards, or remove the information and document the removal.

    Either bring the asset inside the boundary and apply the safeguards, or remove the information and document the removal. An unsanctioned location holding covered information is an unsupported exclusion.

    because: Personal cloud drive (engineering manager) holds CTI but is not an organizationally sanctioned location for it. · traces to MAP-UNSANCTIONED::AST-SHADOW-DRIVE

  8. P2

    Which CMMC level does the contract require?

    Obtain the required level from the solicitation or award section that specifies it.

    because: DFARS 252.204-7021 is present but no level is stated in the ingested documents. · traces to UNRESOLVED-CMMC-LEVEL

  9. P2

    What is the export classification of the technical data?

    Obtain the commodity jurisdiction or classification determination from the program or the data owner.

    because: Export-control obligations are present but the source set records no USML category or ECCN. · traces to UNRESOLVED-EXPORT-CLASSIFICATION

  10. P3

    FedRAMP Moderate equivalent for external cloud services

    An external cloud service provider that processes, stores, or transmits covered defense information must meet security requirements equivalent to the FedRAMP Moderate baseline.

    because: Required by DFARS-252.204-7012. · traces to CLOUD-FEDRAMP-MOD

  11. P3

    CUI marking and dissemination controls

    Apply CUI banner and portion markings, limited dissemination controls where directed by the category authority, and decontrol procedures.

    because: Required by CFR-32-2002. · traces to CUI-MARKING

  12. P3

    United States data residency

    Government data and Government-related data must remain within the United States or outlying areas unless otherwise authorized.

    because: Required by DFARS-252.239-7010. · traces to DATA-RESIDENCY-US

  13. P3

    Foreign-person access control (deemed export)

    Release of controlled technical data to a foreign person, including within the United States, is an export requiring authorization. Applies to access by employees, contractors, and service providers.

    because: Required by CFR-22-120. · traces to DEEMED-EXPORT

  14. P3

    72-hour cyber incident reporting

    Rapidly report cyber incidents affecting covered defense information or affected systems to DoD within 72 hours of discovery.

    because: Required by DFARS-252.204-7012. · traces to INCIDENT-72H

  15. P3

    Either the source set is incomplete or the declaration is wrong.

    Either the source set is incomplete or the declaration is wrong. Resolve before relying on this boundary.

    because: Exchange Online (corporate email) declares information types no obligation in the source set reaches: PROPIN. · traces to MAP-TYPE-NOT-CLASSIFIED::AST-EMAIL

  16. P3

    Either the source set is incomplete or the declaration is wrong.

    Either the source set is incomplete or the declaration is wrong. Resolve before relying on this boundary.

    because: Hosted ERP (production planning) declares information types no obligation in the source set reaches: PROPIN. · traces to MAP-TYPE-NOT-CLASSIFIED::AST-ERP

  17. P3

    Either the source set is incomplete or the declaration is wrong.

    Either the source set is incomplete or the declaration is wrong. Resolve before relying on this boundary.

    because: HR and payroll system declares information types no obligation in the source set reaches: PII. · traces to MAP-TYPE-NOT-CLASSIFIED::AST-HR

  18. P3

    90-day media preservation

    Preserve and protect images of known affected information systems for at least 90 days from incident submission.

    because: Required by DFARS-252.204-7012. · traces to MEDIA-90D

  19. P3

    Apply NIST SP 800-171 Rev. 2 (110 requirements) across 7 in-scope asset(s).

    14 control families apply. 10 are boundary-defining (3.1, 3.10, 3.13, 3.14, 3.3, 3.4, 3.5, 3.7, 3.8, 3.9) and should be implemented first: they determine whether the boundary holds, and segmentation decisions made here are what make a narrower scope supportable.

    because: The obligations in the source set invoke this baseline. · traces to decision_model.required_safeguards

  20. P4

    Test: The declared data estate is complete.

    Reconcile the inventory against discovery tooling and interview.

    because: An asset absent from the inventory cannot be scoped. Completeness is the organization's assertion. · traces to ASSUME-INVENTORY-COMPLETE

  21. P4

    Test: 1 asset(s) remain undetermined and are not counted in the boundary either way.

    Resolve each open item, then re-run.

    because: Treating an undetermined asset as excluded is an unsupported exclusion. · traces to ASSUME-NO-UNDETERMINED-EXPOSURE

  22. P4

    Record the supportable exclusions with their basis.

    2 asset(s) hold no information type reached by the source set. Documenting each exclusion and its basis is what makes a narrower boundary defensible rather than merely asserted.

    because: An undocumented exclusion reads as an oversight on review. · traces to scope.out_of_scope_assets

Open items and assumptions

What the boundary rests on that was not proven.

Open items (12)

  • critical L. Fontaine (Senior Design Engineer (contract)) has access to ITAR-TD on Engineering SharePoint site (TDP library) and is recorded as a foreign person.
    Release of controlled technical data to a foreign person is an export requiring authorization. Restrict access or obtain a license, agreement, or exemption, and record the determination.
  • critical Supplier document exchange portal processes CDI, CTI with data residency recorded as eu.
    Covered defense information under DFARS 252.239-7010 must remain within the United States or outlying areas absent authorization.
  • high Tidewater Managed IT participates in performance and no executed flow-down is on record.
    Execute the required flow-down or document why the provider does not handle covered information.
  • high S. Prakash has access to ITAR-TD on Engineering SharePoint site (TDP library) and person status is undetermined.
    Determine US-person status before relying on this access being authorized. Undetermined is not a yes.
  • high Hosted ERP (production planning) processes CDI and its data residency is not established.
    Confirm the service's data location and its FedRAMP Moderate equivalence before treating this path as compliant.
  • high Personal cloud drive (engineering manager) processes CTI and its data residency is not established.
    Confirm the service's data location and its FedRAMP Moderate equivalence before treating this path as compliant.
  • high Personal cloud drive (engineering manager) holds CTI but is not an organizationally sanctioned location for it.
    Either bring the asset inside the boundary and apply the safeguards, or remove the information and document the removal. An unsanctioned location holding covered information is an unsupported exclusion.
  • high Which CMMC level does the contract require?
    Obtain the required level from the solicitation or award section that specifies it.
  • high What is the export classification of the technical data?
    Obtain the commodity jurisdiction or classification determination from the program or the data owner.
  • medium Exchange Online (corporate email) declares information types no obligation in the source set reaches: PROPIN.
    Either the source set is incomplete or the declaration is wrong. Resolve before relying on this boundary.
  • medium Hosted ERP (production planning) declares information types no obligation in the source set reaches: PROPIN.
    Either the source set is incomplete or the declaration is wrong. Resolve before relying on this boundary.
  • medium HR and payroll system declares information types no obligation in the source set reaches: PII.
    Either the source set is incomplete or the declaration is wrong. Resolve before relying on this boundary.

Assumptions

  • The declared data estate is complete.
    An asset absent from the inventory cannot be scoped. Completeness is the organization's assertion.
  • 1 asset(s) remain undetermined and are not counted in the boundary either way.
    Treating an undetermined asset as excluded is an unsupported exclusion.

Evidence

27 decision records, all pending review.

Every record is in state 'pending_review'. The engine produces the basis for a decision; an authorized owner makes and records the decision.

RecordDecisionOwnerReview
22 CFR 120-130 (ITAR) — International Traffic in Arms Regulations
DR-OB-CFR-22-120
Obligation established at status 'confirmed'.Contracts manager12 mo
32 CFR 2002 — Controlled Unclassified Information (CUI) Program
DR-OB-CFR-32-2002
Obligation established at status 'confirmed'.Contracts manager12 mo
DD Form 254 / 32 CFR 117 — Contract Security Classification Specification / NISPOM
DR-OB-DD-254
Obligation established at status 'confirmed'.Contracts manager12 mo
DFARS 252.204-7008 — Compliance with Safeguarding Covered Defense Information Controls
DR-OB-DFARS-252.204-7008
Obligation established at status 'confirmed'.Contracts manager12 mo
DFARS 252.204-7012 — Safeguarding Covered Defense Information and Cyber Incident Reporting
DR-OB-DFARS-252.204-7012
Obligation established at status 'confirmed'.Contracts manager12 mo
DFARS 252.204-7019 — Notice of NIST SP 800-171 DoD Assessment Requirements
DR-OB-DFARS-252.204-7019
Obligation established at status 'confirmed'.Contracts manager12 mo
DFARS 252.204-7020 — NIST SP 800-171 DoD Assessment Requirements
DR-OB-DFARS-252.204-7020
Obligation established at status 'confirmed'.Contracts manager12 mo
DFARS 252.204-7021 — Contractor Compliance with the Cybersecurity Maturity Model Certification Level Requirement
DR-OB-DFARS-252.204-7021
Obligation established at status 'confirmed'.Contracts manager12 mo
DFARS 252.239-7010 — Cloud Computing Services
DR-OB-DFARS-252.239-7010
Obligation established at status 'confirmed'.Contracts manager12 mo
FAR 52.204-21 — Basic Safeguarding of Covered Contractor Information Systems
DR-OB-FAR-52.204-21
Obligation established at status 'confirmed'.Contracts manager12 mo
FAR 52.204-25 — Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment
DR-OB-FAR-52.204-25
Obligation established at status 'confirmed'.Contracts manager12 mo
Covered Defense Information (CTI)
DR-CL-CDI
Information type CDI applies; provisional impact C=moderate, I=moderate, A=low.Information owner (with security concurrence)12 mo

Showing 12 of 27 records. Each carries source materials, rationale, authority, owner, state, review cadence.

Stated limitations

Carried on every package.

  • Scoping decisions, not a compliance determination or assessment result.
  • Obligation status reflects what the ingested source set contains; a clause absent from the source set is not evidence of its absence from the contract.
  • The data estate is a declaration by the organization; completeness is asserted, not verified by this engine.
  • No CUI marking, export classification, CMMC, or FOCI determination is rendered. Decision records are produced pending review by an authorized owner.

Run this against your own contracts and systems.