# CMMC/CUI Handling Micro-Course Package

A free, reviewable cybersecurity awareness micro-course starter for teams that need to turn CUI handling expectations into practical employee training.

**Audience:** Security awareness leads, GRC teams, compliance managers, L&D teams, MSPs, vCISOs, and contractors supporting CUI/FCI training workflows.

**Use case:** Policy-to-training, CMMC support, LMS-ready cybersecurity awareness, new-hire reinforcement, annual refresher, and targeted remediation after risky data-handling patterns.

**Important review boundary:** This package is not legal advice and does not make an organization compliant. It is designed to support training and documentation workflows when adapted to the organization’s approved policies, systems, contracts, and evidence requirements. Human review is required before publishing.

---

## Course summary

Employees do not need a lecture on every clause in a security framework. They need to know what to do when controlled or sensitive information shows up in normal work: an email attachment, a shared drive, a Teams message, a support ticket, a vendor request, or a public AI tool.

This micro-course teaches one practical decision:

> Before storing, sharing, summarizing, exporting, or discussing CUI or contract-sensitive information, pause and confirm the approved system, approved recipient, approved handling process, and reporting path for uncertainty.

Use this package as a Content Studio by Jericho starter. Replace placeholders with your organization’s approved terms, systems, reporting channels, and policy references before assigning the course.

---

## Learning objectives

By the end of this course, learners should be able to:

1. Recognize common work moments where CUI, FCI, or contract-sensitive information may be mishandled.
2. Choose the approved place to store, share, or discuss sensitive information.
3. Avoid moving sensitive content into unapproved tools, personal accounts, public AI systems, or unsanctioned collaboration spaces.
4. Report uncertainty or suspected mishandling through the approved channel without blame or delay.

---

## Lesson copy

### 1. Sensitive information often appears in ordinary work

CUI and contract-sensitive information do not always arrive with a giant warning label. They may appear in a spreadsheet, engineering note, screenshot, support ticket, proposal, procurement file, email thread, or shared document.

The risk is not only that someone intentionally leaks information. More often, mishandling happens during routine work: saving a file in the wrong folder, forwarding an attachment to the wrong person, pasting text into an unapproved AI tool, or discussing details in a channel that was never approved for that type of information.

The safe habit is simple: when the information may be sensitive, confirm the approved handling path before moving it.

### 2. Know the approved systems

Your organization should define where sensitive information can be stored, shared, discussed, and exported. That may include specific document repositories, ticket systems, encrypted channels, managed devices, approved AI tools, or LMS/reporting systems.

Do not assume a tool is approved because it is convenient, popular, or already used by another team. If the file, message, or request may include CUI, FCI, customer-sensitive information, contract data, export-controlled details, or internal security information, use the approved system or ask before proceeding.

**Placeholder to customize:** Approved storage and collaboration systems: [INSERT APPROVED SYSTEMS]

### 3. Verify recipients and purpose

A recipient can be familiar and still not be authorized for a specific piece of information. Before sharing sensitive material, confirm the business purpose, approved recipient group, and required handling method.

This matters during vendor work, subcontractor coordination, customer support, proposal drafting, audit evidence collection, and internal project handoffs. If the request feels urgent, that is a reason to slow down, not a reason to bypass the process.

**Placeholder to customize:** Approved recipient verification process: [INSERT PROCESS]

### 4. Be careful with AI tools and copy/paste workflows

AI tools can be useful, but they can also create data-handling risk when employees paste sensitive work content into systems that are not approved for that data type.

Before using AI to summarize, rewrite, classify, translate, or analyze work material, check whether the AI tool is approved for that content. If the answer is unclear, do not paste the content. Ask through the approved help channel.

**Placeholder to customize:** Approved AI tools and prohibited data types: [INSERT AI POLICY SUMMARY]

### 5. Report uncertainty early

Reporting uncertainty is not failure. It is part of a healthy security culture. If you think sensitive information may have been stored, sent, discussed, copied, or uploaded in the wrong place, report it through the approved channel.

Early reporting helps the organization understand what happened, limit unnecessary exposure, and improve the process. The goal is to fix the workflow, not shame the learner.

**Placeholder to customize:** Reporting channel: [INSERT REPORTING CHANNEL]

---

## Workplace scenarios

### Scenario 1: The convenient shared drive

A project teammate asks you to upload a spreadsheet from a defense-related customer project to a general department shared drive so the broader team can review it before tomorrow’s meeting.

**Best action:** Pause before uploading. Confirm whether the spreadsheet contains CUI, FCI, contract-sensitive, customer-sensitive, or restricted project information. If it does, use the approved project repository or ask the data owner/security team where it belongs.

**Teaching point:** Convenience is not authorization. The storage location must match the sensitivity of the information.

### Scenario 2: The helpful AI summary

You have a long technical document from a customer project. A public AI tool could summarize it in seconds, and you only need a quick meeting brief.

**Best action:** Do not paste the document into an AI tool unless that tool and use case are approved for the information in the document. Use the approved AI tool or ask through the approved channel.

**Teaching point:** AI use is a data-handling decision. The question is not just whether the tool is helpful. The question is whether the content is allowed there.

### Scenario 3: The familiar subcontractor

A subcontractor you have worked with before asks you to resend a file because they cannot access the project folder. The request comes from a familiar name, but the email address is slightly different from the one normally used.

**Best action:** Verify the recipient and approved sharing method through the normal process before sending anything. If the request is unexpected or the address is different, use a trusted contact method or escalate.

**Teaching point:** Familiarity does not replace recipient verification. Sensitive information should move through approved channels.

---

## Quiz questions with teaching feedback

### Question 1

You are not sure whether a document contains CUI, but it is related to a covered customer project. What should you do before sharing it?

A. Share it normally because there is no visible CUI banner.
B. Upload it to the fastest available folder so the team can review it.
C. Pause and confirm the classification, approved storage location, and approved recipients.
D. Paste it into an AI tool and ask whether it looks sensitive.

**Best answer:** C

**Feedback:** When classification or handling is unclear, pause and verify before moving the content. Banners and labels help, but they are not the only signal. Do not use unapproved AI tools to classify sensitive content unless your policy explicitly allows that workflow.

### Question 2

A manager asks you to send a project file to a vendor immediately. You are unsure whether the vendor is approved for that information. What is the safest next step?

A. Send it because the manager requested it.
B. Verify the approved recipient and sharing method before sending.
C. Send it from a personal account to avoid system delays.
D. Remove the file name and send the attachment anyway.

**Best answer:** B

**Feedback:** Urgency does not remove the need for authorization. Verify the recipient and approved channel first. Personal accounts and informal workarounds can create unnecessary data-handling risk.

### Question 3

Which statement is the safest rule for AI tools at work?

A. If the AI tool is popular, it is approved.
B. It is safe to paste sensitive text if you delete names first.
C. Only use AI tools and prompts that are approved for the type of information you are handling.
D. AI tools are never allowed for any work.

**Best answer:** C

**Feedback:** The safer habit is policy-fit use. Some organizations approve specific AI tools for specific data types and use cases. Do not assume popularity, convenience, or quick redaction makes a tool appropriate for sensitive work content.

### Question 4

You realize you may have uploaded a sensitive project file to the wrong folder. What should you do?

A. Delete it quietly and hope nobody noticed.
B. Report it through the approved channel and follow instructions.
C. Move the file again without telling anyone.
D. Wait until someone asks about it.

**Best answer:** B

**Feedback:** Early reporting helps the organization respond and improve the process. The goal is not blame. The goal is to understand what happened and reduce unnecessary exposure.

---

## Remediation note

If this course follows a simulation, audit finding, help desk pattern, or policy rollout, keep the remediation focused on the missed decision. Good follow-up topics include:

- choosing the correct storage location;
- verifying recipients before sharing;
- recognizing when AI use needs policy review;
- reporting uncertainty quickly;
- checking whether a file or message belongs in an approved system.

Avoid framing remediation as punishment. The learner should leave with a clearer decision path, not a scarlet letter.

---

## LMS packaging guidance

Prepare the course for LMS delivery with:

- Course title: **CMMC/CUI Handling Micro-Course: Work Safely With Sensitive Information**
- Suggested length: 5-7 minutes
- Completion rule: view lesson and answer quiz questions
- Quiz behavior: allow teaching feedback after each answer
- Accessibility support: captions/transcript if converted to video or voiceover
- Export notes: SCORM, xAPI, HTML, or PDF depending on the delivery workflow
- Review record: document security, GRC/compliance, L&D, and legal review where appropriate

Completion records may support training documentation when configured and retained appropriately, but they do not guarantee compliance or prove behavior change.

---

## Content Studio by Jericho prompt

Use this prompt in Content Studio by Jericho to recreate or adapt the course:

> Create a 5-7 minute cybersecurity awareness micro-course for employees who may handle CUI, FCI, customer-sensitive, contract-sensitive, or internal security information. Teach one core decision: before storing, sharing, summarizing, exporting, or discussing sensitive information, confirm the approved system, recipient, handling process, and reporting path. Include learning objectives, concise lesson copy, three realistic workplace scenarios, four quiz questions with teaching feedback, a remediation note, captions/transcript guidance, and LMS-ready export notes. Use plain, respectful language. Do not claim the course makes the organization compliant or prevents incidents. Mark assumptions for human review, including approved systems, reporting channels, AI tool policy, recipient verification, and compliance-sensitive language.

---

## Human review checklist

Before publishing, confirm:

- The course matches current internal policy and contract scope.
- Approved systems, channels, AI tools, and recipient rules are correct.
- Sensitive terms such as CUI, FCI, CDI, export control, and customer data are used accurately for the organization’s context.
- The language avoids compliance guarantees and breach-prevention promises.
- The learner is told what to do when uncertain.
- The course is accessible for the target delivery format.
- The LMS package records the intended completion or quiz data.

---

## Create your own version

Content Studio by Jericho helps security, GRC, and L&D teams create reviewable cybersecurity lessons, quizzes, simulations, remediation content, captions, transcripts, and LMS-ready exports from a prompt or source material.

Start at: https://contentstudio.jerichosecurity.com/campaigns/course-giveaway-cmmc-cui-handling
