What is NIST 800-171 Control 3.13.14?
This control ensures that when digital media containing CUI is moved between locations (e.g., via car, mail, or third-party courier), it must be protected in one of two ways:
1. Encrypted using FIPS-validated methods, or
2. Protected with formal physical safeguards, such as:
◦ Locked containers or safes
◦ Controlled, logged transportation processes
◦ Secure courier services with chain-of-custody procedures
Why It Matters
Transporting unprotected media opens the door to:
• Theft or loss of sensitive data
• Accidental access or exposure
• Regulatory or contractual violations
Encryption or strong physical security ensures that even if the device is lost or stolen, CUI stays protected.
How to Implement It
• Always encrypt data on portable drives (e.g., USB, external hard drives) before transport
• Use encryption tools that meet FIPS 140-2 or equivalent
• If using physical safeguards:
◦ Log the transport process and handlers
◦ Use tamper-evident packaging and restricted access
• Document your transport procedures and safeguards in your CUI handling policy
Common Mistakes
• Hand-carrying unencrypted USB drives with CUI
• Using standard postal mail without tracking or encryption
• Assuming password protection is sufficient—it’s not encryption
How Cuick Trac Helps
Cuick Trac supports this control by:
• Eliminating the need to transport CUI in most cases via its cloud-based secure enclave
• Encrypting all stored and transmitted data using FIPS 140-2 validated cryptography
• Providing templates and policies for securely handling CUI during transport
• Supporting hybrid environments with data transfer guidance and tools
With Cuick Trac, your CUI doesn’t just move securely—it rarely needs to move at all.
Final CTA
When CUI travels, protection travels with it. Encrypt it—or secure it physically.
Schedule a Cuick Trac demo and lock down your data in transit—no matter the route.