Skip to content

ONGOING CUI MONITORING

Keep Your CUI Picture Current

CUI environments change. New files are created, attachments are forwarded, projects move, repositories change, and users interact with information in new ways.

Teramis uses recurring scans to help organizations identify new or moved CUI, surface possible spillage, and compare the current CUI footprint with the boundary they expect to maintain.


Establish the baseline. Monitor what changes.

DISCOVERY IS A STARTING POINT, NOT A FINISH LINE

A Point-in-Time Boundary Can Become Outdated

An initial discovery and validation effort establishes a baseline. Normal business activity begins changing that baseline immediately.

CUI may appear in a new repository, move outside an approved location, return to a legacy system, or arrive through everyday collaboration.

Ongoing monitoring helps teams see those changes instead of assuming the original picture is still accurate.

Trusted by leading companies

HOW ONGOING MONITORING WORKS

Compare the Current Environment With a Known Baseline

1. Establish a baseline

Begin with discovery and validated CUI findings.

2. Re-scan approved sources

Run recurring scans based on the organization's monitoring strategy.

3. Compare findings

Identify what is new, changed, moved, or outside expected locations.

4. Review exceptions

Provide the relevant findings to authorized teams for investigation and action.

Monitoring frequency should reflect how quickly a repository changes, its role in CUI workflows, and the organization's operational requirements. Teramis should not prescribe one cadence for every environment.

Find

Discover CUI across approved Microsoft 365 environments, file systems, email, endpoints, CAD files, PDFs, scanned documents, archives, engineering repositories, and other supported sources. 

 Explore CUI Discovery 

Prove

Validate findings and produce evidence that helps executives, CMMC advisors, compliance teams, and assessors understand whether the documented boundary matches the actual environment. 

 Explore Evidence and Validation 

Monitor

Run recurring scans to identify new CUI, movement, spillage, and boundary drift before the next assessment, annual affirmation, prime contractor request, or internal review. 

 Explore Continuous Monitoring 

WHAT TERAMIS HELPS SURFACE

Focus on the Changes That Need Attention

Recurring monitoring can help identify:

New CUI findings

Content detected after the previous scan.

Location changes

CUI appearing in a different system, repository, or folder.

Possible spillage

Findings outside expected or approved CUI locations.

Boundary drift

Changes that may indicate the documented environment needs review.

Monitoring history

A record that helps teams compare findings across scan cycles.

Microsoft 365

  • SharePoint

  • OneDrive

  • Exchange

  • Supported Microsoft 365 repositories 

File Systems & Endpoints

  • Network file shares

  • Local and distributed endpoints

  • Legacy repositories

  • Project and engineering folders 

Compelx File Types

  • CAD and engineering files
    PDFs

  • Images and scanned documents

  • Email and attachments

  • Archives

  • Structured and unstructured files 

BETTER TOGETHER WITH YOUR EXISTING STACK 

Microsoft Purview

Use labels and compliance workflows with stronger CUI discovery evidence. 

Varonis

Support access governance with clearer visibility into where CUI exists. 

Forcepoint and DLP Tools

Strengthen enforcement strategies by starting with better CUI ground truth.

GRC & Evidence Binders

Connect documentation, control evidence, and boundary decisions to the actual CUI footprint.

CUI DISCOVERY FOR HIGH-STAKES DECISIONS

One Evidence Layer. Multiple CMMC and Risk Use Cases. 

CMMC Scoping

Identify where CUI actually exists before defining the systems, users, repositories, and controls that belong inside the CMMC boundary.

CUI Boundary Validation

Compare the documented boundary with the actual data environment and identify exceptions that require review or customer action.

CUI Migration Support

Identify and report the files, locations, and findings administrators need when planning customer-led movement into approved environments.

Ongoing CUI Spillage Management

Run recurring scans to identify CUI that appears outside approved locations as people, files, systems, and business processes change.

Post-Breach CUI Impact Assessment

Examine affected systems and repositories to help determine whether CUI may have existed within the impacted environment.

Supply Chain and M&A Risk Review

Evaluate whether the actual CUI footprint supports representations made during vendor reviews, acquisitions, integrations, and supply-chain due diligence.

MONITORING AND SPILLAGE MANAGEMENT ARE NOT THE SAME THING

Detection Informs the Response

Teramis provides the monitoring capability that identifies and reports changes.

Spillage management is the broader organizational process for reviewing the finding, determining what happened, assigning responsibility, deciding what action is appropriate, documenting the response, and confirming the resulting condition.

Teramis identifies and reports. The customer or authorized partner acts.

Keep Boundary Evidence Aligned With Reality

Ongoing findings can help organizations review whether their CUI inventory, System Security Plan, asset records, approved storage locations, data flows, and other boundary documentation continue to reflect the actual environment.

That turns CUI visibility from a one-time exercise into an ongoing evidence process.