CUI REMEDIATION
You found CUI in the wrong place. Now prove you fixed it.
Discovery tells you where Controlled Unclassified Information actually lives. Validation confirms which findings are real. Remediation changes the environment, and that work needs a clear record.
Teramis supports controlled remediation of validated CUI findings, including movement to authorized destinations, verified transfers, removal or tombstoning of unauthorized copies, and the manifests and logs that show what happened.
Request a Demo | Start a CUI Discovery Readiness Assessment
Cleanup without documentation is just movement.
AFTER DISCOVERY, BEFORE THE ASSESSMENT
Findings are only useful if something happens next
A discovery or boundary validation effort can produce a list of places where CUI exists outside approved locations. The next step is deciding what changes in the environment and how that change will be documented.
- No one is certain which findings are real and which are false positives
- No one has agreed where the data is supposed to go instead
- Moving files by hand across repositories is slow and easy to get wrong
- Copies get left behind in the source location
- Nobody can produce a record of what was moved, when, or by whom
- The next scan finds the same issues again
Remediation is where a CMMC program becomes more defensible.
ACTING ON BAD DATA CREATES NEW PROBLEMS
Remediation should not start with guesswork
When CUI appears outside approved locations, your team needs to know what was found, where it lives, whether it belongs there, and what should happen to it.
- Teams act on false positives and move data that did not need moving
- CUI remains outside the approved boundary because a finding was missed
- Files are moved without documentation that shows what changed
- Unauthorized copies remain in the source location after a partial move
- Remediation activity does not produce anything useful for assessment evidence
- Leadership cannot tell whether the boundary improved
Teramis connects validated findings to controlled remediation activity and a documented record of the result.
A SEQUENCE, NOT A CLEANUP SPRINT
From validated finding to documented outcome
- Start from validated findings: Remediation begins with findings that have been reviewed, not with raw scan output.
- Confirm the authorized destination: Your organization defines where CUI is supposed to live.
- Approve the action: Your team decides which findings are remediated, in what order, and on what schedule.
- Move the data with verification: Identified CUI can move from file systems, SharePoint, and OneDrive into authorized destinations with transfer verification.
- Handle the source location: Once a transfer is verified, unauthorized source files can be removed or replaced with tombstones as approved.
- Capture conflicts and failures: File conflicts and unsuccessful transfers are reported.
- Produce the record: Transfer manifests and logs document what moved, where it went, and what happened to the source.
- Re-scan to confirm: Run discovery again against the same sources to confirm the environment now matches the intended boundary.
See how remediation works in the platform
A CLEAR DIVISION OF RESPONSIBILITY
Teramis performs approved actions. Your organization sets the policy.
Your organization is responsible for approving remediation actions, defining authorized destinations for CUI, applying compliance policy, and making final CUI handling decisions.
Teramis supports the execution and the record by moving approved data, verifying transfers, reporting conflicts, and producing manifests, logs, and evidence of the activity.
Teramis executes what you approve, and documents what it did.
THE SITUATIONS THAT BRING TEAMS HERE
Common remediation triggers
- CUI outside approved locations: Validated CUI in unauthorized repositories, file systems, SharePoint, or OneDrive needs to move into approved destinations.
- Boundary exceptions: Validation showed the actual CUI footprint does not match the documented boundary. Explore CUI Boundary Validation
- CUI spillage response: Misplaced CUI needs authorized copies moved, unauthorized copies removed, and the activity documented. Explore Spillage Monitoring
- Pre-assessment cleanup: Resolve validated CUI issues before self-assessment or review.
- Enclave and migration projects: Move CUI into the secure environment and confirm nothing was left behind in the source.
- Partner-led remediation: MSPs, MSSPs, RPOs, and CMMC advisors need a repeatable workflow for helping clients act on validated findings.
DOCUMENT WHAT CHANGED
Turn remediation activity into a clear record
- File-level CUI findings
- Repository and location details
- Destination movement records
- Hash comparison verification
- Tombstone activity
- Transfer manifests
- Remediation logs
- File conflict and unsuccessful transfer reporting
- Evidence that supports internal review and assessment preparation
WHAT IS AND IS NOT COVERED
Know what remediation applies to
Remediation activity applies to identified CUI in file systems, SharePoint, and OneDrive, moving into destinations your organization authorizes.
Discovery covers a broader set of sources than remediation does. CUI identified outside the remediation scope is still reported so your team can determine the appropriate action.
Teramis does not decide classification, determine which contractual requirements apply, make legal or notification determinations, or approve the final boundary.
FROM FINDINGS TO A FIXED ENVIRONMENT
Act on what discovery found, and be able to show it
Talk with Teramis about your validated findings, your authorized destinations, and the documentation your team needs to produce.
Request a Demo | Start a CUI Discovery Readiness Assessment
Do not submit Controlled Unclassified Information, credentials, file paths, or incident evidence through this form.
