Skip to content

CUI REMEDIATION & SPILLAGE MONITORING

You found CUI in the wrong place. Now prove you fixed it.

Discovery tells you where Controlled Unclassified Information actually lives. Validation confirms which findings are real. Remediation changes the environment, and that work needs a clear record.

Teramis supports controlled remediation of validated CUI findings, including movement to authorized destinations, verified transfers, removal or tombstoning of unauthorized copies, and the manifests and logs that show what happened.


Cleanup without documentation is just movement.
 

A SEQUENCE, NOT A CLEANUP SPRINT

From Validated Finding to Documented Outcome

  1. Start from validated findings: Remediation begins with findings that have been reviewed, not with raw scan output.
  2. Confirm the authorized destination: Your organization defines where CUI is supposed to live.
  3. Approve the action: Your team decides which findings are remediated, in what order, and on what schedule.
  4. Move the data with verification: Identified CUI can move from file systems, SharePoint, and OneDrive into authorized destinations with transfer verification.
  5. Handle the source location: Once a transfer is verified, unauthorized source files can be removed or replaced with tombstones as approved.
  6. Capture conflicts and failures: File conflicts and unsuccessful transfers are reported.
  7. Produce the record: Transfer manifests and logs document what moved, where it went, and what happened to the source.
  8. Re-scan to confirm: Run discovery again against the same sources to confirm the environment now matches the intended boundary.

A CLEAR DIVISION OF RESPONSIBILITY

Teramis Performs Approved Actions. Your Organization Sets the Policy.

Your organization is responsible for approving remediation actions, defining authorized destinations for CUI, applying compliance policy, and making final CUI handling decisions.

Teramis supports the execution and the record by moving approved data, verifying transfers, reporting conflicts, and producing manifests, logs, and evidence of the activity.

Teramis executes what you approve and documents what it did.

After discovery, before the assessment

Findings Are Only Useful if Something Happens Next

A discovery or boundary validation effort can produce a list of places where CUI exists outside approved locations. The next step is deciding what changes in the environment and how that change will be documented.

Remediation is where a CMMC program becomes more defensible.

01 No one is certain which findings are real and which are false positives.
02 No one has agreed where the data is supposed to go instead.
03 Moving files by hand across repositories is slow and easy to get wrong.
04 Copies get left behind in the source location.
05 Nobody can produce a record of what was moved, when, or by whom.
06 The next scan finds the same issues again.

Acting on bad data creates new problems

Remediation Should Not Start With Guesswork

When CUI appears outside approved locations, your team needs to know what was found, where it lives, whether it belongs there, and what should happen to it.

Teams act on false positives and move data that did not need moving.

CUI remains outside the approved boundary because a finding was missed.

Files are moved without documentation that shows what changed.

Unauthorized copies remain in the source location after a partial move.

Remediation activity does not produce anything useful for assessment evidence.

Leadership cannot tell whether the boundary improved.

Teramis connects validated findings to controlled remediation activity and a documented record of the result.

The situations that bring teams here

Common Remediation Triggers

CUI Outside Approved Locations

Validated CUI in unauthorized repositories, file systems, SharePoint, or OneDrive needs to move into approved destinations.

CUI Spillage Response

Misplaced CUI needs authorized copies moved, unauthorized copies removed, and the activity documented.

Explore Spillage Monitoring →

Pre-Assessment Cleanup

Resolve validated CUI issues before self-assessment or review.

Enclave and Migration Projects

Move CUI into the secure environment and confirm nothing was left behind in the source.

Partner-Led Remediation

MSPs, MSSPs, RPOs, and CMMC advisors need a repeatable workflow for helping clients act on validated findings.

Document what changed

Turn Remediation Activity Into a Clear Record

Create a reviewable record of what was identified, what action occurred, and whether the intended result was achieved.

File-level CUI findings
Repository and location details
Destination movement records
Hash comparison verification
Tombstone activity
Transfer manifests
Remediation logs
File conflict and unsuccessful transfer reporting
Evidence that supports internal review and assessment preparation

What is and is not covered

Know What Remediation Applies To

Included

Remediation activity applies to identified CUI in file systems, SharePoint, and OneDrive, moving into destinations your organization authorizes.

Broader discovery coverage

Discovery covers a broader set of sources than remediation does. CUI identified outside the remediation scope is still reported so your team can determine the appropriate action.

Customer responsibility

Teramis does not decide classification, determine which contractual requirements apply, make legal or notification determinations, or approve the final boundary.

From findings to a fixed environment

Act on What Discovery Found, and Be Able to Show It

Talk with Teramis about your validated findings, your authorized destinations, and the documentation your team needs to produce.

Do not submit Controlled Unclassified Information, credentials, file paths, or incident evidence through this form.


Do not submit Controlled Unclassified Information, credentials, file paths, or incident evidence through this form.