CUI Documents Must Be Reviewed According to Which Procedures?
CUI documents must be reviewed according to Records Management procedures before destruction, ensuring compliance with retention schedules and proper disposal. Under DoDI 5200.48, this review confirms records aren't destroyed prematurely and that CUI is disposed of using approved methods.
The answer
CUI (Controlled Unclassified Information) documents must be reviewed according to Records Management procedures before they are destroyed. This review makes sure a document is not disposed of before its required retention period has expired and that, once it is eligible for destruction, it is destroyed using approved methods that render the CUI unreadable and unrecoverable. The governing policy is DoD Instruction (DoDI) 5200.48, which establishes how CUI is marked, handled, shared, and destroyed across the Department of Defense.
The logic is straightforward: CUI is sensitive information that still requires safeguarding even though it isn't classified. Before you shred, wipe, or otherwise destroy such a record, records-management review confirms two things — that the law and agency retention schedules permit destruction, and that the disposal method meets security standards.
Why Records Management is the correct answer
Records Management procedures exist precisely to control the lifecycle of documents: creation, use, retention, and disposition. Because destroying a record too early can violate federal recordkeeping law (and destroying it improperly can leak CUI), the review step is anchored in records management rather than, say, a purely IT or personnel process. DoDI 5200.48 ties CUI disposal to these procedures so that retention schedules and approved-destruction requirements are both satisfied.
Why the other options are wrong
Distractors on this question usually include:
- "Reviewed according to classification/declassification procedures" — Wrong. Those procedures apply to classified national-security information. CUI is unclassified, so classification review isn't the mechanism.
- "Reviewed according to Freedom of Information Act (FOIA) procedures" — Wrong. FOIA governs public release requests, not the retention-and-destruction lifecycle.
- "No review is required; just shred it" — Wrong. Skipping review risks premature destruction of records still under retention and improper disposal of sensitive data.
- "Reviewed according to physical-security procedures" — Wrong. Physical security protects material in storage/transit; it doesn't govern the retention-and-disposition decision.
Only Records Management procedures address the retention-schedule check plus approved-destruction requirement together, which is why it's the answer.
The bigger picture: the CUI destruction workflow
DoDI 5200.48 and related guidance describe a clean lifecycle. In practice:
- Identify and mark the document as CUI.
- Retain it for the period set by the applicable records schedule.
- Review under Records Management procedures to confirm it is eligible for destruction.
- Destroy using approved methods — cross-cut shredding, pulping, pulverizing, or approved digital wiping — so the CUI cannot be reconstructed. NIST SP 800-88 media-sanitization standards commonly back the digital side.
- Document the disposal as required.
The insight the dense government PDFs bury: the review isn't bureaucratic box-ticking. It's the checkpoint that reconciles two competing obligations — keep records long enough to satisfy the law, but destroy CUI thoroughly enough that it can't be recovered. Records Management procedures are what balance those two demands, which is exactly why CUI must be reviewed under them before destruction.
- 1
1. Identify & mark as CUI
Confirm the document contains Controlled Unclassified Information and is properly marked per DoDI 5200.48.
- 2
2. Retain per records schedule
Hold the document for the retention period set by the applicable records-management schedule.
- 3
3. Review under Records Management procedures
Verify the record is eligible for destruction — retention met and destruction authorized. This is the required review step.
- 4
4. Destroy with approved methods
Use cross-cut shredding, pulping, pulverizing, or approved media sanitization (e.g., NIST SP 800-88) so CUI cannot be reconstructed.
- 5
5. Document the disposal
Record that the CUI was destroyed properly, closing the lifecycle.
Frequently asked
How must CUI be destroyed?
CUI must be destroyed using approved methods that make it unreadable and unrecoverable — cross-cut shredding, pulping, or pulverizing for paper, and approved sanitization (such as NIST SP 800-88) for digital media — after a records-management review confirms it's eligible.
What is DoDI 5200.48?
DoD Instruction 5200.48 is the Department of Defense policy that establishes how Controlled Unclassified Information is identified, marked, safeguarded, shared, and destroyed, standardizing CUI handling across the department.
What are records management procedures for CUI?
They govern the document lifecycle — retention, review, and disposition. For CUI, they ensure a record is kept for its required retention period and only destroyed, using approved methods, once review confirms it is eligible.
Who is responsible for reviewing CUI before destruction?
The responsible records custodian or manager reviews CUI under records-management procedures, confirming retention requirements are met and that an approved destruction method will be used before the document is disposed of.