5 CFR 293.106
Listed by: NARA Registry, DoD Registry, Related authorities
Designation evidence
- NARA authority row: 5 CFR 293.106 | status: Specified | banner: CUI//SP-PERS.
- DoD authority row: 5 CFR 293.106. DoD lists this citation for the category; this DoD detail page does not display a separate Basic/Specified field.
- Related authority evidence: 5 CFR 293.106 | status: Specified | banner: CUI//SP-PERS
- Related authority evidence: DoD lists this authority for the category; the linked authority text is extracted below when available.
- Registry designation context: Basic + Specified, CUI. The linked authority text contains category-scope or applicability language that helps determine when the information falls within this CUI category. The linked authority text contains disclosure, access, protection, release, dissemination, or distribution-control language relevant to handling. The linked authority text contains violation, penalty, sanction, or enforcement language that may affect consequences for mishandling.
- Registry designation for this category is Basic + Specified with banner CUI.
Extracted authority meaning
- order, or regulation that authorizes
- Registry designation context: Basic + Specified, CUI. The linked authority text contains category-scope or applicability language that helps determine when the information falls within this CUI category. The linked authority text contains disclosure, access, protection, release, dissemination, or distribution-control language relevant to handling. The linked authority text contains violation, penalty, sanction, or enforcement language that may affect consequences for mishandling.
Operating conditions
- NARA category scope used with this authority: Related to the employees of federal agencies.
- DoD category scope used with this authority: Personnel records of federal employees.
- 5 CFR 293.106 | status: Specified | banner: CUI//SP-PERS
- DoD lists this authority for the category; the linked authority text is extracted below when available.
- NARA registry status: Basic + Specified. Per-authority NARA status values: Basic, Specified. NARA banner marking evidence: CUI, CUI//SP-PERS. The registry evidence is preserved here; detailed primary-law or regulation text analysis remains pending for this category.
- NARA category scope: Related to the employees of federal agencies.
- DoD category scope: Personnel records of federal employees.
- Extracted authority condition: (a) In addition to following the secu- rity requirements of § 293.106 of this part, managers of automated personnel records shall establish administrative, technical, physical, and security safe- guards for data about individuals in automated records, including input and output documents, reports, punched cards, magnetic tapes, disks, and on- line computer storage.
- Extracted authority condition: (a) To ensure the security and con- fidentiality of personnel records, in whatever form, each agency shall es- tablish administrative, technical, and physical controls to protect informa- tion in personnel records from unau- thorized access, use, modification, de- struction, or disclosure.
- Extracted authority condition: Generally, personnel records should be held, processed, or stored only where facilities and conditions are adequate to prevent unauthorized ac- cess.
- Extracted authority condition: (b) Personnel records must be stored in metal filing cabinets which are locked when the records are not in use, or in a secured room.
Safeguarding and dissemination controls
- NARA registry control evidence: status Specified; banner marking CUI//SP-PERS.
- DoD applicable policies: Hosted by Department of War Information Activity - WEB.mil, ![Image 2: Veterans Crisis Line number. Dial 988 then Press 1
- Nara basic or specified: Basic + Specified
- Nara authority rows: 45 USC 362(d) | status: Basic | banner: CUI | sanctions: 45 USC 359 45 USC 231 || 5 CFR 293.106 | status: Specified | banner: CUI//SP-PERS
- Nara banner markings: CUI, CUI//SP-PERS
- Nara sanctions: 45 USC 359 45 USC 231
- Dod applicable policies: Hosted by Department of War Information Activity - WEB.mil, ![Image 2: Veterans Crisis Line number. Dial 988 then Press 1
- No DoD required dissemination control is listed on the registry page. Apply approved limited dissemination controls only when required or permitted by the designating agency or governing authority.
- Use the registry assertions, NARA authority rows, DoD authorities, DoD policies, warning statements, required dissemination controls, and examples first. Where the cited authority does not specify a handling detail, apply CUI Basic safeguards and dissemination rules so long as they do not conflict with the authority or agency-specific controls.
- Extracted authority control: As a min- imum, these controls shall require that all persons whose official duties re- quire access to and use of personnel records be responsible and accountable for safeguarding those records and for ensuring that the records are secured whenever they are not in use or under the direct control of authorized per- sons.
- Extracted authority control: (a) To ensure the security and con- fidentiality of personnel records, in whatever form, each agency shall es- tablish administrative, technical, and physical controls to protect informa- tion in personnel records from unau- thorized access, use, modification, de- struction, or disclosure.
- Extracted authority control: Except for access by the data subject, only employees whose official duties require access shall be allowed to handle and use personnel records, in whatever form or media the records might appear.
- Extracted authority control: Generally, personnel records should be held, processed, or stored only where facilities and conditions are adequate to prevent unauthorized ac- cess.
- Extracted authority control: (2) Individuals asked to voluntarily (circumstances not covered by para- graph (b)(1) of this section) provide their Social Security Number shall suf- fer no penalty or denial of benefits for refusing to provide it. § 293.106 Safeguarding information about individuals.
Authority excerpts
Most relevant extracted authority passage
As a min- imum, these controls shall require that all persons whose official duties re- quire access to and use of personnel records be responsible and accountable for safeguarding those records and for ensuring that the records are secured whenever they are not in use or under the direct control of authorized per- sons.
Extracted authority passage 2
(a) To ensure the security and con- fidentiality of personnel records, in whatever form, each agency shall es- tablish administrative, technical, and physical controls to protect informa- tion in personnel records from unau- thorized access, use, modification, de- struction, or disclosure.
Extracted authority passage 3
Except for access by the data subject, only employees whose official duties require access shall be allowed to handle and use personnel records, in whatever form or media the records might appear.
Extracted authority passage 4
Generally, personnel records should be held, processed, or stored only where facilities and conditions are adequate to prevent unauthorized ac- cess.
Extracted authority passage 5
(2) Individuals asked to voluntarily (circumstances not covered by para- graph (b)(1) of this section) provide their Social Security Number shall suf- fer no penalty or denial of benefits for refusing to provide it. § 293.106 Safeguarding information about individuals.
Extracted authority passage 6
(a) In addition to following the secu- rity requirements of § 293.106 of this part, managers of automated personnel records shall establish administrative, technical, physical, and security safe- guards for data about individuals in automated records, including input and output documents, reports, punched cards, magnetic tapes, disks, and on- line computer storage.