to move, Enter to open, Esc to close. Try 3.5.3, AC.L2-3.1.1, MFA or unmarked.

Information Systems Vulnerability Information ISVI

A CUI category in the Critical Infrastructure grouping of NARA's registry, CUI Basic, marked CUI.

NARA's description

CUI Registry · Information Systems Vulnerability Information

Related to information that if not protected, could result in adverse effects to information systems. Information system means a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information.

Verbatim from the registry entry, which NARA last reviewed on May 7, 2025. Fetched 2026-09-08.

Markings

Category marking
ISVI
Banner marking
CUI
Alternative banner, Basic
CUI//ISVI

A banner reads CUI for Basic categories and CUI//SP-ISVI for Specified ones, followed by any limited dissemination control such as NOFORN. How the marking rule works, verbatim from 32 CFR 2002.20.

Authorities

The law, regulation or Government-wide policy that makes this information CUI, and whether it does so as a Basic or a Specified authority.

Safeguarding or dissemination authorityBasic or SpecifiedBannerSanctions
44 USC 3554 (see OMB M-24-04 for implementing guidance)BasicCUI
44 USC 3555(f)BasicCUI

Source: https://www.archives.gov/cui/registry/category-detail/info-systems-vulnerability-info.