Skip to content
CUI Trackby inDirectIT

Platform

One box for CUI.
Nothing else in it.

CUI Track is an operated Microsoft 365 GCC High environment for the people who handle Controlled Unclassified Information. The rest of the business keeps its tools, its network, and its MSP.

Tenant
Microsoft 365 GCC High
Licensing
Business Premium + Defender and Purview
Workloads
Teams, Exchange, SharePoint, OneDrive
Users
Named, CUI handlers only
Ready
60 days, or 14 express
AI
Enabled, inside the boundary
Operator
inDirectIT, CMMC Level 2
OUT OF SCOPECorporate networkEveryday emailShop floor PCsYour MSPCUI from primes and DoDCUI TRACK · GCC HIGHTeamsCHAT · MEETINGSExchangeMAILSharePointLIBRARIESOneDriveFILESNAMED USERSJRAMKT+SSPCURRENTBOUNDARY HELD

The architecture

The boundary follows the data. So we move the data.

CUI arrives from primes and the DoD through one managed edge. Inside, it lives in four Microsoft 365 workloads on GCC High, used only by named people. The corporate network, everyday email, shop-floor PCs, and your MSP never see it, so they stay out of the assessment.

Designed as one system

Microsoft 365 Business Premium on GCC High.

Plus the Defender and Purview add-on. Every layer is configured for the enclave, and documented as part of it.

01

Identity
Named identities for the people who handle CUI, with access scoped to the work. Nobody else is onboarded.

02

Mail
Exchange inside the boundary, so CUI mail stays in scope instead of spreading the assessment.

03

Files
SharePoint and OneDrive as the only home for CUI files, with retention set for that environment.

04

Collaboration
Teams for the people and the programs that carry CUI.

05

Protection
The Defender and Purview add-on on top of Business Premium for the enclave’s users.

06

Logging and backup
Designed with the boundary from the first day, not added after it.

The path

Four stations, on a clock.

STATION 01

Draw the flow

We name where CUI is created, received, stored, and sent. If a system never sees it, it stays off the map.

Output: a CUI flow map and the list of people who actually handle it.

STATION 02

Build the boundary

The working environment sits on Microsoft 365 GCC High. Identity, mail, files, and logging are designed for that box, not bolted onto the corporate network.

Output: the enclave, configured and documented as one system.

STATION 03

Name the users

Only the people who handle CUI are onboarded. Everyone else keeps the tools they already use.

Output: named identities with access scoped to the work.

STATION 04

Hold the evidence

The System Security Plan and the remaining customer work stay current. The boundary does not replace policy, physical security, or your existing MSP.

Output: ready for an assessment or a self-attestation.

STANDARD

60 days

$15,000 setup. The pace most contractors take.

EXPRESS

14 days

$50,000 setup. Same enclave, same stations, on a two-week clock.

Shared responsibility

Who owns what, written down before the build.

ResponsibilityCUI TrackYou
Map where CUI is created, received, stored, and sentLeadsProvides access and people
Build and configure the GCC High enclaveOwnsApproves
Decide who handles CUIAdvisesOwns
Onboard and remove named usersOwnsRequests
Keep the SSP and enclave evidence currentOwnsReviews
Corporate network, devices outside the enclaveOut of scopeOwns, with your MSP
Physical security and policies outside the enclaveOut of scopeOwns

The enclave does not replace your policies, your physical security, or your existing MSP. The final matrix is agreed per customer during the first station.

Boundary review

Draw the flow first.

Thirty minutes on where CUI actually moves. We will tell you if CUI Track fits, and if it does not.