STIGhubSTIGhub
STIGsRMF ControlsCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • RMF Controls
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 5 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← All Controls

UL-2

Use LimitationRev 4

Information Sharing with Third Parties

CCI Identifiers (9)

CCI-003589The organization shares personally identifiable information (PII) externally, only for the authorized purposes identified in the Privacy Act and/or described in its notice(s) or for a purpose that is compatible with those purposes.CCI-003590The organization, where appropriate, enters into Memoranda of Understanding, Memoranda of Agreement, Letters of Intent, Computer Matching Agreements, or similar agreements, with third parties that specifically describe the personally identifiable information (PII) covered.CCI-003591The organization, where appropriate, enters into Memoranda of Understanding, Memoranda of Agreement, Letters of Intent, Computer Matching Agreements, or similar agreements, with third parties that specifically enumerate the purposes for which the personally identifiable information (PII) may be used.CCI-003592The organization monitors its staff on the authorized sharing of personally identifiable information (PII) with third parties.CCI-003593The organization audits its staff on the authorized sharing of personally identifiable information (PII) with third parties.CCI-003594The organization trains its staff on the authorized sharing of personally identifiable information (PII) with third parties.CCI-003595The organization trains its staff on the consequences of unauthorized use or sharing of personally identifiable information (PII).CCI-003596The organization evaluates any proposed new instances of sharing personally identifiable information (PII) with third parties to assess whether the sharing is authorized.CCI-003597The organization evaluates any proposed new instances of sharing personally identifiable information (PII) with third parties to assess whether additional or new public notice is required.

Linked STIG Checks (0)

No STIG checks reference this control.