The enclave
The cheapest control is a smaller boundary.
Every system that touches CUI is in scope, and every system in scope has to meet 110 requirements, be documented, and be assessed. It follows that CUI should live in as few systems as possible.
Scope before and after an enclave
What goes inside
The data, the people who handle it, and the devices they use
Every document, drawing, message and dataset that is marked or reasonably identifiable as CUI. Finding all of it is the first task, and it is rarely where the org chart says it should be.
Only staff whose role requires access. Each gets an enclave identity, enclave email and training. Everyone else stays out, and the boundary documentation says so.
Managed, encrypted, and blocked if non-compliant. Conditional Access enforces it: an unenrolled or unhealthy device cannot reach the data. Personal devices are not admitted.
Choosing a tenant
GCC High is not automatic. The data decides.
[confirm against current DoD guidance]
Components
Each component is there because a control family requires it
Entra ID and Conditional Access
Access Control (AC)
Identification and Authentication (IA)
MFA, least privilege, session control
Intune
Configuration Management (CM)
Media Protection (MP)
Baselines, encryption, compliance enforcement
Defender
System and Information Integrity (SI)
Incident Response (IR)
Risk Assessment (RA): vulnerability scanning
Purview
Media Protection (MP): marking and handling
System and Communications Protection (SC): DLP
Labels, retention, eDiscovery
Sentinel or another SIEM
Audit and Accountability (AU)
Log retention, review and alerting
The evidence trail an assessor will ask for
The SSP
Every setting above maps to a requirement.
We write the SSP from the build,
not the build from the SSP.
Process
How the build runs
Locate all CUI, including copies nobody intended to make.
Boundary, data flows, identities and devices, mapped to controls before anything is built.
Tenant, policies, baselines and logging, configured from the design and documented as we go.
Move the data and the people in. Train them. Cut over email and file access.
Purge CUI from the old systems and document that it's gone. Until then, those systems are still in scope.
Running costs
GCC High licensing costs more per user than commercial, and Microsoft validates eligibility before selling it. That's one more reason to keep the enclave small: you pay the premium for the people who need it rather than the whole company. We'll put real numbers on it during scoping.
Not sure where your CUI is?
Most organizations aren't. That's what the discovery phase is for.