Complementary User Entity Controls or "CUECs"
Written By Micah
Complementary User Entity Controls (CUECs) are controls that the end customer is responsible for implementing in order for the utilized product/service/system to function as intended. An organization must define the CUECs that are required within the System Description (typically, they can be found at the conclusion of the System Description).
The following are examples of CUECs for different types of organizations.
User entities for Consulting Services are typically responsible for:
managing their own logical access controls to their data and applications
their own backups
their own change management procedures
their own physical and environmental controls
User entities for Colocations or Datacenters are typically responsible for:
managing their own logical access controls to their data, applications, and operating systems
their own backups
their own change management procedures
their own workstations and VPN controls
their own intrusion detection systems (IDS)
their own data disposal and retention procedures
User entities for SaaS deployed in their environment are typically responsible for:
managing their own logical access to their data
their own backups
their own physical and environmental controls
their own database encryption controls