Complementary User Entity Controls or "CUECs"

Written By Micah

Complementary User Entity Controls (CUECs) are controls that the end customer is responsible for implementing in order for the utilized product/service/system to function as intended. An organization must define the CUECs that are required within the System Description (typically, they can be found at the conclusion of the System Description).

The following are examples of CUECs for different types of organizations.

User entities for Consulting Services are typically responsible for:

  • managing their own logical access controls to their data and applications

  • their own backups

  • their own change management procedures

  • their own physical and environmental controls

User entities for Colocations or Datacenters are typically responsible for:

  • managing their own logical access controls to their data, applications, and operating systems

  • their own backups

  • their own change management procedures

  • their own workstations and VPN controls

  • their own intrusion detection systems (IDS)

  • their own data disposal and retention procedures

User entities for SaaS deployed in their environment are typically responsible for:

  • managing their own logical access to their data

  • their own backups

  • their own physical and environmental controls

  • their own database encryption controls