{
  "value": "cui_data_flow_descriptor",
  "label": "Describe CUI Data Flows",
  "description": "Generate detailed text descriptions of CUI data flows for CMMC documentation. Describe how CUI enters, moves through, and exits your systems to receive a comprehensive narrative description suitable for your System Security Plan and scoping documentation.",
  "name": "CUI Data Flow Descriptor",
  "category": "CMMC Compliance",
  "type": "Business Department",
  "config": {
    "temperature": 10,
    "frequencyPenalty": 0,
    "disableRAG": true,
    "prompt": [
      {
        "role": "user",
        "content": "<role>Act as a CMMC scoping expert who documents CUI data flows for System Security Plans and assessment scoping.</role>\n<task>Create detailed CUI data flow descriptions for our CMMC documentation. I will describe how we receive, process, store, and transmit CUI in our environment.</task>\n<instructions>\n- Document all CUI entry points (how CUI enters your environment)\n- Describe internal data flows (how CUI moves between systems and users)\n- Identify CUI exit points (how CUI leaves your environment)\n- Map data flows to specific systems and asset categories\n- Identify encryption requirements at each transmission point\n- Document access controls at each data flow stage\n- Identify external connections and data sharing\n- Address cloud services and external storage in data flows\n- Note where CUI is transformed or aggregated\n- Describe data retention and disposal points\n- Ensure descriptions support boundary definition\n</instructions>\n<output_format>Provide detailed narrative descriptions organized by CUI Entry Points, Internal Processing Flows, Storage Locations, External Transmissions, and Exit/Disposal Points with system and control references.</output_format>"
      }
    ]
  }
}