16.3 Information Protection & Classification
Key Takeaways
- The three classification levels are Top Secret (exceptionally grave damage), Secret (serious damage), and Confidential (damage) to national security.
- Three conditions must be met before granting access to classified information: security clearance eligibility, a signed SF 312 nondisclosure agreement, and a need-to-know.
- SF 703, SF 704, and SF 705 are the Top Secret, Secret, and Confidential cover sheets; SF 701 is the Activity Security Checklist for end-of-day checks.
- An infraction cannot reasonably be expected to result in loss or compromise and may be unintentional; a violation indicates knowing, willful, and negligent disregard and results or could result in loss or compromise.
- There are 13 adjudicative guidelines used by the DoD Central Adjudication Facility to grant, deny, and revoke security clearance eligibility.
What Information Protection Covers
"Information protection is a subset of the USAF security enterprise and consists of the core security disciplines (personnel, industrial, and information security)." Three disciplines, and the exam asks for them by name.
Those disciplines are used to:
- Determine military, civilian, and contractor personnel eligibility to access classified information
- Ensure the protection of classified information released or disclosed to industry in connection with classified contracts
- Protect classified information and Controlled Unclassified Information (CUI) that, if subject to unauthorized disclosure, could reasonably be expected to cause damage to national security
"All personnel in the USAF are responsible for protecting classified information and CUI under their custody and control."
The Three Classification Levels
The damage language is the discriminator, and it is precise.
| Level | Unauthorized disclosure reasonably could be expected to cause… |
|---|---|
| Top Secret | Exceptionally grave damage to the national security |
| Secret | Serious damage to the national security |
| Confidential | Damage to the national security |
In every case the damage must be one "that the original classification authority is able to identify or describe."
Memorize the three adjectives in order: exceptionally grave → serious → (plain) damage. Any item that pairs "grave" with Secret or "serious" with Top Secret is wrong.
Each individual is responsible for providing the proper safeguards, reporting security incidents, and understanding the sanctions for noncompliance.
Controlled Unclassified Information is "information the government creates or possesses, or that an entity creates or possesses for or on behalf of the government, that a law, regulation, or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls." The reference is DoDI 5200.48 / AFI 16-1403.
Original Versus Derivative Classification
| Type | Definition | Who may do it |
|---|---|---|
| Original classification | "The initial decision by an original classification authority that an item of information could reasonably be expected to cause identifiable or describable damage to the national security if subjected to unauthorized disclosure and requires protection." | Only officials designated in writing may make original classification decisions |
| Derivative classification | "Incorporating, paraphrasing, restating, or generating classified information in a new form or document." | Within DoD, all cleared personnel are authorized to derivatively classify if they have (1) received initial training before making derivative classification decisions and (2) received refresher training every year |
The four derivative verbs — incorporating, paraphrasing, restating, generating — are a testable set. And the training rule matters: initial training before the first decision, refresher every year.
AFH 1 names the derivative classifier's most important responsibility: "to observe and respect the classification determinations made by an original classification authority." Derivative classifiers must use authorized types of sources.
Marking Classified Information
Marking serves to: alert holders to the presence of classified information; identify the information needing protection; indicate the level of classification; provide guidance on downgrading and declassification; give information on the sources of and reasons for classification; notify holders of special access, control, or safeguarding requirements; and promote information sharing, facilitate judicious use of resources, and simplify management.
Every classified document must be marked to show the highest classification of information contained within, conspicuously enough to alert anyone handling it. Every document will contain:
- The overall classification of the document
- Banner lines
- Portion markings indicating the classification level of specific information within the document
- The classification authority block
- Date of origin
- Downgrading instructions, if any, and declassification instructions
"The three most common markings on a classified document are the banner lines, portion markings, and the classification authority block." That trio is a near-certain item. The reference is DoDM 5200.01 V2 / DAFMAN 16-1404 V2.
Safeguarding
"Everyone who works with classified information is personally responsible for taking proper precautions."
The three access conditions — all three must be met:
- Security clearance eligibility
- A signed Standard Form (SF) 312, Classified Information Non-Disclosure Agreement
- A need-to-know
The person with authorized possession, knowledge, or control of the information must determine whether the recipient has been granted the appropriate security clearance access by proper authority. A clearance alone is never sufficient — need-to-know is a separate, independent condition, and that is the point most scenario items turn on.
Material removed from storage must be kept under constant surveillance, and coversheets must be placed on classified documents not in secure storage:
| Form | Level |
|---|---|
| SF 703 | Top Secret cover sheet |
| SF 704 | Secret cover sheet |
| SF 705 | Confidential cover sheet |
End-of-day checks use the SF 701, Activity Security Checklist, required for any area where classified information is used or stored. Ensure all vaults, secure rooms, and containers used for storing classified material are checked. Classified information systems should be stored in a General Services Administration approved safe or in buildings or areas cleared for open storage of classified.
The form numbers run in a memorable block: 701 checklist, 703/704/705 cover sheets descending in classification, 312 nondisclosure agreement.
Security Incidents
"Anyone finding classified material out of proper control must take custody of and safeguard the material and immediately notify their commander, supervisor, or security manager." Note the order of actions: take custody first, then notify — an option that says to leave the material and report it is wrong.
| Incident | Definition |
|---|---|
| Infraction | Failure to comply with requirements which cannot reasonably be expected to, and does not, result in the loss of classified records or the suspected or actual compromise of classified information. May be unintentional or inadvertent. Does not constitute a security violation, but if left uncorrected can lead to violations or compromises. Requires an inquiry to facilitate immediate corrective action but not an in-depth investigation |
| Violation | Incidents that indicate knowing, willful, and negligent disregard for security regulations and result in, or could be expected to result in, the loss of classified records or the compromise of classified information. Require an inquiry and/or investigation |
| Compromise | A security incident — more specifically, a violation — in which there is an unauthorized disclosure of classified information, meaning disclosure to a person who does not have a valid clearance, authorized access, or a need to know |
| Loss | When records containing classified information cannot be physically located or accounted for — including material discovered missing during an audit that cannot be immediately located |
| Data spill | Classified data introduced onto an unclassified information system, onto a system with a lower level of classification, or onto a system not accredited to process data of that restrictive category. Handled as a possible compromise until the inquiry determines whether unauthorized disclosure did or did not occur |
Infraction versus violation is the highest-frequency item in Section 18C. The discriminators are intent (inadvertent versus knowing/willful/negligent) and consequence (cannot reasonably result in loss/compromise versus does or could).
Information in the public media. If classified information appears in public media or a media representative approaches you, "be careful not to make any statement or comment that confirms the accuracy of or verifies the information requiring protection." Report the matter as instructed, but do not discuss it with anyone who does not have an appropriate security clearance and need to know. Publication does not declassify — that is the trap in any scenario built on this rule.
Personnel and Industrial Security
Industrial security: USAF policy is to identify, in classified contracts, specific information and sensitive resources that must be protected against compromise or loss while entrusted to industry.
Personnel security: the program "entails policies and procedures that ensure military, civilian, and contractor personnel who access classified information or occupy a sensitive position are consistent with interests of national security." It involves the investigation process, adjudication (approval) for eligibility, and continuous evaluation for maintaining eligibility.
The supervisor's role is a testable obligation: "Commanders and supervisors must continually observe and evaluate their subordinates with respect to these criteria and immediately report any unfavorable conduct or conditions that might bear on the subordinates' trustworthiness and eligibility."
The Adjudicative Guidelines
The Department of Defense Central Adjudication Facility is the designated authority to grant, deny, and revoke security clearance eligibility, using the 13 adjudicative guidelines while applying the whole person concept and mitigating factors. Individuals are granted due process and may appeal if eligibility is denied or revoked.
| Guideline | Core concern |
|---|---|
| Allegiance to the United States | An individual must be of unquestioned allegiance |
| Foreign Influence | Divided loyalties, foreign financial interests, or vulnerability to pressure or coercion by any foreign interest |
| Foreign Preference | Acting in a way indicating a preference for a foreign country over the United States |
| Sexual Behavior | Behavior involving a criminal offense, a personality or emotional disorder, lack of judgment or discretion, or vulnerability to coercion. "No adverse inference... may be raised solely on the basis of the sexual orientation of the individual" |
| Personal Conduct | Questionable judgment, lack of candor, dishonesty, or unwillingness to comply with rules and regulations |
| Financial Considerations | Failure or inability to live within one's means; a financially overextended individual is at risk of having to engage in illegal acts. Compulsive gambling is a concern, as is affluence that cannot be explained by known sources of income |
| Alcohol Consumption | Excessive consumption leading to questionable judgment or failure to control impulses |
| Drug Involvement | Use of an illegal drug or misuse of a prescription drug |
| Psychological Conditions | Conditions that impair judgment, reliability, or trustworthiness. A formal diagnosis is not required for a concern to exist — but "no negative inference... may be raised solely on the basis of seeking mental health counseling" |
| Criminal Conduct | Criminal activity creates doubt about judgment, reliability, and trustworthiness |
| Handling Protected Information | Deliberate or negligent failure to comply with rules for protecting classified or sensitive information |
| Outside Activities | Employment or activities that pose a conflict of interest with security responsibilities |
| Use of Information Technology | Noncompliance with rules pertaining to information technology systems |
Two protective clauses are frequently tested because they run against expectation: no adverse inference may be drawn solely from sexual orientation, and no negative inference may be drawn solely from seeking mental health counseling. Both appear verbatim in AFH 1, and both are the keyed answer when a scenario invites the opposite conclusion.
Financial Considerations is the guideline with the most sub-elements — debt, compulsive gambling, and unexplained affluence — which makes it the most common subject of a scenario item.
Which three conditions must be met before a person may be granted access to classified information?
How does AFH 1 distinguish a security infraction from a security violation?
Under the adjudicative guidelines, what does AFH 1 say about an individual who seeks mental health counseling?