20.3 Information Protection (AFH-1 Section 18C)
Key Takeaways
- Information protection consists of personnel, industrial, and information security, and every Airman must protect classified information and CUI under their custody and control.
- The three classification levels are Top Secret (exceptionally grave damage), Secret (serious damage), and Confidential (damage) to national security; CUI is not a fourth classification level.
- Three conditions must be met before granting access to classified information: security clearance eligibility, a signed SF 312 nondisclosure agreement, and a need-to-know.
- SF 703, SF 704, and SF 705 are the Top Secret, Secret, and Confidential cover sheets; SF 701 is the Activity Security Checklist for end-of-day checks.
- An infraction cannot reasonably be expected to result in loss or compromise and may be unintentional; a violation indicates knowing, willful, and negligent disregard and results or could result in loss or compromise.
Information Protection Procedures
Information protection is a subset of the USAF security enterprise and consists of the core security disciplines (personnel, industrial, and information security). Those disciplines determine military, civilian, and contractor eligibility to access classified information, protect classified information released or disclosed to industry on classified contracts, and protect classified information and Controlled Unclassified Information (CUI) that, if subject to unauthorized disclosure, could reasonably be expected to cause damage to national security.
All personnel in the USAF are responsible for protecting classified information and CUI under their custody and control. Guidance is DoDM 5200.01 V1 / DAFMAN 16-1404 V1. For SSgts and TSgts, custody is personal.
Classified Information and CUI
Classified information is designated to protect national security. There are three levels of classification. Each individual is responsible for proper safeguards, reporting security incidents, and understanding sanctions for noncompliance. The original classification authority must be able to identify or describe the damage.
| Category | What it is | Unauthorized disclosure reasonably could be expected to cause… | AFH 1 notes |
|---|---|---|---|
| Top Secret | Classified information | Exceptionally grave damage to the national security | Highest classification level |
| Secret | Classified information | Serious damage to the national security | Middle classification level |
| Confidential | Classified information | Damage to the national security | Lowest classification level |
| CUI | Not a classification level | Not described with classified damage adjectives | Government-created or -possessed information (or created/possessed for the government) that a law, regulation, or Government-wide policy requires or permits an agency to handle with safeguarding or dissemination controls (DoDI 5200.48 / AFI 16-1403) |
Memorize exceptionally grave → serious → (plain) damage. CUI still requires controls, but it is not a fourth classification level.
Original and Derivative Classification
Original classification is the initial decision by an original classification authority that information could reasonably be expected to cause identifiable or describable damage to the national security if disclosed without authorization. Only officials designated in writing may make that decision.
Derivative classification is incorporating, paraphrasing, restating, or generating classified information in a new form or document. Within DoD, all cleared personnel are authorized to derivatively classify after initial training before the first decision and refresher training every year. They must use authorized sources and observe and respect original classification authority determinations. USAF policy is to identify, classify, downgrade, declassify, mark, protect, and destroy classified records consistent with national policy. CUI will also be protected per national policy.
Marking and Safeguarding
All classified information shall be clearly identified by marking, designation, or electronic labelling per DoDM 5200.01 V2 / AFMAN 16-1404 V2. Marking alerts holders, identifies what needs protection, indicates the level, and provides downgrading, declassification, source, and safeguarding guidance.
Everyone who works with classified information is personally responsible for taking proper precautions. Before granting access, the person must have:
- Security clearance eligibility
- A signed Standard Form (SF) 312, Classified Information Nondisclosure Agreement
- A need-to-know
The person with authorized possession, knowledge, or control must determine whether the recipient has the appropriate clearance access by proper authority. A clearance is never enough by itself; need-to-know is a separate condition. Material removed from storage stays under constant surveillance, with coversheets on documents not in secure storage:
| Form | Use |
|---|---|
| SF 703 | Top Secret cover sheet |
| SF 704 | Secret cover sheet |
| SF 705 | Confidential cover sheet |
| SF 701 | Activity Security Checklist for end-of-day security checks, required for any area where classified information is used or stored |
End-of-day checks cover vaults, secure rooms, and containers. Classified information systems should be stored in a General Services Administration approved safe or in areas cleared for open storage. Remember 701 (checklist), 703/704/705 (cover sheets descending in classification), and 312 (nondisclosure).
Security Incidents, Industry, and Personnel Security
Anyone finding classified material out of proper control must take custody of and safeguard the material and immediately notify their commander, supervisor, or security manager. Take custody first, then notify.
| Term | AFH 1 distinction |
|---|---|
| Infraction | Failure to comply that cannot reasonably be expected to, and does not, result in loss or suspected/actual compromise. May be unintentional. Requires an inquiry, not an in-depth investigation |
| Violation | Knowing, willful, and negligent disregard for security regulations that results in, or could be expected to result in, loss or compromise. Requires an inquiry and/or investigation |
| Compromise | A violation: unauthorized disclosure to someone without a valid clearance, authorized access, or need to know |
If classified information appears in the public media, including public Internet sites, or if approached by media, DoD personnel shall not confirm the accuracy of or verify the information. Report as instructed. Do not discuss it with anyone who lacks the appropriate clearance and need to know.
Industrial security: USAF policy is to identify, in classified contracts, information and sensitive resources that must be protected while entrusted to industry. Policies apply to USAF personnel and on-base Department of Defense contractors under a properly executed contract and security agreement, as determined by the installation commander.
Personnel security: The Department of Defense Central Adjudication Facility grants, denies, and revokes eligibility using the 13 adjudicative guidelines and the whole person concept (DoDM 5200.02 / AFMAN 16-1405). The 13 guidelines include Allegiance to the United States, Foreign Influence, Foreign Preference, Sexual Behavior, Personal Conduct, Financial Considerations, Alcohol Consumption, Drug Involvement, Psychological Conditions, Criminal Conduct, Handling Protected Information, Outside Activities, and Use of Information Technology Systems. No negative inference may be raised solely on the basis of seeking mental health counseling.
Unauthorized disclosure of Secret information reasonably could be expected to cause which result, as AFH 1 states it?
Before granting access to classified information, which three conditions does AFH 1 require?
How does AFH 1 distinguish a security infraction from a security violation?