Information Security Flashcards

1
Q

What are the names of the policies that provide guidance for the DOD Information Security Program?

A
  • E.O 13526
  • 32 CFR 2, parts 2001 and 2003, CNSI Final Rule
  • DODM 5200.01 VOL 1-4
  • DODI 5230.09
  • DODI 5230.29
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the responisbility of the Information Security Oversight Office, or ISOO?

A

To oversee and manage the information security program, under the guidance of the National Security Council

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the responsibility of the National Security Council (NSC)?

A
  • To provide the overall policy direction for the informatin security program.
  • It assists the President in develping and issuing National Security Policies, and it guides and directs the implementation and application of the Executive Order.
  • The NSC exervises its guidance primarily through the ISOO
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the USD(I) and their responsibility?

A

The Under Secretary of Defense for Intelligence has the primary responsibility for providing guidance, oversight, and approval authority of policies and procedures that govoern the DoD ISP (by issuing the DoD Instruction 5200.01)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

The three levels of classified information are designated by what exectuive order?

A

EO 13526

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the 5 requirements for dreivatie classification?

A
  1. Observe and respect the OCAs original class determination
  2. Apply the required markings
  3. Only use authorized sources
  4. Use caution when paraphrasing
  5. Always take the appropriate steps to resolve any doubts you have
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the 4 tpes of Declassification systems?

A
  1. Systematic
  2. Automatic
  3. Mandatory
  4. Scheduled
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is a scheduled declassification?

A

Instructions consist of either a date or event for declassification.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is automatic declassification?

A

Classified records that have been determined to have permanent historical value, will be automaticall declassified on December 31st of the year that is 25 years from data of its original classification.

There are 9 categories of Information that may be classified beyond 25 years. You can easily identify this information by the yse of 25X instruction for declassificaiton. The exemptions are annotated as 25X with the category nymber following the X, for example, 25X9.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is Mandatory Declassification Review, or MDR?

A

It is another method of declassifiying information based on requesting a review of information to see if classification is still necessary.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is Systematic Declassification?

A

A program to review classified records after a certain age.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are the options an OCA has when determining declassification?

A
  • Specific Date
  • Specific Event
  • 50X1-HUM Exception
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What type of information does not provide declassification instructions?

A
  • Restricted Data
  • Formerly Restriced Data
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are the purposes of the SF 701 and SF 702?

A

The SF 701, or the Activity Security Checklist, is used to record your End of Day Checks.

The SF 702, or the Security Container Check Sheet, is used to record the opening and closing of your security container.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What does the term Information System refer to?

A

Refers to a set of Information Resources organized for the collection, storage, processing, maintenance, use, sharing, dissemination, dispoistion, display, or transmission of information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is COMSEC?

A

Communication Security, COMSEC, is defined as the protection resultinf from all measured designed to deny unauthorized persons, information of value that might be derived from the possession and study of telecommunications, and to ensure the authenticity of such communications.

COMSEC includes crypto security, emission security, transmission security, and physical security of COMSEC material and information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

How is classified information prepared for transmission?

A

Classified material needs to be prepared for shipment, packaged, and sealed in ways that minimize risk of accidental exposure and facilitates detection of tampering.

18
Q

Requirments to hand carry classified information

A
  1. Should be done as a last resort
  2. Written authorization is required
  3. Courier must be briefed.
19
Q

What must be included in the Courier Brief?

A
  1. Couriers liability for the materials.
  2. Material cannon be left unattended
  3. Should not be opened en route (unless customs)
  4. No public discussion
  5. Follow an authorized travel route and schedule
  6. In case of ER, protect classified materials
  7. All travel documents must be valid and current.
20
Q

When can SECRET information be sent via USPS?

A

Only when it is the most effective means considering security, time, cost, and accountability.

21
Q

List 3 approved methods for destroying classified material

A
  • Burning
  • Shredding
  • Pulverizing
  • Disintegrating
  • Pulping
  • Melting
  • Chemical Decomposition
  • Mutilation to preclude recognition
22
Q

Which agency creates the desctruction standard that DoD users?

A

NSA

23
Q

What is NATO?

A

The North Atlantic Treaty Organization is an alliance of 28 countries from North America and Europe, committed to fulfilling the goals of the North Atlantic Treaty signed on April 4, 1949.

The United States is a member of NATO, and as such, has access to NATO Classified documents.

NATO classified information, or documents prepared by for NATO and NATO member nation documents that have been released into the NATO security system, and that bear a NATO classification marking, needs to be safeguarded and marked in compliance with the United States Security Authority for NATO or USSAN.

24
Q

List 3 FOIA exemption categories

A
  1. National Defense
  2. DoD personnel practices
  3. Statutes
  4. Trade Secrets
  5. Litigation
  6. Personal and Private
  7. Law Enforcement
  8. Regulation of financial institutions
  9. Well location
25
Q

What is FOIA?

A

The Freedom of Information Act recognizes the need to withhold certain types of information from public release and, therefor, establises guidance and framwework for evaluating information for release to the public.

The FOIA provides that, for information to be exempt from mandatory release, it must first fit into one of nine qualifying categories and there must be a legitimate Government purpose served by withholding it.

26
Q

What is STIP?

A

STIP stands for the DoD Scientific and Technical Information Program.

STIP is not a control marking.

STIP was established to improve and enhance the acqusition of data sources to prevent redundant research to dissemniate technical information efficiently to prevent the loss of technical information to U.S. adversaries and competitors and last, but no less important, STIP was established to aid the transfer of technical information to qualified researchers in U.S. Industry and government agencies.

27
Q

List 5 common briefings

A
  1. Initial
  2. Indoctrination (access to special types of class data, such as SCI/G/H, etc.)
  3. Annual Refresher
  4. Debriefing
  5. Courier
  6. NATO
  7. Non-Disclosure Briefing (unathorized access)
  8. Foreign Travel Briefing
  9. Attestation (SAP briefing)
  10. Antiterrorism/Force Protection (AT/FP)
28
Q

What must an intitial breifing accomplish?

A

Define classified information and CUI

Explain the importance of protecting such information

Provide a basic understanding of security policies and principles.

Notify personel of their responsibilities within the security program

Inform them of the administrative, civil, and/or criminal sanctions that can be applied when appropriate

Provide individual enough information to ensure the proper protection of classified information and CUI in their possesion, including actions to be taken if such information is discovered unseured, a security vulnerability is noted, or a person has been seeking unathorized acccess to such information

Inform personnel of the need for re view of ALL unclassified DoD information prior to its release to the public.

29
Q

What must a debriefing accomplish?

A

Emphasizes an individuals continued responsiblity to protect classfied information to which they have had access.

Instructions for reporting any unathorized attempt to gain access to such information

Advised on the prohibition against retaining matrial once they depart the organization

Reminded of the potential civil and criminal penalties for the failure to fulfill their continuing security responsibilities.

30
Q

In what circumstance is a foreign travel briefing required?

A

For individuals with SCI/SAP access

Attendance at meetings where foreign nationals are likely to be present.

31
Q

Which DoD policy document establishes the requirements and minimum standards for developing classification guidance?

A

DoDM 5200.01

DoD Information Security Program, Volumes 1-4

32
Q

Which policy document provides guidance to all Government agencies on classification, downgrading, declassification, and safeguarding of classified national security information?

A

ISOO 32 CFR Parts 2001 and 2003, Classified Antional Security Information (CNSI), Final Rule

33
Q

Which policy document prescribes a uniform system for classifying, safeguarding, and declassifying national security information?

A

E.O. 13526, Classified National Security Information

34
Q

What are the 6 steps for an OCA to classify information?

A
  1. Confirm the info is owned/controlled by the Government
  2. Confirm the info is elegible for classification
  3. Determine impact
  4. Determine classification level
  5. Determine classfication duration
  6. Provide Guidance
35
Q

What are the 4 steps to determine if information is eligible for classification?

A
  1. Is the information official?
  2. Is it under any prohibitions or limitations?
  3. Is it already classified?
  4. Does it fall into on of the 8 categories of classied information?
36
Q

List 4 of the 8 categories of classified information

A
  1. Military plans, weapon systems
  2. Foreign Government Information
  3. Intelligence activities/sources/methods
  4. Foreign relations/activities
  5. Science/Technology or economic matters relating to National Security
  6. Safeguarding nuclear material or facilities
  7. Vulnerabilities or capabilities related to National Security
  8. Weapons of Mass Destruction
37
Q

Whats not a reason to classify information?

A
  1. Concealment of a crime or error
  2. Preventing embarrassment
  3. Retrain competition
  4. Prevent or delay public release
38
Q

How is the level of classifcation determined by the OCA?

A
  1. Probable impact
  2. Verbal determinations must be followed by a written confirmation within 7 days
  3. Be prepared to present reason in a court of law
  4. Be prepared to provide a written description of damage.
39
Q

Describe net national advantage

A

Net national advantage is information that is or will be valuable to the U.S, either directly or indirectly.

40
Q

What must be included on a SCG cover page?

A

The name of the sytem, plan, program, or project

The date

The office issuing the guide, identified by name or ersonal identirifer and position

The OCA approving the Guide

a statememnt of supercession, if necessary

Distribution statement

41
Q

What must be submitted when requesting DoD Original Classification Authority?

A

Requests must specify the position title for which the authority is requested

Provide a brief mission specific justification for the request and be submitted through established organizational channels.

When authority is granted to a position that authority is document by an appointment officer.

42
Q

When will Agency grant a request for OCA?

A

Requests will be granted only when an existing Security Classification Guides are insufficient to address the information in question, and when it is impractical to refer decisions to another OCA.