Information Security Flashcards

For SFPC and SAPPC

1
Q

What are the phases of the Information Security Program (ISP)?

A

Classification

Safeguarding

Dissemination

Declassification

Destruction

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the purpose of the Information Security Program (ISP)?

A

Introduces the proper and effective way to:

  • classify, protect and share information
  • apply downgrading
  • apply declassification instructions
  • use authorized destruction methods
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Information Security Policies

A

E.O. 13526

32 CFR 2; Parts 2001 and 2003 CNSI, Final Rule

DoDM 5200.01 v1-3

DoDI 5230.09

DoDI 5230.29

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Name the two parts of National Security

A

National Defense

Foreign Relations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

First Step of Classification

A

Determine if materials are controlled by the U.S. Government and if disclosure of the information could cause damage to national security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Classification Levels and Definitions

A

Levels - Top Secret, Secret and Confidential

Unauthorized disclosure may cause…

Top Secret - exceptionally grave damage

Secret - serious damage

Confidential - damage

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is required for access to classified information?

A
  1. National security eligibility
  2. Need-to-know
  3. SF-312 Classified Information Nondisclosure Agreement

*Eligibility + Need-to-know + SF-312 = Authorized Access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is Eligibility?

A

Determinations made by adjudicative authorities that examine a sufficient period of an individual’s life and background

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is Need-to-know?

A
  • Determination that an individual needs access to classified in order to perform lawful and authorized governmental functions
  • Determination made by an authorized holder of classified information (custodian)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is an SF-312?

A
  • Advises cleared employees of their responsibility to protect classified and the possible consequences of failure to protect
  • Must be executed as a condition of access to classified information
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Define Original Classification

A

Making an initial classification decision for government information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Who can make an original classification determination?

A

A designated Original Classification Authority (OCA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Who can authorize an OCA?

A

President

Vice President

Agency Heads

Officials designated by the President *Authorized in writing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

How are OCA duties delegated?

A
  • OCA is delegated to a position, not an individual person!
  • The person occupying the position that is granted OCA holds OCA authority
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Of the categories in E.O. 13526, how many is each OCA responsible for?

A

Only one of the categories

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are the steps in the Original Classification Process?

A
  1. Ensure information is official government information
  2. Determine if information is eligible for classification
  3. Determine if info could cause damage to national security
  4. Assign level of classification
  5. Determine how long the classification should last
  6. Document the level of classification
  7. Communicate decision
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

How does the OCA communicate classification decisions?

A

The SCG and properly marked source documents

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Define Derivative Classification

A

The creation of new materials based on existing classification guidance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Who is responsible for derivatively classifying information?

A

All cleared personnel within the DoD

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What are the responsibilities of Derivative Classifiers?

A
  1. Respect the OCA’s initial classification
  2. Apply required markings
  3. Use authorized sources of classification guidance
  4. Use caution when paraphrasing/restating classified information, as these can change the classification
  5. Take steps to resolve doubts or conflicts about the classification/level/duration
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Classification Concept: Contained In

A
  • Derivative classifiers incorporate classified, word for word from an authorized source
  • No additional interpretation or analysis is needed to determine the classification of that information
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Classification Concept: Compilation

A

If compiled information reveals an additional association or relationship, but it is individually…

  • Unclassified
  • Classified at a lower level
  • May be classified
  • Classified at a higher level
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Classification Concept: Revealed By

A

Classification is deduced from interpretation or analysis via paraphrased or restated information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

What are the basic rules of Portion Marking?

A
  • Complete before banner markings
  • Indicate highest level of classification in every portion
  • Place at beginning of the portion
  • Utilize abbreviations
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

What are the basics of Banner Marking?

A
  • Highest level of classification of the overall document
  • Determined by highest level of any one portion
  • Top and bottom of each page
  • Classification level spelled out in all capital letters
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

What information is in the Derivative Classification Authority Block?

A

Classified By

Derived From

Downgrade To (if applicable)

Declassify On

*Block is placed on the face of each classified document near the bottom

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

What is the purpose of the SCG?

A
  • Provide derivative classification instructions
  • Facilitate proper and uniform derivative classification
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

Who issues the SCG?

A

The OCA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

What basic information is provided in the SCG?

A
  • Classification level for each element
  • Reason for classification
  • Duration of classification
  • Applicable downgrading instructions
  • Special control notices
  • OCA contact information (front cover)
30
Q

What are the four Authorized Storage Methods?

A
  1. Authorized individual’s head
  2. Authorized individual’s hands
  3. GSA approved security container
  4. Authorized information technology
31
Q

What is the purpose of a Coversheet?

A
  • Alert holders to the presence of classified information
  • Prevent inadvertent view of classified information
32
Q

What are the SF-703, SF-704 and SF-705?

A

SF-703 = cover sheet for Top Secret

SF-704 = cover sheet for Secret

SF-705 = cover sheet for Confidential

33
Q

What is the SF-700?

A

Security Container Information

  • Used to maintain a record for each container
  • Used to record combinations
34
Q

What is an SF-701?

A

Activity Security Checklist

  • Used to record checks of work areas
  • Used at the end of each working day
35
Q

Define Access

A

Ability and opportunity to obtain knowledge of classified

36
Q

What is the difference between a Waiver vs an Exception?

A

Both are approved exclusions or deviations from INFOSEC standards

  • Waivers are temporary
  • Exceptions are permanent
37
Q

What markings belong on the Inner Wrapping of a classified envelope/package?

A
  • Complete return address
  • Specific person to receive the package, if applicable
  • Mailing address
  • Highest classification level
  • Applicable special markings
38
Q

What are the markings on the Outer Wrapping of a classified envelope/package?

A
  • Return address
  • Mailing address
  • Do NOT address it to an individual’s name!
  • Do NOT put any classification markings or indicators!
39
Q

Who is responsible for Prepublication Review?

A

Defense Office of Prepublication and Security Review (DOPSR)

40
Q

When is there a Security Violation?

A
  1. Inquiry reveals there has been a compromise of classified information
  2. Knowing, willful or negligent action that could reasonably be expected to result in the loss, suspected compromise or compromise of classified
41
Q

When is there a Security Incident?

A
  • Inquiry confirms that failure to comply with security requirements did not result in a compromise of classified
  • Cannot reasonably be expected to and does not result in the loss, suspected compromise or compromise of classified information
42
Q

What is a Spillage?

A

Classified data is introduced to an information system not approved for that level of information

43
Q

Define Unauthorized Disclosure

A

Communication or physical transfer of classified to an unauthorized recipient

44
Q

Define Declassification

A
  • Authorized change from classified to unclassified
  • Information no longer requires protection in the interest of national security at any level
45
Q

Declassification Type: Scheduled

A

OCA sets a date or event for declassification

46
Q

Declassification Type: Automatic

A

Information is declassified when it is 25 years old

47
Q

Declassification Type: Mandatory

A

The public can ask for classified information to be reviewed for declassification and public release

48
Q

Declassification Type: Systematic

A

Information is reviewed due to being exempt from automatic declassification

49
Q

Define Destruction

A

Destroying classified information to ensure it cannot be recognized or reconstructed

50
Q

Name 5 of the 8 Authorized Methods for Destroying Classified

A

Burning

Shredding

Pulverizing

Disintegrating

Pulping

Melting

Chemical Decomposition

Mutilation

51
Q

Where can you find a list of approved destruction equipment?

A

The NSA’s evaluated products list (EPL)

52
Q

What is the purpose of the Information Security Oversight Office (ISOO)?

A

Oversee and manage the Information Security Program under the guidance of the National Security Council

53
Q

What is the purpose of the National Security Council (NSC)?

A
  • Provide overall policy direction for the Information Security Program
  • Assist the President in developing and issuing National Security Policy
54
Q

What is the purpose of Under Secretary of Defense for Intelligence (USD(I))?

A

Provides guidance, oversight and approval authority of policies and procedures that govern the DoD Information Security Program

55
Q

List 4 Types of Declassification Systems

A

Scheduled

Automatic

Mandatory

Systematic

56
Q

What 2 types of information do not provide declassification instructions?

A
  • Restricted Data
  • Formerly Restricted Data
57
Q

What information is in a Courier Briefing?

A
  1. The courier is liable for materials
  2. Material cannot be left unattended
  3. Do not open en route (exception: customs)
  4. No public discussion
  5. Follow authorized travel route and schedule
  6. In emergency, protect classified material
  7. Travel documents must be current and valid
58
Q

List 5 Common Briefings

A

Initial Indoctrination

Annual Refresher

Debriefing

Courier

NATO

Non-Disclosure

Foreign Travel

Attestation Antiterrorism/Force Protection

59
Q

List Categories of Classified Information

A
  1. Military plans, weapons systems, or operations;
  2. Foreign government information;
  3. Intelligence activities (including covert action), intelligence sources or methods, or cryptology;
  4. Foreign relations or foreign activities of the United States, including confidential sources;
  5. Scientific, technological, or economic matters relating to the national security;
  6. United States Government programs for safeguarding nuclear materials or facilities;
  7. Vulnerabilities or capabilities of systems, installations, infrastructures, projects, plans, or protection services relating to the national security or
    the development, production, or use of weapons of mass destruction
60
Q

List 4 Reasons NOT to Classify Information

A

Concealment of a crime or error

Preventing embarrassment

Restrain competition

Prevent or delay public release

61
Q

List 3 Methods to Derivatively Classify Info

A

Restating: Taken directly from an authorized source

Paraphrase: Re-word in a new or different document

Generate: Take from one form and generate into another

62
Q

Who can declassify information?

A

Secretary of Defense

Secretaries of the Military Departments

Officials delegated by the OCA

Officials delegated as declassification authorities

63
Q

Define Actual Compromise

A

An unauthorized disclosure of information

64
Q

List 4 Topics of OCA Training

A
  1. OCA Responsibilities
  2. Classification Principles and Avoidance of Over Classification
  3. Proper Safeguarding
  4. Criminal, Civil and Administrative penalties for failing to protect classified nfo
65
Q

What must be included on an SCG cover page?

A

Date

Name of system, plan, program or project

Official issuing the guidance (name/personal identifier and position)

OCA approving the guide

Distribution statement

Statement of supercession, if necessary

66
Q

What must be submitted when requesting DoD Original Classification Authority?

A

Mission specific justification for the request Position

67
Q

Declassification Guide Content

A

Identifies the subject matter

Name and position of the OCA

Declass Authority Date of issuance or last review

States info to be declassified, downgraded or to remain classified

68
Q

Security Classification Guide Content

A

Subject matter

OCA

Agency point of contact

Date of approval or last review

Identification and delineation of the specific items or elements of information warranting protection

Classification levels

Reasons for classification

Duration of classification

Warning and handling notices

Dissemination controls

Declass instructions

69
Q

If classified information appears in the public media, what is DoD personnel appropriate response?

A

Neither confirm nor deny

Personnel must be careful not to make any statement of comment that would confirm the accuracy or verify the classified status of the information

70
Q

Define Potential Compromise

A

Possibility that compromise could exist but it is not known with certainty.

71
Q

What must be submitted when requesting DoD Original Classification Authority?

A

Mission specific justification for the request Position