Information Security Flashcards

For SFPC and SAPPC

1
Q

What are the phases of the Information Security Program (ISP)?

A

Classification

Safeguarding

Dissemination

Declassification

Destruction

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the purpose of the Information Security Program (ISP)?

A

Introduces the proper and effective way to:

  • classify, protect and share information
  • apply downgrading
  • apply declassification instructions
  • use authorized destruction methods
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Information Security Policies

A

E.O. 13526

32 CFR 2; Parts 2001 and 2003 CNSI, Final Rule

DoDM 5200.01 v1-3

DoDI 5230.09

DoDI 5230.29

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Name the two parts of National Security

A

National Defense

Foreign Relations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

First Step of Classification

A

Determine if materials are controlled by the U.S. Government and if disclosure of the information could cause damage to national security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Classification Levels and Definitions

A

Levels - Top Secret, Secret and Confidential

Unauthorized disclosure may cause…

Top Secret - exceptionally grave damage

Secret - serious damage

Confidential - damage

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is required for access to classified information?

A
  1. National security eligibility
  2. Need-to-know
  3. SF-312 Classified Information Nondisclosure Agreement

*Eligibility + Need-to-know + SF-312 = Authorized Access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is Eligibility?

A

Determinations made by adjudicative authorities that examine a sufficient period of an individual’s life and background

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is Need-to-know?

A
  • Determination that an individual needs access to classified in order to perform lawful and authorized governmental functions
  • Determination made by an authorized holder of classified information (custodian)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is an SF-312?

A
  • Advises cleared employees of their responsibility to protect classified and the possible consequences of failure to protect
  • Must be executed as a condition of access to classified information
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Define Original Classification

A

Making an initial classification decision for government information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Who can make an original classification determination?

A

A designated Original Classification Authority (OCA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Who can authorize an OCA?

A

President

Vice President

Agency Heads

Officials designated by the President *Authorized in writing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

How are OCA duties delegated?

A
  • OCA is delegated to a position, not an individual person!
  • The person occupying the position that is granted OCA holds OCA authority
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Of the categories in E.O. 13526, how many is each OCA responsible for?

A

Only one of the categories

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are the steps in the Original Classification Process?

A
  1. Ensure information is official government information
  2. Determine if information is eligible for classification
  3. Determine if info could cause damage to national security
  4. Assign level of classification
  5. Determine how long the classification should last
  6. Document the level of classification
  7. Communicate decision
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

How does the OCA communicate classification decisions?

A

The SCG and properly marked source documents

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Define Derivative Classification

A

The creation of new materials based on existing classification guidance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Who is responsible for derivatively classifying information?

A

All cleared personnel within the DoD

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What are the responsibilities of Derivative Classifiers?

A
  1. Respect the OCA’s initial classification
  2. Apply required markings
  3. Use authorized sources of classification guidance
  4. Use caution when paraphrasing/restating classified information, as these can change the classification
  5. Take steps to resolve doubts or conflicts about the classification/level/duration
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Classification Concept: Contained In

A
  • Derivative classifiers incorporate classified, word for word from an authorized source
  • No additional interpretation or analysis is needed to determine the classification of that information
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Classification Concept: Compilation

A

If compiled information reveals an additional association or relationship, but it is individually…

  • Unclassified
  • Classified at a lower level
  • May be classified
  • Classified at a higher level
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Classification Concept: Revealed By

A

Classification is deduced from interpretation or analysis via paraphrased or restated information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

What are the basic rules of Portion Marking?

A
  • Complete before banner markings
  • Indicate highest level of classification in every portion
  • Place at beginning of the portion
  • Utilize abbreviations
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
What are the basics of Banner Marking?
- Highest level of classification of the overall document - Determined by highest level of any one portion - Top and bottom of each page - Classification level spelled out in all capital letters
26
What information is in the Derivative Classification Authority Block?
Classified By Derived From Downgrade To (if applicable) Declassify On \*Block is placed on the face of each classified document near the bottom
27
What is the purpose of the SCG?
- Provide derivative classification instructions - Facilitate proper and uniform derivative classification
28
Who issues the SCG?
The OCA
29
What basic information is provided in the SCG?
- Classification level for each element - Reason for classification - Duration of classification - Applicable downgrading instructions - Special control notices - OCA contact information (front cover)
30
What are the four Authorized Storage Methods?
1. Authorized individual’s head 2. Authorized individual’s hands 3. GSA approved security container 4. Authorized information technology
31
What is the purpose of a Coversheet?
- Alert holders to the presence of classified information - Prevent inadvertent view of classified information
32
What are the SF-703, SF-704 and SF-705?
SF-703 = cover sheet for Top Secret SF-704 = cover sheet for Secret SF-705 = cover sheet for Confidential
33
What is the SF-700?
Security Container Information - Used to maintain a record for each container - Used to record combinations
34
What is an SF-701?
Activity Security Checklist - Used to record checks of work areas - Used at the end of each working day
35
Define Access
Ability and opportunity to obtain knowledge of classified
36
What is the difference between a Waiver vs an Exception?
Both are approved exclusions or deviations from INFOSEC standards - Waivers are temporary - Exceptions are permanent
37
What markings belong on the Inner Wrapping of a classified envelope/package?
- Complete return address - Specific person to receive the package, if applicable - Mailing address - Highest classification level - Applicable special markings
38
What are the markings on the Outer Wrapping of a classified envelope/package?
- Return address - Mailing address - Do NOT address it to an individual’s name! - Do NOT put any classification markings or indicators!
39
Who is responsible for Prepublication Review?
Defense Office of Prepublication and Security Review (DOPSR)
40
When is there a Security Violation?
1. Inquiry reveals there has been a compromise of classified information 2. Knowing, willful or negligent action that could reasonably be expected to result in the loss, suspected compromise or compromise of classified
41
When is there a Security Incident?
- Inquiry confirms that failure to comply with security requirements did not result in a compromise of classified - Cannot reasonably be expected to and does not result in the loss, suspected compromise or compromise of classified information
42
What is a Spillage?
Classified data is introduced to an information system not approved for that level of information
43
Define Unauthorized Disclosure
Communication or physical transfer of classified to an unauthorized recipient
44
Define Declassification
- Authorized change from classified to unclassified - Information no longer requires protection in the interest of national security at any level
45
Declassification Type: Scheduled
OCA sets a date or event for declassification
46
Declassification Type: Automatic
Information is declassified when it is 25 years old
47
Declassification Type: Mandatory
The public can ask for classified information to be reviewed for declassification and public release
48
Declassification Type: Systematic
Information is reviewed due to being exempt from automatic declassification
49
Define Destruction
Destroying classified information to ensure it cannot be recognized or reconstructed
50
Name 5 of the 8 Authorized Methods for Destroying Classified
Burning Shredding Pulverizing Disintegrating Pulping Melting Chemical Decomposition Mutilation
51
Where can you find a list of approved destruction equipment?
The NSA's evaluated products list (EPL)
52
What is the purpose of the Information Security Oversight Office (ISOO)?
Oversee and manage the Information Security Program under the guidance of the National Security Council
53
What is the purpose of the National Security Council (NSC)?
- Provide overall policy direction for the Information Security Program - Assist the President in developing and issuing National Security Policy
54
What is the purpose of Under Secretary of Defense for Intelligence (USD(I))?
Provides guidance, oversight and approval authority of policies and procedures that govern the DoD Information Security Program
55
List 4 Types of Declassification Systems
Scheduled Automatic Mandatory Systematic
56
What 2 types of information do not provide declassification instructions?
- Restricted Data - Formerly Restricted Data
57
What information is in a Courier Briefing?
1. The courier is liable for materials 2. Material cannot be left unattended 3. Do not open en route (exception: customs) 4. No public discussion 5. Follow authorized travel route and schedule 6. In emergency, protect classified material 7. Travel documents must be current and valid
58
List 5 Common Briefings
Initial Indoctrination Annual Refresher Debriefing Courier NATO Non-Disclosure Foreign Travel Attestation Antiterrorism/Force Protection
59
List Categories of Classified Information
1. Military plans, weapons systems, or operations; 2. Foreign government information; 3. Intelligence activities (including covert action), intelligence sources or methods, or cryptology; 4. Foreign relations or foreign activities of the United States, including confidential sources; 5. Scientific, technological, or economic matters relating to the national security; 6. United States Government programs for safeguarding nuclear materials or facilities; 7. Vulnerabilities or capabilities of systems, installations, infrastructures, projects, plans, or protection services relating to the national security or the development, production, or use of weapons of mass destruction
60
List 4 Reasons NOT to Classify Information
Concealment of a crime or error Preventing embarrassment Restrain competition Prevent or delay public release
61
List 3 Methods to Derivatively Classify Info
Restating: Taken directly from an authorized source Paraphrase: Re-word in a new or different document Generate: Take from one form and generate into another
62
Who can declassify information?
Secretary of Defense Secretaries of the Military Departments Officials delegated by the OCA Officials delegated as declassification authorities
63
Define Actual Compromise
An unauthorized disclosure of information
64
List 4 Topics of OCA Training
1. OCA Responsibilities 2. Classification Principles and Avoidance of Over Classification 3. Proper Safeguarding 4. Criminal, Civil and Administrative penalties for failing to protect classified nfo
65
What must be included on an SCG cover page?
Date Name of system, plan, program or project Official issuing the guidance (name/personal identifier and position) OCA approving the guide Distribution statement Statement of supercession, if necessary
66
What must be submitted when requesting DoD Original Classification Authority?
Mission specific justification for the request Position
67
Declassification Guide Content
Identifies the subject matter Name and position of the OCA Declass Authority Date of issuance or last review States info to be declassified, downgraded or to remain classified
68
Security Classification Guide Content
Subject matter OCA Agency point of contact Date of approval or last review Identification and delineation of the specific items or elements of information warranting protection Classification levels Reasons for classification Duration of classification Warning and handling notices Dissemination controls Declass instructions
69
If classified information appears in the public media, what is DoD personnel appropriate response?
Neither confirm nor deny Personnel must be careful not to make any statement of comment that would confirm the accuracy or verify the classified status of the information
70
Define Potential Compromise
Possibility that compromise could exist but it is not known with certainty.
71
What must be submitted when requesting DoD Original Classification Authority?
Mission specific justification for the request Position