Showing posts with label Classified Information. Show all posts
Showing posts with label Classified Information. Show all posts

Saturday, February 4, 2023

CRS Reports – Week of 1-28-23 – Classified Information

This week, with increasing congressional interest in the various classified document discoveries in homes of former president and vice presidents, the Congressional Research Service published two reports on the protection of classified information:

Rules and Statutes Relevant to Safeguarding Classified Materials, and

The Protection of Classified Information: The Legal Framework

The first is a three-page overview of the legal standards that apply to protecting classified information. The second is a more in depth (30 page) look at the following related topics:

• Executive Order 13,526,

• Handling of Unauthorized Disclosures by:

Information Security Oversight Office,

Intelligence Community,

Department of Defense,

Department of State,

• Penalties for Unauthorized Disclosure,

• Declassification vs. Leaks and “Instant Declassification”,

• Special Considerations for the President, and

• Insider Threat Risk Management.

Interestingly, neither report contains an ‘issues for Congress’ section. This is almost certainly due to the fact that information classification is almost purely an Executive Branch function. This is discussed in the ‘Background Information’ section of the second document:

“The Supreme Court has never directly addressed the extent to which Congress may constrain the executive branch’s power in this area. Citing the President’s constitutional role as commander in chief, the Supreme Court has repeatedly stated in dicta (i.e., language that does not constitute a legal determination) that “[the President’s] authority to classify and control access to information bearing on national security . . . flows primarily from this Constitutional investment of power in the President and exists quite apart from any explicit congressional grant.” This language has been interpreted to indicate that the President has plenary authority to control classified information.”

Tuesday, December 22, 2020

DOD Publishes NISPOM Final Rule

Yesterday the Department of Defense published a final rule in the Federal Register (85 FR 83300-83364) that codifies the National Industrial Security Program Operating Manual (NISPOM) as 32 CFR Part 117. The NISPOM establishes requirements for the protection of classified information disclosed to or developed by contractors, licensees, grantees, or certificate holders to prevent unauthorized disclosure. This final rule becomes effective on February 24th, 2021.

Coverage

According to the new §117.2 this rule applies to: “All industrial, educational, commercial, or other non-USG entities granted access to classified information by the USG executive branch departments and agencies or by foreign governments” {§117.2(3)}.

Section 117.2(b)(1) goes on to clarify that this rule does not:

“Limit in any manner the authority of USG executive branch departments and agencies to grant access to classified information [emphasis added] under the cognizance of their department or agency to any individual designated by them. The granting of such access is outside the scope of the NISP and is accomplished pursuant to E.O. 12968, E.O. 13526, E.O. 13691, the AEA, and applicable disclosure policies.”

Section 177.22 specifically provides DHS with the “authority to determine the eligibility for personnel security clearances and to administer the sharing of relevant classified NSI with certain private sectors or non-federal partners for the purpose of furthering cybersecurity information sharing [emphasis added] among critical infrastructure partners pursuant to E.O. 13691” {§177.22(b)(1)}. It then goes on to clarify that participating entities “will cooperate with DHS security officials to ensure the entity is in compliance with requirements in this rule” {§177.22(b)(2)}.

Security Requirements

Entities granted access to, or generating, classified information are responsible for complying with all of the requirements of this rule. Major areas of interest will include:

117.3Definitions,

117.4Policy,

117.6Responsibilities,

117.7Procedures,

117.8Reporting requirements,

117.10Determination of eligibility for access to classified information for contractor employees,

117.11Foreign Ownership, Control, or Influence (FOCI),

117.15Safeguarding classified information,

117.18Information system security,

117.21COMSEC, and

117.22DHS classified critical infrastructure protection program (CCIPP).

The reporting requirements of §178.8 require special note. As required in §117.8(1) contractors and their cleared employees are required to report:

• Certain events that may have an effect on the status of the entity's or an employee's eligibility for access to classified information,

• Events that indicate an insider threat to classified information or to employees with access to classified information,

• Events that affect proper safeguarding of classified information; and

• Events that indicate classified information has been, or is suspected to be, lost or compromised.

Commentary

I have long maintained that the governmental classification of cybersecurity threat information is a major impediment to information sharing because of the cost involved in being able to properly receive, store, and disseminate classified information. With the codification of the NISPOM, it should no be clear exactly why I have raised these objections over the years. DHS is going to have to make special efforts to ensure that non-classified information on cyber threats is made readily available. Fortunately, the public reporting on the recent SUNBURST vulnerabilities would seem to indicate that CISA has taken that responsibility to heart.

Saturday, August 29, 2020

DOD Sends NISP Operating Manual to OMB for Review


Yesterday the OMB’s Office of Information and Regulatory Affairs announced that it had received from DOD the “National Industrial Security Program Operating Manual (NISPOM)” for review.

According to the abstract for this action in the Spring 2020 Unified Agenda:

“This rule will codify the National Industrial Security Program Operating Manual (NISPOM) which prescribes specific requirements, restrictions, and other safeguards that are necessary to preclude unauthorized disclosure and control authorized disclosure of Federal Government classified information to contractors, licensees, or grantees. The NISPOM applies to the release of classified information during all phases of the contracting process, including bidding, negotiation, award, performance, and termination of contractors, the licensing process or the grant process, with or under the control of departments or agencies.”

Commentary


No, I am not going to start digging into the ins and outs of NISP. The publication, however, of this manual will probably serve as a good, informational guide to any organization that is considering trying to get routine access to classified cyber-threat intelligence information from the government.

Thursday, February 1, 2018

DHS Publishes Private Sector Clearance Program 60-day ICR Renewal Notice


Today the DHS Office of Infrastructure Protection (IP) published a 60-day information collection request renewal notice in the Federal Register (83 FR 4670-4671) for the Private Sector Clearance Program (PSCP), Cooperative Research and Development Agreement, and Classified Critical Infrastructure Protection Program Request. This collection is for the initial information submitted to DHS to start the security clearance review process for private sector individuals in the following programs:

• Sector Coordinating Councils (SCCs);
• Cooperative Research and Development Agreements (CRADA) with NCCIC;
• Classified Critical Infrastructure Protection Program (CCIPP); and
Cyber Information Sharing and Collaboration Program (CISCP)

This renewal expands the PSCP information collection to include the new CISCP. The revised estimate for the annual burden of this collection includes an expected 600 responses at 10 minutes per response. This burden only covers the initial information collected by DHS not the much more extensive (and very time consuming) background information collected by the OMB’s secure portal for investigation processing.

OIP is soliciting public feedback on this ICR renewal. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # DHS-2017-0061). Comments should be submitted by April 2nd, 2018.

Commentary


The limits on this classified information sharing program outlined in this ICR demonstrate how little sharing of classified intelligence information does with the private sector critical infrastructure. Beyond the normal reluctance of the government to share classified information, there are a number of other factors which help to limit this information sharing process. First and foremost are the expensive requirements for appropriate technology to receive and store classified information.

In the ‘old-days’ when most classified information was stored as paper files, a GSA-approved safe secured in a locked room in a protected building provided ‘sufficient’ protection for all but the most sensitive classified information. That was an expense that could be afforded by most corporations. Today, with classified documents being transmitted and stored in electronic format, the security requirements have dramatically increased and the costs skyrocketed. Even when large corporations can afford such installations in their corporate headquarters, they cannot share the information with their scattered subordinate locations where the intelligence would most likely be used.

As I have said on numerous occasions, to share intelligence information with the increasing number of potentially affected private sector organizations, DHS and the rest of the intelligence community must be more proactive (and maybe more importantly) and timely in abstracting actionable information from intelligence reports (separate from the means and methods information which leads to most classification labels) so that the information may be shared in less-than classified formats.

Monday, May 5, 2014

OMB Announces Approval of DHS Classified Information Rule

On Friday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved for publication the DHS final rule on classified national security information. I suspect that this direct final rule will be published in the Federal Register later this week.

According to the listing in the Unified Agenda (RIN: 1601-AA68):

“The Department of Homeland Security (DHS) is revising its procedures for managing classified national security information. DHS is updating its regulations to incorporate new and revised procedures pursuant to Executive Order 13526, ‘Classified National Security Information’.”

This will entail revisions of 6 CFR 7. Exactly what revisions were made is hard to say since there was no notice of proposed rulemakings (NPRM) associated with this rulemaking process.


There is apparently some level of political concern about this rulemaking as it was submitted to OIRA for review last November. 

Wednesday, November 27, 2013

OMB Receives DHS Rule on Classified Information

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received from DHS a copy of their proposed final rule on classified national security information. According to the information in the most recent Unified Agenda the purpose of this rule is:

“The Department of Homeland Security (DHS) is revising its procedures for managing classified national security information. DHS is updating its regulations to incorporate new and revised procedures pursuant to Executive Order 13526, ‘Classified National Security Information.’ Further, DHS is delegating to the Chief Security Officer of DHS the responsibility of serving as the "Senior Agency Official" pursuant to Executive Order 13526.”

It will be interesting to see the justification for going directly to a final rule without publishing a notice of proposed rulemaking.

The EO referenced dates back to 2009 so this is another real quick response to an executive order.

My guess is that this rule will not have a great deal of effect on most folks outside of DHS since most organizations are not set up to received classified information from DHS. Probably the most affected organizations outside of DHS proper will be the various fusion centers around the country.


There is no telling how long it will take OMB to approve this rule. I would be surprised if we see any action before the end of the year.

Friday, October 25, 2013

NISPPAC Meeting Announced – 11-14-13

The National Archives and Records Administration (NARA) published a meeting notice in today’s Federal Register (78 FR 64024-64025) for the next meeting of the National Industrial Security Program Policy Advisory Committee (NISPPAC) on November 14th, 2013 in Washington, DC.

The announcement only notes that purpose of the meeting is to “discuss National Industrial Security Program policy matters”. The minutes from the last meeting, however, indicate that there will be an update “on the status of E.O. 13587 [Structural Reforms to Improve the Security of Classified Networks and the Responsible Sharing and Safeguarding of Classified Information]
 implementation and its impact on Industry” (page 10).


This meeting is open to the public, but due to space limitations advance registration (ISOO@nara.gov) is required by November 5th.

Friday, August 2, 2013

Bills Introduced – 8-1-13

On the next to last day of the session before the summer recess it was a busy day for the introduction of legislation; 70 bills in the Senate and 86 bills in the House. The following may be of specific interest to the chemical security/safety and cybersecurity communities:

S 1429 Latest Title: An original bill making appropriations for the Department of Defense for the fiscal year ending September 30, 2014, and for other purposes. Sponsor: Sen Durbin, Richard (D,IL)

S 1435 Latest Title: A bill to amend title 49, United States Code, to provide certain port authorities, and for other purposes. Sponsor: Sen Gillibrand, Kirsten E. (D,NY)

S 1462 Latest Title: A bill to extend the positive train control system implementation deadline, and for other purposes. Sponsor: Sen Thune, John [SD]

S 1464 Latest Title: A bill to facilitate and enhance the declassification of information that merits declassification, and for other purposes. Sponsor: Sen Shaheen, Jeanne [NH]

HR 2952 Latest Title: To amend the Homeland Security Act of 2002 to make certain improvements in the laws relating to the advancement of security technologies for critical infrastructure protection, and for other purposes.Sponsor: Rep Meehan, Patrick (R,PA)


HR 2958 Latest Title: To amend title 49, United States Code, to provide certain port authorities, and for other purposes.Sponsor: Rep Nadler, Jerrold (D,NY)

Thursday, July 4, 2013

Unified Agenda – Spring 2013 – Published

Yesterday the Office of Management and Budget posted the Spring 2013 Unified Agenda on their Reginfo.gov web site. This includes the individual agency lists of rule makings that are planned and/or in various stages of completion. It includes links to the ‘Current Long Term Actions’ list of rulemakings that are under consideration.

DHS Rulemakings

Table 1 below shows the current list of DHS rulemakings on the Unified Agenda that will be of specific interest to the chemical safety and security communities. Chemical safety is not normally considered an DHS concern, but it is one of the missions of the Coast Guard so some chemical safety rulemakings are included on the DHS list.

OS
Final Rule
Ammonium Nitrate Security Program
OS
Final Rule
Classified National Security Information
USCG
NPRM
Updates to Maritime Security
USCG
Final Rule
Transportation Worker Identification Credential (TWIC); Card Reader Requirements
USCG
Final Rule
Bulk Packaging To Allow for Transfer of Hazardous Liquid Cargoes
USCG
Final Rule
Revision to Transportation Worker Identification Credential (TWIC) Requirements for Mariners
USCG
Final Rule
2012 Liquid Chemical Categorization Updates
TSA
NPRM
General Aviation Security and Other Aircraft Operator Security
TSA
NPRM
Security Training for Surface Mode Employees
TSA
NPRM
Freight Railroads and Passenger Railroads--Vulnerability Assessment and Security Plan
TSA
NPRM
Standardized Vetting, Adjudication, and Redress Services
Table 1: Current DHS Chemical Safety/Security Rulemakings

Comparing this latest Unified Agenda with the previous version published last December there are no major deletions or additions on the list of regulatory actions that the chemical safety/security communities will be specifically interested in on the DHS list (I’ll take a quick look at DOT and EPA lists in a separate post). The TWIC Card Reader rule did move into the ‘Final Rule’ category since the NPRM for that rulemaking has been published.

It hasn’t really struck me until today, but there are no cybersecurity specific rule makings on the DHS list.

There was some movement from the long term actions list to the current Unified Agenda, those items have been marked in BOLD in the table above.

The only changes within the rulemaking plans for these items are changes to the expected dates of the next action. The dates included in the Unified Agenda are, at best, hopeful guesses and the further they are in the future the less accurate they become.

In fact, the only date provided for the rulemaking activities listed above that is worth discussing is the July 2013 date for the Bulk Packaging To Allow for Transfer of Hazardous Liquid Cargoes rulemaking by the Coast Guard. The NPRM was published last year and the ‘expected date’ for the Final Rule is this month. If it is published by the end of July I will be surprised and I will be disappointed if it isn’t published by the end of September.

Long Term Actions

The Long Term Actions list is shown in table 2 below. There are no new additions to this list.

USCG
Top Screen Information Collection From MTSA-Regulated Facilities Handling Chemicals
TSA
Protection of Sensitive Security Information (SSI)
TSA
Drivers Licensed by Canada or Mexico Transporting Hazardous Materials To and Within the United States
Table 2: Long Term Actions

The last two items in the table already have interim final rules in place and just require TSA to respond to comments filed on that action and update the rule. The interim final rules date back to 2004 and 2006 and there is no incentive for TSA to take any action to ‘complete’ these rulemakings.

The Coast Guard Top-Screen for MTSA facilities rule is a slightly different story. This was initiated as part of a congressionally mandated harmonization of the chemical security rules under CFATS and MTSA and keeps moving back and forth between the Unified Agenda and the Long Term Actions list. I doubt that any action will ever be taken on this unless there is an attack on a chemical facility covered by MTSA.


BTW: The Pending DHS Security Rules page on this blog has not been updated in a while; it is hard to get motivated to update it since DHS is SOOOOO slow in moving their rules along. The Obama Administration’s resumption of periodically publishing the Unified Agenda will provide the needed impetus for getting that page updated.

Thursday, June 20, 2013

Impediments to Information Sharing

There is an interesting article over at FederalNewsRadio.com discussing some of the challenges that DHS is trying to overcome in order to provide an information sharing environment about cybersecurity issues. One of the issues raised in the article concerns the difficulty that DHS is having in expanding the participation in the Enhanced Cybersecurity Services (ECS) program. This is the program established to share classified threat information with potentially affected private sector organizations.

Sharing Classified Information

In order to encourage the sharing of this classified information, Congress has focused on directing the DHS Secretary to work on reducing the red tape necessary to get security clearances for private sector employees. Unfortunately, the effective sharing of classified information requires lot more than just providing security clearances; an infrastructure must be put into place to receive, store and protect that information.

Security Requirements for Classified Information

Unless DHS is going to rely on couriers with manacled briefcases to deliver and retrieve classified documents to and from private sector organizations, some sort of secure communications equipment will have to be installed. While modern crypto gear has certainly progressed past the point of the equipment I used in the Army 30 years ago, this still requires special equipment that must be secured against theft and tampering and requires some level of training to operate. Even something as simple as a secure telephone must be placed in an isolated room so that classified conversations may not be overheard through other communications devices.

To be useful, classified threat information will have to be discussed within an organization, documents will have to be prepared, stored and shared, and provisions will have to be made for the destruction of classified documents and devices. An entire information security apparatus, maintained to government (ie: military) standards will have to be established, maintained and periodically audited by a government agency.

Cost of Classified Infosec Program

Now many organizations already work on classified projects for the military or intelligence community, so they will already have this type of operation in place. I would bet that the ‘seventeen or so’ companies that are currently participating in ECS program already had a DOD approved information security program in place. Establishing a military-grade infosec program will just be too costly (in set up and maintenance) to make it worthwhile for most organizations based upon possible access to actionable intelligence about a classified cyber-threat.

Alternative Required

No, while the ECS program will be viable for a limited number of organizations that already have an infosec program in place, DHS is going to have to come up with an alternative that does not rely on these specialized information control measures. Someone is going to have to establish a methodology for converting classified intelligence information into actionable information for the private sector that only requires limited infosec capabilities.


Readily achievable standards for the protection of that information will have to be developed if DHS expects to establish a cyber-threat information sharing capability that will involve the sharing of high-quality threat information with the bulk of critical infrastructure organizations. Something along the lines of the Chemical-Terrorism Vulnerability Information (CVI) program used by the CFATS program would probably be adequate since it has a manual that provides guidance on how to mark and protect the information.

Monday, December 24, 2012

Closer Look at 2012 DHS Rules List


As I mentioned in my earlier blog post the OMB’s Office of Information and Regulatory Affairs (OIRA) recently update their Unified Agenda and the associated agency rule lists. Today I would like to take a closer look at the rulemaking actions on the DHS Rule List that would be of potential interest to readers of this blog.

Classified Information


The one new rulemaking listing in this List deals with the DHS regulation of Classified National Security Information (RIN 1601-AA68). According to the Abstract:

“The Department of Homeland Security (DHS) is revising its procedures for managing classified national security information. DHS is updating its regulations to incorporate new and revised procedures pursuant to Executive Order 13526, ‘Classified National Security Information.’ Further, DHS is delegating to the Chief Security Officer of DHS the responsibility of serving as the ‘Senior Agency Official’ pursuant to Executive Order 13526.”

Apparently the folks at DHS are intending to go directly to issuing a Final Rule in May, 2013 without the intermediate step of issuing a notice of proposed rulemaking. This methodology is allowed if the rule only affects internal actions in the Department and has no significant impact on State, local or tribal governments of private citizens. We will just have to wait and see what the Final Rule actually says.

Maritime Shipping Safety


We have two rulemakings from the Coast Guard dealing with maritime shipping safety that remain on the DHS Rule List. They are:

• Cargo Securing on Vessels Operating in U.S. Waters (RIN 1625-AA25)

• Bulk Packaging To Allow for Transfer of Hazardous Liquid Cargoes (RIN 1625-AB63)

Neither of these has a statutory mandate for date of issue. The Coast Guard intends to issue a supplemental Cargo Securing NPRM in April and a final rule for the Bulk Packaging rule in January.

Maritime Security


There are two Coast Guard rulemakings on the List that deal with MTSA issues. They are:

• TWIC Card Reader Requirements (RIN 1625-AB21)

• Updates to Maritime Security (RIN 1625-AB38)

The Card Reader rule has been long delayed, partly due to problems the TSA had with their field trials of various card readers. The final rule was required to be published in August of 2010 and the Coast Guard is now estimating that the notice of proposed rulemaking will be published in February. As I noted in an earlier blog posting this rule has already been sent to the OMB for review so this date may not be too far out of line, but that still leaves us at least a year before the final rule is published.

According to the Abstract for the Updates to Maritime Security rulemaking this would be the first major update to Subchapter H of 33 CFR since the MTSA regulations were adopted. The Abstract explains that:

“The proposed changes would further the goals of domestic compliance and international cooperation by incorporating requirements from legislation implemented since the original publication of these regulations, such as the SAFE Port Act, and including international standards such as STCW security training. This rulemaking has international interest because of the close relationship between subchapter H and the International Ship and Port Security Code (ISPS).”

The Coast Guard is planning on issuing the NPRM for this rulemaking in April of 2013.

General Aviation Security


TSA is still struggling to overcome resistance to rules governing the security of general aviation aircraft. Their NPRM that was published in 2008 met so much opposition from the public and Congress that TSA will be issuing a ‘supplemental’ NPRM that will almost certainly be a total re-write of their General Aviation Security and Other Aircraft Operator Security rulemaking (RIN 1652-AA53). They expect to issue their supplemental in August of 2013.

Surface Transportation Security Training


A while back TSA rolled three congressionally mandate rulemaking requirements into a single rulemaking, Security Training for Surface Mode Employees (RIN 1652-AA55). The thee mandated publication dates were in 2007 and 2008 and TSA has yet to produce their first public version of the rule that would “propose general requirements for the owner/operators of a freight railroad, public transportation system, passenger railroad, and an over-the-road bus operation determined by TSA to be high-risk to develop and implement a security training program to prepare security-sensitive employees, including frontline employees identified in sections 1402 and 1501 of the Act [the Implementing Recommendations of the 9/11 Commission Act of 2007], for potential security threats and conditions”.

While that certainly seems to be a fairly comprehensive program TSA also intends to extend the “security coordinator and reporting security incident requirements applicable to rail operators under current 49 CFR part 1580” to other portions of the surface transportation industry.

TSA expects to have the NPRM finally go to publication in July of 2013.

Railroad Security Planning


Another long overdue requirement from the Implementing Recommendations of the 9/11 Commission Act of 2007 is the Freight Railroads and Passenger Railroads--Vulnerability Assessment and Security Plan rulemaking (RIN 1652-AA56). According to the Abstract:

“This rulemaking will propose thresholds for which a risk determination can be made to determine whether a freight railroad and passenger railroad should be considered "high risk." The rulemaking will also propose requirements for vulnerability assessments and security plans for owner/operators of those railroads. The proposed requirements include procedures for TSA's review and approval of these assessments and plans, and recordkeeping requirements. The regulation will take into consideration any current security assessment and planning requirements or best practices.”

This rule could easily become the TSA’s version of the CFATS regulations in scope and impact, potentially requiring a significant expansion of the number of Surface Transportation Security Inspectors, something never authorized by Congress; coming up with an effective rule that can overcome that funding obstacle is a real challenge. TSA expects to have the NPRM published by July of 2013.

TSA Security Threat Assessments


The TSA does the security threat assessments for a number of travel related security programs including the Hazardous Materials Endorsement for CDLs and the TWIC as well as future programs such as the CFATS personnel surety program. Each of these programs is currently governed by a slightly different set of rules. With this Standardized Vetting, Adjudication, and Redress Services rulemaking (RIN 1652-AA61) the TSA “intends to propose new regulations to revise and standardize the procedures, adjudication criteria, and fees for most of the security threat assessments (STA) of individuals for which TSA is responsible”. According to the Abstract:

“In accordance with the Implementing Recommendations of the 9/11 Commission Act of 2007 (9/11 Act), the scope of the rulemaking will include transportation workers from all modes of transportation who are required to undergo an STA in other regulatory programs, including certain aviation workers and frontline employees for public transportation agencies and railroads. In addition, TSA will propose fees to cover the cost of the STAs and credentials for some personnel. TSA plans to improve efficiencies in processing STAs and streamline existing regulations by simplifying language and removing redundancies.”

TSA intends to issue their notice of proposed rulemaking for this rule in July of 2013.

Actual Dates for Rulemaking


The dates that I have been reporting for the intended date that DHS components would act on these rulemakings were provided in the DHS Rule List. There is no statutory requirement about the accuracy of these estimates and, even if there were, DHS is more than notorious for missing congressionally mandated deadlines. The only one of the above listed dates that I would have any sort of confidence in is the one for the TWIC Reader Rule and that is because it has already been submitted to OMB for approval, but even that could be delayed for months in the OMB approval process and there is no guarantee that OMB will approve the submitted NPRM.

Tuesday, December 7, 2010

HSIN and Wikileaks

Bob Radvanovsky at SCADASEC List published an email from the people that manage the Homeland Security Information Network (HSIN) reminding folks that potentially have legitimate access to classified information that the Wikileaks publication of classified documents does not make them unclassified. Specifically, the email notes:
“Executive Order 13526, Classified National Security Information (December 29, 2009), Section 1.1.(c), states ‘Classified Information shall not be declassified automatically as a result of any unauthorized disclosure of identical or similar information.’”
They also remind HSIN users that “if any classified material that has not been declassified by proper authority is uploaded in HSIN, it is considered a security incident as serious as any other and will be treated as such”. It wouldn’t matter if the information was obtained from an unclassified source (Wikileaks), it would still be a violation of the rules since HSIN is not cleared for the discussion of classified information.

The Rules are Rules

Those of us who are familiar with the standards for handling and declassifying classified information are well familiar with these rules. In part those rules were designed to protect classified information that was published in limited release from further being publicized, particularly if the released information was not identified as being classified.

Additionally, the current rules designed to prevent an open dialog that would confirm that an isolated document purporting to be a classified document was really and truly what it purported to be. Keeping the in-government discussion of the document classified would allow the government to deny the legitimacy of the document by ignoring it.

The current classified document rules have procedures in place for a review of a compromised document to determine if the classification should be reduced or removed. As one might expect the review procedure is a tad bit bureaucratic. It will be a long time before all of the Wikileaks documents have been so reviewed.

Obviously these rules were never designed to deal with a security breach the size of the Wikileaks fiasco. Unfortunately, just because the rules were not designed for this probably to be repeated problem does not mean that they can be ignored. The rules will almost certainly have to be revised for this type of security breach, but until they are the rule enforcers will still have to enforce those rules.

Unenforceable Rule

There is a more controversial part of the same email that requires some thought. The email states:

“HSIN contractors and users must not knowingly access, download or attempt to download, from any unclassified system, any information from a public web-site that is believed to be classified, nor should they comment [on] or confirm the degree of sensitivity of such information, or, discuss the content in a potentially classified document with persons who would not otherwise be authorized access.”
There are three distinct portions of this legalistic sentence. The last two parts are the easiest to understand. The reason for ‘commenting on or confirming the degree of sensitivity’ goes along with the standard reasoning that without this type of confirmation, the ‘enemy’ will never really be sure that it is a legitimate document, providing some small measure of information protection. Discussing the content with unauthorized personnel is easy to understand.

If you understand the last two parts, you can begin to understand why the first part, the controversial part, of the paragraph came into being. If someone with routine access to unclassified government communications networks, like HSIN, were to access the Wikileaks cables, there might be some confusion as to its security classification status in that person’s mind. That confusion could lead to the type of problems identified as being prohibited in the last two parts of the sentence.

Now, I certainly understand the intention of this complex directive from HSIN and I even agree to a certain degree with its intent. Unfortunately, from a practical view point it is unenforceable (I’ll leave the issue of legal enforceability to the lawyers; I AM NOT A LAWYER). There are just too many devices with which one could conduct such a search or download that the government would never have the opportunity to ensure that such searches were not done; particularly considering that so many of the documents have been reposted on so many different sites..

Now, one of the first leadership lessons that I learned as a young NCO was that you should never give an order that you know will be disobeyed; it makes you look stupid and undermines your authority. This is especially true when, as in this case, there are so many legitimate reasons for ignoring the prohibition. For example, many HSIN users will have a real interest in determining if one or more of the projects that they might be working on may have become compromised by one or more of the leaked documents.

Now I am not going to advocate ignoring this directive. I understand the reason for it being issued, and if it is followed there will be less chance of an inadvertent disclosure or discussion of the classified information in an inappropriate setting. I also understand the reasons and motivations for ignoring the rule. I will warn my readers though, if you do violate it, you are going to have to take some precautions to ensure that you can still identify the information as being classified. Other wise you will inevitably make a mistake that could result in your loosing access to classified information; a very negative mark on one’s career in the security industry.
 
/* Use this with templates/template-twocol.html */