OFFICE OF THE UNDER SECRETARY OF DEFENSE 5000 DEFENSE PENTAGON WASHINGTON, DC

Similar documents
DoD Plain Writing Act Compliance Report April 13, 2018

'i'~~~ DEPARTMENT OF DEFENSE OFFICE OF FREEDOM OF INFORMATION 1155 DEFENSE PENTAGON WASHINGTON, DC OCT 2015.

PLANNING SECTION CHIEF

PRIVACY IMPACT ASSESSMENT (PIA) For the

Quincy University Grants Development & Management Guide

LOGISTICS SECTION CHIEF

Inpatient Rehab/LTLD Discharge Planning Practices Pre- and Post-Implementation Survey Results of TC LHIN Hospitals

Government of Ontario IT Standard (GO-ITS) GO-ITS Number 56.5 OPS Grants Management Reference Model

EMPLOYEE FAMILY CARE UNIT LEADER

OLTL Transition Plan CMS HCBS Regulations. Introduction

Guidelines for Analysis of Credentials to be Included on COOL

Appendix B: Welcome Baby: Summary of Job Responsibilities for Key Personnel

JOB DESCRIPTION. Director of Corporate Affairs and Governance. Corporate Affairs and Governance (1.0 WTE)

Denver Public Schools. Financial Services. Financial Services Manual. Grants

Annual South Carolina School Health LPN of the Year Award ( )

MANUAL SURGE CAPACITY PROTOCOL

Joint Commission Resources Content Proposed for PerforMax 3 Created On-Line Learning Lessons

PAPER FOR NHS LUTON COMMUNITY SERVICES BOARD MEETING HELD ON 21 ST APRIL 2010

GRANT GUIDELINES FOR ORGANIZATIONS 2017 CYCLE

Original Date: January 27, 2010 Reviewed/Last Modified Date: September 15, 2015

Defense Suicide Prevention Office (DSPO) Initiatives. Ms. Jacqueline Garrick, LCSW-C, BCETS Director, DSPO

Roles & Responsibilities Local Rural Addressing Committee Navajo Nation Rural Addressing Roll-out

Medical Assistance in Dying: Update Stakeholder Presentation

Our Epic Project Frequently Asked Questions

GRANT APPLICATION. Sustainable Agricultural Land Strategy Grants SUSTAINABLE AGRICULTURAL LANDS CONSERVATION PROGRAM

Quality Improvement Plan (QIP) Narrative for Health Care Organizations in Ontario

YOUTH What is Heads Up Football? What are the benefits of a youth football organization adopting Heads Up Football?

Application. Community Health Excellence (CHE) Grant Program

Practice Improvement Network (PIN) Project Application

Working Location: Science Council office in Farringdon, London. With some London and UKtravel

Financial Officer 18 Applicant Inventory

CHAPTER 6 NETWORK REQUIREMENTS

ARMTEC POSITION DESCRIPTION

Response to Recommendations in Report: Salt Spring Island Health Services Review

Instructions. Important Dates. Application Deadline: May 15, 2013 at 5:00 p.m. Grant Awards Announced: July 15, 2013

LSU HEALTH SHREVEPORT NOTICE OF PRIVACY PRACTICES FOR PROTECTED HEALTH INFORMATION

February 11, 2011 Volume 16 Number 2 Infection Control F441

EMPLOYEE INNOVATION GRANTS (EIG)

Residential Mental Health Treatment for Children and Adolescents

Environment, Health and Safety Policy Appendix B: Environment, Health and Safety Responsibilities

Security Force Assistance Brigade (SFAB) Frequently Asked Questions (V.1)

Culture of Safety Next Steps Tools-Support

AGENCY NAME - Crisis Stabilization Services

FOCUS AREA 1: Creative use of Existing Infrastructure for Future Transportation Needs:

CENTRAL MANCHESTER UNIVERSITY HOSPITALS NHS FOUNDATION TRUST

Resident Assistant Application

WORKFORCE IMPLEMENTATION GUIDANCE (WIG) LETTER RELEASE OF GEORGIA LWDA STRATEGIC PROGRAMMING GRANTS

SEQOHS Accreditation Assessor Job Description

SOP #: Environmental Health and Safety. Implementation Date: Page #: Page 1 of 9 Last Reviewed/Update Date: 08/01/2010 Expiration

Administration of First Aid Policy

Oregon Registry. Infant Toddler Professional Credential. Overview. Oregon Center for Career Development in Childhood Care and Education

Guidance on Superintendent Evaluation

Draft III Revisions December 2017

Access to Mental Health Care Assessment and Treatment - General. Document author Assured by Review cycle. Quality and Safety Committee

Tourism Events Grants. FY 2019 (July 1, 2018 June 30, 2019)

Critical Access Behavioral Health Agency (CABHA) UPDATE

CANADIAN FOUNDATION FOR DIETETIC RESEARCH LA FONDATION CANADIENNE DE LA RECHERCHE EN DIETETIQUE

SAMPLE- Visit FirehouseSubsFoundation.org to apply online. Firehouse Subs Public Safety Foundation Grant Application

September 26, Dear Chairman Tiberi:

Army Regulation Management. RAND Arroyo Center UNCLASSIFIED

Job & Person Specification

Medical Directors Council. Goals and Strategic Directions 2013

Inter-Service Transfer of Army Commissioned Officers on the Active Duty List

THE FOX THEATRE INSTITUTE

2019 IGP Faculty Research Initiation Grant

The information and instructions below are for College of Business Administration [Departmental] Scholarships only.

Slowing Ohio s Medicaid Per Capita Spending - Progress to Date

Department of Exercise and Nutrition Sciences. Master of Public Health Public Health Nutrition. Academic Year

Learning Together From Safeguarding Adult Reviews

Yes, USERRA Applies to 12304b Duty

EXPLANATORY NOTES. (applicable from 1 July 2015) STAGE 1 DESKTOP ASSESSMENT. for the RECOGNITION OF OVERSEAS OCCUPATIONAL THERAPY QUALIFICATIONS

Directions & Instructions for Filing an Application to the Radiologic Technology Program

Outbreak Investigation Team Roles and Responsibilities

Long course title: Experience the product development process first hand by teaming with a business to define a commercialization plan

AOTF Health Services Research Grant Request For Application

TRAINING PLAN FOR STEM OPT STUDENTS

Resident Assistant Application

Position Description

BEHAVIORAL HEALTH STAFF COVERAGE PROTOCOL. Psychiatrist and Psychologist Coverage Plan...4. Telemedicine.7

DOCUMENT TITLE: Clarification of Bureau of Primary Health Care Credentialing and Privileging Policy outlined in Policy Information Notice

Service Description: Cisco ACI Implementation Review Service (CON-AS-ACI-IMP-REV)

April 2, Jennifer Kent Director California Department of Health Care Services 1501 Capitol Avenue Sacramento, CA 95814

BROCKTON AREA MULTI-SERVICES, INC. ORGANIZATION AND POLICY GUIDE

SC Launch Grant Programs Qualifications and Processing Procedures Effective August 1, 2017

Cambridgeshire Escalation Policy - Resolution of Professional Disagreements in Safeguarding Work

Safety in Practice Compliance and Risk Assessment Procedure January, 2017

Department of Exercise and Nutrition Sciences. Master of Public Health Public Health Nutrition. Academic Year

2018 HBS New Venture Competition Student Social Enterprise Track

About this guide 5 Section 1: Meeting VET sector requirements 7

USF GME - Moonlighting Privileges Request July1, 2018 June 30, 2019

individual Fellows who are interested in designing their own performance assessment strategy using data recorded in their charts or health records

JOB DESCRIPTION. Eastbourne

SOUTHAMPTON UNIVERSITY HOSPITALS NHS TRUST Trust Key Performance Indicators December Regular report to Trust Board

CANADA-LUXEMBOURG CO-DEVELOPMENT AND CO-PRODUCTION INCENTIVE FOR AUDIOVISUAL PROJECTS GUIDELINES

Freedom to Speak Up Report

Terminating the Provider- Patient Relationship. Provided by Coverys Risk Management

Chronic Disease Self-Management Program (CDSMP) Evidence-based Chronic Disease Self-Management Program for Older Adults

State of Florida Department of Children and Families

1. CIMA S SEEDCORN RESEARCH APPLICATION PROCESS: FEASIBILITY STUDIES

STUDY: OUTPATIENT SURGERY MAGAZINE AGAIN RANKED BEST AMONG SURGERY FACILITY MANAGERS

Transcription:

OFFICE OF THE UNDER SECRETARY OF DEFENSE 5000 DEFENSE PENTAGON WASHINGTON, DC 20301-5000 JUN 2 7 2012 INTELLIGENCE Mr. Jhn P. Fitzpatrick Infrmatin Security Oversight Office Natinal Archives and Recrds Administratin 700 Pennsylvania A venue, NW Washingtn, D.C. 20408 Dear Mr. Fitzpatrick: In respnse t yur letters dated January 27,2011 and January 23, 2012, enclsed please find the Final Reprt fr DD's Fundamental Classificatin Guidance Review (FCGR). This reprt prvides a summary f ur effrts frm 2011-2012 t facilitate implementatin f sectin 1.9 f Executive Order 13526. We appreciate having the pprtunity t wrk with yur staff n this endeavr. If yu shuld have any questins, please cntact r Sincerely, ~ccq::l ~ Timthy A. Davis Directr f Security Enclsure: As stated cc: Principle Deputy Directr f Natinal Intelligence

FINAL REPORT: DEPARTMENT OF DEFENSE FUNDAMENTAL CLASSIFICATION GUIDANCE REVIEW (FCGR) I. Intrductin/Purpse. In accrdance with Executive Order 13526, Classified Natinal Security Infrmatin; 32 Cde f Federal Regulatin (CFR) Part 2001, Classified Natinal Security Infrmatin; and Infrmatin Security Oversight Office letters dated January 27, 2011 and January 23, 2012, agencies are required t cmplete an initial FCGR by June 27, 2012. This dcument prvides DD's final status reprt f ur FCGR activities frm 2011-2012 and results achieved t date. Since ur February 16, 2012 interim status reprt, the Department has cmpleted the initial FCGR and is maintaining steady prgress n updating ur Security Classificatin Guides (SCG)s. Thrughut this prject we have fcused n ensuring that classificatin guidance reflects current peratinal I warfighter needs and technical infrmatin prtectin requirements, while delivering up-t-date and readily available guidance n the prper classificatin f infrmatin. Majr strides have been made in centralizatin f ur SCGs and simplifying their disseminatin and availability. As a result f these effrts, 97% f DD's SCGs have been updated and/r declared current, and apprximately 20% f DD's nn-cmpartmented SCGs have either been eliminated r identified fr retirement. Detailed metrics are presented in Sectin II, belw. II. FCGR Status Reprt. a) DD Cllateral-level (nn-cmpartmented) FCGR Results: Effective June 26, 2012, DD Cmpnents have reprted the fllwing FCGR metrics: Ttal number f SCGs identified/reprted: 2,070 (up frm 1,799) Ttal number f SCGs fr which a FCGR has been initiated: 2,070 (up frm 1,703) Ttal number f SCGs fr which a FCGR has nt been initiated: 0 Ttal number f SCGs fr which a FCGR has been cmpleted: 2,064 Ttal number f SCGs scheduled fr retirement/cancellatin: _ill Ttal number f SCGs reprted active/current: 1,657

Cmpnent-by-Cmpnent FCGR reprting details are presented at Attachment 1. b) Remaining Challenges: Nthing significant t reprt. Our FCGR prgram cntinues t evlve, and will remain a high-interest item fr cntinuus attentin by the Defense Infrmatin Security Advisry Bard (DISAB) and the Defense Security Enterprise Advisry Grup (DSEAG). FCGR executin and mnitring effrts f the OUSD(I) staff are in cmplete alignment with DD IG's nging implementatin fthe Reducing Overclassificatin Act (ROA, PL. 111-258), and we lk frward t integrating results f DD IG's ROA findings, particularly as they relate t SCG accuracy, availability, and utilizatin by DD persnnel. c) Other Initiatives: OUSD(l) staff cntinues t generate brad FCGR lessns learned cmmunicatins, as well as cnduct nearly cntinuus Cmpnent-level engagements t imprve existing SCGs, help rganize the staffing prcess fr any new SCGs, and recmmend methdlgies t either cancel r cmbine existing SCGs t create "capstne"-level SCGs. Over the past tw years, this apprach has resulted in the cancellatin f mre than 400 SCGs, nearly ne-fifth f the DD's hldings. In supprt f recent hrizntal prtectin initiatives regarding DD Critical Prgram Infrmatin (CPI), the Navy' s Security Classificatin Guide Management Systems (SCGMS) was pened t the Acquisitin Security Database (ASDB). Originally develped by Navy, the ASDB is nw under the cntrl, versight, and management f the Directr, Defense Research and Engineering (RDA) and has been designated as the DD's central hrizntal prtectin database. USD(I) participates in wrking grups and will cntinue t wrk clsely with the acquisitin cmmunity t achieve unity f effrts between Security and Acquisitin Cmmunities. Our update t DD 5200.1H, Handbk fr Writing Security Classificatin Guides, is in prcessing fr frmal crdinatin fr cnversin t a DD Manual. We anticipate 2

releasing a final draft t the Cmpnents fr frmal review and crdinatin during 4Q, FY12, and signature by USD(I) in early FY13. d) DD Intelligence Cmmunity Element Reprting: Thrughut the FCGR, OUSD(I) staff maintained clse crdinatin with the ODNI!Principle Deputy Directr f Natinal Intelligence staff. Per the ODNI's previus guidance t the Intelligence Cmmunity, DIA, NGA, NSA, and NRO reprted their FCGR executin status directly t ISOO, with a cpy prvided t USD(I). All DD Intelligence Cmmunity (IC) elements successfully cmpleted the FCGR. e) Military Department FCGR Activities and Initiatives: Department f the Army: Fr many years, Army has wrked t bth minimize the number f its OCAs and SCGs. As a result f FCGR prgram develpments, user cmmunity requirements, and general Service needs, the Army has established a database that cntains all f the Army's cllateral-level SCGs, and which is available t bth security prfessinals and freign disclsure fficers thrughut the Army. This effrt parallels Army's wrk with DTIC t ensure their hldings are cmplete and maintained in an up-t-date manner. Additinally, Army security prfessinals have met with the Army Inspectr General (IG) staff n the general subject f SCGs (creatin, maintenance, usage) and will assist them in develping/refining the checklists used by IG teams as they cnduct security inspectins. As a result, FCGR requirements and prgram efficacy will be rutinely assessed. The Army plans t update their plicies as required t ensure MACOMs als maintain a listing f SCGs that fall under their purview. There is n such requirement at present, a fact that has added t the time needed t accmplish the FCGR. As with ther DD Cmpnents, Army anticipates this effrt will be nging lng after cmpletin f this initial FCGR; therefre reprted numbers f SCGs are expected t fluctuate fr sme time. 3

Department f the Navy: The Department fnavy (DON) began with, and still maintains, the largest cllectin f SCGs in the DD. The Service necessarily utilized a wide-ranging series f wrking grups cmprised f subject matter experts, technical warrant hlders, SCG users, and security prfessinals t cmplete the FCGR effrt. As a current initiative, DON has identified and initiated a Security Classificatin Guide Management Systems (SCGMS) t effectively manage its SCGs. The SCGMS architecture and structure prvides a hrizntal cmparisn acrss "like" SCGs, identifying classificatin differences and establishing a classificatin baseline fr infrmatin elements. Additinally, the SCGMS will be used t initiate, prcess, and deliver standardized SCGs via cmmn templates; track SCG cmpliance acrss the DON cmmands and warfare functinal areas; and prvide SCG graphic visual aids (graphs and charts) which display key perfrmance indicatrs. The SCGMS will supprt a metrics-based management and trend analysis capability fr assessing verall cmpliance and prcess efficiencies such as SCG turnarund time, repetitive cycle time, and resurce utilizatin in managing the SCG prgram, all key inputs necessary t infrm leadership n prgram efficiency and effectiveness. Department f the Air Frce: The Air Frce pursued an aggressive, dual-prnged apprach t FCGR executin: the Original Classificatin Authrity (OCA) ppulatin and the universe f SCGs were reviewed against EO 13526 requirements, in rder t determine and validate requirements fr OCA psitins and t identify and cancel duplicative SCGs. As a result, the Air Frce achieved a 29% decrease in OCAs thru the perid f this reprt. The service will likely cntinue t identify OCA psitins fr whm a demnstrable and cntinuing need fr that authrity is lacking, and eliminate them. Develping and validating the Air Frce's inventry f SCGs was extremely challenging yet prductive. The large drp-ff achieved in Air Frce SCGs was 4

due t entries fr many ld and/r bslete SCGs which were imprperly categrized n the legacy master list. During FCGR executin, the Air Frce separated these kinds f dcumentatin updates frm its wrk actually cnducting the FCGR, and therefre did nt certify that all updates have been prvided t DTIC with the applicable DD Frm 2024, DD Security Classificatin Guide Data Elements. " The Air Frce is, hwever, well pstured t frmally manage this fllw-n phase as FCGR wrk will cntinue. The Air Frce managed the FCGR prcess primarily thrugh cllectin f a series f mnthly and weekly suspense reprts, designed t keep OCAs and security prfessinals sharply fcused n the task. The primary lessn learned was the difficulty in changing Service SCG methdlgy, frm a lng histry f imprperly managing many SCGs at the unit, wing, MAJCOM, and Air Staff levels. As f this reprt, the Air Frce has zer verdue SCGs, and all MAJCOMs with SCGs are acutely aware f the requirement t prperly manage SCGs. The Air Frce will cntinue with its versight f this prject at all levels t ensure that SCG creatin, management, and retirement is rutine and well managed. f) Jint Staff As f June 25, 2012, all Jint Staff SCGs are deemed cmpliant with current security classificatin plicy and have been evaluated as part f the FCGR. The Jint Staff and the Cmbatant Cmmands cnducted the FCGR via frmal tasking utilizing the Jint Staff Actin Prcess (JSAP), in rder t identify the SCGs under their purview and cnduct a quality review. Methdlgy: The JS's FCGR review relied upn subject matter experts bth internal and external t the rganizatin bearing primary equity fr the infrmatin, while addressing the fllwing elements: 1. Evaluatin f verall SCG cntent; 11. Determinatin that the infrmatin cnfrms t the current peratinal and technical circumstances and user cmmunity requirements; 5

111. Ensuring the SCG meets the classificatin standards and criteria under sectin 1.4 f the Order, and damage assessments meet criteria under sectin 1.2 fthe Order; IV. Disseminatin and availability f the guidance is t the prper users, and is apprpriate and timely; v. Cnsiders a review f decisins based n the guidance t ensure they reflect the intent f the guidance as t what is classified, the level f classificatin is apprpriate, and the infrmatin is prperly marked fr duratin and declassificatin; v1. Nne f the Cmbatant Cmmands indicated that any JS equity infrmatin had been declassified because f the FCGR, therefre n summaries will be released t the public. Challenges: Obtaining Cmbatant Cmmands' fcus t cllect infrmatin necessary t cmplete this type f data call in the midst f engaging in n-ging military peratins and missins. Summary: The Jint Staff Security Office will cntinue t prvide versight at all levels t ensure all SCGs are prperly created, managed, maintained, and rutinely reviewed fr currency. The primary methdlgy t d this will be via an annual data call t cllect necessary infrmatin and ensure nging versight f the SCG review prcess. g) Defense Agencies Defense Infrmatin Systems Agency (DISA): Like all Cmpnents, DISA was extremely active in its FCGR prcess executin. Agency leadership cntinues t wrk with its subject matter experts t determine the way-frward fr several SCGs fr which a final reslutin and way-frward decisin is pending. USD(I) will cntinue t clsely mnitr the Agency' s prgress and prjects final cmpliance and prject cmpletin by August 31, 2012. Defense Advanced Research Prjects Agency (DARPA): 6

DARPA maintains a small number f highly technical SCGs. A brief summary f primary tpics f infrmatin classified by DARPA OCAs include: Cyber Defense, Manned Platfrms, Space Operatins, and Electrnic Warfare. As a result f the FCGR, all f DARPA's SCGs were successfully inventried, assessed, and deemed cmpliant with extant security classificatin plicy. Necessary updates were prvided t DTIC with the applicable DD Frm 2024. Ultimately, n brad categries r families f classified infrmatin were declassified as a result f the DARPA FCGR effrt. T ensure successful FCGR executin, DARPA frmed internal wrking grups and dispatched SCGs t the apprpriate DARPA technical ffice subject matter experts wh examined all classificatin decisins and the SCG's relevancy. Recmmendatins were prvided t the applicable OCAs fr final determinatin as t the guide's status. Defense Threat Reductin Agency (DTRA): DTRA classifies infrmatin that deals with but is nt limited t the research and develpment f capabilities t reduce, eliminate, and cunter the threat f, and mitigate the effects f Weapns f Mass Destructin (chemical, bilgical, radilgical, nuclear) and high-yield explsives. Because f this sensitive, current, and nging missin, all f the infrmatin cntained in cancelled DTRA SCGs was deemed t be prperly classified in current SCGs, and nne was declassified. T ensure that classificatin guidance is relevant t current circumstances, DTRA assembled a wrking Grup cnsisting f infrmatin security, prgram managers (PM), tpical subject matter experts (SME) and enterprise security managers (SM). PMs and SMEs reviewed the SCGs fr cmpleteness, applicability and clarity. Enterprise SMs and infrmatin security persnnel reviewed each guide fr cmpliance with current security classificatin plicy. As f June 26, 2012, all DTRA SCGs are deemed cmpliant with current security classificatin plicy and have been evaluated as part f the FCGR. A final cpy 7

f all SCG updates (alng with the DD Frm 2024). will be prvided t DTIC n later than September 30, 2012. Lessns Learned: Agency PMs and senir leadership must be alert t and educated early n regarding the imprtance f establishing and integrating the results f an SCG WG frm the nset f a new prgram r revisin t an existing prgram. The clse interactin f SMEs, PMs and SMs is a vital cntributr t ensure prper classificatin f prgram infrmatin. In cnjunctin with the SCG WG, infrmatin security persnnel must implement a tracking system fr each SCG, per classified and/r technical prgram. This tracking system is vital due t the turnver rate f persnnel wh are tasked with the initial writing and maintenance f published SCGs. The tracking system shuld als ensure prper advance ntificatin f the SCG's five year review requirement. This tracking system shuld als track the distributin f the SCG and DD Frm 2024, and deplyment is expected during FY13. Missile Defense Agency: MDA is a highly technical agency executing a cmplex missin that requires a rbust and effective infrmatin security prgram and prtectin envirnment. As a result f the FCGR, MDA certified that each SCG and the Agency declassificatin guide was updated law E.O. 13526. All SCGs have been prvided t Defense Technical Infrmatin Center (DTIC) with the applicable DD Frm 2024. Overall FCGR apprach: MDA has a standing prcedure fr a Classificatin Plicy Panel (CPP) cmpsed f technical subject matter experts frm acrss MDA t review every SCG develped r updated by the Agency (nt including administrative updates), t ensure prpsed tpics f classificatin are technically accurate and relevant t the missin. The CPP is chaired by the Agency's Directr fr Engineering (MDA/DE) and administered by the Research, Develpment, and Acquisitin Security Divisin (MDAIDEW). DEW wrks with the CPP technical representatives and 8

ther subject matter experts thrughut the Agency t ensure prpsed tpics f classificatin are cnsistent and cmpliant with E.O. 13526 requirements. Each MDA SCG nt already underging update during the time the FCRG was initiated was reviewed by a 4-persn team f classificatin management security specialists. The reviews validated cmpliance with current security classificatin plicy (i.e., E.O. 13526) and administrative requirements; as required, SCGs were updated. Technical subject matter experts were cnsulted, as needed, t review SCG tpics f classificatin t verify tpic relevance. MDA' s best practices and FCGR lessns learned: Best practices: The 4-persn review prcess enabled a thrugh review and allwed fr additinal pprtunities t nte and crrect discrepancies. Achieving early cmpliance with DD plicy (DD Manual 5200.01, "DD Infrmatin Security Prgram,") enables the Agency t validate the relevance f SCGs and ensure cntinued cmpliance with updated plicy requirements. All MDA SCGs are reviewed by the agency's CPP as they underg develpment r when updated. The CPP is made up f technical experts frm each f the agency's prgrams wh ensure the classificatin tpics used in the SCGs are relevant and prperly applied frm a technical perspective. Security (MDA/DEW) administrative supprt t the CPP ensures that hrizntal prtectin f prgram infrmatin remains an area f emphasis. Lessns learned: Maintaining standardized frmatting fr all Agency SCGs helped t expedite traditinal reviews and ensures SCGs are mre cnsistent when used by Agency persnnel. It als simplifies brader 9

reviews (such as thse required by the FCGR) because administrative language can be mre easily identified and edited, as necessary. h) Training and Educatin Prduct Develpments: In supprt f the Department's executin f the FCGR, the Center fr Develpment f Security Excellence (CDSE) has cmpleted a Derivative Classifier's curse, available frm the CDSE and Security Directrate website. The CDSE team has als cmpleted an OCA "shrt" curse, intended t cver all training requirements fr OCAs required by EO 13526 and DD regulatins. i) Migratin f Legacy Classificatin Guidance frm DD Issuances: The DD's FCGR has revealed the existence f ptentially duplicative r bslete classificatin management guidance r SGCs embedded within r prvided thru DD issuances (instructins, directives, regulatins, etc.). DD's Infrmatin Security Prgram (DD Manual 5200.01, Vlume 1) requires that all nn-accm, SAP, SCI, r extrardinarily sensitive SCGs are t be distributed t DTIC, ultimately fr psting t its website n NIPRNet and/r ff-line availability t SIPRNet users. We will cntinue ur effrt t review all issuances t cmpare SCGs prmulgated as DD issuances, with thse in the DTIC's hldings. T date, we have identified eighteen such SGCs that are nt yet reflected n DTIC's website. This prject is nging, and may als result in new SCGs being develped (under/thrugh the OCA-t-DTIC prcess); further cancellatin f bslete guidance n the issuances website; r merging f cntent between the tw, in rder t deliver an updated prduct t DTIC. j) Unreslved/Open Issues: An amendment t this reprt will be frthcming. The DD Special Access Prgram (SAP) cmmunity cmpleted the FCGR in accrdance with the requirements f the USD(I)'s tasking. Hwever, the frmal respnse memrandum is pending signature and will be frwarded by early July, 2012. The Office f the Under Secretary f Defense fr Plicy (OUSD(P)) cmpleted the FCGR. Althugh OUSD(P) renders riginal classificatin decisins n a 10

number f internatinal plicy issues, the Office cncluded, as a result f the FCGR, that they d nt have a satisfactry level f fundatinal security classificatin guidance in place, and have initiated develpment f a cndensed set f brad and verarching SCGs t prvide that guidance. This prject is extremely cmplex, requires adjudicatin f multiple crss-oca equity issues, and the results will be reprted as an amendment t this reprt as sn as pssible. Three extant SCGs within OUSD(P)'s claimancy are reflected in the OSD Element cunt (see Attachment 1, belw); hwever, this number will be adjusted depending upn OUSD(P)'s nging reassessment. 11

DOD COMPONENT-BY-COMPONENT FINAL REPORT FUNDAMENTAL CLASSIFICATION GUIDANCE REVIEW 1 Ttal Number O~ganizatln fscgs Air Frce 306 Army 417 DARPA 159 DCMA 1 DIS A 7 DLA (new guide) 1 DTRA 55 JIEDDO 1 Jint Staff (includes COCOMs) 95 MDA 29 Navy 988 (820) OSD Elements 11 DOD.- -' - - 267&11-ftltl FCGRs FCGRs nt FCGR SCGs Initiated Initiated Cmpleted Eliminated Active SCGs 306 0 306 44 262 417 0 417 72 345 159 0 159 25 134 1 0 1 0 1 1 7 0 (see remarks) 1 6 1 0 1 0 1 55 0 55 13 42 1 0 1 0 1 95 0 95 9 86 29 0 29 0 29 988 0 988 248 740..., 11 0 11 1 11.. ~ 21M f:.'it Remarks Initial review cmpleted. Wrking with SMEs/ OCAs n way-frward fr remaining SCGs.. ECD: August 31, 2012.. See paragraph U), abve, regarding OUSD(P) initiatives.. One USD(I) Guide t be transferred t Jint Staff & ptentially eliminated. ATTACHMENT 1 1 This reprt des nt reflect NGA, NRO, NSA & DIA FCGR metrics and reprting. These Cmpnents reprted directly t ISOO, cc: t ODNI and OUSD(l). 2 Reflects an updated ttal SCG cunt frm the DD's 3'd Interim FCGR Reprt (February 16, 20 12) 12