Which Is the Primary Source for Derivative Classification
You found a memo in your inbox. It's marked classified. And now you need to write a new document that references some of the information in it — but you're not an Original Classification Authority. So what do you do?
Here's the thing — this happens constantly in government and contractor workspaces. Day to day, people every day face the task of creating or handling new materials that contain classified information. And most of them know they're supposed to be careful, but not everyone knows exactly where to look when it's time to actually classify something Which is the point..
The answer lives in one specific document. And once you know what it is, a lot of the confusion around derivative classification just... clears up The details matter here..
What Is Derivative Classification (and Its Primary Source)
Derivative classification is what happens when someone — who is not an Original Classification Authority (OCA) — incorporates, restates, paraphrases, or compiles classified information into a new document or product. You didn't originate the secret. But you're now responsible for protecting it, which means you need to mark it correctly, handle it properly, and know why it's classified in the first place.
So where do you get that authority? Also, you don't make it up. That said, you don't guess. You rely on an authorized source It's one of those things that adds up. Turns out it matters..
The primary source for derivative classification is a classification guide.
That's the short version. But let's unpack it, because there's more to understand about what classification guides are and why they carry this weight Worth knowing..
Classification Guides: The Authoritative Reference
A classification guide is a written document — typically an SF-703, SF-704, or SF-705 form in federal use — issued by an Original Classification Authority. It translates broad classification rules from things like Executive Order 13587 into specific, down-to-earth guidance: here's what's classified, at what level, and why.
Think of it as the bridge between policy and practice. The OCA knows why certain information is sensitive. The classification guide tells you (the derivative classifier) exactly how to apply that judgment to your own work.
Other Sources That Feed Derivative Classification
Here's what most people don't realize: classification guides aren't the only source, but they're always the primary one. Other valid sources include:
- Previously classified source documents — if the information already exists in a properly marked document, you can use that as your basis
- Compilations of classified information — combining unclassified items into a classified whole
- Memoranda and declassification guides — issued by OCAs for specific topics
But even when you're pulling from an existing classified document, you're still ultimately relying on the classification guide (or equivalent OCA determination) that made that document classified in the first place. The classification guide is the root source Surprisingly effective..
Why It Matters
You might be thinking: "Okay, I get it — classification guides are important. But does this actually affect anything in practice?"
Yes. More than most people realize.
Without a proper primary source, derivative classifiers face a real problem. On the flip side, they either leave information unmarked (risking exposure), over-classify out of caution (wasting resources and limiting access), or under-classify out of uncertainty (creating security gaps). All three scenarios are bad. And they happen all the time when people don't know where to look.
Here's the concrete risk: let's say you're a contractor working on a project. You reference program details in a report, and you classify it Secret because it "feels" sensitive. But there's no classification guide backing that decision. Still, three months later, someone challenges it during a security review. You've got a problem — not because you were careless, but because you didn't have the right foundation for your decision.
Classification guides solve this. They give every derivative classifier a common, auditable, authoritative basis for what they're doing. When the inspector general or security officer comes knocking, you can point to your source and say: "I classified it at this level because the guide told me to.
That accountability matters. It's the difference between a defensible security practice and guesswork.
How It Works
Using a classification guide isn't complicated, but it does require a deliberate process. Here's how derivative classification actually works in practice.
Step 1: Identify the Information
You're creating or handling material that contains classified information — or you suspect it might. The first step is knowing what you're working with. Are you extracting from an existing document? Paraphrasing a briefing slide? Compiling data from multiple sources?
Step 2: Find the Classification Guide
This is where you stop and look up the relevant classification guide for that topic. In real terms, if the information comes from a specific program, there's likely a guide for that program. Consider this: federal agencies and contractors maintain these guides by subject area. If you're not sure, ask your security office — they're there to help you find what you need.
Step 3: Apply the Guidance
Once you've found the guide, read it carefully. It will tell you:
- What topics or elements are classified
- What classification level applies (Confidential, Secret, or Top Secret)
- What the basis or reason for classification is (e.g., intelligence sources, system vulnerabilities, foreign relations)
- Any applicable caveats, like "RESTRICTED" or compartment designations
Mark your document accordingly. The guide is your instruction manual Small thing, real impact. Surprisingly effective..
Step 4: Document Your Reasoning
This step gets skipped more than it should. Now, when you make a derivative classification decision, you're supposed to note the source — the guide number, date, and specific provision you relied on. Plus, this creates an audit trail. Later, if anyone questions why a document is marked a certain way, you can show exactly where that determination came from Still holds up..
Step 5: Handle and Disseminate Properly
Now that your document is properly classified, it needs the right treatment. Make sure anyone who receives it is cleared and has a need to know. Day to day, follow the handling rules for its classification level. Don't let it sit on an unclassified system. Don't email it to your personal account Turns out it matters..
Common Mistakes / What Most People Get Wrong
After years of reading through security guidance and watching how classification actually plays out in government offices, here are the mistakes that come up most often Not complicated — just consistent..
Treating existing classified documents as a substitute for the guide. Yes, you can classify based on a source document. But if that source document itself was classified based on a guide, the guide is still the authoritative source. People sometimes forget to go back and check whether their source material properly reflects current guidance — and classification levels can change.
Guessing or "feeling" like something should be classified. This is probably the most common mistake. Someone looks at information and thinks, "This seems sensitive, I'll mark it
as Secret.Worth adding: " Stop. Take a breath. Classification isn't about your gut feeling — it's about following established rules. That seemingly innocuous budget line item might actually be unclassified information (U) if it's already publicly available or if the guide specifically excludes it from classification Not complicated — just consistent..
Over-classifying everything. I've seen documents marked Top Secret simply because "it's important" or "someone might want to know this." The classification system only works if we use it appropriately. Over-classification clutters the system, wastes resources, and makes it harder to identify truly sensitive information. Remember: if it's not specifically called out in a guide, it probably shouldn't be classified Worth keeping that in mind. Practical, not theoretical..
Skipping the documentation step. You've got a document marked Confidential, but you didn't write down why or where you found the guidance to support that decision. Six months later, a reviewer asks about your classification basis, and you're left scrambling. Always document your reasoning — it's not bureaucratic busywork, it's accountability.
Assuming classification expires automatically. Just because a document is a few years old doesn't mean you can automatically downgrade it. Many classifications have specific timeframes or require formal review by authorized personnel. Check the guide to see if there's a declassification schedule or review requirement before you start marking things as "Unclassified" based on age alone.
Forgetting about the chain of custody. When you handle classified information, you need to track where it goes and who has access to it. Simply emailing a classified document to yourself or storing it on a personal device violates security protocols, regardless of whether you think the content warrants protection Not complicated — just consistent..
Real-World Example: The Budget Memo
Let's put this into practice with a concrete example. Imagine you're working on a program budget memo that includes cost estimates, contractor names, and technical specifications And it works..
First, you'd identify which classification guide applies — likely one for your specific program or the Defense Department's guidance for budget documents. You'd discover that while cost data might be sensitive, basic program information is often unclassified unless it involves specific vulnerabilities or intelligence sources.
After applying the guidance, you might determine that the technical specifications are Unclassified but the contractor pricing details are For Official Use Only (FOUO) due to potential competitive sensitivity. 28, section 3.Even so, you'd document that you relied on Defense Regulation 5200. 2, paragraph (b), and note that the specific provision excludes routine administrative information from classification Not complicated — just consistent..
Finally, you'd handle the document appropriately — keeping it on a secure network, ensuring only cleared personnel access it, and properly marking it with the determined classification level and any applicable caveats Most people skip this — try not to. That alone is useful..
Conclusion
Classification isn't a guessing game or a security blanket — it's a precise process grounded in specific guidance and clear criteria. By following these steps methodically and avoiding common pitfalls, you're not just protecting information; you're maintaining the integrity of the entire classification system that keeps our nation secure Worth keeping that in mind..
Remember: when in doubt, ask. The security office isn't there to make your job harder — they're there to ensure you get it right. Taking the extra few minutes to properly classify information saves significant time and resources later, and more importantly, ensures that truly sensitive information gets the protection it deserves.