When Derivatively Classifying Information Where Can You: Complete Guide

10 min read

When Derivatively Classifying Information, Where Can You Find the Authority to Do It?

If you've ever worked with classified material in a government role or for a government contractor, you've probably encountered this situation: you need to document or share information that came from an existing classified source, but you're not sure whether you have the right to classify it yourself — or where you'd even find the authority to do that.

Here's the thing — you can't just decide something is classified because it feels sensitive. Classification authority is structured, and derivatively classifying information requires a specific foundation. The good news is that the rules are clear once you know where to look.

Real talk — this step gets skipped all the time.

This guide walks you through what derivatively classifying actually means, where you find the authority to do it, and how to handle the process correctly without getting yourself or your organization into trouble.


What Is Derivative Classification?

Derivative classification is the process of creating new classified information based on existing classified material. You're not inventing a new classification category — you're applying classification guidance to information that already carries a classification designation from some original source.

Think of it this way: an original classification authority (OCA) decides that a specific piece of information reveals something dangerous about national security. Now, later, you need to write a report that incorporates or summarizes that information. Consider this: that information gets marked as Top Secret, Secret, or Confidential. The classification "derives" from the original — hence, derivative classification That's the part that actually makes a difference..

Easier said than done, but still worth knowing.

How It Differs From Original Classification

Original classification is the big one. Only designated officials — typically senior government leaders — have the authority to classify information for the first time. Practically speaking, they determine that certain facts, if revealed, would damage national security. That decision creates the original classification Not complicated — just consistent..

Derivative classification is what happens downstream. You take that already-classified information and incorporate it into something new — a briefing, a report, an email, a database entry. The classification level and markings come from the original source, not from your own judgment about whether the information is sensitive The details matter here..

This distinction matters because it shapes where your authority comes from. Day to day, you don't get to decide something is classified on your own. You apply classification guidance that already exists Practical, not theoretical..


Where Can You Find the Authority to Derivatively Classify?

This is the core question, and the answer has a few layers.

Classification Guides Are Your Primary Source

The most common and authoritative source for derivative classification is a classification guide. These are documents issued by the original classification authority (or their designees) that tell you how to handle specific categories of information.

A classification guide might say something like: "Information regarding the technical specifications of System X is Secret//NOFORN" — meaning it's classified at the Secret level and cannot be released to foreign nationals. Practically speaking, when you encounter technical specifications about System X in your work, you apply that guidance. You're not guessing. You're following the guide.

Classification guides are typically specific to programs, agencies, or subject areas. If you're working on a defense program, you'll have a guide for that program. That said, if you're in intelligence, you'll have guides for intelligence sources and methods. The guide is the authority that lets you derivatively classify.

The Original Source Material Itself

Sometimes the authority is embedded right in the document you're working with. If you're extracting information from a classified document, that document already carries classification markings and handling instructions. When you create something new from it, you carry those markings forward.

Take this: if you're summarizing a Secret report into a shorter briefing, the Secret classification comes with it. But the original document's markings tell you what level applies and what controls (like NOFORN or ORCON) are required. You're derivatively classifying based on the source's existing classification Which is the point..

Agency-Level Guidance and Policies

Beyond specific classification guides, agencies issue overarching policies that provide authority for certain categories of information. Executive orders — particularly Executive Order 13587 for classified national security information — establish the framework. Agency regulations and manuals fill in the details.

If you're in the Department of Defense, for instance, DoD manuals provide classification guidance. The same applies to the Department of Energy (for nuclear-related information), the intelligence community, and other agencies with classified programs.

Your Facility Security Officer or Classification Manager

When you're unsure whether classification guidance exists for something you're working with, your first call should be your organization's security point of contact. A Facility Security Officer (FSO) or designated classification manager can tell you whether a classification guide applies, whether you need to contact the originating agency, or whether the information may not be classified at all.

At its core, where a lot of people get into trouble — they assume information is classified when it isn't, or they classify it at the wrong level because they didn't check. Your security office exists to help you get this right.


Why It Matters Getting This Right

Here's why this isn't just bureaucratic box-checking: getting derivative classification wrong creates real problems.

Overclassification happens when information is marked at a higher level than necessary or classified when it doesn't actually meet the criteria. This clogs up the system, makes it harder to share information that should be shared, and wastes resources. It also frustrates people who need access to information to do their jobs Which is the point..

Underclassification is arguably worse. If information that should be protected gets released improperly, it can damage national security, compromise sources and methods, or put people at risk. The consequences can be serious — criminal penalties are on the table for willful mishandling.

Beyond the legal and security implications, there's a practical reason to get it right: efficiency. Also, when classification is done correctly, the right people can access the information they need, and the system works. When it's done poorly, everything slows down.


How Derivative Classification Actually Works

Let's walk through the process step by step.

Step 1: Identify the Source

You're working with information that came from somewhere. Maybe it's a document, a briefing, a database, or a conversation with someone who has access. Your first job is to trace it back Which is the point..

Ask: Where did this information originate? Is there an existing classification on the source material?

Step 2: Find the Applicable Guidance

Once you know the source, look for classification guidance. Check for:

  • A classification guide that covers this topic
  • Classification markings on the source document
  • Agency policies that address this category of information

If guidance exists, apply it. If it doesn't, that's a signal that you may need to consult your security office before proceeding.

Step 3: Apply the Classification

Based on the guidance, determine the classification level (Top Secret, Secret, or Confidential), any special handling markings (NOFORN, ORCON, REL TO, etc.), and the proper format for the new document or product And that's really what it comes down to. That's the whole idea..

This means using the right classification banner, declassification instructions, and handling caveats. The markings tell everyone who can see it and how it can be shared And it works..

Step 4: Document the Classification Source

When you derivatively classify, you need to be able to show where the classification came from. This is often done with a classification authority block or a notation that references the source guide or document It's one of those things that adds up. But it adds up..

This creates an audit trail. If someone later asks why something is classified, there's an answer — it came from Classification Guide X, or it was extracted from Document Y.


Common Mistakes People Make

After years of working with classification issues, certain errors come up over and over Worth keeping that in mind..

Assuming information is classified without checking. Just because something seems sensitive doesn't mean it's formally classified. Conversely, something that seems innocuous might be classified. Never assume — always check.

Using outdated classification guides. Guides get updated. A classification level that applied five years ago might have been lowered. Make sure you're working with the current version.

Ignoring the declassification instructions. Classification isn't forever. Most classified information has a declassification date or event. Part of your job is including those instructions correctly so people know when the information can be released.

Applying classification to unclassified summaries. If you take classified information and create an unclassified summary (sometimes called a "sanitized" version), that summary should not carry classification markings. But the process of creating it still requires you to handle the underlying classified information correctly Small thing, real impact..

Not consulting when you're unsure. People sometimes classify something incorrectly rather than ask for help because they don't want to look like they don't know what they're doing. But asking is the right move. It's literally what the system is set up for.


Practical Tips for Getting It Right

A few things that actually help in day-to-day work:

  • Keep a copy of your relevant classification guides handy. If you reference them regularly, you won't have to hunt for them every time.
  • When in doubt, write it up. If you're uncertain whether something needs to be classified, document your question and check with your security office before proceeding.
  • Pay attention to the source document's markings. The classification banner, the handling caveats, the declassification instructions — all of it matters. Don't strip it out because it looks cluttered.
  • Remember that classification decisions can be challenged. If you think something is overclassified, there's a process to request a review. You don't have to just accept it.
  • Take the training seriously. If your agency requires derivative classification training, pay attention. It's not just a checkbox — it covers exactly the situations you'll face.

FAQ

Can I derivatively classify information if there's no classification guide?

You need some form of classification authority. Also, if no guide exists for the specific information, you should contact your security office or the originating classification authority. Don't make an independent judgment to classify something without guidance Turns out it matters..

What if the source document has no classification markings?

This is a red flag. Either the information was never classified, the markings were lost, or there's an issue with the document's handling. Don't assume it needs to be classified — check with your security point of contact Still holds up..

Can I lower the classification level when I derivatively classify?

No. Derivative classification means applying the classification that already exists. Think about it: you can't downgrade something on your own. If you believe the classification level is too high, there's a process to request a review, but you don't get to change it unilaterally.

Where do I find declassification instructions?

They're usually on the source document or in the applicable classification guide. Common formats include "Declassify on [date]" or "Declassify upon [specific event]." Make sure these carry forward into any derivative product That's the part that actually makes a difference. Took long enough..

What happens if I get it wrong?

It depends on the severity and intent. On top of that, unintentional mistakes are usually addressed through training or administrative action. Willful mishandling — especially if it leads to an unauthorized disclosure — can result in criminal penalties under federal law.


The Bottom Line

Derivatively classifying information isn't about making judgment calls in the moment. It's about having the right foundation before you start — the classification guides, the source documents, the agency policies that tell you what level applies and how to handle it.

Where can you find that authority? The system is designed to give you what you need to get it right. Right where it should be: in the guides, in the source material, and in conversation with your security office when the answer isn't clear. Use it.

If you're handling classified information as part of your job, this isn't something to figure out as you go. Get the training, get the guides, and get in the habit of checking. It's easier to do it right the first time than to clean up a mistake later Small thing, real impact..

Out the Door

Latest Batch

In That Vein

Readers Went Here Next

Thank you for reading about When Derivatively Classifying Information Where Can You: Complete Guide. We hope the information has been useful. Feel free to contact us if you have any questions. See you next time — don't forget to bookmark!
⌂ Back to Home