Derivative Classification
Derivative classification is the process of creating new documents or materials from information that is already classified, and marking the new product with the appropriate classification. Rather than making an original decision that information needs protection, the person doing derivative classification carries forward the classification decisions already made by others. This applies to national security information within the classified environment.
Derivative classification is generally defined as the incorporating, paraphrasing, restating, or generating in new form information that is already classified, and marking the newly created material consistent with the classification markings that apply to the source information. It relies on existing classified source documents and/or applicable classification guidance rather than an original classification determination, and is performed from a classification management perspective for national security information. Note that this concept is specific to the national security classification system and is distinct from the marking and handling of Controlled Unclassified Information (CUI) or the control-based regimes such as the RMF; readers should verify current governing authorities and marking requirements against official sources, as the evidence provided here describes the concept but does not establish the controlling regulation or its current revision.
Why it matters
Derivative classification is the mechanism through which the vast majority of classified material in day-to-day government and contractor work is created. Very few people make original classification decisions; instead, most cleared personnel who handle national security information generate new products, reports, briefings, emails, memoranda, that draw on already-classified source documents or classification guidance. Because these individuals carry forward existing classification decisions rather than making new ones, the accuracy of their marking directly determines whether sensitive information is properly protected or improperly exposed or over-restricted.
Errors in derivative classification can have consequences in both directions. Under-marking or failing to carry forward a classification can result in the unauthorized disclosure of national security information, while over-marking can impede legitimate information sharing and burden systems with unnecessary handling requirements. Because the derivative classifier is accountable for applying markings consistent with the source material or guidance, mistakes reflect a breakdown in the chain of classification decisions that originated with an original classification authority.
It is important to keep this concept within its proper scope. Derivative classification applies to the national security classification system and is distinct from the marking and handling of Controlled Unclassified Information (CUI) and from control-based regimes such as the RMF. Personnel should not assume the practices, training, or markings of one regime satisfy the requirements of another, and should verify current governing authorities and marking requirements against official sources.
Who it's relevant to
Inside Derivative Classification
Common questions
Answers to the questions practitioners most commonly ask about Derivative Classification.