All Of The Following Are Responsibilities Of Derivative Classifiers

8 min read

You've been handed a stack of source documents — some marked SECRET, a couple TOP SECRET, one with a weird banner line you've never seen before — and now you're supposed to produce a new briefing slide deck. That said, by tomorrow. And every single marking on every single slide has to be defensible.

Welcome to derivative classification.

It's not the flashy part of national security work. That's why people lose clearances. But if you screw it up? Now, programs get shut down. Which means nobody makes movies about the person checking whether a paragraph inherits a (U//FOUO) marking or needs a "REL TO USA, FVEY" caveat. And sometimes, bad intelligence gets acted on because the classification lineage got muddy.

So let's talk about what you're actually on the hook for.

What Is Derivative Classification

Derivative classification happens when you create a new document or product based on already classified source material. Even so, you're not making original classification decisions — that's the Original Classification Authority's (OCA) job. You're carrying forward, combining, and sometimes re-expressing classification guidance that already exists.

Not obvious, but once you see it — you'll see it everywhere.

Think of it like this: the OCA draws the map. Because of that, you're driving the car. Which means you don't get to decide where the roads go. But you do have to stay on them.

The core rule is simple: the new product inherits the highest classification of any source used. But the execution? That's where it gets messy.

It's Not Just "Slapping a Banner On It"

I've seen people treat derivative classification like a copy-paste job. Copy the classification line from the source doc, paste it on the new doc, done. That's not how it works — and that mindset causes real problems Not complicated — just consistent..

When you derive classification, you're making active judgments:

  • Which specific portions carry which markings
  • Whether aggregation raises the classification level
  • If compilation creates new sensitivities
  • What downgrading/declassification instructions apply
  • Whether the new format changes dissemination controls

Every one of those is a decision. And every decision is traceable Small thing, real impact..

Why It Matters / Why People Care

Here's the thing most training slides gloss over: derivative classifiers are the last line of defense before classified information hits the network.

The OCA sets policy. The security manager writes the SCG. But you are the one deciding, in real time, whether that email attachment gets a (S//SI) marking or a (TS//SI//TK) marking. You're the one catching that the new slide deck combines two SECRET sources in a way that — per the SCG — actually makes it TOP SECRET That alone is useful..

Get it wrong one way, and you've overclassified. That sounds safer, but it isn't. And overclassification clogs systems, slows sharing, wastes resources, and erodes trust in the whole system. It's also a violation of EO 13526 The details matter here..

Get it wrong the other way, and you've underclassified. Worth adding: that's a spill. Day to day, maybe a small one. Maybe the kind that triggers a damage assessment, a congressional inquiry, and a very uncomfortable conversation with your FSO.

The Real-World Stakes

In 2019, a DoD component had to recall over 3,000 derivative products because a single contractor misunderstood how a specific "REL TO" caveat propagated through compilation. Three thousand products. Pulled from multiple networks. Because of that, re-reviewed. Worth adding: re-marked. Redistributed.

Cost? Months of work. Worth adding: six figures in labor. And a lot of people asking "how did this happen?

It happened because someone treated derivative classification as administrative instead of analytical.

How It Works (or How to Do It)

Let's walk through what you actually do when you sit down to derive classification. Not the theory — the workflow.

Step 1: Identify and Verify Your Sources

Before you write a single word, you need to know exactly what you're drawing from. Every source document. Every database query. Every conversation with a subject matter expert who might be conveying classified info verbally.

For each source, you need:

  • The overall classification marking
  • Portion markings (if applicable)
  • The classification guide or SCG that governs it
  • Downgrading/declassification instructions
  • Dissemination controls (NOFORN, REL TO, ORCON, etc.)
  • Any special handling caveats (SI, TK, HCS, etc.)

Easier said than done, but still worth knowing.

Pro tip: If a source document doesn't have portion markings but is classified, you can't just assume the whole thing is one level. You have to treat it as "unmarked = unknown" and track down the derivative classification authority or the SCG. I've seen people skip this because "it's just a SECRET doc." Then they extract a paragraph that was actually TS//SI in the original. Oops.

Step 2: Apply the "Highest Classification" Rule — Correctly

The new product gets the highest overall classification of any source used. Here's the thing — not the average. Consider this: not the majority. The highest.

But — and this trips people up — you also have to carry forward all dissemination controls and special caveats from all sources. If Source A is SECRET//NOFORN and Source B is TOP SECRET//REL TO USA, FVEY, your new product is TOP SECRET//NOFORN//REL TO USA, FVEY.

You don't get to pick and choose. The controls are additive.

Step 3: Portion Mark Every. Single. Paragraph.

This is non-negotiable. Every paragraph, bullet, table, figure caption, slide title, header, footer — if it contains classified information, it gets a portion marking.

The format: (U), (C), (S), (TS) — plus any caveats. Examples:

  • (U) This paragraph is unclassified
  • (S//NF) This paragraph is SECRET//NOFORN
  • (TS//SI//TK) This paragraph is TOP SECRET//SI//TK

Common failure mode: People portion-mark the body text but forget:

  • Slide titles
  • Table headers and individual cells
  • Figure captions
  • Footnotes
  • "Continued on next slide" lines
  • Classification authority blocks

If it's on the page/slide/screen and it conveys classified info, it gets marked. Period.

Step 4: Check for Aggregation and Compilation Effects

This is where derivative classification becomes analysis.

Aggregation = combining unclassified or lower-classified pieces of information in a way that reveals a higher-classified fact. Classic example: ten unclassified satellite photos of a facility, taken over time, that together reveal a pattern of activity classified SECRET Easy to understand, harder to ignore..

Compilation = assembling multiple classified pieces into a single product where the collection itself creates new sensitivity. The SCG will tell you if compilation raises the classification level. Sometimes it does. Sometimes it doesn't. You have to check.

Real talk: most derivative classifiers don't check this thoroughly. So " Sometimes it doesn't. They assume "highest source classification covers it.Still, the SCG is your bible here. Read it The details matter here..

Step 5: Apply Downgrading and Declassification Instructions

Every classified product needs a "Classified By" line and a "Declassify On" line (or "Downgrade To" / "Declassify On" for derivative) Most people skip this — try not to..

For derivative products, you use the most restrictive instructions from your sources. If Source A says "Declassify on 20

Step 5: Apply Downgrading and Declassification Instructions – Finish the Puzzle

For derivative products, the most restrictive handling instructions from any source win the day. If Source A says “Declassify on 20 Oct 2025” and Source B says “Downgrade to SECRET by 30 Jun 2024,” you must use the earliest declassification date and the lowest classification level that still satisfies both sources. In practice that means:

  • Classified‑By line – Cite the originating source (e.g., “Classified by: Department of Defense, TOP SECRET//NOFORN”).
  • Declassify/Downgrade line – Use the most restrictive instruction:
    • If any source says “Declassify on X,” that date becomes the product’s declassification trigger.
    • If all sources say “Downgrade to SECRET,” the product is marked “Downgrade to SECRET on Y.”
  • Special caveats – Carry forward every caveat (NOFORN, REL TO USA FVEY, SI, TK, etc.) unchanged. They are not optional even when the classification level changes.

Quick checklist

Item Action
Identify the earliest declassification/downgrade date among sources Use that date in the “Declassify On / Downgrade To” line
Determine the lowest classification level that still satisfies all sources Apply that level to the product header
Preserve every caveat from every source List them all after the classification level
Verify that the “Classified‑By” line references the original derivative source No need to re‑classify the underlying source

Step 6: Final Review and Approval

Once the product is assembled, run it through a dual‑review process:

  1. Original‑Source Validator – Confirms that the derivative classification correctly reflects the source material and that no information has been inadvertently elevated or omitted.
  2. Control‑Authority Reviewer – Checks that all portion markings, caveats, and declassification instructions meet agency policy.

Both reviewers sign off in the Classification Authority Block (usually at the bottom of the first page). If any reviewer flags an issue, the product loops back to the appropriate step—most often Step 3 (portion marking) or Step 4 (aggregation/compilation).

Step 7: Training, Documentation, and Continuous Improvement

Even the most rigorous processes break down without a culture of learning:

  • Regular refreshers – Conduct quarterly briefings that walk analysts through the latest SCG updates and real‑world case studies.
  • Template libraries – Provide pre‑populated classification headers and portion‑marking templates to reduce human error.
  • Audit trails – Keep logs of every review, change, and approval. These records are invaluable during post‑incident investigations and for demonstrating compliance to oversight bodies.

Remember: Classification is a team sport. It thrives on clear communication, disciplined execution, and relentless attention to detail And it works..


Conclusion

Handling classified information in today’s interconnected environment demands more than a checklist—it requires a mindset that treats every document, slide, or data extract as a potential carrier of national‑security risk. By rigorously applying the “highest classification” rule, carrying forward all dissemination controls, portion‑marking every element that contains classified data, scrutinizing aggregation and compilation effects, and finally enforcing the most restrictive downgrading and declassification instructions, you create a defensible, policy‑compliant product that protects what must be protected while enabling the right people to do their jobs Less friction, more output..

When these steps become second nature, the result is not just a set of documents that pass an audit, but a culture where security is built into every decision. That, ultimately, is the true measure of a solid classification program.

Just Got Posted

The Latest

Branching Out from Here

Keep the Momentum

Thank you for reading about All Of The Following Are Responsibilities Of Derivative Classifiers. We hope the information has been useful. Feel free to contact us if you have any questions. See you next time — don't forget to bookmark!
⌂ Back to Home