Monthly Archives

September 2026

What Is a Security Classification Guide

What Is a Security Classification Guide?

By Oatridge Blog

If you work with federal agencies, defense programs, government contracts, or protected information, understanding what is a security classification guide can prevent serious mistakes. A Security Classification Guide, usually shortened to SCG, is an official set of instructions that identifies which specific information about a program, system, operation, project, or subject requires classification and establishes the appropriate level and duration of that protection.

The guide exists so people do not make classification decisions based on personal judgment. Instead, authorized personnel have a consistent source to follow when creating documents, presentations, emails, technical materials, and other work involving classified information.

Under Executive Order 13526, a classification guide is issued by an Original Classification Authority and records decisions about information that requires protection in the interest of national security.

The essentials to know before using an SCG

  • An SCG identifies specific information elements that require protection.
  • It tells authorized users which classification level applies.
  • It helps trained personnel perform derivative classification consistently.
  • It may provide the reason and duration for classification, along with special handling instructions.
  • It does not give an employee original classification authority.
  • The current applicable guide must be used rather than relying on memory or assumptions.

Practical warning: “Sensitive” and “classified” are not interchangeable terms. Information becomes classified through authorized government classification processes, not simply because an organization considers it important or confidential.

What information does a Security Classification Guide contain?

A useful way to understand what is a security classification guide is to look at the decisions it communicates. An SCG is more than a list of protected topics. It connects individual pieces of information to specific instructions that trained personnel can apply.

SCG element What it tells the user
Information element The fact, capability, activity, specification, or subject being addressed
Classification Whether and at what level the information must be protected
Reason Why disclosure could create national-security harm
Duration How long the classification applies or when review or declassification occurs
Additional guidance Relevant caveats, controls, exceptions, or clarification

The National Archives Information Security Oversight Office provides classification-management training and guidance for people working with these requirements. Official guidance emphasizes that an SCG should help users apply the same protection and duration to the same information rather than producing inconsistent results from one document to another.

Who actually decides that information is classified?

Original classification and derivative classification are different processes.

An Original Classification Authority, or OCA, makes the initial determination that information requires classification. A trained derivative classifier does not create a new classification decision. Instead, that person applies an existing decision using authorized guidance, which may include an SCG or properly marked source material.

The three standard U.S. classified levels are Confidential, Secret, and Top Secret. Under Executive Order 13526, those levels correspond to increasing degrees of expected damage to national security if the information is disclosed without authorization.

The U.S. Department of Commerce information security guidance provides a useful practical explanation of this distinction. It also notes that derivative classifiers must evaluate what newly created material contains or reveals against authorized classification guidance.

Important detail: unmarked does not automatically mean unclassified. Personnel responsible for protected material still need to evaluate information against the applicable authorized sources.

How does an SCG work in everyday document preparation?

Consider someone preparing a new technical report for a government program. The report combines facts, project details, system capabilities, and operational information from several authorized sources.

The employee should not simply decide that the entire report “looks Secret” or assume an older document has the right markings.

Instead, the trained derivative classifier reviews the applicable SCG, identifies the information elements present in the new material, applies the established classification decisions, and carries forward the required markings and declassification instructions.

This matters because a classification report, briefing deck, email, or technical summary may contain information in a different format from the original source. The responsibility is still to recognize what the new material contains or reveals.

DCSA derivative classification training specifically trains personnel to analyze authorized sources, apply classification concepts, use appropriate markings, and avoid improper classification.

An SCG is not the same as a company data-classification policy

This is one of the most important distinctions missing from many explanations of what is a security classification guide.

A private organization may have a classification policy that labels internal information as Public, Internal, Confidential, Restricted, or similar terms. Those categories can be valuable for cybersecurity, privacy, intellectual property, and corporate risk management.

They are not automatically federal classified-information designations.

A federal SCG concerns authorized classification decisions under the applicable government framework. Organizations working on government contracts must therefore understand which rules originate from their own corporate information policies and which requirements come from the government program, contract, agency, or classification authority.

Practical tip: when government and internal information-control systems overlap, clearly document which authority controls each category. Similar labels can create dangerous assumptions if employees do not know which policy governs the material.

Classification guidance is only one part of protecting sensitive operations

A correctly marked document still needs an appropriately protected environment.

Organizations supporting government programs may need to consider personnel access, visitor management, restricted areas, physical entry points, monitoring, patrol procedures, and other safeguards alongside information-security requirements.

This is where Oatridge Security Group operates on the protective-services side. OSG specializes in protective security services for commercial and government clients and provides security officers, access control, monitoring, executive protection, patrol services, and security consulting. The company also states that its protective-services programs are designed around varying government agency requirements.

An SCG determines how covered information should be classified. Physical-security professionals help organizations address a different but related question: whether the people, facilities, access points, and protective procedures surrounding operations are appropriately secured. For organizations working in sensitive environments, those controls need to function together rather than as separate checklists.

Why organizations choose OSG for protective security

  • Founded in 2003, with more than 20 years of operating history.
  • HUBZone-certified business based in Tacoma, Washington.
  • More than 100 years of combined security-industry experience among senior management.
  • Protective security experience serving U.S. government and commercial clients.
  • 24-hour communication, 7 days a week, 365 days a year.
  • Licensed under Washington State law, with security officers licensed under applicable Washington requirements.

Strengthen the physical side of your security program

Organizations handling sensitive operations cannot depend on document rules alone. Facilities, restricted areas, access procedures, monitoring, and trained personnel all contribute to a stronger overall security posture.

Oatridge Security Group serves Tacoma, Seattle, Pierce County, King County, Snohomish County, Thurston County, and surrounding Puget Sound communities. If your organization needs professional security officers, access control, physical security, or security consulting, get in touch to discuss the protection requirements of your site or operation.

Frequently Asked Questions

What is a security classification guide used for?

A Security Classification Guide provides authorized classification instructions for specific information associated with a program, system, project, mission, or subject.

It helps trained derivative classifiers consistently determine the appropriate protection and markings for information they use in newly created materials.

Is an SCG a primary source for derivative classification?

Yes. A current Security Classification Guide can serve as an authorized source for derivative classification.

Properly marked classified source documents can also provide classification guidance depending on the applicable requirements.

Can any employee create a Security Classification Guide?

No. An SCG represents original classification decisions made or approved through authorized government classification processes.

Employees performing derivative work apply those decisions rather than creating new original classification decisions themselves.

Is CUI the same as classified information?

No. Controlled Unclassified Information, or CUI, is not one of the three classified national-security levels.

CUI has its own safeguarding and dissemination requirements, while Confidential, Secret, and Top Secret fall under the classified national-security framework.

Can information become classified when several unclassified facts are combined?

In some circumstances, yes. A compilation of information can reveal something that warrants a different classification treatment when evaluated against authorized guidance.

Personnel should use the applicable SCG and other authorized sources rather than assuming that combining individually unclassified facts always produces an unclassified result.

Does an SCG replace physical security procedures?

No. An SCG provides classification guidance, while physical security procedures address matters such as access, facilities, personnel, monitoring, and protection against unauthorized entry.

Organizations handling sensitive operations typically need both information controls and appropriate physical safeguards.