Introduction to Information Security
Which of the following are applicable when using a phone for classified conversations? Select all that apply.
- Be aware of your surroundings and who might be able to hear your end of the conversation - Only use Secure Terminal Equipment (STE) phones - Know how to use your Secure Terminal Equipment (STE)
Which level of classified information may be transported via USPS mail? Select all that apply.
- Confidential - Secret
The purpose of the DoD information security program is to __________. Select all that apply.
- Demonstrate a commitment to transparency in Government - Protect national security information
What is required to access classified information? Select all that apply.
- Eligibility - Signed SF-312, Nondisclosure Agreement - Need-to-know
What are the authorized places for storing classified information? Select all that apply.
- In a GSA-approved security container - In information technology systems authorized for classified information - In an authorized individual's head or hands
When classified information is in an authorized individual's hands, why should the individual use a classified document cover sheet? Select all that apply.
- To alert holders to the presence of classified information - To prevent inadvertent viewing of classified information by unauthorized personnel
What information is listed in the classification authority block on a document containing classified information? Select all that apply.
- Who created the classified document - Classification level to downgrade to at a certain point in time (as applicable) - Which source the information in the document was derived form - Date on which to declassify the document
What are the steps of the information security program life cycle?
?
Cleared U.S. military, civilian employees, or contractors may hand carry which type of classified information?
All of the above
What information do security classification guides (SCG) provide about systems, plans, programs, projects, or missions?
All of the above
Why must all documents containing classified information be marked using a sequential process?
All of the above
Who can be an Original Classification Authority (OCA)?
An individual authorized in writing, either by the President, the Vice President, or by agency heads or officials designated by the President
When are "Downgrade To" instructions listed in the classification authority block on documents containing classified information?
As applicable
If a derivative classifier believes information to be improperly classified, they can _____________ the classification decision.
Challenge
_________________ occurs in some circumstances when information that is individually unclassified, or classified at a lower level, may be classified, or classified at a higher level, only if the combined information reveals an additional association or relationship.
Compilation
The unauthorized disclosure of this type of information could reasonably be expected to cause damage to our national security.
Confidential
The unauthorized disclosure of Confidential information could reasonably be expected to cause __________ to our national security.
Damage
When information, in the interest of national security, no longer requires protection at any level, it should be:
Declassified
Who references information from security classification guides (SCG) in order to classify information?
Derivative classifiers
What is the first step an Original Classification Authority (OCA) must take when originally classifying information?
Determine if the information is official government information
Who has responsibility for the overall policy direction of the Information Security Program?
Director of the Information Security Oversight Office (ISOO)
Requests for waivers and exceptions must identify the specific provision or provisions of the _________________for which the waiver or exception is sought.
DoD Information Security Manual
The unauthorized disclosure of Top Secret information could reasonably be expected to cause __________ to our national security.
Exceptionally grave damage
The unauthorized disclosure of this type of information could reasonably be expected to cause serious damage to our national security.
Exceptionally grave damage
Where do the reasons for classifying certain items, elements or categories of information originally come from?
Executive Order 13526
A waiver is a permanent approved exclusion or deviation from information security standards.
False
Classification levels may be abbreviated (i.e., TS, S, C) in the banner of classified documents.
False
Who provides implementation guidance for the Information Security Program within the DoD?
Heads of DoD Components
The name of the recipient of classified information must be included on which part(s) of the packaging?
Inner wrapped package
All _____________ GSA-approved security containers must conform to Federal Specification FF-L-2740.
Locks for
What type of declassification process is a way for members of the public to request the review of specific classified information?
Mandatory Declassification Review
Whose guidelines should you follow for the destruction of storage media such as thumb drives, zip drives, and computers?
National Security Agency
Which of the following is an example of information technology that is authorized for storing classified information?
On a computer connected to the Secure Internet Protocol Router Network (SIPRNET)
Where can you find the Original Classification Authority's (OCA) contact information in a security classification guide (SCG)?
On the cover of the SCG
Who issues security classification guides (SCG) for systems, plans, programs, projects, or missions?
Original Classification Authorities
In which order must documents containing classified information be marked?
Portion markings, banner markings, classification authority block
Which form is used to record the securing of vaults, rooms, and containers used for storing classified material?
SF-702 Security Container Check Sheet
What do derivative classifiers use to identify specific items or elements of information to be protected?
Security Classification Guides (SCG)
What type of security incident has occurred if an individual neglects to complete the SF702 after securing the container?
Security Infraction
If an individual fails to secure the Sensitive Compartmented Information Facility (SCIF) at the end of the day and, subsequently, unescorted cleaning personnel access the SCIF and see classified information, what type of security incident is this?
Security Infraction ???
The unauthorized disclosure of Secret information could reasonably be expected to cause ____________________ to our national security.
Serious damage
What type of security incident has occurred when classified data is introduced on an information system not approved for that level of information?
Spillage
What type of declassification process is the review of classified information that has been exempted from automatic declassification?
Systematic Declassification-wrong answer
The unauthorized disclosure of this type of information could reasonably be expected to cause exceptionally grave damage to our national security.
Top Secret
Access control measures detect and deter deliberate attempts to gain unauthorized access to classified information.
True
Declassification is the authorized change in the status of information from classified to unclassified.
True
Derivative classifiers are the individuals who generate or create new material based on existing classification guidance.
True
Destruction refers to destroying classified information so that it can't be recognized or reconstructed.
True
Materials and work products submitted by Government, industry, and DoD civilians, contractors, and military members are subject to review by the Defense Office of Prepublication and Security Review (DOPSR) for public and controlled release.
True
Spillage always requires an investigation to determine the extent of the compromise of classified information.
True
The DoD workforce plays a vital role in ensuring the effectiveness of the DoD Information Security Program?
True
The classification authority block identifies the authority, the source, and the duration of classification determination.
True
When not directly in an authorized individual's possession, classified documents must be stored in a GSA-approved security container.
True
The communication or physical transfer of classified information to an unauthorized recipient is _________?
Unauthorized Disclosure