A Security Classification Guide (SCG) Is
7 Essential Facts: What A Security Classification Guide (SCG) Is

Understanding what a Security Classification Guide (SCG) is is fundamental for anyone working in government defense or information security. A Security Classification Guide (SCG) is an official document that provides detailed instructions for determining what specific information must be classified

According to the Information Security Oversight Office (ISOO), an SCG records original classification decisions made by an authorized Original Classification Authority (OCA) concerning specific elements of program-related information. It can then be used by authorized personnel as an official source for derivative classification.

For anyone studying cybersecurity, information security, CompTIA Security+, government security, or security awareness, understanding the meaning and purpose of an SCG is important.

A Security Classification Guide (SCG) Is

A Security Classification Guide (SCG) Is What?

A Security Classification Guide (SCG) is a record of original classification decisions that provides specific classification guidance for information associated with a program, system, operation, project, or other subject.

In simple terms, an SCG tells authorized personnel:

  • What information requires classification
  • What classification level applies
  • Why the information is classified
  • How long the information should remain classified
  • What information is unclassified
  • How classification markings should be applied

An SCG therefore acts as a standardized reference for people who need to create or handle information derived from classified sources.

The U.S. National Archives explains that SCGs provide detailed guidance for derivative classifiers and can be used as source documents when creating derivatively classified material.

Simple Definition

A Security Classification Guide (SCG) is a document that provides authorized classification instructions for specific information and tells derivative classifiers what classification level and duration to apply.

This is the key definition to remember for security training and exam questions.

Why Is a Security Classification Guide Important?

Classification decisions need to be applied consistently. Without standardized guidance, different people could classify similar information differently.

An SCG helps solve this problem by documenting the classification decisions made by an authorized authority.

For example, suppose a government program contains information about:

  • Technical specifications
  • System vulnerabilities
  • Testing schedules
  • Program plans
  • Personnel information
  • Operational capabilities

An SCG can identify which elements are unclassified and which require classification. It can also specify whether information should be marked Confidential, Secret, or Top Secret, depending on the applicable classification decision.

The National Archives identifies three levels of classified national security information: Top Secret, Secret, and Confidential. Unclassified is used for information that does not meet the requirements for classification.

1. An SCG Records Original Classification Decisions

One of the most important facts about an SCG is that it records original classification decisions.

Original classification occurs when an authorized person determines for the first time that information requires protection against unauthorized disclosure in the interest of national security.

An Original Classification Authority, commonly called an OCA, has the authority to make original classification decisions.

The SCG then captures those decisions in a structured form that other authorized personnel can use.

This distinction is important:

The SCG does not give an ordinary employee the authority to create new classification decisions.

Instead, it provides authorized guidance based on decisions already made by the appropriate classification authority.

2. An SCG Supports Derivative Classification

A major purpose of a Security Classification Guide is to support derivative classification.

Derivative classification occurs when someone incorporates, paraphrases, restates, or generates information in a new form based on information that is already classified or based on authorized classification guidance.

For example, imagine an SCG states that specific technical information about a system is classified Secret.

An authorized employee creates a report containing that information. The employee does not independently decide that the information should be Secret. Instead, the employee follows the applicable classification guidance from the SCG.

The resulting document must carry the appropriate classification markings.

This helps ensure that the classification decision is consistently applied.

The National Archives explains that individuals applying derivative classification markings must respect original classification decisions and carry the relevant classification markings into newly created documents.

3. An SCG Identifies Classification Levels

Another important function of an SCG is identifying the appropriate classification level for particular information.

Under the U.S. national security classification system, the three classification levels are:

Confidential

Confidential is the lowest level of classified national security information.

Secret

Secret information requires a higher level of protection because unauthorized disclosure could cause a more serious level of damage to national security.

Top Secret

Top Secret is the highest of the three standard classification levels and applies to information whose unauthorized disclosure could cause exceptionally grave damage to national security.

The classification level should not be selected simply because information appears sensitive. It must be determined according to applicable classification authority and guidance.

4. An SCG Provides Classification Duration

A Security Classification Guide can also provide instructions concerning how long information remains classified.

Classification is not necessarily permanent. Classification guidance can specify a declassification date, event, or other applicable instruction.

When a derivative document is created using an SCG, the classifier follows the applicable declassification instructions from the guide.

The Center for Development of Security Excellence (CDSE) explains that when an SCG is used to determine the declassification date of a derivatively classified document, the declassification instructions provided by the OCA should be followed.

This is important because classification markings are not only about the classification level. They can also communicate information about when classification should end.

5. An SCG Helps Prevent Inconsistent Classification

Consistency is one of the biggest benefits of an SCG.

Imagine ten employees working with information about the same government program. Without a common classification guide, one employee might classify a particular technical detail as Secret while another considers the same information Unclassified.

An SCG provides a common reference.

It helps authorized personnel apply the same classification decisions to the same information elements.

ISOO specifically states that SCGs help ensure users apply the same level of protection and the same classification duration to the same information.

This reduces confusion and supports more consistent information security practices.

6. What Information Can an SCG Contain?

A Security Classification Guide can contain detailed information about specific elements that require classification.

Depending on the program or subject, an SCG may address items such as:

  • Program information
  • Technical information
  • Operational information
  • System capabilities
  • Vulnerabilities
  • Testing information
  • Design information
  • Intelligence-related information
  • Research and development information
  • Specific dates or events
  • Classification reasons
  • Declassification instructions

The exact contents depend on the program and the classification decisions that apply.

An SCG can also identify information that does not require classification. This is important because classification guidance is not simply a list of everything that must be protected. It can distinguish between classified and unclassified information elements.

7. Who Approves a Security Classification Guide?

A Security Classification Guide must be approved through the appropriate classification authority.

Executive Order 13526 provides that agencies with original classification authority prepare classification guides to facilitate proper and uniform derivative classification. It also establishes approval requirements for classification guides.

This means an SCG is not simply an informal document created by an employee.

It represents authorized classification decisions.

The appropriate authority is particularly important because classification decisions affect how national security information is handled, marked, protected, shared, and eventually declassified.

SCG and Derivative Classification: How They Work Together

Understanding the relationship between an SCG and derivative classification is essential.

The basic process is:

Original Classification Decision → Security Classification Guide → Derivative Classification → Proper Marking and Protection

An authorized Original Classification Authority makes an original classification decision.

That decision is documented in classification guidance such as an SCG.

A person performing derivative classification then uses the approved guidance to determine how newly created information should be marked.

The newly created document receives the appropriate classification markings based on the source information or applicable classification guidance.

The National Archives describes derivative classification as incorporating, paraphrasing, restating, or generating classified information in a new form while applying the appropriate classification markings.

Example of Using an SCG

Consider a simplified example.

An SCG contains the following guidance:

Information ElementClassification
General program descriptionUnclassified
Technical specificationsConfidential
Specific vulnerability informationSecret
Certain highly sensitive operational informationTop Secret

An employee needs to prepare a report containing information about the program.

The employee checks the applicable SCG.

The report contains technical specifications classified as Confidential and vulnerability information classified as Secret.

The employee must apply the appropriate classification markings according to the applicable guidance.

The overall classification may therefore be determined by the highest applicable classification of the information included in the document, subject to the governing rules and any applicable handling or dissemination controls.

The employee is not creating a new original classification decision. The employee is applying an existing classification decision.

What Is the Difference Between an SCG and a Classified Source Document?

An SCG and a classified source document can both provide information used for derivative classification, but they are not the same thing.

A source document contains classified information that can be used when creating another document.

An SCG provides classification guidance about specific information elements and tells authorized users how those elements should be classified.

In other words:

Source document: Contains classified information.

SCG: Provides classification instructions.

The distinction is particularly useful when studying derivative classification because authorized personnel may use classification guides and other authorized source material when making derivative classification decisions.

SCG vs. Declassification Guide

Another common point of confusion is the difference between an SCG and a declassification guide.

A Security Classification Guide primarily provides classification guidance for information that needs protection.

A declassification guide provides instructions about information that may be declassified and information that must remain classified.

The National Archives defines a declassification guide as written instructions issued by a declassification authority describing information that may be declassified and information that must remain classified.

Therefore, they have related but different purposes.

Does an SCG Make Someone an Original Classification Authority?

No.

This is an important point for exams and security training.

Simply using or possessing a Security Classification Guide does not make someone an Original Classification Authority.

An SCG provides classification guidance. An OCA is specifically authorized to make original classification decisions.

ISOO’s training guidance explicitly notes that a properly constructed classification guide does not make the user an original classification authority.

So remember:

SCG = classification guidance

OCA = authority to make original classification decisions

Why Are SCGs Important in Cybersecurity?

Although SCGs are strongly associated with government and national security information, the underlying concept is highly relevant to information security.

Cybersecurity professionals routinely work with sensitive information, including:

  • System architecture
  • Vulnerability information
  • Security assessments
  • Incident reports
  • Access-control information
  • Technical documentation
  • Operational information
  • Sensitive research

Organizations need consistent rules for determining how sensitive information should be handled.

In environments governed by national security classification requirements, SCGs provide a formal mechanism for communicating classification decisions.

CDSE provides dedicated training on Security Classification Guidance and Derivative Classification, highlighting the importance of understanding classification determination, classification guidance, and the correct use of authorized sources.

Common SCG Exam Question

A Security Classification Guide (SCG) is:

Answer: A document that provides detailed classification guidance for specific information and supports derivative classification.

If the question provides several choices, look for the option describing an official document or record that:

  • Records classification decisions
  • Identifies information requiring classification
  • Specifies the appropriate classification level
  • Guides derivative classifiers

Avoid answers suggesting that an SCG gives every user authority to classify information originally.

Key Facts to Remember

If you are preparing for a security certification or government security training, remember these points:

  1. SCG stands for Security Classification Guide.
  2. An SCG records original classification decisions.
  3. It is associated with an authorized Original Classification Authority.
  4. It provides guidance for derivative classification.
  5. It identifies specific information elements requiring classification.
  6. It can specify the applicable classification level.
  7. It can provide classification duration or declassification instructions.
  8. It promotes consistent classification decisions.
  9. It does not make the user an Original Classification Authority.
  10. It is different from a declassification guide.

Frequently Asked Questions

What does SCG stand for?

SCG stands for Security Classification Guide.

What is the purpose of an SCG?

The purpose of an SCG is to provide detailed and consistent classification guidance for specific information. It can be used as an authorized source for derivative classification.

Who creates a Security Classification Guide?

Agencies with original classification authority prepare classification guides to support proper and uniform derivative classification. The guide must receive the appropriate approval under the applicable classification rules.

Can an SCG classify information?

An SCG documents and communicates authorized classification decisions. A person using the SCG applies those decisions when performing derivative classification. Using an SCG does not itself give that person original classification authority.

What are the three levels of classified information?

The three standard U.S. national security classification levels are Confidential, Secret, and Top Secret.

Is an SCG used for derivative classification?

Yes. One of the primary purposes of an SCG is to provide guidance that derivative classifiers can use when determining and applying classification markings.

Is an SCG the same as a classified source document?

No. A classified source document contains classified information, while an SCG provides specific classification guidance for information elements. Both may be relevant to derivative classification, depending on the applicable rules.

Final Answer: A Security Classification Guide (SCG) Is

A Security Classification Guide (SCG) is an authorized record of original classification decisions that provides detailed instructions for identifying information that requires classification, determining the appropriate classification level and duration, and applying those decisions during derivative classification.

In simple terms, an SCG tells authorized personnel what information should be classified and how that classification should be applied.

For exam purposes, the most important phrase to remember is:

An SCG provides classification guidance for derivative classifiers and records original classification decisions.

Understanding SCGs ensures that cybersecurity personnel properly handle, segment, mark, and store sensitive digital data according to federal guidelines. Formal training modules are available via the CDSE Security Classification Guidance Training.

Leave a Reply

Your email address will not be published. Required fields are marked *