unauthorized disclosure
CDSE Unauthorized Disclosure training covering UD types, misconceptions, whistleblowing, CNSI and CUI life cycle protection, security and policy reviews, social media policy, the eight reporting steps, and sanctions
Studying for this with your unit? Send it to them.
01What is unauthorized disclosure (UD)?
UD is the communication or physical transfer of classified national security information (CNSI) or controlled unclassified information (CUI) to an unauthorized recipient.
VERIFIED AGAINST THE SOURCE
βUD is the communication or physical transfer of CNSI or CUI to an unauthorized recipient. An unauthorized recipient is anyone who does not meet the criteria to access the information, whether that is access requirements for CNSI or the required lawful, government purpose to access CUI.β
β CDSE IF130.16 Unauthorized Disclosure of Classified Information and CUI Student Guide (January 2025), Lesson 2, p. 2-2 β02Who is an "unauthorized recipient"?
Anyone who does not meet the criteria to access the information β either the access requirements for CNSI, or the required lawful, government purpose to access CUI.
03What is an insider?
Someone who has, or had been, granted eligibility for access to CNSI or eligibility to hold a sensitive position.
VERIFIED AGAINST THE SOURCE
βAn insider is someone who has or had been granted eligibility for access to CNSI or eligibility to hold a sensitive position.β
β CDSE IF130.16 Student Guide (January 2025), Lesson 2, p. 2-2 β04What is a remote actor?
An individual outside of the organization who has gained unauthorized access to CNSI or CUI.
VERIFIED AGAINST THE SOURCE
βUD can also be committed by a remote actor, which is an individual outside of the organization who has gained unauthorized access to CNSI or CUI.β
β CDSE IF130.16 Student Guide (January 2025), Lesson 2, p. 2-2 β05What three things must an individual have for authorized access to CNSI?
A signed Standard Form (SF) 312 Classified Information Non-Disclosure Agreement, eligibility at the appropriate level, and a confirmed need-to-know.
VERIFIED AGAINST THE SOURCE
βFor authorized access to CNSI, an individual must have: A signed Standard Form (SF) 312, Classified Information Non-Disclosure Agreement (NDA); Eligibility at the appropriate level; A confirmed need-to-knowβ
β CDSE IF130.16 Student Guide (January 2025), Lesson 2, p. 2-2 β06What is the standard for authorized access to CUI?
A lawful, government purpose. Authorized holders of CUI are responsible for determining who has a lawful, government purpose. Unlike classified information, an individual generally does not need to demonstrate a need-to-know unless required by a specific law, regulation, or government-wide policy.
VERIFIED AGAINST THE SOURCE
βFor authorized access to CUI, an individual must have a lawful, government purpose to access the information. Authorized holders of CUI are responsible for determining who has a lawful, government purpose. Unlike classified information, an individual or organization generally does not need to demonstrate a need-to-know to access CUI, unless it is required by a specific law, regulation, or government-wide policy.β
β CDSE IF130.16 Student Guide (January 2025), Lesson 2, p. 2-2 β07What are the three levels of intent that can cause unauthorized disclosure?
Willful, negligent, and inadvertent.
08When is a UD incident considered willful?
When the person purposefully disregards DOD security or information safeguarding policies or requirements β for example, intentionally bypassing a known security control or intentionally disclosing classified information in the public domain.
VERIFIED AGAINST THE SOURCE
βAn incident is considered willful if the person purposefully disregards DOD security or information safeguarding policies or requirements. An example of willful UD is an individual intentionally bypassing a known security control, such as an individual with access intentionally disclosing classified information in the public domain.β
β CDSE IF130.16 Student Guide (January 2025), Lesson 2, pp. 2-2 to 2-3 β09When is a UD incident considered negligent?
When the person acted unreasonably, causing UD β for example, a careless act or reckless disregard for proper procedures, such as carelessly sharing classified information via an Unclassified network leading to spillage.
10When is a UD incident considered inadvertent?
When the person did not know, and had no reasonable basis to know, that the security violation or unauthorized disclosure was occurring β for example, reasonably relying on security classification markings in an authorized source document that was later determined to be improperly marked.
VERIFIED AGAINST THE SOURCE
βAn incident is inadvertent if the person did not know, and had no reasonable basis to know, that the security violation or unauthorized disclosure was occurring. An example of inadvertent UD would be an individual who reasonably relied on security classification markings in an authorized source document that was later determined to be improperly marked.β
β CDSE IF130.16 Student Guide (January 2025), Lesson 2, p. 2-3 β11Regardless of intent, what does UD result in?
The loss or degradation of resources or capabilities; it undermines DOD's mission and security, damages public trust, and compromises sources and methods.
12What are the four types of unauthorized disclosure?
Public domain, spillage, espionage, and improper safeguarding of information.
VERIFIED AGAINST THE SOURCE
βAs we just mentioned, there are several types of UD. These include public domain, spillage, espionage, and improper safeguarding of information.β
β CDSE IF130.16 Student Guide (January 2025), Lesson 2, p. 2-5 β13What is a UD in the public domain?
It occurs when CNSI or CUI is released either intentionally or inadvertently to the public β through podcasts, print or web-based articles, books, journals, speeches, television broadcasts, blog postings, social media posts, instant messages, VOIP social platforms such as Discord, Zoom, or Skype, and protected or encrypted messaging apps such as WhatsApp or Signal.
14What is spillage?
A data spill, or spillage, is a willful, negligent, or inadvertent disclosure of CNSI or CUI transferred onto an information system not accredited at the appropriate security level to store, process, or transmit the information.
VERIFIED AGAINST THE SOURCE
βA data spill, or spillage, is a willful, negligent, or inadvertent disclosure of CNSI or CUI transferred onto an information system not accredited at the appropriate security level to store, process, or transmit the information.β
β CDSE IF130.16 Student Guide (January 2025), Lesson 2, p. 2-5 β15When does classified spillage occur?
When classified data is introduced onto an Unclassified information system, an information system with a lower level of classification, or a system not accredited to process data of that restrictive category.
16What is espionage?
Espionage involves activities designed to obtain, deliver, communicate, or transmit CNSI or CUI intended to aid a foreign power.
VERIFIED AGAINST THE SOURCE
βEspionage involves activities designed to obtain, deliver, communicate, or transmit CNSI or CUI intended to aid a foreign power.β
β CDSE IF130.16 Student Guide (January 2025), Lesson 2, p. 2-6 β17What is improper safeguarding of information?
It occurs when inappropriate measures, behaviors, or controls are used to protect CNSI or CUI.
18Lily has access to Top Secret information. During an interview about her DOD role she discloses Top Secret program information, and the journalist publishes it. What type of UD is this?
Public domain.
19Erin, a defense intelligence analyst, is persistently questioned about drone capabilities by an allied foreign analyst who has no need-to-know and works a different problem set. What type of UD is this?
Espionage.
20Marshall leaves Secret paper documents on a restroom counter, where an uncleared custodian later finds them. What type of UD is this?
Improper safeguarding.
21Which special circumstances of UD require unique handling or additional reporting?
UD involving Foreign Government Information (FGI) or NATO information requires further reporting; UD involving criminal activity requires coordination with the Deputy Chief Information Officer (DCIO) during the investigation; and UD involving special information such as SCI, Special Access Program (SAP) information, and Critical Program Information (CPI) has additional reporting requirements.
VERIFIED AGAINST THE SOURCE
βFor UD incidents related to Foreign Government Information (FGI) or North Atlantic Treaty Organization (NATO) information, further reporting is required. Any UDs involving criminal activity require coordination with the Deputy Chief Information Officer (DCIO) during the investigation. Finally, UDs involving special information, such as Sensitive Compartmented Information (SCI), Special Access Program (SAP) information, and Critical Program Information (CPI) have additional reporting requirements.β
β CDSE IF130.16 Student Guide (January 2025), Lesson 2, p. 2-6 β22Is it okay to read, discuss, and freely share CNSI or CUI that has been put in the public domain?
No β this is a misconception. Information that has been disclosed in the public domain remains protected and must not be freely read, discussed, or shared.
23Do you receive protection through "journalist privilege" if you disclose CNSI or CUI to a journalist?
No β this is a misconception. There is no "journalist privilege" protection for disclosing CNSI or CUI.
24Can manuscripts, books, and similar works be submitted to an editor or publisher before undergoing a security review?
No β this is a misconception. They must undergo the required security review first.
25Once you leave your organization, does the SF 312 non-disclosure agreement stop applying?
No β this is a misconception. The SF 312 NDA continues to apply after you leave the organization.
26Is it okay to share Unclassified DOD information on a "secure" messaging app?
No β this is a misconception. Sharing nonpublic DOD Unclassified information on a "secure" messaging app is not authorized.
27What must an individual do for a disclosure to qualify as whistleblowing?
Provide the right information to the right people while still protecting national security assets from unauthorized disclosure, by following the required procedures.
28Whistleblowing occurs when employees report information they reasonably believe provides evidence of what?
A violation of any law, rule, or regulation; gross mismanagement; a gross waste of funds; abuse of authority; or a substantial danger to public health and safety.
VERIFIED AGAINST THE SOURCE
βIt occurs when employees report information they reasonably believe provides evidence of: A violation of any law, rule, or regulation; Gross mismanagement; A gross waste of funds; Abuse of authority; A substantial danger to public health and safetyβ
β CDSE IF130.16 Student Guide (January 2025), Lesson 2, p. 2-10 β29An insider believes the government poses a danger to the public and releases national security information on a social networking site to make the public aware. Is this whistleblowing or unauthorized disclosure?
Unauthorized disclosure. Posting protected national security information in the public domain is unauthorized disclosure, not whistleblowing.
VERIFIED AGAINST THE SOURCE
βIs this whistleblowing or unauthorized disclosure? ... Unauthorized Disclosure (correct response). Feedback: Posting protected national security information in the public domain is unauthorized disclosure.β
β CDSE IF130.16 Student Guide (January 2025), Appendix A: Answer Key, p. A-2 β30What did the Whistleblower Protection Enhancement Act (WPEA) of 2012 do?
It broadened the scope and strengthened the rights and protections of federal employees who blow the whistle on violations involving fraud, waste, and abuse. When reporting violations involving classified programs or information, employees must still follow established guidance for protecting classified information.
31Which issuances outline whistleblower guidance?
PPD 19 (protects employees in the intelligence community or with access to classified information); Title 5 U.S.C. Section 2302, "Prohibited Personnel Practices"; Title 10 U.S.C. Section 1034, "Military Whistleblower Protection Statute"; and Title 10 U.S.C. Section 2890, covering tenants of privatized military housing units.
32A coworker posts on private social media about an upcoming draft DOD policy they were asked to review. The information is not classified β can this disclosure cause damage?
Yes. Even disclosing nonpublic DOD Unclassified information and CUI can cause damage, and nonpublic Unclassified information and CUI can be aggregated to reveal classified information, damaging national security.
33Which two Executive Orders apply to CNSI and CUI?
E.O. 13526, Classified National Security Information, and E.O. 13556, Controlled Unclassified Information.
VERIFIED AGAINST THE SOURCE
βE.O.s that apply to CNSI or CUI are: E.O. 13526, Classified National Security Information; E.O. 13556, Controlled Unclassified Informationβ
β CDSE IF130.16 Student Guide (January 2025), Lesson 2, p. 2-3 β34Which Federal regulations apply to CNSI or CUI?
32 CFR Part 117 (NISPOM), 32 CFR Part 2002 (Controlled Unclassified Information), 32 CFR Parts 2001 and 2003 (Classified National Security Information), and 32 CFR Part 2004 (National Industrial Security Program).
35Which DOD Manual governs the DOD Information Security Program, and what do its three volumes cover?
DODM 5200.01 β Volume 1: Overview, Classification, and Declassification; Volume 2: Marking of Information; Volume 3: Protection of Classified Information.
36Which Intelligence Community Directive addresses unauthorized disclosure of classified national security information?
ICD 701, Unauthorized Disclosure of Classified National Security Information.
VERIFIED AGAINST THE SOURCE
βIn addition, the Intelligence Community (IC) issued Intelligence Community Directive (ICD) 701, Unauthorized Disclosure of Classified National Security Information.β
β CDSE IF130.16 Student Guide (January 2025), Lesson 2, p. 2-4 β37Andrew holds eligibility at the appropriate level and has signed an SF 312. Should you give him access to the Secret CNSI you control?
No β he must also have a need-to-know to access classified information. Eligibility at the appropriate level and a signed SF 312 alone are not sufficient.
VERIFIED AGAINST THE SOURCE
βNo, he must also have a "need-to-know" to access classified information. (correct response) Feedback: It is not simply eligibility at the appropriate level and signed SF 312 that allows an individual to access classified information. That individual also must have a "need-to-know" for that classified information.β
β CDSE IF130.16 Student Guide (January 2025), Appendix A: Answer Key, p. A-3 β38You are hand-carrying paper copies of Top Secret information from your desk to a briefing room. How do you protect it in transit?
Use an SF 703 cover sheet. It is required to protect printed copies of Top Secret information with an SF 703 cover sheet.
VERIFIED AGAINST THE SOURCE
βUse an SF 703 cover sheet (correct response) ... Feedback: It is required to protect printed copies of Top Secret information by using an SF 703 cover sheet.β
β CDSE IF130.16 Student Guide (January 2025), Appendix A: Answer Key, p. A-4 β39How should you transmit Secret information to an authorized coworker located across the country?
Send it on a properly accredited system via secure, properly marked email, after ensuring the recipient has access to a system accredited at the Secret level.
40Your work location has no approved open storage area. How do you store Secret information at the end of the day?
Place it in a GSA-approved container or vault when not in use.
VERIFIED AGAINST THE SOURCE
βPlace it in a GSA-approved container (correct response) ... Feedback: In order to safely store Secret information in an area that is not approved for open storage you must place it in a GSA-approved container or vault when not in use.β
β CDSE IF130.16 Student Guide (January 2025), Appendix A: Answer Key, pp. A-4 to A-5 β41Sandra shared a document containing Top Secret information with a colleague who lacks Top Secret eligibility. What could have prevented this UD?
Ensuring all proper markings were present on the document β a TOP SECRET marking in the header alerts the holder to the presence of CNSI.
42Jim creates a new document that paraphrases Secret information from an authorized source document. What type of classification has occurred?
Derivative classification β incorporating, paraphrasing, restating, or generating in a new form information that is already classified, and marking the newly developed material consistent with the classification markings that apply to the source information.
43As an HR professional, you are asked by a health plan provider for a roster of new personnel. Is the provider an authorized recipient of that CUI?
Yes β this is considered a lawful, government purpose, which is the standard for access to CUI.
44A coworker's new CUI document is marked UNCLASSIFIED//FOUO. Is it properly marked?
No. FOUO is a legacy marking. The document should be assessed against the DOD CUI Registry to see whether it meets the criteria for a CUI category and then marked appropriately.
VERIFIED AGAINST THE SOURCE
βNo (correct response) Feedback: This document is marked FOUO, which is a legacy marking. This document should be assessed to see if it meets criteria for CUI and marked appropriately. Judy should review the DOD CUI Registry to determine if the information aligns with one of the CUI categories.β
β CDSE IF130.16 Student Guide (January 2025), Appendix A: Answer Key, p. A-7 β45What does the Defense Office of Prepublication and Security Review (DOPSR) review submitted material for?
To ensure compliance with established national and DOD policies, and to ensure there is no information that may lead to unauthorized disclosure of classified information or compromise national or operational security.
VERIFIED AGAINST THE SOURCE
βFeedback: DOPSR reviews seek to ensure compliance with established national and DOD policies and that there is no information that may lead to unauthorized disclosure of classified information or compromise national or operational security.β
β CDSE IF130.16 Student Guide (January 2025), Appendix A: Answer Key, pp. A-8 to A-9 β46How does the Public Affairs Office (PAO) determine whether material can be released to the public?
PAO reviews ensure information that could discredit the military or federal government is avoided, that political views are not portrayed, and that offensive or controversial views are not portrayed.
VERIFIED AGAINST THE SOURCE
βFeedback: PAO reviews help ensure information is not included that could discredit the military or federal government. They also ensure political views or controversial views are not portrayed.β
β CDSE IF130.16 Student Guide (January 2025), Appendix A: Answer Key, p. A-9 β47Is it safe to post an image of the DOD installation where you are currently working?
No β delete it. Posting information related to the DOD that has not been cleared for public release on social media is prohibited, including specific information about a DOD installation where you are working.
48You just learned details about an upcoming deployment and want to tell friends and family on social media. Is this safe to post?
No β delete it. Posting details about an upcoming deployment on social media is prohibited in accordance with DODI 5400.17.
VERIFIED AGAINST THE SOURCE
βDelete (correct response) Feedback: Posting details about an upcoming deployment on social media is prohibited in accordance with DODI 5400.17.β
β CDSE IF130.16 Student Guide (January 2025), Appendix A: Answer Key, p. A-10 β49Is it safe to post pictures from a vacation you have already returned from?
Yes. While it is a best practice to wait until after a vacation to share details about it, it is safe to post about it after you return.
50A journalist emails you asking for comment about the range of a new missile. What should you do?
Report it to your Security Manager. Do not make any statement or comment that confirms or denies the accuracy of the information; follow your Component guidance.
VERIFIED AGAINST THE SOURCE
βReport to Security Manager (correct response) Feedback: When approached for comment from a journalist, do not make a statement or comment that confirms or denies the accuracy of the information; you should follow your Component guidance and report this request to your Security Manager.β
β CDSE IF130.16 Student Guide (January 2025), Appendix A: Answer Key, p. A-10 β51A coworker approaches you with Top Secret documents he found in the bathroom. What should you do next?
Safeguard it in the appropriate manner and report it to your Security Manager or Facility Security Officer (FSO).
VERIFIED AGAINST THE SOURCE
βSafeguard it and report it to your Security Manager (correct response) Feedback: When you recognize that CNSI is improperly safeguarded, you must ensure you safeguard it in the appropriate manner and notify your Security Manager or Facility Security Officer (FSO).β
β CDSE IF130.16 Student Guide (January 2025), Appendix A: Answer Key, p. A-11 β52What are the eight steps of the UD reporting process, in order?
Safeguard, Report, Inquire, Investigate, Evaluate, Elevate, Correct, and Sanction.
VERIFIED AGAINST THE SOURCE
βYou have now learned about the eight reporting steps when you encounter UD: Safeguard; Report; Inquire; Investigate; Evaluate; Elevate; Correct; Sanctionβ
β CDSE IF130.16 Student Guide (January 2025), Lesson 6, p. 6-6 β53Which of the eight reporting steps apply to everyone?
The first two β Safeguard and Report. They are the responsibility of anyone who believes they have witnessed, discovered, or have knowledge of an unauthorized disclosure.
VERIFIED AGAINST THE SOURCE
βThe first two steps of the process apply to everyone. They are essential and the responsibility of anyone who believes they have witnessed, discovered, or have knowledge of an unauthorized disclosure.β
β CDSE IF130.16 Student Guide (January 2025), Lesson 6, p. 6-6 β54Who do you report a suspected UD to, and what happens next?
Report it to your Security Manager or Facility Security Officer (FSO) immediately after safeguarding. The FSO or Security Manager will report it to authorities at the next level.
55What happens during step five, Evaluate?
The results of the inquiry and, if necessary, the investigation are evaluated to determine whether the incident is a security infraction or a security violation, and to evaluate the severity of the UD where loss or compromise has occurred.
56When is step four, Investigate, conducted?
When an inquiry does not yield answers to all of the questions required.
VERIFIED AGAINST THE SOURCE
βStep four in the reporting process, Investigate, is conducted when an inquiry does not yield answers to all of the questions required.β
β CDSE IF130.16 Student Guide (January 2025), Lesson 6, p. 6-4 β57In step six, Elevate, who must be notified at minimum when classified information is lost or compromised?
The Original Classification Authority (OCA), so a damage assessment can be initiated. For spillage you would also notify the Information System Security Manager (ISSM), and in some situations results may need to be elevated to the UD Program Management Office (PMO) and the appropriate Military Department Counterintelligence Organizations (MDCOs).
58What is the purpose of step seven, Correct?
Corrective actions are implemented that focus on preventing future incidents and eliminating any conditions that might have contributed to the event. The cognizant DOD Component determines and implements the appropriate corrective actions based on the extent or severity of the incident.
59What administrative sanctions may be imposed for unauthorized disclosure?
Administrative sanctions outlined in DODM 5200.01, Volume 1 include a warning, a reprimand, and suspension without pay.
VERIFIED AGAINST THE SOURCE
βThese include instituting any administrative actions as outlined in DODM 5200.01, Volume 1. Administrative sanctions include a warning, reprimand, and suspension without pay.β
β CDSE IF130.16 Student Guide (January 2025), Lesson 6, p. 6-5 β60When must criminal sanctions be undertaken for unauthorized disclosure?
Criminal sanctions must be undertaken when applicable, in accordance with the Uniform Code of Military Justice or sections 801 to 940 of Title 10, U.S.C.
VERIFIED AGAINST THE SOURCE
βCriminal sanctions must be undertaken when applicable, in accordance with the Uniform Code of Military Justice or sections 801 to 940 of Title 10, U.S.C.β
β CDSE IF130.16 Student Guide (January 2025), Lesson 6, pp. 6-5 to 6-6 β61If a UD involved CNSI, what must a Security Manager or FSO do?
Report it to the Original Classification Authority (OCA) to conduct a damage assessment. This may vary depending on whether you are an FSO or a DOD Security Manager, and UD of certain types of classified information requires unique handling or additional reporting per DODM 5200.01 Volume 3, enclosure 6.
VERIFIED AGAINST THE SOURCE
βIf the unauthorized disclosure involved CNSI, you must report it to the Original Classification Authority (OCA) to conduct a damage assessment; this may vary depending on if you are an FSO or DOD Security Manager.β
β CDSE IF130.16 Student Guide (January 2025), Lesson 6, p. 6-7 β62Which type of CUI carries additional reporting requirements when disclosed?
Personally identifiable information (PII), which is a type of CUI, has additional requirements.
Know questions we're missing?
Submit your own Q&A pairs. AI reviews them for quality, then they go live for everyone.
Study these as flashcards
Load all 62 questions into a free study set β flashcards, a practice test, and spaced repetition. No account.
Works on any PDF, doc or web page too β not just military training.
Veteran? vetaid.ai β free VA benefits help.