05.10.2014 Views

Sensitive Security Information - Transportation Security Administration

Sensitive Security Information - Transportation Security Administration

Sensitive Security Information - Transportation Security Administration

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

SSI Session for GAO Personnel<br />

U.S. Department of Homeland <strong>Security</strong><br />

<strong>Transportation</strong> <strong>Security</strong> <strong>Administration</strong><br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Program<br />

Presents:<br />

SSI Training for<br />

Surface <strong>Transportation</strong><br />

Stakeholders<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 1<br />

SENSITIVE SECURITY INFORMATION TRAINING 1


SSI Session for GAO Personnel<br />

Defining Surface<br />

<strong>Transportation</strong> Stakeholders<br />

For the purposes of this training, the SSI Program is<br />

defining surface transportation stakeholders as non-aviation,<br />

non-maritime and non-rail transportation entities. This<br />

includes both public (state or local government) and private<br />

sector entities.<br />

Examples (not all inclusive):<br />

●<br />

●<br />

●<br />

●<br />

Mass transit (bus service only)<br />

Intercity and commuter bus service<br />

Highway (motor carriers, bridges, tunnels, etc.)<br />

Pipelines (oil and gas)<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 2<br />

SENSITIVE SECURITY INFORMATION BRIEFING 2


SSI Session for GAO Personnel<br />

Objectives<br />

By the end of this training, you will be able to:<br />

●<br />

●<br />

●<br />

Explain the difference between Classified National<br />

<strong>Security</strong> <strong>Information</strong> and <strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong><br />

(SSI)<br />

Discuss highlights from the SSI Federal<br />

Regulation (49 CFR Part 1520) that apply to<br />

Surface <strong>Transportation</strong> Stakeholders<br />

Safely share and protect SSI in accordance<br />

with requirements in the Federal Regulation<br />

and “Best Practices”<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 3<br />

SENSITIVE SECURITY INFORMATION BRIEFING 3


SSI Session for GAO Personnel<br />

Brief History of SSI<br />

SSI was not developed post-9/11<br />

Created in response to hijackings during the early<br />

1970s<br />

The Air <strong>Transportation</strong> <strong>Security</strong> Act of 1974:<br />

●<br />

●<br />

Required the FAA to establish a regulation<br />

for sharing SSI with airlines and airports<br />

The FAA published the first regulation<br />

regarding SSI in the Federal Register in<br />

1976<br />

After 9/11, SSI expanded to apply to all<br />

modes of transportation<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 4<br />

SENSITIVE SECURITY INFORMATION BRIEFING 4


SSI Session for GAO Personnel<br />

Classified <strong>Information</strong><br />

vs.<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong><br />

(SSI)<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 5<br />

SENSITIVE SECURITY INFORMATION TRAINING 5


SSI Session for GAO Personnel<br />

Categories of <strong>Information</strong><br />

All information held by the government<br />

falls into two categories:<br />

• Classified National <strong>Security</strong> <strong>Information</strong><br />

(a.k.a. Classified <strong>Information</strong>)<br />

(Confidential, Secret, Top Secret)<br />

or<br />

• Unclassified<br />

(SSI, For Official Use Only (FOUO), Public, etc.)<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 6<br />

SENSITIVE SECURITY INFORMATION BRIEFING 6


SSI Session for GAO Personnel<br />

Classified <strong>Information</strong><br />

<strong>Information</strong> of which<br />

“unauthorized disclosure could<br />

reasonably be expected to cause<br />

identifiable or describable damage<br />

to the national security”*<br />

Example:<br />

A U.S. Special Operations Team conducts a raid, driven by<br />

intelligence, on an al-Qa'ida compound on the Afghanistan<br />

border. The identity of the “source” of data and the<br />

information he provided would both be classified.<br />

* Source: Executive Order 13526, Dec 09<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 7<br />

SENSITIVE SECURITY INFORMATION BRIEFING 7


SSI Session for GAO Personnel<br />

Unclassified <strong>Information</strong> Falls<br />

into Two Categories<br />

● <strong>Sensitive</strong> But Unclassified (SBU)<br />

A broad category that includes information protected by<br />

Federal Regulation such as SSI and information protected by<br />

agency or government policy such as For Official Use Only<br />

(FOUO)<br />

● Public <strong>Information</strong><br />

All other information<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 8<br />

SENSITIVE SECURITY INFORMATION BRIEFING 8


SSI Session for GAO Personnel<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong><br />

<strong>Information</strong> obtained or developed which, if<br />

released publicly, would be detrimental to<br />

transportation security.<br />

Examples:<br />

●<br />

●<br />

<strong>Security</strong> Plan created by Tri-County<br />

Metropolitan <strong>Transportation</strong> District<br />

of Oregon (TriMET)<br />

Vulnerability assessment of<br />

pipelines issued by DOT<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 9<br />

SENSITIVE SECURITY INFORMATION BRIEFING 9


SSI Session for GAO Personnel<br />

For Official Use Only (FOUO)<br />

<strong>Information</strong> not protected by regulation that could<br />

adversely affect a Federal program if publicly released<br />

without authorization.*<br />

Example:<br />

Federal building security plans<br />

* Source: DHS Management Directive 11042.1<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 10<br />

SENSITIVE SECURITY INFORMATION BRIEFING 10


SSI Session for GAO Personnel<br />

Law Enforcement <strong>Sensitive</strong> (LES)<br />

Documents marked LES are intended for official<br />

use only. No portion of the document should be:<br />

●<br />

●<br />

Released to the media or the general public<br />

Posted to or sent via non-secure Internet servers<br />

Release of LES material could adversely affect or<br />

jeopardize investigative activities.*<br />

Example:<br />

FBI Intelligence Bulletins<br />

* Source: FBI’s website<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 11<br />

SENSITIVE SECURITY INFORMATION BRIEFING 11


SSI Session for GAO Personnel<br />

What are the differences?<br />

FOUO, LES, and SSI are all categories of<br />

<strong>Sensitive</strong> But Unclassified information, but:<br />

● SSI is based on U.S. law and protected by a Federal<br />

regulation; FOUO and LES are not<br />

● SSI protects information related to transportation<br />

security; FOUO and LES have no subject matter<br />

limitations<br />

● Unauthorized SSI disclosure may result in a civil<br />

penalty; FOUO and LES breaches cannot<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 12<br />

SENSITIVE SECURITY INFORMATION BRIEFING 12


What Are the<br />

SSI<br />

Differences?<br />

Session for GAO Personnel<br />

(cont.)<br />

● In litigation, SSI has stronger protection from<br />

court-ordered production requests than LES and FOUO<br />

● SSI is protected from public release under a Freedom of<br />

<strong>Information</strong> Act (FOIA) request; FOUO or LES may be either<br />

protected or released under FOIA<br />

● SSI is always SSI regardless of who holds the information – in<br />

other words, JFK’s security program is always SSI whether<br />

held by TSA or the Port Authority of New York and New<br />

Jersey<br />

● Documents that contain SSI must be marked as SSI – not as<br />

FOUO or LES – when information is pulled from reports<br />

marked LES, FOUO, and SSI, the new report must be marked<br />

as SSI.<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 13<br />

SENSITIVE SECURITY INFORMATION BRIEFING 13


SSI Session for GAO Personnel<br />

What is PCII?<br />

After 9/11, the Government looked beyond aviation<br />

to other sectors that may be vulnerable to a terrorist<br />

attack. As part of Critical Infrastructure <strong>Information</strong> Act of<br />

2002, the Protected Critical Infrastructure <strong>Information</strong><br />

(PCII) Program was created.<br />

PCII protections allow both private and public entities to<br />

submit information to the Federal government without that<br />

information being eligible for public release.<br />

For more information about PCII, please visit:<br />

http://www.dhs.gov/files/programs/editorial_0404.shtm<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 14<br />

SENSITIVE SECURITY INFORMATION BRIEFING 14


SSI Session for GAO Personnel<br />

Controlled Unclassified<br />

<strong>Information</strong> (CUI)<br />

The President signed an Executive<br />

Order on Controlled Unclassified<br />

<strong>Information</strong> (CUI) on November 4 th<br />

● SSI and PCII will become be a category of CUI. SSI will<br />

continue to exist and function in the same manner as it<br />

does today<br />

● DHS shall not implement CUI until such time as<br />

appropriate policies have been developed and training<br />

provided to DHS employees<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 15<br />

SENSITIVE SECURITY INFORMATION BRIEFING 15


SSI Session for GAO Personnel<br />

Focus on SSI Regulation<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 16<br />

SENSITIVE SECURITY INFORMATION TRAINING 16


SSI Session for GAO Personnel<br />

16 SSI Categories<br />

In order for information to be SSI, the information<br />

must be related to transportation security, its release<br />

must be detrimental, and it must fall under the one<br />

of the 16 categories of SSI defined by<br />

the Federal Regulation (49 CFR Part<br />

1520.5(b)).<br />

This training will focus on the four<br />

categories that apply to Surface<br />

<strong>Transportation</strong> Stakeholders.<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 17<br />

SENSITIVE SECURITY INFORMATION BRIEFING 17


SSI Session for GAO Personnel<br />

Four SSI Categories<br />

(1) <strong>Security</strong> programs and contingency plans –<br />

Any security program or security contingency<br />

plan issued, established, required, or approved by<br />

DOT or DHS.<br />

Examples of documents protected under this category:<br />

● <strong>Security</strong> plan for a commuter bus<br />

service<br />

● <strong>Security</strong> plan for a company that runs<br />

pipelines<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 18<br />

SENSITIVE SECURITY INFORMATION BRIEFING 18


SSI Session for GAO Personnel<br />

Four SSI Categories (cont)<br />

(5) Vulnerability assessments – Reviews, audits,<br />

or other examinations of the security of a<br />

transportation system or asset to determine its<br />

vulnerabilities, including any countermeasures<br />

conducted, directed, or held by DOT or DHS<br />

Examples of information protected under this category:<br />

● Grant proposals sent to DHS that outline the vulnerabilities<br />

of a pipeline located near a seaport<br />

● Vulnerability assessment conducted by a metropolitan<br />

transit authority on its bridges<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 19<br />

SENSITIVE SECURITY INFORMATION BRIEFING 19


SSI Session for GAO Personnel<br />

Four SSI Categories (cont)<br />

(7) Threat information – Any information held<br />

by the Federal government concerning threats<br />

against transportation or transportation systems,<br />

and sources and methods used to gather or develop<br />

threat information, including threats against<br />

information technology<br />

Examples of documents protected under this category:<br />

Documents issued by the TSA Office of Intelligence<br />

that are marked as SSI and provide specific threat<br />

information regarding mass transit<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 20<br />

SENSITIVE SECURITY INFORMATION BRIEFING 20


SSI Session for GAO Personnel<br />

Four SSI Categories (cont)<br />

(16) Other <strong>Information</strong> – Any information<br />

not otherwise described in this section<br />

that TSA or the Secretary of DOT<br />

determines is SSI<br />

Explanation of this category:<br />

On a case-by-case basis, DOT or TSA may make a<br />

written determination that certain information should be<br />

protected as SSI under (16)<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 21<br />

SENSITIVE SECURITY INFORMATION BRIEFING 21


SSI Session for GAO Personnel<br />

Common Surface <strong>Transportation</strong><br />

Stakeholders SSI Documents*<br />

● <strong>Security</strong> Plans by mass transit agencies, bus<br />

companies, pipelines, etc.<br />

● Vulnerability Assessments conducted by<br />

transportation asset seeking grants from the Federal<br />

government<br />

● Documents produced by TSA Office of Intelligence<br />

related to threats to surface transportation that are<br />

specifically marked as SSI<br />

* List not all inclusive<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 22<br />

SENSITIVE SECURITY INFORMATION BRIEFING 22


SSI Session for GAO Personnel<br />

Safety <strong>Information</strong> is NOT SSI*<br />

●<br />

●<br />

●<br />

●<br />

●<br />

Fire Evacuation Plans are not SSI<br />

Instructions on how to shut down a<br />

pipeline in an emergency are not SSI<br />

Construction plans are not SSI<br />

Training materials for employees on<br />

safety measures are not SSI<br />

Safety inspections of infrastructure<br />

are not SSI<br />

* List not all inclusive<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 23<br />

SENSITIVE SECURITY INFORMATION BRIEFING 23


SSI Session for GAO Personnel<br />

Covered Persons<br />

According to the SSI Federal Regulation,<br />

covered persons may access SSI. This includes airport<br />

and airline officials, maritime operators, surface<br />

transportation stakeholders, Federal employees, vendors,<br />

contractors, and grantees, among others.<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 24<br />

SENSITIVE SECURITY INFORMATION BRIEFING 24


SSI Session for GAO Personnel<br />

Persons with a<br />

“Need To Know”<br />

Covered persons have a need to know SSI if<br />

access to information is necessary for the performance<br />

of official duties. DHS or DOT may limit access to<br />

specific SSI to certain employees or covered persons.<br />

Example:<br />

A screening equipment vendor does not need to know<br />

which flights Federal Air Marshals are flying on.<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 25<br />

SENSITIVE SECURITY INFORMATION BRIEFING 25


SSI Session for GAO Personnel<br />

Media Requests for SSI<br />

Under the SSI regulation,<br />

members of the news media<br />

are not covered persons and do<br />

not have a “need to know”<br />

SSI.<br />

Requests for SSI from the<br />

media should be forwarded to<br />

TSA Public Affairs (571-227-<br />

2829) for review.<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 26<br />

SENSITIVE SECURITY INFORMATION BRIEFING 26


SSI Session for GAO Personnel<br />

Proper Marking and<br />

Handling of SSI<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 27<br />

SENSITIVE SECURITY INFORMATION TRAINING 27


SSI Session for GAO Personnel<br />

SSI – Protective Marking<br />

Any person who creates a<br />

record containing SSI<br />

must include an SSI<br />

header and footer.<br />

Even if there is only one<br />

sentence containing SSI<br />

in a 50-page document,<br />

every page must have an<br />

SSI header and footer.<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 28<br />

SENSITIVE SECURITY INFORMATION BRIEFING 28


SSI Session for GAO Personnel<br />

Storing SSI: Lock it Up!!!!<br />

When not actually working with an SSI record<br />

(lunch break, end of the day, etc.), store the SSI<br />

record in a locked desk drawer or in a locked<br />

room to prevent unauthorized access by persons<br />

who do not have a “need to know.”<br />

ALL RECIPIENTS OF SSI ARE MANDATED TO LOCK IT UP!!!<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 29<br />

SENSITIVE SECURITY INFORMATION BRIEFING 29


SSI Session for GAO Personnel<br />

“Best Practices” for Non-DHS<br />

Employees in Protecting SSI<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 30<br />

SENSITIVE SECURITY INFORMATION TRAINING 30


SSI Session for GAO Personnel<br />

Best Practices for Non-DHS<br />

Employees<br />

Other than locking SSI in a locked drawer or cabinet,<br />

which is a requirement, DHS stakeholders and other<br />

covered parties are mandated under the SSI<br />

regulation to take “reasonable steps” to prevent<br />

unauthorized disclosure of SSI.<br />

The next set of slides describes “Best Practices”<br />

stakeholders may use in handling and<br />

protecting SSI.<br />

These “Best Practices” are based on policies<br />

and procedures developed for DHS personnel<br />

to protect SSI.<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 31<br />

SENSITIVE SECURITY INFORMATION BRIEFING 31


SSI Session for GAO Personnel<br />

Best Practices:<br />

SSI Transmission in E-Mail<br />

SSI information transmitted by e-mail should be in a<br />

separate password-protected record, and not in the body of<br />

an e-mail. Passwords should be sent separately, and should:<br />

●<br />

●<br />

●<br />

●<br />

Be at least eight characters in length<br />

Have at least one letter capitalized<br />

Contain at least one number and<br />

one special character<br />

Not be a word in the dictionary<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 32<br />

SENSITIVE SECURITY INFORMATION BRIEFING 32


SSI Session for GAO Personnel<br />

Best Practices:<br />

Web Posting SSI<br />

TSA does NOT post<br />

SSI on its public<br />

website (i.e., Internet)<br />

or on the agency-wide<br />

intranet portal that all<br />

TSA employees and<br />

contractors can access.<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 33<br />

SENSITIVE SECURITY INFORMATION BRIEFING 33


SSI Session for GAO Personnel<br />

Best Practices:<br />

Mailing SSI<br />

●<br />

●<br />

SSI should be mailed by U.S.<br />

First Class mail or other<br />

traceable delivery service using<br />

an opaque envelope or wrapping.<br />

The outside wrapping (i.e., box<br />

or envelope) should not be<br />

marked as SSI.<br />

Interoffice mail should be sent using an unmarked,<br />

opaque, sealed envelope so that the SSI cannot be read<br />

through the envelope.<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 34<br />

SENSITIVE SECURITY INFORMATION BRIEFING 34


SSI Session for GAO Personnel<br />

Best Practices:<br />

Storing SSI on CDs<br />

SSI documents saved on compact<br />

discs (CDs) should be password<br />

protected.<br />

The CD’s outside jacket should be<br />

marked with a label that contains the<br />

SSI footer.<br />

CDs should be protected same as<br />

documents (i.e., store the CD in a<br />

locked drawer).<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 35<br />

SENSITIVE SECURITY INFORMATION BRIEFING 35


SSI Session for GAO Personnel<br />

Best Practices: Storing SSI on<br />

Flash (Thumb) Drives<br />

Personnel should use only encrypted thumb drives or<br />

password-protect documents that contain SSI.<br />

Portable drives are convenient, small, and can store a<br />

large volume of information. They are also easily lost<br />

or misplaced.<br />

Be careful about: what information is<br />

placed on these devices; how they are<br />

stored; and who is walking out the door<br />

with them.<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 36<br />

SENSITIVE SECURITY INFORMATION BRIEFING 36


SSI Session for GAO Personnel<br />

Best Practices:<br />

Taking SSI Records out of the Office<br />

It is not recommended!<br />

However, if taking SSI out of the<br />

office is necessary, employees<br />

should have the permission of the<br />

supervisor and should ensure that<br />

SSI is locked away at night to<br />

prevent unauthorized access of<br />

persons who do not have a “need to<br />

know.”<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 37<br />

SENSITIVE SECURITY INFORMATION BRIEFING 37


SSI Session for GAO Personnel<br />

Best Practices:<br />

Processing<br />

electronic SSI<br />

records at home<br />

According to TSA’s <strong>Information</strong> Technology (IT)<br />

<strong>Security</strong> Policy, TSA requires that only TSA-approved<br />

computers may be used to process or store SSI.<br />

This means that the use of personal or home computers<br />

to process or store SSI records is prohibited for TSA<br />

employees.<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 38<br />

SENSITIVE SECURITY INFORMATION BRIEFING 38


SSI Session for GAO Personnel<br />

Destruction of SSI<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 39<br />

SENSITIVE SECURITY INFORMATION TRAINING 39


SSI Session for GAO Personnel<br />

What Does the SSI<br />

Regulation Say?<br />

“A covered person must destroy SSI completely<br />

to preclude recognition or reconstruction of the<br />

information when the covered person no longer needs<br />

the SSI to carry out transportation security measures.”*<br />

In other words, throwing SSI in any garbage can is not<br />

acceptable under the SSI Federal Regulation!<br />

* 49 CFR Part 1520.19(b)(1)<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 40<br />

SENSITIVE SECURITY INFORMATION BRIEFING 40


SSI Session for GAO Personnel<br />

Best Practices:<br />

Destruction of SSI<br />

The most common<br />

methods used to destroy<br />

SSI material include:<br />

●<br />

●<br />

●<br />

Cross-cut shredders<br />

Contract with a shredding<br />

company<br />

Cutting or tearing into pieces that<br />

are no longer than ½ inch on a<br />

side<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 41<br />

SENSITIVE SECURITY INFORMATION BRIEFING 41


SSI Session for GAO Personnel<br />

Summary<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 42<br />

SENSITIVE SECURITY INFORMATION TRAINING 42


SSI Session for GAO Personnel<br />

You are Responsible for SSI!<br />

Everyone is responsible for properly marking, handling,<br />

protecting, storing, and destroying SSI.<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 43<br />

SENSITIVE SECURITY INFORMATION BRIEFING 43


SSI Session for GAO Personnel<br />

Discussing SSI in Public Areas<br />

is Not Recommended!!<br />

Personnel must be very careful when discussing<br />

SSI in public areas.<br />

You never know who is listening<br />

and not everyone has a “need to<br />

know” the information.<br />

Remember: Terrorists do not care how they receive SSI<br />

as long as they get the information they need to plan an<br />

attack.<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 44<br />

SENSITIVE SECURITY INFORMATION BRIEFING 44


Best Practices:<br />

SSI Session for GAO Personnel<br />

DO’s – SSI Handling<br />

Do – Lock up material containing SSI<br />

Do – Turn off or lock down your computer (pressing the<br />

Windows Key and L at the same time) whenever you<br />

walk away from it<br />

Do – Be conscious of surroundings when discussing SSI;<br />

remember not everyone has a “need to know” SSI<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 45<br />

SENSITIVE SECURITY INFORMATION BRIEFING 45


SSI Session for GAO Personnel<br />

Best Practices:<br />

DON’T’s – SSI Handling<br />

Don’t… Leave SSI unattended<br />

Don’t… Discuss SSI with individuals<br />

who do not have a “need to<br />

know”<br />

Don’t… Put SSI in the body of an e-mail<br />

Don’t… Throw SSI away in any garbage can or<br />

recycling bin<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 46<br />

SENSITIVE SECURITY INFORMATION BRIEFING 46


SSI Session for GAO Personnel<br />

Consequences of Unauthorized<br />

Disclosure of SSI<br />

●<br />

●<br />

Lost lives – terrorists could use the<br />

information to plan an attack<br />

Lost jobs – for Federal employees,<br />

appropriate personnel action may be<br />

a letter of reprimand, suspension, or<br />

even dismissal, depending on the<br />

circumstances<br />

●<br />

Lost money – the government can<br />

impose a $10,000 civil penalty per<br />

offense on stakeholders<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 47<br />

SENSITIVE SECURITY INFORMATION BRIEFING 47


SSI Session for GAO Personnel<br />

<strong>Information</strong> on SSI available at<br />

www.tsa.gov/SSI<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 48<br />

SENSITIVE SECURITY INFORMATION BRIEFING 48


SSI Session for GAO Personnel<br />

Safely Sharing <strong>Information</strong><br />

SSI Program<br />

Office of <strong>Security</strong> Services and Assessments<br />

Office of Law Enforcement/<br />

Federal Air Marshal Service<br />

<strong>Transportation</strong> <strong>Security</strong> <strong>Administration</strong><br />

601 S. 12th Street, East Tower<br />

Arlington, VA 20598-6031<br />

E-Mail: SSI@dhs.gov<br />

Phone: 571-227-3513<br />

Fax: 571-227-2945<br />

<strong>Sensitive</strong> <strong>Security</strong> <strong>Information</strong> Branch<br />

Know It… Mark It… Share It… Lock It… Shred It… 49<br />

SENSITIVE SECURITY INFORMATION TRAINING 49

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!