“Sensitive But Unclassified” Information and Other Controls: Policy and Options for Scientific and Technical Information
Congressional research reportDec 29, 2006
Ask Donna
What actually matters in this document.
Text
“Sensitive But Unclassified” Information and
Other Controls: Policy and Options for
Scientific and Technical Information
(name redacted)
December 29, 2006
Congressional Research Service
7-....
www.crs.gov
RL33303
CRS Report for Congress
Prepared for Members and Committees of Congress
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
Summary
Providing access to scientific and technical information (S&T) for legitimate uses while
protecting it from potential terrorists poses difficult policy choices. Federally funded, extramural
academic research is to be “classified” if it poses a security threat; otherwise, it is to be
“unrestricted.” Since the September 11, 2001 terrorist attacks, controls increasingly have been
placed on some unclassified research and S&T information, including that used to inform
decision making and citizen oversight. These controls include “sensitive but unclassified” (SBU)
labels; restrictive contract clauses; visa controls; controlled laboratories; and wider legal
restrictions on access to some federal biological, transportation, critical infrastructure, geospatial,
environmental impact, and nuclear information. Some professional groups have supported
voluntary controls on the conduct or publication of sensitive research. Federal agencies do not
have uniform definitions of SBU or consistent policies to safeguard or release it, raising questions
about how to identify SBU information, especially S&T information; how to keep it from
terrorists, while allowing access for those who need to use it; and how to develop uniform
nondisclosure policies and penalties. On December 16, 2005, President Bush instructed federal
agencies to standardize procedures to designate, mark, and handle SBU information, and to
forward recommendations for government-wide standards to the Director of National Intelligence
(DNI). The Information Sharing Environment Implementation Plan, sent to Congress in
November 2006, reports that final action will occur during the lst quarter of CY2006.
Following the 2001 terrorist attacks, the Bush Administration issued guidance that reversed the
Clinton Administration’s “presumption of disclosure” approach to releasing information under
Freedom of Information Act (FOIA) and cautioned agencies to consider withholding SBU
information if there was a “sound legal basis” to do so. Some agencies contend that SBU
information is exempt from disclosure under FOIA, even though such information per se is not
exempt under FOIA. The 2002 enactment of the Federal Information Security Management Act
(FISMA) rendered moot the definition of SBU that some agencies had used since the passage of
the Computer Security Act of 1987, which identified sensitive information by content. FISMA
requires agencies to categorize the criticality and sensitivity of all information according to the
security control objectives of confidentiality, integrity, and availability across a range of risk
levels and to use safeguards based on risk of release. Many federal agencies have not yet fully
implemented these new procedures. During the 109th Congress, P.L. 109-90 and P.L. 109-295
focused on management, oversight, and appropriate use of the sensitive security information
(SSI) category. Legislative proposals focused on standardizing concepts of “sensitive”
information; modifying penalties for disclosure; and clarifying FOIA. During the 110th Congress,
additional topics likely to be controversial include limiting the number of persons who can
designate SBU; widening the use of risk-based approaches to control; centralizing review,
handling, and appeals; and evaluating the impact of federal policies on nongovernmental
professional groups’ prepublication review and self-policing of sensitive research. This report will
be updated as necessary.
Congressional Research Service
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
Contents
Introduction to the Issues ............................................................................................................1
Summary of Federal Policies to Classify or Control Scientific and Technical Information............2
Policies for Classification of Research Information ...............................................................2
Controls on Nonclassified Academic and Industrial Research ................................................3
Export and Visa Controls ................................................................................................4
Policies To Control SBU Information ..........................................................................................8
Introduction to the Term “SBU” ............................................................................................8
Computer Security Act Definition of “Sensitive”...................................................................8
SBU in Relation to the Freedom of Information Act ..............................................................9
Department of Justice Broadens Interpretation of Exemptions From FOIA in 2003
and 2004 .................................................................................................................... 10
SBU Information Policies in the Homeland Security Act, P.L. 107-296, and
Subsequent Presidential Action ........................................................................................ 12
Requirements to Use Mandatory Minimum NIST-Generated Risk Standards To Protect
All Information ...................................................................................................................... 14
NIST’s Policies, Standards, and Documents ........................................................................ 16
A Formal Risk Analysis Process Is Not Required........................................................... 18
Nongovernmental Experts’ Recommendations to Use Risk Analysis to Identify and
Control Sensitive Information .......................................................................................... 19
Policies To Protect Specific Types of Sensitive Information Involving Scientific and
Technical Applications ........................................................................................................... 21
Critical Infrastructure Information Controls......................................................................... 22
Sensitive Security Information Controls: Transportation...................................................... 23
Critique of SSI Rules .................................................................................................... 25
Controls on Environmental Impact Information................................................................... 26
Critiques of Controls on Environmental Information ..................................................... 27
Illustration of Complexity of the Issue: the Nuclear Regulatory Commission
(NRC)........................................................................................................................ 29
Controls on Unclassified Biological Research Information .................................................. 30
National Science Advisory Board for Biosecurity .......................................................... 31
Views on Adequacy of Biosecurity Protection Policies .................................................. 33
Issues Dealing with Geospatial Information......................................................................... 38
The Department of Homeland Security’s SBU Directives .......................................................... 39
Contentious Issues, Together With Legislative Action and Other Options .................................. 41
Allegations That Some Controls Can Exacerbate Vulnerability and Stifle Scientific
Research and Technological Innovation............................................................................ 42
Critique of Nondisclosure Requirements ............................................................................. 44
Legislation Introduced Affecting Disclosure Policies..................................................... 45
SBU Information in Relation to FOIA................................................................................. 46
Congressional Action, to Clarify FOIA, with Implications for SBU ............................... 49
Federal Information Systems and Automated Identification Processes Used for
Sensitive Information ....................................................................................................... 51
Inconsistency in Agencies’ Processes To Identify SBU Information ..................................... 52
Activities Relating To Developing a Standard Definition of SBU Information ..................... 53
GAO Study on SSI........................................................................................................ 55
Congressional Research Service
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
P.L. 109-90 Requires DHS To Improve Use of SSI Categories and Report to
Congress .................................................................................................................... 56
P.L. 109-525 Limits Excessive Use of the SSI Label...................................................... 57
Studies and Hearings on SBU During 2006 ................................................................... 57
Legislation Introduced on “Pseudo-Classification” .............................................................. 58
Option To Monitor Agency Use of Risk-based Standards for Sensitive Unclassified
Information...................................................................................................................... 59
Recommendations to Institute Better Governance of SBU Information Procedures .............. 60
Limit the Number of Persons Who Can Designate SBU................................................. 60
Options To Centralize Policy Control for SBU Information ........................................... 61
An Appeals Process....................................................................................................... 62
Other Remaining Issues and Unanswered Questions............................................................ 63
Appendixes
Appendix A. Illustrations of Federal Agency Controls on Sensitive Information ........................ 64
Appendix B. Illustrations of Federal Information Systems Created to Transmit Sensitive
But Unclassified Information ................................................................................................. 74
Contacts
Author Contact Information ...................................................................................................... 77
Congressional Research Service
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
Introduction to the Issues
Federal agencies have long confronted the need to balance the release of information for public
use with the need to withhold information that could be used to threaten privacy or security. The
term “sensitive but unclassified” (SBU) information was used before the terrorist attacks of
September 11, 2001, even though there is no statutory definition for it. Since 9/11 more agencies
have started to use the term “SBU,” or some variant of it, and to implement security systems to
identify and protect nonclassified information whose release might benefit terrorists. Many
questions have been raised about how to design uniform policies and controls for SBU
information. This report focuses on controls for two kinds of scientific and technical
information—information used in research and scientific publication and information used to
serve broader public policy purposes, such as in regulatory decisionmaking and citizen oversight.
Both public and privately controlled information are included and in some respects, private
professional groups’ responses are being defined by public pressures and decisions.
Two divergent perspectives are discernable. From one perspective, broadening controls to deny
public access to federal SBU information will constrain terrorists, who might use it to threaten
buildings, infrastructure, people, and services. It has been estimated that “our adversaries derive
up to 80% of their intelligence from open-source information.”1 Another source put this at 90%,
referring to information about local energy infrastructures, water reservoirs, dams, highly
enriched uranium storage sites, and nuclear and gas facilities. Moreover, some say that the
potential for terrorism is heightened if terrorists can aggregate seemingly innocuous bits of public
information. 2 Although many agencies have begun to limit public access to sensitive information,
from this perspective, these efforts are inadequate.
In contrast to those who seek to widen controls, another view contends that inadequate and
insufficient sharing of information with the public and among first responders potentially
weakens efforts to protect the nation from terrorist attacks. A related perspective is that as
government policy on sharing information shifts to the “need to know” rationale that has become
more prevalent since the 9/11 terrorist attacks, the imposition of more controls will deny ordinary
citizens information relating to research, environmental protection, transportation, and so forth
that they need in order to be informed3 and to hold accountable government and industry
decisionmakers. Some say new control policies unduly limit access to information needed to
advance the progress of science and technology and the development of technologies to counter
threats, arguing that if scientific and technical information needs to be restricted, it should be
classified.
This report traces the evolution of SBU-related controls; summarizes actions taken to protect
certain types of scientific and technical information; describes critiques of some control policies;
and summarizes proposals and actions, including congressional, executive and other initiatives, to
1
In a document issued by the Pacific Northwest National Laboratory, a Department of Energy affiliated national
laboratory, in “F.A.Q. Mozart,” at http://www.pnl.gov/isrc/mozart/faq.html.
2
Greg Griffin, “Program Management Perspective: Sensitive Unclassified Information,” The Dragon’s Breath, April
2003.
3
The Final Report of the National Commission on Terrorist Attacks Upon the United States, July 22, 2004, (also called
The 9/11 Commission Report) encouraged the promotion of a “need-to-share” culture, as opposed to a “need-to-know”
culture of information protection, focusing on the development of a “trusted information network” to make information
more accessible. (Available at http://www.9-11commission.gov/report/911Report.pdf.)
Congressional Research Service
1
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
clarify these issues and develop policies that serve various stakeholders. It also raises issues that
may warrant further attention. 4
Summary of Federal Policies to Classify or Control
Scientific and Technical Information
Generally, pursuant to National Security Decision Directive 189 (NSDD-189), fundamental (basic
or applied) research conducted in universities is not to be labeled “classified” if does not affect
national security; it is therefore “unrestricted.”5 Nevertheless, as one commentator noted, “[T]he
federal government seems to possess wide latitude in declaring information, even purely
scientific research, classified or at least sensitive to prevent publication.”6
Policies for Classification of Research Information
If research does compromise national security, it may be classified pursuant to Executive Order
12958 and Executive Order 13292—the latter of which expanded the government’s ability to
classify some scientific and technical information to include information related to “defense
against transnational terrorism” (Section 1.4 of Executive Order 13292).7 During 2001 and 2002,
the heads of several federal agencies with substantial research responsibilities, who did not have
classification authority under Executive Order 12958, were given original classification authority.
These included the Secretaries of Health and Human Services8 and of Agriculture,9 the
4
This report updates CRS Report RL31845, “Sensitive But Unclassified” and Other Federal Security Controls on
Scientific and Technical Information: Background on the Controversy, by (name redacted), which described the
history of governmental controls on “sensitive unclassified information.”
5
National Security Decision Directive-189 (NSDD-189), titled “National Policy on the Transfer of Scientific,
Technical and Engineering Information” and issued on Sept. 21, 1985, says that if federally funded basic scientific and
technical information produced at colleges, universities and laboratories is to be controlled for national security
reasons, it should be classified. But, “... to the maximum extent possible, the products of fundamental research remain
unrestricted. It is also the policy ... that, where the national security requires control, the mechanism for control of
information generated during Federally funded fundamental research in science, technology, and engineering at
colleges, universities, and laboratories is classification.” “Fundamental research” is defined as “basic and applied
research in science and engineering, the results of which ordinarily are published and shared broadly within the
scientific community....” This policy is reflected in Executive Order 12958. NSDD-189 is still in effect, as stated in a
letter from the National Security Advisor to the Center for Strategic and International Studies (Issued by National
Security Advisor Condoleezza Rice on November 1, 2001).
6
Alexander J. Breeding, Sensitive But Unclassified Information: A Threat to Physical Security, SANS Institute, 2003,
p. 24.
7
Executive Order 12958, Apr. 17, 1995 (Federal Register, 60 FR 19825), permitted classification of “scientific,
technological, or economic matters relating to the national security” (Sec. 1.5). But Section 1.8 (b) prohibited
classification of “basic scientific research information not related to the national security.” Executive Order 13292,
Mar. 25, 2003, changed section 1.5 of Executive Order 12958 to permit classification of “scientific, technological, or
economic matters relating to the national security, which includes defense against transnational terrorism” (Sec. 1.4 (e)
of Executive Order 13292, Federal Register, Mar. 25, 2003). The amendment also added a new category of
information, concerning “weapons of mass destruction,” which may be classified (Sec. 1.4 (h)). The exemption for
basic scientific research not clearly related to national security remains (new Section 1.7).
8
“Order of December 10, 2001—Designation Under Executive Order 12958, Federal Register, Dec. 12, 2001, Vol. 66,
No. 239, pp. 64345-64347.
9
“Order of September 26, 2002—Designation Under Executive Order 12958,” Federal Register, Sept. 30, 2002, Vol.
67, No. 189, pp. 61463-61465.
Congressional Research Service
2
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
Administrator of the Environmental Protection Agency (EPA),10 and the Director of the White
House Office of Science and Technology Policy (OSTP).11 Also, pursuant to Executive Order
12958, federally funded researchers at any research-performing institution, including universities
and colleges, are obligated to report to the government information that they produce that should
be classified.12 In addition, the government may exercise prepublication reviews on some R&D
information, 13 and by writing into contracts control clauses for SBU or classified information.
Some R&D information is “born classified,” according to the Atomic Energy Act of 1946.14 In
addition, pursuant to the Information Security Act of 1951, certain patent information may be
classified if release would harm national security.15
Controls on Nonclassified Academic and Industrial Research
Academic and industrial researchers are also subject to sensitive information controls for
nonclassified information. Some of these are voluntary and self-imposed by researchers or
10
“Order of May 6, 2002—Designation Under Executive Order 12958,” Federal Register, May 9, 2002, Vol. 67, No.
90, p. 31109.
11
“Order of September 17, 2003—Designation Under Executive Order 12958,” Federal Register, Sept. 17, 2003, Vol.
68, No. 184, p. 55257.
12
“Most government grants for unclassified technical activity specify that if the grantee believes the results of the work
warrant classification, the grantee has the responsibility to limit the dissemination of that work and to contact the
appropriate U.S. government agency with the authority to classify it. In such extraordinary cases, the initiative to seek
classification rests with the grantee, not the government” (Security Controls on Scientific Information and the Conduct
of Scientific Research: A White Paper of the Commission on Scientific Communication and National Security,
Washington, D.C., Center for Strategic and International Studies, June 2005, pp. 5-6). For instance, according to
section 850 of the current version of the NSF Grant Policy Manual, NSF-02-151, July 2002, “Some basic research
information concerning, among other things, scientific, technological or economic matters relating to the national
security or cryptology may require classification. There may be cases when an NSF grantee originates information
during the course of an NSF-supported project that the grantee believes requires classification under E.O. 12958. In
such a case, the grantee has the responsibility to promptly 1. Submit the information directly to the government agency
with appropriate subject matter interest and classification authority or, if uncertain as to which agency should receive
the information, to the Director of the Information Security Oversight Office, GSA; 2. Protect the information as
though it were classified until the grantee is informed that the information does not require classification, but not longer
than 30 days after receipt by the agency with subject matter interest or by the GSA; and 3. Notify the appropriate NSF
program Officer.” The authority has to decide within 30 days whether to classify the information, and if it requires
classification, the “performing organization may wish or need to discontinue the project.” Dissemination of findings
may also be controlled.
13
The federal government exercises “prepublication review” of some privately published scientific and technical
information by current and former employees and contractors who worked for federal agencies and who had access to
classified information. The Defense Department (DOD) typically includes “prepublication review” clauses in
government contracts for extramural research. These controls are used if classified information was used in research or
when the government seeks to prohibit release of information deemed sensitive because of the way it is aggregated.
Beginning in 1980, all academic cryptography research is to be submitted on a voluntary basis for pre-publication
review to the National Security Agency. The U.S. government may enter into contracts to purchase exclusive rights to
commercial satellite imagery and may stop the collection and dissemination of commercial satellite imagery for
national security reasons. (For additional information, see CRS Report RL31845, op. cit. and CSIS, Security Controls
on Scientific Information, June 2005, op. cit., pp. 13-14.)
14
See CRS Report RL31845, op. cit.
15
Pursuant to 35 U.S.C. 181-188. See CRS Report RL31845 for additional information. According to OMBWatch’s
report, Secrecy Report Card 2005: Quantitative Indicators of Secrecy in the Federal Government, a report by Open the
Government.Org. Americans for Less Secrecy, More Democracy, Washington, D.C., 2005, the number of secrecy
orders imposed on new patents rose from 83 in 2001 to 124 in 2004, and the number of secrecy orders in effect
increased from 4,736 in 2001 to 4,885 in 2004 (p. 5) However, it is likely that most of these were recommended by,
and issued to, federal agencies for their own government-owned technical information.
Congressional Research Service
3
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
professional societies and publishers. For instance, in the early 1940s basic physics research in
fission was voluntarily withheld from publication by a leading journal, Physical Review, because
of fears that publication of research results would benefit German atomic energy research. After
the war ended the results were published. However, reportedly, foreign scientists, especially
Soviet scientists, deduced that the absence of research publications on the topic meant that
Americans “were pursuing an atomic bomb” and started their own inquiries on this subject.16
More recently, some researchers have initiated voluntary controls on the conduct and/or
publication of sensitive research in biological sciences fields that might assist terrorists. (For
additional details, see the section below entitled “Controls on Unclassified Biological Research
Information.”) In addition, the directors of the Department of Homeland Security’s (DHS) six
academic centers of excellence have developed draft guidelines “to control the dissemination of
sensitive information generated by their research”17—which is in the fields of agricultural,
chemical, biological, nuclear and radiological, cyber terrorism, and the behavioral aspects of
terrorism.
There are also formal government-mandated controls. For instance, pursuant to sections 3235 and
3295(c) of the National Defense Authorization Act for FY2000,18 the Department of Energy
(DOE) released regulations, effective August 18, 2006, that require all users of DOE computers,
including persons who e-mail a DOE computer, to give the department written permission for
investigators to check any DOE computer accessed by that person for up to three years in the
future. The regulation applies to all information, including classified and sensitive but
unclassified, and other types.19 Reportedly, the required paperwork might prove to be costly to
some researchers.20
The federal government also mandates controls on contract research. For instance, the issue of
federal agency research contracts with universities imposing prepublication review clauses was
addressed in an April 2004 report, Restrictions on Research Awards: Troublesome Clauses,
released by the Association of American Universities, in cooperation with the Council on
Government Relations. It detailed 138 instances of restrictions placed on publications or other
prohibitions on foreign nationals as preconditions for receiving research awards. The report
opposed the practice, recommended that federal agencies adhere to the mandates of NSDD-189,
and concluded that governmental restrictions were not compatible with university research.
Export and Visa Controls
Export control regulations generally do not apply to the conduct of fundamental research as long
as it is ordinarily published and shared broadly within the scientific community. However, export
control regulations and International Traffic in Arms Control regulations (ITAR) permit the
government to require licensing for the export, or “deemed export,” of certain scientific and
technical information to specific foreign countries or citizens of those countries working in the
16
Chelsa Wald, “Landmarks: The Physical Review’s Explosive Secret,”Oct. 26, 2004.
17
Yudhijit Bhattacharjee, “Scientific Openness; Should Academics Self-Censor Their Findings on Terrorism?,”
Science, May 19, 2006, 993-994.
18
50 U.S.C. 2425, 2483(c).
19
“Computer Security; Access to Information on Department of Energy Computers and Computer Systems,” Final
Rule, Federal Register, July 19, 2006, pp. 40880-40866.
20
Yudhijit Bhattacharjee, “DOE Tightens Monitoring of Lab Collaborators,” Science, Sept. 1, 2006, p. 1218.
Congressional Research Service
4
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
United States21 on university campuses or in industrial laboratories. During 2004 and 2005,
considerable controversy arose22 over the publication of two Inspector General reports,23 one
from the Department of Defense (DOD) and the other from the Department of Commerce (DOC).
They proposed strict adherence to government interpretations that, even if the research being
conducted is fundamental, the operation, technical training, installation, maintenance, repair,
overhaul, or refurbishing of commercially available equipment used in the research is a “deemed
export” that requires an export license for certain foreign researchers. This would be for
equipment as common as fermenters and global positioning system (GPS) locators and would
apply to students from China, Russia, India, and other countries on lists of countries that pose
national security threats. In a notice of a proposed rule published in the Federal Register on
March 28, 2005,24 the DOC recommended that country of birth rather than of citizenship or
permanent residence be used as the criterion for determining nationality for deemed export
controls. DOD’s proposed rules, which would require badging, training, and segregated work
areas for eligible researchers and exclusion of others, were published in July 2005, when the
comment period began.25
21
Both the Export Administration Act (50 U.S.C. App. 2401-2420) (6) and the Arms Export Control Act (22 U.S.C.
2751-2794) provide authority to control the dissemination to foreign nationals, both in the United States and abroad, of
scientific and technical data related to items requiring export licenses according to the Export Administration
Regulations (EAR) or the International Traffic in Arms Regulations (ITAR). Both laws give agencies authority to
regulate the export of technical data. ITAR controls the release of defense articles specified on the U.S. Munitions List
(22 CFR 121) and technical data directly related to them. EAR, among other things, controls the export of dual-use
items (items that have both civilian and military uses) on the Department of Commerce Control List (15 CFR Part 774)
and technical data related to them. The implementing regulations are administered by the Department of Commerce,
which licenses items subject to EAR, and by the Department of State, which licenses items subject to ITAR and the
Munitions List of items. Fundamental research, but not all activities related to the conduct of such research, is excluded
from ITAR and EAR. ITAR generally treats the disclosure or transfer of technical data to a foreign national, whether in
the United States or abroad, as an export. According to ITAR regulations, publicly available scientific and technical
information and academic exchanges and information presented at scientific meetings are not treated as controlled
technical data. Nevertheless, there has been considerable ambiguity and confusion regarding these provisions because
of uncertainties about which research projects might not be excluded because they use space or defense articles,
technologies, and defense services on the Munitions List that is used to identify technologies requiring export licensing.
The Export Administration regulations categorize as “deemed exports” communications both to foreign nationals about
technologies characterized as “sensitive” and to countries identified as “sensitive” under EAR rules. Under language in
a rule issued in March 2002, the State Department exempted U.S. universities from obtaining ITAR licenses for export
of certain space-based fundamental research information or articles in the public domain to certain universities and
research centers in countries that are members of the North Atlantic Treaty Organization (NATO), the European Union,
and the European Space Agency, or to major non-NATO allies, such as Japan and Israel. Also to be permitted are
exports of certain services and unclassified technical data for assembly of products into scientific, research, or
experimental satellites. In addition, collaborators in approved countries would have to guarantee that researchers from
non-approved countries were not receiving restricted information. (For sources and additional information, see CRS
Report RL31845, op. cit.) GAO critiqued the procedures DOC and DOD use to identify and implement export control
decisions in: two recent reports, DOD’s Critical Technologies Lists Rarely Inform Export Controls and Other Policy
Decisions, July 2006, GAO-06-793 and Improvements to Commerce’s Dual-Use System Needed to Ensure Protection
of U.S. Interests in the Post-9/11 Environment, June 2006, GAO-06-638.
22
“Controls on ‘Deemed Export’ May Threaten Research,” Secrecy News, May 2, 2005.
23
U.S. Department of Commerce, Office of Inspector General, Bureau of Industry and Security, Deemed Export
Controls May Not Stop the Transfer of Sensitive Technology to Foreign Nationals in the U.S., Final Inspection Report
No. OPE-16176, March 2004, 54 p. Interagency Review of Foreign Nationals Access to Export-Controlled Technology
in the United States, Vol. 1, April 2004, Report D-20004-062, 33 p.
24
“Revision and Clarification of Deemed Export Related Regulatory Requirements,”Advanced Notice of Proposed
Rulemaking, Federal Register, Mar. 28, 2005, vol. 70, no. 58, pp. 15607-15609.
25
“Defense Federal Acquisition Regulation Supplement: Export-Controlled Information and Technology, Proposed
Rule With Request for Comments, Federal Register, July 12, 2005, vol. 70, no. 132, p. 39977.
Congressional Research Service
5
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
Subsequently, some university officials argued that expanded interpretations of rules for “deemed
export” licenses may be unnecessary.26 Other members of the academic community cite problems
in administering use controls, including ambiguity about identifying which equipment or material
in university laboratories is subject to export controls; discrimination on the basis of nationality;
difficulty in controlling access of students and researchers in university laboratories; time
required to obtain licenses and inflexibility in obtaining licenses;27 modest security benefits;
slowing or preventing important discoveries due to licensing delays; loss of research talent if
students and researchers study in other countries; and reduction in research at the leading edge of
science.
The three presidents of the National Academies [of Science, Engineering, and the Institute of
Medicine] opposed such controls in a letter to DOC Secretary Carlos M. Guitierrez, June 16,
2005, and made several recommendations, including the proposal to “[c]lear international
students and postdoctoral fellows for access to controlled equipment when their visas are issued
or shortly thereafter so that their admission to a university academic program is coupled with
their access to use of export controlled equipment.” One policy group recommended an
alternative approach: to require a deemed export license for “transfers of technology to
specifically identified individuals if specific adverse information exists about that individual.”28
In a 2005 report prepared at congressional request, a National Academies panel recommended
providing all foreign students and researchers engaged in fundamental research with access
comparable to that provided to U.S. citizens and permanent residents and to remove “... all
technology items (information and equipment) from the deemed-export technology lists that are
available for purchase on the overseas open market from foreign or US companies or that have
manuals that are available in the public domain, in libraries, over the Internet, or from
manufacturers.”29 The National Foreign Trade Council and other related technology groups also
have opposed these rules.30 Others charge universities would have to pay “... millions of dollars to
inventory sensitive equipment, determine students’ birthplaces and study which foreigners were
using which machines.”31
In January 2006, a DOC spokesman said that because of comments received on the proposed rule,
DOC would modify its procedure and base controls not on country of birth, but on a foreign
national’s most recent country of citizenship or permanent residency. 32 DOC also established a
26
Security Controls on Scientific Information, June 2005, op. cit., p. 7.
27
For instance, see rationale detailed in CSIS, Security Controls on Scientific Information, June 2005, op. cit. pp. 9-12,
and American Civil Liberties Union, Science Under Siege: The Bush Administration’s Assault on Academic Freedom
and Scientific Inquiry, Written by Tania Simoncelli with Jay Stanley, June 2005, 35 p., which also summarizes reports
and the views of the academic community, pp. 9-13.
28
CSIS, Security Controls on Scientific Information, June 2005, op. cit , p. 12.
29
The National Academies, Rising Above the Gathering Storm: Energizing and Employing America for a Brighter
Economic Future, Executive Summary, 2005, p. 6. See also reports of NAS workshops in May and Sept. 2005, Eugene
Russo, “DoD Export Controls Rule Should Not Apply to Fundamental Research, Officials Say,” Research Policy Alert,
Sept. 23, 2005; “National Academies, Societies Criticize on DoD’s Proposed Export Control Rule,” Research Policy
Alert, Oct. 18, 2005.
30
Danielle Belopotosky, “Techies Challenge Planned Changes On ‘Deemed Exports,’” Technology Daily, June 24,
2005.
31
Scott Shane. “Universities Say New Rules Could Hurt U.S. Research,” New York Times, Nov. 26, 2005.
32
Statement of Peter Lichtenbaum, Assistant Secretary of Commerce for Export Administration at a conference at the
National Academies at which the author of this report was present. See also Kelly Field, “Commerce Department Will
Drop Some But Not All Restrictions on Foreign Researchers, Colleges Are Told,” Chronicle of Higher Education, Jan.
17, 2006. The official announcement is “Revisions and Clarification of Deemed Export Related Regulatory
(continued...)
Congressional Research Service
6
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
committee to examine its rules further. 33 Responding to complaints received during the comment
period, DOD modified its proposed rules with a new proposal published on August 14, 200634
that said it would withdraw the prescriptive identification requirements proposed in July, but
would continue to require researchers to adhere to existing export control rules of the Commerce
and State Departments. Final comments were due by October 13, 2006.
As for other controls to deter terrorism, more governmental scrutiny has been used to review and
issue visas for foreign researchers and students, and more items have been placed on the
Technology Alert List (TAL), which is now classified. The State Department uses the TAL to
identify academic and technical subjects that are viewed as sensitive; foreign students proposing
to study these subject undergo extra visa scrutiny under the Visas Mantis program.35 The State
Department also has tightened entry/exit registration of foreign students and scholars and tracks
their activities in an effort to deter terrorism. These actions may have prohibited the entry of
potential terrorists, but some critics allege that they have reduced the number of foreign students
studying science and technology in the United States36 and increased the number of foreign
students studying in other countries.37 This, they say, portends not only erosion of the U.S. market
share of worldwide Higher education, but also a reduction in the number of new U.S. scientific
and technical personnel.38
In 2004, the federal government proposed rules declaring that American scientists could not
collaborate with, and American publishers could not edit works authored by, scientists in nations
that are targets of trade embargoes, including Iran, Sudan, Libya, Cuba, and North Korea. Most
scientific societies opposed these proposals39 on the grounds that they reduced the intellectual
freedom of those in other countries and hampered international science. Subsequently, the
administering agency, the U.S. Treasury Department’s Office of Foreign Assets Control (OFAC),
decided to permit editing and peer review, but continued to prohibit collaboration between U.S.
scholars and researchers in a sanctioned country. 40
(...continued)
Requirements,” Federal Register, May 31, 2006, vol. 71, no. 104, pp. 30840-30844.
33
Jeffrey Brainard, “Defense Department Shelves Proposal to Increase Restrictions on Foreign Students,” Chronicle of
Higher Education, Aug. 15, 2006.
34
“Defense Federal Acquisition Regulation Supplement; Export-Controlled Information and Technology (DFARS
Case 2004—D010),” Federal Register, vol. 71, No. 156, Aug. 14, 2006, pp. 46434-46441.
35
Science Under Siege, op. cit., pp. 14-15.
36
Molly Laas, “Senate Science Committee to Consider Easing Immigration For Foreign Students,” Research Policy
Alert, Nov. 21, 2005; Marjorie J. Censer, “Visa Problems May Damage U.S. Science, Groups Warn,” American
Association of University Professors, Sept./Oct. 2004. See also: U.S. GAO, Border Security: Streamlined Visas Mantis
Program Has Lowered Burden on Foreign Science Students and Scholars, but Further Refinements Needed, GAO-05198, Feb. 2005.
37
Science Under Siege, op. cit., pp. 16-20 and Alison Abbott, “Europe Revamps Visa Rules to Attract World’s Best
Minds,” Nature, Oct. 27, 2005. See also American Association of University Professors, Report by Special Committee
on Academic Freedom and National Security in a Time of Crisis, Nov./Dec. 2003.
38
See, for example, “Difficulties for Foreign Scientists in Coming to the United States,” Science, July 14, 2006, p. 169.
39
One that did not is the American Institute of Aeronautics and Astronautics. See Yudhijit Bhattacharjee, “Society Bars
Papers From Iranian Authors,” Science, June 17, 2005.
40
Science Under Siege, op. cit., pp. 10-11, and Yudhijit Bhattacharjee, “Scientific Publishing: Editing No Longer
Infringes U.S. Trade Sanctions,” Science, Dec. 24, 2004.
Congressional Research Service
7
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
Policies To Control SBU Information
The history through 2002 of using the label SBU was described in detail in CRS Report
RL31845, “Sensitive But Unclassified” and Other Federal Security Controls on Scientific and
Technical Information: Background on the Controversy and is summarized briefly in this section,
which also updates action through February 15, 2006.
Introduction to the Term “SBU”
Federal agencies began to use the term “SBU” in the 1970s,41 but the term has never been defined
in statutory law. Starting in 1987 and continuing today, when using the term “sensitive
information,” some agencies refer to the definition for sensitive information that was used in the
Computer Security Act of 1987, P.L. 100-235,42 and to information exempt from disclosure in the
Freedom of Information Act (FOIA)43 and the Privacy Act, as amended.44
Computer Security Act Definition of “Sensitive”
The Computer Security Act of 1987 (CSA) was intended to protect the security and privacy of
sensitive unclassified information in federal computer systems and the systems themselves. P.L.
100-235 defined the term “sensitive” information as
any information, the loss, misuse, or unauthorized access to or modification of which could
adversely affect the national interest or the conduct of Federal programs, or the privacy to
which individuals are entitled under section 552a of title 5, United States Code (the Privacy
Act), but which has not been specifically authorized under criteria established by an
Executive order or an Act of Congress to be kept secret in the interest of national defense or
foreign policy” (Section 3).
Because P.L. 100-235 applied to “sensitive information” that was not classified, some say it
defined “sensitive but unclassified.” Pursuant to the CSA, federal agencies were responsible for
protecting such “sensitive” information and for developing plans to secure it “commensurate with
the risk and magnitude of the harm resulting from the loss, misuse, or unauthorized access to or
modification of the information being protected.”45 The CSA, among other things, required
agencies to develop security plans for systems containing sensitive information. It authorized the
National Bureau of Standards (NBS), now called the National Institute of Standards and
Technology (NIST), to create a security-oriented standards program. The definition of “sensitive
information” was placed within the section that listed NBS’s functions, and subsequently NIST
became responsible when the agency’s name was changed in 1988. In 1992, NIST issued
guidance giving agencies authority to implement risk-based procedures to protect sensitive
41
Interview with CRS specialist Harold Relyea, December 2005.
101 Stat. 1724-1730, 40 U.S.C 1441.
43
5 U.S.C. 552, as amended by P.L. 104-231, 110 Stat. 3048.
44
The Privacy Act of 1974, 5 U.S.C. Section 552a , as amended.
45
U.S. Congress, House, Committee on Science and Technology, Computer Security Act of 1987, Report to
Accompany H.R. 145, June 11, 1987, pp. 30-31.
42
Congressional Research Service
8
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
information pursuant to P.L. 100-235. NIST reiterated that “[i]nterpretation of the CSA’s
definition of sensitive is, ultimately, an agency responsibility.” It identified three security goals:
Typically, protecting sensitive information means providing for one or more of the
following: Confidentiality: disclosure of the information must be restricted to designated
parties; Integrity: The information must be protected from errors or unauthorized
modification; Availability: The information must be available within some given time frame
(i.e., protected against destruction).”46[Emphasis added.]
Although it was not mandatory, NIST urged agency information owners to use a risk-based
approach to identify information to be protected and controls needed based on risk of loss:
The type and amount of protection needed depends on the nature of the information and the
environment in which it is processed. The controls to be used will depend on the risk and
magnitude of the harm resulting from the loss, misuse, or unauthorized access to or
modification of the information contained in the system.47
SBU in Relation to the Freedom of Information Act
Predating the CSA, the Freedom of Information Act of 1966 (FOIA) was enacted to ensure public
access to certain types of information held by federal agencies. However, it permits agencies to
exempt from public disclosure nine types of information:
(1) information classified in the interest of national defense or foreign policy,
(2) internal personnel rules and practices of an agency,
(3) information specifically exempted from disclosure by statute,
(4) trade secrets and commercial or financial information obtained from a person and
privileged or confidential,
(5) inter-agency or intra-agency memoranda or letters reflecting predecisional attitudes,
(6) personnel and medical files and similar files the disclosure of which would constitute a
clearly unwarranted invasion of personal privacy,
(7) specified types of law enforcement records or information,
(8) financial institution regulation or supervision reports, and
(9) geological and geophysical information and data concerning wells.48
The CSA,49 the report accompanying it, 50 and NIST guidance51 included explicit instructions that
categorizing information as “sensitive” did not confer authority to withhold information sought
46
National Institute of Standards and Technology, “Advising Users on Computer System Technology,” CSL Bulletin,
Nov. 1992 http://nsi.org/Library/Compsec/sensitiv.txt.
47
“Advising Users on Computer System Technology,” Nov. 1992, op. cit.
48
5 U.S.C. 552.
49
According to P.L. 100-235, “Sec. 8. ... Nothing in this Act, or in any amendment made by this Act, shall be construed
(continued...)
Congressional Research Service
9
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
pursuant to Section 552 of Title 5, United States Code [the Freedom of Information Act].
Nevertheless, as will be discussed below, some federal agencies say that all information
categorized as For Official Use Only (FOUO) or in related categories is SBU, or that all SBU
information may be withheld under FOIA.
Department of Justice Broadens Interpretation of Exemptions From FOIA in
2003 and 200452
After the terrorist attacks of September 2001, the White House and the Department of Justice, in a
series of administrative actions, expanded agencies’ ability to withhold SBU information. To
prevent potential use of sensitive information by terrorists, in March 2002, the White House
issued the so-called “Card memo,” which required agencies to examine their information
holdings and policies; withhold information, including “sensitive but unclassified” information;
and use FOIA exemptions if there was a sound legal basis to do so. Attorney General John
Ashcroft’s prior memorandum of October 2001 on this issue was referenced. These statements
modified the previous Administration’s policy, which urged agencies to release information if
there was no “foreseeable harm” in doing so. 53
(...continued)
(1) to constitute authority to withhold information sought pursuant to Section 552 of title 5, United States Code; or (2)
to authorize any Federal agency to limit, restrict, regulate, or control the collection, maintenance, disclosure, use,
transfer, or sale of any information (regardless of the medium in which the information may be maintained) that is (A)
privately-owned information; (B) disclosable under section 552 of title 5, United States Code, or other law requiring or
authorizing the public disclosure of information; or (C) public domain information.”
50
The report accompanying the legislation said specifically, “The designation of information as sensitive [or as subject
to protection] under the Computer Security Act is not a determination that the information is not subject to public
disclosure” (H.Rept. 100-153, Part I, June 11, 1987).
51
The guidance said, “The Computer Security Act did not alter the Freedom of Information Act (FOIA); therefore, an
agency’s determination of sensitivity under this definition does not change the status of releaseability under the FOIA”
(“Advising Users on Computer System Technology,” op. cit.)
52
For detailed information, see CRS Report RL31845, op. cit.
53
The White House memo, signed by Chief of Staff Andrew Card, entitled “Action to Safeguard Information
Regarding Weapons of Mass Destruction and other Sensitive Documents Related to Homeland Security,” Mar. 19,
2002, required agencies to examine their policies and holdings in accord with accompanying memos issued by the
National Archives and Records Administration’s (NARA) Information Security Oversight Office (ISOO) and the
Department of Justice’s Office of Information and Privacy (OIP). The purpose was to determine if information should
be classified or handled as sensitive but unclassified information that could be “misused to harm the security of our
Nation and the safety of our people” and report their review to the White House. The accompanying memo included a
section titled “sensitive but unclassified information,” which instructed agencies to consider all applicable FOIA
exemptions before releasing “sensitive information related to America’s homeland security”(SHSI) (“Safeguarding
Information Regarding Weapons of Mass Destruction and Other Sensitive Records Related to Homeland Security,”
Memorandum for Departments and Agencies, from Laura L.S. Kimberly, ISOO, NARA, and Richard L. Huff, and
Daniel J. Metcalfe, OIP, Dept. of Justice, “Safeguarding Information Regarding Weapons of Mass Destruction and
Other Sensitive Records Related to Homeland Security,” Mar. 19, 2002). Agencies were referred to guidance that had
been issued by Attorney General Ashcroft in Oct. 2001 that instructed agencies, when undertaking discretionary
disclosure determinations under FOIA (agencies can make their own discretionary decisions about whether to disclose
information even if it falls within one of the nine FOIA exemption categories) to consider using broad interpretations of
the FOIA exemptions because of the need for heightened security in the wake of the 9/11 attacks (“New Attorney
General FOIA Memorandum Issued,” FOIA Post, Oct. 15, 2001, including “Memorandum for Heads of all Federal
Departments and Agencies, From: John Ashcroft, Attorney General, Subject: The Freedom of Information Act, Oct. 15,
2001”). The memo instructed agencies to interpret FOIA exemption two broadly to permit withholding of a document
that if released would allow circumvention of an agency rule, policy or statute, thereby impeding the agency in the
conduct of its mission. (See U.S. Department of Justice, Freedom of Information Act Guide and Privacy Act Overview,
(continued...)
Congressional Research Service
10
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
Subsequently in 2003, the Department of Justice (DOJ) issued guidance based on court decisions
that broadened interpretation of exemptions from disclosure under FOIA.54 It also discussed the
new exemption three provision of P.L. 107-296, the Homeland Security Act of 2002, which
protects voluntarily submitted critical infrastructure information. The Freedom of Information Act
Guide, 2004, explained how an agency’s ability to restrict the release of “sensitive” information
via FOIA would be broadened; and, citing the September 11, 2001, attacks, the passage of P.L.
107-296, and the creation of the Department of Homeland Security (DHS), cautioned vigilance
on releasing “sensitive” information:
These changes have greatly impacted many aspects of the operation of the federal
government, including the administration of the FOIA. Much greater emphasis is now placed
on the protection of information that could expose the nation’s critical infrastructure,
military, government, and citizenry to an increased risk of attack. As a result of these
changes, federal departments and agencies should carefully consider the sensitivity of any
information the disclosure of which could reasonably be expected to cause national security
harm.55
The Guide reiterated, however, that use of labels such as SBU, SHSI, and so forth does not
“provide for any protection from disclosure under any [FOIA] exemption ...” [except for critical
infrastructure information (CII), which is protected by statute]. Nevertheless, the Guide
encouraged agencies to exempt from disclosure information labeled “SHSI” or other
nonclassified information that is highly sensitive, as referenced in the aforementioned court
decisions and in Homeland Security Presidential Directive HSPD-7, issued on December 22,
2003:
[W]hatever the safeguarding label that an agency might (or might not) use for the
information maintained by it that has special sensitivity—e.g., “for official use only”
(FOUO), “restricted data” (a Department of Energy designation), or “sensitive homeland
security information” (SHSI)—whenever predominantly internal agency records may reveal
(...continued)
May 2002, ed., pp. 16-17, 124-127 and CRS Report RL31547, Critical Infrastructure Information Disclosure and
Homeland Security, by (name redacted) and (name redacted).) In the predecessor memorandum issued by Attorney General
Janet Reno in 1993, agencies were encouraged to release documents, even if the law provided a way to withhold
information, if there was no “foreseeable harm” from doing do.
In 2002 and 2003, the House oversight committee on FOIA, the Committee on Government Reform, called the
Attorney General’s October 2001 memorandum into question and specifically rejected its standard to allow the
withholding of information sought under FOIA whenever there is merely a “sound legal basis” for doing so. The
committee directed agencies to withhold documents only in those cases when the agency reasonably foresees that
disclosure would be harmful to an interest protected by an exemption (A Citizen’s Guide on Using the Freedom of
Information Act and the Privacy Act of 1974 to Request Government Records, 107th Cong., 2nd sess. H.Rept. 107-371,
2002, p. 3; and in a report with the same title, 108th Congress, 1st sess., 2003, H.Rept. 108-172).
54
On June 25, 2003 officials from the DOJ’s Office of Information and Privacy and from the National Security Council
held a closed conference that was summarized on the DOJ website. (U.S. Department of Justice,”FOIA Officers
Conference Held on Homeland Security,” FOIA Post, July 3, 2003 http://www.usdoj.gov/oip/foiapost/
2003foiapost25.htm). Among other things, it reviewed several court cases in 2003 that allowed agencies to use national
security considerations, other than those defined in FOIA exemption 1, to withhold information of possible use to
terrorists. These included one that allowed the U.S. Customs Service to use exemption 2 to deny information on
inspections of seaport operations (Coastal Delivery Corp. v. U.S. Customs Service, decided Mar.17, 2003, by the U.S.
District Court in Los Angeles), and another to allow withholding under exemption 7 (e) of “inundation maps”that had
been compiled as law enforcement records and showed flood area below Hoover and Glen Canyon dams (Living
Rivers, Inc., v. the U.S. Bureau of Reclamation, Mar. 25, 2003. by the U.S. District Court in Salt Lake City).
55
FOIA Guide, 2004 Edition, Exemption one, http://www.usdoj.gov/oip/foi-act.htm.
Congressional Research Service
11
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
information the disclosure of which could reasonably be expected to cause any of the harms
described above [to critical systems, facilities, stockpiles, and other assets], responsible
federal officials should carefully consider the propriety of protecting such information under
Exemption 2.56
SBU Information Policies in the Homeland Security Act, P.L. 107296, and Subsequent Presidential Action
The Homeland Security Act, P.L. 107-296, signed on November 25, 2002, defined homeland
security information as “any information possessed by a Federal, State or local agency that (A)
relates to the threat of terrorist activity; (B) relates to the ability to prevent, interdict, or disrupt
terrorist activity; (C) would improve the identification or investigation of a suspected terrorist or
terrorist organization; or (D) would improve the response to a terrorist act.”57 The law, among
other things, required agencies to develop information-sharing systems to transmit classified or
unclassified information and to share it with appropriate recipients, including those at the state
and local levels. It also recognized the use of nondisclosure agreements for sharing sensitive but
unclassified information with state and local personnel. Section 892, as amended, 58 required the
President to “prescribe and implement procedures” for federal agencies to “identify and safeguard
sensitive homeland security information that is sensitive but unclassified,” [now abbreviated
SHSI] and to prescribe procedures to share this information with other federal agencies and
appropriate state and local personnel (required by section 892 (a) (1) (A)(B) of P.L. 107-296). In
Executive Order 13311, July 29, 2003, the President transferred some of these functions to the
Department of Homeland Security Secretary, to be carried out in consultation with other
governmental officials.59 The President is still mandated to prescribe procedures for federal
agencies. Section 893 of the law had required the President to report to specified congressional
committees about implementation of section 892 and any recommendations for additional
measures to “increase the effectiveness of sharing of information between and among Federal,
State, and local entities.” According to that report60 and other documents, 61 in 2004, DHS was
preparing the guidance to identify and protect sensitive but unclassified SHSI. In its report to
Congress, DHS wrote that the procedures it was developing
will provide guidance on identifying SHSI by defining SHSI, establishing uniform
procedures for identifying and marking SHSI, and delineating entities with which it may be
properly shared. The procedures will aid in safeguarding SHSI by establishing uniform
minimum standards for the secure handling of sensitive information designated as SHSI, in a
manner consistent with existing law. Lastly, the procedures will help to facilitate the sharing
of SHSI with appropriate Federal, state and local users, while also protecting it from
56
FOIA Guide, 2004 Edition, Exemption Two.
6 U.S.C. 482 (f).
58
Amended by Section 316 of the Intelligence Authorization Act for Fiscal Year 2004, P.L. 108-177, Section 316, 117
Stat. 2599, 2610-11 (2003). This section mandates that DHS develop a training program for state and local officials to,
among other things, improve their ability to identify and report threat information.
59
Executive Order 13311, Federal Register, July 29, 2003, pp. 45149-45150. The President retained responsibility to
“ensure that such procedures apply to all agencies of the Federal Government....”
60
Report Pursuant to Section 893, not dated but reportedly sent to the committee chairmen in February 2004, op. cit.
61
U.S. Department of Justice,” FOIA Officers Conference Held on Homeland Security,” FOIA Post, July 3, 2003,
http://www.usdoj.gov/oip/foiapost/2003foiapost25.htm.
57
Congressional Research Service
12
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
unwarranted public disclosure that could result in reduction of the ability of Federal, State,
and local authorities to protect against threats to our homeland security. 62
The referenced guidance had not been issued as of November 14, 2006, and, before being made
final, was to have been sent to the Office of Management and Budget for release and a period of
public comment.63 In a related development, on December 16, 2005, the President issued a
memorandum to federal agencies, “Guidelines and Requirements in Support of the Information
Sharing Environment,” that included requiring agencies to standardize procedures “for
designating, marking, and handling SBU information ... across the Federal Government” in order
to promote both appropriate, consistent safeguarding and sharing of information.64 Within 90 days
agencies were to inventory specific SBU information procedures, determine the authority for each
entry, assess the effectiveness of procedures, and report to the Director of National Intelligence
(DNI), who is to provide the results to the Secretary of Homeland Security and the Attorney
General. Within a year, the DNI in coordination with specific department and agency heads is to
submit recommendations to the President through the DNI for government-wide standards for all
SBU information. The Program Manager for the Information Sharing Environment is to support
executive departments and agencies implementation, as well as in the development of relevant
guidance and training programs for the standardized SBU procedures.
According to a news report, an interagency group has been working on this issue. But federal
agencies have not yet agreed upon which SBU-related labels to use and which to give up.
Furthermore state and local officials apparently have disagreed about which labels should be
retained. Reportedly, in June 2006, the Department of Justice and the Department of Homeland
Security
... delivered a 36-page report recommending that the group continue its efforts to settle on a
new system. (In a small sign of progress, they also urged agencies to stop creating new
labels, according to one intelligence official.) The White House concluded that the proposal
lacked substance and told the two agencies to try again, the official said.65
Similarly,
According to Aftergood, the report [which was then pending] “... set forth principles upon
which SBU policy should be based, but stops short of the crucial task of defining exactly
how those principles ought to be implemented, government officials said. One of those
principles is that each type of control on unclassified information should have a uniform,
public and government-wide definition so that it is employed the same way by all
agencies.”66
Testimony on this issue was heard at a hearing held on May 10, 2006. (See below in the section
labeled “Studies and Hearings on SBU During 2006.”)
62
Report Pursuant to Section 893, 2004, op. cit., p. 5.
Interview with OMB officials, Nov. 10, 2004.
64
Information Sharing Guideline 3 http://www.fas.org/sgp/news/2005/12/wh121605-memo.html.
63
65
Siobhan Goirman, “Turf War Hampers War on Terror: Justice, Homeland Security’s Failure to Agree on semantics
Hinders Information Sharing,” Baltimore Sun, July 13, 2006.
66
“Agencies Pursue Standardized Policy for ‘Sensitive’ Info,” Secrecy News, July 12, 2006.
Congressional Research Service
13
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
In November 2006, the Program Manager for the Information Sharing Environment issued a
report entitled, Information Sharing Environment Implementation Plan. Chapter 10 described
creation of an interagency coordinating committee which plans to issue guidelines and
recommendations for SBU standardization during the lst quarter of CY2007.
Requirements to Use Mandatory Minimum NISTGenerated Risk Standards To Protect All
Information
As noted above, the Computer Security Act of 1987 (CSA) authorized the Department of
Commerce’s NBS (and then its successor, NIST) to develop standards and guidelines for federal
agencies to protect sensitive information on federal computer information systems. The act
defined sensitive information that was not classified. (For a definition, see the section above
entitled “Computer Security Act Definition of “Sensitive””.) Under the CSA, agencies could
obtain a waiver not to use the standards.
The CSA provisions were modified with passage of the Federal Information Security Act of 2002,
(FISMA), P.L. 107-347, December 2002.67 While CSA required the development of standards to
protect sensitive information, FISMA required the development of standards to protect all
information, and did not refer to sensitive information when mandating development of standards.
It rewrote the section of the NIST act that required development of standards for sensitive
information, and had used the CSA definition of “sensitive” information (15 U.S.C. 278g-3). The
law replaced aspects of the CSA, including the definition of “sensitive” information because the
definition was considered static and unresponsive to changing information systems
environments.68 FISMA also deleted specific requirements to inventory information systems that
contained sensitive information.69 These actions, in essence, rendered the definition moot. Also,
under FISMA, agencies may no longer obtain a waiver to not use the standards developed by
NIST.
67
FISMA clarified and changed some provisions of the Government Information Security Reform Act (GISRA), which
was part of the Floyd D. Spence National Defense Authorization Act of FY2001 (Div. A, Title X, Subtitle G, sec.
1061-1065, P.L. 106-398, Oct. 30, 2000). While GISRA expanded NIST’s functions regarding developing risk-based
standards, it would have sunseted in 2002 and did not, like FISMA, render moot the definition of sensitive as used in
CSA. See U.S. Congress, House, Committee on Government Reform, E-Government Act of 2002. H.Rept. 107-787,
Part 1, 107th Congress, 2nd sess., Nov. 14, 2002, pp. 54-61. Specifically, according to the report, “the purpose of
FISMA is to permanently authorize a government-wide risk-based approach to information security by eliminating
GISRA’s two-year sunset, and to further strengthen Federal information security by requiring compliance with
minimum mandatory management controls for securing information and information systems, clarifying and
strengthening current management and reporting requirements, and strengthening the role of National Institute of
Standards and Technology (NIST)” (p. 54).
68
This was described in the House Committee on Government Reform report on the amended version of the bill that
was enacted, H.Rept. 107-787, part I, op. cit., describing section 303 of what eventually became P.L. 107-347.
69
Section 305 of P.L. 107-347 repealed section 6 of the CSA, which required the identification of systems containing
sensitive information and the development of systems security plans, which, according to the legislative report
accompanying the bill that was enacted, “is unnecessary given the overall scheme and specific requirements for agency
risk-based management of information and information systems supporting agency operations and assets” (H.Rept.
107-787, pt. 1. p. 87. See also CRS Report RL31057, A Primer on E-Government: Sectors, Stages, Opportunities, and
Challenges of Online Governance, by (name redacted)).
Congressional Research Service
14
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
Specifically, section 303 of P.L. 107-347 updated NIST’s mission in light of new understandings
relating to information security and required NIST, in consultation with other agencies, including
OMB, the National Security Agency, the Government Accountability Office (GAO), and the
DHS, to develop risk-based standards to categorize “the criticality and sensitivity of agency
information according to information security control objectives and across a range of risk levels”
and to develop minimum information security requirements for each information category. Under
FISMA, the standards NIST was directed to develop and the Secretary of Commerce to
promulgate, are to be issued by the Director of OMB in consultation with the Secretary of
Homeland Security70 as mandatory minimum federal information processing standards (FIPS)
that agencies and their contractors must use to protect all nonclassified information and
information systems based on a range of risk levels. 71 FISMA is silent on defining “sensitive” or
the relationship between the act and SBU or the sensitive homeland security information referred
to in section 892 of the Homeland Security Act of 2002, P.L. 107-296.
FISMA also clarified management and reporting, strengthened NIST’s role and responsibilities,
and consolidated statutory information security requirements. The OMB is required by FISMA to
authorize formally and accredit each agency’s nonsecurity information system as established by
the information security plan. (Responsibility for certification of national security information
systems is shared between DOD and the Central Intelligence Agency.) The three security
objectives—confidentiality, integrity, and availability—that NIST has used in previous guidance
are to continue to guide NIST in its development of standards (116 STAT. 2947, P.L. 107-347,
title III, paragraph 301), although these concepts were broadened from the way NIST originally
used them in 1992 to read:
The term “information security” means protecting information and information systems from
unauthorized access, use, disclosure, disruption, modification, or destruction in order to
provide—(A) integrity, which means guarding against improper information modification or
destruction and includes ensuring information nonrepudiation and authenticity; (B)
confidentiality, which means preserving authorized restrictions on access and disclosure,
including means for protecting personal privacy and proprietary information; and (C)
availability, which means ensuring timely and reliable access to and use of information (Sec.
301 of P.L. 107-347).
The law also allows agencies to develop more stringent standards than those generated by NIST,
since it—
70
OMB, in consultation with the Secretary of Homeland Security, has responsibility under FISMA to issue the
standards and guidelines developed by NIST (40 U.S.C. 11331 (b) (1) (A)) and promulgated by the Secretary of
Commerce. In addition, OMB manages the federal acquisition regulation (FAR). It is to be updated to include the
information security requirements of FISMA, so that new agency contracts for information systems would reflect them.
(U.S. GAO, Information Security: Improving Oversight of Access to Federal Systems and Data by Contractors Can
Reduce Risk, April 2005, GAO-05-362.p. 3.) See also, U.S. GAO, Information Security: Weaknesses Persist at Federal
Agencies Despite Progress Made in Implementing Related Statutory Requirements, July 2005, GAO-05-552.
71
Specifically, Title III of FISMA requires, “(b) Minimum requirements for standards and guidelines. The standards
and guidelines required by subsection (a) of this section shall include, at a minimum—(1) (A) standards to be used by
all agencies to categorize all information and information systems collected or maintained by or on behalf of each
agency based on the objectives of providing appropriate levels of information security according to a range of risk
levels; (B) guidelines recommending the types of information and information systems to be included in each such
category; and (C) minimum information security requirements for information and information systems in each such
category ....” (U.S. Code, Title 15, Chapter 7, Section 278g-3. Computer standards program, i.e., 15 U.S.C. 278g-3).
Congressional Research Service
15
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
preserves the provision in current law (at 40 U.S.C 11331(c) permitting agencies to use more
stringent standards than provided by NIST-developed standards, but only if those more
stringent standards incorporate applicable mandatory NIST requirements and are otherwise
consistent with the risk management policies and guidelines issued by OMB under 44 U.S.C.
3533.72
NIST’s Policies, Standards, and Documents
The risk analysis procedures and information systems controls specified by NIST have been
developed iteratively, incorporating public comments since the end of 2002. Several reports
constitute the NIST documentation standards and two are core, that is FIPS Publication 199 and
FIPS Publication 200. NIST had anticipated publishing all documentation by the statutory
deadline of December 2005 when implementation was to become mandatory,73 but the final
document in the series, dubbed FIPS Publication 200, was delayed a few months until March
2006.74 Agencies are to use NIST’s guidance documents and risk management procedures to
categorize federal information and information systems and to determine security protection
levels for them based on level of risk. 75
The first core document, Federal Information Processing Standards (FIPS) 199, Standards for
Security Categorization of Federal information and Information Systems, commonly called FIPS
199, issued in final form in February 2004, provides a common framework, method, and
mandatory standards for agencies to use to identify information to protect (that is not governed by
national security controls) according to the potential impact of loss. FIPS 199 enables “...
agencies to identify and prioritize their most important information and information systems by
defining the maximum impact a break in confidentiality, integrity, or availability would have on
the agency’s operation, assets, and/or individuals.”76 It establishes a continuum of “criticality and
sensitivity” for information dependent upon agency requirements and priorities. The potential
minimum impact value (low, moderate, or high77) on the compromise of a security objective is the
highest value (i.e., high-water mark) for security categories for each type of information on the
system. 78
72
Paragraph (a) (3) of section 302, according to H.Rept. 107-787, pt. 1, p. 84.
William Jackson, “FISMA Guidance Nearly Complete,” Government Computer News, Oct. 26, 2005.
74
National Institute of Standards and Technology, Minimum Security Requirements for Federal Information and
Information Systems, Federal Information Processing Standards Publication, FIPS Pub 200, March 2006.
75
Based in part on Ron Ross, “FISMA Implementation Project; Protecting the Nation’s Critical Information
Infrastructure; An Overview,” Slide Show, Version 1.4.
76
Shirley Radack, ITL Bulletin, Mar. 2004, p. 1.
77
“... [L]ow [or limited], moderate [having a serious adverse effect], or high [severe or catastrophic adverse] impact for
the three security objectives of confidentiality, integrity (including authenticity and non-repudiation), and
availability”(Ron S. Ross, Computer Security Division, NIST, “The New FISMA Standards and Guidelines. Changing
the Dynamic of Information Security for the Federal Government,” [2003], p. 2. For additional details, see NIST,
Standards for Security Categorization of Federal Information and Information Systems, FIPS Publication 199, Dec.
2003, pp. 1-3).
78
As an example “... A power plant contains a SCADA (supervisory control and data acquisition) system controlling
the distribution of electric power for a large military installation. The SCADA system contains both real-time sensor
data and routine administrative information. The management at the power plant determines that (I) for the sensor data
being acquired by the SCADA system, there is no potential impact from a loss of confidentiality, a high potential
impact from a loss of integrity, and a high potential impact from a loss of availability; and (ii) for the administrative
information being processed by the system, there is a low potential impact from a loss of confidentiality, a low
potential impact from a loss of integrity, and a low potential impact from a loss of availability. The resulting security
(continued...)
73
Congressional Research Service
16
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
FIPS Publication 200, Minimum Security Requirements for Federal Information and Information
Systems, the second of the mandatory security standards documents, specifies minimum security
requirements for information and information systems supporting the federal agencies and a riskbased process for selecting the security controls necessary to satisfy the minimum security
requirements. This standard is intended to establish minimum levels of due diligence for
information security and to facilitate a more consistent, comparable, and repeatable approach for
selecting and specifying security controls for information systems that meet minimum security
requirements.
NIST Special Publication 800-60, Guide for Mapping Types of Information and Information
Systems, issued in final version in June 2004,79 is intended to help agencies identify their
information types and systems and to assign impact levels for confidentiality, integrity, and
availability for them for a range of risk levels. The impact levels are based on the security
categorization guidelines in FIPS Publication 199.80 Special Publication 800-60 gives agencies
explicit guidance on developing impact standards for each of the three risk categories for all types
of information and information systems handled by federal agencies (based on OMB’s Federal
Enterprise Architecture Program Management Office’s publication, The Business Reference
Model Version 2.0). Agencies are given guidance to determine impact levels for information in
fields such as public health, environmental management, energy, and general sciences and
innovation, including research and development. Thus the high-water mark, or highest value
category for security impact (and thus minimum security categorization) for both “Scientific and
Technical Research and Innovation Information” and for “Research and Development
Information,” is moderate.81 Examples of minimum security categories for some other types of
information are environmental remediation information, moderate;82 pollution prevention and
control, low;83 and health care services, high. 84 Each explanation describes circumstances,
including homeland security and national security-related implications, that agencies could
identify to raise the threshold level of security controls for each type of information.
When agencies need to evaluate the levels of protection for information, they are to undertake a
risk assessment using threat and vulnerability analysis that incorporates local conditions and then
(...continued)
categories, SC, of these information types are expressed as: SC sensor data = {(confidentiality, NA),(integrity, HIGH),
(availability, HIGH)}, and SC administrative information = {(confidentiality, LOW), (integrity, LOW), (availability,
LOW)}. The resulting security category of the information system is initially expressed as: SC SCADA system =
{(confidentiality, LOW), (integrity, HIGH), (availability, HIGH)}, representing the high water mark or maximum
potential impact values for each security objective from the information types resident on the SCADA system. The
management at the power plant chooses to increase the potential impact from a loss of confidentiality from low to
moderate reflecting a more realistic view of the potential impact on the information system should there be a security
breach due to the unauthorized disclosure of system-level information or lineprocessing functions. The final security
category of the information system is expressed as: SC SCADA system = {(confidentiality, MODERATE), (integrity,
HIGH), (availability, HIGH)}.” (FIPS 199.)
79
William C. Barker, Volume 1: Guide for Mapping Types of Information and Information Systems to Security
Categories, NIST Special Publication 800-60, Version 2.0, June 2004, pp. 21-22. William C. Barker and Annabelle
Lee, NIST, Information Security, Volume II: Appendixes to Guide for Mapping Types of information and Information
Systems to Security Categories, June 2004, 295 pages.
80
Barker, Volume 1, NIST Special Publication 800-60, June 2004, op. cit., pp. 21-22.
81
NIST Special Publication 800-60, op. cit., pp. 217-218.
82
NIST Special Publication 800-60, op. cit., pp. 154-155.
83
NIST Special Publication 800-60, op. cit., p. 120.
84
NIST Special Publication 800-60, op. cit., p. 120.
Congressional Research Service
17
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
adjust their security controls using NIST publication SP 800-30.85 An agency is to identify the
minimum information security requirements (i.e., management, operational, and technical
controls) for information and information systems in each such category as identified in
document 800-53, that is Recommended Security Controls for Federal Information Systems,
February 2005. NIST identified 17 types of security control clusters to guide selection of
minimum security controls (i.e., safeguards and countermeasures) to protect information and
information systems and 154 uniquely identified controls (i.e., management, operational, and
technical security controls) for information and information systems in each category. These
include access control; awareness and training; audit and accountability; certification,
accreditation, and security assessments; configuration management; contingency planning;
identification and authentication; incident response; maintenance; media protection; physical and
environmental protection; planning; personnel security; risk assessment; systems and services
acquisition; system and communications protection; and system and information integrity.86
A Formal Risk Analysis Process Is Not Required
OMB’s apparent operative guidance for information security protection, Appendix III of OMB
Circular A-130,87 cautions agencies that they do not need to conduct expensive, formal risk
analyses to fulfill these requirements. Specifically, Appendix III to OMB Circular A-130 says that
OMB
no longer requires the preparation of formal risk analyses. In the past, substantial resources
have been expended doing complex analyses of specific risks to systems, with limited
tangible benefit in terms of improved security for the systems. Rather than continue to try to
precisely measure risk, security efforts are better served by generally assessing risks and
taking actions to manage them. While formal risk analyses need not be performed, the need
to determine adequate security will require that a risk-based approach be used. This risk
assessment approach should include a consideration of the major factors in risk management:
the value of the system or application, threats, vulnerabilities, and the effectiveness of
current or proposed safeguards. Additional guidance on effective risk assessment is available
in “An Introduction to Computer Security: The NIST Handbook” (March 16, 1995).88
While NIST recognizes this dictum, it seems that little information is available about how
agencies make decisions to categorize information in response to NIST standards.89
85
Risk Management Guide for Information Technology Systems, Recommendations of the National Institute of
Standards and Technology, by Gary Stoneburner, Alice Goguen, and Alexis Feringa, NIST, SP 800-30, July 2002.
86
NIST, Recommended Security Controls for Federal Information Systems, Special Publication 800-53, Appendix D
and Appendix F.
87
OMB Circular A-130, Appendix III, “Security of Federal Automated Information Resources,” to “OMB Circular A130, Transmittal Memorandum #4, Management of Federal Information Resources (11/28/2000),” requires agencies
and their contractors to maintain programs that provide adequate security for all information collected, processed,
transmitted, stored, or disseminated in general support systems and major applications” (http://www.whitehouse.gov/
OMB/circulars/a130/a130appendix_iii.html).
88
Appendix III, to OMB Circular A-130, 11/28/2000, op.cit.
89
Interviews with officials at NIST and GAO.
Congressional Research Service
18
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
Nongovernmental Experts’ Recommendations to Use Risk Analysis
to Identify and Control Sensitive Information
Nongovernmental experts have recommended using various types of risk-based processes to
identify, categorize, and develop controls for sensitive information involving science and
technology, and other kinds of information control.90 For instance, the use of risk analysis figured
prominently at the November 21, 2005 meeting of the National Science Advisory Board for
Biosecurity (NSABB) in discussions related to developing criteria for a code of conduct for
researchers, identification of code violations, and development of appropriate consequences. Risk
analysis has also figured in NSABB discussions about developing a process and time schedule to
vet and communicate dual-use research while it is being conducted and before publication, and
about determining the consequences of public release.91 (For more information about NSABB,
see in the section below entitled “National Science Advisory Board for Biosecurity.”) Others have
also proposed using risk-based models to handle sensitive scientific and technical information.
These are discussed next.
Jacques S. Gansler and William Lucyshyn proposed that criteria be developed, and that an
executive order be issued, that identifies “controlled unclassified security information (CUSI),”
consisting of CII and SHSI, whose improper release by government or academic/scientific
institutions “... could egregiously endanger public safety.”92 The objective “... for both
government-funded and privately-funded research is to create a culture that frowns on the
research, experimentation, and publication of CUSI, much like the culture that constrains certain
experimental techniques, such as stem-cell research, and restrains others, such as human
cloning.”93 A risk-based process called a “‘Work-Factor’ for Leveraging Dangerous
Information”—the amount of resources needed to use the information for harmful purposes—
would be used to determine risk of release:
When information that could threaten the public safety is easily accessible—that is, when the
costs of obtaining it are low and the convenience of using it is relatively high—this “workfactor” for leveraging potentially harmful information provides a benchmark for determining
90
Horizontal Integration: Broader Access Models for Realizing Information Dominance is a report prepared by the
Defense Department JASON advisory group for the Under Secretary for Defense Research and Engineering,
Horizontal Integration: Broader Access Models for Realizing Information Dominance, JASON Program Office,
MITRE, JSR-04-132, Dec. 2004, p. 1. The report focused on the goal of enabling “information dominance [in]
warfare” and concluded that more information should flow directly to military personnel in the field, who might not
always have clearance levels required to handle classified information or sensitive information, which is
“....increasingly defined by the eye of the beholder”(pp. 4, 24-30). The report recommended using an information
system based on “... transactional risk—that is the chance that any given transaction will be compromised, rather than
on assigning a level of classification to a document based on the potential damage caused by disclosure” (Shaun
Waterman, “Report: Govt Secrecy Hurting War Fighters,” UPI, Dec. 15, 2004).
91
The archived webcast of the Nov. 21, 2005 meeting is available at http://videocast.nih.gov/ram/od112105.ram. See
also, Andrew J. Hawkins, “National Biosecurity Panel Lays Groundwork for Identifying Dual-Use Research,”
Research Policy Alert, Nov.22, 2005; Andrew J. Hawkins, “Success of Scientist Code of Conduct Hinges On
Education, Biosecurity Board Hears,” Research Policy Alert, Nov.23, 2005; and Eugene Russo, “Biosecurity Advisory
Board Reports Lessons Learned From 1918 Flu Papers, Aims to Improve Screening Process,” Research Policy Alert,
Nov. 23, 2005.
92
Jacques S. Gansler and William Lucyshyn, The Unintended Audience: Balancing Openness and Secrecy: Crafting an
Information Policy for the 21st Century, Center for Public Policy and Private Enterprise School of Public Policy,
University of Maryland, Sept. 2004, pp. 27, 32.
93
The Unintended Audience: Balancing Openness and Secrecy, op. cit., pp. 38-39.
Congressional Research Service
19
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
whether information should be controlled. While high-level descriptions of and mitigations
for vulnerabilities should be released to inform and alert the public, “push-button” or
“cookbook” instructions on how to do harm are easily identifiable and clearly should be
withheld. The amount of resources, including the number of knowledgeable personnel,
needed to exploit vulnerabilities describes a work-factor, which is a good, practical indicator
of where disclosure borders on weaponization.94
The report recommended that with respect to “public sector information,” a policy embodying
CUSI would “enable the sharing of sensitive materials between departments and agencies at the
federal, state, and local levels, as well as with those in the private sector with a need to know,”95
and would ensure “... that similar information produced in different agencies is identified and
protected in the same way” and that FOIA and CUSI guidelines are not in conflict.”96 DHS, it was
recommended, should develop educational programs, government controls, and voluntary
restraints to prevent the disclosure of information that should not be released.97 Governmentdefined policy controls should extend to publicly funded private researchers and DHS, assisted by
NSF and NIH and other agencies, should issue guidance to privately funded researchers.
Professional peer reviews would be conducted before publication of work that might meet criteria
for safeguarding. Specifically, 98
[f]ederally-funded researchers should disclose potential security concerns in their grant
proposals. DHS monitored review panels will assess the security implications of the work
with potentially significant negative impact in accordance with established guidelines. DHS
should lead the effort to develop model review policies, encouraging non-federally-funded
researchers to adopt them and to submit their work to the government-monitored review
panel or an independent, government-certified review panel. DHS should also train
publishers to conduct reviews just before research is made available to serve as a safety net
after research is already completed, and publishers should implement a two-tiered
publication scheme to restrict detailed content to premium access where the credentials of the
readers can be verified.99
94
The Unintended Audience: Balancing Openness and Secrecy, op. cit., pp. 40-42. The following illustrations were
given “[f]or potential low-impact events, the most serious threats are those that are highly convenient and extremely
low cost.... Typically, these threats cause a high level of disruption and/or annoyance. An example of such a threat
would be contaminating food with bacteria, similar to the 1984 case where members of a religious cult sprayed
salmonella bacteria on salad bars throughout the Oregon region, causing 751 cases of food poisoning.... For a potential
medium-impact event, those threats that are high in cost and low in convenience warrant the least amount of concern....
Information on agents that when directly applied to fields would decrease crop yield without completely destroying the
harvest might fall into this category. It would be difficult to deliver such agents, and decreasing the yield for some
crops in the United States might succeed only in reducing the surplus. Nearly all of the threats of a potential highimpact event should be considered serious, and information related to these threats should be controlled.... A grey area,
where information would have to be carefully evaluated, forms when costs are high and convenience is low. For
example, information on how to create vaccines for highly-communicable diseases could fall into this category, as the
method for creating vaccines now in use first increases the virulence of normal diseases and then finds inhibitors to
block or antibodies to combat the strongest variants of the diseases. Increasing controls significantly could slow the
development of preventive measures, which, in the end, might cause more harm than good” (The Unintended Audience:
Balancing Openness and Secrecy, op. cit., pp. 43-44).
95
The Unintended Audience: Balancing Openness and Secrecy, op. cit.,p. ii, p. 33.
96
The Unintended Audience: Balancing Openness and Secrecy, op. cit., p. 33.
97
The Unintended Audience: Balancing Openness and Secrecy, op. cit., p. 44.
98
The Unintended Audience: Balancing Openness and Secrecy, op. cit., p. 45.
99
The Unintended Audience: Balancing Openness and Secrecy, op. cit., pp. ii-iii.
Congressional Research Service
20
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
Brian J. Gorman proposed a risk-based alternative approach for prepublication peer review. He
called for a risk-based process called “Due Process Vetting System” (DPVS) together with “... a
Risk Assessment Scale [RAS] and a Least Restrictive Classification System for the
communication, assessment, and disposition of sensitive life science research in a manner
consistent with national security interests.”100 The aforementioned reports proposed that
researchers should self-evaluate the sensitivity of their work and that self-imposed professional
association or governmental constraints, including classification, be imposed if the information
could be weaponized and if the consequences of its use were high risk, but that such information
should be communicated among those with a “need to know.”101 (This proposal and others for
institutional or governmental bodies to review and approve biological sciences research plans or
publications are discussed below in the section “Controls on Unclassified Biological Research
Information.”)
Mobilizing Information to Prevent Terrorism: Accelerating Development of a Trusted Information
Sharing Environment, a report by the Markle Foundation Task Force on National Security in the
Information Age, examined how to reconcile national security needs with civil liberties
requirements. 102 It sought to redress problems with “current classification procedures” that
frequently are “a barrier to effective information sharing because they overemphasize the risks of
inadvertent disclosure over those of failure to share information.”103 Among other things it
proposed use of a “risk management” approach to classification that balances the risks of
inappropriate disclosure with the risks of failing to share information.
Policies To Protect Specific Types of Sensitive
Information Involving Scientific and Technical
Applications
Specific laws have been enacted and policies and procedures are in varying stages of
implementation that define and protect sensitive unclassified science- and technology-related
100
Brian J. Gorman, “Balancing National Security and Open Science: A Proposal for Due Process Vetting,” Yale
Journal of Law and Technology, 2005, pp. 2, 15.
101
The Unintended Audience: Balancing Openness and Secrecy, op. cit., pp. 39-40. See also J. Gaudioso and R. M. “A
Conceptual Framework for Biosecurity Levels,” BTR 2004: Unified Science and Technology for Reducing Biological
Threats and Countering Terrorism—Proceedings, Albuquerque, NM, March 18-19, 2004, p. ii. As an illustration:
“Restricting research and development must rely on constraining knowledge rather than forbidding it. For example,
such restrictions would control research into the engineering of viral factors that introduce animal pathogens into
humans but would not prohibit it, categorically. Production refers to the ways in which information can be weaponized,
or leveraged against the public. As such, production restraints should entail issues similar to ways of refining anthrax
and ways of enriching uranium. Although information about weapons programs would be classified, scientific “knowhow” that may be—as in the case of bioweapons—only one step away from implementation generally would not be
classified. Employment refers to final-stage delivery. For example, issues of employment may refer to detailed
schematics on the briefcases used in the Tokyo sarin gas attacks or plans for maximizing the radiological contamination
from a “dirty bomb” (Gaudioso and Salerno, op. cit., Mar. 18-19, 2004, p. 28).
102
Zoe Baird, James Barksdale, chairmen, Mobilizing Information to Prevent Terrorism: Accelerating Development of
a Trusted Information Sharing Environment, Third Report of the Markle Foundation Task Force, 2006, Markle
Foundation, New York City, 93 p.
103
Markle Foundation, “Markle Task Force on National Security in the Information Age Releases Third Report,
‘Mobilizing Information to Prevent Terrorism: Accelerating Development of a Trusted Information Sharing
Environment,’ “Press Release, July 13, 2006.
Congressional Research Service
21
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
information in such fields as critical infrastructure, transportation, environmental impacts,
biology, geospatial data, and DHS information. These and criticisms that have been made about
them are summarized next.
Critical Infrastructure Information Controls
The need to protect critical infrastructure information is based on the premise that potential
terrorists should not have access to information that might expose vulnerabilities in, or provide
roadmaps to, the nation’s core physical transportation, water, communication, energy, and related
systems, or to major buildings, bridges, and other major structures. As an example of critical
infrastructure vulnerabilities, Charlie Reeder, Interagency Operations Security Support Staff,
DOD, and part of a Pentagon group that represents the National Security Agency, Central
Intelligence Agency, Federal Bureau of Investigation, DOD, General Services Administration,
and Department of Energy (DOE), is reported to have said that “‘... he’s seen government
websites include maps of installations ... specifications of weapons and communications systems
... and much more. ... When we publish this information on the Internet, we might as well fax it
directly to our adversaries ...’”104 He also commented that “‘According to a message sent by
Secretary of Defense Donald Rumsfeld ... an al Qaeda training manual recovered in Afghanistan
states ‘using public sources openly and without resorting to illegal means, it is possible to gather
at least 80 percent of information about the enemy.’” Open-source information can be accessed
through Internet sites, job announcements, budget documents, and newsletters.105 Similarly, a
survey by Computerworld noted that “the widespread availability of sensitive information on
corporate websites appears to have been largely overlooked by IT and security managers....”106
Among the information available on the Web are “3-D models of the exterior and limited portions
of the interior of the Citigroup headquarters building in Manhattan—one of the sites especially
named in the latest terror advisory issued by the Department of Homeland Security,” and various
similar kinds of information about the building’s structural design weaknesses.
In part to cope with issues like these, the “Critical Infrastructure Information Act of 2002,” Title
II of P.L. 107-296, prohibits disclosure under FOIA of “critical infrastructure information” (CII)
relating to the security of critical infrastructure and protected systems submitted to DHS
voluntarily by private companies. 107 Criminal penalties for disclosure by employees under this
statute include fines, dismissal, or imprisonment for up to a year (Section 214).108 The statute also
provides for the preemption of state freedom of information laws regarding the public disclosure
of such information if it is shared with a state or local government official in the course of DHS’s
activities. 109 The DOD issued a memo on March 25, 2003, that applied prohibitions like those in
P.L. 107-296 to critical infrastructure information voluntarily submitted to DOD.110 On April 15,
104
Stephen Larsen, “Secure Sensitive Unclassified Information,” Pentagram, Nov. 28, 2003
http://www.dcmilitary.com/army/pentagram/8_47/commentary/26442-1.html.
105
Larsen, op. cit.
106
“Too Much Info on Websites,” SAP Info, Sept. 8, 2004.
107
Sections 211-215 of P.L. 107-296, codified as 6 U.S.C. 131-134, define the term “critical infrastructure
information” to mean information not customarily in the public domain and related to the security of critical
infrastructure or protected systems. For rules, see 6 C.F.R. 29.1 and 6 C.F.R. 29.2.
108
For additional analysis, see CRS Report RL31547, op. cit.
109
See also “Homeland Security Law Contains New Exemption 3 Statute,” FOIA Post, Jan. 27, 2003.
110
Memo from H.J. McIntyre on “FOIA Requests for Critical Infrastructure Information,” described in Steven
Aftergood, “DOD on Critical Infrastructure Info,” Secrecy News, Apr. 29, 2003, and “Efforts Made to Expand Critical
(continued...)
Congressional Research Service
22
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
2003, DHS published interim rules to implement the critical information infrastructure protection
provisions of P.L. 107-296, which would extend the rules to other agencies by requiring them to
pass to DHS similar information that they receive.111 On December 17, 2003, President Bush
issued Homeland Security Presidential Directive 7 (HSPD-7), which among other things, directed
all federal agencies to protect voluntarily submitted information about critical infrastructure
vulnerabilities in line with Title II of P.L. 107-296.
The DHS published an interim final rule that established the “Protected Infrastructure Information
(PCII) Program,” effective February 18, 2004, with public comments allowed until May 20,
2004.112 The rules were amended and issued in a final regulation entitled “Procedures for
Handling Protected Critical Infrastructure Information,” on September 1, 2006.113 The procedures
govern the receipt, validation, handling, storage, marking, and use of critical infrastructure
information voluntarily submitted to the Department of Homeland Security and apply to all
federal, state, local, and tribal government agencies and contractors that have access to, handle,
use, or store critical infrastructure information.
CII information submitted to DHS is not subject to disclosure under FOIA, under an exemption
three category, established pursuant to section 214 of the Homeland Security Act of 2002,114 if it
has not been made public previously.115 The language in P.L. 107-296 protects only CII submitted
to the DHS, but the Department of Justice reports that in the future, it may be applied to
submissions made to other federal agencies. 116 (For additional information, see CRS Report
RL33670, Protection of Security-Related Information, by (name redacted) and (name redacted).)
Sensitive Security Information Controls: Transportation
Both the Department of Agriculture (USDA) and the Transportation Security administration
(TSA) use the term “sensitive security information” (SSI). The use of the term in transportation is
discussed in this section.117 The Federal Aviation Administration (FAA) had been permitted since
(...continued)
Infrastructure Information,” OMB Watcher, May 5, 2002.
111
“6 CFR Part 29, Procedures for Handling Critical Infrastructure Information; Proposed Rule, Department of
Homeland Security,” Federal Register, Apr. 15, 2003, pp. 18523-18529. For additional information, see CRS Report
RL30153, Critical Infrastructures: Background, Policy, and Implementation, by (name redacted).
112
The implementing regulations are contained in the Code of Federal Regulations (6 CFR Part 29). See also
Department of Homeland Security, “DHS Launches Protected Critical Infrastructure Information Program to Enhance
Homeland Security, Facilitate Information Sharing,” Press Release, Feb. 18, 2004, and attached information sheet
“Protected Critical Infrastructure Information (PCII) Program.” See the Federal Register, Feb. 20, 2004, pp. 80738089. Comments are posted on the DHS website. See also Lucy A. Dalglish and Gregg P. Leslie, Homefront
Confidential: How the War on Terrorism Affects Access to Information and the Public’s Right to Know, fifth ed., 2004,
pp. 70-71.
113
Federal Register, vol. 71, no. 170, Sept. 1, 2006, pp. 52261-52277.
114
6 U.S.C.A. section 133. See the memo on “Critical Infrastructure Information Regulations Issued by DHS,” FOIA
Post, Feb. 27, 2004, http://www.usdoj.gov/oip/foiapost/2004foiapost6.htm, Leslie, op. cit., and CRS Report RL30153,
op. cit.
115
DHS press release, Feb. 18, 2004, op. cit.
116
“Critical Infrastructure Information Regulations Issued by DHS,” op. cit. 2004.
117
For a discussion of usage in USDA and TSA, see Appendix A to this report. See also: CRS Report RL33494,
Security Classified and Controlled Information: History, Status, and Emerging Management Issues, by (name red
acted).
Congressional Research Service
23
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
passage of the Air Transportation Security Act of 1974118 to issue regulations to protect, and to
distribute to those with a “need to know,” sensitive civil aviation security information that was
obtained during security investigations or consisted of research and development information that
would invade privacy, would reveal a trade secret or financial or commercial information, or
would be detrimental to the safety of persons traveling by air. “The FAA implemented this
authority by promulgating regulations, which, among other things, established a category of
information known as Sensitive Security Information (SSI). In 1997, the Department of
Transportation (DOT) definition of SSI included ‘records and information ... obtained or
developed during security activities or research and development activities.’”119 Subsequently,
this type of information was given a statutory basis pursuant to the Aviation and Transportation
Security Act, P.L. 107-71, which created the Transportation Security Administration (TSA) and
prohibited disclosure of certain kinds of information relating to transportation if the disclosure
would be detrimental to the safety of passengers in transportation.120 P.L. 107-296 expanded this
coverage to include information detrimental to the “security of transportation.” As the FAA was
moved to the TSA, first located in the DOT and then to the DHS,121 the SSI withholding authority
appears to have been expanded to include “all transportation related activities including air and
maritime cargo, trucking and freight transport, and pipelines.”122 On May 18, 2004, the DOT and
DHS jointly promulgated revised regulations,123 which, “adopt the Homeland Security Act
language as the definition of SSI. In addition, the new regulations incorporate former SSI
provisions, including the sixteen categories of information and records that constitute SSI.”124 SSI
information is defined by statute (49 U.S.C. section 114 (s)) and an implementing regulation (49
C.F.R. part 1520)125 as
(1) Security programs and contingency plans ... issued, established, required, received, or
approved by DOT or DHS.... (2) Security Directives.... (3) Information Circulars ... issued by
DHS or DOT regarding a threat to aviation or maritime transportation.... (4) Performance
specifications.... (5) Vulnerability assessments.... (6) Security inspection or investigative
information.... (7) Threat information.... (8) Security measures.... (9) Security screening
information.... (10) Security training materials.... (11) Identifying information of certain
transportation security personnel.... (12) Critical aviation or maritime infrastructure asset
information.... (13) Systems security information... (14) Confidential business information....
(15) ... Information obtained or developed in the conduct of research related to aviation or
maritime transportation security activities, where such research is approved, accepted,
118
Air Transportation Security Act of 1974, P.L. 93-366, Section 316, 88 Stat. 409 (1974), as cited in CRS Report
RL32664, Interstate Travel: Constitutional Challenges to the Identification Requirement and Other Transportation
Security Regulations, by (name redacted).
119
According to Tatelman, op. cit., codified at 14 C.F.R. § 191.1 (1997).
120
Created pursuant to the Aviation and Transportation Security Act (ATSA), P.L. 107-71, section 101 (e)(3), 115 Stat.
597, 603 (2002).
121
For detailed history of the laws and regulations that govern SSI and transportation, see CRS Report RL32664, op.
cit., and CRS Report RL32425, Sensitive Security Information and Transportation Security: Issues and Congressional
Options, by (name redacted).
122
CRS Report RL32664, op. cit.
123
See also “Protection of Sensitive Security Information, Transportation Security Administration (TSA), DHS, and
Office of the Secretary of Transportation (OST), DOT.” Federal Register, May 18, 2004 (v. 69, no. 96), pp. 2806628086. (DOT, Office of the Secretary of Transportation, 49 CFR Part 15; Department of Homeland Security,
Transportation Security Administration, 49 CFR Part 1520.)
124
Tatelman, op. cit., pp. 3-4. See the original for footnotes to this quotation.
125
Report Pursuant to Section 893, not dated but reportedly sent to the committee chairmen in February 2004, p. 5, op.
cit.
Congressional Research Service
24
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
funded, recommended, or directed by the DHS or DOT, including research results... (16)
Other information....
This information, like CII information, was also designated as exempt from disclosure under
FOIA (49 U.S.C sec 40119(b) (1)) under exemption 3, which permits the withholding of
information protected by other statutes, has use limitations for sharing with state or local
governments, and imposes criminal penalties on federal officers or employees who disclose such
information. 126
Critique of SSI Rules
Terrorists have capitalized on vulnerabilities in national and foreign transportation systems
several times since 2001. Nevertheless, some critics charge that too much transportation-related
information is being withheld from public access. Many of the criticisms of SSI rules focus on the
alleged consequences of preventing the public from accessing information that might be used to
promote safety or be used in citizen oversight. For instance, some aircraft personnel and
consumer advocates say that TSA’s use of SSI can “muzzle debate of security initiatives and
insulate TSA from criticism.”127 The newsletter OMBWatch reported that the TSA has denied
access to information when “reasonable access to it could improve safety conditions for
communities and workers.”128 Examples include TSA denying pilots access to information to
comply with TSA regulations to avoid flying near nuclear power plants, disagreeing with TSA’s
views that information on such sites compiled from public data by the Aircraft Owners and Pilots
Association should be labeled SSI and not be made available, and denying the District of
Columbia government access to information to help them determine if trains carrying chlorine
through D.C. should be rerouted. The Coalition of Journalists for Open Government (CJOG), a
group of journalist advocacy organizations, 129 in a filing on July 16, 2004, in response to
regulations jointly filed by the Department of Transportation and the Transportation Security
Administration, 130 said
[The] ... unrestricted use of the ... (SSI) designation ... will have a seriously adverse impact
on traditional citizen and media oversight of the governance of our seaports, airports and
transit systems.... There appear to be no limits to the type of information that might be
gathered or generated as SSI and then sealed. Local and state officials, bound by nondisclosure agreements, may be forced to deny access to records that state law and local
ordinance require be made available to citizens. Information needed by civic activists or
organizations to maintain oversight and challenge local officials on their management of
126
See CRS Report RL32597, Information Sharing for Homeland Security: A Brief Overview, by (name redacted) and
(name redacted).
127
Secrecy in the Bush Administration, by U.S. House of Representatives, Committee on Government Reform—
Minority Staff Special Investigations Division Prepared for Rep. Henry A. Waxman, Sept. 14, 2004, p. 54. Tim Starks,
“A Fine Mess: TSA’s New Information Security Rules Leaves Stakeholders Confused,” CQ Homeland Security, July
21, 2004.
128
“Transportation Agency Hides Vital Data ‘Sensitive Security Information,’” OMB Watch, Apr. 4, 2005.
129
Composed of American Society of Newspaper Editors; Associated Press Managing Editors; Committee of
Concerned Journalists; National Association of Science Writers; Newspaper Association of America; Reporters
Committee for Freedom of the Press; Radio-Television News Directors Association; Society of Professional
Journalists; Society of Environmental Journalists.
130
See also “Press Coalition Defends Access to “Critical Oversight Info,” Secrecy News, July 19, 2004.
Congressional Research Service
25
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
public facilities may be withheld, even when the information’s relevance to any possible
terrorist threat is at best tenuous.131
In the same document, 132 the CJOG recommended that federal agencies should preserve public
access to what it calls “critical oversight information” (COI)—“any information a citizen might
use to judge whether his or her public servants are serving well,” information “that speaks to the
quality and integrity of their performance as policy makers, managers or employees of our
seaports, airports and transit systems,” including budget information and details on revenue and
spending and information about personnel and their qualifications, training, and performance. 133
Various courts have ruled on the interpretation of the SSI regulations.134
Controls on Environmental Impact Information
Controls on environmental impact information are premised on the need to protect internal
agency decision making procedures and to control access to information that terrorists might use
to harm critical infrastructures, deliver services, or poison the, air, water, and so forth. The actions
discussed next represent steps that have been taken to safeguard public access to environmental
information.
The Department of Homeland Security (DHS) expanded its ability to withhold certain types of
environmental impact information that previously was available to the public pursuant to the
National Environmental Policy Act (NEPA).135 On June 14, 2004, DHS issued a directive
proposing new categorical exclusions to disclosure requirements under FOIA for assessments of
environmental impacts of DHS decision making and included component DHS agencies in the
categorical exclusions policy.136 The directive specified three levels for projects or grants that
might have environmental impacts: “those affecting national security that are categorically
excluded from coverage under NEPA; those that require DHS agencies to conduct environmental
assessments; and those with the greatest potential to affect natural resources and the environment,
which would require more detailed environmental impact statements.” Specifically, EPA allows
categorical exclusions for “actions that ... do not ... have significant impact on the human
environment, and therefore ... do not require an environmental assessment ... or environmental
impact statement....” (40 C.F.R. 1500-1508.)
Some of the agencies that were transferred to DHS had previously identified such exclusions. In
addition, the directive exempted all DHS agencies (Transportation Security Administration, Coast
Guard, Border Patrol, FEMA and others) from releasing classified, proprietary, or other
131
Pete Weitzel, “Comments of the Coalition of Journalists for Open Government (CJOG), Before The Department of
Transportation and the Transportation Security Administration, In the Matter of Protection of Sensitive Security
Information,” RIN 1652 AA08 Docket # TSA 2003-15569.
132
These comments were made in a filing by CJOG and nine of its member organizations on July 16, 2004, in response
to regulations jointly filed by the DOT and the TSA involving the designation and disclosure of information designated
as Sensitive Security Information.
133
Weitzel, CJOG, op. cit.
134
See, Stevens and Tatelman, CRS Report RL33670, op. cit., pp. 19-26.
135
42 U.S.C. Section 5321 et. seq.
136
DHS, “Proposed Management Directive 5100.1, Environmental Planning Program,” Federal Register, v. 69, no.
33043-33066. June 14, 2004.
Congressional Research Service
26
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
information exempt from disclosure under FOIA, and proposed to exempt critical infrastructure
information, sensitive security information, and other information described in “laws, regulations,
or Executive Orders prohibiting or limiting the release of information.”137 Some say this could
exclude from public view environmental impact statements required by NEPA. In its Federal
Register announcement, DHS said that it would place protected information prepared for
compliance with NEPA into appendix sections for viewing only by decision makers, but would
allow the public to view nonsensitive portions of the material. However, it added “...if segregation
would leave essentially meaningless material, the DHS elements will withhold the entire NEPA
analysis from the public.” The plan also would allow DHS to categorize some environmental
reviews as “sensitive security information” or “critical infrastructure information” exempt from
public disclosure. The public comment period was for one month and then was extended to
August 16, 2004. DHS held a meeting on October 12, 2004 to discuss public comments
received. 138 On April 4, 2006, DHS published a final rule. On this topic EPA responded to public
comments by empanelling a group to examine release of environmental review information and
concluded that it would permit environmental review information that is not withheld according
to statute to be made accessible to the public pursuant to FOIA.139
A 2005 supplemental appropriations bill (H.R. 1268), enacted as P.L. 109-13,140 exempted the
DHS from certain legal requirements when physically securing U.S. borders. Some contend that
this may enable DHS to waive environmental protection laws, among others, relating to border
security. 141
Critiques of Controls on Environmental Information
Some critics allege that these types of policies, including SBU information control policies,
conflict with the environmental quality laws of the 1970s and the Emergency Planning and
Community Right-To-Know Act of 1986 (42 U.S.C. 11049). Critics of regulations limiting access
to some critical infrastructure information focus on their preemption of state and local disclosure
laws and the inability of citizens to obtain information needed to ensure community safety.142
137
Federal Register, June 14, 2004, op. cit., p. 33063.
Management Draft Management Directive 5100.1, Environmental Planning Program Meeting Minutes, Subject:
Draft Environmental Directive for the Department of Homeland Security (DHS) Meeting: October 12, 2004, at
http://www.dhs.gov/dhspublic/interapp/editorial/editorial_0528.xml.
139
Section “9. Appendix A, Section 6.2, Classified or Protected Information” in “Department of Homeland Security,
Environmental Planning Program, Notice of Final Directive,” Federal Register, vol. 71, no. 64, April 4, 2006, pp.
16790-16820.
140
According to Sec. 102 of P.L. 109-13: “Waiver of Legal Requirements Necessary for Improvement of Barriers at
Borders; Federal Court Review,” Section 102(c) of the Illegal Immigration Reform and Immigrant Responsibility Act
of 1996 (8 U.S.C. 1103 note) is amended to read as follows: “... Notwithstanding any other provision of law, the
Secretary of Homeland Security shall have the authority to waive all legal requirements ... [he] determines necessary to
ensure expeditious construction of the barriers and roads under this section.... Any such decision by the Secretary shall
be effective upon being published in the Federal Register.”
141
“Homeland Security Wins Power to Waive All Law,” OMB Watch, Feb, 2005.
138
142
Reportedly, once submitted to DHS, “information that is designated CII is not merely exempt from public
disclosure. It can’t be disclosed to any government official except for national security purposes. Nor can it be used in
court. That means a company could tell the Department of Homeland Security about an eroding chemical storage tank
on the bank of a river, but DHS could not disclose that information to the public or even to the Environmental
Protection Agency. And if there were a spill ... , the information given DHS couldn’t be subpoenaed in a law suit. No
one knows just what that will mean in practice, but the concern is palpable” (Pete Weitzel, “A Skip Through the Rabbit
Hole,” The American Editor [American Society of Newspaper Editors], May-June-July 2004).
(continued...)
Congressional Research Service
27
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
Several environmental groups have criticized controls on environmental information, saying too
much is being withheld by EPA and DHS pursuant to its DHS environmental directive released on
June 14, 2004. The Natural Resources Defense Council charged that because the agencies
subsumed by DHS make environmentally related decisions relating to oil spills, border security,
flood planning, and chemical plant security, and so forth, communities should be given an
opportunity to evaluate these decisions.143 In addition, some agencies label environmental impact
statements as SBU, saying that they should be released only to those who have a “need to know.”
Some agencies post environmental impact materials on the Internet with blacked-out markings for
what appears to be locational or infrastructure details.144 Other agencies have published
documents and put SBU information into a separate appendix, available under controlled access.
Generally, because of “security sensitivity,” most DOE environmental assessment documents are
not available to the public online but may be accessible via hardcopy in NEPA reading rooms if
the requestor qualifies. 145 Other examples have been cited of agencies withholding or controlling
information that, reportedly, prevents informing the public of environmental and other hazards.146
The American Library Association (ALA) proposed that, with respect to environmental
information, DHS should limit “its non-disclosure provision to information that unambiguously
qualifies for withholding under one of the exemptions provided in the Freedom of Information
Act....”147 It contended that the provision allowing DHS to withhold “essentially meaningless”
information not now subject to exemption from disclosure should be deleted since Congress
intended the public to determine what information is meaningful in the environmental statements.
OMB Watch concurred: “There are no procedures contained in the directive for how DHS will
determine which pieces of environmental analysis to remove if it falls within an exemption, or
how it will determine if the public finds the information meaningful.”148
(...continued)
Problems were reported by a community group working with the Project on Government Oversight (POGO) “to track
drinking water supplies contaminated with perchlorate, a rocket fuel that causes developmental problems in children.
After 9/11, the Army refused to share critical information with the community groups, including maps of drinking
water test wells. What confused community groups the most was the fact that these maps were already shared
publicly—but the Army refused to acknowledge them and claimed they were ‘sensitive’ information not for public
release. The community group refused to back down and is now suing the Army for information under an
environmental law that gives community groups the right to be informed about toxic chemical threats” (“Fighting
Secrecy—And Winning,” OMB Watch, Feb. 23, 2004. For additional examples of the issue of SBU in the
environmental area, see, Richard Dahl, “Does Secrecy Equal Security?” Environmental Health Perspectives, Feb.
2004, pp. A104-A107). See also regarding withholding of flood inundation maps, Gregg Sangillo, “Groups Raise
Concerns About Increased Classification of Documents,” GovExec.com, Oct. 27, 2004.
143
National Resources Defense Council, Comments to Proposed Management Directive 5100.1, Environmental
Planning Program, July 14, 2004, as cited in Secrecy in the Bush Administration, op. cit., Sept. 14, 2004, p. 56. See
also regarding access to maps locating perchlorate plumes, “Post 9-11 Secrecy Hits Homer in Aberdeen Maryland,”
Release prepared by the Working Group on Community Right-to-Know, Jan. 29, 2004.
144
See, for instance, U.S. Department of Energy, Environmental Assessment For the Strategic Petroleum Reserve West
Hackberry Facility Raw Water Intake Pipeline Replacement Cameron and Calcasieu Parishes, Louisiana, DOE/EA1497 http://www.eh.doe.gov/nepa/ea/EA1497/EA-1497.pdf and “NRC Censors Environmental Impact Statement,”
OMB Watch, Jan. 24, 2005.
145
Source: http://www.eh.doe.gov/nepa/documents.html.
146
See for instance, Lance Gay, “Government Withholds ‘Sensitive-but-Unclassified’ Information,” Scripps Howard
News Service, Feb. 2, 2006 http://www.shns.com/shns/g_index2.cfm?action=detail&pk=UNCLASSIFIED-02-02-06.
147
Emily Sheketoff, American Library Association, Letter “Re: Department of Homeland Security’s Proposed
Management Directive 5100.1, Environmental Planning Program,” Aug. 16, 2004.
148
“DHS Seeks Exemptions From Public Disclosure Requirements,” OMB Watcher, July 29, 2004. See also,: Mike
Ferullo, “Groups Wary of Homeland Security Plan Exemptions Some Environmental Reviews,” Daily Report for
(continued...)
Congressional Research Service
28
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
Illustration of Complexity of the Issue: the Nuclear Regulatory Commission
(NRC)
The complexity of balancing access to, and protection of, information is illustrated by actions
taken by the Nuclear Regulatory Commission (NRC). In August 2004, the agency issued a
statement that “certain security information formerly included in the Reactor Oversight Process
will no longer be publicly available.”149 Its efforts to “scrub” its website while balancing public
access and information security generated public criticism that NRC withheld information
relevant to the safety of surrounding residents but shared such information with power companies
and industrial lobbying groups. The NRC also allegedly threatened criminal prosecution for
persons who published critiques of two nuclear reactors in Indian Point, New York, even though
the NRC is reported to have said it could not specify what information was compromised. 150 In
the fall 2004, some “... news and watchdog organizations pointed out that some sensitive
documents in the [NRC online] library could be used by terrorists”; the NRC subsequently closed
major portions of the library and reviewed items it contained. 151
Representative Edward J. Markey, a senior minority member of the House Committee on Energy
and Commerce, wrote to the NRC, requesting that its inspector general investigate the agency’s
information release policies and, specifically. concerns about the NRC “improperly restricting
access to specific documents that should be releasable from a security perspective but are
nevertheless being withheld from public release.” 152 He cited the agency’s proposals to widen its
definition of “proprietary information” to withhold more public information and to broaden
restrictions on the dissemination of sensitive information to include emergency evacuation plans
and safety analyses concerning the protection of nuclear materials; its actions to withhold an
unclassified version of an NAS report allegedly because the NRC disagreed with its findings; and
the agencies’ prohibitions on non-industry representatives attending meetings and having
information, even though industrial representatives were given access. In June 2005, the Nuclear
Regulatory Commission announced it would restore viewing on the web to more than 70,000
documents, after reviewing them for “sensitive security information.”153 An NRC task force
concluded that the agency could withhold information that could be deemed useful to terrorists if
the information were not already available to the public pursuant to its new Sensitive Information
Screening Project, but FOIA principles needed to be followed to withhold information. The task
(...continued)
Executives, July 16, 2004, p. A-21.
149
“NRC Modifies Availability of Security Information From All Nuclear Plants” NRC News, Aug. 4, 2004 (No. 04091).
150
R. Jeffrey Smith, “Nuclear Security Decisions Are Shrouded in Secrecy, Agency Withholds Unclassified
Information,” Washington Post, May 29, 2004, p. A21.
151
“NRC Initiates Additional Security Review of Publicly Available Documents; Temporarily Suspends Agency’s OnLine Library,” NRC News, Oct. 25, 2004, No. 04-135; Sean Madigan, “Documents Return to Online Nuclear
Regulatory Library After Terror Review,” CQ Homeland Security, Nov. 17, 2004. These were identified as such things
as floor plans for university laboratories giving the location of equipment that uses nuclear materials and of storage
facilities for them. (See, for example, M. Ahlers, “Blueprints for Terrorists? Sensitive Nuclear Info Ends Up on NRC
Web Site,” CNN.Com at http://www.cnn.com/2004/US/10/19/terror.nrc/index.html).
152
Letter from Rep. Edward J. Markey to Hubert T. Bell, Inspector General, U.S. Nuclear Regulatory Commission,
Mar. 21, 2005.
153
Sean Madigan, “Nuclear Documents Back Online,” CQ Homeland Security, June 10, 2005. For original wording,
see “NRC Task Force Report on Public Disclosure of Security-Related Information,” Nuclear Regulatory Commission,
May 18, 2005, approved June 30, 2005. http://www.fas.org/sgp/othergov/nrc-disc.pdf.
Congressional Research Service
29
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
force identified the precise kinds of information that could be withheld under the various FOIA
exemptions. 154
Also during this time period, the National Academies released an unclassified version of a report,
that included among its findings that the commission’s security restrictions on the sharing of
information with industry and the public negatively affected “constructive feedback and
cooperation. The committee recommended that the ... NRC improve the sharing of pertinent
information on its security analyses of spent fuel storage with nuclear power plants operators and
system vendors. More constructive interaction with the public and with independent analysts also
could increase confidence in ... NRC and industry decisions and their actions to reduce the
vulnerability of spent fuel storage to terrorist attacks.”155
Controls on Unclassified Biological Research Information
Traditionally, open communication of biological information fosters the conduct of research and
development. Also, emergency preparedness requires exchange of information to inform local
health officials “... of what agents are being studied in their jurisdictions so they can prepare for
any unlikely future events.”156 However, some biological information and data could pose a
domestic or international security threat, which has led to federal controls.157 For instance, a 2006
National Academies report described a variety of biotechnology agents and specific genetic
advances that could be used in research and could increase the potential for biowarfare.158 It also
inventoried some dual-use biological agents and research developments that could be used
malevolently. For example, “The same reverse genetic technologies that can be used to develop
new vaccines against RNA viruses could also be used to construct modified viruses, including
possibly viruses that express heterologous virulence factors that result in more lethal disease.”159
Ominously, it observed that
[in] the past, dual-use concerns have focused on pathogens and on the challenges associated
with controlling dangerous pathogens. As already emphasized, this committee’s
deliberations have indicated that the problem will be far broader and more profound in the
future. For example, advances in neurobiology may make it possible to manipulate behavior
and thought processes, while gene expression technologies just now coming to fruition will
make it possible to activate endogenous molecules in the body—with possibly wide ranging
and everlasting effects. Advances in synthetic biology and nanotechnology will offer similar
154
“NRC Task Force Report on Public Disclosure of Security-Related Information,” NRC, May 18, 2005, approved
June 30, 2005, originally cited in “NRC Adopts Policy on Disclosure of Security Information,” Secrecy News, Aug. 16,
2005, http://www.fas.org/sgp/othergov/nrc-disc.pdf.
155
“Spent Fuel Stored in Pools at Some U.S. Nuclear Power Plants Potentially at Risk From Terrorist Attacks; Prompt
Measures Needed to Reduce Vulnerabilities,” NAS Press Release, April 6, 2005. See also “Secrecy Impedes Security,
National Academy Says,” Secrecy News, Apr. 8, 2005; and the NAS report: Safety and Security of Commercial Spent
Nuclear Fuel Storage: Public Report, by Committee on the Safety and Security of Commercial Spent Nuclear Fuel
Storage, National Academy of Sciences Press, 2005.
156
“Laura H. Kahn, “Biodefense Research: Can Secrecy and Safety Coexist?” Biosecurity and Bioterrorism:
Biodefense Strategy, Practice and Science, vol. 3, no. 2, 2004, p. 4.
157
For additional information, see CRS Report RL31695, Balancing Scientific Publication and National Security
Concerns: Issues for Congress, by (name redacted).
158
Committee on Advances in Technology and the Prevention of Their Applications to Next Generation Biowarfare
Threats, Globalization, Biosecurity, and The Future of the Life Sciences, National Academies Press, 2006, pp. 39-40.
159
Globalization, Biosecurity, and The Future of the Life Sciences, op. cit., p. 53.
Congressional Research Service
30
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
rich opportunities for dual use. Nanodevices that may be used to unplug blocked arteries
could instead be employed to interfere with circulatory function. Advanced drug delivery
technologies and pharmacogenomics knowledge could be used to develop and deliver with
greater efficiency new bioweapons, perhaps even selectively targeting certain racial or ethnic
groups.”160
To deal with concerns like these, some types of biological sciences information have already been
controlled and proposals have been made to develop other types of governmental or
nongovernmental systems to control access to information before research is conducted or in the
prepublication phase. These proposals, which are discussed next, are not without controversy.
The federal government’s regulation requiring the registration of laboratories that transferred
certain “select agents”—organisms and toxins identified by the Centers for Disease Control and
Prevention (CDC) as potentially useful in bioterrorist activities—began in 1996.161 Registration
of laboratories that possess such agents was mandated by P.L. 107-188, “The Public Health
Security and Bioterrorism Preparedness and Response Act of 2002,” enacted after the 9/11
attacks. The law requires coordination between the Department of Health and Human Services
(DHHS) and the Department of Agriculture (USDA) to identify and regulate the use and transfer
of such agents that pose a risk to public health, crops or livestock; registration of all facilities that
use such agents; minimum safety requirements for registered facilities; background screening of
persons using such agents; and a national database of such users. The USA PATRIOT Act, P.L.
107-56 prohibits access to select agents by certain persons, including certain immigrants, and
persons with criminal or drug use history and other factors. Interim final regulations
implementing these laws were issued in December 2002.162
National Science Advisory Board for Biosecurity
A National Academy of Sciences (NAS) report, Biotechnology Research in an Age of Terrorism:
Confronting the “Dual Use” Dilemma, published in 2004 and dubbed the “Fink” report after the
committee chairman, called for greater self-regulation by scientists, use of institutional biosafety
committees at academic and research institutions to monitor research that could possibly aid
terrorism, NIH review of certain types of research reports before they are published, and use of
screening criteria in a prepublication review. Regarding private scientific publishing, the Fink
report largely left it up to journal publishers to make decisions about prepublication review
procedures for articles involving biological agents. The Fink report also urged creation of a new
federal advisory board to guide nongovernmental researchers and to develop responsibility
among scientists to control flows of biodefense information. But it did not propose governmental
control of such research.
In March 2004, the DHHS announced its intent to create a National Science Advisory Board for
Biosecurity (NSABB), which became funded in 2005. It is managed and staffed by the National
Institutes of Health (NIH). The NSABB is chartered to have 25 voting nongovernmental members
160
Globalization, Biosecurity, and The Future of the Life Sciences, op. cit., p. 55.
Pursuant to the Antiterrorism and Effective Death Penalty Act of 1996 (P.L. 104-132). For further information on
this and subsequent activity, see CRS Report RL31719, An Overview of the U.S. Public Health System in the Context of
Emergency Preparedness, by (name redacted).
162
The DHHS regulation is codified at 42 CFR Section 73.0, and the USDA regulation at 7 CFR Part 331 and 9 CFR
Part 121.
161
Congressional Research Service
31
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
with a broad range of expertise in molecular biology, microbiology, infectious diseases, biosafety,
public health, veterinary medicine, plant health, national security, biodefense, law enforcement,
scientific publishing, and related fields. The NSABB also includes nonvoting ex officio members
from 15 federal agencies and departments. It is supposed to advise federal departments and
agencies regarding oversight of dual-use nonclassified biological research. The board’s charter
also includes work to develop national policies to communicate and publish sensitive research
results, a code of conduct for life sciences researchers, training programs and materials to educate
the community about biosecurity, and strategies to foster international collaboration to oversee
dual-use life sciences research. NIH aims to use the committee’s guidance to develop policies to
require performer institutions that it funds to use Institutional Biosafety Committees (IBC), to
educate researchers, to issue guidance, and to review and advise on specific experiments that
might be misused or pose a threat to the public health or national security. Policy guidance will
flow from the federal board to the institutional committees if there is uncertainty or disagreement
regarding denial of an experiment. The NSABB met several times in 2005 and 2006; it will meet
next on January 31 to February 2, 2007.
During its first meeting, the board established five working groups to develop criteria to identify
dual-use research; criteria to communicate results of dual-use research; a life sciences code of
conduct; international perspectives on dual-use research; and guidance on chemical synthesis of
bacterial and viral genomes. 163 Some discussants proposed that biologists should be licensed to
conduct sensitive biological research, that codes of conduct would need to be certified, and that
methods of assuring compliance among research institutions would need to be developed. 164
Some contended that if the scientific community did not develop methods of monitoring and
protecting sensitive research, policy makers might develop and try to enforce more stringent
controls that ultimately might prove to be unacceptable.165
During the July 2006 meeting, NSABB recommended in draft guidelines released for public
comment that authors, institutional reviewers, and journal editors conduct a risk-benefit analysis
as part of “formal procedures to presecreen the publication of findings from...dual-use projects”
that might be useful to terrorists.166
During its October 25, 2006 meeting,167 which addressed the topic of synthetic biology, among
other things, the Board adopted draft recommendations, published for comment, that the
government “regulate potentially dangerous gene sequences instead of a list of known pathogens”
since the current rules for select agents identify a finite list of organisms, and do not account for
biological entities that can be synthetically engineered. 168 The board “...also wants the
163
Janet Coleman, “NSABB Working Groups Will Begin Discussions Soon...,” Research Policy Alert, July 5, 2005.
“Rules of Engagement,” Nature, July 7, 2005, p. 2.
165
Eugene Russo, “New Biosecurity Panel Struggles With Role in Monitoring Sensitive Research,” Research Policy
Alert, July 5, 2005. See also Jeffrey Brainard, “National Biosecurity Board Holds First Meeting, Ponders Limits on
Research,” Chronicle of Higher Education, July 1, 2005.
166
Yudhijit Bhattacharjee, “Biosecurity: U.S. Panel Calls for Extra Review of Dual-Use Research,” Science, July 21,
2006, p. 284. The draft guidelines are: National Science Advisory Board for Biosecurity, NSABB Draft Guidance
Documents, July 2006, http://www.biosecurityboard.gov/pdf/NSABB%20Draft%20Guidance%20Documents.pdf.
They focus on I. Criteria for Identifying Dual Use Research of Concern, II. Tools for the Responsible Communication
of Research with Dual Use Potential, III. Considerations in Developing a Code of Conduct for Dual Use Research in
the Life Sciences.
167
See, http://www.biosecurityboard.gov/meetings_archive_102506.asp.
168
Yudhijit Bhattacharjee, “Bioterrrorism Agents: U.S. Panel Wants Security Rules Applied to Genomes, Not
(continued...)
164
Congressional Research Service
32
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
government to require companies to screen orders for synthetic DNA against the genomes of
select agents and to maintain a record of purchase orders. Neither procedure is currently
mandated by law.”169 Topics for subsequent NSABB meetings include developing oversight plans
and implementation processes for these guidelines in academia and in government. It is likely that
some scientists will object to guidelines requiring prepublication review. 170
Views on Adequacy of Biosecurity Protection Policies
Some critics say existing biosecurity protections are inadequate to prevent terrorists from
obtaining and using biological information and suggest that stronger measures should be taken,
such as creation of a network that interacts closely with intelligence and military agencies to
prevent misuse of biological information. 171 Related to this, a 2006 National Academies report,
concerned about how new developments in the life sciences coupled with rapidly advancing
fields such as nanotechnology and materials science could prove to threatening, endorsed the free
and open change of information in the life sciences to the maximum extent possible. However, it
also recommended,
•
creating statutorily an independent advisory group in the security community to
strengthen scientific and technical expertise within the intelligence and security
communities;
•
adopting and promoting a “common culture of awareness and a shared sense of
responsibility within the global communities of life scientists,” including
development of codes of ethics; and
•
establishing, “... a decentralized, globally distributed network of informed
concerned scientists who have the capacity to recognize when knowledge or
technology is being used inappropriately or with the intent to cause harm”172 and
whose interventions could take the form of counseling or “... reporting such
activity to national authorities when its appears potentially malevolent in
intent.”173
Other shortcomings in current policy have been identified. For instance, the scope of the DHHS’s
NSABB board has been faulted because it does not extend to privately funded research nor
harmonize international standards.174 Others criticize the select agent rules as inadequate and say
federal regulations should be expanded to prevent unauthorized persons from possessing the DNA
(...continued)
Pathogens,” Science, Nov. 3, 2006, p. 743. The draft document is entitled, NSABB, Addressing Biosecurity Concerns
Related to the Synthesis of Select Agents. Draft Recommendations, Prepared by the Working Group in Synthetic
Genomics, 18 p.
169
Bhattacharjee, July 21, 2006, op. cit.
170
Bhattacharjee, July 21, 2006, op. cit. For additional information, see CRS Report RL33342, Oversight of Dual-Use
Biological Research: The National Science Advisory Board for Biosecurity, by (name redacted).
171
Russo, July 6, 2005, op. cit
172
Globalization, Biosecurity, and the Future of the Life Sciences, op. cit., p. 8.
173
Globalization, Biosecurity, and the Future of the Life Sciences, op. cit., p. 9.
174
Jennifer Couzin, “U.S. Agencies Unveil Plan for Biosecurity Peer Review,” Science, Mar. 12, 2004, citing Elisa
Harris of the University of Maryland’s Center for International and Security Studies.
Congressional Research Service
33
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
components of a select agent.175 George Church, a genetics professor at Harvard, reportedly “is
organizing a consortium of researchers and academics to push the federal government to license
anyone interested in purchasing DNA segments for agents of bioterror.”176 Similarly, John
Steinbruner and colleagues at the Center for International and Security Studies at Maryland
(CISSM), in a 2005 report, advocated mandatory licensure of researchers and institutions that
conduct biodefense research. Three levels of independent review—at the institutional, national,
and international level—would monitor risks and benefits of research proposals and would issue
approval or disapproval for conduct of researchers and publications.177
Nongovernmental professional groups have explored the use of codes of conduct or self-policing
policies178 for research topics and publications. Some publishers adopted a set of voluntary, riskbased publishing principles, called “Statement of Scientific Publication and Security,” 2003; but
this, reportedly, has resulted in changes in only very few articles before publication.179 In June
2005, the American Society for Microbiology drafted a code of ethics for its members and urged
them to report to “appropriate authorities” misuses of microbiology information.180 The
Interacademy Panel on International Issues, consisting of most of the world’s national science
academies, issued a set of principles that urged scientists to take responsibility to prevent misuse
of their work. 181 Two researchers, Margaret A. Somerville of McGill University and Ronald M.
Atlas, President of the American Society for Microbiology, proposed an international code of
ethics to prevent bioterrorism.182 Adherents to the code would refuse to conduct work that could
175
Caitlin Harrington, “Lab-Synthesized Diseases Open a New Front in Bioterror War,” CQ Homeland Security, Aug.
2, 2004.
176
Harrington, op. cit.
177
Eugene Russo, “Biodefense Research Needs Formal Oversight and Licensure - University of Maryland Report,”
Research Policy Alert, Feb. 22, 2006, citing John Steinbruner, et al., Controlling Dangerous Pathogens: A Prototype
Protective Oversight System, University of Maryland, 2005.
178
For a representative list of codes of ethics developed by professional groups, see online at
http://www.biosecuritycodes.org/codes_archive.htm.
179
Reportedly, the statement of policy was adopted by science journal editors and released on Feb. 15, 2003, and was
published in Science, Nature, and the Proceedings of the National Academy of Sciences. It is available at
http://www.fas.org/sgp/news/2003/02/sci021503.html. For additional information, see CRS Report RL31695, op. cit. It
has been reported that, according to an article published in 2003, “... the American Society of Microbiology (ASM)
flagged two out of fourteen thousand articles as unsuitable for publication, and both of these papers were likely to be
published after changes were made....(The Unintended Audience: Balancing Openness and Secrecy: Crafting an
Information Policy for the 21st Century, op. cit., p. 39).
180
Eugene Russo, “Biosecurity Advisory Board Considers Code of Ethics,” Research Policy Alert, July 6, 2005.
181
Shirley Haley, “Scientists Must Take Responsibility for Preventing Misuse of Their Work—Interacademy Panel,”
Research Policy Alert, Dec. 6, 2005. The document is “IAP Statement on Biosecurity,” Nov. 7, 2005.
182
Margaret A. Somerville and Ronald M. Atlas, “Ethics: A Weapon to Counter Bioterrrorism,” Science, Mar. 25,
2005, pp. 1881, 1882. The proposed code is: “In order to prevent the life sciences from becoming the death sciences
through bioterrorism or biowarfare, all persons and institutions engaged in all aspects of the life sciences must: “1.
Work to ensure that their discoveries and knowledge first do no harm: I) by refusing to engage in any research that is
intended to facilitate, or there is a high probability of its being used to facilitate bioterrorism or biowarfare, both of
which violate the fundamental moral values of humanity; and ii) by complying with the prohibition of the Biological
Weapons Convention to never, under any circumstances, knowingly or recklessly contribute to the development,
production or acquisition of microbial or other biological agents or toxins, whatever their origin or method of
production, of types or in quantities that cannot be justified on the basis of their being necessary for prophylactic,
protective, therapeutic, or other peaceful purposes. 2. Work for the ethical and beneficent advancement, development
and use of scientific knowledge. 3. Call to the attention of the public, or the appropriate persons or bodies, activities,
including unethical research, that there are reasonable grounds to believe are likely to contribute to bioterrorism or
biowarfare. 4. Take reasonable care to assure biosecurity by seeking to allow access to biological agents that could be
used as biological weapons only to individuals who there are reasonable grounds to believe will not misuse them. 5.
(continued...)
Congressional Research Service
34
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
be used in bioterrorism and would seek to restrict access of those they believe could use
information maliciously.
It was noted above in the section on “Nongovernmental Experts’ Recommendations To Use Risk
Analysis To Identify and Control Sensitive Information,” that proposals have been made to instill
in researchers a culture that discourages research that could be used malevolently, that
professional peer reviews should be conducted before publication of work that should be
protected, and that the federal government should define policy controls for these activities. In
addition, J. Gaudioso and R. M. Salerno proposed a biosecurity risk assessment process that
would restrict the use of agents that have the potential to be weaponized and that could serve as
the basis for international standards. This process would involve using
four Biosecurity levels: low, moderate, high, and extreme risk. The overwhelming majority
of pathogens and toxins would fall into the low-risk category (requiring practices such as
locking unattended laboratories and maintenance of documentation of agents used), and most
select agents would be placed in the moderate-risk category (requiring additional safeguards
such as access controls and personnel checks). The security measures for low-and moderaterisk categories should pose reasonable costs and largely rely on existing biosafety measures.
Very few agents would be designated high risk (requiring more stringent security measures
and a dedicated Biosecurity officer). Perhaps only variola major, because it is no longer
found in nature would be considered an extreme risk, requiring the most stringent protections
(such as comprehensive background investigations and an on-site guard force). Higher
security than that currently mandated by federal regulations would only be applied for those
very few agents that represent true weapon threats. Biosecurity levels should be developed
and vetted by experts in biological weapons, microbiology, security, and public and
agricultural health. This would help federal agencies apply uniform criteria to grantees and
could form the basis for standardizing biosecurity internationally.183
Brian J. Gorman proposed a risk-based alternative approach for prepublication peer review. He
called for a risk-based process called “Due Process Vetting System” (DPVS) together with “... a
Risk Assessment Scale [RAS] and a Least Restrictive Classification System for the
communication, assessment, and disposition of sensitive life science research in a manner
consistent with national security interests.”184 The process would be overseen by a new agency
(...continued)
Seek to restrict the dissemination of dual-use information and knowledge to those who need to know in cases where
there are reasonable grounds to believe that there are serious risks that information or knowledge could be readily
misused to inflict serious harm through bioterrorism or biowarfare. 6. Subject research activities to ethics and safety
reviews and monitoring to establish their ethical acceptability: I) to ensure that legitimate benefits are being sought and
that they outweigh the risks and harms; and ii) if human or animal subjects are involved, to ensure that such
involvement is ethical and essential for carrying out highly important research. 7. Abide by laws and regulations that
apply to the conduct of science unless to do so would be unethical, and recognize a responsibility to work through
relevant societal institutions to change those laws and regulations that are in conflict with ethics. 8. Recognize all
persons’ rights of conscientious objection to participation in research that they consider ethically or morally
objectionable and to refuse to participate without penalty. 9. Faithfully transmit the duties and obligations embodied in
this code, and the ethical principles upon which it is based to all who are, or may become, engaged in the conduct of
science.”
183
Jennifer Gaudioso and Reynolds M. Salerno, “Biosecurity and Research: Minimizing Adverse Impacts,” Science,
Apr. 30, 2004, citing J. Gaudioso and R. M. Salerno, “A Conceptual Framework for Biosecurity Levels,” BTR 2004:
Unified Science and Technology for Reducing Biological Threats and Countering Terrorism—Proceedings,
Albuquerque, NM, March 18-19, 2004.
184
Brian J. Gorman, “Balancing National Security and Open Science: A Proposal for Due Process Vetting,” Yale
Journal of Law and Technology, 2005, pp. 2, 15.
Congressional Research Service
35
“Sensitive But Unclassified” Information and Other Controls: Policy and Options
called the Biologic Regulatory Commission, modeled after the Nuclear Regulatory Commission.
The vetting process would be triggered at the request of an author or peer reviewer if an article
attained a predetermined score on the RAS set by the BRC. “The RAS surveys opinions of
informed reviewers including the author of the article, the author’s Institutional Review Board or
Institutional Biosafety Committee (IBC), and finally the journal interested in publishing the
article.”185 The DPVS would safeguard high-risk articles by providing the government with a
mechanism to identify “potentially dangerous articles before they reach the presses,”186 would
avoid the “deleterious effects of censorship,”187 and would make articles available only to a
“select academy of biodefense researchers after the authors, the publishing journal and others,
reach a consensus with the government through cooperative vetting of the article in question.”188
Gorman proposed expanding the academy to a
This text is long and has been trimmed here. Open the source document for the complete record.
This is a copy of a public record, reproduced as it was published. It is not legal advice, and it may not be the version a court would rely on. Check the official source before you cite it.