“Sensitive But Unclassified” Information and Other Controls: Policy and Options for Scientific and Technical Information

Congressional research reportDec 29, 2006

Ask Donna

What actually matters in this document.

Text

“Sensitive But Unclassified” Information and

Other Controls: Policy and Options for

Scientific and Technical Information

(name redacted)

December 29, 2006

Congressional Research Service

7-....

www.crs.gov

RL33303

CRS Report for Congress

Prepared for Members and Committees of Congress

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

Summary

Providing access to scientific and technical information (S&T) for legitimate uses while

protecting it from potential terrorists poses difficult policy choices. Federally funded, extramural

academic research is to be “classified” if it poses a security threat; otherwise, it is to be

“unrestricted.” Since the September 11, 2001 terrorist attacks, controls increasingly have been

placed on some unclassified research and S&T information, including that used to inform

decision making and citizen oversight. These controls include “sensitive but unclassified” (SBU)

labels; restrictive contract clauses; visa controls; controlled laboratories; and wider legal

restrictions on access to some federal biological, transportation, critical infrastructure, geospatial,

environmental impact, and nuclear information. Some professional groups have supported

voluntary controls on the conduct or publication of sensitive research. Federal agencies do not

have uniform definitions of SBU or consistent policies to safeguard or release it, raising questions

about how to identify SBU information, especially S&T information; how to keep it from

terrorists, while allowing access for those who need to use it; and how to develop uniform

nondisclosure policies and penalties. On December 16, 2005, President Bush instructed federal

agencies to standardize procedures to designate, mark, and handle SBU information, and to

forward recommendations for government-wide standards to the Director of National Intelligence

(DNI). The Information Sharing Environment Implementation Plan, sent to Congress in

November 2006, reports that final action will occur during the lst quarter of CY2006.

Following the 2001 terrorist attacks, the Bush Administration issued guidance that reversed the

Clinton Administration’s “presumption of disclosure” approach to releasing information under

Freedom of Information Act (FOIA) and cautioned agencies to consider withholding SBU

information if there was a “sound legal basis” to do so. Some agencies contend that SBU

information is exempt from disclosure under FOIA, even though such information per se is not

exempt under FOIA. The 2002 enactment of the Federal Information Security Management Act

(FISMA) rendered moot the definition of SBU that some agencies had used since the passage of

the Computer Security Act of 1987, which identified sensitive information by content. FISMA

requires agencies to categorize the criticality and sensitivity of all information according to the

security control objectives of confidentiality, integrity, and availability across a range of risk

levels and to use safeguards based on risk of release. Many federal agencies have not yet fully

implemented these new procedures. During the 109th Congress, P.L. 109-90 and P.L. 109-295

focused on management, oversight, and appropriate use of the sensitive security information

(SSI) category. Legislative proposals focused on standardizing concepts of “sensitive”

information; modifying penalties for disclosure; and clarifying FOIA. During the 110th Congress,

additional topics likely to be controversial include limiting the number of persons who can

designate SBU; widening the use of risk-based approaches to control; centralizing review,

handling, and appeals; and evaluating the impact of federal policies on nongovernmental

professional groups’ prepublication review and self-policing of sensitive research. This report will

be updated as necessary.

Congressional Research Service

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

Contents

Introduction to the Issues ............................................................................................................1

Summary of Federal Policies to Classify or Control Scientific and Technical Information............2

Policies for Classification of Research Information ...............................................................2

Controls on Nonclassified Academic and Industrial Research ................................................3

Export and Visa Controls ................................................................................................4

Policies To Control SBU Information ..........................................................................................8

Introduction to the Term “SBU” ............................................................................................8

Computer Security Act Definition of “Sensitive”...................................................................8

SBU in Relation to the Freedom of Information Act ..............................................................9

Department of Justice Broadens Interpretation of Exemptions From FOIA in 2003

and 2004 .................................................................................................................... 10

SBU Information Policies in the Homeland Security Act, P.L. 107-296, and

Subsequent Presidential Action ........................................................................................ 12

Requirements to Use Mandatory Minimum NIST-Generated Risk Standards To Protect

All Information ...................................................................................................................... 14

NIST’s Policies, Standards, and Documents ........................................................................ 16

A Formal Risk Analysis Process Is Not Required........................................................... 18

Nongovernmental Experts’ Recommendations to Use Risk Analysis to Identify and

Control Sensitive Information .......................................................................................... 19

Policies To Protect Specific Types of Sensitive Information Involving Scientific and

Technical Applications ........................................................................................................... 21

Critical Infrastructure Information Controls......................................................................... 22

Sensitive Security Information Controls: Transportation...................................................... 23

Critique of SSI Rules .................................................................................................... 25

Controls on Environmental Impact Information................................................................... 26

Critiques of Controls on Environmental Information ..................................................... 27

Illustration of Complexity of the Issue: the Nuclear Regulatory Commission

(NRC)........................................................................................................................ 29

Controls on Unclassified Biological Research Information .................................................. 30

National Science Advisory Board for Biosecurity .......................................................... 31

Views on Adequacy of Biosecurity Protection Policies .................................................. 33

Issues Dealing with Geospatial Information......................................................................... 38

The Department of Homeland Security’s SBU Directives .......................................................... 39

Contentious Issues, Together With Legislative Action and Other Options .................................. 41

Allegations That Some Controls Can Exacerbate Vulnerability and Stifle Scientific

Research and Technological Innovation............................................................................ 42

Critique of Nondisclosure Requirements ............................................................................. 44

Legislation Introduced Affecting Disclosure Policies..................................................... 45

SBU Information in Relation to FOIA................................................................................. 46

Congressional Action, to Clarify FOIA, with Implications for SBU ............................... 49

Federal Information Systems and Automated Identification Processes Used for

Sensitive Information ....................................................................................................... 51

Inconsistency in Agencies’ Processes To Identify SBU Information ..................................... 52

Activities Relating To Developing a Standard Definition of SBU Information ..................... 53

GAO Study on SSI........................................................................................................ 55

Congressional Research Service

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

P.L. 109-90 Requires DHS To Improve Use of SSI Categories and Report to

Congress .................................................................................................................... 56

P.L. 109-525 Limits Excessive Use of the SSI Label...................................................... 57

Studies and Hearings on SBU During 2006 ................................................................... 57

Legislation Introduced on “Pseudo-Classification” .............................................................. 58

Option To Monitor Agency Use of Risk-based Standards for Sensitive Unclassified

Information...................................................................................................................... 59

Recommendations to Institute Better Governance of SBU Information Procedures .............. 60

Limit the Number of Persons Who Can Designate SBU................................................. 60

Options To Centralize Policy Control for SBU Information ........................................... 61

An Appeals Process....................................................................................................... 62

Other Remaining Issues and Unanswered Questions............................................................ 63

Appendixes

Appendix A. Illustrations of Federal Agency Controls on Sensitive Information ........................ 64

Appendix B. Illustrations of Federal Information Systems Created to Transmit Sensitive

But Unclassified Information ................................................................................................. 74

Contacts

Author Contact Information ...................................................................................................... 77

Congressional Research Service

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

Introduction to the Issues

Federal agencies have long confronted the need to balance the release of information for public

use with the need to withhold information that could be used to threaten privacy or security. The

term “sensitive but unclassified” (SBU) information was used before the terrorist attacks of

September 11, 2001, even though there is no statutory definition for it. Since 9/11 more agencies

have started to use the term “SBU,” or some variant of it, and to implement security systems to

identify and protect nonclassified information whose release might benefit terrorists. Many

questions have been raised about how to design uniform policies and controls for SBU

information. This report focuses on controls for two kinds of scientific and technical

information—information used in research and scientific publication and information used to

serve broader public policy purposes, such as in regulatory decisionmaking and citizen oversight.

Both public and privately controlled information are included and in some respects, private

professional groups’ responses are being defined by public pressures and decisions.

Two divergent perspectives are discernable. From one perspective, broadening controls to deny

public access to federal SBU information will constrain terrorists, who might use it to threaten

buildings, infrastructure, people, and services. It has been estimated that “our adversaries derive

up to 80% of their intelligence from open-source information.”1 Another source put this at 90%,

referring to information about local energy infrastructures, water reservoirs, dams, highly

enriched uranium storage sites, and nuclear and gas facilities. Moreover, some say that the

potential for terrorism is heightened if terrorists can aggregate seemingly innocuous bits of public

information. 2 Although many agencies have begun to limit public access to sensitive information,

from this perspective, these efforts are inadequate.

In contrast to those who seek to widen controls, another view contends that inadequate and

insufficient sharing of information with the public and among first responders potentially

weakens efforts to protect the nation from terrorist attacks. A related perspective is that as

government policy on sharing information shifts to the “need to know” rationale that has become

more prevalent since the 9/11 terrorist attacks, the imposition of more controls will deny ordinary

citizens information relating to research, environmental protection, transportation, and so forth

that they need in order to be informed3 and to hold accountable government and industry

decisionmakers. Some say new control policies unduly limit access to information needed to

advance the progress of science and technology and the development of technologies to counter

threats, arguing that if scientific and technical information needs to be restricted, it should be

classified.

This report traces the evolution of SBU-related controls; summarizes actions taken to protect

certain types of scientific and technical information; describes critiques of some control policies;

and summarizes proposals and actions, including congressional, executive and other initiatives, to

1

In a document issued by the Pacific Northwest National Laboratory, a Department of Energy affiliated national

laboratory, in “F.A.Q. Mozart,” at http://www.pnl.gov/isrc/mozart/faq.html.

2

Greg Griffin, “Program Management Perspective: Sensitive Unclassified Information,” The Dragon’s Breath, April

2003.

3

The Final Report of the National Commission on Terrorist Attacks Upon the United States, July 22, 2004, (also called

The 9/11 Commission Report) encouraged the promotion of a “need-to-share” culture, as opposed to a “need-to-know”

culture of information protection, focusing on the development of a “trusted information network” to make information

more accessible. (Available at http://www.9-11commission.gov/report/911Report.pdf.)

Congressional Research Service

1

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

clarify these issues and develop policies that serve various stakeholders. It also raises issues that

may warrant further attention. 4

Summary of Federal Policies to Classify or Control

Scientific and Technical Information

Generally, pursuant to National Security Decision Directive 189 (NSDD-189), fundamental (basic

or applied) research conducted in universities is not to be labeled “classified” if does not affect

national security; it is therefore “unrestricted.”5 Nevertheless, as one commentator noted, “[T]he

federal government seems to possess wide latitude in declaring information, even purely

scientific research, classified or at least sensitive to prevent publication.”6

Policies for Classification of Research Information

If research does compromise national security, it may be classified pursuant to Executive Order

12958 and Executive Order 13292—the latter of which expanded the government’s ability to

classify some scientific and technical information to include information related to “defense

against transnational terrorism” (Section 1.4 of Executive Order 13292).7 During 2001 and 2002,

the heads of several federal agencies with substantial research responsibilities, who did not have

classification authority under Executive Order 12958, were given original classification authority.

These included the Secretaries of Health and Human Services8 and of Agriculture,9 the

4

This report updates CRS Report RL31845, “Sensitive But Unclassified” and Other Federal Security Controls on

Scientific and Technical Information: Background on the Controversy, by (name redacted), which described the

history of governmental controls on “sensitive unclassified information.”

5

National Security Decision Directive-189 (NSDD-189), titled “National Policy on the Transfer of Scientific,

Technical and Engineering Information” and issued on Sept. 21, 1985, says that if federally funded basic scientific and

technical information produced at colleges, universities and laboratories is to be controlled for national security

reasons, it should be classified. But, “... to the maximum extent possible, the products of fundamental research remain

unrestricted. It is also the policy ... that, where the national security requires control, the mechanism for control of

information generated during Federally funded fundamental research in science, technology, and engineering at

colleges, universities, and laboratories is classification.” “Fundamental research” is defined as “basic and applied

research in science and engineering, the results of which ordinarily are published and shared broadly within the

scientific community....” This policy is reflected in Executive Order 12958. NSDD-189 is still in effect, as stated in a

letter from the National Security Advisor to the Center for Strategic and International Studies (Issued by National

Security Advisor Condoleezza Rice on November 1, 2001).

6

Alexander J. Breeding, Sensitive But Unclassified Information: A Threat to Physical Security, SANS Institute, 2003,

p. 24.

7

Executive Order 12958, Apr. 17, 1995 (Federal Register, 60 FR 19825), permitted classification of “scientific,

technological, or economic matters relating to the national security” (Sec. 1.5). But Section 1.8 (b) prohibited

classification of “basic scientific research information not related to the national security.” Executive Order 13292,

Mar. 25, 2003, changed section 1.5 of Executive Order 12958 to permit classification of “scientific, technological, or

economic matters relating to the national security, which includes defense against transnational terrorism” (Sec. 1.4 (e)

of Executive Order 13292, Federal Register, Mar. 25, 2003). The amendment also added a new category of

information, concerning “weapons of mass destruction,” which may be classified (Sec. 1.4 (h)). The exemption for

basic scientific research not clearly related to national security remains (new Section 1.7).

8

“Order of December 10, 2001—Designation Under Executive Order 12958, Federal Register, Dec. 12, 2001, Vol. 66,

No. 239, pp. 64345-64347.

9

“Order of September 26, 2002—Designation Under Executive Order 12958,” Federal Register, Sept. 30, 2002, Vol.

67, No. 189, pp. 61463-61465.

Congressional Research Service

2

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

Administrator of the Environmental Protection Agency (EPA),10 and the Director of the White

House Office of Science and Technology Policy (OSTP).11 Also, pursuant to Executive Order

12958, federally funded researchers at any research-performing institution, including universities

and colleges, are obligated to report to the government information that they produce that should

be classified.12 In addition, the government may exercise prepublication reviews on some R&D

information, 13 and by writing into contracts control clauses for SBU or classified information.

Some R&D information is “born classified,” according to the Atomic Energy Act of 1946.14 In

addition, pursuant to the Information Security Act of 1951, certain patent information may be

classified if release would harm national security.15

Controls on Nonclassified Academic and Industrial Research

Academic and industrial researchers are also subject to sensitive information controls for

nonclassified information. Some of these are voluntary and self-imposed by researchers or

10

“Order of May 6, 2002—Designation Under Executive Order 12958,” Federal Register, May 9, 2002, Vol. 67, No.

90, p. 31109.

11

“Order of September 17, 2003—Designation Under Executive Order 12958,” Federal Register, Sept. 17, 2003, Vol.

68, No. 184, p. 55257.

12

“Most government grants for unclassified technical activity specify that if the grantee believes the results of the work

warrant classification, the grantee has the responsibility to limit the dissemination of that work and to contact the

appropriate U.S. government agency with the authority to classify it. In such extraordinary cases, the initiative to seek

classification rests with the grantee, not the government” (Security Controls on Scientific Information and the Conduct

of Scientific Research: A White Paper of the Commission on Scientific Communication and National Security,

Washington, D.C., Center for Strategic and International Studies, June 2005, pp. 5-6). For instance, according to

section 850 of the current version of the NSF Grant Policy Manual, NSF-02-151, July 2002, “Some basic research

information concerning, among other things, scientific, technological or economic matters relating to the national

security or cryptology may require classification. There may be cases when an NSF grantee originates information

during the course of an NSF-supported project that the grantee believes requires classification under E.O. 12958. In

such a case, the grantee has the responsibility to promptly 1. Submit the information directly to the government agency

with appropriate subject matter interest and classification authority or, if uncertain as to which agency should receive

the information, to the Director of the Information Security Oversight Office, GSA; 2. Protect the information as

though it were classified until the grantee is informed that the information does not require classification, but not longer

than 30 days after receipt by the agency with subject matter interest or by the GSA; and 3. Notify the appropriate NSF

program Officer.” The authority has to decide within 30 days whether to classify the information, and if it requires

classification, the “performing organization may wish or need to discontinue the project.” Dissemination of findings

may also be controlled.

13

The federal government exercises “prepublication review” of some privately published scientific and technical

information by current and former employees and contractors who worked for federal agencies and who had access to

classified information. The Defense Department (DOD) typically includes “prepublication review” clauses in

government contracts for extramural research. These controls are used if classified information was used in research or

when the government seeks to prohibit release of information deemed sensitive because of the way it is aggregated.

Beginning in 1980, all academic cryptography research is to be submitted on a voluntary basis for pre-publication

review to the National Security Agency. The U.S. government may enter into contracts to purchase exclusive rights to

commercial satellite imagery and may stop the collection and dissemination of commercial satellite imagery for

national security reasons. (For additional information, see CRS Report RL31845, op. cit. and CSIS, Security Controls

on Scientific Information, June 2005, op. cit., pp. 13-14.)

14

See CRS Report RL31845, op. cit.

15

Pursuant to 35 U.S.C. 181-188. See CRS Report RL31845 for additional information. According to OMBWatch’s

report, Secrecy Report Card 2005: Quantitative Indicators of Secrecy in the Federal Government, a report by Open the

Government.Org. Americans for Less Secrecy, More Democracy, Washington, D.C., 2005, the number of secrecy

orders imposed on new patents rose from 83 in 2001 to 124 in 2004, and the number of secrecy orders in effect

increased from 4,736 in 2001 to 4,885 in 2004 (p. 5) However, it is likely that most of these were recommended by,

and issued to, federal agencies for their own government-owned technical information.

Congressional Research Service

3

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

professional societies and publishers. For instance, in the early 1940s basic physics research in

fission was voluntarily withheld from publication by a leading journal, Physical Review, because

of fears that publication of research results would benefit German atomic energy research. After

the war ended the results were published. However, reportedly, foreign scientists, especially

Soviet scientists, deduced that the absence of research publications on the topic meant that

Americans “were pursuing an atomic bomb” and started their own inquiries on this subject.16

More recently, some researchers have initiated voluntary controls on the conduct and/or

publication of sensitive research in biological sciences fields that might assist terrorists. (For

additional details, see the section below entitled “Controls on Unclassified Biological Research

Information.”) In addition, the directors of the Department of Homeland Security’s (DHS) six

academic centers of excellence have developed draft guidelines “to control the dissemination of

sensitive information generated by their research”17—which is in the fields of agricultural,

chemical, biological, nuclear and radiological, cyber terrorism, and the behavioral aspects of

terrorism.

There are also formal government-mandated controls. For instance, pursuant to sections 3235 and

3295(c) of the National Defense Authorization Act for FY2000,18 the Department of Energy

(DOE) released regulations, effective August 18, 2006, that require all users of DOE computers,

including persons who e-mail a DOE computer, to give the department written permission for

investigators to check any DOE computer accessed by that person for up to three years in the

future. The regulation applies to all information, including classified and sensitive but

unclassified, and other types.19 Reportedly, the required paperwork might prove to be costly to

some researchers.20

The federal government also mandates controls on contract research. For instance, the issue of

federal agency research contracts with universities imposing prepublication review clauses was

addressed in an April 2004 report, Restrictions on Research Awards: Troublesome Clauses,

released by the Association of American Universities, in cooperation with the Council on

Government Relations. It detailed 138 instances of restrictions placed on publications or other

prohibitions on foreign nationals as preconditions for receiving research awards. The report

opposed the practice, recommended that federal agencies adhere to the mandates of NSDD-189,

and concluded that governmental restrictions were not compatible with university research.

Export and Visa Controls

Export control regulations generally do not apply to the conduct of fundamental research as long

as it is ordinarily published and shared broadly within the scientific community. However, export

control regulations and International Traffic in Arms Control regulations (ITAR) permit the

government to require licensing for the export, or “deemed export,” of certain scientific and

technical information to specific foreign countries or citizens of those countries working in the

16

Chelsa Wald, “Landmarks: The Physical Review’s Explosive Secret,”Oct. 26, 2004.

17

Yudhijit Bhattacharjee, “Scientific Openness; Should Academics Self-Censor Their Findings on Terrorism?,”

Science, May 19, 2006, 993-994.

18

50 U.S.C. 2425, 2483(c).

19

“Computer Security; Access to Information on Department of Energy Computers and Computer Systems,” Final

Rule, Federal Register, July 19, 2006, pp. 40880-40866.

20

Yudhijit Bhattacharjee, “DOE Tightens Monitoring of Lab Collaborators,” Science, Sept. 1, 2006, p. 1218.

Congressional Research Service

4

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

United States21 on university campuses or in industrial laboratories. During 2004 and 2005,

considerable controversy arose22 over the publication of two Inspector General reports,23 one

from the Department of Defense (DOD) and the other from the Department of Commerce (DOC).

They proposed strict adherence to government interpretations that, even if the research being

conducted is fundamental, the operation, technical training, installation, maintenance, repair,

overhaul, or refurbishing of commercially available equipment used in the research is a “deemed

export” that requires an export license for certain foreign researchers. This would be for

equipment as common as fermenters and global positioning system (GPS) locators and would

apply to students from China, Russia, India, and other countries on lists of countries that pose

national security threats. In a notice of a proposed rule published in the Federal Register on

March 28, 2005,24 the DOC recommended that country of birth rather than of citizenship or

permanent residence be used as the criterion for determining nationality for deemed export

controls. DOD’s proposed rules, which would require badging, training, and segregated work

areas for eligible researchers and exclusion of others, were published in July 2005, when the

comment period began.25

21

Both the Export Administration Act (50 U.S.C. App. 2401-2420) (6) and the Arms Export Control Act (22 U.S.C.

2751-2794) provide authority to control the dissemination to foreign nationals, both in the United States and abroad, of

scientific and technical data related to items requiring export licenses according to the Export Administration

Regulations (EAR) or the International Traffic in Arms Regulations (ITAR). Both laws give agencies authority to

regulate the export of technical data. ITAR controls the release of defense articles specified on the U.S. Munitions List

(22 CFR 121) and technical data directly related to them. EAR, among other things, controls the export of dual-use

items (items that have both civilian and military uses) on the Department of Commerce Control List (15 CFR Part 774)

and technical data related to them. The implementing regulations are administered by the Department of Commerce,

which licenses items subject to EAR, and by the Department of State, which licenses items subject to ITAR and the

Munitions List of items. Fundamental research, but not all activities related to the conduct of such research, is excluded

from ITAR and EAR. ITAR generally treats the disclosure or transfer of technical data to a foreign national, whether in

the United States or abroad, as an export. According to ITAR regulations, publicly available scientific and technical

information and academic exchanges and information presented at scientific meetings are not treated as controlled

technical data. Nevertheless, there has been considerable ambiguity and confusion regarding these provisions because

of uncertainties about which research projects might not be excluded because they use space or defense articles,

technologies, and defense services on the Munitions List that is used to identify technologies requiring export licensing.

The Export Administration regulations categorize as “deemed exports” communications both to foreign nationals about

technologies characterized as “sensitive” and to countries identified as “sensitive” under EAR rules. Under language in

a rule issued in March 2002, the State Department exempted U.S. universities from obtaining ITAR licenses for export

of certain space-based fundamental research information or articles in the public domain to certain universities and

research centers in countries that are members of the North Atlantic Treaty Organization (NATO), the European Union,

and the European Space Agency, or to major non-NATO allies, such as Japan and Israel. Also to be permitted are

exports of certain services and unclassified technical data for assembly of products into scientific, research, or

experimental satellites. In addition, collaborators in approved countries would have to guarantee that researchers from

non-approved countries were not receiving restricted information. (For sources and additional information, see CRS

Report RL31845, op. cit.) GAO critiqued the procedures DOC and DOD use to identify and implement export control

decisions in: two recent reports, DOD’s Critical Technologies Lists Rarely Inform Export Controls and Other Policy

Decisions, July 2006, GAO-06-793 and Improvements to Commerce’s Dual-Use System Needed to Ensure Protection

of U.S. Interests in the Post-9/11 Environment, June 2006, GAO-06-638.

22

“Controls on ‘Deemed Export’ May Threaten Research,” Secrecy News, May 2, 2005.

23

U.S. Department of Commerce, Office of Inspector General, Bureau of Industry and Security, Deemed Export

Controls May Not Stop the Transfer of Sensitive Technology to Foreign Nationals in the U.S., Final Inspection Report

No. OPE-16176, March 2004, 54 p. Interagency Review of Foreign Nationals Access to Export-Controlled Technology

in the United States, Vol. 1, April 2004, Report D-20004-062, 33 p.

24

“Revision and Clarification of Deemed Export Related Regulatory Requirements,”Advanced Notice of Proposed

Rulemaking, Federal Register, Mar. 28, 2005, vol. 70, no. 58, pp. 15607-15609.

25

“Defense Federal Acquisition Regulation Supplement: Export-Controlled Information and Technology, Proposed

Rule With Request for Comments, Federal Register, July 12, 2005, vol. 70, no. 132, p. 39977.

Congressional Research Service

5

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

Subsequently, some university officials argued that expanded interpretations of rules for “deemed

export” licenses may be unnecessary.26 Other members of the academic community cite problems

in administering use controls, including ambiguity about identifying which equipment or material

in university laboratories is subject to export controls; discrimination on the basis of nationality;

difficulty in controlling access of students and researchers in university laboratories; time

required to obtain licenses and inflexibility in obtaining licenses;27 modest security benefits;

slowing or preventing important discoveries due to licensing delays; loss of research talent if

students and researchers study in other countries; and reduction in research at the leading edge of

science.

The three presidents of the National Academies [of Science, Engineering, and the Institute of

Medicine] opposed such controls in a letter to DOC Secretary Carlos M. Guitierrez, June 16,

2005, and made several recommendations, including the proposal to “[c]lear international

students and postdoctoral fellows for access to controlled equipment when their visas are issued

or shortly thereafter so that their admission to a university academic program is coupled with

their access to use of export controlled equipment.” One policy group recommended an

alternative approach: to require a deemed export license for “transfers of technology to

specifically identified individuals if specific adverse information exists about that individual.”28

In a 2005 report prepared at congressional request, a National Academies panel recommended

providing all foreign students and researchers engaged in fundamental research with access

comparable to that provided to U.S. citizens and permanent residents and to remove “... all

technology items (information and equipment) from the deemed-export technology lists that are

available for purchase on the overseas open market from foreign or US companies or that have

manuals that are available in the public domain, in libraries, over the Internet, or from

manufacturers.”29 The National Foreign Trade Council and other related technology groups also

have opposed these rules.30 Others charge universities would have to pay “... millions of dollars to

inventory sensitive equipment, determine students’ birthplaces and study which foreigners were

using which machines.”31

In January 2006, a DOC spokesman said that because of comments received on the proposed rule,

DOC would modify its procedure and base controls not on country of birth, but on a foreign

national’s most recent country of citizenship or permanent residency. 32 DOC also established a

26

Security Controls on Scientific Information, June 2005, op. cit., p. 7.

27

For instance, see rationale detailed in CSIS, Security Controls on Scientific Information, June 2005, op. cit. pp. 9-12,

and American Civil Liberties Union, Science Under Siege: The Bush Administration’s Assault on Academic Freedom

and Scientific Inquiry, Written by Tania Simoncelli with Jay Stanley, June 2005, 35 p., which also summarizes reports

and the views of the academic community, pp. 9-13.

28

CSIS, Security Controls on Scientific Information, June 2005, op. cit , p. 12.

29

The National Academies, Rising Above the Gathering Storm: Energizing and Employing America for a Brighter

Economic Future, Executive Summary, 2005, p. 6. See also reports of NAS workshops in May and Sept. 2005, Eugene

Russo, “DoD Export Controls Rule Should Not Apply to Fundamental Research, Officials Say,” Research Policy Alert,

Sept. 23, 2005; “National Academies, Societies Criticize on DoD’s Proposed Export Control Rule,” Research Policy

Alert, Oct. 18, 2005.

30

Danielle Belopotosky, “Techies Challenge Planned Changes On ‘Deemed Exports,’” Technology Daily, June 24,

2005.

31

Scott Shane. “Universities Say New Rules Could Hurt U.S. Research,” New York Times, Nov. 26, 2005.

32

Statement of Peter Lichtenbaum, Assistant Secretary of Commerce for Export Administration at a conference at the

National Academies at which the author of this report was present. See also Kelly Field, “Commerce Department Will

Drop Some But Not All Restrictions on Foreign Researchers, Colleges Are Told,” Chronicle of Higher Education, Jan.

17, 2006. The official announcement is “Revisions and Clarification of Deemed Export Related Regulatory

(continued...)

Congressional Research Service

6

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

committee to examine its rules further. 33 Responding to complaints received during the comment

period, DOD modified its proposed rules with a new proposal published on August 14, 200634

that said it would withdraw the prescriptive identification requirements proposed in July, but

would continue to require researchers to adhere to existing export control rules of the Commerce

and State Departments. Final comments were due by October 13, 2006.

As for other controls to deter terrorism, more governmental scrutiny has been used to review and

issue visas for foreign researchers and students, and more items have been placed on the

Technology Alert List (TAL), which is now classified. The State Department uses the TAL to

identify academic and technical subjects that are viewed as sensitive; foreign students proposing

to study these subject undergo extra visa scrutiny under the Visas Mantis program.35 The State

Department also has tightened entry/exit registration of foreign students and scholars and tracks

their activities in an effort to deter terrorism. These actions may have prohibited the entry of

potential terrorists, but some critics allege that they have reduced the number of foreign students

studying science and technology in the United States36 and increased the number of foreign

students studying in other countries.37 This, they say, portends not only erosion of the U.S. market

share of worldwide Higher education, but also a reduction in the number of new U.S. scientific

and technical personnel.38

In 2004, the federal government proposed rules declaring that American scientists could not

collaborate with, and American publishers could not edit works authored by, scientists in nations

that are targets of trade embargoes, including Iran, Sudan, Libya, Cuba, and North Korea. Most

scientific societies opposed these proposals39 on the grounds that they reduced the intellectual

freedom of those in other countries and hampered international science. Subsequently, the

administering agency, the U.S. Treasury Department’s Office of Foreign Assets Control (OFAC),

decided to permit editing and peer review, but continued to prohibit collaboration between U.S.

scholars and researchers in a sanctioned country. 40

(...continued)

Requirements,” Federal Register, May 31, 2006, vol. 71, no. 104, pp. 30840-30844.

33

Jeffrey Brainard, “Defense Department Shelves Proposal to Increase Restrictions on Foreign Students,” Chronicle of

Higher Education, Aug. 15, 2006.

34

“Defense Federal Acquisition Regulation Supplement; Export-Controlled Information and Technology (DFARS

Case 2004—D010),” Federal Register, vol. 71, No. 156, Aug. 14, 2006, pp. 46434-46441.

35

Science Under Siege, op. cit., pp. 14-15.

36

Molly Laas, “Senate Science Committee to Consider Easing Immigration For Foreign Students,” Research Policy

Alert, Nov. 21, 2005; Marjorie J. Censer, “Visa Problems May Damage U.S. Science, Groups Warn,” American

Association of University Professors, Sept./Oct. 2004. See also: U.S. GAO, Border Security: Streamlined Visas Mantis

Program Has Lowered Burden on Foreign Science Students and Scholars, but Further Refinements Needed, GAO-05198, Feb. 2005.

37

Science Under Siege, op. cit., pp. 16-20 and Alison Abbott, “Europe Revamps Visa Rules to Attract World’s Best

Minds,” Nature, Oct. 27, 2005. See also American Association of University Professors, Report by Special Committee

on Academic Freedom and National Security in a Time of Crisis, Nov./Dec. 2003.

38

See, for example, “Difficulties for Foreign Scientists in Coming to the United States,” Science, July 14, 2006, p. 169.

39

One that did not is the American Institute of Aeronautics and Astronautics. See Yudhijit Bhattacharjee, “Society Bars

Papers From Iranian Authors,” Science, June 17, 2005.

40

Science Under Siege, op. cit., pp. 10-11, and Yudhijit Bhattacharjee, “Scientific Publishing: Editing No Longer

Infringes U.S. Trade Sanctions,” Science, Dec. 24, 2004.

Congressional Research Service

7

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

Policies To Control SBU Information

The history through 2002 of using the label SBU was described in detail in CRS Report

RL31845, “Sensitive But Unclassified” and Other Federal Security Controls on Scientific and

Technical Information: Background on the Controversy and is summarized briefly in this section,

which also updates action through February 15, 2006.

Introduction to the Term “SBU”

Federal agencies began to use the term “SBU” in the 1970s,41 but the term has never been defined

in statutory law. Starting in 1987 and continuing today, when using the term “sensitive

information,” some agencies refer to the definition for sensitive information that was used in the

Computer Security Act of 1987, P.L. 100-235,42 and to information exempt from disclosure in the

Freedom of Information Act (FOIA)43 and the Privacy Act, as amended.44

Computer Security Act Definition of “Sensitive”

The Computer Security Act of 1987 (CSA) was intended to protect the security and privacy of

sensitive unclassified information in federal computer systems and the systems themselves. P.L.

100-235 defined the term “sensitive” information as

any information, the loss, misuse, or unauthorized access to or modification of which could

adversely affect the national interest or the conduct of Federal programs, or the privacy to

which individuals are entitled under section 552a of title 5, United States Code (the Privacy

Act), but which has not been specifically authorized under criteria established by an

Executive order or an Act of Congress to be kept secret in the interest of national defense or

foreign policy” (Section 3).

Because P.L. 100-235 applied to “sensitive information” that was not classified, some say it

defined “sensitive but unclassified.” Pursuant to the CSA, federal agencies were responsible for

protecting such “sensitive” information and for developing plans to secure it “commensurate with

the risk and magnitude of the harm resulting from the loss, misuse, or unauthorized access to or

modification of the information being protected.”45 The CSA, among other things, required

agencies to develop security plans for systems containing sensitive information. It authorized the

National Bureau of Standards (NBS), now called the National Institute of Standards and

Technology (NIST), to create a security-oriented standards program. The definition of “sensitive

information” was placed within the section that listed NBS’s functions, and subsequently NIST

became responsible when the agency’s name was changed in 1988. In 1992, NIST issued

guidance giving agencies authority to implement risk-based procedures to protect sensitive

41

Interview with CRS specialist Harold Relyea, December 2005.

101 Stat. 1724-1730, 40 U.S.C 1441.

43

5 U.S.C. 552, as amended by P.L. 104-231, 110 Stat. 3048.

44

The Privacy Act of 1974, 5 U.S.C. Section 552a , as amended.

45

U.S. Congress, House, Committee on Science and Technology, Computer Security Act of 1987, Report to

Accompany H.R. 145, June 11, 1987, pp. 30-31.

42

Congressional Research Service

8

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

information pursuant to P.L. 100-235. NIST reiterated that “[i]nterpretation of the CSA’s

definition of sensitive is, ultimately, an agency responsibility.” It identified three security goals:

Typically, protecting sensitive information means providing for one or more of the

following: Confidentiality: disclosure of the information must be restricted to designated

parties; Integrity: The information must be protected from errors or unauthorized

modification; Availability: The information must be available within some given time frame

(i.e., protected against destruction).”46[Emphasis added.]

Although it was not mandatory, NIST urged agency information owners to use a risk-based

approach to identify information to be protected and controls needed based on risk of loss:

The type and amount of protection needed depends on the nature of the information and the

environment in which it is processed. The controls to be used will depend on the risk and

magnitude of the harm resulting from the loss, misuse, or unauthorized access to or

modification of the information contained in the system.47

SBU in Relation to the Freedom of Information Act

Predating the CSA, the Freedom of Information Act of 1966 (FOIA) was enacted to ensure public

access to certain types of information held by federal agencies. However, it permits agencies to

exempt from public disclosure nine types of information:

(1) information classified in the interest of national defense or foreign policy,

(2) internal personnel rules and practices of an agency,

(3) information specifically exempted from disclosure by statute,

(4) trade secrets and commercial or financial information obtained from a person and

privileged or confidential,

(5) inter-agency or intra-agency memoranda or letters reflecting predecisional attitudes,

(6) personnel and medical files and similar files the disclosure of which would constitute a

clearly unwarranted invasion of personal privacy,

(7) specified types of law enforcement records or information,

(8) financial institution regulation or supervision reports, and

(9) geological and geophysical information and data concerning wells.48

The CSA,49 the report accompanying it, 50 and NIST guidance51 included explicit instructions that

categorizing information as “sensitive” did not confer authority to withhold information sought

46

National Institute of Standards and Technology, “Advising Users on Computer System Technology,” CSL Bulletin,

Nov. 1992 http://nsi.org/Library/Compsec/sensitiv.txt.

47

“Advising Users on Computer System Technology,” Nov. 1992, op. cit.

48

5 U.S.C. 552.

49

According to P.L. 100-235, “Sec. 8. ... Nothing in this Act, or in any amendment made by this Act, shall be construed

(continued...)

Congressional Research Service

9

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

pursuant to Section 552 of Title 5, United States Code [the Freedom of Information Act].

Nevertheless, as will be discussed below, some federal agencies say that all information

categorized as For Official Use Only (FOUO) or in related categories is SBU, or that all SBU

information may be withheld under FOIA.

Department of Justice Broadens Interpretation of Exemptions From FOIA in

2003 and 200452

After the terrorist attacks of September 2001, the White House and the Department of Justice, in a

series of administrative actions, expanded agencies’ ability to withhold SBU information. To

prevent potential use of sensitive information by terrorists, in March 2002, the White House

issued the so-called “Card memo,” which required agencies to examine their information

holdings and policies; withhold information, including “sensitive but unclassified” information;

and use FOIA exemptions if there was a sound legal basis to do so. Attorney General John

Ashcroft’s prior memorandum of October 2001 on this issue was referenced. These statements

modified the previous Administration’s policy, which urged agencies to release information if

there was no “foreseeable harm” in doing so. 53

(...continued)

(1) to constitute authority to withhold information sought pursuant to Section 552 of title 5, United States Code; or (2)

to authorize any Federal agency to limit, restrict, regulate, or control the collection, maintenance, disclosure, use,

transfer, or sale of any information (regardless of the medium in which the information may be maintained) that is (A)

privately-owned information; (B) disclosable under section 552 of title 5, United States Code, or other law requiring or

authorizing the public disclosure of information; or (C) public domain information.”

50

The report accompanying the legislation said specifically, “The designation of information as sensitive [or as subject

to protection] under the Computer Security Act is not a determination that the information is not subject to public

disclosure” (H.Rept. 100-153, Part I, June 11, 1987).

51

The guidance said, “The Computer Security Act did not alter the Freedom of Information Act (FOIA); therefore, an

agency’s determination of sensitivity under this definition does not change the status of releaseability under the FOIA”

(“Advising Users on Computer System Technology,” op. cit.)

52

For detailed information, see CRS Report RL31845, op. cit.

53

The White House memo, signed by Chief of Staff Andrew Card, entitled “Action to Safeguard Information

Regarding Weapons of Mass Destruction and other Sensitive Documents Related to Homeland Security,” Mar. 19,

2002, required agencies to examine their policies and holdings in accord with accompanying memos issued by the

National Archives and Records Administration’s (NARA) Information Security Oversight Office (ISOO) and the

Department of Justice’s Office of Information and Privacy (OIP). The purpose was to determine if information should

be classified or handled as sensitive but unclassified information that could be “misused to harm the security of our

Nation and the safety of our people” and report their review to the White House. The accompanying memo included a

section titled “sensitive but unclassified information,” which instructed agencies to consider all applicable FOIA

exemptions before releasing “sensitive information related to America’s homeland security”(SHSI) (“Safeguarding

Information Regarding Weapons of Mass Destruction and Other Sensitive Records Related to Homeland Security,”

Memorandum for Departments and Agencies, from Laura L.S. Kimberly, ISOO, NARA, and Richard L. Huff, and

Daniel J. Metcalfe, OIP, Dept. of Justice, “Safeguarding Information Regarding Weapons of Mass Destruction and

Other Sensitive Records Related to Homeland Security,” Mar. 19, 2002). Agencies were referred to guidance that had

been issued by Attorney General Ashcroft in Oct. 2001 that instructed agencies, when undertaking discretionary

disclosure determinations under FOIA (agencies can make their own discretionary decisions about whether to disclose

information even if it falls within one of the nine FOIA exemption categories) to consider using broad interpretations of

the FOIA exemptions because of the need for heightened security in the wake of the 9/11 attacks (“New Attorney

General FOIA Memorandum Issued,” FOIA Post, Oct. 15, 2001, including “Memorandum for Heads of all Federal

Departments and Agencies, From: John Ashcroft, Attorney General, Subject: The Freedom of Information Act, Oct. 15,

2001”). The memo instructed agencies to interpret FOIA exemption two broadly to permit withholding of a document

that if released would allow circumvention of an agency rule, policy or statute, thereby impeding the agency in the

conduct of its mission. (See U.S. Department of Justice, Freedom of Information Act Guide and Privacy Act Overview,

(continued...)

Congressional Research Service

10

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

Subsequently in 2003, the Department of Justice (DOJ) issued guidance based on court decisions

that broadened interpretation of exemptions from disclosure under FOIA.54 It also discussed the

new exemption three provision of P.L. 107-296, the Homeland Security Act of 2002, which

protects voluntarily submitted critical infrastructure information. The Freedom of Information Act

Guide, 2004, explained how an agency’s ability to restrict the release of “sensitive” information

via FOIA would be broadened; and, citing the September 11, 2001, attacks, the passage of P.L.

107-296, and the creation of the Department of Homeland Security (DHS), cautioned vigilance

on releasing “sensitive” information:

These changes have greatly impacted many aspects of the operation of the federal

government, including the administration of the FOIA. Much greater emphasis is now placed

on the protection of information that could expose the nation’s critical infrastructure,

military, government, and citizenry to an increased risk of attack. As a result of these

changes, federal departments and agencies should carefully consider the sensitivity of any

information the disclosure of which could reasonably be expected to cause national security

harm.55

The Guide reiterated, however, that use of labels such as SBU, SHSI, and so forth does not

“provide for any protection from disclosure under any [FOIA] exemption ...” [except for critical

infrastructure information (CII), which is protected by statute]. Nevertheless, the Guide

encouraged agencies to exempt from disclosure information labeled “SHSI” or other

nonclassified information that is highly sensitive, as referenced in the aforementioned court

decisions and in Homeland Security Presidential Directive HSPD-7, issued on December 22,

2003:

[W]hatever the safeguarding label that an agency might (or might not) use for the

information maintained by it that has special sensitivity—e.g., “for official use only”

(FOUO), “restricted data” (a Department of Energy designation), or “sensitive homeland

security information” (SHSI)—whenever predominantly internal agency records may reveal

(...continued)

May 2002, ed., pp. 16-17, 124-127 and CRS Report RL31547, Critical Infrastructure Information Disclosure and

Homeland Security, by (name redacted) and (name redacted).) In the predecessor memorandum issued by Attorney General

Janet Reno in 1993, agencies were encouraged to release documents, even if the law provided a way to withhold

information, if there was no “foreseeable harm” from doing do.

In 2002 and 2003, the House oversight committee on FOIA, the Committee on Government Reform, called the

Attorney General’s October 2001 memorandum into question and specifically rejected its standard to allow the

withholding of information sought under FOIA whenever there is merely a “sound legal basis” for doing so. The

committee directed agencies to withhold documents only in those cases when the agency reasonably foresees that

disclosure would be harmful to an interest protected by an exemption (A Citizen’s Guide on Using the Freedom of

Information Act and the Privacy Act of 1974 to Request Government Records, 107th Cong., 2nd sess. H.Rept. 107-371,

2002, p. 3; and in a report with the same title, 108th Congress, 1st sess., 2003, H.Rept. 108-172).

54

On June 25, 2003 officials from the DOJ’s Office of Information and Privacy and from the National Security Council

held a closed conference that was summarized on the DOJ website. (U.S. Department of Justice,”FOIA Officers

Conference Held on Homeland Security,” FOIA Post, July 3, 2003 http://www.usdoj.gov/oip/foiapost/

2003foiapost25.htm). Among other things, it reviewed several court cases in 2003 that allowed agencies to use national

security considerations, other than those defined in FOIA exemption 1, to withhold information of possible use to

terrorists. These included one that allowed the U.S. Customs Service to use exemption 2 to deny information on

inspections of seaport operations (Coastal Delivery Corp. v. U.S. Customs Service, decided Mar.17, 2003, by the U.S.

District Court in Los Angeles), and another to allow withholding under exemption 7 (e) of “inundation maps”that had

been compiled as law enforcement records and showed flood area below Hoover and Glen Canyon dams (Living

Rivers, Inc., v. the U.S. Bureau of Reclamation, Mar. 25, 2003. by the U.S. District Court in Salt Lake City).

55

FOIA Guide, 2004 Edition, Exemption one, http://www.usdoj.gov/oip/foi-act.htm.

Congressional Research Service

11

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

information the disclosure of which could reasonably be expected to cause any of the harms

described above [to critical systems, facilities, stockpiles, and other assets], responsible

federal officials should carefully consider the propriety of protecting such information under

Exemption 2.56

SBU Information Policies in the Homeland Security Act, P.L. 107296, and Subsequent Presidential Action

The Homeland Security Act, P.L. 107-296, signed on November 25, 2002, defined homeland

security information as “any information possessed by a Federal, State or local agency that (A)

relates to the threat of terrorist activity; (B) relates to the ability to prevent, interdict, or disrupt

terrorist activity; (C) would improve the identification or investigation of a suspected terrorist or

terrorist organization; or (D) would improve the response to a terrorist act.”57 The law, among

other things, required agencies to develop information-sharing systems to transmit classified or

unclassified information and to share it with appropriate recipients, including those at the state

and local levels. It also recognized the use of nondisclosure agreements for sharing sensitive but

unclassified information with state and local personnel. Section 892, as amended, 58 required the

President to “prescribe and implement procedures” for federal agencies to “identify and safeguard

sensitive homeland security information that is sensitive but unclassified,” [now abbreviated

SHSI] and to prescribe procedures to share this information with other federal agencies and

appropriate state and local personnel (required by section 892 (a) (1) (A)(B) of P.L. 107-296). In

Executive Order 13311, July 29, 2003, the President transferred some of these functions to the

Department of Homeland Security Secretary, to be carried out in consultation with other

governmental officials.59 The President is still mandated to prescribe procedures for federal

agencies. Section 893 of the law had required the President to report to specified congressional

committees about implementation of section 892 and any recommendations for additional

measures to “increase the effectiveness of sharing of information between and among Federal,

State, and local entities.” According to that report60 and other documents, 61 in 2004, DHS was

preparing the guidance to identify and protect sensitive but unclassified SHSI. In its report to

Congress, DHS wrote that the procedures it was developing

will provide guidance on identifying SHSI by defining SHSI, establishing uniform

procedures for identifying and marking SHSI, and delineating entities with which it may be

properly shared. The procedures will aid in safeguarding SHSI by establishing uniform

minimum standards for the secure handling of sensitive information designated as SHSI, in a

manner consistent with existing law. Lastly, the procedures will help to facilitate the sharing

of SHSI with appropriate Federal, state and local users, while also protecting it from

56

FOIA Guide, 2004 Edition, Exemption Two.

6 U.S.C. 482 (f).

58

Amended by Section 316 of the Intelligence Authorization Act for Fiscal Year 2004, P.L. 108-177, Section 316, 117

Stat. 2599, 2610-11 (2003). This section mandates that DHS develop a training program for state and local officials to,

among other things, improve their ability to identify and report threat information.

59

Executive Order 13311, Federal Register, July 29, 2003, pp. 45149-45150. The President retained responsibility to

“ensure that such procedures apply to all agencies of the Federal Government....”

60

Report Pursuant to Section 893, not dated but reportedly sent to the committee chairmen in February 2004, op. cit.

61

U.S. Department of Justice,” FOIA Officers Conference Held on Homeland Security,” FOIA Post, July 3, 2003,

http://www.usdoj.gov/oip/foiapost/2003foiapost25.htm.

57

Congressional Research Service

12

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

unwarranted public disclosure that could result in reduction of the ability of Federal, State,

and local authorities to protect against threats to our homeland security. 62

The referenced guidance had not been issued as of November 14, 2006, and, before being made

final, was to have been sent to the Office of Management and Budget for release and a period of

public comment.63 In a related development, on December 16, 2005, the President issued a

memorandum to federal agencies, “Guidelines and Requirements in Support of the Information

Sharing Environment,” that included requiring agencies to standardize procedures “for

designating, marking, and handling SBU information ... across the Federal Government” in order

to promote both appropriate, consistent safeguarding and sharing of information.64 Within 90 days

agencies were to inventory specific SBU information procedures, determine the authority for each

entry, assess the effectiveness of procedures, and report to the Director of National Intelligence

(DNI), who is to provide the results to the Secretary of Homeland Security and the Attorney

General. Within a year, the DNI in coordination with specific department and agency heads is to

submit recommendations to the President through the DNI for government-wide standards for all

SBU information. The Program Manager for the Information Sharing Environment is to support

executive departments and agencies implementation, as well as in the development of relevant

guidance and training programs for the standardized SBU procedures.

According to a news report, an interagency group has been working on this issue. But federal

agencies have not yet agreed upon which SBU-related labels to use and which to give up.

Furthermore state and local officials apparently have disagreed about which labels should be

retained. Reportedly, in June 2006, the Department of Justice and the Department of Homeland

Security

... delivered a 36-page report recommending that the group continue its efforts to settle on a

new system. (In a small sign of progress, they also urged agencies to stop creating new

labels, according to one intelligence official.) The White House concluded that the proposal

lacked substance and told the two agencies to try again, the official said.65

Similarly,

According to Aftergood, the report [which was then pending] “... set forth principles upon

which SBU policy should be based, but stops short of the crucial task of defining exactly

how those principles ought to be implemented, government officials said. One of those

principles is that each type of control on unclassified information should have a uniform,

public and government-wide definition so that it is employed the same way by all

agencies.”66

Testimony on this issue was heard at a hearing held on May 10, 2006. (See below in the section

labeled “Studies and Hearings on SBU During 2006.”)

62

Report Pursuant to Section 893, 2004, op. cit., p. 5.

Interview with OMB officials, Nov. 10, 2004.

64

Information Sharing Guideline 3 http://www.fas.org/sgp/news/2005/12/wh121605-memo.html.

63

65

Siobhan Goirman, “Turf War Hampers War on Terror: Justice, Homeland Security’s Failure to Agree on semantics

Hinders Information Sharing,” Baltimore Sun, July 13, 2006.

66

“Agencies Pursue Standardized Policy for ‘Sensitive’ Info,” Secrecy News, July 12, 2006.

Congressional Research Service

13

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

In November 2006, the Program Manager for the Information Sharing Environment issued a

report entitled, Information Sharing Environment Implementation Plan. Chapter 10 described

creation of an interagency coordinating committee which plans to issue guidelines and

recommendations for SBU standardization during the lst quarter of CY2007.

Requirements to Use Mandatory Minimum NISTGenerated Risk Standards To Protect All

Information

As noted above, the Computer Security Act of 1987 (CSA) authorized the Department of

Commerce’s NBS (and then its successor, NIST) to develop standards and guidelines for federal

agencies to protect sensitive information on federal computer information systems. The act

defined sensitive information that was not classified. (For a definition, see the section above

entitled “Computer Security Act Definition of “Sensitive””.) Under the CSA, agencies could

obtain a waiver not to use the standards.

The CSA provisions were modified with passage of the Federal Information Security Act of 2002,

(FISMA), P.L. 107-347, December 2002.67 While CSA required the development of standards to

protect sensitive information, FISMA required the development of standards to protect all

information, and did not refer to sensitive information when mandating development of standards.

It rewrote the section of the NIST act that required development of standards for sensitive

information, and had used the CSA definition of “sensitive” information (15 U.S.C. 278g-3). The

law replaced aspects of the CSA, including the definition of “sensitive” information because the

definition was considered static and unresponsive to changing information systems

environments.68 FISMA also deleted specific requirements to inventory information systems that

contained sensitive information.69 These actions, in essence, rendered the definition moot. Also,

under FISMA, agencies may no longer obtain a waiver to not use the standards developed by

NIST.

67

FISMA clarified and changed some provisions of the Government Information Security Reform Act (GISRA), which

was part of the Floyd D. Spence National Defense Authorization Act of FY2001 (Div. A, Title X, Subtitle G, sec.

1061-1065, P.L. 106-398, Oct. 30, 2000). While GISRA expanded NIST’s functions regarding developing risk-based

standards, it would have sunseted in 2002 and did not, like FISMA, render moot the definition of sensitive as used in

CSA. See U.S. Congress, House, Committee on Government Reform, E-Government Act of 2002. H.Rept. 107-787,

Part 1, 107th Congress, 2nd sess., Nov. 14, 2002, pp. 54-61. Specifically, according to the report, “the purpose of

FISMA is to permanently authorize a government-wide risk-based approach to information security by eliminating

GISRA’s two-year sunset, and to further strengthen Federal information security by requiring compliance with

minimum mandatory management controls for securing information and information systems, clarifying and

strengthening current management and reporting requirements, and strengthening the role of National Institute of

Standards and Technology (NIST)” (p. 54).

68

This was described in the House Committee on Government Reform report on the amended version of the bill that

was enacted, H.Rept. 107-787, part I, op. cit., describing section 303 of what eventually became P.L. 107-347.

69

Section 305 of P.L. 107-347 repealed section 6 of the CSA, which required the identification of systems containing

sensitive information and the development of systems security plans, which, according to the legislative report

accompanying the bill that was enacted, “is unnecessary given the overall scheme and specific requirements for agency

risk-based management of information and information systems supporting agency operations and assets” (H.Rept.

107-787, pt. 1. p. 87. See also CRS Report RL31057, A Primer on E-Government: Sectors, Stages, Opportunities, and

Challenges of Online Governance, by (name redacted)).

Congressional Research Service

14

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

Specifically, section 303 of P.L. 107-347 updated NIST’s mission in light of new understandings

relating to information security and required NIST, in consultation with other agencies, including

OMB, the National Security Agency, the Government Accountability Office (GAO), and the

DHS, to develop risk-based standards to categorize “the criticality and sensitivity of agency

information according to information security control objectives and across a range of risk levels”

and to develop minimum information security requirements for each information category. Under

FISMA, the standards NIST was directed to develop and the Secretary of Commerce to

promulgate, are to be issued by the Director of OMB in consultation with the Secretary of

Homeland Security70 as mandatory minimum federal information processing standards (FIPS)

that agencies and their contractors must use to protect all nonclassified information and

information systems based on a range of risk levels. 71 FISMA is silent on defining “sensitive” or

the relationship between the act and SBU or the sensitive homeland security information referred

to in section 892 of the Homeland Security Act of 2002, P.L. 107-296.

FISMA also clarified management and reporting, strengthened NIST’s role and responsibilities,

and consolidated statutory information security requirements. The OMB is required by FISMA to

authorize formally and accredit each agency’s nonsecurity information system as established by

the information security plan. (Responsibility for certification of national security information

systems is shared between DOD and the Central Intelligence Agency.) The three security

objectives—confidentiality, integrity, and availability—that NIST has used in previous guidance

are to continue to guide NIST in its development of standards (116 STAT. 2947, P.L. 107-347,

title III, paragraph 301), although these concepts were broadened from the way NIST originally

used them in 1992 to read:

The term “information security” means protecting information and information systems from

unauthorized access, use, disclosure, disruption, modification, or destruction in order to

provide—(A) integrity, which means guarding against improper information modification or

destruction and includes ensuring information nonrepudiation and authenticity; (B)

confidentiality, which means preserving authorized restrictions on access and disclosure,

including means for protecting personal privacy and proprietary information; and (C)

availability, which means ensuring timely and reliable access to and use of information (Sec.

301 of P.L. 107-347).

The law also allows agencies to develop more stringent standards than those generated by NIST,

since it—

70

OMB, in consultation with the Secretary of Homeland Security, has responsibility under FISMA to issue the

standards and guidelines developed by NIST (40 U.S.C. 11331 (b) (1) (A)) and promulgated by the Secretary of

Commerce. In addition, OMB manages the federal acquisition regulation (FAR). It is to be updated to include the

information security requirements of FISMA, so that new agency contracts for information systems would reflect them.

(U.S. GAO, Information Security: Improving Oversight of Access to Federal Systems and Data by Contractors Can

Reduce Risk, April 2005, GAO-05-362.p. 3.) See also, U.S. GAO, Information Security: Weaknesses Persist at Federal

Agencies Despite Progress Made in Implementing Related Statutory Requirements, July 2005, GAO-05-552.

71

Specifically, Title III of FISMA requires, “(b) Minimum requirements for standards and guidelines. The standards

and guidelines required by subsection (a) of this section shall include, at a minimum—(1) (A) standards to be used by

all agencies to categorize all information and information systems collected or maintained by or on behalf of each

agency based on the objectives of providing appropriate levels of information security according to a range of risk

levels; (B) guidelines recommending the types of information and information systems to be included in each such

category; and (C) minimum information security requirements for information and information systems in each such

category ....” (U.S. Code, Title 15, Chapter 7, Section 278g-3. Computer standards program, i.e., 15 U.S.C. 278g-3).

Congressional Research Service

15

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

preserves the provision in current law (at 40 U.S.C 11331(c) permitting agencies to use more

stringent standards than provided by NIST-developed standards, but only if those more

stringent standards incorporate applicable mandatory NIST requirements and are otherwise

consistent with the risk management policies and guidelines issued by OMB under 44 U.S.C.

3533.72

NIST’s Policies, Standards, and Documents

The risk analysis procedures and information systems controls specified by NIST have been

developed iteratively, incorporating public comments since the end of 2002. Several reports

constitute the NIST documentation standards and two are core, that is FIPS Publication 199 and

FIPS Publication 200. NIST had anticipated publishing all documentation by the statutory

deadline of December 2005 when implementation was to become mandatory,73 but the final

document in the series, dubbed FIPS Publication 200, was delayed a few months until March

2006.74 Agencies are to use NIST’s guidance documents and risk management procedures to

categorize federal information and information systems and to determine security protection

levels for them based on level of risk. 75

The first core document, Federal Information Processing Standards (FIPS) 199, Standards for

Security Categorization of Federal information and Information Systems, commonly called FIPS

199, issued in final form in February 2004, provides a common framework, method, and

mandatory standards for agencies to use to identify information to protect (that is not governed by

national security controls) according to the potential impact of loss. FIPS 199 enables “...

agencies to identify and prioritize their most important information and information systems by

defining the maximum impact a break in confidentiality, integrity, or availability would have on

the agency’s operation, assets, and/or individuals.”76 It establishes a continuum of “criticality and

sensitivity” for information dependent upon agency requirements and priorities. The potential

minimum impact value (low, moderate, or high77) on the compromise of a security objective is the

highest value (i.e., high-water mark) for security categories for each type of information on the

system. 78

72

Paragraph (a) (3) of section 302, according to H.Rept. 107-787, pt. 1, p. 84.

William Jackson, “FISMA Guidance Nearly Complete,” Government Computer News, Oct. 26, 2005.

74

National Institute of Standards and Technology, Minimum Security Requirements for Federal Information and

Information Systems, Federal Information Processing Standards Publication, FIPS Pub 200, March 2006.

75

Based in part on Ron Ross, “FISMA Implementation Project; Protecting the Nation’s Critical Information

Infrastructure; An Overview,” Slide Show, Version 1.4.

76

Shirley Radack, ITL Bulletin, Mar. 2004, p. 1.

77

“... [L]ow [or limited], moderate [having a serious adverse effect], or high [severe or catastrophic adverse] impact for

the three security objectives of confidentiality, integrity (including authenticity and non-repudiation), and

availability”(Ron S. Ross, Computer Security Division, NIST, “The New FISMA Standards and Guidelines. Changing

the Dynamic of Information Security for the Federal Government,” [2003], p. 2. For additional details, see NIST,

Standards for Security Categorization of Federal Information and Information Systems, FIPS Publication 199, Dec.

2003, pp. 1-3).

78

As an example “... A power plant contains a SCADA (supervisory control and data acquisition) system controlling

the distribution of electric power for a large military installation. The SCADA system contains both real-time sensor

data and routine administrative information. The management at the power plant determines that (I) for the sensor data

being acquired by the SCADA system, there is no potential impact from a loss of confidentiality, a high potential

impact from a loss of integrity, and a high potential impact from a loss of availability; and (ii) for the administrative

information being processed by the system, there is a low potential impact from a loss of confidentiality, a low

potential impact from a loss of integrity, and a low potential impact from a loss of availability. The resulting security

(continued...)

73

Congressional Research Service

16

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

FIPS Publication 200, Minimum Security Requirements for Federal Information and Information

Systems, the second of the mandatory security standards documents, specifies minimum security

requirements for information and information systems supporting the federal agencies and a riskbased process for selecting the security controls necessary to satisfy the minimum security

requirements. This standard is intended to establish minimum levels of due diligence for

information security and to facilitate a more consistent, comparable, and repeatable approach for

selecting and specifying security controls for information systems that meet minimum security

requirements.

NIST Special Publication 800-60, Guide for Mapping Types of Information and Information

Systems, issued in final version in June 2004,79 is intended to help agencies identify their

information types and systems and to assign impact levels for confidentiality, integrity, and

availability for them for a range of risk levels. The impact levels are based on the security

categorization guidelines in FIPS Publication 199.80 Special Publication 800-60 gives agencies

explicit guidance on developing impact standards for each of the three risk categories for all types

of information and information systems handled by federal agencies (based on OMB’s Federal

Enterprise Architecture Program Management Office’s publication, The Business Reference

Model Version 2.0). Agencies are given guidance to determine impact levels for information in

fields such as public health, environmental management, energy, and general sciences and

innovation, including research and development. Thus the high-water mark, or highest value

category for security impact (and thus minimum security categorization) for both “Scientific and

Technical Research and Innovation Information” and for “Research and Development

Information,” is moderate.81 Examples of minimum security categories for some other types of

information are environmental remediation information, moderate;82 pollution prevention and

control, low;83 and health care services, high. 84 Each explanation describes circumstances,

including homeland security and national security-related implications, that agencies could

identify to raise the threshold level of security controls for each type of information.

When agencies need to evaluate the levels of protection for information, they are to undertake a

risk assessment using threat and vulnerability analysis that incorporates local conditions and then

(...continued)

categories, SC, of these information types are expressed as: SC sensor data = {(confidentiality, NA),(integrity, HIGH),

(availability, HIGH)}, and SC administrative information = {(confidentiality, LOW), (integrity, LOW), (availability,

LOW)}. The resulting security category of the information system is initially expressed as: SC SCADA system =

{(confidentiality, LOW), (integrity, HIGH), (availability, HIGH)}, representing the high water mark or maximum

potential impact values for each security objective from the information types resident on the SCADA system. The

management at the power plant chooses to increase the potential impact from a loss of confidentiality from low to

moderate reflecting a more realistic view of the potential impact on the information system should there be a security

breach due to the unauthorized disclosure of system-level information or lineprocessing functions. The final security

category of the information system is expressed as: SC SCADA system = {(confidentiality, MODERATE), (integrity,

HIGH), (availability, HIGH)}.” (FIPS 199.)

79

William C. Barker, Volume 1: Guide for Mapping Types of Information and Information Systems to Security

Categories, NIST Special Publication 800-60, Version 2.0, June 2004, pp. 21-22. William C. Barker and Annabelle

Lee, NIST, Information Security, Volume II: Appendixes to Guide for Mapping Types of information and Information

Systems to Security Categories, June 2004, 295 pages.

80

Barker, Volume 1, NIST Special Publication 800-60, June 2004, op. cit., pp. 21-22.

81

NIST Special Publication 800-60, op. cit., pp. 217-218.

82

NIST Special Publication 800-60, op. cit., pp. 154-155.

83

NIST Special Publication 800-60, op. cit., p. 120.

84

NIST Special Publication 800-60, op. cit., p. 120.

Congressional Research Service

17

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

adjust their security controls using NIST publication SP 800-30.85 An agency is to identify the

minimum information security requirements (i.e., management, operational, and technical

controls) for information and information systems in each such category as identified in

document 800-53, that is Recommended Security Controls for Federal Information Systems,

February 2005. NIST identified 17 types of security control clusters to guide selection of

minimum security controls (i.e., safeguards and countermeasures) to protect information and

information systems and 154 uniquely identified controls (i.e., management, operational, and

technical security controls) for information and information systems in each category. These

include access control; awareness and training; audit and accountability; certification,

accreditation, and security assessments; configuration management; contingency planning;

identification and authentication; incident response; maintenance; media protection; physical and

environmental protection; planning; personnel security; risk assessment; systems and services

acquisition; system and communications protection; and system and information integrity.86

A Formal Risk Analysis Process Is Not Required

OMB’s apparent operative guidance for information security protection, Appendix III of OMB

Circular A-130,87 cautions agencies that they do not need to conduct expensive, formal risk

analyses to fulfill these requirements. Specifically, Appendix III to OMB Circular A-130 says that

OMB

no longer requires the preparation of formal risk analyses. In the past, substantial resources

have been expended doing complex analyses of specific risks to systems, with limited

tangible benefit in terms of improved security for the systems. Rather than continue to try to

precisely measure risk, security efforts are better served by generally assessing risks and

taking actions to manage them. While formal risk analyses need not be performed, the need

to determine adequate security will require that a risk-based approach be used. This risk

assessment approach should include a consideration of the major factors in risk management:

the value of the system or application, threats, vulnerabilities, and the effectiveness of

current or proposed safeguards. Additional guidance on effective risk assessment is available

in “An Introduction to Computer Security: The NIST Handbook” (March 16, 1995).88

While NIST recognizes this dictum, it seems that little information is available about how

agencies make decisions to categorize information in response to NIST standards.89

85

Risk Management Guide for Information Technology Systems, Recommendations of the National Institute of

Standards and Technology, by Gary Stoneburner, Alice Goguen, and Alexis Feringa, NIST, SP 800-30, July 2002.

86

NIST, Recommended Security Controls for Federal Information Systems, Special Publication 800-53, Appendix D

and Appendix F.

87

OMB Circular A-130, Appendix III, “Security of Federal Automated Information Resources,” to “OMB Circular A130, Transmittal Memorandum #4, Management of Federal Information Resources (11/28/2000),” requires agencies

and their contractors to maintain programs that provide adequate security for all information collected, processed,

transmitted, stored, or disseminated in general support systems and major applications” (http://www.whitehouse.gov/

OMB/circulars/a130/a130appendix_iii.html).

88

Appendix III, to OMB Circular A-130, 11/28/2000, op.cit.

89

Interviews with officials at NIST and GAO.

Congressional Research Service

18

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

Nongovernmental Experts’ Recommendations to Use Risk Analysis

to Identify and Control Sensitive Information

Nongovernmental experts have recommended using various types of risk-based processes to

identify, categorize, and develop controls for sensitive information involving science and

technology, and other kinds of information control.90 For instance, the use of risk analysis figured

prominently at the November 21, 2005 meeting of the National Science Advisory Board for

Biosecurity (NSABB) in discussions related to developing criteria for a code of conduct for

researchers, identification of code violations, and development of appropriate consequences. Risk

analysis has also figured in NSABB discussions about developing a process and time schedule to

vet and communicate dual-use research while it is being conducted and before publication, and

about determining the consequences of public release.91 (For more information about NSABB,

see in the section below entitled “National Science Advisory Board for Biosecurity.”) Others have

also proposed using risk-based models to handle sensitive scientific and technical information.

These are discussed next.

Jacques S. Gansler and William Lucyshyn proposed that criteria be developed, and that an

executive order be issued, that identifies “controlled unclassified security information (CUSI),”

consisting of CII and SHSI, whose improper release by government or academic/scientific

institutions “... could egregiously endanger public safety.”92 The objective “... for both

government-funded and privately-funded research is to create a culture that frowns on the

research, experimentation, and publication of CUSI, much like the culture that constrains certain

experimental techniques, such as stem-cell research, and restrains others, such as human

cloning.”93 A risk-based process called a “‘Work-Factor’ for Leveraging Dangerous

Information”—the amount of resources needed to use the information for harmful purposes—

would be used to determine risk of release:

When information that could threaten the public safety is easily accessible—that is, when the

costs of obtaining it are low and the convenience of using it is relatively high—this “workfactor” for leveraging potentially harmful information provides a benchmark for determining

90

Horizontal Integration: Broader Access Models for Realizing Information Dominance is a report prepared by the

Defense Department JASON advisory group for the Under Secretary for Defense Research and Engineering,

Horizontal Integration: Broader Access Models for Realizing Information Dominance, JASON Program Office,

MITRE, JSR-04-132, Dec. 2004, p. 1. The report focused on the goal of enabling “information dominance [in]

warfare” and concluded that more information should flow directly to military personnel in the field, who might not

always have clearance levels required to handle classified information or sensitive information, which is

“....increasingly defined by the eye of the beholder”(pp. 4, 24-30). The report recommended using an information

system based on “... transactional risk—that is the chance that any given transaction will be compromised, rather than

on assigning a level of classification to a document based on the potential damage caused by disclosure” (Shaun

Waterman, “Report: Govt Secrecy Hurting War Fighters,” UPI, Dec. 15, 2004).

91

The archived webcast of the Nov. 21, 2005 meeting is available at http://videocast.nih.gov/ram/od112105.ram. See

also, Andrew J. Hawkins, “National Biosecurity Panel Lays Groundwork for Identifying Dual-Use Research,”

Research Policy Alert, Nov.22, 2005; Andrew J. Hawkins, “Success of Scientist Code of Conduct Hinges On

Education, Biosecurity Board Hears,” Research Policy Alert, Nov.23, 2005; and Eugene Russo, “Biosecurity Advisory

Board Reports Lessons Learned From 1918 Flu Papers, Aims to Improve Screening Process,” Research Policy Alert,

Nov. 23, 2005.

92

Jacques S. Gansler and William Lucyshyn, The Unintended Audience: Balancing Openness and Secrecy: Crafting an

Information Policy for the 21st Century, Center for Public Policy and Private Enterprise School of Public Policy,

University of Maryland, Sept. 2004, pp. 27, 32.

93

The Unintended Audience: Balancing Openness and Secrecy, op. cit., pp. 38-39.

Congressional Research Service

19

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

whether information should be controlled. While high-level descriptions of and mitigations

for vulnerabilities should be released to inform and alert the public, “push-button” or

“cookbook” instructions on how to do harm are easily identifiable and clearly should be

withheld. The amount of resources, including the number of knowledgeable personnel,

needed to exploit vulnerabilities describes a work-factor, which is a good, practical indicator

of where disclosure borders on weaponization.94

The report recommended that with respect to “public sector information,” a policy embodying

CUSI would “enable the sharing of sensitive materials between departments and agencies at the

federal, state, and local levels, as well as with those in the private sector with a need to know,”95

and would ensure “... that similar information produced in different agencies is identified and

protected in the same way” and that FOIA and CUSI guidelines are not in conflict.”96 DHS, it was

recommended, should develop educational programs, government controls, and voluntary

restraints to prevent the disclosure of information that should not be released.97 Governmentdefined policy controls should extend to publicly funded private researchers and DHS, assisted by

NSF and NIH and other agencies, should issue guidance to privately funded researchers.

Professional peer reviews would be conducted before publication of work that might meet criteria

for safeguarding. Specifically, 98

[f]ederally-funded researchers should disclose potential security concerns in their grant

proposals. DHS monitored review panels will assess the security implications of the work

with potentially significant negative impact in accordance with established guidelines. DHS

should lead the effort to develop model review policies, encouraging non-federally-funded

researchers to adopt them and to submit their work to the government-monitored review

panel or an independent, government-certified review panel. DHS should also train

publishers to conduct reviews just before research is made available to serve as a safety net

after research is already completed, and publishers should implement a two-tiered

publication scheme to restrict detailed content to premium access where the credentials of the

readers can be verified.99

94

The Unintended Audience: Balancing Openness and Secrecy, op. cit., pp. 40-42. The following illustrations were

given “[f]or potential low-impact events, the most serious threats are those that are highly convenient and extremely

low cost.... Typically, these threats cause a high level of disruption and/or annoyance. An example of such a threat

would be contaminating food with bacteria, similar to the 1984 case where members of a religious cult sprayed

salmonella bacteria on salad bars throughout the Oregon region, causing 751 cases of food poisoning.... For a potential

medium-impact event, those threats that are high in cost and low in convenience warrant the least amount of concern....

Information on agents that when directly applied to fields would decrease crop yield without completely destroying the

harvest might fall into this category. It would be difficult to deliver such agents, and decreasing the yield for some

crops in the United States might succeed only in reducing the surplus. Nearly all of the threats of a potential highimpact event should be considered serious, and information related to these threats should be controlled.... A grey area,

where information would have to be carefully evaluated, forms when costs are high and convenience is low. For

example, information on how to create vaccines for highly-communicable diseases could fall into this category, as the

method for creating vaccines now in use first increases the virulence of normal diseases and then finds inhibitors to

block or antibodies to combat the strongest variants of the diseases. Increasing controls significantly could slow the

development of preventive measures, which, in the end, might cause more harm than good” (The Unintended Audience:

Balancing Openness and Secrecy, op. cit., pp. 43-44).

95

The Unintended Audience: Balancing Openness and Secrecy, op. cit.,p. ii, p. 33.

96

The Unintended Audience: Balancing Openness and Secrecy, op. cit., p. 33.

97

The Unintended Audience: Balancing Openness and Secrecy, op. cit., p. 44.

98

The Unintended Audience: Balancing Openness and Secrecy, op. cit., p. 45.

99

The Unintended Audience: Balancing Openness and Secrecy, op. cit., pp. ii-iii.

Congressional Research Service

20

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

Brian J. Gorman proposed a risk-based alternative approach for prepublication peer review. He

called for a risk-based process called “Due Process Vetting System” (DPVS) together with “... a

Risk Assessment Scale [RAS] and a Least Restrictive Classification System for the

communication, assessment, and disposition of sensitive life science research in a manner

consistent with national security interests.”100 The aforementioned reports proposed that

researchers should self-evaluate the sensitivity of their work and that self-imposed professional

association or governmental constraints, including classification, be imposed if the information

could be weaponized and if the consequences of its use were high risk, but that such information

should be communicated among those with a “need to know.”101 (This proposal and others for

institutional or governmental bodies to review and approve biological sciences research plans or

publications are discussed below in the section “Controls on Unclassified Biological Research

Information.”)

Mobilizing Information to Prevent Terrorism: Accelerating Development of a Trusted Information

Sharing Environment, a report by the Markle Foundation Task Force on National Security in the

Information Age, examined how to reconcile national security needs with civil liberties

requirements. 102 It sought to redress problems with “current classification procedures” that

frequently are “a barrier to effective information sharing because they overemphasize the risks of

inadvertent disclosure over those of failure to share information.”103 Among other things it

proposed use of a “risk management” approach to classification that balances the risks of

inappropriate disclosure with the risks of failing to share information.

Policies To Protect Specific Types of Sensitive

Information Involving Scientific and Technical

Applications

Specific laws have been enacted and policies and procedures are in varying stages of

implementation that define and protect sensitive unclassified science- and technology-related

100

Brian J. Gorman, “Balancing National Security and Open Science: A Proposal for Due Process Vetting,” Yale

Journal of Law and Technology, 2005, pp. 2, 15.

101

The Unintended Audience: Balancing Openness and Secrecy, op. cit., pp. 39-40. See also J. Gaudioso and R. M. “A

Conceptual Framework for Biosecurity Levels,” BTR 2004: Unified Science and Technology for Reducing Biological

Threats and Countering Terrorism—Proceedings, Albuquerque, NM, March 18-19, 2004, p. ii. As an illustration:

“Restricting research and development must rely on constraining knowledge rather than forbidding it. For example,

such restrictions would control research into the engineering of viral factors that introduce animal pathogens into

humans but would not prohibit it, categorically. Production refers to the ways in which information can be weaponized,

or leveraged against the public. As such, production restraints should entail issues similar to ways of refining anthrax

and ways of enriching uranium. Although information about weapons programs would be classified, scientific “knowhow” that may be—as in the case of bioweapons—only one step away from implementation generally would not be

classified. Employment refers to final-stage delivery. For example, issues of employment may refer to detailed

schematics on the briefcases used in the Tokyo sarin gas attacks or plans for maximizing the radiological contamination

from a “dirty bomb” (Gaudioso and Salerno, op. cit., Mar. 18-19, 2004, p. 28).

102

Zoe Baird, James Barksdale, chairmen, Mobilizing Information to Prevent Terrorism: Accelerating Development of

a Trusted Information Sharing Environment, Third Report of the Markle Foundation Task Force, 2006, Markle

Foundation, New York City, 93 p.

103

Markle Foundation, “Markle Task Force on National Security in the Information Age Releases Third Report,

‘Mobilizing Information to Prevent Terrorism: Accelerating Development of a Trusted Information Sharing

Environment,’ “Press Release, July 13, 2006.

Congressional Research Service

21

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

information in such fields as critical infrastructure, transportation, environmental impacts,

biology, geospatial data, and DHS information. These and criticisms that have been made about

them are summarized next.

Critical Infrastructure Information Controls

The need to protect critical infrastructure information is based on the premise that potential

terrorists should not have access to information that might expose vulnerabilities in, or provide

roadmaps to, the nation’s core physical transportation, water, communication, energy, and related

systems, or to major buildings, bridges, and other major structures. As an example of critical

infrastructure vulnerabilities, Charlie Reeder, Interagency Operations Security Support Staff,

DOD, and part of a Pentagon group that represents the National Security Agency, Central

Intelligence Agency, Federal Bureau of Investigation, DOD, General Services Administration,

and Department of Energy (DOE), is reported to have said that “‘... he’s seen government

websites include maps of installations ... specifications of weapons and communications systems

... and much more. ... When we publish this information on the Internet, we might as well fax it

directly to our adversaries ...’”104 He also commented that “‘According to a message sent by

Secretary of Defense Donald Rumsfeld ... an al Qaeda training manual recovered in Afghanistan

states ‘using public sources openly and without resorting to illegal means, it is possible to gather

at least 80 percent of information about the enemy.’” Open-source information can be accessed

through Internet sites, job announcements, budget documents, and newsletters.105 Similarly, a

survey by Computerworld noted that “the widespread availability of sensitive information on

corporate websites appears to have been largely overlooked by IT and security managers....”106

Among the information available on the Web are “3-D models of the exterior and limited portions

of the interior of the Citigroup headquarters building in Manhattan—one of the sites especially

named in the latest terror advisory issued by the Department of Homeland Security,” and various

similar kinds of information about the building’s structural design weaknesses.

In part to cope with issues like these, the “Critical Infrastructure Information Act of 2002,” Title

II of P.L. 107-296, prohibits disclosure under FOIA of “critical infrastructure information” (CII)

relating to the security of critical infrastructure and protected systems submitted to DHS

voluntarily by private companies. 107 Criminal penalties for disclosure by employees under this

statute include fines, dismissal, or imprisonment for up to a year (Section 214).108 The statute also

provides for the preemption of state freedom of information laws regarding the public disclosure

of such information if it is shared with a state or local government official in the course of DHS’s

activities. 109 The DOD issued a memo on March 25, 2003, that applied prohibitions like those in

P.L. 107-296 to critical infrastructure information voluntarily submitted to DOD.110 On April 15,

104

Stephen Larsen, “Secure Sensitive Unclassified Information,” Pentagram, Nov. 28, 2003

http://www.dcmilitary.com/army/pentagram/8_47/commentary/26442-1.html.

105

Larsen, op. cit.

106

“Too Much Info on Websites,” SAP Info, Sept. 8, 2004.

107

Sections 211-215 of P.L. 107-296, codified as 6 U.S.C. 131-134, define the term “critical infrastructure

information” to mean information not customarily in the public domain and related to the security of critical

infrastructure or protected systems. For rules, see 6 C.F.R. 29.1 and 6 C.F.R. 29.2.

108

For additional analysis, see CRS Report RL31547, op. cit.

109

See also “Homeland Security Law Contains New Exemption 3 Statute,” FOIA Post, Jan. 27, 2003.

110

Memo from H.J. McIntyre on “FOIA Requests for Critical Infrastructure Information,” described in Steven

Aftergood, “DOD on Critical Infrastructure Info,” Secrecy News, Apr. 29, 2003, and “Efforts Made to Expand Critical

(continued...)

Congressional Research Service

22

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

2003, DHS published interim rules to implement the critical information infrastructure protection

provisions of P.L. 107-296, which would extend the rules to other agencies by requiring them to

pass to DHS similar information that they receive.111 On December 17, 2003, President Bush

issued Homeland Security Presidential Directive 7 (HSPD-7), which among other things, directed

all federal agencies to protect voluntarily submitted information about critical infrastructure

vulnerabilities in line with Title II of P.L. 107-296.

The DHS published an interim final rule that established the “Protected Infrastructure Information

(PCII) Program,” effective February 18, 2004, with public comments allowed until May 20,

2004.112 The rules were amended and issued in a final regulation entitled “Procedures for

Handling Protected Critical Infrastructure Information,” on September 1, 2006.113 The procedures

govern the receipt, validation, handling, storage, marking, and use of critical infrastructure

information voluntarily submitted to the Department of Homeland Security and apply to all

federal, state, local, and tribal government agencies and contractors that have access to, handle,

use, or store critical infrastructure information.

CII information submitted to DHS is not subject to disclosure under FOIA, under an exemption

three category, established pursuant to section 214 of the Homeland Security Act of 2002,114 if it

has not been made public previously.115 The language in P.L. 107-296 protects only CII submitted

to the DHS, but the Department of Justice reports that in the future, it may be applied to

submissions made to other federal agencies. 116 (For additional information, see CRS Report

RL33670, Protection of Security-Related Information, by (name redacted) and (name redacted).)

Sensitive Security Information Controls: Transportation

Both the Department of Agriculture (USDA) and the Transportation Security administration

(TSA) use the term “sensitive security information” (SSI). The use of the term in transportation is

discussed in this section.117 The Federal Aviation Administration (FAA) had been permitted since

(...continued)

Infrastructure Information,” OMB Watcher, May 5, 2002.

111

“6 CFR Part 29, Procedures for Handling Critical Infrastructure Information; Proposed Rule, Department of

Homeland Security,” Federal Register, Apr. 15, 2003, pp. 18523-18529. For additional information, see CRS Report

RL30153, Critical Infrastructures: Background, Policy, and Implementation, by (name redacted).

112

The implementing regulations are contained in the Code of Federal Regulations (6 CFR Part 29). See also

Department of Homeland Security, “DHS Launches Protected Critical Infrastructure Information Program to Enhance

Homeland Security, Facilitate Information Sharing,” Press Release, Feb. 18, 2004, and attached information sheet

“Protected Critical Infrastructure Information (PCII) Program.” See the Federal Register, Feb. 20, 2004, pp. 80738089. Comments are posted on the DHS website. See also Lucy A. Dalglish and Gregg P. Leslie, Homefront

Confidential: How the War on Terrorism Affects Access to Information and the Public’s Right to Know, fifth ed., 2004,

pp. 70-71.

113

Federal Register, vol. 71, no. 170, Sept. 1, 2006, pp. 52261-52277.

114

6 U.S.C.A. section 133. See the memo on “Critical Infrastructure Information Regulations Issued by DHS,” FOIA

Post, Feb. 27, 2004, http://www.usdoj.gov/oip/foiapost/2004foiapost6.htm, Leslie, op. cit., and CRS Report RL30153,

op. cit.

115

DHS press release, Feb. 18, 2004, op. cit.

116

“Critical Infrastructure Information Regulations Issued by DHS,” op. cit. 2004.

117

For a discussion of usage in USDA and TSA, see Appendix A to this report. See also: CRS Report RL33494,

Security Classified and Controlled Information: History, Status, and Emerging Management Issues, by (name red

acted).

Congressional Research Service

23

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

passage of the Air Transportation Security Act of 1974118 to issue regulations to protect, and to

distribute to those with a “need to know,” sensitive civil aviation security information that was

obtained during security investigations or consisted of research and development information that

would invade privacy, would reveal a trade secret or financial or commercial information, or

would be detrimental to the safety of persons traveling by air. “The FAA implemented this

authority by promulgating regulations, which, among other things, established a category of

information known as Sensitive Security Information (SSI). In 1997, the Department of

Transportation (DOT) definition of SSI included ‘records and information ... obtained or

developed during security activities or research and development activities.’”119 Subsequently,

this type of information was given a statutory basis pursuant to the Aviation and Transportation

Security Act, P.L. 107-71, which created the Transportation Security Administration (TSA) and

prohibited disclosure of certain kinds of information relating to transportation if the disclosure

would be detrimental to the safety of passengers in transportation.120 P.L. 107-296 expanded this

coverage to include information detrimental to the “security of transportation.” As the FAA was

moved to the TSA, first located in the DOT and then to the DHS,121 the SSI withholding authority

appears to have been expanded to include “all transportation related activities including air and

maritime cargo, trucking and freight transport, and pipelines.”122 On May 18, 2004, the DOT and

DHS jointly promulgated revised regulations,123 which, “adopt the Homeland Security Act

language as the definition of SSI. In addition, the new regulations incorporate former SSI

provisions, including the sixteen categories of information and records that constitute SSI.”124 SSI

information is defined by statute (49 U.S.C. section 114 (s)) and an implementing regulation (49

C.F.R. part 1520)125 as

(1) Security programs and contingency plans ... issued, established, required, received, or

approved by DOT or DHS.... (2) Security Directives.... (3) Information Circulars ... issued by

DHS or DOT regarding a threat to aviation or maritime transportation.... (4) Performance

specifications.... (5) Vulnerability assessments.... (6) Security inspection or investigative

information.... (7) Threat information.... (8) Security measures.... (9) Security screening

information.... (10) Security training materials.... (11) Identifying information of certain

transportation security personnel.... (12) Critical aviation or maritime infrastructure asset

information.... (13) Systems security information... (14) Confidential business information....

(15) ... Information obtained or developed in the conduct of research related to aviation or

maritime transportation security activities, where such research is approved, accepted,

118

Air Transportation Security Act of 1974, P.L. 93-366, Section 316, 88 Stat. 409 (1974), as cited in CRS Report

RL32664, Interstate Travel: Constitutional Challenges to the Identification Requirement and Other Transportation

Security Regulations, by (name redacted).

119

According to Tatelman, op. cit., codified at 14 C.F.R. § 191.1 (1997).

120

Created pursuant to the Aviation and Transportation Security Act (ATSA), P.L. 107-71, section 101 (e)(3), 115 Stat.

597, 603 (2002).

121

For detailed history of the laws and regulations that govern SSI and transportation, see CRS Report RL32664, op.

cit., and CRS Report RL32425, Sensitive Security Information and Transportation Security: Issues and Congressional

Options, by (name redacted).

122

CRS Report RL32664, op. cit.

123

See also “Protection of Sensitive Security Information, Transportation Security Administration (TSA), DHS, and

Office of the Secretary of Transportation (OST), DOT.” Federal Register, May 18, 2004 (v. 69, no. 96), pp. 2806628086. (DOT, Office of the Secretary of Transportation, 49 CFR Part 15; Department of Homeland Security,

Transportation Security Administration, 49 CFR Part 1520.)

124

Tatelman, op. cit., pp. 3-4. See the original for footnotes to this quotation.

125

Report Pursuant to Section 893, not dated but reportedly sent to the committee chairmen in February 2004, p. 5, op.

cit.

Congressional Research Service

24

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

funded, recommended, or directed by the DHS or DOT, including research results... (16)

Other information....

This information, like CII information, was also designated as exempt from disclosure under

FOIA (49 U.S.C sec 40119(b) (1)) under exemption 3, which permits the withholding of

information protected by other statutes, has use limitations for sharing with state or local

governments, and imposes criminal penalties on federal officers or employees who disclose such

information. 126

Critique of SSI Rules

Terrorists have capitalized on vulnerabilities in national and foreign transportation systems

several times since 2001. Nevertheless, some critics charge that too much transportation-related

information is being withheld from public access. Many of the criticisms of SSI rules focus on the

alleged consequences of preventing the public from accessing information that might be used to

promote safety or be used in citizen oversight. For instance, some aircraft personnel and

consumer advocates say that TSA’s use of SSI can “muzzle debate of security initiatives and

insulate TSA from criticism.”127 The newsletter OMBWatch reported that the TSA has denied

access to information when “reasonable access to it could improve safety conditions for

communities and workers.”128 Examples include TSA denying pilots access to information to

comply with TSA regulations to avoid flying near nuclear power plants, disagreeing with TSA’s

views that information on such sites compiled from public data by the Aircraft Owners and Pilots

Association should be labeled SSI and not be made available, and denying the District of

Columbia government access to information to help them determine if trains carrying chlorine

through D.C. should be rerouted. The Coalition of Journalists for Open Government (CJOG), a

group of journalist advocacy organizations, 129 in a filing on July 16, 2004, in response to

regulations jointly filed by the Department of Transportation and the Transportation Security

Administration, 130 said

[The] ... unrestricted use of the ... (SSI) designation ... will have a seriously adverse impact

on traditional citizen and media oversight of the governance of our seaports, airports and

transit systems.... There appear to be no limits to the type of information that might be

gathered or generated as SSI and then sealed. Local and state officials, bound by nondisclosure agreements, may be forced to deny access to records that state law and local

ordinance require be made available to citizens. Information needed by civic activists or

organizations to maintain oversight and challenge local officials on their management of

126

See CRS Report RL32597, Information Sharing for Homeland Security: A Brief Overview, by (name redacted) and

(name redacted).

127

Secrecy in the Bush Administration, by U.S. House of Representatives, Committee on Government Reform—

Minority Staff Special Investigations Division Prepared for Rep. Henry A. Waxman, Sept. 14, 2004, p. 54. Tim Starks,

“A Fine Mess: TSA’s New Information Security Rules Leaves Stakeholders Confused,” CQ Homeland Security, July

21, 2004.

128

“Transportation Agency Hides Vital Data ‘Sensitive Security Information,’” OMB Watch, Apr. 4, 2005.

129

Composed of American Society of Newspaper Editors; Associated Press Managing Editors; Committee of

Concerned Journalists; National Association of Science Writers; Newspaper Association of America; Reporters

Committee for Freedom of the Press; Radio-Television News Directors Association; Society of Professional

Journalists; Society of Environmental Journalists.

130

See also “Press Coalition Defends Access to “Critical Oversight Info,” Secrecy News, July 19, 2004.

Congressional Research Service

25

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

public facilities may be withheld, even when the information’s relevance to any possible

terrorist threat is at best tenuous.131

In the same document, 132 the CJOG recommended that federal agencies should preserve public

access to what it calls “critical oversight information” (COI)—“any information a citizen might

use to judge whether his or her public servants are serving well,” information “that speaks to the

quality and integrity of their performance as policy makers, managers or employees of our

seaports, airports and transit systems,” including budget information and details on revenue and

spending and information about personnel and their qualifications, training, and performance. 133

Various courts have ruled on the interpretation of the SSI regulations.134

Controls on Environmental Impact Information

Controls on environmental impact information are premised on the need to protect internal

agency decision making procedures and to control access to information that terrorists might use

to harm critical infrastructures, deliver services, or poison the, air, water, and so forth. The actions

discussed next represent steps that have been taken to safeguard public access to environmental

information.

The Department of Homeland Security (DHS) expanded its ability to withhold certain types of

environmental impact information that previously was available to the public pursuant to the

National Environmental Policy Act (NEPA).135 On June 14, 2004, DHS issued a directive

proposing new categorical exclusions to disclosure requirements under FOIA for assessments of

environmental impacts of DHS decision making and included component DHS agencies in the

categorical exclusions policy.136 The directive specified three levels for projects or grants that

might have environmental impacts: “those affecting national security that are categorically

excluded from coverage under NEPA; those that require DHS agencies to conduct environmental

assessments; and those with the greatest potential to affect natural resources and the environment,

which would require more detailed environmental impact statements.” Specifically, EPA allows

categorical exclusions for “actions that ... do not ... have significant impact on the human

environment, and therefore ... do not require an environmental assessment ... or environmental

impact statement....” (40 C.F.R. 1500-1508.)

Some of the agencies that were transferred to DHS had previously identified such exclusions. In

addition, the directive exempted all DHS agencies (Transportation Security Administration, Coast

Guard, Border Patrol, FEMA and others) from releasing classified, proprietary, or other

131

Pete Weitzel, “Comments of the Coalition of Journalists for Open Government (CJOG), Before The Department of

Transportation and the Transportation Security Administration, In the Matter of Protection of Sensitive Security

Information,” RIN 1652 AA08 Docket # TSA 2003-15569.

132

These comments were made in a filing by CJOG and nine of its member organizations on July 16, 2004, in response

to regulations jointly filed by the DOT and the TSA involving the designation and disclosure of information designated

as Sensitive Security Information.

133

Weitzel, CJOG, op. cit.

134

See, Stevens and Tatelman, CRS Report RL33670, op. cit., pp. 19-26.

135

42 U.S.C. Section 5321 et. seq.

136

DHS, “Proposed Management Directive 5100.1, Environmental Planning Program,” Federal Register, v. 69, no.

33043-33066. June 14, 2004.

Congressional Research Service

26

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

information exempt from disclosure under FOIA, and proposed to exempt critical infrastructure

information, sensitive security information, and other information described in “laws, regulations,

or Executive Orders prohibiting or limiting the release of information.”137 Some say this could

exclude from public view environmental impact statements required by NEPA. In its Federal

Register announcement, DHS said that it would place protected information prepared for

compliance with NEPA into appendix sections for viewing only by decision makers, but would

allow the public to view nonsensitive portions of the material. However, it added “...if segregation

would leave essentially meaningless material, the DHS elements will withhold the entire NEPA

analysis from the public.” The plan also would allow DHS to categorize some environmental

reviews as “sensitive security information” or “critical infrastructure information” exempt from

public disclosure. The public comment period was for one month and then was extended to

August 16, 2004. DHS held a meeting on October 12, 2004 to discuss public comments

received. 138 On April 4, 2006, DHS published a final rule. On this topic EPA responded to public

comments by empanelling a group to examine release of environmental review information and

concluded that it would permit environmental review information that is not withheld according

to statute to be made accessible to the public pursuant to FOIA.139

A 2005 supplemental appropriations bill (H.R. 1268), enacted as P.L. 109-13,140 exempted the

DHS from certain legal requirements when physically securing U.S. borders. Some contend that

this may enable DHS to waive environmental protection laws, among others, relating to border

security. 141

Critiques of Controls on Environmental Information

Some critics allege that these types of policies, including SBU information control policies,

conflict with the environmental quality laws of the 1970s and the Emergency Planning and

Community Right-To-Know Act of 1986 (42 U.S.C. 11049). Critics of regulations limiting access

to some critical infrastructure information focus on their preemption of state and local disclosure

laws and the inability of citizens to obtain information needed to ensure community safety.142

137

Federal Register, June 14, 2004, op. cit., p. 33063.

Management Draft Management Directive 5100.1, Environmental Planning Program Meeting Minutes, Subject:

Draft Environmental Directive for the Department of Homeland Security (DHS) Meeting: October 12, 2004, at

http://www.dhs.gov/dhspublic/interapp/editorial/editorial_0528.xml.

139

Section “9. Appendix A, Section 6.2, Classified or Protected Information” in “Department of Homeland Security,

Environmental Planning Program, Notice of Final Directive,” Federal Register, vol. 71, no. 64, April 4, 2006, pp.

16790-16820.

140

According to Sec. 102 of P.L. 109-13: “Waiver of Legal Requirements Necessary for Improvement of Barriers at

Borders; Federal Court Review,” Section 102(c) of the Illegal Immigration Reform and Immigrant Responsibility Act

of 1996 (8 U.S.C. 1103 note) is amended to read as follows: “... Notwithstanding any other provision of law, the

Secretary of Homeland Security shall have the authority to waive all legal requirements ... [he] determines necessary to

ensure expeditious construction of the barriers and roads under this section.... Any such decision by the Secretary shall

be effective upon being published in the Federal Register.”

141

“Homeland Security Wins Power to Waive All Law,” OMB Watch, Feb, 2005.

138

142

Reportedly, once submitted to DHS, “information that is designated CII is not merely exempt from public

disclosure. It can’t be disclosed to any government official except for national security purposes. Nor can it be used in

court. That means a company could tell the Department of Homeland Security about an eroding chemical storage tank

on the bank of a river, but DHS could not disclose that information to the public or even to the Environmental

Protection Agency. And if there were a spill ... , the information given DHS couldn’t be subpoenaed in a law suit. No

one knows just what that will mean in practice, but the concern is palpable” (Pete Weitzel, “A Skip Through the Rabbit

Hole,” The American Editor [American Society of Newspaper Editors], May-June-July 2004).

(continued...)

Congressional Research Service

27

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

Several environmental groups have criticized controls on environmental information, saying too

much is being withheld by EPA and DHS pursuant to its DHS environmental directive released on

June 14, 2004. The Natural Resources Defense Council charged that because the agencies

subsumed by DHS make environmentally related decisions relating to oil spills, border security,

flood planning, and chemical plant security, and so forth, communities should be given an

opportunity to evaluate these decisions.143 In addition, some agencies label environmental impact

statements as SBU, saying that they should be released only to those who have a “need to know.”

Some agencies post environmental impact materials on the Internet with blacked-out markings for

what appears to be locational or infrastructure details.144 Other agencies have published

documents and put SBU information into a separate appendix, available under controlled access.

Generally, because of “security sensitivity,” most DOE environmental assessment documents are

not available to the public online but may be accessible via hardcopy in NEPA reading rooms if

the requestor qualifies. 145 Other examples have been cited of agencies withholding or controlling

information that, reportedly, prevents informing the public of environmental and other hazards.146

The American Library Association (ALA) proposed that, with respect to environmental

information, DHS should limit “its non-disclosure provision to information that unambiguously

qualifies for withholding under one of the exemptions provided in the Freedom of Information

Act....”147 It contended that the provision allowing DHS to withhold “essentially meaningless”

information not now subject to exemption from disclosure should be deleted since Congress

intended the public to determine what information is meaningful in the environmental statements.

OMB Watch concurred: “There are no procedures contained in the directive for how DHS will

determine which pieces of environmental analysis to remove if it falls within an exemption, or

how it will determine if the public finds the information meaningful.”148

(...continued)

Problems were reported by a community group working with the Project on Government Oversight (POGO) “to track

drinking water supplies contaminated with perchlorate, a rocket fuel that causes developmental problems in children.

After 9/11, the Army refused to share critical information with the community groups, including maps of drinking

water test wells. What confused community groups the most was the fact that these maps were already shared

publicly—but the Army refused to acknowledge them and claimed they were ‘sensitive’ information not for public

release. The community group refused to back down and is now suing the Army for information under an

environmental law that gives community groups the right to be informed about toxic chemical threats” (“Fighting

Secrecy—And Winning,” OMB Watch, Feb. 23, 2004. For additional examples of the issue of SBU in the

environmental area, see, Richard Dahl, “Does Secrecy Equal Security?” Environmental Health Perspectives, Feb.

2004, pp. A104-A107). See also regarding withholding of flood inundation maps, Gregg Sangillo, “Groups Raise

Concerns About Increased Classification of Documents,” GovExec.com, Oct. 27, 2004.

143

National Resources Defense Council, Comments to Proposed Management Directive 5100.1, Environmental

Planning Program, July 14, 2004, as cited in Secrecy in the Bush Administration, op. cit., Sept. 14, 2004, p. 56. See

also regarding access to maps locating perchlorate plumes, “Post 9-11 Secrecy Hits Homer in Aberdeen Maryland,”

Release prepared by the Working Group on Community Right-to-Know, Jan. 29, 2004.

144

See, for instance, U.S. Department of Energy, Environmental Assessment For the Strategic Petroleum Reserve West

Hackberry Facility Raw Water Intake Pipeline Replacement Cameron and Calcasieu Parishes, Louisiana, DOE/EA1497 http://www.eh.doe.gov/nepa/ea/EA1497/EA-1497.pdf and “NRC Censors Environmental Impact Statement,”

OMB Watch, Jan. 24, 2005.

145

Source: http://www.eh.doe.gov/nepa/documents.html.

146

See for instance, Lance Gay, “Government Withholds ‘Sensitive-but-Unclassified’ Information,” Scripps Howard

News Service, Feb. 2, 2006 http://www.shns.com/shns/g_index2.cfm?action=detail&pk=UNCLASSIFIED-02-02-06.

147

Emily Sheketoff, American Library Association, Letter “Re: Department of Homeland Security’s Proposed

Management Directive 5100.1, Environmental Planning Program,” Aug. 16, 2004.

148

“DHS Seeks Exemptions From Public Disclosure Requirements,” OMB Watcher, July 29, 2004. See also,: Mike

Ferullo, “Groups Wary of Homeland Security Plan Exemptions Some Environmental Reviews,” Daily Report for

(continued...)

Congressional Research Service

28

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

Illustration of Complexity of the Issue: the Nuclear Regulatory Commission

(NRC)

The complexity of balancing access to, and protection of, information is illustrated by actions

taken by the Nuclear Regulatory Commission (NRC). In August 2004, the agency issued a

statement that “certain security information formerly included in the Reactor Oversight Process

will no longer be publicly available.”149 Its efforts to “scrub” its website while balancing public

access and information security generated public criticism that NRC withheld information

relevant to the safety of surrounding residents but shared such information with power companies

and industrial lobbying groups. The NRC also allegedly threatened criminal prosecution for

persons who published critiques of two nuclear reactors in Indian Point, New York, even though

the NRC is reported to have said it could not specify what information was compromised. 150 In

the fall 2004, some “... news and watchdog organizations pointed out that some sensitive

documents in the [NRC online] library could be used by terrorists”; the NRC subsequently closed

major portions of the library and reviewed items it contained. 151

Representative Edward J. Markey, a senior minority member of the House Committee on Energy

and Commerce, wrote to the NRC, requesting that its inspector general investigate the agency’s

information release policies and, specifically. concerns about the NRC “improperly restricting

access to specific documents that should be releasable from a security perspective but are

nevertheless being withheld from public release.” 152 He cited the agency’s proposals to widen its

definition of “proprietary information” to withhold more public information and to broaden

restrictions on the dissemination of sensitive information to include emergency evacuation plans

and safety analyses concerning the protection of nuclear materials; its actions to withhold an

unclassified version of an NAS report allegedly because the NRC disagreed with its findings; and

the agencies’ prohibitions on non-industry representatives attending meetings and having

information, even though industrial representatives were given access. In June 2005, the Nuclear

Regulatory Commission announced it would restore viewing on the web to more than 70,000

documents, after reviewing them for “sensitive security information.”153 An NRC task force

concluded that the agency could withhold information that could be deemed useful to terrorists if

the information were not already available to the public pursuant to its new Sensitive Information

Screening Project, but FOIA principles needed to be followed to withhold information. The task

(...continued)

Executives, July 16, 2004, p. A-21.

149

“NRC Modifies Availability of Security Information From All Nuclear Plants” NRC News, Aug. 4, 2004 (No. 04091).

150

R. Jeffrey Smith, “Nuclear Security Decisions Are Shrouded in Secrecy, Agency Withholds Unclassified

Information,” Washington Post, May 29, 2004, p. A21.

151

“NRC Initiates Additional Security Review of Publicly Available Documents; Temporarily Suspends Agency’s OnLine Library,” NRC News, Oct. 25, 2004, No. 04-135; Sean Madigan, “Documents Return to Online Nuclear

Regulatory Library After Terror Review,” CQ Homeland Security, Nov. 17, 2004. These were identified as such things

as floor plans for university laboratories giving the location of equipment that uses nuclear materials and of storage

facilities for them. (See, for example, M. Ahlers, “Blueprints for Terrorists? Sensitive Nuclear Info Ends Up on NRC

Web Site,” CNN.Com at http://www.cnn.com/2004/US/10/19/terror.nrc/index.html).

152

Letter from Rep. Edward J. Markey to Hubert T. Bell, Inspector General, U.S. Nuclear Regulatory Commission,

Mar. 21, 2005.

153

Sean Madigan, “Nuclear Documents Back Online,” CQ Homeland Security, June 10, 2005. For original wording,

see “NRC Task Force Report on Public Disclosure of Security-Related Information,” Nuclear Regulatory Commission,

May 18, 2005, approved June 30, 2005. http://www.fas.org/sgp/othergov/nrc-disc.pdf.

Congressional Research Service

29

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

force identified the precise kinds of information that could be withheld under the various FOIA

exemptions. 154

Also during this time period, the National Academies released an unclassified version of a report,

that included among its findings that the commission’s security restrictions on the sharing of

information with industry and the public negatively affected “constructive feedback and

cooperation. The committee recommended that the ... NRC improve the sharing of pertinent

information on its security analyses of spent fuel storage with nuclear power plants operators and

system vendors. More constructive interaction with the public and with independent analysts also

could increase confidence in ... NRC and industry decisions and their actions to reduce the

vulnerability of spent fuel storage to terrorist attacks.”155

Controls on Unclassified Biological Research Information

Traditionally, open communication of biological information fosters the conduct of research and

development. Also, emergency preparedness requires exchange of information to inform local

health officials “... of what agents are being studied in their jurisdictions so they can prepare for

any unlikely future events.”156 However, some biological information and data could pose a

domestic or international security threat, which has led to federal controls.157 For instance, a 2006

National Academies report described a variety of biotechnology agents and specific genetic

advances that could be used in research and could increase the potential for biowarfare.158 It also

inventoried some dual-use biological agents and research developments that could be used

malevolently. For example, “The same reverse genetic technologies that can be used to develop

new vaccines against RNA viruses could also be used to construct modified viruses, including

possibly viruses that express heterologous virulence factors that result in more lethal disease.”159

Ominously, it observed that

[in] the past, dual-use concerns have focused on pathogens and on the challenges associated

with controlling dangerous pathogens. As already emphasized, this committee’s

deliberations have indicated that the problem will be far broader and more profound in the

future. For example, advances in neurobiology may make it possible to manipulate behavior

and thought processes, while gene expression technologies just now coming to fruition will

make it possible to activate endogenous molecules in the body—with possibly wide ranging

and everlasting effects. Advances in synthetic biology and nanotechnology will offer similar

154

“NRC Task Force Report on Public Disclosure of Security-Related Information,” NRC, May 18, 2005, approved

June 30, 2005, originally cited in “NRC Adopts Policy on Disclosure of Security Information,” Secrecy News, Aug. 16,

2005, http://www.fas.org/sgp/othergov/nrc-disc.pdf.

155

“Spent Fuel Stored in Pools at Some U.S. Nuclear Power Plants Potentially at Risk From Terrorist Attacks; Prompt

Measures Needed to Reduce Vulnerabilities,” NAS Press Release, April 6, 2005. See also “Secrecy Impedes Security,

National Academy Says,” Secrecy News, Apr. 8, 2005; and the NAS report: Safety and Security of Commercial Spent

Nuclear Fuel Storage: Public Report, by Committee on the Safety and Security of Commercial Spent Nuclear Fuel

Storage, National Academy of Sciences Press, 2005.

156

“Laura H. Kahn, “Biodefense Research: Can Secrecy and Safety Coexist?” Biosecurity and Bioterrorism:

Biodefense Strategy, Practice and Science, vol. 3, no. 2, 2004, p. 4.

157

For additional information, see CRS Report RL31695, Balancing Scientific Publication and National Security

Concerns: Issues for Congress, by (name redacted).

158

Committee on Advances in Technology and the Prevention of Their Applications to Next Generation Biowarfare

Threats, Globalization, Biosecurity, and The Future of the Life Sciences, National Academies Press, 2006, pp. 39-40.

159

Globalization, Biosecurity, and The Future of the Life Sciences, op. cit., p. 53.

Congressional Research Service

30

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

rich opportunities for dual use. Nanodevices that may be used to unplug blocked arteries

could instead be employed to interfere with circulatory function. Advanced drug delivery

technologies and pharmacogenomics knowledge could be used to develop and deliver with

greater efficiency new bioweapons, perhaps even selectively targeting certain racial or ethnic

groups.”160

To deal with concerns like these, some types of biological sciences information have already been

controlled and proposals have been made to develop other types of governmental or

nongovernmental systems to control access to information before research is conducted or in the

prepublication phase. These proposals, which are discussed next, are not without controversy.

The federal government’s regulation requiring the registration of laboratories that transferred

certain “select agents”—organisms and toxins identified by the Centers for Disease Control and

Prevention (CDC) as potentially useful in bioterrorist activities—began in 1996.161 Registration

of laboratories that possess such agents was mandated by P.L. 107-188, “The Public Health

Security and Bioterrorism Preparedness and Response Act of 2002,” enacted after the 9/11

attacks. The law requires coordination between the Department of Health and Human Services

(DHHS) and the Department of Agriculture (USDA) to identify and regulate the use and transfer

of such agents that pose a risk to public health, crops or livestock; registration of all facilities that

use such agents; minimum safety requirements for registered facilities; background screening of

persons using such agents; and a national database of such users. The USA PATRIOT Act, P.L.

107-56 prohibits access to select agents by certain persons, including certain immigrants, and

persons with criminal or drug use history and other factors. Interim final regulations

implementing these laws were issued in December 2002.162

National Science Advisory Board for Biosecurity

A National Academy of Sciences (NAS) report, Biotechnology Research in an Age of Terrorism:

Confronting the “Dual Use” Dilemma, published in 2004 and dubbed the “Fink” report after the

committee chairman, called for greater self-regulation by scientists, use of institutional biosafety

committees at academic and research institutions to monitor research that could possibly aid

terrorism, NIH review of certain types of research reports before they are published, and use of

screening criteria in a prepublication review. Regarding private scientific publishing, the Fink

report largely left it up to journal publishers to make decisions about prepublication review

procedures for articles involving biological agents. The Fink report also urged creation of a new

federal advisory board to guide nongovernmental researchers and to develop responsibility

among scientists to control flows of biodefense information. But it did not propose governmental

control of such research.

In March 2004, the DHHS announced its intent to create a National Science Advisory Board for

Biosecurity (NSABB), which became funded in 2005. It is managed and staffed by the National

Institutes of Health (NIH). The NSABB is chartered to have 25 voting nongovernmental members

160

Globalization, Biosecurity, and The Future of the Life Sciences, op. cit., p. 55.

Pursuant to the Antiterrorism and Effective Death Penalty Act of 1996 (P.L. 104-132). For further information on

this and subsequent activity, see CRS Report RL31719, An Overview of the U.S. Public Health System in the Context of

Emergency Preparedness, by (name redacted).

162

The DHHS regulation is codified at 42 CFR Section 73.0, and the USDA regulation at 7 CFR Part 331 and 9 CFR

Part 121.

161

Congressional Research Service

31

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

with a broad range of expertise in molecular biology, microbiology, infectious diseases, biosafety,

public health, veterinary medicine, plant health, national security, biodefense, law enforcement,

scientific publishing, and related fields. The NSABB also includes nonvoting ex officio members

from 15 federal agencies and departments. It is supposed to advise federal departments and

agencies regarding oversight of dual-use nonclassified biological research. The board’s charter

also includes work to develop national policies to communicate and publish sensitive research

results, a code of conduct for life sciences researchers, training programs and materials to educate

the community about biosecurity, and strategies to foster international collaboration to oversee

dual-use life sciences research. NIH aims to use the committee’s guidance to develop policies to

require performer institutions that it funds to use Institutional Biosafety Committees (IBC), to

educate researchers, to issue guidance, and to review and advise on specific experiments that

might be misused or pose a threat to the public health or national security. Policy guidance will

flow from the federal board to the institutional committees if there is uncertainty or disagreement

regarding denial of an experiment. The NSABB met several times in 2005 and 2006; it will meet

next on January 31 to February 2, 2007.

During its first meeting, the board established five working groups to develop criteria to identify

dual-use research; criteria to communicate results of dual-use research; a life sciences code of

conduct; international perspectives on dual-use research; and guidance on chemical synthesis of

bacterial and viral genomes. 163 Some discussants proposed that biologists should be licensed to

conduct sensitive biological research, that codes of conduct would need to be certified, and that

methods of assuring compliance among research institutions would need to be developed. 164

Some contended that if the scientific community did not develop methods of monitoring and

protecting sensitive research, policy makers might develop and try to enforce more stringent

controls that ultimately might prove to be unacceptable.165

During the July 2006 meeting, NSABB recommended in draft guidelines released for public

comment that authors, institutional reviewers, and journal editors conduct a risk-benefit analysis

as part of “formal procedures to presecreen the publication of findings from...dual-use projects”

that might be useful to terrorists.166

During its October 25, 2006 meeting,167 which addressed the topic of synthetic biology, among

other things, the Board adopted draft recommendations, published for comment, that the

government “regulate potentially dangerous gene sequences instead of a list of known pathogens”

since the current rules for select agents identify a finite list of organisms, and do not account for

biological entities that can be synthetically engineered. 168 The board “...also wants the

163

Janet Coleman, “NSABB Working Groups Will Begin Discussions Soon...,” Research Policy Alert, July 5, 2005.

“Rules of Engagement,” Nature, July 7, 2005, p. 2.

165

Eugene Russo, “New Biosecurity Panel Struggles With Role in Monitoring Sensitive Research,” Research Policy

Alert, July 5, 2005. See also Jeffrey Brainard, “National Biosecurity Board Holds First Meeting, Ponders Limits on

Research,” Chronicle of Higher Education, July 1, 2005.

166

Yudhijit Bhattacharjee, “Biosecurity: U.S. Panel Calls for Extra Review of Dual-Use Research,” Science, July 21,

2006, p. 284. The draft guidelines are: National Science Advisory Board for Biosecurity, NSABB Draft Guidance

Documents, July 2006, http://www.biosecurityboard.gov/pdf/NSABB%20Draft%20Guidance%20Documents.pdf.

They focus on I. Criteria for Identifying Dual Use Research of Concern, II. Tools for the Responsible Communication

of Research with Dual Use Potential, III. Considerations in Developing a Code of Conduct for Dual Use Research in

the Life Sciences.

167

See, http://www.biosecurityboard.gov/meetings_archive_102506.asp.

168

Yudhijit Bhattacharjee, “Bioterrrorism Agents: U.S. Panel Wants Security Rules Applied to Genomes, Not

(continued...)

164

Congressional Research Service

32

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

government to require companies to screen orders for synthetic DNA against the genomes of

select agents and to maintain a record of purchase orders. Neither procedure is currently

mandated by law.”169 Topics for subsequent NSABB meetings include developing oversight plans

and implementation processes for these guidelines in academia and in government. It is likely that

some scientists will object to guidelines requiring prepublication review. 170

Views on Adequacy of Biosecurity Protection Policies

Some critics say existing biosecurity protections are inadequate to prevent terrorists from

obtaining and using biological information and suggest that stronger measures should be taken,

such as creation of a network that interacts closely with intelligence and military agencies to

prevent misuse of biological information. 171 Related to this, a 2006 National Academies report,

concerned about how new developments in the life sciences coupled with rapidly advancing

fields such as nanotechnology and materials science could prove to threatening, endorsed the free

and open change of information in the life sciences to the maximum extent possible. However, it

also recommended,

•

creating statutorily an independent advisory group in the security community to

strengthen scientific and technical expertise within the intelligence and security

communities;

•

adopting and promoting a “common culture of awareness and a shared sense of

responsibility within the global communities of life scientists,” including

development of codes of ethics; and

•

establishing, “... a decentralized, globally distributed network of informed

concerned scientists who have the capacity to recognize when knowledge or

technology is being used inappropriately or with the intent to cause harm”172 and

whose interventions could take the form of counseling or “... reporting such

activity to national authorities when its appears potentially malevolent in

intent.”173

Other shortcomings in current policy have been identified. For instance, the scope of the DHHS’s

NSABB board has been faulted because it does not extend to privately funded research nor

harmonize international standards.174 Others criticize the select agent rules as inadequate and say

federal regulations should be expanded to prevent unauthorized persons from possessing the DNA

(...continued)

Pathogens,” Science, Nov. 3, 2006, p. 743. The draft document is entitled, NSABB, Addressing Biosecurity Concerns

Related to the Synthesis of Select Agents. Draft Recommendations, Prepared by the Working Group in Synthetic

Genomics, 18 p.

169

Bhattacharjee, July 21, 2006, op. cit.

170

Bhattacharjee, July 21, 2006, op. cit. For additional information, see CRS Report RL33342, Oversight of Dual-Use

Biological Research: The National Science Advisory Board for Biosecurity, by (name redacted).

171

Russo, July 6, 2005, op. cit

172

Globalization, Biosecurity, and the Future of the Life Sciences, op. cit., p. 8.

173

Globalization, Biosecurity, and the Future of the Life Sciences, op. cit., p. 9.

174

Jennifer Couzin, “U.S. Agencies Unveil Plan for Biosecurity Peer Review,” Science, Mar. 12, 2004, citing Elisa

Harris of the University of Maryland’s Center for International and Security Studies.

Congressional Research Service

33

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

components of a select agent.175 George Church, a genetics professor at Harvard, reportedly “is

organizing a consortium of researchers and academics to push the federal government to license

anyone interested in purchasing DNA segments for agents of bioterror.”176 Similarly, John

Steinbruner and colleagues at the Center for International and Security Studies at Maryland

(CISSM), in a 2005 report, advocated mandatory licensure of researchers and institutions that

conduct biodefense research. Three levels of independent review—at the institutional, national,

and international level—would monitor risks and benefits of research proposals and would issue

approval or disapproval for conduct of researchers and publications.177

Nongovernmental professional groups have explored the use of codes of conduct or self-policing

policies178 for research topics and publications. Some publishers adopted a set of voluntary, riskbased publishing principles, called “Statement of Scientific Publication and Security,” 2003; but

this, reportedly, has resulted in changes in only very few articles before publication.179 In June

2005, the American Society for Microbiology drafted a code of ethics for its members and urged

them to report to “appropriate authorities” misuses of microbiology information.180 The

Interacademy Panel on International Issues, consisting of most of the world’s national science

academies, issued a set of principles that urged scientists to take responsibility to prevent misuse

of their work. 181 Two researchers, Margaret A. Somerville of McGill University and Ronald M.

Atlas, President of the American Society for Microbiology, proposed an international code of

ethics to prevent bioterrorism.182 Adherents to the code would refuse to conduct work that could

175

Caitlin Harrington, “Lab-Synthesized Diseases Open a New Front in Bioterror War,” CQ Homeland Security, Aug.

2, 2004.

176

Harrington, op. cit.

177

Eugene Russo, “Biodefense Research Needs Formal Oversight and Licensure - University of Maryland Report,”

Research Policy Alert, Feb. 22, 2006, citing John Steinbruner, et al., Controlling Dangerous Pathogens: A Prototype

Protective Oversight System, University of Maryland, 2005.

178

For a representative list of codes of ethics developed by professional groups, see online at

http://www.biosecuritycodes.org/codes_archive.htm.

179

Reportedly, the statement of policy was adopted by science journal editors and released on Feb. 15, 2003, and was

published in Science, Nature, and the Proceedings of the National Academy of Sciences. It is available at

http://www.fas.org/sgp/news/2003/02/sci021503.html. For additional information, see CRS Report RL31695, op. cit. It

has been reported that, according to an article published in 2003, “... the American Society of Microbiology (ASM)

flagged two out of fourteen thousand articles as unsuitable for publication, and both of these papers were likely to be

published after changes were made....(The Unintended Audience: Balancing Openness and Secrecy: Crafting an

Information Policy for the 21st Century, op. cit., p. 39).

180

Eugene Russo, “Biosecurity Advisory Board Considers Code of Ethics,” Research Policy Alert, July 6, 2005.

181

Shirley Haley, “Scientists Must Take Responsibility for Preventing Misuse of Their Work—Interacademy Panel,”

Research Policy Alert, Dec. 6, 2005. The document is “IAP Statement on Biosecurity,” Nov. 7, 2005.

182

Margaret A. Somerville and Ronald M. Atlas, “Ethics: A Weapon to Counter Bioterrrorism,” Science, Mar. 25,

2005, pp. 1881, 1882. The proposed code is: “In order to prevent the life sciences from becoming the death sciences

through bioterrorism or biowarfare, all persons and institutions engaged in all aspects of the life sciences must: “1.

Work to ensure that their discoveries and knowledge first do no harm: I) by refusing to engage in any research that is

intended to facilitate, or there is a high probability of its being used to facilitate bioterrorism or biowarfare, both of

which violate the fundamental moral values of humanity; and ii) by complying with the prohibition of the Biological

Weapons Convention to never, under any circumstances, knowingly or recklessly contribute to the development,

production or acquisition of microbial or other biological agents or toxins, whatever their origin or method of

production, of types or in quantities that cannot be justified on the basis of their being necessary for prophylactic,

protective, therapeutic, or other peaceful purposes. 2. Work for the ethical and beneficent advancement, development

and use of scientific knowledge. 3. Call to the attention of the public, or the appropriate persons or bodies, activities,

including unethical research, that there are reasonable grounds to believe are likely to contribute to bioterrorism or

biowarfare. 4. Take reasonable care to assure biosecurity by seeking to allow access to biological agents that could be

used as biological weapons only to individuals who there are reasonable grounds to believe will not misuse them. 5.

(continued...)

Congressional Research Service

34

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

be used in bioterrorism and would seek to restrict access of those they believe could use

information maliciously.

It was noted above in the section on “Nongovernmental Experts’ Recommendations To Use Risk

Analysis To Identify and Control Sensitive Information,” that proposals have been made to instill

in researchers a culture that discourages research that could be used malevolently, that

professional peer reviews should be conducted before publication of work that should be

protected, and that the federal government should define policy controls for these activities. In

addition, J. Gaudioso and R. M. Salerno proposed a biosecurity risk assessment process that

would restrict the use of agents that have the potential to be weaponized and that could serve as

the basis for international standards. This process would involve using

four Biosecurity levels: low, moderate, high, and extreme risk. The overwhelming majority

of pathogens and toxins would fall into the low-risk category (requiring practices such as

locking unattended laboratories and maintenance of documentation of agents used), and most

select agents would be placed in the moderate-risk category (requiring additional safeguards

such as access controls and personnel checks). The security measures for low-and moderaterisk categories should pose reasonable costs and largely rely on existing biosafety measures.

Very few agents would be designated high risk (requiring more stringent security measures

and a dedicated Biosecurity officer). Perhaps only variola major, because it is no longer

found in nature would be considered an extreme risk, requiring the most stringent protections

(such as comprehensive background investigations and an on-site guard force). Higher

security than that currently mandated by federal regulations would only be applied for those

very few agents that represent true weapon threats. Biosecurity levels should be developed

and vetted by experts in biological weapons, microbiology, security, and public and

agricultural health. This would help federal agencies apply uniform criteria to grantees and

could form the basis for standardizing biosecurity internationally.183

Brian J. Gorman proposed a risk-based alternative approach for prepublication peer review. He

called for a risk-based process called “Due Process Vetting System” (DPVS) together with “... a

Risk Assessment Scale [RAS] and a Least Restrictive Classification System for the

communication, assessment, and disposition of sensitive life science research in a manner

consistent with national security interests.”184 The process would be overseen by a new agency

(...continued)

Seek to restrict the dissemination of dual-use information and knowledge to those who need to know in cases where

there are reasonable grounds to believe that there are serious risks that information or knowledge could be readily

misused to inflict serious harm through bioterrorism or biowarfare. 6. Subject research activities to ethics and safety

reviews and monitoring to establish their ethical acceptability: I) to ensure that legitimate benefits are being sought and

that they outweigh the risks and harms; and ii) if human or animal subjects are involved, to ensure that such

involvement is ethical and essential for carrying out highly important research. 7. Abide by laws and regulations that

apply to the conduct of science unless to do so would be unethical, and recognize a responsibility to work through

relevant societal institutions to change those laws and regulations that are in conflict with ethics. 8. Recognize all

persons’ rights of conscientious objection to participation in research that they consider ethically or morally

objectionable and to refuse to participate without penalty. 9. Faithfully transmit the duties and obligations embodied in

this code, and the ethical principles upon which it is based to all who are, or may become, engaged in the conduct of

science.”

183

Jennifer Gaudioso and Reynolds M. Salerno, “Biosecurity and Research: Minimizing Adverse Impacts,” Science,

Apr. 30, 2004, citing J. Gaudioso and R. M. Salerno, “A Conceptual Framework for Biosecurity Levels,” BTR 2004:

Unified Science and Technology for Reducing Biological Threats and Countering Terrorism—Proceedings,

Albuquerque, NM, March 18-19, 2004.

184

Brian J. Gorman, “Balancing National Security and Open Science: A Proposal for Due Process Vetting,” Yale

Journal of Law and Technology, 2005, pp. 2, 15.

Congressional Research Service

35

“Sensitive But Unclassified” Information and Other Controls: Policy and Options

called the Biologic Regulatory Commission, modeled after the Nuclear Regulatory Commission.

The vetting process would be triggered at the request of an author or peer reviewer if an article

attained a predetermined score on the RAS set by the BRC. “The RAS surveys opinions of

informed reviewers including the author of the article, the author’s Institutional Review Board or

Institutional Biosafety Committee (IBC), and finally the journal interested in publishing the

article.”185 The DPVS would safeguard high-risk articles by providing the government with a

mechanism to identify “potentially dangerous articles before they reach the presses,”186 would

avoid the “deleterious effects of censorship,”187 and would make articles available only to a

“select academy of biodefense researchers after the authors, the publishing journal and others,

reach a consensus with the government through cooperative vetting of the article in question.”188

Gorman proposed expanding the academy to a

This text is long and has been trimmed here. Open the source document for the complete record.

This is a copy of a public record, reproduced as it was published. It is not legal advice, and it may not be the version a court would rely on. Check the official source before you cite it.

A word about cookies

We need a few to keep you signed in and the library working. The rest help us see which pages people use and where they get stuck. They stay off unless you say yes.