DoDM 5200.01 Vol 2: DoD Information Security Program Marking Standards and Marking of Information Guide
Manual Overview, Purpose, and Applicability
The Department of Defense Manual , Volume , titled "DoD Information Security Program: Marking of Information," was issued on February , and includes Change , effective July .
The Under Secretary of Defense for Intelligence and Security (USD(I&S)) is the authorizing official for this guidance.
General Purpose: This volume implements policy, assigns responsibilities, and provides procedures for the designation, marking, protection, and dissemination of controlled unclassified information (CUI) and classified information (collateral, SCI, and SAP).
Regulatory Alignment: The guidance complies with DoDI , Executive Order (E.O.) , E.O. , and Title CFR Parts and .
Applicability: It applies to the Office of the Secretary of Defense (OSD), the Military Departments, the Joint Staff, Combatant Commands, the Office of the Inspector General of the DoD, Defense Agencies, DoD Field Activities, and all other organizational entities (collectively referred to as "DoD Components").
Intelligence Community (IC) Note: It does not alter the authorities of the Director of National Intelligence (DNI). SCI must be safeguarded according to DNI policies and DoDM .
General Policy and Information Sharing
Policy Objectives:
Identify and protect national security information and CUI according to national policies.
Promote standardized processes to facilitate information sharing and resource management.
Enforce standards for marking all classified national security information.
Apply restrictive dissemination markings only when clearly warranted to avoid impeding information sharing.
Releasability: This volume is cleared for public release and is available via the Directives Division Website.
Marking Standards and Uniformity
Uniformity: The manual specifies an authorized list of classification designators, abbreviations, and portion markings.
Grandfathering: Documents marked according to previous guidance do not require re-marking; however, all new (original and derivative) documents must comply with current standards.
Key Changes in Change 4:
The overall classification line is now formally called the "banner line."
Dissemination control markings (e.g., REL TO) must be included in both banner lines and portion marks.
Portion marks for subjects and titles must be placed before the text (no exceptions).
The annotation format for dates in the classification authority block is strictly .
Markings must follow a specific hierarchical order and syntax.
Intelligence Data: Components handling intelligence must refer to the CAPCO Register and the IC Classification and Control Markings Implementation Manual (accessible via JWICS or SIPRNET).
Waivers for Marking Requirements
Authority: Only the Director of the Information Security Oversight Office (ISOO) can grant waivers for classified information marking. Administrative burden is not a sufficient reason for a waiver.
Submission Process: Non-Intelligence DoD Components must submit requests to the DDI(CL&S); IC elements must provide a copy to DDI(CL&S) while following DNI policy.
Request Requirements: Must include identification of info, detailed explanation, anticipated dissemination judgment, and a statement of support from USD(I&S).
Portion Marking Waivers: Must explain the impact on derivative classification and describe mitigation strategies to ensure information sharing is not negatively impacted.
Physical Security: Cover Sheets and Labels
Classification Folders: Groups of documents must have markings on the outside. This is satisfied by standard cover sheets:
SF 703: Top Secret.
SF 704: Secret.
SF 705: Confidential.
Storage Exception: Cover sheets are not required when items are in GSA-approved secure storage containers.
IT Media Labels: SF labels identify the highest level of info on removable electronic media and equipment:
SF 706: Top Secret Label.
SF 707: Secret Label.
SF 708: Confidential Label.
SF 710: Unclassified Label (used only in environments where classified and unclassified info are both processed).
Trigraphs and Tetragraphs for International Data
Country Codes: Used to identify foreign countries (ISO trigraphs) or coalitions/organizations (tetragraphs).
Operational Tetragraph Requests:
Process: Submit to DDI(CL&S) for review prior to need. Urgent requests () require specific justification.
Development Rules: Must be alphabetic characters; cannot repeat the same character times (e.g., RRRR); cannot spell an actual word.
Membership Stability: Membership lists for the tetragraph should not change more than twice per year.
General Marking Principles
Goal: Markings must be conspicuous and immediately apparent to identify the level of protection, reasons for classification, office of origin, and guidance on sharing/declassification.
Classifier Responsibility: The original or derivative classifier (author) is responsible for proper marking.
Public Media Items: No security markings may be applied to articles from newspapers or magazines. If such an article contains classified info, the evaluation must be filed separately.
Attachments: Whenever possible, use classified attachments to allow the main document to remain unclassified or at a lower level.
Metadata: Electronic data must have security metadata tags to identify classification and control caveats for electronic handling.
Required Elements of a Classified Document
Banner Lines: Conspicuously placed at the top and bottom of the outside front cover, title page, first page, and back cover.
Format: All uppercase; highest classification first; double forward slashes (//) to separate classification level from control markings.
Interior Pages: May reflect the highest classification on that specific page or the overall document classification.
Portion Marks: Every portion (paragraphs, bullets, subjects, titles, tables, pictures) must be marked at its beginning.
Symbols: for Top Secret, for Secret, for Confidential, for Unclassified.
Sub-portions: If sub-portions have different levels, they must be marked individually to prevent over-classification.
Origin Block: Must identify the DoD Component, office of origin, and the date of the document on the face of the document.
The Classification Authority Block
Original Classification Block requires:
Classified By: Name and position (or personal identifier).
Reason: Cite E.O. section categories ( through ).
Downgrade To (if applicable): Lower level and date/event.
Declassify On: Specific date or event.
Derivative Classification Block requires:
Classified By: Name and position.
Derived From: Cite the source document (title, date, agency) or security guide. Use "Multiple Sources" only if more than one source is used; a source list must then be maintained.
Declassify On: Carried forward from the source or calculated based on the most restrictive source.
Hierarchical Declassification Selection (most restrictive order):
ISCAP approved exemption ().
or .
ISCAP approved exemption.
ISCAP approved exemption.
Specific date or event within .
Calculated date from the creation of the derivative document (used when no instruction is provided).
Managing Changes in Classification
Downgrading/Declassification: Old markings should be lined through with an "X" or horizontal line and new markings applied. For bulky documents, changing the cover, title page, and first page is the minimum requirement.
Confirmation: Holders must confirm with the Original Classification Authority (OCA) that classification hasn't been extended before declassifying.
Reclassification: Previously declassified info may be reclassified only under specific conditions; it requires a new authority block and date of action.
Bulk Changes: A notice may be attached to the storage unit for large volumes of material to avoid re-marking every individual item until they are removed for use.
Electronic Marking Requirements
E-mails: Banner lines must appear at the top and bottom of the message body. The classification authority block follows the signature block. Subject lines must be portion marked based on the sensitivity of the subject text alone.
Web Pages: Display banner line at top and bottom. Metadata and hypertext must include classification strings for readability by text translators.
URLs: Must be portion marked based on the content of the URL string itself, not the content it links to. Ideally developed as unclassified.
Dynamic Documents (e.g., database queries): If classification cannot be determined automatically, the highest classification of the source data must be used, and a warning statement must be applied: "This content shall not be used as a source of derivative classification."
Wikis/Blogs: Entries must be marked as finished documents. Wikis must have a log to track user identity and time/date of changes to classified content.
Chat: Captured chat discussions must be marked with banner and portion marks. Chat rooms should display "system-high" overall markings.
Special Types of Materials
Maps and Charts: Unabbreviated banner markings at top and bottom. Legend/title must be portion marked. Markings must be visible when rolled or folded.
Photographs: Mark on the face if possible; otherwise, mark the reverse side. Digital photos should have overlays.
Film/Video: Mark classification at the beginning and end of the played/projected portion. Discs and containers must also be marked.
Sound Recordings: Audible statement of classification at the beginning and end.
Microform: Marking must be visible to the unaided eye in the image area.
Working Papers: Classified info created during preparation. Must be dated, marked with highest classification, and annotated "WORKING PAPER." If retained > ( for SAP), they must be marked as a finished document.
Foreign Government Information (FGI)
Equivalent Levels: Most use levels equating to U.S. Top Secret, Secret, and Confidential. Some use "RESTRICTED" or "IN CONFIDENCE."
Marking Format: Items consisting entirely of FGI start with double slashes (//) and the country code (e.g., //DEU SECRET). No authority block is used.
NATO Classifications:
COSMIC: NATO Top Secret.
ATOMAL: Applied to U.S. RD/FRD or UK Atomic info released to NATO.
BOHEMIA: Used for NATO TS SIGINT-derived info.
Modified Handling: Foreign "Restricted" or "In Confidence" info is marked "CONFIDENTIAL - Modified Handling" in the U.S.
Jointly Owned Info: Use //JOINT followed by classification and alphabetical country codes (e.g., //JOINT SECRET CAN GBR USA).
Atomic Energy Act (AEA) Information
Restricted Data (RD): Data regarding nuclear weapon design, SNM production, or energy use. Managed by DOE. Automatic declassification is prohibited.
Formerly Restricted Data (FRD): Info relating primarily to military utilization of atomic weapons. Removed from RD by joint DoD/DOE determination.
Marking Rules:
Banner: [Classification]//RESTRICTED DATA or [Classification]//FORMERLY RESTRICTED DATA.
Warning Notice: Specific verbatim text is required on the face of the document (e.g., "Unauthorized disclosure subject to administrative and criminal sanctions").
No declassification date is annotated. The line says "Not Applicable."
Critical Nuclear Weapon Design Information (CNWDI): A subset of RD. Appended with "-N" (e.g., ). Requires a special warning notice and access briefing.
SIGMA Categories: Identify specific RD/FRD regarding nuclear explosive devices. Marked with Sigma numbers through (e.g., SECRET//RD-SIGMA 1 2).
Dissemination Control Markings
NOFORN (Not Releasable to Foreign Nationals):
Only for intelligence info under DNI purview.
Exceptions for non-intelligence: Naval Nuclear Propulsion Information (NNPI), NDP-1, and Cover support info.
ORCON (Originator Controlled): Used when dissemination must be strictly controlled by the originator. Requires a point of contact for release determinations ( response time).
REL TO: Authorized for release to specific countries. Trigraphs start with "USA," then other countries alphabetically.
DISPLAY ONLY: Disclosure allowed without providing a copy for retention. Must remain under U.S. control at all times.
ACCM (Alternative Compensatory Control Measures): Security measures for intelligence/operations when normal measures are insufficient but SAP is not required. Portions marked with acronym and program nickname (e.g., ).
Marking Syntax Order
Hierarchy: Markings must appear in the following absolute order in the banner line:
U.S. Classification Level (Top Secret, Secret, Confidential).
SCI Control Systems (e.g., HCS, SI, TK).
Special Access Programs (SAP).
Atomic Energy Act (AEA) (RD, FRD).
Foreign Government Information (FGI-Country Codes).
Dissemination Controls (e.g., ORCON, REL TO, NOFORN).
Other Dissemination (e.g., ACCM, FISA).
Syntax: Double slashes (//) separate categories; single slashes (/) separate items within a category (e.g., SECRET//SI/TK//REL TO USA, CAN).