FAS

DoD Leaks Now Termed “Serious Security Incidents”

10.30.14 | 2 min read | Text by Steven Aftergood

Unauthorized disclosures of classified information, leaks to the news media, acts of espionage, and certain other information security offenses are now to be collectively designated as “serious security incidents,” according to a Department of Defense directive that was published this week.

The new terminology was adopted in order to standardize procedures for preventing, identifying, investigating and reporting such violations when they occur. See “Management of Serious Security Incidents Involving Classified Information,” DoD Directive 5210.50, October 27, 2014.

The new directive replaces a previous directive from 2005, which had simply been titled “Unauthorized Disclosure of Classified Information to the Public.”

Not every episode of mishandling classified information qualifies as a “serious security incident.” But that term applies whenever there is an unauthorized disclosure of classified information in the news media, or an act of espionage, or a willful disclosure of classified information to an unauthorized person that involves large amounts of classified information, or that reveals a systemic weakness in classification practices, among other circumstances. The threshold is determined by what is reportable to senior to DoD authorities (as specified in DoD Manual 5200.01, vol. 3, enclosure 6, at p. 88).

(Strictly speaking, the creation of an unauthorized DoD “special access program” would also appear to constitute a “serious security incident” requiring investigation, reporting and accountability. But that possibility is not mentioned in the new directive.)

“Serious security incident investigations and reporting will integrate security, counterintelligence, law enforcement, and other appropriate DoD interests to ensure that the causes of serious security incidents are identified and that all appropriate means are utilized to identify and mitigate damage to national security and avoid similar occurrences,” the new directive states.

This week, Michael Isikoff of Yahoo News reported that the FBI had identified a new leaker (“Feds identify suspected ‘second leaker’ for Snowden reporters,” October 27). The story also cited concerns among some intelligence officials that the Department of Justice may be reluctant to initiate new criminal prosecutions of suspected leakers due to criticism of past overzealousness.

It is hard to confirm from a distance that such reluctance on the part of Justice Department officials exists. But in fact, the government has always had alternatives to Espionage Act prosecutions of suspected leakers, including civil or administrative penalties and loss of security clearance.

The new DoD directive says that “DoD personnel responsible for serious security incidents may be held accountable, as appropriate, in a criminal proceeding, civil judicial action, disciplinary or adverse administrative action, or other administrative action authorized by federal law or regulations.”

Likewise, a July 2013 Department of Justice review of policies concerning the news media said that “The Department will work with others in the Administration to explore ways in which the intelligence agencies themselves, in the first instance, can address information leaks internally through administrative means, such as the withdrawal of security clearances and imposition of other sanctions.”

publications
See all publications
Global Risk
Blog
When the Climate Shifts, So Do the Pathogens (And So Should We)

As humans expand our geographic reach, encroach on untouched natural territories, and interact more with animal populations, we will encounter novel zoonotic diseases that threaten the human body. The sooner we act to address these risks, the better.

09.11.26 | 7 min read
read more
State & Local Innovation
Report
Before Breaking Ground: A Local Government Guide to Better Data Center Policy and Community Benefits

This report serves as a landscape assessment and toolbox from which local governments can negotiate an informed position when it comes to the levers available to them and includes a first-of-its kind analysis of eight executed community benefits agreements.

09.10.26 | 42 min read
read more
Government Capacity
Blog
Federal Data Help Communities Prepare for, Respond to, and Recover from Hurricanes. Data Terminations Will Make Them More Deadly.

When a hurricane hits, it’s all hands on deck – that goes for federal data, too. Pulling back from our investments in timely, accurate, and accessible public data will only make us less prepared and put us all at greater risk.

09.08.26 | 5 min read
read more
Government Capacity
Blog
The Public Health Cost of Eliminating Race and Ethnicity Data

This is bigger than a singular elimination of race and ethnicity questions. It could accelerate the second wave of widespread reductions to demographic data, leaving public health officials with even less information to deliver better health outcomes for all Americans. 

09.04.26 | 6 min read
read more