FAS

Protecting “Critical Program Information” Within DoD

07.21.08 | 2 min read | Text by Steven Aftergood

The Department of Defense last week issued new guidelines (pdf) for protecting “critical program information” (CPI), a term that refers to the most sensitive technology information in DoD research, development and acquisition programs.

CPI consists of those program elements “that, if compromised, could cause significant degradation in mission effectiveness; shorten the expected combat-effective life of the system; reduce technological advantage; significantly alter program direction; or enable an adversary to defeat, counter, copy, or reverse engineer the technology or capability.”

CPI “includes technology that would reduce the US technological advantage if it came under foreign control.”

“It is DoD policy… to provide uncompromised and secure military systems to the warfighter by performing comprehensive protection of CPI.”

The new CPI instruction, issued by James. R. Clapper, Jr., the Under Secretary of Defense for Intelligence, updates and expands upon a prior directive (pdf) from 1997.

Among the interesting changes adopted in the new instruction is an increased role for security oversight by the DoD Inspector General, who is called upon to “develop a uniform system of periodic inspections” to ensure compliance with CPI protection requirements, and to “publish an annual report of significant findings, recommendations, and best practices.”

Though it is not specifically addressed in the new instruction, the use of agency inspectors general to conduct oversight of classification and declassification activity is the single most promising near-term option for augmenting oversight of the government secrecy system. Increased IG oversight of CPI may serve as a useful precedent for validating the IG’s capacity to perform that function and advancing its classification oversight role.

See “Critical Program Information (CPI) Protection Within the Department of Defense,” DoD Instruction 5200.39, July 16, 2008.

publications
See all publications
State & Local Innovation
Report
Before Breaking Ground: A Local Government Guide to Better Data Center Policy and Community Benefits

This report serves as a landscape assessment and toolbox from which local governments can negotiate an informed position when it comes to the levers available to them and includes a first-of-its kind analysis of eight executed community benefits agreements.

09.10.26 | 42 min read
read more
Government Capacity
Blog
Federal Data Help Communities Prepare for, Respond to, and Recover from Hurricanes. Data Terminations Will Make Them More Deadly.

When a hurricane hits, it’s all hands on deck – that goes for federal data, too. Pulling back from our investments in timely, accurate, and accessible public data will only make us less prepared and put us all at greater risk.

09.08.26 | 5 min read
read more
Government Capacity
Blog
The Public Health Cost of Eliminating Race and Ethnicity Data

This is bigger than a singular elimination of race and ethnicity questions. It could accelerate the second wave of widespread reductions to demographic data, leaving public health officials with even less information to deliver better health outcomes for all Americans. 

09.04.26 | 6 min read
read more
Emerging Technology
Blog
How AI’s Soft Law Sandcastles Can Become Hard Law Skyscrapers

Soft law was never meant to be a permanent solution. Treating it as one, and letting the sandcastle stand in for the skyscraper indefinitely, is how we end up with a decade of voluntary commitments and no enforceable accountability to show for it.

09.03.26 | 10 min read
read more