What Is a Security Classification Guide
What is a Security Classification Guide?
A Security Classification Guide (SCG) is a document or other formal source that tells people what information needs protection and how classification decisions should be applied.
Put simply, an SCG helps answer questions such as:
- What information is classified?
- What classification level applies?
- Which parts of a system, plan, program, or mission require protection?
- How should people mark documents that contain that information?
The main goal is consistency. Everyone who handles the same type of information should apply the same classification decision instead of making a personal guess each time.
An SCG is guidance. It is not the person who decides whether information should be classified. That distinction matters, especially in cyber awareness and derivative-classification training.
What information does an SCG identify?
An SCG identifies specific information that requires protection in the interest of national security. It may cover a broad subject, such as a defense program, or a more focused subject, such as a particular system, plan, mission, or technical capability.
The guide connects information to its required classification treatment. For example, it may explain that certain details about a program are classified while other details are not. It may also identify the classification level that applies to the protected information.
An SCG can set out classification guidance for:
- A system
- A plan
- A program
- A mission
- Related operations, capabilities, or information
The key point is that the guide does not merely say, “Protect this topic.” It identifies the information that needs protection and provides a basis for handling classification decisions.
That can include information found in a new document, report, briefing, message, database record, or other material. The exact format depends on the organization and the subject covered by the guide.
Why security classification guides are used
Without shared guidance, two people could review similar information and reach different decisions. One person might mark it as classified. Another might leave it unclassified. An SCG helps prevent that kind of inconsistency.
The purpose of security classification guidance is to communicate the uniform application of classification decisions to all users of the relevant information.
That gives people a common reference point. Instead of relying only on memory or personal judgment, they can check the applicable guide and follow its direction.
An SCG also helps protect classified information in practical ways:
- It identifies what needs protection.
Users can recognize information that falls within the guide.
- It supports consistent decisions.
Similar information receives similar classification treatment.
- It guides document preparation.
Users can apply the proper classification and downgrading information to documents that contain classified material.
- It supports later users.
Someone working with information created by another person can use the guide to understand how that information should be treated.
The guide is not a replacement for an organization’s full security procedures. Agency and department rules may explain how to store, transmit, review, or release classified information. An SCG focuses on the classification guidance itself.
How an SCG supports derivative classification
Derivative classification means creating new classified material from information that has already been classified. The new material might restate, summarize, combine, or use information from an existing classified source.
A Security Classification Guide is a primary source for derivative classification. In this setting, “primary source” means a main reference that tells the user how to classify information being reused in a new document or product.
For example, a person preparing a briefing may use information from an existing program record. The person checks the relevant SCG to determine whether the details in the briefing need classification and what markings apply.
The person is not making an entirely new classification decision from scratch. The guide provides the existing classification direction for the information.
A useful way to separate the ideas is:
- The SCG gives the classification guidance.
- The existing classified information provides source material.
- The person preparing the new material applies the guidance to the new product.
- The new document or product receives the required markings.
Derivative classification does not mean that every document about a classified subject automatically receives the same classification. The user still has to determine whether the specific information in the new material matches the information described in the applicable guide.
That is why reading the SCG carefully matters. The guide may distinguish between protected details and information that does not require classification.
SCG versus an Original Classification Authority
An SCG and an Original Classification Authority (OCA) are different things.
An SCG is a document or source of guidance. An OCA is an authorized official who has the authority to make an original classification decision.
Here is the short version:
| Term | What it is | Main function |
|---|---|---|
| Security Classification Guide | A document or formal source | Identifies information that requires protection and explains its classification |
| Original Classification Authority | An authorized official | Makes an original decision to classify information |
An original classification decision is the first decision to classify particular information. The OCA makes that decision within the applicable rules and authority. The resulting decision can then be recorded in classification guidance, such as an SCG.
After that, people who create new material can use the SCG for derivative classification.
This distinction answers a common quiz question: An SCG is not the person who decides whether information is classified. It is the source that communicates the decision and helps users apply it consistently.
Specific procedures can vary by department or agency. Training for the Department of Defense may refer to a security classification guide DoD requirement or process, but the basic distinction remains the same: the guide provides classification direction, while an authorized official makes the original classification decision.
How SCGs relate to classified-document markings
An SCG tells users how information should be classified. A classified document then needs markings that show its classification status and downgrading information.
These markings help people recognize how the document must be handled. They are part of the document itself, while the SCG is the source that supports the classification decision.
The connection works like this:
- The SCG identifies information that requires protection.
- A user includes that information in a document or other product.
- The user applies the classification marking directed by the applicable guidance.
- The document also includes the required downgrading information.
A document’s markings should match the classification guidance for the information it contains. If the document combines information from more than one source, the person preparing it needs to apply the relevant guidance to the material included.
Do not treat a title, subject, or general connection to a classified program as enough by itself. The classification decision depends on the information in the document and the applicable guidance.
Security Classification Guide questions in cyber awareness training
Cyber awareness courses often ask for a short definition. The safest way to remember it is to separate three ideas:
- What an SCG is:
A document or formal source of classification guidance.
- What it identifies:
Specific information that requires protection in the interest of national security.
- How people use it:
As a primary source for derivative classification and as a way to apply classification decisions consistently.
A common security classification guide cyber awareness answer is therefore:
> A Security Classification Guide identifies information that requires protection and provides guidance for applying classification decisions consistently.
Training questions may use slightly different wording. They may describe an SCG as guidance for a system, plan, program, or mission. They may also ask whether it is a primary source for derivative classification. Those descriptions point to the same basic idea.
Searches for a security classification guide quizlet answer can be useful for reviewing terms, but flashcards may leave out the difference between an SCG and an OCA. Remember that the SCG is the guide. It is not the authorized official who makes the original classification decision.
Likewise, a security classification guide PDF is simply a file format or copy of the guidance. The format does not change what an SCG does.
There is no separate definition just because a course or search result refers to “cyber awareness 2026.” The exact training program may use its own wording, and agency-specific procedures may add details. For the rules that apply to your work, follow the official security-classification or cyber-awareness guidance provided by your organization and training program.