ConceptioArchiveCode of Federal Regulations (eCFR)
Code of Federal Regulations (eCFR)public full text

12 CFR Part 403 — Classification, Declassification, and Safeguarding of National Security Information

Office of the Federal Register (NARA) · Code of Federal Regulations (eCFR, Office of the Federal Register)
Code of Federal Regulations (eCFR) · Legal · License: Public Domain
Open Source ↗
exportimportbankoftheunitedstates
united states, us regulation, us federal regulation, code of federal regulations, cfr, federal regulation, 12, 403, part 403, 12 cfr 403, 12 cfr part 403, banks, and, banking, export-import bank of the united states

PART 403—CLASSIFICATION, DECLASSIFICATION, AND SAFEGUARDING OF NATIONAL SECURITY INFORMATION Authority: E.O. 12356, National Security Information, April 2, 1982 (3 CFR, 1982 Comp. p. 166) (hereafter referred to as the Order Directive NSDD 84 Source: 50 FR 27215, July 2, 1985, unless otherwise noted. § 403.1 General policies and definitions. (a) This regulation of the Export-Import Bank (the Bank) implements executive orders which govern the classification, declassification, and safeguarding of national security information and material of the United States. This regulation is based on Executive Order 12356, National Security Information, April 2, 1982 (3 CFR, 1982 Comp. p. 166) (hereafter referred to as the Order Directive NSDD 84 (b) For the purposes of the Order, the Directive and these guidelines, the following terms shall have the meanings specified below: (1) Information (2) National security information (3) Foreign government information (i) Information provided by a foreign government or governments, an international organization of governments, or any element thereof with the expectation, expressed or implied, that the information, the source of the information, or both, are to be held in confidence; or (ii) Information produced by the United States pursuant to or as a result of a joint arrangement with a foreign government or governments or an international organization of governments, or any element thereof, requiring that the information, the arrangement, or both, are to be held in confidence. (4) National security (5) Confidential source (6) Original classification § 403.2 Responsibilities. In the carrying out of security procedures, responsibility falls on all personnel generally and on certain personnel in a more particular manner. (a) Individual. (b) Office and Division Heads. (c) Security Officer. (2) The Security Officer shall be responsible for disseminating written material and conducting oral briefings to inform Bank personnel of the Order, Directive, and regulations. An explanation of the practical application of these procedures and the underlying policy objectives thereof shall be emphasized. (d) Security Committee. Chairman) (2) All suggestions and complaints regarding the Bank's Information Security Program, including those regarding over-classification, failure to declassify, or delay in declassifying, not otherwise provided for herein, shall be referred to the Security Committee for review. (3) The Security Committee shall have responsibility for recommending to the Chairman appropriate administrative action to correct abuse or violation of these regulations or of any provision of the Order or Directive thereunder, including but not limited to notification by warning letter, formal suspension without pay, and removal. Upon receipt of such a recommendation, the Chairman shall make a decision and advise the Security Committee of this action. § 403.3 Classification principles and authority. (a) Classification Principles. (2) Before a classification determination is made, each item of information that may require protection shall be identified exactly. This requires identification of that specific information, disclosure of which could affect the national security. When there is reasonable doubt about the need to classify, the information should be safeguarded as if it were confidential until a final determination is made by an authorized classifier as to its classification. The final determination must be made within thirty (30) days. (b) Classification Designations. classified information (1) TOP SECRET shall be applied only to information, the unauthorized disclosure of which reasonably could be expected to cause exceptionally grave damage to the national security. (2) SECRET shall be applied only to information, the unauthorized disclosure of which reasonably could be expected to cause serious damage to the national security. (3) CONFIDENTIAL shall be applied to information, the unauthorized disclosure of which reasonably could be expected to cause damage to the national security. Except as provided by statute, no other terms, such as SENSITIVE, OFFICIAL BUSINESS ONLY, AGENCY, BUSINESS, ADMINISTRATIVELY, (c) Original Classification Authority and Criteria. Classification Classifier CONFIDENTIAL President and Chairman. First Vice President and Vice Chairman. General Counsel. Senior Vice Presidents. Security Officer. (2) A determination to classify information shall be made by an original classification authority when the information concerns one or more of categories (i) through (x) of this paragraph, and when the unauthorized disclosure of the information, either by itself or in the context of other information, reasonably could be expected to cause damage to the national security. Information shall be considered for classification if it concerns: (i) Military plans, weapons, or operations; (ii) The vulnerabilities or capabilities of systems, installations, projects, or plans relating to the national security; (iii) Foreign government information; (iv) Intelligence activities (including special activities), or intelligence sources or methods; (v) Foreign relations or foreign activities of the United States; (vi) Scientific, technological, or economic matters relating to the national security; (vii) United States Government programs for safeguarding nuclear materials or facilities; (viii) Cryptology; (ix) A confidential source; or (x) Other categories of information that are related to the national security and that require protection against unauthorized disclosure as determined by the President of the United States, by the Chairman or by other officials who have been delegated original classification authority by the President. Recommendations concerning the need to designate additional categories of information that may be considered for classification shall be forwarded through the Security Officer to the Chairman for determination. Such a determination shall be reported to the Director of the Information Security Oversight Office. (3) Information that is determined to concern one or more of the above categories shall be classified when an original classification authority also determines that its unauthorized disclosure, either by itself or in the context of other information, reasonably could be expected to cause damage to the national security. Accordingly, certain information which would otherwise be unclassified may require classification when associated with other unclassified or classified information. Classification on this basis shall be supported by a written explanation that, at a minimum, shall be maintained with the file or reference on the recent copy of the information. (4) Unauthorized disclosure of foreign government information, the identity of a confidential foreign source, or disclosure of intelligence sources or methods is presumed to cause damage to the national security. (5) Information classified in accordance with the above classification categories shall not be declassified automatically as a result of any unofficial publication or inadvertent or unauthorized disclosure in the United States or abroad of identical or similar information. (d) Duration of Original Classification. (2) Automatic declassification determinations under predecessor orders shall remain valid unless the classification is extended by an authorized declassification authority. These extensions may be by individual documents or categories of information, provided, however, that any extension of classification on other than an individual document basis shall be reported to the Director of the Information Security Oversight Office. The declassification authority shall be responsible for notifying holders of the information of such extensions. (3) Information classified under predecessor orders and marked for declassification review shall remain classified until reviewed for declassification under the provisions of the Order. (e) Marking and Identification. (i) One of the three classification levels defined in § 403.3(b); “(TS)” for Top Secret, “(S)” for Secret, “(C)” for Confidential, and “(U)” for Unclassified; with each page marked at top and bottom according to the highest level of classified information on each page. (ii) The identity of the original classification authority if other than the person whose name appears as the approving or signing official; (iii) The agency and office of origin; and (iv) The date or event for declassification, or the notation “Originating Agency's Determination Required.” (2) Each classified document shall, by marking or other means, indicate which portions are classified, with the applicable classification level, and which portions are not classified. The Chairman may, for good cause, grant and revoke waivers of this requirement for specified classes of documents or information. The Director of the Information Security Oversight Office shall be notified of any waivers. (3) Marking designations implementing the provisions of the Order, including abbreviations, shall conform to the standards prescribed in implementing directives issued by the Information Security Oversight Office. All authorized classifiers shall be issued a uniform stamp that has a “Classified by” line and a “Declassify on” line. (4) Documents that contain foreign government information shall include either the marking, “FOREIGN GOVERNMENT INFORMATION”, or a marking that otherwise indicates that the information is foreign government information. If that fact must be concealed, the document will be marked as if it were of U.S. origin. Foreign government information shall either retain its original classification or be assigned a United States classification that shall ensure a degree of protection at least equivalent to that required by the entity that furnished the information. (5) Documents that contain information relating to intelligence sources or methods shall include the following marking unless proscribed by the Director of the Central Intelligence; WARNING NOTICE—INTELLIGENCE SOURCES OR METHODS INVOLVED. (6) Information assigned a level of classification under predecessor orders shall be considered as classified at that level of classification despite the omission of other required markings. Omitted markings may be inserted on a document by the General Counsel or the Security Officer. (f) Limitations on Classification. (2) Basic scientific research information not clearly related to the national security may not be classified. (3) The Chairman or other authorized original classifiers may reclassify information previously declassified and disclosed if it is determined in writing that— (i) The information requires protection in the interest of national security, and (ii) The information may reasonably be recovered. In making such determination, the Chairman or any other authorized original classifier shall consider the following factors: The lapse of time following disclosure; the nature and extent of disclosure; the ability to bring the fact of reclassification to the attention of persons to whom the information was disclosed; the ability to prevent further disclosure; and the ability to retrieve the information voluntarily from persons not authorized access to its reclassified state. These reclassification actions shall be reported promptly to the Director of the Information Security Oversight Office. (4) Information may be classified or reclassified after an agency has received a request for it under the Freedom of Information Act (5 U.S.C. 552) or the Privacy Act of 1974 (5 U.S.C. 552a), or the mandatory review provisions of the Order and these regulations, if such classification meets the requirements of the Order and is accomplished personally and on a document-by-document basis by the Chairman, the Vice Chairman, or the Security Officer. § 403.4 Derivative classification. (a) Use of derivative classification. (2) Persons who apply such derivative classification markings shall: (i) Respect original classification decisions; (ii) Verify the information's current level of classification so far as practicable before applying the markings; and (iii) Carry forward to any newly created documents the assigned dates or events for declassification or review. The latest date for declassification should be entered in the case of multiple source documents. (b) New Material. (2) New material that derives its classification under prior orders shall be treated as follows: (i) If the source material bears a classification date or event 20 years or less from the date or origin, that date or event shall be carried forward on the new material. (ii) If the source material bears no declassification date or event or is marked for declassification beyond 20 years, the new material shall be marked with a date for review for declassification at 20 years from the date of original classification of the source material. (iii) If the source material is foreign government information bearing no date or event for declassification or is marked for declassification beyond 30 years, the new material shall be marked for review for declassification at 30 years from the date of original classification of the source materials. (iv) A copy of the source document or documents should be maintained with the file copy of the new document or documents which have been derivatively classified. § 403.5 Declassification and downgrading. (a) Authority and policy for declassification and downgrading. (1) The official who authorized the original classification, if that official is still serving in the same position, by a successor, or by a supervisory official of either; or (2) Officials specifically delegated this authority in writing by the Chairman or by the Security Officer. A list of those who may be so delegated shall be maintained by the Security Officer. (3) If the Director of the Information Security Oversight Office determines that information is unlawfully classified, the Director may require the Export-Import Bank to declassify it. Any such decision by the Director may be appealed to the National Security Council. The information shall remain classified until the appeal is decided. (b) Declassification Procedure. (c) Notification to Holders. (d) Downgrading. (e) Transferred Information. § 403.6 Systematic review for declassification. Classified information determined by the Archivist of the United States to be of sufficient value to warrant permanent retention will be subject to systematic declassification review by the Archivist in accordance with guidelines provided by the Bank, as originator of the information. These guidelines shall be developed by the Security Officer who is designated by the Bank to assist the Archivist in the review process. The guidelines shall be reviewed every five years or as requested by the Archivist of the United States. § 403.7 Mandatory review for declassification. (a) Classified information under the jurisdiction of the Bank shall be reviewed for declassification upon receipt of a request by a United States citizen or permanent resident alien, a Federal agency, or a State or local government. A request for mandatory review of classified information shall be submitted in writing and describe the information with sufficient particularity to locate it with a reasonable amount of effort. Requests may be addressed to the: General Counsel, Export-Import Bank of the U.S., 811 Vermont Avenue, NW., Washington, DC 20571 (b) The Bank's response to mandatory review requests will be governed by the amount of search and review time required to process the request. The Bank will acknowledge receipt of all requests, and will inform the requester if additional time is needed to process the request. Except in unusual circumstances, the Bank will make a final determination within one year from the date of receipt of the request. (c) When information cannot be declassified in its entirety, the Bank will make a reasonable effort to release, consistent with other applicable laws, those declassified portions that constitute a coherent segment. (d) The bank shall determine whether information under the classification jurisdiction of the Bank or any reasonably segregable portion of it no longer requires protection. If so, the General Counsel shall promptly make such information available to the requester, and shall inform the requester of any fees due before releasing the document. If the information may not be released, in whole or in part, the General Counsel shall give the requester a brief statement of the reasons, and a notice, mailed with return receipt requested, of the right to appeal the determination within 60 days of the denial letter's receipt. (e) The agency that initially received or classified records containing foreign government information shall be responsible for making a declassification determination on review requests for classified records which contain such foreign government information. Such requests shall be referred to the appropriate agency for action. (f) When the Bank receives a mandatory declassification review request for records in its possession that were originated by another agency, it shall forward the request to that agency. The Bank may request notification of the declassification determination. (g) Information originated by a President, the White House staff, by committees, commissions, or boards appointed by the President, or other specifically providing advice and counsel to a President or acting on behalf of a President is exempted from the provisions of mandatory review for declassification, except as consistent with applicable laws that pertain to presidential papers or records. (h) The bank shall process requests for declassification that are submitted under the provisions of the Freedom of Information Act, as amended, or the Privacy Act of 1974, in accordance with the provisions of those acts. ( See, (i) The Bank shall refuse to confirm or deny the existence or non-existence of requested information whenever the fact of its existence or non-existence is itself classifiable under the Order. § 403.8 Appeals. (a) The Vice Chairman is designated to receive appeals on requests for declassification which have been denied by the Bank. Such appeals shall be addressed to: First Vice President & Vice Chairman, Export-Import Bank of the United States, 811 Vermont Avenue NW., Washington, DC 20571 The appeal must be received within 60 days after receipt by appellant of the denial letter. Appeals shall be decided within 30 days of their receipt by the Vice Chairman. (1) If the decision is to declassify the materials in their entirety, the Vice Chairman shall promptly make such information available to the requester, and inform the requester of any fees due before releasing the documents. (2) If the decision is to deny declassification of a portion of the material, the Vice Chairman shall promptly make the part which was declassified available to the requester, and shall advise the requester, in writing, of the reasons for the partial denial of declassification. (3) If the decision is to deny declassification of all the material, the Vice Chairman shall promptly advise the requester, in writing, of the reasons for such denial. § 403.9 Fees. The following specific fees shall be applicable with respect to services rendered to members of the public under these regulations, by the Bank, except that the search fee will normally be waived when the search involves less than one-half hour of clerical time. (a) Search for records, per hour or fraction thereof: (i) Professional $11.00 (ii) Clerical 6.00 (b) Computer service charges per second for actual use of computer central processing unit .25 (c) Copies made by photostat or otherwise (per page); maximum of 5 copies will be provided .10 (d) Certification of each record as a true copy 1.00 (e) Certification of each record as a true copy under official seal 1.50 (f) Duplication of architectural photographs and drawings 2.00 Fees must be paid in full prior to issuance of requested copies. Remittances shall be in the form either of a personal check or bank draft drawn on a bank in the United States, or postal money order. Remittances shall be made payable to the order of the Export-Import Bank of the United States, and mailed to: General Counsel, Export-Import Bank of the United States, 811 Vermont Avenue NW., Washington, DC 20571 § 403.10 Safeguarding. (a) General Access Requirements. (1) Determination of Trustworthiness. (2) Determination of Need to Know. (b) Classified Information Nondisclosure Agreement. (c) Access by Historical Researchers and Former Presidential Appointees. (d) Media Contacts. (e) Dissemination. (f) Accountability Procedures. (1) TOP SECRET. (i) To receive the material for the Bank; (ii) To maintain registers which will reflect the routing of the material and the return thereof in a reasonable length of time for security storage; (iii) To dispatch and make record of material disseminated to authorize persons outside the Bank; (iv) To make a physical inventory of all material at least annually; and (v) To maintain current access records. (2) SECRET. (i) To receive the material for the Bank; (ii) To maintain registers which will reflect the routing of the material and the return thereof in a reasonable length of time for security storage; (iii) To dispatch and make record of material disseminated to authorized persons outside the Bank; (iv) To maintain current access records. (3) CONFIDENTIAL. (i) To review material for the Bank; (ii) To route the material to proper Bank offices; (iii) To dispatch and make record of material disseminated to authorized persons outside the Bank; (iv) To maintain current access records. (g) Storage. (h) Coversheets. (i) Transmittal. (2) Preparation and Receipting. (3) Transmittal of CONFIDENTIAL information. (4) Transmittal of TOP SECRET and SECRET information shall be in accordance with the Directive. Reference may be made to 32 CFR 2001.44 for preliminary guidance. (j) Destruction. (k) Reproduction controls. (2) TOP SECRET documents may not be reproduced without the consent of the originating agency unless otherwise marked by the originating office. (3) Reproduction of SECRET and CONFIDENTIAL documents may be restricted by the originating agency. (4) Reproduced copies of classified documents are subject to the same accountability and controls as the original documents. (5) Records shall be maintained by the Security Officer to show the number and distribution or reproduced copies of all TOP SECRET documents, of all documents covered by special access programs distributed outside the originating agency, and all SECRET and all CONFIDENTIAL documents which are marked with special dissemination and reproduction limitations. § 403.11 Enforcement and investigation procedures. (a) Loss or Possible Compromise. (b) Reporting and Investigating Unauthorized Disclosures. (2) The Bank shall promptly notify the Information Security Oversight Office at the General Services Administration, Washington, DC 20405, of all unauthorized disclosures of classified information. (3) If the Bank believes that it is the source of an unauthorized disclosure of classified information that it originated, it shall evaluate the disclosure under paragraph (b)(7) of this section. If the disclosure is serious, the Bank shall report the disclosure and the results of the evaluation to the Department of Justice together with notification that it is conducting an internal investigation. (4) If the Bank believes that it is the source of an unauthorized disclosure of classified information that it handled but did not originate, it shall report the disclosure to the Department of Justice and to the originating agency(ies) or department(s) for evaluation under paragraph (b)(7) of this section. If the Bank cannot determine the identity of the originating agency(ies) or department(s), it shall report the disclosure to the Department of Justice together with any information or reasonable inferences as to the identity of the originating agency(ies) or department(s). (5) If the Bank receives a request for an evaluation of information it originated, it shall, if the evaluation shows the disclosure was serious, inform the agency(ies) or department(s) from which the disclosure occurred of this conclusion and request that the agency(ies) or department(s) conduct an internal investigation. (6) If the Bank determines that an unauthorized disclosure of classified information has occurred but that it neither originated, handled nor disclosed the information, it shall report the disclosure to the likely originating agency(ies) or department(s). (7) In determining whether a disclosure is sufficiently serious to warrant reporting to the Department of Justice, the Bank, if it is the originating agency, shall ascertain the nature of the disclosed information, determine the extent to which it disseminated the information and evaluate the disclosure to determine whether it seriously damages its mission and responsibilities. In evaluating the damage caused by the disclosure, the Bank shall consider such matters as whether the disclosure jeopardizes an ongoing project, operation or source of information and to what extent the policy goals underlying the project or operation must be altered. (8) In any instance where the Bank is determined to be the source of an unauthorized disclosure and an evaluation by the Bank or the originating agency(ies) or department(s) determines the disclosure to be of a serious nature, an internal investigation will be initiated and an investigation report, containing such information as may be required by the Department of Justice, will be submitted to the Department of Justice within 15 days after notification from the originating agency or Department of Justice, but in any case no later than 30 days. If the investigation report is not completed within 15 days, the Bank shall submit as much of the required information as is available at that time and furnish additional information as it is developed. (9) Whenever the Bank determines during the course of an investigation that it is necessary to compel or induce the cooperation of an employee, the Bank shall first consult with the Department of Justice. The Department of Justice will coordinate with the Bank to determine the procedures the Bank may use to compel an employee's participation without foreclosing possible criminal proceedings. (10) The Bank shall maintain records of all disclosures that have been reported or investigated. (11) All employees shall cooperate fully with officials of the Bank or other agencies who are conducting investigations of unauthorized disclosures of classified information. (12) Employees determined by the Bank to have knowingly participated in an unauthorized disclosure of classified information or who have refused to cooperate with an investigation of such a disclosure shall be denied further access to classified information and shall be subject to other appropriate administrative sanctions. Prior to taking action against an employee in connection with the unauthorized disclosure or classified information, the Bank shall consult with the Department of Justice, National Security Division. [50 FR 27215, July 2, 1985, as amended at 72 FR 66043, Nov. 27, 2007]

Related documents

Record · ID 505420 · SHA-256 940788128580d9e3
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.