Under active development Content is continuously updated and improved

PS-6(2)Access Agreements | Classified Information Requiring Special Protection

IL6

>Control Description

Verify that access to classified information requiring special protection is granted only to individuals who: (a) Have a valid access authorization that is demonstrated by assigned official government duties; (b) Satisfy associated personnel security criteria; and (c) Have read, understood, and signed a nondisclosure agreement.

>DoD Impact Level Requirements

No specific parameter values or requirements for this impact level.

>Discussion

Classified information that requires special protection includes collateral information, Special Access Program (SAP) information, and Sensitive Compartmented Information (SCI). Personnel security criteria reflect applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.

>Assessment Interview Topics

Questions assessors commonly ask

Process & Governance:

  • What policies govern classified information requiring special protection for organizational personnel?
  • Who is responsible for implementing and overseeing classified information requiring special protection controls?
  • How does the organization coordinate classified information requiring special protection with HR and legal teams?
  • What is the process for handling exceptions to classified information requiring special protection requirements?
  • What governance exists for ensuring consistent application of classified information requiring special protection across the organization?

Technical Implementation:

  • What systems or tools technically implement classified information requiring special protection?
  • How are classified information requiring special protection activities integrated with HR and identity management systems?
  • What automation supports classified information requiring special protection enforcement and tracking?
  • What audit capabilities exist for classified information requiring special protection?
  • How are classified information requiring special protection requirements technically enforced in access control systems?

Evidence & Documentation:

  • Provide documented policies and procedures for classified information requiring special protection.
  • Provide personnel records demonstrating classified information requiring special protection implementation.
  • Provide evidence of classified information requiring special protection for all personnel with system access.
  • Provide records of classified information requiring special protection reviews and updates.
  • Provide documentation of coordination between classified information requiring special protection and HR processes.

Ask AI

Configure your API key to use AI features.