What happens when your new material aggregates or brings together separate pieces of information?
When new material aggregates individually unclassified pieces of information, the combination can reveal a classified fact. This is classification by compilation: the whole is classified even though the parts are not, so it must be marked and protected at the classified level.
The answer
When your new material aggregates or brings together separate pieces of information, you must consider classification by compilation (also called classification by aggregation). The rule: individual items may each be unclassified, but when they are combined, the compilation can reveal an additional association or relationship that meets the standard for classification. In that case the compiled document is classified — and must be marked and protected at the appropriate level — even though none of its parts is classified on its own.
Why the whole can exceed the parts
This is a core concept in derivative classification training (such as the DoD/IF103-style courses). A classic illustration: a phone directory entry, a project name, and a shipping schedule might each be public. But combined, they could reveal that a specific classified program is operating from a specific location on a specific date — a fact the government protects. The compilation exposes a relationship that the isolated facts did not, so the new document derives a classification even though you never copied classified source material into it.
What a derivative classifier must do
If you are creating material that aggregates information, you are expected to:
- Recognize that combining items may produce a classified compilation.
- Consult the security classification guide (SCG) or an original classification authority to determine whether the compilation is classified and at what level.
- Mark the document at the classified level the compilation warrants, including a note in the "Reason" or classification-by-compilation explanation that the classification results from the compilation, so a reader does not wrongly conclude each part is classified.
- Protect and handle the document at that classified level — storage, transmission, and access controls.
Why the simpler answers are wrong
It is tempting to think, "every piece is unclassified, so the document is unclassified." That is exactly the mistake this rule guards against — classification depends on what the combination reveals, not just on the status of each part. It is equally wrong to assume aggregation always produces classified material; it only does so when the compiled whole reveals something meeting the classification standard, which is why a classifier must evaluate it rather than guess.
The bigger picture
Derivative classification is the act of incorporating, paraphrasing, restating, or generating in new form information already classified, and marking the new material consistent with its source or a classification guide. Classification by compilation is a special case where the act of assembling unclassified pieces creates classified information. The safe practice: whenever you aggregate data, pause and check the classification guidance before releasing it.
- 1
Are you combining multiple separate pieces of information into new material?
If yes, the aggregation/compilation rule may apply. Keep going.
- 2
Does the combination reveal a new fact, association, or relationship not obvious from the parts alone?
- 3
Does that revealed fact meet the classification standard?
- 4
Mark, explain, and protect
Frequently asked
What is classification by compilation?
It is the rule that combining individually unclassified pieces of information can produce a classified whole when the compilation reveals an additional fact or relationship that meets the classification standard. The compiled document is then classified and protected accordingly.
Can unclassified information become classified when combined?
Yes. Even if every individual item is unclassified, the aggregation can reveal a sensitive association that qualifies for classification. When that happens, the combined material must be marked and safeguarded at the classified level.
What must a derivative classifier do when aggregating information?
Recognize that the compilation may be classified, consult the security classification guide or an original classification authority, mark the document at the appropriate level with a compilation explanation, and store, transmit, and control access to it at that level.
What is derivative classification?
Derivative classification is incorporating, paraphrasing, restating, or generating in new form information that is already classified, and marking the new material consistent with its source or a classification guide. It differs from original classification, which creates the initial classification decision.