Understanding security incidents and staying vigilant in our daily work are essential to protecting national security, our organization, our customers, and our data. This month, we’re focusing on how to recognize a security incident, understand the difference between an infraction and a violation, and ensure proper and timely reporting.
Defining Security Incidents: Infractions vs. Violations
A security incident is any occurrence that involves, or could reasonably lead to, the loss, compromise, or suspected compromise of classified information or controlled unclassified information (CUI).
While 32 CFR Part 117 (NISPOM) governs classified information requirements, most government contractor organizations operate under multiple federal frameworks (FAR, DFARS, NARA etc.), and incidents involving CUI must also be reported.
Security incidents typically arise when a required security procedure was not followed or was improperly applied. Examples include unsecured classified or CUI documents, improper receipt or handling of information or access credentials, or spillage involving classified information on an unclassified network or CUI on networks not authorized to handle CUI.
Incidents are categorized as either a security infraction or a security violation. It’s easy to confuse these terms, but the distinction is important for determining required responses and reporting.
Security Infraction
A Security Infraction is a security incident that does not result in the loss, compromise, or suspected compromise
of classified information. Infractions require an initial inquiry to facilitate immediate actions, identify root causes, and take corrective action to strengthen the security program. Although an infraction is not a security violation, uncorrected or repeated infractions can increase risk and may eventually contribute to a compromise.
Security Violation
A Security Violation is a security incident that did or reasonably could result in the loss or compromise of classified information. Violations require a formal investigation, documented analysis, and a final determination.
In either case, Security Incidents can be intentional, unintentional, or inadvertent and can reveal recent or recurring patterns of questionable judgment, irresponsibility, negligence, or carelessness.
How Compromise is Determined
Security incidents are evaluated to determine whether classified information was lost, compromised, suspected of compromise, or not compromised.
Loss: Loss occurs when classified information cannot be physically located or accounted for (for example, material discovered missing during an audit and not immediately located). If classified information is transmitted through unsecure means, it is treated as a loss at a minimum and may be elevated depending on exposure.
Compromise: Compromise occurs when there is an unauthorized disclosure of classified information to an individual who does not possess the appropriate clearance, access authorization, or need‑to‑know.
Suspected Compromise: Suspected compromise occurs when identifiable classified information was made available to unauthorized individuals who may have gained access. Although proving direct access may be difficult, the facts would lead a reasonable person to conclude unauthorized access more than likely occurred. Examples include physical or electronic storage of classified information in unsecured areas for extended periods where unauthorized personnel had unrestricted or unmonitored access.
No compromise: A no‑compromise determination is made when the facts show that no classified information was lost, compromised, or suspected of compromise. Contractors must still produce a final report documenting the incident and determination.
Although compromise determinations under 32 CFR Part 117 (NISPOM) apply primarily to classified information, organizations must make similar assessments related to potential exposure of CUI in accordance with applicable federal requirements.
These determinations guide the required reporting steps and ensure the incident is handled in accordance with 32 CFR Part 117 (NISPOM) requirements.
Reporting Security Incidents
What to Report
Any event, large or small, that could involve the loss, compromise, or suspected compromise of classified information, or could otherwise affect the confidentiality, integrity, or availability of organizational systems or data, is a security incident and must be reported.
Security incidents may also involve CUI, which must be safeguarded and reported in accordance with federal handling requirements.
Report any occurrence involving:
- Improper handling, storage, or transmission of classified information or CUI
- Classified material found in an unapproved or unsecured location
- Possible loss, compromise, or suspected compromise
- Unsecure communication channels used for classified discussions or data
- Spillage of classified onto an unclassified network, system, device, or platform
- Spillage of CUI onto an unauthorized system, device, network, or platform
- Improper receipt or handling of classified information or CUI
- Questionable access situations (e.g., personnel without a verified need‑to‑know near classified material)
- Passwords, access badges, authentication tokens left out in plain sight
- Lost or stolen access cards, badges, authentication tokens, materials, etc.
- Unlocked workstations or devices left unattended
- Security containers left unlocked in a secured area
- Anything unusual, unsafe, or out of place involving classified information or security procedures
If you discover anything that may indicate a security procedure was not followed, or may not have been in place, report it immediately. If you’re ever unsure, err on the side of reporting.
How to Report
All security incidents, whether categorized as infractions or violations, must be reported immediately upon discovery. Prompt reporting allows the security team to:
- Contain risks before they escalate
- Investigate root causes, determine the incident category, and determine if classified has been compromised
- Protect systems, data, and personnel
- Provide required notifications to the Cognizant Security Agency (CSA) when applicable
A “wait and see” approach creates avoidable gaps that threat actors and environmental factors can easily exploit.
Report all security incidents to the appropriate security POCs immediately upon discovery:
- Company FSO (always)
- Host U.S. Government (USG) security staff, if located at a government location
- Host contractor security staff, if located at another contractor location
Share what you know at the time; additional details can be added as they develop.
You should never be penalized for reporting a concern in good faith. Underreporting introduces far more risk than reporting something that ultimately proves harmless.
Any occurrence that may involve classified information or controlled unclassified information being lost, improperly handled, exposed, accessed by unauthorized individuals, or placed at risk must be reported immediately. If you see something unusual, unsafe, or out of place, report it.
Why Reporting Matters
Timely reporting is essential to maintaining a secure operating environment. When incidents are reported quickly, security personnel can take immediate action to contain risks, determine whether classified information was exposed, and ensure all requirements under 32 CFR Part 117 are met. Early notification also helps prevent small issues from becoming major vulnerabilities and ensures the organization consistently protects classified information, personnel, and mission objectives. Ultimately, reporting strengthens our overall security posture and supports full compliance with Government standards.
Resources and Additional Learning
CDSE Job Aid Special Circumstances for Reporting Security Incidents
CDSE Security Incidents Reporting Requirements
32 CFR Part 147 (Adjudicative Guidelines)
As always, if you have any questions…ask your FSO! Your company’s FSO is the best person to help you navigate any questions you have about security compliance, briefing, and reporting requirements. As security professionals, we are here to help you navigate all things security and ensure you fulfill all security requirements.

