Understanding and Reporting Security Incidents

image security incident

Understanding security incidents and staying vigilant in our daily work are essential to protecting national security, our organization, our customers, and our data. This month, we’re focusing on how to recognize a security incident, understand the difference between an infraction and a violation, and ensure proper and timely reporting.

 

Defining Security Incidents: Infractions vs. Violations

A security incident is any occurrence that involves, or could reasonably lead to, the loss, compromise, or suspected compromise of classified information or controlled unclassified information (CUI).

While 32 CFR Part 117 (NISPOM) governs classified information requirements, most government contractor organizations operate under multiple federal frameworks (FAR, DFARS, NARA etc.), and incidents involving CUI must also be reported.

Security incidents typically arise when a required security procedure was not followed or was improperly applied. Examples include unsecured classified or CUI documents, improper receipt or handling of information or access credentials, or spillage involving classified information on an unclassified network or CUI on networks not authorized to handle CUI.

Incidents are categorized as either a security infraction or a security violation. It’s easy to confuse these terms, but the distinction is important for determining required responses and reporting.

 

Security Infraction

A Security Infraction is a security incident that does not result in the loss, compromise, or suspected compromise

of classified information. Infractions require an initial inquiry to facilitate immediate actions, identify root causes, and take corrective action to strengthen the security program. Although an infraction is not a security violation, uncorrected or repeated infractions can increase risk and may eventually contribute to a compromise.

 

Security Violation

A Security Violation is a security incident that did or reasonably could result in the loss or compromise of classified information. Violations require a formal investigation, documented analysis, and a final determination.

In either case, Security Incidents can be  intentional, unintentional, or inadvertent and can reveal recent or recurring patterns of questionable judgment, irresponsibility, negligence, or carelessness.

 

How Compromise is Determined

Security incidents are evaluated to determine whether classified information was lost, compromised, suspected of compromise, or not compromised.

Loss: Loss occurs when classified information cannot be physically located or accounted for (for example, material discovered missing during an audit and not immediately located). If classified information is transmitted through unsecure means, it is treated as a loss at a minimum and may be elevated depending on exposure.

Compromise: Compromise occurs when there is an unauthorized disclosure of classified information to an individual who does not possess the appropriate clearance, access authorization, or need‑to‑know.

Suspected Compromise: Suspected compromise occurs when identifiable classified information was made available to unauthorized individuals who may have gained access. Although proving direct access may be difficult, the facts would lead a reasonable person to conclude unauthorized access more than likely occurred. Examples include physical or electronic storage of classified information in unsecured areas for extended periods where unauthorized personnel had unrestricted or unmonitored access.

No compromise: A no‑compromise determination is made when the facts show that no classified information was lost, compromised, or suspected of compromise. Contractors must still produce a final report documenting the incident and determination.

Although compromise determinations under 32 CFR Part 117 (NISPOM) apply primarily to classified information, organizations must make similar assessments related to potential exposure of CUI in accordance with applicable federal requirements.

These determinations guide the required reporting steps and ensure the incident is handled in accordance with 32 CFR Part 117 (NISPOM) requirements.

 

Reporting Security Incidents

 

What to Report

Any event, large or small, that could involve the loss, compromise, or suspected compromise of classified information, or could otherwise affect the confidentiality, integrity, or availability of organizational systems or data, is a security incident and must be reported.

Security incidents may also involve CUI, which must be safeguarded and reported in accordance with federal handling requirements.

Report any occurrence involving:

  • Improper handling, storage, or transmission of classified information or CUI
  • Classified material found in an unapproved or unsecured location
  • Possible loss, compromise, or suspected compromise
  • Unsecure communication channels used for classified discussions or data
  • Spillage of classified onto an unclassified network, system, device, or platform
  • Spillage of CUI onto an unauthorized system, device, network, or platform
  • Improper receipt or handling of classified information or CUI
  • Questionable access situations (e.g., personnel without a verified need‑to‑know near classified material)
  • Passwords, access badges, authentication tokens left out in plain sight
  • Lost or stolen access cards, badges, authentication tokens, materials, etc.
  • Unlocked workstations or devices left unattended
  • Security containers left unlocked in a secured area
  • Anything unusual, unsafe, or out of place involving classified information or security procedures

If you discover anything that may indicate a security procedure was not followed, or may not have been in place, report it immediately. If you’re ever unsure, err on the side of reporting.

 

 

How to Report

All security incidents, whether categorized as infractions or violations, must be reported immediately upon discovery. Prompt reporting allows the security team to:

  • Contain risks before they escalate
  • Investigate root causes, determine the incident category, and determine if classified has been compromised
  • Protect systems, data, and personnel
  • Provide required notifications to the Cognizant Security Agency (CSA) when applicable

A “wait and see” approach creates avoidable gaps that threat actors and environmental factors can easily exploit.

Report all security incidents to the appropriate security POCs immediately upon discovery:

  • Company FSO (always)
  • Host U.S. Government (USG) security staff, if located at a government location
  • Host contractor security staff, if located at another contractor location

Share what you know at the time; additional details can be added as they develop.

You should never be penalized for reporting a concern in good faith. Underreporting introduces far more risk than reporting something that ultimately proves harmless.

Any occurrence that may involve classified information or controlled unclassified information being lost, improperly handled, exposed, accessed by unauthorized individuals, or placed at risk must be reported immediately. If you see something unusual, unsafe, or out of place, report it.

 

 

Why Reporting Matters

Timely reporting is essential to maintaining a secure operating environment. When incidents are reported quickly, security personnel can take immediate action to contain risks, determine whether classified information was exposed, and ensure all requirements under 32 CFR Part 117 are met. Early notification also helps prevent small issues from becoming major vulnerabilities and ensures the organization consistently protects classified information, personnel, and mission objectives. Ultimately, reporting strengthens our overall security posture and supports full compliance with Government standards.

 

Resources and Additional Learning

CDSE Job Aid Special Circumstances for Reporting Security Incidents

CDSE Security Incidents Reporting Requirements

DoD CUI Registry

DoD CUI Policies

NARA CUI References

FAR 52.204-21

DFARS 252.204-7012

CDSE Case Studies

Security Awareness Games

32 CFR Part 117 (NISPOM Rule)

32 CFR Part 147 (Adjudicative Guidelines)

 

As always, if you have any questions…ask your FSO! Your company’s FSO is the best person to help you navigate any questions you have about security compliance, briefing, and reporting requirements. As security professionals, we are here to help you navigate all things security and ensure you fulfill all security requirements.

Related Articles

Unauthorized Disclosure

Unauthorized Disclosure: It’s Not Always Intentional

Unauthorized disclosures rarely begin with bad intentions. More often, they happen during quick conversations, fast moving emails, working in the wrong system, or assuming everyone in the room already has the appropriate need to know.

For those of us supporting the National Industrial Security Program (NISP), protecting classified information and Controlled Unclassified Information (CUI) is part of our daily responsibilities. While cyber and physical security tend to get most of the attention, routine interactions can create risks if we aren’t careful.

Read More
AI Driven Social Engineering

AI Driven Social Engineering: The New Threat Targeting Federal Contractors

Artificial intelligence driven social engineering is no longer a theoretical concern. It is already being used by adversaries to target federal contractors because of the sensitive information, predictable workflows, and publicly visible roles common in this environment. It is important to understand why this threat deserves your attention and how it affects every cleared and uncleared individual.

Read More

Learn how FSO PROS® can help
support your security program

Let’s discuss how we can help support your security and compliance needs.
Secret Link