Intelligence chief guarded most sensitive digital data with DCID 6/3
By Vera Kessler ·
Specific methods for protecting the government's most sensitive data remain hidden in a missing manual, though later breaches jeopardized national security for a generation.
On May 24, 2000, the Director of Central Intelligence issued a manual designated as DCID 6/3. The document is titled "Protecting Sensitive Compartmented Information Within Information Systems." According to the file's catalogue entry from the National Security Archive, this manual specifies the roles and responsibilities of organizations tasked with protecting Sensitive Compartmented Information, or SCI, when that information is stored in information systems.
DCID 6/3
The catalogue description notes that the manual covers "security features, administrative security requirements, and risk management." It does not list the specific security features, nor does it name the organizations whose roles are specified. It provides the framework for how the government handles the highest tiers of secrecy once they leave the paper folder and enter the digital realm.
For a records researcher, the gap between a catalogue entry and the full text is where the real story usually hides. We have the table of contents, in a sense, but not the instructions. We know that the DCI wanted to define who was responsible for the data and how the risk should be managed, but the record provided here stops at the description. It tells us the manual exists and what it intends to cover, but the actual text of those requirements—the "how" of the protection—remains absent.
Document imagery from nsarchive.gwu.edu From the files: nsarchive.gwu.edu
SCIF Standards
To understand the stakes of DCID 6/3, one has to understand the physical environment it governs. The public record defines a sensitive compartmented information facility, or SCIF, as a secure facility designed for handling intelligence subject to the United States' Sensitive Compartmented Information system. These facilities are built to specifications dictated by the National Counterintelligence and Security Center.
A SCIF is not merely a locked room. It is a controlled environment designed to prevent electronic eavesdropping and unauthorized physical entry. When SCI is moved into an "information system," as DCID 6/3 addresses, the facility's walls must be supplemented by the "administrative security requirements" mentioned in the archive's description. The manual exists because the digital transfer of data creates leak points that a physical wall cannot stop.
The concept of compartmented information is not new. Records from the State Department's Foreign Relations of the United States (FRUS) series show the Intelligence Advisory Committee meeting as early as 1950 to 1955 to manage the intelligence community's early structures. In those years, "compartmentalization" meant physical folders, locked safes, and a limited number of people with the right clearance to see a specific piece of paper. By the time DCID 6/3 was issued in 2000, the "compartment" had to be translated into the language of information systems.
May 2000
The timing of DCID 6/3 suggests a government grappling with a fundamental shift in how it stores and moves its most sensitive data. Other records from the same period in the National Security Archive highlight a broader preoccupation with network security and the vulnerabilities of the digital age.
By May 2000, the government was operating in the immediate wake of the Y2K panic. The National Infrastructure Protection Center had issued Advisory 88-031 on December 28, 1999, specifically addressing Year 2000 issues. At the same time, the President's National Security Telecommunications Advisory Committee was producing a "Protecting Systems Task Force Report on Enhancing the Nation's Network Security Efforts."
This era also saw the conceptual blending of traditional warfare and digital operations. An April 2000 document from Air University, titled "Space War Meets Info War: The Integration of Space and Information Operations," points to a shift toward viewing information as a theater of conflict. In this environment, a manual like DCID 6/3 is not just a set of rules; it is a response to the realization that information systems are both a tool for intelligence and a target for the opposition.
The catalogue entry for DCID 6/3 tells us the manual specifies the roles of organizations, but it does not name them. It mentions "risk management," but the specific risks the DCI feared at the turn of the millennium are not listed in the summary. We are left with the outline of a security perimeter without knowing where the fences were actually placed.
The effectiveness of these "administrative security requirements" is often measured by what happens when they fail. The National Security Archive holds later records that point to gaps in these systems. A September 2016 report from the House Committee on Oversight and Government Reform discusses the OPM data breach and how the government "jeopardized our national security for more than a generation." Similarly, an October 2016 report from the Office of the Inspector General, Department of Homeland Security, notes that the United States Secret Service "faces challenges protecting sensitive case management systems and data."
These later failures leave the 2000 manual as a marker of intent. DCID 6/3 established who was responsible for the digital vault, but the record stops at the catalogue entry, leaving the specific methods of that protection unspoken.