Sensitive Security Information (SSI) is a category of protected information used by the United States Department of Homeland Security (DHS) and its component agencies, most notably the Transportation Security Administration (TSA). SSI is information whose disclosure could be expected to endanger the safety of transportation systems, compromise security measures, or otherwise threaten public safety.
The concept of SSI was created to balance two competing national interests:
SSI provisions allow agencies to withhold, limit, or control the dissemination of material that falls within this protective envelope while still complying with Freedom of Information Act (FOIA) requirements.
Not every piece of securityrelated data automatically becomes SSI. The regulation (49 CFR Part 1520) defines SSI broadly but gives specific examples, including but not limited to:
| Category | Examples |
|---|---|
| Security procedures | Screening techniques, patrol routes, emergency response plans. |
| Vulnerability assessments | Lists of facilities identified as highrisk, threat analyses. |
| Technical specifications | Design details of detection equipment, software algorithms. |
| Training material | Instructor guides, simulators, roleplaying scenarios. |
| Operational data | Incident reports, passenger screening statistics that could reveal patterns. |
SSI is governed primarily by three statutes and their implementing regulations:
Key regulations include 49 CFR Part 1520 (Defining SSI) and 49 CFR Part 1521 (Handling, marking, and dissemination rules). Violations can result in civil penalties, criminal prosecution, or loss of access privileges.
Proper marking is essential for both internal and external communications. The standard format is:
SENSITIVE SECURITY INFORMATION [Category] [Agency] [Date]
Requirements:
SSI is not permanent. Circumstances may change, allowing for declassification or limited release. The process generally follows these steps:
Common triggers for declassification include:
Understanding SSI is important for a wide range of audiences:
Airlines, railroads, and maritime operators routinely receive SSI that informs security planning. Failure to protect this data can result in fines and, more critically, increased vulnerability.
Researchers often request data for safety studies. Agencies may provide sanitized data sets that remove SSI while preserving analytical value.
Lawyers representing clients in cases involving security incidents must navigate SSI exemptions and may need court orders to obtain protected material.
The public benefits from overall enhanced security, but should not expect detailed operational data that could compromise safety.
SSI is the same as classified information. No. Classification (e.g., Top Secret) is a national security designation handled by the Executive Branch. SSI is a civil security protection under DHS, with different handling rules.
If a document isnt marked, it isnt SSI. Incorrect. Even unmarked material may contain SSI if its content meets the definition. Agencies are responsible for proper marking during creation.
FOIA always overrides SSI. FOIAs Exemption 2 specifically preserves SSI from disclosure, unless the agency determines a compelling public interest outweighs the security risk.
In the past two years, several notable changes have affected SSI handling:
For further reading, consult the following official sources:
Sensitive Security Information is a crucial tool for protecting the United States transportation infrastructure. By clearly defining what constitutes SSI, establishing strict handling procedures, and providing mechanisms for controlled declassification, the government can maintain robust security while still respecting public transparency. All stakeholdersgovernment employees, private sector partners, researchers, and the general publicmust understand and respect SSI requirements to keep the nations transportation systems safe.
