Guide To Official and Sensitive Document Marking

For anyone wondering or might find it handy to know:

3 Likes

Hmm, so merely putting the acronym ā€˜OSā€™ in the filename isnā€™t enough you say?

You shock me sir!

7 Likes

Other things OS could stand for:

Operating System
Official Secrets
Official Solicitor
Original Signed
Ordnance Survey
Open Source

4 Likes

Orifice sore

2 Likes

OpenStack

1 Like

Offal Sausage

3 Likes

Iā€™ve worked somewhere where documents were suffixed with the initials of the uploader.

2 Likes

Sorry to hear that.

4 Likes

Putting OS in the file name would be sufficient if we were trained to recognise it. Unfortunately there are a lot of permanent staff who forget that volunteers are Very Rarely Trained.

1 Like

Thatā€™s not what the guidance says though.

It is important that we are able to identify
this type of information quickly and easily
so that it can be protected appropriately.
Sensitive OFFICIAL information should
always be clearly marked as:
OFFICIAL-SENSITIVE

I disagree, the issue is not with the training, itā€™s the poor practice.

1 Like

Only putting it at the end of the subject line means its particularly hard to identify on mobile too. All I see is first half of subject line and the start of the emailā€¦ could easily not spot it.

1 Like

However, putting OS at the end of the filename or email subject is the standard defence naming convention.

Within Bader MS365 we also have the ability to electronically mark the documents as OFFICIAL-SENSITIVE as well.

This now provides a great opportunity for me to rant about my pet hate - People who mark their routine emails ā€œ-Oā€ at the end. Gaaaaaah. Donā€™t do it!

(Also donā€™t put spaces between the hyphens and remember to put the date right at the beginningā€¦ :wink: )

1 Like

But if we produce documents that are OS, it is still normal/required that it be put in the header and/or footer. I point to all the pers forms as examples of how it should be done!

Using -OS is just for the end of the email subject. If done properly by the book my understanding is that an email should have -OS at the end of the subject line and also OFFICIAL-SENSITIVE written at the start and end of the text body.

The guidance is abundantly clear that every page should have OFFICIAL SENSITIVE on its face.

Because filenames donā€™t show up when you print.

The guidance also says nothing about using the acronym ā€˜OSā€™ being convention. Its laziness, and to someone who has no experience of this convention, like a volunteer, itā€™s meaningless.

1 Like

That is generic guidance which specifically says that it is the readerā€™s responsibility to find out how they are required to mark information.

The defence standard is to put the PM in the header and footer of documents and, iaw with the defence record naming policy, to put the abbreviated marking at the end of filenames and email subject lines.

It isnā€™t laziness, itā€™s protocol and itā€™s easy for anyone to learn, volunteer or not. I donā€™t see the issue.

1 Like

The issue is, that someone didnā€™t follow either the quick guidance here, or the full policy, the document was not protected in accordance with the guidance, but in a lazy manner not even mentioned in the policy.

A volunteer saw the unmarked document, not knowing that a filename ending in ā€˜OSā€™ meant official sensitive. (when no guidance I have seen mentions that) and copied text from it.

And now weā€™re getting flak behind the scenes for their screw up.

(They referring to the document writer, not the volunteer.)

1 Like

Iā€™m sorry, Iā€™ve got no idea what event youā€™re referring to. All Iā€™ve seen is this topic.

We as an organisation must train people in things we want them to know. We canā€™t rely on people randomly deciding to google how the MOD marks documents. We also canā€™t expect them to trawl through hundreds of ACPs and ACTOs to ensure they know everything they need to know for their day-to-day business.

2 Likes

Yes we should. And defence writing is easy so it wouldnā€™t be difficult to do it.
We already have to complete protection of information training which should teach everyone that all information is ā€˜need to knowā€™.
Adding on a simple expanded guide to protective marking would be a simple fix.

1 Like