Ron Lloyd BETWEEN INTENT AND OUTCOMES

Home / Published Work / Canada's Security Classification Framework

POLICY PERSPECTIVECANADIAN GLOBAL AFFAIRS INSTITUTEJUNE 2024

Canada's Security Classification Framework

The Biggest Impediment to Realizing Our Digital Ambition

Security & Assurance Digital Government & Procurement

SYNOPSIS

Canada adopted its security classification framework more than 40 years ago, when the only considerations for the security of digital data were physical and the classification dictated which filing cabinet the disk was locked in. This paper argues that the framework has become the biggest impediment to realizing Canada's Digital Ambition. It assigns the same level of injury to two different classifications, so that the compromise of personal or administrative data is treated as equivalent to the compromise of information in the national interest, a position no ally shares. The consequence is a culture of over-classification that precludes technologies Canadians use every day, drives up the cost of the digital enterprise, adversely affects procurement and the Contract Security Program, and reduces interoperability with allies. The paper recommends a three-tier framework of Top Secret, Secret and Official, placed in the body of the Policy on Government Security, together with changes to how levels of injury, data aggregation and privacy impact assessment are defined.

“Policy, not culture, drives the security classification framework, directs an elevated risk sensitivity/level of injury, and requires departments to proactively mitigate risk.”

From the paper, page 18

KEY FINDINGS

  1. 1

    Two different classifications, one level of injury. Canada assigns the same level of injury to Top Secret and Protected C, to Secret and Protected B, and to Confidential and Protected A. The paper states that all nations other than Canada recognize that the loss of classified information in the national interest results in greater injury than the loss of information that is not.

  2. 2

    The framework was built for filing cabinets. In the 1980s the classification determined whether the floppy disk, hard disk, laptop or USB was locked in a filing cabinet, a cabinet with a locking bar, or one with a Sargent and Greenleaf lock. The implications were insignificant when everything was physical. They are not insignificant in a digital world.

  3. 3

    Canada is out of step with its allies. The paper compares Canada's framework with those of its closest allies. It reports that the United Kingdom implemented a new framework in 2014 and notes explicitly that 90 per cent of its data holdings should sit at the lowest classification; that Australia followed in 2018; and that the United States classifies only national security data, its executive order directing that where there is significant doubt about the need to classify, information shall not be classified.

  4. 4

    Over-classification carries documented costs. It prevents important information reaching a decision maker in time, accrues physical and IT storage costs, creates volumes too large to protect adequately, desensitizes understanding of what is actually classified, increases demand for security clearances, limits public access to the historical record, and reinforces a culture of risk aversion.

  5. 5

    A classification decision propagates through the wider institutional system. The paper argues that the implications of the framework affect almost all government operations, including procurement, and traces them through privacy impact assessment, the Contract Security Program, security screening, technology choices and interoperability with allies. The cost is visible in clearances: roughly 750,000 status and security clearances are held by non-public servants, about 490,000 reliability, 245,000 Secret and 15,000 Top Secret, with some 75,000 renewals each year. Of 74 core and non-core departments, the paper assesses that 54 would not require access to Secret information under an allied level of injury, and that a Treasury Board Secretariat requirement for 100 per cent of personnel to hold a Secret clearance would fall to roughly 20 per cent.

  6. 6

    Changing the classification framework alone would not be enough. Because classification reaches into other security regimes, the paper argues that as the connected policies are amended the opportunity should be taken to align terminology across data, physical, network and personnel security, naming the RCMP physical security zones guide, the CSE baseline requirement for network security zones and the OCIO standard on security screening. Its illustration is a public servant holding an Official clearance to reach official data, on an official network zone, in an official physical zone. The purpose is to avoid gaps and seams, and to ensure the reform is not simply words on a page but a change in the culture and the business.

RECOMMENDATIONS

A three-tier frameworkAdopt Top Secret, Secret and Official, with the handling instructions Official - For Public Release and Official-Sensitive. Place it in the body of the Policy on Government Security rather than in a directive.
Codify the level of injuryDefine the level of injury and business impact for each categorization across business lines, aligned with closest allies, particularly for Secret. Consider rescinding TRA-1, or redeveloping it after the frameworks are amended.
Define data aggregationRecognize that where aggregation increases risk, the mechanism to mitigate it is access and controls, not a higher classification, unless a new data set is created.
A principles approach to privacyThe paper recommended amending the then-current Directive on Privacy Impact Assessment: make Appendix C a tool rather than a requirement, and replace the inflexible risk categorization in Section II with a framework that lets departments characterize and mitigate risk properly.

WHERE THIS FITS

Added September 2026

This was the first paper in the series. It examined a single policy instrument, the security classification framework, and traced its consequences through procurement, security clearances, privacy assessment and the ability of government to use ordinary commercial technology. Its closing observation, that policy rather than culture drives the framework, became the starting point of the next paper, which moved from the instrument to the machinery that produces institutional behaviour.

ABOUT THE AUTHOR

Vice-Admiral (Ret'd) Ron Lloyd was the 35th Commander of the Royal Canadian Navy and is a Fellow of the Canadian Global Affairs Institute. Transparency →