Security vetting in the United Kingdom

Last updated

In the United Kingdom, government policy requires that staff undergo security vetting in order to gain access to government information.

Contents

The government uses four levels [1] :Annex C,p. 24 of personnel security controls depending on the level of assurance required. Three of these levels are types of national security vetting clearance. [1] :Annex B

Vetting is intended to assure government bodies that the individual has not been involved in espionage, terrorism, sabotage or actions intended to overthrow or undermine Parliamentary democracy by political, industrial or violent means. It also assures the department that the individual has not been a member of, or associated with, an organisation which has advocated such activities or has demonstrated a lack of reliability through dishonesty, lack of integrity or behaviour. Finally, the process assures the department that the individual will not be subject to pressure or improper influence through past behaviour or personal circumstances. [2]

Vetting is usually carried out by United Kingdom Security Vetting (UKSV), a department within the Cabinet Office. [3] UKSV was created in January 2017 by combining DBS National Security Vetting (DBS NSV) and FCDO Services National Security Vetting (FCDOS NSV). [3] This change was an outcome of the Strategic Defence and Security Review 2015. [4]

Security and intelligence agencies such as MI5, MI6 and Government Communications Headquarters carry out their own vetting. The minimum is Developed Vetting and very occasionally Enhanced Security Check.

It is possible to pass vetting with one department yet fail it with another as vetting is tailored to the role/department. Clearances can be transferred between departments. Holders of vetting clearance may face travel restrictions on private travel to high-risk countries.

Vetting in the UK is currently undergoing change as part of the Vetting Transformation Programme. This will see a series of "Levels" introduced and the phasing out of the current nomenclature. These new levels will be broadly:

Note: Baseline Personnel Security Standard (BPSS) is not considered a formal security clearance level but this, or an equivalent background check, is used to underpin all vetting.

The target date for this transformation is 2025. Level 1B was introduced October 2022 and is currently the only "new" level operating.

Types of personnel security check

Baseline Personnel Security Standard (BPSS)

The Baseline Personnel Security Standard (BPSS) checks are normally performed when a person is recruited.

All those with access to government assets are subject on recruitment to the requirements of the Baseline Personnel Security Standard. This includes all applicants for employment in the civil service and armed forces and applies to both permanent and temporary staff and private sector employees working on government contracts, with access to government assets.

The Baseline Personnel Security Standard requires the verification of the following four elements:

  1. Identity [1] :7(a)
  2. Employment history (past three years) [1] :7(b)
  3. Nationality and immigration status [1] :7(c)
  4. Criminal record (unspent convictions only) [1] :7(d)

A reasonable account of any significant periods (a total of 6 months or more in the past 3 years) spent abroad. [1] :Annex B Prospective employees who have recently come to the UK or lived abroad may be asked to provide overseas police certificates of good conduct. [1] :7(d)

BPSS [1] :Annex B

Employers may initiate the following incremental national security vetting checks on recruits after performing the BPSS check.

Counter Terrorist Check (CTC)/Level 1B

A Counter Terrorist Check (CTC)/Level 1B is required for individuals who are employed in posts that: [1] :Annex B

The process for CTC clearance includes:

A CTC/Level 1B clearance must be formally reviewed after ten years (five years for non-List X Contractors). [1] :Annex B

In the transport sector security vetting requirements, including for Counter Terrorist Check, is regulated by the Department of Transport. [6]

A CTC/Level 1B is required for police officers and many associated staff. [7]

Security Check (SC)

A Security Check (SC) is the most widely held level of security clearance. [8] SC is required for posts involving regular and uncontrolled access to SECRET assets and/or occasional, supervised access to TOP SECRET assets, [8] and for individuals who: [1] :Annex B

The process for SC clearance includes:

Checks may extend to third parties included on the security questionnaire.

An SC security clearance must be formally reviewed after ten years (seven years for non-List X contractors) or at any time up to that point at the discretion of the vetting authority. [1] :Annex B

Enhanced Security Check (eSC)

This is similar to an SC but also includes a financial questionnaire and may include an interview with a vetting officer. It is a pre-requisite for the granting of access to STRAP codeword material at the SECRET level.

Developed Vetting (DV)

DV is one of the most detailed and comprehensive form of security clearance in UK government. It is needed for posts that require individuals to have frequent and uncontrolled access to TOP SECRET assets, or require any access to TOP SECRET codeword material. It is also required for individuals who:

The process for DV clearance includes:

A DV security clearance must be reviewed every seven years or at any time up to those points at the discretion of the vetting authority. [1] :Annex B

Enhanced Developed Vetting (eDV)

Enhanced Developed Vetting requires additional in-depth interviews, beyond that of DV, including a full list of all foreign travel within the last 10 years. It is required for a limited number of highly sensitive roles and can only be requested by a small number of government departments. [9]

STRAP

STRAP is a code-word, combined with SECRET or TOP SECRET, to further restrict access to particularly sensitive material.

Access is granted to certain holders of Enhanced SC (eSC) or (Enhanced) Developed Vetting (DV/eDV) clearance, allowing them to access SECRET/TOP SECRET STRAP code-word material:

This is commonly referred to as holding "STRAP Clearance".

Whilst comparatively little is known of the requirements to obtain such a level of clearance, it is mentioned by UK government bodies on occasion in recruitment, policy and procurement documents. [10] [11] [ dead link ]

Caveats/Nationality Restrictions

A clearance of any level can be granted with "caveats" which may restrict the holder from accessing certain types of material, for example relating to specific countries, regions or projects. Where there is an explicit requirement for the viewer of a document to be a UK Citizen, the individual must hold a clearance with no "caveats" and be deemed to meet "UK Eyes Only". Further restrictions can include "No Dual Nationals".

Clearance Aftercare

Change of personal circumstances

A change of personal circumstances (CPC) questionnaire has to be submitted when a CTC, SC, eSC, DV, eDV, STRAP clearance holder is "marrying, remarrying, entering into a civil partnership, setting up a stable unmarried relationship which includes living with someone as a couple", "due to significant changes in financial circumstances" or "due to contact with law enforcement". DV clearance holders also have to report the arrival of new "co-residents" such as a lodger or flatmate. [3]

Annual Security Appraisals/Aftercare Reports

Holders of eSC, DV and eDV must annually complete a "Security Appraisal Form" (SAF) in conjunction with their line management, detailing any areas of concern or changes in circumstances that have occurred in the previous year which have yet to be notified to UKSV.

Any issues that require immediate notification to UKSV during the year are either self-reported as a change in circumstances, or if caused by a security issues filed as an "Aftercare Incident Report".

Transfer of a clearance

A request can be made to transfer national security clearances between organisations, providing they have not expired. Transfers are requested by the "new employing sponsor". Transfers can be the same level of clearance or a lower level clearance can be "extracted" from a higher level clearance (usually SC extracted from DV). No more than twelve months must have elapsed since the holder left the organisation for which the clearance was originally granted and no more than six months spent living overseas. New completed change of circumstances questionnaires, to bring the UKSV and departmental records up to date, may be required. [3] The new sponsor reviews the details of the clearance and decides if it is acceptable for the specific new role. [1] :44

Other Checks

Disclosure and Barring

In addition to national security clearances, other types of roles and organisations stipulate a need for background checks, these are often required for vulnerable group access (including children), as operated by the Disclosure and Barring Service (DBS), replacing former Criminal Records Bureau (CRB) and Independent Safeguarding Authority (ISA) checks.

Police Vetting

The police service has its own system of vetting:

Force Vetting [12] with a hierarchy of Police Personnel Vetting (PPV) and Non-Police Personnel Vetting (NPPV) levels.

Within this there are several levels. For police officers, there is:

For civilian police staff and contractors, there is "non-police personnel vetting":

When an actual SC, eSC, or DV is required alongside Force Vetting, it is carried out by UKSV.

Related Research Articles

<span class="mw-page-title-main">MI5</span> British domestic intelligence agency

The Security Service, also known as MI5, is the United Kingdom's domestic counter-intelligence and security agency and is part of its intelligence machinery alongside the Secret Intelligence Service (MI6), Government Communications Headquarters (GCHQ), and Defence Intelligence (DI). MI5 is directed by the Joint Intelligence Committee (JIC), and the service is bound by the Security Service Act 1989. The service is directed to protect British parliamentary democracy and economic interests and to counter terrorism and espionage within the United Kingdom (UK).

<span class="mw-page-title-main">Counterintelligence</span> Offensive measures using enemy information

Counterintelligence (counter-intelligence) or counterespionage (counter-espionage) is any activity aimed at protecting an agency's intelligence program from an opposition's intelligence service. It includes gathering information and conducting activities to prevent espionage, sabotage, assassinations or other intelligence activities conducted by, for, or on behalf of foreign powers, organizations or persons.

<span class="mw-page-title-main">Classified information</span> Material that government claims requires confidentiality

Classified information is material that a government body deems to be sensitive information that must be protected. Access is restricted by law or regulation to particular groups of people with the necessary security clearance and need to know. Mishandling of the material can incur criminal penalties.

A security clearance is a status granted to individuals allowing them access to classified information or to restricted areas, after completion of a thorough background check. The term "security clearance" is also sometimes used in private organizations that have a formal process to vet employees for access to sensitive information. A clearance by itself is normally not sufficient to gain access; the organization must also determine that the cleared individual needs to know specific information. No individual is supposed to be granted automatic access to classified information solely because of rank, position, or a security clearance.

Eyes only is jargon used with regard to classified information. Whereas a classified document is normally intended to be available to readers with the appropriate security clearance and a need to know, an "eyes only" designation, whether official or informal, indicates that the document is intended only for a specific set of readers. As such the document should not be read by other individuals even if they otherwise possess the appropriate clearance. Another meaning is that the document is under no circumstances to be copied or photographed, "eyes only" meaning that it is to be physically read by cleared personnel and nothing more, to ensure that no unauthorized copies of the text are made which might be unaccounted for.

A credential is a piece of any document that details a qualification, competence, or authority issued to an individual by a third party with a relevant or de facto authority or assumed competence to do so.

<span class="mw-page-title-main">Disclosure and Barring Service</span> UK Government body for background checks

The Disclosure and Barring Service (DBS) is a non-departmental public body of the Home Office of the United Kingdom. The DBS enables organisations in the public, private and voluntary sectors to make safer recruitment decisions by identifying candidates who may be unsuitable for certain work, especially involving children or vulnerable adults, and provides wider access to criminal record information through its disclosure service for England and Wales.

The United States government classification system is established under Executive Order 13526, the latest in a long series of executive orders on the topic of classified information beginning in 1951. Issued by President Barack Obama in 2009, Executive Order 13526 replaced earlier executive orders on the topic and modified the regulations codified to 32 C.F.R. 2001. It lays out the system of classification, declassification, and handling of national security information generated by the U.S. government and its employees and contractors, as well as information received from other governments.

<span class="mw-page-title-main">Q clearance</span> U.S. Department of Energy security clearance level

Q clearance or Q access authorization is the U.S. Department of Energy (DOE) security clearance required to access Top Secret Restricted Data, Formerly Restricted Data, and National Security Information, as well as Secret Restricted Data. Restricted Data (RD) is defined in the Atomic Energy Act of 1954 and covers nuclear weapons and related materials. The lower-level L clearance is sufficient for access to Secret Formerly Restricted Data (FRD) and National Security Information, as well as Confidential Restricted Data and Formerly Restricted Data. Access to Restricted Data is only granted on a need-to-know basis to personnel with appropriate clearances.

Classified information in the United Kingdom is a system used to protect information from intentional or inadvertent release to unauthorised readers. The system is organised by the Cabinet Office and is implemented throughout central and local government and critical national infrastructure. The system is also used by private sector bodies that provide services to the public sector.

A Single Scope Background Investigation (SSBI), now called a Tier 5 (T5) investigation, is a type of United States security clearance investigation. It involves investigators or agents interviewing past employers, coworkers and other individuals associated with the subject of the SSBI. It is governed by the U.S. Intelligence Community Policy Guidance Number 704.1.

The counter-terrorism page primarily deals with special police or military organizations that carry out arrest or direct combat with terrorists.

An Aviation Security Identification Card (ASIC) is an Australian identification card that shows that the holder of the card has undergone a security check and is suitable to enter a secure area of an Australian Airport. Security checks are performed by AusCheck and include a criminal records check undertaken by the Australian Federal Police, a security assessment conducted by the Australian Security Intelligence Organisation (ASIO) and an unlawful non-citizen check conducted by the Department of Home Affairs. An ASIC is required for all personnel working at a security controlled airport in Australia. Personnel requiring access to a secure airport who are under the age of 18 are required to display an ASIC however issuing bodies can not apply for a security check. An ASIC has to be renewed every two years except for someone who has applied for an ASIC before they turned 18 in which case an ASIC is valid until 6 months after the person's 18th birthday. Only people with an operational need to enter a secure airport may apply for an ASIC. The goal of the ASIC is not just to prevent terrorist activities at airports but to ensure aircraft, equipment and facilities can not be tampered with.

<span class="mw-page-title-main">Security guard</span> Person employed to protect properties or people

A security guard is a person employed by a government or private party to protect the employing party's assets from a variety of hazards by enforcing preventative measures. Security guards do this by maintaining a high-visibility presence to deter illegal and inappropriate actions, looking for signs of crime or other hazards, taking action to minimize damage, and reporting any incidents to their clients and emergency services, as appropriate.

e-QIP

e-QIP is a secure website managed by OPM that is designed to automate the common security questionnaires used to process federal background investigations. e-QIP was created in 2003 as part of the larger e-Clearance initiative designed to speed up the process of federal background investigations conducted by OPM's Federal Investigative Services (FIS). e-QIP is a front end data collection tool that has automated the SF-86, questionnaire for national security investigations as well as the SF-85P, the questionnaire for public trust positions. e-QIP allows applicants for federal jobs to enter, edit and submit their investigation data over a secure internet connection to their sponsoring agency for review and approval.

The Norwegian Defence Security Department (NORDSD) is a joint security and counter-intelligence military intelligence service within the Norwegian Armed Forces. Its members are a mix of civilian employees and military personnel. The head of the service holds the military rank Colonel or (naval) captain.

<span class="mw-page-title-main">Ministry of Defence Police</span> Civilian police force of the United Kingdoms Ministry of Defence

The Ministry of Defence Police (MDP) is a civilian special police force which is part of the United Kingdom's Ministry of Defence. The MDP's primary responsibilities are to provide armed security and counter terrorism services to designated high-risk areas, as well as uniformed policing and limited investigative services to Ministry of Defence property, personnel, and installations throughout the United Kingdom. The MDP are not military police. Service personnel often refer to the MDP by the nickname "MOD plod".

USIS (US Investigation Services) was a US corporation that provided security-based information and service solutions to both government and corporate customers, in the United States and abroad. Its corporate headquarters were in Falls Church, Virginia, in Greater Washington, D.C. Training took place in Boyers, Pennsylvania. USIS was a part of Altegrity Inc., a company headquartered in the Falls Church area that was owned by Providence Equity Partners.

The Government Security Classifications Policy (GSCP) is a system for classifying sensitive government data in the United Kingdom.

References

  1. 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 HMG Personnel Security Controls (Version 3.0). www.gov.uk: Cabinet Office. 2017. Retrieved 10 January 2018.
  2. Hansard, Written answers 15 Dec 1994 Hansard online
  3. 1 2 3 4 "Guidance United Kingdom Security Vetting". GOV.UK. His Majesty's Government. Retrieved 5 June 2017.
  4. National Security Strategy and Strategic Defence and Security Review 2015 (PDF) (Report). HM Government. November 2015.
  5. "HMG Personnel Security Controls (HTML)". GOV.UK. Retrieved 15 November 2023.
  6. "National security vetting in the regulated transport industry". GOV.UK website. His Majesty's Government. Retrieved 30 January 2014.
  7. "P04e National Security Vetting". Kent Police. Retrieved 27 October 2014.
  8. 1 2 Subjects information leaflet. Ministry of Defence. Retrieved 26 March 2018.
  9. "National Security Vetting". Security Cleared Expo. Retrieved 11 September 2018.
  10. "A Technical Architect Supporting Development of Service Delivery to Defence and PAG - Digital Marketplace".[ dead link ]
  11. "Minimum User Clearance Requirements Guide - MoJ Security Guidance".[ dead link ]
  12. Chalk, Peter; William Rosenau; Martin Wachs; Myles Collins; Mark Hanson (2004). Confronting the "enemy within": security intelligence, the police, and counterterrorism in four democracies. RAND Corporation. JSTOR   10.7249/mg100rc .