(Updated: March 16, 2026)
Most of the documents leaked by Edward Snowden are from the American signals intelligence agency NSA, but there are also quite a number from their British counterpart GCHQ. Documents from both countries are classified as TOP SECRET and often have additional markings to further restrict their dissemination.
Where on American documents we see markings like COMINT (Communications Intelligence) and NOFORN (No Foreign Nationals), the British have the mysterious term STRAP followed by a number.
Information about American classification and dissemination markings can rather easily be found on the internet (see also The US classification system on this weblog), but there are hardly any details about the British classification system.
But luckily, there's one source available which describes STRAP and other British classification practices in detail: the extensive Defence Manual of Security from 2001. Chapter 17 (page 1131-1135) of Volume 1 gives an overview of the STRAP Security Guidelines.
Compartmentalization
In the manual, STRAP is described as a set of nationally agreed principles and procedures to enhance the "need-to-know" protection of sensitive intelligence (and related operational information) produced by the British intelligence agencies, including military sources.
It adds additional procedures to the standard security measures employed for intelligence matters. STRAP is therefore comparable with the American system of protecting the most sensitive information by control systems with separate compartments, which are generally designated by codewords.
Although on some websites it's suggested that STRAP might stand for "STRategic Action Plan", the Defence Manual clearly states that STRAP is a codeword, not an acronym. The STRAP codeword itself is not classified.
Some intelligence information, handled within the STRAP System, require more stringent protection than others. To assure this, there are three levels of STRAP protection. These levels are designated, in ascending order of sensitivity and, hence, access control: STRAP 1, STRAP 2 and STRAP 3.
Examples of STRAP documents
An example of a document from the least sensitive category, marked STRAP 1, is a slide from a powerpoint presentation about the BULLRUN program aimed at breaking encryption methods used on the internet:

Information that is somewhat more sensitive is marked STRAP 2, like this presentation slide about operation SOCIALIST, which infiltrated the network of the Belgian telecommunications provider Belgacom:

From the category of most sensitive documents, marked STRAP 3, there are no actual examples available. STRAP 3 for example protects the precise locations where these interceptions takes place. The real names of the telecommunication companies that cooperate with GCHQ are classified one level below this, at STRAP 2.
As several of these real names have been published, Snowden must somehow got access even to STRAP 3 documents. Probably because they are so sensitive, Greenwald and the papers may have decided not to publish them, but only use some of the information they contain.
STRAP protection measures
The STRAP system is designed to protect information against threats that are specific for sensitive intelligence. A principal threat is when a target becomes aware of an intelligence attack against him, so he can initiate countermeasures. Therefore, the STRAP system aims to minimise the risk of leakage of sensitive intelligence operations and products into the public domain - whether by accidental exposure or deliberate intent. This is done through the following measures:
- Restricting access to sensitive intelligence material on a strict "need-to-know" basis;
- Agreeing the appropriate facilities for its protection in transit ("STRAP Channels") use, storage and disposal;
- Providing explicit briefings and guidance for individuals who handle this type of material.
Information that requires protection under the STRAP system has to be clearly defined and labelled with the appropriate STRAP level marking. It has to be carried by authorized couriers during transit, and signed receipts have to be obtained at all stages of handover.
Within the British Ministry of Defence, the implementation of the approved STRAP security measures is overseen by individually appointed STRAP Security Officers (STRAPSOs). The overall responsibility for the review and formulation of STRAP policy and guidelines is with the STRAP Management Board.
Update:
According to documents from the British Foreign, Commonwealth and Development Office (FCDO) released in March 2026, a STRAP clearance is role specific, which means that when assuming a new job or function, a new STRAP application form has to be submitted. This has to be accompanied by Developed Vetting (DV), which is the highest level of security vetting in the UK.
According to documents from the British Foreign, Commonwealth and Development Office (FCDO) released in March 2026, a STRAP clearance is role specific, which means that when assuming a new job or function, a new STRAP application form has to be submitted. This has to be accompanied by Developed Vetting (DV), which is the highest level of security vetting in the UK.
11 comments:
So strap1 and strap2 are ok to share across FVEY? As FVEY stuff comes in from NSA, does GCHQ classify some of it internally as Strap? Did not some employee leave strap2 docs on the train recently, turned to bbc?
http://www.bbc.co.uk/blogs/theeditors/2008/06/topsecret_files.html
Bbc strap1 docs from 2008 - odd thing was only strap1 despite AQ intel - how do we actually know that strap3 is highest, not lowest?
At the moment, it's not clear what the rules are for sharing STRAP information among partner agencies. However, it's interesting that on some documents we see TOP SECRET STRAP combined with the American marking COMINT or with "[country code] Eyes Only". In those cases it's quite clear that the information can be shared with partners. But if that means that STRAP documents without any further markings are restricted to UK nationals, it's strange indeed that Snowden had access to them.
The fact that STRAP 1 is the lowest and STRAP 3 the highest level, is said in the Defence Security Manual from 2001.
Goedenavond, P/K, en gelukkig nieuwjaar,
[blockquote]The STRAP system is designed to protect information against threats that are specific for sensitive intelligence. A principal threat is when a target becomes aware of an intelligence attack against him, so he can initiate countermeasures. Therefore, the STRAP system aims to minimise the risk of leakage of sensitive intelligence operations and products into the public domain - whether by accidental exposure or deliberate intent. This is done through the following measures:
- Restricting access to sensitive intelligence material on a strict "need-to-know" basis;
- Agreeing the appropriate facilities for its protection in transit ("STRAP Channels") use, storage and disposal;
- Providing explicit briefings and guidance for individuals who handle this type of material.[/blockquote]
There is a enigmatic problem, which in some cases can be easily immediately resolved and solved by the ignorant transfer of fantastic paper wealth to the prime subject and object of interest …. and a seriously heavy lottery win is a great cover story for such an unexpected windfall and radical change of circumstance …. and that is whenever the sensitive intelligence being shared is not the intellectual property or coveted secret of any existing authority and/or intelligence service and/or associate body.
And there is no good reason at all to not suppose that such largesse would result in a novel working, mutually beneficial arrangement between the subject/object of interest and the parties who would have concerns which they be unwilling or unable to resolve themselves.
It be in the fields being discussed here akin to the smart poacher turned great gamekeeper play.:-) …. and oh so simple to try.
After all, it is only worthless fiat being exchanged for sublime treasure, is it not, and that makes virtually everything a real basement bargain.
Great post! Been reading a lot about data leak situations like this. Thanks for the info here!
http://o-thrax.blogspot.gr/2014/12/top-secret-srap.html
Bit late to the game but here are some answers for you (source: Working for the MOD): The fact that a document is 'STRAPped' doesn't automatically mean it cannot be shared with other nations. Just as you can have a document marked SECRET UK/US EYES ONLY, you can have a TOP SECRET STRAP2 UK/US EYES ONLY. Yes, you're more likely to come across UK EYES ONLY when you have a STRAP document, but it's not exclusively like that. And to confirm, STRAP3 is the most sensitive... It's actually split into STRAP3a and STRAP3b too...
There is an example of STRAP3 out there. A project FULSOME GCHQ memo has TS STRAP3 markings. https://noagendasocial.com/@RexRedbone/110411697636513278
Try calling your cellular provider in UK. Enjoy as they mention things to make you annoyed or paranoid like, "you know what I do if I have problems? Sit by my bedroom window and make phone calls." What a coincidence? That's where your sitting. Enjoy contacting Netflix because the paid service you are using is being throttled, paused constantly on a stable network and their Man-In-The-Middle spies purposefully give you the wrong number to the energy company in Scotland. No joke. They intercept calls and messages and play childish, immature games that an insane alcoholic given a clearance would do. Went to a cell phone store to check out phones and contemplate switching service and phones and somebody calls the Indian guy up and he starts saying "let me see your phone real quick" THEN he takes a picture of the IMEI and serial number, phone number, etc. on the settings area and hands it back to me so he can send it to somebody that was already stalking me and watching my movements. I was just explaining a problem and he acted like he knew some magical setting but wanted the personal data for somebody.
Went to my cellular provider store and had a black woman take my SIM card out and put it into another "store model" phone and she started walking around doing stuff on the phone. I asked for it back because checking my SIM card was not normal that way. I got ahold of the device she was using and she was activating my SIM card and phone number on a dozen black peoples' accounts. I took a picture of them. Then over the next couple months I would get SMS saying "your password has been changed for [insert black persons' email/Gmail]" in the middle of night when the store was closed. It wasn't just a floor model display. It had prepared accounts to be finalized or activated when a SIM card was plugged in. Some were photos of black teenagers which means they could download any mobile apps through their new Google Play Store accounts utilizing a different person's phone number (MINE) then move the accounts to different devices or potentially clone the/my SIM. The customer service people said it's not normal and was a scam. COMPLETLEY normal in London though.
Dozens of scams, stealing, spycop entrapment techniques and street theater in UK. They are muppets for the US and will harass, help US with repatriation, order Metropolitan Police Department to do nothing when you're a victim of crimes, death threats, assault, assault with a deadly weapon, get tricked to going to job interviews when they are doing liberal XR/PETA protests in the area, steal the latest Apple iPhone underneath CCTV Starbucks cameras and then they (spycops or agents that probably sent the thief inside) immediately and coincidentally called the Starbucks Store's GM and told her not to call the Met Police for me the victim of a theft of $1000+ phone, etc, etc etc.
Corrupt country just like US! It's not about securing their borders, protecting their citizens, or helping people. It's about immature gamification, job security, and creating or manufacturing criminals or terrorists just like Snowden said and discovered in Top Secret pdf's. Workplaces are no different including Irish based HQ hotel chains inside UK or City of London. Gaslighting, stealing, weaponizing Labour Party supporters, weaponizing minority groups, encouraged theft and promoted those that were stealing, committed entrapment, theft under CCTV's by managers that they would not do anything about, committed wage theft, hired staff that didn't know what they were doing or were lying about experience then people were paying them abnormal and excessive amounts for tips (that were extremely rare), eavesdropping conversations and was warned by a manager before he left, they used hotel as living space for Met Police, US police/agents, increased room costs (essentially money laundering), etc.
Housing scams are extremely prevalent too. Asking to transfer money to people to view rentals. Hidden shell/business accounts. "Transfer money to this [insert person/business] then tell me when done," Those types. Scammers like Philipino with multiple accounts, California Facebook, London Facebook, Ireland Facebook and a Phillipines Facebook page for herself and the owner told me how she was a straight up dishonest scam artist.
UK is same as US just more support for middle Eastern people and Indians (sending their money back to their people...they'd line up at money transfer offices after getting their HRMC monthly welfare money) and they're more like the Mexicans in Texas, California, or border states where it's similar or more prevalent and normal.
Post a Comment