The U.S. government -- minus key spy operations -- spent $11.36 billion to protect classified data in 2011, according to the Information Security Oversight Office (ISOO).
The number has increased substantially over the past decade, from $4.7 billion in 2001, the agency said.
[ Prevent corporate data leaks with Roger Grimes' "Data Loss Prevention Deep Dive" PDF expert guide, only from InfoWorld. | Stay up to date on the latest security developments with InfoWorld's Security Central newsletter. ]
The ISOO report comes from its compilation of cost estimates provided by 41 executive branch agencies, including the U.S. Department of Defense.
The report doesn't include cost estimates from the CIA, the Office of the Director of National Intelligence, the Defense Intelligence Agency, the National Security Agency and other secret spy agencies.
The ISOO reports to the White House and oversees the implementation of a government-wide security classification system for protecting sensitive and classified data.
Each year, the ISSO collects estimates from federal agencies on how much they spent on personnel, physical controls and IT systems to protect classified data. The estimates also include training costs and salaries for those involved in classifying and declassifying data.
The ISOO's latest report shows that the agencies spent about 12 percent, or about $1.2 billion, more on security classification in 2011 that the previous year.
The biggest costs increases were associated with IT systems and training.
Spending on information security controls for classified data jumped 19 percent from $5.21 billion in 2010 to $6.18 billion in 2011. Costs for professional education, training and awareness rose from $102 million in 2010 to $502 million last year.
The 2011 figures reflect a steep increase in security classification costs since the terrorist attacks of Sept., 2001, much of it for counterterrorism programs and an increased focus on preventing Wikileaks-type hacks into government systems.
For instance, President Barack Obama last October issued an executive order directing federal agencies to implement new measures to limit access to classified networks and data. The order required the heads of all federal agencies to appoint a senior official to oversee the protection of classified data security and required agencies to put in place insider threat-detection and prevention programs.
Obama issued a similar executive order in late 2009 that directed federal agencies to adopt uniform standards for classifying, declassifying and protecting national security information including that related to counter-terrorism operations.
Such directives, and fears of data leaks -- such as those related to the Stuxnet attacks that have dogged the Obama administration -- have considerably heightened attention on better protecting classified data.
John Pescatore, an analyst at Gartner, said the ISOO spending report reflects several trends.