In and Out Processing.pdf

PDF 120 KB Posted

Attached to
2011-N-13070 Comprehensive Analytical Chemistry Support Federal contract opportunity
Solicitation number
2011-N-13070
Issued by
Department of Health and Human Services Centers for Disease Control and Prevention Pittsburgh

About this file

J.1 In and Out Processing of CDC

View the file

Other files for this federal contract opportunity

Other files attached to 2011-N-13070 Comprehensive Analytical Chemistry Support, newest first.
File Type Posted
Amend 2 2011-N-13070.pdf PDF
Amed 1 CASC 2011-N-13070.pdf PDF
PB Award Fee CACS.docx DOCX document
2011-N-13070 CASC Solicitation.pdf PDF
ACH Vendor Enrollment Form.pdf PDF
Health_and_Safety_Manual.pdf PDF
J.10 Sample for Calculations.zip ZIP file
DART SOPs.zip ZIP file
SB Subcontracting Plan HHS.doc DOC document
Visitors and Foreign Nationals.pdf PDF
QA_Manual.pdf PDF
Contractor Performance_Standard_Form 09-23-09 NEW.doc DOC document
Show all 12

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

CATEGORY: General Administration

CDC-GA-2007-01

DATE OF ISSUE: 3/2/2007 REVISED: 9/17/20071

PROPONENTS: Management Information Systems Office; Office of the Chief Information Security Officer

IN- AND OUT-PROCESSING OF CDC FTEs, PSCs, CONTRACTORS, AND OTHER

NON-FTEs POLICY

SECTIONS: I. PURPOSE

II. BACKGROUND

III. ABBREVIATIONS, ACRONYMS AND DEFINITIONS

IV. POLICY

V. PROCEDURES

VI. RESPONSIBILITIES

VII. OVERSEAS EXCLUSION

VIII. REFERENCES

ATTACHMENTS: A. IN-PROCESSING CHECKLIST

B. OUT-PROCESSING CHECKLIST

C. EXIT INTERVIEW PROCESS

I. PURPOSE

In- and out-processing encompasses the entire lifecycle of logical (electronic or computer) and physical access to information and resources required by someone working at or associated with the Centers for Disease Control and Prevention (CDC2

). As such, it includes any applicable activities or tasks required at any time during the period the individual is connected with CDC.

This policy defines the applicable laws, regulations, and procedures necessary to incorporate all such activities into a comprehensive set of guidelines to better manage CDC’s workforce and secure CDC’s assets.

This policy applies to all CDC full-time equivalent employees (FTEs) and non-FTEs, including civil service employees, Commissioned Corps, field staff, personal services contractors (PSCs), emerging leaders, cooperative agreement employees, commercial contractors, guest researchers, fellows, students, and any other staff with a need for logical or physical access to CDC resources (except as excluded in Section VII). This policy will continue to be updated as procedures mature.

The requirements established by this policy can be exceeded, but at least the minimum requirements must be met. The policy is not location specific; the minimum required procedures must be accomplished regardless of the work or duty location of a given individual. Work or duty locations covered by the policy procedures include, but are not limited to, CDC headquarters or CDC-designated campuses and facilities; ATSDR regional offices; quarantine stations; other federal, state, county or local facilities; international locations; and private and partner organizations. Where appropriate, modifications to the procedures may be necessary for international and field staff and other persons located outside CDC Atlanta, but in all cases, the minimum requirements to ensure proper in- or out-processing of staff must be followed within the mandatory timeframes (see Section V, “Procedures”).

1 Revised to add links to recently issued policies (Section VIII.K. and TT.)

2 References to CDC also apply to the Agency for Toxic Substances and Disease Registry (ATSDR).

http://aops-mas-iis/policy/Doc/936_1534.pdf� http://aops-mas-iis/policy/Doc/936_1535.pdf� http://aops-mas-iis/policy/Doc/664_1262.doc�

II. BACKGROUND

According to Homeland Security Presidential Directive 12 (HSPD-12), dated August 27, 2004, “Wide variations in the quality and security of forms of identification used to gain access to secure Federal and other facilities where there is potential for terrorist attacks need to be eliminated. Therefore, it is the policy of the United States to enhance security, increase Government efficiency, reduce identity fraud, and protect personal privacy by establishing a mandatory, Government-wide standard for secure and reliable forms of identification issued by the Federal Government to its employees and contractors (including contractor employees).”

Therefore, it is the policy of CDC to enhance security, increase in- and out-processing efficiency, reduce non-compliance, and protect government property by establishing a mandatory, CDC-wide standard for secure and reliable in- and out-processing of all CDC FTEs, PSCs, contractors, and other non-FTEs. CDC shall annually review the policy and update it as appropriate in consultation with the affected organizations.

Effective October 27, 2006, all in- and out-processing of FTEs, PSCs, contractors and other non-FTEs must be completed in accordance with this policy to meet the requirements of (HSPD-12). Executive or management leadership from each coordinating center (CC), coordinating office (CO), national center (NC3

), or office shall, to the maximum extent practical, require complete in- and out-processing compliance to gain or remove physical access to federally controlled facilities and logical (computer) access to federally controlled information systems as promptly as possible.

III. ABBREVIATIONS, ACRONYMS, AND DEFINITIONS

A. For the purposes of this policy, the following acronyms apply:

1. AHRC – Atlanta Human Resources Center

2. AO – administrative officer

3. APCO – alternate property custodial officer

4. ATSDR – Agency for Toxic Substances and Disease Registry

5. CDC – Centers for Disease Control and Prevention

6. CC/CO – coordinating center/coordinating office

7. CDC/IS – CDC Information System

8. CISO – Chief Information Security Officer

9. COGH – Coordinating Office on Global Health

10. FAR – Federal Acquisition Regulation

11. FEO – Facilities Engineering Office

12. FTE – full time equivalent

13. GRS – General Records Schedule

14. HHS – Department of Health and Human Services

15. IOP – in- and out-processing

16. ISSO – Information Systems Security Officer

17. IT – information technology

3 For ease of reference within policy documents, “NC” will refer collectively to CDC’s national centers, institute, the National Immunization Program, the National Office of Public Health Genomics, and the Agency for Toxic Substances and Disease Registry (an independent Health and Human Services Agency that is led by the CDC director and for which CDC provides administrative services).

http://www.whitehouse.gov/omb/e-gov/hspd12_reports/� http://www.whitehouse.gov/omb/e-gov/hspd12_reports/�

18. ITSO – Information Technology Services Office

19. LAN – local-area network

20. LES – locally employed staff

21. LSB – Laboratory Safety Branch

22. MASO – Management Analysis and Services Office

23. NACI – National Agency Check and Inquiries

24. NC – national center

25. OCISO – Office of the Chief Information Security Officer

26. OHS – Office of Health and Safety

27. OSEP – Office of Security and Emergency Preparedness

28. PCO – property custodial officer

29. PGO – Procurement and Grants Office

30. PMO – property management officer

31. PO – project officer

32. PSC – personal services contractor

33. TM – technical monitor

34. WAN – wide-area network

B. For the purposes of this policy, the following definitions apply:

1. Agent

: An entity designated and approved by NC or executive leadership to perform many in- or out-processing tasks as necessary or as assigned by the responsible authority. The agent can act on behalf of the responsible authority, but the responsible authority is ultimately accountable for ensuring policy compliance and completion of all required tasks.

2. Alternate property custodial officer: A non-FTE can be an alternate property custodial officer when designated by the contract by which he or she is employed. However, non-FTEs filling this position are specifically precluded from final authorization of any action that affects the financial standing of the government (see CDC policy, CDC Use of Contractors as Alternate Property Custodial Officers, CDC-MM-2006-01).

3. Center or executive leadership

: This policy requires executive or management leadership from each CC, CO, NC, or office to assist CDC by ensuring that the resources necessary to administer this policy are provided and by coordinating and managing the CDC In- and Out-Processing Policy. Center or executive leadership designate specific individuals or groups within their organization to serve as task owners to perform specific functions associated with in- or out-processing.

4. Contracting officer

FAR 2.101, Subpart 2.1 – Definitions

: A person with the authority to enter into, administer, and/or terminate contracts and make related determinations and findings. The term includes certain authorized representatives of the contracting officer acting within the limits of their authority as delegated by the contracting regulation (

; JFMIP 2003, p.76). The contracting officer is responsible for in- and out-processing of commercial contractors and other third-party consultants. A contracting officer can delegate in- and out-processing responsibility and tasks to another FTE, PSC, or non-FTE as directed by NC or executive leadership (see Section III.B.1, “Agent”), but ultimate responsibility for ensuring policy compliance remains with the contracting officer (see Section III.B.1, “Agent”).

5. FTEs, PSCs, Contractors, and other non-FTEs: FTE refers to any CDC employee, Commissioned Corps officer, visiting researcher, or transferring employee who occupies a CDC FTE position. PSC refers to an individual staffing a CDC position http://aops-mas-iis.od.cdc.gov/Policy/Doc/policy482.htm� http://farsite.hill.af.mil/reghtml/regs/far2afmcfars/fardfars/far/02.htm#P10_604� http://farsite.hill.af.mil/reghtml/regs/far2afmcfars/fardfars/far/02.htm#P10_604� abroad via direct contract between that individual and CDC that establishes an employee-employer relationship. Note that PSCs may only be engaged for service abroad, not in the U.S. In this context, contractor refers to any commercial or third-party consultant contractually providing services to CDC. Other non-FTE refers to any other category of person, including traveler, guest researcher, fellow, student, committee member, retiree, other federal agency employee on detail to CDC, cooperative agreement/partner agency employee working at a CDC site, etc., who requires access to any CDC resources or facilities, who does not qualify as a short-term visitor, and who does not occupy a CDC FTE position.

6. In- and Out-Processing

: In- and out-processing tasks can include assignment or removal of property or assets or access to information or facilities that may occur at any time during the lifecycle of association with CDC. In-processing refers to all activities and tasks required to validate a user’s identity and his or her need for specific access to physical or logical resources associated with CDC. Out-processing refers to all activities and tasks required to transfer ownership, remove physical and logical access when no longer required due to separation, and ensure proper disposal or traceability of any assets, resources, access, or information for a given FTE, PSC, contractor, or other non-FTE associated with CDC.

7. Project officer (other non-FTEs)

: A project officer is responsible for the in- and out-processing of non-FTEs. In some cases, a non-FTE will also have a technical monitor (TM). Either the TM or the PO is ultimately responsible for ensuring proper processing of non-FTE staff assigned to a given project/task order. A PO or TM can delegate in- and out-processing responsibility and tasks to another FTE, PSC, or non-FTE as directed by NC or executive leadership (see Section III. B. 17. “Agent”), but ultimate responsibility for ensuring policy compliance remains with the PO or TM.

8. Property custodial officer or property custodian: The individual designated in writing and located at the field operating unit level with physical custody and control over property (see CDC policy, CDC Use of Contractors as Alternate Property Custodial Officers, CDC-MM-2006-01).

9. Property management officer:

The Director, PGO. This individual is responsible for directing an effective personal property system, including: property accountability, inventory, utilization and reutilization, declaration of excess property, and rehabilitation.

10. Responsible authority

: Hereafter, responsible authority will be used to describe the supervisor, contracting officer, or project officer with primary responsibility for ensuring that in- or out-processing has been performed and completed for any person for whom the responsible authority is accountable.

11. Supervisor (FTEs or PSCs)

: The person responsible for the in- and out-processing of FTEs or PSCs. A supervisor can delegate in- and out-processing responsibilities and tasks to another FTE, PSC, or non-FTE as directed by NC or executive leadership (see Section III.B.1, “Agent”), but ultimate responsibility for ensuring policy compliance remains with the supervisor.

12. Task owner: A task owner is the person designated to accomplish or complete a given task(s). A task or task owner is determined and assigned by varying officials within an organization. A task owner is responsible for ensuring that the tasks comply with this policy. Task owners may include the incoming or departing individual, http://aops-mas-iis.od.cdc.gov/Policy/Doc/policy482.htm� designated administrative staff, Information Technology (IT) staff, security personnel, property officers, organizational managers, or any other persons responsible for a given task. For many tasks, the NC or executive leadership within a given organization will designate the appropriate responsible task owner. For example, the property custodian is responsible for ensuring that during out-processing, government property is transferred to another party according to property governance guidelines and that the responsible authority or agent has been notified of the completion of the task.

13. User ID

: User ID stands for “user identification,” a code that consists of four digits— three letters and one number (e.g., abc2).

IV. POLICY

Compliance with this policy, for purposes of the HSPD-12 directive, ensures that procedures are completed and verified by the appropriate official during the in- and out-processing process. The standard will include directives pertaining to the person being processed, NC or executive leadership, supervisor (for FTEs or PSCs), contracting officer (for contractors) or project officer (for other non-FTEs), task owner, physical security, property custodial officer, alternate property custodial officer, and any official or non-official involved in any in- and out-processing activity.

This policy will be evaluated annually by the Management Information Systems Office and the Office of the Chief Information Security Officer, and the results will be used to modify the policy as necessary to ensure effectiveness.

The policy on Identification of Contractors’ Employees and Safeguarding Government Information states that PSCs and other non-FTEs must adhere to all applicable CDC policies and agreements outlined in their service contract. It is the responsibility of contracting officers (FAR 2.101, Subpart 2.1 – Definitions; JFMIP 2003, p.76) to incorporate this policy’s applicable requirements into contract solicitations. A contracting officer is also the party responsible for ensuring that their contractors are aware of and comply with the disclosures required by CDC policies.

Responsible parties must complete and verify that all applicable tasks related to in- or out-processing of FTEs and non-FTEs, changes in duty station, employment status, or any other change affecting logical (computer) or physical access to CDC or government resources and facilities are properly performed according to the laws, regulations, standards, and procedures pertaining to governance of government property, access to facilities and information, and security-related activities. Refer to In- or Out-Processing Checklists (Attachments A and B) for tasks and instructions that must be completed to officially in-process, transfer, change employment status, detail, or out-process from CDC; and to provide or restrict access to CDC facilities, resources, and information.

V. PROCEDURES

The procedures in this section provide guidance on requirements for in- and out-processing compliance. Specific procedures on how to comply may differ by center or may require alternate compliance measures due to geographic or situational circumstances. In any case, the minimum requirements for ensuring access to physical or logical (computer) resources must be followed.

Active accounts for LAN, e-mail, mainframe, or other electronic systems cannot be granted nor can a badge or card key be issued until all required security procedures are completed, a user profile/user ID has been established, and the user has been cleared. To see whether a given http://www.whitehouse.gov/omb/e-gov/hspd12_reports/� http://aops-mas-iis.cdc.gov/Policy/Doc/policy481.htm� http://aops-mas-iis.cdc.gov/Policy/Doc/policy481.htm� http://acquisition.gov/far/05-15/html/FARtoHTML.htm� user is cleared for issuance of a badge/card key, LAN, or electronic access, one can use the network access validation tool (http://peoplestatus.cdc.gov/WebForm1.aspx) to view the status of a user’s request.

Minimum Requirements for Logical (Computer) and Physical Access (Card Key)

• Establishment of user profile (user ID creation) (See Section V.A, “Establishing a User Profile and Enabling an Account”.)

• Security background investigation (See Section V.B, “Security Requirements”.)

• Security awareness training (See Section V.C, “Annual Security Awareness Training”.)

• Safety training

Minimum Requirements for Out-Processing

• Account disablement (See Section V.E, “Account Disablement”.)

• Review of e-mail, files, and documents for federal records (See Section V.F, “E-mail and

LAN Accounts and Records Management”.)

• Return and/or disablement of government property or assets, including badges, card keys, passports, key fobs, credit purchase or travel cards, phone cards, etc. (See Section V.G, “Badges and Card Keys”; Section V.H, “Credit Purchase, Travel, Phone and Other Credit Cards”; Section V.I, “Government-Issued Passports”; Section V.J, “Door Keys”; Section V.K, “Key Fobs”; Section V.L, “Auto Decals”; and Section V.M, “Return of Government Property”.)

A. Establishing a User Profile and Enabling an Account

After an individual has been offered a position or role at CDC and has accepted the position or appointment, whether as an employee, a student, a committee member, a guest researcher, etc., the responsible authority or agent establishes a user profile.

Creation of the user profile entails entering required information in the CDC/IS Directory and subsequently creating the user ID. Anyone who requires logical (computer) or physical access to CDC resources, or who is consigned as a CDC affiliate must have a valid profile. Until the profile and user ID are established, the remainder of the minimum requirements for in-processing cannot be met.

After the profile and user ID have been established, the intake process requires completion of security tasks including fingerprinting, background checks, and/or security clearances. (See Section V.B, “Security Requirements”.)

B. Security Requirements

To complete required in-processing tasks more efficiently, CDC policy has been enhanced to enable new staff to complete the following security-related activities prior to their starting date:

• Fingerprinting

• Security training

• Safety training

• Security documents (NACI, public trust and/or security clearance documents)

• All FTEs, PSCs and other non-FTEs are required to be evaluated and assigned a security level (CDC-HR-2006-01).

http://peoplestatus.cdc.gov/WebForm1.aspx� http://peoplestatus.cdc.gov/WebForm1.aspx� http://aops-mas-iis.od.cdc.gov/Policy/Doc/policy95.htm�

Security-related in-processing tasks are conducted by OSEP. Details regarding current policies and procedures for completion of fingerprints, background investigations, security clearances, and related security training can be found on the OSEP intranet web pages at http://intranet.cdc.gov/od/osep/personnel/clearanc.htm.

C. Annual Security Awareness Training

Each year CDC users with access to physical and logical (computer) resources are required to complete the Security Awareness Training. New users must complete the Security Awareness Training before they are granted access to physical or logical (computer) resources. Questions regarding Security Awareness Training can be directed to OCISO.

D. Changes in Employment Status, Transfers, Changes in Duty Station, Details, and

Temporary Promotions

Changes in employment status, transfers, changes in duty station, details, and temporary promotions require changes in an employee’s physical or logical access to government resources. For example, a temporary promotion would likely result in a need for access to different or additional systems, data, and information. Any change to a user’s employment status that affects or creates different needs regarding physical or logical access, resources, or access to data and information requires that specific in- or out-processing tasks be completed.

Change in Employment Status

If a user changes employment status from an FTE to a PSC or other non-FTE or vice versa, the user must be out-processed and then in-processed. Procedures for a change in employment status (e.g., FTEs, PSCs, etc., who are changing their status from employee to non-employee or vice-versa) follow in principle the same procedures as those required to out-process people who are permanently separating from CDC. Completion of specific tasks (such as fingerprinting) would not be required again; however, the change in status necessitates a review of the need and type of access and property required in the new position. After an FTE, PSC, or other non-FTE has been out-processed, the employee can then be in-processed by following standard in-processing procedures.

Transfers, Reassignments, or Changes in Duty Station or Organization

These require all applicable in- or out-processing tasks to be completed by the appropriate task owner. The former responsible authority or agent is responsible for ensuring that any out-processing tasks are completed, and the new responsible authority or agent is responsible for ensuring that any in-processing tasks are completed.

Details and Temporary Promotions

A change in position or duties requires that all applicable in- or out-processing tasks be completed by the appropriate task owner. The responsible authority or agent is required to ensure that these tasks are performed in a timely manner. Likewise, when the employee returns to his or her original assignment or responsibilities, the responsible authority or agent would be required to ensure that the user’s is updated http://intranet.cdc.gov/od/osep/� http://intranet.cdc.gov/od/osep/� http://intranet.cdc.gov/od/osep/personnel/clearanc.htm� record to match current job responsibilities with needs for physical and logical access to information and resources.

E. Disabling Accounts

All government FTEs, PSCs, and other non-FTEs are required to exercise common sense, good judgment, and propriety in the use of government-provided resources. The responsible authority or agent must ensure that all user accounts are disabled in a timely manner when someone departs from CDC. In the case of immediate separation, the responsible authority or agent immediately terminates the account in the CDC/IS Directory and notifies OSEP of the departure. For normal separations, the responsible authority or agent can establish a future separation/expiration date in the CDC/IS Directory for departing FTEs, PSCs, and other non-FTEs. On the day of expiration, mainframe, LAN, and e-mail accounts will be disabled automatically.

No reason is acceptable for delaying the process of disabling an account (e.g., to come back later to clean up e-mail boxes). The responsible authority or agent must ensure that account access is deactivated within 23 hours of notification. Note: Disabling or deactivating an account in the CDC/IS Directory will not prevent employees from receiving a final paycheck.

To ensure policy compliance, CDC has automated the process of disabling accounts between the CDC/IS Directory and the active directory. Beginning April 1, 2005, any account that has been disabled or deactivated in the CDC/IS Directory is also disabled in the active directory. This automated process deactivates any LAN, WAN, or Internet access. As a result, the responsible authority or agent is required only to deactivate the account in the CDC/IS Directory, and that deactivation automatically disables LAN and Internet access.

Procedures for disabling an account include the following

1. Expiration dates on employee records. The responsible authority or agent accesses the departing employee’s record in the CDC/IS Directory and enters the date the account should be disabled. Normally the date would be the last day of work. If the status of the departing employee changes and the date needs to be modified or deleted (in the case of an employee who decides not to depart), the responsible authority or agent can update the date in the CDC/IS Directory.

2. Expiration dates on non-employee records. Non-employees are required to have an expiration date on their user profile that does not exceed 1 year from the date the record is initiated. The expiration date should reflect the end of the person’s contract, tour, or period of performance at CDC if sooner than 1 year. An e-mail notification is sent automatically to the user and his or her responsible authority 2 weeks prior to the expiration date. If the person is not separating from CDC, the responsible authority or agent must update the profile in the CDC/IS Directory with the new expiration date. If a given profile is not updated by the expiration date, the profile is disabled, and access to all mainframe, LAN, and e-mail accounts will be discontinued.

A deactivation notice will be sent to the responsible authority, AO, and ISSO informing them of the account expiration. The notice will alert the authority, AO, and ISSO that system access must be removed for any applications to which the departing person has been given rights.

To re-enable/reactivate a disabled/deactivated account, the appropriate responsible authority or agent must reactivate the account in the CDC/IS Directory. This action will re-enable LAN and e-mail accounts within the hour. Accounts should be re-enabled only for those users who are active CDC staff. No retired or separated staff should have an active account, and their accounts must not be reactivated without prior approval from OSEP.

F. E-mail and LAN Accounts and Records Management

Users with access to the CDC LAN and e-mail are required to properly dispose of federal records according to legal requirements outlined in the CDC Records Management Policy for their records retention period. Retention periods vary depending on the series, or type, of records created. E-mails considered federal records must be retained according to the CDC, ATSDR, or General Records Schedule (GRS). Electronic records must be maintained in a “machine readable” format (i.e., created in a form that will be readable or transferable in current or future versions of software). Prior to their separation from CDC, it is mandatory that user e-mail and files stored electronically are reviewed to determine the correct disposition. If the files or e-mails are not deemed federal records, the user must either delete or transfer any files, folders, electronic records, or e-mails.

Any e-mails, records, or files not deemed federal records will be permanently removed within 90 days of the user’s separation. The responsible authority or agent must ensure that the e-mail and electronic records for departing persons are reviewed and that those records not deemed federal records are deleted or transferred within the 90-day timeframe. Any questions regarding recordkeeping requirements for federal records should be addressed to the CDC Records Officer at MASO.

G. Badges and Card Keys

Upon activation, the badge or card key grants access to CDC facilities. Physical Security issues electronic ID badges. Upon out-processing, the ID badge must be removed from the actual card key and destroyed so that it is no longer usable. The card key should then be returned by the departing individual to the card key administrator. The responsible authority or agent is responsible for informing the card key administrator that access should be disabled (CDC-GA-2001-04).

CDC policy requires departing FTEs and non-FTEs to turn in their badges and card keys on or before their last day. If the person also holds a radiation badge, it must be returned by the departing individual to the radiation safety officer at their location within the same timeframe. The radiation safety officer is required to deactivate the account when notified. Departees in the field or locations where no responsible authority or agent can physically collect the badge or card key should contact the card key administrator in advance for instructions. The departee must also notify the responsible authority of their departure and pass along the instructions from the card key administrator.

After out-processing has been completed, reuse of an electronic ID badge or its details is prohibited. All assigned FTES, PSCs, and other non-FTEs (other than visitors) must display permanent badges with an expiration date within their date range (CDC-GA- 2001-04). The expiration date system works as follows:

Type of Badge FTE orNon-FTE Expiration Date http://aops-mas-iis.cdc.gov/Policy/Doc/policy449.pdf� http://aops-mas-iis.cdc.gov/Policy/Doc/policy449.pdf� http://aops-mas-iis.od.cdc.gov/Policy/Doc/policy256.htm� http://aops-mas-iis.od.cdc.gov/Policy/Doc/policy256.htm� http://aops-mas-iis.od.cdc.gov/Policy/Doc/policy256.htm�

Type of Badge FTE orNon-FTE Expiration Date Permanent employee FTE 5 years from the date of issue at the end of the employee's birth month.

Visiting scientist or guest researcher

Either Visiting scientists and guest researchers, 1 year or less (specified by the supervisor).

EIS officers, 2 years from issuance date or less, to match their appointment expiration.

Contractor Non-FTE Date specified by the administrative officer or project officer according to the contract, not to exceed 1 year.

Other workers Non-FTE Date specified by the project officer, not to exceed 1 year.

Note: The expiration date displayed on the ID badge may or may not coincide with the separation or expiration dates entered in the user’s record in the CDC/IS Directory. For FTEs or PSCs, no separation date is entered in the record until the actual date of departure is known. For contractors and other non-FTEs, the expiration date is the last day of the contract term or 1 year, whichever is sooner.

H. Credit Purchase, Travel, Phone, and Other Credit Cards

All credit purchase, travel, phone, and other credit cards must be returned prior to departure. It is recommended that cards be collected as early as 30 days before departure so any recent charges will be posted on the account and the remaining balance will be cleared prior to cancellation of the card. Departees in the field may need to retain the travel or credit purchase cards until they are out-processed if they are returning from travel or overseas. In these cases, the departee must notify the responsible authority or agent in advance. The responsible authority or agent ensures that the card is retrieved and DESTROYED immediately and the account cancelled upon notification.

• Credit Purchase

– The responsible authority or agent should contact PGO to request cancellation of credit purchase cards.

• Travel Card

– If the card cannot be returned and destroyed, a written statement signed by the responsible authority and the center or executive leadership needs to be prepared to identify and record the reason. The corresponding administrators or responsible parties in FMO need to cancel or deactivate the card upon notification.

The CC/CO, NC, or office representative should contact the Accounts Payable Customer Service Desk in FMO at 404-498-4050 to request cancellation of cards.

• Phone Card

– The responsible authority or agent should contact the ITSO Service Desk at (404) 639-6000 to request cancellation of phone cards.

I. Government-Issued Passports

All U.S. government passports are U.S. government property and should be stored in the CDC COGH or approved field site (per COGH) except when checked out by individuals for official international travel. The responsible authority or agent notifies the appropriate official in COGH of the departure and collects and returns the passport to

COGH.

Departees in the field may need to retain the passport until they are out-processed upon their return from travel or overseas. Departees in the field not returning to the Unites States from locations where no responsible authority or agent is available can return the passport to the U.S. Embassy in that country. In both cases, the departee must notify the responsible authority and the COGH in advance.

J. Door Keys

Door keys (government property) must be returned prior to the departing person’s separation. The responsible authority or agent collects the door key and notifies the door key administrator of the departure. The door key administrator is required to collect the returned key and deactivate the account when notified. Departees in the field or locations where no responsible authority or agent can physically collect the door key should contact the door key administrator in advance for instructions. The departee must also notify the responsible authority of his or her departure and pass along the instructions from the door key administrator.

K. Key Fobs

All key fobs (RSA SecureID tokens) must be returned and accounted for prior to the person’s departure. The responsible authority or agent collects the key fob and informs ITSO Service Desk at (404) 639-6000 of the departure. The ITSO Service Desk fob administrator is required to deactivate the account when notified. Departees in the field or locations where no responsible authority or agent can physically collect the key fob should contact the fob administrator in advance for instructions. The departee must also notify the responsible authority of their departure and pass along the instructions from the fob administrator.

L. Auto Decals

Departing FTEs, PSCs, and other non-FTEs are required to remove all government-issued decals from personally owned vehicles and return them to their responsible authority or agent. The responsible authority or agent notifies Physical Security in OSEP of the departure. Physical Security is required to deactivate the account immediately after being notified. Departees in the field or locations where no responsible authority or agent can physically collect the decals should contact Physical Security in advance for instructions. The departee must also notify the responsible authority of their departure and pass along the instructions from Physical Security. Please refer to the Atlanta Area Parking Policy, CDC-GA-2002-07.

M. Return of Government Property

CDC policy states that all government owned property, both at home and at work, must be accounted for prior to the permanent separation or transfer of all personnel from the CDC. It is the responsibility of the assigned user of government owned property to ensure that all property has been properly accounted for according to (Federal Property Management Regulations) legal and/or contractual requirements. The responsible authority or agent, usually supervisors, ensures that the property has been transferred to the PMO and/or the PCO. The contracting officer is responsible for ensuring that any government property associated with a contract or agreement is properly accounted for http://aops-mas-iis.od.cdc.gov/Policy/Doc/policy345.htm� http://aops-mas-iis.od.cdc.gov/Policy/Doc/policy345.htm� and transferred or disposed of according to the terms of the contract and in accordance with 45 CFR 73.735-304.

CDC personnel in field assignments or located at duties stations without a CDC property management representative or PCO must make arrangements in advance with the necessary officials in order to properly transfer the property to a CDC property representative. The individual should contact their PCO or PGO in advance for instructions.

If cases where the person separating is a PCO, all property under his or her custodianship must be transferred to a new PCO (CDC-480). All questions and concerns should be directed to the CDC PMO, located in PGO. The PMO is responsible for providing the overall guidance and direction for the management and administration of government owned property at the CDC.

N. Debriefings for People Who Hold Security Clearances

Anyone who holds a security clearance must complete a debriefing with Personnel

Security prior to his or her departure. The responsible authority or agent notifies Personnel Security of the departure. Departees in the field or at locations where no security debriefing can be held in person need to contact OSEP for instructions on debriefing procedures.

VI. RESPONSIBILITIES

Within each CDC organization, in- and out-processing tasks are performed by a variety of individuals including the person affected. All in- and out-processing tasks must be performed in a timely manner and be consistent with the directives outlined in this policy and other federal policies, laws, regulations, standards, and procedures pertaining to in- and out-processing, information protection, property governance, and system security.

A. All CDC staff including FTEs, PSCs, contractors and other non-FTEs

All CDC FTEs, PSCs, and other non-FTEs have the following mandatory in- and out-processing responsibilities:

1. Comply with the tasks, standards, and procedures outlined in and associated with this policy. They are responsible for understanding the requirements and responsibilities of in- and out-processing as well as for performing the tasks in a timely and conscientious manner. If a person is uncertain about this policy, its requirements, or performing in- and out-processing tasks, he or she should seek guidance from the responsible authority.

2. Demonstrate a complete understanding of the appropriate use and processing of government property and resources. In addition, they are required to exercise common sense, good judgment, and propriety in the use of government-provided resources.

3. Whenever FTEs, PSCs, and other non-FTEs foresee a change in their employment status, they are required to facilitate processing of the new status by immediately confirming the change to their responsible authority.

4. Complete all assigned or required in- or out-processing tasks for which they are responsible.

5. Ensure that official records are properly disposed of according to CDC Records

Management Policy and legal requirements. In addition, they must delete, transfer, or dispose of any e-mail, electronic files, folders, or documents not deemed official records prior to their departure or separation.

B. Responsible Authority

A responsible authority has the following in- and out-processing responsibilities under his or her authority:

1. Supervise and ensure in- and out-processing task compliance from all persons under your direction and provide the education, awareness, and resources necessary to ensure the process is followed.

2. Wherever needed, appoint the appropriate persons as in- and out-processing task owners. The task owner is then responsible for completing the tasks that they own.

The in- and out-processing task owner is also responsible for ensuring that the tasks comply with this policy, standards, and procedures.

3. Ensure that any departure, resignation, retirement, removal, or change of duty station or employment status is reflected in the user’s profile in the directory and that any access to IT or physical resources is deactivated upon notification of the separation. All logical and physical access/accounts must be deactivated within 23 hours of an individual’s departure, or immediately on those occasions when the terms of departure (including involuntary separation) may cause an immediate security risk. If the person’s departure is involuntary or takes place under unfavorable circumstances, the responsible authority must notify the appropriate ISSO immediately. If the ISSO is not available, he or she must contact the appropriate

CISO.

4. Ensure that all applicable in- or out-processing tasks have been completed and verified.

5. Ensure that official records are properly disposed of according to CDC Records

Management Policy and legal requirements. The responsible authority ensures that the departing person has deleted, transferred, or disposed of any e-mail, electronic files, folders, or documents not deemed official records prior to departure or separation.

6. If government property has not been recovered prior to a person’s departure, notify the organization’s property management officer.

7. Pursue disciplinary or adverse action for violations of this policy.

C. Center or Executive Leadership

An NC or executive leader has the following in- and out-processing responsibilities under his or her authority:

http://aops-mas-iis.cdc.gov/Policy/Doc/policy449.pdf� http://aops-mas-iis.cdc.gov/Policy/Doc/policy449.pdf�

1. Ensure that all persons comply with this policy, and be educated and aware of in-and out-processing responsibilities.

2. Ensure that training and resources are made available to assist in complying with and administering this policy.

3. Ensure that all supervisors, responsible authorities, agents, and task owners in your organization complete and verify all applicable in- or out-processing tasks for which they are responsible.

4. Assign and communicate with the designated task owners within your organization for each task associated with in- or out-processing activities. The NC or executive leadership is responsible for ensuring that every person in their organization knows the appropriate task owners designated for a given task. Failure to communicate the proper procedures will result in noncompliance and will put CDC security at risk.

5. Develop, promote, and coordinate CDC in- and out-processing training and initiatives.

6. Develop, promote, and coordinate in- and out-processing implementation plans with key affected parties.

7. Serve as a focal point for incident reporting and subsequent resolution.

8. Ensure that in- and out-processing incident response procedures are established to investigate and resolve incidents.

9. Pursue disciplinary or adverse action for violations of this policy.

D. Task Owner

A task owner has the following in- and out-processing responsibilities under his or her authority:

1. Ensure that all in- and out-processing tasks are performed in compliance with the standards and procedures identified in or associated with this policy.

2. Perform given tasks as directed by NC or executive leadership in a timely manner in accordance with the policy requirements. Within an organization, management or executive leadership will delegate specific in- or out-processing tasks to an individual or group members (such as administrative staff). In some cases, a PSC, contractor, or non-FTE may be directed as a task owner.

3. After the task owner completes all assigned tasks, he or she notifies the responsible authority.

VII. OVERSEAS EXCLUSION

Individuals (other than those FTE employees assigned abroad by headquarters) who are employed exclusively overseas and who have no access to CDC domestic sites or computer and communications networks, such as locally employed staff (LES), shall be exempt from this policy and shall fall exclusively under security and in- and out-processing requirements established by the servicing U.S. Embassy.

VIII. REFERENCES

A. Acquisition of Information Technology Resources. CDC, April 2002.

B. Allowable Expenses for Honor Awards, Honor Award Ceremonies, and Informal

Recognition Awards. CDC, revised February 2009.

C. Rules of Behavior for Information Security Program Policy, last updated February 2008.

D. Appendix III to OMB Circular No. A-130: Security of Federal Automated Information

Resources.

E. Atlanta Area Parking Policy. CDC, June 2002.

F. Authorized Shipment of Household Goods. CDC, July 2003.

G. CDC/ATSDR Telework Policy for Civilian Employees. CDC, revised October 2008.

H. CDC/ATSDR Workforce Safety Training Policy. CDC, revised December 2008.

I. CDC Basic Property Management Guide. Last updated November 15, 2005.

J. CDC Policy for Issuance of Unique CDC Identifier As An Alternate for Social Security

Number. CDC, April 2007.

K. Classified Material. CDC, revised February 2009.

L. Confidential Financial Disclosure System Policy for CDC/ATSDR. CDC, December

2005.

M. Contracting for Services. CDC, July 2000.

N. Contracting for Services of State and Local Officials. CDC, March 2000.

O. NIST SP 800-63: Electronic Authentication Guideline.

P. Controls for Government Property and Guidance on Removing Government Property from CDC Facilities. CDC, December 2005.

Q. E-Gov Enterprise Architecture Guidance (Common Reference Model).

R. E-Gov: Technical Approach for the Authentication Service Component.

S. Visitors and Foreign Nationals in the Workplace at CDC. CDC, revised November 2006.

T. Employee Identification Badge. CDC, May 2001.

U. Federal Identity and Credentialing Committee website.

http://aops-mas-iis/policy/Doc/policy325.pdf� http://aops-mas-iis.cdc.gov/Policy/Doc/policy68.pdf� http://aops-mas-iis.cdc.gov/Policy/Doc/policy68.pdf� http://intranet.hhs.gov/infosec/docs/policies_guides/ROB/Information_Security_Program_Rules_of_Behavior.htm� http://www.whitehouse.gov/omb/circulars/a130/appendix_iii.pdf� http://www.whitehouse.gov/omb/circulars/a130/appendix_iii.pdf� http://aops-mas-iis.od.cdc.gov/Policy/Doc/policy345.htm� http://aops-mas-iis.cdc.gov/Policy/Doc/policy390.htm� http://aops-mas-iis.cdc.gov/Policy/Doc/policy6.pdf� http://aops-mas-iis.cdc.gov/Policy/Doc/policy62.pdf� http://pgo.cdc.gov/pgo/webcache/Training/Basic_Property_Mgmt_Guide_Master_Doc_042105.doc� http://aops-mas-iis/policy/Doc/policy520.pdf� http://aops-mas-iis/policy/Doc/policy520.pdf� http://aops-mas-iis.cdc.gov/Policy/Doc/policy302.pdf� http://aops-mas-iis.cdc.gov/Policy/Doc/policy450.htm� http://aops-mas-iis.cdc.gov/Policy/Doc/policy239.htm� http://aops-mas-iis.cdc.gov/Policy/Doc/policy241.htm� http://csrc.nist.gov/publications/nistpubs/800-63/SP800-63V1_0_2.pdf� http://aops-mas-iis.cdc.gov/Policy/Doc/policy480.htm� http://aops-mas-iis.cdc.gov/Policy/Doc/policy480.htm� http://aops-mas-iis/policy/Doc/936_1536.pdf� http://www.cio.gov/eauthentication/documents/techApproach.pdf� http://aops-mas-iis.cdc.gov/Policy/Doc/policy334.pdf� http://aops-mas-iis.cdc.gov/Policy/Doc/policy256.htm� http://www.idmanagement.gov/drilldown.cfm?action=icam�

V. FIPS 199: February 2004, Standards for Security Categorization of Federal Information and Information Systems

W. FIPS 201-1: March 2006, Personal Identity Verification (PIV) of Federal Employees and

Contractors

X. Foreign Travel and Contacts Policy. CDC, June 2005.

Y. General Administrative Manual, Chapter 1-00, HHS Staff Manual System, Department of

Health and Human Services. Last updated July 31, 1991.

Z. HHS Logistics Management Manual. Last updated September 21, 2005.

AA. HHS Logistics Management Manual (LMM) 103-1.5014, (LMM) 103-1.5014, Responsibilities of Property Custodial Officers (PCO). Last updated February 27, 2006.

BB. Homeland Security Presidential Directive (HSPD) 12, August 27, 2004.

CC. Information Security Program Handbook, US Department of Health and Human

Services.

DD. Information Security Program Handbook, US Department of Health and Human

Services, Supervisors, P.14.

EE. Medical Examinations and Reimbursements Relating to the US Department of State

Medical Clearance. CDC, August 2005.

FF. National Agency Check and Inquiry Procedures. CDC, February 2006.

GG. NIST SP 800-12: An Introduction to Computer Security – The NIST Handbook.

HH. NIST SP 800-61: Computer Security Incident Handling Guide.

II. NIST SP 800-63: Electronic Authentication Guideline.

JJ. NIST SP 800-53: Recommended Security Controls for Federal Information Systems.

KK. OMB Memorandum M-04-04: E-Authentication Guidance for Federal Agencies.

LL. PeopleStatus, http://peoplestatus.cdc.gov/WebForm1.aspx. Last updated October

2006.

MM. Permanent Residency Petitions. CDC, May 2002.

NN. Policy Management. CDC, October 2003.

OO. Property Action Request, CDC Electronic Form 0.993, Last updated November 1, 2000.

PP. Record Keeping Procedures for Managing E-Mails and Attachments That Qualify as

Federal Records. CDC, last updated October 2005.

http://csrc.nist.gov/publications/fips/fips199/FIPS-PUB-199-final.pdf� http://csrc.nist.gov/publications/fips/fips199/FIPS-PUB-199-final.pdf� http://csrc.nist.gov/publications/fips/fips201-1/FIPS-201-1-chng1.pdf� http://csrc.nist.gov/publications/fips/fips201-1/FIPS-201-1-chng1.pdf� http://aops-mas-iis.cdc.gov/Policy/Doc/policy458.htm� http://www.hhs.gov/hhsmanuals/gam/chapters/1-00.pdf� http://www.hhs.gov/hhsmanuals/logistic.pdf� http://www.hhs.gov/hhsmanuals/logistic.pdf� http://www.hhs.gov/hhsmanuals/logistic.pdf� http://www.whitehouse.gov/omb/e-gov/hspd12_reports/� http://www.hhs.gov/ocio/policy/2004-0002.001.html� http://aops-mas-iis.cdc.gov/Policy/Doc/policy468.htm� http://aops-mas-iis.cdc.gov/Policy/Doc/policy468.htm� http://aops-mas-iis.cdc.gov/Policy/Doc/policy95.htm� http://csrc.nist.gov/publications/nistpubs/800-12/handbook.pdf� http://csrc.nist.gov/publications/nistpubs/800-61-rev1/SP800-61rev1.pdf� http://csrc.nist.gov/publications/nistpubs/800-63/SP800-63V1_0_2.pdf� http://csrc.nist.gov/publications/nistpubs/800-53-Rev2/sp800-53-rev2-final.pdf� http://www.whitehouse.gov/omb/memoranda/fy04/m04-04.pdf� http://peoplestatus.cdc.gov/WebForm1.aspx� http://aops-mas-iis.cdc.gov/Policy/Doc/policy344.htm� http://aops-mas-iis.cdc.gov/Policy/Doc/policy353.htm� http://intraspn.cdc.gov/maso/EForms/PDF/Form1106.pdf� http://aops-mas-iis.cdc.gov/Policy/Doc/policy238.htm� http://aops-mas-iis.cdc.gov/Policy/Doc/policy238.htm�

QQ. Records Management Policy. CDC, last updated February 2008.

RR. Restrictions on Personal Convenience Items. CDC, June 2003.

SS. Securing Approval for Sponsorship of Conferences. CDC, last updated September

2008.

TT. Recruitment, Retention and Relocation Incentives. CDC, November 2009.

UU. Telecommunications Management. CDC, last updated June 2006.

VV. The In or Out-Processing…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .