Attachment_3_Foreign_Visitors_445_DM_3.pdf

PDF 206 KB Posted

Attached to
BIA Reston Cellular Connectivity Improvement Federal contract opportunity
Solicitation number
140A1624Q0047
Issued by
Department of the Interior Bureau of Indian Affairs Central Office

About this file

This document is a Departmental Manual Chapter from the U.S. Department of the Interior establishing the Foreign Visitor Access Management Program (FVAMP). The FVAMP outlines policies and procedures for identifying, documenting, and tracking foreign visitors who access Department facilities, information, data, technologies, and equipment. It defines responsibilities for various Department roles, including the Counterintelligence Unit, Foreign Visitor Sponsors, and Foreign Visitor Coordinators. The manual provides guidance on foreign visitor approvals, required identification, escort requirements, use of electronic devices, suspicious activity reporting, and other related requirements. It references relevant federal authorities and definitions. This document does not contain information about a specific federal contract opportunity. Rather, it establishes the Department's overarching policy for managing foreign visitor access.

View the file

Other files for this federal contract opportunity

Other files attached to BIA Reston Cellular Connectivity Improvement, newest first.
File Type Posted
Sol_140A1624Q0047_Amd_0003.pdf PDF
Sol_140A1624Q0047_Amd_0002.pdf PDF
Sol_140A1624Q0047_Amd_0001.pdf PDF
Sol_140A1624Q0047.pdf PDF
Attachment_2_DOL_Wage_Determination.pdf PDF
Attachment_5_-_Site_Visit_-_Offeror_Representative_Information.docx DOCX document
Attachment_1_Statement_of_Objective_SOO.docx DOCX document
Attachment_4_Foreign_Visitor_Template.xlsx XLSX spreadsheet

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

445 DM 3

11/30/2022 #5142

NEW

Department of the Interior Departmental Manual

Effective Date: 11/30/2022 Series: Law Enforcement and Security Part 445: Counterintelligence and Operational Security Chapter 3: Foreign Visitor Access Management Program

Originating Office: Office of Law Enforcement and Security

445 DM 3

3.1 Purpose. This Chapter establishes and defines the Foreign Visitor Access Management Program (FVAMP) for monitoring foreign visitor access to U.S. Department of the Interior (Department) facilities, information, data, technologies, and equipment by establishing Departmental requirements and controls for the following:

A. A process for identifying, documenting, and tracking foreign visitors who access Department facilities and may have access to the Department’s information, data, technologies, and equipment.

B. A process to review identifying information related to foreign visitors consistent with the Department’s program-specific policies, requirements, and objectives.

C. Policies and procedures to ensure that unauthorized access to information, equipment, or technologies by foreign visitors does not occur.

3.2 Scope. The provisions of this Chapter apply to all Department employees who may interact with foreign visitors, as defined in Appendix 2, Definitions. This Chapter refers to foreign visitors that access Department facilities except as follows:

A. When the foreign visitor is a lawful permanent resident of the United States, a

Department employee or contractor, or an employee of another federal, state, local or tribal department or agency.

B. When the foreign visitor is a family member of a Department employee or contractor, is always escorted by a Department employee, does not have access to Department computers or networks, and does not take part in discussions about official agency business.

C. When the foreign visitor is a diplomat or senior government official at the ambassadorial or vice-ministerial level or above who visits Department officials for the purpose of high-level policy dialogue. Accompanying staff members or advance teams shall be treated as foreign visitors pursuant to this Chapter.

D. When there is a public event held inside or outside a Department facility that does not require an invitation.

E. When foreign visitors are detailed to support emergency operations domestically.

3.3 Authority. This policy is issued pursuant to 112 DM 17 and 212 DM 17 in addition to the Federal guidelines and directives as noted in Appendix 1 Table of Authorities of this Chapter.

3.4 Implementation. This Chapter is effective upon publication and will be reviewed periodically and updated as needed.

3.5 Guiding Principles. Because the Department recognizes the value of their contributions to U.S. scientific and technological efforts and other Departmental functions, it offers foreign visitors access to its facilities, staff, information, and data while engaged in a broad range of collaborative activities. This access, however, must be balanced with the need to protect classified; controlled unclassified information or otherwise controlled, proprietary; or not-for-public release data, information, or technology.

3.6 Definitions. The terms used in this Chapter are defined in Appendix 2, Definitions.

3.7 Responsibilities.

A. Assistant Secretary – Policy, Management and Budget (PMB) is responsible for management direction and support for all Office of Law Enforcement and Security (OLES) programs through Department-wide policies, standards, and guidelines for OLES program activities and responsibilities of the Department.

B. Deputy Assistant Secretary, Public Safety, Resource Protection, and Emergency

Services (DAS-PRE) is the Department’s primary OLES policy officer and the principal advisor to the Secretary, Deputy Secretary, and Assistant Secretary - Policy, Management and Budget, on OLES policy and operations.

C. Director, Office of Law Enforcement and Security (OLES) has the responsibility for OLES policy development and for oversight of OLES programs, as delegated by the DAS-

PRE.

D. Assistant Director, OLES Intelligence Division is responsible for providing first-level program management and oversight of the Counterintelligence Unit (CIU) activities regarding the FVAMP, professional development of CIU personnel, and providing an annual summary of the FVAMP through the Director-OLES to the DAS-PRE.

E. OLES Counterintelligence Unit (CIU) shall have programmatic responsibility and oversee all the Department’s roles and responsibilities related to documenting, reviewing, and approving foreign visitors accessing Department facilities.

F. Office of the Chief Information Officer (OCIO) shall appoint a representative to support the CIU on all relevant information technology matters related to foreign visitors who access Department facilities.

G. Office of the Solicitor (SOL) shall provide legal advice to the Director, OLES and the CIU related to the establishment, implementation, execution, management, and oversight of CIU activities related to the requirements of this Chapter.

H. Bureau and Office Directors are responsible for ensuring compliance with the FVAMP in accordance with law, regulation, and Departmental policy. Heads of Bureaus and Offices shall designate a Foreign Visitor Coordinator (FVC) who is responsible for coordinating office or region-wide foreign visitor activities and support the FVAMP as necessary.

I. The Foreign Visitor Sponsor (FVS) is responsible for:

(1) Understanding their roles and responsibilities as defined on the Department OLES Foreign Visitor Reporting Portal.

(2) Collecting and verifying, in accordance with all applicable U.S.

Government policies and directives, the required Personally Identifiable Information (PII) from the foreign visitor at least 30 days in advance of the visit, or as soon as they are notified of the visit.

(3) Sending the PII to the FVC via encrypted email within two business days of receipt.

(4) Checking foreign visitors’ identification consistent with program requirements (see Section 3.10) upon their arrival.

(5) Escorting the foreign visitors while in Department facilities.

(6) As necessary, explain Department foreign visitor policies and procedures to all foreign visitors to ensure their understanding and compliance.

(7) Reporting any observed suspicious activities to CIU, and the

Bureau/Office Security Office within two business days of the activity.

(8) Reporting to CIU any gifts received during the visit.

J. Foreign Visitor Coordinator (FVC) is responsible for:

(1) Collecting and verifying foreign visitor’s required PII for prompt submission to CIU for processing.

(2) Submitting foreign visitor’s PII to CIU via the Department OLES Foreign Visitor Reporting Portal, which hosts the most up-to-date procedures, forms, and reporting requirements (see Section 3.15 for contact information).

K. Department employees are responsible for protecting sensitive information, equipment, and technologies from unauthorized access by foreign visitors in order to safeguard the Department’s ability to accomplish its mission and to serve the public.

3.8 Training. CIU will provide training to those employees designated by their program or office to be an FVS and/or FVC. Updated training will be provided as needed.

3.9 Foreign Visitor Approvals.

A. CIU will conduct applicable Agency checks, make a risk assessment determination, and notify the Bureau/Office of approval or denial of access based upon the information concerning each foreign visitor, or if additional escort procedures are necessary.

B. Approval rests upon the favorable completion of applicable Agency checks and a determination that no unauthorized physical, visual, or virtual access to classified, Sensitive But Unclassified (SBU), or otherwise Controlled Unclassified Information (CUI), proprietary, or not-for-public release data, information, or technology is likely to occur.

C. In the event of denial of access, a senior official of the affected Bureau/Office may appeal to the Director, OLES who will consider whether the benefits of a proposed visit justify the risks or require additional precautions.

D. For any additional questions or concerns pertaining to Foreign Visitor Approvals, contact the CIU (see 3.15).

3.10 Proper Identification Required. Foreign visitors are required to present a valid country passport and/or Department of State diplomatic identification card prior to gaining access to Department facilities if their visit is of a professional nature. Failure to present valid credentials could lead to a denial of entry for the scheduled foreign visit. A passport or diplomatic identification is not required for visits of a recreational or personal nature.

3.11 Escort Requirements. The hosting Bureau/Office is responsible for ensuring that foreign visitors are always escorted by a Department employee and closely monitored while they are visiting Department facilities.

Foreign visitors may be granted unescorted access to designated areas of a facility upon approval by the servicing Bureau/Office security office.

3.12 Use of Personal and/or Foreign Government Electronic Devices and Equipment.

Foreign visitors may not use any personal and/or foreign government-issued communication, photographic, recording, or other electronic devices in those areas of Departmental facilities where classified, SBU, or otherwise CUI, proprietary, or not-for-public release data, information, or technology is present without the explicit authorization of their FVS.

A. These devices include but are not limited to cell phones/camera phones, still or video cameras, audio recorders, laptops, tablets, iPads, flash drives, thumb drives, USBs, etc.

B. The FVS must take all reasonable steps to ensure that adequate measures are in place to protect against access to or collection of said data, information, or technology before authorizing use of such devices.

C. When necessary, all electronic devices that are brought by the representative(s) of foreign governments or foreign industry will be collected and securely stored until the meeting/visit is concluded.

D. Media devices, including flash drives, Compact Discs (CDs), and any other device obtained from or provided by a representative of a foreign government or foreign industry must never be used in Department or United States government computers or other devices.

3.13 Briefings and Debriefings.

A. CIU will provide briefings as needed for Department employees who host foreign visitors, particularly for those employees who work in high-risk positions or special access programs.

B. When appropriate, employees who host foreign visitors with authorized access to sensitive subjects or security areas must attend pre-visit and post-visit briefings/debriefings by CIU or their Bureau/Office Security Office.

C. CIU will conduct a debriefing of Department employees who have had contact with a foreign visitor as warranted.

3.14 Records. CIU will maintain a foreign visitor database containing identifying data for all Foreign National visitors and guests to which this Chapter applies.

3.15 Contact Information.

A. The OLES Counterintelligence Unit can be reached via the CIU Hotline at 1-844-565-1929 or via unclassified email at DOI_Counterintelligence@ios.doi.gov.

B. For classified reporting, the CIU can be reached by secure phone at:

5345284/9342218 or via classified email DOI_Counterintelligence@dhs.sgov.gov (HSDN/SIPRNet); counterintelligence@doi.csp.ic.gov (JWICS/IC Mail).

mailto:DOI_Counterintelligence@ios.doi.gov mailto:DOI_Counterintelligence@dhs.sgov.gov mailto:counterintelligence@doi.csp.ic.gov

Appendix 1 Table of Authorities

A. Section 811(c) of the Intelligence Authorization Act of 1995 (50 U.S.C. § 402a).

B. National Security Presidential Memorandum.NSPM-28, The National Operations

Security Program, dated January 13, 2021.

C. Departmental Manual Chapter 441 DM 7, Security Briefings, Education, and Training, dated January 8, 2010.

D. Departmental Manual Chapter 111 DM 3, Office of International Affairs, dated December 4, 2020.

E. Presidential Decision Directive/NSC 12, Security Awareness and Reporting

Foreign Contacts, dated August 5, 1993.

F. National Counterintelligence Strategy of the United States 2020-2022, dated

January 7, 2020.

G. Office of the Director of National Intelligence/National Counterintelligence and

Security Center, Countering Foreign Intelligence Threats-Implementation and Best Practices Guide, dated June 8, 2017.

Appendix 2 Definitions

A. Agency. For the purpose of this document, any “executive agency”, as defined, in

5 U.S.C. 105; any “military department” as defined in 5 U.S.C. 105 102; any “independent establishment”, as defined in 3.4 (f) of Executive Order 12333; and any other entity within the executive branch that comes into possession of classified information, or that possesses, processes, produces, or otherwise handles information that, even when unclassified, can be exploited by adversaries to gain insight into sensitive information or activities relevant to national security.

B. Classified Information. Information that has been determined pursuant to Executive Order (EO) 13526, Classified National Security Information or any successor order, to require protection against unauthorized disclosure and that is marked to indicate its classified status when in documentary form.

C. Controlled Unclassified Information (CUI). Unclassified information the United

States Government creates or possess, that an entity creates or possess for or on behalf of the United States Government, that law, regulation, or government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls.

D. Counterintelligence. Information gathered and activities conducted to identify, deceive, exploit, disrupt, or protect against espionage, Foreign Intelligence Entities, or other intelligence activities, sabotage, incapacitations, or assassinations conducted for or on behalf of foreign powers, organizations, or persons, or their agents, or international terrorist organizations or activities.

E. Employee. A person employed by, detailed, or assigned to the Department, including members of the Armed Forces; experts or consultants to the Department; contractors and subcontractors, or any other category of person who has been determined eligible for access to classified information, or who acts for or on behalf of the Department as determined by the Secretary.

F. Escort. An employee of the Department assigned the responsibility of accompanying a foreign visitor within a facility in order to ensure adherence to security measures protecting classified, SBU, or otherwise controlled, proprietary, or not-for-public release data, information, or technology from physical, visual, or virtual access.

G. Facility. Any office, laboratory, or workspace where official Department business is conducted.

H. Foreign Access Management. The management of risks and threats, and accompanying protective measures, focused on mission critical engagement with foreign representatives or foreign counterparts. This term includes measures to detect or identify, validate, collect, analyze, track, correlate, alert, and mitigate foreign access security risks and threats to United States Government and national security information, personnel, systems or networks, facilities, resources, programs, policies, and operations.

I. Foreign National. Any person who is not a citizen or national of the United

States.

J. Foreign Visitor. Any foreign national, detailee, volunteer, student intern, or interpreter representing or sponsored by a foreign government.

K. Information. Any knowledge that can be communicated or documentary material, regardless of its physical form or characteristics that is owned, produced, or under the control of the U.S. Government.

L. Official Capacity. Any foreign visitor fulfilling a role wherein they are representing their respective government.

M. Suspicious Activity. Activity or action that must be reported to the CIU or bureau/office security officer if it occurs during a visit by a foreign national. Suspicious activities that need to be reported are listed on Appendix 3 and are also identified on the

N. Foreign Visitor. Any foreign national, detailee, volunteer, student intern, or interpreter representing or sponsored by a foreign government.

O. Information. Any knowledge that can be communicated or documentary material, regardless of its physical form or characteristics that is owned, produced, or under the control of the U.S. Government.

P. Official Capacity. Any foreign visitor fulfilling a role wherein they are representing their respective government.

Q. Suspicious Activity. Activity or action that must be reported to the CIU or Bureau/Office security officer if it occurs during a visit by a foreign national. Suspicious activities that need to be reported are listed in Appendix 3 and are also identified on the

Appendix 3 Suspicious Activities

The OLES CIU must be notified if any of the following activities occurred during a foreign visit:

1. Attempt to obtain sensitive information not initially requested.

2. Attempt to discuss or access classified information or ask if you have access to classified information.

3. Attempt to discuss sensitive unclassified internal deliberative information about U.S. Government negotiations with their country or any other country.

4. Attempt to obtain information about their country’s or organization’s interactions with the State Department or other parts of the U.S. Government.

5. Access or attempt to access a Department computer without permission.

6. Insert or attempt to insert a thumb drive or other media device into a Department computer.

7. Attempt to access information contained in someone’s workspace.

8. Wander away from the group or Department escort.

9. Attempt to obtain information about Department’s computer network infrastructure or network security practices.

10. Seek out or attempt to establish friendships with individuals outside their areas of interest/expertise.

11. Take photographs of any unauthorized areas or use a cell phone or micro camera in a concealed manner.

12. Solicit you or other staff to visit their country for personal business, not while on official Department travel.

13. Invite you to present information or training in their country. This could come as a subsequent contact via email as a request for your expertise.

14. Solicit you or other staff to meet them in a country other than the United States or the country they represent.

15. Request your personal email address or personal cell phone number.

16. Request permission for other individuals from their country to visit Departmental facilities outside of official Departmental channels.

17. Solicit you or other staff to become involved in personal scientific collaborations with their country outside of official Department channels.

18. Solicit anyone to send emails or access websites for them.

19. In a group of foreign visitors, seem out of place.

20. Act offended or belligerent when confronted about a security or protocol procedure.

21. Photograph or attempt to keep their visitor pass or badge.

Appendix 1
Table of Authorities
A. Section 811(c) of the Intelligence Authorization Act of 1995 (50 U.S.C. § 402a).
B. National Security Presidential Memorandum.NSPM-28, The National Operations Security Program, dated January 13, 2021.
C. Departmental Manual Chapter 441 DM 7, Security Briefings, Education, and Training, dated January 8, 2010.
D. Departmental Manual Chapter 111 DM 3, Office of International Affairs, dated December 4, 2020.
E. Presidential Decision Directive/NSC 12, Security Awareness and Reporting Foreign Contacts, dated August 5, 1993.
F. National Counterintelligence Strategy of the United States 2020-2022, dated January 7, 2020.
G. Office of the Director of National Intelligence/National Counterintelligence and Security Center, Countering Foreign Intelligence Threats-Implementation and Best Practices Guide, dated June 8, 2017.
Appendix 2
Definitions

File details come from the government source that posted it. Updated .