Attachment 5 - REF FAA Order 1600.69C.pdf
PDF 943 KB Posted
- Attached to
- Amendment 0004 to Replace Parking Lot Lighting at Seattle Air Traffic Facility Federal contract opportunity
- Solicitation number
- 697DCK-23-R-00332
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 697DCK-23-R-00332 Amendment 0004.pdf | ||
| Attachment 11 - Drawing ZSE-20006240-E204 - Revised 5-24-2023.pdf | ||
| Attachment 10 - Grounding Grid Layout.pdf | ||
| 697DCK-23-R-00332 Amendment 0003.pdf | ||
| 697DCK-23-R-00332 Amendment 0002.pdf | ||
| 697DCK-23-R-00332 Amendment 0001.pdf | ||
| RFO 697DCK-23-R-00332.pdf | ||
| Attachment 1 - Specifications.pdf | ||
| Attachment 1(a) - Drawings.pdf | ||
| Attachment 6 - REF FAA Order 3900.19b.pdf | ||
| Attachment 7 - COVID-19 Contractual Requirement.pdf | ||
| Attachment 3 - REF FAA-C-1391e.pdf | ||
| Attachment 4 - REF FAA-STD-019f.pdf | ||
| Attachment 8 - Customer Satisfaction Survey.doc | DOC document | |
| Attachment 9 - DB WD No. WA20230011 dated 2-3-2023.pdf | ||
| Attachment 2 - REF FAA-C-1217h.pdf |
Show all 16
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
U.S. DEPARTMENT OF TRANSPORTATION
FEDERAL AVIATION ADMINISTRATION
National Policy
ORDER
1600.69C
Effective Date 08122/16
SUBJ: FAA Facility Security Management Program
This order prescribes the Federal Aviation Administration's (FAA) Facility Security Management Program (FSMP). This directive establishes facility security policy, delegates authority, assigns responsibilities and mandates security req'Jirements at facilities for which the FAA is responsible for security oversight. Unless otherwise explicitly provided, this order establishes requirements for all FAA personnel, including federal employees and FAA contractors as defined in FAA Order 1600.72 Contractor and Industrial Security Program, regardless of their assigned duty location.
FAA Order 1600.69C is a complete revision of the FAA s FSMP and supersedes all previous
Z;Z;~{J Michael P. Huerta Administrator
Distribution: Electronic Initiated By: AIN-1
FOR OFFICIAL USE ONLY
(Public availability to be determined under 5 USC 552) ii
08/22/2016 1600.69C
Table of Contents
Paragraph Page Chapter 1. General Information
1-1. Purpose of This Order………………………………………………………….. 1-1
1-2. Audience……………………………………………………………………….. 1-1
1-3. Where Can I Find This Order?………………………………………………... 1-1
1-4. Cancellation…………………………………………………………………….. 1-1
1-5. Related Publications and References…………………………………………... 1-2
1-6. Definitions…………………………………………………………………….... 1-2
1-7. Acronyms………………………………………………………………………. 1-2
1-8. Authority to Change This Order……………………………………………....... 1-2
1-9. Explanation of Policy Changes………………………………………………… 1-2
1-10. Background…………………………………………………………………… 1-3
1-11. Scope of This Order…………………………………………………………... 1-3
Chapter 2. Roles and Responsibilities
2-1. FAA Lines of Business, Staff Offices, and the Office of the Administrator, AOA 2-1
2-2. The Associate Administrator for Security and Hazardous Materials Safety, ASH-1 …………………….…………………………………………………. 2-1
2-3. The Director, Office of Security, AIN-1……………………………………….. 2-1
2-4. The Director, Office of National Security Programs and Incident Response, AEO-1………………………………………………………………............... 2-2
2-5. The Directors, Joint Security and Hazardous Materials Safety Office East, AHE-1; Central, AHC-1; West, AHW-1 and Security Division Manager of the Mike Monroney Aeronautical Center (MMAC), AMC-700…………….. 2-2
2-6. Office of the Chief Counsel, AGC………..……..…………………………….. 2-3
2-7. Office of Government and Industry Affairs, AGI ......…………………………. 2-3
2-8. Office of International Affairs, API …………………………………………….. 2-3
2-9. The Chief Operating Officer, Air Traffic Organization (ATO)……..................... 2-4
2-10. The Director, Office of Air Traffic Control Facilities, AJW-2……………....... 2-4
2-11. Facility Manager (FM)..……………………………………………………….. 2-4
2-12. The Assistant Administrator for Regions and Center Operations/Aviation
Logistics Organization, ARC/ALO …………………………………………... 2-5
2-13. Service Area/Regional Program and Project Managers of New Facility
Construction, Existing Facility Modification, or New Leases………………. 2-6
2-14. FAA Federal Employees and Contractors ………………………………….… 2-6
Chapter 3. FSMP Overview
3-1. Purpose…………………………………………………………………………. 3-1
3-2. Facility Categories……………………………………………………………… 3-1
3-3. Facility Security Level (FSL) ………………………………..………………… 3-1
3-4. Facility Security Assessments………………………………………………….. 3-4
3-5. Security Design for New or Renovated Facilities and Leased Spaces…………. 3-7
3-6. Facility Accreditation……………………………………………………...…… 3-8
3-7. Waivers and Exceptions to Requirements……………………………………… 3-9 iii
3-8. Facility Security Information………………………………………………...… 3-11 3-9. Program Evaluations…………………………………………………………… 3-11 3-10. Executive Reporting……………………………………………………...…… 3-11
Chapter 4. Facility Security Protective Measures 4-1. Purpose…………………………………………………………………………. 4-1 4-2. Concept/Objective of Protection……………………………………………….. 4-1 4-3. Baseline Protective Measures…………………………………………………... 4-1 4-4. Based on Evaluation (BOE) Protective Measures……………………………… 4-2 4-5. When Baseline Protective Measures do not Apply…………………………….. 4-2 4-6. Existing Protective Measures not Required by This Order…………………….. 4-2
Chapter 4. Facility Security Protective Measures Section 4-1. Facility Siting and Structural Protective Measures
4-1-1. Purpose……………………………………………………………………….. 4-1-1 4-1-2. Protective Measure Matrix…………………………………………………… 4-1-1 4-1-3. Crime Prevention Through Environmental Design (CPTED)……………….. 4-1-2 4-1-4. Blast Resistance and Setback………………………………………………… 4-1-3 4-1-5. Heating, Ventilation, and Air-conditioning (HVAC) Control……………….. 4-1-5 4-1-6. Buffer Zones…………………………………………………………………. 4-1-6 4-1-7. Signs………………………………………………………………………….. 4-1-7 4-1-8. Perimeter Fencing……………………………………………………………. 4-1-9 4-1-9. Security Lighting…………………………………………………………….. 4-1-11 4-1-10. Vehicle Barriers…………………………………………………………….. 4-1-13 4-1-11. Securing Doors, Windows, and Other Openings…………………………… 4-1-13 4-1-12. Locking Systems……………………………………………………………. 4-1-15
Chapter 4. Facility Security Protective Measures Section 4-2. Facility Access and Circulation Control
4-2-1. Purpose……………………………………………………………………….. 4-2-1 4-2-2. Protective Measure Matrix…………………………………………………… 4-2-1 4-2-3. Contract Security Officers (CSOs) ..........……………………………………. 4-2-1 4-2-4. Facility Security Checkpoints………………………………………………... 4-2-2 4-2-5. Security Control Center (SCC)…………………………….…………………. 4-2-3 4-2-6. X-Ray and Metal Detection Devices (MDD)……….………………………... 4-2-3 4-2-7. Vehicle Entry Control………………………………………………………... 4-2-4 4-2-8. Facility Entry Controls………………………………………………………... 4-2-5 4-2-9. Visitor Controls…………………………………………….…………………. 4-2-7 4-2-10. Prohibited Items…………………………………………….……………….. 4-2-12 4-2-11. Controlled Items……………………………………………….…………….. 4-2-13 4-2-12. Facility Photography………………………………………….……………... 4-2-14
Chapter 4. Facility Security Protective Measures Section 4-3. Security System Requirements
4-3-1. Purpose……………………………………………………………………….. 4-3-1 iv
4-3-2. Protective Measure Matrix…………………………………………………… 4-3-1 4-3-3. Security Management Systems………………………………………………. 4-3-2 4-3-4. Physical Access Control System (PACS)…………………………………….. 4-3-2 4-3-5. Video Monitoring System (VMS)………………………………………..…... 4-3-4 4-3-6. Intrusion Detection System (IDS)…………………...………………………... 4-3-6
Chapter 4. Facility Security Protective Measures Section 4-4. Security Administration Requirements 4-4-1. Purpose……………………………………………………………………….. 4-4-1 4-4-2. Security Coordinator (SC)………………………….………………………… 4-4-1 4-4-3. Facility Security Committee (FSC)……………..……………….…………… 4-4-1 4-4-4. Facility Security Plan (FSP)………….………………………………………. 4-4-2 4-4-5. Security Awareness Training………………………………………………… 4-4-6 4-4-6. Critical Areas………………………………………………………………… 4-4-8 4-4-7. Storage of Classified National Security Information (CNSI)..………………. 4-4-8 4-4-8. Control of Protected Information…………………………………………….. 4-4-8 4-4-9. Key, Lock, and Electronic Access Card Management………………………. 4-4-9 4-4-10. Loss and Theft Prevention………………………………………………….. 4-4-11 4-4-11. Incident Reporting………………………………………………………….. 4-4-13 4-4-12. Mail and Package Handling………………………………………………… 4-4-14
Chapter 5. Contract Security Officers
5-1. Purpose…………………………………………………………………………. 5-1
5-2. Selection of a Contract Security Officer (CSO) Provider……………………… 5-1
5-3. Contract Security Officer (CSO) Provider Responsibilities……………………. 5-1
5-4. Oversight of Contract Security Officer (CSO) Services………………………... 5-5
5-5. Individual Contract Security Officer (CSO) Requirements…….………………. 5-6
5-6. Arming a Contract Security Officer (CSO)…………….……………………….. 5-11
5-7. Use of Force Incident Reporting…………………………..…………………….. 5-14
5-8. Contract Security Officer (CSO) Operations………………………….………… 5-15
Appendix A. Related Publications and References A-1
Appendix B. Construction Standards for Open Storage Security Areas
B-1. Open Storage Secure Area……………………………………………………... B-1
B-2. General Construction Requirements…………………………………………… B-1
B-3. Acoustical Security…………………………………………………………….. B-4
Appendix C. Security Requirements for Flight Standards District Offices (FSDOs)
C-1. Purpose………………………………………………………………………… C-1
C-2. Security Requirements………………………………………………………… C-1
Appendix D. Security Requirements for Child Care Centers (CCCs)
D-1. Purpose………………………………………………………………………. D-1
D-2. Security Requirements………………………………………………………. D-1 lic availability to be determined under 5 USC 552) v b(Pu
D-3. New Child Care Center (CCC) Facility Planning and Design
Considerations……………………… D-1
Appendix E. Security Requirements for the ACT
E-1. Purpose…………………………………………………………………………. E-1
E-2. Description……………………………………………………………………... E-1
E-3. Assessments and Accreditation………….……………………………………… E-1
E-4. Security Level Assignment…………………………………………………….. E-1
E-5. Security Measures……………………………………………………………… E-1
Appendix F. Security Requirements for the MMAC
F-1. Purpose………………………………………………………………………… F-1
F-2. Assessments and Accreditation………………………………………………... F-1
F-3. Security Level Assignment……………………………………………………. F-1
F-4. Security Measures……………………………………………………………... F-1
F-5. Frequency of Assessments…………………………………………………….. F-3
Appendix G. Security Requirements for Air Route Surveillance RADAR Joint
Surveillance System (ARSR-4/JSS) Facilities with Communication Security
(COMSEC)
G-1. Purpose……………………………………………………………………….… G-1
G-2. Scope………………………………………………………………………….… G-1
G-3. Security Level Assignment ………...…………………………………………... G-1
G-4. Security Accreditation Requirements…………………………………………... G-1
G-5. Physical Security Enhancements …………………………………………….… G-1
G-6. Intrusion Detection System (IDS)…………………………………………….… G-3
G-7. COMSEC Storage Requirements…………………………………………….…. G-4
G-8. Facility Access Controls while Conducting COMSEC Operations………….… G-5
G-9. Unescorted Entry into Unstaffed Air Route Surveillance RADAR/Joint
Surveillance site (ARSR/JSS) Facilities…………………………………...……………... G-5
Appendix H. Definitions H-1
Appendix I. Frequently Used Acronyms I-1
List of Tables Table Page 3-1. FSL and Assessment Frequency…………………………………………………… 3-5
4-1-1. Facility Siting and Structural Protective Measures………………………………. 4-1-1
4-1-2. FAA Signage Available from FAA Depot…...…………………………………... 4-1-8
4-1-3. FAA Security Illumination………………………………………………………. 4-1-12
4-2-1. Facility Access and Circulation Control Protective Measures…………………... 4-2-1
4-2-2. Facility Security Checkpoint Functions………………………………………….. 4-2-3
4-3-1. System Security Requirements Matrix………………….……………………….. 4-3-1
4-4-1. Sample Facility Security Plan Contents………………………………………….. 4-4-6 vi
4-4-2. Initial and Annual Local Security Awareness Briefing Topics………………..… 4-4-7 B-1. Acoustical Standards………………………………………………………………. B-4
1-1
Chapter 1. General Information
1-1. Purpose of This Order. This order defines the Facility Security Management Program (FSMP). The FSMP establishes security requirements at facilities for which the FAA is responsible for security oversight, as described in paragraphs 3-2 and 3-3 of this order and applies to all FAA personnel (i.e., employees and contractors as defined in Order 1600.72, Contractor and Industrial Security Program) regardless of their assigned duty location as well as to all personnel permanently or temporarily assigned to work in or on FAA owned or leased properties, or properties utilized by the FAA that are owned, leased, security-controlled, or staffed by the General Services Administration (GSA) or others (e.g., other agencies, public or private entities in the U.S. or its territories, unless otherwise provided).
1-2. Audience. This order applies to any and all FAA employees, contractors, other government employees, and military personnel assigned to facilities that are owned, leased, or controlled by the FAA.
1-3. Where Can I Find This Order? This order can be found on the Directives Management System (DMS) website: https://employees.faa.gov/tools_resources/orders_notices.
1-4. Cancellation. Upon publication, this order cancels and incorporates information previously contained within the following:
a. FAA Order 1600.69B Change 1, FAA Facility Security Management Program (FSMP) dated March 29, 2005.
b. FAA Order 1600.74, Visitor Policy, dated July 18, 2013.
c. AIN-1 Memorandum dated June 27, 2014, Subject: Use of Explosive/Weapons (Test)
Kits and Guard Testing.
d. AIN-1 Memorandum dated June 23, 2014, POLICY UPDATE: Automated International
Visitor Program (IVP) Processing Protocols.
e. AIN-1 Memorandum dated May 28, 2014, POLICY UPDATE: Perimeter Intrusion
Detection System (PIDS) Requirements at FAA Facilities.
f. AIN-1 Memorandum dated March 10, 2014, POLICY UPDATE: Crime Mapping
Application.
g. AIN-1 Memorandum dated November 8, 2013, POLICY UPDATE: - Frequency of
Physical Fitness Evaluations and Random Drug Testing for Contract Security Officers (CSOs).
h. FAA Order 1600.74, Visitor Policy, dated July 18, 2013.
i. AIN-1 Memorandum dated April 25, 2013, Subject: ACTION: Request for Exception to
Requirements for the Guard Staffing Standard for FAA Facilities.
https://employees.faa.gov/tools_resources/orders_notices
1-2
j. ASH-1 Policy Memorandum dated April 15, 2013, POLICY UPDATE: Facility Security Levels (FSL) Designation of Air Traffic Facilities and Contract Security Officer (CSO) Requirements.
k. AIN-1 Memorandum dated September 18, 2012, FAA Contract Tower (FCT) Security
Requirements and Compliance Procedures.
l. AIN-1 Memorandum dated April 27, 2012, Subject: POLICY UPDATE: Assessment and
Inspection Criteria for FAA Armed Security Officers (ASO).
m. AIN-1 Memorandum dated April 16, 2012, Subject: POLICY UPDATE: Blast Mitigation and Exterior Setback Interim Policy. AIN-1 Memorandum dated March 23, 2012, POLICY UPDATE: Designated Facility Security Levels and Requirement for Security Guard Services at Stand-Alone TRACON Facilities.
n. AIN-1 Memorandum dated July 1, 2011, ACTION: Implementation Guidance for
Sponsor Owned/Leased Federal Contract Towers.
o. ASH-1 Policy Memorandum dated November 19, 2007, Interim Policy Changes
Affecting US and Foreign Persons Facility Visitor Procedures and International Travel Security Requirements.
1-5. Related Publications and References. Some related publications and references are listed in appendix A of this order.
1-6. Definitions. Definitions are listed in appendix H of this order.
1-7. Acronyms. Frequently used acronyms are listed in appendix I of this order.
1-8. Authority to Change This Order. The Associate Administrator for Security and Hazardous Materials Safety, ASH-1, may issue changes to this order as necessary to ensure that its provisions remain current and apply to all Lines of Business (LOBs) and Staff Offices (SOs) affected by the Order, consistent with the authority delegated by the Administrator in FAA Order 1600.6.
1-9. Explanation of Policy Changes. This policy is a complete revision from the prior order.
It has been updated as follows to reflect changes to national and department level policies and organizational changes within the FAA:
a. Updates Agency policy for non-critical infrastructure to align with national-level guidance provided by the Interagency Security Committee (ISC).
b. Updates application of risk methodology for National Airspace System (NAS) critical infrastructure (CI) (further defined in paragraphs 1-10 and 3-2) to better allow for adjustments to levels of protection through focused use of security measures based on evaluation and waivers and exceptions to standard security configuration.
c. Updates standard facility security levels (FSLs) for NAS critical infrastructure.
1-3
d. Integrates appropriate elements of updated federal requirements related to physical security and federal identification (ID) media.
1-10. Background. The FAA owns and operates thousands of facilities and physical assets (e.g., mobile towers, navigational aids) that support the FAA’s mission essential functions. This order establishes the administrative and physical security requirements necessary to secure FAA personnel, facilities, and assets that enable the FAA to achieve its mission. The FAA has the authority and responsibility to conduct searches of every individual’s personal effects upon entering or exiting any federal property. Entry searches of both personnel and visitors to government buildings have been upheld citing the safety concerns associated with building entry as the constitutional justification for their use.
a. FAA facilities and assets are described as either critical or non-critical infrastructure.
Critical infrastructure includes those facilities that provide air navigation services, which enable the operation of the NAS or use air navigation service capabilities to contribute to national defense, homeland security, law enforcement, and national response efforts to protect the nation from threats involving the Air Domain. Non-critical infrastructure (or referred to within this order as “administrative facilities”) support the efforts of the FAA’s CI by providing services, such as airport certification and compliance, aviation regulatory and safety oversight and certification. Administrative facilities also include those facilities that house FAA personnel who provide organizational and administrative support to the FAA.
b. For CI, Presidential Policy Directive (PPD) 21, Critical Infrastructure Security and Resiliency, states: “All Federal department and agency heads are responsible for the identification, prioritization, assessment, remediation, and security of their respective internal critical infrastructure that support primary mission essential functions.” This order is consistent with that directive and establishes both the minimum required protective measures needed for NAS critical infrastructure as well as the means to adjust those minimum requirements based on assessment processes and current risk environments.
c. For non-critical infrastructure, Executive Order 12977 established the ISC and charged that committee with the authority to: “…develop and evaluate standards for federal facilities…” These published ISC standards are used to identify and implement security requirements for non critical (referred to in this order as “administrative”) facilities. This order provides the mechanism for assessment, implementation, and oversight of those ISC standards for FAA facilities.
1-11. Scope of This Order. This order applies to all facilities for which the FAA is responsible for security oversight. This order also applies to all personnel permanently or temporarily assigned to work in or on FAA owned or leased properties, or properties utilized by the FAA that are owned, leased, security-controlled, or staffed by GSA or others (e.g., other agencies, public or private entities) in the United States and its territories, unless otherwise provided. FAA overseas facilities follow United States Department of State (DOS) security directives and procedures. Domestic Servicing Security Elements (SSEs) may provide support on physical security issues at FAA organizations overseas provided the overseas facility submits to ASH-1, in writing, a description of the support being sought and all relevant documentation to support the request. In all cases, requests must have ASH-1 approval, and must be coordinated with the
1-4
DOS, Bureau of Diplomatic Security. Any conflicting guidance contained in this order and any other applicable DOT/FAA order or directive must be referred to AIN-1 through the ASH SSE for resolution by AIN-1 in coordination with the Office of the Chief Counsel (AGC). Questions regarding what agency and office is responsible for the security of a particular facility or FAA office should be referred to AIN-1.
2-1
Chapter 2. Roles and Responsibilities
2-1. FAA Lines of Business, Staff Offices, and the Office of the Administrator, AOA.
a. Associate and Assistant Administrators; Senior Vice Presidents and Vice Presidents;
Service Area Directors; Regional Administrators; the Directors of the Mike Monroney Aeronautical Center (MMAC) and William J. Hughes Technical Center (ACT); Office Directors;
and managers at all levels must ensure that the contents of this order are effectively communicated to, adhered to by, and implemented within their organization.
b. Managers and their staff having responsibility for conceptual development and planning for programs, projects, operations, systems, and facility construction; modification, or leasing must be coordinated with their assigned SSE to ensure the implementation of this order.
2-2. The Associate Administrator for Security and Hazardous Materials Safety, ASH-1.
a. Exercises overall responsibility and authority for the implementation of the FSMP on behalf of the Administrator.
b. Ensures that policies, procedures, and standards for the FSMP are planned, developed, and implemented throughout the agency.
c. Coordinates with and supports the LOBs/SOs and other organizations as necessary to ensure the security of FAA facilities.
d. Through scheduled and unscheduled assessments, monitors the FSMP on behalf of the Administrator to ensure that each LOB/SO develops and implements comprehensive security policies and procedures for its facilities.
e. Ensures that appropriate resources are obtained and budgets planned as needed for execution and management of the FSMP.
f. Coordinates with affected LOBs and SOs and issues changes to this order as necessary to meet changing security requirements.
2-3. The Director, Office of Security, AIN-1.
a. Executes centralized governance over the FSMP across the agency, on behalf of ASH-1.
b. Ensures that physical security vulnerabilities that put FAA mission and/or NAS operations at risk are addressed by identifying security measures to reduce or eliminate vulnerabilities.
c. Issues policy updates and clarification affecting the implementation of this order in coordination with ASH-1, AGC, and interested LOBs/SOs as appropriate.
d. Ensures that facility security assessments are planned and conducted by the ASH Joint Offices (East, Central, West, and MMAC) as required and that findings are tracked to ensure they are closed. For the purpose of this document, MMAC is grouped in the term ASH Joint Offices in the rest of this document. Each ASH Joint Office is led by a Director, referred to as an ASH Joint Office Director (JOD).
2-2
e. Reviews and approves assessment reports and findings submitted by the ASH Joint Offices.
f. Evaluates requests for and grants or denies requests for exceptions to requirements.
g. Evaluates and grants or denies requests for additional security measures to mitigate or eliminate vulnerabilities identified based on evaluation.
h. Partners with the Facility Security Risk Management (FSRM) Program, managed by the Air Traffic Organization (ATO) consistent with FAA Order 1600.6, to represent the program at the Joint Resources Council (JRC), Capital Investment Team, and Operations Review Board on matters concerning facility security policy.
i. Oversees and develops training in conjunction with the Director, ASH Office of Workplace Management and Administration, AWM-1.
j. Resolves conflicts, in coordination with AGC, between this order and other published national, departmental, or agency policy.
k. Reviews accreditation suspensions before notice is sent to the facility.
l. Evaluates changes to a facility’s security level as recommended by the SSE.
m. Conducts evaluations of the FSMP throughout the ASH Joint Offices.
n. Conducts agency checks on foreign national visitors, as appropriate.
o. Verifies investigative information on personnel from other departments or agencies who visit FAA facilities, as appropriate.
p. Notifies the Office of International Affairs, API and the responsible SSE on the status of all foreign national visitor requests.
q. Develops the annual national-level security awareness virtual initiative (SAVI) and program awareness training.
2-4. The Director, Office of National Security Programs and Incident Response, AEO-1.
a. Obtains any available additional information concerning questionable information developed during agency checks conducted in support of foreign visit requests to help determine visit approval/denial or appropriate security measures.
b. Coordinates with federal law enforcement and intelligence agencies on national security matters and insider threats and advises AIN-1 of any nexus to facility security operations.
2-5. The Directors, Joint Security and Hazardous Materials Safety Office East, AHE-1;
Central, AHC-1; West, AHW-1; and Security Division Manager of the Mike Monroney Aeronautical Center (MMAC), AMC-700.
2-3
(Note: For purposes of this order, the MMAC Security and Investigations Division Manager is grouped within the “ASH JOD” acronym when assigned further responsibilities established elsewhere in this order.)
a. Implements the provisions of this order.
b. Develops staffing plans for infrastructure protection specialists in ASH that accurately reflect the number and types of positions necessary to fully comply with the requirements of this order.
c. Assigns SSEs as members on any group or team responsible for the planning and design of new facilities, major renovations or modification of existing facilities, and the proposed leasing of FAA office space to ensure those planned facilities meet the security requirements of this order.
d. Prepares annual work plans and conducts facility security assessments as required.
e. Provides subject matter expertise as requested by facility managers (FMs).
f. Ensures that reported security incidents are addressed and tracked until resolved.
g. Evaluates requests for and grants or denies waivers to requirements.
h. Issues facility accreditations or accreditation suspensions.
i. Submits requests for FSMP evaluations to AIN-1.
j. Develops reports for each facility assessed, detailing requested security requirements based on evaluation (BOE) of a facility.
k. Notifies ASH-1, ASH-2, and AIN-1 of any high level protocol visits to any FAA facility within their assigned area of responsibility.
l. Provides onsite security awareness briefings/training for components supported.
2-6. Office of the Chief Counsel, AGC.
a. Reviews all foreign national visit requests that may involve the disclosure or inadvertent compromise of export-controlled information or technology and determines, based on the information in the visit request, whether the proposed visit would be consistent with export laws, regulations, and policies.
b. Reviews all real property transactions that meet the requirements of the Acquisition Management System (AMS) Real Estate Policy 4.2.3.1 to ensure compliance with applicable law, policy and the terms of this order.
c. Interprets applicable law and policy and advises agency decision-makers regarding compliance with applicable law and policy including the terms of this order.
d. Coordinates with AIN-1 to resolve conflicts between this order and other published national, departmental, or agency policy.
2-4
2-7. Office of Government and Industry Affairs, AGI. Provides guidance on visits by congressional and high profile government officials.
2-8. Office of International Affairs, API. Coordinates all visits by foreign nationals to FAA facilities and ensures completion of the visit requests through the International Visitors Program.
2-9. The Chief Operating Officer, ATO.
a. Determines the criticality of ATO facilities in accordance with NAS operational requirements and provides that information to ASH.
b. Oversees the FSRM Program and provides resources necessary to acquire and implement required physical security measures and close security findings.
c. Identifies and assigns resources as needed for the implementation of and compliance with the requirements of this order.
2-10. The Director, Office of Air Traffic Control Facilities, AJW-2.
a. Manages and implements the FSRM Program on behalf of ATO.
b. Implements required security measures as identified in facility security assessments approved by AIN-1.
c. Identifies and investigates technology changes that improve or enhance facility security or result in cost savings without diminishing facility security.
d. In partnership with AIN-1, develops presentation products for and represents the FSRM at the JRC.
e. Manages and implements the required security measures for mobile assets when they are deployed in support of NAS operations in accordance with paragraph 4-3f.
f. The Unstaffed Infrastructure Sustainment (UIS) Program, AJW-24, is the office of primary responsibility for unstaffed facilities, but the SSE may conduct assessments as outlined in paragraph 3-4.
2-11. Facility Manager (FM).
a. Implements the FSMP as described in this order.
b. Includes the appropriate SSE in facility security planning and implementing security policies or procedures.
c. Completes required corrective actions to reduce or eliminate security vulnerabilities identified during facility security assessments or other evaluations.
d. Completes written action plans identifying the status of open security findings and submitting associated reports to the appropriate SSE as required.
(Public availability to be determined under 5 USC 552
2-5
e. Develops, implements, maintains, and exercises a facility security plan (FSP) for their facility.
f. Requests resources outside the scope of the FSRM Program as necessary to fully implement provisions of this order.
g. Reports possible security incidents as required by this order.
h. Establishes and serves as the chair of a facility security committee (FSC) as outlined in this order.
i. Assigns a security coordinator (SC), as necessary, in writing to assist in the management of the facility’s security program.
j. Reports inoperable, malfunctioning or deteriorating security fixtures, equipment, or systems to the FSRM Program Office and the SSE.
k. Reviews access permissions annually and takes measures to restrict or deny individual access to facilities or controlled area within 24 hours of any event (transfer, termination, suspension, etc.,) that alters an individual’s need for access.
l. Reviews and tests alarms and access systems annually.
m. Appoints the key control official in writing.
n. Establishes and implements proper visitor control procedures that comply with this policy for their facility and areas of responsibility. The procedures must include the facility/office manager approval process and delegation of visitor approval authorities, if any. The procedures must also include a process to validate whether a foreign national visit request is required.
o. Ensures all site specific visitor approval and visitor handling procedures are included in the site’s FSP and approved by the SSE.
p. Notifies their assigned SSE and the appropriate executive(s) within their respective LOB/SO of any visit request by Department of Transportation (DOT) executives, other federal, State, and local officials, foreign dignitaries and Heads of State.
q. Notifies the responsible SSE of any foreign national visitor request.
2-12. The Assistant Administrator for Regions and Center Operations/Aviation Logistics Organization, ARC/ALO
a. Is the Senior Real Property Officer of FAA.
b. Provides administrative oversight and training of, and warranting requirements for, FAA Real Estate Contracting Officers (RECOs).
c. Drafts FAA AMS policy and guidance applicable to real property.
d. Maintains the Real Estate Management System database of all interests in real property under the jurisdiction of FAA.
2-6
e. Notifies the SSE of all new lease agreements, modifications to lease agreements, and required site surveys as early as possible so that security requirements are included in construction planning and lease transactions.
f. Includes the SSE as an active, contributing member of any planning or design group for new facilities, major renovations or modifications to existing facilities, and FAA leases. This involvement should begin as early as possible during the planning stage.
2-13. Service Area/Regional Program and Project Managers of New Facility Construction, Existing Facility Modification, or New Leases. Coordinate with the SSE during all phases of facility planning and design and lease negotiations to ensure that facilities meet the standards and requirements of this order prior to FAA acceptance, lease or occupancy.
2-14. FAA Federal Employees and Contractors.
a. Comply with the requirements of this order.
b. Use good judgment and reasonable care in safeguarding government property entrusted to your care.
c. Federal employees must report all security incidents or weaknesses upon discovery to your first line supervisor or the next available supervisor in your chain of command. Supervisors must notify the responsible FM and SSE. Contractors must report all security incidents or weaknesses upon discovery to the responsible FM and SSE and provide notice of the reporting to the assigned contracting officer (CO) or contracting office representative (COR).
d. Federal employees must report non-functional security equipment to your first line supervisor or the next available supervisor in your chain of command. Supervisors must notify the responsible FM and SSE. Contractors must report any non-functional security equipment upon discovery to the assigned CO or COR.
e. Wear issued ID Media in accordance with this Order and FAA Order 1600.78, “Personal Identity Verification (PIV) and Other Identification (ID) Cards.”
f. Immediately curtail a visitor’s access and notify your first line supervisor or the next available supervisor in your chain of command, FM, and responsible SSE when visit circumstances change or arise that could possibly compromise information, systems, or operations.
3-1
Chapter 3. FSMP Overview
3-1. Purpose. This chapter provides requirements for planning, coordinating, evaluating and implementing the FSMP. It details FAA facility categories, FSLs, facility security assessment requirements, security design for new or renovated facilities and leased spaces, facility accreditation, waivers and exceptions, facility security information, program evaluations, and executive reporting. SSEs and FMs, their respective management hierarchies and personnel involved in building or acquiring new facilities or new/renewed leased space are subject to the provisions of this chapter.
3-2. Facility Categories. FAA facilities are grouped into three categories for the purpose of the FSMP: CI, administrative, and unstaffed facilities. See paragraph 1-10 for further information on CI and administrative facilities.
a. Critical Infrastructure (CI). Under PPD-21, departments and agencies are responsible for the security of their respective internal CI that support primary mission essential functions.
Security risks identified by the FAA at its CI facilities may necessitate implementing counter measures that deviate from ISC standards. In that respect security measures for these facilities are included in chapter 4.
b. Administrative Facilities. Security measures for administrative facilities adhere to the ISC security standards and, as they apply to the FSMP, are included in chapter 4.
c. Unstaffed Facilities. An unstaffed facility is defined as a facility where no FAA personnel are permanently assigned, but may make onsite visits. Some examples of unstaffed facilities include: remote center air/ground communications facility, remote transmitter/receiver, airport surveillance radar. The UIS Program, AJW-24, is the office of primary responsibility for these facilities, but the SSE may conduct assessments as outlined in paragraph 3-4.
3-3. FSLs. An FSL represents further categorization of FAA facilities based on an analysis of security-related facility factors and are assigned to both CI and administrative facilities. These levels then serve as the basis for assigning specific security measures that are identified in chapter 4. Administrative and CI facilities are evaluated against the ISC-determined facility factors, which include mission criticality, symbolism, total facility population, facility size, and the threat to tenant organizations. CI facilities are also evaluated against the following FAA-determined mission-specific factors: air traffic count level, Core 30 airport support, and resiliency/impact to the NAS. As a result, CI may be designated a higher security level and/or require additional security measures than if evaluated under ISC guidelines alone.
a. Assigning Security Levels to FAA Facilities. The FSMP is a standards-based security program. The FSRM Program, administered by Air Traffic, Technical Operations, projects funding requirement, and security improvements based on anticipated security needs defined by the FSMP. Because of these mutually supporting strategies, the FAA has elected to pre-assign facility security levels with common levels of protection for similar facilities conducting similar missions. In doing so, ASH has applied the risk criteria to the FAA facility inventory. This helps provide a stable security planning environment and minimizes program anomalies from occurring across the FAA.
3-2
b. Design-Based Threat (DBT). In evaluating the threat posed to NAS CI as part of assigning facility security levels, the DBT identified by the ISC was used as the baseline threat.
Although the overall terrorist threat to transportation, and aviation in particular, is expected to remain high, there is no agency-specific threat assessment published that exceeds the current ISC DBT. According to ISC guidance, absent information which merits a modification, the baseline threat is applicable.
c. Changing an FSL. Circumstances may present where, because of unique or changing mission needs, population, or specific facility threats (elevated or unusual risk or history of loss), the FSL of a particular facility may need to be adjusted up or down. Any such changes are based on an SSE recommendation that is documented in an ASH JOD memo that is forwarded to AIN 1for a decision. The decision to change an FSL away from the standard should be a last resort where BOE measures, on their own, cannot compensate for a particular facility’s unique security issue.
d. New Facilities. The security level of new facilities must be evaluated jointly between the SSE and AIN-100. Unless a difference from the standard is justified, they will be assigned the same security level as similar facilities (i.e. facilities in which the same FAA functions are performed; for example, a new tower facility would be assigned a security level consistent with other towers with comparable air traffic count levels) already in the FAA inventory.
e. Unstaffed Facilities. Unstaffed facilities (navigation aids, remote transmitters and receivers, vehicle and government equipment storage areas, etc.,) are not normally assigned an FSL (FSL 0). However, an SSE may, through the security assessment process, recommend that BOE security measures be implemented to compensate for particular security needs. This paragraph does not extend to unstaffed Common Air Route Surveillance RADAR (CARSR) and Air Route Surveillance RADAR / Joint Surveillance System (ARSR-4/JSS) sites with or without COMSEC. These facilities are considered FSL 2 CI facilities (see paragraphs 3-2a, 3-3f(3) and table 3-1) and will be assessed accordingly.
f. FAA FSL Listing. FAA facilities are assigned FSLs as follows in subparagraphs below.
The FAA assigns the FSL for any facility for which it is directly responsible for security oversight. The FSL for certain other facilities, including the Anchorage Federal Building and FAA Headquarters, is established by another agency, such as Department of Homeland Security (DHS) or DOT, when that agency is responsible for security oversight of the facility. For any facility not addressed, the SSE must coordinate with AIN-1 to determine the FSL. As Air Traffic Count levels are subject to fluctuation, specific Terminal Radar Approach Control (TRACON) and Air Traffic Control Tower (ATCT) count levels are monitored over a 24-month period.
ATO must provide to AIN-1 a listing of Air Traffic Count levels of terminal services facilities on a yearly basis. AIN-1 will publish an FSL listing of TRACONS and ATCTs by July 1 every year. Facilities listed below that are preceded by an asterisk (*) are NOT considered critical infrastructure as defined by PPD-21. While MMAC and ACT are considered FSL 4 campuses, facilities located within each campus constitute a mix of CI and administrative facilities with different FSLs (see appendices E and F).
(1) Facility Security Level 4 Facilities.
Public availability to be determined under 5 USC 552)
3-3
(a) MMAC.
(b) ACT.
(c) Air Route Traffic Control Centers (ARTCC) with co-located National Enterprise Management Centers.
(2) Facility Security Level 3 Facilities.
(a) Air Traffic Control System Command Center.
(b) ARTCC.
(c) Center RADAR Approach Control.
(d) Combined ATCT/TRACON typically operating at air traffic count levels 10-12.
(e) ATCT typically operating at air traffic count levels 10-12, as determined on an annual basis.
(f) TRACON typically operating at ATC levels 10-12, as determined on an annual basis, and supporting a Core 30 airport.
(g) *FAA administrative facilities as established in existing facility assessment reports and documented within the facility security database (referred to as FSRS); typically, FAA regional office buildings.
(3) Facility Security Level 2 Facilities.
(a) ATCT typically operating at air traffic count levels 7-9, as determined on an annual basis.
(b) Combined ATCT/TRACON not meeting the criteria of an FSL 3 ATCT/TRACON facility.
(e) TRACON not meeting criteria of an FSL 3 TRACON facility.
(c) RADAR Approach Control.
(d) Automated Flight Service Stations (AFSS).
(e) CARSR staffed or unstaffed.
(f) ARSR/JSS staffed or unstaffed with or without COMSEC.
(g) *FAA administrative facilities as established in existing facility assessment reports and documented within the facility security database; includes but not limited to:
Automatic Flight System Field Office, Systems Support Center (SSC), Security Field Office (SECFO), Certificate Management Office (CMO), Aircraft Certification Office, FSDO, Flight Inspection Field Office, and FAA Child Care Centers (CCC).
(4) Facility Security Level 1 Facilities.
3-4
(a) ATCT operating at air traffic count levels 1-6, as determined on an annual basis.
(b) * FAA administrative facilities as established in existing facility assessment reports and documented within the facility security database; includes but not limited to Airport District Office, Manufacturing Inspection District Office (MIDO), International Field Office, SSC, Systems Support Unit, Medical Field Office, and leased contract weather observer facilities.
(c) Federal contract towers (FCT) owned or leased by FAA.
(d) FAA owned or leased Flight Service Stations in Alaska.
(5) Facility Security Level 1A Facilities. FSL 1A facilities are sponsor owned or leased FCTs.
(6) FSL 0 Facilities. FSL 0 facilities are unstaffed facilities.
3-4. Facility Security Assessments. A facility security assessment is required for all staffed facilities and identifies both the baseline security measures (either required by this order and/or BOE) a facility is required to implement and whether the required security measures are being properly implemented. Additionally, these assessments determine whether a facility meets accreditation standards. Security assessments are not normally conducted for unstaffed facilities unless requested by an LOB/SO or determined necessary by an ASH JOD because of an unusual security situation.
a. Assessment Components. An assessment consists of an on-site examination of the facility and its operations as well as the local threats and vulnerabilities. It results in a determination of the overall risk level of the facility and documents the facility’s required security measures. The written assessment report must identify:
(1) Required security measures based on this order. The security measures are identified in chapter 4 of this order depending on the category and security level of the facility.
(2) Required security measures BOE. These are security measures in addition to the baseline requirements of this order or ISC standards. See chapter 4 for additional information.
(3) Any existing waivers or exceptions to requirements.
(4) Any existing protective measures that are not based on this order or BOE. Non-required security measures do not need to meet the standards identified in this order.
b. Risk Concept Methodology. The AIN-published risk assessment tool (RAT) must be used to structure facility security assessments. In order to effectively assess and analyze the known risks at each facility, SSEs must evaluate the data associated with risks to the facility prior to the assessment. In the event this evaluation indicates that a facility has an elevated risk or an unusual history or risk of loss, additional security measures may be recommended to compensate. This determination must be documented in the facility’s assessment report. SSEs are required to review the following prior to an assessment:
3-5
(1) Past assessment reports (if they exist).
(2) Any waivers or exceptions granted to existing security requirements.
(3) Incident history of the facility.
(4) Any other CI within 25 miles of the facility that may have a threat impact. These may be owned or operated by other government departments or agencies or the private sector.
(5) Incident history of the facility and the public areas surrounding as identified by the AIN-approved Crime Mapping tool.
(6) Geographic location and any history of natural disasters or weather issues which may affect security measures implemented at the facility.
c. Facility Security Assessment Types. There are two types of facility security assessments: comprehensive and supplemental.
(1) Comprehensive assessment. A comprehensive assessment is an on-site review of the status of all facility security program areas.
(2) Supplemental assessment. Supplemental assessments are narrower in scope than the scheduled comprehensive assessment. They are conducted to verify closure of open findings, in response to an incident, or as deemed necessary by the SSE.
d. Scheduling of Comprehensive Assessments. ASH JODs must notify the FM of the planned comprehensive assessment to ensure the availability of key personnel. While the ASH JODs may schedule comprehensive assessments as necessary to ensure the effective security of FAA facilities, at a minimum, facilities will be assessed according to the following schedule:
Table 3-1. FSL and Assessment Frequency
Facility Security Assessment Frequency – Minimum
Baseline Target
Level Accredited Facilities
Unaccredited or Elevated Risk Facilities
All – Regardless of Risk or Accreditation Status
4 18 months 12 months 12 months
3 18 months 12 months 12 months
2 36 months 24 months 24 months 2 – CARSR and
ARSR/JSS*
24 months 12 months 12 months
1/1A 48 months 36 months 36 months
0 As Needed As Needed As Needed
* Includes unstaffed CARSR and ARSR/JSS with or without COMSEC
ASH JODs must schedule activities to meet the “target” frequency to the extent resources allow.
AIN-1 will provide guidance to ASH JODs on any mandates to transition from the minimum baseline to target frequencies as anticipated resources become available.
3-6
(1) There is no established frequency for supplemental assessments. Supplemental assessments may be conducted as the SSE deems necessary, in coordination with the FM.
(2) There is no established frequency for unstaffed facilities. Assessments of unstaffed facilities may be conducted if events dictate and/or in response to an LOB/SO request.
(3) The SSEs must maintain frequent dialogue with FMs as an essential measure of their facilities’ security programs. Supplemental assessments should be conducted anytime there are frequent or ongoing security issues at a facility or when the SSE has reason to believe that the security posture of a facility is in question.
(4) FAA facilities that are located on military bases or contractor facilities or those staffed by a military entity may be exempt from FAA facility security assessments and, if so, will follow the physical and administrative security requirements of the relevant military organization or contract company. SSEs will evaluate whether a facility meets this exemption and, if so, will notify AIN-1 in writing of that determination. A copy of the memo will be made part of the facility record in the ASH facility security database. These determinations will be re-evaluated every 3 years from the date of the memo and, if the exemption still applies, a new memo will be provided. See also paragraph 4-1.
e. Tracking and Resolving Security Findings. In the course of conducting a facility security assessment, any security “findings,” or deficiencies, must be identified by the SSE and documented in the assessment report. The status of these security findings at each facility will be individually tracked by the SSE and the responsible FM until closed. The SSE will assist the responsible FM and the applicable LOB/SO in resolving all findings.
(1) For those findings that cannot be closed within 90 days of the assessment report, the FM must submit a written corrective action plan (CAP) to the SSE. The plan, due 90 days after the assessment was completed, must detail actions taken, or planned, along with anticipated timelines for resolving each finding. Waivers or exceptions should be considered and pursued where applicable. Non-funding dependent findings (administrative findings) must be corrected within 90 days of submission of the CAP (180 days from the assessment report or finding being identified, whichever is later). Extensions to these timelines may be granted by the SSE.
(2) Findings will be noted as closed when the SSE verifies that the required actions have been satisfactorily implemented. Normally, this is done through a supplemental assessment, but may be accomplished by reviewing documentation (including photographs) provided by the FM.
Updates to a facility’s security findings will be made in the ASH facility security database within 10 business days of SSE verification.
f. Facility Security Assessment Reporting.
(1) Prior to beginning an assessment and at the conclusion…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .