About this file

This directive establishes the classified national security information and industrial security program requirements for NASA's Goddard Space Flight Center (GSFC). It outlines policies and procedures for original classification authority, derivative classification, declassification, access, accountability, storage, destruction, transportation, security violations, and information systems security for classified national security information. It also addresses requirements for sensitive compartmented information facilities, industrial security for classified contracts, and reporting to the Information Security Oversight Office. Responsibilities are defined for key roles including the Center Director, Chief of Protective Services, program managers, employees, and contractors. Records management requirements are provided.

View the file

Other files for this federal contract opportunity

Other files attached to NASA Sounding Rocket Operations Contract (NSROC) IV - FINAL Request for Proposal, eLibrary, newest first.
File Type Posted
NSROC CBA IAMAW 11.01.21 final FULLY EXECUTED.pdf PDF
Rocket_Report_1st_quarter_2019.pdf PDF
Rocket Report 2nd quarter 2021.pdf PDF
Rocket_Report_3rd_quarter_2019.pdf PDF
Rocket Report 4th quarter 2020.pdf PDF
Rocket Report 1st quarter 2021.pdf PDF
SRPO Annual Report 2017.pdf PDF
Rocket Report 1st quarter 2020.pdf PDF
SRWG_Findings_Jan_2021.pdf PDF
Sounding rocket litho 2017.pdf PDF
SRWG_Findings_July_2020.pdf PDF
GSFC-STD-8009T-SRPO WFF Range Safety Manual Rev B.pdf PDF
300-PG-8730.6.1 ESD Control Plan.pdf PDF
800-WI-8715.2.1B Severe Weather Notification.pdf PDF
810-PG-5100.1.3G NSROC Development and Routine Project Assignments Process.pdf PDF
GPR 4220.1.pdf PDF
GPR 1700.7.pdf PDF
GPR 1860.2.pdf PDF
GPR 8730.1.pdf PDF
GPR 8710.8.pdf PDF
GPR 8500.5.pdf PDF
GPR 5340.3.pdf PDF
NPR 2190.1.pdf PDF
GPR 8500.8.pdf PDF
GPR 1700.8.pdf PDF
GPR 1800.5.pdf PDF
NPR 8735.2.pdf PDF
810-FORM-0003H SRPO MRR Checklist.pdf PDF
NPD 1490.1.pdf PDF
NPD 4200.1.pdf PDF
NPR 1441.1.pdf PDF
GPR 8730.6.pdf PDF
NPD 6000.1.pdf PDF
NPD 2540.1.pdf PDF
NPD 1440.6.pdf PDF
803-PG-3410.2.2 WFF Safety Office Training and Certification Program.pdf PDF
NPD 1280.1.pdf PDF
NPR 8705.6.pdf PDF
810-FORM-0002G SRPO DR Checklist.pdf PDF
810-FORM-0004H SRPO MCR Checklist.pdf PDF
NPR 8715.5.pdf PDF
NPR 4200.1.pdf PDF
SRPO Cryogenic Safety Users Guide Revision A Final.pdf PDF
NSROC III NNG16WA70C Attachment M - Contract Historical Data 19-20.pdf PDF
SRPO Technology Roadmap June 2021.pdf PDF
NSROC III List of Ongoing Work - October 2021.pdf PDF
SRPO Annual Report 2016.pdf PDF
Rocket_Report_4th_quarter_2019.pdf PDF
SR User Handbook Final_July 2015.pdf PDF
SRPO Annual Report 2019.pdf PDF
Show all 50

NASA Sounding Rocket Operations Contract (NSROC) IV - FINAL Request for Proposal, eLibrary has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DIRECTIVE NO. GPR 1600.2A APPROVED BY Signature: Original Signed By

EFFECTIVE DATE: June 29, 2018 NAME: Raymond J. Rubilotta

EXPIRATION DATE: June 29, 2023 TITLE: Director, Management Operations Directorate

CHECK THE GSFC DIRECTIVES MANAGEMENT SYSTEM AT

http://gdms.gsfc.nasa.gov TO VERIFY THAT THIS IS THE CORRECT VERSION PRIOR TO USE.

08/16

Goddard Procedural Requirements (GPR)

CURRENT

COMPLIANCE IS MANDATORY

Responsible Office: Code 240/GSFC Protective Services Division

Title: GSFC Protective Service Division Classified National Security Information and Industrial

Security

PREFACE

P.1 PURPOSE

a. This Goddard Space Flight Center (GSFC) Procedural Requirement (GPR) establishes the Center-wide classified National Security information and industrial security program implementation requirements set forth in NASA Procedural Requirement (NPR) 1600.2, NASA Classified National

Security Information (CNSI).

b. This GPR prescribes personnel responsibilities and procedural requirements for the management of

CNSI to assist the GSFC and component programs in executing the NASA security program designed to protect people, property, and information.

c. This GPR also establishes Center procedures for the proper implementation and management of a uniform system for classifying, accounting, safeguarding, and declassifying national security information generated by or in the possession of NASA.

P.2 APPLICABILITY

a. This GPR applies to all GSFC personnel, facilities, and activities, including all permanent and temporary sites, and to all GSFC contractors, tenant organizations, tenant contractors, grantees, clubs, visitors, vendors, guests, and/or anyone else doing business or physically present on the GSFC or its component facilities, in accordance with applicable law. This GPR applies to contractors, grant recipients, or parties to agreements only to the extent specified or referenced in the appropriate contracts, grants, or agreements. Exceptions or special provisions for specific sites are identified in the body of the document.

b. In this GPR, all document citations are assumed the latest version unless otherwise noted.

c. In this GPR, all mandatory actions (i.e., requirements) are denoted by statements containing the term

“shall.” The terms “may” or “can” denote discretionary privilege or permission; “should” denotes a http://gdms.gsfc.nasa.gov/

DIRECTIVE NO. GPR 1600.2A Page 2 of 18

EFFECTIVE DATE: June 29, 2018

EXPIRATION DATE: June 29, 2023 good practice and is recommended but not required; “will” denotes expected outcome; and “are/is” denotes descriptive material.

P.3 AUTHORITY

a. National Aeronautics and Space Act, as amended, 51 U.S.C. § 20132, Pub. L. No. 113-314, Dec. 18,

b. NPR 1600.2, NASA Classified National Security Information (CNSI)

c. Classified National Security Information, E.O. 13526, 75 Fed. Reg.707 (Jan. 5, 2010).

P.4 APPLICABLE DOCUMENTS and FORMS

a. Access to Classified Information, as amended, E.O. 12968, 60 Fed. Reg. 40245 (Aug. 7, 1995).

b. Classified National Security Information, E.O. 13526, 75 Fed. Reg.707 (Jan. 5, 2010).

c. Classified National Security Information; Final Rule, 32 CFR pt. 2001.

d. National Industrial Security Program Directive No. 1, 32 CFR pt. 2004

e. Information Security Program, 14 CFR pt. 1203.

f. Records Management by Federal Agencies, 44 U.S.C. § 2905, § 3101, and § 3102

g. NPR 1600.2, NASA Classified National Security Information (CNSI)

h. NPR 1441.1, NASA Records Management Program Requirements.

i. NPR 1450.10, NASA Correspondence Management and Communications Standards and Style.

j. NPR 7120.5, NASA Space Flight Program and Project Management Requirements.

k. NPR 7120.7, NASA Information Technology and Institutional Infrastructure Program and Project

Management Requirements.

l. NPR 7120.8, NASA Research and Technology Program and Project Management Requirements.

m. NASA ITS-HBK-2810.09-04, Incident Response and Management.

n. National Industrial Security Program Operation Manual (NISPOM) DoD 5220.22-M.

o. Classified National Security Information, E.O. 13526, 75 Fed. Reg.707 (Jan. 5, 2010).

p. NASA Handbook for Writing Security Classification Guides.

q. SF 312, Classified Information Nondisclosure Statement.

r. SF 702, Security Container Check Sheet.

s. NF 387, Classified Material Receipt.

t. NF 1833, Request for SCI Classified Visit.

u. Form 2018a, Special Access Request.

v. DD form 254, Department of Defense Contract Security Classification Specification.

P.5 CANCELLATION

GPR 1600.2, GSFC Protective Service Division Classified National Security Information and Industrial

Security, dated December 11, 2013.

P.6 SAFETY

DIRECTIVE NO. GPR 1600.2A Page 3 of 18

None

P.7 TRAINING

a. In accordance with Exec. Order No. 13526 and Information Security Oversight Office (ISOO)

Directive No. 1, NISPOM, and this GPR, all NASA civil service employees, and contractor personnel to the extent required by their NASA contract, who have met the standards for access to classified information will receive initial training, annual refresher training, specialized training as required, and termination briefings. The training will be developed in coordination with the Office of

Protective Services (OPS) to ensure the minimum requirements of Federal policies are met. The training will include information, personnel, and industrial security policies and procedures.

b. Personnel entrusted with classified information shall attend the required briefings and security awareness training provided by the GSFC Protective Services Division (GPSD) or other Government agencies that provide classified information to NASA personnel. Individuals who handle CNSI are fully knowledgeable of and in compliance with the provisions set forth in this GPR and Exec. Order

No. 13526, as amended, established for governing, accessing, protecting, accounting for, and safeguarding classified information and material. The management of classified information will be included in individual performance plans as a critical element as required by Section 5.4, (7) of

Exec. Order No. 13526.

c. Persons who apply derivative classification markings shall receive initial specialized training in the proper application of the derivative classification principles of Exec. Order No. 13526, with an emphasis on avoiding over classification. Once initial training is accomplished, annual refresher derivative classification training shall be accomplished by completion of NASA Annual Security

Education and Training for Clearance Holders.

P.8 RECORDS

The table below lists both the records required by this GPR and those required by NPR 1600.2. See

Appendix B for identification of acronyms. The term “appropriate” in the Record Custodian column means the location appropriate for a given GSFC site, e.g., the Greenbelt Protective Services Division

Office as opposed to the Wallops Protective Services Division Office, the Goddard Institute for Space

Studies (GISS), the Independent Verification and Validation (IV&V) Facility and the White Sands

Complex (WSC).

No. Record Title Record Custodian Retention

1 Classified Documents

Inventory Reporting Files

Appropriate GPSD Office *NRRS 1600/101 Destroy when 2 years old.

DIRECTIVE NO. GPR 1600.2A Page 4 of 18

2 Classified Information

Nondisclosure Agreements (SF-

312)

Appropriate GPSD Office *NRRS 1610/102 Destroy when 50 years old.

3 Personnel Security Clearance

Files of investigative reports and related papers furnished to agencies by investigative organizations for use in making security/suitability determinations.

GPSD Personnel Security

Office

*NRRS 1610/103B Destroy in accordance with the investigating agency instructions.

4 Personnel Security Clearance

Files Index to the Personnel

Security Case Files.

GPSD Personnel Security

Office

*NRRS 1610/103C Destroy with related case file.

5 Personnel Security Clearance

Status Files Lists, or Rosters maintained in security units showing the current security clearance status of individuals.

GPSD Personnel Security

Office

*NRRS 1610/103D Destroy when superseded or obsolete.

6 Facilities Checks (By Guard

Force) data sheets, door slip summaries, check sheets, and guard reports on security violations (except copies in files of agency security offices covered elsewhere).

Appropriate GPSD Office *NRRS 1620/107A Destroy when 1 year old.

7 Container Files – Classified

Document Security

Appropriate GPSD Office *NRRS 1620/109A Destroy when superseded by a new form or list, or upon turn-in of containers.

23 Container Files – Returnable Appropriate GPSD Office *NRRS 1620/109B Destroy 3 years after return of container or purchase of container, whichever is applicable.

24 Documents, Accountability/

Inventory Files – Top Secret

Documents

Appropriate GPSD Office *NRRS 1630/111A Destroy 5 years after documents shown on forms are downgraded, transferred, or destroyed.

25 Documents, Accountability/

Inventory Files – Classified

Documents

Appropriate GPSD Office *NRRS 1630/111B Destroy when 2 years old.

26 Industrial Security Files –

Precedent and unusual cases selected by pertinent NASA officials

Appropriate GPSD Office *NRRS 1650/113A Destroy after the document to which the classification action applies has been downgraded or declassified by suitable markings

DIRECTIVE NO. GPR 1600.2A Page 5 of 18

27 Industrial Security Files – All other offices/case files

Appropriate GPSD Office *NRRS 1650/113B Destroy when no longer needed, or not later than 3 years after contract is closed/completed.

*NRRS – NASA Records Retention Schedules (NPR 1441.1A)

P.9 MEASUREMENT/VERIFICATION

a. The Office of Protective Services (OPS) audits, conducts functional reviews of the Center, and conducts spot-checks and inspections to review Center compliance and implementation of this GPR.

OPS audits/reviews are conducted at least every 3 years, or sooner as required to determine compliance with this GPR. The findings of the audits/reviews are provided to the Center Director for resolution no later than 30 days from the completion of the reviews/audits.

b. The ISOO maintains continuous liaison with their agency counterparts on all matters relating to the

Government-wide security classification program and the National Industrial Security Program.

ISOO also conducts on-site inspections and special classified document reviews to monitor agency compliance with applicable Executive Orders. Each year ISOO gathers relevant statistical data regarding each agency's security classification program. ISOO analyzes this data and reports them, along with other relevant information, in its Annual Report to the President. NASA follows ISOO guidance and is subject to ISOO inspections and reviews.

PROCEDURES

CHAPTER 1. INTRODUCTION AND RESPONSIBILITIES

1.1 Introduction

Requirements in this directive are derived from and support the requirements established in NPR 1600.2, NASA Classified National Security Information (CNSI).

1.2 Responsibilities

The individuals and organizations at the GSFC shall comply with the specific responsibilities for the protection and management of NASA Classified National Security Information (CNSI) are identified in

NPR 1600.2. These responsibilities are identified for the following:

a. Center Director

b. Center Chief of Protective Services (CCPS)/Chief of Center Security (CCS)

c. Center COMSEC Officer

d. Program Managers, Line Managers, and Supervisors.

e. Employees and contractors.

1.3 Waivers and Exceptions

http://nodis3.gsfc.nasa.gov/library/lib_docs.cfm?range=1___

DIRECTIVE NO. GPR 1600.2A Page 6 of 18

1.3.1 Requests for Waivers or Exceptions to this GPR shall be approved by the Senior Agency Official

(SAO), Assistant Administrator for Protective Services in accordance with NPR 1600.1A, Chapter 1.

1.4 Violations of Security Requirements

1.4.1 Anyone who willfully violates, attempts to violate, or conspires to violate any regulation or order involving the NASA personnel security program is subject to disciplinary action up to and including termination of employment and/or possible prosecution under 18 U.S.C. §799, that provides fines or imprisonment for not more than 1 year, or both.

CHAPTER 2. CNSI MANAGEMENT

2.1 Original Classification Authority (OCA) and Marking

2.1.1 Classification. Collateral information is classified pursuant to Exec. Order No. 13526, as amended by an OCA and is designated and marked as Top Secret, Secret, or Confidential.

2.1.2 Classification Levels. Information may be classified at one of the following three levels:

a. "Top Secret" shall be applied to information, the unauthorized disclosure of which reasonably could be expected to cause exceptionally grave damage to the national security that the original classification authority is able to identify or describe.

b. "Secret" shall be applied to information, the unauthorized disclosure of which reasonably could be expected to cause serious damage to the national security that the original classification authority is able to identify or describe.

c. "Confidential" shall be applied to information, the unauthorized disclosure of which reasonably could be expected to cause damage to the national security that the original classification authority is able to identify or describe.

2.1.3 Except as otherwise provided by statute, no other terms shall be used to identify United States classified information.

2.1.4 Overall classified document markings along with page, component, portion markings, and use of cover sheets shall conform to guidelines established by the CCPS/CCS in accordance with Exec. Order

No. 13526 and promulgated in Chapter 8, "Classified Correspondence," of NPR 1450.10D, NASA

Correspondence Management and Communications Standards and Style. The Information Security

Oversight Office (ISOO) Pamphlet, "Marking Classified National Security Information," also shows examples for marking classified e-mails and other devices.

DIRECTIVE NO. GPR 1600.2A Page 7 of 18

2.1.5 Marking of documents on classified system, shall be accordance with the Classification

Management Tool (CMT) installed on the systems. For marking pieces of equipment or some other unique classified item, please contact your Center Protective Service Office for specific instructions on how to mark each item.

2.2. Designation of Original Classification Authority

2.2.1 Agency personnel with OCA designation are identified in 14 C.F.R, Subpart H - Delegation of

Authority to Make Determinations in Original Classification Matters, Part 1203.

a. The following NASA personnel possess OCA designation up to and including Top Secret: the

NASA Administrator, Deputy Administrator, Associate Administrator, and the AA for Protective

Services.

2.2.2 Designation of OCA and required training shall be accomplished in accordance with NPR

1600.2, Chapter 2. The GPSD designated Top Secret Control Officer (TSCO) may be contacted for assistance.

2.3 Derivative Classification

2.3.1 Derivative classification is the act of incorporating, paraphrasing, restating, or using in a new form, information that is already classified, and marking the newly developed material consistent with the markings of the source information.

2.3.2 Derivative classification of CNSI shall be accomplished in accordance with NPR 1600.2, Chapter 2. The GPSD designated TSCO may be contacted for assistance.

2.4 25-Year Automatic Declassification and Downgrading of CNSI

2.4.1 In accordance with Exec. Order No. 13526, as amended, all CNSI records that are more than 25 years old and have been determined to have permanent historical value under "Records Management by

Federal Agencies," 44 U.S.C. § 2905, § 3101, and § 3102, shall be automatically declassified, on

December 31 of each year, whether or not the records have been reviewed.

2.4.2 Automatic declassification of CNSI shall be accomplished in accordance with NPR 1600.2,

2.5 Access to CNSI

2.5.1 At a minimum, NASA personnel and other individuals associated by contract or other agreement shall meet the following criteria for accessing CNSI in accordance with Access to Classified

Information, as amended, Exec. Order No.12968 and Exec. Order No. 13526:

DIRECTIVE NO. GPR 1600.2A Page 8 of 18

a. Possess a personnel security clearance commensurate with the required access.

b. Have an official need-to-know.

c. Sign an official Classified Information Nondisclosure Agreement (SF 312) witnessed by a NASA security official, an approved facility security officer, or other approved official.

d. Complete annually NASA Annual Security Education and Training for Clearance Holders in

SATERN.

2.6 Accountability and Control of CNSI

2.6.1 Accountability of Top Secret classified information is essential to maintaining a history of what classified material the Center has on site, where it is stored on the Center, and the cleared civil service employee or contractor has it. Effective accounting procedures must exist to immediately trace the movement and detect the loss of classified information.

2.6.2 Secret and Confidential material shall be protected and safeguarded from persons without authorized access or need to know in accordance with ISOO Directive 1, Section 2001.41 and Executive

Order No. 13526.

2.6.3 Accountability of classified material shall be accomplished in accordance with NPR 1600.2, Chapter 2. The GPSD designated TSCOs or the Classified Material Control Officers (CMCO) may be contacted for assistance.

2.6.4 The CMCOs are responsible to the CCPS/CCS for the Center Security Control Points (SCP) and oversight of the Document Control Points (DCP) within the GSFC. All incoming and outgoing classified information, to include CNSI received through Mailrooms and Shipping Facilities, will be immediately processed through the SCP with the following exceptions:

a. SCI material and classified messages that are handled, processed, and stored within secure telecommunications spaces.

2.7 Storage of CNSI

2.7.1 CNSI information and materials shall be stored in security containers (safes) and vaults approved by the GPSD.

2.7.2 Security container (safe) combination changes shall be requested by contacting the GPSD when a combination needs to be changed due to any of the below circumstances:

a. At least annually, at the completion of the annual inventory.

b. When a security container account is established.

c. When the list of authorized users changes due to an employee resignation or position change, etc.

DIRECTIVE NO. GPR 1600.2A Page 9 of 18

d. A compromise is suspected.

2.7.3 A Security Container Check Sheet (SF-702) shall be attached to each security container containing CNSI and must be initialed and dated daily. A Security Activities Checklist (SF-701) shall be placed on the outer door to verify all equipment and security containers are properly secured.

2.8 Destruction of CNSI

2.8.1 Destruction of classified material shall be accomplished in accordance with NPR 1600.2,

2.9 Carrying, Transporting and Receiving of CNSI

2.9.1 Carrying, Transporting and Receiving of CNSI material shall be accomplished in accordance with NPR 1600.2, Chapter 2. The GPSD designated TSCO may be contacted for assistance.

2.9.2 A GSFC Courier Card shall be required to hand carry classified material outside of GSFC, Courier Cards are issued through the GPSD and are valid for 1 year.

2.9.3 Deliveries of incoming secret and confidential classified information can be received by registered mail through the GSFC Mail Room. This mail is delivered to the GPSD for processing and then delivered to the addressee.

2.10 Security Violations and Compromise of CNSI

2.10.1 Any employee suspecting or observing a loss, possible compromise or unauthorized disclosure of classified information or material shall immediately report the finding to the CCPS/CCS upon discovery of the incident. The CCPS/CCS will appoint a lead from the Center Protective Services

Office to head the investigation and to contact the appropriate organizations required to complete this action. This includes data-spillages on the NASA unclassified network.

2.10.2 The CCPS/CCS shall notify the OPS Security Management Division Director, the Central

Adjudication Facility (CAF), and, as appropriate, Center management officials when classified information is presumed compromised. The NASA Security Operations Center and Center Chief

Information Officer will be notified when the incident involves an information system or electronic media as described in ITS-HBK-2810.09-04,

2.10.3 An investigation of the incident shall be accomplished in accordance with NPR 1600.2, and a written incident report will be made to the OPS Security Management Division Director.

2.11 Classified Material Is NOT Personal Property

DIRECTIVE NO. GPR 1600.2A Page 10 of 18

2.11.1 CNSI is always the property of the United States Government. Individuals who remove CNSI may be subject to disciplinary action up to and including criminal prosecution under Titles 18 and 50 of the United States Code and other applicable laws.

2.12. Security Classification Reviews for NASA Programs and Projects

2.12.1 Special Access Programs (SAP) are established for a specific class of classified information that imposes safeguarding and access requirements that exceed those normally required for information at the same classification level. In addition, programs may utilize or create classified Sensitive

Compartmented Information (SCI) concerning or derived from intelligence sources, methods, or analytical processes that is required to be handled within formal access control systems established by the Director of National Intelligence.

2.12.2 Pursuant to NPR 7120.5E, NPR 7120.7, and NPR 7120.8, programs and projects must conduct formal security reviews that, in addition to personnel, physical, and information technology security, shall include reviews for traditional information classification security needs. Security reviews will be undertaken to determine if information used or produced as part of a program or project, meets the requirements for designation as CNSI controlled information.

2.12.3 Program and project managers will contact their local Center Protective Services Office for classification assistance at the beginning of all new projects as required. Upon the conclusion of the security review, if the information surrounding or concerning the program or project, or portions thereof, meet one or more of the categories of information presented in Exec. Order No. 13526, a subject matter expert (SME) with assistance from the CCS must develop an appropriate Security Classification Guide

(SCG).

2.12.4 SCG creation and review shall be accomplished in accordance with NPR 1600.2.

CHAPTER 3. SENSITIVE COMPARTMENTED INFORMATION FACILTIES (SCIF)

3.1 SCIF Access

3.1.1 The CCPS is responsible for operation of all GSFC SCIFs in accordance with Intelligence

Community Directive (ICD) 705 and NPR 1600.2.

3.1.2 All SCIF access shall be controlled by the GSFC Protective Services Division.

3.1.3 Requests for access to the GPSD SCIFs shall be requested at least 72 hours in advance of the need for access.

3.2 Classified Visits/Meetings

DIRECTIVE NO. GPR 1600.2A Page 11 of 18

3.2.1 Employees attending classified meetings (conference, seminar, exhibit, and symposium) occurring at another site require a Classified Visit Request for the classification level of the meeting.

3.2.2 The employee shall contact the GPSD 72 hours prior to the event to allow sufficient time for the

Visit request issuance.

3.2.3 The employee must provide the proper security Point of Contact, phone number, secure fax number and email if possible. A Classified Visit Request will be sent within 24 Hours of receiving the information.

3.2.4 NASA personnel seeking to visit a Federal agency or contractor facility requiring TS/SCI level access must complete NASA FORM 1833 (Request for SCI Classified Visit Approval) requesting either a Term Cert (1 day to 3 months) or Perm Cert (91 days to 12 months).

3.2.5 Contractors needing Classified Visit Requests sent shall contact their company Facility Security

Officer (FSO) to arrange completion. Contractors with NASA sponsored SCI clearances follow the procedures listed in Section 3.2.4.

3.2.6 Employees and contractors with clearances issued from other agencies attending a meeting at a

NASA SCIF shall have their Classified Visit Request sent to the appropriate office within the GPSD at least 48 hours prior to the scheduled classified meeting.

CHAPTER 4. INDUSTRIAL SECURITY

4.1 Industrial Security

4.1.1 Industrial security pertains to, but is not limited to, the requirement to review all programs/projects in accordance with associated regulations, classified contract administration rules and requirements, and the processing and control of classified visits for cleared Government and contractor employees.

4.1.2 The Defense Security Service (DSS) administers the National Industrial Security Program on behalf of NASA. This support extends to contractor sites. The CCPS is responsible for oversight of industrial security services of contractors on NASA Centers and facilities, excluding personnel security clearances.

4.2 Classified Contracts

4.2.1 The standard security provisions of NASA classified contracts require the contractor to have a

Facility Clearance Level (FCL), which is an administrative determination that a facility and contractor

DIRECTIVE NO. GPR 1600.2A Page 12 of 18 personnel are eligible for access to classified information or award of a classified contract. It is a partnership between NASA and the Contractor.

4.2.2 The Defense Security Service (DSS) is primarily responsible for ensuring that the contractor complies with all security requirements. In addition, DSS is responsible for granting the FCL and personnel clearances when the contractor determines that access is essential to the performance of tasks and services related to the fulfillment of a classified GSFC contract.

4.2.3 NASA shall exercise its right as documented in contracts, to inspect contractor operations located on NASA property that are involved in accessing and safeguarding classified information. This review must be documented on the Department of Defense DD-254 Form and within the contract specifications.

4.2.4 Pursuant to the NISPOM, ensure the contractor provides a "Classified Visit Request" to the

CCPS with a list of all the contractors and their clearance level. The contractor shall provide the CCPS an updated list when a contractor is added or deleted from the contract.

4.3 Periodic Review of DD Form 254.

4.3.1 The review or modification of DD Form 254 shall be accomplished annually in accordance with

NPR 1600.2, Chapter 2.

4.4 Information Systems Security of CNSI

4.4.1 Information systems (IS) that are used to capture, create, store, process, or distribute CNSI must be properly managed to protect against unauthorized disclosure of classified information, loss of data integrity, and to ensure the availability of the data and system.

4.4.2 The OPS shall be responsible for the certification and accreditation for all NASA Classified

National Security Information (CNSI) systems, networks, and Protected Distribution Systems.

4.4.3 All personnel having a need to access the NIN/SIPR computer systems shall have an approved

NSS User Agreement. Prior to being granted access, all users must complete the Center for

Development of Security Excellence training course Derivative Classification (IF103.16) and accompanying knowledge understanding exam. After successfully passing the exam, the certificate shall be provided to the GPSD designated Security Specialist.

4.5 ISOO Reporting Requirements

4.5.1 The OPS is responsible for coordinating the completion and submission of Agency security classification management data to the ISOO for each fiscal year.

DIRECTIVE NO. GPR 1600.2A Page 13 of 18

4.5.2 The CCPS shall provide GSFC specific information to OPS for completing the following annual reports from ISOO in accordance with Exec. Order No. 13526:

a. Agency Security Classification Cost Estimate.

b. Agency Annual Self-Inspection Program Data.

c. Agency Security Classification Management Program Data Report.

4.5.3 In accordance with Section 5.5 of Exec. Order No. 13526, the OPS will report to ISOO any violation or sanction that is prohibited by the Executive Order.

DIRECTIVE NO. GPR 1600.2A Page 14 of 18

Appendix A-Definitions

A.1 Access - The ability or opportunity to gain knowledge of classified information.

A.2 Automatic declassification - The declassification of information based solely upon the occurrence of a specific date or event as determined by the original classification authority or the expiration of a maximum timeframe for duration of classification established under Exec. Order No. 13526.

A.3 Center Chief of Protective Services Security (CCPS) - The senior Center security official responsible for technical management of the Center security program.

A.4 Classification - The act or process by which information is determined to be classified information.

A.5 Classification Guide - A documentary form of classification guidance issued by an original classification authority that identifies the elements of information regarding a specific subject that must be classified and establishes the level and duration of classification for each such element.

A.6 Classified Material - Any physical object on which is recorded or in which is embodied CNSI that must be discerned by the study, analysis, observation, or other use of the object itself.

A.7 Classified National Security Information (CNSI) - Information that must be protected against unauthorized disclosure in accordance with Exec. Order No. 13526, "Classified National Security

Information," as amended and is marked to indicate its classified status when in documentary form.

A8 Classified Visit Request - Employees attending classified meetings (conference, seminar, exhibit, and symposium) occurring at another site require a Classified Visit Request for the classification level of the meeting.

A.9 Collateral Classified – Includes all CNSI, excluding information in the SCI or SAP information category.

A.10 Communications Security (COMSEC) - Measures and controls taken to deny unauthorized individuals information derived from telecommunications and to ensure the authenticity of such telecommunications. Communications security includes crypto security, transmission security, emission security, and physical security of COMSEC material.

A.11 Compromise - The improper or unauthorized disclosure of or access to classified information.

A.12 Contractor - For the purpose of this GPR, any non-NASA entity or individual working on a

NASA installation or accessing NASA information technology.

DIRECTIVE NO. GPR 1600.2A Page 15 of 18

A.13 Declassification - The authorized change in the status of information from classified information to unclassified information.

A.14 Declassification Authority (DCA) - An official delegated declassification authority in writing by the Agency head or the SAO.

A.15 Facility Clearance Level (FCL) - Is an administrative determination that a facility and contractor personnel are eligible for access to classified information or award of a classified contract.

A.16 Information Security Oversight Office (ISOO) - Office established under the Executive Office of the President tasked with policy development and oversight of Federal agency compliance with national-level policy for management of CNSI.

A.17 NASA Employee - NASA civil service personnel.

A.18 National Security – Includes the national defense or foreign relations of the United States.

A.19 National Security Position - Positions that have the potential to cause damage to the national security. These positions require access to classified information and are designated by the level of potential damage to the national security.

A.20 Non-disclosure Agreement - Standard Form (SF) 312 is a non-disclosure agreement required under Exec. Order No. 13292 to be signed by employees of the U.S. Federal Government or one of its contractors when they are granted a security clearance for access to classified information.

The form is issued by the ISOO of the NARA and its title is "Classified Information

Nondisclosure Agreement." SF 312 prohibits confirming or repeating classified information to unauthorized individuals, even if that information is already leaked. The SF 312 replaces the earlier forms SF 189 or the SF 189-A. Enforcement of SF 312 is limited to civil actions to enjoin disclosure or seek monetary damages and administrative sanctions, "including reprimand, suspension, demotion, or removal, in addition to the likely loss of the security clearance."

A.21 Original Classification - An initial determination that information requires, in the interest of the national security, protection against unauthorized disclosure.

A.22 Original Classification Authority (OCA) - An individual authorized in writing, either by the

President, by agency heads, or other senior Government officials designated by the President, to classify information in the first instance.

A.23 Safeguarding – The measures and controls prescribed to protect classified information.

DIRECTIVE NO. GPR 1600.2A Page 16 of 18

A.24 Security Classification Guide - The written direction issued or approved by a Top Secret/OCA that identifies the information or material to be protected from unauthorized disclosure and specifies the level and duration of classification assigned or assignable to such information or material.

A.25 Security Clearance - A designation identifying an individual's highest level of allowable access to classified information based upon a positive adjudication that the individual does not pose a risk to national security.

A.26 Senior Agency Official (SAO) - The official designated by the agency head under section 5.4 (d) of Exec. Order No. 13526 to direct and administer the agency's program under which information is classified, safeguarded, and declassified.

A.27 Sensitive Compartmented Information (SCI) - Classification level denoting information, generally intelligence related, requiring security clearances and physical/procedural security measures above those established for collateral classified information or SAP information.

A.28 Unauthorized Disclosure (Exec. Order No. 13526) - A communication or physical transfer of classified information to a recipient who does not have the appropriate credentials for access.

DIRECTIVE NO. GPR 1600.2A Page 17 of 18

Appendix B - Acronyms

CAGE CODE Commercial and Government Entity Code

CCPS Center Chief of Protective Services

CMCO Classified Material Control Officer

COMSEC Communications Security

DCA Declassification Authority

DCP Document Control Point

DSS Defense Security Service

EO Executive Order

FCL Facility Clearance

FSO Facility Security Officer

GCA Government Contracting Agency

GPSD GSFC Protective Services Division

GSFC Goddard Space Flight Center

GSA General Services Administration

HSPD Homeland Security Presidential Directive

ICD Intelligence Community Directive

ISOO Information Security Oversight Office

NISPOM National Industrial Security Program Operating Manuel

NPD NASA Policy Directive

NPR NASA Procedural Requirement

NSD National Security Directive

OCA Original Classification Authority

OPS Office of Protective Services

SAO Senior Agency Official

SAP Special Access Program

SCI Sensitive Compartmented Information

SCIF Sensitive Compartmented Information Facility

SCP Security Control Point

SF Standard Form

SSO Special Security Officer

TSCO Top Secret Control Officer

DIRECTIVE NO. GPR 1600.2A Page 18 of 18

CHANGE HISTORY LOG

Revision Effective Date Description of Changes

Baseline 12/11/13 Initial Release

A 06/29/18

Administrative Revisions to include:

1. Updated P.4 with new reference documents.

2. Updated Applicable Documents and Forms in P.4.

3. Updated P.8 with correct NRRS references.

4. Clarified marking requirements in Section 2.1.

5. Clarified CNSI Security Violations in Section 2.10.

6. Clarified Classified Visit requirements in Section 3.2.

7. Clarified ISOO reporting requirements in Section 4.5.

File details come from the government source that posted it. Updated .