About this file

This directive establishes the Goddard Space Flight Center's identity and credential management security policies and procedures. It requires all GSFC personnel, facilities, activities, contractors, tenants, visitors, and others with access to GSFC facilities or resources to comply with its guidelines. It defines roles and responsibilities for issuing PIV and non-PIV credentials, outlines processes for issuing, returning, deactivating, and destroying credentials, and provides details on foreign national access credentialing and escort requirements. Access requests for foreign nationals must be submitted through the Identity Management and Account Exchange system along with required documentation and assigned access control plans.

View the file

Other files for this federal contract opportunity

Other files attached to NASA Sounding Rocket Operations Contract (NSROC) IV - FINAL Request for Proposal, eLibrary, newest first.
File Type Posted
SR Risk Management Plan Official Release - 2010-04-15 signed and scanned.PDF PDF
NSROC III Selection Statement.pdf PDF
SRPO Annual Report 2018.pdf PDF
Wallops Range Users Handbook.pdf PDF
Rocket Report 3rd quarter 2020.pdf PDF
Rocket Report 2nd quarter 2020.pdf PDF
SRPO Annual Report 2020.pdf PDF
SRPO Missions Bluebook September 2021.pdf PDF
SRWG_Findings_Jan_2020.pdf PDF
SRWG_Findings_Feb_2019.pdf PDF
NPR 9501.2.pdf PDF
NPR 7120.8.pdf PDF
NPR 8621.1.pdf PDF
800-PG-8710.3.1 Updated WFF Flex Hose Handling.pdf PDF
NPR 1800.1 Updated.pdf PDF
800-PG-8715.1.1E Danger Area Control and Roadblocks for Hazardous Operations.pdf PDF
GPR 1860.1.pdf PDF
GPR 1600.1.pdf PDF
800-PG-7150.4.1 Updated Software SMA Process.pdf PDF
GPR 8710.3.pdf PDF
GPR 1860.3.pdf PDF
GPR 1700.5.pdf PDF
GPR 8830.1.pdf PDF
GPR 8719.1.pdf PDF
800-PG-8715.1.1E Unmanned Roadblocks_ Danger Area Control for Hazardous Operations April 2021_FINAL_ GDMS (1).pdf PDF
GPR 8500.4.pdf PDF
NPD 4500.1.pdf PDF
GPR 6730.1.pdf PDF
GPR 4520.4.pdf PDF
GPR 1860.4.pdf PDF
NPR 2810.1.pdf PDF
810-PG-7120.1.1E Review of NSROC Sounding Rocket Mission Work Orders.pdf PDF
GPR 1820.1.pdf PDF
GPR 4520.2.pdf PDF
NPR 9710.1.pdf PDF
NPR 1600.3.pdf PDF
NPD 1600.3.pdf PDF
GPR 8800.2 Admin Ext Local Exhaust Ventilation.pdf PDF
NPD 9501.1.pdf PDF
NPD 1600.9 Updated.pdf PDF
NPD 2810.1.pdf PDF
NPD 2530.1.pdf PDF
NPD 1600.2 Updated.pdf PDF
800-PG-8710.0.1D Mission Planning for Fire Alarm Contingencies.pdf PDF
GPR 1700.1.pdf PDF
NPR 1600.2.pdf PDF
GPR 8715.10.pdf PDF
NPD 8610.6.pdf PDF
NPD 1040.4.pdf PDF
Vehicle Launcher and Performance Info.pdf PDF
Show all 50

NASA Sounding Rocket Operations Contract (NSROC) IV - FINAL Request for Proposal, eLibrary has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DIRECTIVE NO. GPR 1600.4A APPROVED BY Signature: Original Signed By

EFFECTIVE DATE: June 22, 2018 NAME: Raymond J. Rubilotta

EXPIRATION DATE: June 22, 2023 TITLE: Director, Management Operations Directorate

CHECK THE GSFC DIRECTIVES MANAGEMENT SYSTEM AT

http://gdms.gsfc.nasa.gov TO VERIFY THAT THIS IS THE CORRECT VERSION PRIOR TO USE.

08/16

Goddard Procedural Requirements (GPR)

CURRENT

COMPLIANCE IS MANDATORY

Responsible Office: Code 240/GSFC Protective Services Division

Title: GSFC Identity and Credential Management

PREFACE

P.1 PURPOSE

a. This Goddard Space Flight Center Procedural Requirement (GPR) establishes the Center-wide

Identity and Credential Management security policies and procedures for the Goddard Space Flight

Center (GSFC) and its component facilities for identifying individuals and controlling their eligibility for access to resources (e.g. facilities and logical systems) by associating user rights and restrictions with the established identity as required in NASA Procedural Requirements (NPR)

1600.4A, Identity and Credential Management.

b. This GPR establishes security program standards and requirements necessary to achieve Center-wide consistency and uniformity, while allowing reasonable flexibility in implementing risk management principles, where appropriate, at all GSFC facilities. Individuals and organizations security responsibilities are also identified within the document.

c. Access management services in support of asset management, community management, permission management, and authentication and authorization services for both physical and logical (IT) access are outside the scope of this GPR. Access management policies and procedures are identified within

NPR 2841.1, Identity, Credential, and Access Management.

P.2 APPLICABILITY

a. This GPR applies to all GSFC personnel, facilities, and activities, including all permanent and temporary sites, and to all GSFC contractors, tenant organizations, tenant contractors, grantees, clubs, visitors, vendors, guests, and/or anyone else doing business or physically present on the GSFC or its component facilities, in accordance with applicable law. This GPR applies to contractors, grant recipients, or parties to agreements only to the extent specified or referenced in the appropriate contracts, grants, or agreements. Exceptions or special provisions for specific sites are identified in the body of the document.

b. In this GPR, all document citations are assumed the latest version unless otherwise noted.

http://gdms.gsfc.nasa.gov/

DIRECTIVE NO. GPR 1600.4A Page 2 of 15

EFFECTIVE DATE: June 22, 2018

EXPIRATION DATE: June 22, 2023

c. In this GPR, all mandatory actions (i.e., requirements) are denoted by statements containing the term

“shall.” The terms “may” or “can” denote discretionary privilege or permission; “should” denotes a good practice and is recommended but not required; “will” denotes expected outcome; and “are/is” denotes descriptive material.

P.3 AUTHORITY

a. National and Commercial Space Programs, 51 U.S.C. § 20132, Public Law 111-314, 124 Stat. 3328

(2010).

b. NPR 1600.4A, Identity and Credential Management.

c. NAII 1600.4A, Foreign National Access Management (FNAM) Operations Manual

P.4 APPLICABLE DOCUMENTS AND FORMS

a. NPD 1382.17, NASA Privacy Policy.

b. NPD 1440.6, NASA Records Management.

c. NPR 1382.1, NASA Privacy Procedural Requirements.

d. NPR 1441.1, NASA Records Retention Schedules.

e. NPR 1600.1, Security Program Procedural Requirement.

f. NPR 1600.4A, Identity and Credential Management.

g. NAII 1600.4A, Foreign National Access Management (FNAM) Operations Manual

h. NPR 2841.1, Identity, Credential, and Access Management Services.

i. NASA IT-HBK2841-003, Identity, Credential, and Access Management (ICAM) Services.

j. Homeland Security Presidential Directive 12 (HSPD-12), April 27, 2004.

k. Federal Information Processing Standards Publication (FIPS) 201-2, Personal Identity

Verification (PIV) of Federal Employees and Contractors.

l. Office of Management and Budget (OMB) Memo M-05-24, August 5, 2005, "Implementation of

Homeland Security Presidential Directive (HSPD)-12, Policy for a Common Identification.

m. Office of Personnel Management (OPM) Federal Investigations Notice No. 10-05, May 17, 2010, "Reminder to Agencies of the Standards for Issuing Credentials under HSPD-12."

Standards for Federal Employees and Contractors."

n. Office of Personnel Management Electronic Questionnaire for Investigation Processing (e-QIP)

System.

o. GSFC Locator and Information Services Tracking System (LISTS) form (GSFC Form 24-27).

P.5 CANCELLATION

GPR 1600.4, GSFC Identity and Credential Management, December 4, 2013.

P.6 SAFETY

DIRECTIVE NO. GPR 1600.4A Page 3 of 15

None

P.7 TRAINING

All GSFC civil service employees, contractors, tenants and others shall take Personal Identity

Verification (PIV) Training for the authorization level within Identity and Credential Management

Exchange System (IdMAX), available from the System for Administration, Training, and Educational

Resources for NASA (SATERN);

P.8 RECORDS

The table below lists both the records required by this GPR and those required by NPR 1600.4. See

P.12 for identification of acronyms. The term “appropriate” in the Record Custodian column means the location appropriate for a given GSFC site, e.g., the Greenbelt Protective Services Division Office as opposed to the Wallops Protective Services Division Office, the Goddard Institute for Space Studies

(GISS), White Sands Complex (WSC) and the Independent Verification and Validation (IV&V)

Facility.

No Record Title Record Custodian Retention

1 Foreign National (FN) Visitors

Files (i.e., copies of passports, visas, permanent resident cards, visit requests, etc.)

Appropriate GPSD

International Visit

Coordinator

*NRRS 1370/35 Destroy 2 years after termination of visit.

2 Personnel Security Clearance

Files documenting processing of investigations on Federal employees or applicants, or others who perform work on a

Federal agency under contract that requires access to

Government facilities or sensitive data.

GPSD Personnel Security

Office

*NRRS 1610/103A Destroy upon notification of death or not later than 5 years after separation or transfer of employee or no later than 5 years after contract relationship expires, whichever is applicable.

3 Personnel Security Clearance

Files of investigative reports and related papers furnished to agencies by investigative organizations for use in making security/suitability determinations.

GPSD Personnel Security

Office

*NRRS 1610/103B Destroy in accordance with the investigating agency instructions.

4 Personnel Security Clearance

Files Index to the Personnel

Security Case Files.

GPSD Personnel Security

Office

*NRRS 1610/103C Destroy with related case file.

http://gdms.gsfc.nasa.gov/ https://satern.nasa.gov/ https://satern.nasa.gov/

DIRECTIVE NO. GPR 1600.4A Page 4 of 15

5 Personnel Security Clearance

Status Files Lists, or Rosters maintained in security units showing the current security clearance status of individuals.

GPSD Personnel Security

Office

*NRRS 1610/103D Destroy when superseded or obsolete.

6 GSFC LISTS database – NASA

51 LIST (GSFC Form 24-27)

GPSD LISTS Manager *NRRS 1620/104 Records are retained for varying periods of time, in compliance with NPR 1441.1 and the

Privacy Act System Notice. Contact the

Center Records Manager.

7 Identification Credentials Files, including cards, Credentials, parking permits, photographs, agency permits to operate motor vehicles, and property, and visitor passes, and any other similar identification credentials.

Appropriate GPSD Office *NRRS 1620/105A Destroy credentials

3 months after return to issuing office.

8 Identification Credentials Files

Receipts, Indices, Listings, and

Accountable Records.

Appropriate GPSD Office *NRRS 1620/105B Destroy after all listed credentials are accounted for.

9 Logs, Registers, and Control

Files – Visitors

Appropriate GPSD Office *NRRS 1680/114A Destroy 5 years after final entry or date of document, as appropriate.

10 Foreign National Files –

Personal Identification or passport photographs

Appropriate GPSD

International Visits

Coordinator

*NRRS 1680-2630/115 Return original to requester, destroy when 5 years old or when superseded or obsolete, whichever is later.

*NRRS – NASA Records Retention Schedules (NPR 1441.1A)

P.9 MEASUREMENT/VERIFICATION

To determine compliance with this GSFC directive, the Protective Services Division (PSD) shall provide assessments/audits of the application of this policy requirement. This will consist of periodic reporting, including information collected for the satisfaction of OMB. The specific metrics utilized will conform to those described in Federal Identity, Credential, and Access Management (FICAM) Roadmap and

Implementation Guidance.

PROCEDURES

CHAPTER 1. INTRODUCTION

1.1 Overview

1.1.1 The policies and procedures identified within this document define the approved processes for http://nodis3.gsfc.nasa.gov/library/lib_docs.cfm?range=1___

DIRECTIVE NO. GPR 1600.4A Page 5 of 15

NASA to manage personal identities and the issuance of NASA Personal Identity Verification (PIV) credentials. This GPR also establishes the policy for the management of other types of NASA credentials, visitor Credentials, and Center-specific Credentials.

1.1.2 The terms "PIV Credential" and "non-PIV Credential" are used frequently in this document. The term "PIV Credential" refers to the credential which is issued to civil service and contractor employees who need physical or logical access to NASA facility and IT systems for 180 days or more. NASA's procedures for issuing PIV Credentials must conform to HSPD-12. All other credentials issued by

NASA are referred to as "Non-PIV" credentials. Non-PIV credentials include such things as: Visitor

Credentials, Center-specific Issued Credentials to include Agency Smart Badges (ASB) and Local

Badges, RSA tokens, proximity cards, etc.

1.1.3 Identity management and credential management allows the identity of an individual to be verified in the digital realm, so that his or her identity may be trusted to conduct business and utilize information systems. Even low-risk employees may possess capabilities for unintended access despite physical and logical safeguards that can give them unprecedented access to critical information and systems.

1.2 Waivers and Exceptions

1.2.1 Requests for Waivers or Exceptions to this GPR shall be requested in accordance with NPR

1600.4, Chapter 1.

1.3 Violations of Security Requirements

1.3.1 Anyone who willfully violates, attempts to violate, or conspires to violate any regulation or order involving the NASA personnel security program is subject to disciplinary action up to and including termination of employment and/or possible prosecution under 18 U.S.C. §799, that provides fines or imprisonment for not more than 1 year, or both.

CHAPTER 2. RESPONSIBILITIES

2.1.1 Certain individuals and organizations have specific responsibilities for security at GSFC. NPR

1600.4A identifies these responsibilities for the following:

a. Center Director

b. Center Chief of Protective Services (CCPS)

c. Chief Information Officer

d. Program Managers, Line Managers, and Supervisors

e. Individual Employees and Contractors

DIRECTIVE NO. GPR 1600.4A Page 6 of 15

2.1.2 The GSFC PIV Issuing Facility (PIF) Manager shall oversee the identity management and credential management program implementation at the Center and will document the operations and procedures of the Center's identity management as identified in NPR 1600.4A, Section 2.3.

2.1.2.1 The Identity Management and Credential Management Processes are designed to conform to the system-based model for identity proofing, registration, and issuance process that is described in

NIST FIPS 201-2.

2.1.3 GSFC PSD badging personnel shall apply the credentialing processes and standards as provided in the OPM Memorandum of July 31, 2008, Final Credentialing Standards for Issuing Personal Identity

Verification Cards under HSPD-12 to non-U.S. nationals who work as employees or contractor employees, including those who require long-term logical or physical access to NASA facilities. For individuals who are non-U.S. nationals in the United States or a U.S. territory for 3 years or more, a background investigation (i.e. NACI or equivalent) will be initiated after employment authorization is appropriately verified.

2.1.4. Identity vetting requirements established by NPR 1600.4A shall not preclude GPSD from enacting additional requirements regarding access to the Center, buildings, or other secured areas.

Additional vetting requirements for foreign nationals accessing information technology are documented within an Access Control Plan (ACP) in IdMAX.

CHAPTER 3. PIV ROLES

3.1.1 Per the requirements specified in FIPS 201-2, the principle of separation of duties shall be enforced to ensure that no single individual has the capability to issue a PIV credential without the participation of at least one other authorized person.

3.1.2 Individuals and entities assigned to the PIV enrollment official, PIV authorizer, PIV investigation reviewer, PIV issuance official, and the PIV requestor and PIV sponsor roles shall complete training that is specific to their duties prior to being allowed to perform in their function.

CHAPTER 4. ISSUANCE OF PIV AND NON-PIV ACCESS CREDENTIALS

4.1 PIV Access Credentials

4.1.1 NASA uses both PIV credentials and non-PIV credentials to allow physical only, logical only, and both physical and logical access to resources at NASA.

4.1.2 Persons issued active NASA PIV badges shall not be issued non-PIV credentials. An ASB badge may be temporarily issued for lost or stolen PIV badges while awaiting issuance of a new replacement PIV badge. Prior to issuance of the temporary ASB, the original PIV badge must be disabled in accordance Section 4.3 of the GPR.

DIRECTIVE NO. GPR 1600.4A Page 7 of 15

4.1.3 The GPSD shall issue both PIV credentials and non-PIV credentials as identified and required in

NPR 1600.4A and the IT-HBK-2841-003.

4.1.4 All employees and contractors receiving NASA PIV badge must complete a GSFC Locator and

Information Services Tracking System (LISTS) form (GSFC Form 24-27) and submit it to GPSD before a PIV badge will be issued. The information on the LISTS form will be utilized to provide appropriate

Center resources.

4.2 Non-PIV Access Credentials and Temporary Credentials

4.2.1 NASA Non-PIV Center-specific ASB, local or temporary credentials shall be issued to accommodate unique situations of the Center not otherwise accommodated by NASA PIV credentials and NASA visitor Credentials. At the discretion of the CCPS, Non-PIV credentials may be issued up to

3 years. All NASA Center-specific Credential templates will have the approval of the Agency Identity

Management Official prior to their creation and utilization.

4.2.2 The GPSD Center-specific credential shall be issued upon completion of a favorable adjudication of an NCIC name query. This is a minimum requirement, and additional security measures may be employed at the discretion of the CCPS.

4.2.3 NASA Visitor credentials are NASA non-PIV Credentials which allow only physical access to the issuing NASA Center. Requests for Visitor access shall be requested in the Management

Operations Services and Information (MOSI) system Visitor Badge service at least 48 hours (2 business days) in advance of the required visit for a maximum of 29 calendar days in a year. The CCPS determines security measures for issuance of Visitor credentials to include all Escorting requirements.

Foreign Nationals Visitor requests are entered within IdMAX in accordance with Chapter 6 of this GPR.

4.2.4 Visitors not approved in MOSI require escorting at all times. Escorts shall be NASA PIV or ASB credentialed.

4.2.5 Meetings or events where more than 20 visitors are attending shall be requested in the MOSI system Special Event Request service and should not be entered under the Visitor Badge service as visitors. Foreign nationals must also be processed in IdMAX in accordance with Chapter 6. The PSD

Special Event Coordinator will coordinate special event access.

4.3 Lost or Stolen Credentials

4.3.1 Lost and stolen credentials shall be reported to the GSFC Badging Office within 18 hours of discovery of the loss/theft. The employee must complete a lost/stolen report prior to a new PIV card or ASB being issued.

4.3.2 The PIV credential holder shall, within five business days of reporting the loss/theft, appear in person at the badging office to verify the loss/theft of the PIV/ASB credential and begin the

PIV/ASB credential reissuance process.

DIRECTIVE NO. GPR 1600.4A Page 8 of 15

4.3.3 The lost/stolen PIV/ASB credentials will be revoked and/or disabled, cancelling all certificates and access privileges of that card. The identity of the PIV/ASB credential holder itself will remain active, as only the card is disabled.

4.3.4 The PIV/ASB credential holder shall be required to undergo a PIV/ASB credential re-issuance, in accordance with NPR 1600.4A and IT-HBK2841-003 PIV/ASB Credential Re-issuance requirements. The PIV credential holder will be issued a temporary ASB assess credentials until the replacement PIV credential is issued. The ASB credential holder will be issued a new ASB badge.

4.4 Acceptance of PIV and CAC Badges from other Federal Agencies

4.4.1 The GPSD shall accept PIV badges from NOAA employees and contractors on official government business for physical access to all GSFC facilities. The CCPS may require the issuance of non-PIV credentials to NOAA employees and contractors to facilitate access to GSFC controlled or restricted areas. A NASA issued non-PIV credential is required to perform any escorts.

4.4.2 The GPSD shall accept Common Access Card (CAC) badges from Department of Defense

(DoD) employees and contractors on official government business for physical access to the WFF.

The CCPS may require the issuance of non-PIV credentials to DoD employees and contractors to facilitate access to WFF controlled or restricted areas. A NASA issued non-PIV credential is required to perform any escorts.

4.4.3 The GSPD shall require all foreign national NOAA and DoD employees and contractors possessing PIV or CAC badges to process through IdMAX for access to the Center. Escorting is not authorized.

CHAPTER 5. ACCESS CREDENTIALS RETURN, DEACTIVATION AND

DESTRUCTION

5.1 Access Credentials Return

5.1.1 PIV credentials, GSFC Center-Specific Non-PIV credentials and GSFC Visitor credentials shall be returned to GSFC badging office once an individual's affiliation with NASA GSFC has ended. Credentials should be returned no later than the last day of association with NASA GSFC.

5.1.2 The GSFC PSD shall be responsible for recording receipt of the PIV and ASB credentials that are returned and properly storing the PIV/ASB credentials until destruction. Credentials are not allowed to be kept as souvenirs. The responsibility for PIV/ASB credential return is:

a. OHCM for NASA civil servant (PIV only);

b. Contract program manager for contractors; or

c. Grant administrator for grantees.

DIRECTIVE NO. GPR 1600.4A Page 9 of 15

5.2 Access Credential Deactivation

5.2 .1 NASA PIV credentials and associated identity will be deactivated within 18 hours of notification of the need for PIV credential termination.

5.2.2 GSFC Non-PIV ASB credentials or Temporary credentials returned to the badging office shall have all data, certificates, and access privileges invalidated, revoked, and/or disabled. Non-

PIV ASB credentials that are terminated will have their status set to "terminated" and a reason will be supplied for the termination.

5.3 Access Credential Destruction

5.3.1 Credentials meeting the following criteria shall be destroyed:

a. Expired credentials;

b. Credentials discovered or located after being declared lost or stolen;

c. Credentials that are damaged; and

d. Terminated credentials.

5.3.2 Terminated PIV/ASB credentials will be destroyed following the requirements in NPR

1600.4A.

5.3.3 Credentials shall be thoroughly destroyed using heavy-duty cross cut shredders that are capable of smart card destruction, by depositing into a burn bag for burning, or by more rigorous methods.

CHAPTER 6. FOREIGN NATIONAL ACCESS CREDENTIALING

6.1.1 Requests for access by foreign nationals to NASA physical and/or IT resources for any purpose other than an appropriately authorized tour of facilities that is, or would normally be, conducted for the general public shall be entered into IdMAX. This includes all foreign national adults and children 12 years of age and older.

6.1.2 Requests for foreign national access shall be entered in IdMAX. These requests must be submitted in their entirety within IdMAX for IVC consideration, with all required identity documentation uploaded and Access Control Plan(s) (ACP) assigned. Incomplete submissions will not be processed and will be returned to the requestor by the IVC.

6.1.3 Requests for access for foreign nationals from non-designated countries must be submitted at least 6 business days prior to any required access. Requests for foreign nationals born in, or with current or previous citizenship from designated countries must be submitted at least 20 business days prior to required access. Larger events where more than 3 foreign nationals are attending require additional coordination and processing time by the IVC.

DIRECTIVE NO. GPR 1600.4A Page 10 of 15

6.1.4 The GSFC IVC will directly receive and review all requests from, or on behalf of, foreign nationals for access to its buildings, installations, facilities, or IT resources. The IVC will approve the requests for foreign nationals from non-designated countries after obtaining appropriate Center approvals.

6.1.5 Requests for foreign nationals from designated countries will be forwarded to and approved by Headquarters' Office of International and Interagency Relations (OIIR) before final approval by the Center IVC on behalf of the CCPS.

6.1.6 The IVC shall determine escort requirements for foreign nationals from a non-designated country and will notify the foreign national's sponsor within IdMAX the terms and conditions of the on-site assignment which include, but are not limited to, the security and export control provisos.

6.1.7 The sponsor shall ensure that the foreign national adheres to the access requirements as documented in IdMAX and the ACP throughout the foreign national's on-site assignment.

6.1.8 Foreign national "limited privileged" access to IT systems shall be allowed only if the foreign national is involved in a program under an International Space Act Agreement (ISAA) and the foreign national's ACP includes that the foreign national is involved in a program under an ISAA and the foreign national's ACP includes that access. The sponsor will verify that an ISAA and ACP are in place and has accountability for ensuring the security of IT system data being accessed by the foreign national.

CHAPTER 7. ESCORTING

7.1.1 Escorts are responsible for providing continuous physical supervision of those persons without sufficient access privileges, as determined by a risk-based determination by the CCPS or the IVC.

7.1.2 Escorts of foreign nationals shall acknowledge an understanding and acceptance of the Access

Control Plan (ACP) and escort requirements associated with each foreign national visitor, prior to the beginning of the visit.

7.1.3 Foreign nationals born in, or with current or previous citizenship from designated countries shall be escorted at all times by NASA PIV credentialed persons.

7.1.4 Escorts of foreign nationals are required to maintain active certified escort status by completing annual Escort training in SATERN and requesting Escort eligibility status through NASA Access

Management System (NAMS). Escorts of foreign nationals are issued an additional Agency Escort badge that they must display when performing escorts that identifies their certified status as an escort of foreign nationals.

7.1.5 All escorts of foreign nationals from designated countries will complete an in-person briefing with the Counterintelligence Special Agent (CISA) prior to the visit and an in-person debriefing with the

CISA following the visit.

DIRECTIVE NO. GPR 1600.4A Page 11 of 15

7.1.6 The pre-visit CISA briefings and Escort training shall be completed by the escort and documented in IdMAX prior to any escorting of the foreign national.

Appendix A – Definitions

A.1 Access - The ability to obtain and use information and related information processing services;

and/or enter specific physical facilities (e.g., Federal buildings, military establishments, and border crossing entrances).

A.2 Access Control - The process of granting or denying specific access requests.

A.3 Access Control Plan (ACP) – For a program, project, or foreign national, the assets to which that foreign national may request access. For additional information, refer to NPR 2190.1, NASA

Export Control Program. Formerly known as a Technology Transfer Control Plan

(TTCP)/Security Technology Transfer Control Plan (STTCP).

A.4 Adjudication - A fair and logical Agency determination, based upon established adjudicative guidelines and sufficient investigative information, as to whether or not an individual's access to classified information, suitability for employment with the U.S. Government, or access to NASA facilities, information, or IT resources is in the best interest of national security or efficiency of the Government.

A.5 Agency Smart Badge - (Synonymous with ASB Card) Non-PIV local credential issued with an individual's unique vetted identity information encoded and physically printed on the exterior and with embedded integrated circuits which can process data. Issued to persons needing access that do not meet PIV requirements for issuance.

A.6 Center Chief of Protective Services (CCPS) - The senior Center security official who is responsible for management of the Center security program.

A.7 Contractor - For the purpose of this NPR, any non-NASA entity or individual working on a

NASA installation or accessing NASA IT for an employer who is subject to Executive Order

11246.

A.8 Credential - A physical/tangible or electronic object through which data elements associated with an individual are bound to the individual's identity. Credentials are presented to access control systems in order to gain access to assets. The term “credential” and “badge” are interchangeable within this document.

A.9 Escort - The management of a visitor's movements and/or accesses implemented through the constant presence and monitoring of the visitor by appropriately designated and properly trained

DIRECTIVE NO. GPR 1600.4A Page 12 of 15

U.S. Government or approved contractor and tenant personnel. Training shall include the purpose of the visit, where the individual may access the Center, where the individual may go, whom the individual is to meet, authorized topics of discussion, etc.

A.10 Foreign National - A synonym for "foreign person" (see definition of "Foreign Person" below).

A.11 Foreign Person - Any person who is not a U.S. citizen and who is not a lawful permanent resident as defined by 8 U.S.C. 1101(a) (20) or any person who is not a protected individual as defined by

8 U.S.C. 1324b(a) (3). This also means any foreign corporation, business association, partnership, trust, society or any other entity or group that is not incorporated or organized to do business in the U.S., as well as any international organizations, any foreign government, and any agency or subdivision of foreign governments (e.g., diplomatic missions).

A.12 I-9 document - One of the documents listed on the OMB Form I-9, Employment Eligibility

Verification.

A.13 Identity - The set of attributes that uniquely identify an individual for the purpose of gaining logical and physical access to protected resources and identification in electronic transactions.

A.14 Identity Verification - The process of confirming or denying that a claimed identity is correct by comparing the credentials (something you know, something you have, something you are) of a person requesting access with those previously proven and stored in the credential or system and associated with the identity being claimed.

A.15 Identity Vetting - A review of information about a person for possible approval or acceptance. In this document, a vetted person has been reviewed to determine eligibility for access to NASA physical and/or logical assets.

A.16 International Partners - Foreign entities or persons who are involved in a particular international program or project under an International Space Act Agreement (ISAA).

A.17 Lawful Permanent Resident (LPR) - Replaces the term "Permanent Resident Alien (PRA)" - A non-U.S. citizen, legally permitted to reside and work within the U.S. and issued the Resident

Alien Identification (Green Card). Afforded all the rights and privileges of a U.S. citizen with the exception of voting, holding public office, employment in the federal sector (except for specific needs or under temporary appointments per 5 CFR, Part 7, Section 7.4), and access to classified national security information (CSNI). (NOTE: LPR's are not prohibited from accessing export controlled commodities, but will still have a work-related "need-to-know" and are still considered foreign nationals under immigration laws.

A.18 Logical Access - Access to information records, data, information technology systems and applications.

DIRECTIVE NO. GPR 1600.4A Page 13 of 15

A.19 Non-designated Country - A country with which the United States has favorable diplomatic relations.

A.20 Permanent Resident Alien (PRA) - A non-U.S. citizen legally permitted to reside and work within the United States and issued the Resident Alien Identification (Green Card). Afforded all the rights and privileges of a U.S. citizen with the exception of voting, holding public office, employment in the Federal sector (except for specific needs or under temporary appointments per

5 CFR, Part 7, Section 7.4), and access to CNSI.

(NOTE: PRA's are not prohibited from accessing export controlled commodities but will still have a work related "need-to-know" and are still considered Foreign nationals under immigration laws.)

A.21 Revocation - The removal of an individual's eligibility to access physical or logical assets based upon unfavorable adjudication that continued access poses a risk to the Agency.

A.22 Smartcard - (Synonymous with PIV Card) Credential issued with an individual's unique vetted identity information encoded and physically printed on the exterior and with embedded integrated circuits which can process data.

A.23 Temporary Workers - A person (i.e., construction worker, club member, childcare drop off/pickup, delivery driver, retiree, Center transit, and others approved by Center Chiefs of

Protective Services/Security) who requires intermittent access for 180 days or more.

A.24 U.S. Person (non-U.S. Citizen) - For the purpose of implementing protection and accountability under the ITAR; a person who is a LPR as defined by 8 U.S.C. 1101(a)(20) or who is a protected individual as defined by 8 U.S.C. 1324b(a)(3). It also means any corporation, business association, partnership, society, trust, or any other entity, organization or group that is incorporated to do business in the U.S. It also includes any governmental (Federal, state, or local) entity. It does not include any foreign person as defined in this chapter.

A.25 Visitor - Any person who needs physical access to a NASA facility for less than 30 days.

A.26 Waiver - The approved continuance of a condition authorized by the AA for Protective Services that varies from a requirement and implements risk management on the designated vulnerability.

DIRECTIVE NO. GPR 1600.4A Page 14 of 15

Appendix B - Acronyms

AA Associate Administrator

ACP Access Control Plan

ASB Agency Smart Badge

CAC Common Access Card

CCPS Center Chief of Protective Services

CHUID Cardholder Unique Identifier

CPR Card Production Request

DoD Department of Defense

EPACS Enterprise Physical Access Control System

FICAM Federal Identity, Credential, and Access Management

FIPS Federal Information Processing Standards

FISMA Federal Information Systems Management Act

HSPD Homeland Security Presidential Directive

ICAM Identity, Credential, and Access Management

IdMAX Identity Management and Account Exchange

IDMS Identity Management System

IT Information Technology

ITAR International Traffic in Arms Regulations

ITSM Information Technology Security Manager

IV&V Independent Verification and Validation

IVC International Visit Coordinator

LPR Lawful Permanent Resident

MOU Memorandum of Understanding

NAC National Agency Check

NCIC National Crime Information Center

NIST National Institutes of Standards and Technology

NPD NASA Policy Directive

NPR NASA Procedural Requirements

OCIO Office of the Chief Information Officer

OPM Office of Personnel Management

OPS Office of Protective Services

PACS Physical Access Control System

PIF PIV Issuing Facility

PII Personally Identifiable Information

PIN Personal Identification Number

PIV Personal Identity Verification

SAVE Systematic Alien Verification for Entitlements

STTCP Security/Technology Transfer Control Plan

DIRECTIVE NO. GPR 1600.4A Page 15 of 15

CHANGE HISTORY LOG

Revision Effective Date Description of Changes

Baseline 12/04/2013 Initial Release

A 06/22/2018

Revisions include:

1. Updated P.4 with new reference documents.

2. Updated P.8 with correct NRRS references.

3. Clarified Non-PIV and Temporary Credentials e requirements in Chapter 4.

4. Clarified Escorting Requirements in Chapter 7.

5. Updated Applicable Documents and Forms in P.2.

File details come from the government source that posted it. Updated .