USSOCOM_Manual_380-1.pdf
PDF 1017 KB Posted
- Attached to
- DRAFT* Special Operations Forces Global Logistics Support Services (SOF GLSS) Federal contract opportunity
- Solicitation number
- H92254-16-R-0001
- Issued by
- United States Special Operations Command
About this file
PWS App Doc 27
View the file
Other files for this federal contract opportunity
Show all 50
DRAFT* Special Operations Forces Global Logistics Support Services (SOF GLSS) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
*USSOCOM MANUAL 380-1
UNITED STATES SPECIAL OPERATIONS COMMAND
7701 Tampa Point Boulevard
MacDill Air Force Base, Florida 33621–5323
USSOCOM MANUAL
Number 380-1 16 July 2002
Security
INFORMATION SECURITY PROGRAM MANUAL
*This manual supersedes M 380-1, 1 June 1998; USSOCOM Policy Memorandums 99-29, 21 Oct 99;
00-02, 29 Jan 00; 00-12, 27 Apr 00; 01-02, 6 Feb 01; 01-10, 8 Aug 01. (See Summary of Changes on page ii.) Pages: 200
COVER
i
FOREWORD
1. Purpose. This manual prescribes policies, responsibilities, and procedures for the Information Security Program of Headquarters, US Special Operations Command (USSOCOM). This manual establishes a system for classification, downgrading, and declassification of information; sets forth policies and procedures to safeguard such information; and provides for oversight and administrative sanctions for violations.
2. Applicability. This manual applies to all Centers of Headquarters, USSOCOM, to include the Washington Office (SOWO). It does not apply to Subordinate Commands or Elements unless they wish to further supplement this document for use in their respective commands.
3. Procedures. This manual supplements DoD 5200.1-R, Information Security Program Regulation, January 1997, by inserting USSOCOM policy and requirements within the text of DoD 5200.1-R. DoD guidance is printed in light type and USSOCOM guidance is distinguished by being printed in bold type.
4. Proponent. The proponent for this manual is the Command Support Center (SOCS), Security Management Office (SOCS-SM). Users are invited to send comments and suggested improvements directly to: USSOCOM, ATTN: Deputy Security Manager SOCS-SM, 7701 Tampa Point Blvd., MacDill
AFB, FL 33621-5323.
(SOCS-SM)
USSOCOM M 380-1 16 July 2002 ii
FOR THE COMMANDER:
OFFICIAL: BRUCE E. BURDA
Colonel, U.S. Air Force Chief of Staff
LEO M. SMITH, JR.
Chief, Command Information Services Division, SOCS-SJS-S
DISTRIBUTION: A; C
SUMMARY OF CHANGES
THIS MANUAL CONTAINS EXTENSIVE REVISIONS AND SHOULD
BE READ IN ITS ENTIRETY.
iii
Table of Contents Paragraph Page
Foreword ............................................................................................................... i Table of Contents........................................................................................................ iii
CHAPTER 1. POLICY AND PROGRAM MANAGEMENT
Section I. Policy
Purpose and Scope.............................................................................. 1-100 1 Policies................................................................................................ 1-101 1
Section II. Program Management Department of Defense (DoD)............................................................ 1-200 2 DoD Components ............................................................................... 1-201 3 Senior Agency Officials...................................................................... 1-202 5
Section III. Special Types of Information Restricted Data.................................................................................... 1-300 6 Sensitive Compartmented Information (SCI) and Communications
Security (COMSEC) Information .................................................. 1-301 7 Special Access Program (SAP) Information ...................................... 1-302 7 North Atlantic Treaty Organization (NATO)and Other Foreign ........ 1-303 7
Government Information
Section IV. Exceptional Situations Military Operations............................................................................. 1-400 7 Waivers to Requirements .................................................................... 1-401 7
Section V. Corrective Actions and Sanctions General................................................................................................ 1-500 8 Sanctions............................................................................................. 1-501 8 Reporting of Incidents ........................................................................ 1-502 9
Section VI. Reports Reporting Requirements ..................................................................... 1-600 9
Section VII. Self-Inspection General................................................................................................ 1-700 10 iv
Paragraph Page
CHAPTER 2. ORIGINAL CLASSIFICATION
Section I. General Provisions
Section II. Original Classification Authority Policy.................................................................................................. 2-200 11 Delegation of Authority...................................................................... 2-201 11 Required Training............................................................................... 2-202 12
Section III. The Original Classification Process Overview ............................................................................................ 2-300 12 Eligibility for Classification ............................................................... 2-301 13 Possibility of Protection...................................................................... 2-302 13 The Decision to Classify..................................................................... 2-303 13 Level of Classification........................................................................ 2-304 14 Duration of Classification................................................................... 2-305 14 Communicating the Decision ............................................................. 2-306 14
Section IV. Special Considerations Compilation ........................................................................................ 2-400 15 The Acquisition Process ..................................................................... 2-401 15 Limitations and Prohibitions .............................................................. 2-402 15
Section V. Security Classification and/or Declassification Guides Policy.................................................................................................. 2-500 15 Content................................................................................................ 2-501 16 Approval, Distribution and Indexing.................................................. 2-502 16 Review, Revision and Cancellation .................................................... 2-503 17
Section VI. Information from Private Sources Policy.................................................................................................. 2-600 18 Classification Determination .............................................................. 2-601 18 Patent Secrecy Act.............................................................................. 2-602 19
CHAPTER 3. DERIVATIVE CLASSIFICATION
Section I. Policy and General Requirements
The Nature of the Process................................................................... 3-100 21 Authority and Responsibility.............................................................. 3-101 21 Policy.................................................................................................. 3-102 21
Section II. Procedures General................................................................................................ 3-200 22 Special Cases ...................................................................................... 3-201 22 v
Paragraph Page
CHAPTER 4. DECLASSIFICATION AND REGRADING
Section I. General
Policy .................................................................................................. 4-100 23 Declassification Systems .................................................................... 4-101 23 Declassification Authority .................................................................. 4-102 23 Exceptions........................................................................................... 4-103 24
Section II. Declassification Decisions by Original Classifiers Requirement........................................................................................ 4-200 24 The “10-Year Rule” ............................................................................ 4-201 24 Exemption from the 10 Year Rule ...................................................... 4-202 24 Extension of 10 Year Declassification Periods................................... 4-203 25
Section III. Automatic Declassification System at 25 Years The Automatic Declassification System............................................. 4-300 26 Exemption of Specific Information .................................................... 4-301 26
Section IV. Mandatory Review for Declassification General................................................................................................ 4-400 28 Responsibilities and Procedures ......................................................... 4-401 28
Section V. Systematic Review for Declassification General................................................................................................ 4-500 21
Section VI. Downgrading Purpose and Authority ........................................................................ 4-600 22 Downgrading Decisions During Original Classification .................... 4-601 22 Downgrading at a Later Date.............................................................. 4-602 22
Section VII. Upgrading General................................................................................................ 4-700 29
Section VIII. Foreign Government Information Policy and Procedures......................................................................... 4-800 30 Communications with Foreign Governments ..................................... 4-801 30
Section IX. Challenges to Classification Classification Challenges.................................................................... 4-900 31
CHAPTER 5. MARKING
Section I. General Provisions
Marking and Designation Rules ......................................................... 5-100 33 Exceptions........................................................................................... 5-101 33 Marking Classified Documents and Other Material ........................... 5-102 33 vi
Paragraph Page
Section II. Specific Markings on Documents Overall Classification Marking........................................................... 5-200 34 Agency, Office of Origin, and Date.................................................... 5-201 34 Source(s) of Classification.................................................................. 5-202 34 Reason for Classification.................................................................... 5-203 35 Declassification Instructions............................................................... 5-204 36 Downgrading Instructions .................................................................. 5-205 39 Identification of Specific Classified Information ............................... 5-206 39 Page Marking...................................................................................... 5-207 41 Special Control and Similar Notices .................................................. 5-208 42
Section III. Marking Special Types of Documents Documents With Component Parts .................................................... 5-300 43 Transmittal Documents....................................................................... 5-301 43 Classification by Compilation ............................................................ 5-302 44 Translations......................................................................................... 5-303 44 Information Transmitted Electronically.............................................. 5-304 44 Documents and Material Marked for Training Purposes.................... 5-305 44 Files, Folders, and Groups of Documents .......................................... 5-306 45 Printed Documents Produced by AIS Equipment .............................. 5-307 45
Section IV. Marking Special Types of Materials General Policy Statement ................................................................... 5-400 45 Blueprints, Schematics, Maps, and Charts ......................................... 5-401 45 Photographs, Negatives, and Unprocessed Film ................................ 5-402 46 Slides and Transparencies................................................................... 5-403 46 Motion Picture Films and Videotapes ................................................ 5-404 46 Sound Recordings............................................................................... 5-405 46 MicroForms ........................................................................................ 5-406 46 Removable AIS Storage Media .......................................................... 5-407 47 Fixed and Internal AIS Storage Media ............................................... 5-408 47 Standard Form (SF) Labels................................................................. 5-409 47 Intelligence Information ..................................................................... 5-410 48
Section V. Changes in Markings Downgrading and Declassification in Accordance with Markings .... 5-500 48 Downgrading and Declassification Earlier Than Scheduled .............. 5-501 49 Upgrading ........................................................................................... 5-502 49 Posted Notice on Bulky Quantities of Material.................................. 5-503 49 Extensions of Duration of Classification............................................ 5-504 50
Section VI. Remarking and Using Old Classified Material Old Markings Can Remain ................................................................. 5-600 50 Earlier Declassification and Extension of Classification ................... 5-601 50 vii
Paragraph Page
Section VII. Foreign Government Information/Equivalent U.S. Classification Designation General................................................................................................ 5-700 50 Marking NATO Documents................................................................ 5-701 50 Marking Other Foreign Government Documents............................... 5-702 50 Marking of Foreign Government and NATO Information in DoD
Documents...................................................................................... 5-703 51 Marking for Transfer to Archives ....................................................... 5-704 52
CHAPTER 6. SAFEGUARDING
Section I. Control Measures
General................................................................................................ 6-100 58 Working Papers................................................................................... 6-101 62
Section II. Access Policy .................................................................................................. 6-200 63 Access by Persons Outside the Executive Branch.............................. 6-201 63 Visits ................................................................................................... 6-202 65
Section III. Safeguarding General Policy..................................................................................... 6-300 66 Care During Working Hours............................................................... 6-301 66 End-of-Day Security Checks .............................................................. 6-302 67 Emergency Planning ........................................................................... 6-303 69 Telephone Conversations.................................................................... 6-304 70 Removal of Classified Storage Equipment ......................................... 6-305 70 Residential Storage Arrangements...................................................... 6-306 70 Classified Meetings and Conferences................................................. 6-307 70 U.S. Classified Information Located in Foreign Countries ................ 6-308 74 Information Processing Equipment .................................................... 6-309 75
Section IV. Storage General Policy..................................................................................... 6-400 75 Standards for Storage Equipment ....................................................... 6-401 76 Storage of Classified Information....................................................... 6-402 76 Procurement of New Storage Equipment ........................................... 6-403 79 Equipment Designations and Combinations....................................... 6-404 79 Repair of Damaged Security Containers ............................................ 6-405 81 Maintenance and Operating Inspections............................................. 6-406 82
Section V. Reproduction of Classified Material Policy .................................................................................................. 6-500 82 Approval for Reproduction................................................................. 6-501 82 Control Procedures ............................................................................. 6-502 83 viii
Paragraph Page
Section VI. Foreign Government Information General................................................................................................ 6-600 83 Foreign Government Top Secret, Secret and Confidential
Information..................................................................................... 6-601 83 Foreign Government Restricted Information Provided in
Confidence ..................................................................................... 6-602 84 Third-Country Transfers ..................................................................... 6-603 84 Storage ................................................................................................ 6-604 84
Section VII. Disposition and Destruction of Classified Material Policy.................................................................................................. 6-700 85 Methods and Standards....................................................................... 6-701 85
Section VIII. Alternative or Compensatory Control Measures General................................................................................................ 6-800 86 Special Access Controls ..................................................................... 6-801 87
CHAPTER 7. TRANSMISSION AND TRANSPORTATION
Section I. Methods of Transmission or Transportation
Policy.................................................................................................. 7-100 89 Top Secret Information ....................................................................... 7-101 89 Secret Information .............................................................................. 7-102 90 Confidential Information .................................................................... 7-103 92 Transmission of Classified Material to Foreign Governments........... 7-104 92 Shipment of Freight ............................................................................ 7-105 93
Section II. Preparation of Material for Transmission Envelopes or Containers ..................................................................... 7-200 93 Addressing .......................................................................................... 7-201 94
Section III. Escort or Hand-Carrying of Classified Material General Provisions.............................................................................. 7-300 95 Documentation.................................................................................... 7-301 97 Hand-Carrying or Escorting Classified Material Aboard Commercial
Passenger Aircraft .......................................................................... 7-302 98 Authority to Approve Escort or Hand-Carry of Classified Information
Aboard Aircraft .............................................................................. 7-303 99 ix
Paragraph Page
CHAPTER 8. SPECIAL ACCESS PROGRAMS
Policy .................................................................................................. 8-100 102 SAP Procedures .................................................................................. 8-101 102 Control and Administration ................................................................ 8-102 104 Establishment of DoD SAPs............................................................... 8-103 105 Reviews of SAPs ................................................................................ 8-104 109 Annual Reports and Revalidation....................................................... 8-105 109 Interim Reports ................................................................................... 8-106 110 Changes in Classification ................................................................... 8-107 111 Termination and Transitioning of SAPs ............................................. 8-108 111
CHAPTER 9. SECURITY EDUCATION AND TRAINING
Section I. Policy
General Policy..................................................................................... 9-100 112 Methodology....................................................................................... 9-101 112
Section II. Initial Orientation Cleared Personnel ............................................................................... 9-200 112 Uncleared Personnel ........................................................................... 9-201 114
Section III. Special Requirements General................................................................................................ 9-300 114 Original Classifiers ............................................................................. 9-301 114 Declassification Authorities Other Than Original Classifiers ............ 9-302 115 Derivative Classifiers, Security Personnel and Others ....................... 9-303 115 Others.................................................................................................. 9-304 116
Section IV. Continuing Security Education/Refresher Training Continuing Security Education........................................................... 9-400 116 Refresher Training .............................................................................. 9-401 117
Section V. Termination Briefings General................................................................................................ 9-500 117
Section VI. Program Oversight General .............................................................................................. 9-600 117
CHAPTER 10. ACTUAL OR POTENTIAL COMPROMISE OF CLASSIFIED INFORMATION
Policy................................................................................................. 10-100 119 Reporting........................................................................................... 10-101 120 Inquiry/Investigation ......................................................................... 10-102 122 Results of the Inquiry/Investigation .................................................. 10-103 123 x
Paragraph Page
Verification, Reevaluation, and Damage Assessment.................... 10-104 124 Debriefings in Cases of Unauthorized Access ............................... 10-105 125 Management and Oversight ........................................................... 10-106 126 Additional Investigation................................................................. 10-107 126 Unauthorized Absences.................................................................. 10-108 126 Suicide and Attempted Suicide ...................................................... 10-109 126 Derogatory Information ................................................................. 10-110 127
Appendixes A - Controlled Unclassified Information............................................... A-1 B - Special Procedures for use in Systematic and Mandatory Review of
Cryptologic Information.............................................................. B-1 C - Control of Dissemination of Intelligence Information
(to be provided at a later date)..................................................... C-1 D - Equivalent Foreign Security Classifications ................................... D-1 E - Physical Security Standards............................................................. E-1 F - Transmission to Foreign Governments ............................................ F-1 G - Special Access Program (SAP) Documentation ............................. G-1 H - Procedures for an Information Security Incident Report ................ H-1 I - Top Secret Control Accounts............................................................ I-1 J - Sample Format for Emergency Destruction of Classified Material . J-1
Glossary ............................................................................................................... GL-1
Forms Prescribed USSOCOM Form 3, Security Education Record USSOCOM Form 95, Statement for Couriers of Classified Information 5
Figures 5-1 – Marking Classified Slides……………………………………… ... 53 7-1 - Identification of Official Courier H-1 - Sample Appointment Letter ............................................................ H-4 H-2 – Sample Report of Inquiry/Investigation……………... .................. H-5 H-3 - Sample First Endorsement .............................................................. H-7 H-4 - Inquiry Official's Checklist……………………………..………… H-8
CHAPTER 1
POLICY AND PROGRAM MANAGEMENT
SECTION I – POLICY
1-100. Purpose and Scope.
a. This manual implements Executive Order 12958, Classified National Security Information, April 20, 1995, Classified National Security Information, and associated Office of Management and Budget (OMB) directives within the Department of Defense (DoD). It applies to all Components of the Department of Defense. It establishes the DoD Information Security Program to promote proper and effective classification, protection and downgrading of official information requiring protection in the interest of the national security. It also promotes the declassification of information no longer requiring such protection.
b. There is information, other than classified information, that has been determined to require some type of protection or control. This information is generally known as “controlled unclassified information, Sensitive But Unclassified, and For Official Use Only (FOUO).” Guidance concerning the protection or controls required for such information may be found in a number of DoD Directives, Regulations and Instructions. However, since classified information and controlled unclassified information often exist side-by-side in the work environment, often in the same document, the essence of available guidance pertaining to controlled unclassified information has been captured in Appendix A of this manual. The purpose of the appendix is to provide the user, to the extent possible, a single source document for guidance concerning both classified and controlled unclassified information.
c. Questions regarding guidance and policy interpretation are encouraged and should be addressed to USSOCOM Security Management Office, (SOCS-SM).
1-101. Policies.
a. All personnel of the DoD are personally and individually responsible for providing proper protection to classified information under their custody and control. All officials within DoD who hold command, management, or supervisory positions have specific, nondelegable responsibility for the quality of implementation and management of the Information Security Program within their areas of responsibility.
Management of classified information shall be included as a critical element or item to be evaluated in the rating of original classification authorities, security managers or specialists, and other personnel whose duties primarily involve the creation or handling of classified information.
b. Except for information subject to the Atomic Energy Act of 1954 (as amended), Executive Order 12958, and this manual provide the only basis for application of security classification to information within DoD.
c. Information shall be classified only when necessary in the interest of national security, and shall be declassified as soon as it is consistent with the requirements of national security.
d. Information shall not be reclassified after it has been declassified and officially released to the public by proper authority.
e. Persons shall be allowed access to classified information only if they (1) possess a valid and appropriate security clearance, (2) have executed an appropriate non-disclosure agreement, and (3) have a valid need for access to the information to perform a lawful and authorized governmental function. DoD 5200.2-R, DoD Personnel Security Program Regulation, January 1987, contains detailed guidance on personnel security investigation, adjudication and clearance. Contact the Personnel Security Branch, Security Management Office, for further information.
f. Classified information shall be protected at all times. See Chapters 6 and 7 and 8 of this manual.
g. Classified information shall be maintained only when it is required for effective and efficient operation of the organization or its retention is required by law or regulation. Classified information is subject to the Records Information Management (RIMS) information classification and management schedules and shall be processed accordingly.
h. Classified documents and material that constitute permanently valuable records of the government shall be maintained and disposed of in accordance with (IAW) DoD Directive 5015.2. (Records Management Guidance can be ascertained by contacting SOCS-SJS-SI). Other classified material shall be destroyed IAW Chapter 6 of this manual.
i. Special Access Programs (SAP) shall be created, continued, managed, and discontinued in conformance with Chapter 8 of this manual. Special Access Programs (SAP) shall be established, disestablished, restructured and managed in conformance with chapter 8 of this manual, DoD O- 5205.7, SAP Policy, DoDI 5205.11, Management, Administration, and Oversight of DoD SAPs, and USSOCOM M 380-2, (O) USSOCOM Special Access Program, (SAP) Program Security Guide (SAP PSG), 22 August 2001. The USSOCOM Special Access Program Central Office (SAPCO) (SOOR- S) will be consulted for guidance on USSOCOM SAP requirements.
j. Sensitive Compartmented Information (SCI) shall be protected in accordance with applicable national policy, Director of Central Intelligence and DoD Directives and Instructions. Further guidance will be provided by SOIO-IN-SSO and USSOCOM Manual 380-6.”
SECTION II -- PROGRAM MANAGEMENT
1-200. Department of Defense (DoD). The Secretary of Defense has designated the Assistant Secretary of Defense for Command, Control, Communications, and Intelligence (ASD(C3I)) as the senior agency official responsible for direction and administration of the Information Security Program for DoD.
(SOCS-SM is responsible for direction and administration of the Information Security Program at
HQ USSOCOM).
The Under Secretary of Defense for Policy (USD(P)) has been designated as the senior official responsible for administering that portion of the DoD Information Security Program pertaining to SAPs, the National Disclosure Policy (NDP), foreign government (including North Atlantic Treaty Organization (NATO)) information, and security arrangements for international programs. The USSOCOM SAPCO is responsible for implementing SAP security measures and all pertinent associated policy within HQ USSOCOM. These officials shall perform those functions specified in subsection 5.6(c) of Executive Order 12958 and appropriate implementing directives for DoD.
1-201. DoD Components. The head of each DoD Component shall:
a. Appoint a senior agency official to be responsible for direction and administration of the program within the Component. (The Component head may designate a separate senior official to be responsible for overseeing SAPs within the Component, if necessary.); The Chief of Staff (CS) shall be the Security Manager of USSOCOM. The Command’s Deputy Security Manager is the Director of Security/Provost Marshall, SOCS-SM and shall:
(1) Recommend security policy, procedures, and responsibilities to the Security Manager.
(2) Advise and assist the Centers on implementing the Information Security Program.
(3) Provide technical advice and assistance to the Center Security Managers.
(4) Represent USSOCOM at security management meetings outside the Command.
(5) Monitor Center annual self-inspection programs for sufficiency.
(6) Conduct annual security program reviews. These will be accomplished in a team-oriented fashion on an annual basis. SOCS-SM will serve as team leader and will review each center’s Information (INFOSEC), Personnel (PERSEC), Industrial, and Physical Security programs. In coordination and simultaneously, the appropriate USSOCOM representative will conduct an additional security review of each functional area. Those additional areas to be reviewed include, but are not limited to, Special Access Program protection, Focal Point safeguarding procedures, Operations Security (OPSEC), Information Assurance (COMPUSEC), Communications Security (COMSEC), and protection of Sensitive Compartmented Information (SCI). Each activity will be inspected annually unless, the CS has approved a waiver. Centers will be required to conduct self-inspections on a bi-annual basis, or 6 months from the date of the last SMO review. Results of program reviews will be forwarded to the Center Directors for action. Centers shall take corrective action, and when required, will prepare a written first endorsement, and forwarded to the CS, through SOCS-SM within 30 days of the inspection report.
b. Commit necessary resources to the effective implementation of the Information Security Program;
and
c. Establish procedures to ensure that the head of each activity within the Component that creates, handles or stores classified information appoints an official to serve as security manager for the activity, to provide proper management and oversight of the activity's Information Security Program.
Persons appointed to these positions shall be provided training as required by Chapter 9 of this manual.
Within USSOCOM, each Center shall appoint, in writing, a security manager and alternate. These individuals must possess a Top Secret clearance. The Center Security Manager shall be a commissioned officer, warrant officer, civilian grade GS-11 or above, or noncommissioned officer in grade E-8 or above. Alternates can be commissioned officer, warrant officer, non-commissioned officer in grade E-5 or above, or civilians GS-5 or above. Center Directors shall provide the names of the security manager and alternate to SOCS-SM. Once a person has been assigned as a Center Security Manager, they must contact SOCS-SM for an initial briefing within 30 days of appointment.
Furthermore, they must attend mandatory Formal security manager training given by SOCS-SM within 90 days of assignment. Duties of the Center Security Managers are:
(1) Advise the Center Director on implementing the Information Security Program.
(2) Establish and manage a continuous security education program. Record training on USSOCOM Form 3, Security Education Record.
(3) Establish a security indoctrination outline for newly assigned employees to USSOCOM. This includes Military (active duty, reserves, IMAs) and Civilian appointments. Refresher training, to occur at least annually, will be conducted and documented on all employees who work in USSOCOM (regardless of employment status or frequency of classified access.)
(4) Maintain a vigorous program of declassification, downgrading, and destruction.
(5) Conduct and document an annual internal security self-inspection to enhance the Command Security Program review. Internal self- inspections will be conducted 6 months after a program review conducted by SMO.
(6) Maintain a Security Manager’s Handbook. As a minimum, the Handbook will contain:
(a) Security Manager Appointment Letter/Orders.
(b) SOCOM Forms 3, Security Education Record.
(c) M380-1 (Optional if access to electronic version is readily accessible).
(d) Current personnel roster and security clearance and access roster.
(e) Marking supplement.
(f) Activity inspection reports with response and corrective action taken (last 2 years).
(g) All security violation reports since the last program review.
(h) Training plans.
(i) End of Day check SOP.
(j) Emergency Destruction Plans.
(k) Hand-carry Authorizations and USSOCOM Form 95s, Statement for Couriers of Classified information.
(l) OCA training memo (if applicable).
(m)Container listing with locations and date of change records.
(n) Open Storage certifications.
(o) Alarm activation/deactivation lists.
(p) Assignment of division level security management persons who assist in the overall security management throughout the Center, if applicable.
1-202. Senior Agency Officials. The senior agency official appointed in each Component (In USSOCOM, the CS has been appointed the Senior Agency Official), IAW paragraph 1-201a., shall:
a. Oversee the Component's Information Security Program;
b. Promulgate (or cause to be promulgated) implementing directives as necessary for program implementation;
c. Establish and maintain a security education program as required by Chapter 9 of this manual;
d. Establish and maintain an ongoing self-inspection program, to include periodic review and assessment of the Component's classified products;
e. Establish procedures to prevent unauthorized access to classified information (In USSOCOM, this includes Top Secret Control and Accountability);
f. Develop special contingency plans, as necessary, for the safeguarding of classified information used in or near hostile or potentially hostile areas;
g. Ensure that the performance contract or other system used to rate the performance of civilian and military personnel includes the management of classified information as a critical element or item to be evaluated in the rating of the following:
(1) Original classification authorities,
(2) Security managers and security specialists, and
(3) All other personnel whose duties include significant involvement with the creation or handling of classified information;
h. Account for the costs associated with the implementation of this manual within the Component and report those costs as required; and
i. Ensure prompt and appropriate response to any request, appeal, challenge, complaint, or suggestion arising out of the implementation of this manual within the Component.
e. Establish procedures to prevent unauthorized access to classified information (In USSOCOM, this includes Top Secret Control and Accountability);
f. Develop special contingency plans, as necessary, for the safeguarding of classified information used in or near hostile or potentially hostile areas;
g. Ensure that the performance contract or other system used to rate the performance of civilian and military personnel includes the management of classified information as a critical element or item to be evaluated in the rating of the following:
(1) Original classification authorities,
(2) Security managers and security specialists, and
(3) All other personnel whose duties include significant involvement with the creation or handling of classified information;
h. Account for the costs associated with the implementation of this manual within the Component and report those costs as required; and
i. Ensure prompt and appropriate response to any request, appeal, challenge, complaint, or suggestion arising out of the implementation of this manual within the Component.
SECTION III -- SPECIAL TYPES OF INFORMATION
1-300. Restricted Data. Classified information in the custody of DoD marked as Restricted Data under the Atomic Energy Act of 1954 (as amended) shall be stored, protected, and destroyed as required by this manual for other information of a comparable level of security classification. DoD policy and procedures concerning access to and dissemination of Restricted Data within DoD are contained in DoD Directive
5210.2. Further information concerning access to Restricted Data and Critical Nuclear Weapon Design Information (CNWDI) can be obtained from the Personnel Security Branch, SOCS-SM.
1-301. Sensitive Compartmented Information (SCI) and Communications Security (COMSEC) Information. SCI and COMSEC information shall be controlled and protected in accordance with applicable national policy and DoD Directives and Instructions. Security classification and declassification policies of this manual apply to SCI and COMSEC information in the same manner as other classified information except that Appendix B of this manual provides special procedures for use in systematic and mandatory review of cryptologic information. Within USSOCOM, SOIO-IN-SSO is the focal point for SCI matters. SOIO-C4I-OC is the focal point for COMSEC guidance.
1-302. Special Access Program (SAP) Information. Information covered by Special Access Programs established in accordance with Chapter 8 of this manual shall be classified, declassified, controlled and protected as required in this manual and instructions issued by officials charged with management of those programs. The provisions of this manual pertaining to classification, declassification and marking apply, without exception, to Special Access Program information unless waivers of specific requirements are obtained in accordance with Section VI of this chapter. Consult USSOCOM M 380-2 SAP PSG, 22 Aug 01, for specific guidance on classification, declassification, control and protection of SAP information.
1-303. North Atlantic Treaty Organization (NATO) and Other Foreign Government Information.
NATO classified information shall be safeguarded in compliance with United States Security Authority for NATO (USSAN) Instruction I-69. Other foreign government information shall be safeguarded as described herein for U.S. information except as specified in Appendix F or as required by treaties or international agreements. SOCS-SJS-S is the command POC for NATO information management.
SECTION VI -- EXCEPTIONAL SITUATIONS
1-400. Military Operations. The provisions of this manual pertaining to accountability, dissemination, transmission, and storage of classified information and material may be modified by military commanders as necessary to meet local conditions encountered during military operations. Military operations include combat and peacekeeping operations as well as other operations involving military deployments.
Classified information shall be introduced into combat areas or zones, or areas of potential hostile activity, only as necessary to accomplish the military mission. Transmission or introduction of classified material into combat areas requires prior written approval of both SOCS-SM and CS.
1-401. Waivers to Requirements.
a. Unless otherwise specified herein, DoD Components shall submit requests for waivers to the requirements of this manual through established channels, to the ASD (C3I) or, for information related to SAPs, foreign government information (including NATO) information, and security arrangements for international programs, to the Under Secretary of Defense (Policy) (USD(P)). Requests for waivers concerning SAP information shall be forwarded through the USSOCOM SAPCO to the USSOCOM Deputy Commander for approval. The ASD (C3I) and USD(P) shall be responsible for promptly notifying the Director, Information Security Oversight Office of all waivers approved involving E.O.
12958 and its’ implementing directives.
b. Requests for waivers shall contain sufficient information to permit a complete and thorough analysis to be made of the impact on national security of approval of the waiver. DoD Components shall maintain documentation regarding approved waivers and furnish such documentation, upon request, to other agencies with who classified information or secure facilities are shared.
SECTION V -- CORRECTIVE ACTIONS AND SANCTIONS
1-500. General. Heads of the DoD Components shall establish procedures to ensure that prompt and appropriate management action is taken in case of compromise of classified information, improper classification of information, violation of the provisions of this manual, and incidents that may put classified information at risk of compromise. Within USSOCOM, discovery or knowledge of any violations of the provisions of this manual will be reported to SOCS-SM within 24 hours, whereby a AF Form 3545 (Incident Form) will be initiated to determine the cause and factors leading to the suspected violation (See Chapter 10 for guidance). Such actions shall focus on correction or elimination of the conditions that caused or occasioned the incident. All reports of security violations will be reviewed by the Command Personnel Security Officer (SOCS-SC). Violations involving SAP material will be reported to the USSOCOM SAPCO within 24 hours. The USSOCOM SAPCO will notify SOCS-SM and coordinate the initiation of an inquiry in accordance with Chapter 10 of this regulation and USSOCOM M 380-2.
1-501. Sanctions.
a. DoD military and civilian personnel shall be subject to sanctions if they knowingly, willfully, or negligently:
(1) Disclose to unauthorized persons information properly classified under this manual;
(2) Classify or continue the classification of information in violation of this manual;
(3) Create or continue a SAP contrary to the requirements of this manual; or
(4) Violate any other provision of this manual.
b. Sanctions include, but are not limited to, warning, reprimand, suspension without pay, forfeiture of pay, removal, discharge, loss or denial of access to classified information, and removal of classification authority. Action may also be taken under the uniform Code of Military Justice (UCMJ) for violations of that Code and under applicable criminal law.
c. In case of demonstration of reckless disregard or a pattern of error in applying the classification standards of this manual on the part of a person holding original classification authority, the appropriate official shall, as a minimum, remove the offending individual's original classification authority.
d. Violation of any portion of 1-501 a(1)-a(4) shall be reported immediately to SOCS-SM. Evidence or willful compromise of classified information shall be punishable under either the UCMJ or federal law for military and civilians. See UCMJ, Article 106A, Espionage, which is punishable by death or such other punishment as the court-martial shall direct; and 18 U.SC. 793, which makes disclosure of classified information punishable by an indeterminate fine and imprisonment for not more than 10 years.
e. SOCS-SC will maintain a database of security offenders. Personnel involved in three security violations (See Glossary for “Violation” definition) within a 12 month period are subject to having this information reported, as a minimum, to the appropriate security clearance adjudication authority to determine if continued access to classified information is warranted.
1-502. Reporting of Incidents. Whenever a violation under paragraph 1-501a(1), (2) or (3), occurs, the Component Senior Agency Official shall promptly notify SOCS-SM, who will notify the CS. The CS will notify the ASD (C3I) through appropriate channels. The ASD (C3I)) shall notify the Director, Information Security Oversight Office, as required by paragraph 5.7(e)(2) of Executive Order 12958. If the violation involves SAP, NATO or foreign government information, it shall be promptly reported to the Assistant Deputy to the USD (P) for Policy Support through CORB/SOOR and the CS, who will be responsible for all further notifications and appropriate coordination.
SECTION VI – REPORTS
1-600. Reporting Requirements.
a. The ASD (C3I) shall establish requirements for the collection and reporting of data necessary to support fulfillment of the requirements of Executive Order 12958 and OMB and Security Policy Board implementing directives. As a minimum, DoD Components shall submit, on a fiscal year basis, a consolidated report concerning the Information Security Program of the Component on Standard Form (SF) 311, Agency Information Security Program Data, to reach the Principal Director for Information Warfare, Security and Counterintelligence (PD (IWS&CI)), OASD(C3I), by October 20 of each year. SF 311 shall be completed in accordance with the instructions thereon and augmenting instructions issued by the OASD (C3I). The OASD (C3I) shall submit the DoD report (SF 311) to the Information Security Oversight Office by October 31 of each year. Interagency Report Control Number 0230-GSA-AN applies to this information collection requirement.
b. The USD (P) shall establish requirements for the collection and reporting of data necessary to the proper management of SAP within the Department. The USSOCOM SAPCO shall provide guidance on special reporting requirements received from USD (P). USSOCOM SAPCO will determine survey periods. Centers shall provide SOCS-SM with input for the reports not later than 10 October of each year based on the Center’s Information Security Program.
c. Instructions for the completion of the Standard Form 311 will be provided by SOCS-SM in August of each year.
SECTION VII -- SELF-INSPECTION
1-700. General. Heads of DoD Components shall establish and maintain a self-inspection program based on program needs and the degree of involvement with classified information. The purpose of the program shall be to evaluate and assess the effectiveness and efficiency of the Component’s implementation of the DoD Information Security Program. Component activities that originate significant amounts of classified information should be inspected at least annually. Within USSOCOM, all activities will be required to conduct a self-inspection, 6 months after the last SMO Security Program Review. A record of findings and corrective actions will be maintained until the next Security Program Review.
Checklists used by Security Program Review team members will be used by…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .