Bidders Library JITC Instructions - JITCI 240-110-08.pdf
PDF 202 KB Posted
- Attached to
- TEC II Services RFP Federal contract opportunity
- Solicitation number
- HC102821R0006
- Issued by
- Defense Information Systems Agency
About this file
This document is an instruction manual for the Joint Interoperability Test Command's (JITC) Information Security Program. It outlines policies and procedures for classifying, safeguarding, disseminating, and destroying sensitive information related to test, evaluation, and certification services. The Defense Information Systems Agency (DISA) is soliciting proposals under solicitation HC102821R0006 for Test, Evaluation, and Certification Services to support the JITC. Offerors would be responsible for complying with the security protocols described in the manual, such as derivative classification, applying appropriate markings, limiting access to cleared personnel, and using approved transmission methods.
View the file
Other files for this federal contract opportunity
Show all 50
TEC II Services RFP has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DEFENSE INFORMATION SYSTEMS AGENCY
P.O. BOX 4502
ARLINGTON, VIRGINIA 22204-4502
JITC INSTRUCTION 240-110-8* 31 March 2010
SECURITY
Information Security Program
1. Purpose. To prescribe policies, assign responsibilities, and provide procedures for the Information Security Program within the Joint Interoperability Test Command (JITC).
2. Applicability. This Instruction applies to all military, civilian, and contractor personnel assigned to or employed by
JITC.
3. Authority. This Instruction is published in accordance with:
3.1 Executive Order (E.O.) 12958, as amended Classified
National Security Information, 25 Mar 2003. In case of conflict between the DoD Regulation and the E.O, 12958, as amended, the E.O. takes precedence.
3.2 DoD 5200.1-R, Department of Defense Information Security
Program, January 1997. In case of conflict between the DoD Regulation and DISAI 240-110-8, the DoD regulation takes precedence.
3.3 DISAI 240-110-8, Defense Information Systems Agency
Information Security Program, June 1996. In case of conflict between the DISAI 240-110-8 and JITCI 240-110-8, the DISAI takes precedence.
4. References.
4.1 Executive Order (E.O.) 12958, as amended Classified
National Security Information, 25 March 2003.
4.2 DoD 5200.1-R, Department of Defense Information Security
Program, January 1997.
4.3 DISAI 240-110-8, Defense Information Systems Agency
Information Security Program, June 1996.
4.4 DISAI 240-15-4, U.S. Security Authority for North Atlantic Treaty Organization (NATO) Affairs, March 2003.
5. Policy.
5.1 Classified information will be protected by each individual who possesses or who has knowledge of such information regardless of how it was obtained.
5.2 Compliance with the provisions of this Instruction is
mandatory. Violators are subject to administrative or judicial sanctions, or both.
5.3 Additional policy regarding information security is
prescribed throughout pertinent chapters of this Instruction.
6. Composition of Instruction. This instruction supplements DISAI 240-110-8 and DOD 5200.1-R and must be used in conjunction to obtain complete guidance on a particular subject.
6.1 Where DISAI 240-110-8 and DoD 5200.1-R provides sufficient guidance, no JITC supplementation is furnished. Therefore, when a paragraph from DISAI 240-110-8 is not cited, refer directly to the DISA regulations.
6.2 The numbers in parentheses following the paragraph headings refer to the chapter and paragraph in DISAI 240-110-8. The word (ADDED) is used when JITC policy applies and/or the subject is not addressed by the DISA regulation.
7. Responsibilities.
7.1 General. The protection of classified information is the
responsibility of each individual employed by or assigned to the JITC who possesses, or has knowledge of such information regardless of how obtained. Security directives do not guarantee protection and cannot be written to cover all conceivable situations; therefore, basic security principles, common sense, and logical interpretation of existing directives must be applied. The collection, recording, or removal of any classified material for personal use from the JITC is prohibited in the interest of national security and is punishable under Executive Order 12958.
7.2 The JITC Commander has responsibility for the overall
implementation of the JITC Security Program.
7.3 The Security Manager will:
7.3.1 Serve as focal point for the organizational element for advice and assistance and distribution of DOD and DISA policy on classification, declassification, downgrading, and marking of national security information.
7.3.2 Conduct annual self-inspections of their security
programs.
7.3.3 Access the data base of clearances to facilitate
distribution of classified correspondence.
7.3.4 Implement a security education and training program.
7.3.5 Attend scheduled security manager meetings.
7.3.6 Prepare a standard Operating Procedure (SOP) for unique situations in their organizational element which have not been addressed in this instruction.
7.3.7 Ensure that indoctrination, refresher, threat, courier, foreign travel, and termination briefings are conducted.
Maintain an official file copy of the orientation briefings and annual refresher briefings.
7.3.8 Ensure a periodic document review program is conducted in the organizational element annually in order to reduce unnecessary classified holdings. The program will include downgrading, declassifying, destroying, or returning documents to originator.
7.3.9 Report all security incidents or violations to the
Security and Certification Department and serve as point of contact on status of ongoing preliminary inquiries and/or formal investigations.
7.3.10 Ensure that appropriate personnel are briefed, rebriefed, and debriefed for access to NATO, COSMIC, ATOMAL, and CNWDI. The Security Manager or Monitor for an organizational element may perform the briefings, in the interest of operational efficiency.
7.3.11 Collect and submit data on the organizational element’s information security program using an SF 311: Agency Information Security Program Data.
7.3.12 Manage courier authorization program for the
organizational element. Prepare and/or coordinate on requests for badges and designation letters submitted for approval.
7.3.13 Coordinate on DD Forms 1610: Request and Authorization for TDY Travel of DoD Personnel, as necessary, acknowledging that travelers have been authorized to hand-carry classified material and have received a briefing prior to departure regarding applicable export control, foreign disclosure, and security requirements. Maintain inventory of classified material hand carried aboard commercial aircraft.
7.4 Supervisors operating within the JITC are responsible for the effective application of the JITC Security Program within their areas of jurisdiction. They must ensure individuals who have access to classified information are appropriately cleared, are aware of their security responsibilities, and are indoctrinated and proficient in the security procedures, which apply to them in the performance of their duties.
7.5 Portfolio Managers/Division Chiefs are responsible for:
7.5.1 Ensuring Security Monitors are appointed and informing
the Security Office of changes.
7.5.2 Providing the librarian with a current list of projects, project managers, and appropriately cleared personnel (including contractors) authorized to work on classified project(s).
7.5.3 Justifying the need for access to NATO information for
assigned personnel.
7.5.4 Identifying positions as critical sensitive and
noncritical sensitive.
7.6 Security Monitors are responsible for:
7.6.1 Briefing new personnel on security procedures.
7.6.2 Ensuring end-of-day procedures are adhered to.
7.6.3 Serving as a Classified Document Custodian.
7.8 The Classified Document Manager is overall responsible for all classified information, within JITC and for:
7.8.1 Managing the automated document register.
7.8.2 Providing the incoming and outgoing Classified Document Custodian a pre-printed inventory list.
7.8.3 Officially relieving the outgoing Classified Document
Custodian (upon completion of the inventory) from accountability of classified material.
7.9 Classified Document Custodians are responsible for:
7.9.1 All classified material entrusted to them until they are officially relieved of accountability by the Classified Document Manager.
7.9.2 Inventorying all classified material prior to change of classified document custodian and as directed by the Security Manager. The inventory will be signed and dated by the incoming and outgoing Classified Document Custodian.
7.9.3 Ensuring the automated document register reflects the
current status of their holdings at all times.
7.9.4 Ensuring classified distribution is picked-up in a timely manner.
7.10 The Top Secret Control Officer (TSCO) is accountable for all Top Secret information except Sensitive Compartmented Information (SCI).
7.11 The Special Security Contact Officer (SSCO) is accountable for all SCI.
7.12 The Technical/Media Library Manager is overall responsible for the safekeeping, storing, and controlling all classified information required for reference and historical purposes.
7.13 The Technical/Media Librarian is responsible to the
Library Manager and serves as Classified Document Custodian.
7.14 Laboratory (LAB) Managers and Project Managers are
responsible for:
CONTENTS
BASIC INSTRUCTIONS
1. Purpose
2. Applicability
3. Authority
4. Reference
5. Policy
6. Composition of Instruction
7. Responsibilities
8. Delegation of Authority
C1 CHAPTER 1. GENERAL PROVISIONS
C2 CHAPTER 2. CLASSIFICATION
C3 CHAPTER 3. DERIVATIVE CLASSIFICATION
C4 CHAPTER 4. MARKINGS
C5 CHAPTER 5. SAFEKEEPING AND STORAGE
C5.1 STORAGE AND STORAGE EQUIPMENT
C5.2 CUSTODIAL PRECAUTIONS
C6 CHAPTER 6. COMPROMISE OF CLASSIFIED INFORMATION
C7 CHAPTER 7. ACCESS, DISSEMINATION, ACCOUNTABILITY, AND
REPRODUCTION
C7.1 ACCESS
C7.2 ACCOUNTABILITY AND CONTROL
C8 CHAPTER 8. TRANSMISSION
C.8.1 METHODS OF TRANSMISSION OR TRANSPORTATION
C.8.2 PREPARATION OF MATERIAL FOR TRANSMISSION, SHIPMENT, OR
CONVEYANCE
C.8.2 RESTRICTIONS ON HAND-CARRYING CLASSIFIED INFORMATION
C9 CHAPTER 9. DISPOSAL AND DESTRUCTION
C10 CHAPTER 10. SECURITY EDUCATION
C11 CHAPTER 11. FOREIGN GOVERNMENT INFORMATION
C12 CHAPTER 12. SPECIAL ACCESS PROGRAM
C13 CHAPTER 13. PROGRAM MANAGEMENT – INDIAN HEAD
C14 CHAPTER 14. ADMINISTRATION SANCTIONS
C15 CHAPTER 15. INFORMATION SYSTEM
C1. CHAPTER 1. GENERAL PROVISIONS
Refer to DISAI 240-110-8
(This page intentionally left blank)
C.2 CHAPTER 2. CLASSIFICATION
C3. CHAPTER 3. DERIVATIVE CLASSIFICATION
C3.1 The Nature of the Process. Derivative classification is the process of determining whether information that is to be included in a document or material has been classified and, if it has, ensuring that it is identified as classified information by marking or similar means. Information is derivatively classified whenever it is extracted, paraphrased, restated, or generated in a new form. Application of classification markings to a document or other material as directed by a security classification guide or other source material is derivative classification. Simply photocopying or otherwise mechanically reproducing classified material is not derivative classification.
C3.2 Authority and Responsibility. Within the Department of Defense, all cleared personnel who generate or create material that should be derivatively classified are responsible for ensuring that the derivative classification is accomplished in accordance with this chapter. No specific delegation of authority is required by persons doing derivative classification. DoD officials who sign or approve derivatively classified documents have principal responsibility for the quality of their derivative classification.
C3.3 Policy. All persons performing derivative classification shall:
C3.3.1 Observe and respect the classification determinations made by original classification authorities. If they believe information to be improperly classified, they will take action as required by subsection 4-900 of this Regulation, below.
C3.3.2 Apply markings or other means of identification to the derivatively classified material as required by Chapter 5 of this Regulation.
C3.3.3 Use only authorized sources of instructions about the classification of the information in question. Authorized sources of instructions about classification are security classification guides, other forms of classification guidance, and markings on material from which the information is extracted. The use of only memory or "general rules" about the classification of broad classes of information is prohibited.
C3.3.4 Use caution when paraphrasing or restating information extracted from a classified source document to determine whether the classification may have been changed in the process.
C3.3.5 Take appropriate and reasonable steps to resolve doubts or apparent conflicts about the classification, level of classification, and duration of classification of information.
These steps may include consulting a security classification guide or referral to the organization responsible for the original classification. In cases of apparent conflict between a security classification guide and a classified source document about a discrete item of information, the instructions in the security classification guide shall take precedence.
C3.4. General
C3.4.1 Derivative classifiers must carefully analyze the material they are classifying to determine what information it contains or reveals and evaluate that information against the instructions provided by the classification guidance or the markings on source documents.
C3.4.2 Drafters of documents that must be derivatively classified should be encouraged to portion mark their drafts and keep records of the sources they use, to facilitate derivative classification of the finished product.
C3.4.3 Declassification instructions for derivatively classified documents shall not be automatically copied from source documents. They must be determined as required by Chapter 4, and applied in accordance with Chapter 5 of this Regulation.
C3.4.4 When material is derivatively classified based on "multiple sources" (more than one security classification guide, classified source document, or combination thereof), the derivative classifier must compile a list of the sources used. A copy of this list must be included in or attached to the file or record copy of the document.
C3.5 Special Cases
C3.5.1 If information is extracted from a document or section of a document classified by compilation, the derivative classifier will consult the explanation on the source document to determine the appropriate classification. If that does not provide enough guidance, the originator of the source document should be contacted for assistance.
C3.5.2 If the derivative classifier has reason to believe the classification applied to information is inappropriate; the classifier of the source document shall be contacted to resolve the issue. The information will continue to be classified as specified in the source document until the matter is resolved.
C3.5.3 If the activity originating the classified information no longer exists, the activity that inherited the functions of the originating activity is responsible for determining the action to be taken with respect to declassification. If the functions of the originating activity were dispersed to more than one other activity, the inheriting activity(ies) cannot be determined or, the functions have ceased to exist, the senior agency official of the DoD Component of which the originating activity was a part, is responsible for determining the action to be taken with respect to classification.
C4. CHAPTER 4. MARKINGS
C5. CHAPTER 5. SAFEKEEPING AND STORAGE
C5.1 STORAGE AND STORAGE EQUIPMENT
C5.1.1 SAFES. The user of the safe will inform the Security Office of the location of the safe and the JITC control number.
Part 1 of SF 700, Security Container Information, will be attached to the inside of the combination dial drawer. Part 2 and 2A of SF 700 will be marked with the highest classification and delivered to the Security Office for storage.
C5.1.2 Anyone discovering a safe unsecured will safeguard the material by locking the safe and contacting the security office.
If after duty hours, contact the security cell phone. Under no circumstances will anyone depart without being properly relieved by the security personnel.
C5.1.2 TEMPEST AREA. The government point of contact (GPOC) will provide an e-mail request to the Security Office for personnel requiring access and or combination/alarm codes to the vault area. Request will contain name, social security number (SSN), floor number, beginning and ending dates, justification, and type of access. If ending date cannot be determined, the GPOC will notify the Security Office when access is no longer required.
C5.1.2.2 Authorized personnel will receive a briefing from the Security Office prior to being granted access.
C5.1.2.3 Personnel discovering the vault unsecured will notify the Security Office or pager immediately. Under no circumstances will anyone depart without being properly relieved by security personnel.
C5.1.3 CUSTODIAL PRECAUTIONS. When documents are removed from classified storage files, an Optional Form 23: Charge out Record, will be completed and will replace the document(s) when temporarily removed. When the documents are returned, the individual’s name will be lined out and the form stored for future use.
C5.1.3.1 Classified Meetings/Conferences
C5.1.3.1.1 The Portfolio Manager / Division Chief will appoint a sponsor to serve as POC for the classified meeting/conference.
C5.1.3.1.2 The sponsor is responsible overall for the classified meeting/conference.
C5.1.3.1.3 Entrance into the meeting/conference will be controlled and clearance verified at the entrance door prior to the classified meeting/conference.
C5.1.3.1.4 The sponsor will receive a briefing from the Security Office prior to the meeting/conference.
C5.1.3.1.5 All entrances will be clearly marked to indicate a classified meeting/conference is in progress.
C5.1.3.1.6 The sponsor will provide a list of attendees to the Security Office at least 5 working days prior to the meeting/conference. The Security Office will verify clearances and return the list to the government POC. Only cleared personnel with the need-to-know will be authorized into the meeting/conference room.
C5.1.3.1.7 Once the classified meeting/conference commences, the door(s) will be locked or monitored to ensure only cleared personnel with the need-to-know enters.
C5.1.3.1.8 In the event of an emergency during a classified meeting/conference, every effort will be made to secure all classified material. However, the safety of personnel will be the first consideration. If classified material is unable to be secured, a list of the unsecured classified material will be provided to the Security Manager as soon as possible. A complete inventory will be conducted upon return to the meeting/conference and any discrepancies will be reported to the security office immediately.
C5.1.3.2 The Security Office is responsible for
C5.1.3.2.1 Providing guidance and assistance to the department in developing and planning security measures.
C5.1.3.2.2 Monitoring meetings/conferences to ensure compliance with established security measures.
C5.1.3.2.3 Processing requests concerning the attendance of foreign nationals and advising of approval or disapproval of the request.
C6. CHAPTER 6. COMPROMISE OF CLASSIFIED INFORMATION
Refer to DISAI 240-11-8
C7. CHAPTER 7. ACCESS, DISSEMINATION, ACCOUNTABILITY,
AND REPRODUCTION
Section A. ACCESS
C7.1 Restrictions on Access (Ch 7, Sec A) (Added)
C7.1.1 Security clearance shall be verified through the Security Office prior to releasing or discussing classified information.
C7.2 Access by Foreign Nationals, Foreign Government, and International Organizations (Ch 7, Sec A) (Added)
C7.2.1 Access to classified information will not be granted without the approval of the Security Office.
C7.3 Access by Visitors (Ch 7, Sec A) (Added)
C7.3.1 All visitors will have a valid visit request on file prior to being granted access to classified information.
C7.3.2 Foreign Visits
C7.3.2.1 All foreign visit requests must be processed by DIA and DISA and will be referred to the JITC Security Office for appropriate action.
C7.3.2.2 Foreign visitors (excluding Foreign Exchange Officers, and green card/U.S. work visa holders who represent a U.S. firm) who anticipate visiting JITC will initiate the action through their embassy. Foreign Exchange Officers and foreign visitors who possess a valid green card or U.S. work visa representing a U.S. firm will have a valid visit request on file prior to visiting JITC.
C7.3.2.3 The Project Manager will inform the Security Office of all anticipated foreign visits as soon as they are aware and complete a foreign visit notification form and return it to the Security Office.
C7.3.2.4 No foreign visitor will be granted access to classified information and no classified document will be released unless approved by the DISA and JITC Security Offices.
C7.3.2.5 With the exception of assigned officials of a foreign government who serve as fully integrated members of JITC (Foreign Exchange Officers), foreign visitors will be escorted at all times.
C7.3.2.6 Once a foreign visit has been approved, no changes will be made without prior approval from the JITC Security Office.
C7.3.2.7 Integrated Personnel
C7.3.2.7.1 Detailed job descriptions shall be prepared by each Division Chief for those positions to which integrated personnel are assigned.
Section B. ACCOUNTABILITY AND CONTROL
C7.4 Secret and Confidential Classified Material (Ch 7, Sec C) (Added)
C7.4.1 The JITC Automated Classified Document Register (ACDR) will reflect the disposition of all Secret and Confidential material within JITC.
C7.4.2 All Secret and Confidential classified material, to include classified NATO, will be processed through the Security Office and assigned a JITC control number.
C7.4.3 All unclassified NATO material will be processed through the Security Office.
C7.4.4 Internal Controls:
C7.4.4.1 The Classified Document Custodian will:
C7.4.4.1.1 Receive the classified material and electronically accept receipt of it as soon as they are notified but not later than close of business the same day.
C7.4.4.1.2 Update the ACDR to reflect current status of the document.
C7.4.4.2 The Project/Lab Manager will:
C7.4.4.2.1 Verify clearance and need-to-know prior to routing classified material.
C7.4.4.2.2 Coordinate with the Classified Document Custodian prior to routing the document.
C7.4.4.2.3 Ensure the document is returned when no longer needed but not later than the closure of the designated project.
The Project Manager will properly store or destroy the material and inform the Security Monitor of such.
C7.5 Restraint on Reproduction (Ch 7, Sec C) (Added)
C7.5.1 Request for classified reproduction will be processed through the Project Manager and Security Monitor prior to the approval of the approving officials.
C7.5.2 All copies will be marked to reflect copy number and total number of copies reproduced, i.e., COPY 01 of 04, 02 of 04, etc..
C7.5.3 All copies will be delivered to the Security Office and processed in accordance with the procedures outlined in section B of this chapter.
C7.5.4 If copies are assigned the same control number as the original, the Security Monitors will annotate the remarks column of the ACDR to reflect the disposition of each copy.
C7.5.5 The copiers in the mailroom are the only copiers authorized for the reproduction of classified information.
Copiers authorized for the reproduction of classified material will bear a label indicating the highest level of reproduction authorized. Copiers not authorized for classified reproduction will display the DISA Form 205 or other appropriate label.
C7.6 Facsimile Machine Controls (Ch 7, Sec C) (Added)
C7.6.1 The facsimile machine located in building 57305, room 110 (Security Office), is the only machine authorized for the transmittal and reception of Secret and Confidential information. Prior arrangements must be coordinated with the Classified Document Manager.
C7.6.1.1 All incoming classified faxes will be assigned a JITC control number and electronically transferred to the appropriate Classified Document Custodian. The Classified Document Custodian will provide an electronic receipt for the incoming classified fax and annotate the remarks column of the ACDR to reflect current disposition.
C7.6.1.2 All outgoing classified faxes will be assigned a JITC control number prior to being transmitted. The Classified Document Manager will annotate the ACDR with the addressee’s name, address, fax number, and phone number.
C7.6.2 The Project/Lab Manager will submit a completed Secure Facsimile Header Sheet with the classified material to be faxed.
C7.6.3 Classified material will only be received and transmitted during normal duty hours.
C8. CHAPTER 8. TRANSMISSION
Section A. METHODS OF TRANSMISSION OR TRANSPORTATION
C8.1 Policy (Ch 8, Section A) (Added)
C8.1.1 All Secret and Confidential material being transmitted outside of JITC will be processed through the Lab/Project Manager, the Classified Document Custodian, and the Classified Document Manager. The Classified Document Custodian will annotate the remarks section of the Automated Classified Document Register (ACDR) to reflect method of transmission;
recipients name, address, telephone number; and accountable mail control number. The Classified Document Custodian will also transfer the material to the OUT file of the ACDR. Classified material will be transmitted as accountable mail and will be delivered to the JITC mailroom.
C8.1.2 Federal Express (FEDEX) may be used for the transmission of all collateral Secret and Confidential material in the Continental United States (CONUS) and shall be used only when it is the most cost effective way to meet a program requirement, given time, security and accountability restraints.
C8.1.2.1 All material prepared for FEDEX should be delivered to the JITC mailroom and personally given to the mail clerks.
Packages over 70 pounds require coordination with mailroom personnel. Material will be mailed via FEDEX only Monday through Thursday.
C8.1.2.2 Any problems encountered with the use of FEDEX are to be reported to the Security Office as soon as possible.
C8.1.2.3 All FEDEX packages must be safeguarded as classified until it is determined that it is not. FEDEX packages that contain classified material will be processed through the Security Office.
Section B. PREPARATION OF MATERIAL FOR TRANSMISSION, SHIPMENT, OR CONVEYANCE
C8.2 Receipt Systems (Ch 8, Section B) (Added). The Project Manager will generate three copies of DA Form 3964. Two copies will accompany the classified material and one copy will be maintained in the Project Managers suspense file. A tracer will be initiated if no receipt has been received within 30 days and the Project Manager will inform the Security Office of the same.
Section C. RESTRICTIONS ON HAND-CARRYING CLASSIFIED INFORMATION
C8.3 General Restrictions (Ch 8, Section C) (Added). All requests for hand-carrying classified information will be processed by the Project Manager through the Security Office.
C9. CHAPTER 9. DISPOSAL AND DESTRUCTION
C9.1 Policy (Ch 9) (Added)
C9.1.1 Destruction:
C9.1.1.1 Personnel destroying classified material will utilize Section C - Destruction Certificate, DA Form 3964 to annotate the destruction of all CONFIDENTIAL and above (to include NATO classified) material. The DA Form 3964 will be filed IAW, Chapter 1, DCAI 210-15-6, Records Management. The Automated Classified Document Register must be updated accordingly.
C9.1.1.2 Personnel destroying classified material will inform the Classified Document Custodian of all material destroyed.
C9.1.1.3 The use of privately owned vehicles is not authorized to transport classified material to the classified destruction facility located at Greely Hall.
C9.1.1.4 For large volumes of classified material for destruction, contact the classified destruction facility at 538-6310 to make an appointment. JITC has a Disintegrator approved for classified. Contact the JITC Service Desk to schedule an appointment, 538-5313.
C10. CHAPTER 10. SECURITY EDUCATION
C11. CHAPTER 11. FOREIGN GOVERNMENT INFORMATION
C11.1 NATO Classified Information (Ch 11, Section D) (Added)
C11.1.1 Personnel must be NATO briefed prior to having access.
Request for access to NATO information will be confined to those essential to accomplish the assigned mission. Division Chiefs will provide written justification to the Security Manager for granting personnel access to NATO material. Justifications will include full name, rank or grade, Social Security Number (SSN), and position title. Division Chiefs will also provide written notification to the Security Manager when access is no longer required. Personnel no longer requiring access to NATO material will be debriefed. DA Form 2543, Briefing/Rebriefing/Debriefing Certificate will be used for briefing and debriefing personnel.
C11.1.2 Contractors who require access to NATO material will contact their respective Facility Security Officer (FSO) for NATO briefings.
C11.1.3 NATO RESTRICTED. The U.S. does not have a security classification equivalent to NATO RESTRICTED. The material will be safeguarded in a manner that shall prevent disclosure to nongovernmental personnel.
C12. CHAPTER 12. SPECIAL ACCESS PROGRAM
C13. CHAPTER 13. PROGRAM MANAGEMENT
Section A. JITC INDIAN HEAD (IH)
C13.1 General Management (Ch 13, Section C) (Added). The Division Chief, JITC Business Management Division (JT2), shall establish and maintain an Information Security program designed to ensure compliance with the provisions of this Instruction.
C13.2 Program Monitorship (Ch 13, Section C) (Added). The JITC Security Manager is responsible for monitoring, inspecting, and conducting staff assistance visits, announced/unannounced, at JITC IH.
C13.3 Program Management (Ch 13, Section C) (Added)
C13.3.1 The Division Chief, JITC JT2, shall appoint, in writing, an official to serve as a Security Monitor. A copy of the appointment will be forwarded to JITC Security Manager.
This official shall be responsible for the administration of an effective security program.
C13.3.2 Appointing authority shall provide sufficient resources of time and funds to permit accomplishment of the Security Monitor’s responsibilities, to include meaningful oversight of the Information Security program at all levels of the activity.
C13.3.3 Appointed Security Monitor will:
C13.3.3.1 Serve as a focal point for all security matters.
C13.3.3.2 Conduct annual self-inspections.
C13.3.3.3 Ensure proper clearance and the need-to-know is verified before the distribution of classified information.
C13.3.3.4 Prepare a Standard Operating Procedure (SOP) for unique situations which have not been addressed in this Instruction. The SOP will be submitted to the JITC Security Manager for approval before implementation.
C13.3.3.5 Ensure all briefings are conducted and filed IAW DODI 210-15-6.
C13.3.3.6 Report any security weaknesses, incidents, or violations to the JITC Security Manager.
C13.3.3.7 Manage courier authorization program.
C13.3.3.8 Ensure DD Forms 1610, Request and Authorization for TDY Travel of DOD Personnel, are processed through security when hand carrying classified information.
C13.3.3.9 Conduct oversight reviews of their area (normal and after duty hours).
C13.3.3.10 Ensure periodic security awareness training.
C13.3.3.11 Prepare and transmit visit notifications.
C13.4 The above duties are not inclusive and a common sense approach must be exercised to implement and enforce a sound security program.
C14. CHAPTER 14. ADMINISTRATIVE SANCTIONS
C15. CHAPTER 15. INFORMATION SYSTEMS
C15.1 Additional Security Controls (Ch 15, Section D) (Added)
C15.1.1 Physical Security
C15.1.1.1 Information Systems (IS) processing classified information will be properly safeguarded at all times.
C15.2 Accountability, Marking, and Control of IS Media.
C15.2.1 Accountability and control of media shall be consistent with the highest level of national security information ever recorded on the media and shall maintain its original JITC control number, until the information on the media, or the media itself, is declassified or wiped cleaned using an approved software. All wiped and declassified media will be certified by the Information Systems Security Officer (ISSO).
C15.2.2 All floppy disk and optical type media will be destroyed vice wiped or declassified.
C15.2.3 All declassified, wiped, or destroyed media will be reported to the appropriate Classified Document Custodian.
C15.2.4 The classified Document Custodian will annotate the remarks section of the Automated Classified Document Register with the date, ISSO’s name, and appropriate action taken and transferred to the OUT file.
| P.O. BOX 4502 |
| BASIC INSTRUCTIONS |
| C3. CHAPTER 3. DERIVATIVE CLASSIFICATION |
File details come from the government source that posted it. Updated .