Bidders Library Security - DISAI 240-110-33.pdf
PDF 357 KB Posted
- Attached to
- TEC II Services RFP Federal contract opportunity
- Solicitation number
- HC102821R0006
- Issued by
- Defense Information Systems Agency
About this file
This document summarizes a federal agency's solicitation for test, evaluation, and certification services. The Defense Information Systems Agency is seeking proposals to provide Joint Interoperability Test Command services, including testing, evaluating, and certifying systems to ensure interoperability. Proposals are due by the date specified in solicitation number HC102821R0006. Interested parties should review the full solicitation for detailed requirements, response instructions, and additional terms.
View the file
Other files for this federal contract opportunity
Show all 50
TEC II Services RFP has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DEFENSE INFORMATION SYSTEMS AGENCY
P. O. BOX 549
FORT MEADE, MARYLAND 20755-0549
DISA INSTRUCTION 240-110-33*
SECURITY
Physical Security
1. Purpose. This Instruction prescribes policy and assigns responsibilities and duties for physical security. It advises of training for physical security, exercises and drills.
It also provides guidance on physical security self-assessments, physical security plans (PSPs), identification (ID) cards and badges, entry and exit inspections (E&EIs), and collateral open storage areas (COSAs).
2. Applicability.
2.1 This Instruction applies to areas and facilities physically controlled or managed by DISA, DISA activities that are tenants on other government installations, DISA occupied leased facilities located outside a DoD installation, and areas located within DISA facilities that are manned or operated by non-DISA organizations or contractors supporting a DISA project.
2.2 This Instruction does not apply to the operation of any sensitive compartmented information facilities (SCIFs) within DISA, as SCIF operations are mandated by DoD Manual 5105.21-M, Volume 2, Sensitive Compartmented Information (SCI) Administrative Security Manual:
Administration of Physical Security, Visitor Control, and Technical Security.
3. Authority. This Instruction is published in accordance with the authority contained in DoD Regulation 5200.08-R, Physical Security Program, April 2007; DoD Manual 5200.01-M, Volume 3, DoD Information Security Program: Protection of Classified Information, 24 February 2012; and Homeland Security Presidential Directive (HSPD) - 12, Policy for a Common Identification Standard for Federal Employees and Contractors, 27 August 2004.
This Instruction also derives limited authority from Committee on National Security Systems Instruction (CNSSI) 7003, Protected Distribution System (PDS), September 2015, and CNSSI 500, Guidelines for Voice over Internet Protocol (VoIP) Computer Telephony, April 2007.
4. Definitions. Definitions of "physical security" and "security-in-depth" follow; additional definitions are provided in enclosure 1.
4.1 Physical Security. Part of security concerned with physical measures designed to safeguard personnel; to prevent unauthorized access to equipment, installations, material, information, and documents; and to safeguard them against espionage, sabotage, damage, inadvertent disclosure, and theft.
DISAI 240-110-33
4.2 Security In-Depth. A determination by the Senior Agency Official (SAO) that a facility's security program consists of layered and complementary security controls sufficient to deter, detect, and document unauthorized entry or movement within the facility, as well as leveraging communication technology to limit the transmittal of information to persons who do not have a need to know; i.e., the incorporation of directional versus omnidirectional microphones.
Examples of complementary security controls that mitigate known vulnerabilities include, but are not limited to, the use of perimeter fences, employee and visitor access control systems (ACSs), intrusion detection systems (IDSs), onsite security forces, communication devices, and closed circuit video monitoring.
5. Policy.
5.1 Measures and procedures will be employed by DISA that are necessary to safeguard its personnel, all information, its physical infrastructure and property, and any other resources determined to be essential to mission assurance. These measures will include, but are not limited to, the use of access control devices and systems, appropriately equipped security forces, physical barriers, IDSs, communication restriction devices, and surveillance systems.
5.2 Periodic assessments, program reviews, and inspections will be used to ensure prescribed policies and procedures are in compliance with DoD, appropriate combatant command, and DISA-specific guidance.
5.3 Standardized physical security measures and procedures will be implemented throughout DISA in order to streamline intra-Agency visits, access control interoperability, entry control designs, and security operation for common facilities throughout the Ecosystem.
5.4 Access to identification or authorizing data, operating system software, or any identifying data associated with the electronic security system (ESS) shall be limited to the minimum number of personnel possible, while maintaining the two-person integrity rule, where applicable.
The ESS shall not be utilized for manpower or timekeeping purposes without written authoriza-tion from the Chief of Security and Counterintelligence Division (MP6). A request for ESS data must include justification and reason for the request.
5.5 Restricted area warning signs will be posted conspicuously near the access points of all secure areas where national security systems (NSSs) are located and classified information is stored, processed, produced, viewed, or shared; i.e., verbally or on a storage media.
5.6 Telephone systems used in areas where classified or sensitive information may be discussed, to include all open storage areas, must be equipped with off-hook audio protection through the use of a hold feature, modified handset (i.e., push-to-talk), or equivalent.
5.6.1 Speakerphones and audio conferencing systems are not approved for use on unclassified telephone systems in a COSA. Telephone systems used in closed private offices within a COSA may have speakerphone capability enabled. However, when the speakerphone is in use, measures must be taken to limit inadvertent disclosure of discussed information; i.e., close the office doors and be mindful of conversation levels and its classification within the host office.
These measures will ensure classified or sensitive information being discussed is not inadver-tently compromised by those who do not have a legitimate need to know.
5.6.2 A request for an exception to the requirements in subparagraph 5.6.1 may be submitted to the Security Division (MP6) for consideration. A request must include the justification as to why speakerphones are required, how many speaker phones are needed to be enabled to meet mission requirements, why other means can not be used to accomplish the mission, certification from the site security manager that sufficient audio isolation can be maintained from other classified discussion areas in the COSA when the speakerphones are in use, and a standard operating procedure (SOP) for the use of the speakerphone in the COSA.
5.7 Built-in or detachable camera systems that can be used on a computer desktop system or laptop system may be used within a COSA closed private office to conduct or participate in a DCS (Defense Collaboration Services) or GVS (Global Video Services) video conference.
When the camera system is not being used, it must be detached from the computer system, if possible, or the lens of the camera must be covered with a nontransparent material (i.e., tape or sticker) to prevent inadvertent compromise through remote or accidental activation of the camera.
5.8 DISA-owned and -operated access control systems (ACSs) across the DISA area of responsibility (AOR) shall be operationally compatible with the ESS being used at DISA headquarters (HQ), which will facilitate the use of one DISA ID card or badge to gain access to all DISA-operated sites. All new installations or system upgrades of an ACS must be both compatible with the ESS being used at DISA HQ and compliant with HSPD-12 (authority document).
5.9 This Instruction will not nullify the authority or responsibility of commanders and directors to apply more stringent physical security standards required during emergencies, increased threat level, or high risk determinations.
6. Responsibility.
6.1 Directors, Executives, Commanders, and Chiefs of Major Organizational Elements.
These individuals will:
6.1.1 Oversee and provide operational guidance on all physical security areas that are under their control.
6.1.2 Appoint, in writing, qualified individuals to manage the physical security of their assigned organization or geographic site (e.g., Security Managers).
6.1.3 Ensure resources are available to fully implement all measures and procedures applicable to physical security throughout an assigned AOR.
6.1.4 Ensure all sites and facilities within their AOR have established, trained, and exercised the measures and procedures set forth in their site-specific PSP(s).
6.1.5 Ensure a thorough risk and vulnerability assessment is conducted and updated at least annually and appropriate courses of action for mitigation are reflected within the PSP(s).
6.2 Chief of Security and Counterintelligence (MP6). The Chief, MP6, located in the Workforce Service Directorate (WSD), is the Senior Agency Official (SAO) for the interpre-tation of any guidance in this Instruction or the general security guidance in DoD Regulations, Instructions, or Manuals, as they apply to operations in the DISA AOR.
7. Duties. Overall duties are assigned as follows; specific duties are assigned in the enclosures.
7.1 Chief of Security Programs and Oversight (MP61). The Chief, MP61, located in the Security Division (MP6), will:
7.1.1 Provide expert guidance in the interpretation and implementation of regulations, policies, and procedures relative to physical security.
7.1.2 Serve as or appoint a representative to be the COSA Program Manager for COSAs operated by DISA.
7.1.3 Serve as the approving official for granting physical security waivers within the
DISA AOR.
7.1.4 Provide oversight of DISA security programs and initiatives that enable or enhance the effective implementation of Agency-wide physical security .
7.1.5 Ensure all legal concerns are addressed before implementation of any physical security measure or procedure.
7.2 Physical Security Program Manager. The Physical Security Program Manager, located in the Security Division (MP6) Security Programs and Oversight Branch (MP61), will:
7.2.1 Serve as a physical security subject matter expert for the Agency on collateral concerns.
7.2.2 Monitor and assess the overall effectiveness of the Agency's physical security posture and establish recommendations and guidance to ensure mission assurance.
7.2.3 Assist with the development of and assess semiannual physical security exercises conducted by DISA controlled sites.
7.2.4 Conduct or oversee program reviews and assistance visits to field sites, as needed, to ensure all mandated physical security protocols are being followed.
7.3 Security Manager. A Security Manager will:
7.3.1 Be familiar with and enforce the guidance in this Instruction and existing DoD and DISA policies, as well as articulate the intent of the guidance to the organization's command staff and workforce.
7.3.2 Identify, list, and include all DISA mission essential vulnerable areas (MEVAs) within the organization's PSP, ensuring measures and procedures to protect those areas are tailored to their criticality to the mission and the availability of organizational resources.
7.3.3 Monitor and assess the physical security measures and procedures implemented throughout the assigned organization and recommend enhancements, as needed.
7.3.4 Work with the chain of command to ensure physical security issues and concerns are addressed and mitigated within 10 days of discovery (immediately for critical issues), while providing situational awareness to the appropriate leadership and decision makers (e.g., assigned organizational Commander or Director; Physical Security Program Manager; Chief, Security Programs and Oversight Branch [MP61]; and Chief of Security and Counterintelligence [MP6]).
7.3.5 Identify and track the resolution of physical security concerns in the organization's AOR and ensure all issues unresolved at the organizational level are directed to the Physical Security Program Manager for resolution assistance.
7.3.6 Conduct semiannual physical security exercises that test the effectiveness of the site's PSP.
7.3.7 Conduct, at a minimum, an annual physical security self-assessment at the organizational or geographic site level to achieve and maintain situational awareness and program compliance.
7.3.8 Ensure all contractors assigned to their AOR are briefed on all site-specific security policies and procedures prior to granting their contractual access.
7.4 Civilian Employees, Military Members, and Contractors. Duties are assigned as follows; specific duties with respect to ID cards and badges are assigned in enclosure 4.
These individuals will:
7.4.1 Be familiar and comply with the physical security measures and procedures outlined in this Instruction, as well as SOPs and DISA-specific policies that enhance the physical security posture of the DISA AOR.
7.4.2 Maintain awareness of the physical security elements (i.e., doors, windows, locks, turn styles, access control procedures, common communication devices, etc.) in and around DISA facilities and report any nonfunctioning or inadequate elements to a security manager, security officer, or member of the chain of command.
8. Training. Nominated and assigned Security Managers (primary and alternate) shall receive initial training within the first 6 months of nomination and refresher training every 2 years thereafter, at a minimum. This training will include DISA-specific physical security training along with other security discipline specific training. In order to achieve and maintain proficiency in this security discipline, continuing education is encouraged. Courses are offered by the Center for Development of Security Excellence (CDSE) (www.cdse.edu) and are recommended to Security Managers and any employee seeking a greater understanding of DoD's physical security methodologies, practices, and implementation. (The courses are delineated at www.dss.mil.)
9. Exercises and Drills. Exercises and drills that test the effectiveness and validity of PSPs, policies, and procedures are mandatory, in accordance with the appropriate DoD Instruction or Directive. After action reviews or reports (AARs) documenting the conduct and results of all physical security exercises and drills will be kept on file by the site Security Manager for a minimum of 2 years. (DISA elements that are imbedded in a host organization or facility [i.e., DISA HQ, DISA Special Operations Command (SOCOM), etc.] and do not have primary responsibility for facility access control, emergency response, or testing of the facility ESS are not required to conduct physical security exercises that test those functions.
However, those DISA elements are required to ensure their organization's personnel are familiar with all existing physical security standards and practices of the host organization.)
10. Contents. Guidance on physical security self-assessments, PSPs, ID cards and badges, E&EIs, and COSAs is provided in enclosures 2 through 6.
6 Enclosures a/s BRADLEY W. BARNHART
Colonel, USAF Chief of Staff
SUMMARY OF SIGNIFICANT CHANGES. This revision includes policy direction on the posting of restricted area warning signs, off-hook audio protection on telephone systems in areas where classified or sensitive information may be discussed, and built-in or detachable camera systems that can be used on a computer desktop system or laptop system. It includes specific duties for critical personnel. It provides guidance on the mitigation of vulnerabilities inherent to wireless devices, telephone communication systems, devices equipped with microphones, and the authorized confiscation of prohibited items in secure spaces. It provides updated and additional guidance on collateral open storage area (COSA) administration, access control protocols, and personnel positive identification measures. Text in enclosure 4 that pertained to the use of multiple primary DISA-specific identification (ID) badges has been removed, as the common access card (CAC) is the primary ID badge now used throughout the DISA area of responsibility (AOR).
*This Instruction replaces DISAI 240-110-33, 16 August 2016.
OPR: WSD - disa.meade.mps.mbx.mps-front-office@mail.mil DISTRIBUTION: Y - DISA Workforce Internal Use Only
Enclosure 1
DEFINITIONS
Access Control. Prevention of entry to buildings and systems by unauthorized personnel.
Authority to enter areas are authenticated through the use of an identification (ID) badge or card.
Common Access Card (CAC). Identification (ID) card used for access to DISA facilities and computer systems.
Collateral Information. All national security information (NSI) classified confidential, secret, or top secret under the provisions of an Executive order for which special systems of compart-mentation (such as, sensitive compartmented information [SCI] or special access program [SAP]) are not formally required.
Collateral Open Storage Area (COSA). An area constructed in accordance with the require-ments of the Appendix to Enclosure 3 of DoDM 5200.1, Volume 3, and authorized by the Senior Agency Official (SAO) for the open storage of national security information (NSI) classified either confidential, secret, or top secret under the provisions of an Executive order for which special systems of compartmentation (such as, sensitive compartmented information [SCI] or special access program [SAP]) are not formally required.
Controlled Access Area (CAA). The complete building or facility area under direct physical control within which unauthorized persons are denied unrestricted access and are either escorted by authorized persons or are under continuous physical or electronic surveillance.
Electronic Security System (ESS). That part of physical security concerned with safeguarding of personnel and property by use of electronic systems. These systems include, but are not limited to, intrusion detection systems (IDSs), automated entry control systems (AECS), and video assessment systems.
Escorting. The assignment of an individual(s) with a proper security clearance to obtain and maintain positive control of any individual(s) who has been granted accompanied access to a DISA controlled area.
Joint Personnel Adjudication System (JPAS). A DoD system conceived to standardize the adjudication process within DoD, provide an improved database and processes within the security manager realm of functions, and allow better communication between the central adjudication facility (CAF) and the security personnel in the field who actually give cleared individuals access to classified information. JPAS consists of two separate and distinct subsystems: Joint Adjudication Management System (JAMS), used at the CAF, and Joint Clearance and Access Verification System (JCAVS), used by security personnel in the field.
CAF personnel enter information and clearance eligibility determinations into JAMS allowing field security personnel to view the CAF actions in JCAVS and perform a myriad of functions like grant/withdraw access, visit requests, initiate investigations, in/out processes, etc.
Personal Identity Verification (PIV) Card. A physical artifact (e.g., identity card or "smart" card) issued to an individual that contains stored identity credentials (e.g., photograph, crypto-graphic keys, and biometric data) so that the claimed identity of the cardholder can be verified against the stored credentials by another person (human readable and verifiable) or an automated process (computer readable and verifiable).
Protective Distribution System. Wireline or fiber-optic distribution systems used to transmit unencrypted classified national security information (NSI) through an area of lesser classification or control.
Secure Space. A building, facility, or controlled area (whether permanent, temporary, or mobile) that meets all of the following criteria: (1) contains National Security Systems (NSS);
(2) is operated by a United States Government (USG) Department or Agency, U.S. or Allied Military Command, an appropriately cleared contractor, or a State, Local, or Tribal government;
(3) is protected at a level commensurate with the classification or sensitivity of the information that is processed, stored, used, or discussed therein; (4) falls under the responsibility of a Cognizant Security Authority (CSA) or Senior Agency Official responsible for ensuring the physical and technical security of the space; and (5) is not an accredited sensitive compart-mented information facility (SCIF) or special access program facility (SAPF).
Senior Agency Official (SAO). An official appointed by the Head of a DoD Component to be responsible for direction, administration, and oversight of the Component's Information Security Program, to include classification, declassification, safeguarding, and security educa-tion and training programs, and for the efficient and effective implementation of the associated DoD regulations, instructions, manuals, and policies.
United States Government (USG) Managed Mobile Device. A mobile device under the control and management of a USG enterprise system (i.e., Mobile Device Management, Enterprise Mobility Management, Active Directory, etc.) capable of enforcing and monitoring security controls and configuration settings and in compliance with the minimum standards of a Department or Agency. (A non-USG managed mobile device does not meet the definition of a USG managed mobile device.)
Enclosure 2
PHYSICAL SECURITY SELF-ASSESSMENT
1. General. An annual physical security self-assessment shall be conducted of an area of responsibility (AOR) by DISA organizations that are geographically separated from the DISA headquarters (HQ) campus located at Fort George G. Meade, Maryland. This assessment will serve to ensure all applicable physical security measures and procedures are being implemented and enforced. DISA organizations that are colocated within the DISA HQ complex are not required to complete this assessment, as the assessment is conducted annually by the Security Division (MP6). A checklist is to be used to conduct the physical security self-assessment.
The checklist is located on the DISA Security (MP6) Home Page on the DoD Enterprise Portal Services (DEPS). (Click on "Branches" and, on the drop-down menu, click on "Physical Security" and scroll down to "DISA Physical Security Self-assessment Checklist.")
2. Objective. A physical security self-assessment will serve to evaluate the overall status of the physical security of an organization and to provide the organization's leadership with situational awareness of the physical security of the organization. The assessment can also be requested and used by the Security Division (MP6) to assist with the evaluation of the Agency's overall physical security environment.
3. Applicability. The conducting of physical security self-assessments applies to all facilities and installations for which DISA has command and control (C2) responsibilities. Appropriate check measures will also be considered for all sites that have a DISA presence but do not have C2 responsibilities. (These measures will ensure adequate situational awareness of security protocols, regardless of ownership.)
4. Duties.
4.1 Physical Security Program Manager. The Physical Security Program Manager will:
4.1.1 Ensure the physical security self-assessment remains up to date to reflect current opera-tions and its content provides the framework for an appropriate assessment of DISA critical physical security measures and procedures.
4.1.2 Keep a file copy of completed annual physical security self-assessment checklists for each DISA site.
4.1.3 Use the site-specific physical security self-assessments to prioritize site assistance visits and higher HQ formal assessments of DISA elements.
4.1.4 Formulate corrective courses of action (COAs) for all major physical security deficiencies noted within 30 days of discovery, track the corrective progress until completion, and keep a record of deficiencies and corrective actions on file. (Records will assist with tracking and addressing security trends throughout DISA.)
4.2 Security Manager. A Security Manager will:
4.2.1 Conduct a physical security self-assessment of their AOR at least annually and provide a completed copy to the Security Division (MP6) within 30 days of completion.
4.2.2 Initiate corrective actions for any items on the checklist that are not in compliance with current policy, instructions, or regulations and provide a summary of corrective actions taken to the Security Division (MP6) within 30 days of implementation.
4.2.3 Ensure the site commander or director is kept informed of the outcome of all security assessments preformed on their AOR.
5. Recordkeeping. A copy of all self-assessments will be maintained for a minimum of 2 years.
A copy of a self-assessment may also be requested by the Security Division (MP6) to keep on file at DISA HQ.
Enclosure 3
PHYSICAL SECURITY PLAN (PSP)
1. General. The strategic strength of a physical security plan (PSP) is the first line of defense for a DISA site, resource, its personnel, or property. Elements of a PSP must be fully resourced and executable by the organization for which it was developed. All DISA elements with command and control (C2) responsibilities for their area of responsibility (AOR) are required to establish, train, and exercise the measures and procedures set forth in their PSP(s). Physical security measures and procedures do not have to be captured in one consoli-dated plan. Commonly, these measures and procedures may be captured in other plans; such as, the Antiterrorism and Force Protection (AT/FP) Plan, Occupant Emergency Plan, etc. As long as all required elements are established in some AOR-specific plan, the minimum essential requirements will be considered satisfied.
2. Objective. A PSP will ensure site-specific physical security measures and procedures have been developed to adequately provide DISA personnel with physical safeguards to mitigate the risks associated with the known and perceived threats in the AOR.
3. Applicability. The requirement to establish, train, and exercise a PSP(s) applies to all facilities and installations for which DISA has C2 responsibilities. Measures will also be considered for all sites that have a DISA presence, to include critical and noncritical assets, regardless of ownership.
4. Duties.
4.1 Physical Security Program Manager. The Physical Security Program Manager will:
4.1.1 Provide needed assistance to all DISA elements requiring the development of their site-specific PSPs.
4.1.2 Maintain a copy of all PSPs for the DISA elements.
4.1.3 Establish collaborative processes with complementary security-related program managers to assess threat trends and available resources to determine appropriate implementation of physical security guidance within developed plans.
4.2 Security Manager. A Security Manager will:
4.2.1 Develop and maintain, to include updating, the site-specific PSP for their assigned AOR.
4.2.2 Provide an updated copy of their site-specific PSP to the Security Division (MP6) annually.
5. Minimum Essential Elements. Each site PSP should address the following elements. The questions after each element should be used to thoroughly address concerns and mission impact of the element during the planning and development of appropriate physical security measures and procedures. To ensure the PSP remains at or below the "For Official Use Only" handling caveat, specific mention of the actual threat of vulnerability to the AOR of concern will not be in the PSP. The location of specific details will only be referenced in the PSP, i.e., "This plan is designed to deter, detect, and protect the personnel and property at DECC Falcon against the threats and hazards identified in the host installation's threat assessment dated 12 March 20XX."
5.1 Threat Assessment.
What is the Designated Basic Threat (DBT), which is derived from the threat identified in the host installation or area local threat assessment?
5.2 Vulnerability Assessment.
What are the physical security measures and procedures that will be implemented to mitigate identified vulnerabilities to an asset to include mission areas and/or personnel?
5.3 Access Control Measures.
What type of access control measures are used at the specific site?
Who is responsible for maintaining the access control systems (ACSs)?
Where are the ACSs located?
What are the capabilities of the ACSs to control access to a specified area?
What are the installation and/or facility access control procedures and all access points and control measures?
5.4 Intrusion Detection Systems (IDSs).
Where is IDS required?
Who monitors the system and responds to alarms?
Who tests the system?
Where are test records kept?
5.5 Barrier Plan. (if appropriate)
Where will barriers be placed during elevated threats to enforce facility standoff?
Where will barriers be stored when not employed?
Who will place the barriers?
5.6 Escorting Procedures.
Who is responsible for providing escorts?
What procedures are in place for escorting visitors and potentially antagonistic employees in or out of the facility/site?
5.7 Emergency Evacuations.
What physical security actions must be executed during emergency evacuations?
What physical security actions must be executed after emergency evacuations?
5.8 Force Protection Conditions (FPCON) Transition Protocol.
What physical security actions must be executed to achieve each FPCON level?
Who is responsible for executing the physical security actions that must occur to achieve each FPCON level?
5.9 Mass Notification.
How is mass notification accomplished before, during, and after an emergency?
Who is responsible for initiating mass notification alert messages for the AOR?
5.10 Bomb Threat Response.
Who are the responders?
How are the responders contacted (phone contact lists, etc.)?
What are the telephonic response procedures?
What are the suspicious item/package response procedures?
5.11 Active Shooter Response.
Who are the responders?
How are the responders contacted (phone contact lists, etc.)?
What methods are available for mass notification?
What physical security procedures must be accomplished to mitigate the threat?
What are the lockdown, shelter, or evacuation procedures?
Enclosure 4
IDENTIFICATION (ID) CARDS AND BADGES
1. General. A personal identity verification (PIV) card is used by DISA to identify the personnel who have been granted access into a DISA occupied space. The PIV card (i.e., Common Access Card [CAC]) must comply with Federal Information Processing Standards (FIPS) Publication 201, which requires the use of a common identification standard for all Federal employees and contractors. The CAC is used by DISA as the standard means of personnel identification. DISA personnel occupying sites or facilities not controlled by DISA will comply with the access control measures of the host.
2. Objective. ID cards and badges provide a standardized protocol and easily recognizable method of identifying personnel and their eligibility to gain or be denied access to DISA space.
3. Applicability. ID cards and badges apply to all DISA assigned, contracted, and approved support personnel (i.e., supporting emergency responders and long-term liaisons to DISA), visitors, and authorized very important persons (VIPs).
4. Duties of Security Manager. A Security Manager will:
4.2.1 Ensure all personnel that have been granted access to a DISA controlled space have been issued a DISA-approved ID card, in accordance with the specific criteria.
4.2.2 Ensure all personnel with authorized access to a DISA controlled space have been briefed on the proper wearing and safeguarding protocols established for the permanent or temporary issued ID card.
4.2.3 Establish effective procedures, to include coordination with Contracting Officer's Representatives (CORs), to ensure all personnel issued a DISA ID card during in-processing (permanent or temporary) turn in the card when out-processing.
4.2.4 Ensure all required background checks have been verified prior to the issuance of any DISA-specific ID card or badge.
5. Duties of Civilian Employees, Military Members, Contractors, and Visitors.
These individuals will:
5.1 Display their issued ID card or badge (photograph or DISA seal facing front) on their outer most garment between their neck and waistline at all times when inside a DISA facility, unless directed to remove the card or badge for a special event or when wearing the card or badge is unsafe; i.e., working out in the gym or working directly with equipment that could snare dangling badges and cause injury to the wearer.
5.2 Refrain from wearing or displaying an issued ID card or badge outside official DoD facilities, inside commercial or retail facilities, or in any area that increases the risk of compromise due to theft, photograph, or the wearer affiliation with DISA or DoD.
5.3 Challenge anyone seen in a DISA controlled space who is not displaying an authorized DISA ID card, escort the individual(s) to the site security manager or security office if an authorized ID card cannot be produced, and immediately report the individual to the site security manager or security office if individual(s) is uncooperative.
5.4 Turn in their DISA-specific ID card when no longer needed (i.e., no longer work for DISA or a status change; such as, contractor to civilian employee, etc.)
5.5 Report the loss of an ID card immediately to the site security manager or security office.
6. Issuance.
6.1 A CAC or a CAC coded for the appropriate site-specific access will be issued to all DISA civilian employees, military members, and authorized contractors. If the local access control system (ACS) cannot accept the CAC as the primary access control credential, a locally produced ID card or badge will be issued during in-processing (on boarding).
6.2 The development and use of a unique identifying badge or tab to further distinguish special access must be approved by the Senior Agency Official (SAO) . There will not be any encrypted, magnetic, or digital information embedded in the special badges or tabs. All encrypted, magnetic, or digital information identifying the bearer and their credentials will be embedded on the CAC or locally used primary ID card or badge. DISA special badges or tabs will be used for visual recognition only. Special badges or tabs will not be used as a sole means of recognition or to gain access to a restricted area.
Enclosure 5
ENTRY AND EXIT INSPECTION (E&EI)
1. General. The implementation of entry and exit inspections (E&EIs) at all sites where DISA has command and control (C2) responsibilities is mandatory. All personnel entering or exiting a DISA site are subject to being inspected, in accordance with prescribed standards.
DISA employees who refuse to comply will be identified and their supervisor notified for corrective action.
1.1 The diligent use of E&EIs will assist in the establishment and sustainment of a robust physical security posture that serves to protect against the intentional and accidental compro-mise of sensitive and/or classified information. Effective E&EIs, used in concert with the random antiterrorism measures (RAMs), enable security to appear not only formidable but also unpredictable and ambiguous to instill uncertainty in individuals or groups; i.e., terrorists, criminals, and insiders plotting nefarious actions against DISA.
1.2 An E&EI random security inspection is conducted by designated DISA security officers or staff members assigned to the organization being inspected. The inspectors will focus on the personnel using primary and alternate access control points to gain access to or egress from a DISA controlled facility or area of responsibility (AOR). All carried items will be subject to inspection. These inspections encourage adherence to DoD and Agency policies, directives, and regulations established to protect personnel, material, and property against injury, loss, destruction, compromise, or sabotage.
2. Objective. Establishment and implementation of facility E&EIs are designed to mitigate the compromise of sensitive and/or classified information or material.
3. Applicability. An E&EI applies to all DISA sites where DISA has the responsibility of providing primary security and access control.
4. Security Manager Duties. A Security Manager will:
4.1 Ensure E&EIs are scheduled and conducted monthly, at a minimum, using available resources.
4.2 Ensure E&EI methods or procedures do not violate standing legal precedence;
i.e., Rights to Privacy, Civil Liberties, Status of Forces Agreements (SOFA), etc.
4.3 Ensure all violations or infractions noted during an E&EI are documented and reported to the site commander or director and the Security Division (MP6).
5. Warning. All entrances to DISA facilities shall have the following warning conspicuously posted. The exact wording is not mandatory, but the full intent must be conveyed if other wording is used:
WARNING RESTRICTED AREA
You have entered a restricted area. All persons entering herein are subject to search and any unauthorized/prohibited items, documents, or devices discovered during a search can be confiscated and processed in accordance with Title 18 & Title 50 of the United States Code.
Furthermore, any photographing or making notes, maps, drawings or graphic representations of this area or its activities is prohibited unless specifically authorized by the commanding officer or their designated officials, DoD regulation, or DISA policy. Violation could lead to fines, imprisonment, or both.
5.1 Any confiscated United States Government (USG) property can be held for an indefinite period of time to conduct any necessary inquiry or investigation to determine if there has been a compromise of sensitive or classified information, in accordance with DoD published guidance.
5.2 Any confiscated personally owned property (i.e. mobile/cellular device, recordable media, fitness tracking device, etc.) can only be held for 5 calendar days unless it has been determined by the Senior Agency Official (SAO), under the advisement of the office of the DISA General Counsel (GC), that the property may have been used to compromise sensitive or classified information. If a personally owned item is confiscated, the owner will be provided a hand receipt identifying all items confiscated.
6. Inspectable Items. Inspectable items include, but are not limited to, briefcases, shoulder or handbags, laptop cases, luggage, athletic bags, and other similar containers. Packages and gift wrapped items will also be subject to inspection if the inspecting officer suspects the item may contain harmful or unauthorized materials. Inspections must be supervised by a designated employee or military member who has been thoroughly briefed on the local standard operating procedures consistent with DISA and DoD policies and, when applicable, host nation laws relegated to the inspection of property in the possession of individuals on a DoD installation.
Hands-on body searches (pat downs) will not be conducted unless the inspectors are authorized to act in a law enforcement capacity; i.e. military police, etc.
7. Minimum Standards.
7.1 An E&EI point is set up to prevent personnel from circumventing a search or inspection.
When conducting inspections, either all personnel entering and/or exiting are inspected or personnel will be selected at random; i.e., every third or fifth person, etc.
7.2 Prohibited items and equipment are subject to confiscation and may be detained until appropriate documentation, assessment, or investigation can be obtained or conducted.
Accountable government equipment must be accompanied by a current property pass or hand receipt identifying the carrier as being authorized to possess the equipment in question.
7.3 Identifiable classified items or documents must be packaged or wrapped in accordance with DoD Manual 5200.01, volume 3, DoD Information Security Program: Protection of Classified Information, and the carrier must possess a valid courier card (DD Form 2501:
Courier Authorization) or courier letter to bring classified items or documents in or out of a DISA facility.
8. Reporting of Violations. Any suspected or actual violation of security policies or regulations pertaining to intentional or unintentional introduction or extraction of unauthorized materials or items is to be reported immediately to the local security manager and to the Security Division (MP6) within 24 hours of discovery.
Enclosure 6
COLLATERAL OPEN STORAGE AREA (COSA)
1. General. A DISA-operated collateral open storage area (COSA) is described as a room, office, building, or other form of facility of which the DISA element having residency therein is directly responsible for the command and control (C2) of that designated space. This respon-sibility can be derived through a direct lease by DISA or delegated to DISA by the legal owners of the designated space. Admittance to a COSA will be limited to persons who have official business within the area (need to know) and have been granted the appropriate security clearance and access level to view and/or process information up to their designated clearance level.
A space nominated as a COSA must meet the applicable standards as set forth in DoD Manual 5200.01-M, Volume 3, DoD Information Security Program: Protection of Classified Information, and be approved, in writing, by the Chief, Security Division (MP6).
2. Objective. A COSA ensures the proper safeguard of classified information and/or materials within a designated DISA-operated area where individual or collaborative viewing and/or processing of that information or material can be accomplished without being compromised by unauthorized personnel.
3. Applicability. A COSA designation will apply to all DISA-operated areas within a facility that have been properly authorized for viewing, discussing, and openly storing classified material within that designated area.
4. Area Nominations. The following areas should be nominated for and built to meet COSA standards:
4.1 An area where large amounts of classified information, not to exceed a top secret classifica-tion level, will be handled, processed, or stored in non-General Services Administration (GSA) approved containers. This does not include areas that have been certified as a sensitive compart-mented information facility (SCIF).
4.2 An area where uncontrolled access would interfere with or disrupt personnel assigned to the area in carrying out their official duties.
4.3 An area where the introduction of numerous GSA-approved containers for classified storage would degrade proficiency, productivity, or structure integrity.
5. Duties.
5.1 COSA Program Manager. The COSA Program Manager will:
5.1.1 Establish and maintain a list of all DISA COSAs to include, but not be limited to, their location, organization, primary points of contact (POCs), and certification.
5.1.2 Conduct virtual or onsite physical security surveys/inspections of all DISA sites to determine if they meet the governing guidance to operate a COSA.
5.1.3 Maintain copies of all certification, recertification, and decertification checklists and standard operating procedures (SOPs).
5.1.4 Produce a quarterly status report on all DISA-operated COSAs.
5.1.5 Send expiration notification e-mails to COSA POCs within 60 days of accreditation expiration to prompt the start of the reaccreditation or decertification process.
5.2 Security Manager. A Security Manager will:
5.2.1 Ensure continued compliance with all applicable DoD and DISA COSA requirements.
(Violations are to be reported immediately.)
5.2.2 Submit full and complete documentation for COSA certification, modification, recertification, or decertification, as described in paragraph 6. (Recertification documentation will be due no later than 30 days prior to the expiration of the current COSA certification.)
5.2.3 Create and/or verify continued compliance with COSA-specific SOPs for each COSA.
5.2.4 Review COSA SOPs at least annually to ensure the policies and procedures contained therein adequately prevent unauthorized access to, and unauthorized disclosure of, classified information based on current site conditions.
5.2.5 Perform alarm system integrity checks at least semiannually.
6. Documentation. Proper documentation is required for all approved DISA COSAs.
The following documentation will be kept on file for each COSA at their specific location and copies provided to the Security Division (MP6) upon request.
6.1 Request for Certification, Modification, or Recertification Interoffice Memorandum (IM). A formal request and justification for COSA certification, modification, or recertification signed by an organization official, deputy level or higher.
6.2 Request for Decertification IM. A formal request and justification for COSA decertifi-cation signed by an organization official, deputy level or higher, requesting decertification of a COSA when a determination has been made that a previously accredited facility, room, or area no longer requires COSA certification or no longer meets the required standards. The letter must verify all classified material, including classified documents, computer hard drives, storage media, and accessories, has been removed from the COSA or is being placed in a GSA-approved container when not being handled or in use by authorized individuals.
6.3 Final Approval or Certification Letter. The final approval or certification letter signed by the Chief, Security Division (MP6), or designated representative, certifying or decertifying the facility, room, or area designated on the letter. The approval letter will be effective for 2 years or until the area no longer meets the required standards.
6.4 Certification, Recertification, and Modifications Checklist. A detailed checklist completed for each facility, room, or area nominated for certification, periodic recertification (every 2 years), or modified from its original accredited state. The checklist must be signed by the requesting organization's Security Manager or Alternate Security Manager and be forwarded along with the IM to the Chief, Security Division (MP6). A blank copy of the COSA checklist is located on the Security (MP6) Home Page on the DoD Portal Services (DEPS). Select "Security Managers" and scroll down and select "Security Managers Toolkit."
Under the Security Programs and Oversight Page [bottom right], click "Physical Security (Collateral)" and select "DISA COSA Checklist."
6.5 Decertification Checklist. A detailed checklist completed for each facility, room, or area being decertified. The checklist must be completed and signed by the Security Manager or Alternate Security Manager and be forwarded along with the Decertification IM to Chief, Security Division (MP6).
6.6 Specific Standard Operating Procedure (SOP). A detailed document developed for each COSA outlining its specific security procedures. A finalized, signed copy of the SOP is to be forwarded to the Security Division (MP6) upon request for all COSA accreditations, modifications, and reaccreditations. Failure to provide a copy of the SOP, without being granted a waiver, will result in immediate decertification of the COSA. The security proce-dures contained in the SOP will reflect the specific operating conditions at the designated site.
At a minimum, the SOP must include the following information:
Access Control Procedures Sign-In Procedures Escorting and Sanitizing Procedures for Uncleared Visitors Procedures to prevent “Piggy Back” entry into the COSA Opening and Closing Procedures Emergency Evacuation Procedures Power Failure Response Procedures Room Modification Procedures Alarm Integrity Check Procedures Security Check Procedures (including the regular removal of false ceiling/ false floor tiles to check above or below for evidence of a security breach) Control of Classified Information Procedures Control of Classified Processing Equipment Procedures Prohibition of Classified Discussions (if acceptable sound-proofing measures are not in place)
6.7 Waiver Request IM (If Applicable). A waiver request signed by a requesting organization official at the deputy level or higher. The request must identify the facility, room, or area that cannot meet the prescribed DoD or DISA COSA standard, why the standard(s) cannot be met, and the mitigations in place to address the risk(s) that could result from the specific standard(s) not being followed.
6.8 Area Diagram or Blueprint. A legible area diagram of the COSA that depicts all access points to the protected area, i.e., doors and windows, as well as the location of Intrusion Detection System/Access Control System (IDS/ACS) devices. The space surrounding the COSA must be identified within the diagram. A current diagram is required for each new, renewal, or modification request.
| 2019-06-25T07:51:54-0400 | |
| BARNHART.BRADLEY.WILLIAM.1140635789 |
File details come from the government source that posted it. Updated .