Bidders Library Security - DISAI 240-110-35.pdf
PDF 237 KB Posted
- Attached to
- TEC II Services RFP Federal contract opportunity
- Solicitation number
- HC102821R0006
- Issued by
- Defense Information Systems Agency
About this file
This instruction prescribes the policies and procedures for handling sensitive compartmented information (SCI) within the Defense Information Systems Agency (DISA). It assigns responsibilities for SCI security to key officials and outlines requirements for personnel security, indoctrination and debriefing, clearances and certifications, physical security of special access facilities, information systems security, destruction of classified materials, foreign travel briefings, and reporting obligations. Adherence to the guidance in this instruction helps DISA fulfill its mission to protect SCI and enable authorized access while mitigating risks to networks and data.
View the file
Other files for this federal contract opportunity
Show all 50
TEC II Services RFP has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DEFENSE INFORMATION SYSTEMS AGENCY
P. 0. BOX 549
FORT MEADE, MARYLAND 207 55-0549
DISA INSTRUCTION 240_1l0_35*
SECURITY
Sensitive Compartmented Information (SCI)
1. Purpose. This Instruction prescribes policy, assigns responsibility, and provides procedures for sensitive compartmented information (SCI)
2. Applicability. This Instruction applies to all DISA activities worldwide.
3. Authority. This Instruction is published in accordance with the authority contained in DoD Instruction 5200.01, DoD Information Security Program and Protection of SensitiveCompartmented Information, 9 October 2008; DoD 5105.21-M-l, Sensitive Compartmented Information Administrative SecurityManual, 3 August 1998; Intelligence Community Directive (lCD)700, Protection of National Intelligence, 21 September 2007;lCD 701, Security Policy Directive for Unauthorized Disclosuresof Classified Information, 14 March 2007; lCD 705, SensitiveCompartmented Information Facilities, 26 May 2010; lCD 503,Information Technology Systems Security, Risk Management, Certification and Accreditation, 15 September 2008.
4. Policy. Protective measures and administrative procedures to prevent unauthorized disclosure of SCI materials will be utilized within DISA.
5. Responsibilities.
5.1 Principal Directors, Directors, Commanders, and Chiefs
of Major Organizational Elements. These individuals will:
5.1.1 Coordinate with the Manpower, Personnel, and Security
(MPS) Security Division (MPS6) Special Security Officer (SSO)(MPS62) on all SCI or sensitive compartmented information facility (SCIF) matters.
5.1.2 Nominate appropriate personnel to serve as Special
Security Representatives (SSR5) and alternates.
5.1.3 Evaluate organizational sci positions on a yearly basis.
5.2 Manpower, Personnel, and Security (MPS) Chief, Security
Division (MPS6). The Chief, MPS6, is appointed as the Senior Intelligence Officer (Sb) for the Agency and will:
5.2.1 Oversee SCI and SCIF security for the Agency.
5.2.2 Appoint the primary and alternate 550, primary and
alternate SSR, and control officers for compartments, as required; SCI Information System Security Manager (ISSM);
and SCI Information System Security Officer (ISSO), in writing, to manage the day-to-day operations of the DISA SSO.
5.2.3 Ensure appropriate agreements are established when SCI
or SCIF areas of responsibility, training, and operational needseither support, overlap, or are shared with internal or external organizations.
5.2.4 Coordinate and approve any preconstruction, renovation, or modification to SCIFs.
5.2.5 Ensure SCI systems are properly accredited through the
Defense Intelligence Agency (DIA)
5.3 Chief, Special Security Office (SSO). The Chief, SSO, will:
5.3.1 Manage the day-to-day operations of Agency SCI security and facilities.
5.3.2 Maintain SCI security oversight and cognizance over
subordinate Agency SCIFs through each organization’s SSR(s).
5.3.3 Coordinate SCI security issues on behalf of DISA
combatant command field offices with the local servicing sso.
5.3.4 Report SCI security infractions to the DISA SlO and DIA.
5.3.5 Provide oversight to preliminary inquiries resulting
from reported security violations.
6. Sd and SCIF Related Duties. The following individuals areunder the direction of, and will coordinate with, the DISA SSOon all Sd or SCIF related matters.
6.1 Special Security Representative (SSR). An SSR will overseethe day—to-day management and implementation of Sd security instructions for a separate subordinate SCIF.
6.1.1 Coordinate with the DISA SSO physical security point ofcontact (POC) to ensure the facility and TEMPEST accreditationsremain current for the SCIF.
6.1.2 Coordinate with the DISA SSO ISSM to process system
accreditations and resolve information systems security issues.
6.2 Information System Security Manager (ISSM).
6.2.1 Implement operations of SCI information systems securityfor Agency SCIFs.
6.2.2 Ensure coordination between the SSO ISSM, site ISSM, SCIF ISSO, and DIA to ensure all SCI automated information systems (AISs) are properly accredited in accordance with DS-2610-ll42-Ol, DoD Intelligence Information Systems (D0DIIS)Security Certification and Accreditation Guide, and applicable information systems directives.
6.2.3 Validate appointment of an ISSO, in writing, for each
DISA SCIF. (Appointment letters will be forwarded to the SSQ 155M to maintain as a matter of record.)
6.2.4 Ensure all SCI AISs are properly accredited prior to use.
6.3 Information Systems Security Officer (ISSO). An ISSO will oversee day-to-day management and implementation of AISs within DISA SCIFs.
6.4 Contracting Officer’s Representative (COR). A COR will:
6.4.1 Coordinate all SCI requirements pertaining to the
execution of a DISA contract with the DISA SSO.
6.4.2 Initiate and validate requests for access to SCI
information.
6.4.3 Submit requests for visit certifications messages to
external organizations in support of the contractual effort.
6.4.4 Identify the contractual requirement for a SCIF at
the contractor location to the DISA SSO for their action.
7. Personnel Security.
7.1 Nomination. An SCI nomination request for civilian
employees, military members, and contractors will be submitted to and approved by the appointed SSR, CUR, or the organization’ssecurity POC. DoD civilian and military personnel are nominatedfor Sd access based on mission requirements and/or position sensitivity and the individual’s need-to-know, as determined bya senior management official. Contractors are nominated basedon the requirements stipulated within the Statement of Work for the DISA effort and the subsequent DO Form 254: Department of Defense Contract Security Classification Specification.
7.1.1 A nomination will contain the individual’s full name, social security number, place of birth, date of birth, office code, job title, phone number, access levels requested, and a detailed justification explaining how the SCI information will be accessed and utilized in the performance of the nominee’s daily duties. In addition to this information, a contractor nomination requires the endorsement by the CUR, copy of the DO Form 254 with the contract number, contract start date, expiration date, location of facility where the work is to be performed, and the cage code and company name under which the contract will be executed.
7.1.2 An updated Electronic Questionnaires for Investigations Processing (e-QIP), initiated by the SSO, or a Standard Form (SF) 86: Questionnaire for National Security Positions, may be required when a nominee’s investigation date is between 1 year and 7 years old. This form must be completed by the nominee.
The e-QIP is submitted electronically directly to the SSO. The SF 86 is submitted through the SSR or security POC to the SSO.
A Foreign Preference/Connection Questionnaire will be submitted by the subject through the SSR or security POC to the SSO should any foreign relatives, associates, property, bank accounts, or interests be listed on the e-QIP or SF 86. The questionnaire can be obtained from the SSR, security POC, or SSO.
7.1.3 A prescreening interview will be scheduled for the
nominee with DISA SSO if the nominee has never had an SCI eligibility determination made on the most recent investigation.
A nominee outside of the National Capital Region (NCR) will be prescreened by a local SSO within his or her region coordinated by the DISA SSO.
7.1.4 The eligibility request will be processed by the DISASSO to the appropriate military service Central AdjudicationFacility (CAF) or DIA CAF and monitored for eligibility change.Any subsequent requests for additional information generatedfrom the CAF will be coordinated through the SSR.
7.2 Indoctrination and Debriefing.
7.2.1 The indoctrination is the briefing an individual receivesprior to being granted access to Sd systems or programs. AnSd eligible employee inside the NCR schedules an appointmentthrough the SSR or COR upon notification of the eligibilitychange from the CAF. An SCI eligible employee outside the NCRis indoctrinated by a DISA appointed Special Security ContactOfficer (SSCO) or servicing SSO for that region. The DISA SSOinitiates all SCI indoctrination assistance messages to the SSCOor servicing SSO. The local SSR and employee are to providecontact information, such as daytime phone number, to allow the indoctrination to be scheduled by the servicing SSO in theregion. Upon completion of indoctrination, the DISA SSO updatesthe Corporate Management Information System (CMIS) and Joint Personnel Adjudication System (JPAS) to reflect indoctrinationupdates and access. Indoctrination oaths are electronically stored within CMIS.
7.2.2 A debriefing is conducted during the duty day by the
DISA SSO, SSCO, or servicing SSO. The SSR or COR will notify the DISA SSO of any debriefing requests for individuals outsidethe NCR in order for the DISA SSO to coordinate with the SSCOor servicing SSO. The SSR or COR will collect any badges andcourier cards that the debriefed individual is in possession of at the time of the debriefing and return the items to the DISA SSO. Upon completion, the DISA SSO will update CMIS and JPAS systems to reflect the debriefing.
7.3 Permanent (PERM) and Visitation (VISIT) Clearance
Certifications. SCI clearance certifications can only be initiated by DISA SSO or authorized SSCO5. A PER1’1 certificationis requested for a DISA SCI cleared civilian or military member to be certified to any Sd organization for official purposes for a time period of 1 to 3 years. A VISIT certification is requested for DISA SCI cleared civilians, military members, or contractors to any Sd organization for official purposes for up to 1 year.
7.3.1 The DISA SSO only recogniz5 the sso Form 1: SCi Access
Certification as the officjai certification request The form may be generated through the CMIS Security Generate Forms sub-tab or obtained Upon request from the DISA SSO. The form is submitted via e-mail by the SSR to the DISA SSO. exception for faxing or hand delivery to the DISA SSQ is made at the discretion of the Chief, DISA SSO, when time sensitive actions are requir
7.3.2 The SSO Form 1 is completed in its entirety to include
the JPAS Security Manage Office (SMO) code or Plain Language Address (PLA) of the organiza0 to be visited any Passing instructions and a visit POC with telephone number The JPAS SMO is the Primary means of transmitting certifications PLA, F, or alternative methods are only utilized if the organjz tion to be visited does not have a valid JPAS SMO code. y SSO Form 1 requesting the certification be sent by PLA must also include the date of birth Place of birth, investigajQ date, and CAF for each individual listed on the sso Form 1.
If a PLA is returned by the messaging system as invalid the DISA SSO will contact the SSR to validate the PLA with the organizatj0 to be visited.
7.4 Local Suspension ACtj0 Actions will be suspended
locally by the DISA SSO on an individual who becomes ineligib until the issue is resolved. Actions may include, but are not limited to, an adverse security clearance ±ssue, expired visit authorization for contractors, or employee failure to complete a periodic reinvestigj0 when requjre A local suspension action will include retraction of any active certification message.
8. Intel1jgefl Communj. (IC) Badge.
8.1 To be eligible for issuance of an IC badge, in accordance with the DIA Chief, Personnel Security Division, an individual must (1) be a u.s. citizen; (2) be currently indoctrinated to SCI and Possess a final SCI eligibility determination;
(3) be the rank of Lieutenant Colonel or Commander (0-5) or above in the military or GS-14 or above as a civilian employee;
and (4) be assignee to official duties that require regular and freque physic access (i.e., two or more visits per week) to at least two of the declared facilities of the intellig agenci5 that are signatorj5 to the agreeme Any requests for exceptions to the require5 will be submitted in writing, by the component’s signature authority through the DISA SSO to the DIA Chief, Special Security Branch.
DIA oversees the administration of these delegated authorities and reserves the right to withdraw any delegation of authority where a component’s adherence to the eligibility requirements is questioned.
8.2 A request for an IC badge is initiated by a DISA Security Manager or SSR via an interoffice memorandum (TM) to the DISA SSO. The request will contain the individual’s name, grade or rank, social security number, organization, office symbol, phone number, date and place of birth, gender, color of hair, color of eyes, height, and weight, drivers license number and state of issuance; an unclassified justification paragraph explaining the need for the badge and frequency of visits; the name of each facility visited and POC for each facility (with phone number);
and the length of certification (not to exceed 3 years) . All requests for individuals below the rank of Senior Executive Service (SES) must have a signature from their organization’s Principal or Deputy Director concurring with the request.
8.3 All submissions will be reviewed by the DISA SSO to ensure the individual meets all DIA requirements to obtain an IC badge.
DISA SSO completes all DIA required documentation from the information submitted on the IM. After completion of the DIA required documentation, the SSO will send a clearance certification to DIA via JPAS and then route the documentation to DIA for approval. The DISA Security Manager or SSR will be notified of the approval decision. Upon approval for an IC badge, the individual will receive directions for badge issuance from the DISA SSO. The individual has 30 days to complete card issuance following notification of approval.
If more than 30 days lapse, the badge request is nullified.
9. Polygraphs.
9.1 To be eligible to receive a polygraph, DISA employees
must possess final Sd eligibility, be indoctrinated to SCI, and meet one of the following criteria: (1) be selected to fill a position which supports U.S. Cyber Command (USCYBERCOM) and/or requires access to a National Security Agency (NSA) controlled network or system, or (2) be selected for access to information protected under Special Access Program guidelines, or (3) provides sufficient justification to the DISA Sb.
9.2 A polygraph request is submitted to DISA SSO from the
organization’s security manager or SSR. The justification onthe requesting memorandum is to be kept at the unclassified level.
9.3. The DISA SSO will generate a requesting memorandum onDISA letterhead and submit to the Army Intelligence PolygraphProgram Office (DAMI-CDC) requesting approval to polygraph.The memorandum will include the name, social security numberof the individual to be examined, rank or grade, estimated timeof separation (ETS) date, last polygraph date per JPAS, and anunclassified justification. DAMI-CDC will notify the DISA SSOof approval or denial of the polygraph request. The DISA SSOwill directly notify the individual requiring the polygraph to report to the appropriate polygraph office for a mandatoryprebrief appointment. The individual will receive their appointment date and time before they depart from the prebriefappointment. Directions to the appropriate polygraph office will be provided when the individual is advised of the prebriefrequirement.
10. Physical Security.
10.1 SCIF Accreditation. The DIA Accreditations Management
Branch (DAC-2B) is the sole accrediting authority for DoD SCIFs.The DISA SSO will coordinate any request for SCIF5 with DAC-2B on behalf of the Agency.
10.1.1 Any DISA element considering a SCIF build will prepare aformal Concept Approval Request (CAR); Fixed-Facility Checklist (FFC); Construction Security Plan Worksheet; and TEMPEST addendum, provided in DoD 5l05.21-M-1, Sensitive CompartmentedInformation Administrative Security Manual, and lCD 705, Sensitive Compartmented Information Facilities, authority documents, detailing the SCI mission being supported. All four items are to be submitted to the DISA SSO to review for completeness andprovide feedback prior to submission to DIA. It is imperative that organizations be aware that the CAR must have the concur rence of the DISA SlO before the packet is submitted to DIA.
10.1.2 The SSR will ensure all requirements identified by DISA SSO or DAC-2B are completed prior to requesting formal accreditation, and the DISA SSO will liaise during the construction with DAC-2B and the SSR on construction requirements, alarms, and security hardware issues.
10.1.3 Each accredited DISA SCIF will have an approved Standard Operating Procedure (SOP) and Emergency Action Plan (EAP), in accordance with the guidelines of DoD 5105.21-M-l, approved bythe DISA Sb.
10.2 Portable Electronic Devices (PEDs). A PED is a generic
title for multiple types of small data-processing electronic items. A PED can be used to store, process, or transmit valuable business-critical information. These devices, however, also pose risks to the security of DISA SCIF5 and DoD networks and data and must be properly managed. A PED is not allowed within a DISA SCIF unless approved by the local ISSM and DISA SSO prior to introduction. The DISA SSO and ISSM will provide copies of the governing DIA and Director, National Intelligence (DNI), policy to local SSR5 for inclusion within the respectiveSCIF binder.
11. Defense Courier Service (DCS). The Security Division (MPS6) conducts, as required, courier runs for DCS material pickup and dropoff. Pickups and dropoffs are made to the DCS Baltimore, Fort Meade, location. Other qualified classified material may be picked up and delivered on the courier run, if approved by the MPS62 Security Operations Branch Chief or SSO Chief. Only qualified, properly briefed couriers and SCI cleared MPS security office personnel will travel in a govern ment owned vehicle (GOV) to courier material on behalf of the
DISA SSO.
11.1 The DISA SSO approves requests for DCS accounts from
subordinate organizations prior to requesting an account from DCS.
11.2 Outgoing classified information will be prepared by the
activity in need of the service. A comprehensive DCS Customer Service Manual is available on the DCS Web site for use in preparing the request forms and addressing of packages.
The customer will be directed to the Web site to obtain all required information for shipping DCS packages. The link is https://lsotools.wpafb.af.mil/dc—atcmd/docs/DC-ATCMDGUIDE.ppt.
11.3 Qualified materials for shipping will be prepared as
an inner package with an AF Form 310: Document Receipt and Destruction Certificate, as the receipt for outgoing materials form DISA. The individual in charge of shipment will sign an IN stating the material is qualified for shipment via DCS.
The IN will be maintained with record copies of the Advanced Transportation Control and Movement Document (ATCMD) receipt.
12. Courier Authorization. A request for a courier card (DD Form 2501: Courier Authorization), is initiated by a DISASecurity Manager or SSR. An employee required to hand-carryclassified information within their local region requires a courier card to facilitate movement through installations and facility entry points. A courier card is not issued fortransporting information outside of the Virginia, District ofColumbia, and Maryland local commuting areas. The DISA SSO should be contacted for information regarding transporting SCI materials outside of the Virginia, District of Columbia,and Maryland local commuting areas.
12.1 An IM will be forwarded by the activity SSR to the DISASSO requesting courier card issuance. An Sd courier card willbe prepared by the DISA SSO, in accordance with DoD 5105.21-M-l.The level of material will be identified as Top Secret SCI, andthe duration is set as 2 years for government employee, unlessa shorter time is indicated, and 1 year for contractors.
12.2 An acknowledgement briefing will be conducted by the
DISA SSO for the individual accepting their responsibilities as a courier and signing the courier card. The SSR will returnthe acknowledgement memorandum to the servicing SSO for filing.When an employee is debriefed, the employee surrenders the courier card at the time of the debriefing.
12.3 The local servicing SSO will be contacted for processingrequirements in cases where an individual must courier SCI materials at DISA field sites. A courier will adhere to localservicing SSO requirements and standards.
13. Information System Security. The DISA SSO ISSM is the leadSCI ISSM for the Agency and is responsible for all information system security and information assurance issues within DISA SCIF5 and for all systems connected to the disa.ic.gov domain.An ISSO will be nominated by organizations to oversee information system security and information assurance within their SCIFand to implement guidance and/or direction from the DISA SSO
IS SM.
13.1 Accreditation. Systems that process SCI information mustmeet accreditation standards set forth in lCD 503, InformationTechnology Systems Security, Risk Management, Certification andAccreditation. Controls must be established and implemented inaddition to system security features to ensure confidentiality,integrity, and availability of hardware, software, and data to secure operations of an information system. The DISA SSO ISSMreviews all accreditation paperwork for Sd systems to ensure it is properly completed and updated. Sites will submit all required accreditation documentation to the DISA ISSM for review. The DISA ISSM will submit accreditation paperwork to DIA on behalf of the Agency. All sites that have host-base(non-DISA) provided access to the Joint Worldwide IntelligenceComputer System (JWICS) network will provide a copy of their accreditation Approval to Operate (ATO) to the DISA SSO ISSM to maintain as a matter of record.
13.2 Encryption. Encryption will be used when transmitting
national security information on external devices. NSA approveddevices and key management systems should be used for recoveryof plain text for a minimum of 5 years from the time of encryption.
13.3 Disclosure Record. A disclosure record is required for
Top Secret information contained within an information system.A disclosure record is a written conveyance of classified or sensitive information to another person or a physical transferof tangible products to an authorized recipient for retention.Thereafter, the recipient assumes responsibility for the physical security of, and all personnel access to, the products in accordance with the classification and/or special handlingcontrol specified for the product.
14. Destruction of SCI Classified Material. All DISA organizations are required to properly destroy SCI classified material within their SCIFs. The primary mode for destructionof SCI classified material will be through the use of shredders that are compliant with current DoD Directives and/or NSA evaluated product lists. Other SCI media, such as hard drives,compact discs (CD5), and digital video discs (DVDs), must also be destroyed using authorized destruction devices. The DISA SSOcan provide validation upon request and can provide informationfrom the approved products list. In the headquarters Fort Meadecampus, all organizations will directly coordinate destruction runs to the NSA Classified Destruction Facility for SCI destruc tion and abide by NSA instructions and guidance.
15. Foreign Travel Brief. A foreign travel brief is mandated from a Level II certified antiterrorism training officer within 90 days of the travel for all official travel. The SSR or Security Manager will notify DISA SSO of the itinerary and the certification of the foreign travel briefing prior to commencing travel.
16. Employee Reporting Requirement. Employees will immediately report suspected security violations, compromises, or any unauthorized disclosure or exposure of Sd to their Security Manager or SSR and DISA SSO and take immediate action to protectSd found in nonsecure environments until Sd control can be restored. In addition, employees will report to the DISA SSO any change in personal status, employee outside activities, contact with foreign nationals, foreign travel, inadvertent disclosure, missing Sd personnel, Sd appearing in the publicmedia, and termination of Sd access.
FOR THE DIRECTOR:
FREDERICK A. HE RY
Brigadier General, USA Chief of Staff
SUMMARY OF SIGNIFICANT CHANGES. This revision updates the authoritative references, expands on the assignment of responsibilities related to the management and protection of sensitive compartmented information (SCI), and provides additional direction on standards and procedures pertaining to SCI for the Agency.
*Thjs Instruction cancels DISAI 240-110-35, 4 December 2006.
OPR: MPS
DISTRIBUTION: Y
disa . meade. spi . mbx. disa-publications@mail . mil
File details come from the government source that posted it. Updated .