Bidders Library Security - DoD 5220 22.pdf
PDF 682 KB Posted
- Attached to
- TEC II Services RFP Federal contract opportunity
- Solicitation number
- HC102821R0006
- Issued by
- Defense Information Systems Agency
About this file
This document is a Request for Proposal (RFP) from the Defense Information Systems Agency (DISA) for Test, Evaluation, and Certification Services for the Joint Interoperability Test Command. The RFP seeks proposals to provide services such as testing and evaluation of communications and information systems to validate interoperability and certification for deployment. Offerors must submit proposals by the closing date of October 28, 2021. The contract will be a single-award Indefinite Delivery/Indefinite Quantity (IDIQ) with one base year and four option years, and an estimated total value of $249 million. Small businesses are encouraged to compete. The RFP includes detailed requirements for testing services, security requirements, and proposal preparation instructions.
View the file
Other files for this federal contract opportunity
Show all 50
TEC II Services RFP has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DOD MANUAL 5220.22, VOLUME 2
NATIONAL INDUSTRIAL SECURITY PROGRAM: INDUSTRIAL
SECURITY PROCEDURES FOR GOVERNMENT ACTIVITIES
Originating Component: Office of the Under Secretary of Defense for Intelligence
Effective: August 1, 2018
Releasability: Cleared for public release. Available on the Directives Division Website at http://www.esd.whs.mil/DD/.
Incorporates and Cancels: DoD 5220.22-R, “Industrial Security Regulation,” December 4, 1985 DoD 5220.22-C, “Carrier Supplement to Industrial Security Manual for
Safeguarding Classified Information,” October 1, 1986 Under Secretary of Defense for Intelligence Memorandum, “Authority to
Suspend Contractor Personnel Security Clearances,” May 13, 2009
Approved by: Joseph D. Kernan, Under Secretary of Defense for Intelligence
Purpose: This manual is composed of several volumes, each containing its own purpose. In accordance with the authority in DoD Directive (DoDD) 5143.01:
• This manual implements policy, assigns responsibilities, establishes requirements, and provides procedures, consistent with Executive Order (E.O.) 12829, DoD Instruction (DoDI) 5220.22, and E.O.
10865, for the protection of classified information that is disclosed to, or developed by contractors, licensees, and grantees (referred to in this manual as contractors) of the U.S. Government (USG).
• This volume prescribes industrial security procedures and practices applicable to USG activities using the DoD as their cognizant security agency (CSA). This ensures maximum uniformity and effectiveness in DoD implementation of the National Industrial Security Program (NISP) in accordance with E.O. 12829.
DoDM 5220.22 Volume 2, August 1, 2018
TABLE OF CONTENTS 2
TABLE OF CONTENTS
SECTION 1: GENERAL ISSUANCE INFORMATION
1.1. Applicability
1.2 Policy
1.3. Information Collections
SECTION 2: RESPONSIBILITIES
2.1. Under Secretary of Defense for Intelligence (USD(I))
2.2. Director, Defense Security Service (DSS)
2.3. USD(P)
2.4 USD(AT&L)
2.5. Director, Washington Headquarters Services (WHS)
2.6. GC DoD
2.7. DoD Component Heads
SECTION 3: PROCEDURES
3.1. Amendment of Volume
3.2. Expenditure of Funds for Security
3.3. Exceptions to Policy and Procedures
3.4. Components and Their GCAs
3.5 Security Cognizance Within the United States, its Territorial Areas, and the
District of Columbia
3.6. Security Cognizance for SAPS with Contractors
3.7. Security Cognizance for the Protection of SCI with Contractors
3.8. Contractor Operations on USG Controlled Installations
3.9. Reporting Requirements to ISOO
3.10. Handling Information Reported by or About Contractors
a. General
b. Information Reported About Contractors
c. Information Reported About Individuals
3.11. ISLs
SECTION 4: FCLS
4.1. General
4.2. Reciprocity
4.3 FCL Request
4.4. U.S. Company FCL Eligibility Requirements
4.5. FCL Processing Requirements
4.6. Interim FCLs
4.7. Issuance of the FCL
4.8. Business Structures and KMP Considerations for an FCL
4.9. Foreign Persons Serving as Officers, Partners, or Members of Boards of Directors
4.10. Exclusion Procedures
4.11. PCLs Concurrent with the FCL Other Than KMP
4.12. Administrative Termination and Downgrading of an FCL
4.13. Changed Conditions Affecting the FCL
TABLE OF CONTENTS 3
a. Change of Operating Name
b. Change in Management
c. Change in Ownership
d. Change of Address
e. Business Closing
f. Bankruptcy
g. Placement of Contractor as Excluded on the SAM
h. Changes Involving a Parent Organization
i. Changes Involving an MFO
j. Changes Involving an FF
k. Upgrading of an FCL
l. Other Changes That Could Impact FCL Eligibility
4.14. Personnel Actions Affecting an FCL
4.15. Invalidation of an FCL
4.16. Revalidation of an FCL
4.17. Revocation of an FCL
4.18. Maintenance of Contractor Information
APPENDIX 4A: DSS MAINTENANCE OF CONTRACTOR INFORMATION
SECTION 5: ELIGIBILITY FOR ACCESS TO CLASSIFIED INFORMATION
5.1. General
5.2. Reciprocity
5.3. Investigative Requirements
5.4. Clearance Application
5.5. Pre-employment Clearance Action
5.6. Interim PCLs
5.7. Limited Access Authorization (LAA)
5.8. Consultants
5.9. PCLSA
5.10. Suspending an Existing PCL
SECTION 6: CONTRACTING THAT REQUIRES ACCESS TO CLASSIFIED INFORMATION
6.1. General
6.2. Procedures
a. Determine the Security Requirements of the Contract
b. Determine Clearance Status of Prospective Contractors
c. Pre-Award Access to Classified Information
6.3. Security Classification Guidance
6.4. Unsoliciated Proposals
6.5. Public Disclosure
6.6. Classification Interpretation Procedures
6.7. Retention of Classified Material
6.8. Downgrading and Declassification
SECTION 7: SAFEGUARDING
7.1. General
7.2. Storage of Classified Material
7.3. Transmission of Classified Information
TABLE OF CONTENTS 4
7.4. Reproduction of Classified Material
7.5. Destruction of Classified Material
SECTION 8: INQUIRIES, INVESTIGATIONS, AND ADMINISTRATIVE ACTIONS
8.1. Application
8.2. Procedures for Suspicious Contacts, Possible Espionage, Sabotage, Acts of
Terrorism, or Subversive Activities
8.3. Loss, Compromise, or Suspected Compromise of Classified Information
8.4. Component or GCA Reporting
8.5. Responsibility of the Component and GCA to Investigate Certain Breaches of
Security
SECTION 9: SETA
9.1. Application
9.2. SETA
SECTION 10: VISITS AND MEETINGS
10.1. General
10.2. Visits to Contractor Facilities
10.3. Visits to USG Activities by Contractor Personnel
10.4. Meetings at Which Classified Information is Disclosed
SECTION 11: IS SECURITY
11.1. General
11.2. DSS
11.3. GCA
11.4. Federal IS Operating in Contractor Cleared Facilities
SECTION 12: INTERNATIONAL SECURITY PROGRAMS
12.1. General
12.2. Authority for International Program Security Requirements
12.3. Exceptions to the Requirements of this Section
12.4. International Programs Involving Access to U.S. Classified Information by
Foreign Governments and Their Contractors
12.5. International Programs Involving Access to FGI by U.S. Contractors
12.6. Transfers of Classified Information and Material to Foreign Governments
12.7. Transfers of Defense Articles to the U.K. and Australia Without a License or
Other Written Authorization
12.8. Responsibilities of a U.S. Designated Government Representative (DGR)
12.9. Transportation Plans
12.10. Escorts
12.11. FFs
12.12. Shipments Using a Transportation Plan
12.13. Use of International Carriers
12.14. International Hand Carrying of Classified Material
12.15. Secure Communications
12.16. International Visits, Assignments of Foreign Nationals, and Control of
Foreign National Employees
a. Visits by Foreign Nationals to U.S. Contractors and Control of Foreign
National Employees
TABLE OF CONTENTS 5
b. Disclosures of Unclassified Technical Data by U.S. Contractors
c. Receipt of RFVs by U.S. DoD Defense Visits Offices (DVOs)
d. Types of Visit Authorizations
e. Responses to RFVs
f. Exemption to the Export License
g. Data Retention Requirements for an Approved RFV
h. U.S. Contractor Employee Visits to Foreign Governments and Foreign
Contractor Facilities
12.17. U.S. Contractor Operations Outside of the United States, its Territories, or the
District of Columbia
a. Storage of U.S. Classified Information and Material in a Foreign Country
b. Exception Requests for Storage of Classified Information and Material in a
Foreign Country
c. Safeguarding Approval for an FCL on a USG-Controlled Installation in a
Foreign Country
d. U.S. Contractor Operations Outside of the United States
e. U.S. Contractor Employees Located on a Foreign Government or NATO-
Controlled Facility or Installation
12.18. NATO Requirements
a. General
b. Protection of NATO Information
c. NATO Facility Security Clearance Certificate
d. Access to NATO Classified Information
e. Classification Guidance
f. NATO Briefings to Cleared U.S. Contractor Personnel or DCMA Personnel
g. Safeguarding and Accounting for NATO Classified Information
h. International Transfers of Classified NATO Information
i. Disclosure of U.S. Classified Information to NATO
j. NATO Visits
12.19. Reciprocal Filing of Classified Patent Applications
SECTION 13: ASSOCIATED PROGRAMS OR INFORMATION
13.1. AA&E
13.2. Biological Select Agents and Toxins (BSAT) Biological Personnel Reliability
Program (BPRP)
13.3. Chemical Agent Personnel Reliability Program (CPRP)
13.4. Classified National Security Information Program for State, Local, Tribal, and
Private Sector Information Entities
13.5. COMSEC Information
13.6. CNWDI
13.7. CPI Identification and Protection
13.8. CRADAs
13.9. Defense Technical Information Center (DTIC)
13.10. IR&D Efforts
13.11. Installation, Base, or Facility Physical Access
13.12. Nuclear Weapon Personnel Reliability Program (PRP)
TABLE OF CONTENTS 6
13.13. OPSEC
13.14. RD and FRD
13.15. TEMPEST Countermeasures
13.16. Protection of Mission Critical Functions to Achieve Trusted Systems and
Networks
SECTION 14: SECURITY REVIEWS AND CONTINUING SECURITY ASSURANCE ACTIVITY
14.1. Security Reviews
14.2. Scope of Security Reviews
14.3. Compliance Security Review
14.4. Closeout Security Review
14.5. Security Review Report
14.6. Advice and Assistance
APPENDIX 14A: SECURITY REVIEW REPORT
GLOSSARY
G.1. Acronyms G.2. Definitions
REFERENCES
SECTION 1: GENERAL ISSUANCE INFORMATION 7
SECTION 1: GENERAL ISSUANCE INFORMATION
1.1. APPLICABILITY. This volume applies to:
a. OSD, the Military Departments, the Office of the Chairman of the Joint Chiefs of Staff and the Joint Staff, the Combatant Commands, the Office of the Inspector General of the Department of Defense, the Defense Agencies, the DoD Field Activities, and all other organizational entities within the DoD (referred to collectively as the “DoD Components”).
b. Those non-DoD executive branch departments and agencies (referred to collectively as the “non-DoD Components”) identified in DoD 5220.22-M. These non-DoD Components have entered into agreements with the Secretary of Defense (SecDef), pursuant to E.O. 12829, under which DoD acts as the CSA, to provide security oversight services to ensure the protection of classified information disclosed to or generated by contractors.
c. When the term “Component” is used in this volume, it is referring to both DoD and non- DoD Components.
d. When the term “Government Contracting Activity (GCA)” is used in this volume, it will refer to contracting activities of both DoD and non-DoD Components.
(1) This manual does not limit in any manner the authority of the SecDef, the Secretaries of the Military Departments, or the Component heads to grant access to classified information under the cognizance of their department or agency to any individual designated by them. The granting of such access is outside the scope of the NISP and will be governed by E.O. 13526 and applicable disclosure policies.
(2) This volume does not restrict the authority of a Component or a GCA to limit, deny, or revoke access to classified information under its statutory, regulatory, or contractual jurisdiction and does not apply to:
e. Contractors and companies in process for facility security clearances (FCLs), as those are subject to the requirements of DoD 5220.22-M and the security requirements of their contracts.
f. The protection of national intelligence and access to intelligence sources and methods, including sensitive compartment information (SCI). The Director of National Intelligence (DNI) has the authority to prescribe standards for the protection of national intelligence and access to intelligence sources and methods, including SCI, pursuant to section 3024 of Title 50, United States Code (U.S.C.) as implemented in Intelligence Community Directive (ICD) 700.
Eligibility for access to SCI must be verified through applicable SCI channels.
g. Eligibility for access to Special Access Program (SAP) information must be verified through applicable SAP channels in accordance with DoDI 5205.11.
SECTION 1: GENERAL ISSUANCE INFORMATION 8
1.2 POLICY It is DoD policy that:
a. The SecDef serves as the Federal Executive Agent for inspecting and monitoring contractors under the NISP in accordance with E.O. 12829. The SecDef may prescribe such specific requirements and procedures for Components and their GCAs to follow to protect classified information that may be disclosed, or has been disclosed, to current, prospective, or former contractors, licensees, or grantees of USG agencies.
b. The SecDef is authorized by E.O. 12829 to enter into agreements with any other Executive Branch department or agency to provide industrial security services required for safeguarding classified information disclosed to contractors by these non-DoD Components.
c. As a CSA, the DoD will establish, in accordance with E.O. 12829 and DoDI 5220.22, policies, procedures, and practices to be followed by Components and their GCAs for the effective protection of classified information provided to industry, including foreign government information (FGI) that the USG is obligated to protect in the interest of national security.
d. In accordance with E.O. 12829, DoD, the Office of the DNI, Department of Energy (DOE), the Nuclear Regulatory Commission, and the Department of Homeland Security (DHS) are the only Executive Branch agencies that are authorized to function as CSAs for the NISP.
Pursuant to Part 2004 of Title 32, Code of Federal Regulations (CFR), CSAs are responsible for the security of classified contracts and activities under their purview; oversight of contractors under their security cognizance; and ensuring that redundant and duplicative security review and audit activity of contractors is held to a minimum, including such activity conducted at contractor facilities where multiple CSAs have equities.
e. Security eligibility for contractor personnel requiring access to classified information will be determined in accordance with the established standards and criteria in DoDD 5220.6.
1.3. INFORMATION COLLECTIONS. DD Form 254, “Department of Defense Contract Security Classification Specification,” referred to in paragraph 3.4.a of this volume, is assigned Office of Management and Budget (OMB) control number 0704-0567 for contract security classification specification requirements in accordance with Volume 2 of DoD Manuel (DoDM) 8910.01.
a. The reports on violations to the Director, Information Security Oversight Office (ISOO), referred to in Paragraph 3.9 of this volume, are exempt from licensing in accordance with Paragraph 8.a.(2)(c) of Enclosure 3 of Volume 2 of DoDM 8910.01.
b. The requests for FCL, referred to in Paragraph 4.3 of this volume, are assigned OMB control number 0704-0571, in accordance with Volume 2 of DoDM 8910.01.
c. The collection and maintenance of contractor FCL records, referred to in Appendix 4a of this volume, is assigned OMB control number 0704-0571, in accordance with Volume 2 of DoDM 8910.01.
SECTION 1: GENERAL ISSUANCE INFORMATION 9
d. The reporting of suspicious contacts, referred to in Paragraph 8.2 of this volume, is exempt from licensing in accordance with Paragraph 8.a.(2)(d) of Enclosure 3 of Volume 2 of DoDM 8910.01.
e. The Security Review Report, referred to in Appendix 14A of this volume, is exempt from licensing in accordance with Paragraph 8.a.(2)(c) of Enclosure 3 of Volume 2 of DoDM 8910.01.
SECTION 2: RESPONSIBILITIES 10
SECTION 2: RESPONSIBILITIES
2.1. UNDER SECRETARY OF DEFENSE FOR INTELLIGENCE (USD(I)). In accordance with DoDD 5143.01 and DoDI 5220.22, the USD(I):
a. Oversees policy and management of the NISP.
b. Directs, administers, and oversees the NISP to ensure that the program is efficient and consistent.
c. In accordance with E.O. 12829, reports intra- or inter-agency agreements that create redundant and duplicative security reviews, inspections, or audit activity by other CSAs to the Director, ISOO.
d. Considers and, as warranted:
(1) Approves or disapproves any requests for exceptions to this volume;
(2) Approves or disapproves any requests for exceptions to DoD 5220.22-M as described in Paragraph 2.2.x of this volume that apply to more than one contractor location, and;
(3) Coordinates with the Under Secretary of Defense for Policy (USD(P)) on all matters involving requests for exception to this volume or DoD 5220.22-M that would affect international agreements, the international security requirements of DoD international cooperative projects and programs, including those relating to FGI and international issues, and on all matters affecting international technology transfer.
e. May delegate the authorities in Paragraph 1.1.d.(1) - (3) to a DoD Official.
2.2. DIRECTOR, DEFENSE SECURITY SERVICE (DSS). Under the authority, direction, and control of the USD(I), in accordance with DoDI 5220.22 and DoDD 5105.42, and in addition to the responsibilities in DoDD 5240.02, DoDD 5240.06 (when required by contract)), DoDD 5205.16 and in Paragraph 2.7 of this volume, the Director, DSS:
a. Budgets and funds the NISP.
b. Administers the NISP as a separate program element on behalf of the GCAs, to include providing security oversight as the cognizant security office (CSO) on behalf of the GCAs, for U.S. contractors and U.S. companies in process for an FCL in accordance with this manual. DSS is relieved of this oversight function for DoD SAPs when the SecDef or the Deputy Secretary of Defense approves a carve-out provision for a DoD SAP in accordance with the provisions described in Section 3 of this volume.
c. Executes intra- and inter-agency agreements as necessary to avoid redundant and duplicative security reviews or inspections, including such activity conducted at contractor facilities by other CSAs. Notifies the Office of the Under Secretary of Defense for Intelligence
SECTION 2: RESPONSIBILITIES 11
CI and Security (OUSD(I) CI&S) of unresolved instances of redundant or duplicative security reviews, inspections or audit activity.
d. Trains GCA personnel (i.e., contracting officers, contracting officer representatives, industrial security personnel and others performing security duties) on the requirements of this manual and of industrial security matters as required or upon request, including insider threat education and awareness.
e. Provides, as authorized in support of cleared contractors and within DSS, CI assistance or support, in accordance with DoDD 5105.42.
f. Leverages the security expertise of contractors by granting self-approval authority to a contractor’s designated personnel who meet specific criteria demonstrating appropriate security education training and awareness (SETA) applicable to a specific topic or area of industrial security in accordance with Paragraph 9.2.b.(6) of this volume.
g. Establishes a professional career development program for DSS personnel to ensure the continuing effectiveness of DSS oversight of NISP contractors.
h. Develops authorizing official (AO) guidance for contractor information systems to process classified information for those contractors under DSS security cognizance and coordinates the guidance with OUSD(I) CI&S and the National Industrial Security Program Policy Advisory Committee (NISPPAC) prior to publication. If requested, provides the DoD GCAs, and the Office of the Chief Information Officer of the Department of Defense with the published AO guidance for their reference about contractor information systems that process classified information under DSS security cognizance.
i. Determines, in coordination with the General Counsel of the Department of Defense (GC DoD), whether action should be taken to suspend a contractor employee’s clearance eligibility in accordance with the provisions of DoDD 5220.6 and Section 5 of this volume.
j. In accordance with DoDD 5105.42 and the provisions in Section 12 of this volume, directs the proper implementation by DSS of the requirements in parts 120-130 of Title 22, CFR, also known as the International Traffic in Arms Regulations (ITAR); DoDD 5230.11; bilateral security agreements; guidance from the USD(P) pursuant to DoDD 5111.1 and DoDD 5230.20;
program-specific agreements with allies and other friendly countries; and North Atlantic Treaty Organization (NATO) requirements implemented by United States Security Authority for NATO Affairs Instruction 1-07 and DoDI 5210.60, as described in DoD 5220.22-M for the protection of U.S. classified information and FGI to which U.S. contractors may have access.
k. In consultation with the Office of the Under Secretary of Defense for Policy (OUSD(P)), maintains a complete set of copies of the security agreements that have been negotiated with various foreign governments or international organizations (referred to collectively in this volume as “foreign governments”) and allows contractors cleared to the appropriate level and having a need-to-know to view the applicable agreement at a DSS office.
SECTION 2: RESPONSIBILITIES 12
l. Develops appropriate changes to maintain the volumes of this manual in a current and effective basis in accordance with DoDI 5025.01. Proposed changes to these documents will be forwarded to the OUSD(I) CI&S.
m. Prepares, coordinates, and publishes industrial security letters (ISLs) with the approval of the USD(I).
n. Establishes and maintains a system for timely and effective communication with the GCAs and the NISP contractors.
o. Provides information, upon GCA request, to assist with the review of the security aspects of GCA classified contracts.
p. Provides updates to the FCL and safeguarding capability status of specific facilities upon request.
q. Maintains a DoD database (currently the Industrial Security Facilities Database (ISFD)) for all current, pending, and recently terminated FCLs with the associated oversight activity and resulting actions.
r. Maintains a record of GCA or contractor requests and responses for facility security clearance assurances (FCLA) or personnel security clearance assurances (PCLSA) for foreign companies and individuals.
s. Maintains the forms and associated instructions in this volume in accordance with DoD 7750.07-M.
t. Maintains an industrial security operating manual with any detailed procedures and direction for DSS personnel in the execution of the industrial security mission, consistent with the requirements of this manual.
u. Provide procedures and any subsequent updates to any DoD Components performing FCL oversight (i.e., commanders or heads of USG-controlled installations who have retained oversight of any cleared facility on the installation) to assure that they know where and to whom at DSS to submit updates about any pending or on base cleared contractor facilities under their cognizance.
v. Develops procedures that provide for:
(1) When and how notices of proposed or final FCL revocation or denial decisions will be communicated to contractors.
(2) The content of those notices.
(3) Designation of which DSS officials will be authorized to revoke or deny an FCL.
(4) Administrative requests for reconsideration or appeals that contractors can request after an FCL has been revoked or denied.
SECTION 2: RESPONSIBILITIES 13
(5) Required coordination with OUSD(I) and the Office of the Deputy General Counsel for Intelligence, if the procedures provide that requests for reconsideration or appeals from FCL revocations or denials may be made to the USD(I) or an official on the OUSD(I) staff outside of
DSS.
w. Retains the Standard Form (SF) 312, “Classified Information Nondisclosure Agreement,” executed by all contractor personnel cleared for access to classified information under DoD NISP security cognizance. DoD 5220.22-M provides guidance to contractor personnel regarding the SF 312 execution and debriefing requirements. Blank copies of the SF 312, which includes revisions made by the Office of the Director of National Intelligence to reflect language required by two statutes: Public Law 112-74 and Public Law 112-199 can be found at http://www.gsa.gov/portal/forms/download/116218.
x. Considers, and as warranted, approves or disapproves requests for exceptions to DoD 5220.22-M in consultation with affected GCAs for specific contractor locations and for specific periods of time (such as, for the duration of a contract).
y. Coordinates with the USD(P) and the Under Secretary of Defense for Acquisition, Technology and Logistics (USD(AT&L)) on matters under their cognizance that impact the NISP consistent with this manual.
2.3. USD(P). In accordance with DoDD 5111.1, the USD(P):
a. Develops policy and procedures for the safeguarding, access control, and transfer of classified information subject to export control pursuant to the ITAR.
b. Develops policy and procedures for the safeguarding, access control, and transfer of NATO information consistent with United States Security Authority for NATO Affairs Instruction 1-07.
c. Develops policy and procedures for the safeguarding, access control, and transfer of classified information subject to bilateral and multinational security and program-specific agreements with foreign governments.
d. Develops policy and procedures for the negotiation of international agreements and the foreign disclosure, technology control, and security requirements for international programs.
When such agreements are executed, provide DSS with a copy.
e. Establishes qualifications and standards and provides guidance for the content of courses of instruction that are to fully train attendees on national and DoD policies on foreign disclosure, technology control, and security requirements for DoD international programs, consistent with DoDD 5230.11 and the October 22, 1999 Deputy Secretary of Defense Memorandum.
2.4 USD(AT&L). In accordance with DoDD 5134.01, consistent with the responsibilities in DoDI 5220.22, the USD(AT&L):
SECTION 2: RESPONSIBILITIES 14
a. Advises the USD(I) on the development and implementation of NISP policies, in accordance with DoDI 5220.22.
b. Ensures DoD GCAs establish and maintain a record of the current and legitimate need for access to classified information by contractors in the defense industrial base.
2.5. DIRECTOR, WASHINGTON HEADQUARTERS SERVICES (WHS). Under the authority, direction, and control of the Deputy Chief Management Officer of the Department of Defense and in accordance with Security Executive Agent Directive 4, DoDI 5200.02, DoDD 5220.6, DoDM 5200.02, the October 22, 2012 Director of National Intelligence Memorandum, and the May 3, 2012 Deputy Secretary of Defense Memorandum, the Director, WHS, conducts national security eligibility adjudications for access to classified information by contractor personnel under DSS cognizance. See Sections 4, 5, and 8 of this volume for additional guidance.
2.6. GC DOD. In accordance with DoDD 5220.6, DoDD 5145.01, and DoDI 5145.03, the GC DoD:
a. Provides advice and guidance to the DoD as to the legal sufficiency of procedures and standards established by this manual.
b. Ensures that DoD NISP policies, standards, and procedures are in accordance with all applicable E.Os., ICDs, court decisions, and statutory requirements.
c. Ensures that all relevant statutes, E.Os., and court decisions are reviewed on a continuing basis and that analysis of the foregoing is accomplished and disseminated to DoD NISP management authorities.
d. Performs functions relating to the NISP in accordance with DoDD 5220.6, including maintenance and oversight of the Defense Office of Hearings and Appeals (DOHA).
2.7. DOD COMPONENT HEADS. In accordance with DoDI 5220.22 and DoDD 5205.16, the DoD Component heads:
a. Oversee compliance by the Component’s personnel with applicable procedures identified in this volume.
b. May augment this volume by prescribing more detailed procedures for Components and their GCAs as may be required for particular circumstances, provided they are consistent with this volume.
c. Ensure that the Component or its GCA industrial security personnel, and others performing security duties (i.e., contracting officers or contractor officer representatives) complete appropriate security education and training.
SECTION 2: RESPONSIBILITIES 15
d. Provide oversight of contractor personnel visiting or working on USG-controlled installations.
e. Review the security aspects of classified contracts with contractors as needed.
f. Propose changes to the volumes of this manual as deemed appropriate and provide them to the OUSD(I) CI&S.
g. Notify the OUSD(I) CI&S of any substantive issues prior to public meetings of the NISPPAC or NISPPAC working group meetings to facilitate a coordinated DoD position.
h. Establish procedures to report in the DoD personnel security system of record information that becomes known to the GCA or to other elements of the respective Component that adversely reflects on the integrity or character of a contractor or contractor employee; that suggests that his or her ability to safeguard classified information may be impaired; that his or her access to classified information clearly may not be in the interest of national security or the contractor employee poses an actual or potential insider threat.
SECTION 3: PROCEDURES 16
SECTION 3: PROCEDURES
3.1. AMENDMENT OF VOLUME. Amendment of this volume, in accordance with DoDI 5220.22, requires coordination with the DoD Components and consultation with the non-DoD Components. Unless otherwise specified in any amendment, compliance with an amendment will not be mandatory until 30 days after date of publication, although compliance will be authorized from the date of its publication.
3.2. EXPENDITURE OF FUNDS FOR SECURITY. The CSO (be it DSS or the commander or head of a USG-controlled installation) will not commit the government to reimburse a contractor for funds expended in connection with the contractor’s security program.
a. In the case of a cost-reimbursement-type contract, the allowability of security costs is determined by the contracting officer in accordance with the terms of the contract and with the cost principles of the Federal Acquisition Regulation (FAR). Under a fixed price contract, the initial contract price includes all applicable security costs. An equitable adjustment may be made in the initial contract price when, as indicated in the contract security clause, the security classification or security requirements under the contract are changed by the government (e.g., changes to DoD 5220.22-M, and the change results in an increase or decrease in contract price).
DoD 5220.22-M provides that a U.S. contractor must implement changes no later than 6 months from the date of the published change to DoD 5220.22-M to allow the contractor to discuss what impact, if any, the changes have on existing classified contracts.
b. As a precondition for receiving an FCL, DSS will require an uncleared company to execute the DD Form 441, “Department of Defense Security Agreement,” located at http://www.esd.whs.mil/Portals/54/Documents/DD/forms/dd/dd0441_2017.pdf. When executing the DD Form 441, the uncleared company agrees to implement a security program meeting standards of DoD 5220.22-M and acknowledges that the agreement does not obligate government funds, nor does the government agree to any costs or claims of the contractor arising out of the agreement or its instructions.
3.3. EXCEPTIONS TO POLICY AND PROCEDURES.
a. The USD(I), or designee, will provide overall policy guidance to this program, in accordance with DoDI 5220.22 and will render decisions regarding exceptions to, or deviations from, the security policy and procedures promulgated in the volumes that comprise this manual.
When required, the USD(I) or designee will coordinate with the applicable Component or its GCA and other elements of OSD having an interest in the matter. Exceptions will not be contrary to any existing Executive orders or laws. All requests for exceptions or deviations will include an explanation why the stated policy or procedures cannot be accommodated and a proposed alternative with supporting justification, explaining how the alternative will result in substantially the same degree of protection. Requests will be submitted to OUSD(I) CI&S following the Component’s procedures in accordance with Paragraph 3.4 of this volume.
OUSD(I) CI&S will coordinate and consult on any requests for exception involving international
SECTION 3: PROCEDURES 17
security programs with the Office of the Under Secretary of Defense for Policy Director, International Security Programs, Defense Technology Security Administration, (referred to in this volume as “OUSD(P) Director, ISP”).
b. Any conflict that develops between instructions in the volumes of this manual will be reported to OUSD(I) CI&S following Component procedures in accordance with Paragraph 3.4 of this volume. Pending resolution, the provisions of this volume will govern.
3.4. COMPONENTS AND THEIR GCAS.
a. The Component will require their GCAs to provide an executed DD Form 254 or security aspects letter, if applicable, as an attachment to contracts, solicitations, and other arrangements or agreements that require access to classified information. The DD Form 254 or security aspects letter, if applicable, should be provided to affected contractors, to the applicable GCA elements as defined in Component procedures and to the responsible DSS field activities. The DD Form 254 and its associated instructions are located at http://www.esd.whs.mil/portals/54/documents/dd/forms/dd/dd0254.pdf and http://www.esd.whs.mil/portals/54/documents/dd/forms/dd/dd0254-Inst.pdf, respectively.
b. If the Component or GCA chooses to augment this volume with any detailed procedures, the Component will ensure that those procedures are consistent with the provisions of this volume. The Component or GCA detailed operating procedures will also be consistent with the requirements, restrictions, and safeguards that directives implementing ICD 700 or Section 2011 et seq., of Title 42, U.S.C. (also known and referred to in this volume as “The Atomic Energy Act of 1954, as amended”) establish for the protection of classified information by GCAs.
3.5 SECURITY COGNIZANCE WITHIN THE UNITED STATES, ITS TERRITORIAL
AREAS, AND THE DISTRICT OF COLUMBIA. Overall security cognizance for each contractor facility will be provided by only one of the five NISP CSAs in the case of contractors with contracts requiring access to classified information from more than one CSA (i.e., DoD, DOE, Office of the Director of National Intelligence, Nuclear Regulatory Commission, or DHS).
When DoD and another NISP CSA have classified involvement at the same contractor facility, DSS, as the CSO, will determine security cognizance, in coordination with the other CSA. That determination will be made consistent with the provisions of Part 2004 of Title 32 CFR based upon the preponderance of classified involvement (e.g., the highest level of classified performance or volume of classified work as the number of classified contracts need not be the sole, determining factor) and will include execution of a memorandum of agreement between DSS and the other NISP CSA relating to each affected contractor. DSS will then notify all affected Components for which DSS serves as the CSO whether DSS or another CSA has security cognizance.
a. DSS, when acting as the CSO:
(1) Exercises security cognizance, in accordance with this manual, for any U.S. company with an FCL (otherwise referred to in this manual as a U.S. contractor) in the United States, the District of Columbia, and its territories (see Paragraph 4.4.b of this volume). Such cognizance
SECTION 3: PROCEDURES 18
does not include those FCLs on USG-controlled installations where the commander or head of the USG installation (referred to in this volume as “Commander”)) has retained security cognizance pursuant to Paragraph 3.8.c of this volume.
(2) Assigns security cognizance to a DSS region or field office and post a list of the region or field offices and their assigned areas of responsibility at www.dss.mil.
(3) Advises the uncleared company during the initial facility clearance process which DSS office has security cognizance.
(4) Provides the Commander with the contact information for the applicable DSS office that serves as a liaison to the Commander for any FCLs on a USG-controlled installation.
Security cognizance and oversight of contractor operations located on a USG-controlled installation are addressed in paragraph 3.8 of this volume.
b. A representative of a GCA will notify DSS, as the CSO, of any GCA visits to a contractor to review security aspects of a collateral contract requiring access to classified information or FGI. Any significant deviation from the requirements of DoD 5220.22-M that may be noted during the visit will be referred promptly to DSS, along with any suggested corrective action or additional security requirements to be levied on the contractor. DSS will be responsible for ensuring appropriate action is taken regarding these matters, and will notify the GCA of the corrective action taken by the contractor.
3.6. SECURITY COGNIZANCE FOR SAPS WITH CONTRACTORS. Security
cognizance with respect to the DoD and industry contracts involving DoD SAPs is stipulated in this section and in accordance with E.O. 13526 and DoDD 5205.07. The security measures for SAPs that are in addition to those prescribed in DoD 5220.22-M for collateral contracts are contained in Appendix D of DoD 5220.22-M, and the DoD Special Access Program (SAP) Security Manual, Volumes 1-4.
a. The Director, DSS, or upon delegation, the DSS Regional Directors, will exercise security oversight for DoD SAPs operating consistent with the NISP and perform the following security functions to satisfy SAP requirements:
(1) Exercise security oversight in accordance with the provisions of this manual. DSS will record the highest classification level eligible, however, DSS will not record or verify contractor eligibility for access or possession of SAP information.
(2) Provide the SAP GCA written reports conveying security review results, as well as the security posture of the contractor and any threat or incident information that relates specific threats to the technology or geographic area of interest. When appropriate, any such threat and incident information will also be provided to the contractor’s security personnel and GCA counterintelligence (CI) support personnel.
(3) Notify the SAP GCA of security issues that may affect SAP information in the hands of a contractor.
SECTION 3: PROCEDURES 19
b. When DSS is the CSO, GCAs:
(1) Notify DSS of the applicable GCA SAP security officers and provide updates as necessary for SAPs that have DSS security cognizance.
(2) Ensure that any adverse information coming to the attention of the GCA regarding a contractor employee whose clearance is maintained by the DoD is provided to DSS.
c. When the SecDef or the Deputy Secretary of Defense determine that the security interests of DoD and the sensitivities of a SAP warrant, he or she may relieve DSS of this oversight responsibility and assign security cognizance to another DoD Component. When this occurs, the contracts are referred to as “carve-outs.” Generally, this mechanism is used when knowledge of the existence of a particular contract or its association with the SAP is classified and designated as SAP protected information. In these instances, the DoD Component that assumes security cognizance will:
(1) Advise the DoD Special Access Program Central Office (SAPCO) of the creation and continuing existence of the carve-out to ensure the DoD SAPCO is aware of this arrangement should relevant security changes arise; e.g., the prospective acquisition of the contractor by a foreign interest. The DoD SAPCO will implement a mechanism to facilitate DSS awareness of approved carve-out arrangements at contractors.
(2) Perform all security oversight functions for the applicable SAP in accordance with the provisions of this manual and reflect the carve-out status of a contract on the DD Form 254.
3.7. SECURITY COGNIZANCE FOR THE PROTECTION OF SCI WITH
CONTRACTORS.
a. Oversight of the protection of SCI in the hands of contractors is the responsibility of the GCA in accordance with Section 3024 of Title 50, U.S.C. as implemented in ICD 700. SCI released to contractor personnel will be controlled in accordance with the provisions of Director of Central Intelligence Directive 6/1, DoDM 5105.21, Volumes 1-3, and implementing Component policies.
b. Before releasing or providing SCI to contractor personnel, the GCA will ensure that they are appropriately cleared in accordance with ICD 704 and they agree to follow controls and procedures for the protection, handling, and accountability of SCI. All activities involving SCI (including discussions) will be conducted in sensitive compartmented information facilities (SCIFs). Physical security standards for SCIFs are contained in ICD 705, applicable IC specifications, or standards and implementing DoD Component policies.
c. While DSS has no responsibility for the oversight of the protection of SCI, the Director, DSS, or designee:
(1) Maintains FCLs for contractors working on contracts involving access to, or possession of, SCI, when requested by an SCI CSO. DSS will not record or verify contractor eligibility for access to or possession of SCI or SAP information.
SECTION 3: PROCEDURES 20
(2) Provides the SCI CSO written reports conveying security review results, as well as the security posture of the contractor and any threat or incident information that relates specific threats to the technology or geographic area of interest. When appropriate, provides such threat and incident information to the contractor’s security personnel.
(3) Notifies the SCI CSO of security issues that may affect the protection of SCI information in the hands of a contractor.
(4) Notifies an SCI CSO if it becomes aware of a contractor storing collateral classified information not specific to the GCA programs within the SCI CSO accredited space without prior written approval from the approving SCI CSO and the supported GCAs.
(5) Coordinates with the Office of the National Counterintelligence and Security Center with regard to evaluation and approval of access to SCI by foreign-owned U.S. cleared companies or any other Intelligence Community equities in accordance with the provisions of Volume 3 of DoDM 5220.22 and also Directive-type Memorandum 15-002 to provide updated guidance.
d. An SCI CSO and the GCAs within an SCI CSO accredited space must provide prior written approval for storage of collateral classified information not specific to the GCA programs within the applicable SCI CSO accredited space. Based upon that written approval, DSS would not have oversight responsibility for such collateral classified information in the applicable SCI CSO accredited space. The SCI CSO would have oversight of that collateral classified information even though it is not specific to the GCA programs within the applicable SCI CSO accredited space because of the written approval for storage.
3.8. CONTRACTOR OPERATIONS ON USG CONTROLLED INSTALLATIONS. A
contractor’s personnel assigned to a USG-controlled installation to perform operations that require access to classified information for the Commander or a GCA may be considered visitors, notwithstanding the duration of the assignment, and are subject to the security procedures of the installation and as applicable, a tenant command. Alternatively, the Commander may request an FCL subject to the provisions of Paragraph 3.8.b of this volume and Section 4 of this volume.
a. Visitors to a USG-Controlled Installation. The Commander or designee will provide security oversight of all contractor visitors, in which case, they will follow the security procedures of the installation. When requested by the Commander, any GCA-controlled location on the installation will execute an agreement with the host installation setting forth the security procedures that contractor visitors will be required to follow.
b. FCLs on a USG-Controlled Installation. DSS may process a contractor’s operation on any USG-controlled installation for an FCL if the contractor is otherwise eligible for an FCL in accordance with Section 4 of this volume and all of the following criteria apply:
(1) The contractor’s operation is sufficiently complex to warrant assignment of a segregated work area such as a suite of offices, a building, or portion thereof.
SECTION 3: PROCEDURES 21
(2) The contractor maintains a long-term operational presence on the installation (i.e., of a year or more).
(3) The contractor maintains management control over its operations.
(4) The contractor is in a position to maintain security procedures that are separate from the host activity and in accordance with the terms of any formal agreement with the tenant DoD Component or host installation and DoD 5220.22-M.
(5) If located on a USG-controlled installation in a foreign country, the contractor is a branch or division office of an already cleared U.S. contractor in the United States, or of a U.S.
company being processed for an FCL in the United States.
c. Security Cognizance of a Cleared Facility on a USG-Controlled Installation
(1) If the Commander decides that a contractor’s on-installation operations requires an FCL and meets the provisions of Paragraph 3.8.b of this volume, the Commander will ordinarily request DSS to assume security cognizance in accordance with Section 4 of this volume. If DSS assumes security cognizance, DSS is responsible for all aspects of security oversight, except if the proposed FCL will be located on a USG-controlled installation in a foreign country. In such cases, before an FCL will be granted, DSS and the Commander must establish a formal agreement that sets forth how oversight will be conducted because DSS may require assistance for aspects of the oversight from the Commander or sponsoring tenant USG activity depending upon the location.
(2) If a tenant USG activity decides that a contractor’s on-installation operation requires an FCL, and meets the provisions of Paragraph 3.8.b of this volume, the tenant USG activity may submit a request for FCL through the Commander. The Commander may:
(a) Endorse the FCL sponsorship request and submit it to DSS.
(b) Disapprove the request and handle the contractor’s operation as a visitor group.
The Commander is responsible for all aspects of security oversight.
(c) Retain security cognizance for the sponsored FCL. If the Commander has compelling reasons, as described in Paragraph 3.8.c.(5) of this volume, to retain security cognizance and so formally advises DSS, the Commander is responsible for all aspects of security oversight.
(3) Responsibility will not be divided between the Commander and DSS unless the provisions of Paragraph 3.8.c.(1) of this volume apply where the proposed FCL will be located on a USG-controlled installation in a foreign country.
(4) DSS will annually provide a list of all on-base cleared facilities to the designated industrial security point of contact for each of the Military Services, noting whether DSS or a Commander retains security cognizance. If DSS has security cognizance of a cleared facility on a USG-controlled installation, DSS will:
SECTION 3: PROCEDURES 22
(a) Exercise security oversight of the contractor facility in accordance with the provisions of this manual.
(b) Notify the Commander of any significant changes at the contractor as such changes occur.
(c) Provide the Commander with copies of all suspicious contact reports submitted.
(d) Notify the Commander immediately if any security review rating is marginal or unsatisfactory as described in Section 14 of this volume and provide the Commander with an update after completion of any compliance security reviews.
(e) Provide the Commander copies of any reports resulting from investigations conducted in cases of loss, compromise, or suspected compromise of classified information.
(5) If the Commander decides to retain security cognizance, the Commander will notify DSS in writing, explaining why the contractor operations are of such criticality to the installation mission (e.g., the company’s work is essential to the safety or security of the installation or the classified program is at a high level of sensitivity, such as a SAP) that retention of security cognizance is necessary. The Commander will also include the compelling reasons to retain security cognizance in any new FCL sponsorship letters to DSS. DSS will not process the new FCL until security cognizance responsibility is resolved.
(a) If the Commander retains security cognizance, the Commander will:
1. Request that DSS process the company for an FCL, (including adjudication of foreign ownership, control, or influence (FOCI) factors, if applicable) based on a legitimate government requirement for access to classified information in accordance with Section 4 of this volume.
2. Provide security oversight of the contractor by personnel trained in accordance with Paragraph 2.7.c of this volume and the provisions of this manual.
3. Notify DSS of any changes affecting the FCL (e.g., change of ownership, change of management personnel, change in FOCI factors, change in safeguarding capability, or any other factors in DoD 5220.22-M).
4. Approve safeguarding capability, if needed to perform on a classified procurement requirement and provide notice to DSS of the initial approval and immediate notice of any changes to that safeguarding capability.
5. Require that the contractor report promptly to the Commander and to DSS any suspicious contacts and any incidents which involve actual, probable or possible espionage, sabotage, terrorism, or subversive activity, or the loss, compromise, or suspected compromise of classified information in accordance with DoD 5220.22-M.
SECTION 3: PROCEDURES 23
6. Notify DSS immediately if any security review rating is marginal or unsatisfactory as described in Section 14 of this volume and provide DSS with an update regarding the security review rating after completion of any compliance security reviews.
7. Provide an annual certification to DSS that the cleared facility is still able to properly protect classified information, on or about the anniversary date of the FCL, based on the Commander’s recurring security reviews. This annual certification from the Commander will serve as the basis for DSS to continue to verify the FCL and, as applicable, the safeguarding capability of the cleared facility.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .