Bidders Library Security - DoD 5220 22-M.pdf

PDF 1 MB Posted

Attached to
TEC II Services RFP Federal contract opportunity
Solicitation number
HC102821R0006
Issued by
Defense Information Systems Agency

About this file

This document is the National Industrial Security Program Operating Manual (NISPOM) which prescribes requirements, restrictions, and safeguards for protecting classified information released by the U.S. Government to contractors. It outlines general provisions including the purpose and authority of the manual, security clearances for facilities and personnel, foreign ownership reporting requirements, security training, classification and marking procedures, safeguarding classified information, visits and meetings, subcontracting, and information system security. It also details special requirements for Restricted Data, intelligence information, communication security, and international security.

View the file

Other files for this federal contract opportunity

Other files attached to TEC II Services RFP, newest first.
File Type Posted
HC102821R0006 Conformed Through amendment 0008.pdf PDF
HC102821R0006 Conformed Through amendment 0007.pdf PDF
HC102821R0006 Conformed Through amendment 0006.pdf PDF
HC102821R0006 Conformed through amendment 0002.pdf PDF
HC102821R00060002.pdf PDF
Bidders Library DODI 5000 02.pdf PDF
Bidders Library Security - ISOO Handbook.pdf PDF
Bidders Library Security - DoDM 5200 01 Vol 1.pdf PDF
Bidders Library Security - DISAI 240-115-04.pdf PDF
Bidders Library Security - DISAI 240-110-35.pdf PDF
Bidders Library Operational Test and Evaluation - JITC OTE Guidebook v2 0.docx DOCX document
Bidders Library Operational Test and Evaluation - DoTE MEMO 10-19-2010.pdf PDF
Bidders Library Operational Test and Evaluation - DoTE MEMO 10-18-2010.pdf PDF
Bidders Library Operational Test and Evaluation - DoTE MEMO 6-16-2003.pdf PDF
Bidders Library Operational Test and Evaluation - DoTE MEMO 04-03-2018.pdf PDF
Bidders Library Operational Test and Evaluation - DoTE MEMO 1-21-2015.pdf PDF
Bidders Library JITC Instructions - JITCI 100-50-01.pdf PDF
Bidders Library JITC Instructions - JITCI 210-20-02.pdf PDF
Bidders Library JITC Instructions - JITCI 210-15-01.pdf PDF
Bidders Library JITC Instructions - JITCI 200-05-07.pdf PDF
Bidders Library Interoperability Test and Evaluation - JITC Notional Guide for Action Officers.pdf PDF
Bidders Library Interoperability Test and Evaluation - JITC Fact Sheet.pdf PDF
Bidders Library Interoperability Test and Evaluation - DODI 8551 01.pdf PDF
Bidders Library Interoperability Test and Evaluation - DoD 8570 01-M.pdf PDF
Bidders Library DoD Policy Instruction and Guidance - DoDI 4000 19.pdf PDF
Bidders Library DoD Policy Instruction and Guidance - DoDD 510035.pdf PDF
Bidders Library DoD Policy Instruction and Guidance - DoD Net Centric Service Strategy.pdf PDF
Bidders Library DISA - DISA Mandatory Contractor Training as of 20201110.xlsx XLSX spreadsheet
Bidders Library Cybersecurity - DoDI 8510 01.pdf PDF
Bidders Library Security - DISAI 240-110-8.pdf PDF
Bidders Library Cybersecurity - DOD Cybersecurity TE Guidebook.pdf PDF
Bidders Library Security - DoDM 5200 01 Vol 3.pdf PDF
Bidders Library Security - DoDM 5200 02.pdf PDF
Bidders Library Security - DoDM 5200 01 Vol 2.pdf PDF
Bidders Library Security - DoDM 5200 48.pdf PDF
Bidders Library Security - DoDD 5230 20.pdf PDF
Bidders Library Security - DoDM 5105 21.pdf PDF
Bidders Library Security - DISAI 240-110-39.pdf PDF
Bidders Library Operational Test and Evaluation - DOTE TEMP Guidebook.pdf PDF
Bidders Library Operational Test and Evaluation - DTM 11-003.pdf PDF
Bidders Library Operational Test and Evaluation - DoTE MEMO 7-23-2013.pdf PDF
Bidders Library Operational Test and Evaluation - DISA Test and Evaluation Scorecard Template.pptx PPTX presentation
Bidders Library Operational Test and Evaluation - DoDD 5000 01.pdf PDF
Bidders Library JITC Instructions - JITCI 280-120-01.pdf PDF
Bidders Library JITC Instructions - JITCI 640-50-07.pdf PDF
Bidders Library JITC Instructions - JITCI 380-50-02.pdf PDF
Bidders Library JITC Instructions - JITCI 200-50-02.pdf PDF
Bidders Library JITC Instructions - JITCI 200-05-05.pdf PDF
Bidders Library JITC Instructions - JITCI 200-05-06.pdf PDF
HC102821R0006.pdf PDF
Show all 50

TEC II Services RFP has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

he

Incorporating Change 2, May 18, 2016

DoD 5220.22-M, February 28, 2006

Change 2, 05/18/2016 2

TABLE OF CONTENTS

Page

Table of Contents

References

AL1. Acronyms

CHAPTER 1. GENERAL PROVISIONS AND REQUIREMENTS

Section 1. Introduction 1-100. Purpose ..................................................................................................... 1-1-1 1-101. Authority ................................................................................................... 1-1-1 1-102. Scope ......................................................................................................... 1-1-2 1-103. Agency Agreements ................................................................................ 1-1-2 1-104. Security Cognizance ................................................................................ 1-1-2 1-105. Composition of Manual ........................................................................... 1-1-3 1-106. Manual Interpretations ............................................................................. 1-1-3 1-107. Waivers and Exceptions to this Manual ................................................. 1-1-3 1-108. Releasability and Effective Date .............................................. 1-1-3 Section 2. General Requirements 1-200. General ........................................................................................................... 1-2-1 1-201. Facility Security Officer (FSO)................................................................... 1-2-1 1-202. Insider Threat Program ................................................................................ 1-2-1 1-203. Standard Practice Procedures ...................................................................... 1-2-1 1-204. One-Person Facilities ................................................................................... 1-2-1

1-205. Cooperation with Federal Agencies and Officially Credentialed Representatives of Those Agencies ....................................................... 1-2-1

1-206. Security Training and Briefings .................................................................. 1-2-1 1-207. Security Reviews .......................................................................................... 1-2-1 1-208. Hotlines .......................................................................................................... 1-2-2 1-209. Classified Information Procedures Act (CIPA) ........................................ 1-2-2 Section 3. Reporting Requirements 1-300. General ...................................................................................................... 1-3-1 1-301. Reports to be Submitted to the FBI ........................................................ 1-3-1 1-302. Reports to be Submitted to the CSA ....................................................... 1-3-2 1-303. Reports of Loss, Compromise, or Suspected Compromise .................. 1-3-2 1-304. Individual Culpability Reports ................................................................ 1-3-3 Section 4. Reports to DoD About Cyber Incidents On Cleared Defense Contractors (CDCs) ISs Approved to Process Classified Information 1-400. General ...................................................................................................... 1-4-1 1-401. Reports to be Submitted to DoD ............................................................. 1-4-1 1-402. Access to Equipment and Information by DoD Personnel ................... 1-4-1

Change 2, 05/18/2016 3

CHAPTER 2. SECURITY CLEARANCES

Section 1. Facility Clearances 2-100. General ...................................................................................................... 2-1-1 2-101. Reciprocity ............................................................................................... 2-1-1 2-102. Eligibility Requirements .......................................................................... 2-1-1 2-103. Processing the FCL .................................................................................. 2-1-1 2-104. PCLs Required in Connection with the FCL ......................................... 2-1-1 2-105. PCLs Concurrent with the FCL .............................................................. 2-1-1 2-106. Exclusion Procedures .............................................................................. 2-1-1 2-107. Interim FCLs ............................................................................................ 2-1-2 2-108. Multiple Facility Organizations (MFOs) ................................................ 2-1-2 2-109. Parent-Subsidiary Relationships ............................................................. 2-1-2 2-110. Termination of the FCL ........................................................................... 2-1-2 2-111. Records Maintenance .............................................................................. 2-1-2 Section 2. Personnel Security Clearances 2-200. General ...................................................................................................... 2-2-1 2-201. Investigative Requirements ..................................................................... 2-2-1 2-202. Procedures for Completing the Electronic Version of the SF 86 ......... 2-2-1 2-203. Common Adjudicative Standards ........................................................... 2-2-2 2-204. Reciprocity ............................................................................................... 2-2-2 2-205. Pre-employment Clearance Action ......................................................... 2-2-2 2-206. Contractor-Granted Clearances ............................................................... 2-2-2 2-207. Verification of U.S. Citizenship .............................................................. 2-2-2 2-208. Acceptable Proof of Citizenship ............................................................. 2-2-2 2-209. Non-U.S. Citizens .................................................................................... 2-2-3 2-210. Access Limitations of an LAA ............................................................... 2-2-3 2-211. Interim PCLs ............................................................................................ 2-2-3 2-212. Consultants ............................................................................................... 2-2-3 Section 3. Foreign Ownership, Control, or Influence (FOCI) 2-300. Policy.............................................................................................................. 2-3-1 2-301. Factors ............................................................................................................ 2-3-1 2-302. Procedures ..................................................................................................... 2-3-2 2-303. FOCI Action Plans ....................................................................................... 2-3-2 2-304. Citizenship of Persons Requiring PCLs .................................................... 2-3-3 2-305. Qualifications of Trustees, Proxy Holders, and Outside Directors ........ 2-3-4 2-306. GSC ................................................................................................................ 2-3-4 2-307. TCP ................................................................................................................ 2-3-4 2-308. Annual Review and Certification ............................................................... 2-3-4 2-309. Limited FCL .................................................................................................. 2-3-5

2-310. Foreign Mergers, Acquisitions and Takeovers and the Committee on Foreign Investment in the United States (CFIUS) ................................. 2-3-5

CHAPTER 3. SECURITY TRAINING AND BRIEFINGS

Change 2, 05/18/2016 4

Section 1. Security Training and Briefings 3-100. General ...................................................................................................... 3-1-1 3-101. Training Materials .................................................................................... 3-1-1 3-102. FSO Training ............................................................................................ 3-1-1 3-103. Insider Threat Training ............................................................................ 3-1-1 3-104. Government-Provided Briefings ............................................................. 3-1-1 3-105. Temporary Help Suppliers ...................................................................... 3-1-1 3-106. Classified Information Nondisclosure Agreement (SF 312) ................ 3-1-1 3-107. Initial Security Briefings .......................................................................... 3-1-2 3-108. Refresher Training ................................................................................... 3-1-2 3-109. Debriefings ............................................................................................... 3-1-2

CHAPTER 4. CLASSIFICATION AND MARKING

Section 1. Classification 4-100. General ..................................................................................................... 4-1-1 4-101. Original Classification ............................................................................. 4-1-1 4-102. Derivative Classification Responsibilities ............................................. 4-1-1 4-103. Security Classification Guidance ........................................................... 4-1-2 4-104. Challenges to Classification .................................................................... 4-1-2 4-105. Contractor Developed Information ........................................................ 4-1-2 4-106. Classified Information Appearing in Public Media .............................. 4-1-3 4-107. Downgrading or Declassifying Classified Information ....................... 4-1-3 Section 2. Marking Requirements 4-200. General ...................................................................................................... 4-2-1 4-201. Marking Requirements for Information and Material ........................... 4-2-1 4-202. Identification Markings ........................................................................... 4-2-1 4-203. Overall Markings ..................................................................................... 4-2-1 4-204. Page Markings .......................................................................................... 4-2-1 4-205. Component Markings .............................................................................. 4-2-1 4-206. Portion Markings ..................................................................................... 4-2-1 4-207. Subject and Title Markings ..................................................................... 4-2-2 4-208. Markings for Derivatively Classified Documents ................................. 4-2-2 4-209. Documents Generated Under Previous E.O.s ........................................ 4-2-2 4-210. Marking Special Types of Material ........................................................ 4-2-3 4-211. Marking Transmittal Documents ............................................................ 4-2-3 4-212. Marking Wholly Unclassified Material .................................................. 4-2-3 4-213. Marking Compilations ............................................................................. 4-2-4 4-214. Working Papers ........................................................................................ 4-2-4

4-215. Marking Miscellaneous Material ............................................................ 4-2-4 4-216. Marking Training Material ...................................................................... 4-2-4 4-217. Downgrading or Declassification Actions ............................................. 4-2-4 4-218. Upgrading Action .................................................................................... 4-2-4 4-219. Inadvertent Release .................................................................................. 4-2-5 4-220. Marking requirements for transfers of defense articles to AUS or the

Change 2, 05/18/2016 5

UK ......................................................................................................... 4-2-5 4-221. Comingling of Restricted Data (RD) and Formerly Restricted

Data (FRD)............................................................................................ 4-2-5

CHAPTER 5. SAFEGUARDING CLASSIFIED INFORMATION

Section 1. General Safeguarding Requirements 5-100. General ........................................................................................................... 5-1-1 5-101. Safeguarding Oral Discussions ................................................................... 5-1-1 5-102. End of Day Security Checks ....................................................................... 5-1-1 5-103. Perimeter Controls ........................................................................................ 5-1-1 5-104. Emergency Procedures ................................................................................ 5-1-1

Section 2. Control and Accountability 5-200. Policy ........................................................................................................ 5-2-1 5-201. Accountability for TOP SECRET .......................................................... 5-2-1 5-202. Receiving Classified Material ................................................................. 5-2-1 5-203. Generation of Classified Material ........................................................... 5-2-1 Section 3. Storage and Storage Equipment 5-300. General ........................................................................................................... 5-3-1 5-301. GSA Storage Equipment ............................................................................. 5-3-1 5-302. TOP SECRET Storage ................................................................................ 5-3-1 5-303. SECRET Storage .......................................................................................... 5-3-1 5-304. CONFIDENTIAL Storage.......................................................................... 5-3-1 5-305. Restricted Areas ............................................................................................ 5-3-1 5-306. Closed Areas ................................................................................................. 5-3-1 5-307. Supplemental Protection .............................................................................. 5-3-2

5-308. Protection of Combinations to Security Containers, Cabinets, Vaults and Closed Areas ................................................................................... 5-3-2

5-309. Changing Combinations .............................................................................. 5-3-2 5-310. Supervision of Keys and Padlocks ............................................................. 5-3-2 5-311. Repair of Approved Containers .................................................................. 5-3-2 5-312. Supplanting Access Control Systems or Devices .................................... 5-3-3 5-313. Automated Access Control Systems .......................................................... 5-3-3 5-314. Electronic, Mechanical, or Electro-mechanical Devices ......................... 5-3-4 Section 4. Transmission 5-400. General ...................................................................................................... 5-4-1 5-401. Preparation and Receipting ..................................................................... 5-4-1 5-402. TOP SECRET Transmission Outside a Facility .................................... 5-4-1 5-403. SECRET Transmission Outside a Facility ............................................. 5-4-1 5-404. CONFIDENTIAL Transmission Outside a Facility ............................. 5-4-1

5-405. Transmission Outside the United States and Its Territorial Areas......... 5-4-1 5-406. Addressing Classified Material ............................................................... 5-4-2 5-407. Transmission Within a Facility ............................................................... 5-4-2 5-408. SECRET Transmission by Commercial Carrier ................................... 5-4-2 5-409. CONFIDENTIAL Transmission by Commercial Carrier .................... 5-4-3

Change 2, 05/18/2016 6

5-410. Use of Couriers, Hand Carriers, and Escorts ......................................... 5-4-3 5-411. Use of Commercial Passenger Aircraft for Transmitting Classified Material ............................................................................................... 5-4-3 5-412. Use of Escorts for Classified Shipments ................................................ 5-4-4 5-413. Functions of an Escort ............................................................................. 5-4-4 Section 5. Disclosure 5-500. General ...................................................................................................... 5-5-1 5-501. Disclosure to Employees ......................................................................... 5-5-1 5-502. Disclosure to Subcontractors ................................................................... 5-5-1 5-503. Disclosure between Parent and Subsidiaries .......................................... 5-5-1 5-504. Disclosure in an MFO ............................................................................. 5-5-1 5-505. Disclosure to DoD Activities .................................................................. 5-5-1 5-506. Disclosure to Federal Agencies ............................................................... 5-5-1 5-507. Disclosure of Classified Information to Foreign Persons ...................... 5-5-1 5-508. Disclosure of Export Controlled Information to Foreign Persons ........ 5-5-1 5-509. Disclosure to Other Contractors .............................................................. 5-5-1 5-510. Disclosure of Classified Information in Connection with Litigation ... 5-5-1 5-511. Disclosure to the Public ........................................................................... 5-5-1 Section 6. Reproduction 5-600. General ...................................................................................................... 5-6-1 5-601. Limitations ................................................................................................ 5-6-1 5-602. Marking Reproductions ........................................................................... 5-6-1 5-603. Records ..................................................................................................... 5-6-1 Section 7. Disposition and Retention 5-700. General ...................................................................................................... 5-7-1 5-701. Retention of Classified Material ............................................................. 5-7-1 5-702. Termination of Security Agreement ....................................................... 5-7-1 5-703. Disposition of Classified Material Not Received Under a Specific Contract ................................................................................................................ 5-7-1 5-704. Destruction ............................................................................................... 5-7-1 5-705. Methods of Destruction ........................................................................... 5-7-1 5-706. Witness to Destruction ............................................................................. 5-7-2 5-707. Destruction Records ................................................................................. 5-7-2 5-708. Classified Waste ....................................................................................... 5-7-2 Section 8. Construction Requirements 5-800. General ...................................................................................................... 5-8-1 5-801. Construction Requirements for Closed Areas........................................ 5-8-1 5-802. Construction Requirements for Vaults ................................................... 5-8-2 Section 9. Intrusion Detection Systems 5-900. General ...................................................................................................... 5-9-1 5-901. CSA Approval .......................................................................................... 5-9-1 5-902. Central Monitoring Station ...................................................................... 5-9-1 5-903. Investigative Response to Alarms ........................................................... 5-9-1 5-904. Installation ................................................................................................ 5-9-2 5-905. Certification of Compliance .................................................................... 5-9-2 5-906. Exceptional Cases .................................................................................... 5-9-2

Change 2, 05/18/2016 7

CHAPTER 6. VISITS and MEETINGS

Section 1. Visits 6-100. General ...................................................................................................... 6-1-1 6-101. Classified Visits ........................................................................................ 6-1-1 6-102. Need-to-Know Determination ................................................................ 6-1-1 6-103. Visits by Government Representatives .................................................. 6-1-1 6-104. Visit Authorization ................................................................................... 6-1-1 6-105. Long-Term Visitors ................................................................................. 6-1-1 Section 2. Meetings 6-200. General ...................................................................................................... 6-2-1 6-201. Government Sponsorship of Meetings ................................................... 6-2-1 6-202. Disclosure Authority at Meetings ........................................................... 6-2-2 6-203. Requests to Attend Classified Meetings ................................................. 6-2-2

CHAPTER 7. SUBCONTRACTING

Section 1. Prime Contractor Responsibilities 7-100. General....................................................................................... 7-1-1 7-101. Responsibilities .......................................................................... 7-1-1 7-102. Security Classification Guidance............................................... 7-1-1 7-103. Responsibilities (Completion of the Subcontract) ..................... 7-1-2 7-104. Notification of Unsatisfactory Conditions ................................. 7-1-2

CHAPTER 8. IS SECURITY

Section 1. Responsibilities and Duties 8-100. General ................................................................................................................. 8-1-1 8-101. IS Security Program ........................................................................................... 8-1-1 8-102. System Security Plan ......................................................................................... 8-1-1 8-103. Contractor Roles & Responsibilities ............................................................... 8-1-1 Section 2. Assessment and Authorization

8-200. Overview ........................................................................................................ 8-2-1 8-201. Assessment ..................................................................................................... 8-2-1 8-202. Authorization ................................................................................................. 8-2-1

Section 3. Security Controls 8-300. Security Controls ...................................................................................... 8-3-1 8-301. Management Controls ............................................................................. 8-3-1 8-302. Operational Controls ................................................................................ 8-3-1 8-303. Technical Controls ................................................................................... 8-3-3 8-304. Special Categories .................................................................................... 8-3-3

CHAPTER 9. SPECIAL REQUIREMENTS

Change 2, 05/18/2016 8

Section 1. RD and FRD, and Transclassified Foreign Nuclear Information (TFNI) 9-100. General ........................................................................................................... 9-1-1

Section 2. DoD Critical Nuclear Weapon Design Information (CNWDI) 9-200. General ........................................................................................................... 9-2-1 9-201. Background ................................................................................................... 9-2-1 9-202. Briefings ......................................................................................................... 9-2-1 9-203. Markings ........................................................................................................ 9-2-1 9-204. Subcontractors ............................................................................................... 9-2-1 9-205. Transmission Outside the Facility ............................................................... 9-2-1 9-206. Records........................................................................................................... 9-2-1 9-207. Weapon Data ................................................................................................. 9-2-1 Section 3. Intelligence Information 9-300. General ...................................................................................................... 9-3-1 Section 4. Communication Security (COMSEC) 9-400. General ...................................................................................................... 9-4-1 9-401. Instructions ............................................................................................... 9-4-1 9-402. Clearance and Access Requirements ...................................................... 9-4-1 9-403. Establishing a COMSEC Account ......................................................... 9-4-1 9-404. COMSEC Briefing and Debriefing Requirements ................................ 9-4-1 9-405. CRYPTO Access Briefing and Debriefing Requirements ................... 9-4-2 9-406. Destruction and Disposition of COMSEC Material .............................. 9-4-2 9-407. Subcontracting COMSEC Work ............................................................ 9-4-2 9-408. Unsolicited Proposals .............................................................................. 9-4-2

CHAPTER 10. INTERNATIONAL SECURITY REQUIREMENTS

Section 1. General and Background Information 10-100. General ....................................................................................................... 10-1-1 10-101. Applicable Federal Laws ......................................................................... 10-1-1 10-102. Bilateral Security Agreements ................................................................ 10-1-1 Section 2. Disclosure of U.S. Information to Foreign Interests 10-200. Authorization for Disclosure ................................................................... 10-2-1 10-201. Direct Commercial Arrangements .......................................................... 10-2-1 10-202. Contract Security Provisions ................................................................... 10-2-1 Section 3. Foreign Government Information 10-300. General ....................................................................................................... 10-3-1 10-301. Contract Security Requirements ............................................................. 10-3-1 10-302. Marking Foreign Government Classified Material .............................. 10-3-1 10-303. Foreign Government RESTRICTED Information and “In Confidence” Information ............................................................................... 10-3-1 10-304. Marking U.S. Documents Containing FGI ........................................... 10-3-1 10-305. Marking Documents Prepared For Foreign Governments ................. 10-3-1 10-306. Storage and Control ................................................................................. 10-3-2 10-307. Disclosure and Use Limitations .............................................................. 10-3-2

Change 2, 05/18/2016 9

10-308. Transfer ...................................................................................................... 10-3-2 10-309. Reproduction ............................................................................................. 10-3-2 10-310. Disposition ................................................................................................ 10-3-2 10-311. Reporting of Improper Receipt of Foreign Government Material ..... 10-3-2 10-312. Subcontracting .......................................................................................... 10-3-2 Section 4. International Transfers 10-400. General.................................................................................................. 10-4-1 10-401. International Transfers of Classified Material.................................... 10-4-1 10-402. Transfers of Freight .............................................................................. 10-4-1 10-403. Return of Material for Repair, Modification, or Maintenance .......... 10-4-2 10-404. Use of Freight Forwarders ................................................................... 10-4-2 10-405. Hand Carrying Classified Material ..................................................... 10-4-2 10-406. Classified Material Receipts ................................................................ 10-4-3

10-407. Contractor Preparations for International Transfers Pursuant to Commercial and User Agency Sales ................................................................ 10-4-3 10-408. Transfers Pursuant to an ITAR Exemption ........................................ 10-4-3

Section 5. International Visits and Control of Foreign Nationals 10-500. General ....................................................................................................... 10-5-1 10-501. International Visits .................................................................................... 10-5-1 10-502. Types and Purpose of International Visits ............................................. 10-5-1 10-503. Emergency Visits ...................................................................................... 10-5-1 10-504. Requests for Recurring Visits .................................................................. 10-5-1 10-505. Amendments ............................................................................................. 10-5-1 10-506. Visits Abroad by U.S. Contractors ......................................................... 10-5-1 10-507. Visits by Foreign Nationals to U.S. Contractor Facilities ..................... 10-5-2 10-508. Control of Access by On-Site Foreign Nationals .................................. 10-5-2 10-509. TCP ............................................................................................................ 10-5-3 10-510. Security and Export Control Violations Involving Foreign Nationals 10-5-3 Section 6. Contractor Operations Abroad.

10-600. General ....................................................................................................... 10-6-1 10-601. Access by Contractor Employees Assigned Outside the United States ............................................................................................................ 10-6-1

10-602. Storage, Custody, and Control of Classified Information Abroad by Employees of a U.S. Contractor ...................................................................... 10-6-1 10-603. Transmission of Classified Material to Employees Abroad ............... 10-6-1 10-604. Security Briefings ..................................................................................... 10-6-2

Section 7. NATO Information Security Requirements 10-700. General ....................................................................................................... 10-7-1 10-701. Classification Levels ................................................................................. 10-7-1 10-702. NATO RESTRICTED ............................................................................ 10-7-1 10-703. NATO Contracts ....................................................................................... 10-7-1 10-704. NATO Facility Security Clearance Certificate ...................................... 10-7-1 10-705. PCL Requirements ................................................................................... 10-7-1 10-706. NATO Briefings ....................................................................................... 10-7-1 10-707. Access to NATO Classified Information by Foreign Nationals .......... 10-7-1 10-708. Subcontracting for NATO Contracts ...................................................... 10-7-1

Change 2, 05/18/2016 10

10-709. Preparing and Marking NATO Documents .......................................... 10-7-1 10-710. Classification Guidance ........................................................................... 10-7-2 10-711. Further Distribution .................................................................................. 10-7-2 10-712. Storage of NATO Documents................................................................. 10-7-2 10-713. International Transmission ....................................................................... 10-7-2 10-714. Hand Carrying ........................................................................................... 10-7-3 10-715. Reproduction ............................................................................................. 10-7-3 10-716. Disposition ................................................................................................. 10-7-3 10-717. Accountability Records ............................................................................ 10-7-3 10-718. Security Violations and Loss, Compromise, or Possible Compromise ............................................................................................................ 10-7-3 10-719. Extracting from NATO Documents ....................................................... 10-7-3 10-720. Release of U.S. Information to NATO ................................................... 10-7-4 10-721. Visits ........................................................................................................... 10-7-4 Section 8. Transfers of Defense Articles to AUS or the UK without a License or Other Written Authorization .......................................... 10-8-1 10-800. General ................................................................................................. 10-8-1 10-801. Defense Articles ................................................................................... 10-8-1 10-802. Marking Requirements ........................................................................ 10-8-1 10-803. Notice ................................................................................................... 10-8-1 10-804. Labelling ............................................................................................... 10-8-2 10-805. Transfers ............................................................................................... 10-8-2 10-806. Records ................................................................................................. 10-8-2

CHAPTER 11. MISCELLANEOUS INFORMATION

Section 1. TEMPEST 11-100. General.................................................................................................. 11-1-1 11-101. TEMPEST Requirements ................................................................... 11-1-1 11-102. Cost ....................................................................................................... 11-1-1 Section 2. Defense Technical Information Center (DTIC) 11-200. General ....................................................................................................... 11-2-1 11-201. User Community ...................................................................................... 11-2-1 11-202. Registration Process ................................................................................. 11-2-1 11-203. Safeguarding Requirements .................................................................... 11-2-1 11-204. DTIC Downgrading or Declassification Notices ................................. 11-2-1 11-205. Questions Concerning Reference Material ........................................... 11-2-1 11-206. Subcontracts .............................................................................................. 11-2-1 Section 3. Independent Research and Development (IR&D) Efforts 11-300. General ....................................................................................................... 11-3-1 11-301. Information Generated Under an IR&D Effort that Incorporates

Classified Information .............................................................................. 11-3-1 11-302. Classification Guidance ........................................................................... 11-3-1 11-303. Preparation of Security Guidance........................................................... 11-3-1 11-304. Retention of Classified Documents Generated Under IR&D Efforts11-3-1

Change 2, 05/18/2016 11

APPENDIXES

Appendix A. Cognizant Security Office Information ................................................................................. A-l Appendix B. International Visits Standard Request for Visit Format (RFV) ....................................... B-l Appendix C. Definitions ........................................................................................................................... C-l Appendix D. NISPOM Supplement – Security Requirements for SAPS, SCI, IC Compartmented Programs, RD and FRD .......................................................................................................................... D-1

Change 2, 05/18/2016 12

REFERENCES

(a) Executive Order 12829, “National Industrial Security Program,” January 6, 1993

(b) Executive Order 13526, “Classified National Security Information,” December 29, 2009

(c) Section 2011 et seq. of title 42, United States Code, “Atomic Energy Act of 1954,” as amended

(d) Section 403 of title 50, United States Code, “National Security Act of 1947,” as amended

(e) Executive Order 12333, “United States Intelligence Activities,” December 4, 1981, as amended

(f) Public Law 108-458, “Intelligence Reform and Terrorism Prevention Act of 2004,” 118

Stat. 3638, December 17, 20041

(g) Section 781 of title 50, United States Code, “Internal Security Act of 1950”

(h) Section 552(f) of title 5, United States Code, “Government Organization and Employees”

(i) DoD 5220.22-C, “Carrier Supplement to the Industrial Security Manual for Safeguarding

Classified Information,” October 1986

(j) Title 18 USC, Appendix 3, “Classified Information Procedures Act (CIPA)”

(k) Section 552 of title 5, United States Code, “Freedom of Information Act”

(l) Section 552a of title 5, United States Code, “Privacy Act of 1975”

(m) Section 2170 of Title 50, United States Code Appendix, “Defense Production Act of 1950”

(n) Intelligence Community Directive 705, “Sensitive Compartmented Information Facilities

(SCIFs),” May 26, 2010.

(o) Underwriters Laboratories Standard 2050, “Standard for National Industrial Security

Systems for the Protection of Classified Materials,” current edition2

(p) Title 10, Code of Federal Regulations

(q) DoD Instruction 5210.02, “Access to and Dissemination of Restricted Data and Formerly

Restricted Data,” June 3, 2011

(r) Department of Energy Order 452.8, “Control of Nuclear Weapon Data,” July 21, 2011

(s) Sections 793, 794, and 798 of title 18, United States Code, Chapter 37, “Espionage and

Censorship”

(t) Section 2751 et seq. of title 22, United States Code, “Arms Export Control Act (AECA),”

June 30, 1976, as amended

(u) App. 2401 et seq. of title 50, United States Code, “The Export Administration Act of 1979

(EAA),” September 29, 1979, as amended

(v) Title 22, Code of Federal Regulations, Parts 120-130, “International Traffic in Arms

Regulations,” current edition

(w) Section 130(c) of title 10, United States Code, “Authority to Withhold from Public

Disclosure Certain Technical Data”

(x) Section 1101(a)(22) and Section 1401, subsection (a) of title 8, United States Code, “Aliens and Nationality”

(y) Title15, Code of Federal Regulations, parts 368.1-399.2, “Export Administration

Regulation (EAR),” current edition

(z) Title 32, Code of Federal Regulations

1 Not codified 2 Copy is available at www.ul.com/contact us. Government agencies with a role as a Cognizant Security Agency or Cognizant Security Office may obtain this reference without charge.

Change 2, 05/18/2016 13

(aa) Information Security Oversight Office Notice 2011-02, “Further Guidance and Clarification on Commingling Atomic Energy Information and Classification National Security Information,” May 18, 2011

(ab) DoD 5220.22-M, Supplement 1, “National Industrial Security Program Operating Manual Supplement,” February 1, 1995 (hereby cancelled)

(ac) Executive Order 13587, “Structural Reforms To Improve the Security of Classified Networks and the Responsible Sharing and Safeguarding of Classified Information”, October 7, 2011

(ad) “The National Insider Threat Policy and Minimum Standards for Executive Branch Insider Threat Programs,” November 21, 20123

(ae) DoD Instruction 5220.22, “National Industrial Security Program (NISP),” March 18, 2011

(af) Public Law 112-239, “National Defense Authorization Act for Fiscal Year 2013,”

January 2, 2013

(ag) Section 391 of title 10, United States Code,“Reporting on cyber incidents with respect to networks and information systems of operationally critical contractors and certain other contractors”

(ah) Subpart 204.73 of title 48, Code of Federal Regulations, “Safeguarding Covered Defense Information and Cyber Incident Reporting”

(ai) Section 3541 et seq. of title 44, United States Code (also known as the “Federal Information Security Management Act (FISMA)”)

(aj) National Institute of Standards and Technology Special Publication 800-37, “Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach” February 2010, as amended4

(ak) Committee on National Security Systems Directive 504, “Protecting NSS from Insider Threat,” February 4, 2014

(al) National Institute of Standards and Technology Special Publication 800-53, “Security and Privacy Controls for Federal Information Systems and Organizations,” current edition

(am) Committee on National Security Systems Information (CNNSI) No. 1253, “Security Categorization and Control Selection for National Security Systems,” March 27, 2014”

(an) Office of Management and Budget Memorandum M-14-03, “Enhancing the Security of Federal Information and Information Systems,” November 18, 2013

(ao) Treaty Between the Government of the United States of America and the Government of the United Kingdom of Great Britain and Northern Ireland Concerning Defense Trade Cooperation, June 21, 20075

(ap) Treaty Between the Government of the United States of America and the Government of the Australia Concerning Defense Trade Cooperation, September 5, 20075

(aq) Committee on National Security Systems Instruction No. 4009, “National Information Assurance (IA) Glossary,” April 26, 2010

(ar) National Security Presidential Directive-54, “Cyber Security and Monitoring,” January 8,

(as) Department of Energy Order 475.2B, “Identifying Classified Information,” October 3, 2014

3 Copy is available at http://www.ncix.gov/nittf/docs/National_Insider_Threat_Policy.pdf 4 Copy is available at http: //csrc.nist.gov/publications/.

5 Copy is available at http://www/pmddtc.state.gov

Change 2, 05/18/2016 14

(at) Department of Energy Manual 205.1B, “Department of Energy Cyber Security Program,” May 16, 2011, as amended

(au) Department of Energy Order 452.7, “Protection of Use Control Vulnerabilities and Designs,” May 14, 2010

(av) Department of Energy Order 452.4B, “Security and Use Control of Nuclear Explosives and Nuclear Weapons,” January 22, 2010

(aw) Department of Energy Order 473.3, “Protection Program Operations,” June 29, 2011

(ax) Department of Energy Order 471.6, “Information Security,” June 20, 2011, as amended

(ay) Department of Energy Manual 483.1-1A, “DOE Cooperative Research and Developments

Agreements Manual,” November 6, 2013

Change 2, 05/18/2016 15

AL1. Acronyms

AL.1.1. ACCM Alternative Compensatory Control Measures AL.1.2. AECA Arms Export Control Act AL.1.3. AO Authorizing Official AL.1.4. ASC Alarm Service Company AL.1.5. ATD Authorization Termination Date AL.1.6 ATO Authorization to Operate AL.1.7 AUS Australia

AL.1.8. BL Bill of Lading

AL.1.9. C CONFIDENTIAL

AL.1.10. CAGE Commercial and Government Entity AL.1.11. CAP Controlled Access Program AL.1.12. CFIUS Committee on Foreign Investment in the United States AL.1.13. CFR Code of Federal Regulations AL.1.14. CI Counterintelligence AL.1.15. CIA Central Intelligence Agency AL.1.16. CM Configuration Management AL.1.17. CNSS Committee on National Security Systems AL.1.18. CNWDI Critical Nuclear Weapons Design Information AL.1.19. COMSEC Communications Security AL.1.20. COR Central Office of Record AL.1.21. CRYPTO Cryptographic AL.1.22. CSA Cognizant Security Agency AL.1.23. CSO Cognizant Security Office AL.1.24. CUSR Central United States Registry AL.1.25. CVA Central Verification Activity

AL.1.26. DCID Director of Central Intelligence Directive AL.1.27. DDTC Directorate of Defense Trade Controls AL.1.28. DGR Designated Government Representative AL.1.29. DNI Director of National Intelligence AL.1.30. DOD Department of Defense AL.1.31. DOE Department of Energy AL.1.32. DOJ Department of Justice AL.1.33. DSS Defense Security Service AL.1.34. DTIC Defense Technical Information Center

AL.1.35. EAA Export Administration Act AL 1.36. EPA Environmental Protection Agency

AL.1.37. FBI Federal Bureau of Investigation AL.1.38. FCC Federal Communications Commission AL.1.39. FCL Facility (Security) Clearance AL.1.40. FGI Foreign Government Information AL.1.41. FOCI Foreign Ownership, Control or Influence AL.1.42. FOUO For Official Use Only AL.1.43. FRD Formerly Restricted Data AL.1.44. FRS Federal Reserve System AL.1.45. FSCC NATO Facility Security Clearance Certificate AL.1.46. FSO Facility Security Officer

AL.1.47. GAO Government Accountability Office

Change 2, 05/18/2016 16

AL.1.48. GCA Government Contracting Activity AL.1.49. GCMS Government Contractor Monitoring Station AL.1.50. GFE Government Furnished Equipment AL.1.51. GSA General Services Administration AL.1.52. GSC Government Security Committee

AL.1.53. IATO Interim Authorization to Operate AL.1.54. IC Intelligence Community AL.1.55. IDS Intrusion Detection System AL.1.56. IFB Invitation for Bid AL.1.57. IR&D Independent Research & Development AL.1.58. IS Information System AL.1.59. ISs Information Systems AL.1.60. ISCAP Interagency Security Classification Appeals Panel AL.1.61. ISL Industrial Security Letter AL.1.62. ISOO Information Security Oversight Office AL.1.63. ISR Industrial Security Representative AL.1.64. ISSM Information System Security Manager AL.1.65. ISSO Information System Security Officer AL.1.66. ITAR International Traffic in Arms Regulations

AL.1.67. LAA Limited Access Authorization AL.1.68. LAN Local Area Network AL.1.69. MFO Multiple Facility Organization

AL.1.70. NACLC National Agency Check with Local Agency Check and Credit Check AL.1.71. NASA National Aeronautics and Space Administration AL.1.72. NATO North Atlantic Treaty Organization AL.1.73. NIAG NATO Industrial Advisory Group AL.1.74. NID National Interest Determination AL.1.75. NISP National Industrial Security Program AL.1.76. NISPOM National Industrial Security Program Operating Manual AL.1.77. NISPOMSUP National Industrial Security Program Operating Manual Supplement AL.1.78. NIST National Institute for Standards and Technology AL.1.79. NOFORN Not Releasable to Foreign Nationals AL.1.80. NPLO NATO Production Logistics Organization AL.1.81. NRC Nuclear Regulatory Commission AL.1.82. NSA National Security Agency AL.1.83. NSF National Science Foundation AL.1.84. NSI National Security Information

AL.1.85. OADR Originating Agency's Determination Required AL.1.86. ORCON Dissemination and Extraction of Information Controlled by Originator

AL.1.87 PCL Personnel (Security) Clearance AL.1.88. PROPIN Proprietary Information Involved

AL.1.89. RD Restricted Data AL.1.90. RDT&E Research, Development, Test, and Evaluation AL.1.91. REL TO Authorized for Release to AL.1.92. RFP Request for Proposal AL.1.93. RFQ Request for Quotation AL.1.94. RFV Request for Visit

AL.1.95. S SECRET

AL.1.96. SAP Special Access Program

Change 2, 05/18/2016 17

AL.1.97. SBA Small Business Administration AL.1.98. SCA Security Control Agreement AL.1.99. SCI Sensitive Compartmented Information AL.1.100. SCIF Sensitive Compartmented Information Facility AL.1.101. SDDC Surface Deployment and Distribution Command AL.1.102. SIO Senior Intelligence Officer AL.1.103. SSA Special Security Agreement AL.1.104. SSBI Single Scope Background Investigation AL.1.105. SSP Systems Security Plan

AL.1.106. TS TOP SECRET

AL.1.107. TCO Technology Control Officer AL.1.108. TCP Technology Control Plan AL.1.109. TFNI Transclassified Foreign Nuclear Information AL.1.110. TP Transportation Plan

AL.1.111. UK United Kingdom AL.1.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .