Bidders Library Security - DoDM 5200 01 Vol 1.pdf
PDF 495 KB Posted
- Attached to
- TEC II Services RFP Federal contract opportunity
- Solicitation number
- HC102821R0006
- Issued by
- Defense Information Systems Agency
About this file
This request for proposal solicits test, evaluation, and certification services for the Joint Interoperability Test Command. The Defense Information Systems Agency is seeking proposals to provide services such as testing and evaluating new and existing command, control, communications, computers, and intelligence systems to ensure interoperability and integration across the joint force. Offerors should have experience with interoperability testing of IT systems and networks. The closing date for proposals is June 15, 2022. The period of performance is a one-year base period with four one-year options.
View the file
Other files for this federal contract opportunity
Show all 50
TEC II Services RFP has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Department of Defense
MANUAL
NUMBER 5200.01, Volume 1 February 24, 2012
Incorporating Change 2, July 28, 2020
USD(I&S)
SUBJECT: DoD Information Security Program: Overview, Classification, and
Declassification
References: See Enclosure 1
1. PURPOSE
a. Manual. This Manual is composed of several volumes, each containing its own purpose.
The purpose of the overall Manual, as authorized by DoD Directive (DoDD) 5143.01 (Reference (a)) and DoD Instruction (DoDI) 5200.01 (Reference (b)), is to reissue DoD 5200.1-R (Reference (c)) as a DoD manual (DoDM) to implement policy, assign responsibilities, and provide procedures for the designation, marking, protection, and dissemination of controlled unclassified information (CUI) and classified information, including information categorized as collateral, sensitive compartmented information (SCI), and Special Access Program (SAP). This guidance is developed in accordance with Reference (b), Executive Order (E.O.) 13526 and E.O.
13556, and parts 2001 and 2002 of title 32, Code of Federal Regulations (References (d), (e), and (f)). This combined guidance is known as the DoD Information Security Program.
b. Volume. This Volume:
(1) Describes the DoD Information Security Program.
(2) Provides guidance for classification and declassification of DoD information that requires protection in the interest of the national security.
(3) Cancels Reference (c) and DoD O-5200.1-I (Reference (g)).
(4) Incorporates and cancels Directive-Type Memorandums 04-010 (Reference (h)) and 11-004 (Reference (i)).
2. APPLICABILITY. This Volume:
DoDM 5200.01-V1, February 24, 2012
Change 2, 7/28/2020 2
a. Applies to OSD, the Military Departments, the Office of the Chairman of the Joint Chiefs of Staff and the Joint Staff, the Combatant Commands, the Office of the Inspector General of the Department of Defense, the Defense Agencies, the DoD Field Activities, and all other organizational entities within the Department of Defense (hereinafter referred to collectively as the “DoD Components”).
b. Does NOT alter existing authorities and responsibilities of the Director of National Intelligence (DNI) or of the heads of elements of the Intelligence Community pursuant to policies issued by the DNI. Consistent with Reference (b), SCI shall be safeguarded in accordance with the policies and procedures issued by the DNI, as implemented by Volumes 1 - 3 of DoDM 5105.21 (Reference (j)) and other applicable guidance.
3. DEFINITIONS. See Glossary.
4. POLICY. It is DoD policy, in accordance with Reference (b), to:
a. Identify and protect national security information and CUI in accordance with national level policy issuances.
b. Promote information sharing, facilitate judicious use of resources, and simplify management through implementation of uniform and standardized processes.
c. Classify and declassify national security information as required by References (d) and (f).
5. RESPONSIBILITIES. See Enclosure 2.
6. PROCEDURES. See Enclosures 3 through 6.
7. INFORMATION COLLECTION REQUIREMENTS
a. The Annual Report on Classified Information referenced in paragraph 7.m. of Enclosure 2 of this Volume has been assigned Report Control Symbol (RCS) DD-INT(AR)1418 in accordance with the procedures in Volume 1 of DoDM 8910.01 (Reference (k)).
b. The DoD Security Classification Guide Data Elements, DoD (DD) Form 2024, “DoD Security Classification Guide Certified Data Elements,” referenced in section 6 of Enclosure 6 of this Volume, has been assigned RCS DD-INT(AR)1418 in accordance with the procedures in Reference (k).
Change 2, 7/28/2020 3
8. RELEASABILITY. Cleared for public release. This Volume is available on the DoD Issuances Website at https://www.esd.whs.mil/DD.
9. SUMMARY OF CHANGE 2. This administrative change updates:
a. The title of the Under Secretary of Defense for Intelligence to the Under Secretary of Defense for Intelligence and Security (USD(I&S)) in accordance with Public Law 116-92 (Reference (bo)).
b. Administrative changes in accordance with current standards of the Office of the Chief Management Officer of the Department of Defense.
10. EFFECTIVE DATE. This Volume is effective February 24, 2012.
Enclosures
1. References
2. Responsibilities
3. DoD Information Security Program Overview
4. Classifying Information
5. Declassification and Changes in Classification
6. Security Classification Guides
Glossary
Change 2, 7/28/2020 4 CONTENTS
TABLE OF CONTENTS
ENCLOSURE 1: REFERENCES
ENCLOSURE 2: RESPONSIBILITIES
(USD(I&S))
UNDER SECRETARY OF DEFENSE FOR POLICY (USD(P))
DoD CHIEF INFORMATION OFFICER (CIO)
ADMINISTRATOR, DEFENSE TECHNICAL INFORMATION CENTER (DTIC)
DIRECTOR, WHS
HEADS OF THE DoD COMPONENTS
SENIOR AGENCY OFFICIALS
HEADS OF DoD ACTIVITIES
ACTIVITY SECURITY MANAGER
TSCO
SENIOR INTELLIGENCE OFFICIALS
INFORMATION SYSTEMS SECURITY OFFICIALS
ENCLOSURE 3: DoD INFORMATION SECURITY PROGRAM OVERVIEW
PURPOSE
SCOPE
PERSONAL RESPONSIBILITY
NATIONAL AUTHORITIES FOR SECURITY MATTERS
President of the United States National Security Council (NSC)
DNI
ISOO
CUI Office (CUIO)
DoD INFORMATION SECURITY PROGRAM MANAGEMENT
USD(I&S)
USD(P)
DoD CIO National Security Agency/Central Security Service (NSA/CSS)
DIA
Defense Security Service (DSS)
DTIC
DoD COMPONENT INFORMATION SECURITY MANAGEMENT Head of the DoD Component Senior Agency Officials Activity Security Management
TSCO
Other Security Management Roles
USE OF CONTRACTORS IN SECURITY ADMINISTRATION
Change 2, 7/28/2020 5 CONTENTS
USE OF FOREIGN NATIONALS IN SECURITY
ADMINISTRATION……………………
CLASSIFICATION AUTHORITY
CLASSIFICATION POLICY
RECLASSIFICATION
ACCESS TO CLASSIFIED INFORMATION
Requirements for Access Nondisclosure Agreements NATO Briefing for Cleared Personnel Access By Individuals Outside the Executive Branch
PROTECTION REQUIREMENTS
Protection of Restricted Data (RD) and Formerly Restricted Data (FRD) Protection of SCI Protection of COMSEC Information Protection of SAP Information Protection of NATO and FGI Protection of Nuclear Command and Control-Extremely Sensitive Information
(NC2-ESI)
RETENTION
PERMANENTLY VALUABLE RECORDS
MILITARY OPERATIONS
WAIVERS AND EXCEPTIONS
CORRECTIVE ACTIONS AND SANCTIONS
Procedures Sanctions Reporting of Incidents
APPENDIX: DOD COMPONENT REQUEST FOR WAIVER OR
EXCEPTION………………………… ......................................................................…...39
ENCLOSURE 4: CLASSIFYING INFORMATION
CLASSIFICATION POLICY
CLASSIFICATION PROHIBITIONS
LEVELS OF CLASSIFICATION
Top Secret Secret Confidential
ORIGINAL CLASSIFICATION
REQUESTS FOR OCA
ORIGINAL CLASSIFICATION PROCESS
CHANGING THE LEVEL OF CLASSIFICATION
SECURITY CLASSIFICATION GUIDANCE
TENTATIVE CLASSIFICATION
DERIVATIVE CLASSIFICATION
RESPONSIBILITIES OF DERIVATIVE CLASSIFIERS
Change 2, 7/28/2020 6 CONTENTS
PROCEDURES FOR DERIVATIVE CLASSIFICATION
DURATION OF CLASSIFICATION
Originally Classified Information Derivatively Classified Information Extending the Duration of Classification
FORMAT FOR DISSEMINATION
COMPILATIONS
CLASSIFICATION OF ACQUISITION INFORMATION
CLASSIFICATION OF INFORMATION RELEASED TO THE PUBLIC
Classified Information Released Without Proper Authority Reclassification of Information Declassified and Released to the Public Under
Proper Authority Information Declassified and Released to the Public Without Proper Authority
CLASSIFICATION OR RECLASSIFICATION FOLLOWING RECEIPT OF A
REQUEST FOR INFORMATION
CLASSIFYING NON-GOVERNMENT RESEARCH AND DEVELOPMENT
INFORMATION
THE PATENT SECRECY ACT OF 1952
REQUESTS FOR CLASSIFICATION DETERMINATION
CHALLENGES TO CLASSIFICATION
Principles Procedures
ENCLOSURE 5: DECLASSIFICATION AND CHANGES IN CLASSIFICATION
DECLASSIFICATION POLICY
PROCESSES FOR DECLASSIFICATION
AUTHORITY TO DECLASSIFY
DECLASSIFICATION GUIDANCE
DECLASSIFICATION OF INFORMATION
CANCELING OR CHANGING CLASSIFICATION MARKINGS
SPECIAL PROCEDURES FOR CRYPTOLOGIC INFORMATION
PERMANENTLY VALUABLE RECORDS
RECORDS DETERMINED NOT TO HAVE PERMANENT HISTORICAL VALUE
EXTENDING CLASSIFICATION BEYOND 25 YEARS FOR UNSCHEDULED
RECORDS
CLASSIFIED INFORMATION IN THE CUSTODY OF CONTRACTORS,
LICENSEES, GRANTEES, OR OTHER AUTHORIZED PRIVATE
ORGANIZATIONS OR INDIVIDUALS
AUTOMATIC DECLASSIFICATION
Deadline Secretary of Defense Certification Public Release of Automatically Declassified Documents Basis for Exclusion or Exemption from Automatic Declassification Exclusion of RD and FRD Integral File Block
Change 2, 7/28/2020 7 CONTENTS
Delays of Automatic Declassification Automatic Declassification of Backlogged Records at NARA Declassification Review Techniques
EXEMPTIONS FROM AUTOMATIC DECLASSIFICATION
Exemption Types Exemption Criteria and Duration Exemption Requests When to Request an Exemption Who Identifies and Requests an Exemption ISCAP Authority Notice to Information Holders
DECLASSIFICATION OF INFORMATION MARKED WITH OLD
DECLASSIFICATION INSTRUCTIONS
REFERRALS IN THE AUTOMATIC DECLASSIFICATION PROCESS
Description Referral Responsibility
MANDATORY DECLASSIFICATION REVIEW
SYSTEMATIC REVIEW FOR DECLASSIFICATION
DOWNGRADING CLASSIFIED INFORMATION
UPGRADING CLASSIFIED INFORMATION
DECLASSIFYING FGI
APPLICATION OF DECLASSIFICATION AND EXTENSION OF CLASSIFICATION
TO PRESENT AND PREDECESSOR EXECUTIVE ORDERS
ENCLOSURE 6: SECURITY CLASSIFICATION GUIDES
GENERAL
CONTENT OF SECURITY CLASSIFICATION GUIDES
CUI AND UNCLASSIFIED ELEMENTS OF INFORMATION
DATA COMPILATION CONSIDERATIONS
APPROVAL OF SECURITY CLASSIFICATION GUIDES
DISTRIBUTION OF SECURITY CLASSIFICATION GUIDES
INDEX OF SECURITY CLASSIFICATION GUIDES
REVIEW OF SECURITY CLASSIFICATION GUIDES
REVISION OF SECURITY CLASSIFICATION GUIDES
CANCELLING SECURITY CLASSIFICATION GUIDES
REPORTING CHANGES TO SECURITY CLASSIFICATION GUIDES
FUNDAMENTAL CLASSIFICATION GUIDANCE REVIEWS
GLOSSARY
PART I. ABBREVIATIONS AND ACRONYMS
PART II. DEFINITIONS
Change 2, 7/28/2020 8 ENCLOSURE 1
ENCLOSURE 1
REFERENCES
(a) DoD Directive 5143.01, “Under Secretary of Defense for Intelligence and Security
(USD(I&S)),” October 24, 2014, as amended
(b) DoD Instruction 5200.01, “DoD Information Security Program and Protection of Sensitive
Compartmented Information (SCI),” April 21, 2016
(c) DoD 5200.1-R, “Information Security Program,” January 14, 1997 (hereby cancelled)
(d) Executive Order 13526, “Classified National Security Information,” December 29, 2009
(e) Executive Order 13556, “Controlled Unclassified Information,” November 4, 2010
(f) Parts 2001 and 2002 of title 32, Code of Federal Regulations
(g) DoD O-5200.1-I, “Index of Security Classification Guides (U),” September 1, 1996 (hereby cancelled)
(h) Directive-Type Memorandum 04-010, “Interim Information Security Guidance,” April 16, 2004 (hereby cancelled)
(i) Directive-Type Memorandum 11-004, “Immediate Implementation Provisions of Executive
Order 13526, “Classified National Security Information,” April 26, 2011 (hereby cancelled)
(j) DoD Manual 5105.21, Volumes 1 - 3, “Sensitive Compartmented Information (SCI)
Administrative Security Manual,” October 19, 2012
(k) DoD Manual 8910.01, Volume 1,“DoD Information Collections Manual: Procedures for
DoD Internal Information Collections,” June 30, 2014, as amended
(l) Section 2723 of title 10, United States Code
(m) DoD Directive 5210.50, “Management of Serious Security Incidents Involving Classified
Information,” October 27, 2014
(n) DoD Directive 5205.16, “The DoD Insider Threat Program,” September 30, 2014, as amended
(o) Joint Under Secretary of Defense for Intelligence, DoD Chief Information Officer, and
Commander, United States Strategic Command Memorandum, “Effective Integration of Cyber and Traditional Security Efforts,” March 31, 2014
(p) DoD Directive 5111.1, “Under Secretary of Defense for Policy (USD(P)),” December 8, 1999
(q) DoD Directive 5205.07, “Special Access Program (SAP) Policy,” July 1, 2010
(r) DoD Inspector General Report DODIG-2013-142, “DoD Evaluation of Over-Classification of National Security Information,” September 30, 2013
(s) DoD 5200.2-R, “Personnel Security Program,” January 1987, as amended
(t) DoD Directive 5100.55, “United States Security Authority for North Atlantic Treaty
Organization Affairs (USSAN),” February 27, 2006
(u) United States Security Authority for NATO Affairs Instruction 1-07, “Implementation of
North Atlantic Treaty Organization (NATO) Security Requirements,” April 5, 20071
(v) DoD Directive 5230.09, “Clearance of DoD Information for Public Release,”
August 22, 2008, as amended
(w) DoD Instruction 5230.29, “Security and Policy Review of DoD Information for Public
Release,” August 13, 2014, as amended
1 Available from the Central U.S. Registry.
Change 2, 7/28/2020 9 ENCLOSURE 1
(x) DoD Instruction 8550.01, “DoD Internet Services and Internet-Based Capabilities,” September 11, 2012
(y) DoD Directive 5230.11, “Disclosure of Classified Military Information to Foreign Governments and International Organizations,” June 16, 1992
(z) DoD Directive 5230.20, “Visits and Assignments of Foreign Nationals,” June 22, 2005
(aa) DoD Instruction 5200.08, “Security of DoD Installations and Resources and the DoD
Physical Security Review Board (PSRB),” December 10, 2005, as amended
(ab) DoD Instruction 5220.22, “National Industrial Security Program (NISP),” March 18, 2011
(ac) Executive Order 12968, “Access to Classified Information,” August 2, 1995, as amended
(ad) Intelligence Community Directive 703, “Protection of Classified National intelligence, Including Sensitive Compartmental Information (SCI),” June 21 20132
(ae) DoD Instruction 8500.01, “Cybersecurity,” March 14, 2014
(af) Sections 3021, 3141, 3142, 3143, 3144, 1801(p) and 2673 of title 50, United States Code
(ag) Section 1011 of Public Law 108-458, “Intelligence Reform and Terrorism Prevention Act of 2004,” December 17, 2004
(ah) Executive Order 12333, “United States Intelligence Activities,” December 4, 1981, as amended
(ai) Part 1045 of title 10, Code of Federal Regulations
(aj) DoD Directive 5144.02, “DoD Chief Information Officer (DoD CIO),”November 21, 2014, as amended
(ak) National Security Directive 42, “National Policy for the Security of National Security
Telecommunications and Information Systems,” July 5, 19903
(al) DoD Instruction 3305.13, “DoD Security Education, Training, and Certification,” February
13, 2014
(am) DoD Instruction 5230.24, “Distribution Statements on Technical Documents,”
August 23, 2012, as amended
(an) National Security Agency/Central Security Service Policy Manual 3-16, “Control of
Communications Security (COMSEC) Material,” August 5, 20054
(ao) DoD Instruction 1100.22, “Policy and Procedures for Determining Workforce Mix,”
April 12, 2010, as amended
(ap) Office of Federal Procurement Policy Letter 11-01, “Performance of Inherently
Governmental and Critical Functions,” September 12, 2011
(aq) Section 2011, et seq, of title 42, United States Code (also known as “The Atomic Energy
Act of 1954, as amended”)
(ar) DoD Directive 5210.48, “Credibility Assessment (CA) Program,” April 24, 2015, as amended
(as) DoD Instruction 5210.02, “Access to and Dissemination of Restricted Data and Formerly
Restricted Data,” June 3, 2011, as amended
(at) DoD Instruction 5205.11, “Management, Administration, and Oversight of DoD Special
Access Programs (SAPs),” February 6, 2013
2 Available from the Office of the Director of National Intelligence.
3 Available on SIPRNET at http://www.iad.nsa.smil.mil/resources/library/natl_pols_dirs_orders_section/index.cfm.
4 CUI document, available to authorized users. Contact the NSA/CSS Office of Corporate Policy (DJP1) for assistance.
Change 2, 7/28/2020 10 ENCLOSURE 1
(au) Chairman of the Joint Chiefs of Staff Instruction 3231.01B, “Safeguarding Nuclear Command and Control Extremely Sensitive Information,” June 21, 20065
(av) Chapters 21, 22,6 31, 33, and 35 of title 44, United States Code
(aw) DoD Instruction 5015.02, “DoD Records Management Program,” February 24, 2015, as amended
(ax) Sections 801-940 of title 10, United States Code (also known as “The Uniform Code of
Military Justice”)
(ay) Sections 102, 105, 552,7 and 552a8 of title 5, United States Code
(az) DoD Directive 5000.01, “The Defense Acquisition System,” May 12, 2003
(ba) DoD Instruction 5000.02, “Operation of the Defense Acquisition System,” January 7, 2015, as amended
(bb) DoD Instruction 5200.39, “Critical Program Information (CPI) Identification and
Protection Within Research, Development, Test, and Evaluation (RDT&E),” May 28, 2015, as amended
(bc) DoD Instruction 3204.01, “DoD Policy for Oversight of Independent Research and Development (IR&D),” August 20, 2014
(bd) Sections 181 through 188 of title 35, United States Code (also known as “The Patent Secrecy Act of 1952, as amended”)
(be) DoD Directive 5230.25, “Withholding of Unclassified Technical Data From Public Disclosure,” November 6, 1984, as amended
(bf) Section 1041 of Public Law 106-65, “National Defense Authorization Act for Fiscal Year 2000,” October 5, 1999
(bg) Section 3161 of Public Law 105-261, “Strom Thurmond National Defense Authorization Act for Fiscal Year 1999,” October 17, 1998, as amended (also known as “The Kyl-Lott Amendment”)
(bh) Presidential Memorandum, “Implementation of the Executive Order, ‘Classified National Security Information,’” December 29, 2009
(bi) Executive Order 12951, “Release of Imagery Acquired by Space-Based National Intelligence Reconnaissance Systems,” February 22, 1995
(bj) DoD 7000.14-R, Volume 11A, “Department of Defense Financial Management Regulation (FMR): Reimbursable Operations Policy,” current edition
(bk) DoD Instruction 3200.12, “DoD Scientific and Technical Information Program (STIP),” August 22, 2013
(bl) Executive Order 12958, “Classified National Security Information,” April 17, 1995, as amended
(bm) DoD Manual 5200.45, “Instructions for Developing Security Classification Guides,” April 2, 2013
(bn) DoD 5400.7-R, “DoD Freedom of Information Act Program,” September 4, 1998, as amended
(bo) Public Law 116-92, “National Defense Authorization Act for Fiscal Year 2020,” December 20, 2019
5 This document is CUI. It is available to authorized recipients at https://ca.dtic.mil/cjcs_directives/index.htm 6 Chapter 22 is also known as “The Presidential Records Act of 1978.”
7 Section 552 is also known as “The Freedom of Information Act, as amended.”
8 Section 552a is also known as “The Privacy Act of 1974, as amended.”
Change 2, 7/28/2020 11 ENCLOSURE 2
ENCLOSURE 2
RESPONSIBILITIES
1. (USD(I&S)). The USD(I&S) shall:
a. Serve as the DoD Senior Security Official, in accordance with Reference (a), and in that capacity is the DoD Senior Agency Official appointed pursuant to subsection 5.4(d) of Reference
(d) to direct, administer, and oversee the DoD Information Security Program.
b. Notify the Congress and the Director, Information Security Oversight Office (ISOO), as appropriate, of violations involving classified information and of approval of waivers involving Reference (d) and its implementing directive, Reference (f), as required by section 2723 of title 10, United States Code (U.S.C.) (Reference (l)) and References (d) and (f).
c. Establish requirements for collecting and reporting data as necessary to fulfill the requirements of References (d) and (f) and other national-level guidance.
d. Designate a senior-level Federal employee, and an alternate, to represent the Department of Defense on the Interagency Security Classification Appeals Panel (ISCAP) as required by Reference (d). The individuals so designated must be full-time or permanent part-time employees of the Department of Defense. Designate to the ISCAP Chair in writing one or more individuals as identified by the Director, Washington Headquarters Services (WHS) to serve as a liaison in support of the DoD representative in accordance with the ISCAP bylaws in Reference (f).
e. Establish policy and oversee program implementation for reporting and investigating known or suspected incidents of unauthorized disclosure of classified information and for reporting corrective and disciplinary action taken in accordance with DoDD 5210.50 (Reference (m)).
f. Serve as the principal point of contact on counterintelligence (CI) and security investigative matters that involve the unauthorized disclosure of classified information referred to the Department of Defense by other government agencies or that may involve other government agencies in accordance with Reference (m).
g. Develop and oversee policy, strategy, plans, programs, required capabilities and resources for DoD intelligence, CI, security, sensitive activities, and other intelligence and security related matters, as necessary to counter insider threats. Serves as the senior official and principal advisor to the Secretary of Defense on the DoD Insider Threat program in accordance with DoDD 5205.16 (Reference (n)), and in this capacity, will:
(1) Provide oversight of the DoD Insider Threat Program.
Change 2, 7/28/2020 12 ENCLOSURE 2
(2) Assign responsibilities to the DoD Components to implement the DoD Insider Threat Program.
(3) Recommend improvements to the Secretary of Defense on DoD insider threat activities.
h. In coordination with the DoD Chief Information Officer (DoD CIO), the Chairman of the Joint Chiefs of Staff, the DoD Component heads, and the Director of National Intelligence, develop and integrate traditional and cyber security risk-based strategies and phased approaches to measurably increase DoD’s security posture against insider threats in accordance with the joint USD(I&S), DoD CIO, and Commander, United States Strategic Command Memorandum (Reference (o)).
2. UNDER SECRETARY OF DEFENSE FOR POLICY (USD(P)). The USD(P) shall:
a. Serve as the senior official responsible for administering that portion of the DoD Information Security Program pertaining to the National Classified Military Information Disclosure Policy, foreign government (including North Atlantic Treaty Organization (NATO)) information, and security arrangements for international programs in accordance with DoDD
5111.1 (Reference (p)) and Reference (a).
b. Notify the Director, ISOO, of approval of waivers involving Reference (d) and its implementing directive, Reference (f).
3. DoD CIO. The DoD CIO shall:
a. Establish procedures, consistent with References (d) and (f) and this Manual, to ensure that information systems, including networks and telecommunications systems, that process, disseminate, or store classified information:
(1) Prevent access by unauthorized persons.
(2) Assure the integrity of the information.
(3) Use, to the maximum extent practicable, common information technology (IT) standards, protocols, and interfaces, and standardized electronic formats to maximize availability and authorized access.
b. Direct the use of technical means to prevent unauthorized copying of classified data and for anomaly detection to recognize unusual patterns of accessing, handling, downloading, and removal of digital classified information.
4. ADMINISTRATOR, DEFENSE TECHNICAL INFORMATION CENTER (DTIC). The Administrator, DTIC, under the authority, direction, and control of the Under Secretary of
Change 2, 7/28/2020 13 ENCLOSURE 2
Defense for Acquisition, Technology, and Logistics and in addition to the responsibilities in section 6 of this enclosure, shall maintain an index of security classification guides in an online database accessible through www.dtic.mil.
5. DIRECTOR, WHS. The Director, WHS, under the authority, direction, and control of the Chief Management Officer of the Department of Defense, through the Director of Administration, shall identify to the USD(I&S) an individual and at least one alternate to serve as the ISCAP liaison for the Department of Defense in accordance with the ISCAP Bylaws in Reference (f).
6. HEADS OF THE DoD COMPONENTS. The Heads of the DoD Components shall, in accordance with Reference (b):
a. Be responsible for the overall management, functioning, and effectiveness of the information security program within their respective DoD Component.
b. Appoint a senior agency official to be responsible for directing, administering, and overseeing the information security program within the Component on his or her behalf and ensure that official accomplishes the responsibilities in section 7 of this enclosure. The DoD Component Head may designate a separate senior official to be responsible for overseeing SAPs within the Component, if necessary, in accordance with DoDD 5205.07 (Reference (q)).
c. If the Component is not an element of the Intelligence Community, designate a senior intelligence official to be responsible for ensuring adequate funding and effective implementation of the Component’s SCI security program, including awareness and education, consistent with guidance established by the DNI.
d. Identify, program for, and commit necessary resources to effectively implement the requirements for protection of classified information as part of the Component’s information security program.
e. Conduct, as periodically directed by the USD(I&S), reviews of the DoD Component’s classification guidance and provide reports summarizing results.
f. Ensure the Component Senior Agency Official and the Component Senior Intelligence Official coordinate as appropriate to achieve a harmonized and cohesive information security program within the DoD Component.
7. SENIOR AGENCY OFFICIALS. The senior agency officials, under the authority, direction, and control of the Heads of the DoD Components, appointed in accordance with section 6 of this enclosure shall, in addition to the responsibilities in Volume 4 of this Manual:
a. Direct, administer, and oversee their respective DoD Component’s information security program.
Change 2, 7/28/2020 14 ENCLOSURE 2
b. Develop guidance as necessary for program implementation within the DoD Component.
c. Direct the head of each activity within the DoD Component that creates, handles, or stores classified information to appoint, in writing, an official to serve as security manager for the activity, to properly manage and oversee the activity’s information security program. Persons appointed to these positions shall be provided training as Enclosure 5 of Volume 3 of this Manual requires.
d. Establish and maintain an ongoing self-inspection and oversight program to evaluate and assess the effectiveness and efficiency of the DoD Component’s implementation of that portion of the information security program pertaining to classified information.
(1) Evaluation criteria shall consider, at a minimum, original and derivative classification, declassification, safeguarding, security violations, education and training, and management and oversight.
(2) The program shall include regular review and assessment of representative samples of the DoD Component’s classified products. Appropriate officials shall be authorized to correct misclassification of information, except for information covered by paragraph 17.b. or section 18 of Enclosure 4 of this Volume.
(3) Self-inspections shall be conducted at least annually with the frequency established based on program needs and classification activity. DoD Component activities that originate significant amounts of classified information should be inspected at least annually. Annual reports on the Component’s self-inspection program shall be submitted as required by ISOO and/or USD(I&S). The report shall include:
(a) A description of the agency’s self-inspection program, to include activities assessed, program areas covered, and methodology utilized.
(b) A summary of the findings in the following program areas: original classification, derivative classification, declassification, safeguarding, security violations, security education and training, and management and oversight.
(c) Specific information on the findings of the annual review of agency original and derivative classification actions to include the volume of classified materials reviewed and the number and type of discrepancies that were identified.
(d) Actions taken or planned to correct identified deficiencies or misclassification actions, and to deter their recurrence.
(e) Best practices identified. The DoD Inspector General Report DODIG-2013-142 (Reference (r)) identifies examples of DoD Component best practices, including the following:
Change 2, 7/28/2020 15 ENCLOSURE 2
(1) Using Microsoft SharePoint to make available all information that security managers need to manage their programs and share unit best practices.
(2) Creating and using an electronic security manager handbook.
(3) Providing and maintaining open communications between different levels of management structure within the organization.
(4) Establishing and using online training tools to track training requirement completion.
(5) Issuing and using the Quarterly Security newsletter that provides information security articles, security updates, and upcoming security courses.
(6) Maintaining an automated security incident reporting program.
(7) Maintaining complete inventories of all classified documents and electronic media to provide precise tracking of classified holdings.
(8) Developing organization derivative classification training.
(9) Reviewing the process for public release of information.
(10) Maintaining a central security and education awareness mailbox with questions answered by close of business.
(11) Tracking mandatory annual security and derivative classification training by the Human Resources Information System of Record, which enhances better oversight of training completion rates.
(12) Developing a comprehensive security database reflecting final adjudication and investigation of security incidents.
e. Establish procedures to prevent unauthorized persons from accessing classified information, including:
(1) Specific requirements for protecting classified information at DoD Component-sponsored meetings and conferences, to include seminars, exhibits, symposiums, conventions, training activities, workshops, or other such gatherings, during which classified information is disseminated.
(2) Requirements for protecting U.S. classified information located in foreign countries, with particular attention on ensuring proper enforcement of controls on release of U.S. classified information to foreign entities.
Change 2, 7/28/2020 16 ENCLOSURE 2
(3) Procedures to accommodate visits to DoD Component facilities involving access to, or disclosure of, classified information.
f. Establish and maintain declassification programs and plans that meet the requirements of this Manual and ensure that necessary resources are applied to the review of information to ensure it is neither classified for longer than necessary nor declassified prematurely.
g. Establish and maintain a security education and training program as required by Enclosure 5 of Volume 3 of this Manual, ensure that DoD Component personnel receive security education and training as appropriate to their functions, and grant, when appropriate, waivers to the original and derivative classification training requirements of section 7 of Enclosure 5 of Volume 3.
h. Ensure that the performance contract or other system used to rate the performance of civilian and military personnel includes the designation and management of classified information, to include Restricted Data and Formerly Restricted Data information when appropriate, as a critical element or item to be evaluated in the rating of:
(1) Original classification authorities (OCAs).
(2) Security managers and security specialists.
(3) Personnel who derivatively classify information on a routine basis.
(4) Information system security personnel if their duties involve access to classified information and information system personnel (e.g., system administrators) with privileged access to classified system or network resources.
(5) All other personnel whose duties include significant involvement with the creation or handling of classified information.
i. Account for the costs associated with implementing this Manual within the DoD Component and report those costs as required.
j. Ensure prompt and appropriate response to any request, appeal, challenge, complaint, or suggestion arising out of implementation of this Manual within the DoD Component.
k. Establish procedures for receipt of information, allegations, or complaints regarding over-classification or incorrect classification within the DoD Component and, as needed, provide guidance to personnel on proper classification.
l. Approve, when appropriate, the use of alternative compensatory control measures (ACCM) for classified information over which the senior agency official has cognizance and provide written notification within 30 days to the Director of Security, Office of the Under Secretary of Defense for Intelligence and Security (OUSD(I&S)), or the Director, International Security Programs, Defense Technology Security Administration, Office of the USD(P) (OUSD(P)), as appropriate, when establishing or terminating an ACCM.
Change 2, 7/28/2020 17 ENCLOSURE 2
m. Submit an annual report addressing how the DoD Component implemented that portion of the information security program dealing with classified information.
(1) The report, covering the previous fiscal year, shall be submitted on Standard Form (SF) 311, “Agency Information Security Program Data,” to reach the Director of Security, OUSD(I&S), prior to October 31 of each year. The Military Departments shall submit their reports directly to ISOO, with a copy furnished to OUSD(I&S). OUSD(I&S) shall compile the reports, excluding those of the Military Departments, and provide a consolidated report to ISOO.
(2) The SF 311 shall be completed according to the instructions accompanying the form and those provided by ISOO and OUSD(I&S).
n. Submit to the Director of Security, OUSD(I&S), prior to October 31 of each year, a report listing, by position title, those officials within the DoD Component who hold OCA delegated in accordance with paragraph 4.c. of Enclosure 4 and those officials who hold declassification authority delegated in accordance with paragraph 3.b. of Enclosure 5. The report shall be organized by level of highest classification authority and by activity.
o. Cooperate and coordinate with the Component senior intelligence official as appropriate to achieve a harmonized and cohesive information security program within the DoD Component.
8. HEADS OF DoD ACTIVITIES. The heads of DoD activities shall:
a. Be responsible for overall management, functioning and effectiveness of the activity’s information security program.
b. Designate, in writing, an activity security manager, who shall be given the necessary authority to ensure personnel adhere to program requirements. Provide the designated activity security manager direct access to activity leadership and ensure he or she is organizationally aligned to ensure prompt and appropriate attention to program requirements.
(1) The activity security manager may be assigned full-time, part-time, or as a collateral duty, provided that the responsibilities delineated in section 9 of this enclosure can be adequately and professionally executed and implemented.
(2) The activity security manager shall:
(a) Be a military officer, senior non-commissioned officer, or a civilian employee with sufficient authority, staff, and other resources necessary to manage the program for the activity.
1. For activities with more than 100 personnel assigned, a senior non-commissioned officer designated as the activity security manager shall be E-7 or above; a civilian employee so designated shall be GS-11 or above (or pay band equivalent).
Change 2, 7/28/2020 18 ENCLOSURE 2
2. For activities with less than 100 personnel assigned, a senior non-commissioned officer designated as the activity security manager shall be E-6 or above; a civilian employee so designated shall be GS-7 or above (or pay band equivalent).
(b) Be a U.S. citizen.
(c) Have been the subject of a favorably adjudicated, current background investigation appropriate for the highest level of classification of information handled by personnel within the activity in accordance with requirements of DoD 5200.2-R (Reference (s)).
(d) Have access appropriate to the level of information managed.
c. In large activities and where circumstances warrant, designate, in writing, activity assistant security manager(s) to assist in program implementation, maintenance, and local oversight.
(1) Responsibilities assigned to assistant security managers shall be commensurate with their grade level, experience, and training.
(2) Individuals assigned as assistant security managers shall be U.S. citizens with security clearances and accesses appropriate to their assigned responsibilities.
(3) Assistant security managers shall report directly to the activity security manager who shall provide guidance, direction, coordination, training, and oversight necessary to ensure that the program is being administered effectively.
d. Optionally, where circumstances warrant (such as in activities with large repositories of Top Secret information), designate an activity Top Secret control officer (TSCO) to manage and account for Top Secret materials, and Top Secret control assistant(s) (TSCA(s)) as needed to assist the TSCO. When used, designations shall be in writing. Top Secret couriers are NOT considered TSCA(s).
(1) An individual designated as the TSCO must have been the subject of a favorably adjudicated, current background investigation in accordance with requirements of Reference (s) and must have Top Secret access. The TSCO shall report directly to the activity security manager, or the activity security manager may serve concurrently as the TSCO.
(2) An individual designated as a TSCA must have been the subject of a favorably adjudicated, current background investigation in accordance with requirements of Reference (s) and must have Top Secret access.
e. When required by DoDD 5100.55 (Reference (t)), designate, in writing, an activity NATO control point officer and at least one alternate to ensure that NATO information is correctly controlled and accounted for, and that NATO security procedures are followed. United States Security Authority for NATO (USSAN) Instruction 1-07 (Reference (u)) was written by USD(P)
Change 2, 7/28/2020 19 ENCLOSURE 2 on behalf of the Secretary of Defense, acting as the U.S. Security Authority to NATO and administrator of NATO information security regulation. It establishes procedures and minimum security standards for the handling and protection of NATO classified information.
9. ACTIVITY SECURITY MANAGER. The activity security manager shall:
a. Manage and implement the DoD activity’s information security program on behalf of the activity head, to whom he or she shall have direct access.
b. Serve as the principal advisor and representative to the activity head in all matters pertaining to this Manual and maintain cognizance of all activity information, personnel, information systems, physical and industrial security functions to ensure that the information security program is coordinated in its execution and inclusive of all requirements in this Manual.
c. Provide guidance, direction, coordination, and oversight to designated assistant security managers, TSCOs, TSCAs, security assistants and, as appropriate, others in security management roles as necessary to ensure that all elements of the information security program are being administered effectively, efficiently, and in a coordinated manner.
d. Develop a written activity security instruction that shall include provisions for safeguarding classified information during emergency situations and military operations, if appropriate.
e. Ensure that personnel in the activity who perform security duties are kept abreast of changes in policies and procedures, and provide assistance in solving problems.
f. Formulate, coordinate, and conduct the activity security education and training program.
Organizations with elements that are deployable for contingency operations shall ensure information security training, to include appropriate application to information systems, is an integral part of pre-deployment training and preparation.
g. Ensure that threats to security and security incidents pertaining to classified information, including foreign government information (FGI), are reported, recorded, coordinated with the proper authorities, and, when necessary, investigated and that appropriate action is taken to mitigate damage and prevent recurrence. Ensure that incidents involving the loss or compromise of classified material (as described in Enclosure 6 of Volume 3 of this Manual) are immediately referred to the cognizant investigative authority. In cases where compromise is determined or cannot be ruled out, ensure that security reviews and other required assessments are conducted as soon as possible. Coordinate with local information assurance officials, but retain responsibility for inquiries into incidents involving possible or actual compromise of classified information resident in or on IT systems.
h. Coordinate the preparation, dissemination, and maintenance of security classification guides under the activity’s cognizance as required by Enclosure 6 of this Volume.
Change 2, 7/28/2020 20 ENCLOSURE 2
i. Maintain liaison with the activity public affairs officer or information security officer, as appropriate, and the operations security (OPSEC) officer to ensure that information, including press releases and photos, proposed or intended for public release, including via website posting, is subject to a security review in accordance with DoDD 5230.09 (Reference (v)), DoDI 5230.29 (Reference (w)), and DoDI 8550.01 (Reference (x)).
j. Coordinate with other activity officials regarding security measures for the classification, safeguarding, transmission, declassification, and destruction of classified information.
(1) Coordinate as required with the foreign disclosure officer on all matters governing the disclosure of classified information to foreign governments and international organizations in accordance with DoDD 5230.11 (Reference (y)).
(2) Ensure implementation of and compliance with the requirements of this Manual for all uses of IT. Coordinate with information systems security personnel (e.g., designated approval authorities (DAAs), information assurance managers (IAMs), information system security managers) as required for effective management, use, and oversight of classified information in electronic form.
k. Develop security measures and procedures, consistent with DoDD 5230.20 (Reference (z)), DoDI 5200.08 (Reference (aa)) and other applicable policies, regarding visitors who require access to classified information and facilities containing same.
l. Ensure compliance with the requirements of this Manual when access to classified information is provided to industry at activity facilities and locations in connection with a classified contract. If the classified information is provided to industry at the contractor’s facility, ensure compliance with the provisions of DoDI 5220.22 (Reference (ab)).
m. Ensure that access to classified information is limited to appropriately cleared personnel with a need to know as required by section 4.1 of Reference (d) and section 3.1 of E.O. 12968 (Reference (ac)).
n. Maintain liaison with the special security officer (SSO), as appropriate, on issues of common concern.
10. TSCO. The TSCO, when designated in accordance with paragraph 8.d. of this enclosure, shall:
a. For paper documents and other physical media (e.g., disk drives and removable computer media), maintain a system of accountability (e.g., registry) to record the receipt, reproduction, transfer, transmission, downgrading, declassification, and destruction of Top Secret information, that is not SAP, SCI, and other special types of classified information.
b. Ensure that inventories of Top Secret information are conducted at least annually or more frequently when circumstances warrant.
Change 2, 7/28/2020 21 ENCLOSURE 2
11. SENIOR INTELLIGENCE OFFICIALS. The senior intelligence officials, including those who are heads of elements of the Intelligence Community and those designated according to paragraph 6.c of this enclosure, shall:
a. In accordance with Reference (b):
(1) Protect intelligence and intelligence sources and methods from unauthorized disclosure consistent with the policies of the DNI and, where applicable, the requirements of this Manual and Reference (j).
(2) Administer and oversee, within their respective organizations, those aspects of the SCI security programs not delegated to Defense Intelligence Agency (DIA) in accordance with Reference (b).
(3) Develop DoD Component-specific implementation guidance as necessary for the protection of SCI.
b. Cooperate and coordinate with the Component senior agency official as appropriate to achieve a harmonized and cohesive information security program within the DoD Component.
c. Where required by this Manual, provide the USD(I&S) with copies of requests for exceptions and waivers of information security policies, security incident reports, and other information submitted to the DNI.
d. Designate, as required by Intelligence Community Directive 703 (Reference (ad)) and Reference (j), an activity SSO to be responsible for the day-to-day security management, operation, implementation, use, and dissemination of SCI within the activity and, as needed, alternate SSO(s). Such designations shall be made for any activity that is accredited for and authorized to receive, use, and store SCI and shall be in writing.
(1) All SCI matters shall be referred to the SSO.
(2) The SSO may be designated as the activity security manager if the grade requirements for the position are met; however, the activity security manager cannot function as the SSO unless so designated by the cognizant senior intelligence official.
12. INFORMATION SYSTEMS SECURITY OFFICIALS. Information systems security officials (e.g., DAA or agency official (AO), IAM or information systems security manager (ISSM), and information systems security officer) designated, in writing, as required by DoDI
8500.01 (Reference (ae)), shall:
a. Coordinate with the activity security manager regarding implementation of information systems security measures and procedures.
Change 2, 7/28/2020 22 ENCLOSURE 2
b. Notify the activity security manager, who retains overall security responsibility for required inquiries and investigations, when there are incidents involving possible or actual compromise or data spills of classified information resident in information systems, as required by Reference (ae), and coordinate with him or her as required for resolution of the incident.
Change 2, 7/28/2020 23 ENCLOSURE 3
ENCLOSURE 3
DoD INFORMATION SECURITY PROGRAM OVERVIEW
1. PURPOSE. Effective execution of a robust information security program that gives equal priority to both protecting information and demonstrating a commitment to open Government and that includes accurate, accountable application of classification standards and routine, secure, and effective declassification is a national security imperative. This Manual provides overarching program guidance and direction for the DoD Information Security Program. While day-to-day program execution is the responsibility of all DoD personnel, program implementation must be guided by active and engaged senior managers at all levels who have the responsibility for overall program execution and by security managers who ensure the program is visible, effective, and efficient.
2. SCOPE. The DoD Information Security Program implements References (b), (d), and (f) with regard to the classification, declassification, and protection of classified information, including information categorized as collateral, SCI, and SAP, and provides guidance to users to identify, mark, and protect certain types of unclassified information, referred to as CUI, in accordance with Reference (e), Reference (f), and other national-level directives. This combined guidance is known as the DoD Information Security Program and is applicable to all DoD Components.
3. PERSONAL RESPONSIBILITY. All personnel of the Department of Defense are personally and individually responsible for properly protecting classified information and CUI under their custody and control. All officials within the Department of Defense who hold command, management, or supervisory positions have specific, non-delegable responsibility for the quality and effectiveness of implementation and management of the information security program within their areas of responsibility.
4. NATIONAL AUTHORITIES FOR SECURITY MATTERS
a. President of the United States. The President of the United States bears executive responsibility for the security of the Nation, which includes the authority to classify information for the protection of the national defense and foreign relations of the United States. The President has established standards for the classification, safeguarding, and declassification of national security information through the issuance of Reference (d) and for the designation and protection of CUI through the issuance of Reference (e).
b. National Security Council (NSC). In accordance with section 3021 of title 50, U.S.C.
(Reference (af)), the NSC provides overall policy guidance on information security.
Change 2, 7/28/2020 24 ENCLOSURE 3
c. DNI. The DNI is head of the Intelligence Community and principal advisor to the President and the NSC for intelligence matters related to national security pursuant to Section 1011 of Public Law 108-458 (Reference (ag)) and Section 1.3 of E.O. 12333 (Reference (ah)).
The DNI is also charged by section 1.3(b)(8) of Reference (ah) with protecting intelligence sources, methods, and activities, and in this role, the DNI issues instructions in the form of Intelligence Community Directives or other security policies and standards for the protection, management and oversight of SCI and other national intelligence.
d. ISOO. The ISOO, under the authority of the Archivist of the United States, acting in consultation with the NSC, issues directives as necessary to implement Reference (d). The directives establish national standards for the classification and marking of national security information, security education and training programs, safeguarding, self-inspection programs, and…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .