ATT_10_SAAR-N_Guidance_2016Oct19.docx
DOCX document 1 MB Posted
- Attached to
- Aircrew Scheduling and Ground Support Federal contract opportunity
- Solicitation number
- N00421-17-R-0066
About this file
Attachment 10
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| ATT_6_Base_Acc_Req.doc | DOC document | |
| ATT_13_OPSEC_DI-MGMT.pdf | ||
| N00421-17-R-0066.docx | DOCX document | |
| ATT_9_SAAR-N_Instructions.pdf | ||
| ATT_P-5_PPQ.doc | DOC document | |
| ATT_12_Travel_Req.xls | XLS spreadsheet | |
| ATT_P-4_Past_Performance.xlsx | XLSX spreadsheet | |
| Attachment_P-6B_Cost_Summary_Spreadsheet.xls | XLS spreadsheet | |
| ATT_8-TASS-Reg_Req.pdf | ||
| ATT_11_SAAR-N_Form_Rev_9_11.pdf | ||
| ATT_1_SOW_Final.docx | DOCX document | |
| ATT_3_CONTRACT_SURVEILLANCE_PLAN.doc | DOC document | |
| ATT_7_SECNAV_BaseVisitReq.pdf | ||
| ATT_5_Funds_Expenditure_Report.xlsx | XLSX spreadsheet | |
| Attachment_P6-A_-_Cost_Summary_Spreadsheet.xls | XLS spreadsheet | |
| ATT_16_CDRLS_5-8.pdf | ||
| ATT_19_CDRLS__17-20.pdf | ||
| ATT_17__CDRLS__9-12.pdf | ||
| ATT_15__CDRLS__1-4.pdf | ||
| ATT_23_COR_Functions__Duties.doc | DOC document | |
| ATT_P-3_PastPerformMatrix.doc | DOC document | |
| ATT_24_OCI_List.doc | DOC document | |
| ATT_18_CDRLS__13-16.pdf |
Show all 23
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Completion Instructions for the SAAR-N (OPNAV 5239/14 (Rev 9/2011))
Once the SAAR-N is complete, send it and your IA Training Certificate to the NAVAIR Help Desk via:
- e-mail: navair_SAAR@navy.mil
- or Fax: (301)995-0285
- or HelpDesk online: https://nhd.navair.navy.mil
Please see “Common Reasons the SAAR-N form is Rejected:” on page 5 before completing SAAR-N.
Completed by the Requestor Type of Request:
| (Type of request must have a check in either Initial or Modification) |
| Initial: Brand new account |
| Modification: Transferring commands, name change, contract renewal |
(*if an account already exists- but needs some kind of change/update)
· IF you have previously had an NMCI account please include your User ID
· If you select Modification, the entire form should be updated from your previous copy on file
| Deactivate: Deactivate an active account | |
| User ID: Required if a user already has a navy.mil account | |
| -if your e-mail address is mike.smith2@navy.mil, your User ID is: mike.smith2 |
Date: DDMMMYYYY Format (*REQUIRED) – No future dates System Name (Platform or Application): This has to be specific – “all IT systems” by itself is not acceptable. List the systems the individual will have access to, such as: NMCI NIPRNet, SIPRNet, SDREN, DREN, RDT&E Lab Name, Navy ERP, AIM, COLTS, etc. If more space is needed, continue in Block 11 for systems.
Location: Your physical location. i.e, NAS Patuxent River, Bldg 1490, Room 54, Cube 1A (If requesting multiple systems access – use the location of the primary system being used. For example, where you will be accessing your computer.)
Part 1-
1. Name: Last, First MI (if no middle name, use “NMN”)
2. Organization: Command – NAWCAD or NAVAIR
a. **For contractors: Command/Program Supported (No Company Name should be listed)
3. Office Symbol/Department: Program Office/Competency Being Supported – PMA-### or Code
4. Phone: Work Number ONLY – Requestor’s work phone number or Supervisor’s work phone number if requestor does not have one.
5. Official E-Mail Address: .mil work e-mail address only. (No personal or EDU e-mail address should be included)
a. If an @navy.mil account doesn’t exist yet - leave blank
b. **If you’re an external customer requiring access to government systems, and will NEVER have a .mil address, please use your company’s email address.
6. Job Title and Grade/Rank: Title & Grade of your specific position
a. Job title only necessary for contractors
7. Official Mailing Address: Official COMMAND mailing address for your Bldg
8. Citizenship: Choose ONE only- US, FN, LN, Other_______
a. If you select FN- See page 5 for amplifying instructions
9. Designation of Person: Choose ONE only- Military, Civilian, or Contractor
10. IA Awareness Training: This must be completed before a SAAR-N will be approved.
a. Check the box and enter date training was taken. ***Include the certificate of completion when you submit the SAAR-N form. All training is required within the fiscal year, not calendar year or every 12 months.
i. Authorized methods for training delivery:
· Total Workforce Management Service (TWMS), https://twms.navy.mil/selfservice/login.asp;
· Navy e-Learning (NEL) via the Navy Knowledge Online portal;
· CAC V3 is available at: http://iatraining.disa.mil/eta/cyberchallenge_v3_fy15/launchPage.htm
Requestor- Continue on Page 3
22. Requestor must read this section and acknowledge that they understand the rules for maintaining access to Government IT systems by signing Block 24 on the next page.
23. Name: Last, First MI (if no middle name, use NMN)
24. User’s Signature: either manual or digital CAC signature (must contain users EDIPI # or contractor email in signature {small print})
25. Date Signed: DDMMYYYY (If scanned multiple times, ensure Date is legible)
Part II – Endorsement of Access by Information Owner, User Supervisor, and Government Sponsor
11. Justification for Access: Write in the box “To gain access to Navy IT resources in support of duties on a need to know basis.” *Include additional systems in this block, if applicable.* - Do not reference Heat Ticket Numbers in this section
12. Type of Access Required: Check one- “Authorized” or “Privileged”. Most users will be Authorized. Privileged users will be based on Position Description (PD) or job description.
· If you require both please put a check in both “Authorized” and “Privileged” 12a. Privileged users need to include the Privileged Access Agreement (PAA) form. The date in this block should match the date the user signed the PAA. (PAA forms should not exceed 6 months of date of submission)
PAA Attached and instructions:
13. User Access Required: Check- Unclassified or Classified. If a user is requesting access to both classified and unclassified, check both boxes. If accessing classified information, please specify the category of data (e.g., Secret, TS). SIPRNET is acceptable for this as well.
14. Verification of Need-to-Know: Box must be checked. As the supervisor you are acknowledging the user’s appropriate level of need-to-know.
14a. Access Expiration Date: **Required for Contractors** Specify Company Name, Contract Number, Expiration Date
15. Supervisor’s Organization/Department: Command, Office Code. i.e, NAWCAD 7.2.3. This should correlate with Line 16 and be the Government Supervisor. If the Contractor Supervisor signs in this block, then the government supervisor must additionally sign as the Information Owner in Block 17.
15a. Supervisor’s E-mail: Official .mil account 15b. Supervisor’s Phone: Official work phone number
16. Supervisor’s Name: Last, First. Can be the government or contractor supervisor (*contractors can use the COR, direct government supervisor or TPOC). If the contractor supervisor signs the form, then the government supervisor must sign as the Information Owner in Block 17.
16a. Supervisor’s Signature: either manual or digital CAC signature.
16b. Date: DDMMYYYY (If scanned multiple times, ensure Date is legible)
17. Signature of Information Owner: The Information owner of a specific system (i.e., Navy ERP, Lab x, Website x). Refer to the system(s) being requested above. If a Contractor Supervisor signed in Block 16, then the Government Supervisor (TPOC, COR, or direct government supervisor) must sign as the Information Owner.
18. Signature of IAM or Appointee: Leave blank, unless the following exist:
a. Information Owner of the System/PMA has a government IAM or,
b. System/SAAR-N is maintained at the PMA/Lab level. This is typically the case with smaller standalone systems.
c. If you are located at another Command ****The IAM/PMA IAM will have the last signature on the OPNAV 5239/14 Rev 9/2011**** ****Also, an ISSM cannot sign as their own ISSM on a SAAR-N or PAA in any instance****
19. Organization/Department: Command – NAWCAD or NAVAIR
20. Phone Number: Official work phone number
21. Date: DDMMMYYYY
If Civilian or Military- Supervisor Completes Part III, #26c 26c. IT Level Designation: Based on position Sensitivity (Critical, Non-Critical, Non-Sensitive – refer to Position Description for Government) Level I – Privileged Access (Refer to the SECNAV M-5510.30 for a complete list of roles and responsibilities that qualify as IT Level I Designation – Questions? Contact the IAM/CSM.)
Level II – Limited Privilege, Sensitive Information Access (Most users fall into this category) Level III – Does NOT exist at NAVAIR
Embedded Doc explaining IT Level Designations:
Part III - Security Manager Validates the Background Investigation or Clearance Information Civilian or Military-NAVAIR/NAWCAD users- upon completing Parts I, II & 26c in Part III, e-mail or Fax the SAAR-N & IA Training Certificate to the NAVAIR National Help Desk for 7.4 Security to complete Part III. If you are not a NAVAIR/NAWCAD employee, please have your local Security Office complete part III. Then submit to the NAVAIR National Help Desk for final processing and approval. navair_saar@navy.mil or (301)995-0285 Contractor- upon completing Parts I & II, submit the form to your company’s Facility Security Officer (FSO) or Security Manager for processing. Once they have completed Part III, then e-mail or FAX the SAAR-N & IA Training Certificate to the NAVAIR National Help Desk for final processing and approval. navair_saar@navy.mil or (301)995-0285
26. Type of Investigation: ANACI, NACLC, SSBI, SSBI-PR, PPR, SBPR, T3, T3R Note: Any ANACI or NACLC investigations that are initiated or opened after Dec 2015, will be adjudicated under the T3 (Initial) or T3R (Reinvestigation) criteria.
26a. Date of Investigation: DDMMYYYY (for contractors, it should be the open/closed date of the investigation, not the PSQ date. For CIV/MIL, it is allowed to be the PSQ date OR the open/close date)
· Top Secret OR IT I (Limited Privilege, Sensitive Information Access) or IT I (Privileged Access (See 26c IT I Level Designation Criteria) = 5 years (NO two year extension allowed)
· Secret OR IT II = 10 years (NO two year extension allowed)
· Favorable/None = 15 years (NO two year extension allowed) 26b. Clearance Level: TS, Secret, Confidential, Interim Clearance, Favorable, None (N/A not acceptable) 26c. IT Level Designation: Based on position sensitivity (Critical Sensitive, Non-Critical Sensitive, Non-Sensitive – refer to Position Description for Government) Level I – Privileged Access (Refer to the SECNAV M-5510.30 for a complete list of roles and responsibilities that qualify as IT Level I Designation – Questions? Contact the IAM/CSM.)
Level II – Limited Privilege, Sensitive Information Access (Most users fall into this category) Level III – Does not exist at NAVAIR.
*Refer to the embedded Word Doc for Designating Sensitive Positions. See below.
27. Verified by: Security Manager/FSO Name
28. Security Manager Phone Number: Official work phone number
29. Security Manager Signature: either manual or digital CAC signature. (If scanned multiple times, ensure Date is legible)
29. Date: DDMMYYYY
Submit the SAAR-N Form At Patuxent River NAS, submit the completed SAAR-N form & IA Training Certificate, Electronically to the NAVAIR National Help Desk for processing one of two ways:
-via encrypted e-mail to NAVAIR_SAAR@navy.mil -or via Fax (301)995-0285.
-or HelpDesk online: https://nhd.navair.navy.mil
If you have questions, please contact the NAVAIR National Help Desk at 301-342-3104.
Common Reasons the SAAR-N form is Rejected:
Clearance/IT Level/Privileged Access
1. Clearance Level doesn’t meet the minimum requirement for access required.
2. Type of access required doesn’t meet the investigation and IT Designation Level.
3. IT Level Designation is not checked.
4. Requestor requires access to both unclassified and classified – check both blocks, not just Classified.
5. If the requestor requires privileged access, check the box. By policy, the user will have two accounts (one for normal use and a second account for elevated privileges).
6. If Privileged access is required, Block 12a needs to be filled out and the PAA letter should be attached to the SAAR-N form for processing. They must also meet the background investigation requirements for IT-I Privileged Access (i.e., SSBI).
Contractor Specific
7. Contractor supervisor signs Blocks #15 -16b, but the Government Supervisor doesn’t also sign as the Information Owner in Block 17.
8. Contract expiration date is expired.
Other
9. Official Mailing address isn’t for the Program/Competency supported.
10. Official e-mail entered isn’t a .mil address. It is incorrectly entered as a @gmail or @yahoo. If there is no .mil address, leave it blank.
11. Blank or missing information in any section.
a. The only exception is Block 17, Information Owner. Not all systems have an Information Owner and it is OK if this section is blank. The only exception is for contractors who have their contractor supervisor sign the form and also need their Government supervisor to sign. See #5.
12. Verification of Need-to-Know (Block 14) needs to be checked by the Government Supervisor.
Foreign National (FN) SAAR-N Requirements System Name: Required to list the specific systems the FN user will have access to. If the space is not large enough to list all of the systems, write "See attached" and include a document listing all of the systems.
Access Expiration: Expiration date of the FN visit/orders.
Supervisor: FN’s U.S. contact officer.
Security Section: Leave this section blank and send to the 7.4 Foreign Disclosures POC (Mitch Hamrick). The 7.4 Foreign Disclosures representative will complete this section with the required FN visit request information and obtain appropriate Security Manager endorsement.
NAWCAD Patuxent River MD Unclassified/FOUO 04/19/2016 v1.6 image1.emf
Form-PAA Form_NAVAIR_SECNAV_5239_1_15260.pdf
Please wait...
If this message is not eventually replaced by the proper contents of the document, your PDF viewer may not be able to display this type of document.
You can upgrade to the latest version of Adobe Reader for Windows®, Mac, or Linux® by visiting http://www.adobe.com/go/reader_download.
For more assistance with Adobe Reader visit http://www.adobe.com/go/acrreader.
Windows is either a registered trademark or a trademark of Microsoft Corporation in the United States and/or other countries. Mac is a trademark of Apple Inc., registered in the United States and other countries. Linux is the registered trademark of Linus Torvalds in the U.S. and other countries.
INFORMATION SYSTEM (IS) PRIVILEGED ACCESS AGREEMENT AND ACKNOWLEDGMENT (PAA) OF RESPONSIBILITIES
Page of
SECNAV M-5239.2
SECNAV 5239/1
(Apr 2016)
PRIVACY ACT STATEMENT
AUTHORITY FOR MAINTENANCE OF THE SYSTEM:
10 U.S.C. 5013, Secretary of the Navy; 10 U.S.C. 5041, Headquarters, Marine Corps; and E.O. 9397 (SSN).
PURPOSE(S):
To manage, supervise, and administer programs for all Department of the Navy civilian, military, and contractor personnel. Information is used to prepare organizational locator, recall rosters, and social rosters; notify personnel of arrival of visitors; locate individuals on routine and/or emergency matters; locate individuals during medical emergencies, facility evacuations and similar threat situations; provide mail distribution and forwarding addresses; compile a social roster for official and non-official functions; send personal greetings and invitations; track attendance at training; identify routine and special work assignments; determine clearance for access control; identify record handlers of hazardous materials; record rental of welfare and recreational equipment; track beneficial suggestions and awards; control the budget; travel claims; track manpower, grades, and personnel actions; maintain statistics for minorities; track employment; track labor costing; prepare watch bills; project retirement losses; verify employment to requesting banking activities; rental and credit organizations; name change location; checklist prior to leaving activity; safety reporting/monitoring; and, similar administrative uses requiring personnel data.
ROUTINE USES:
In addition to those disclosures generally permitted under 5 U.S.C. 552a(b) of the Privacy Act of 1974, these records contained therein may specifically be disclosed outside the DoD as a routine use pursuant to 5 U.S.C. 552a(b)(3) as follows: To arbitrators and hearing examiners for use in civilian personnel matters relating to civilian grievances and appeals. To authenticate authorization for access to services and spaces such as Morale, Welfare, and Recreation (MWR) facilities and food services. The DoD 'Blanket Routine Uses' that appear at the beginning of the Navy's compilation of systems of records notices apply to this system.
DISCLOSURE: Disclosure of this information is voluntary; however, failure to provide the requested information will result in denial of privileged access to the requested information system..
SYSTEM OF RECORDS NOTICE: http://dpcld.defense.gov/Privacy/SORNsIndex/DODwideSORNArticleView/tabid/6797/Article/570436/nm05000-2.aspx
PART I PRIVILEDGED USER INFORMATION
*NOTE: DoD Component collectively refers to: OSD, the Military Departments, the Office of the Chairman of the Joint Chiefs of Staff and the Joint Staff, the Combatant Commands, the Office of the Inspector General of the Department of Defense, the Defense Agencies, the DoD Field Activities, and all other organizational entities in the DoD.
PART II PRIVILEGED ACCESS AGREEMENT
1. I understand there are two DoD Information Systems (IS), classified (SIPRNET) and unclassified (NIPRNET), and that I have the necessary clearance for privileged access to the IS. I will not introduce or process data or software for the IS that I have not been specifically authorized to handle.
2. I understand the need to protect all passwords and other authenticators at the highest level of data they secure. I will not share any password(s), account(s), or other authenticators with other coworkers or other personnel not authorized to access the IS. As a privileged user, I understand the need to protect the root password and/or authenticators at the highest level of data it secures. I will NOT share the root password and/or authenticators with coworkers who are not authorized IS access.
3. I understand that I am responsible for all actions taken under my account(s), root, or otherwise. I will not attempt to
“hack” the network or any connected information systems, or gain access to data to which I do not have authorized access.
4. I understand my responsibility to appropriately protect and label all output generated under my account (including printed materials, magnetic tapes, floppy disks, and downloaded hard disk files).
5. I will immediately report any indication of computer network intrusion, unexplained degradation or interruption of network services, or the actual or possible compromise of data or file access controls to the appropriate
Information System Security Manager (ISSM). I will NOT install, modify, or remove any hardware or software (e.g., freeware/shareware and security tools) without written permission and approval from the ISSM or senior representatives.
6. I will not install any unauthorized software (e.g., games, entertainment software) or hardware (e.g., sniffers).
7. I will not add/remove any users' names to the Domain Administrators, Local Administrator, or Power Users group without the prior approval and direction of the ISSM or senior representatives.
8. I will not introduce any unauthorized code, Trojan horse programs, malicious code, or viruses into the local area networks.
9. I understand that I am prohibited from the following while using the DoD IS:
a. Introducing Classified and/or Controlled Unclassified Information (CUI) into a NIPRNET environment.
b. Accessing, storing, processing, displaying, distributing, transmitting, or viewing material that is abusive, harassing, defamatory, vulgar, pornographic, profane, or racist; that promotes hate crimes, or is subversive or objectionable by nature, including material encouraging criminal activity, or violation of local, state, federal, national, or international law.
c. Storing, accessing, processing, or distributing Classified, Proprietary, CUI, For Official Use Only (FOUO), or Privacy
Act protected information in violation of established security and information release policies.
d. Obtaining, installing, copying, pasting, transferring, or using software or other materials obtained in violation of the appropriate vendor's patent, copyright, trade secret, or license agreement.
e. Knowingly writing, coding, compiling, storing, transmitting, or transferring malicious software code, to include viruses, logic bombs, worms, and macro viruses.
f. Engaging in prohibited political activity.
g. Using the system for personal financial gain such as advertising or solicitation of services or sale of personal property
(e.g., eBay), or stock trading (i.e., issuing buy, hold, and/or sell directions to an online broker).
h. Fundraising activities, either for profit or non-profit, unless the activity is specifically approved by the organization
(e.g., organization social event fund raisers and charitable fund raisers, without approval).
i. Gambling, wagering, or placing of any bets.
j. Writing, forwarding, or participating in chain letters.
k. Posting personal home pages.
l. Any other actions prohibited by DoD Directive 5500.7-R or any other DoD issuances.
10. Personal encryption of electronic communications is strictly prohibited and can result in the immediate termination of access.
11. I understand that if I am in doubt as to any of my roles or responsibilities I will contact the ISSM or Cyber
IT/CSWF-PM for clarification.
12. I understand that all information processed on the is subject to monitoring. This includes email and browsing the web.
13. I will not allow any user who is not cleared access to the network or any other connected system without prior approval or specific guidance from the ISSM.
14. I will use the special access or privileges granted to me ONLY to perform authorized tasks or mission related functions.
15. I will not use any IS to violate software copyright by making illegal copies of software.
16. I will ONLY use my PRIVILEGED USER account for official administrative actions. This account will NOT be used for day to day network communications.
17. I will obtain and maintain required qualification(s), according to SECNAV M-5239 and maintain certification(s) (if applicable) according to the certification provider, to retain privileged system access.
18. I understand that failure to comply with the above requirements will be reported and may result in the following actions:
a. Revocation of IS privileged access.
b. Counseling.
c. Adverse actions pursuant to the Uniform Code of Military Justice and/or criminal prosecution.
d. Disciplinary action, discharge or loss of employment.
e. Revocation of Security Clearance.
PART III CERTIFICATION OF DOD COMPONENT OPR AND/OR ACTION OFFICER, APPROVING OFFICIAL
PRIVILEGED USER CERTIFICATION OF INFORMATION
COMMAND ISSM APPROVAL
COMMAND CYBER IT/CSWF-PM APPROVAL
11.0.1.20130826.2.901444.899636
CurrentPage:
PageCount:
DateField1:
TF_pAU_Nme:
TF_pAU_tel: (301) 342-3203
TF_pAU_eml: david.baden1@navy.mil
TF_pAU_org: AD723 Enterprise Architecture
TF_pAU_dodCOM: NAME of IS Owner, Competency/Team Leader or Program Manager
TF_isNme:
TF_isNmeACRO:
TF_isDtails:
TF_IS1:
TF_IS2:
TF_IS3:
TF_IS4:
TF_IS5:
TF_IS6:
TF_IS7:
TF_IS8:
TF_IS9:
TF_IS10:
TF_DoD_cOMP1: NAME of IS Owner, Competency/Team Leader or Program Manager cSWF_PMsig:
tf_PuNme:
pUCertSig:
DTF_pU:
tf_cISSMnme:
DTF_cISSM:
cISSMsig:
tf_cSWF_PM: David M Baden dTF_cSWF_PM:
image2.emf
How to complete the IA Technical (IAT) Privileged Access Agreement (PAA) Form DRAFT.docx
How to complete the IA Technical (IAT) Privileged Access Agreement (PAA) Form
PAA Requirements:
SAAR-N-
· Privileged must be marked in block 12
· Block 12a must be dated
· Block 26 must be SSBI or equivalent
· Block 26b must be Secret or Top Secret
· Block 26c must be marked IT Level 1
PAA -
· Date must be completed
· Blocks 1-14 should be completed in their entirety by the privileged user
· Blocks 15-26 should be completed AFTER being submitted to the NHD image3.emf
How to Designate Sensitive Positions - SECNAV5510.30.docx
SECNAV M-5510.30
June 2006
5-3 CRITERIA FOR DESIGNATING SENSITIVE POSITIONS
1. The following criteria for designating position sensitivity for DON employees is based on OPM and DoD criteria. The criteria for designating IT position sensitivity is based on OMB criteria, DoD criteria, and DON requirements:
a. Special-Sensitive (SS): Any position which the head of the agency determines to be at a level higher than critical sensitive:
(1) Due to the greater degree of damage to the national security that an individual could effect by virtue of his/her position, or
(2) Special requirements concerning the position under authority other than EO 10450, such as designations applied under SSO cognizance pertaining to DCID 6/4.
(3) DAAs shall be designated as special-sensitive
(SS), due to the degree of damage an individual could effect by virtue of his/her position, including those IT duties in which the incumbent has:
(a) Responsibility for planning, direction and implementation of a major (DON-wide or DoD-wide) IT security program; has responsibility for direction, planning, and design of a major (DON-wide or DoD-wide) computer system, including the hardware and software; or can access a major (DON-wide or DoDwide) system during the operation or maintenance in such a way and with relatively high risk for causing inestimable damage or realizing extreme personal gain, or
(b) DAA.
b. Critical-Sensitive (CS): Any position that includes:
(1) Access to Top Secret national security information.
(2) Development or approval of plans, policies, or programs which affect the overall operations of the DON (e.g., policy making or policy determining positions).
(3) Development or approval of war plans, plans or particulars of future major or special operations of war, or critical and extremely important items of war.
(4) Investigative and certain investigative support duties, the issuance of personnel security clearances or access authorizations, or the making of personnel security determinations.
(5) Fiduciary, public contact, or other duties demanding the highest degree of public trust. (Fiduciary duties involving IT systems are also designated as IT positions as described below.)
(6) Certain IT positions will be designated as CS, and IT-I, due to the potential for grave damage to the national security. CS IT-I positions include those in which the incumbent has:
(a) Responsibility for development and administration of computer security programs, and also including direction and control of risk analysis and/or threat assessment.
(b) Been designated as IAM or IAO.
(c) Significant involvement in life-critical or mission-critical systems.
(d) Responsibility for the preparation or approval of data for input into a system which does not necessarily involve personal access to the system, but with relatively high risk for effecting grave damage or realizing significant personal gain.
(e) Relatively high risk assignments associated with or directly involving the accounting, disbursement or authorization for disbursement from systems of (1) dollar amounts of $10 million per year or greater, or (2) lesser amounts if the activities of the individual are not subject to technical review by a higher authority in the IT-I category to insure the integrity of the system.
(f) Positions involving major responsibility for the direction, planning, design, testing, maintenance, operation, monitoring and/or management of systems hardware and software.
(g) Other IT positions as designated by the agency head that involve relatively high risk for effecting grave damage or realizing significant personal gain.
(7) Any other position so designated by the SECNAV and/or his designee.
c. Noncritical-Sensitive (NCS): Any position that involves:
(1) Access to Secret or Confidential national security information.
(2) Assignment to duties involving the protection and safeguarding of DON personnel and property (e.g., security police, provost marshal, duties associated with ammunitions and explosives).
(3) Duties involving education and orientation of DoD personnel.
(4) Duties involving the design, operation, or maintenance of intrusion detection systems deployed to safeguard
DON personnel and property.
(5) Responsibility for financial operations subject to routine supervision or approval, but with no funds disbursement or transfer capabilities. (Fiduciary duties involving IT systems are also designated as IT positions as described below.)
(6) Non-management DON mission support positions with authority for independent or semi-independent action.
(7) Duties involving delivery of service to support the DON mission requiring confidence or trust.
(8) Certain IT positions will be designated as NCS, and IT-II, due to the potential for serious damage to the national security. NCS IT-II positions include those in which the incumbent has:
(a) Responsibility for systems design, operations, testing, maintenance, and/or monitoring that is carried out under technical review of higher authority in the CS
IT-I category.
(b) Access to and/or processing of proprietary data, information requiring protection under the Privacy Act of
1974, sensitive information, and Government-developed privileged information involving the award of contracts; including user level access to DON or DoD networks and information systems, system security and network defense systems, or to system resources providing visual access and/or ability to input, delete or otherwise manipulate sensitive information without controls to identify and deny sensitive information.
(c) Duties associated with or directly involving the accounting, disbursement or authorization for disbursement of funds in dollar amounts of less than $10 million per year;
and/or duties that involve the development, writing and administration of, and/or awarding, approving or modifying of contracts which total dollar amounts less than $10 million per year; or as deemed appropriate by the agency head those commensurate fiscal duties with potential for damage or personal gain.
(d) Other positions as designated by the agency head that involve a degree of access to a system that creates a potential for serious damage or personal gain less than that in
CS IT-I positions.
d. Non Sensitive (NS): Only those:
(1) Positions with limited relation to the DON mission, devoid of 5 CFR 732 security risk criteria and 5 CFR
731 public trust risk criteria will be designated as non sensitive.
(2) IT-III positions are designated as Non Sensitive
(NS), and are dependent upon very rigorous IT controls to remain non-sensitive and to:
(a) Preclude access to system security and network defense systems, or to system resources;
(b) Preclude visual access to proprietary data, information requiring protection under the Privacy Act of 1974, government-developed privileged information involving the award of contracts, and other protected sensitive information.
(c) Preclude ability to input, delete or otherwise manipulate protected sensitive information.
(d) Except in those cases where sensitive information (e.g., privacy act data but not government furnished information) is stored in contractor-owned and operated computer networks and databases with no interconnection (including data feeds) to DON IT systems or networks, may use other safeguards as authorized by applicable guidance, in lieu of these position designation requirements.
2. Commanding officers are responsible for ensuring that positions that meet the above criteria are properly designated as sensitive. The majority of DON positions are sensitive due to the DON’s national security mission.
How to Designate Sensitive Positions - SECNAV5510.30.docx
SECNAV M-5510.30
June 2006
5-3 CRITERIA FOR DESIGNATING SENSITIVE POSITIONS
1. The following criteria for designating position sensitivity for DON employees is based on OPM and DoD criteria. The criteria for designating IT position sensitivity is based on OMB criteria, DoD criteria, and DON requirements:
a. Special-Sensitive (SS): Any position which the head of the agency determines to be at a level higher than critical sensitive:
(1) Due to the greater degree of damage to the national security that an individual could effect by virtue of his/her position, or
(2) Special requirements concerning the position under authority other than EO 10450, such as designations applied under SSO cognizance pertaining to DCID 6/4.
(3) DAAs shall be designated as special-sensitive
(SS), due to the degree of damage an individual could effect by virtue of his/her position, including those IT duties in which the incumbent has:
(a) Responsibility for planning, direction and implementation of a major (DON-wide or DoD-wide) IT security program; has responsibility for direction, planning, and design of a major (DON-wide or DoD-wide) computer system, including the hardware and software; or can access a major (DON-wide or DoDwide) system during the operation or maintenance in such a way and with relatively high risk for causing inestimable damage or realizing extreme personal gain, or
(b) DAA.
b. Critical-Sensitive (CS): Any position that includes:
(1) Access to Top Secret national security information.
(2) Development or approval of plans, policies, or programs which affect the overall operations of the DON (e.g., policy making or policy determining positions).
(3) Development or approval of war plans, plans or particulars of future major or special operations of war, or critical and extremely important items of war.
(4) Investigative and certain investigative support duties, the issuance of personnel security clearances or access authorizations, or the making of personnel security determinations.
(5) Fiduciary, public contact, or other duties demanding the highest degree of public trust. (Fiduciary duties involving IT systems are also designated as IT positions as described below.)
(6) Certain IT positions will be designated as CS, and IT-I, due to the potential for grave damage to the national security. CS IT-I positions include those in which the incumbent has:
(a) Responsibility for development and administration of computer security programs, and also including direction and control of risk analysis and/or threat assessment.
(b) Been designated as IAM or IAO.
(c) Significant involvement in life-critical or mission-critical systems.
(d) Responsibility for the preparation or approval of data for input into a system which does not necessarily involve personal access to the system, but with relatively high risk for effecting grave damage or realizing significant personal gain.
(e) Relatively high risk assignments associated with or directly involving the accounting, disbursement or authorization for disbursement from systems of (1) dollar amounts of $10 million per year or greater, or (2) lesser amounts if the activities of the individual are not subject to technical review by a higher authority in the IT-I category to insure the integrity of the system.
(f) Positions involving major responsibility for the direction, planning, design, testing, maintenance, operation, monitoring and/or management of systems hardware and software.
(g) Other IT positions as designated by the agency head that involve relatively high risk for effecting grave damage or realizing significant personal gain.
(7) Any other position so designated by the SECNAV and/or his designee.
c. Noncritical-Sensitive (NCS): Any position that involves:
(1) Access to Secret or Confidential national security information.
(2) Assignment to duties involving the protection and safeguarding of DON personnel and property (e.g., security police, provost marshal, duties associated with ammunitions and explosives).
(3) Duties involving education and orientation of DoD personnel.
(4) Duties involving the design, operation, or maintenance of intrusion detection systems deployed to safeguard
DON personnel and property.
(5) Responsibility for financial operations subject to routine supervision or approval, but with no funds disbursement or transfer capabilities. (Fiduciary duties involving IT systems are also designated as IT positions as described below.)
(6) Non-management DON mission support positions with authority for independent or semi-independent action.
(7) Duties involving delivery of service to support the DON mission requiring confidence or trust.
(8) Certain IT positions will be designated as NCS, and IT-II, due to the potential for serious damage to the national security. NCS IT-II positions include those in which the incumbent has:
(a) Responsibility for systems design, operations, testing, maintenance, and/or monitoring that is carried out under technical review of higher authority in the CS
IT-I category.
(b) Access to and/or processing of proprietary data, information requiring protection under the Privacy Act of
1974, sensitive information, and Government-developed privileged information involving the award of contracts; including user level access to DON or DoD networks and information systems, system security and network defense systems, or to system resources providing visual access and/or ability to input, delete or otherwise manipulate sensitive information without controls to identify and deny sensitive information.
(c) Duties associated with or directly involving the accounting, disbursement or authorization for disbursement of funds in dollar amounts of less than $10 million per year;
and/or duties that involve the development, writing and administration of, and/or awarding, approving or modifying of contracts which total dollar amounts less than $10 million per year; or as deemed appropriate by the agency head those commensurate fiscal duties with potential for damage or personal gain.
(d) Other positions as designated by the agency head that involve a degree of access to a system that creates a potential for serious damage or personal gain less than that in
CS IT-I positions.
d. Non Sensitive (NS): Only those:
(1) Positions with limited relation to the DON mission, devoid of 5 CFR 732 security risk criteria and 5 CFR
731 public trust risk criteria will be designated as non sensitive.
(2) IT-III positions are designated as Non Sensitive
(NS), and are dependent upon very rigorous IT controls to remain non-sensitive and to:
(a) Preclude access to system security and network defense systems, or to system resources;
(b) Preclude visual access to proprietary data, information requiring protection under the Privacy Act of 1974, government-developed privileged information involving the award of contracts, and other protected sensitive information.
(c) Preclude ability to input, delete or otherwise manipulate protected sensitive information.
(d) Except in those cases where sensitive information (e.g., privacy act data but not government furnished information) is stored in contractor-owned and operated computer networks and databases with no interconnection (including data feeds) to DON IT systems or networks, may use other safeguards as authorized by applicable guidance, in lieu of these position designation requirements.
2. Commanding officers are responsible for ensuring that positions that meet the above criteria are properly designated as sensitive. The majority of DON positions are sensitive due to the DON’s national security mission.
File details come from the government source that posted it.