DOD MANUAL AND COMSEC SUPPLEMENT.pdf

PDF 589 KB Posted

Attached to
Medium Range Tanker Time Charter Federal contract opportunity
Solicitation number
N32205-22-R-5435
Issued by
Department of the Navy Military Sealift Command

About this file

This document is a request for proposal (RFP) from the Department of the Navy's Military Sealift Command for a medium range tanker time charter.

The RFP seeks a contractor to provide a medium range tanker vessel for time charter use in support of Department of Defense operations. The vessel must be able to load and discharge fuel and dry cargo, have a minimum cargo capacity of 30,000 barrels of fuel, and be able to maintain a speed of 16 knots fully loaded. The charter period is for one year with four one-year option periods. The contractor must submit pricing for the initial charter period and each option period by the closing date of August 15, 2022. The contract award date is anticipated to be September 30, 2022.

The RFP includes attachments outlining vessel specifications, fuel and cargo handling requirements, schedule of rates, and evaluation criteria. The opportunity is open to all responsible sources and has no set-aside provisions. The incumbent contractor was not identified.

View the file

Other files for this federal contract opportunity

Other files attached to Medium Range Tanker Time Charter, newest first.
File Type Posted
N3220522R5435 A0004.docx DOCX document
22R5435 A0003.pdf PDF
22R5435 Attachment IX (F) - Basic Pricing Data Rev 2.xlsx XLSX spreadsheet
COMSCINST 3541.5 PART 1 APPENDIX C.pdf PDF
SECNAVINST 5510.36B.pdf PDF
22R5435 Attachment IX (J) - Technical Offer Worksheet Rev.XLSX XLSX spreadsheet
SECNAVINST 5510.30C.pdf PDF
22R5435 Attachment IX (I) - PWS Rev.pdf PDF
22R5435 Attachment IX (F) - Basic Pricing Data Rev.xlsx XLSX spreadsheet
COMSCNOTE 2280.3.PDF PDF
22R5435 A0002.pdf PDF
Drawings Decon Station.pdf PDF
22R5435 A0001.pdf PDF
22R5435 Attachment IX (S) - MSC Standard Operating Manual (SOM).pdf PDF
22R5435 Attachment IX (T) - Clarification and Question Form.docx DOCX document
22R5435 Attachment IX (K) - ATFP CBRD Requirements.pdf PDF
22R5435 Attachment IX (B) - US Department of Labor Wage Determination.pdf PDF
22R5435 Attachment IX (E) - GFP.xlsx XLSX spreadsheet
22R5435 Attachment IX (L) - CBRN Requirements.pdf PDF
22R5435 Attachment IX (J) - Technical Offer Worksheet.XLSX XLSX spreadsheet
22R5435 Attachment IX (O) - CONSOL Station Requirement.pdf PDF
22R5435 Attachment IX (Q) - MECSP Worksheet.docx DOCX document
22R5435 Attachment IX (F) - Basic Pricing Data.xlsx XLSX spreadsheet
22R5435 Attachment IX (M) - CBRN-D Decon Station.pdf PDF
22R5435 Attachment IX (R) - CDRL.pdf PDF
22R5435 Attachment IX (G) - Crew Complement.docx DOCX document
N3220522R5435 RFP.pdf PDF
22R5435 Attachment IX (P) - Disclosure of Lobbying Activities (SFLLL).pdf PDF
22R5435 Attachment IX (H) - DD Form 254 25 JUL 2022 1.1.pdf PDF
22R5435 Attachment IX (N) - Shipboard Security System.pdf PDF
22R5435 Attachment IX (I) - PWS.pdf PDF
Show all 31

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

83300 Federal Register / Vol. 85, No. 245 / Monday, December 21, 2020 / Rules and Regulations

DEPARTMENT OF DEFENSE

Office of the Secretary

32 CFR Part 117

[Docket ID: DOD–2020–OS–0045]

RIN 0790–AK85

National Industrial Security Program Operating Manual (NISPOM)

AGENCY: Office of the Under Secretary of Defense for Intelligence & Security, Department of Defense (DoD).

ACTION: Final rule with request for comment.

SUMMARY: The Department of Defense (DoD) is codifying the National Industrial Security Program Operating Manual (NISPOM) in regulation. The NISPOM establishes requirements for the protection of classified information disclosed to or developed by contractors, licensees, grantees, or certificate holders (hereinafter referred to as contractors) to prevent unauthorized disclosure. In addition to adding the NISPOM to the Code of Federal Regulations (CFR), this rule incorporates the requirements of Security Executive Agent Directive (SEAD) 3, ‘‘Reporting Requirements for Personnel with Access to Classified Information or Who Hold a Sensitive Position.’’ SEAD 3 requires reporting by all contractor cleared personnel who have been granted eligibility for access to classified information. This NISPOM rule provides for a single nation-wide implementation plan which will, with this rule, include SEAD 3 reporting by all contractor cleared personnel to report specific activities that may adversely impact their continued national security eligibility, such as reporting of foreign travel and foreign contacts. NISP Cognizant Security Agencies (CSAs) shall conduct an analysis of such reported activities to determine whether they pose a potential threat to national security and take appropriate action. Finally, the rule also implements the provisions of Section 842 of Public Law 115–232, which removes the requirement for a covered National Technology and Industrial Base (NTIB) entity operating under a special security agreement pursuant to the NISP to obtain a national interest determination as a condition for access to proscribed information.

DATES: Effective date: This rule is effective February 24, 2021. Comments must be received by February 19, 2021.

ADDRESSES: You may submit comments, identified by docket number and/or Regulatory Information Number (RIN) and title, by any of the following methods:

• Federal Rulemaking Portal: http:// www.regulations.gov. Follow the instructions for submitting comments.

• Mail: DoD cannot receive written comments at this time due to the COVID–19 pandemic. Comments should be sent electronically to the docket listed above.

Instructions: All submissions received must include the agency name and docket number or RIN for this Federal Register document. The general policy for comments and other submissions from members of the public is to make these submissions available for public viewing at http://www.regulations.gov as they are received without change, including any personal identifiers or contact information.

FOR FURTHER INFORMATION CONTACT:

Valerie Heil, 703–692–3754.

SUPPLEMENTARY INFORMATION:

I. Overview of the NISP and NISPOM

In April 1990, President George Bush directed the National Security Council to explore the creation of a single, integrated industrial security program to improve security protection and provide cost savings. Prior to this, contractors doing business with different U.S.

Government (USG) agencies which required access to classified information had to meet different requirements to protect the same levels of classified information, e.g., the type of safe to protect a specific classified item could vary across both contracts and agencies.

The diversity of industrial security requirements levied on contractors by an estimated 21 USG agencies created a significant burden on both industry and government and increased the cost of the goods and services provided to the

USG.

Representatives from government and industry participated in an initiative which led to the creation of Executive Order (E.O.) 12829 ‘‘National Industrial Security Program (NISP)’’ (available at https://www.archives.gov/files/isoo/ policy-documents/eo-12829-with-eo- 13691-amendments.pdf). With the National Security Council providing overall policy direction, this E.O.

established the NISP as the single integrated program to protect classified information and preserve our Nation’s economic and technological interests.

Nothing in the E.O. shall supersede the authority of the Secretary of Energy or the Nuclear Regulatory Commission under the Atomic Energy Act of 1954, as amended, or the authority of the Director of National Intelligence (or any Intelligence Community element) under the Intelligence Reform and Terrorism Prevention Act of 2004, the National Security Act of 1947, as amended, or Executive Order No. 12333 of December 8, 1981, as amended, or the authority of the Secretary of Homeland Security, as the Executive Agent for the Classified National Security Information Program established under Executive Order 13549 of August 18, 2010 (Classified National Security Information Program for State, Local, Tribal, and Private Sector Entities). The Information Security Oversight Office (ISOO), a component of the National Archives and Records Administration (NARA), was tasked with overseeing overall implementation of the NISP with the goal of:

• Holding classification activity to the minimum necessary to protect the national security;

• ensuring the safeguarding of classified national security information in both USG and industry in a cost-effective and efficient manner; and

• promoting declassification and public access to information as soon as national security considerations permit.

ISOO issues implementing directives and produces an annual report to the President on the NISP. E.O. 12829 also established the National Industrial Security Program Policy Advisory Committee (NISPPAC), a federal advisory committee comprised of both Government and industry representatives, which is responsible for recommending changes in industrial security policy. The NISPPAC, chaired by the Director of the ISOO, also advises ISOO on all issues concerning the policies of the NISP, including recommended changes to those policies, and serves as a forum to discuss policy issues in dispute. The NISPPAC industry members represent all types and sizes of NISP cleared entities, whose scope of operations range from a one person entity, having a single classified contract to some of the largest U.S. entities, having numerous classified contracts. All NISPPAC industry members have expertise comprising the primary functions of an industrial security program, to include information, personnel, physical, and information system security.

Five USG executive branch agencies— DoD, DOE, the Nuclear Regulatory Commission (NRC), the Office of the Director of National Intelligence (ODNI), and the Department of Homeland Security (DHS)—have been designated as Cognizant Security Agencies (CSAs) and have specific responsibilities within the NISP. For DoD, the Defense Counterintelligence and Security Agency (DCSA) is the Cognizant

VerDate Sep<11>2014 23:08 Dec 18, 2020 Jkt 253001 PO 00000 Frm 00002 Fmt 4701 Sfmt 4700 E:\FR\FM\21DER3.SGM 21DER3 https://www.archives.gov/files/isoo/policy-documents/eo-12829-with-eo-13691-amendments.pdf https://www.archives.gov/files/isoo/policy-documents/eo-12829-with-eo-13691-amendments.pdf https://www.archives.gov/files/isoo/policy-documents/eo-12829-with-eo-13691-amendments.pdf http://www.regulations.gov http://www.regulations.gov http://www.regulations.gov

83301 Federal Register / Vol. 85, No. 245 / Monday, December 21, 2020 / Rules and Regulations

Security Office (CSO) for DoD Components and non-DoD agencies where an industrial security agreement is in place. DCSA, as the DoD CSO, DOE, and NRC each has the following responsibilities:

• Administers the NISP.

• provides security oversight.

• conducts security review actions.

• provides security education and training.

• provides supplementary procedures for unique mission requirements (e.g.

DoD publishes industrial security letters (ISLs), which provide DoD-specific guidance and clarification on NISP policies and supplementary procedures to its unique CSO mission requirements (available at: https://www.dcsa.mil/mc/ ctp/tools/)).

• assesses, authorizes and oversees contractor information systems used to process classified information.

• makes temporary national security eligibility determinations pursuant to SEAD 8, Temporary Eligibility (available at: https://www.dni.gov/files/ NCSC/documents/Regulations/SEAD-8_ Temporary_Eligibility_U.pdf), for contractor personnel who require access to classified information.

DHS receives NISP industrial security services from DoD due to its industrial security services agreement and also has the following responsibilities:

• Prescribes procedures for the portions of this rule that pertain to the

CCIPP.

• retains authority over access to information under the CCIPP.

• inspects and monitors contractor, licensee, certificate holder, and grantee programs and facilities that involve access to CCIPP.

ODNI has the following responsibilities:

• Prescribes procedures for the portions of this rule pertaining to intelligence sources, methods, and activities, including, but not limited to, SCI.

• retains authority over access to intelligence sources, methods, and activities, including SCI.

• provides guidance on the security requirements for intelligence sources and methods of information, including, but not limited to, SCI.

DOE and NRC provide similar industrial security oversight actions, including national security eligibility determinations for contractor personnel, authorization of contractor information systems to process classified information, as well as monitoring and inspecting those contractors under DOE or NRC security cognizance, respectively. In 2004, the Intelligence Reform and Terrorism Prevention Act

(IRTPA) (Pub. L. 108–458) created the position of the Director of National Intelligence (DNI) and recognized the ODNI as a CSA. E.O. 13691 ‘‘Promoting Private Sector Cybersecurity Information Sharing,’’ February 13, 2015 (available at https:// obamawhitehouse.archives.gov/the-press-office/2015/02/13/executive-order-promoting-private-sector-cybersecurity-information-sharing), amended E.O. 12829 to make DHS the fifth CSA in 2015.

II. NISP Implementation DoD is the Executive Agent of the

NISP and has the largest NISP contractor population of the five CSAs.

DCSA inspects and monitors cleared entities, also referred to as contractors, who require access to classified information during all phases of the contracting, licensing, and grant (hereinafter referred to as contracting or contract) process to include the preparation and submission of bids and proposals, negotiation, award, performance, and termination. It also determines eligibility for access to classified information for contractors performing on classified contracts with DoD and with those USG agencies which have an industrial security agreement with DoD. The Department currently has industrial security agreements with 33 agencies (list available at: https://www.dcsa.mil/mc/ ctp/nisp/). DCSA field elements provide oversight of contractor compliance, authorize contractor information systems to process classified information, and conduct security review actions for approximately 12,500 cleared contractor entities which includes headquarters, divisions, subsidiaries and branch offices of industrial, educational, commercial, or other non-USG entities which are performing on classified contracts.

Under the NISP, the USG establishes requirements for the protection of classified information to be safeguarded in a manner equivalent to its protection within the executive branch of USG, where practicable. When bound by contract, industry must comply with the NISPOM and any CSA-specific supplementary guidance for unique CSA mission requirements. Industry implements those requirements for the protection of classified information with advice, assistance, and oversight from the applicable CSA.

When a Government Contracting Activity (GCA), an element of an agency that has authority regarding acquisition or grant functions, awards a contract that has been determined to require access to classified information, the contract is considered to be a ‘‘classified contract.’’ The GCA checks with its applicable CSA to determine if the awarded legal entity already has an entity eligibility determination (also referred to as a facility security clearance (FCL)). GCAs will ordinarily include enough lead-time in the acquisition cycle to accomplish all required security actions. In many instances, advanced planning can ensure that access to classified information will not be required in the pre-award process. This would preclude processing an entire bidder list for FCLs.

When access to classified information is not a factor in the pre-award phase, but will be required for contract performance, only the successful bidder or offeror will be processed for an FCL.

Before an entity can have access to classified information during its contract performance, it must have an FCL. If the legal entity does not already have an FCL when awarded a classified contract, a GCA must sponsor the entity for an FCL. Or, an entity already part of the NISP (i.e., a prime contractor) may sponsor another entity in order to subcontract part of its classified business. To sponsor an entity, the GCA or prime contractor puts in a request, often referred to as a sponsorship letter, to the appropriate CSA for the entity to access classified information in connection with a legitimate government requirement, which may include a foreign government requirement.

With an approved FCL, an entity is then eligible for access to information classified at the level of the FCL (i.e., TOP SECRET, SECRET or CONFIDENTIAL) when competing for a classified contract. Among other requirements, an entity must have sponsorship based on a valid government requirement for access to classified information. The USG agency sponsoring an entity for an FCL must include the applicable security requirements clause or equivalent in the contract (e.g., for DoD this is the Federal Acquisition Regulation (FAR) 52.204–2 ‘‘Security Requirements,’’ or the terms and conditions of a grant award under 2 CFR part 200.210) to require compliance with the NISPOM.

A GCA provides the security requirements for a classified contract in a contract security classification specification as part of the contract. For DoD, the DD form 254, ‘‘Department of Defense Contract Security Classification Specification,’’ OMB Control number 0704–0567, is part of the classified contract and provides the contractor (or a subcontractor) with security requirements and the classification

VerDate Sep<11>2014 23:08 Dec 18, 2020 Jkt 253001 PO 00000 Frm 00003 Fmt 4701 Sfmt 4700 E:\FR\FM\21DER3.SGM 21DER3 https://www.dni.gov/files/NCSC/documents/Regulations/SEAD-8_Temporary_Eligibility_U.pdf https://www.dni.gov/files/NCSC/documents/Regulations/SEAD-8_Temporary_Eligibility_U.pdf https://www.dni.gov/files/NCSC/documents/Regulations/SEAD-8_Temporary_Eligibility_U.pdf https://www.dcsa.mil/mc/ctp/nisp/ https://www.dcsa.mil/mc/ctp/nisp/ https://www.dcsa.mil/mc/ctp/tools/ https://www.dcsa.mil/mc/ctp/tools/ https://obamawhitehouse.archives.gov/the-press-office/2015/02/13/executive-order-promoting-private-sector-cybersecurity-information-sharing https://obamawhitehouse.archives.gov/the-press-office/2015/02/13/executive-order-promoting-private-sector-cybersecurity-information-sharing https://obamawhitehouse.archives.gov/the-press-office/2015/02/13/executive-order-promoting-private-sector-cybersecurity-information-sharing https://obamawhitehouse.archives.gov/the-press-office/2015/02/13/executive-order-promoting-private-sector-cybersecurity-information-sharing https://obamawhitehouse.archives.gov/the-press-office/2015/02/13/executive-order-promoting-private-sector-cybersecurity-information-sharing

83302 Federal Register / Vol. 85, No. 245 / Monday, December 21, 2020 / Rules and Regulations guidance necessary to execute a specific classified contract. See https:// www.esd.whs.mil/Portals/54/ Documents/DD/forms/dd/dd0254.pdf and available at https://www.dcsa.mil/ is/nccs/) for the current version of this collection. A contract security classification specification with its attachments, supplements, and incorporated references, provides security classification guidance (lists the applicable security classification guides for a contractor to use) to a contractor in connection with a classified contract.

It is designed to identify the classified areas of information involved in the classified effort and, particularly, to identify the specific items of information within these areas that require protection. This rule provides NISP contractors security requirements which align to 32 CFR part 2001, in a manner equivalent to the protection of classified information within the executive branch of the USG. If a GCA determines that additional safeguards are essential in specific contracts, the GCA can impose more operational security provisions above the requirements of this rule. The GCA can also determine that additional physical or technical security requirements are needed in a contract above the requirements of this rule. Even though the contract security classification is contract-specific, it is not always all-inclusive. Additional security requirements are sometimes included in other parts of a contract. All related materials for approved information collection are available at: https:// www.reginfo.gov/public/do/PRAMain.

In addition, specific locations for finalized collection instruments, to include the designated OMB Control Number is included where information collections are cited in this rule.

In addition, depending upon the CSA with security cognizance, an entity’s legal headquarters may need to implement additional information collections, such as:

• DD Form 441, ‘‘DoD Security Agreement’’ for DoD is an agreement between DCSA and the cleared legal entity for the entity to comply with the NISPOM security requirements, to be subject to inspections and to allow for a 30 day notice by the entity or DCSA to terminate the agreement (e.g., if there is no longer a valid USG requirement for access to classified information (available at https://www.esd.whs.mil/ Portals/54/Documents/DD/forms/dd/ dd0441_2020.pdf);

• NRC Form 441, ‘‘Security Agreement’’ for NRC, the provisions of the NRC Form 441 are similar to those included in the DD Form 441 (available at https://www.nrc.gov/reading-rm/doc-collections/forms/nrc441info.html).

• DOE does not have a separate Form 441, but instead, binds the contractor to the FCL (and security requirements) via the contract, along with meeting all other requirements in this rule.

As part of FCL processing, an entity must complete a Standard Form (SF) 328, ‘‘Certificate Pertaining to Foreign Interest,’’ OMB Control number 0704– 0579, (available at https://www.gsa.gov/ forms-library/certificate-pertaining-foreign-interests, for a CSA to review and make a determination whether the entity is under foreign ownership, control or influence (FOCI) to a degree that renders it ineligible for an FCL. The CSA will consider a U.S. entity to be under FOCI when a foreign interest has the power to direct or decide issues affecting the entity’s management or operations in a manner that could either result in unauthorized access to classified information; or adversely affect performance of a classified contract or agreement. The U.S. entity may also be considered to be under FOCI when a foreign interest or government is currently exercising, or could exercise, that power, whether directly or indirectly, such as through ownership of the U.S. entity’s securities, by contractual arrangements, or other means. Further, if a foreign interest or government has the ability to control or influence the election or appointment of members of the entity’s governing board, the entity may be considered to be under FOCI. When a CSA has determined that an entity is under FOCI, the primary consideration will be the protection of classified information. The CSA will take whatever action is necessary to protect classified information, in coordination with other affected agencies as appropriate. A U.S.

entity that is in process for an FCL for access to classified information and subsequently determined to be under FOCI, is ineligible for access to classified information unless and until effective security measures have been put in place to negate or mitigate FOCI to the satisfaction of the CSA.

Once an entity becomes a contractor in the NISP with an existing FCL, a GCA can select and award a classified contract to the entity as part of the acquisition process. The GCA attaches the ‘‘Contract Security Classification Specification: (e.g., for DoD, it is the DD Form 254, available at https:// www.esd.whs.mil/Portals/54/ Documents/DD/forms/dd/dd0254.pdf and available at https://www.dcsa.mil/ is/nccs/), to all such contracts requiring access to classified information.

II. SEAD 3 Requirements and the

NISPOM

In 2008, with the publication of E.O.

13467, ‘‘Reforming Processes Related to Suitability for Government Employment, Fitness for Contractor Employees, and Eligibility for Access to Classified National Security Information’’ (available at https:// obamawhitehouse.archives.gov/the-press-office/2016/09/29/executive-order-amending-executive-order-13467-establish-roles-and), the DNI was assigned the role of the Security Executive Agent (SecEA), for the development, implementation, and oversight of effective, efficient, and uniform policies and procedures governing the conduct of investigations and adjudications for eligibility for access to classified information and eligibility to hold a sensitive position.

In December 2016, the SecEA issued SEAD 3, ‘‘Reporting Requirements for Personnel with Access to Classified Information or Who Hold a Sensitive Position’’ (available at https:// www.dni.gov/files/NCSC/documents/ Regulations/SEAD-3-Reporting-U.pdf), to executive branch agencies or covered individuals with an effective date of June 12, 2017. SEAD 3 defines covered individuals as:

• A person who performs work for or on behalf of the executive branch who has been granted access to classified information or holds a sensitive positions, but does not include the President or the Vice President.

• a person who performs work for or on behalf of a state, local, tribal, or private sector entity, as defined in E.O.

13549, who has been granted access to classified information or holds a sensitive position, but does not include duly elected or appointed governors of a state or territory, or an official who has succeeded to that office under applicable law; and

• a person working in or for the legislative or judicial branches who has been granted access to classified information or holds a sensitive position and the investigation or determination was conducted by the executive branch, but does not include members of Congress, Justices of the Supreme Court, or Federal judges appointed by the President.

• covered individuals are not limited to government employees and include all persons, not excluded under paragraphs D.5(a), (b), or (c) of SEAD 3, who have access to classified information or who hold sensitive positions, including, but not limited to, contractors, subcontractors, licensees, certificate holders, grantees, experts, VerDate Sep<11>2014 23:08 Dec 18, 2020 Jkt 253001 PO 00000 Frm 00004 Fmt 4701 Sfmt 4700 E:\FR\FM\21DER3.SGM 21DER3 https://www.dni.gov/files/NCSC/documents/Regulations/SEAD-3-Reporting-U.pdf https://www.dni.gov/files/NCSC/documents/Regulations/SEAD-3-Reporting-U.pdf https://www.dni.gov/files/NCSC/documents/Regulations/SEAD-3-Reporting-U.pdf https://www.esd.whs.mil/Portals/54/Documents/DD/forms/dd/dd0441_2020.pdf https://www.esd.whs.mil/Portals/54/Documents/DD/forms/dd/dd0441_2020.pdf https://www.esd.whs.mil/Portals/54/Documents/DD/forms/dd/dd0441_2020.pdf https://www.gsa.gov/forms-library/certificate-pertaining-foreign-interests https://www.gsa.gov/forms-library/certificate-pertaining-foreign-interests https://www.gsa.gov/forms-library/certificate-pertaining-foreign-interests https://www.esd.whs.mil/Portals/54/Documents/DD/forms/dd/dd0254.pdf https://www.esd.whs.mil/Portals/54/Documents/DD/forms/dd/dd0254.pdf https://www.esd.whs.mil/Portals/54/Documents/DD/forms/dd/dd0254.pdf https://www.esd.whs.mil/Portals/54/Documents/DD/forms/dd/dd0254.pdf https://www.esd.whs.mil/Portals/54/Documents/DD/forms/dd/dd0254.pdf https://www.esd.whs.mil/Portals/54/Documents/DD/forms/dd/dd0254.pdf https://www.reginfo.gov/public/do/PRAMain https://www.reginfo.gov/public/do/PRAMain https://www.dcsa.mil/is/nccs/ https://www.dcsa.mil/is/nccs/ https://www.dcsa.mil/is/nccs/ https://www.dcsa.mil/is/nccs/ https://www.nrc.gov/reading-rm/doc-collections/forms/nrc441info.html https://www.nrc.gov/reading-rm/doc-collections/forms/nrc441info.html https://obamawhitehouse.archives.gov/the-press-office/2016/09/29/executive-order-amending-executive-order-13467-establish-roles-and https://obamawhitehouse.archives.gov/the-press-office/2016/09/29/executive-order-amending-executive-order-13467-establish-roles-and https://obamawhitehouse.archives.gov/the-press-office/2016/09/29/executive-order-amending-executive-order-13467-establish-roles-and

83303 Federal Register / Vol. 85, No. 245 / Monday, December 21, 2020 / Rules and Regulations consultants, and government employees.

SEAD 3 identifies required reporting of data elements that are contained in the Standard Form-86, ‘‘Questionnaire for National Security Positions’’ (available at https://www.opm.gov/ forms/pdf_fill/sf86.pdf), which applicants and clearance holders complete during the initial and periodic reinvestigation processes, respectively.

SEAD 3 requires these elements to be reported prior to participation in such activities or otherwise as soon as possible following the start of their involvement. Most notably, SEAD 3 requires covered individuals to obtain prior agency approval before conducting unofficial foreign travel.

For this rule, SEAD 3 applies only for those contractor personnel who have been granted eligibility for access to classified information through the NISP.

In accordance with paragraph E.4 of SEAD 3, NISP CSAs, acting on behalf of Heads of agencies or designees, for the NISP contractors under their security cognizance may determine that operational and mission needs preclude strict adherence to these reporting requirements. In those instances, a NISP CSA may provide CSA guidance to supplement unique CSA mission requirements to the contractors under its security cognizance of equivalent notification, briefing and reporting to be accomplished.

III. Requirements From Section 842 of Public Law 115–232

Currently, the NISPOM and 32 CFR part 2004 require that GCAs, in coordination with the applicable CSAs and controlling agencies (ODNI for Sensitive Compartmented Information (SCI), DOE for Restricted Data (RD) or NSA for Communications Security (COMSEC)), complete a National Interest Determination (NID) before granting access to proscribed information to an entity that is owned or controlled by a foreign interest and cleared under a Special Security Agreement (SSA). The term ‘‘proscribed information’’ means information that is—

(A) classified at the level of top secret;

(B) communications security information (excluding controlled cryptographic items when un-keyed or utilized with unclassified keys);

(C) Restricted Data (as defined in section 11 of the Atomic Energy Act of 1954, as amended (42 United States Code (U.S.C.) 2014));

(D) special access program information under section 4.3 of E.O.

13526 (75 FR 707; 50 U.S.C. 3161 note) or successor order; or

(E) designated as sensitive compartmented information, as defined in Intelligence Community Directive 703, ‘‘Protection of National Intelligence, Including Sensitive Compartmented Information’’ (available at https://www.dni.gov/files/documents/ ICD/ICD%20703.pdf).

An SSA is one of the mechanisms used by the USG to mitigate FOCI to an acceptable level as determined by the CSA. A company is considered to be operating under FOCI whenever a foreign interest has the power, direct or indirect, whether or not exercised, and whether or not exercisable, to direct or decide matters affecting the management or operations of that company in a manner which may result in unauthorized access to classified information or may adversely affect the performance of classified contracts. The following factors relating to a company, the foreign interest, and the government of the foreign interest are reviewed in the aggregate in determining whether a company is under FOCI:

D Record of economic and government espionage against U.S. targets D Record of enforcement and/or engagement in unauthorized technology transfer

D The type and sensitivity of the information that shall be accessed

D The source, nature and extent of FOCI D Record of compliance with pertinent

U.S. laws, regulations and contracts D The nature of any bilateral and multilateral security and information exchange agreements that may pertain

D Ownership or control, in whole or in part, by a foreign government.

Section 842 of Public Law 115–232 and this final rule provide that a covered NTIB entity operating under an SSA pursuant to the NISP, shall not be required to obtain a NID as a condition for access to proscribed information, effective October 1, 2020. DoD notified the DoD components and 33 non-DoD agencies with which DoD has industrial security agreements that NIDs pursuant to the provisions of Section 842 of Public Law 115–232 are no longer required as of October 1, 2020. DCSA is no longer submitting NID requests to ODNI for SCI, DOE for RD, or NSA for COMSEC, respectively that fall within the provisions of Section 842 of Public Law 115–232.

As provided for in the law, the Under Secretary of Defense for Intelligence and Security, on behalf of the Secretary, granted waivers of NIDs for those categories of proscribed information under the control of the Secretary of Defense, to 20 contractors that met the criteria in summer 2019 with the waivers expiring as of October 1, 2020, since the statute went into effect. Those contractors, pursuant to Section 842 of Public Law 115–232 had to meet the following criteria as part of the waiver determination:

(1) A demonstrated successful record of compliance with the NISP assessed by the CSA; and

(2) previously been approved for access to proscribed information as indicated in CSA FCL records.

The law is limited to ‘‘a person that is a subsidiary located in the United States—

(A) for which the ultimate parent entity and any intermediate parent entities of such subsidiary are located in a country that is part of the national technology and industrial base (as defined in section 2500 of title 10, United States Code); and

(B) that is subject to the FOCI requirements of the NISP.’’

Legal Authority for the NISP

In addition to E.O. 12829, which, establishes the NISP and requires the Secretary of Defense to issue and maintain the NISPOM, the following are other relevant authorities for the program.

• E.O. 10865 ‘‘Safeguarding Classified Information within Industry,’’ February 20, 1960, as amended (available at https://www.archives.gov/federal-register/codification/executive-order/ 10865.html), addresses the protection of classified information that is disclosed to, or developed by contractors.

• E.O. 12968, ‘‘Access to Classified Information,’’ August 2, 1995, as amended (available at https:// www.govinfo.gov/content/pkg/FR-1995- 08-07/pdf/95-19654.pdf), establishes a uniform personnel security program for individuals who will be considered for initial or continued access to classified information.

• E.O. 13526, ‘‘Classified National Security Information,’’ December 29, 2009 (available at https:// www.archives.gov/files/isoo/pdf/cnsi-eo.pdf), prescribes a uniform system for classifying, safeguarding and declassifying national security information.

• E.O. 13587, ‘‘Structural Reforms to Improve the Security of Classified Networks and the Responsible Sharing and Safeguarding of Classified Information,’’ October 7, 2011 (available at https://www.govinfo.gov/app/details/ CFR-2012-title3-vol1/CFR-2012-title3-vol1-eo13587), directs structural reforms to ensure responsible sharing and safeguarding of classified information on computer networks consistent with

VerDate Sep<11>2014 23:08 Dec 18, 2020 Jkt 253001 PO 00000 Frm 00005 Fmt 4701 Sfmt 4700 E:\FR\FM\21DER3.SGM 21DER3 https://www.govinfo.gov/app/details/CFR-2012-title3-vol1/CFR-2012-title3-vol1-eo13587 https://www.govinfo.gov/app/details/CFR-2012-title3-vol1/CFR-2012-title3-vol1-eo13587 https://www.govinfo.gov/app/details/CFR-2012-title3-vol1/CFR-2012-title3-vol1-eo13587 https://www.archives.gov/federal-register/codification/executive-order/10865.html https://www.archives.gov/federal-register/codification/executive-order/10865.html https://www.archives.gov/federal-register/codification/executive-order/10865.html https://www.govinfo.gov/content/pkg/FR-1995-08-07/pdf/95-19654.pdf https://www.govinfo.gov/content/pkg/FR-1995-08-07/pdf/95-19654.pdf https://www.govinfo.gov/content/pkg/FR-1995-08-07/pdf/95-19654.pdf https://www.dni.gov/files/documents/ICD/ICD%20703.pdf https://www.dni.gov/files/documents/ICD/ICD%20703.pdf https://www.archives.gov/files/isoo/pdf/cnsi-eo.pdf https://www.archives.gov/files/isoo/pdf/cnsi-eo.pdf https://www.archives.gov/files/isoo/pdf/cnsi-eo.pdf https://www.opm.gov/forms/pdf_fill/sf86.pdf

83304 Federal Register / Vol. 85, No. 245 / Monday, December 21, 2020 / Rules and Regulations appropriate protection for privacy and civil liberties.

• E.O. 13691; Promoting Private Sector Cybersecurity Information Sharing,’’ February 13, 2015 (available at https:// obamawhitehouse.archives.gov/the-press-office/2015/02/13/executive-order-promoting-private-sector-cybersecurity-information-sharing), encourages the voluntary formation of organizations engaged in the sharing of information related to cybersecurity risks and incidents to establish mechanisms to continually improve their capabilities and functions as well as to better allow them to partner with the Federal government on a voluntary basis.

• E.O. 12333; ‘‘United States Intelligence Activities,’’ December 4, 1981, as amended (available at https:// www.archives.gov/federal-register/ codification/executive-order/ 12333.html, provides general principles that in addition to and consistent with applicable laws are intended to achieve the proper balance between the acquisition of essential information and the protection of individual interests.

• Title 42 U.S.C. 2011 et seq. (also known as and referred to in this rule as ‘‘The Atomic Energy Act of 1954,’’ as amended (AEA));

• Title 50 U.S.C. chapter 44 (also known as ‘‘The National Security Act of 1947, as amended);

• Title 50 U.S.C. 3501 et seq. (also known as ‘‘The Central Intelligence Agency Act of 1949,’’ as amended);

• Public Law 108–458 (also known as the ‘‘Intelligence Reform and Terrorism Prevention Act of 2004’’), which includes development of uniform and consistent policies and procedures to ensure effective, efficient and timely completion of security clearances.

• Finally, 32 CFR part 2004 ‘‘National Industrial Security Program,’’ May 7, 2018, establishes uniform standards for the NISP, and helps agencies implement requirements in E.O. 12829, and establishes agency responsibilities for implementing the insider threat provisions of E.O. 13587.

III. Changes Made by This Rule and Expected Impact

The NISPOM was first published in 1995 as DoD Manual 5220.22. Updates to the NISPOM have included Conforming Change 1, March 28, 2013 and NISPOM Change 2 in May 21, 2016.

The most current version of the NISPOM (Change 2) is available at https://www.esd.whs.mil/Portals/54/ Documents/DD/issuances/dodm/ 522022M.pdf?ver=2019-06-06-145530-

170. In addition to codifying the

NISPOM in the CFR and adding the requirements of SEAD 3 and Section 842 of Public Law 115–232, DoD is also removing 32 CFR part 117, subpart C, ‘‘National Industrial Security Program’’ because it is duplicative of 32 CFR part 2004, ‘‘National Industrial Security Program’’ and removing 32 CFR part 117, subpart B, because it is also duplicative of other industrial security provisions set forth in 32 CFR part 2004.

These administrative removals support a recommendation from the DoD Regulatory Reform Task Force created under E.O. 13777, Enforcing the Regulatory Reform Agenda (available at https://www.govinfo.gov/content/pkg/ FR-2017-03-01/pdf/2017-04107.pdf), and by themselves create no changes in current DoD policy. Upon the effective date of 32 CFR part 117, DoD will no longer publish the DoD Manual 5220.22, NISPOM as a DoD policy issuance.

Specific changes in this rule that are not in the current NISPOM, include the following.

• § 117.8: Reporting Requirements.

§ 117.8(a) General includes that contractors must submit reports pursuant to this rule, SEAD 3 and CSA guidance to supplement unique CSA mission requirements. SEAD 3 reporting establishes a single nationwide implementation plan for covered individuals, which for this rule provides reporting by contractors and their employees eligible for access to classified information. SEAD 3 requirements will be implemented for all contractor cleared personnel to report specific activities that may adversely impact their continued national security eligibility. Contractor cleared personnel must be aware of risks associated with foreign intelligence operations and/or possible terrorist activities directed against them in the United States and abroad, and have a responsibility to recognize and avoid personal behaviors and activities that adversely affect their national security eligibility. NISP CSAs shall conduct an analysis of such reported activities, such as foreign travel or foreign contacts, to determine whether they pose a potential threat to national security and take appropriate action. Contractors will be responsible for collecting the foreign travel data from cleared employees, providing pre- and post-travel briefings to those cleared employees when necessary, and tracking and reporting those foreign travel activities of its cleared employees through the CSA designated system of record for personnel security clearance data.

• § 117.9(m) Limited entity eligibility determination (Non-FOCI) and, § 117.11(e) Limited entity eligibility determination due to FOCI. In accordance with 32 CFR part 2004, ‘‘NISP Directive,’’ provisions for granting two new types of limited entity facility clearance eligibility determinations (FCLs) to meet government requirements for narrowly scoped requirements for a companies to access classified information.

• § 117.11(d)(2)(iii)(A) Requirement for National Interest Determinations (NIDs): This paragraph provides for the implementation of the provisions of Section 842 of Public Law 115–232, which was effective on October 1, 2020, and eliminates requirements for a covered NTIB entity operating under an SSA to obtain a NID for access to proscribed information: Top Secret, Special Access Program, Communications Security, Sensitive Compartmented Information, and Restricted Data. This provision will allow covered NTIB entities to begin performing on contracts that require access to proscribed information without having to wait on a NID, and thus removing costly contract performance delays.

• § 117.15(e)(2) TOP SECRET Information: Permits specific determinations by a CSA with respect to requirements for TOP SECRET accountability (e.g., the CSA can determine that TOP SECRET material stored in an electronic format on an authorized classified information system does not need to be individually numbered in series provided the contractor has in place controls in place to address accountability, need to know and retention). As stated in this paragraph: ‘‘. . . Contractors will establish controls for TOP SECRET information and material to validate procedures are in place to address accountability, need to know and retention, e.g., demonstrating that TOP SECRET material stored in an electronic format on an authorized classified information system does not need to be individually numbered in series. These controls are in addition to the information management system and must be applied, unless otherwise directed by the applicable CSA, regardless of the media of the TOP SECRET information, to include information processed and stored on authorized information systems. Unless otherwise directed by the applicable CSA, the contractor will establish the following additional controls . . .’’

• § 117.15(d)(4) Installation: Clarifies that an Intrusion Detection System (IDS) shall be installed by a Nationally Recognized Testing Laboratory (NRTL)-approved entity to make it clear that any NRTL-approved entity may do such

VerDate Sep<11>2014 23:08 Dec 18, 2020 Jkt 253001 PO 00000 Frm 00006 Fmt 4701 Sfmt 4700 E:\FR\FM\21DER3.SGM 21DER3 https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodm/522022M.pdf?ver=2019-06-06-145530-170 https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodm/522022M.pdf?ver=2019-06-06-145530-170 https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodm/522022M.pdf?ver=2019-06-06-145530-170 https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodm/522022M.pdf?ver=2019-06-06-145530-170 https://www.archives.gov/federal-register/codification/executive-order/12333.html https://www.archives.gov/federal-register/codification/executive-order/12333.html https://www.archives.gov/federal-register/codification/executive-order/12333.html https://www.archives.gov/federal-register/codification/executive-order/12333.html https://www.govinfo.gov/content/pkg/FR-2017-03-01/pdf/2017-04107.pdf https://www.govinfo.gov/content/pkg/FR-2017-03-01/pdf/2017-04107.pdf https://obamawhitehouse.archives.gov/the-press-office/2015/02/13/executive-order-promoting-private-sector-cybersecurity-information-sharing https://obamawhitehouse.archives.gov/the-press-office/2015/02/13/executive-order-promoting-private-sector-cybersecurity-information-sharing https://obamawhitehouse.archives.gov/the-press-office/2015/02/13/executive-order-promoting-private-sector-cybersecurity-information-sharing https://obamawhitehouse.archives.gov/the-press-office/2015/02/13/executive-order-promoting-private-sector-cybersecurity-information-sharing https://obamawhitehouse.archives.gov/the-press-office/2015/02/13/executive-order-promoting-private-sector-cybersecurity-information-sharing

83305 Federal Register / Vol. 85, No. 245 / Monday, December 21, 2020 / Rules and Regulations installations. ‘‘The IDS will be installed by a NRTL-approved entity or by an entity approved in writing by the

CSA . . .’’

• § 117.7(b)(2) Senior Management Official: Clarifies responsibilities of the Senior Management Official of each cleared entity to better reflect the critical role and accountability of this position for entity compliance with the NISPOM. This change further emphasizes the essential role of the Senior Management Official with the entity’s security staff to ensure NISPOM compliance.

• § 117.13(d)(5) Clarifies to the contractor that upon completion of a classified contract, the ‘‘contractor must return all government provided or deliverable information to the custody of the government. Such clarification ensures the contractor is not retaining official government records without specific authorization from the government customer. ‘‘(i) If the GCA does not advise to the contrary, the contractor may retain copies of the government material for a period of 2 years following the completion of the contract. The contract security classification specification, or equivalent, will continue in effect for this 2-year period. (ii) If the GCA determines the contractor has a continuing need for the copies of the government material beyond the 2-year period, the GCA will issue a final contract security classification specification, or equivalent, for the classified contract and will include disposition instructions for the copies.’’

Costs The DoD invites comment from the members of the public on the costs estimated to implement this rule.

A. Baseline The Defense Counterintelligence and

Security Agency (DCSA), as the DoD designated NISP cognizant security office, has collected information about baseline costs using an OMB-approved information collection process employing statistical methods for contractors’ NISP implementation (OMB Control Number 0704–0458, ‘‘Industry Cost Collection Report Survey.’’ The most recent data collected by DCSA on contractors’ NISP implementation costs are for fiscal year (FY) 2017 and reported in the ISOO 2017 annual report to the President. DCSA has used this survey collection methodology for contractors’ NISP implementation under DoD security cognizance for over 11 years. A NISP government and industry working group developed the survey in 1995 and predecessor office to the OUSD(I&S) initially ran the annual survey. The Information Security Oversight Office (ISOO) placed a moratorium on conducting this survey after 2017 until a new NISP survey methodology is developed.

DCSA began the costs analysis for the baseline costs for fiscal year 2017 by randomly selecting active NISP contractor facilities that have existing DoD approval for classified storage at their own physical locations and having those facilities submit security costs.

The randomly selected contractor facilities also have an active facility security clearance and a permanent Commercial and Government Entity

(CAGE) Code. In addition to the randomly selected cleared facilities having approved classified storage, DCSA categorizes these contractor facilities for the survey based on the size, scope, and complexity of each contractor’s security program.

The general methodology used to estimate security costs incurred by contractor cleared facilities with approved storage of classified information is based on the costs incurred by respondent contractors for the protection of classified information.

The methodology captures the most significant portion of industry’s costs, which is labor. Security labor in the survey is defined as personnel whose positions exist to support operations and staff in the implementation of government security requirements for the protection of classified information.

Guards who are required as supplemental controls are included in security labor. The respondent contractors are requested to compile their cleared facility’s current annual security labor cost in burdened, current year dollars with the most recent data being from the 2017 survey. The labor cost, when identified as an estimated percent of each contractor’s total security costs, enables the respondent contractors to calculate their total security costs.

Information collected is compiled to create an aggregate estimated cost of NISP classification-related activities.

Only the aggregate data is reported.

There is a 95% confidence that the full enterprise industrial security total baseline cost does not exceed $1.486 billion for fiscal year 2017.

NISP cost estimates (2017) Benefits of NISP rule

Number of Facilities with Approved Classified Storage (Of Over 12,000 NISP Cleared Facilities):

3658 ................................................................................................... A single, integrated, cohesive industrial security program to protect classified information and to preserve our Nation’s economic and technological interests.

Facilities Randomly Selected and Responding to Data Collection:

1038 ................................................................................................... Maximum uniformity and consistency by contractors who support the

Executive branch to effectively protect and safeguard classified infor-mation through all phases of the contracting process for any classi-fied information an Agency releases to a contractor.

Estimated Total NISP Security Costs for Facilities with Approved Clas-sified Storage (With 95% Margin of Error to give 95% Upper Con-fidence Limit):

$1,413,150,249 + $72,968,977 = $1,486,119,226 ............................ Contractors must comply, when levied by the FAR security require-ments clause or equivalent clauses in contracts involving access to classified information, with uniform procedures for the proper safe-guarding of classified information to reduce the risk of unauthorized disclosure of classified information.

Based on the data collected from the survey, we can be 95% confident the true 2017 total NISP security cost for contractor facilities with ap-proved classified storage is less than $1.486B.

Assumptions and Notes:

• Of over 12,000 NISP cleared facilities, 3,658 facilities are approved for classified storage and 1,038 responded to the survey.

VerDate Sep<11>2014 23:08 Dec 18, 2020 Jkt 253001 PO 00000 Frm 00007 Fmt 4701 Sfmt 4700 E:\FR\FM\21DER3.SGM 21DER3

83306 Federal Register / Vol. 85, No. 245 / Monday, December 21, 2020 / Rules and Regulations

• Companies were selected at random according to survey methodology.

• The applicable NISP CSA, based on a valid requirement for access to classified information (e.g., contract or bid), funds the costs for evaluating and processing a contractor for an entity eligibility determination (facility clearance) and the costs of personnel security vetting requirements for required access to classified information by any contractor employees.

• The security cost profile for non-responding companies is assumed to be similar to that of responding companies.

• Outlying survey data points were removed from data analysis.

• Overall DoD contract spending for 2017 was $331 billion; but DoD does not have such data for these contractor…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .