SECNAVINST 5510.36B.pdf

PDF 213 KB Posted

Attached to
Medium Range Tanker Time Charter Federal contract opportunity
Solicitation number
N32205-22-R-5435
Issued by
Department of the Navy Military Sealift Command

About this file

This is a Request for Proposal (RFP) from the Department of the Navy's Military Sealift Command seeking medium range tanker time charter services. The RFP requests offers for the time charter of one medium range tanker vessel for a base period of one year plus four one-year option periods. Offerors must provide pricing for the base period and each option period. The vessel must be able to load, transport, and discharge various petroleum products including gasoline, diesel, and jet fuel. The closing date for receipt of proposals is March 25, 2022. Award is expected by May 2022 with an anticipated start date of July 2022. At least 20% of the vessel's operating time must be reserved for small business set-aside charters.

View the file

Other files for this federal contract opportunity

Other files attached to Medium Range Tanker Time Charter, newest first.
File Type Posted
N3220522R5435 A0004.docx DOCX document
22R5435 A0003.pdf PDF
22R5435 Attachment IX (F) - Basic Pricing Data Rev 2.xlsx XLSX spreadsheet
COMSCINST 3541.5 PART 1 APPENDIX C.pdf PDF
Drawings Decon Station.pdf PDF
SECNAVINST 5510.30C.pdf PDF
DOD MANUAL AND COMSEC SUPPLEMENT.pdf PDF
22R5435 Attachment IX (I) - PWS Rev.pdf PDF
22R5435 Attachment IX (F) - Basic Pricing Data Rev.xlsx XLSX spreadsheet
COMSCNOTE 2280.3.PDF PDF
22R5435 A0002.pdf PDF
22R5435 Attachment IX (J) - Technical Offer Worksheet Rev.XLSX XLSX spreadsheet
22R5435 A0001.pdf PDF
22R5435 Attachment IX (S) - MSC Standard Operating Manual (SOM).pdf PDF
22R5435 Attachment IX (T) - Clarification and Question Form.docx DOCX document
22R5435 Attachment IX (K) - ATFP CBRD Requirements.pdf PDF
22R5435 Attachment IX (B) - US Department of Labor Wage Determination.pdf PDF
22R5435 Attachment IX (H) - DD Form 254 25 JUL 2022 1.1.pdf PDF
22R5435 Attachment IX (N) - Shipboard Security System.pdf PDF
22R5435 Attachment IX (I) - PWS.pdf PDF
22R5435 Attachment IX (M) - CBRN-D Decon Station.pdf PDF
22R5435 Attachment IX (R) - CDRL.pdf PDF
22R5435 Attachment IX (G) - Crew Complement.docx DOCX document
N3220522R5435 RFP.pdf PDF
22R5435 Attachment IX (P) - Disclosure of Lobbying Activities (SFLLL).pdf PDF
22R5435 Attachment IX (E) - GFP.xlsx XLSX spreadsheet
22R5435 Attachment IX (L) - CBRN Requirements.pdf PDF
22R5435 Attachment IX (J) - Technical Offer Worksheet.XLSX XLSX spreadsheet
22R5435 Attachment IX (O) - CONSOL Station Requirement.pdf PDF
22R5435 Attachment IX (Q) - MECSP Worksheet.docx DOCX document
22R5435 Attachment IX (F) - Basic Pricing Data.xlsx XLSX spreadsheet
Show all 31

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DEPARTMENT OF THE NAVY

OFFICE OF THE SECRETARY

1000 NAVY PENTAGON

WASHINGTON DC 20350·1000

SECNAVINST 5510.36B

DUSN

12 Jul 2019

SECNAV INSTRUCTION 5510.36B

From: Secretary of the Navy

Subj: DEPARTMENT OF THE NAVY INFORMATION SECURITY PROGRAM

Ref: See enclosure (1)

Encl: (1) References

(2) Responsibilities

(3) Department of the Navy Information Security Program Overview

(4) Classification Management

(5) Alternative Compensatory Control Measures

(6) Violations of This Instruction

(7) Records Management

(8) Forms and Reports

1. Purpose. Per the authority in reference (a), this instruction updates policy and responsibilities for Classified National Security Information (CNSI) and Controlled Unclassified Information (CUI) within an overarching Department of the Navy (DON) Information Security Program (ISP), pursuant to references

(b) through (f); establishes uniform ISP policies and procedures per references (b) through (f); complies with the intent of references (b) and (d) to observe the democratic principles of openness and the free flow of information, as well as to enforce protective measures for safeguarding information critical to national security; incorporates policies and procedures established by other executive branch agencies and supplements volumes 1 through 4 of reference (f), where needed. When applying guidance of this instruction, the user must consult the appropriate volume of reference (f) to ensure proper application of DON and Department of Defense (DoD) ISP standards.

2. Cancellation. SECNAVINST 5510.36A, SECNAV M-5510.36, DUSN

(P) ltr 5510 Ser DUSN (P)/006 of 2 Feb 18, and DUSN (P) ltr 5510 Ser DUSN (P)/009 of 31 Aug 16.

3. Definitions. For DoD definitions for the Information, Personnel, Physical, Special Access, and Industrial Security

12 Jul 2019

Programs, see reference (g). Reference (g) can be obtained by accessing the Deputy Under Secretary of the Navy (DUSN) Security Directorate Microsoft SharePoint Portal.

4. Applicability. This instruction applies to the Offices of the Secretary of the Navy (SECNAV), the Chief of Naval Operations (CNO), the Commandant of the Marine Corps (CMC), and all U.S. Navy (USN) and U.S. Marine Corps (USMC) installations, commands, activities, field offices, and all other organizational entities within the DON. It does not alter or supersede the existing authorities delegated to the Director, DON Special Access Program (SAP) Central Office (DON SAPCO) for SAP, per references (h) through (l), or those delegated to the USMC Director of Intelligence (DIRINT) and the Director of Naval Intelligence (DNI) as Heads of the Intelligence Community Elements (HICE) by the Director of National Intelligence as delineated in reference (m).

5. Policy. It is DON policy that:

a. The DUSN is appointed as the DON Senior Agency Official (SAO) for the DON ISP, including SAO responsibilities pursuant to reference (b), and is delegated Top Secret (TS) Original Classification Authority (OCA).

b. The Deputy CNO for Information Warfare, Office of the CNO is designated as the USN HICE for Sensitive Compartmented Information (SCI) as defined in references (a), (f), and (n).

c. The DIRINT is designated as the USMC HICE for SCI as defined in references (a), (f), and (n).

d. The Director, DON SAPCO is responsible for the execution, management, oversight, administration, security, information systems and networks, information assurance, and records management for SAPs under the responsibility of the DON, per references (j) through (l).

e. All personnel of the DON are personally and individually responsible for properly creating/marking, safeguarding, transmitting, and destroying classified information and CUI under their custody and control, per volumes 1 through 4 of reference (f).

f. All officials within the DON who hold command, management, or supervisory positions have specific, non-delegable responsibility for the quality and effectiveness of implementation and management of the DON ISP within their areas of responsibility.

g. National security information will be classified, safeguarded, and declassified per references (b), (c), (f), and (g). CUI will be identified and safeguarded consistent with the requirements of references (d) through (f).

h. Classified information released to industry will be safeguarded, per reference (o).

i. Security requirements and responsibilities for protecting classified information and CUI from Unauthorized Disclosure (UD) will be emphasized in DON Component training programs, pursuant to references (b) through (f).

j. Before being approved for public release, all DoD information will be reviewed pursuant to references (f) and (o) through (r) and other applicable policies including reference (s).

k. Safeguarding requirements and incident response measures addressing willful, negligent, and inadvertent mishandling of classified information, to include on Information Systems, must be implemented across DON, per reference (t).

l. Necessary resources are committed to effectively implement the DON ISP.

m. Management takes prompt and appropriate action in cases of compromise or UD of CNSI and CUI. Such actions shall focus on correcting or eliminating the conditions that caused or brought about the incident.

n. Commanders/Directors are allowed to submit waivers and exceptions through the chain-of-command to the DON SAO when situations arise that require deviation from the standards of this instruction or any of its implementing directives.

o. All personnel with access to classified information systems that are capable of processing North Atlantic Treaty

Organization (NATO) classified information must be briefed on their responsibilities for protecting NATO information and acknowledge in writing the receipt of the NATO briefing.

p. All personnel who are authorized access to classified information systems must complete derivative classification training initially and annually thereafter.

q. To use the current holder of the General Services Administration (GSA) contract for overnight delivery of information for the Executive Branch when the requirement exists for overnight delivery to a DoD Component within the U.S. and its territories. The use of external (street side) collection boxes is prohibited.

r. Volume 2 of reference (f) is the DON authoritative source for marking CNSI. Documents marked per previous guidance or the Information Security Oversight Office (ISOO) Marking Guide do not need to be re-marked. All newly created documents must carry compliant markings per this volume.

s. Volume 4 of reference (f) is the DON authoritative source for marking CUI. CUI will be marked as “For Official Use Only” (FOUO) until DoD publishes new guidance. CUI marked FOUO will be protected per the guidelines of this volume.

t. All persons (i.e., military, civilian, and contractor) must possess a valid and appropriate security clearance, signed a Standard Form (SF) 312, “Classified Information Nondisclosure Agreement,” and a valid need-to-know prior to being granted access to CNSI.

u. Visitors to a DON facility who require access to, or where disclosure of, classified information may occur during the visit will have their identity, security clearance and access level, and need-to-know verified prior to the visit.

Unannounced visitors will not be allowed entry to a facility where access to, or where disclosure of, classified information may occur until their identity, security clearance and access level, and need-to-know are verified.

v. The DON SAO, CNO, or CMC may authorize personnel under their authority to remove secret and confidential information from their designated working areas for work at home provided authority has been granted, per volume 3 of reference (f). The CNO or CMC may further delegate this authority to the heads of Echelon I and II activities. No further delegation is authorized.

6. Responsibilities. See enclosure (2).

7. DON ISP Overview. The purpose of the DON ISP is to ensure classified and controlled CUI is properly created, safeguarded, transmitted, and destroyed (see enclosure (3)).

8. Classification Management. For more information on DON Classification Management, see enclosure (4).

9. Alternative Compensatory Control Measures (ACCM). For information on ACCM, see enclosure (5).

10. Violations of this Instruction. For information on possible disciplinary action and criminal penalties, see enclosure (6).

11. Records Management. See enclosure (7).

12. Forms and Reports. See enclosure (8).

THOMAS B. MODLY

Under Secretary of the Navy

Distribution:

Electronic only, via Department of the Navy Issuance website https://www.secnav.navy.mil/doni/.

https://www.secnav.navy.mil/doni/

Enclosure (1)

REFERENCES

(a) DoD Instruction 5200.01 of 21 April 2016

(b) E.O. 13526

(c) 32 CFR 2001

(d) E.O. 13556

(e) 32 CFR 2002

(f) DoDM 5200.01 volumes 1-4, DoD Information Security Program of 24 February 2012

(g) PDUSD memo, DoD Security Lexicon of 13 June 2013

(h) DoD Directive 5205.07 of 1 July 2010

(i) DoD Instruction 5205.11 of 6 February 2013

(j) SECNAVINST S5460.3H

(k) SECNAVINST 5460.4

(l) SECNAVINST 5430.7R

(m) DoD Directive 5200.43 of 1 October 2012

(n) DoDM 5105.21 volumes 1-3, Sensitive Compartmented Information (SCI) Administrative Security Manual of 19 October 2012

(o) DoD Instruction 5220.22 of 18 March 2011

(p) DoD Directive 5230.09 of 22 August 2008

(q) DoD Instruction 5400.04 of 17 March 2009

(r) DoD Instruction 5230.29 of 13 August 2014

(s) DoD Directive 5122.05 of 7 August 2017

(t) Deputy Secretary of Defense memo, Unauthorized Disclosures of Classified Information or Controlled Unclassified Information on DoD Information Systems of 14 August 2014

(u) SECNAVINST 5500.36

(v) SECNAV memo, Delegation of Declassification Authority for the Department of the Navy Declassification Program of 20 September 2018

(w) Department of the Navy Declassification Guide of 3 December 2018

(x) SECNAVINST 5430.107

(y) DoD Instruction 8500.01 of 14 March 2014

(z) SECNAVINST 5239.3C

(aa) EKMS-1E, Electronic Key Management System (EKMS) Policy and Procedures for Navy Tiers 2 & 3 of 7 June 2017

(ab) SECNAVINST 2201.1

(ac) SECNAVINST 5211.5E

(ad) ICD 704 of 1 October 2008

(ae) JAGINST 5800.7F

2 Enclosure (1)

(af) SECNAV memo, Delegation of Authority to Grant Waivers and Exceptions to Department of the Navy Information Security Program Policies and Procedures of 15 November 2016

(ag) SECNAV memo, Department of the Navy Security Executive of 25 April 2013

(ah) DoDM 5200.45, Instructions for Developing Security Classification Guides of 2 April 2013

(ai) SECNAVINST 5000.34F

(aj) SECNAV WASHINGTON DC 051800Z Jan 16 (ALNAV 001/16)

(ak) SECNAV M-5214.1

Enclosure (2)

RESPONSIBILITIES

1. SECNAV

a. Approves all DON TS OCA. This authority is not delegable;

b. Approves the removal of TS classified information for work at home, in the absence of the SAO.

2. DUSN. The DUSN, under the authority, direction, and control of the SECNAV:

a. Serves as the DON SAO for both classified and CUI and executes the duties identified in volumes 1 and 4 of reference (f), “Senior Agency Officials;”

b. Reviews and approves/denies waivers and exceptions to this instruction and any of its implementing directives. When necessary, forward the waiver/exception to the Director of Security, Office of the Deputy Under Secretary of Defense, Intelligence and Security (DUSD (I&S));

c. Approves all DON secret OCAs. This authority is not delegable. Submits TS OCA requests to SECNAV;

d. Reviews and approves/denies all classified conferences not held in a cleared government or contractor facility (e.g., hotel, university, etc.). This authority is not delegable;

e. Serves as an impartial official for reviewing formal challenges to classification of DON information. May convene an impartial panel of OCAs to assist with the review;

f. Convenes an impartial panel of OCAs to address any appeals to formal classification challenges of DON information.

Different OCAs will be selected if a panel was initially used;

g. Refers formal challenges involving Restricted Data information to the Department of Energy and Formerly Restricted Data to the Deputy Assistant Secretary of Defense, Nuclear Matters;

2 Enclosure (2)

h. Submits waivers involving marking of classified information to the DUSD (I&S) for submission to the Director, ISOO;

i. Approves removal of TS classified information for work at home;

j. Should consider whether the workforce needs to be reminded of actions to be or not to be taken by DON personnel in response to widely known public disclosures;

k. Maintains a world-wide available government-only private unclassified but secure web presence that provides information related to the DON Security Programs;

l. Designates a CUI program manager to help oversee the DON’s entire CUI planning and implementation program, including necessary training.

3. Senior Director for Security and Intelligence. The Senior Director for Security and Intelligence, DUSN Security and Intelligence (S&I) Directorate is responsible for the development of policy and an integrated strategic framework for the management, integration, oversight, and assessment of the DON Security Enterprise and provides staff support for the DUSN functions and responsibilities described in reference (u)

a. Develops guidance as necessary for implementation of the

DON ISP;

b. Provides oversight to the DON ISP to assess the effectiveness and efficiency of the DON’s ability to create, protect, and destroy classified and CUI;

c. Ensures prompt and appropriate response to any request, appeal, challenge, complaint, or suggestion arising out of implementation of this instruction or any of its implementing directives;

d. Receives information, allegations, or complaints regarding over-classification or incorrect classification within the DON and, as needed, provide guidance to personnel on proper classification;

3 Enclosure (2)

e. Processes ACCM requests to establish or terminate to the senior agency office for approval. Forwards the written notification within 30 days to the Director of Security, Office of the Under Secretary of Defense for Intelligence (OUSD (I)) or the Director, International Security Programs, Defense Technology Security Administration, Office of the Under Secretary of Defense for Policy (OUSD (P)), as appropriate;

f. Processes annual reports to the SAO and ensures copies are furnished to OUSD (I) and ISOO, as required;

g. Validates OCAs, annually;

h. Coordinates and cooperates with other protection program equities to achieve a harmonized and cohesive ISP within the

DON;

i. Processes OCA requests to the SECNAV or SAO, as required;

j. Manages the security directorate web presence ensuring timely accurate information is made available to DON activities;

k. Provides policy and technical support to the Services;

l. Serves as the focal point for Defense Technical Information Center (DTIC) on all DON Security Classification Guide (SCG) inquiries;

m. Serves as the program management office to help oversee the DON’s entire CNSI and CUI planning and implementation programs, including necessary training.

4. Department of the Navy/Administrative Assistant (DON/AA).

Per the authorities granted in reference (v), DON/AA is responsible for the implementation and oversight of DON automatic, systematic, and mandatory declassification reviews, including the update and issuance of reference (w). The DON/AA Directives and Records Management Division (DRMD) is the program office that executes DON/AA responsibilities pursuant to this directive as follows:

a. Provides adequate funding and resources to implement the declassification program;

4 Enclosure (2)

b. Consults with the SAO to determine the declassification action to be taken when a function was dispersed to more than one activity, the inheriting activity(ies) cannot be determined, or the functions have ceased to exist;

c. Develops and issues declassification guidance to facilitate effective review and declassification of information classified under both current and previous CNSI Executive Orders.;

d. Manages the systematic and automatic declassification program in accordance with volume 1 of reference (f);

e. Develops processes for responding to Mandatory Declassification Reviews. Refer to volume 1, “Mandatory Declassification Review” of reference (f) for additional guidance;

f. Is not authorized to declassify cryptological, Restricted Data, Formerly Restricted Data, Naval Nuclear Propulsion Information, SCI, SAP information originated by another department or agency, or Foreign Government Information (FGI) without the prior consent of the originating entity.

Refer these documents to the appropriate agency or foreign government for further declassification consideration.

5. Director, Naval Criminal Investigative Service (DIRNCIS).

The DIRNCIS is the senior official for criminal investigations and counterintelligence (CI) within the DON. DIRNCIS is the senior official within the DON for terrorism investigations and related operations designed to identify, detect, neutralize, or prevent terrorist planning and activities, and provides antiterrorism expertise and services to DON activities. NCIS initiates, conducts, and directs criminal, CI, terrorism, and related investigations and operations as deemed appropriate, and conducts the full range of CI activities. Additionally, the DIRNCIS is the sole liaison with the Federal Bureau of Investigation on DON security matters, per reference (x).

6. Chief of Information (CHINFO). The CHINFO is the SECNAV’s direct representative for public affairs. CHINFO is delegated the responsibility for coordinating, planning, implementing, and assessing public affair policies and programs of the DON.

5 Enclosure (2)

7. Director, Navy International Programs Office (NIPO). The Director, NIPO is responsible to the Assistant Secretary of the Navy (Research, Development and Acquisition) (ASN (RD&A)) for:

a. Implementing policies and managing DON participation in international efforts (e.g., Foreign Military Sales and International Agreements) concerning ASN (RD&A).

b. NIPO is responsible for reference (u).

c. Making technology security and foreign disclosure determinations for disclosure of classified and CUI to foreign governments and organizations in compliance with DON and national disclosure policy.

d. Managing personnel exchange programs with foreign governments.

8. DON CIO. The DON CIO is responsible for DON policies and implementation of the DoD cybersecurity program to include the protection of classified information and CUI on DON Information Technology (IT) systems under reference (y). The DON CIO issues reference (z), develops DON-wide Information Management (IM)/IT/Information Risk Management policy, standards, and guidance, and aligns and integrates IM/IT programs across the USN and USMC. The DON CIO is also responsible for policy and oversight of Communication Security (COMSEC), per references

(aa) and (ab), and is the DON’s senior military component official for privacy and civil liberties, per reference (ac).

9. CNO and CMC. The CNO and CMC:

a. Approves removal of secret and confidential classified information for work at home for their respective services.

This may be delegated to the heads of Echelon I and II commands.

No further delegation is authorized;

b. Submits waivers and exceptions to this instruction and any of its implementing directives to the SAO;

c. Submits TS and secret OCA requests to the SAO;

d. Establishes procedures to accommodate visits to their service facilities involving access to, or disclosure of, 6 Enclosure (2) classified information and CUI. Refer to volume 3, “Visits” of reference (f) for additional guidance;

e. Submits requests to the SAO for classified meetings and conferences, or classified sessions thereof, that are held at a location other than a cleared U.S. government facility or a U.S.

contractor facility that has an appropriate facility security clearance, and as required, secure storage capability to the SAO for approval;

f. Submits Service endorsements on requests to use ACCM for classified information over which they have cognizance to the

SAO;

g. Reports confirmed security incidents to the SAO when incidents have or may have significant consequences or the fact of the incident may become public;

h. Manages the Service’s SCG Program, to include issuance of SCG Identification (ID) numbers for all new or revised SCGs in accordance with enclosure (4);

i. Coordinates with the DTIC for SCG retrieval;

j. Encourages classification challenges and establishes procedures for processing formal challenges to DON classified information received from within and from outside their Services in accordance with enclosure (4) of volume 1 of reference (f).

10. Commander, U.S. Fleet Cyber Command (FCC). The Commander, FCC as the USN’s Service Cryptologic Component commander to the National Security Agency/Central Security Service, is responsible for the security program for all Cryptologic field sites as well as Cryptologic and IT personnel, regardless of assignment, per reference (ad).

11. Commander, Naval Communications Security Material System (NCMS). The Commander, NCMS administers the DON COMSEC program as the service authority and serves as the central office of records for all NCMS accounts and COMSEC material throughout the DON, U.S. Coast Guard, and national COMSEC community as required per reference (y).

7 Enclosure (2)

12. Heads of DON Activities. The heads of DON activities are responsible for overall management, functioning, and effectiveness of the activity’s ISP. Authority delegated by this instruction to the head of an activity may be further delegated unless specifically prohibited in reference (g).

a. Execute the duties and responsibilities in volume 1, “Heads of DoD Activities” of reference (f).

b. Submit waivers and exceptions to this instruction and any of its implementing directives through the chain-of-command to the CNO and CMC, for approval. Refer to volume 3, “Waivers and Exceptions” of reference (f) for additional guidance.

c. Determine if TS Control Officers (TSCO) are required to facilitate appropriate control of collateral TS material where there is a need (e.g., accountability of Sigma material).

Collateral TS material entering SCI Facilities (SCIF) and SAP Facilities (SAPF) will be processed in accordance with SCI and SAP directives.

d. Determine if other security management roles are necessary for management of the activity ISP in accordance with volume 1, “Other Security Management Roles” of reference (f).

e. Ensure contractors used in security administration are prohibited from performing certain critical, closely associated roles which are inherently governmental, or otherwise exempt functions and activities that cannot or should not be performed by a contractor in accordance with volume 1, “Use of Contractors in Security Administration” of reference (f).

f. Prohibit the use of foreign nationals in security administration in accordance with volume 1, “Use of Foreign Nationals in Security Administration” of reference (f).

g. Ensure all assigned personnel have a valid and appropriate security clearance, have executed an appropriate non-disclosure agreement, and have a valid need-to-know before allowing access to classified information.

h. Ensure all persons with access to classified information systems (e.g., Secret Internet Protocol Router Network (SIPRNet), collateral TS networks, etc.) receive the NATO

8 Enclosure (2) briefing and responsibilities for safeguarding NATO classified information, and acknowledge receipt of the brief in writing:

(1) Mass briefing sign-in rosters are not sufficient and may not serve as written acknowledgement of the brief.

(2) For Joint Worldwide Intelligence Communications System (JWICS) access requirements, consult the activity’s Special Security Officer (SSO), and follow DNI policy requirements.

i. Ensure classified information and CUI are protected in accordance with this instruction, volumes 1 through 4 of reference (f), and any of its implementing policies.

j. Ensure prompt and appropriate management action is taken in cases of compromise, UD, or loss of classified information or CUI. Report any violation of this instruction, or one of its implementing directives, that results in negligence or willful disclosures of classified information or CUI, as determined by a security inquiry (Preliminary Inquiry (PI)) or investigation (command investigation) in the Joint Personnel Adjudication System (JPAS), or its successor system. Refer to volume 1, “Corrective Actions and Sanctions” of reference (f) and sections 0203 and 0209 of reference (ae) for more information.

k. Submit request for OCA in accordance with enclosure (4) of this instruction, through established organizational channels to the SAO.

l. Not take retribution against any individual for questioning a classification or making an informal or formal challenge to a classification.

m. Submit requests for waivers involving marking of classified information through the chain-of-command to the SAO.

Refer to volume 2, “Waivers Involving Marking of Classified Information” of reference (f).

n. Establish a system of security checks at the close of each duty and/or business day where classified information is used is stored securely. Refer to volume 3, “End of Day Security Checks” of reference (f) for documenting the checks.

Automated means may be used in place of SF 701, “Activity

9 Enclosure (2)

Security Checklist” and SF 702, “Security Container Checksheet” (e.g., alarm logs, swipe access logs, etc.).

o. Develop emergency plans to protect, remove, or destroy classified material in case of fire, natural disaster, civil disturbance, terrorist activities, or enemy action to minimize the risk of compromise, and for the recovery of classified information. Refer to volume 3, “Emergency Plans” of reference

(f) for additional details. An “Emergency Plan Template” located at the DUSN Security Directorate Microsoft SharePoint Portal may be used.

p. Approve all equipment used to reproduce classified information in writing, and post the approval notice in a conspicuous place where all users can see. In addition, ensure the use of equipment for such reproduction, including controls comply with the standards in volume 3, “Reproduction of Classified Material” of reference (f).

q. Develop activity security procedures to appropriately safeguard information that may retain all or part of information contained in copiers, facsimile machines, computers, and other IT equipment and peripherals, display systems, and electronic typewriters. Refer to volume 3, “Equipment Used for Processing Classified Information” of reference (f).

r. Approve classified meetings or conferences, or classified sessions thereof, that take place in an appropriately cleared U.S. government facility or U.S. contractor facility that has an appropriate facility security clearance and, as required, secure storage capability. Ensure the approval includes the appointment of an activity security manager and the additional requirements and events are conducted in accordance with volume 3, “Classified Meetings and Conferences” of reference (f).

s. Conduct and evaluate risk assessments to determine whether installation of an intrusion detection system is warranted or whether other supplemental controls are sufficient.

As a minimum, the risk assessment/analysis shall contain the minimum criteria identified in volume 3, “Risk Assessments” of reference (f).

10 Enclosure (2)

t. When special circumstances exist, may authorize the use of key operated locks for storing bulky material containing secret and confidential information. The authorization must be in writing and must explain the special circumstances and administrative procedures for control and accounting of keys and locks, outlined in volume 3, “Bulky Material” of reference (f).

The keys shall be protected at the level of the classified bulky material.

u. Establish procedures to ensure that hand-carrying of classified material is minimized to the greatest extent possible and does not pose unacceptable risk to the information.

Additional guidance is provided in volume 3, “Escort, Courier, or Hand-Carry of Classified Information” of reference (f).

v. Serve as the responsible official by providing a written statement to each individual who is authorized to escort, courier, or hand-carry classified material. Refer to volume 3, “Escort, Courier, or Hand-Carry Authorization” of reference (f) for additional details.

w. Advise their chain-of-command of compromises occurring within their area of security responsibility or involving assigned personnel. If the head of the activity does not have security cognizance over the incident, ensure the incident is reported to the appropriate authority to include forwarding to DUSN (S&I) Directorate, if necessary.

x. Notify appropriate authorities when a security incident reveals information suggestive of a criminal or CI nature is discovered and cease all actions pending coordination with appropriate authorities as outlined in volume 3, “Security Inquiries and Investigations” of reference (f).

y. Immediately notify the OCA if a PI or command investigation determines a loss or compromise has occurred. In addition, notify the SAO through the chain-of-command.

z. Appoint an individual to lead PIs into security incidents to determine the facts and circumstances of the incident in writing. Ensure the appointed individual characterizes the incident as an infraction or a violation. Do not appoint the activity security manager as a PI official.

Ensure the official appointed is not involved in the incident.

11 Enclosure (2)

A “Preliminary Inquiry Convening Order Template” is available at the DUSN Security Directorate Microsoft SharePoint Portal.

aa. Appoint investigating officials in writing, to conduct a command investigation into classified security incidents when the circumstances of an incident require a more detailed inquiry, additional information is needed, or where the head of the activity is contemplating punitive actions. Refer to volume 3, “Security Inquiries and Investigations” of reference (f) for additional guidance and restrictions on appointing a command investigation official.

ab. Take prompt action to resolve deficiencies identified in security incident reports by PI and command investigation officials. Refer to volume 3, “Results of Inquiries and Investigations” of reference (f) for additional details.

ac. Determine if a debriefing is warranted following unauthorized access to classified information. Refer to volume 3, “Debriefing in case of Unauthorized Access” of reference (f) for general guidelines.

ad. Ensure ACCM information, documents, and material are properly:

(1) Safeguarded in accordance with the OCA instructions and volume 3, “Alternative Compensatory Control Measures (ACCM)” of reference (f).

(2) Marked in accordance with volume 2, “Other Dissemination Control Markings: Alternative Compensatory Control Measures (ACCM)” of reference (f).

ae. At a minimum, designate one day per calendar year as a “clean out” day to reduce the amount of the classified and CUI on hand.

13. DON Activity Security Managers. DON Activity Security Managers shall execute the duties in enclosures (2), “Activity Security Manager,” and (3), “Activity Security Management” of volume 1 of reference (f) and shall:

a. Ensure all assigned personnel have a valid and appropriate security clearance, have executed an appropriate

12 Enclosure (2) non-disclosure agreement, and have a valid need-to-know before allowing access to classified information. Refer to volume 1, “Access to Classified Information” of reference (f) for more information.

b. Ensure all persons with access to classified information systems (e.g., SIPRNet, collateral TS networks, etc.) receive the NATO briefing and responsibilities for safeguarding NATO classified information, and acknowledge receipt of the brief in writing:

(1) Mass briefing sign-in rosters are not sufficient and may not serve as written acknowledgement of the brief.

(2) For JWICS access requirements, consult the activity’s SSO and follow DNI policy requirements.

c. Ensure classified information and CUI is protected in accordance with this instruction, volumes 1 through 4 of reference (f), and any of its implementing policies.

d. Ensure prompt and appropriate management action is taken in cases of compromise, UD, or loss of classified information or CUI. Report any violation of this instruction, or one of its implementing directives, that results in negligence or willful disclosures of classified information or CUI, as determined by a PI or command investigation in JPAS, or its successor system.

Refer to volume 1, “Corrective Actions and Sanctions” of reference (f) and sections 0203 and 0209 of reference (ae) for more information.

e. Ensure all OCAs receive training and certify in writing they have received training, before exercising their authority and annually thereafter on the fundamentals of proper security classification and declassification. Emphasis should be made on over-classification, duration of classification, and compilation of information in electronic formats (e.g., databases, spreadsheets) that lead to new aggregations making the information vulnerable to data mining and other data correlations. OCAs shall receive training that covers:

(1) The limitations of their authority;

(2) The sanctions that may be imposed;

13 Enclosure (2)

(3) OCA duties and responsibilities, as required by volume 3, “OCA Training” of reference (f).

f. Maintain all OCA delegation letters or SECNAV list of OCAs for any positions within their organization, and OCA training certifications. Provide this information when requested by appropriate authorities (e.g., SAO, USD (I), ISOO, etc.).

g. Review all OCA SCGs to ensure they are properly marked and formatted prior to requesting an SCG number from the Service’s DON SCG Program Manager.

h. Assist all DON personnel with submitting tentative classification information to an OCA, when requested.

i. Ensure all organization personnel, prior to accessing a classified Information System (IS), receive derivative classification training as specified in volume 1, “Derivative Classification, Responsibilities of Derivative Classifiers, and Procedures for Derivative Classification” and volume 3, “Initial Orientation” of reference (f) and annually thereafter.

j. Assist personnel (i.e., military, civilian, and contractor) with making informal and formal classification challenges when they believe information is improperly or unnecessarily classified and communicate that belief to the OCA or activity security manager assigned to the OCA.

(1) Prior to submitting the challenge, attempt to validate if the information is properly classified according to SCG or other document transmitting classification guidance.

(2) Encourage personnel to submit an informal challenge before resorting to formal challenge.

(3) Process informal and formal challenges in accordance with volume 1, “Challenges to Classification” of reference (f) through the chain-of-command to the OCA.

(4) In addition to the OCA and/or OCA’s activity security manager, submit copies of all formal challenges to the SAO through the appropriate chain-of-command.

14 Enclosure (2)

(5) Do not take retribution against any individual for questioning a classification or making of an informal or formal challenge to a classification.

k. Direct personnel outside the DON to enclosure (4) of this instruction and the Service-specific requirements.

l. Sample derivatively classified documents generated by the organization to ensure the documents/materials are marked in accordance with volume 2, “Marking Principles” of reference (f).

Figures 1 through 58 of volume 2 are examples of marking most types of derivate classified documents and material. Figure 4 of volume 2 is an example of a derivatively classified document.

m. Sample classified files, folders, and similar groups of documents, and IT systems to ensure they are marked in accordance with volume 2, “Coversheets and Classification Labels” of reference (f).

n. Sample records to validate end of day security checks are conducted and properly documented for the activity.

o. Conduct risk assessments, as needed, to facilitate security–in-depth determinations and to aid in identification and selection of supplemental controls that may need to be implemented. Refer volume 3, “Risk Assessment” of reference (f) for a list of the minimum criteria used in risk assessments.

p. Complete management and oversight training on topics identified in volume 3, “Management and Oversight Training” of reference (f). This may be accomplished by completion of the Navy Security Manager’s Course, online and/or in-residence DoD security specialist or information security management courses, or completion and maintenance of the security fundamentals professional certification under the DoD Security, Professional, Education, and Development Program.

q. Advise their chain-of-command of compromises occurring within their area of security responsibility or involving assigned personnel. If the activity security manager does not have security cognizance over the incident, ensure the incident is reported to the appropriate authority to include up channeling to DUSN Security Directorate, if necessary.

15 Enclosure (2)

r. Ensure certain types of classified information or specific circumstances are addressed using unique handling or consideration of additional reporting, as defined in volume 3, “Special Circumstances” of reference (f).

s. Notify the head of the activity when a security incident reveals information suggestive of a criminal or CI nature is discovered and cease all actions pending coordination with appropriate authorities as outlined in volume 3, “Security Inquiries and Investigations” of reference (f).

t. Immediately notify the head of the activity if a PI official or command investigating official determines the security incident has resulted in a loss or compromise. If directed by the head of the activity, notify the OCA, and through the chain-of-command, notify the SAO.

u. When authorized, appoint an individual to lead inquiries into security incidents to determine the facts and circumstances of the incident and to characterize the incident as an infraction or a violation. Ensure the official appointed is not involved in the incident.

v. Consult with the head of the activity and take prompt action to resolve identified deficiencies identified by PI and command investigation officials’ security incident reports.

Refer to volume 3, “Results of Inquiries and Investigations” of reference (f) for additional details.

w. Address IT issues in accordance with volume 3, “IT Issues for the Security Manager” of reference (f).

14. TSCO. When designated, a TSCO shall execute the duties in volume 1, TSCO, enclosure (2) and TSCO, enclosure (3), of reference (f).

15. The HICE, Deputy CNO for Information Warfare/DNI (N2/N6) and DIRINT shall execute the duties identified in volume 1, “Senior Intelligence Officials” of reference (f), and references

(n) and (ad) for their respective service.

16. The Director, DON SAPCO shall execute responsibilities for SAP, per references (h) through (l).

16 Enclosure (2)

17. IS Security Officials (ISSO) (e.g., authorizing official, IS Security Manager, and IS Security Officer). When designated, an ISSO shall execute the duties in volume 1, “Information Systems Security Officials” of reference (f). In addition:

a. Work closely with activity security managers at all levels, security specialists, and DUSN Security Directorate to ensure classified information and CUI are properly protected when data and/or information resides on IT and IS, and networks managed and controlled by the DON CIO.

b. If not already done, notify the activity security management when data spills occur and assist the security manager as required. Security personnel have the overall lead for addressing such events, while IT and/or cybersecurity staff have overall responsibility for the operation of the networks and systems.

18. Military Commanders of Military Operations. Military commanders are authorized to modify the provisions of this instruction and any of its implementing guidance pertaining to accountability, dissemination, transmission, and storage of classified and controlled unclassified material and information as necessary to meet local conditions encountered during military operations. Refer to volume 1 of reference (f) for a definition of Military Operations.

19. All DON personnel (i.e., military or civilian) who hold command, management, or supervisory positions shall:

a. Have specific, non-delegable responsibility for the quality and effectiveness of implementation and management of the DON ISP within their areas of responsibility.

b. Ensure classified information and CUI are protected at all times by following the guidance in this instruction and volumes 1 through 3 of reference (f) for the protection of classified information and volume 4 of reference (f) for the protection of CUI.

c. Submit Waivers and Exceptions to this instruction and any of its implementing directives through their service chain-of-command to the SAO. Refer to reference (af), and volume 3, 17 Enclosure (2)

“Waivers and Exceptions” of reference (f) for additional guidance.

d. Ensure contractors used in security administration are prohibited from performing certain critical, closely associated roles with inherently governmental, or otherwise exempt functions and activities that cannot or should not be performed by a contractor in accordance with volume 1, “Use of Contractors in Security Administration” of reference (f).

e. Prohibit the use of foreign nationals in security administration in accordance with volume 1, “Use of Foreign Nationals in Security Administration” of reference (f).

f. Ensure all assigned personnel have a valid and appropriate security clearance, have executed an appropriate non-disclosure agreement, and have a valid need-to-know before allowing access to classified information. Refer to volume 1, “Access to Classified Information” of reference (f) for more information.

g. Ensure all persons with access to classified information systems (e.g., SIPRNet, collateral TS networks, etc.) receive the NATO briefing and responsibilities for safeguarding NATO classified information, and acknowledge receipt of the brief in writing:

(1) Mass briefing sign-in rosters are not sufficient and may not serve as written acknowledgement of the brief.

(2) For JWICS access requirements, consult the activity’s SSO and follow DNI policy requirements.

h. Ensure classified information and CUI are protected in accordance with this instruction, volumes 1 through 4 of reference (f), and any of its implementing policies.

i. Ensure prompt and appropriate management action is taken in cases of compromise, UD, or loss of classified information or CUI. Report any violation of this instruction, or one of its implementing directives, that results in negligence or willful disclosures of classified information or CUI, as determined by a PI, management inquiry (for CUI), or investigation in JPAS, or its successor system. Refer to volume 1, “Corrective Actions

18 Enclosure (2) and Sanctions” and section 1k of enclosure (3) of volume 4 of reference (f), and paragraph 10 of reference (t) for more information.

j. Ensure their personnel, prior to accessing a classified information system, receive derivative classification training as specified in volume 1, “Derivative Classification, Responsibilities of Derivative Classifiers, and Procedures for Derivative Classification” and volume 3, “Initial Orientation” of reference (f) and annually thereafter. For additional information on this training contact a supervisor, manager, commander, or activity security manager.

k. Not take retribution against any individual for questioning a classification or making an informal or formal challenge to a classification.

l. Ensure personnel under their authority mark derivatively classified documents with banner lines, portion markings, and classification authority block in accordance with volume 2, “Marking Principles” of reference (f). Figures 1 through 58 of reference (f) are examples of marking most types of derivate classified documents and material. Figure 4 of reference (f) is an example of a derivatively classified document.

m. Ensure personnel properly mark classified files, folders, and similar groups of documents, and IT systems in accordance with volume 2, “Coversheets and Classification Labels” of reference (f).

n. Ensure personnel properly create, mark, protect, and destroy working papers in accordance with volume 3, “Working Papers” of reference (f). Figure 11 of volume 2, “Marking Principles” of reference (f), is an example of marking a working paper.

o. Ensure personnel under their authority completely destroy classified documents and material identified for destruction to prevent anyone from reconstructing the classified information using only the method and equipment identified in volume 3, “Destruction of Classified Information and Destruction Procedures” of reference (f).

19 Enclosure (2)

p. Ensure personnel are familiar with and follow the transmission and transportation procedures in “Transmission and Transportation” of volume 3 of reference (f). Use of the current holder of the GSA contract for overnight delivery is authorized.

q. Train their personnel on reporting and notification procedures in the event anyone finds classified information out of proper control in accordance with the procedures identified in “Reporting and Notifications” of volume 3 of reference (f).

r. Train their personnel on proper notification procedures when they discover classified information in the public media in accordance with volume 3, “Information Appearing in the Public Media” of reference (f).

s. Train personnel assigned to a program employing ACCM on the procedures for safeguarding and marking ACCM material in accordance with the OCA’s guidelines and volume 3, “Alternative Compensatory Control Measures (ACCM)” and volume 2, “Other Dissemination Control Marking: Alternative Compensatory Control Measures (ACCM)” of reference (f).

t. Enforce prohibition of personally owned electronic devices (unmanaged government devices) in open storage rooms (secure rooms), SCIF, SAPF, classified meetings, conferences, or other forums where classified information is to be discussed or processed. Finally, heads of activities should consider whether to restrict personally owned electronic devices in meetings, conferences, or other forums where CUI is to be discussed or processed.

20. All DON Personnel (i.e., military, civilian, and contractor) shall:

a. Be personally and individually responsible for properly protecting classified information and CUI under their custody and control.

b. Have a valid and appropriate security clearance, have executed an appropriate non-disclosure agreement, and have a valid need-to-know before allowing access to classified information. Refer to volume 1, “Access to Classified Information” of reference (f) for more information.

20 Enclosure (2)

c. When authorized access to classified information systems (e.g., SIPRNet, collateral TS networks, etc.), acknowledge in writing that they have received the NATO briefing and responsibilities for safeguarding NATO classified information.

(1) Mass briefing sign-in rosters are not sufficient and may not serve as written acknowledgement of the brief.

(2) For JWICS access requirements, consult the activity’s SSO and follow DNI policy requirements.

d. Ensure classified information and CUI are protected in accordance with this instruction, volumes 1 through 4 of reference (f), and any of its implementing policies.

e. Report all security incidents to their supervisor, management, commander, or activity security manager.

f. May submit tentative classified information to an OCA for original classification decisions by submitting the required information in volume 1, “Original Classification Process” of reference (f). Contact the activity security manager for additional assistance. Safeguard the information at the specified level of classification and do not use as a source document for derivative classification.

g. Prior to accessing a classified information system receive derivative classification training as specified in volume 1, “Derivative Classification, Responsibilities of Derivative Classifiers, and Procedures for Derivative Classification” and volume 3, “Initial Orientation” of reference

(f) and annually thereafter. For additional information on this training contact a supervisor, manager, head of the activity, or activity security manager.

h. Make informal and formal classification challenges when they believe information is improperly or unnecessarily classified and communicate that belief to their supervisor and activity security manager; protect the information at its current classification level or the recommended change level, whichever is higher until a decision is made and process informal and formal challenges in accordance with volume 1, “Challenges to Classification” of reference (f) through the chain of command to the OCA.

21 Enclosure (2)

i. Mark derivatively classified documents with banner lines, portion markings, and classification authority block in accordance with volume 2, “Marking Principles” of reference (f).

Figures 1 through 58 of reference (f) are examples of marking most types of derivatively classified documents and material.

Figure 4 of reference (f) is an example of a derivatively classified document.

j. Properly mark classified files, folders, and similar groups of documents, and IT systems in accordance with volume 2, “Coversheets and Classification Labels” of reference (f).

k. Be personally responsible for taking proper precautions to ensure that unauthorized persons do not gain access to classified information and for protecting the classified information they know, possess, or control, and comply with the pre-publication security review…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .