About this file

This eLibrary documentation represents the request for proposal for the NASA Sounding Rocket Operations Contract (NSROC) IV solicitation. The RFP seeks proposals for operation and integration services to support NASA's suborbital research rocket program. Offerors must provide end-to-end mission operations including payload integration, launch services, data acquisition, and post-flight analysis. The period of performance is a five-year base period starting in 2022, with three optional one-year extensions. Proposals are due by August 2021, with award expected in early 2022. The total contract value including options is estimated at $150 million. The solicitation is unrestricted and available on the Federal Business Opportunities website.

View the file

Other files for this federal contract opportunity

Other files attached to NASA Sounding Rocket Operations Contract (NSROC) IV - FINAL Request for Proposal, eLibrary, newest first.
File Type Posted
SRPO Cryogenic Safety Users Guide Revision A Final.pdf PDF
NSROC III NNG16WA70C Attachment M - Contract Historical Data 19-20.pdf PDF
SRPO Technology Roadmap June 2021.pdf PDF
NSROC III List of Ongoing Work - October 2021.pdf PDF
SRPO Annual Report 2016.pdf PDF
Rocket_Report_4th_quarter_2019.pdf PDF
SR User Handbook Final_July 2015.pdf PDF
SRPO Annual Report 2019.pdf PDF
Doing Business with Wallops.pdf PDF
Sounding Rockets_NASA_fact_sheet.pdf PDF
NASA-STD-8719.12A Safety Standard for Explosives, Propellants, and Pyrotechnics.pdf PDF
803-GS-ESP-ES-F10-01 F-10 Explosive Site Plan.pdf PDF
803-PG-8730 1 WFF Met and Cal Lab Quality Manual.pdf PDF
GPR 8710.2.pdf PDF
NPR 8715.3.pdf PDF
NPR 4200.2.pdf PDF
GPD 7150.0.pdf PDF
GPR 1840.1.pdf PDF
GPR 8715.8.pdf PDF
GPR 8715.1.pdf PDF
GPR 8710.7.pdf PDF
GPR 7120.11.pdf PDF
200-PG-8812.1.1 Wallops Facilities Review Committee.pdf PDF
800-PG-8715.5.1A Range Safety Process for Programs and Projects.pdf PDF
GPR 8500.1.pdf PDF
NPR 1040.1 Updated.pdf PDF
NPD 8730.5.pdf PDF
GPR 1820.2.pdf PDF
GPR 1840.2.pdf PDF
GPR 1600.2.pdf PDF
GPR 8800.1.pdf PDF
GPR 8715.12.pdf PDF
GPR 4100.2.pdf PDF
NPD 8700.1 Updated.pdf PDF
800-PG-8715.0.4C_Certification Procedures for OSS at WFF.pdf PDF
NPD 2800.1.pdf PDF
NPR 6000.1.pdf PDF
NPD 2025.1.pdf PDF
800-PG-8710.0.2D Operations in Cold Weather Environments.pdf PDF
GPD 1800.0.pdf PDF
800-PG-7120.4.1 Risk Mgmt.pdf PDF
NPR 5200.1.pdf PDF
NSROC CBA IAMAW 11.01.21 final FULLY EXECUTED.pdf PDF
Rocket_Report_1st_quarter_2019.pdf PDF
Rocket Report 2nd quarter 2021.pdf PDF
Rocket_Report_3rd_quarter_2019.pdf PDF
Rocket Report 4th quarter 2020.pdf PDF
Rocket Report 1st quarter 2021.pdf PDF
SRPO Annual Report 2017.pdf PDF
Rocket Report 1st quarter 2020.pdf PDF
Show all 50

NASA Sounding Rocket Operations Contract (NSROC) IV - FINAL Request for Proposal, eLibrary has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

| NODIS Library | Organization and Administration(1000s) | Search |

NASA

Procedural Requirements

NPR 1600.2A

Effective Date: September 11, Expiration Date: September 11, COMPLIANCE IS MANDATORY FOR NASA EMPLOYEES

NASA Classified National Security Information (CNSI)

Responsible Office: Office of Protective Services

Table of Contents Preface P.1 Purpose P.2 Applicability P.3 Authority P.4 Applicable Documents and Forms P.5 Measurement/Verification P.6 Cancellation

Chapter 1. Introduction

1.1 Overview

1.2 Responsibilities

Chapter 2. CNSI Management

2.1 General

2.2 Original Classification

2.3 Classification Levels

2.4 NASA Original Classification Authority

2.5 Classification Categories

2.6 Application of Original Classification Authority

2.7 Derivative Classification

2.8 Application of Derivative Classification Authority

2.9 Identification, Designation and Markings

2.10 Working Papers

2.11 Classification Prohibitions and Limitations

2.12 Classification Challenges

NPR 1600.2A -- TOC

This document does not bind the public, except as authorized by law or as incorporated into a contract. This document is uncontrolled when printed. Check the NASA Online Directives Information System (NODIS) Library to verify that this is the correct version before use: https://nodis3.gsfc.nasa.gov.

NPR 1600.2A -- TOC Page 1 of 85 https://nodis3.gsfc.nasa.gov/main_lib.html https://nodis3.gsfc.nasa.gov/lib_docs.cfm?range=1___ https://nodis3.gsfc.nasa.gov/adv_search.cfm https://nodis3.gsfc.nasa.gov/

2.12 Classification Challenges

2.13 Declassification Authority

2.14 Declassification

2.15 Access to CNSI

2.16 Accountability and Control of CNSI

2.17 Accountability Logs

2.18 Handling of Incoming Classified Material

2.19 Record of Destruction

2.20 Inventory Requirements

2.21 Top Secret Inventory

2.22 Guidelines for Electronic Classified Information Processing

2.23 Storage of CNSI - Security Containers and Vaults

2.24 Forms

2.25 Storage of NATO Classified Information and FGI

2.26 Emergency Authority

2.27 Reproduction of CNSI

2.28 Hand-Carrying and Receipting of Classified Material

2.29 Transmission of Classified Material

2.30 Receipt System

2.31 Defense Courier Service Reimbursement Program

2.32 Disposition or Destruction of Classified Material

2.33 Destruction Procedures

2.34 Sanctions

2.35 Security Violations, Security Infractions and Compromise of CNSI

2.36 CNSI Meetings

2.37 Security Areas

2.38 Classified Material Ownership

2.39 Security Classification Reviews for NASA Programs and Projects

2.40 Access to Classified National Security Information Granted by Another Government Agency

2.41 Special Access Program (SAP)

2.42 Information Systems (IS)

2.43 ISOO Reporting Requirements

2.44 Self-Inspections

Chapter 3. Sensitive Compartmented Information Programs

3.1 General

3.2 Information Systems for processing (SCI) information

3.3 Self-Inspections of the SCI Program

3.4 Facility Accreditations

3.5 Contractors performing SCI

3.6 Standard Classification Markings

3.7 Storage

3.8 SCI Accountability

3.9 Media

3.10 Document Control Procedures

3.11 Transportation of SCI

3.12 Electronic Transmissions

NPR 1600.2A -- TOC

This document does not bind the public, except as authorized by law or as incorporated into a contract. This document is uncontrolled when printed. Check the NASA Online Directives Information System (NODIS) Library to verify that this is the correct version before use: https://nodis3.gsfc.nasa.gov.

NPR 1600.2A -- TOC Page 2 of 85

3.13 Emergency Plans

3.14 Request for SCI Access

3.15 Reporting Requirements

3.16 SCIF Construction Procedures

3.17 Co-Use Agreements

3.18 SCI File Transmission Procedures

3.19 SCI Visit Requests

3.20 Training

Chapter 4. Security Education and Training

4.1 General

4.2 Initial Security Education and Training

4.3 Annual Refresher Security Education and Training

4.4 Original Classification Training

4.5 Derivative Classifier Training

4.6 Other Specialized Security Education and Training

4.7 Termination Briefings

Chapter 5. Industrial Security

5.1 General

5.2 DoD Support

5.3 NISP Responsibilities

5.4 Suspension, Revocation, and Denial of Access to Classified Information

5.5 Requirements of DD Form 254

Appendix A. Definitions Appendix B. Acronyms Appendix C. Derivative Classification in Electronic Media Appendix D. References

NPR 1600.2A -- TOC

This document does not bind the public, except as authorized by law or as incorporated into a contract. This document is uncontrolled when printed. Check the NASA Online Directives Information System (NODIS) Library to verify that this is the correct version before use: https://nodis3.gsfc.nasa.gov.

NPR 1600.2A -- TOC Page 3 of 85

Preface P.1 Purpose

a. This NASA Procedural Requirement (NPR) establishes Agency-wide requirements for the protection of Classified National Security Information (CNSI).

b. This NPR prescribes personnel responsibilities and procedural requirements for the management of CNSI to assist NASA Centers and Component Facilities in executing the NASA security program designed to protect people, property, and information.

c. In accordance with, Classified National Security Information, Executive Order (E.O.) 13526, and 32 CFR pt. 2001, this NPR establishes Agency procedures for the proper implementation and management of a uniform system for classifying, safeguarding, and declassifying national security information generated by, for, or in the possession of NASA.

P.2 Applicability

a. This NPR is applicable to NASA Headquarters and all NASA Centers, including Component Facilities, Technical and Service Support Centers. This language applies to the Jet Propulsion Laboratory (JPL) (a Federally Funded Research and Development Center (FFRDC)), other contractors, recipients of grants and cooperative agreements, and parties to other agreements only to the extent specified or referenced in the applicable contracts, grants, or agreements.

b. This NPR is applicable to all NASA civil service employees, NASA contractor employees, personnel completing work through Space Act Agreements or Memorandums of Agreement (MOA) or Memorandums of Understanding (MOU), those assigned or detailed under the partners, recipients of grants and cooperative agreements, visitors, and other binding transactions in which access to Classified National Security Information is required for performance of the work.

c. Chapter 5 is applicable to contracts, grants, cooperative agreements, and other binding transactions in which performance requires access to CNSI by the contractor, supplier, grantee, or its employees. It does not apply to agreements with other Federal agencies.

d. In this directive, all document citations are assumed to be the latest version unless otherwise noted.

e. In this NPR, all mandatory actions (i.e., requirements) are denoted by statements containing the term "shall." The terms: "may" or "can" denote discretionary privilege or permission, "should" denotes a good practice and is recommended, but not required, "will" denotes expected outcome, and "are/is" denotes descriptive materials.

P.3 Authority

a. The National Aeronautics and Space Act, 51 United States Code (U.S.C.), Security Requirements § 20132, Dec 18, 2010.

b. Classified National Security Information, E.O. 13526, 75 Fed. Reg.707 (Jan. 5, 2010).

NPR 1600.2A -- Preface This document does not bind the public, except as authorized by law or as incorporated into a contract. This document is uncontrolled when printed. Check the NASA Online Directives Information System (NODIS) Library to verify that this is the correct version before use: https://nodis3.gsfc.nasa.gov.

NPR 1600.2A -- Preface Page 4 of 85

b. Classified National Security Information, E.O. 13526, 75 Fed. Reg.707 (Jan. 5, 2010).

P.4 Applicable Documents and Forms

a. Freedom of Information Act, 5 U.S.C. § 552

b. Privacy Act of 1974, 5 U.S.C. § 552a.

c. Intergovernmental Personnel Act, as amended, 5 U.S.C. § 3372.

d. Atomic Energy Act of 1954, 42 U.S.C. § 2011 et seq.

e. Records Management by Federal Agencies, 44 U.S.C. §§ 2905, 3101, and 3102.

f. National Security Act of 1947, 50 U.S.C. § 2671 et seq.

g. National Security Act of 1947, 50 U.S.C. § 3001 et seq.

h. National Industrial Security Program, E.O. 12829, 58 Fed. Reg. 3479 (Jan. 6, 1993).

i. Access to Classified Information, as amended, E.O. 12968, 60 Fed. Reg. 40245 (Aug. 7, 1995).

j. Information Security Program, 14 CFR pt. 1203.

k. Export Administration Regulations, 15 CFR pts. 730-774.

l. International Traffic in Arms Regulations, 22 CFR pts. 120-130.

m. Classified National Security Information, 32 CFR pt. 2001.

n. National Industrial Security Program, 32 CFR pt. 2004.

o. Federal Acquisition Regulation (FAR), 48 CFR subpt. 4.4.

p. NASA FAR Supplement (NFS), 48 CFR subpart 1804.4.

q. NASA Policy Directive (NPD) 1210.2, NASA Surveys, Audits, and Review Policy

r. NPD 1600.4, National Security Programs.

s. NPD 1600.9, NASA Insider Threat Program.

t. NPR 1441.1, NASA Records Management Program Requirements.

u. NPR 1600.3, Personnel Security.

v. NPR 1600.4, Identity and Credential Management.

w. NPR 1600.6, Communications Security (COMSEC).

x. NPR 1620.3, Physical Security Requirements for NASA Facilities and Property.

y. NPR 1660.1C, NASA Counterintelligence and Counterterrorism.

z. NPR 4100.1F, NASA Supply Support and Material Management.

aa. NPR 7120.5, NASA Space Flight Program and Project Management Requirements.

NPR 1600.2A -- Preface This document does not bind the public, except as authorized by law or as incorporated into a contract. This document is uncontrolled when printed. Check the NASA Online Directives Information System (NODIS) Library to verify that this is the correct version before use: https://nodis3.gsfc.nasa.gov.

NPR 1600.2A -- Preface Page 5 of 85

bb. NPR 7120.7, NASA Information Technology and Institutional Infrastructure Program and Project Management Requirements.

cc. NPR 7120.8, NASA Research and Technology Program and Project Management Requirements.

dd. Guidelines for Data Spillages, ITS-HBK-2820.09-04.

ee. NASA Handbook for Writing Security Classification Guides.

ff. NASA Form (NF) 387, Classified Material Receipt.

gg. NF 1733, Information and Technology Classification and/or Sensitivity Level Determination Checklist.

hh. NF 1833, Request for SCI Classified Visit.

ii. Committee on National Security Systems (CNSS) Instruction 1253.

jj. Federal Qualified Products List of Products Qualified Under Federal Specification FF-L-2740A Locks, Combination, Federal Specification FF-L-2740.

kk. Intelligence Community Directive (ICD) 503, Intelligence Community Information Technology Systems Security Risk Management, Certification and Accreditation.

ll. Intelligence Community Directive (ICD) 704, Personnel Security Standards and Procedures Governing Eligibility for Access to Sensitive Compartmented Information and Other Controlled Access Program Information.

mm. Intelligence Community Directive (ICD) 705, Sensitive Compartmented Information Facilities.

nn. ISOO Booklet, Marking Classified National Security Information.

oo. National Industrial Security Program Operation Manual (NISPOM) DoD 5220.22-M.

pp. National Institute of Standards and Technology (NIST) Special Publications 800-53 and 800-37.

qq. NSA/Central Security Service Policy 9-12.

rr. Security Executive Agent Directive 3 (SEAD 3).

ss. Special Historical Records Review Plan (Supplement).

tt. U. S. Security Authority for North Atlantic Treaty Organization Affairs (USSAN) Instruction 1-07.

uu. DD Form 254, Department of Defense Contract Security Classification Specification.

vv. SF 311, Agency Security Classification Management Program Data.

ww. SF, 700, Security Container Information.

xx. SF 701, Activity Security Checklist.

yy. SF 702, Security Container Check Sheet.

zz. SF 703, Top Secret Coversheet.

NPR 1600.2A -- Preface This document does not bind the public, except as authorized by law or as incorporated into a contract. This document is uncontrolled when printed. Check the NASA Online Directives Information System (NODIS) Library to verify that this is the correct version before use: https://nodis3.gsfc.nasa.gov.

NPR 1600.2A -- Preface Page 6 of 85 aaa. SF 704, Secret Cover Sheet.

bbb. SF 705, Confidential Cover Sheet.

ccc. SF 706, Top Secret Label.

ddd. SF 707, Secret Label.

eee. SF 708, Confidential Label.

fff. SF 710, Unclassified Label.

ggg. SF 715, Declassification Review Tab.

hhh. SF 716, Agency Security Classification Costs Estimates.

iii. Special Access Request (SAR) Form 2018a.

P.5 Measurement/Verification

a. To determine Center compliance with E.O. 13526, 32 CFR pt. 2001, and this NPR, Center Directors and Center Chiefs of Protective Services/Chief of Security (CCPS/CCS) or their designees will determine and document compliance through annual self-assessments and reviews conducted by the Office of Protective Services (OPS). Each Center Protective Services Office will conduct assessments of select organizations throughout their Center on a yearly basis to determine if Center organizations are in compliance with this NPR. OPS will provide the Centers with an OPS Self-Inspection Checklist to be used in conjunction with the NPR to ensure that all Center reviews will be tailored to include all steps necessary to perform a comprehensive review of all pertinent areas within a Center.

b. OPS will conduct evaluations, by way of the functional review process, of Center compliance and implementation. OPS will evaluate each Center at least every three years, or sooner if required, using the OPS Functional Review Checklist to determine compliance with this NPR. The functional review process will identify non-compliant issues (findings), observations, and best practices.

Non-compliance with this NPR, the E.O. 13526, and/or 32 CFR pt. 2001, will result in findings that will be forwarded to the Center Director and the Assistant Administrator (AA) for Protective Services. The findings from the OPS Functional Reviews will be provided to the Center Director no later than 30 days after completion of the review. The Center will be required to submit an action plan outlining the non-compliant area along with the corrective action for compliance. OPS will review the findings within 30 days and inform the Center of the approval or disapproval of the corrective actions.

c. The Information Security Oversight Office (ISOO) maintains continuous relationships with agency counterparts on all matters relating to the Classified National Security Program and 32 CFR

pt. 2004. ISOO also conducts on-site assessments to monitor agency compliance with E.O. 13526 and 32 CFR pt. 2001. Each year ISOO gathers relevant statistical data regarding each agency's security classification program. ISOO analyzes and reports this data, along with other relevant information in its Annual Report to the President. NASA follows ISOO guidance and is subject to ISOO inspections and reviews.

d. Internal and external auditors responsible for ensuring that Agency compliance and effective implementation of the E.O. 13526 will evaluate the NASA CNSI program.

NPR 1600.2A -- Preface This document does not bind the public, except as authorized by law or as incorporated into a contract. This document is uncontrolled when printed. Check the NASA Online Directives Information System (NODIS) Library to verify that this is the correct version before use: https://nodis3.gsfc.nasa.gov.

NPR 1600.2A -- Preface Page 7 of 85

P.6 Cancellation NPR 1600.2, NASA Classified National Security Information (CNSI), dated October 11, 2011.

NPR 1600.2A -- Preface This document does not bind the public, except as authorized by law or as incorporated into a contract. This document is uncontrolled when printed. Check the NASA Online Directives Information System (NODIS) Library to verify that this is the correct version before use: https://nodis3.gsfc.nasa.gov.

NPR 1600.2A -- Preface Page 8 of 85

Chapter 1. Introduction

1.1 Overview

1.1.1 NASA generates, receives, disseminates, and maintains an enormous amount of information, much of which is of an unclassified nature with few restrictions on its use and dissemination.

1.1.2 NASA also generates, receives, stores, disseminates, and maintains CNSI under a variety of Agency programs, projects, partnerships, collaboration with other Federal agencies, academia, and private enterprises.

1.1.3 NASA establishes agency-wide procedures for the proper implementation and management of a uniform system for classifying, accounting, safeguarding, and declassifying national security information generated by, for, or in the possession of NASA.

1.1.4 Nothing in this chapter or E.O. 13526 limits the protection afforded any information by other provisions of law, including the exemptions to the 5 U.S.C. § 552, 50 U.S.C. § 3001, or 5 U.S.C. § 552a.

1.1.5 Furthermore, this chapter defines the security review requirements for programs and projects, pursuant to NPR 7120.5 and 7120.8. It establishes procedures for the creation of security classification guides (SCG), as well as requirements for reviewing permanent historical documents, pursuant to E.O. 13526, 32 CFR pt. 2001, and NPR 1441.1, before retirement into the Federal Records Centers or the National Archives and Records Administration (NARA).

1.2 Responsibilities

1.2.1 Pursuant to E.O. 13526 and 32 CFR pt. 2001, the Administrator shall demonstrate personal commitment, commit senior management, and commit necessary resources to the successful implementation of the program established under this NPR.

1.2.2 The Administrator shall designate a senior agency official (SAO) to direct and administer the information security program for managing and safeguarding CNSI in accordance with the E.O.

1.2.3 The Assistant Administrator for Protective Services has been designated as the SAO responsible for providing direction, oversight, and implementation for an Agency-wide information security program , 14 CFR pt. 1203, E O. 13526, and 32 CFR pt. 2001 for the protection of CNSI in NASA's custody. The AA for OPS shall:

a. Direct and administer the NASA program under which information is classified, safeguarded, and declassified.

b. Establish Agency-wide procedures pertaining to the management of CNSI and material generated by or in the custody of NASA.

c. Establish Agency procedures for formal classification challenges by developing a system for processing, tracking and recording formal classification challenges made by authorized holders.

d. Periodically review procedures and systems of Headquarters, Centers, (including Component

NPR 1600.2A -- Chapter1 This document does not bind the public, except as authorized by law or as incorporated into a contract. This document is uncontrolled when printed. Check the NASA Online Directives Information System (NODIS) Library to verify that this is the correct version before use: https://nodis3.gsfc.nasa.gov.

NPR 1600.2A -- Chapter1 Page 9 of 85

Facilities), technical support centers, and service support centers to ensure CNSI is properly protected against unauthorized disclosure or access.

e. Be responsible for the funding, maintenance, and operation of Information Technology systems supporting CNSI.

f. Provide direction, oversight, and implementation of the NASA North Atlantic Treaty Organization (NATO) program in accordance with USSAN Instruction 1-07.

g. Provide direction, oversight, and implementation of 50 U.S.C. § 2672 et seq, by developing a plan to prevent the inadvertent release of records containing Restricted Data (RD) or Formerly Restricted Data (FRD) during the automatic declassification review of records under section 3.3 of E.O. 13526.

h. Provide direction, oversight, and implementation of E.O. 12829 and 32 CFR pt. 2004 by ensuring all the responsibilities of the Cognizant Security Agency (CSA) are met.

1.2.4 Center Directors shall, through the respective Center Chief of Protective Services (CCPS)/Center Chief of Security (CCS):

a. Ensure proper planning and resources for the implementation of E.O. 13526 and 32 CFR pt. 2001, and managing classified information and material under the jurisdiction and custody of their respective Centers. This responsibility includes component activities at facilities or locations geographically separated from the parent Center.

b. Ensure appropriate sanctions for security violations are coordinated with respective Center Office of Human Capital and Management, documented in Center policies, and notify OPS.

c. Ensure the implementation of the CSA requirements at the Center level is incorporated in the acquisition and maintenance of classified contracts process.

1.2.5 The CCPS/CCS shall:

a. Ensure an information security program for CNSI is developed, implemented, and maintained at a level sufficient to meet the requirements of this NPR and national-level requirements.

b. Develop and implement appropriate processes and procedures for ensuring that classified NASA information meets the requirements E.O. 13526 and 32 CFR pt. 2001, and this NPR.

c. Develop and implement appropriate processes and procedures for automatic, systematic, and mandatory review of declassification pursuant to E.O. 13526 and 32 CFR pt. 2001 subpt. D.

d. Develop and implement procedures for the appropriate safeguarding of CNSI.

e. Develop and implement a Center internal annual self-inspection program.

f. Maintain the accountability of the costs associated with implementing this NPR, the E.O. 13526 and 32 CFR pt. 2001.

g. Investigate and report sanctions, security violations, security infractions, loss, possible compromise, or unauthorized disclosure of CNSI pursuant to this NPR. Immediately notify the servicing NASA Counterintelligence office and the OPS Security Management Division Director of all actual or suspected compromises of CNSI.

h. Raise the security threat level or develop temporary procedures to handle national security incidents when necessary.

NPR 1600.2A -- Chapter1 This document does not bind the public, except as authorized by law or as incorporated into a contract. This document is uncontrolled when printed. Check the NASA Online Directives Information System (NODIS) Library to verify that this is the correct version before use: https://nodis3.gsfc.nasa.gov.

NPR 1600.2A -- Chapter1 Page 10 of 85 incidents when necessary.

i. Develop and administer a security education and training program that encompasses initial training, specialized training as required (e.g., derivative classification, courier, and safe custodian training), and termination briefings for all NASA civil service employees and for contractor personnel as required in accordance with an official NASA contract.

j. Ensure the requirements of the National Industrial Security Program (NISP) are incorporated in the acquisition and maintenance of classified contracts.

1.2.6 NASA supervisors shall:

a. Ensure that performance plans for personnel whose duties significantly involve the creation or handling of classified information, including personnel who apply derivative classification markings, are appropriately designated and rated on at least one performance element related to the execution of work required for managing classified information as required by Section 5.4(7) of E.O. 13526.

b. Ensure that personnel entrusted with or handling classified information attend the required briefings, security education, and training provided by the Center Protective Services Office, the Office of Protective Services, or other Government agencies that provide classified information to NASA personnel.

1.2.7 The Center Communications Security (COMSEC) Officer shall serve as the focal point for all COMSEC issues. The Center COMSEC Account Manager (CAM) and Alternate CAM serve as the focal point for all Center COMSEC issues, in accordance with the requirements of NPR 1600.6.

1.2.8 All cleared NASA employees and contractor personnel shall:

a. Protect classified national security information from unauthorized disclosure, to include securing it in approved equipment or facilities whenever it is not under the direct control of an authorized person.

b. Meet safeguarding requirements prescribed by this NPR.

c. Ensure that classified information is not communicated over unsecured voice or data circuits, in public conversations, public places, or in any other manner that permits interception by unauthorized persons.

d. Maintain an annual count of all derivative classification decisions made.

e. Immediately report the following to the CCPS/CCS:

(1) Loss, possible compromise, or unauthorized disclosure of classified information or material.

(2) Known or suspected practice or condition that compromises the proper safeguarding and handling of classified information or material.

(3) Attempts by non-cleared personnel or personnel without a need-to-know to gain access to CNSI.

(4) Security violations or infractions.

f. Initial classification, downgrading, or declassification actions associated with NASA-generated information or material. Immediately report the following to their servicing NASA Counterintelligence office:

NPR 1600.2A -- Chapter1 This document does not bind the public, except as authorized by law or as incorporated into a contract. This document is uncontrolled when printed. Check the NASA Online Directives Information System (NODIS) Library to verify that this is the correct version before use: https://nodis3.gsfc.nasa.gov.

NPR 1600.2A -- Chapter1 Page 11 of 85

Counterintelligence office:

(1) Unusual or suspicious overtures by foreign nationals or representatives of a foreign entity to acquire CNSI or other sensitive information outside established official channels.

(2) Contact between cleared employees and known or suspected intelligence officers from any foreign country.

(3) Any contact that suggests a cleared employee may be the target of an attempted exploitation by a foreign intelligence entity.

(4) Any information regarding suspected or actual threats related to espionage.

g. Challenge classification, when necessary, as a means for promoting proper and thoughtful classification actions.

h. Forward information believed to be improperly classified to the Original Classification Authority (OCA), the Office of Protective Services, or the Center Protective Services Office for further guidance.

i. Ensure all required training outlined in E.O. 13526, 32 CFR pt. 2001, and this NPR established for governing, accessing, protecting, accounting for, and safeguarding classified information and material is completed.

NPR 1600.2A -- Chapter1 This document does not bind the public, except as authorized by law or as incorporated into a contract. This document is uncontrolled when printed. Check the NASA Online Directives Information System (NODIS) Library to verify that this is the correct version before use: https://nodis3.gsfc.nasa.gov.

NPR 1600.2A -- Chapter1 Page 12 of 85

Chapter 2. CNSI Management

2.1 General

2.1.1 All personnel accessing classified information are required to have a “need-to-know” to access that level of information.

2.1.2 All personnel accessing classified information are required to have a favorable personnel security investigation, equivalent to or above the level of access required, completed in accordance with NPR 1600.3.

2.1.3 All personnel accessing classified information shall complete training, annually, in the proper procedures for handling, storing, and safeguarding classified information in accordance with the requirements of this policy.

2.1.4 Classified information is always the property of the U.S. Government and may never be perceived or construed as personal property.

2.1.5 Facility security control requirements for all CNSI areas are identified in NPR 1620.3.

2.2 Original Classification

2.2.1 Information is classified pursuant to E.O. 13526 and 32 CFR § 2001.21 by an OCA.

2.2.2 Information may be originally classified under the terms of E.O. 13526 only if all of the following conditions are met:

a. An OCA is classifying the information.

b. The information is owned by, produced by or for, or is under the control of NASA;

c. The information falls within one or more of the categories of information listed in section 1.4 of E.O. 13526;

d. The OCA determines that an unauthorized disclosure of the information would reasonably be expected to result in damage to the national security, which includes defense against transnational terrorism, and the OCA is able to identify or describe the damage.

2.2.3 If there is significant doubt about the need to classify information, do not classify it and consult OPS for guidance. This provision does not:

a. Amplify or modify the substantive criteria or procedures for classification; or

b. Create any substantive or procedural rights subject to judicial review.

2.2.4 Classified information is not automatically declassified because of unauthorized disclosure of identical or similar information. Do not use information that has been improperly disclosed to make classification determinations.

2.2.5 OCAs shall ensure the proper protection of foreign government information (FGI). The unauthorized disclosure of FGI is presumed to cause damage to the national security. FGI will be

NPR 1600.2A -- Chapter2 This document does not bind the public, except as authorized by law or as incorporated into a contract. This document is uncontrolled when printed. Check the NASA Online Directives Information System (NODIS) Library to verify that this is the correct version before use: https://nodis3.gsfc.nasa.gov.

NPR 1600.2A -- Chapter2 Page 13 of 85 unauthorized disclosure of FGI is presumed to cause damage to the national security. FGI will be protected at the U.S. Government level equivalent.

2.3 Classification Levels

2.3.1 In accordance with Section 1.2 of E.O. 13526, information may be classified at one of the three levels described in Figure 1.

Figure 1. Classification Levels

2.4 NASA Original Classification Authority

2.4.1 Pursuant to the provisions of section 1.3 of E.O. 13526, the President has designated the Administrator as an original classification authority (OCA). Only the Administrator can delegate OCA authority to other NASA personnel. Per delegation of the Administrator in this NPR, the following NASA personnel possess OCA designation up to and including Top Secret:

a. Deputy Administrator,

b. Associate Administrator,

c. Assistant Administrator for Protective Services, and

d. Deputy Assistant Administrator for Protective Services.

2.4.2 When designated in writing by the NASA Administrator, personnel with sufficient justification may possess OCA designation up to and including Top Secret (non-delegable).

2.4.3 OCAs shall receive training in proper classification and declassification prior to originally classifying information and at least once each calendar year thereafter. Security education requirements are in Chapter 3 of this NPR.

NPR 1600.2A -- Chapter2 This document does not bind the public, except as authorized by law or as incorporated into a contract. This document is uncontrolled when printed. Check the NASA Online Directives Information System (NODIS) Library to verify that this is the correct version before use: https://nodis3.gsfc.nasa.gov.

NPR 1600.2A -- Chapter2 Page 14 of 85 npr1600.2AC2G1 npr1600.2AC2G1

2.5 Classification Categories

2.5.1 In accordance with Section 1.4 of E.O. 13526, specific information will only be considered for classification when its unauthorized disclosure is reasonably expected to cause identifiable or describable damage to the national security, as described in Figure 2.

Figure 2. Classification Categories

2.6 Application of Original Classification Authority

2.6.1 At the time of original classification of both hard copy and electronic records, OCAs will indicate the following in a manner that is immediately apparent:

a. Classification level. The OCA shall decide which of the three classification levels defined in E.O.

13526 Section 1.2 most appropriately applies to the information.

b. “Classified By” line. The name and position of the OCA shall be written on the “Classified By” line.

c. Reason for the classification. The OCA shall identify the reason(s) for the decision to classify on the “Reason” line with the number 1.4 plus the letter(s) that corresponds to that classification category in section 1.4 of the E.O. 13526 (e.g. 1.4(a)).

d. Declassification instructions. The duration of the original classification decision will be placed on the “Declassify On” line, which indicates one of the following: the date (YYYYMMDD) or event for declassification as prescribed in section 1.5 (a) of the E.O., the date that is 10 years from the date of original classification as prescribed in 1.5 (b) of the E.O., or the date that is up to 25 years from the date of original classification as prescribed in section 1.5 (b) of the E.O.

NPR 1600.2A -- Chapter2 This document does not bind the public, except as authorized by law or as incorporated into a contract. This document is uncontrolled when printed. Check the NASA Online Directives Information System (NODIS) Library to verify that this is the correct version before use: https://nodis3.gsfc.nasa.gov.

NPR 1600.2A -- Chapter2 Page 15 of 85 npr1600.2AC2G2 npr1600.2AC2G2

e. Establishing duration. If the classified information should clearly and demonstrably be expected to reveal the identity of a confidential human source or a human intelligence source or key design concepts of weapons of mass destruction, an original classification authority will follow the sequence listed in 32 CFR pt. 2001.12 (a)(1) (i)-(iii).

(1) In accordance with the E.O. 13526, no information may remain classified indefinitely. At the time of original classification, the OCA shall establish a specific date or event for declassification based on the duration of the national security sensitivity of the information. Upon reaching the date or event, the information will be automatically declassified.

(2) If the OCA cannot determine a specific date or event for declassification, the information will be marked for declassification 10 years from the date of the original decision, unless the OCA otherwise determines that the sensitivity of the information requires that it be marked for declassification for up to 25 years from the date of the original decision.

(3) An OCA may extend the duration of classification up to 25 years from the date of original of the document, change the level of classification, or reclassify specific information only when the standards and procedures for classifying information under the E.O. 13526 are followed.

f. Date of origin of the document. The date of origin of the document will be indicated in a manner that is immediately apparent within the record.

g. A sample classification authority block for an original classification:

Classified By: <insert name and title or position of the OCA>

Reason: <insert the reason for the classification (e.g., 1.4 followed by the letter that corresponds to that classification category)>

Declassify On: <insert declassify instructions>

2.6.2 The OCA shall issue classification guidance. The OCA classification guidance may be issued in the form of an action memorandum, source document, or security classification guide (SCG).

Security classification guides are the primary format for classification guidance when possible.

However, other forms are acceptable when a SCG is deemed excessive or unnecessary.

2.6.3 Whenever practicable, use a classified addendum when classified information constitutes a small portion of an otherwise unclassified document or prepare a product to allow for dissemination at the lowest level of classification possible or in unclassified form.

2.6.4 Overall markings along with page, component, portion markings, and use of cover sheets will conform to guidelines in accordance with E.O. 13526, 32 CFR pt. 2001, and the ISOO Booklet “Marking Classified National Security Information”. If you are required to mark documents on a classified information system, classified equipment or some other unique classified item, please contact your Center Protective Services Office for specific instructions on how to mark and label each item. CNSI in the electronic environment is subject to all marking requirements.

2.6.5 Exceptional classification cases. Personnel shall not designate information as classified Confidential, Secret, or Top Secret without specific guidance from an OCA or official classification guidance. When an employee, Government contractor, licensee, certificate holder, or grantee of NASA not designated as an original classification authority obtains information believed to require original classification, the information will be protected in a manner consistent with the E.O. 13526, 32 CFR pt. 2001 and this NPR. The individual will contact the Office of Protective Services by way

NPR 1600.2A -- Chapter2 This document does not bind the public, except as authorized by law or as incorporated into a contract. This document is uncontrolled when printed. Check the NASA Online Directives Information System (NODIS) Library to verify that this is the correct version before use: https://nodis3.gsfc.nasa.gov.

NPR 1600.2A -- Chapter2 Page 16 of 85 of their CCPS/CCS for determination by a subject matter expert and classification authority with respect to this information.

2.6.6 In some cases, an aggregation of pre-existing unclassified items of information may require that a classification action be initiated. This act is called compilation or mosaic. Contact the Office of Protective Services by way of your CCPS/CCS to determine if a classification action is warranted.

2.7 Derivative Classification

2.7.1 The CCPS/CCS shall develop procedures for the identification, appointment, and authorization of personnel at their Center which will perform derivative classification actions.

2.7.2 Persons authorized to perform derivative classification shall be identified in writing by the CCPS/CCS, and will receive required initial and annual refresher training courses.

2.7.3 CCPS/CCS shall report all appointments of derivative classifiers to the Office of Protective Services, Security Management Division (SMD).

2.7.4 All persons with access to classified systems will be designated as derivative classifiers. Prior to gaining access to classified systems and performing derivative classification activities, authorized individuals shall:

a. Initiate the Derivative Classifier role and the request for access to classified systems in the NASA Access Management System (NAMS); and

b. Receive training in the proper application of the derivative classification principles.

2.7.5 Derivative classifiers will receive initial training upon designation of authority and annual refresher training thereafter. Security education requirements for the training are in Chapter 4 of this

NPR.

2.7.6 Derivative classifiers who fail to take the annual clearance holder training annually will have their authority and access to classified systems suspended by the SAO until the training is completed.

A waiver may be granted by the SAO if an individual is unable to receive the training due to unavoidable circumstances. Whenever a waiver is granted, the individual will receive training as soon as practicable.

2.8 Application of Derivative Classification Authority

2.8.1 At the time of derivative classification, the following will be indicated in a manner that is immediately apparent. These marking instructions apply to both hard copies and electronic records.

Information derivatively classified will:

a. Be derived from a source document(s) or SCG.

b. Bear standard markings under the uniform security classification system and as prescribed in this

NPR.

c. Carry forward the markings, the classification authority, and declassification instructions from the source document(s) or the SCG.

NPR 1600.2A -- Chapter2 This document does not bind the public, except as authorized by law or as incorporated into a contract. This document is uncontrolled when printed. Check the NASA Online Directives Information System (NODIS) Library to verify that this is the correct version before use: https://nodis3.gsfc.nasa.gov.

NPR 1600.2A -- Chapter2 Page 17 of 85

2.8.2 Derivative classifiers shall not designate information as Confidential, Secret, or Top Secret without specific guidance from an OCA in the form of a source document or SCG.

2.8.3 Derivative Classifiers shall apply the following to all derivatively classified documents:

a. Identify the person performing the derivative classification action by position and title or badge number.

b. Identify the source documents or SCG, including the agency or office of origin and the date of the source document. In the case of multiple sources, all sources will be listed on the document or in an attachment.

c. A sample classification authority block for derivative classifiers should appear as:

Classified By: <insert name and title or position of the derivative classifier>

Derived From : < source document, office of origin, date> or <multiple sources>

Declassify On: <insert declassify instructions>

2.8.4 Overall markings along with page, component, portion markings, and use of cover sheets will conform to guidelines in accordance with E.O. 13526, 32 CFR pt. 2001, and the ISOO Booklet “Marking Classified National Security Information”. If you are required to mark documents on a classified information system, classified equipment or some other unique classified item, please contact your Center Protective Service Office for specific instructions on how to mark and label each item. CNSI in the electronic environment is subject to all marking requirements.

2.8.5 Guidance on what is considered a derivative classification action in the electronic media realm is included in the appendix of this NPR.

2.8.6 Derivative classifiers shall track and report the number of derivative classification actions annually to ISOO in conjunction with SF 311 reporting.

2.9 Identification, Designation and Markings

2.9.1 Marking. Marking is the principal way of letting holders of information know the specific protection requirements for that information. Markings and designations serve the following purposes:

a. Alert holders to the presence of classified information and information with restrictions on its dissemination.

b. Identify, as specifically as possible, the exact information needing protection.

c. Provide guidance on information sharing.

d. Provide guidance on downgrading (if any) and declassification.

e. Give information on the source(s) and reason(s) for classification and other restrictions.

f. Warn holders of special access, control, or safeguarding requirements.

2.9.2 Portion Marking. A portion is ordinarily defined as a paragraph, but also includes: subjects, titles, graphics, tables, charts, illustrations, pictures, bullet statements, sub-paragraphs, classified

NPR 1600.2A -- Chapter2 This document does not bind the public, except as authorized by law or as incorporated into a contract. This document is uncontrolled when printed. Check the NASA Online Directives Information System (NODIS) Library to verify that this is the correct version before use: https://nodis3.gsfc.nasa.gov.

NPR 1600.2A -- Chapter2 Page 18 of 85 signature blocks, and other portions within slide presentations will be marked with the appropriate classification marking.

2.9.3 Classification designations for portion markings are:

a. (U) for Unclassified.

b. (C) for Confidential.

c. (S) for Secret.

d. (TS) for Top Secret.

2.9.4 These abbreviations are placed in parentheses before the portion to which they apply.

Whenever possible, use an unclassified title or subject line.

2.9.5 Markings other than “Top Secret”, “Secret”, and “Confidential”, such as “For Official Use Only”, “Sensitive But Unclassified”, “Controlled Unclassified Information”, “Limited Official Use”, or “Sensitive Security Information”, are not to be used to identify CNSI.

2.9.6 Special Access Program (SAP) Markings. NASA employs SAP markings that are authorized and prescribed by the NASA SAP Security Guide concerning national security information for limiting access to cleared personnel having a need-to-know in the performance of their official duties.

2.9.7 Sensitive Compartmented Information (SCI). The NASA Special Security Office shall review for appropriate classification and marking any document for interagency use (MOU/MOA, memorandum, or general correspondence) involving SCI or suspected SCI produced without the benefit of a specific classification guide.

2.9.8 Foreign Government Information (FGI). Mark documents containing FGI with: “This document contains (country of origin) Information.” Mark the portions that contain the FGI to indicate the country of origin and the classification level (e.g., (Country of Origin S)). Use the Office of the Director of National Intelligence Controlled Access Program Coordination Office (CAPCO) register to locate the official abbreviation for a particular country. Substitute the country name with the words “Foreign Government Information” or “FGI” in situations where the identity of the specific government requires concealing. If the fact that information is FGI needs to be concealed, please contact the Office of Protective Services for specific instructions on how to apply appropriate markings.

2.9.9 Banner Markings. Banner markings represent the overall classification of the document. The banner markings should appear on the top and bottom of each page. Identifying the proper classification for each portion is the primary way to determine the overall classification level of a document. The banner line will specify the highest level of classification (Confidential, Secret, or Top Secret) of information contained within the document and the most restrictive control and handling markings contained within the document.

a. The highest level of classification is determined by the highest level of any one portion within the document.

b. The classification level in the banner line is printed in English and spelled out completely. Only the highest classification level is used on the banner line.

c. Any other control markings (e.g., disseminating control markings) included may be spelled out or

NPR 1600.2A -- Chapter2 This document does not bind the public, except as authorized by law or as incorporated into a contract. This document is uncontrolled when printed. Check the NASA Online Directives Information System (NODIS) Library to verify that this is the correct version before use: https://nodis3.gsfc.nasa.gov.

NPR 1600.2A -- Chapter2 Page 19 of 85

c. Any other control markings (e.g., disseminating control markings) included may be spelled out or abbreviated.

d. Banner markings always use uppercase letters.

e. If a document contains more than one page, the banner marking will be placed at the top and bottom of the front cover (if any), the title page (if any), the first page and on the outside of the back cover (if any). Each interior page of a classified document is marked with a banner line at the top and bottom of the page. Interior pages may be marked with the highest classification level of the information contained on that page, whereas the first page of a classified document’s banner reflects the highest classification level of information within the whole document.

2.10 Working Papers

2.10.1 Working papers are documents and material accumulated or created in the preparation of finished documents and material. Classifying as “working papers” is not intended as a way around the original classification procedure or temporary classification. The derivative classifier shall notify the CCPS/CCS of all working paper documents. The CCS/CCPS will ensure that the proper markings and safeguarding are being utilized to protect the information. Required markings for working papers containing classified information are:

a. Creation date.

b. “Working Paper” Annotation at the top and bottom.

c. The highest level of classification contained within.

2.10.2 Working papers are required to be handled in the following manner:

a. Protected in a manner consistent with the highest level of classification contained within the document.

b. Controlled and marked in the manner prescribed for a finished document of the same classification when:

(1) Retained more than 180 days from the date of origin,

(2) Released by the originator outside NASA, or

(3) Filed permanently.

c. Destroyed when no longer needed.

2.11 Classification Prohibitions and Limitations

2.11.1 The OCA, Declassification Authority (DCA), or derivative classifiers shall not classify information, continue to maintain a classification, or fail to declassify information in accordance with Section 1.7 of E.O. 13526.

2.11.2 Classification is prohibited when attempting to classify basic scientific research information not clearly related to the national security.

NPR 1600.2A -- Chapter2 This document does not bind the public, except as authorized by law or as incorporated into a contract. This document is uncontrolled when printed. Check the NASA Online Directives Information System (NODIS) Library to verify that this is the correct version before use: https://nodis3.gsfc.nasa.gov.

NPR 1600.2A -- Chapter2 Page 20 of 85

2.11.3 Classification is prohibited when attempting to reclassify information after declassification and release to the public under proper authority unless it is compliant with Section 1.7 (c) - (e) E.O.

13526.

2.12 Classification Challenges

2.12.1 In order to challenge the classification status of information, authorized holders of the classified information shall present such challenges to the OPS Security Management Division Director to the SAO. Once the challenge is received, the SMD will establish an ad-hoc committee to review the challenge and make the final Agency determination.

2.12.2 A formal challenge under this provision will be submitted in writing, but need not be any more specific than to question why information is or is not classified or is classified at a certain level.

2.12.3 Anyone with access to the information in question may challenge the classification without reprisal. Herein after the individual(s) that challenge the classification of information will be referenced as the challenger.

2.12.4 The SAO shall provide an initial written response to a challenge within 60 days.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .