ConceptioArchiveCode of Federal Regulations (eCFR)
Code of Federal Regulations (eCFR)public full text

32 CFR Part 117 — National Industrial Security Program Operating Manual (NISPOM)

Office of the Federal Register (NARA) · Code of Federal Regulations (eCFR, Office of the Federal Register)
Code of Federal Regulations (eCFR) · Legal · License: Public Domain
Open Source ↗
nationalpersonnel
united states, us regulation, us federal regulation, code of federal regulations, cfr, federal regulation, 32, 117, part 117, 32 cfr 117, 32 cfr part 117, national, defense, office of the secretary of defense, personnel, military and civilian

PART 117—NATIONAL INDUSTRIAL SECURITY PROGRAM OPERATING MANUAL (NISPOM) Authority: 32 CFR part 2004; E.O. 10865; E.O. 12333; E.O. 12829; E.O. 12866; E.O. 12968; E.O. 13526; E.O. 13563; E.O. 13587; E.O. 13691; Public Law 108-458; Title 42 U.S.C. 2011 et seq. et seq. Source: 85 FR 83312, Dec. 21, 2020, unless otherwise noted. § 117.1 Purpose. (a) This rule implements policy, assigns responsibilities, establishes requirements, and provides procedures, consistent with E.O. 12829, “National Industrial Security Program”; E.O. 10865, “Safeguarding Classified Information within Industry”; 32 CFR part 2004; and DoD Instruction (DoDI) 5220.22, “National Industrial Security Program (NISP)” (available at https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/522022p.pdf?ver=2018-05-01-073158-710 (b) This rule, also in accordance with E.O. 12829, E.O. 13587,”Structural Reforms To Improve the Security of Classified Networks and the Responsible Sharing and Safeguarding of Classified Information”; E.O. 13691, “Promoting Private Sector Cybersecurity Information Sharing”; E.O. 12333, “United States Intelligence Activities”; 42 U.S.C. 2011 et seq. et seq. (1) Prescribes industrial security procedures and practices, under E.O. 12829 or successor orders, to safeguard USG classified information that is developed by or disclosed to contractors of the USG. (2) Prescribes requirements, restrictions, and other safeguards to prevent unauthorized disclosure of classified information and protect special classes of classified information. (3) Prescribes that contractors will implement the provisions of this part no later than 6 months from February 24, 2021, with the exception of requirements for reporting foreign travel to the Department of Defense prescribed in SEAD 3 and implemented through this rule. Contractors under the security cognizance of the Department of Defense will begin reporting foreign travel to the Department of Defense no later than 18 months from February 24, 2021. [85 FR 83312, Dec. 21, 2020, as amended at 86 FR 46598, Aug. 19, 2021] § 117.2 Applicability. (a) This rule applies to: (1) The Office of the Secretary of Defense, the Military Departments, the Office of the Chairman of the Joint Chiefs of Staff and the Joint Staff, the Combatant Commands, the Office of the Inspector General of the Department of Defense, the Defense Agencies, the DoD Field Activities, and all other organizational entities within the DoD (referred to collectively in this rule as the “DoD Components”). (2) All executive branch departments and agencies. (3) All industrial, educational, commercial, or other non-USG entities granted access to classified information by the USG executive branch departments and agencies or by foreign governments. (4) The release of classified information by the USG to contractors, who are required to safeguard classified information released during all phases of the contracting, agreement (including cooperative research and development agreements), licensing, and grant processes, i.e., (b) This rule does not: (1) Limit in any manner the authority of USG executive branch departments and agencies to grant access to classified information under the cognizance of their department or agency to any individual designated by them. The granting of such access is outside the scope of the NISP and is accomplished pursuant to E.O. 12968, E.O. 13526, E.O. 13691, the AEA, and applicable disclosure policies. (2) Apply to criminal proceedings in the courts or authorize contractors or their employees to disclose classified information in connection with any criminal proceedings. Defendants and their representative in criminal proceedings in U.S. District Courts, Courts of Appeal, and the U.S. Supreme Court may gain access to classified information in accordance with 18 U.S.C. Appendix 3, Section 1, also known as and referred to in this rule as the “Classified Information Procedures Act,” as amended. § 117.3 Acronyms and Definitions. (a) Acronyms. ACCM AEA AUS CAGE CCIPP CDC CFIUS CFR CI CIA CNSS CNWDI COMSEC COR CSA CSO CUSR DCSA DD DDTC DGR DHS DNI DoD DoDD DoDI DoDM DOE ECP E.O. FBI FCL FGI FOCI FRD FSCC FSO GCA GCMS GSA GSC IDE IDS IFB ISOO ISSM ISSO ITAR ITPSO KMP LAA MFO NATO NDA NIAG NID NISP NISPOM NIST NNPI NNSA NPLO NRC NRTL NSA NSI NTIB OCA OMB PA PCL RD RFP RFQ SAP SCA SCI SD SEAD SF SMO SSA SSP TCP TFNI TP UK UL U.S.C. USD (I&S) USG USML VAL VT (b) Definitions. Access Access Permittee ACCM Adverse information Affiliate Agency(ies) Alarm service company Alarm system description form Approved security container Approved vault AUS community https://pmddtc.state.gov/ Authorized person Branch office CCIPP CDC Certification Classification guide Classified contract Classified covered information system e.g., Classified information Classified meetings Classified visit Classifier Cleared commercial carrier Cleared employees Closed area CNWDI Compromise COMSEC CONFIDENTIAL Consignee i.e., Consignor i.e., Constant surveillance service Consultant Continuous evaluation Continuous monitoring program Contracting officer Contractor Cooperative agreement Cooperative research and development agreement Corporate family Counterintelligence Courier CRYPTO CSA CSO CUI Custodian Cybersecurity Cyber incident Declassification Defense articles Defense services (1) Furnishing assistance (including training) to foreign persons, whether in the United States or abroad, in the design, development, engineering, manufacture, production, assembly, testing, repair, maintenance, modification, operation, demilitarization, destruction, processing or use of defense articles; (2) Furnishing to foreign persons any controlled technical data, whether in the United States or abroad; or (3) Providing military training of foreign units and forces, regular and irregular, including formal or informal instruction of foreign persons in the United States or abroad or by correspondence courses, technical, educational, or information publications and media of all kinds, training aid, orientation, training exercise, and military advice. Derivative classification Document Downgrade Embedded system Empowered official Entity Entity eligibility determination Escort Extent of protection Facility FCL e.g., FGI (1) Provided to the United States by a foreign government or governments, an international organization of governments, or any element thereof with the expectation, expressed or implied, that the information, the source of the information, or both, are to be held in confidence; or (2) Produced by the United States pursuant to, or as a result of, a joint arrangement with a foreign government or governments, an international organization of governments, or any element thereof, requiring that the information, the arrangement, or both are to be held in confidence. Foreign interest Foreign national Foreign person FRD Freight forwarder (transportation agent) GCA Governing board Grant Grantee Hand carrier Home office Industrial security Information Information security Information system Insider Insider threat Joint venture KMP L access authorization LAA Material Matter Media MFO National of the United States NATO information NATO visits Need-to-know Network NNPI Non-DoD executive branch agencies https://www.dcsa.mil. Non-Federal information system NRTL NSI NTIB NTIB entity Nuclear weapon data OCA Original classification Parent PCL Prime contract Prime contractor Privileged user Proscribed information (1) TOP SECRET information; (2) COMSEC information or material, excluding controlled cryptographic items when unkeyed or utilized with unclassified keys. (3) RD; (4) SAP information; or. (5) SCI. Protective security service Q access authorization Remote terminal Restricted area RD SAP Schedule 13D https://www.sec.gov/fast-answers/answerssched13htm.html SCI SECRET Security in depth Security violation Shipper SMO Source document Standard practice procedures Subcontract Subcontractor Subsidiary System software Technical data (1) Information, other than software, which is required for the design, development, production, manufacture, assembly, operation, repair, testing, maintenance or modification of defense articles. This includes information in the form of blueprints, drawings, photographs, plans, instructions or documentation. (2) Classified information relating to defense articles and defense services on the U.S. Munitions List and 600-series items controlled by the Commerce Control List. (3) Information covered by an invention secrecy order. (4) Software directly related to defense articles. TFNI TOP SECRET Transmission Transshipping activity UK community https://www.pmddtc.state.gov/ Unauthorized person United States United States and its territorial areas Upgrade U.S. classified cryptographic information U.S. person Voting securities Working hours (1) There is present in the specific area where classified material is located, a work force on a regularly scheduled shift, as contrasted with employees working within an area on an overtime basis outside of the scheduled work shift; and (2) The number of employees in the scheduled work force is sufficient in number and so positioned to be able to detect and challenge the presence of unauthorized personnel. This would, therefore, exclude janitors, maintenance personnel, and other individuals whose duties require movement throughout the facility. Working papers § 117.4 Policy. E.O. 12829 established the NISP to serve as a single, integrated, cohesive industrial security program to protect classified information and preserve our Nation's economic and technological interests. (a) When contracts, licenses, agreements, and grants to contractors require access to classified information, national security requires that this information be safeguarded in a manner equivalent to its protection within the executive branch of the USG. (b) National security requires that the industrial security program promote the economic and technological interests of the United States. Redundant, overlapping, or unnecessary requirements impede those interests. § 117.5 Information collections. The information collection requirements are: (a) Standard Form (SF) 328 https://www.gsa.gov/forms-library/certificate-pertaining-foreign-interests https://apps.sp.pentagon.mil/sites/dodiic/Pages/default.aspx. (b) NRC collection. (c) DOE collection. (d) DoD collection. https://www.esd.whs.mil/Portals/54/Documents/DD/forms/dd/dd0254.pdf https://www.dcsa.mil/is/nccs/ § 117.6 Responsibilities. (a) Under Secretary of Defense for Intelligence & Security (USD(I&S)). (1) Carries out the direction in section 201 of E.O. 12829 that the Secretary of Defense issue and maintain this rule and changes to it. The USD(I&S) does so in consultation with all affected agencies (E.O. 12829 section 201), with the concurrence of the Secretary of Energy, the Chairman of the NRC, the DNI, and the Secretary of Homeland Security (E.O.12829 section 201), and in consultation with the ISOO Director (E.O. 12829 section 102). (2) Acts as the CSA for DoD. (3) Provides policy and management of the NISP for non-DoD executive branch agencies who enter into inter-agency security agreements with DoD to provide industrial security services required when classified information is disclosed to contractors in accordance with E.O. 12829, as amended. (b) Director, DCSA. 1 https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodd/510542p.pdf?ver=2019-01-14-090012-283 1 (1) Oversees and manages DCSA, which serves as the DoD CSO. (2) Administers the NISP as a separate program element on behalf of DoD GCAs and those agencies with agreements with DoD for security services. (3) Provides security oversight of the NISP as the DoD CSO on behalf of DoD components and those non-DoD executive branch agencies who enter into agreements with DoD as noted in paragraph (a)(3) of this section. The Director, DCSA, will be relieved of this oversight function for DoD special access programs (SAPs) when the Secretary of Defense or the Deputy Secretary of Defense approves a carve-out provision in accordance with DoDD 5205.07, “DoD SAP Policy” (available at: https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodd/520507p.pdf?ver=2020-02-04-142942-827 (c) Secretary of Energy. (1) Prescribes procedures for the portions of this rule pertaining to information classified under the AEA ( i.e., (2) Retains authority over access to information classified under the AEA. (3) Inspects and monitors contractor, licensee, certificate holder, and grantee programs and facilities that involve access to information classified under the AEA, as necessary. (d) Chairman of the NRC. (1) Prescribes procedures for the portions of this rule that pertain to information under NRC programs classified under the AEA, other federal statutes, and executive orders. (2) Retains authority over access to information under NRC programs classified under the AEA, other federal statutes, and executive orders. (3) Inspects and monitors contractor, licensee, certificate holder, and grantee programs and facilities that involve access to information under NRC programs classified pursuant to the AEA, other federal statutes, and executive orders where appropriate. (e) DNI. (1) Prescribes procedures for the portions of this rule pertaining to intelligence sources, methods, and activities, including, but not limited to, SCI. (2) Retains authority over access to intelligence sources, methods, and activities, including SCI. (3) Provides guidance on the security requirements for intelligence sources and methods of information, including, but not limited to, SCI. (f) Secretary of Homeland Security. (1) Prescribes procedures for the portions of this rule that pertain to the CCIPP. (2) Retains authority over access to information under the CCIPP. (3) Inspects and monitors contractor, licensee, certificate holder, and grantee programs and facilities that involve access to CCIPP. (g) All the CSA heads. (1) Oversee the security of classified contracts and activities under their purview. (2) Provide oversight of contractors under their security cognizance. (3) Minimize redundant and duplicative security review and audit activities of contractors, including such activities conducted at contractor locations where multiple CSAs have equities. (4) Execute appropriate intra-agency and inter-agency agreements to avoid redundant and duplicate reviews. (5) Designate one or more CSOs for security administration. (6) Designate subordinate officials, in accordance with governing policies, to act as the authorizing official. Authorizing officials will: (i) Assess and authorize contractors to process classified information on information systems. (ii) Conduct oversight of such information system processing and provide information system security guidelines in accordance with Federal information system security control policies, standards, and procedures. Minimize redundant and duplicative security review and audit activity of contractors, including such activity conducted at contractor locations where multiple CSAs have equities. (h) Heads of component agencies. (1) Oversee compliance with procedures identified by the applicable CSA or designated CSO. (2) Provide oversight of contractor personnel visiting or working on USG installations. (3) Promptly apprise the CSO of information received or developed that could adversely affect a cleared contractor, licensee, or grantee, and their employees, to hold an FCL or PCL, or that otherwise raises substantive doubt about their ability to safeguard classified information entrusted to them. (4) Propose changes to this rule as deemed appropriate and provide them to the applicable CSA for submission to the OUSD(I&S) Counterintelligence, Law Enforcement and Security Directorate. (i) Director, ISOO. (1) Oversees the NSIP and agency compliance with it, in accordance with E.O. 12829. (2) Issues and maintains the NISP implementing directive (32 CFR part 2004), in accordance with E.O. 12829, to provide guidance to the CSAs and USG agencies under the NISP. (3) Chairs the NISP Policy Advisory Committee. Addresses complaints and suggestions from contractors, as detailed in the NISP Policy Advisory Committee bylaws. § 117.7 Procedures. (a) General. (b) Contractor Security Officials. (1) Appointed security officials listed in paragraphs (b)(2), (b)(3), and (b)(4) of this section must: (i) Oversee the implementation of the requirements of this rule. Depending upon the size and complexity of the contractor's security operations, a single contractor employee may serve in more than one position. (ii) Undergo the same security training that is required for all other contractor employees pursuant to § 117.12, in addition to their position specific training. (iii) Be designated in writing with their designation documented in accordance with CSA guidance. (iv) Undergo a personnel security investigation and national security eligibility determination for access to classified information at the level of the entity's eligibility determination for access to classified information ( e.g., (2) SMO. (i) Ensure the contractor maintains a system of security controls in accordance with the requirements of this rule. (ii) Appoint a contractor employee or employees, in writing, as the FSO and appoint the same employee or a different employee as the ITPSO. The SMO may appoint a single employee for both roles or may appoint one employee as the FSO and a different employee as the ITPSO. (iii) Remain fully informed of the facility's classified operations. (iv) Make decisions based on classified threat reporting and their thorough knowledge, understanding, and appreciation of the threat information and the potential impacts caused by a loss of classified information. (v) Retain accountability for the management and operations of the facility without delegating that accountability to a subordinate manager. (3) FSO. (i) Supervise and direct security measures necessary for implementing the applicable requirements of this rule and the related USG security requirements to ensure the protection of classified information. (ii) Complete security training pursuant to § 117.12 and as deemed appropriate by the CSA. (4) ITPSO. (i) If the appointed ITPSO is not also the FSO, the ITPSO will ensure that the FSO is an integral member of the contractor's insider threat program. (ii) The ITPSO will complete training pursuant to § 117.12. (iii) An entity family may choose to establish an entity family-wide insider threat program with one senior official appointed, in writing, to establish, and execute the program as the ITPSO. Each cleared entity using the entity-wide ITPSO must separately appoint that person as its ITPSO for that facility. The ITPSO will provide an implementation plan to the CSA for executing the insider threat program across the entity family. (5) ISSM. (6) Employees performing security duties. (c) Other KMP. (1) Require these KMP to be determined to be eligible for access to classified information as a requirement for the entity's eligibility determination or; (2) Allow the entity to formally exclude these KMP from access to classified information. The entity's governing board will affirm the exclusion by issuing a formal action (see table), and provide a copy of the exclusion action to the CSA. The entity's governing board will document this exclusion action. Table 1 to Paragraph ( c Type of affirmation Language to be used in exclusion action Affirmation for Exclusion from Access to Classified Information [Insert name and address of entity or name and position of officer, director, partner, or similar entity official or officials] will not require, will not have, and can be effectively and formally excluded from, access to all classified information disclosed to the entity and does not occupy a position that would enable them to adversely affect the organization's policies or practices in the performance of classified contracts. Affirmation for Exclusion from Higher-level Classified Information [Insert name and address of entity or name and position of officer, director, partner, or similar entity official or officials] will not require, will not have, and can be effectively and formally excluded from access to [insert SECRET or TOP SECRET] classified information and does not occupy a position that would enable them to adversely affect the organization's policies or practices in the performance of [insert SECRET or TOP SECRET] classified contracts. (d) Insider Threat Program. (e) Standard practice procedures. (f) Cooperation with Federal agencies. e.g., (1) Providing suitable arrangements within the facility for conducting private interviews with employees during normal working hours; (2) Providing, when requested, relevant employment or personnel files, security records, supervisory files, records pertinent to insider threat ( e.g., (3) Providing access to employment and security records that are located at an offsite location; and (4) Rendering other necessary assistance. (g) Security training and briefings. (h) Security reviews USG reviews. (i) Review cycle. (ii) Procedures. (B) The CSA will make every effort to avoid unnecessary intrusion into the personal effects of contractor personnel. (C) The CSA may conduct physical examinations of the interior space of containers not authorized to secure classified material. Such examinations will always be accomplished in the presence of a representative of the contractor. (iii) Controlled unclassified information (CUI). (A) The contractor is a participant in the NISP based on a requirement to access classified information; (B) A classified contract under the CSA's cognizance includes provisions for access to, or protection or handling of, CUI; and (C) The CSA has provided the contractor with specific guidance regarding the assessment criteria and methodology it will use for overseeing protection of the CUI being accessed, stored or transmitted by the contractor as part of the classified contract. (2) Contractor reviews. (i) Self-inspections will include the review of the classified activity, classified information, classified information systems, conditions of the overall security program, and the insider threat program. They will have sufficient scope, depth, and frequency, and will have management support during the self-inspection and during remedial actions taken as a result of the self-inspection. Self-inspections will include the review of samples representing the contractor's derivative classification actions, as applicable. (ii) The contractor will prepare a formal report describing the self-inspection, its findings, and its resolution of issues discovered during the self-inspection. The contractor will retain the formal report for CSA review until after the next CSA security review is completed. (iii) The SMO at the cleared facility will annually certify to the CSA, in writing, that a self-inspection has been conducted, that other KMP have been briefed on the results of the self-inspection, that appropriate corrective actions have been taken, and that management fully supports the security program at the cleared facility in the manner as described in the certification. (i) Contractors working at USG locations. (j) Hotlines. (k) Agency agreements. https://www.dcsa.mil. (l) Security cognizance. (m) Rule interpretations. (n) Waivers to this rule. (o) Complaints and suggestions. Table 2 to Paragraph ( o Addressee Mailing address Telephone No. Facsimile Email address Director, ISOO, National Archives and Records Administration 700 Pennsylvania Avenue NW, Room 100, Washington, DC 20408-0001 202-357-5250 202-357-5907 [email protected]. § 117.8 Reporting requirements. (a) General. https://www.dni.gov/files/NCSC/documents/Regulations/SEAD-3-Reporting-U.pdf (1) Report certain events that may have an effect on the status of the entity's or an employee's eligibility for access to classified information; report events that indicate an insider threat to classified information or to employees with access to classified information; report events that affect proper safeguarding of classified information; and report events that indicate classified information has been, or is suspected to be, lost or compromised. (2) Establish internal procedures to ensure employees with eligibility for access to classified information are aware of their responsibilities for reporting pertinent information to the FSO. The contractor will: (i) Provide reports to the FBI, or other Federal authorities as required by this rule, the terms of a classified contract or other agreement, and by U.S. law. (ii) Provide complete information to enable the CSA to ascertain whether classified information is adequately protected. (iii) Submit reports to the FBI, the CSA, or the ISOO as specified in paragraphs (b), (c), and (g) of this section. (3) Appropriately mark reports containing classified information in accordance with § 117.14. (4) Clearly mark a report containing information submitted in confidence as containing that information. When reports contain information pertaining to an individual, 5 U.S.C. 552a (also known as and referred to in this rule as “The Privacy Act of 1974, as amended,”) permits the withholding of certain information from the individual in accordance with specific exemptions, which include authority to withhold release of information to the extent that the disclosure of the information would reveal the identity of a source who furnished the information to the USG under an express promise that the identity of the source would be held in confidence. (b) Reports to be submitted to the FBI. (1) An initial report may be made by phone, but it must be followed up in writing ( e.g., (2) The contractor will promptly notify the CSA when they make a report to the FBI and provide the CSA a copy of the written report. (c) Reports to be submitted to the CSA Adverse information. (i) The termination of employment of an employee does not negate the requirement to submit this report. If a contractor employee is assigned to a USG location, the contractor will furnish a copy of the report and its final disposition to the USG security point of contact for that location. (ii) Pursuant to Becker Philco, (2) Suspicious contacts. (i) Efforts by any individual, regardless of nationality, to obtain illegal or unauthorized access to classified information. (ii) Efforts by any individual, regardless of nationality, to elicit information from an employee determined eligible for access to classified information, and any contact which suggests the employee may be the target of an attempted exploitation by an intelligence service of another country. See SEAD 3 for specific information to be reported. (3) Change in status of employees determined eligible for access to classified information. (i) Death. (ii) Change in name. (iii) Termination of employment. (iv) Change in citizenship. (4) Citizenship by naturalization. (i) City, county, and state where naturalized. (ii) Date naturalized. (iii) Court. (iv) Certificate number. (5) Employees desiring not to be processed for a national security eligibility determination or not to perform classified work. (6) Classified information nondisclosure agreement (NDA). https://www.gsa.gov/cdnstatic/SF312-13.pdf?forceDownload=1 (7) Changed conditions affecting the contractor's eligibility for access to classified information. e.g., (i) Change of ownership or control of the contractor, including stock transfers that affect control of the entity. (ii) Change of operating name or address of the entity or any of its locations determined eligible for access to classified information. (iii) Any change to the information previously submitted for KMP including, as appropriate, the names of the individuals the contractor is replacing. A new complete KMP listing need be submitted only at the discretion of the contractor or when requested by the CSA. The contractor will provide a statement indicating: (A) Whether the new KMP are cleared for access to classified information, and if cleared, to what level they are cleared and when they were cleared, their dates and places of birth, social security numbers, and citizenship. (B) Whether they have been excluded from access to classified information in accordance with § 117.7(b)(5)(ii). (C) Whether they have been temporarily excluded from access to classified information pending the determination of eligibility for access to classified information in accordance with § 117.9(g). (iv) Any action to terminate business or operations for any reason, imminent adjudication or reorganization in bankruptcy, or any change that might affect the validity of the contractor's eligibility for access to classified information. (v) Any material change concerning the information previously reported concerning foreign ownership, control, or influence (FOCI). This report will be made by the submission of an updated SF 328, “Certificate Pertaining to Foreign Interests,” in accordance with CSA-provided guidance. When submitting this information, it is not necessary to repeat answers that have not changed. When entering into discussion, consultations, or agreements that may reasonably lead to effective ownership or control by a foreign interest, the contractor will report the details to the CSA in writing. If the contractor has received a Schedule 13D from the investor, the contractor will forward a copy with the report. (8) Changes in storage capability. (9) Inability to safeguard classified material. (10) Unsatisfactory conditions of a prime or subcontractors. (ii) Subcontractors will report any information coming to their attention that may indicate that classified information cannot be adequately protected or other circumstances that may impact the validity of the eligibility for access to classified information of their prime contractor. (11) Dispositioned material previously terminated. (12) Foreign classified contracts. (i) The release or disclosure of U.S. classified information to a foreign interest. (ii) Access to classified information furnished by a foreign interest. (13) Reporting of improper receipt of foreign government material. (14) Reporting by subcontractor. (d) Reports of loss, compromise, or suspected compromise. (1) Preliminary inquiry. (2) Initial report. (3) Final report. (i) Material and relevant information that was not included in the initial report. (ii) The full name and social security number of the individual or individuals primarily responsible for the incident, including a record of prior loss, compromise, or suspected compromise for which the individual had been determined responsible. (iii) A statement of the corrective action taken to preclude a recurrence. (iv) Disciplinary action taken against the responsible individual or individuals, if any. (v) Specific reasons for reaching the conclusion that loss, compromise, or suspected compromise occurred or did not occur. (4) Employee information in compromise cases. (e) Individual culpability reports. (1) Contractors will establish a system to manage and track information regarding employees with eligibility for access to classified information who violate the requirements of this rule in order to be able to identify patterns of negligence or carelessness, or to identify a potential insider threat. (2) Contractors will establish and apply a graduated scale of administrative and disciplinary actions in the event of employee security violations or negligence in the handling of classified information. CSAs may provide guidance to contractors with examples of administrative or disciplinary actions that the contractor may consider implementing in the event of employee violations or negligence. Contractors are required to submit a final report to the CSA with the findings of an employee's culpability and what corrective actions were taken. (3) Contractors will include a statement of the administrative or disciplinary actions taken against an employee in a final report to the CSA. A statement must be included when the individual responsible for a security violation can be determined. Contractors' final reports will indicate whether one or more of the following factors are evident: (i) Involved a deliberate disregard of security requirements. (ii) Involved negligence in the handling of classified material. (iii) Was not deliberate in nature but reflects a recent or recurring pattern of questionable judgment, irresponsibility, negligence, or carelessness. (f) CDC cyber incident reports. (1) Reports to be submitted to the designated DoD CSO. (i) At a minimum, the report will include: (A) A description of the technique or method used in the cyber incident. (B) A sample of the malicious software involved in the cyber incident, if discovered and isolated by the CDC, (C) A summary of information in connection with any DoD program that has been potentially compromised due to the cyber incident. (ii) Information that is reported by the CDC (or derived from information reported by the CDC) will be safeguarded, used, and disseminated in a manner consistent with DoD procedures governing the handling of such information pursuant to Public Law 112-239 and 10 U.S.C. 391. (iii) Reports involving classified foreign government information will be reported to the Director, Defense Technology Security Administration (DoD). (2) Reports on non-Federal information systems not authorized to process classified information. (3) Access to equipment and information by DoD personnel. (ii) The CDC is only required to provide DoD access to equipment or information to determine whether information created by or for DoD in connection with any DoD program was successfully exfiltrated from a CDC's network or information system, and what information was exfiltrated from the CDC's network or information system. (g) Reports to ISOO. (2) Contractors will report instances of CSAs duplicating processing to determine an entity's eligibility for access to classified information when there is an existing determination of an entity's eligibility for access to classified information by another CSA. § 117.9 Entity eligibility determination for access to classified information. (a) General. (1) Prior to the entity being granted an entity eligibility determination for access to classified information, the responsible CSA must have determined that: (i) The entity is eligible for access to classified information to meet a legitimate USG or foreign government need. (ii) Access is consistent with national security interests. (2) The CSA will provide guidance on processing entity eligibility determinations for entity access to classified information. (3) The determination of entity eligibility for access is separate from the determination of a classified information safeguarding capability (see § 117.15). (4) Neither the contractor nor its employees will be permitted access to classified information until the CSA has made an entity eligibility determination ( e.g., (5) The requirement for a favorable entity eligibility determination (also referred to in some instances as an FCL) for a prime contractor includes instances where all access to classified information will be limited to subcontractors. A prime contractor must have a favorable entity eligibility determination at the same or higher classification level as its subcontractors. (6) Contractors are eligible for storage of classified material in connection with a legitimate USG or foreign government requirement if they have a favorable entity eligibility determination and a classified information safeguarding capability approved by the CSA. (7) An entity eligibility determination is valid for access to classified information at the same or lower classification level. (8) Each CSA will maintain a record of entity eligibility determinations made by that CSA. (9) A contractor will not use its favorable entity eligibility determination for advertising or promotional purposes. This does not prohibit the contractor from advertising employee positions that require a PCL in connection with the position. (10) A contractor or prospective contractor cannot apply for its own entity eligibility determination. A GCA or a currently cleared contractor may sponsor an entity for an entity eligibility determination at any point during the contracting or agreement life cycle at which the entity must have access to classified information to participate (including the solicitation or competition phase). (b) Reciprocity. (c) Eligibility requirements. (1) Need access to classified information in connection with a legitimate USG or foreign government requirement, and access must be consistent with U.S. national security interests as determined by the CSA. (2) Be organized and existing: (i) Under the laws of the United States, one of the fifty States, the District of Columbia, or an organized U.S. territory (Guam, Commonwealth of the Northern Marianas Islands, Commonwealth of Puerto Rico, and the U.S. Virgin Islands); or (ii) Under the laws of an American Indian/Alaska Native tribal entity if: (A) The American Indian or Alaska Native tribe under whose laws the entity is chartered has been formally acknowledged by the Assistant Secretary—Indian Affairs, of the U.S. Department of the Interior. (B) The contractor is organized and continues to exist, during the period of the eligibility under a tribal statue or code, or pursuant to a resolution of an authorized tribal legislative body. (C) The contractor has submitted or will submit records such as a charter, certificate of organization, or other applicable tribal documents and statute or code provisions governing the formation and continuation of the entity, for CSA determination that the entity is tribally chartered. (3) Be located in the United States or its territorial areas. (4) Have a record of integrity and lawful conduct in its business dealings. (5) Have a SMO, FSO, and ITPSO who have and who maintain eligibility for access to classified information and are not excluded from participating in USG contracts or agreements in accordance with § 117.7(b)(1) through § 117.7(b)(3). (6) Not be under FOCI to such a degree that a favorable entity eligibility determination for access to classified information would be inconsistent with the national interest, in the judgment of the CSA. (7) Maintain sufficient authorized and cleared employees to manage and implement the requirements of this rule in accordance with CSA guidance. (8) Not pose an unacceptable risk to national security interests, in the judgment of the CSA. (9) Meet all requirements governing access to classified information established by the CSA or the relevant authorizing law, regulation, or government-wide policy. (d) Processing the entity eligibility determination. (1) At a minimum, the entity will: (i) Provide CSA-requested documentation within timelines established by the CSA. (ii) Have and identify the SMO. (iii) Appoint a U.S. citizen employee as the FSO. (iv) Appoint a U.S. citizen employee as the ITPSO. (v) Submit requests for personnel security investigations for the SMO, FSO, ITPSO, and those other KMP identified by the CSA as requiring eligibility for access to classified information in connection with the entity eligibility. (2) If the entity is under FOCI with a special security agreement (SSA) as the proposed method of FOCI mitigation, and the GCA requires the entity to have access to proscribed information, the CSA must consider the measures listed in § 117.11(d) as part of the entity eligibility determination. (e) Other personnel eligibility determinations concurrent with the entity eligibility determination. i.e., (2) The entity eligibility determination is not dependent on the PCL eligibility for access to classified information by such employees, provided none of these employees are among those listed in paragraph (c)(5) of this section. Even so, the employees will not be granted access to classified information until both a favorable entity eligibility determination and PCL eligibility has been granted. (f) Exclusion procedures. (g) Temporary exclusions. (1) The SMO or other KMP are not appointed as the FSO or ITPSO. FSOs and ITPSOs may not be temporarily excluded. A cleared employee must always be appointed to fulfill the requirements of these positions in accordance with this rule. (2) An employee, cleared to the level of the entity eligibility determination, must be able to fulfill the NISP responsibilities of the temporarily excluded KMP in accordance with this rule while the temporary exclusion is in effect. (3) The applicable CSA may provide additional guidance on the duration of a temporary exclusion from access to classified information based on circumstances, business structure, and other relevant security information. (4) The contractor's governing board affirms the exclusion action, and provides a copy of the exclusion action to the CSA. The organization's governing body will document this action. Table 1 to Paragraph (g)(4) Type of affirmation Language to be used in exclusion action Affirmation for Temporary Exclusion from Access to Classified Information Pending a final determination of eligibility for access to classified information by the U.S. Government, [insert name and position] will not require, will not have, and can be effectively and formally excluded from access to all classified information disclosed to the entity. Affirmation for Temporary Exclusion from Higher Level Classified Information Pending a final determination of eligibility for access to classified information at the [insert SECRET or TOP SECRET] level, [insert name and position] will not have, and can be effectively and formally excluded from access to higher-level classified information [specify which higher level of information]. (h) Interim entity eligibility determinations. (i) An interim entity eligibility determination is made on a temporary basis pending completion of the full investigative requirements. (ii) If the contractor with an interim entity eligibility determination is unable or unwilling to comply with the requirements of this rule and CSA-provided guidance regarding the process to obtain a final entity eligibility determination, the CSA will withdraw the interim entity eligibility. (i) Multiple facility organizations. (j) Parent-subsidiary relationships. (1) If the CSA determines the parent must be processed for an entity eligibility determination, then the parent must have an entity eligibility determination at the same or higher level as the subsidiary. (2) When a parent and subsidiary or multiple cleared subsidiaries are collocated, a formal written agreement to use common security services may be executed by the entities, subject to the approval of the CSA. (k) Joint ventures. (1) The joint venture must be established as a legal business entity ( e.g. (2) The business entity operating as a joint venture must have been awarded a classified contract or sponsored by a GCA or prime contractor for an entity eligibility determination in advance of a potential award for which the business entity has bid pursuant to paragraph (c) of this section. (3) The business entity operating as a joint venture must have an employee or employees appointed as security officials or KMP pursuant to § 117.7(b). (l) Consultants. (m) Limited entity eligibility determination (Non-FOCI). (i) Limited entity eligibility determinations (or FCLs) involving FOCI will be processed in accordance with § 117.11(e). (ii) This paragraph (paragraph (m) of this section) applies to limited entity eligibility determinations for purposes other than FOCI mitigation in accordance with 32 CFR part 2004. Additional guidance may be provided by the responsible CSA. (2) An entity must be sponsored for a limited entity eligibility determination by a GCA in accordance with the sponsorship requirements contained in paragraph (c) of this section. The contractor should be aware that the sponsorship request from the GCA to the CSA must also include: (i) Description of the compelling need for the limited entity eligibility determination that is in accordance with U.S. national security interests. (ii) Specific reason(s) or rationale for limiting the entity eligibility determination. (iii) The GCA's formal acknowledgement and acceptance of the risk associated with this rationale. (3) The entity must otherwise meet the entity eligibility determination requirements set out in this rule. (4) Access limitations are inherent with the limited entity eligibility determination and are imposed upon all of the entity's employees regardless of citizenship. (5) Contractors should be aware that the CSA will document the requirements of each limited entity eligibility determination it makes, including the scope of, and any limitations on, access to classified information. (6) Contractors should be aware that the CSA will verify limited entity eligibility determinations only to the requesting GCA. In the case of multiple limited entity eligibility determinations for a single entity, the CSA verifies each one separately only to its requestor. (7) The applicable CSA administratively terminates the limited entity eligibility determination when there is no longer a need for access to the classified information for which the CSA approved the limited entity eligibility determination. (n) Termination of the entity eligibility determination. (1) After coordination with applicable GCAs, administratively terminate the entity eligibility determination because the contractor no longer has a need for access to classified information. (2) Revoke an entity eligibility determination if the contractor is unable or unwilling to protect classified information or is unable to comply with the security requirements of this rule. (o) Invalidation of the entity eligibility determination. (p) Records maintenance. § 117.10 Determination of eligibility for access to classified information for contractor employees. (a) General. (i) The contractor must determine that access to classified information is essential in the performance of tasks or services related to the fulfillment of a classified contract. (ii) Access must be clearly consistent with U.S. national security interests as determined by the CSA. (iii) A contractor may give an employee access to classified information at the same or lower level of classification as the level of the contractor's entity eligibility determination if the employee has: (A) A valid need-to-know for the classified information. (B) A USG favorable eligibility determination for access to classified information at the appropriate level; and (C) Signed a non-disclosure agreement. (2) The CSA will determine eligibility for access to classified information in accordance with SEAD 4 (available at: https://www.dni.gov/files/NCSC/documents/Regulations/SEAD-4-Adjudicative-Guidelines-U.pdf (i) The CSA will notify the contractor when an employee's eligibility has been denied, suspended, or revoked. (ii) The contractor will immediately deny access to classified information to any employee when notified of a denial, revocation, or suspension of eligibility regardless of the contractor employee's location. (iii) If the employee's performance is at a USG facility, the contractor will provide notification to the appropriate GCA of any denial, revocation, or suspension of eligibility for access to classified information. (3) Contractors will annotate and maintain the accuracy of their employees' records in the system of record for contractor eligibility and access to classified information, when one has been designated by the CSA. (4) Within an MFO or within the same business organization, contractors may centrally manage eligibility for access to classified information and access to classified information records. (5) The contractor will limit requests for determinations of eligibility for access to classified information to the minimum number of employees and consultants necessary for operational efficiency in accordance with contractual obligations and other requirements of this rule. Requests for determinations of eligibility for access to classified information will not be used to establish a cache of cleared employees. (6) The contractor will not submit a request for an eligibility determination to one CSA if the employee applicant is known to be cleared or in process for eligibility for access to classified information by another CSA. In such cases, reciprocity of eligibility determination in accordance with SEAD 7 (available at: https://www.dni.gov/files/NCSC/documents/Regulations/SEAD-7_BI_ReciprocityU.pdf (7) Contractors will not submit requests for determination of eligibility for access to classified information for individuals who are not their employees or consultants; nor will they submit requests for employees of subcontractors. (8) Access to SCI, SAP, FRD, and RD information is a determination made by the granting authority by the applicable USG granting authority for each category of information. (b) Investigative requirements. (1) Investigative tiers. (2) Investigative coverage. Automated sources. i.e., (ii) Interviews. (iii) Information Covered in Previous Investigations. e.g., (3) Polygraph. (4) Financial disclosure. (5) Reinvestigation and Continuous Evaluation. (c) Verification of U.S. citizenship. (1) Any document, or its successor, listed in this paragraph is an acceptable document to corroborate U.S. citizenship by birth, including by birth abroad to a U.S. citizen. (i) A birth certificate certified with the registrar's signature, which bears the raised, embossed, impressed, or multicolored seal of the registrar's office. (ii) A current or expired U.S. passport or passport card that is unaltered and undamaged and was originally issued to the individual. (iii) A Department of State Form FS-240, “Consular Report of Birth Abroad of a Citizen of the United States of America.” (iv) A Department of State Form FS-545 or DS-1350, “Certification of Report of Birth.” (2) Any document, or its successor, listed in this paragraph is an acceptable document to corroborate U.S. citizenship by certification, naturalization, or birth abroad to a U.S. citizen. (i) A U.S. Citizenship and Immigration Services Form N-560 or N-561, “Certification of U.S. Citizenship.” (ii) A U.S. Citizenship and Immigration Services Form 550, 551, or 570, “Naturalization Certificate.” (iii) A valid or expired U.S. passport or passport card that is unaltered and undamaged and was originally issued to the individual. (d) Procedures for completing the electronic version of the SF 86, “Questionnaire for National Security Positions.” https://www.opm.gov/forms/pdf_fill/sf86.pdf (1) Provide the employee with written notification that review of the SF 86 by the FSO or other contractor employee is for adequacy and completeness and information will be used for no other purpose within the entity. The use and disclosure by the U.S. Government, and by U.S. Government contractors operating systems of records on behalf of a U.S. Government agency to accomplish an agency function, of the information provided by the employee on the SF-86 is governed by the Privacy Act of 1974, as amended, and by the routine uses published by the USG in the applicable System of Records Notice. (2) Not share information from the employee's SF 86 within the entity and will not use the information for any purpose other than determining the adequacy and completeness of the SF 86. (e) Fingerprint collection. (f) Pre-employment eligibility determination action. (i) A written commitment for employment has been made by the contractor. (ii) The candidate has accepted the offer in writing. (2) The commitment for employment must indicate employment will commence within 45 days of the employee being granted eligibility for access to classified information at a level that allows them to perform the tasks or services associated with the contract or USG requirement for which they were hired. (3) Contractors will comply with the requirements pursuant to paragraph (a) (5) of this section. (g) Classified information NDA. e.g., (1) An employee determined eligible for access to classified information must execute an NDA prior to being granted access to classified information. (2) The employee must sign and date the NDA in the presence of a witness. The employee's and witness' signatures must bear the same date. (3) The contractor will forward the executed NDA to the CSA for retention. The CSA may authorize the contractor to retain a copy of the form for administrative purposes, if appropriate. (4) If the employee refuses to execute the NDA, the contractor will deny the employee access to classified information and submit a report to the CSA in accordance with § 117.8(c)(6). (h) Reciprocity. https://www.dni.gov/files/NCSC/documents/Regulations/SEAD-7_BI_ReciprocityU.pdf (1) Any current eligibility determination for access to classified information that is based on an investigation of a scope that meets or exceeds that necessary for the required level of access will provide the basis for a new eligibility determination. (2) The prior investigation will be used without further investigation or adjudication unless the CSA becomes aware of significant derogatory information that was not previously adjudicated. (i) Break in access. (j) Break in employment. (2) The contractor may not provide access to classified information to an employee who previously was eligible for access to classified information, but has had a break in employment that resulted in a loss of eligibility without a new eligibility determination by the CSA. (k) Non-U.S. citizens. (2) An LAA granted under the provisions of this rule is not valid for access to: (i) TOP SECRET information. (ii) RD or FRD. (iii) Information that has not been determined releasable by a USG designated disclosure authority to the country of which the individual is a citizen. (iv) Communications security (COMSEC) information. (v) Intelligence information. (vi) NATO information. Foreign nationals of a NATO member nation may be authorized access to NATO information provided: (A) The CSA obtains a NATO security clearance certificate from the individual's country of citizenship. (B) NATO access is limited to performance on a specific NATO contract. (vii) Information for which foreign disclosure has been prohibited in whole or in part. (viii) Information provided to the USG in confidence by a third-party government. (ix) Classified information furnished by a third-party government. (l) Temporary eligibility for access to classified information. https://www.dni.gov/files/NCSC/documents/Regulations/SEAD-8_Temporary_Eligibility_U.pdf (1) A temporary SECRET or CONFIDENTIAL eligibility determination is valid for access to classified information at the level of the eligibility granted. Access to RD, COMSEC information, and NATO information requires a final SECRET eligibility determination. (2) A temporary TOP SECRET eligibility determination is valid for access to TOP SECRET information. If an individual has a temporary TOP SECRET eligibility determination and has a final SECRET eligibility determination based on a previously completed investigation, the temporary TOP SECRET eligibility determination is valid for access to RD, NATO, and COMSEC information at the SECRET or CONFIDENTIAL level. (3) Access to SCI and SAP information based on a temporary eligibility determination is a determination made by the granting authority. (4) When a temporary eligibility determination has been made and derogatory information is subsequently developed, the CSA may withdraw the temporary eligibility pending completion of the processing that is a prerequisite to the final eligibility determination. (5) When a temporary eligibility determination is withdrawn for an individual who is required to be eligible for access to classified information in connection with the entity eligibility determination for access to classified information, the contractor must remove the individual from access to classified information and any KMP position requiring PCL eligibility or the temporary entity eligibility determination will also be withdrawn. (6) Withdrawal of a temporary eligibility determination is not a denial, termination, or revocation of eligibility under this rule and may not be appealed. (m) Consultants. (2) A contractor may only assign a consultant outside the United States with responsibilities requiring access to classified information when: (i) The consultant agreement between the contractor and consultant includes: (A) Identification of the contract, license, or agreement that requires access to classified information, the level of classified information that is required, and access to FGI by the consultant while assigned outside the United States. (B) A formal agreement that prohibits the consultant from disclosing any classified information related to the contract, license, or agreement as required in paragraph (m)(i)(A) of this section to any party other than the USG or foreign government with which the consultant is meeting, and who possesses the requisite clearance and need to know. (ii) The consultant and the using contractor will jointly execute the consultant agreement setting forth respective security responsibilities. The contractor will retain an original signed copy of the agreement and will ensure its availability if requested by the CSA. (iii) The contractor, in consultation with the applicable CSA as appropriate, will determine what threat briefing(s) the consultant should receive before the assignment, and conduct those briefings as part of the consultant's pre-assignment and recurring security training. (iv) The contractor provides notice of any changes to the consultant agreement to the applicable CSA during assessments or upon CSA request. (3) The using contractor will be the consumer of the consultant services as set forth in the consultant agreement. (4) For security administration purposes, a consultant will be considered an employee of the using contractor for compliance with this rule. (5) Consultants to GCAs are not under the purview of the NISP and will be processed for determination of eligibility by the GCA in accordance with GCA procedures. § 117.11 Foreign Ownership, Control, or Influence (FOCI). (a) General. (1) The CSA will consider a U.S. entity to be under FOCI when: (i) A foreign interest has the power to direct or decide issues affecting the entity's management or operations in a manner that could either: (A) Result in unauthorized access to classified information; or (B) Adversely affect performance of a classified contract or agreement. (ii) The foreign government is currently exercising, or could prospectively exercise, that power, whether directly or indirectly, such as: (A) Through ownership of the U.S. entity's securities, by contractual arrangements, or other means, or; (B) By the ability to control or influence the election or appointment of one or more members to the entity's governing board. (2) When the CSA has determined that an entity is under FOCI, the primary consideration will be the protection of classified information. The CSA will take whatever action is necessary to protect classified information, in coordination with other affected agencies as appropriate. (3) A U.S. entity that is in process for an entity eligibility determination for access to classified information and subsequently determined to be under FOCI is ineligible for access to classified information unless and until effective security measures have been put in place to negate or mitigate FOCI to the satisfaction of the CSA. (4) When a contractor determined to be under FOCI is negotiating an acceptable FOCI mitigation or negation measure in good faith, an existing entity eligibility determination may continue in effect so long as there is no indication that classified information is at risk of compromise in consultation with the applicable GCA. The applicable CSA may decide that circumstances involving the FOCI are such that the entity eligibility determination will be invalidated until implementation of an acceptable FOCI mitigation plan. (5) An existing entity eligibility determination will be invalidated if the contractor is unable or unwilling to negotiate and implement an acceptable FOCI mitigation or negation measure. An existing entity eligibility determination will be revoked if security measures cannot be taken to remove the possibility of unauthorized access to classified information or adverse effect on performance of classified contracts. (6) Changed conditions, such as a change in ownership, indebtedness, or a foreign intelligence threat, may justify certain adjustments to the security terms under which an entity is operating or, alternatively, that a different FOCI mitigation or negation method be employed. If a changed condition is of sufficient significance, it might also result in a determination that a contractor is no longer considered to be under FOCI, or, conversely, that a contractor is no longer eligible for access to classified information. (7) The USG reserves the right, and has the obligation, to impose any security method, safeguard, or restriction (including denial, termination or revocation of an entity eligibility determination) it believes necessary to ensure that unauthorized access to classified information is effectively precluded and performance of classified contracts is not adversely affected. (8) Nothing contained in this section affects the authority of a Federal agency head to limit, deny, or revoke access to classified information under its statutory, regulatory, or contract jurisdiction. (b) Factors. (1) Record of espionage against U.S. targets, either economic or government. (2) Record of enforcement actions against the entity for transferring technology without authorization. (3) Record of compliance with pertinent U.S. laws, regulations, and contracts or agreements. (4) Type and sensitivity of the information the entity would access. (5) Source, nature, and extent of FOCI, including whether foreign interests hold a majority or minority position in the entity, taking into consideration the immediate, intermediate, and ultimate parent entities. (6) Nature of any relevant bilateral and multilateral security and information exchange agreements. (7) Ownership or control, directly or indirectly, in whole or in part, by a foreign government. (8) Any other factor that indicates or demonstrates capability of foreign interests to control or influence the entity's operations or management. (c) Procedures. (1) If an entity provides any affirmative answers on the SF 328, or the CSA receives other information which indicates that the applicant entity may be under FOCI, the CSA will make a risk-based determination regarding the relative significance of the information in regard to: (i) Whether the applicant is under FOCI. (ii) The extent and manner to which the FOCI represents a risk to the national security or may adversely impact classified contract performance. (iii) The type of actions, if any, that would be necessary to mitigate or negate the effects of FOCI to a level deemed acceptable to the USG. The CSA will advise entities on the CSA's appeal channels for disputing CSA FOCI determinations. (2) When an entity with a favorable eligibility determination enters into negotiations for the proposed merger, acquisition, or takeover by a foreign interest, the entity will submit notification to the CSA of the commencement of such negotiations. (i) The submission will include the type of transaction under negotiation ( e.g., (ii) The entity will submit copies of loan, purchase, and shareholder agreements, annual reports, bylaws, articles of incorporation, partnership agreements, other organizational documents, and reports filed with other Federal agencies to the CSA. (d) FOCI action plans. (i) Modification or termination of loan agreements, contracts, and other understandings with foreign interests. (ii) Diversification or reduction of foreign-source income. (iii) Demonstration of financial viability independent of foreign interests. (iv) Elimination or resolution of problem debt. (v) Assignment of specific oversight duties and responsibilities to board members. (vi) Formulation of special executive-level security committees to consider and oversee issues that affect the performance of classified contracts. (vii) Physical or organizational separation of the contractor component performing on classified contracts. (viii) Adoption of special board resolutions. (ix) Other actions that negate or mitigate foreign control or influence. (x) A combination of these methods, as determined by the CSA. (2) When FOCI factors related to ownership are present, methods the CSA may apply to negate or mitigate the risk of foreign ownership include, but are not limited to: (i) Board resolution. ( 1 ( 2 ( 3 ( 4 (B) The governing board will provide for annual certifications to the CSA acknowledging the continued effectiveness of the resolution. (C) The entity will distribute to members of its governing board and to its KMP copies of such resolutions, and report in the entity's corporate records the completion of such distribution. (ii) Security control agreement (SCA). i.e., (iii) SSA. (A) Requirement for a National Interest Determination (NID). e.g., (B) NID process: 1 ( 2 ( 3 ( 4 ( i ( ii ( iii ( iv ( 5 4 i 4 iv ( 6 ( i ( ii ( iii ( iv ( 7 (iv) Voting Trust (VT) or Proxy Agreement (PA). (A) Establishment of a VT or PA involves the selection of trustees or proxy holders, all of whom must become members of the entity's governing board. Both arrangements must provide for the exercise of all prerogatives of ownership by the trustees or proxy holders with complete freedom to act independently from the foreign owners, except as provided in the VT or PA. The arrangements may limit the authority of the trustees or proxy holders by requiring approval be obtained from the foreign owner with respect to issues such as: ( 1 ( 2 ( 3 ( 4 ( 5 (B) The trustees or proxy holders may consult with the foreign owner, or vice versa, where otherwise consistent with U.S. laws, regulations, and the terms of the VT or PA. (C) The trustees or proxy holders assume full responsibility for the foreign owner's voting interests and for exercising all governance and management prerogatives relating thereto to ensure the foreign owner will be insulated from the entity, thereby solely retaining the status of a beneficiary. The entity must be organized, structured, and financed to be capable of operating as a viable business entity and independent from the foreign owners' interests that required FOCI mitigation or negation. (v) Combination measures. (e) Limited entity eligibility determination due to FOCI. (1) In exceptional circumstances, when an entity is under FOCI, the CSA may decide that a limited entity eligibility determination is appropriate when the entity is unable or unwilling to implement FOCI mitigation or negation measures, and the conditions in paragraphs (e)(1)(i) through (iii) of this section are met. This is not the same as a limited entity eligibility determination for purposes not related to FOCI. Information on limited entity eligibility determinations for purposes other than FOCI can be found in § 117.9(m). A CSA may decide that a limited entity eligibility is appropriate for an entity under FOCI if: (i) The limited entity eligibility determination is in accordance with national security interests and a GCA has informed the CSA that access to classified information by the contractor is essential to contract or agreement performance. (ii) There is an industrial security agreement with the foreign government of the country from which the FOCI is derived. (iii) The contractor meets all other entity eligibility requirements outlined in § 117.9(c) except that KMP, other than the FSO, may be citizens of the country from which the FOCI derives and the United States has obtained security assurances at the appropriate level from that country. (2) A U.S. subsidiary of a foreign entity may be sponsored for a limited entity eligibility determination by a foreign government when the foreign government desires to award a contract or agreement to the U.S. subsidiary that involves access to only that classified information for which the foreign government is the OCA. (3) Limited entity eligibility determinations are specific to the classified information for the requesting GCA or foreign government and the single narrowly defined contract, agreement, or circumstance the request was based on. The limited entity eligibility determination will only be verified to that GCA or foreign government for the authorized level of access to classified information and any limitations to that access to classified information. (4) A limited entity eligibility determination is not an option for contractors that require access to proscribed information when a foreign government has ownership or control over the entity. (5) Release of classified information must be in conformity with the U.S. National Disclosure Policy-1 (provided to designated disclosure authorities on a need-to-know basis from the Office of the Under Secretary of Defense for Policy, Defense Technology Security Administration). (6) A limited entity eligibility determination will be administratively terminated when there is no longer a need for the contractor to access the classified information for which it was sponsored. Administrative termination of one limited entity eligibility determination does not impact a contractor's other limited entity eligibility determinations. (7) If there is no industrial security agreement with the foreign government of the country from which the FOCI is derived, in extraordinary circumstances, a limited entity eligibility determination may also be granted if there is a compelling need to do so consistent with U.S. national security interests and the GCA has informed the applicable CSA that access to classified information by the contractor is essential to contract or agreement performance. Under this circumstance, the entity must follow all provisions of this rule. (f) Qualifications of trustees, proxy holders, and outside directors. (1) Trustees and proxy holders must be resident U.S. citizens who can exercise governance and management prerogatives relating to their position in a way that ensures that the foreign owner can be effectively insulated from the entity. (2) Outside directors must be resident U.S. citizens who can exercise governance and management prerogatives relating to their position in a way that ensures that the foreign owner can be effectively separated from the entity's classified work. (3) New trustees, proxy holders, and outside directors must be completely disinterested individuals with no prior involvement with the entity, the entities with which it is affiliated, or the foreign owner. (4) The CSA may consider other circumstances that may affect an individual's eligibility to serve effectively including the number of boards on which the individual serves, the length of time serving on any other governance boards, and other factors in accordance with CSA-provided guidance. (5) Trustees, proxy holders, and outside directors must be determined eligible for access to classified information at the level of the entity eligibility determination for access to classified information. Individuals who are serving as trustees, proxy holders, or outside directors as part of a mitigation measure for the entity are not considered to have prior involvement solely by performing that role for purposes of paragraph (f)(3) of this section. (g) Government security committee (GSC). (1) Unless otherwise approved by the CSA, the GSC consists of trustees, proxy holders, or outside directors and those officer directors who have been determined to be eligible for access to classified information. (2) The members of the GSC are required to ensure that the contractor adheres to laws and regulations and maintains internal entity policies and procedures to safeguard classified information entrusted to it. The GSC ensures that violations of those policies and procedures are promptly investigated and reported to the appropriate authority when it has been determined that a violation has occurred. (3) The contractor's FSO will be the principal advisor to the GSC and attend GSC meetings. The chairman of the GSC must concur with the appointment and replacement of FSOs selected by management. The FSO functions will be carried out under the authority of the GSC. (h) Additional procedures for FOCI mitigation or negation measures. (1) Technology control plan (TCP). e.g., (2) Electronic communications plan (ECP). (3) Affiliated operations plan. (4) Facilities location plan. i.e., (i) Annual review and certification Annual review. (i) Acts of compliance or noncompliance with the approved security arrangement, standard rules, and applicable laws and regulations. (ii) Problems or impediments associated with the practical application or utility of the security arrangement. (iii) Whether security controls, practices, or procedures warrant adjustment. (2) Annual certification. (i) A detailed description of the manner in which the contractor is carrying out its obligations under the agreement. (ii) Changes to security procedures, implemented or proposed, and the reasons for those changes. (iii) A detailed description of any acts of noncompliance, whether inadvertent or intentional, with a discussion of remedial measures, including steps taken to prevent such acts from recurring. (iv) Any changes, or impending changes, of KMP or key board members, including the reasons therefore. (v) Any changes or impending changes in the organizational structure or ownership, including any reorganizations, acquisitions, mergers, or divestitures. (vi) Any other issues that could have a bearing on the effectiveness of the applicable agreement. (j) Transactions involving foreign persons, and the Committee on Foreign Investment in the United States (CFIUS). (1) The CFIUS is a USG interagency committee chaired by the Treasury Department that conducts assessments, reviews and investigations of transactions that could result in foreign control of a U.S. business, and certain non-controlling investments and certain real estate transactions involving foreign persons under 50 U.S.C. 4565. (2) In CFIUS cases where the acquired U.S. business requires access to classified information, the CFIUS assessment, review or investigation, as applicable, and the CSA industrial security FOCI review are carried out in parallel, but are separate processes with different time constraints and considerations. (3) The CSA will promptly advise the parties in a transaction under CFIUS review that would require FOCI negation or mitigation measures if consummated, to submit to the CSA a plan to negate or mitigate FOCI. If it appears that an agreement cannot be reached on material terms of a FOCI action plan, or if the U.S. person that is a party, or in applicable cases, a subject of the proposed transaction fails to comply with the FOCI reporting requirements of this rule, the CSA may recommend a full investigation of the transaction by the CFIUS to determine the effects on national security. § 117.12 Security training and briefings. (a) General. (b) Training materials. (c) Government provided briefings. (d) FSO training. (e) Initial security briefings. (1) Threat awareness, including insider threat awareness in accordance with paragraph (g) in this section. (2) Counterintelligence (CI) awareness. (3) Overview of the information security classification system. (4) Reporting obligations and requirements, including insider threat. (5) Cybersecurity training for all authorized information system users in accordance with CSA-provided guidance pursuant to § 117.18(a)(1) and (a)(2). (6) Security procedures and duties applicable to the employee's position requirements ( e.g. (f) CUI training. (g) Insider threat training. (1) The contractor will provide training to insider threat program personnel, including the contractor's designated ITPSO, on: (i) CI and security fundamentals. (ii) Procedures for conducting insider threat response actions. (iii) Applicable laws and regulations regarding the gathering, integration, retention, safeguarding, and use of records and data, including the consequences of misuse of such information. (iv) Applicable legal, civil liberties, and privacy policies and requirements applicable to insider threat programs. (2) The contractor will provide insider threat awareness training to all cleared employees on an annual basis. Depending upon CSA specific guidance, a CSA may instead conduct such training. The contractor must provide all newly cleared employees with insider threat awareness training before granting access to classified information. Training will address current and potential threats in the work and personal environment and will include at a minimum: (i) The importance of detecting potential insider threats by cleared employees and reporting suspected activity to the insider threat program designee. (ii) Methodologies of adversaries to recruit trusted insiders and collect classified information, in particular within information systems. (iii) Indicators of insider threat behavior and procedures to report such behavior. (iv) CI and security reporting requirements, as applicable. (3) The contractor will establish procedures to validate all cleared employees who have completed the initial and annual insider threat training. (h) Derivative classification Initial training. (2) Refresher training. (i) Classification levels. (ii) Duration of classification. (iii) Identification and markings. (iv) Classification prohibitions and limitations. (v) Sanctions and classification challenges. (vi) Security classification guides. (vii) Information sharing. (3) Record of training. (i) Information systems security. (j) Temporary help suppliers. (k) Refresher training. (l) Debriefings. § 117.13 Classification. (a) Original classification. (1) An OCA classifies information pursuant to E.O. 13526 and 32 CFR part 2001, designates and marks it as TOP SECRET, SECRET, or CONFIDENTIAL, and, except as provided by statute, may use no other terms to identify classified information. (2) The designation UNCLASSIFIED is used to identify information that does not meet the criteria for classification in accordance with E.O. 13526. In accordance with 32 CFR 2002, CUI implementing guidance (including the Marking Handbook) and any GCA-provided guidance, CUI commingled with classified information must be marked as CUI to alert users to its presence and sensitivity. The CUI regulation, guidance, and handbook are available at: https://www.archives.gov/cui. (b) Derivative classification. (2) Derivative classification is the classification of information based on guidance from an OCA, which may be either a properly marked source document or a current security classification guide provided by a GCA in accordance with E.O. 13526. The duplication or reproduction of existing classified information is not derivative classification. (3) A source document that does not contain portion markings, due to an ISOO-approved waiver, must contain a warning statement that it may not be used as a source for derivative classification in accordance with 32 CFR 2001.24(k)(4). (4) Classified information in email messages is marked pursuant to E.O. 13526 and 32 CFR part 2001. If an email is transmitted on a classified system, includes a classified attachment, and contains no classified information within the body of the email itself, the email serves as a transmittal document and is not a derivatively classified document. The email's overall classification must reflect the highest classification level present in the attachment. (c) Derivative classification responsibilities. (1) Mark the face of each derivatively classified document with a classification authority block that includes the employee's name and position or personal identifier, the entity name, and when applicable, the division or the branch. Figure 1 to Paragraph ( c UNCLASSIFIED: CLASSIFICATION MARKINGS FOR ILLUSTRATION PURPOSES ONLY Classified by: John Doe, Security Specialist, Entity ABC Security Division (2) Observe and respect original classification decisions. (3) Carry forward the pertinent classification markings to any newly created documents. For information derivatively classified based on multiple sources, the derivative classifier will carry forward: (i) The date or event for declassification that corresponds to the longest period of classification among the sources. (ii) A listing of the source materials. (4) Be trained, in accordance with § 117.12(h), in the proper application of the derivative classification principles at least once every two years. (5) Whenever possible, use a classified addendum if classified information constitutes a small portion of an otherwise unclassified document. (d) Security classification guidance. (i) Incorporate appropriate security requirement clauses in a classified contract, IFB, RFP, RFQ, or all solicitations leading to a classified contract. (ii) Provide the contractor with the security classification guidance needed during performance of the contract. (iii) Provide this guidance to the contractor in the contract security classification specification, or equivalent. (2) The contract security classification specification, or equivalent, must identify the specific elements of classified information involved in the contract that require security protection. (3) At the discretion of the CSA, contractors may, to the extent possible, advise and assist in the development and any updates to or any revisions to the contract security classification specification, or equivalent. (4) The contractor will comply with all aspects of the classification guidance. (i) Users of classification guides are encouraged to notify the originator of the guide when they acquire information that suggests the need for change in the instructions contained in the guide. (ii) Classification guidance is the exclusive responsibility of the GCA, and the final determination of the appropriate classification for the information rests with that activity. The contract security classification specification, or equivalent, is a contractual specification necessary for the performance of a classified contract. Challenges to classification status are in paragraph (e) in this section. (iii) If the contractor receives a classified contract without a contract security classification specification, or equivalent, the contractor will notify the GCA. If the GCA does not respond with the appropriate contract security classification specification, or equivalent, the contractor will notify the CSA. (5) Upon completion of a classified contract, the contractor must return all USG provided or deliverable information to the custody of the USG. (i) If the GCA does not advise to the contrary, the contractor may retain copies of the USG material for a period of two years following the completion of the contract. The contract security classification specification, or equivalent, will continue in effect for this two-year period. (ii) If the GCA determines the contractor has a continuing need for the copies of the USG material beyond the two-year period, the GCA will issue a final contract security classification specification, or equivalent, for the classified contract and will include disposition instructions for the copies. (e) Challenges to classification status. (i) Information is classified improperly or unnecessarily. (ii) Current security considerations justify downgrading to a lower classification level or upgrading to a higher classification level. (iii) Security classification guidance is not provided, improper or inadequate. (2) If the GCA does not provide a remedy, and the contractor still believes that corrective action is required, the contractor will make a formal written challenge to the GCA. The challenge will include: (i) A description sufficient to identify the issue. (ii) The reasons why the contractor thinks that corrective action is required. (iii) Recommendations for appropriate corrective action. (3) The contractor will safeguard the information as required for its assigned or proposed level of classification, whichever is higher, until action is completed. (4) If the contractor does not receive a written answer from the GCA within 60 days, the contractor will request assistance from the CSA. If the contractor does not receive a response from the GCA within 120 days, the contractor may appeal the challenge to the Interagency Security Classification Appeals Panel through ISOO. (5) The fact that a contractor has initiated such a challenge will not, in any way, serve as a basis for adverse action against the contractor by the USG. If a contractor believes that adverse action did result from a classification challenge, the contractor will promptly furnish full details to ISOO for resolution. (f) Contractor developed information. (1) If the information was previously identified as classified, it will be classified according to an appropriate classification guide, or source document, and appropriately marked. (2) If the information was not previously classified, but the contractor believes the information may or should be classified, the contractor will: (i) Protect the information as though classified at the appropriate level. (ii) Submit the information to the agency that has an interest for a classification determination. In such cases, clearly mark the material “CLASSIFICATION DETERMINATION PENDING; Protect as either TOP SECRET, SECRET, or CONFIDENTIAL.” This marking will appear conspicuously at least once on the material but no further markings are necessary until a classification determination is received. (iii) Not be precluded from marking such material as entity-private or entity-proprietary information, unless the material was based upon information obtained from prior deliverables to the USG or was developed from USG material. (iv) Protect the information pending a final classification determination. The information may be CUI, if it is not classified. Only information that is owned by, produced by, produced for, or is under the control of the USG can be classified in accordance with E.O. 13526. (3) To be eligible for classification: (i) The information must incorporate classified information to which the contractor was given prior access. (ii) The information must be partially or wholly owned by, produced by or for, or under the control of the USG. (4) 10 CFR 1045.21 includes provisions for the DOE with regard to privately generated RD, whereby the DOE may classify such information in accordance with the AEA. (g) Improperly released classified information appearing in public media. (1) Continue to protect the information at the appropriate classification level until formally advised to the contrary by the GCA. (2) Bring any questions about the propriety of continued classification in these cases to the immediate attention of the GCA. (3) Notify the applicable CSA if an employee downloads the improperly released classified information to determine how to resolve a data spill. (h) Downgrading or declassifying classified information. (1) Downgrading. (2) Declassification. (i) RD, FRD, and TFNI. § 117.14 Marking requirements. (a) Purpose for marking. (2) Contractors will clearly mark all classified information and material to convey to the holder the level of classification assigned, the portions that contain or reveal classified information, the period of time protection is required, the identity (by name and position or personal identifier) of the classifier, the source(s) for derivative classification, and any other notations required for protection of the information. (b) Marking guidance for classified information and material. https://www.archives.gov/isoo/training/training-aids (c) Marking guidance for CUI. https://www.archives.gov/files/cui/documents/20161206-cui-marking-handbook-v1-1-20190524.pdf (d) Working papers. (e) Translations. (f) Marking wholly unclassified material. (1) The material has been examined specifically with a view to impose a security classification and has been determined not to require classification by the GCA. (2) The material has been reviewed and has been determined to no longer require classification and it has been declassified by the applicable GCA. (g) Marking miscellaneous material. (1) Handle miscellaneous material developed in connection with the handling, processing, production, storage, and utilization of classified information in a manner that ensures adequate protection of the classified information involved. (2) Destroy the miscellaneous material at the earliest practical time, unless a requirement exists to retain such material. Notwithstanding the provisions of paragraph (a) of this section, there is no requirement for the contractor to mark such material, but disposition and retention requirements in § 117.15(i) and (j) apply. (h) Marking training material. (i) Downgrading or declassification actions. (1) The documents or material must be re-marked pursuant to paragraph (i)(1)(i) or (i)(1)(ii) in this section. (i) Prior to taking any action to downgrade or declassify information, the contractor will seek guidance from the GCA. If the GCA approves such action, the contractor will cancel all old classification markings with the new markings substituted, whenever practical. For documents, at a minimum the outside of the front cover, the title page, the first page, and the outside of the back will reflect the new classification markings, or include the designation UNCLASSIFIED. The contractor will re-mark other material by the most practical method for the type of material involved to ensure that it is clear to the holder what level of classification is assigned to the material. (ii) When the GCA notifies contractors of downgrading or declassification actions that are contrary to the markings shown on the material, the contractor will re-mark material to indicate the change and notify other holders if further dissemination was made. The contractor will mark the material to indicate the: (A) Authority for the action. (B) Date of the action. (C) Identity and position of the individual taking the action. (2) If the volume of material is such that prompt re-marking of each classified item cannot be accomplished without unduly interfering with operations, the contractor may attach a downgrading and declassification notice to the inside of the file drawers or other storage container instead of the re-marking otherwise required. (3) When such documents or materials are withdrawn from the container solely for transfer to another container, or when the container is transferred from one place to another, the transfer may be made without re-marking if the notice is attached to the new container or remains with each shipment. (4) For the purpose of paragraphs (i)(2) and (i)(3) in this section, the contractor must include in the downgrading and declassification notice: (i) The authority for the downgrading or declassification action. (ii) The date of the action. (iii) The storage container to which it applies. (j) Upgrading action. (i) Immediately enter the new markings on the material according to the notice to upgrade, and strike through all the superseded markings. (ii) Enter the authority for and the date of the upgrading action on the material. (iii) Ensure all records affected are stored at the appropriate level of security, including digital networks and systems. Upgrades requiring network or system adjustment will be coordinated with the GCA to mitigate or account for impact on the execution of the contract. (2) The contractor will notify all holders to whom they disseminated the material. The contractor will not mark the notice as classified unless it contains additional information warranting classification. (3) In the case of material which was inadvertently released as UNCLASSIFIED, the contractor will mark and protect the notice as classified at the CONFIDENTIAL level, unless it contains additional information warranting a higher classification. The contractor will cite the applicable Contract Security Classification Specification, or equivalent, or other classification guide on the “Derived From” line and mark the notice with an appropriate declassification instruction. (k) Dissemination of improperly marked information. (1) Determine whether all holders of the material are cleared and authorized access to it. (2) If recipients are authorized persons, and the contractor disseminated the information through authorized channels, promptly provide written notice to all holders of the proper classification to be assigned. The contractor will also include the classification source as well as declassification instructions in the notification. (3) Report compromises to the CSA in accordance with the provisions of § 117.8(d), if: (i) Any of the recipients of the material are not authorized persons. (ii) Any material cannot be accounted for. (iii) The material was transmitted through unauthorized channels. (l) Marking foreign government classified material. (m) Foreign government restricted information and “in confidence” information. (1) Some foreign governments have a fourth level of classification that does not correspond to an equivalent U.S. classification that is identified as RESTRICTED information. In many cases, security agreements require RESTRICTED information to be protected as U.S. CONFIDENTIAL information. (2) Some foreign governments may have a category of unclassified information that is protected by law. This latter category is normally provided to other governments with the expectation that the information will be treated “In Confidence.” The foreign government or international organization must state that the information is provided in confidence and that it must be protected from release. (i) 10 U.S.C. 130c protects information provided “In Confidence” by foreign governments which is not classified but meets special requirements. (ii) This provision also applies to RESTRICTED information which is not required by an agreement to be protected as classified information. (iii) The contractor will not disclose information protected by this statutory provision to anyone except personnel who require access to the information in connection with the contract. (3) It is the responsibility of the foreign entity that awards the contract to incorporate requirements for the protection and marking of RESTRICTED or “In Confidence” information in the contract. The contractor will advise the CSA if requirements were not provided by the foreign entity. (n) Marking U.S. documents containing FGI. e.g., (2) If the identity of the foreign government must be concealed, the front of the document will be marked “THIS DOCUMENT CONTAINS FOREIGN GOVERNMENT INFORMATION;” paragraphs will be marked FGI, together with the classification level ( e.g., (3) A U.S. document that contains FGI will not be downgraded below the highest level of FGI contained in the document or be declassified without the written approval of the foreign government that originated the information. Recommendations concerning downgrading or declassification will be submitted to the GCA or foreign government contracting authority, as applicable. (o) Marking documents prepared for foreign governments. (p) Marking requirements for transfers of defense articles to Australia (AUS) or the United Kingdom (UK). (q) Commingling of RD and FRD. § 117.15 Safeguarding classified information. (a) General safeguarding. (1) Oral discussions. (2) End of day security checks. (ii) Contractors that operate multiple work shifts will perform the security checks at the end of the last working shift in which classified material was removed from storage for use. The checks are not required during continuous 24-hour operations. (3) Perimeter controls. (ii) If the unauthorized introduction or removal of classified material can be reasonably prevented through technical means ( e.g., (iii) The contractor will: (A) Provide appropriate authorization to personnel who have a legitimate need to remove or transport classified material for passing through designated entry or exit points. (B) Conspicuously post notices at all pertinent entries and exits that persons who enter or depart the facility are subject to an inspection of their personal, except under circumstances where the possibility of access to classified material is remote. (C) Limit inspections to buildings or areas where classified work is being performed. (D) Establish the extent, frequency, and location of inspections in a manner consistent with contractual obligations and operational efficiency. The contractor may use any appropriate random sampling technique. (E) Seek legal advice during the formulation of implementing procedures. (F) Submit significant problems pertaining to perimeter controls and inspections to the CSA. (iv) Contractors will develop procedures for safeguarding classified material in emergency situations. (A) The procedures should be as simple and practical as possible and adaptable to any type of emergency that may reasonably arise. (B) Contractors will promptly report to the CSA any emergency situation that renders them incapable of safeguarding classified material. (b) Standards for Security Equipment. (c) Storage. (1) CONFIDENTIAL. See 32 CFR 2001.43(b)(3). (2) SECRET. See 32 CFR 2001.43(b)(2). (3) TOP SECRET Documents. See 32 CFR 2001.43(b)(1). (d) Intrusion Detection Systems (IDS). (1) CSA approval. https://www.dni.gov/files/documents/ICD/ICD_705_SCIFs.pdf www.ul.com/contact (ii) Installation will be performed by an alarm services company certified by a NRTL that meets the requirements in 29 CFR 1910.7 to perform testing and certification. The NRTL-approved alarm service company is responsible for completing the appropriate alarm system description form approved by the NRTL. (iii) All the intrusion detection equipment (IDE) used in the IDS installation will be tested and approved (or listed) by a NRTL, ensuring its proper operation and resistance from tampering. Any IDE that has not been tested and approved by a NRTL will require CSA approval. (2) Central monitoring station. (A) Government contractor monitoring station (GCMS), formerly called a proprietary central station. (B) Cleared commercial central station. (C) Cleared protective signal service station ( e.g., (D) Cleared residential monitoring station. (E) National industrial monitoring station. (ii) SECRET-cleared central station employees at the alarm monitoring station will be in attendance in sufficient number to monitor each alarmed area within the cleared contractor facility. (iii) The central monitoring station will be supervised continuously by a U.S. citizen who has eligibility for access to SECRET information. (iv) The IDS must be activated at the close of business whenever the area is not occupied by cleared personnel. Any IDS exit delay function must expire prior to the cleared personnel leaving the immediate area. A record will be maintained to identify the person or persons who are responsible for setting and deactivating the IDS. (v) Records will be maintained for 12 months indicating time of receipt of alarm, name(s) of security force personnel responding, time dispatched to facility or area, time security force personnel arrived, nature of alarm, and what follow-up actions were accomplished. (3) Investigative response to alarms. (A) If an alarm activation resets in a reasonable amount of time and no damage to the area is visible, then entrance into the area is not required and an initial response team may consist of uncleared personnel. (B) If the alarm activation does not reset and damage is observed, then a cleared response team must be dispatched. The initial uncleared response team must stay on station until relieved by the cleared response team. If a cleared response team does not arrive within 1 hour, then a report to the CSA must be made by the close of the next business day. (ii) The following resources may be used to investigate alarms: Proprietary security force personnel, central station guards, local law enforcement personnel, or a subcontracted guard service. The CSA may approve procedures for the use of entity cleared employees who can meet the minimum response requirements outlined in this section. (A) For a GCMS, trained proprietary or subcontractor security force personnel, cleared to the SECRET level and sufficient in number to be dispatched immediately to investigate each alarm, will be available at all times when the IDS is in operation. (B) For a commercial central station, protective signaling service station, or residential monitoring station, there will be a sufficient number of trained guards available to respond to alarms. Guards will be cleared only if they have the ability and responsibility to access the area or container(s) housing classified material ( i.e., (C) Uncleared guards dispatched by a commercial central station, protective signaling service station, or residential monitoring station in response to an alarm will remain on the premises until a designated, cleared representative of the facility arrives, or for a period of not less than 1 hour, whichever comes first. If a cleared representative of the facility does not arrive within 1 hour following the arrival of the guard, the central control station must provide the CSA with a report of the incident that includes the name of the subscriber facility, the date and time of the alarm, and the name of the subscriber's representative who was contacted to respond. A report will be submitted to the CSA by the end of business on the next business day. (D) Subcontracted guards must be under a classified contract with either the installing alarm service company or the cleared facility. (iii) The response time will be in accordance with the provisions in paragraphs (c)(1) through (c)(3) in this section as applicable. When environmental factors ( e.g., (4) Installation. i.e., (i) When line security is not available, installation will require two independent means of transmission of the alarm signal from the alarmed area to the monitoring station. (ii) Alarm installation provides a level of protection, e.g. (iii) Where law enforcement personnel are the primary alarm response. Under those circumstances, the contractor must obtain written assurance from the police department regarding the ability to respond to alarms in the required response time. (iv) Alarm signal transmission is over computer-controlled data-networks ( e.g., e.g., (v) Alarm investigator response time exceeds the parameters outlined in paragraphs (c)(1) through (c)(3) in this section as applicable. (5) Certification of compliance. (i) Will have been issued to the protected facility by the NRTL, through the alarm service company. (ii) Serves as evidence that the alarm service company that did the installation is: (A) Listed as furnishing security systems of the category indicated. (B) Authorized to issue the certificate of installation as representation that the equipment is in compliance with requirements established by NRTL for the class of alarm system. (C) Subject to the NRTL inspection program whereby periodic inspections are made of representative alarm installations by NRTL personnel to verify the correctness of certification practices. (6) Exceptional cases. (A) Monitored by a central control station but responded to by a local (municipal, county, state) law enforcement organization. (B) Connected by direct wire to alarm receiving equipment located in a local (municipal, county, State) police station or public emergency service dispatch center. This alarm system is activated and deactivated by employees of the contractor, but the alarm is monitored and responded to by personnel of the monitoring police or emergency service dispatch organization. Personnel monitoring alarm signals at police stations or dispatch centers do not require PCLs. Police department response systems may be requested only when: ( 1 ( 2 (ii) An installation proposal, explaining how the system would operate, will be submitted to the CSA. The proposal must include: (A) Sufficient justification for the granting of an exception and the full name and address of the police department that will monitor the system and provide the required response. (B) The name and address of the NRTL-approved entity that will install the system, and inspect, maintain, and repair the equipment. (iii) The response times will be in accordance with the provisions in paragraphs (c)(1) through (c)(3) in this section as applicable. Arrangements will be made with the central monitoring station to immediately notify a contractor representative on receipt of the alarm. The contractor representative is required to go immediately to the facility to investigate the alarm and to take appropriate measures to secure the classified material. (iv) In exceptional cases where central station monitoring service is available, but no proprietary security force, central station, or subcontracted guard response is available, and where the police department does not agree to respond to alarms, and no other manner of investigative response is available, the CSA may approve cleared employees as the sole means of response. (e) Information controls Information management system. (i) A system to verify that classified information in their custody is used or retained only for a lawful and authorized USG purpose. (ii) An information management system to protect and control the classified information in their possession regardless of media, to include information processed and stored on authorized information systems. (2) Top secret information. (i) Designate TOP SECRET control officials to receive, transmit, and maintain access and accountability records to TOP SECRET information. (ii) Conduct an annual inventory of TOP SECRET information and material. (iii) Establish a continuous receipt system for the transmittal of TOP SECRET information within and outside the contractor location. (iv) Number each item of TOP SECRET material in a series. Place the copy number on TOP SECRET documents, regardless of media, and on all associated transactions documents. (v) Establish a record of TOP SECRET material when the material is: (A) Completed as a finished document. (B) Retained for more than 180 days after creation, regardless of the stage of development. (C) Transmitted outside the contractor location. (vi) Establish procedures for destruction of TOP SECRET material by two authorized persons. (vii) Establish destruction records for TOP SECRET material and maintain the records for two years in accordance with § 117.13(d)(5) or in accordance with GCA requirements. (3) Working papers. (i) Date working papers when they are created. (ii) Mark each page of the working papers with the highest classification level of any information contained in them and with the annotation “WORKING PAPERS.” (iii) Destroy working papers when no longer needed. (iv) Mark in the same manner prescribed for a finished document at the same classification level if released outside the contractor location or retained for more than 180 days from the date of origin. (4) Combinations to locks. (5) Information system passwords. (6) Reproduction of classified information. (f) Transmission of classified information. (1) Top secret. (2) Transmission outside the United States and its Territorial Areas. (3) Commercial delivery entities. https://www.archives.gov/isoo/faqs#what-is-overnightcarriers (i) Prior to CSA approval, the contractor must establish and document procedures to ensure the proper protection of incoming and outgoing classified packages, including the street delivery address, for each cleared facility intending to use GSA-listed commercial delivery entities for overnight services. (ii) Contractors will establish procedures for the use of commercial delivery entities in accordance with 32 CFR part 2001. The procedures will: (A) Confirm that the commercial delivery entity provides nationwide, overnight delivery service with automated in-transit tracking of the classified packages. (B) Ensure the package integrity during transit and that incoming shipments are received by appropriately cleared personnel. (C) Not be used for COMSEC, NATO, or FGI. (4) Couriers and hand carriers. (i) Brief employees providing such services on their responsibility to safeguard classified information and keep classified material in their possession at all times. (ii) Provide employees with an identification card or badge which contains the contractor's name and the name and a photograph of the employee. (iii) Make arrangements in advance of departure for overnight storage at a USG installation or at a cleared contractor's facility that has appropriate storage capability, if needed. (iv) Conduct an inventory of the material prior to departure and upon return. The employee will carry a copy of the inventory with them. (5) Use of commercial passenger aircraft. (i) Routine processing. (ii) Special processing. (A) Routine processing would subject the classified material to compromise or damage. (B) Visual examination is or may be required to successfully screen a classified package. (C) Classified material is in specialized containers, which due to its size, weight, or other physical characteristics cannot be routinely processed. (iii) Authorization letter. (A) Full name, date of birth, height, weight, and signature of the traveler and statement that he or she is authorized to transmit classified material. (B) Description of the type of identification the traveler will present on request. (C) Description of the material being hand carried, with a request that it be exempt from opening. (D) Identification of the points of departure, destination, and known transfer points. (E) Name, telephone number, and signature of the FSO, and the location and telephone number of the CSA. (6) Escorts. (i) Name and address of persons, including alternates, to whom the classified material is to be delivered. (ii) Receipting procedures. (iii) Means of transportation and the route to be used. (iv) Duties of each escort during movement, during stops end route, and during loading and unloading operations. (v) Emergency and communication procedures. (g) Destruction. (1) Destroy classified material in their possession based on the disposition instructions in the contract security classification specification or equivalent. (2) Follow the guidance for destruction of classified material in accordance with 32 CFR 2001.47 and the destruction equipment standards in accordance with 32 CFR 2001.42(b). See https://www.nsa.gov/resources/everyone/media-destruction/ (h) Disclosure. (1) Disclosure to employees. (2) Disclosure to subcontractors. (A) Are authorized to disclose classified information to a cleared subcontractor with the appropriate entity eligibility determination (also known as a facility security clearance) and need to know when access to classified information is necessary for the performance of tasks or services essential to the fulfillment of a prime contract or a subcontract. (B) Will convey appropriate classification guidance for the classified information to be disclosed with the subcontract in accordance with § 117.13. (ii) The CSA must have: (A) Made a determination of eligibility for access to classified information for the subcontractor, at the same level, or higher, than the classified information to be disclosed, to allow for such disclosures. (B) Approved storage capability for classified material at the subcontractor location if a physical transfer of classified material occurs. (3) Disclosure between parent and subsidiaries. (A) Are authorized to disclose classified information between parent and subsidiary entities with the appropriate entity eligibility determination (also known as a facility security clearance) and need to know when access to classified information is necessary for the performance of tasks or services essential to the fulfillment of a prime or subcontract. (B) Will convey appropriate classification guidance with the agreement or procurement action that necessitates the disclosure. (ii) The CSA must have: (A) Made a determination of eligibility for access to classified information for both the parent and subsidiary, at the same level, or higher, than the classified information to be disclosed, to allow for such disclosures. (B) Approved storage capability for classified material at the parent and the subsidiary if a physical transfer of classified material occurs. (4) Disclosure to federal agencies. (5) Disclosure of classified information to foreign persons. i.e. (6) Disclosure to other contractors. (7) Disclosure of classified information in connection with litigation. (i) Attorneys hired solely to represent the contractor in any civil or criminal case in federal or State courts unless the disclosure is specifically authorized by the agency that has jurisdiction over the information. (ii) Any federal or state court except on specific instructions of the agency, which has jurisdiction over the information or the attorney representing the United States in the case. (8) Disclosure to the public. (i) The contractor will: (A) Submit requests for approval through the activity specified in the GCA-provided classification guidance for the contract involved. (B) Include in each request the approximate date the contractor intends to release the information for public disclosure and identify the media to be used for the initial release. (C) Retain a copy of each approved request for release for a period of one inspection cycle for review by the CSA. (D) Clear all information developed subsequent to the initial approval through the appropriate office prior to public disclosure. (ii) Unless specifically prohibited by the GCA, the contractor does not need to request approval for disclosure of: (A) The fact that a contract has been received, including the subject of the contract or type of item in general terms provided the name or description of the subject is not classified. (B) The method or type of contract. (C) Total dollar amount of the contract unless that information equates to: ( 1 ( 2 (D) Whether the contract will require the hiring or termination of employees. (E) Other information that from time-to-time may be authorized on a case-by-case basis in a specific agreement with the contractor. (F) Information previously officially approved for public disclosure. (iii) Information that has been declassified is not authorized for public disclosure. If the information is comingled with CUI, or qualifies as CUI once declassified, it will be marked and protected as CUI until it is decontrolled pursuant to 32 CFR part 2002 and reviewed for public release. If the information does not qualify as CUI, it will be protected in accordance with the basic safeguarding requirements in 48 CFR 52.204-21 and subject to the agency's public release procedures. Contractors will request approval for public disclosure of declassified information in accordance with the procedures of this paragraph. (i) Disposition. (1) Establish procedures for review of their classified holdings on a recurring basis to ensure the classified holdings are in support of a current contract or authorization to retain beyond the end of the contract period. (2) Destroy duplicate copies as soon as practical. (3) For disposition of classified material not received under a specific contract: (i) Return or destroy classified material received with a bid, proposal, or quote if the bid, proposal, or quote is not: (A) Submitted or is withdrawn within 180 days after the opening date of bids, proposals, or quotes. (B) Accepted within 180 days after notification that a bid, proposal, or quote has not been accepted. (ii) If the classified material was not received under a specific contract, such as material obtained at classified meetings or from a secondary distribution center, return or destroy the classified material within one year after receipt. (j) Retention. (1) If contractors propose to retain copies of classified material beyond 2 years, the contractor will identify: (i) TOP SECRET material identified in a list of specific documents unless the GCA authorizes identification by subject and approximate number of documents. (ii) SECRET and CONFIDENTIAL material may be identified by general subject and the approximate number of documents. (iii) Contractors will include a statement of justification for retention beyond two years based on if the material: (A) Is necessary for the maintenance of the contractor's essential records. (B) Is patentable or proprietary data to which the contractor has the title. (C) Will assist the contractor in independent research and development efforts. (D) Will benefit the USG in the performance of other prospective or existing agency contracts. (E) Will benefit the USG in the performance of another active contract and will be transferred to that contract (specify contract). (2) If the GCA does not authorize retention beyond two years, the contractor will destroy all classified material received or generated in the performance of a classified contract unless it has been declassified or the GCA has requested that the material be returned. (k) Termination of security agreement. (l) Safeguarding CUI. § 117.16 Visits and meetings. (a) Visits. (1) Classified visits. (i) Must determine that the visit is necessary and the purpose of the visit cannot be achieved without access to, or disclosure of, classified information. (ii) Will establish procedures to ensure positive identification of visitors, appropriate PCL, and need-to-know prior to the disclosure of any classified information. (iii) Will establish procedures to ensure that visitors are only afforded access to classified information consistent with the purpose of the visit. (2) Need-to-know determination. (3) Visits by USG representatives. (4) Visit authorization. (ii) If a CSA-designated database is not available and a VAL is required, contractors will include in all VALs: (A) Contractor's name, employee's name, address, and telephone number, assigned commercial and government entity (CAGE) code, if applicable, and certification of the level of the entity eligibility determination. (B) Name, date and place of birth, and citizenship of the employee intending to visit. (C) Certification of the proposed visitor's PCL and any special access authorizations required for the visit. (D) Name of person(s) to be visited. (E) Purpose and sufficient justification for the visit to allow for a determination of the necessity of the visit. (F) Date or period during which the VAL is to be valid. (5) Long term visitors. (ii) USG personnel assigned to or visiting a contractor facility and engaged in oversight of an acquisition program will retain control of their work product. Classified work products of USG employees will be handled in accordance with this rule. Contractor procedures will not require USG employees to relinquish control of their work products, whether classified or not, to a contractor. (iii) Contractor employees at USG installations will follow the security requirements of the host. This does not relieve the contractor from security oversight of their employees who are long-term visitors at USG installations. (b) Classified meetings. (1) Meeting conducted by a cleared contractor. (i) Must approve security arrangements, announcements, attendees, and the location of the meeting. (ii) May delegate certain responsibilities to a cleared contractor for the security arrangements and other actions necessary for the meeting under the general supervision of the USG agency. (2) Request for authorization. (i) An explanation of the USG purpose to be served by disclosing classified information at the meeting and why the use of conventional channels for release of the classified information will not advance those interests. (ii) The subject of the meeting and scope of classified topics, to include the classification level, to be disclosed at the meeting. (iii) The expected dates and location of the meeting. (iv) The general content of the proposed announcement or invitation to be sent to prospective attendees or participants. (v) The identity of any other non-government organization involved and a full description of the type of support it will provide. (vi) A list of any foreign representatives (including their nationality, name, organizational affiliation) whose attendance at the meeting is proposed. (vii) A description of the security arrangements necessary for the meeting to comply with the requirements of this rule. (3) Locations of meetings. (4) Security arrangements for meetings. (i) Announcements. (A) Announcements will be unclassified and will be limited to a general description of topics expected to be presented, names of speakers, and administrative instructions for requesting invitations or participation. Classified presentations will not be solicited in the announcement. (B) When the meeting has been approved, announcements may only state that the USG agency has authorized the conduct of classified sessions and will provide necessary security assistance. (C) The announcement will further specify that security clearances and justification to attend classified sessions are to be forwarded to the authorizing agency or its designee. (D) Invitations to foreign persons will be sent by the authorizing USG agency. (ii) Clearance and need-to-know. (A) Need-to-know will be determined by the authorizing agency or its designee based on the justification provided. (B) Attendance will be authorized only to those persons whose security clearance and justification for attendance have been verified by the security officer of the organization represented. (C) The names of all authorized attendees or participants must appear on an access list with entry permitted to the classified session only after verification of the attendee's identity based on presentation of official photographic identification such as a passport, contractor or USG identification card. (iii) Presentations. (A) Individuals making presentations at meetings will provide sufficient classification guidance to enable attendees to identify what information is classified and the level of classification. (B) Classified presentations will be delivered orally or visually. (C) Copies of classified presentation materials will not be distributed at the classified meeting, and any classified notes or electronic recordings of classified presentations will be classified, safeguarded, and transmitted as required by this rule. (iv) Physical security. (5) Disclosure authority at meetings. (i) Obtain prior written authorization for each proposed disclosure of classified information from the USG agency having jurisdiction over the information involved. (ii) Furnish a copy of the disclosure authorization to the USG agency sponsoring the meeting. (6) Requests to attend classified meetings. § 117.17 Subcontracting. (a) Prime contractor responsibilities Responsibilities. (i) A “security requirements clause” and a “Contract Security Classification Specification,” or equivalent, will be incorporated in the solicitation and in the subcontract. (See the “security requirements clause” in the prime contract.) (ii) The subcontractor must possess an appropriate entity eligibility determination and a classified information safeguarding capability if possession of classified information will be required. (A) If access to classified information will not be required in the pre-award phase, prospective subcontractors are not required to possess an entity eligibility determination to receive or bid on the solicitation. (B) If a prospective subcontractor requires access to classified information during the pre-award phase and does not have the appropriate entity eligibility determination or a classified information safeguarding capability, the prime contractor will request the CSA of the subcontractor to initiate the necessary action. (iii) If access to classified information will not be required, the contract is not a classified contract within the meaning of this rule. If the prime contract contains requirements for release or disclosure of protected information that is not classified, such as CUI, the requirements will be incorporated in the solicitation and the subcontract and are not covered by this rule. (2) Prospective subcontractors entity eligibility determinations. (ii) If a prospective subcontractor does not have the appropriate entity eligibility determination or a classified information safeguarding capability, the prime contractor will request that the CSA of the subcontractor initiate the necessary action. (A) Requests will include, at a minimum, the full name, address, and contact information for the requester; the full name, address, and contact information for a contact at the facility to be processed for an entity eligibility determination; the level of clearance and the required classified information safeguarding capability; and full justification for the request. (B) Requests for safeguarding capability will include a description, quantity, end-item, and classification of the information related to the proposed subcontract. (C) Other factors necessary to help the CSA determine if the prospective subcontractor meets the requirements of this rule will be identified, such as any special access requirements. (3) Lead time for entity eligibility determination when awarding to an uncleared subcontractor. (i) The delay in processing the entity eligibility determination was not caused by a lack of cooperation on the part of the prospective subcontractor. (ii) Future classified negotiations may occur within 12 months. (iii) There is reasonable likelihood the subcontractor may be awarded a classified subcontract. (iv) Subcontracting that involves access to FGI. (B) The contractor cannot award subcontracts involving FGI to a contractor in a third country or to a U.S. entity with a limited entity eligibility determination based on third-country FOCI without the express written consent of the originating foreign government. The CSA will coordinate with the appropriate foreign government authorities. (b) Security classification guidance. (i) When preparing classification guidance for a subcontract, the prime contractor may extract pertinent information from: (A) The Contract Security Classification Specification, or equivalent, issued with the prime contract. (B) Security classification guides issued with the prime contract. (C) Any security guides that provide guidance for the classified information furnished to, or that will be generated by, the subcontractor. (ii) The Contract Security Classification Specification, or equivalent, prepared by the prime contractor will be certified by a designated official of the contractor. (iii) In the absence of exceptional circumstances, the classification specification will not contain any classified information. If classified supplements are required as part of the Contract Security Classification Specification, or equivalent, they will be identified and forwarded to the subcontractor by separate correspondence. (2) An original Contract Security Classification Specification, or equivalent, will be included with each RFQ, RFP, IFB, or other solicitation to ensure that the prospective subcontractor is aware of the security requirements of the subcontract and can plan accordingly. An original Contract Security Classification Specification, or equivalent, will also be included in the subcontract awarded to the successful bidder. (3) A revised Contract Security Classification Specification, or equivalent, will be issued as necessary during the lifetime of the subcontract when the security requirements change. (4) Requests for public release by a subcontractor will be forwarded through the prime contractor to the GCA. (c) Responsibilities upon completion of the subcontracts. (2) If retention is required beyond the two-year period, the subcontractor must request written retention authority through the prime contractor to the GCA, including the information required by § 117.15(j). (3) If retention authority is approved by the GCA, the prime contractor will issue a final Contract Security Classification Specification, or equivalent, annotated to provide the retention period and final disposition instructions. (d) Notification of invalidation, marginal, or unsatisfactory conditions. § 117.18 Information system security. (a) General. (2) The CSA will issue guidance based on requirements for federal systems, pursuant to 44 U.S.C. Ch. 35 of subchapter II, also known as the “Federal Information Security Modernization Act,” and as set forth in National Institute of Standards and Technology (NIST) Special Publication 800-37 (available at: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final https://www.cnss.gov/CNSS/openDoc.cfm?QwPYrAJ5Ldq+s+jvttTznQ== e.g., (b) Information system security program. (1) Policies and procedures that reduce information security risks to an acceptable level and address information security throughout the information system life cycle. (2) Plans and procedures to assess, report, isolate, and contain data spills and compromises, to include sanitization and recovery methods. (3) Information system security training for authorized users, as required in CSA provided guidance. (4) Policies and procedures that address key components of the contractor's insider threat program, such as: (i) User activity monitoring network activity, either automated or manual. (ii) Information sharing procedures. (iii) A continuous monitoring program. (iv) Protecting, interpreting, storing, and limiting access to user activity monitoring automated logs to privileged users. (5) Processes to continually evaluate threats and vulnerabilities to contractor activities, facilities, and information systems to ascertain the need for additional safeguards. (6) Change control processes to accommodate configuration management and to identify security relevant changes that may require re-authorization of the information system. (7) Methods to ensure users are aware of rights and responsibilities through the use of banners and user agreements. (c) Contractor responsibilities Certification. (i) Certify to the CSA that the security program for information systems to process classified information addresses management, operation, and technical controls in accordance with CSA-provided guidelines. (ii) Provide adequate resources to the information system security program and organizationally align to ensure prompt support and successful execution of a compliant information system security program. (2) ISSM. (i) Oversee the development, implementation, and evaluation of the contractor's information system program for contractor management, information system personnel, users, and others as appropriate. (ii) Coordinate with the contractor's insider threat senior program official so that insider threat awareness is addressed in the contractor's information system security program. (iii) Develop, document, and monitor compliance of the contractor's information system security program in accordance with CSA-provided guidelines for management, operational, and technical controls. (iv) Verify self-inspections are conducted at least every 12 months on the contractor's information systems that process classified information, and that corrective actions are taken for all identified findings. (v) Certify to the CSA in writing that the systems security plan (SSP) is implemented for each authorized information systems, specified in the SSP; the specified security controls are in place and properly tested; and the information system continues to function as described in the SSP. (vi) Brief users on their responsibilities with regard to information system security and verify that contractor personnel are trained on the security restrictions and safeguards of the information system prior to access to an authorized information system. (vii) Develop and maintain security documentation of the security authorization request to the CSA. Documentation may include: (A) SSPs. (B) Security assessment reports. (C) Plans of actions and milestones. (D) Risk assessments. (E) Authorization decision letters. (F) Contingency plans. (G) Configuration management plans. (H) Security configuration checklists. (I) System interconnection agreements. (3) Information systems security officer (ISSO). (i) Verify the implementation of the contractor's information system security program as delegated by the ISSM. (ii) Ensure continuous monitoring strategies and verify corrective actions to the ISSM. (iii) Conduct self-inspections and verify corrective actions to the ISSM. (4) Information system users. (i) Comply with the information system security program requirements as part of their responsibilities for protecting classified information. (ii) Be accountable for their actions on an authorized information system. (iii) Not share any authentication mechanisms (including passwords) issued for the control of their access to an information system. (iv) Protect authentication mechanisms at the highest classification level and most restrictive classification category of information to which the mechanisms permit access. (v) Be subject to monitoring of their activity on any classified network, understanding that the results of such monitoring can be used against them in a criminal, security, or administrative proceeding or action. (vi) Notify the ISSM or ISSO when access to a classified system is no longer required. (d) Information system security life-cycle. (1) Building security into information systems during initial development. (2) Maintaining continuous awareness of the current state of information system security. (3) Keeping contractor management informed to facilitate risk management decisions. (4) Supporting reciprocity of information system authorizations. (e) Risk management framework. (1) Prepare. (2) Categorize. (3) Select. (4) Implement. (5) Assess. (6) Authorize. (7) Monitor. (i) Effectiveness of security controls. (ii) Documentation of changes to the information system and the operational environment. (iii) Analysis of the security impact of changes to the information system. (iv) Making appropriate reports to the CSA. (f) Unclassified information systems that process, store, or transmit CUI. § 117.19 International security requirements. (a) General. (b) Disclosure of classified U.S. information to foreign interests Applicable federal law. et seq., (2) Security agreements e.g., (A) Requires that each government provide substantially the same degree of protection to classified information released by the other government. (B) Contains provisions concerning limits on the use of each government's information, including restrictions on third-party transfers and proprietary rights. (C) Does not commit governments to share classified information, nor does it constitute authority to release classified material to that government. (D) Satisfies, in part, the eligibility requirements of the Arms Export Control Act concerning the agreement of the recipient foreign government to protect U.S. classified defense articles and classified information. (ii) The applicable CSA will provide a mechanism for contractors to access, for official purposes, classified general security agreements. (iii) Industrial security agreements have been negotiated with certain foreign governments that identify the procedures to be used when foreign government classified information is provided to U.S. industry and UUSG classified information is provided to foreign defense industry. (3) Authorization for disclosure. (i) Contractors will only disclose non-public USG information to foreign persons in accordance with specified requirements of the contract. In the absence of any specified requirements the contractor will not disclose non-public USG information to foreign persons. (ii) Disclosure authorization may be in the form of an export license or other export authorization by a cognizant export authority. (iii) The contractor may not use disclosure guidance provided by the GCA for a previous contract or program unless so instructed in writing by the GCA or the licensing authority. (iv) Disclosure and export of classified information, authorized by an appropriate USG disclosure official, by a contractor will ensure the following: (A) International agreements. (B) Symposia, seminars, exhibitions, and conferences. (C) Visits by foreign nationals to the contractor. (D) Temporary exports. i.e., (4) Direct commercial arrangements. (ii) If a proposed disclosure is in support of a foreign government requirement, the contractor should consult with U.S. in-country officials, normally the U.S. Security Assistance/Armaments Cooperation Office or Commercial Counselor. (A) Before a contractor makes a proposal to a foreign interest that involves the eventual disclosure of U.S. classified information, the contractor must obtain appropriate government disclosure authorization. (B) Such disclosure authorization does not equate with authorization for export. Export authorization must be obtained from the appropriate regulatory body. (iii) The contractor will request a FCL assurance for a foreign entity through the CSA from the security authority of the foreign entity's sponsoring government prior to entering into a contractual arrangement with the foreign entity. (5) Subcontract security provisions. (A) Award of a subcontract. (B) Department of State authorized manufacturing license agreement, technical assistance agreement, or other direct commercial arrangement. (ii) The contractor will incorporate security provisions into the subcontract document or agreement, and provide security classification guidance by means of a Contract Security Classification Specification, or equivalent. (iii) The contractor will provide a copy of the signed contract with the provisions and the classification guidance to the CSA. (iv) If the export authorization specifies that additional security arrangements are necessary for performance on the contract, the contractor will incorporate those additional arrangements by appropriate provision in the contract or in a separate security document. (v) The contractor will prepare and maintain a written record that identifies the originator or source of classified information that will be used in providing classified defense articles, material or services to foreign customers. The contractor will maintain this listing with the contractor's record copy of the pertinent export authorization. (vi) The contractor will include the security provisions in accordance with paragraph (b)(5) in this section in all contracts and subcontracts involving classified information that are awarded to foreign contractors. Contractors must insert the bracketed contract specific information ( e.g., (A) All classified information and material furnished or generated under the contract will be protected to ensure that: ( 1 ( 2 ( 3 (B) Classified information and material furnished or generated under this contract will be transferred through government channels or other channels specified in writing by the governments of the United States and [insert applicable country]. It will only be transferred to persons who have an appropriate security clearance and an official need for access to the information in order to perform on the contract. (C) Classified information and material furnished under the contract will be re-marked by the recipient with its government's equivalent security classification markings. (D) Classified information and material generated under the contract must be assigned a security classification as specified by the Contract Security Classification Specifications, or equivalent, provided with this contract. (E) All cases in which it is known or there is reason to believe that classified information or material furnished or generated under the contract has been lost or disclosed to unauthorized persons will be reported promptly and fully by the contractor to its government's security authorities. (F) Classified information and material furnished or generated pursuant to the contract will not be further provided to another potential contractor or subcontractor unless: ( 1 ( 2 (G) Upon completion of the contract, all classified material furnished or generated pursuant to the contract will be [insert whether the material is to be returned or destroyed, or provide other instructions]. (H) The recipient contractor will insert terms that substantially conform to the language of these provisions, including this one, in all subcontracts under this contract that involve access to classified information furnished or generated under this contract. (c) FGI General. (2) Contract security requirements. (3) Marking foreign government classified material. (4) Foreign Government RESTRICTED Information and “In Confidence” Information. (5) Marking U.S. documents containing FGI. (6) Marking documents prepared for foreign governments. (7) Storage and control. (8) Disclosure and use limitations. (A) Not disclose FGI to nationals of a third country, or to any other third party, or use it for any purpose other than that for which it was provided without the prior written consent of the originating foreign government. (B) Submit requests for other uses or further disclosure to the GCA for U.S. contracts, and through the CSA for direct commercial contracts. (ii) Approval of the request by the foreign government does not eliminate the requirement for the contractor to obtain an export authorization. (9) Transfer. (10) Reproduction. (11) Disposition. (i) Will destroy FGI on completion of the contract unless the contract specifically authorizes retention or return of the information to the U.S. GCA or foreign government that provided the information. (ii) Must witness the destruction of TOP SECRET, execute a destruction certificate, and retain the destruction certificate for two years. (12) Reporting of improper receipt of foreign government material. (13) Subcontracting. (d) International transfers of classified material General. (i) All international transfers of classified material must take place through channels approved by both governments. U.S. control of classified material must be maintained until the material is officially transferred to the intended recipient government through its designated government representative (DGR). (ii) To ensure government control, written transmission instructions must be prepared for all international transfers of classified material. The contractor is responsible for the preparation of instructions for direct commercial arrangements, and the GCA will prepare instructions for government arrangements. (iii) The contractor will contact the CSA at the earliest possible stage in deliberations that will lead to the international transfer of classified material. The CSA will advise the contractor on the transfer arrangements, identify the recipient government's DGR, appoint a U.S. DGR, and ensure that the transportation plan prepared by the contractor or foreign government is adequate. (iv) The contractor's empowered official is responsible for requests for all export authorizations, including ones that will involve the transfer of classified information. (2) Transfers of freight Transportation plan (TP). ( 1 ( 2 (B) The U.S. and recipient government DGRs will be identified in the TP as well as any requirement for an escort. When there are to be repetitive shipments, a notice of classified consignment will be used. (ii) Government agency arrangements. (A) The government agency that executes the arrangement is responsible, in coordination with the recipient foreign government, for preparing a TP. (B) When the point of origin is a U.S. contractor facility, the GCA will provide the contractor with a copy of the TP and the applicable letter of offer and acceptance. If a freight forwarder will be involved in processing the shipment, the GCA will provide a copy of the TP to the freight forwarder. (C) Commercial arrangements. 1 ( 2 (D) International carriers. ( 1 ( 2 ( 3 (E) Escorts. 1 ( 2 ( 3 ( 4 ( i ( ii ( iii ( iv ( v (3) Secure communications plan. (ii) The secure communications plan may be approved within a program security instruction, SSP, or a government to government agreement by the designated security authorities. A separate memorandum of understanding or memorandum of agreement is not required. (iii) Additionally, an SSP must be authorized in accordance with § 117.18 and the CSA provided guidance. (4) Return of material for repair, modification, or maintenance. (ii) The approved methods of return will be specified in either the GCA sales arrangement, the security requirements section of a direct commercial sales arrangement or, in the case of material transferred as freight, in the original TP. (iii) The contractor, on receipt of notification that classified material is to be received, will notify the applicable CSA. (5) Use of freight forwarders. (A) The freight forwarder must be under contract to a USG agency, U.S. contractor, or the recipient foreign government. (B) The contract will describe the specific functions to be performed by the freight forwarder. (C) The responsibility for security and control of the classified material that is processed by freight forwarders remains with the USG until the freight is transferred to a DGR of the recipient government. (ii) Only freight forwarders that have a valid determination of eligibility for access to classified information and storage capability for classified material at the appropriate level are eligible to take custody or possession of classified material for delivery as freight to foreign recipients. Freight forwarders that only process unclassified paperwork and make arrangements for the delivery of classified material to foreign recipients do not require an eligibility determination for access to classified information. (iii) A freight forwarder cannot serve as a DGR. (6) Hand carrying classified material. (i) The CSA will ensure that the contractor has made necessary arrangements with U.S. airport security and customs officials and that security authorities of the receiving government approve the plan. If the transfer is under a contract or a bilateral or multinational government program, the GCA will approve the request in writing. The contractor will notify the CSA of a requirement to hand carry at least 5 working days in advance of the transfer. (ii) The courier must be a full-time employee of the dispatching or receiving contractor who has been determined eligible and has been granted access to classified information. (iii) The employing contractor will provide the courier with a courier certificate that is consecutively numbered and valid for one journey only. The journey may include more than one stop if approved by the CSA and secure government storage has been arranged at each stop. The courier will return the courier certificate to the dispatching contractor immediately on completion of the journey. (iv) Before commencement of each journey, the courier will read and initial the notes to the courier attached to the courier certificate and sign the courier declaration. The contractor will maintain the declaration until completion of the next CSA security review. (v) The dispatching contractor will inventory, wrap, and seal the material in the presence of the U.S. DGR. The contractor will place the address of the receiving security office and the return address of the dispatching contractor security office on the inner envelope or wrapping and mark it with the appropriate classification. The contractor will place the address of the receiving government's DGR on the outer envelope or wrapping along with the return address of the dispatching contractor. (vi) The dispatching contractor will prepare three copies of a receipt based on the inventory and list the classified material that is being sent. The dispatching contractor will retain one copy of the receipt. The contractor will pack the other two copies with the classified material. The contractor will obtain a receipt for the sealed package from the courier. (vii) The dispatching contractor will provide the receiving contractor with 24 work hours advance notification of the anticipated date and time of the courier's arrival and the identity of the courier. The receiving contractor must notify the dispatching contractor if the courier does not arrive within 8 hours of the expected time of arrival. The dispatching contractor will notify its DGR of any delay, unless officially notified otherwise of a change in the courier's itinerary. (viii) The receiving DGR will verify the contents and sign the receipts enclosed in the consignment. The receiving DGR will return one copy to the courier. On return, the courier will provide the executed receipt to the dispatching contractor. (ix) Throughout the journey, the courier will maintain the classified material under direct personal control. The courier will not leave the material unattended at any time during the journey, in the transport being used, in hotel rooms, in cloakrooms, or other such location, and will not deposit it in hotel safes, luggage lockers, or in luggage offices. In addition, the courier will not open envelopes or packages containing the classified material en route, unless required by customs or other government officials. (x) When inspection by government officials is unavoidable, the courier will request that the officials provide written verification that they have opened the package. The courier will notify their employing contractor as soon as possible. The contractor will notify the U.S. DGR. If the inspecting officials are not of the same country as the dispatching contractor, the CSA will notify the designated security authority in the country whose officials inspected the consignment. Under no circumstances will the courier hand over the classified material to customs or other officials for their custody. (xi) When carrying classified material, the courier will not travel by surface routes through third countries, except as authorized by the CSA. The courier will travel only on carriers described in paragraph (d)(2)(iv) in this section, and will travel direct routes between the United States and the destination. (7) Classified material receipts. (A) An active suspense record until return of applicable receipts for the material. (B) A copy of the external receipt that records the passing of custody of the package containing the classified material and each intermediate consignee in a suspense file until the receipt that is enclosed in the package is signed and returned. (ii) The contractor will initiate follow-up action through the CSA if the signed receipt is not returned within 45 days. (8) Contractor preparations for international transfers of classified material pursuant to direct commercial and foreign military sales. (i) Identify each party to be involved in the transfer in the applicable contract or agreement and in the license application or letter request. (ii) Notify the appropriate U.S. DGR when the material is ready. (iii) When the classified material is also ITAR-controlled, provide documentation or written certification by an empowered official (as defined in the ITAR) to the U.S. DGR. This documentation must verify that the classified shipment is within the limitation scope of the pertinent export authorization or an authorized exemption to the export authorization requirements, or is within the limitations of the pertinent GCA contract. (iv) Have the classified shipment ready for visual review and verification by the DGR. As a minimum this will include: (A) Preparing the packaging materials, address labels, and receipts for review. (B) Marking the contents with the appropriate U.S. classification or the equivalent foreign government classification, downgrading, and declassification markings, as applicable. (C) Ensuring that shipping documents (including, as appropriate, the shipper's export declaration) include the name and contact information for the CSA that validates the license or letter authorization, and the FSO or designee for the particular transfer. (D) Sending advance notification of the shipment to the CSA, the recipient, and to the freight forwarder, if applicable. The notification will require that the recipient confirm receipt of the shipment or provide notice to the contractor if the shipment is not received in accordance with the prescribed shipping schedule. (9) Transfers pursuant to an ITAR exemption. i.e., (ii) Classified technical data information or certain defense articles to be exported pursuant to ITAR exemptions will be supported by a written authorization signed by an authorized exemption official or exemption certifying official who has been appointed by the GCA's responsible disclosure authority. (A) The contractor will provide a copy of the authorization to the CSA. (B) The CSA will provide a copy of the authorization to the Department of State Directorate of Defense Trade Controls (DDTC). (e) International visits General. (ii) Contractors cannot use visit authorizations to employ or otherwise acquire the services of foreign nationals that require access to export-controlled information. An export authorization is required for such situations. (2) International visits by U.S. contractor employees Types and purpose of international visits One-time visits. (B) Recurring visits. (C) Long-term visits. (D) Emergency visits. (ii) Requests for visits. (A) Many foreign governments require the submission of a visit request for all visits to a government facility or a cleared contractor facility, even though classified information may not be involved. They may also require that the requests be received a specified number of days in advance of the visit. (B) The contractor can obtain information pertaining to the visit requirements of other governments and the NATO from the CSA. The contractor must obtain an export authorization if classified export controlled articles or technical data is to be disclosed or if information to be divulged is related to a classified USG program, unless the disclosure of the information is covered by other agreements, authorizations, or exemptions. (iii) Request format. (iv) Government agency programs. (v) Requests for emergency visits. (A) The complete name, position, address, and telephone number of the person to be visited. (B) A knowledgeable foreign government point of contact. (C) The identification of the contract, agreement, or program and the justification for submission of the emergency visit request. (vi) Requests for recurring visits. (vii) Amendments. (B) The contractor cannot amend visit requests to specify dates that are earlier than originally specified. (C) The contractor cannot amend emergency visit authorizations. (3) Classified visits by foreign nationals to U.S. contractors Requests for classified visits. (ii) USG approval. (A) USG-Approved Visits. 1 ( 2 ( 3 (B) Visit request denials. 1 ( 2 (C) Non-sponsorship. i.e., ( 1 ( 2 (D) Visits to subsidiaries. (E) Long-term classified visits and assignments of foreign nationals. e.g., ( 1 ( 2 ( 3 (4) Control of foreign visitors to U.S. contractors Contractor. (A) Establish procedures to ensure that foreign visitors are not afforded access to classified information except as authorized by an export license, approved visit request, or other exemption to the licensing requirements. (B) Not inform the foreign visitor of the scope of access authorized or of the limitations imposed by the government. (ii) Foreign visitors. (iii) Visitor records. (iv) Temporary approval of safeguarding. (B) This does not preclude the contractor from furnishing a foreign visitor with a security container for the temporary storage of classified material, consistent with the purpose of the visit or assignment, provided the CSA approves and responsibility for the container and its contents remains with the U.S. contractor. ( 1 ( 2 (v) TCP. (f) Contractor operations abroad Access by contractor employees assigned outside the United States. (ii) The assignment of an employee who is a non-U.S. citizen outside the United States on programs that will involve access to classified information is prohibited. (2) Storage, custody, and control of classified information abroad by contractor employees. (ii) A contractor employee may be furnished a security container to temporarily store classified material at a USG agency overseas location. The decision to permit a contractor to temporarily store classified information must be approved in writing by the senior security official for the USG host organization. (iii) A contractor employee may be permitted to temporarily remove classified information from an overseas USG-controlled facility when necessary for the performance of a GCA contract or pursuant to an approved export authorization. (A) The responsible USG security official at the facility will verify that the contractor has an export authorization or other written USG approval to have the material, verify the need for the material to be removed from the facility, and brief the employee on handling procedures. ( 1 ( 2 (B) The security office at the USG facility will report violations of this policy to the applicable CSA. (iv) A contractor employee will not store classified information at overseas divisions or subsidiaries of U.S. entities incorporated or located in a foreign country. (A) The divisions or subsidiaries may possess classified information that has been transferred to the applicable foreign government through government-to-government channels pursuant to an approved export authorization or other written USG authorization. (B) Access to this classified information at such locations by a U.S. contractor employee assigned abroad by the parent facility on a visit authorization in support of a foreign government contract or subcontract, is governed by the laws and regulations of the country in which the division or subsidiary is registered or incorporated. The division or subsidiary that has obtained the information from the foreign government will provide the access. (v) U.S. contractor employees assigned to foreign government or foreign contractor locations under a direct commercial sales arrangement will be subject to the host-nation's industrial security policies. (3) Transmission of classified material to employees abroad. (i) If the material is to be used for other than USG purposes, an export authorization is required and a copy of the authorization, validated by the DGR, will accompany the material. The material will be addressed to a U.S. military organization or other USG organization ( e.g., (ii) USG organization abroad will be responsible for custody and control of the material. (4) Security briefings. (g) NATO information security requirements General. http://archives.nato.int/informationobject/browse?topLod=0&query=United+States+Security+Authority+for+NATO+Affairs+Instruction+1-07 (2) NATO security classification levels. Table 1 to Paragraph ( g NATO security classification Classification level COSMIC TOP SECRET Top Secret. NATO SECRET Secret. NATO CONFIDENTIAL Confidential. NATO RESTRICTED 1 Does not correspond to an equivalent U.S. classification. 1 (3) ATOMAL Classification Markings. Table 2 to Paragraph ( g ATOMAL marking Classification level COSMIC TOP SECRET ATOMAL Top Secret. NATO SECRET ATOMAL Secret. NATO CONFIDENTIAL ATOMAL Confidential. (4) NATO contracts. e.g., (5) NATO facility security clearance certificate (FSCC). (i) A U.S. entity qualifies for a NATO FSCC if it has an equivalent U.S. entity eligibility determination and its personnel have been briefed on NATO procedures. (ii) The CSA will provide the NATO FSCC to the requesting activity. (iii) A NATO FSCC is not required for GCA contracts involving access to NATO classified information. (6) Eligibility for personnel access to classified information. (7) NATO briefings. (i) When access to NATO classified information is no longer required, the contractor will debrief the employees. The employees will sign a certificate stating that they have been briefed or debriefed, as applicable, and acknowledge their responsibility for safeguarding NATO information. (ii) The contractor will maintain certificates for two years for NATO SECRET and CONFIDENTIAL, and three years for COSMIC TOP SECRET and all ATOMAL information. The contractor will maintain a record of all NATO briefings and debriefings in the CSA-designated database. (8) Access to NATO classified information by foreign nationals. (i) Requests will be submitted to the Central U.S. Registry (CUSR). (ii) Access to NATO classified information may be permitted for citizens of NATO member nations, provided a NATO security clearance certificate is provided by their government and they have been briefed. (9) Subcontracting for NATO contracts. (10) Preparing and marking NATO documents. (i) All U.S.-originated NATO classified documents will bear an assigned reference number and date on the first page. The reference numbers will be assigned as follows: (A) The first element will be the abbreviation for the name of the contractor. (B) The second element will be the abbreviation for the highest classification followed by a hyphen and the 4-digit sequence number for the document within that classification that has been generated for the applicable calendar year. (C) The third element will be the year; e.g., (ii) COSMIC TOP SECRET, NATO SECRET, and ATOMAL documents will bear the reference number on each page and a copy number on the cover or first page. (A) Copies of NATO documents will be serially numbered. (B) Pages will be numbered. (C) The first page, index, or table of contents will include a list, including page numbers, of all annexes and appendices. (D) The total number of pages will be stated on the first page. (E) All annexes or appendices will include the date of the original document and the purpose of the new text (addition or substitution) on the first page. (iii) One of the following markings will be applied to NATO documents that contain ATOMAL information: (A) “This document contains U.S. ATOMIC Information (RESTRICTED DATA or FORMERLY RESTRICTED DATA) made available pursuant to the NATO Agreement for Cooperation Regarding ATOMIC Information, dated 18 June 1964, and will be safeguarded accordingly.” (B) “This document contains UK ATOMIC Information. This information is released to NATO including its military and civilian agencies and member states on condition that it will not be released by the recipient organization to any other organization or government or national of another country or member of any other organization without prior permission from H.M. Government in the United Kingdom.” (iv) Working papers will be retained only until a final product is produced and in accordance with § 117.15(e)(3). (11) Classification guidance. (i) If adequate classification guidance is not received, the contractor will contact the CSA for assistance. (ii) NATO classified documents and NATO information in other documents will not be declassified or downgraded without the prior written consent of the originating activity. (iii) Recommendations concerning the declassification or downgrading of NATO classified information will be forwarded to the CUSR. (12) Further distribution. (13) Storage of NATO documents. (i) NATO classified documents will not be comingled with other documents. (ii) Combinations for containers used to store NATO classified information will be changed annually. The combination also will be changed when an individual with access to the container departs or no longer requires access to the container, and if the combination is suspected of being compromised. (iii) When the combination is recorded it will be marked with the highest classification level of documents stored in the container as well as to indicate the level and type of NATO documents in the container. The combination record must be logged and controlled in the same manner as NATO classified documents. (14) International transmission. (i) The CUSR establishes sub registries at USG organizations for further distribution and control of NATO documents. Sub registries may establish control points at contractor facilities. (ii) COSMIC TOP SECRET, NATO SECRET, and all ATOMAL documents will be transferred through the registry system. NATO CONFIDENTIAL documents provided as part of NATO infrastructure contracts will be transmitted via government channels in compliance with paragraph (d) in this section. (15) Hand carrying. (16) Reproduction. (17) Disposition. (ii) NATO classified documents may also be destroyed when permitted. COSMIC TOP SECRET and COSMIC TOP SECRET ATOMAL documents will be destroyed by the registry that provided the documents. (A) Destruction certificates are required for all NATO classified documents except NATO CONFIDENTIAL. (B) The destruction of COSMIC TOP SECRET, NATO SECRET, and all ATOMAL documents must be witnessed. (18) Accountability records. (i) COSMIC TOP SECRET and all ATOMAL documents will be recorded on logs maintained separately from other NATO logs and will be assigned unique serial control numbers. (ii) Additionally, disclosure records bearing the name and signature of each person who has access are required for all COSMIC TOP SECRET, COSMIC TOP SECRET ATOMAL, and all other ATOMAL or NATO classified documents to which special access limitations have been applied. (iii) Minimum identifying data on logs, receipts, and destruction certificates will include the NATO reference number, short title, date of the document, classification, and serial copy numbers. Logs will reflect the short title, unclassified subject, and distribution of the documents. (iv) Receipts are required for all NATO classified documents except NATO CONFIDENTIAL. (v) Inventories will be conducted annually of all COSMIC TOP SECRET, NATO SECRET, and ATOMAL documents. (vi) Accountability records for ATOMAL documents will be retained for 10 years after transfer or destruction of the ATOMAL document. Destruction certificates will be retained for 10 years after destruction of the related ATOMAL documents. (19) Security violations and loss, compromise, or possible compromise. (20) Extracting from NATO documents. (i) If extracts of NATO information are included in a U.S. document prepared for a non-NATO contract, the document will be marked with U.S. classification markings. The caveat, “THIS DOCUMENT CONTAINS NATO (level of classification) INFORMATION” also will be marked on the front cover or first page of the document. Additionally, each paragraph or portion containing the NATO information will be marked with the appropriate NATO classification, abbreviated in parentheses ( e.g., (ii) The declassification or downgrading of NATO information in a U.S. document requires the approval of the originating NATO activity. Requests will be submitted to the CUSR for NATO contracts, through the GCA for U.S. contracts, and through the CSA for non-NATO contracts awarded by a NATO member nation. (21) Release of U.S. information to NATO. (A) Documents containing U.S. classified information and U.S. classified documents that are authorized for release to NATO will be marked on the cover or first page “THIS DOCUMENT CONTAINS U.S. CLASSIFIED INFORMATION. THE INFORMATION IN THIS DOCUMENT HAS BEEN AUTHORIZED FOR RELEASE TO (cite the NATO organization) BY (cite the applicable license or other written authority).” (B) The CSA will provide transmission instructions to the contractor. The material will be addressed to a U.S. organization at NATO, which will then place the material into NATO security channels. The material will be accompanied by a letter to the U.S. organization that provides transfer instructions and assurances that the material has been authorized for release to NATO. The inner wrapper will be addressed to the intended NATO recipient. (C) Material to be sent to NATO via mail will be routed through the U.S. Postal Service and U.S. military postal channels to the U.S. organization that will make the transfer. (ii) A record will be maintained that identifies the originator and source of classified information that are used in the preparation of documents for release to NATO. The record will be provided with any request for release authorization. (22) Visits. (i) NPLO and NATO industrial advisory group (NIAG) recurring visits. (ii) Visitor record. (h) Security and export control violations involving foreign nationals. (i) Transfers of defense articles to the UK or AUS without a license or other written authorization Treaties with AUS and UK. (i) The Treaties provide a comprehensive framework for exports and transfers to the UK or AUS of certain classified and unclassified defense articles without a license or other written authorization. (ii) The ITAR part 126, supplement no. 1 identifies those defense articles and services that are not eligible for export via treaty exemptions. (iii) This exemption applies to contractors registered with the DDTC and eligible to export defense articles. (2) Defense articles. (i) U.S. and UK or U.S. and AUS combined military or counter-terrorism operations. (ii) U.S. and UK or U.S. and AUS cooperative security and defense research, development, production, and support programs. (iii) Mutually agreed specific security and defense projects where the government of the UK or AUS is the end-user. (iv) USG end-use. (3) Marking requirements. Table 3 to Paragraph ( i UNCLASSIFIED: CLASSIFICATION MARKINGS FOR ILLUSTRATION PURPOSES ONLY Treaty with: Marking Example Government of UK //CLASSIFICATION LEVEL USML/REL GBR AND USA TREATY COMMUNITY// //SECRET USML//REL GBR AND USA TREATY COMMUNITY//” Government of AUS //CLASSIFICATION LEVEL USML/REL AUS AND USA TREATY COMMUNITY// //SECRET USML//REL AUS AND USA TREATY COMMUNITY//” Table 4 to Paragraph ( i UNCLASSIFIED: CLASSIFICATION MARKINGS FOR ILLUSTRATION PURPOSES ONLY Treaty with: Marking Government of UK //RESTRICTED-USML//REL GBR AND USA TREATY COMMUNITY// Government of AUS //RESTRICTED-USML//REL AUS AND USA TREATY COMMUNITY// (4) Notice. e.g., Table 5 to Paragraph ( i Notice text These U.S. Munitions List commodities are authorized by the U.S. Government under the U.S. [AUS or UK, as applicable] Defense Trade Cooperation Treaty for export only to [AUS or UK, as applicable] for use in approved projects, programs or operations by members of the [AUS or UK, as applicable] Community. They may not be retransferred or re-exported or used outside of an approve project, program, or operation, either in their original form or after being incorporated into other end-items, without the prior written approval of the U.S. Department of State. (5) Labeling. e.g., (ii) Technical data (including data packages, technical papers, manuals, presentations, specifications, guides and reports), regardless of media or means of transmission ( i.e., (iii) Defense services will be accompanied by documentation ( e.g. (6) Transfers. (ii) For transfers of defense articles as freight, the contractor will prepare a transportation plan. For transfer of classified U.S. defense articles, a freight forwarder must have a valid entity eligibility determination and a classified information storage capability at the appropriate level. For unclassified U.S. defense articles transferred as freight, a freight forwarder is not required to be cleared. (7) Records. (i) Port of entry or exit. (ii) Date and time of export or import. (iii) Method of export or import. (iv) Commodity code and description of the commodity, including technical data. (v) Value of export. (vi) Justification for export under the Treaties. (vii) End-user or end-use. (viii) Identification of all U.S. and foreign parties to the transaction. (ix) How export was marked. (x) Security classification of the export. (xi) All written correspondence with the USG on the export. (xii) All information relating to political contributions, fees, or commissions furnished or obtained, offered, solicited, or agreed upon, as outlined in the ITAR parts 126.16(m) or 126.17(m). (xiii) Purchase order, contract, or letter of intent. (xiv) Technical data actually exported. (xv) The internal transaction number for the electronic export information filing in the automated export system. (xvi) All shipping documentation (including, but not limited to, the airway bill, bill of lading, packing list, delivery verification, and invoice). (xvii) Statement of registration (Department of State Form DS-2032 (available at: https://www.pmddtc.state.gov/sys_attachment.do?sysparm_referring_url=tear_off&view=true&sys_id=dabc05f6db6be344529d368d7c961984 § 117.20 Critical Nuclear Weapon Design Information (CNWDI). (a) General. https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/521002p.pdf?ver=2019-01-14-072742-700 (b) Briefings. (1) The briefing will include: (i) The definition of CNWDI. (ii) A reminder of the extreme sensitivity of the information. (iii) An explanation of the individual's continuing responsibility for properly safeguarding CNWDI and for ensuring that dissemination is strictly limited to other personnel who have been authorized for access and have a need-to-know for the particular information. (2) The briefing will also be tailored to cover any special local requirements. Upon termination of access to CNWDI, the employee will be given an oral debriefing. (c) Markings. (d) Subcontractors. (e) Transmission outside the facility. (1) Prior to transmission to another cleared facility, the contractor will verify from the CSA that the facility has been authorized access to CNWDI. When CNWDI is transmitted to another facility, the inner wrapping will be addressed to the personal attention of the FSO or his or her alternate, and in addition to any other prescribed markings, the inner wrapping will be marked: “Critical Nuclear Weapon Design Information-DoD Instruction 5210.02 Applies.” (2) The same marking will be used on the inner wrapping of transmissions addressed to the GCA or other USG. (f) Records. (g) Nuclear weapon data. https://www.directives.doe.gov/directives-documents/400-series/0452.8-border/@@images/file § 117.21 COMSEC. (a) General. (1) Requires the use of COMSEC systems in the performance of a contract. (2) Is required to install, maintain, or operate COMSEC equipment for the USG. (3) Is required to accomplish research, development, or production of COMSEC systems, COMSEC equipment, or related COMSEC material. (b) Instructions. (c) Clearance and access requirements. (i) COMSEC account managers and alternate COMSEC account managers having access to operational TOP SECRET keying material marked as CRYPTO must have a final TOP SECRET security clearance based upon a current investigation of a scope that meets or exceeds that necessary for the access required. (ii) This requirement does not apply to contractors using only data transfer devices and seed key. (2) Before disclosure of COMSEC information to a contractor, GCAs must first verify with the CSA that appropriate COMSEC procedures are in place at the contractor facility. If procedures are not in place, the GCA will provide a written request and justification to the CSA to establish COMSEC procedures and a COMSEC account, if appropriate, at the facility and to conduct the initial COMSEC or cryptographic access briefings for the FSO and COMSEC account personnel. (3) Access to COMSEC information by a contractor requires a final entity eligibility determination and a USG-issued final PCL at the appropriate level; however, an Interim TOP SECRET entity eligibility determination or PCL is valid for access to COMSEC at the SECRET and CONFIDENTIAL levels. (4) If a COMSEC account will be required, the Contract Security Classification Specification, or equivalent, will contain a statement regarding the establishment of a COMSEC account as appropriate. (d) Establishing a COMSEC account. (2) The COR will then establish the COMSEC account and notify the CSA that the account has been established. (3) An individual may be appointed as the COMSEC account manager or alternate COMSEC account manager for more than one account only when approved by each COR concerned. (e) COMSEC briefing and debriefing. (i) The unique nature of COMSEC information and its unusual sensitivity. (ii) The special security requirements for the handling and protection of COMSEC information. (iii) The penalties prescribed in 18 U.S.C. 793, 794, and 798 for disclosure of COMSEC information. (2) COMSEC debriefings are not required. (3) The contractor will maintain a record of all COMSEC briefings as specified by the appropriate COR. (f) U.S. classified cryptographic information access briefing and debriefing requirements. (2) A contractor's employee may be granted access to U.S. classified cryptographic information only if the employee: (i) Is a U.S. citizen. (ii) Has a final USG-issued eligibility determination appropriate to the classification of the U.S. cryptographic information to be accessed. (iii) Has a valid need-to-know to perform duties for, or on behalf of, the USG. (iv) Receives a security briefing appropriate to the U.S. Classified Cryptographic Information to be accessed. (v) Acknowledges the granting of access to classified information by executing Section I of Secretary of Defense (SD) Form 572, “Cryptographic Access Certification and Termination” (available at: https://www.esd.whs.mil/Portals/54/Documents/DD/forms/sd/sd0572.pdf (vi) Where so directed by a USG department or agency head, acknowledges the possibility of being subject to a CI scope polygraph examination that will be administered in accordance with department or agency directives and applicable law. (3) An employee granted access to cryptographic information will be debriefed and execute Section II of the SD 572 not later than 90 days from the date access is no longer required. (4) The contractor will maintain the SD 572 for a minimum of five years following the debriefing. (5) Cryptographic access briefings must fully meet the requirements of paragraph (e) of this section. (g) Destruction and disposition of COMSEC material. e.g., (h) Subcontracting COMSEC work. (i) Unsolicited proposals. § 117.22 DHS CCIPP. (a) General. (b) Authority. (2) DHS provides security oversight and assumes security responsibilities similar to those of an FSO, unless otherwise provided in this section. Participating entities will cooperate with DHS security officials to ensure the entity is in compliance with requirements in this rule. § 117.23 Supplement to this rule: Security Requirements for Alternative Compensatory Control Measures (ACCM), Special Access Programs (SAPs), Sensitive Compartmented Information (SCI), Restricted Data (RD), Formerly Restricted Data (FRD), Transclassified Foreign Nuclear Information (TFNI), and Naval Nuclear Propulsion Information (NNPI). (a) General. (1) Compliance. e.g., (2) CSA-imposed higher standards. (3) Waivers. (b) Intelligence information. (c) ACCM. (1) ACCM contracts. (2) Non-DoD with ACCMs. (d) SAPs DoD SAP contracts. (2) Non-DoD SAPs. (e) RD, FRD, and TFNI General. (i) The DOE is the sole authority for establishing requirements for classifying, accessing, handling, securing, and protecting RD. The DOE and the DoD share authority for the requirements for FRD. The DOE and ODNI share authority for establishing requirements for TFNI. (ii) RD, FRD, and TFNI categories are distinguished from the NSI category, which is governed in accordance with E.O. 13526. (A) RD, FRD, and TFNI have unique marking requirements and are not subject to automatic declassification. In addition, RD and FRD have special restrictions regarding foreign release. (B) It is necessary to differentiate between the handling of this information and NSI because of its direct relationship to our nation's nuclear deterrent. (iii) Some access requirements for RD and FRD exceed the requirements for NSI. Due to the unique national security implications of RD and FRD, and to facilitate maintaining consistency of codified requirement, they are not repeated in the baseline of this rule, but may be applied through specific contract requirements. (iv) When RD is transclassified as TFNI, it is safeguarded as NSI. Such information will be labeled as TFNI. The label TFNI will be included on documents to indicate it is exempt from automatic declassification as specified in 10 CFR part 1045, the AEA, E.O. 13526, and 32 CFR part 2001. (2) Unauthorized disclosures. (3) International requirements. (i) Information controlled in accordance with the AEA, RD, and FRD may be shared with another nation only under the terms of an agreement for cooperation. The disclosure by a contractor of RD and FRD will not be permitted until an agreement is signed by the United States and participating governments, and disclosure guidance and security arrangements are established. (ii) RD and FRD will not be transmitted to a foreign national or regional defense organization unless such action is approved and undertaken under an agreement for cooperation between the United States and the cooperating entity and supporting statutory determinations, as prescribed in the AEA. (4) Personnel security clearance and access. (5) Classification and declassification. (A) What information is potentially RD and FRD. (B) Matter that potentially contains RD or FRD must be reviewed by an RD derivative classifier to determine whether it is RD or FRD. (C) The DOE must review matter that potentially contains RD or TFNI for public release and DOE or DoD must review matter that potentially contains FRD for public release. (D) RD derivative classification authority is required to classify or upgrade matter containing RD or FRD, or to downgrade the level of matter containing RD or FRD. (E) Only a person trained in accordance with § 1045.120 10 CFR may classify matter containing TFNI. (F) Matter containing RD, FRD, and TFNI is not automatically declassified and only DOE-authorized persons may downgrade the category or declassify matter marked as containing RD. Only DOE or DoD authorized persons may downgrade the category or declassify matter marked as containing FRD. (G) How to submit a challenge if they believe RD, FRD, or TFNI information ( e.g., (H) Access requirements for matter marked as containing RD or FRD. (ii) All persons with access to TFNI must receive initial and periodic refresher training as required under § 1045.120 10 CFR. This training may be combined with the training for access to RD and FRD. The training must include the following information: (A) What information is potentially TFNI. (B) Only a person with appropriate training may determine if matter contains TFNI. (C) Marking requirements for matter containing TFNI. (D) Matter containing TFNI is not automatically declassified and only DOE authorized persons may downgrade the category or declassify matter marked as containing TFNI. (E) How to submit a challenge if they believe TFNI information ( e.g., (iii) Persons with access to RD, FRD, or TFNI must submit matter that potentially contains RD or FRD to an RD derivative classifier for review. If matter potentially contains TFNI, it must be submitted to a person trained to make TFNI determinations. Matter potentially containing RD, FRD, or TFNI must be reviewed, even if the potential RD, FRD, or TFNI is derived from the open literature. Prior to review, the matter must be marked as a working paper under 10 CFR 1045.140(c). If the matter is intended for pubic release and potentially contains RD or TFNI, it must be submitted to the DOE for review. If the matter is intended for public release and contains FRD, it must be submitted to the DOE or the DoD. (iv) Only RD derivative classifiers may classify matter containing RD or FRD. RD derivative classifiers must receive initial training and refresher training every two years as required under 10 CFR 1045.120. The training must include the content for persons with access to RD and FRD, along with the following: (A) The use of classification guides, classification bulletins, and portion-marked source documents to classify matter containing RD and FRD. (B) What to do if applicable classification guidance is not available. (C) Limitations on an RD derivative classifier's authority to remove RD or FRD portions from matter. (D) Marking requirements for matter containing RD and FRD. (v) Only persons with appropriate training may review matter to determine if it contains TFNI. Training must be completed prior to making determinations and every two years after. The training must include the content for persons with access to TFNI and the following: (A) The markings applied to matter containing TFNI. (B) Limitations on their authority to remove TFNI portions from matter. (C) Only DOE authorized persons may determine that classified matter no longer contains TFNI. (D) Only DOE-authorized persons may declassify matter marked as containing TFNI. (E) The DOE must review matter that potentially contains TFNI for public release. (vi) RD derivative classifiers must use approved classification guides, classification bulletins, or portion-marked source documents as the basis for classifying matter containing RD and FRD. (vii) Persons trained to make TFNI determinations must use approved TFNI guidelines, classification guides, classification bulletins, or portion-marked source documents as the basis for classifying or upgrade matter containing TFNI. (6) Marking matter containing RD, FRD, and TFNI. (i) Documents classified as RD or FRD must also include a Classification Authority Block with the RD derivative classifier's name and position, title, or unique identifier and the classification guide or source document (by title and date) used to classify the document. No declassification date or event may be placed on a document containing RD, FRD, or TFNI. If a document containing RD, FRD, or TFNI also contains NSI, “N/A to RD/FRD/TFNI” (as appropriate) must be placed on the “Declassify On:” line. (ii) Each interior page of matter containing RD or FRD must be clearly marked at the top and bottom with the overall classification level and category of the matter or the overall classification level and category of the page, whichever is preferred. The abbreviations “RD” or “FRD” may be used in conjunction with the matter classification ( e.g., Table 1 to Paragraph ( e ii Document Admonishment that must be included on the RD “RESTRICTED DATA FRD “FORMERLY RESTRICTED DATA (iii) Documents classified as RD or FRD must also include a Classification Authority Block with the RD derivative classifier's name and position, title, or unique identifier and the classification guide or source document (by title and date) used to classify the document. (iv) Other than the required subject or title markings, portion marking is permitted, but not required, for matter containing RD or FRD. Each agency that generates matter containing RD or FRD determines the policy for portion-marking matter generated within the agency. If matter containing RD or FRD is portion-marked, each portion containing RD or FRD must be marked with the level and category of the information in the portion ( e.g., (v) Additional information and requirements are in 10 CFR 1045.140. Requests for additional information about the classification and declassification of RD, FRD, and TFNI can be directed to Agency RD Management Officials or the DOE Office of Classification at [email protected] (7) Declassification. (ii) RD derivative classifiers may remove RD or FRD from portion-marked source matter if the resulting matter is not for public release. RD derivative classifiers cannot declassify matter marked as containing RD, FRD, and TFNI. Matter that potentially contains RD or TFNI must be sent to designated individuals in the DOE and those containing FRD must be sent to designated individuals in the DoD for declassification or removal of the RD, FRD, or TFNI prior to public release. (iii) Matter containing TFNI is excluded from the automatic declassification provisions of E.O. 13526 until the TFNI designation is properly removed by the DOE. When the DOE determines that a TFNI designation may be removed, any remaining classified information must be referred to the appropriate agency. (iv) Any matter marked as or that potentially contains RD, FRD, or TFNI within a document intended for public release that contains RD or FRD subject area indicators must be reviewed by the appropriate DOE organization. (8) Challenges to RD, FRD, and TFNI. (9) Commingling. (10) Protection of RD and FRD. (i) Any DOE contractor that violates a classified information security requirement may be subject to a civil penalty under the provisions of 10 CFR part 824. (ii) Certification is required for individuals authorized access to specific Sigma categories, as appropriate. Address questions regarding these requirements to DOE's National Nuclear Security Administration, Office of Defense Programs. (iii) Storage and distribution requirements are determined by the classification level, category, and Sigma category. Sigma designation is not a requirement for all RD documents. Storage and distribution requirements will be dependent only on classification level and category. (11) Accountability. e.g., (12) Cybersecurity. (f) NNPI. https://www.secnav.navy.mil/doni/Directives/09000%20General%20Ship%20Design%20and%20Support/09-200%20Propulsion%20Plants%20Support/N9210.3%20(Unclas%20Portion).pdf § 117.24 Cognizant Security Office information. (a) DoD. https://www.dcsa.mil Table 1 to Paragraph ( a Designation Office name Mailing address Telephone No. Headquarters, CSO Defense Counterintelligence and Security Agency 27130 Telegraph Rd., Quantico, VA 22134 (888) 282-7682 (b) DOE. Table 2 to Paragraph ( b Designation Office name Mailing address Telephone No. Headquarters Headquarters Office of Security Operations (AU-40) 19901 Germantown Road, Germantown, MD 20874 (301) 903-2177 CSO, Clearance Agency, Central Verification Activity, Adjudicative Authority, and PCL and FCL databases DOE/National Nuclear Security Administration Office of Personnel and Facility Clearances and Classifications Pennsylvania & H Street, Kirtland Air Force Base, Albuquerque, NM 87116 (505) 845-4154 CSO U.S. Department of Energy, Idaho Operations Office 850 Energy Drive, Idaho Falls, ID 83401 (208) 526-2216 Table 3 to Paragraph ( b Designation Office name Mailing address Telephone No. CSO, Naval Nuclear Propulsion Information Director, Naval Reactors NA-30, 1240 Isaac Hull Ave., SE., Washington Navy Yard, DC 20376 (202) 781-6297 CSO U.S. Department of Energy, Office of Science Consolidated Service Center 200 Administration Road, P.O. Box 2001, Oak Ridge, TN 37830 (865) 576-2140 CSO U.S. Department of Energy, Pacific Northwest Site Office 902 Battelle Boulevard, Richland, WA 99354 (888) 375-7665 CSO U.S. Department of Energy, Richland Operations Office 825 Jadwin Avenue, P.O. Box 550, Richland, WA 99352 (509) 376-7411 CSO U.S. Department of Energy, Savannah River Operations Office Road 1A, Aiken, SC 29801 (803) 725-6211 (c) NRC. Table 4 to Paragraph ( c Designation Mailing address Telephone No. CSO, Adjudicative Authority, PCL and FCL databases, and Industrial Security Program U.S. Nuclear Regulatory Commission, ATTN: Director of Facilities and Security, Washington, DC 20555 (301) 415-8080 CSO, FCL Database and Industrial Security Program for Licensees U.S. Nuclear Regulatory Commission, ATTN: Information Security Branch, 11555 Rockville Pike, Rockville, MD 20853 (301) 415-7048 Clearance Agency U.S. Nuclear Regulatory Commission, ATTN: Director of Facilities and Security Personnel Security, 11545 Rockville Pike, Rockville, MD 20853 (301) 415-8080 Central Verification Agency U.S. Nuclear Regulatory Commission, ATTN: Director of Security Facilities Security, 11545 Rockville Pike, Rockville, MD 20853 (301) 415-8080 (d) DHS. Table 6 to Paragraph ( d Designation Mailing address Telephone No. CSO DHS Cognizant Security Office, ATTN: Chief Security Officer, 245 Murray Lane, M/S 0120-3, Washington, DC 20528 (202) 447-5424;

Related documents

Record · ID 508527 · SHA-256 bd26b7ae3819b9ff
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.