ConceptioArchiveCode of Federal Regulations (eCFR)
Code of Federal Regulations (eCFR)public full text

32 CFR Part 2004 — National Industrial Security Program (NISP)

Office of the Federal Register (NARA) · Code of Federal Regulations (eCFR, Office of the Federal Register)
Code of Federal Regulations (eCFR) · Legal · License: Public Domain
Open Source ↗
nationalnationalarchivesandrecordsadministration
united states, us regulation, us federal regulation, code of federal regulations, cfr, federal regulation, 32, 2004, part 2004, 32 cfr 2004, 32 cfr part 2004, national, defense, information security oversight office, national archives and records administration

PART 2004—NATIONAL INDUSTRIAL SECURITY PROGRAM (NISP) Authority: Section 102(b)(1) of E.O. 12829 (January 6, 1993), as amended by E.O. 12885 (December 14, 1993), E.O. 13691 (February 12, 2015), and section 4 of E.O. 13708 (September 30, 2015). Source: 83 FR 19951, May 7, 2018, unless otherwise noted. Subpart A—Implementation and Oversight § 2004.1 Purpose and scope. (a) This part sets out the National Industrial Security Program (“NISP” or “the Program”) governing the protection of agency classified information released to Federal contractors, licensees, grantees, and certificate holders. It establishes uniform standards throughout the Program, and helps agencies implement requirements in E.O. 12829, National Industrial Security Program, as amended by E.O. 12558 and E.O.13691 (collectively referred to as “E.O. 12829”), E.O. 13691, Promoting Private Sector Cybersecurity Information Sharing, and E.O. 13587, Structural Reforms to Improve the Security of Classified Networks and the Responsible Sharing and Safeguarding of Classified Information. It applies to any executive branch agency that releases classified information to current, prospective, or former Federal contractors, licensees, grantees, or certificate holders. However, this part does not stand alone; users should refer concurrently to the underlying executive orders for guidance. ISOO maintains policy oversight over the NISP as established by E.O.12829. (b) This part also does not apply to release of classified information pursuant to criminal proceedings. The Classified Information Procedures Act (CIPA) (18 U.S.C. Appendix 3) governs release of classified information in criminal proceedings. (c) Nothing in this part supersedes the authority of the Secretary of Energy or the Nuclear Regulatory Commission under the Atomic Energy Act of 1954, as amended (42 U.S.C. 2011, et seq. et seq. § 2004.4 Definitions that apply to this part. (a) Access (b) Agency(ies) (c) Classified Critical Infrastructure Protection Program (CCIPP) Critical Infrastructure Security and Resilience (d) Classified Critical Infrastructure Protection Program (CCIPP) security point of contact (security POC) (e) Classified information (f) Cognizance (g) Cognizant security agencies (CSAs) (h) Cognizant security office (CSO) (i) Contracts or agreements (j) Controlling agency (k) Entity (l) Entity eligibility determination (m) Foreign interest (n) Government contracting activity (GCA) (o) Industrial security services (p) Insider(s) (q) Insider threat (r) Insider threat response action(s) (s) Insider threat program senior official (SO) (t) Key managers and officials (KMO) (u) Proscribed information (v) Security officer (w) Senior agency official for NISP (SAO for NISP) (x) Senior management official (SMO) (y) Sub-entity § 2004.10 Responsibilities of the Director, Information Security Oversight Office (ISOO). The Director, ISOO: (a) Implements E.O. 12829, including ensuring that: (1) The NISP operates as a single, integrated program across the executive branch of the Federal Government ( i.e., (2) A responsible CSA oversees each entity's NISP implementation in accordance with § 2004.22; (3) All agencies that contract for classified work include the Security Requirements clause, 48 CFR 52.204-2, from the Federal Acquisition Regulation (FAR), or an equivalent clause, in contracts that require access to classified information; (4) Those agencies for which the Department of Defense (DoD) serves as the CSA or provides industrial security services have agreements with DoD defining the Secretary of Defense's responsibilities on behalf of their agency; (5) Each CSA issues directions to entities under their cognizance that are consistent with the NISPOM insider threat guidance; (6) CSAs share with each other, as lawful and appropriate, relevant information about entity employees that indicates an insider threat; and (7) CSAs conduct ongoing analysis and adjudication of adverse or relevant information about entity employees that indicates an insider threat. (b) Raises an issue to the National Security Council (NSC) for resolution if the EA's NISPOM coordination process cannot reach a consensus on NISPOM security standards (see § 2004.20(d)). § 2004.11 CSA and agency implementing regulations, internal rules, or guidelines. (a) Each CSA implements NISP practices in part through policies and guidelines that are consistent with this regulation, so that agencies for which it serves as the CSA are aware of appropriate security standards, engage in consistent practices with entities, and so that practices effectively protect classified information those entities receive (including foreign government information that the U.S. Government must protect in the interest of national security). (b) Each CSA must also routinely review and update its NISP policies and guidelines and promptly issue revisions when needed (including when a change in national policy necessitates a change in agency NISP policies and guidelines). (c) Non-CSA agencies may choose to augment CSA NISP policies or guidelines as long as the agency policies or guidelines are consistent with the CSA's policies or guidelines and this regulation. § 2004.12 ISOO review of agency NISP implementation. (a) ISOO fulfills its oversight role based, in part, on information received from NISP Policy Advisory Committee (NISPPAC) members, from on-site reviews that ISOO conducts under the authority of E.O. 12829, and from any submitted complaints and suggestions. ISOO reports findings to the responsible CSA or agency. (b) ISOO reviews agency policies and guidelines to ensure consistency with NISP policies and procedures. ISOO may conduct reviews during routine oversight visits, when a problem or potential problem comes to ISOO's attention, or after a change in national policy that impacts agency policies and guidelines. ISOO provides the responsible agency with findings from these reviews. Subpart B—Administration § 2004.20 National Industrial Security Program Executive Agent and Operating Manual. (a) The executive agent (EA) for NISP is the Secretary of Defense. The EA: (1) Provides industrial security services for agencies that are not CSAs but that release classified information to entities. The EA provides industrial security services only through an agreement with the agency. Non-CSA agencies must enter an agreement with the EA and comply with EA industrial security service processes before releasing classified information to an entity; (2) Provides services for other CSAs by agreement; and (3) Issues and maintains the National Industrial Security Program Operating Manual (NISPOM) in consultation with all affected agencies and with the concurrence of the other CSAs. (b) The NISPOM sets out the procedures and standards that entities must follow during all phases of the contracting process to safeguard any classified information an agency releases to an entity. The NISPOM requirements may apply to the entity directly ( i.e., (c) The EA, in consultation with all affected agencies and with the concurrence of the other CSAs, develops the requirements, restrictions, and safeguards contained in the NISPOM. The EA uses security standards applicable to agencies as the basis for developing NISPOM entity standards to the extent practicable and reasonable. (d) The EA also facilitates the NISPOM coordination process, which addresses issues raised by entities, agencies, ISOO, or the NISPPAC, including requests to create or change NISPOM security standards. § 2004.22 Agency responsibilities. (a) Agency categories and general areas of responsibility. (1) CSAs. (2) Non-CSA agencies. (3) Agencies that are components of another agency. (b) Responsible CSA role. (2) In general, the goal is to have one responsible CSA for each agency and for each entity, to minimize the burdens that can result from complying with differing CSA procedures and requirements. (i) With regard to agencies, NISP accomplishes this goal by a combination of designated CSAs and agreements between agencies and CSAs. (ii) With regard to entities, CSAs strive to reduce the number of responsible CSAs for a given entity as much as possible. To this end, when more than one CSA releases classified information to a given entity, those CSAs agree on which is the responsible CSA. However, due to certain unique agency authorities, there may be circumstances in which a given entity is under the oversight of more than one responsible CSA. (3) Responsible CSA for agencies: (i) In general, each CSA serves as the responsible CSA for classified information that it (or any of its component agencies) releases to entities, unless it enters an agreement otherwise with another CSA. (ii) DoD serves as the responsible CSA for DHS with the exception of the CCIPP, based on an agreement between the two CSAs. (iii) DoD serves as the responsible CSA on behalf of all non-CSA agencies, except CSA components, based on E.O. 12829 and its role as NISP EA. (iv) ODNI serves as the responsible CSA for CIA. (4) Responsible CSA for entities: When determining the responsible CSA for a given entity, the involved CSAs consider, at a minimum: retained authorities, the information's classification level, number of contracts requiring access to classified information, location, number of Government customers, volume of classified activity, safeguarding requirements, responsibility for entity employee eligibility determinations, and any special requirements. (5) Responsible CSAs may delegate oversight responsibility to a cognizant security office (CSO) through CSA policy or by written delegation. The CSA must inform entities under its cognizance if it delegates responsibilities. For purposes of this rule, the term CSA also refers to the CSO. (c) CSA responsibilities. (2) As CSA, the CSA performs or delegates the following responsibilities: (i) Designates a CSA senior agency official (SAO) for NISP; (ii) Identifies the insider threat program senior official (SO) to the Director, ISOO; (iii) Shares insider threat information with other CSAs, as lawful and appropriate, including information that indicates an insider threat about entity employees eligible to access classified information; (iv) Acts upon and shares—with security management, GCAs, insider threat program employees, and Government program and CI officials—any relevant entity-reported information about security or CI concerns, as appropriate; (v) Submits reports to ISOO as required by this part; and (vi) Develops, coordinates, and provides concurrence on changes to the NISPOM when requested by the EA. (3) As a responsible CSA, the CSA also performs or delegates the following responsibilities: (i) Determines whether an entity is eligible for access to classified information (see § 2004.32); (ii) Allocates funds, ensures appropriate investigations are conducted, and determines entity employee eligibility for access to classified information (see § 2004.36); (iii) Reviews and approves entity safeguarding measures, including making safeguarding capability determinations (see § 2004.38); (iv) Conducts periodic security reviews of entity operations (see § 2004.26) to determine that entities: effectively protect classified information provided to them; and follow NISPOM (or equivalent) requirements; (v) Provides and regularly updates guidance, training, training materials, and briefings to entities on: (A) Entity implementation of NISPOM (or equivalent) requirements, including: responsibility for protecting classified information, requesting NISPOM interpretations, establishing training programs, and submitting required reports; (B) Initial security briefings and other briefings required for special categories of information; (C) Authorization measures for information systems processing classified information (except DHS) (see § 2004.40); (D) Security training for security officers (or CCIPP POCs) and other employees whose official duties include performing NISP-related functions; (E) Insider threat programs in accordance with the National Insider Threat Policy and Minimum Standards for Executive Branch Insider Threat Programs; and (F) Other guidance and training as appropriate; (vi) Establishes a mechanism for entities to submit requests for waivers to NISPOM (or equivalent) provisions; (vii) Reviews, continuously analyzes, and adjudicates, as appropriate, reports from entities regarding events that: (A) Impact the status of the entity's eligibility for access to classisfied information; (B) Impact an employee's eligibility for access; (C) May indicate an employee poses an insider threat; (D) Affect proper safeguarding of classified information; or (E) Indicate that classified information has been lost or compromised; (viii) Verifies that reports offered in confidence and so marked by an entity may be withheld from public disclosure under applicable exemptions of the Freedom of Information Act (5 U.S.C. 552); (ix) Requests any additional information needed from an entity about involved employees to determine continued eligibility for access to classified information when the entity reports loss, possible compromise, or unauthorized disclosure of classified information; and (x) Posts hotline information on its website for entity access, or otherwise disseminates contact numbers to the entities for which the CSA is responsible. (d) Non-CSA agency head responsibilities. (1) Designates an SAO for the NISP; (2) Identifies the insider threat program SO to ISOO to facilitate information sharing; (3) Enters into an agreement with the EA (except agencies that are components of another agency or a cross-agency oversight office) to act as the responsible CSA on the agency's behalf (see paragraph (a)(1)(ii) of this section); (4) Performs, or delegates in writing to a GCA, the following responsibilities: (i) Provides appropriate education and training to agency personnel who implement the NISP; (ii) Includes FAR security requirements clause 52.204-2, or equivalent (such as the DEAR clause 952.204-2), and a contract security classification specification (or equivalent guidance) into contracts and solicitations that require access to classified information (see § 2004.30); and (iii) Reports to the appropriate CSA adverse information and insider threat activity pertaining to entity employees having access to classified information. § 2004.24 Insider threat program. (a) Responsible CSAs oversee and analyze entity activity to ensure entities implement an insider threat program in accordance with the National Insider Threat Policy and Minimum Standards for Executive Branch Insider Threat Programs (via requirements in the NISPOM or its equivalent) and guidance from the CSA. CSA oversight responsibilities include, but are not limited to: (1) Verifying that entities appoint insider threat program SOs; (2) Requiring entities to monitor, report, and review insider threat program activities and response actions in accordance with the provisions set forth in the NISPOM (or equivalent); (3) Providing entities with access to data relevant to insider threat program activities and applicable reporting requirements and procedures; (4) Providing entities with a designated means to report insider threat-related activity; and (5) Advising entities on appropriate insider threat training for entity employees eligible for access to classified information. (b) CSAs share with other CSAs any insider threat information reported to them by entities, as lawful and appropriate. § 2004.26 Reviews of entity NISP implementation. (a) The responsible CSA conducts recurring oversight reviews of entities' NISP security programs to verify that the entity is protecting classified information and is implementing the provisions of the NISPOM (or equivalent). The CSA determines the scope and frequency of reviews. The CSA generally notifies entities when a review will take place, but may also conduct unannounced reviews at its discretion. (b) CSAs make every effort to avoid unnecessarily intruding into entity employee personal effects during the reviews. (c) A CSA may, on entity premises, physically examine the interior spaces of containers not authorized to store classified information in the presence of the entity's representative. (d) As part of a security review, the CSA: (1) Verifies that the entity limits entity employees with access to classified information to the minimum number necessary to perform on contracts requiring access to classified information. (2) Validates that the entity has not provided its employees unauthorized access to classified information; (3) Reviews the entity's self-inspection program and evaluates and records the entity's remedial actions; and (4) Verifies that the GCA approved any public release of information pertaining to a contract requiring access to classified information. (e) As a result of findings during the security review, the CSA may, as appropriate, notify: (1) GCAs if there are unfavorable results from the review; and (2) A prime entity if the CSA discovers unsatisfactory security conditions pertaining to a sub-entity. (f) The CSA maintains a record of reviews it conducts and the results. Based on review results, the responsible CSA determines whether an entity's eligibility for access to classified information may continue. See § 2004.32(g). § 2004.28 Cost reports. (a) Agencies must annually report to the Director, ISOO, on their NISP implementation costs for the previous year. (b) CSAs must annually collect information on NISP implementation costs incurred by entities under their cognizance and submit a report to the Director, ISOO. Subpart C—Operations § 2004.30 Security classification requirements and guidance. (a) Contract or agreement and solicition requirements. (2) The GCA must also include a contract security classification specification (or equivalent guidance) with each contract or agreement and solicitation that requires access to classified information. The contract security classification specification (or equivalent guidance) must identify the specific elements of classified information involved in each phase of the contract or agreement life-cycle, such as: (i) Level of classification; (ii) Where the entity will access or store the classified information, and any requirements or limitations on transmitting classified information outside the entity; (iii) Any special accesses; (iv) Any classification guides or other guidance the entity needs to perform during that phase of the contract or agreement; (v) Any authorization to disclose information about the contract or agreement requiring access to classified information; and (vi) GCA personnel responsible for interpreting and applying the contract security specifications (or equivalent guidance). (3) The GCA revises the contract security classification specification (or equivalent guidance) throughout the contract or agreement life-cycle as security requirements change. (b) Guidance. (c) Requests for clarification and classification challenges. (2) The responsible CSA assists entities to obtain appropriate classification guidance from the GCA, and to obtain a classification challenge response from the GCA. (d) Instructions upon contract or agreement completion or termination. (2) The GCA also determines whether the entity may retain classified information for particular purposes after the contract or agreement terminates, and if so, provides written authorization to the entity along with any instructions or limitations (such as which information, for how long, etc). § 2004.32 Determining entity eligibility for access to classified information. (a) Eligibility determinations. (2) A favorable access eligibility determination is not the same as a safeguarding capability determination. Entities may access classified information with a favorable eligibility determination, but may possess classified information only if the CSA determines both access eligibility and safeguarding capability, based on the GCA's requirement in the contract security classification specification (or equivalent). (3) If an entity has an existing eligibility determination, a CSA will not duplicate eligibility determination processes performed by another CSA. If a CSA cannot acknowledge an entity eligibility determination to another CSA, that entity may be subject to duplicate processing. (4) Each CSA maintains a record of its entities' eligibility determinations (or critical infrastructure entity eligibility status under the CCIPP, for DHS) and responds to inquiries from GCAs or entities, as appropriate and to the extent authorized by law, regarding the eligibility status of entities under their cognizance. (b) Process. (2) The CSA coordinates with appropriate authorities to determine whether an entity meets the eligibility criteria in paragraph (e) of this section. This includes coordinating with appropriate U.S. Government regulatory authorities to determine entity compliance with laws and regulations. (3) An entity cannot apply for its own eligibility determination. A GCA or an eligible entity must sponsor the entity to the responsible CSA for an eligibility determination. The GCA or eligible entity may sponsor an entity at any point during the contracting or agreement life-cycle at which the entity must have access to classified information to participate (including the solicitation or competition phase). An entity with limited eligibility granted under paragraph (f) of this section may sponsor a sub-entity for a limited eligibility determination for the same contract, agreement, or circumstance so long as the sponsoring entity is not under FOCI (see § 2004.34(i)). (4) The GCA must include enough lead time in each phase of the acquisition or agreement cycle to accomplish all required security actions. Required security actions include any eligibility determination necessary for an entity to participate in that phase of the cycle. The GCA may award a contract or agreement before the CSA completes the entity eligibility determination. However, in such cases, the entity may not begin performance on portions of the contract or agreement that require access to classified information until the CSA makes a favorable entity eligibility determination. (5) When a CSA is unable to make an eligibility determination in sufficient time to qualify an entity to participate in the particular procurement action or phase that gave rise to the GCA request (this includes both solicitation and performance phases), the GCA may request that the CSA continue the determination process to qualify the entity for future classified work for any GCA, provided that the processing delay was not due to the entity's lack of cooperation. Once the CSA determines that an entity is eligible for access to classified information, but a GCA does not award a contract or agreement requiring access to classified information to the entity, or the entity's eligibility status changes, the CSA terminates the entity eligibility determination in accordance with paragraph (g) of this section. (c) Coverage. (2) The CSA must ensure that all entities needing access to classified information as part of a legitimate U.S. or foreign government requirement have or receive a favorable eligibility determination before accessing classified information. This includes both prime or parent entities and sub-entities, even in cases in which an entity intends to have the classified work performed only by sub-entities. A prime or parent entity must have a favorable eligibility determination at the same classification level or higher than its sub-entity(ies), unless the CSA determined that the parent entity could be effectively excluded from access (see paragraph (a)(1) of this section). (3) If a parent and sub-entity need to share classified information with each other, the CSA must validate that both the parent and the sub-entity have favorable eligibility determinations at the level required for the classified information prior to sharing the information. (d) DHS Classified Critical Infrastructure Protection Program (CCIPP). (e) Eligibility criteria. (1) It must need to access classified information as part of a legitimate U.S. Government or foreign government requirement, and access must be consistent with U.S. national security interests as determined by the CSA; (2) It must be organized and existing under the laws of any of the 50 States, the District of Columbia, or an organized U.S. territory (Guam, Commonwealth of the Northern Marianas Islands, Commonwealth of Puerto Rico, and the U.S. Virgin Islands); or an American Indian or Alaska native tribe formally acknowledged by the Assistant Secretary—Indian Affairs, of the U.S. Department of the Interior; (3) It must be located in the United States or its territorial areas; (4) It must have a record of compliance with pertinent laws, regulations, and contracts (or other relevant agreements); (5) Its KMOs must each have and maintain eligibility for access to classified information that is at least the same level as the entity eligibility level; (6) It and all of its KMOs must not be excluded by a Federal agency, contract review board, or other authorized official from participating in Federal contracts or agreements; (7) It must meet all requirements the CSA or the authorizing law, regulation, or Government-wide policy establishes for access to the type of classified information or program involved; and (8) If the CSA determines the entity is under foreign ownership, control, or influence (FOCI), the responsible CSA must: (i) Agree that sufficient security measures are in place to mitigate or negate risk to national security interests due to the FOCI (see § 2004.34); (ii) Determine that it is appropriate to grant eligibility for a single, narrowly defined purpose (see § 2004.34(i)); or (iii) Determine that the entity is not eligible to access classified information. (9) DoD and DOE cannot award a contract involving access to proscribed information to an entity effectively owned or controlled by a foreign government unless the Secretary of the agency first issues a waiver (see 10 U.S.C. 2536). A waiver is not required if the CSA determines the entity is eligible and it agrees to establish a voting trust agreement (VTA) or proxy agreement (PA) (see § 2004.34(f)) because both VTAs and PAs effectively negate foreign government control. (f) Limited entity eligibility determination. (1) The GCA, or an entity with limited eligibility, must first request a limited entity eligibility determination from the CSA for the relevant entity and provide justification for limiting eligibility in that case; (2) Limited entity eligibility is specific to the requesting GCA's classified information, and to a single, narrowly defined contract, agreement, or circumstance; (3) The entity must otherwise meet the requirements for entity eligibility set out in this part; (4) The CSA documents the requirements of each limited entity eligibility determination it makes, including the scope of, and any limitations on, access to classified information; (5) The CSA verifies limited entity eligibility determinations only to the requesting GCA or entity. In the case of multiple limited entity eligibility determinations for a single entity, the CSA verifies each one separately only to its requestor; and (6) CSAs administratively terminate the limited entity eligibility when there is no longer a need for access to the classified information for which the CSA approved the limited entity eligibility. (g) Terminating or revoking eligibility. (2) The responsible CSA revokes the entity's eligible status if the entity is unable or unwilling to protect classified information. (3) The CSA coordinates with the GCA(s) to take interim measures, as necessary, toward either termination or revocation. § 2004.34 Foreign ownership, control, or influence (FOCI). (a) FOCI determination. (1) A foreign interest has the power to direct or decide matters affecting the entity's management or operations in a manner that could: (i) Result in unauthorized access to classified information; or (ii) Adversely affect performance of a contract or agreement requiring access to classified information; and (2) The foreign interest exercises that power: (i) Directly or indirectly; (ii) Through ownership of the U.S. entity's securities, by contractual arrangements, or other similar means; (iii) By the ability to control or influence the election or appointment of one or more members to the entity's governing board ( e.g., (iv) Prospectively ( i.e., (b) CSA guidance. (c) FOCI factors. (1) Considers information the entity or its parent provides on the SF 328/CF 328 (OMB Control No. 0704-0194), and any other relevant information; and (2) Considers in the aggregate the following factors about the entity: (i) Record of espionage against U.S. targets, either economic or Government; (ii) Record of enforcement actions against the entity for transferring technology without authorization; (iii) Record of compliance with pertinent U.S. laws, regulations, and contracts or agreements; (iv) Type and sensitivity of the information the entity would access; (v) Source, nature, and extent of FOCI, including whether foreign interests hold a majority or minority position in the entity, taking into consideration the immediate, intermediate, and ultimate parent entities; (vi) Nature of any relevant bilateral and multilateral security and information exchange agreements; (vii) Ownership or control, in whole or in part, by a foreign government; and (viii) Any other factor that indicates or demonstrates foreign interest capability to control or influence the entity's operations or management. (d) Entity access while under FOCI. (2) The CSA may not determine that the entity is eligible to access classified information until the entity has put into place appropriate security measures to negate or mitigate FOCI or is otherwise no longer under FOCI. If the degree of FOCI is such that no mitigation or negation efforts will be sufficient, or access to classified information would be inconsistent with national security interests, then the CSA will determine the entity ineligible for access to classified information. (3) If an entity comes under FOCI, the CSA may allow the existing eligibility status to continue while the CSA and the entity negotiate acceptable FOCI mitigation or negation measures, as long as there is no indication that classified information is at risk. If the entity does not actively negotiate mitigation or negation measures in good faith, or there are no appropriate measures that will remove the possibility of unauthorized access to classified information or adverse effect on the entity's performance of contracts or agreements involving classified information, the CSA will take steps, in coordination with the GCA, to terminate eligibility. (e) FOCI and entities under the CCIPP. (1) The Secretary of DHS proposes appropriate FOCI risk mitigation or negation measures (see paragraph (f) of this section) to the other CSAs and ensures the anticipated release of classified information: (i) Is authorized for release to the country involved; (ii) Does not include information classified under the Atomic Energy Act; and (iii) Does not impede or interfere with the entity's ability to manage and comply with regulatory requirements imposed by other Federal agencies, such as the State Department's International Traffic in Arms Regulation. (2) If the CSAs agree the mitigation or negation measures are sufficient, DHS may proceed to enter a CCIPP information sharing agreement with the entity. If one or more CSAs disagree, the Secretary of DHS may seek a decision from the Assistant to the President for National Security Affairs before entering a CCIPP information sharing agreement with the entity. (f) Mitigation or negation measures to address FOCI. (2) Any mitigation or negation measures the CSA approves for an entity must not impede or interfere with the entity's ability to manage and comply with regulatory requirements imposed by other Federal agencies (such as Department of State's International Traffic in Arms Regulation). (3) If the CSA approves a FOCI mitigation or negation measure for an entity, it may agree that the measure, or particular portions of it, may apply to all of the present and future sub-entities within the entity's organization. (4) Mitigation or negation measures are different for ownership versus control or influence. (5) Methods to mitigate foreign control or influence (unrelated to ownership) may include: (i) Assigning specific oversight duties and responsibilities to independent board members; (ii) Formulating special executive-level security committees to consider and oversee matters that affect entity performance on contracts or agreements requiring access to classified information; (iii) Modifying or terminating loan agreements, contracts, agreements, and other understandings with foreign interests; (iv) Diversifying or reducing foreign-source income; (v) Demonstrating financial viability independent of foreign interests; (vi) Eliminating or resolving problem debt; (vii) Separating, physically or organizationally, the entity component performing on contracts or agreements requiring access to classified information; (viii) Adopting special board resolutions; (ix) A combination of these methods, as determined by the CSA; or (x) Other actions that effectively negate or mitigate foreign control or influence. (6) Methods to mitigate or negate foreign ownership include: (i) Board resolutions. (ii) Security control agreements (SCAs). i.e., (iii) Special security agreements (SSAs). (iv) Voting trust agreements (VTAs) or proxy agreements (PAs). (v) Combinations of the measures in paragraphs (f)(6)(i) through (iv) of this section or other similar measures that effectively mitigate or negate the risks involved with foreign ownership. e.g., (g) Standards for FOCI mitigation or negation measures. (1) Annual certification and annual compliance reports by the entity's governing board and the KMOs; (2) The U.S. Government remedies in case the entity is not adequately protecting classified information or not adhering to the provisions of the mitigation or negation measure; (3) Supplements to FOCI mitigation or negation measures as the CSA deems necessary. In addition to the standard FOCI mitigation or negation measure's requirements, the CSA may require more procedures via a supplement, based upon the circumstances of an entity's operations. The CSA may place these requirements in supplements to the FOCI mitigation or negation measure to allow flexibility as circumstances change without having to renegotiate the entire measure. When making use of supplements, the CSA does not consider the FOCI mitigation measure final until it approves the required supplements ( e.g., (4) For agreements to mitigate or negate ownership (PAs, VTAs, SSAs, and SCAs), the following additional requirements apply: (i) FOCI oversight. (A) Maintains policies and procedures to safeguard classified information in the entity's possession with no adverse impact on performance of contracts or agreements requiring access to classified information; and (B) Verifies the entity is complying with the FOCI mitigation or negation measure and related documents, contract security requirements or equivalent, and the NISP; (ii) Qualifications of trustees, proxy holders, and outside directors. (A) Be a U.S. citizen residing in the United States who can exercise management prerogatives relating to their position in a way that ensures that the foreign owner can be effectively insulated from the entity or effectively separated from the entity's classified work; (B) Be completely disinterested individuals with no prior involvement with the entity, the entities with which it is affiliated, or the foreign owner and its affiliates. Individuals who are serving as trustees, proxy holders, or outside directors as part of a mitigation measure for the entity are not considered to have prior involvement solely by performing that role; and (C) Be involved in no other circumstances that may affect an individual's ability to serve effectively, such as the number of boards on which the individual serves or the length of time serving on any other boards; (iii) Annual meeting. (A) Compliance with the approved FOCI mitigation or negation measure; (B) Problems regarding practical implementation of the mitigation or negation measure; and (C) Security controls, practices, or procedures and whether they warrant adjustment; and (iv) Annual certification. (h) National interest determination (NID) Requirement for a NID. (A) The GCA requires an entity to have access to proscribed information; (B) The entity is under FOCI; and (C) The CSA proposes an SSA to mitigate the FOCI. (ii) This determination is called a national interest determination (NID). A favorable NID confirms that an entity's access to the proscribed information under an SSA is consistent with national security interests. If the CSA is unable to render a favorable NID, it must consider other FOCI mitigation measures instead of an SSA or reassess the entity's eligibility for access to classified information. (2) NID process. (ii) In cases in which any category of the proscribed information is controlled by another agency (ODNI for SCI, DOE for RD, NSA for COMSEC), the CSA asks that controlling agency to concur on the NID for that category of information. (iii) The CSA informs the GCA and the entity when the NID is complete. In cases involving SCI, RD, or COMSEC, the CSA also informs the GCA and the entity when a controlling agency concurs or non-concurs on that agency's category of proscribed information. The entity may begin accessing a category of proscribed information once the CSA informs the GCA and the entity that the controlling agency concurs, even if other categories of proscribed information are pending concurrence. (iv) An entity's access to SCI, RD, or COMSEC remains in effect so long as the entity remains eligible for access to classified information and the contract or agreement (or program or project) which imposes the requirement for access to those categories of proscribed information remains in effect, except under the following circumstances: (A) The CSA, GCA, or controlling agency becomes aware of adverse information that impacts the entity eligibility determination; (B) The CSA's threat assessment pertaining to the entity indicates a risk to one of the categories of proscribed information; (C) The CSA becomes aware of any material change regarding the source, nature, and extent of FOCI; or (D) The entity's record of NISP compliance, based on CSA reviews in accordance with § 2004.26, becomes less than satisfactory. (v) Under any of these circumstances, the CSA determines whether an entity may continue being eligible for access to classified information, it must change the FOCI mitigation measure in order to remain eligible, or the CSA must terminate or revoke access. (3) Process for concurring or non-concurring on a NID. (ii) The CSA requests from the GCA justification for access, a description of the proscribed information involved, and other information the controlling agency requires to concur or non-concur on the NID. (iii) The CSA requests concurrence on the NID from the controlling agency for the relevant category of proscribed information (ODNI for SCI, DOE for RD, NSA for COMSEC), and provides the information that controlling agency identified. (iv) The relevant controlling agency (ODNI for SCI, DOE for RD, NSA for COMSEC) responds in writing to the CSA's request for concurrence. (A) The controlling agency may concur with the NID for access under a particular contract or agreement, access under a program or project, or for all future access to the same category of proscribed information. (B) If the relevant controlling agency does not concur with the NID, the controlling agency informs the CSA in writing, citing the reasons why it does not concur. The CSA notifies the applicable GCA and, in coordination with the GCA, then notifies the entity. The entity cannot have access to the category of proscribed information under the control of that agency ( i.e., (v) When an entity is eligible for access to classified information that includes a favorable NID for SCI, RD, or COMSEC, the CSA does not have to request a new NID concurrence for the same entity if the access requirements for the relevant category of proscribed information and terms remain unchanged for: (A) Renewing the contract or agreement; (B) New task orders issued under the contract or agreement; (C) A new contract or agreement that contains the same provisions as the previous one (this usually applies when the contract or agreement is for a program or project); or (D) Renewing the SSA. (vi) When making the decision whether or not to concur with a NID for proscribed information under its control, the controlling agency will not duplicate work already performed by the GCA during the contract award process or by the CSA when determining entity eligibility for access to classified information. (4) Timing for concurrence process. (ii) The controlling agency provides a final, written concurrence or non-concurrence to the CSA within 30 days after receiving the request for concurrence from the CSA. (iii) In cases when a controlling agency requires clarification or additional information from the CSA, the controlling agency responds to the CSA within 30 days to request clarification or additional information as needed, and to coordinate a plan and timeline for concurring or non-concurring. The controlling agency must provide written updates to the CSA every 30 days until it concurs or non-concurs. In turn, the CSA provides the GCA and the entity with updates every 30 days. (i) Limited eligibility determinations (for entities under FOCI without mitigation or negation). (2) The GCA first decides whether to request a limited eligibility determination for the entity and must articulate a compelling need for it to the CSA that is in accordance with U.S. national security interests. The GCA must verify to the CSA that access to classified information is essential to contract or agreement performance, and accept the risk inherent in not mitigating or negating the FOCI. See § 2004.32(b)(3). (3) The CSA may grant a limited eligibility determination if the GCA requests and the entity meets all other eligibility criteria in § 2004.32(e). (4) A foreign government may sponsor a U.S. sub-entity of a foreign entity for limited eligibility when the foreign government desires to award a contract or agreement to the U.S. sub-entity that involves access to classified information for which the foreign government is the original classification authority ( i.e., (5) Limited eligibility determinations are specific to the classified information of the requesting GCA or foreign government, and specific to a single, narrowly defined contract, agreement, or circumstance of that GCA or foreign government. (6) The access limitations of a favorable limited eligibility determination apply to all of the entity's employees, regardless of citizenship. (7) A limited eligibility determination is not an option for entities that require access to proscribed information when a foreign government has ownership or control over the entity. See § 2004.32(e)(9). (8) The CSA administratively terminates the entity's limited eligibility when there is no longer a need for access to the classified information for which the CSA made the favorable limited eligibility determination. Terminating one limited eligibility status does not impact other ones the entity may have. § 2004.36 Determining entity employee eligibility for access to classified information. (a) Making employee eligibility determinations. (i) Determines whether entity employees meet the criteria established in the Security Executive Agent Directive (SEAD) 4, National Security Adjudicative Guidelines (December 10, 2016). Entity employees must have a legitimate requirement ( i.e., (ii) Notifies entities of its determinations of employee eligibility for access to classified information. (iii) Terminates eligibility status when there is no longer a need for access to classified information by entity employees. (2) The responsible CSA maintains: (i) SF 312s, Classified Information Nondisclosure Agreements, or other approved nondisclosure agreements, executed by entity employees, as prescribed by ODNI in accordance with 32 CFR 2001.80 and E.O. 13526; and (ii) Records of its entity employee eligibility determinations, suspensions, and revocations. (3) CSAs ensure that entities limit the number of employees with access to classified information to the minimum number necessary to work on contracts or agreements requiring access to classified information. (4) The CSA determines the need for event-driven reinvestigations for entity employees. (5) CSAs use the Federal Investigative Standards (FIS) issued jointly by the Suitability and Security Executive Agents. (6) The CSA provides guidance to entities on: (i) Requesting employee eligibility determinations, to include guidance for submitting fingerprints; and (ii) Granting employee access to classified information when the employee has had a break in access or a break in employment. (7) If the CSA receives adverse information about an eligible entity employee, the CSA should consider and possibly investigate, as authorized, to determine whether the employee's eligibility to access classified information remains clearly consistent with the interests of national security. If the CSA determines that an entity employee's continued eligibility is not in the interest of national security, the CSA implements procedures leading to suspension and ultimate revocation of the employee's eligible status, and notifies the entity. (b) Consultants. (c) Reciprocity. (d) Limited access authorization (LAA). (i) A non-U.S. citizen employee possesses unique or unusual skill or expertise that the agency urgently needs to support a specific U.S. Government contract or agreement; and (ii) A U.S. citizen with those skills is not available. (2) A CSA may grant LAAs up to the secret classified level. (3) CSAs may not use LAAs for access to: (i) Top secret (TS) information; (ii) RD or FRD information; (iii) Information that a Government-designated disclosure authority has not determined releasable to the country of which the individual is a citizen; (iv) COMSEC information; (v) Intelligence information, to include SCI; (vi) NATO information, except as follows: Foreign nationals of a NATO member nation may be authorized access to NATO information subject to the terms of the contract, if the responsible CSA obtains a NATO security clearance certificate from the individual's country of citizenship. NATO access is limited to performance on a specific NATO contract; (vii) Information for which the U.S. Government has prohibited foreign disclosure in whole or in part; or (viii) Information provided to the U.S. Government by another government that is classified or provided in confidence. (4) The responsible CSA provides specific procedures to entities for requesting LAAs. The GCA must concur on an entity's LAA request before the CSA may grant it. § 2004.38 Safeguarding and marking. (a) Safeguarding approval. e.g., (2) The CSA maintains records of its safeguarding capability determinations and, upon request from GCAs or entities, and as appropriate and to the extent authorized by law, verifies that it has made a favorable safeguarding determination for a given entity and at what level. (b) Marking. Marking Classified National Security Information; e.g., § 2004.40 Information system security. (a) The responsible CSA must authorize an entity information system before the entity can use it to process classified information. The CSA must use the most complete, accurate, and trustworthy information to make a timely, credible, and risk-based decision whether to authorize an entity's system. (b) The responsible CSA issues to entities guidance that establishes protection measures for entity information systems that process classified information. The responsible CSA must base the guidance on standards applicable to Federal systems, which must include the Federal Information Security Modernization Act of 2014 (FISMA), Public Law 113-283, and may include National Institute of Standards and Technology (NIST) publications, Committee on National Security Systems (CNSS) publications, and Federal information processing standards (FIPS). § 2004.42 [Reserved] Appendix A to Part 2004—Acronym Table For details on many of these terms, see the definitions at § 2004.4. CCIPP—Classified Critical Infrastructure Protection Program CCIPP POC—Entity point of contact under the CCIPP program CIA—Central Intelligence Agency CSA—Cognizant security agency CNSS—Committee on National Security Systems COMSEC—Communications security CSO—Cognizant security office DHS—Department of Homeland Security DoD—Department of Defense DOE—Department of Energy EA—Executive agent (the NISP executive agent is DoD) E.O.—Executive Order FAR—Federal Aquisition Regulation FOCI—Foreign ownership, control, or influence GCA—Government contracting activity Insider threat program SO—insider threat senior official (for an agency or for an entity) ISOO—Information Security Oversight Office of the National Archives and Records Administration (NARA) KMO—Key managers and officials (of an entity) LAA—Limited access authorization NID—National interest determination NISPOM—National Industrial Security Program Operating Manual NRC—Nuclear Regulatory Commission NSA—National Security Agency ODNI—Office of the Director of National Intelligence PA—Proxy agreement RD—Restricted data SF—Standard Form SAO—Senior agency official for NISP SAP—Special access program SCA—Security control agreement SCI—Sensitive compartmented information SSA—Special security agreement TS—Top secret (classification level) VT—Voting trust

Related documents

Record · ID 508711 · SHA-256 790805f76a01a300
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.