DOE M 470.4-1 Chg 2, Safeguards and Security Program Planning and Management
Functional areas: Safety and Security
The manual establishes program planning and management requirements for the Department’s Safeguards and Security (S&S) Program. Change 2 is a revision to Section M of both the Manual and the CRD to realign the process for establishing deviations from DOE directives containing safeguards and security requirements to reflect established Departmental policy as set forth in DOE O 251.1C. Original publication, 8-26-05; Chg 1, 3-7-06. Canceled by DOE O 470.4B
Version history and related documents
Supersedes
Earlier documents this one replaced.
Related documents
Document text
Text extracted from the attached file. Refer to the original document for the authoritative version.
Section 1
Vertical line denotes change.
AVAILABLE ONLINE AT: INITIATED BY:
http://www.directives.doe.gov Office of Security and Safety
Performance Assurance
MANUAL
Approved: 8-26-05
Review: 8-26-07
Chg 2: 10-20-10
SAFEGUARDS AND SECURITY
PROGRAM PLANNING AND
MANAGEMENT
U.S. DEPARTMENT OF ENERGY
Office of Security and Safety Performance Assurance
DOE M 470.4-1
DOE M 470.4-1 i
8-26-05
SAFEGUARDS AND SECURITY PROGRAM PLANNING AND MANAGEMENT
1. PURPOSE. To establish program planning and management requirements for the
Department’s Safeguards and Security (S&S) Program.
2. OBJECTIVES.
a. Effect the policy in DOE P 470.1, Integrated Safeguards and Security
Management (ISSM) Policy, by integrating program planning and management
into Department of Energy (DOE) operations as determined by line management,
and according to sound risk management practices. [DOE P 470.1, Integrated
Safeguards and Security Management (ISSM) Policy, is the Department’s
philosophical approach to the management of the S&S Program. A principal
objective of the ISSM Program is to integrate S&S into management and work
practices at all levels, based on program line management’s risk management-
based decisions, so that missions may be accomplished without security events,
such as interruption, disruption or compromise. This approach includes
individual responsibility and implementation of the security requirements found
in this Manual.]
b. Establish individual responsibilities to fulfill the requirements in this Manual.
c. Establish requirements for S&S planning and evaluations.
d. Establish requirements for S&S management.
e. Promulgate the requirements of the National Industrial Security Program.
3. PROGRAM INTEGRATION. S&S program planning and management must be
integrated with other programs such as physical protection, protective force (PF),
information security, personnel security, and nuclear material control & accountability
(MC&A). Mechanisms must also exist to assure that S&S program planning is fully
integrated with overall site strategic and near-term operational planning. Additionally,
the activities and requirements in the weapons surety, foreign visits and assignments,
safety, emergency management, cyber security, and intelligence and counterintelligence
programs should also be considered in the implementation of this Manual.
4. CANCELLATIONS. The directives listed below are canceled. Cancellation of a
directive does not by itself modify or otherwise affect any contractual obligation to
comply with the directive. Canceled directives that are incorporated by reference in a
contract remain in effect until the contract is modified to delete the reference to the
requirements in the canceled directives. The publication of this Manual incorporates or
cancels all previous memoranda or letters that were issued by the Office of Security or its
predecessor organizations that established policy.
ii DOE M 470.4-1
8-26-05
a. DOE N 473.9, Security Conditions, dated 7-8-04.
b. DOE M 470.1-1, Safeguards and Security Awareness Program, dated 10-02-02.
5. APPLICABILITY.
a. Departmental Elements. Except for the exclusion in paragraph 5c, this Manual
applies to all Departmental elements, listed on Attachment 1. This Manual
automatically applies to Departmental elements created after it is issued.
The Administrator of the National Nuclear Security Administration (NNSA) will
assure that NNSA employees and contractors comply with their respective
responsibilities under this Manual.
Section 2
b. Contractors.
(1) The Contractor Requirements Document (CRD), Attachment 2, sets forth
requirements of this Manual that will apply to site/facility management
contracts that include the CRD.
(2) The CRD must be included in the site/facility management contracts that
involve classified information or matter, or nuclear materials and contain
DOE Acquisition Regulation (DEAR) clause 952.204-2, titled Security
Requirements.
(a) Departmental elements must notify contracting officers of affected
site/facility management contracts to incorporate this directive into
those contracts.
(b) Once notified, contracting officers are responsible for
incorporating this directive into the affected contracts via the Laws,
Regulations, and DOE Directives clause of the contracts.
(3) A violation of the provisions of the CRD relating to the safeguarding or
security of Restricted Data or other classified information may result in a
civil penalty pursuant to subsection a. of section 234B, of the Atomic
Energy Act of 1954 (42 U.S.C. 228b.). The procedures for the assessment
of civil penalties are set forth in Title 10, Code of Federal Regulations
(CFR), Part 824, Procedural Rules for the Assessment of Civil Penalties
for Classified Information Security Violations, (10 CFR Part 824).
(4) As stated in DEAR clause 970.5204-2, titled Laws, Regulations, and DOE
Directives, regardless of the performer of the work, site/facility
contractors with the CRD incorporated into their contracts are responsible
for compliance with the CRD. Affected site/facility management
contractors are responsible for flowing down the requirements of the CRD
DOE M 470.4-1 iii
8-26-05
to subcontracts at any tier to the extent necessary to ensure compliance
with the requirements. In doing so, contractors must not unnecessarily or
imprudently flow down requirements to subcontracts. That is, contractors
must both ensure that they and their subcontractors comply with the
requirements of this CRD and incur only costs that would be incurred by a
prudent person in the conduct of competitive business.
(5) This Manual does not automatically apply to other than site/facility
management contracts. Application of any of the requirements in this
Manual to other than site/facility management contracts will be
communicated as follows.
(a) Heads of Field Elements and Headquarters Departmental
Elements. Review procurement requests for new non-site-/
non-facility-management contracts that involve classified
information or matter, or nuclear materials and contain DEAR
clause 952.204-2, titled Security Requirements. If appropriate,
ensure that the requirements of the CRD of this Manual are
included in the contract.
(b) Contracting Officers. Assist originators of procurement requests
who want to incorporate the requirements of the CRD of this
Manual in new non-site-/non-facility-management contracts, as
appropriate.
c. Exclusion. In accordance with the responsibilities and authorities assigned by
Executive Order 12344 and to ensure consistency throughout the joint Navy and
DOE organization of the Naval Nuclear Propulsion Program, the Deputy
Administrator for Naval Reactors will implement and oversee all requirements
and practices pertaining to this Manual for activities under the Deputy
Administrator’s cognizance.
d. Exemption.
Section 3
(1) Requirements in this Manual that overlap or duplicate requirements of the,
Nuclear Regulatory Commission (NRC) related to radiation protection,
nuclear safety (including quality assurance), and safeguards and security
of nuclear material, do not apply to the design, construction, operation,
and decommissioning of the Office of Civilian Radioactive Waste
Management (RW) facilities.
iv DOE M 470.4-1 Chg 1
3-7-06
Vertical line denotes change.
(2) This exemption does not apply to requirements for which the NRC defers
to DOE or does not exercise regulatory jurisdiction.
6. DEVIATIONS. Deviations from requirements must be processed in accordance with
Section M.
7. DEFINITIONS. Terms commonly used in the program are defined in the S&S Glossary
located in DOE M 470.4-7, Safeguards and Security Program References. In addition to
those in the Glossary, the following definitions are provided for use in this Manual.
a. DOE line management refers to DOE and NNSA Federal employees who have
been granted the authority to commit resources or direct the allocation of
personnel or approve implementation plans and procedures in the accomplishment
of specific work activities.
b. Line management refers to DOE and NNSA Federal and contractor employees
who have been granted the authority to commit resources or direct the allocation
of personnel or approve implementation plans and procedures in the
accomplishment of specific work activities.
c. DOE cognizant security authority refers to DOE and NNSA Federal employees
who have been granted the authority to commit security resources or direct the
allocation of security personnel or approve security implementation plans and
procedures in the accomplishment of specific work activities.
d. Cognizant security authority refers to DOE and NNSA Federal and contractor
employees who have been granted the authority to commit security resources or
direct the allocation of security personnel or approve security implementation
plans and procedures in the accomplishment of specific work activities.
e. Category I/II refers to facilities or sites possessing Category I quantities of special
nuclear material (SNM) or credible rollup quantities of SNM to a Category I
quantity.
f. For the purposes of this Manual, the Office of Security refers to the DOE Office
of Health, Safety and Security.
8. IMPLEMENTATION. Requirements that cannot be implemented within 6 months of the
effective date of this Manual or within existing resources must be documented by the
cognizant security authority and submitted to the relevant program officers: the Under
Secretary for Energy, Science and Environment or the Under Secretary for Nuclear
Security/Administrator, NNSA; and the Office of Security. The documentation must
include timelines and resources needed to fully implement this Manual. The
documentation must also include a description of the vulnerabilities and impacts created
by the delayed implementation of the requirements.
DOE M 470.4-1 v (and vi)
8-26-05
9. CONTACT. Questions concerning this Manual should be directed to the Office of
Security at 202-586-3345.
BY ORDER OF THE SECRETARY OF ENERGY:
CLAY SELL
Deputy Secretary
DOE M 470.4-1 Chg 1 vii
3-7-06
Vertical line denotes change..
CONTENTS
PART 1. PLANNING AND EVALUATIONS
SECTION A—SAFEGUARDS AND SECURITY PROGRAM PLANNING
1. OBJECTIVE ................................................................................................................... A-1
Section 4
2. REQUIREMENTS .......................................................................................................... A-1
3. PLANNING .................................................................................................................... A-4
APPENDIX 1—SAFEGUARDS AND & SECURITY MANAGEMENT PLAN
1. EXECUTIVE SUMMARY ............................................................................ Appendix 1-1
2. PART 1—ORGANIZATIONAL STRUCTURE AND
ACCOUNTABILITY ................................................................................... Appendix 1-1
3. PART 2—ROLES, RESPONSIBILITIES, DELEGATIONS,
AND AUTHORITIES .................................................................................... Appendix 1-2
4. PART 3—S&S PROGRAM IMPLEMENTATION ...................................... Appendix 1-3
5. PART 4—PLANNING AND BUDGET (INCLUDING PERSONNEL
RESOURCES) .............................................................................................. Appendix 1-3
APPENDIX 2—DEPARTMENT OF ENERGY TACTICAL DOCTRINE
1. INTRODUCTION .......................................................................................... Appendix 2-1
2. TACTICAL DOCTRINE................................................................................ Appendix 2-1
3. MANAGEMENT CONSIDERATIONS ........................................................ Appendix 2-9
SECTION B—SECURITY CONDITIONS
1. OBJECTIVE ....................................................................................................................B-1
2. THREAT INDICATORS.................................................................................................B-1
3. SECURITY CONDITIONS.............................................................................................B-2
SECTION C—SITE SAFEGUARDS AND SECURITY PLANS
1. OBJECTIVE ....................................................................................................................C-1
2. APPLICATION ...............................................................................................................C-1
3. SCOPE .............................................................................................................................C-1
4. PURPOSE ........................................................................................................................C-1
5. PLAN COMPOSITION ...................................................................................................C-1
6. EVIDENCE FILES ..........................................................................................................C-2
7. DATA COLLECTION ....................................................................................................C-2
8. FORMAT .........................................................................................................................C-2
viii DOE M 470.4-1
8-26-05
CONTENTS (continued)
SECTION C—TABLES
Table C-1. SNM Theft/Diversion Targets .............................................................................C-6
Table C-2. Radiological Sabotage Targets ............................................................................C-6
Table C-3. Biological/Chemical Sabotage Targets ................................................................C-7
Table C-4. Disruption of Critical Mission Targets ................................................................C-7
Section 5
Table C-5. Site-Wide Protection Strategies ...........................................................................C-8
Table C-6. Facility Protection Systems ................................................................................C-10
Table C-7. Qualification and Training .................................................................................C-11
Table C-8. MC&A Plans and Procedures ............................................................................C-12
Table C-9. Personnel Security/Human Reliability Program Implementation ......................C-13
Table C-10. Automated Information Systems Security Programs .........................................C-13
Table C-11. S&S-Related Maintenance, Testing, and Records Management
Programs ............................................................................................................C-16
Table C-12. Site Protection Program Evaluation Program ....................................................C-16
Table C-13. Deviations from DOE Directives .......................................................................C-17
Table C-14. Pending Deviations from DOE Directives .........................................................C-17
Table C-15. Summary of Identified Risks .............................................................................C-19
Table C-16. SNM Theft/Diversion Targets ...........................................................................C-20
Table C-17. Credible Radiological Sabotage Targets ............................................................C-20
Table C-18. Credible Biological Sabotage Targets ...............................................................C-20
Table C-19 Credible Chemical Sabotage Targets .................................................................C-20
Table C-20. Disruption of Critical Mission Targets ..............................................................C-21
Table C-21. Performance Testing Results of Site-Specific Essential
Protection Element Values .................................................................................C-22
Table C-22. Critical Path Scenarios .......................................................................................C-24
Table C-23. Protection Effectiveness (PE) for Theft or Diversion of SNM ...........................C-25
Table C-24. Protection Effectiveness (PE) for Radiological Sabotage ..................................C-25
Table C-25. Protection Effectiveness (PE) for Biological Sabotage ......................................C-26
Table C-26. Protection Effectiveness (PE) for Chemical Sabotage .......................................C-26
Table C-27. Protection Effectiveness (PE) for Disruption of Critical Missions ....................C-26
DOE M 470.4-1 ix
3-7-06
Vertical line denotes change.
CONTENTS (continued)
Table C-28. Protection Effectiveness (PE) for Theft or Espionage of Classified
Matter .................................................................................................................C-27
Table C-29. Protection Effectiveness (PE) for Other Losses .................................................C-27
Table C-30. System Effectiveness Summary .........................................................................C-27
SECTION D—SITE SAFEGUARDS AND SECURITY PLAN/RESOURCE PLAN
1. OBJECTIVE ................................................................................................................... D-1
Section 6
2. UNFUNDED/UNSUPPORTED REQUIREMENTS ..................................................... D-5
3. REFERENCES FOR THE RESOURCE PLAN............................................................. D-5
4. HEADINGS AND TERMS FOR TABLES D-1 THROUGH D-5 ................................ D-5
SECTION D—TABLES
Table D-1. Operational Requirements .................................................................................. D-1
Table D-2. Capital Equipment .............................................................................................. D-2
Table D-3. General Plant Projects ......................................................................................... D-3
Table D-4. Line Item Construction Projects ......................................................................... D-4
Table D-5. Unfunded/Unsupported Requirements ................................................................ D-4
SECTION E—VULNERABILITY ASSESSMENT PROGRAM
1. OBJECTIVE .................................................................................................................... E-1
2. CONDUCTING VULNERABILITY ASSESSMENTS ................................................. E-1
3. QUALITY ASSURANCE ............................................................................................... E-3
4. VULNERABILITY ASSESSMENT DOCUMENTATION ........................................... E-3
5. ASSIGNING FIGURES OF MERIT ............................................................................... E-3
6. CRITICAL SYSTEM ELEMENTS ................................................................................ E-4
7. VULNERABILITY ASSESSMENT REPORTS ............................................................ E-4
8. SYSTEM EFFECTIVENESS .......................................................................................... E-4
9. TRAINING AND CERTIFICATION ............................................................................. E-6
APPENDIX 3—VULNERABILITY ASSESSMENT MODELING TOOLS ........... Appendix 3-1
APPENDIX 4—SYSTEM PERFORMANCE EFFECTIVENESS
EQUATION ..................................................................................... Appendix 4-1
APPENDIX 5—SUGGESTED VULNERABILITY ASSESSMENT REPORT
FORMAT ......................................................................................... Appendix 5-1
x DOE M 470.4-1
8-26-05
CONTENTS (continued)
SECTION F—PERFORMANCE ASSURANCE PROGRAM
1. OBJECTIVE .................................................................................................................... F-1
2. REQUIREMENTS ........................................................................................................... F-1
SECTION G—SURVEY, REVIEW, AND SELF-ASSESSMENT PROGRAMS
1. OBJECTIVES ................................................................................................................. G-1
2. REQUIREMENTS .......................................................................................................... G-1
3. CONDUCT ..................................................................................................................... G-4
4. FINDINGS ...................................................................................................................... G-5
5. RATINGS ....................................................................................................................... G-6
Section 7
6. REPORT CONTENT...................................................................................................... G-8
7. DISTRIBUTION........................................................................................................... G-10
8. NOTIFICATIONS AND ACTIONS FOR LESS THAN SATISFACTORY
SURVEY COMPOSITE RATINGS............................................................................. G-11
9. NOTIFICATIONS AND ACTIONS FOR LESS THAN SATISFACTORY
SELF-ASSESSMENT COMPOSITE RATINGS ........................................................ G-12
10. CORRECTIVE ACTIONS ........................................................................................... G-12
11. UPGRADE OF COMPOSITE RATINGS.................................................................... G-13
12. RECORDS RETENTION ............................................................................................. G-13
13. CONTINUOUS IMPROVEMENT PROCESS ............................................................ G-13
PART 2. SAFEGUARDS AND SECURITY MANAGEMENT
SECTION H—FOREIGN OWNERSHIP, CONTROL, OR INFLUENCE PROGRAM
1. OBJECTIVE ................................................................................................................... H-1
CHAPTER I. GENERAL FOCI PROGRAM INFORMATION
1. GENERAL REQUIREMENTS ........................................................................................ I-1
2. APPLICABILITY ............................................................................................................. I-2
3. CONTRACT AWARD MUST NOT BE MADE PRIOR TO FCL ISSUANCE ............. I-3
4. ELECTRONIC SUBMISSION/PROCESSING WEB SITE............................................ I-3
CHAPTER II. FOCI ACTIVITIES
1. DETERMINING THE SECURITY REQUIREMENTS OF THE
CONTRACT/AGREEMENT ..........................................................................................II-1
2. DETERMINING THE FCL STATUS OF THE APPLICANT .......................................II-1
DOE M 470.4-1 xi
3-7-06
Vertical line denotes change.
CONTENTS (continued)
3. ACCEPTING A FOCI DETERMINATION RENDERED BY
ANOTHER FEDERAL AGENCY ..................................................................................II-1
4. CLASSIFIED CONTRACT ............................................................................................II-1
5. ADJUDICATION ............................................................................................................II-3
6. COMMITTEE ON FOREIGN INVESTMENT IN THE UNITED STATES .................II-6
CHAPTER III. REPORTING REQUIREMENTS
1. FOCI CHANGES OCCUR FOLLOWING SUBMISSION OF AN SF 328 AND
BEFORE CONTRACT AWARD .................................................................................. III-1
2. UPDATES...................................................................................................................... III-1
3. ANNUAL CERTIFICATION ....................................................................................... III-3
CHAPTER IV. FOCI MITIGATION ACTION PLANS
1. GENERAL ..................................................................................................................... IV-1
2. MITIGATION ACTION PLANS .................................................................................. IV-1
3. FOREIGN OWNERSHIP .............................................................................................. IV-1
Section 8
4. ANNUAL COMPLIANCE MEETING ....................................................................... IV-11
5. NONCOMPLIANCE WITH MITIGATION PLANS ................................................. IV-11
APPENDIX 6 – FOCI MATRIX CHART ................................................................ Appendix 6-1
SECTION I—FACILITY CLEARANCES AND REGISTRATION OF SAFEGUARDS
AND SECURITY ACTIVITIES
1. OBJECTIVE ..................................................................................................................... I-1
CHAPTER I. FACILITY CLEARANCE (FCL) PROGRAM
1. GENERAL ........................................................................................................................ I-1
2. EXCEPTIONS TO REGISTRATION IN SSIMS ............................................................ I-3
CHAPTER II. IMPORTANCE RATINGS
1. FACILITY IMPORTANCE RATINGS ..........................................................................II-1
2. UPGRADING AND DOWNGRADING A FACILITY’S ASSIGNED
IMPORTANCE RATING ...............................................................................................II-2
CHAPTER III. ORGANIZATIONAL STRUCTURES AND FCLs
1. FCL FOR SINGLE LEGAL ENTITIES ........................................................................ III-1
2. PARENT–SUBSIDIARY RELATIONSHIP ................................................................ III-2
xii DOE M 470.4-1 Chg 1
8-26-05
CONTENTS (continued)
CHAPTER IV. INTERIM AND LIMITED FCLs
1. INTERIM FCL............................................................................................................... IV-1
2. LIMITED FCL ............................................................................................................... IV-1
CHAPTER V. ACCESS AUTHORIZATIONS AND EXCLUSION PROCEDURES
REQUIRED IN CONNECTION WITH FCLs
1. ACCESS AUTHORIZATIONS REQUIRED IN CONNECTION WITH THE
FCL ................................................................................................................................. V-1
2. MULTIPLE FACILITY ORGANIZATIONS ................................................................ V-1
3. ACCESS AUTHORIZATIONS CONCURRENT WITH THE FCL ............................. V-1
4. EXCLUSION PROCEDURES ....................................................................................... V-2
CHAPTER VI. FACILITY CLEARANCE
1. REQUIREMENTS ......................................................................................................... VI-1
2. ISSUANCE OF FCLs .................................................................................................... VI-2
3. CHANGED CONDITIONS AFFECTING THE FCL .................................................. VI-2
4. INTERFACE WITH FOCI REQUIREMENTS ............................................................ VI-2
CHAPTER VII. PROCESS FOR FCL AND SECURITY ACTIVITY REGISTRATION
1. ACCEPTING OGA FCLs............................................................................................. VII-1
2. OGA VERIFICATION REQUESTS ............................................................................ VII-5
3. REGISTERING OGA FCLs ......................................................................................... VII-5
4. REGISTRATION OF OGA CONTRACTORS IN SSIMS ......................................... VII-6
5. REGISTERING WORK FOR OTHERS (WFO) ACTIVITIES .................................. VII-6
Section 9
6. REGISTRATION OF DOE FCLs ................................................................................ VII-7
7. REGISTRATION OF SECURITY ACTIVITIES ...................................................... VII-10
SECTION J—SAFEGUARDS AND SECURITY TRAINING PROGRAM
1. OBJECTIVE ..................................................................................................................... J-1
2. REQUIREMENTS ............................................................................................................ J-1
SECTION K—SAFEGUARDS AND SECURITY AWARENESS PROGRAM
1. OBJECTIVE ................................................................................................................... K-1
2. REQUIREMENTS .......................................................................................................... K-1
3. PROGRAM DESIGN AND DEVELOPMENT ............................................................. K-1
4. BRIEFINGS .................................................................................................................... K-1
DOE M 470.4-1 xiii
3-7-06
Vertical line denotes change.
CONTENTS (continued)
5. CLASSIFIED INFORMATION NONDISCLOSURE AGREEMENT (SF-312) ......... K-5
6. SUPPLEMENTARY AWARENESS ACTIVITIES ...................................................... K-6
SECTION L—CONTROL OF CLASSIFIED VISITS PROGRAM
1. OBJECTIVE .................................................................................................................... L-1
2. REQUIREMENTS ........................................................................................................... L-1
APPENDIX 7—ACCESS TO RESTRICTED DATA IN POSSESSION
OF OTHER FEDERAL AGENCIES ........................................................................ Appendix 7-1
SECTION M—DEVIATIONS
1. OBJECTIVE ................................................................................................................... M-1
2. REQUIREMENTS .......................................................................................................... M-1
3. DEVIATIONS…………………………………………………………………………M-1
4. DEVIATIONS TO NATIONAL POLICY…………………………………………….M-2
5. DOCUMENTATION………………………………………………………………….M-2
6. REVIEW AND UPDATE……………………………………………………………..M-3
SECTION N—INCIDENTS OF SECURITY CONCERN
1. OBJECTIVE ................................................................................................................... N-1
2. REQUIREMENTS .......................................................................................................... N-1
CHAPTER I. IDENTIFICATION AND REPORTING REQUIREMENTS
1. GENERAL ........................................................................................................................ I-1
2. INCIDENT IDENTIFICATION AND CATEGORIZATION ......................................... I-1
3. REPORTING REQUIREMENTS .................................................................................... I-8
4. INQUIRY OFFICIALS .................................................................................................. I-14
5. FEDERAL, STATE, OR LOCAL LAW ENFORCEMENT PERSONNEL ................. I-15
6. CONDUCT OF INQUIRIES .......................................................................................... I-16
7. INQUIRY REPORT CONTENT/CLOSURE CONSIDERATIONS ............................. I-19
8. ADMINISTRATIVE ACTIONS .................................................................................... I-21
Section 10
9. RECORDS RETENTION ............................................................................................... I-21
SECTION N, CHAPTER I—TABLES AND FIGURES
Table 1. Reportable Categories of Incidents of Security Concern, Impact
Measurement Index 1 (IMI-1) ...................................................................................................... I-3
xiv DOE M 470.4-1 Chg 1
3-7-06
Vertical line denotes change.
CONTENTS (continued)
Table 2. Reportable Categories of Incidents of Security Concern, Impact
Measurement Index 2 (IMI-2) .............................................................................. I-4
Table 3. Reportable Categories of Incidents of Security Concern, Impact
Measurement Index 3 (IMI-3) .............................................................................. I-5
Table 4. Reportable Categories of Incidents of Security Concern, Impact
Measurement Index 4 (IMI-4) .............................................................................. I-7
Figure 1. Incidents of Security Concern ............................................................................. I-10
Figure 2. Example Chain of Custody Form ....................................................................... I-17
CHAPTER II. INCIDENTS OF SECURITY CONCERN INVOLVING COMPROMISE OR
POTENTIAL COMPROMISE OF CLASSIFIED INFORMATION
1. INQUIRIES INTO COMPROMISE OF POTENTIAL COMPROMISE OF, OR
MISSING CLASSIFIED INFORMATION ....................................................................II-1
2. DAMAGE ASSESSMENTS ...........................................................................................II-2
3. CONDUCT OF DAMAGE ASSESSMENTS .................................................................II-3
4. PROCEDURES................................................................................................................II-3
5. CONTENT OF DAMAGE ASSESSMENT REPORTS .................................................II-3
6. COMBINING SIMILAR INCIDENTS ...........................................................................II-4
7. CASES INVOLVING OTHER GOVERNMENT AGENCY INFORMATION ............II-4
8. CASES INVOLVING FOREIGN GOVERNMENT INFORMATION .........................II-4
9. JOINT DAMAGE ASSESSMENT WITH ANOTHER GOVERNMENT
AGENCY .........................................................................................................................II-5
SECTION O—RESTRICTIONS ON THE TRANSFER OF SECURITY-FUNDED
TECHNOLOGIES OUTSIDE THE DEPARTMENT AND ITS OPERATIONAL
FACILITIES
1. OBJECTIVE ................................................................................................................... O-1
2. REQUIREMENTS .......................................................................................................... O-1
APPENDIX 9—TECHNOLOGY TRANSFER APPROVAL REQUESTS .............. Appendix 9-1
ATTACHMENTS
ATTACHMENT 1. DEPARTMENTAL ELEMENTS TO WHICH DOE M 470.4-1 APPLIES
ATTACHMENT 2. CONTRACTOR REQUIREMENTS DOCUMENT
DOE M 470.4-1 Chg 1 Part 1, Section A
3-7-06 A-1
Vertical line denotes change.
PART 1—PLANNING AND EVALUATIONS
SECTION A—SAFEGUARDS AND SECURITY PROGRAM PLANNING
1. OBJECTIVE. To establish a standardized approach for protection program planning that
will provide an information baseline for use in integrating Departmental safeguards and
security (S&S) considerations, facilitating management evaluation of program elements,
determining resources for needed improvements, and establishing cost-benefit bases for
analyses and comparisons.
Section 11
2. REQUIREMENTS. The following are essential elements for planning for S&S
programs.
a. S&S Philosophy. S&S interests and activities must be protected from theft,
diversion, terrorist attack, industrial sabotage, radiological sabotage, chemical
sabotage, biological sabotage, espionage, unauthorized access, compromise, and
other acts that may have an adverse impact on national security; the environment;
or pose significant danger to the health and safety of Department of Energy
(DOE) Federal and contractor employees or the public. DOE protective forces
(PFs) that protect Category I quantities of special nuclear material (SNM);
credible rollup of SNM to a Category I quantity; or those facilities that meet or
exceed the Threat Level 2 criteria specified in DOE O 470.3A, Design Basis
Threat Policy, dated 11-29-05, for chemical, radiological, or biological
thresholds, must employ the DOE Tactical Doctrine contained in Appendix 2 of
Section A.
b. S&S Management Plan. This Plan must provide a description of the
implementation of S&S policy and provide detailed information on the
assignment of roles, responsibilities, and authorities, as well as the development
of budgets and allocation of resources. The S&S Management Plan must be
updated annually (at least every 12 months) and must document:
(1) roles, responsibilities, delegations, and authorities for the S&S program;
(2) organizational structure and accountability; and
(3) planning and budget (including personnel resources).
See Appendix 1, S&S Management Plan, for content requirements and suggested
format. However, if a Functions, Responsibilities, and Authorities Manual for
S&S has been approved and issued, and it meets the requirements stated above, it
can be used in place of a S&S Management Plan.
c. S&S Program Operations. Actions must be taken to ensure an acceptable S&S
program, including curtailment or suspension of operations when such operations
would result in an immediate and unacceptable impact to national security, the
environment, or the health and safety of the public or employees.
Part 1, Section A DOE M 470.4-1 Chg 1
A-2 3-7-06
Vertical line denotes change.
(1) Site-Specific Characterization. Protection programs must be tailored to
address specific site characteristics and requirements, current technology,
ongoing programs, and operational needs to achieve acceptable protection
levels that reduce risks in a cost-effective manner.
(2) Threat Policy/Guidance. DOE O 470.3, Design Basis Threat (DBT)
Policy must be used with local threat guidance during the conduct of
vulnerability assessments (VAs) for protection and control program
planning. The DBT must be the baseline threat definition but local threat
guidance may be used to increase the level of threat to be analyzed.
(3) Targeted Protection Strategies.
(a) Strategies for the physical protection of special nuclear materials
(SNM) and vital equipment must incorporate the applicable
requirements established in DOE M 470.4-2, Physical Protection.
(b) Protection strategies must be implemented as specified in the DBT.
PF resources must focus on decisively defeating the terrorist threat,
which is facilitated by positioning posts so there is little or no
delay in responding to critical targets, eliminating posts which
detract from constant readiness, and maximizing use of physical
protection systems to enhance PF effectiveness. PF resources must
be positioned to interdict and neutralize the adversary threat as far
as possible outside the boundaries of the target location.
Section 12
(c) Protection program elements must be designed to prevent and/or
mitigate the consequences of acts of radiological, chemical, or
biological sabotage that would cause unacceptable impact to
national security, the environment, or the health and safety of the
public or employees. Protection elements, such as active denial
systems, must be designed and deployed to minimize the need for
PF recapture/recovery operations.
(d) Strategies for the protection and control of classified information
or matter must incorporate the applicable requirements established
in DOE M 470.4-4, Information Security.
(e) Security systems must be used that prevent, detect, or deter
unauthorized access, modification, or loss of classified and
unclassified controlled matter and its unauthorized removal from a
site or facility.
(f) Strategies for the protection of government property not covered
above must reflect a graded approach. DOE offices, facilities, and
property protection areas (PPAs) must meet or exceed General
Services Administration (GSA) minimum security standards.
DOE M 470.4-1 Chg 1 Part 1, Section A
3-7-06 A-3
Vertical line denotes change.
(g) Security countermeasures for explosive threats must address a
range of activities including hand-carried, mailed, and
vehicle-transported devices.
d. Graded Protection. The Department recognizes that risks must be accepted
(i.e., that actions cannot be taken to reduce the potential for or consequences of
all malevolent events to zero); however, an acceptable level of risk must be
determined based on evaluation of a variety of facility-specific goals and
considerations. By a graded approach, the Department intends that the highest
level of protection be given to security interests and activities whose loss, theft,
compromise, and/or unauthorized use would seriously affect the national security,
the environment, Departmental programs, and/or the health and safety of the
public or employees. Protection of other interests and activities must be graded
accordingly.
e. Risk Management. S&S programs must be based on the results of vulnerability
and risk assessments, the results of which are used to design and provide graded
protection in accordance with an asset’s importance or the impact of its loss,
destruction, or misuse. The results of the assessments, to include the
determination of system effectiveness, are one of the key considerations the
manager must evaluate when establishing the level of risk. For example, if it is
determined that there is high risk that is not being mitigated by compensatory
measures, reporting must be made to the Secretary of Energy or the Deputy
Secretary who can accept high risk. Cognizant Under Secretaries can accept
moderate risk.
(1) Vulnerability and risk assessments must be conducted and documented to
support the identification of risks to be accepted by the Department.
(2) To determine the appropriate level of protection against risk, line
management must consider the threat, the vulnerability of the potential
target, and the potential consequences of an adversarial act.
f. Site-Specific Programs.
(1) S&S programs must address site-specific characteristics.
(2) Performance assurance programs must be developed, managed, and
implemented to ensure that S&S programs and protection program
elements protect security interests and activities. These programs must
ensure intensive, frequent performance testing of PF individual and unit
tactics with oversight by line management and independent oversight
organizations.
Section 13
Part 1, Section A DOE M 470.4-1
A-4 8-26-05
(3) A management and planning process to achieve integrated, site-specific
protection from unauthorized actions must be implemented. This process
must be based on a graded approach that implements the integrated
concepts of deterrence, prevention, detection, and response.
(4) The DBT must be used as the basis for planning protection programs.
3. PLANNING.
a. S&S Plans. S&S plans must be developed for facilities with any of the following
S&S interests:
(1) Category I quantities of SNM or credible roll-up quantities of SNM to a
Category I quantity;
(2) Category II, Category III, or Category IV SNM;
(3) radiological, chemical, or biological sabotage threats;
(4) critical mission disruption threats;
(5) intra-/inter-site transportation of SNM;
(6) classified information or matter;
(7) facilities engaged in the protection of government property;
(8) facilities that the Secretary, Deputy Secretary, or Under Secretaries deem
appropriate.
b. Site Safeguards and Security Plan (SSSP). The SSSP is a 5-year master planning
document that must be prepared for sites with facilities described in paragraphs
3a(1), (3), (4), or (8) above. The SSSP must depict the existing condition of site
protection programs and, when the DBT performance standard cannot be met,
establish improvement priorities and resource requirements for the necessary
improvements. Plan composition is reflected in Part 1, Section C, 5.
c. Site Security Plan (SSP). At locations where an SSSP is not required because of
the limited scope of interests (i.e., criteria contained in 3a(2), (5), (6), or (7)
above, apply), an SSP must be developed to describe the protection program.
SSPs must be approved by the local DOE cognizant security authority. In
addition, specialized plans must be developed to address protection programs for
other protection operations. Requirements for specialized plans that may or may
not be components of the SSP are set forth in the applicable DOE directives.
d. Planning Inputs. The documents listed below must be used to support program
forecasts and information input used in the protection program planning process.
DOE M 470.4-1 Part 1, Section A
8-26-05 A-5 (and A-6)
(1) Applicable Departmental directives, guidance, and intelligence assessment
information developed and disseminated by line management or the Office
of Security.
(2) Programmatic guidance and forecasts of significant changes planned in
site operations as communicated through line management.
(3) Current and projected operational constraints and resources.
(4) Analysis of cost and effectiveness of security technologies versus
traditional protection methodologies.
e. Plan Review and Approval.
(1) The SSSP requires approval by DOE line management and concurrence by
the cognizant Head of the Departmental Element (see Attachment 1).
Such approval authority must be formally delegated to line management.
(a) Copies of approved SSSPs must be provided to the Office of
Security for review and comment.
(b) Other security plans may be approved as stipulated in the
applicable directive. If approving authority is not otherwise
stipulated, these security plans may be approved by DOE line
management.
(2) The SSSP must be submitted to DOE line management within 150 days of
the termination date of data collection and approved within 120 days of
the submittal date. Directive changes, facility reconfiguration, a new VA,
or other activities that occur after the stated effective date will not be
considered for purposes of reviewing/approving the plan.
Section 14
(3) The SSSP must be reviewed annually (at least every 12 months). Updates
to the SSSP that may significantly alter the agreed-upon protection
philosophy or performance standards of protection systems must be
subjected to the formal VA process, and if changes are shown to
significantly alter system effectiveness performance, the update(s) will be
subject to the same concurrence and approval as stated in paragraph 3e(1),
above.
(4) An information copy of approved modifications must be provided to the
Office of Security.
DOE M 470.4-1 Part 1, Section A
8-26-05 Appendix 1, 1-1
SECTION A
APPENDIX 1—SAFEGUARDS & SECURITY MANAGEMENT PLAN
The Safeguards and Security (S&S) Management Plan provides a description of the
implementation of S&S policy and provides detailed information on the assignment of roles,
responsibilities, and authorities, as well as the development of budgets and allocation of
resources. The following outline delineates the content requirements and provides a suggested
format.
1. EXECUTIVE SUMMARY.
a. Program Mission Statement. Briefly describe the program mission and how the
mission relates to national security. Describe the major elements or activities
performed in terms of program mission and its relationship to the DOE national
security mission.
b. S&S Program Structure. Briefly describe the strategy and organizational
elements used to implement the S&S program under their cognizance.
c. Management and Planning Assumptions. Briefly describe those assumptions that
affect the management and planning of the implementation of the S&S program.
These assumptions should include items such as:
(1) future of the program (mission, staffing levels, site status, etc.);
(2) current and planned S&S projects; and
(3) status of the organization’s S&S budget.
2. PART 1—ORGANIZATIONAL STRUCTURE AND ACCOUNTABILITY
a. Line Management Organization. Describe the structure and relationship of line
management. Identify the roles, responsibilities, and authorities of these line
management elements to include organizational charts.
b. Cognizant Security Authority Organization. Describe the structure of line
management that is specifically responsible for implementing the Departmental
element’s S&S program. Identify the individuals and positions responsible for
committing resources and directing the activities of personnel associated with the
S&S program.
(1) Headquarters Organizational Structure. For the Headquarters elements,
provide an organizational chart to show the S&S organization and
management structure and the lines of authority and points of interface
with other programs which affect S&S (e.g., safety, facility operations,
and the cognizant security authority’s material control and accountability
Part 1, Section A DOE M 470.4-1
Appendix 1, 1-2 8-26-05
(MC&A) organization, if independent of the security organization).
Describe the functions and responsibilities of S&S personnel and indicate
how S&S activities are integrated with those of other facility
organizations; include organizational responsibilities for line management
overseeing the program as well as the interface points with the respective
Departmental element.
Section 15
(2) Field Organizational Structure. For the Field elements, provide an
organizational chart to show the S&S organization and management
structure and the lines of authority and points of interface with other
programs which affect S&S (e.g., safety, facility operations, and the
cognizant security authorities’ MC&A organization, if independent of the
security organization). Describe the functions and responsibilities of S&S
personnel and indicate how S&S activities are integrated with those of
other facility organizations; include organizational responsibilities for line
management overseeing the program as well as the interface points with
the respective Departmental element.
c. Contractor Sites. Provide the contract name, number, and other information that
describes the authority under which the contractor executes management
functions for facilities under the cognizance of a Departmental element. Identify
the site contractor elements responsible for S&S programs and describe their S&S
activities. Provide Federal and contractor organization charts and identify key
positions and the relationships between the organizations responsible for S&S
activities. Describe Federal and contractor involvement in the development of
S&S resource requirements.
3. PART 2—ROLES, RESPONSIBILITIES, DELEGATIONS, AND AUTHORITIES.
Delegations must be documented in writing and delineate all assigned S&S roles,
responsibilities, and authorities for the S&S program. This section:
a. documents offices/positions affected by the S&S Management Plan;
b. establishes the approval chain for S&S plans, procedures and implementation
policy;
c. establishes the approval chain for S&S policy deviations;
d. assigns reporting requirements for incidents of security concern; and
e. provides a list of roles and responsibilities for key positions and the delegated
authorities for each.
DOE M 470.4-1 Part 1, Section A
8-26-05 Appendix 1, 1-3 (and 1-4)
4. PART 3—S&S PROGRAM IMPLEMENTATION. This section of the S&S
Management Plan documents the processes and methods used to implement the
Department’s security policies. This section identifies:
a. the methods used for ensuring all applicable programmatic requirements are
implemented throughout the organizational element;
b. the methods used for ensuring effective integration of S&S programmatic
elements; and
c. SSSPs and SSPs used to implement S&S policy requirements.
5. PART 4—PLANNING AND BUDGET (INCLUDING PERSONNEL RESOURCES).
This section of the S&S Management Plan documents the key processes of planning and
budgeting, including strategic planning, budget formulation, budget execution, and
program evaluation.
a. Describe the strategic planning assumptions used to ensure the S&S program will
meet mission objectives.
b. Provide a 5-year plan that describes the budget formulation priorities for future
S&S resources and programs.
c. Provide the current year plan for executing the S&S budget. This plan details the
allocation of resources that support S&S functions and missions.
d. Provide a program evaluation plan that details how the cognizant security
authority will assess the implementation of the S&S program and the
organization’s progress toward meeting established missions/goals. The program
evaluation plan must cover both the Federal and contractor elements of the
Departmental element. This plan can be used to support award fee decisions by
the Departmental element.
Section 16
e. Briefly describe any changes to operational requirements which affect S&S
program operations or would require increments or decrements to operational
accounts (e.g., program direction, operational support, etc.).
DOE M 470.4-1 Chg 1 Part 1, Section A
3-7-06 Appendix 2, 2-1
Vertical line denotes change.
SECTION A
APPENDIX 2—DEPARTMENT OF ENERGY TACTICAL DOCTRINE
1. INTRODUCTION.
a. Overview. The establishment of Departmental doctrine governing the defense of
sensitive national security assets is necessary to ensure the uniform application of
effective security measures throughout the complex. This appendix is the
condensed expression of the Department‘s fundamental approach to protecting
nuclear weapons and components, special nuclear material, or targets subject to
radiological or toxicological sabotage. In keeping with the development of higher
standards for individual training and fitness, aggressive small unit tactics must be
employed within the bounds of a well-defined and constructed area defense that is
supported by fixed strong points, obstacles/barriers, advanced detection and
assessment capabilities, coordinated fire planning, updated weapon systems, and
armored vehicles.
b. Purpose of an Armed Protective Force (PF). Within DOE, armed PFs exist to
deter and to defeat terrorist or other adversarial actions that could have major
national security consequences; primarily, unauthorized access to nuclear
weapons and components, special nuclear material, or targets subject to chemical,
biological, or radiological sabotage or that contain a unique capability that must
be protected. When availability of armed PFs is limited, they shall not be used to:
(1) perform routine, repetitive tasks that are not related directly to target
protection;
(2) perform access control functions that can be better accomplished through
automation;
(3) act as administrative escorts for construction projects or service personnel
(unless required for protection of assets); or
(4) staff posts that offer convenience to management and/or employees.
2. TACTICAL DOCTRINE.
a. Concept. In general, at Category I/II facilities within the DOE, defensive plans
will involve an area defense with fixed strong points, or fighting positions, that
encompass a target and lie within a concentric arrangement of intrusion detection
systems and barriers designed to detect, delay, and engage the adversary as far
from the target as possible. A Tactical Response Force (TRF) consisting of
highly trained, motivated, and skilled tactical units/teams will be positioned on, or
in proximity to, each target. Early detection will permit interdiction by mobile
Part 1, Section A DOE M 470.4-1 Chg 1
Appendix 2, 2-2 3-7-06
Vertical line denotes change.
response teams using fire and maneuver techniques to deny further access to
adversaries and/or to channel them into attrition areas covered by interlocking
bands of fire from fixed, hardened fighting positions.
b. Defensive Planning Principles.
(1) Prepare the Defensive Area.
(a) Prepare a barrier plan to:
1 Minimize the number of access points and/or avenues of
approach.
2 Channel the adversary into attrition areas by use of barriers
and preplanned, interlocking bands of fire.
3 Control the high ground, either by physical presence or by
weapons fire.
(b) Prepare a defensive fire plan to ensure that:
1 clear fields of fire and observation across the battlefield are
maintained;
2 defensive positions are mutually supporting;
Section 17
3 high volumes of fire can be brought onto key terrain
features, obstacles, and along expected routes of approach;
and
4 the volume of fire brought upon an adversary increases as a
target area is approached.
(2) Integrate All Aspects of the Defensive Plan.
(a) Employ multiple layers of detection.
(b) Employ multiple layers of delay (e.g., barriers/obstacles).
(c) Integrate technology, such as remotely operated weapon systems
ROWS), active denial systems, and advanced detection and
observation systems, with response force tactics.
(d) Ensure that barriers are covered by weapons fire.
(e) Ensure that the entire defensive perimeter is covered by
interlocking fields of fire from mutually supporting positions.
DOE M 470.4-1 Chg 1 Part 1, Section A
3-7-06 Appendix 2, 2-3
Vertical line denotes change.
(f) Where feasible, control the configuration of the battlefield by
eliminating anything that could provide potential adversary cover
and/or concealment.
(g) Ensure that likely avenues of approach are defended with sufficient
force to compel a decisive engagement with the adversary.
(h) Protect defenders by employing hardened fighting positions
situated for mutual support.
(i) Establish supplementary defensive positions.
(j) Prepare to maneuver offensive forces to attack and to defeat an
adversary whose progress is delayed by engagement with
defensive fire.
(3) Make the Adversary Fight to the Target.
(a) Adversary detection and engagement must occur as far from the
target as possible.
(b) Assign sufficient resources to be able to assess remote alarms to
identify the number of adversaries, thereby helping to differentiate
between diversionary attacks and the main force.
(c) Plan for staged withdrawal of forces dispatched to assess remote
alarms to prepared supplementary defensive positions.
(d) Plan for overwatch of assessment forces with long range weapons
from within the defensive perimeter.
(e) Coordinate barrier and fire control planning to ensure that the
adversary will be subjected to high volumes of fire in exposed
positions prior to entry into the defensive perimeter.
(f) Ensure adequate standoff for vehicle-borne improvised explosive
devices (VBIEDs).
(g) Limit the ability of airborne improvised explosive devices to
impact key defensive positions and primary target buildings.
(4) Make the Target Location Deadly.
(a) Use technology to distract, interrupt, disable, or neutralize anyone
who has obtained unauthorized access to target locations.
(b) Include considerations for re-entry and recapture of target locations
in all barrier and response plans.
Part 1, Section A DOE M 470.4-1 Chg 1
Appendix 2, 2-4 3-7-06
Vertical line denotes change.
(5) Manage the Site Population.
(a) Limit the number of personnel, vehicles, and equipment in the
target area at all times.
(b) Develop formal site-specific procedures for the disposition of
workers in the event of an attack.
1 If the tactical conditions permit, workers may be evacuated
to safe areas from prospective target locations and likely
avenues of approach.
2 Sheltering in place may be the best option. Workers should
be provided with specific instructions, such as to remain off
the phone unless they possess information about the event,
to lie on the floor, and, if PF enter their location, to keep
their hands and security badges visible.
Section 18
c. Tactical Application. The TRF is deployed in a strategic posture to interrupt,
interdict, deny, and neutralize an adversary force attack. The TRF is armed and
equipped with state of the art weaponry, tactical equipment, vehicles, and
communication systems. The TRF is adept at implementing approved Security
Incident Response Plans under adverse emergency conditions. The primary
mission of the TRF is the protection of nuclear weapons, weapons components,
and SNM from theft, sabotage, and unauthorized control. Ancillary duties include
the safeguarding of classified information and other classified assets.
(1) Tactical Response Force Characteristics.
(a) Survivability
(b) Mobility
(c) Lethality
(d) Flexibility
(e) Speed
(f) Unpredictability
(g) Mutual Support
(h) Reliable communications
(2) Tactical Response Force Element Missions. A site TRF is composed of
small units/teams of no fewer than two SPO II and/or SPO III personnel,
deployed in configurations that provide tactical advantages for both
DOE M 470.4-1 Chg 1 Part 1, Section A
3-7-06 Appendix 2, 2-5
Vertical line denotes change.
defensive and offensive operations.
(a) Special Response Team (SRT).
Mission: The SRT executes recapture/recovery and pursuit
operations and supports interruption, interdiction, neutralization,
containment, and denial strategies.
Capabilities: SPO III qualified personnel are deployed as one or
more dedicated teams with specialized weapons and equipment,
operating from mobile tactical vehicles, as ground assault forces,
or a combination of both.
(b) Security Police Officer-II.
Mission: Executes interruption, interdiction, neutralization,
containment, and denial strategies and supports recapture/recovery
and fresh pursuit operations.
Capabilities: SPO II personnel operate in small units with
specialized weapons and equipment from mobile patrols/tactical
vehicles and fixed posts.
(3) Tactical Response Force Support. All site Security Police Officers and
Security Officers have a key role in supporting the overall site security
posture and the TRF.
(a) Security Police Officer-I.
Mission: Supports interruption, interdiction, neutralization,
containment, and denial strategies.
Capabilities: SPO I personnel operate from mobile patrols and
fixed posts. SPO I personnel perform routine S&S related
functions and are capable of performing specialized active defense
functions such as staffing defensive fighting positions, operating
Remotely Operated Weapon Systems (ROWS), and performing
Central Alarm Station (CAS) duties.
(b) Security Officer.
Mission: Ensures routine security-related functions are maintained
(e.g., access/egress control, escort duties, CAS operations).
Capabilities: Unarmed SOs perform observation and reporting
activities, logistical re-supply to other PF elements, message
courier duties, and provide transportation support.
Part 1, Section A DOE M 470.4-1 Chg 1
Appendix 2, 2-6 3-7-06
Vertical line denotes change.
(4) Deployment Considerations.
(a) A layered, or zone, defensive strategy is implemented that
maximizes the TRF’s ability to detect, engage, and neutralize
adversary forces as they move toward a target location.
(b) Fixed, reinforced fighting positions, or bunkers, are utilized to
enhance survivability, deny access to targets, provide overlapping
fields of fire for mutual support, and to control avenues of
approach.
(c) Protection strategies are designed to reduce predictability of the
response.
Section 19
(d) Small units/teams of no fewer than two SPO II and/or SPO III
personnel are deployed in configurations that provide tactical
advantages for both defensive and offensive operations.
(e) Personnel who will occupy fixed fighting positions, those who will
perform as the flexible maneuver elements, and those who will, if
required, conduct recapture/recovery operations are identified.
(f) Each TRF member is issued at least one primary weapon along
with a secondary firearm, such as a handgun, used principally for
close quarters engagement or for transition in the event of a
stoppage of the primary weapon.
(g) TRF weapons are capable of tactical operations in both day and
night conditions.
(h) The TRF employs direct-fire weapons (i.e., machine guns,
precision rifles, battle rifles, etc.) to engage and to neutralize
adversary forces out to the maximum effective range of the
weapon.
(i) As prescribed by the SSSP, the TRF employs indirect-fire or
explosive projectile weapons (e.g., M3 MAAWS, MK19/GMG,
M203, etc.) to deny access to target locations and to suppress and
to neutralize adversary forces occupying positions of cover and/or
concealment.
(j) TRF members are knowledgeable of adversary attack methods
identified in the Design Basis Threat (DBT) and critical pathways
documented in site-specific vulnerability assessment reports.
DOE M 470.4-1 Chg 1 Part 1, Section A
3-7-06 Appendix 2, 2-7
Vertical line denotes change.
(k) A secure tactical command post is identified to ensure that
command, control, and communications links are maintained and
that backup systems are available.
(l) Command and control is structured down to the lowest unit/team
level. Operational control of forces includes organizing and
employing of forces, designating combat objectives, assigning
individual and unit tasks, and issuing orders and directions
necessary for mission accomplishment.
(m) Accurate adversary and battle information is relayed to
command/control centers as it occurs.
(n) A system for Identification, Friend or Foe (IFF) is employed to
minimize incidents of casualties from “friendly fire.”
(5) Denial Strategy Implementation.
(a) Early warning system technologies are emplaced to detect and to
assess adversary movement as far as possible from target locations.
(b) Highly mobile tactical vehicles (armored and/or unarmored)
mounted with light and/or heavy weapon systems are deployed to
support combat operations, conduct reconnaissance operations,
control avenues of approach, maneuver to suppress and destroy
hostile threats, and to provide mutual support for other tactical
vehicles.
(c) A commander is designated for each tactical armored vehicle (for a
two-person crew, usually the gunner).
(d) Potential target access points are covered by suppressive fire
weapons.
(e) TRF members utilize positions of cover and maximize the element
of surprise to the extent possible.
(f) The TRF initiates a decisive engagement with adversary forces as
far as possible outside the target location.
(g) Once an adversary has been identified and engaged, TRF elements
never lose contact.
(h) Adversaries are engaged while they negotiate obstacles (i.e.,
fences, barriers, etc.), deploy from vehicles (both airborne and
ground based), and cross open ground.
Part 1, Section A DOE M 470.4-1 Chg 1
Appendix 2, 2-8 3-7-06
Vertical line denotes change.
(i) TRF teams, using suppressive fire weapons, maneuver in force
against adversaries occupying covered positions.
Section 20
(j) The TRF has plans in place to transition quickly from defensive to
offensive operations.
(6) Recapture/Recovery Operations.
(a) The site PF is staffed and deployed in sufficient strength to ensure
the protection of sensitive assets. The dedicated
recapture/recovery element of the SRT is established with
additional resources sufficient to ensure that recapture/recovery
capabilities continue to exist in the event that the denial strategy
fails.
(b) SRT training is focused on site-specific targets and ensures that
SRTs are adequately prepared to conduct recapture/recovery
operations within identified target locations.
(c) SRTs possess the tactics, tools, and techniques necessary to gain
entry, neutralize the adversary threat, control the situation, and
secure national security assets.
(d) If hostages are involved and SNM is at risk, regaining control of
the SNM is the primary consideration.
(e) SRTs are supported by other TRF elements to the maximum extent
possible as they move toward the target objective.
(f) TRF members provide overwatch for the assault team(s)
movement, cover avenues of approach, and provide support by fire
to the SRT as they breach/enter the target location.
(g) All TRF personnel are capable of providing direct support to the
recapture/recovery mission by supplementing the main assault
force, controlling the target area, and suppressing enemy defensive
positions.
(7) Pursuit Operations.
(a) TRF members are trained and equipped to conduct Fresh Pursuit
operations, on and off DOE property in accordance with DOE
M 470.4-3, Section A, Appendix A-1, “Guidelines for Fresh
Pursuit.”
DOE M 470.4-1 Chg 1 Part 1, Section A
3-7-06 Appendix 2, 2-9
Vertical line denotes change.
(b) Fresh Pursuit operations are coordinated with responding Federal,
State, and local law enforcement agencies according to approved
agreements.
(c) TRF members use vehicle immobilization techniques and/or other
means of applying deadly force to terminate the pursuit.
(d) TRF members maintain control of sensitive assets until relieved by
cognizant Federal authorities.
(8) Weapons of Mass Destruction.
(a) All TRF and SPO-I personnel are trained and equipped to operate
within an environment where Weapons of Mass Destruction
(WMD) have been employed; i.e., chemical, biological, or
radiological weaponry. PF training programs include tactical
deployment in WMD personal protective equipment.
(b) TRF members are able to transition to WMD fighting procedures
rapidly enough so as to not weaken the overall combat posture.
(c) Individual tactical equipment is compatible with WMD personal
protective equipment.
3. MANAGEMENT CONSIDERATIONS.
a. Training. Training is the key to a quality force, and the best form of tactical
training is person-on-person, or force-on-force (FOF) engagements, on a
repetitive basis. A requirement for increased FOFs for training purposes does not
always have to involve the very large scale exercises that are conducted during
inspections and annual SSSP validations. Nor do they always need to occur in or
around the actual facilities. Encouraging and assisting PF members to refine their
individual and small unit tactical skills and to condition them to the reflex of
shooting at adversaries can be facilitated with smaller scale training exercises
using surrogate facilities. This will enable the Department to afford a much
higher frequency of such activities because the costs in terms of facility shut
down, coordination with operations, shadow force deployment, etc., will be
substantially avoided. But, in order to achieve the desired results, these exercises
must employ engagement simulation systems such as Multiple Integrated Laser
Engagement Systems (MILES), dye marking cartridge (DMC) weapons, or hybrid
DMC/MILES weapons that combine DMC for close-range and MILES for longer
range.
Section 21
b. Planning and Implementation. There are issues that may be considered ancillary
to the planning and implementation of the DOE facility defense model but which
nevertheless are important to the viability of tactical planning and execution.
Some factor directly into the planning process while others relate indirectly.
Part 1, Section A DOE M 470.4-1 Chg 1
Appendix 2, 2-10 3-7-06
Vertical line denotes change.
Examples are:
(1) Targets must be as small and as few as possible.
(2) All tactical training should simulate as closely as practicable the
environment and manner in which PF personnel are expected to fight.
(3) Persons assigned as full-time staff PF instructors must be qualified in
accordance with the provisions of DOE M 470.4-3, Protective Force,
Section A, Chapter II, paragraph 9.
DOE M 470.4-1 Part 1, Section B
8-26-05 B-1
SECTION B—SECURITY CONDITIONS
1. OBJECTIVE. To ensure that the Department uniformly meets the requirements of the
Homeland Security Advisory System outlined in Homeland Security Presidential
Directive-3, (HSPD-3), dated 3-11-02, and provides the responses specified in
Presidential Decision Directive 39, U.S. Policy on Counterterrorism (U), dated 6-21-95.
2. THREAT INDICATORS. While the Design Basis Threat (DBT) provides specific
description of threats that all components of the safeguards and security (S&S) system
must be capable of defeating, analysis of terrorism should be an ongoing process.
Although each analysis relies on information included in previous assessments,
judgments with respect to threats to Federal and Department of Energy (DOE)-affiliated
personnel, facilities, and assets begin anew with each analysis.
a. Homeland Security Threat Conditions [known in DOE as Security Conditions
(SECONs)] are established based on the analysis of a continuous and timely flow
of integrated all-source threat assessments and reporting provided to Executive
Branch decision-makers. A threat indicator is a condition that, when present,
increases the possibility of a terrorist incident. Seldom does one single indicator
suggest that the threat is imminent, but, when a number of indicators are present,
the level of concern should increase correspondingly. A decision on assigning
SECONs must integrate a variety of considerations. This integration will rely on
qualitative assessment, not quantitative calculation. Higher SECONs indicate
greater risk of a terrorist act, with risk including both probability and gravity.
Despite best efforts, there can be no guarantee that, at any given SECON, a
terrorist attack will not occur. An initial and important factor is the quality of the
threat information itself. The evaluation of this threat information includes, but is
not limited to, the following factors.
(1) To what degree is the threat information credible?
(2) To what degree is the threat information corroborated?
(3) To what degree is the threat specific and/or imminent?
(4) How grave are the potential consequences of the threat?
b. Local and site-specific threat analysis is a dynamic process because the threat and
the countermeasures used to combat the threat are constantly changing. To keep
up with possible changes in the threat, security professionals should develop a
predetermined list of general and specific threat indicators. Threat indicators
should be revised according to site/facility situations and needs. They should be
reviewed at least every 6 months or when a significant incident or change in
conditions indicates that the threat level is increasing or decreasing. Examples of
threat indicators that can be used to develop a site-/facility-specific assessment are
listed below.
Section 22
Part 1, Section B DOE M 470.4-1
B-2 8-26-05
(1) International incidents or indicators against U.S. interests, personnel, or
facilities.
(2) Domestic incidents or indicators against Federal or State interests
countrywide.
(3) Local incidents or indicators directed against Federal or DOE interests.
(4) Specific targeting of DOE personnel, facilities, or materials.
3. SECURITY CONDITIONS. The DOE SECON system has been aligned with the
Homeland Security Advisory System.
a. The DOE SECON system describes a progressive level of common sense
protective measures that may be implemented in response to a malevolent or
terrorist threat to any or all DOE facilities, assets, and personnel. The purpose of
the SECON system is to establish standardized protective measures for a wide
range of threats and to help disseminate appropriate, timely, and standardized
information for the coordination and support of DOE crisis or contingency
activities. Once a SECON level is declared, the associated protective measures
should be implemented as soon as possible to the extent they apply to the
individual site or facility. Cognizant security authorities must coordinate SECON
status through their DOE points of contact, as appropriate, and notify the DOE
Headquarters (HQ) Operations Center (OC) and Departmental element of the
site/facility SECON status. Measures associated with each SECON are not
prioritized but should be initiated concurrently when practical.
b. National Nuclear Security Administration (NNSA) facilities must be prepared to
respond to SECON directives provided by the Under Secretary for Nuclear
Security/Administrator, NNSA. Non-NNSA facilities must be prepared to
respond to SECON directives provided by the Under Secretary for Energy,
Science and Environment for their individual facilities. Headquarters facilities
must be prepared to respond to SECON directives provided by the Director,
Office of Security. At their discretion, DOE line management may increase
protection measures for facilities under their cognizance if they determine that the
local threat situation warrants additional security. In this event, the DOE HQ OC
and Departmental element must be notified of the SECON level. If DOE line
management or Departmental elements believe that their facilities’ SECON levels
should be less than those issued by the Under Secretary for Energy, Science and
Environment or the Under Secretary for Nuclear Security/Administrator, NNSA,
a request for exception must be submitted for consideration (see paragraph 3c
below).
c. Any departure from the requirements of this section must be considered an
exception which must be approved in accordance with the requirements set forth
in Section M. No exception is permitted to the protective measures when under
SECON 1, Severe Condition (Red).
DOE M 470.4-1 Part 1, Section B
8-26-05 B-3
d. To the extent possible throughout each increase or decrease in SECON, the
cognizant security authority must:
(1) keep employees informed;
(2) coordinate when appropriate with State and local officials’ actions taken
regarding security and emergency planning; and
(3) at each level of SECON, review security plans, vulnerability assessments
(VAs), emergency response procedures, public affairs guidance and plans,
legal authorities, and Continuity of Operations Plans.
e. A record of specific actions taken for each measure must be maintained. A
description of each SECON, including the necessary circumstances for
implementing, the impact on operations, and the purpose of each protective
posture, is outlined below.
Section 23
(1) SECON 5, LOW CONDITION (GREEN). This condition is declared
when there is a low risk of terrorist attacks. SECON 5, Low Condition
(Green) exists when a general threat of possible malevolent or terrorist
activity exists, but warrants only a routine security posture.
(2) SECON 4, GUARDED CONDITION (BLUE). This condition is
declared when there is a general risk of terrorist attacks. SECON 4,
Guarded Condition (Blue) applies when there is an increased general
threat of possible malevolent or terrorist activity against personnel and
facilities, the nature and extent of which are unpredictable, and
circumstances do not justify full implementation of SECON 3, Elevated
Condition (Yellow) measures. It may be necessary, however, to
implement certain selected measures from higher SECONs to address
intelligence received or to act as a deterrent. All measures selected for use
under SECON 4, Guarded Condition (Blue) must be capable of being
maintained indefinitely.
(a) Measure 1. At regular intervals, warn all personnel to report the
following to security:
1 suspicious personnel, particularly those carrying suitcases
or other containers, or those observing, photographing, or
asking questions about site operations or security measures;
2 unidentified vehicles parked or operated in a suspicious
manner on or in the vicinity of the site or near site facilities;
3 abandoned parcels or suitcases; and
4 any other activity considered suspicious.
Part 1, Section B DOE M 470.4-1
B-4 8-26-05
(b) Measure 2.
1 Ensure that security personnel have immediate access to
building floor plans and emergency/evacuation plans for all
site facilities.
2 Ensure that security personnel are able to seal off an area
immediately.
3 Ensure that key personnel required to implement security
plans are on-call and readily available.
4 Maintain the site Emergency Management Team (EMT) on
2-hour recall.
5 Expand Operations Security measures.
6 Exercise bomb threat procedures.
(c) Measure 3. Secure and seal buildings, rooms, and storage areas
not in regular use. Maintain a list of secured facilities.
(d) Measure 4. Increase unannounced security spot checks (inspection
of personal identification; vehicle registration; and the contents of
vehicles, suitcases, briefcases, and other containers) at access
points for the site and facilities.
(e) Measure 5. Reduce the number of access points for vehicles and
personnel to minimum levels consistent with the requirement to
maintain a reasonable flow of traffic.
(f) Measure 6. As a deterrent, randomly apply measures 14, 15, 16,
17, or 18 from SECON 3, Elevated Condition (Yellow) either
individually or in combination.
(g) Measure 7. Review all operations plans, personnel details, and
logistics requirements that pertain to implementing higher
SECONs.
(h) Measure 8. Review security measures for critical/sensitive
personnel (e.g., directors, managers, members of special access/
security programs, etc.) and implement additional measures
warranted by the threat and existing vulnerabilities (e.g., identified
personnel should alter established patterns of behavior when
traveling in public areas).
DOE M 470.4-1 Part 1, Section B
8-26-05 B-5
(i) Measure 9. Increase liaison with local law enforcement,
intelligence community, security agencies, and the Federal Bureau
of Investigation, (FBI) to monitor the threat to site personnel and
facilities. Notify local law enforcement agencies and the FBI
concerning SECON 3, Elevated Condition (Yellow) measures that,
if implemented, could affect their operations in the local
community.
Section 24
(j) Measure 10. Reserve for site/facility use.
(3) SECON 3, ELEVATED CONDITION (YELLOW). A SECON 3,
Elevated Condition (Yellow) is declared when there is a significant risk of
terrorist attack. Elevated Condition (Yellow) applies when an increased
and more predictable threat of malevolent or terrorist activity exists. The
measures in this SECON must be capable of being maintained for lengthy
periods without causing undue hardship, affecting operational capability,
or aggravating relations with the local community. For measures
requiring an increase in the frequency of a specific action, the new
frequency is to be more often than in the lower-level security condition.
In addition to the measures required by SECON 4, Guarded Condition
(Blue), the following measures should be implemented.
(a) Measure 11. Increase the frequency of warnings required by
Measure 1, and inform personnel of additional unclassified threat
information, if available. Encourage increased community security
awareness of suspicious persons, vehicles, and activities.
(b) Measure 12. Maintain EMT personnel on 2-hour recall;
periodically exercise recall to ensure readiness. Keep all other
personnel involved in implementing special response/contingency
plans on call. Identify, contact, and brief specialists that may be
required for unique contingencies; coordinate lines of
communication.
(c) Measure 13. Review provisions of all operations plans and orders
and special operating procedures associated with implementing
SECON 2, High Condition (Orange).
(d) Measure 14. Move automobiles and objects such as trash
containers, newspaper boxes, crates, etc., at least 30 yards from all
facilities, particularly buildings of a sensitive or prestigious nature.
Identify any areas where an improvised explosive device could be
hidden (i.e., pallet stacks, trash piles, stacked construction supplies,
etc.). If the configuration of the facility or area precludes
implementation of this measure, take appropriate compensatory
measures per local plans [frequent inspection by Explosive
Part 1, Section B DOE M 470.4-1
B-6 8-26-05
Ordnance Disposal (EOD) teams, if available; controlled access to
parking areas; etc.]. Consider centralized parking.
(e) Measure 15. Secure, seal, and regularly inspect all buildings,
rooms, and storage areas that can be isolated with minimum site
impact.
(f) Measure 16. At the beginning and end of each work day and at
frequent intervals, inspect the interior and exterior of buildings in
regular use for suspicious activity or unattended packages and for
signs of tampering or indications of unauthorized entry.
(g) Measure 17. Implement screening procedures for all incoming
official mail to identify possible explosive or incendiary devices or
other dangerous material. If available, have EOD-trained teams
inspect suspicious items and screen mail periodically. Provide
guidance concerning suspicious packages. Encourage employees
to inspect their individual mail, report suspicious items to security,
and refrain from handling such items until cleared by the
appropriate authority.
(h) Measure 18. Inspect other deliveries and locally designated
common-use facilities to identify explosives and incendiary,
biological, or chemical devices. Use EOD-trained teams for some
screening inspections when available. Instruct site personnel to
report suspicious packages to security and refrain from handling
them until cleared by the appropriate authority.
Section 25
(i) Measure 19. Increase both overt and covert security force
surveillance of locally designated soft targets to improve
deterrence and build confidence among site personnel. (Covert
surveillance must comply with DOE directives and appropriate
regulatory restrictions.)
(j) Measure 20. Inform employees of the general threat situation.
Limit visitors and escorted uncleared personnel. Periodically
update all personnel as the situation changes to stop rumors and
prevent unnecessary alarm.
(k) Measure 21. Brief representatives of all activities on the site
concerning the threat and security measures implemented in
response to the threat. Explain reasons for actions. Implement
procedures to provide periodic updates for these activity
representatives.
(l) Measure 22. Verify the identity of all personnel entering property
protection areas (PPAs) and other sensitive activities specified in
DOE M 470.4-1 Part 1, Section B
8-26-05 B-7
local plans (i.e., inspect identification badges and grant access
based on visual recognition). Use of automated access control
systems at interior security areas is acceptable and encouraged,
where practical.
On a random basis, visually inspect the interior of all vehicles and
the exterior of all suitcases, briefcases, packages, and other
containers. Increase the frequency of detailed vehicle inspections
(trunk, undercarriage, glove boxes, etc.) and the frequency of
detailed inspections of suitcases, briefcases, and other containers.
(m) Measure 23. Increase the frequency of random identity checks
(inspection of security badges and vehicle registration documents)
conducted by security force patrols on the site.
(n) Measure 24. Remind all personnel to lock parked vehicles and
inspect vehicles for suspicious items before entering and driving
them.
(o) Measure 25. Implement additional security measures for
critical/sensitive personnel in accordance with existing plans.
(p) Measure 26. Brief all security force personnel concerning the
threat and policies governing rules of engagement, use of deadly
force, and fresh pursuit. Ensure there is no misunderstanding of
these instructions. Repeat this briefing on a periodic basis.
(q) Measure 27. Increase liaison with local police, intelligence,
security agencies, and the FBI to monitor the threat to site
personnel and facilities. Notify local police agencies concerning
SECON 2, High Condition (Orange) or SECON 1, Severe
Condition (Red) measures that, if implemented, could affect their
operations in the local community.
(r) Measure 28. Survey the surrounding area to determine whether
operational activities near the area might create emergencies or
contingencies that could affect the site/facility (e.g., airports,
military/other government facilities, industrial facilities, railroads
or pipelines, etc.).
(s) Measure 29. Reserve for site/facility use.
(4) SECON 2, HIGH CONDITION (ORANGE). A SECON 2, High
Condition (Orange) is declared when there is a high risk of terrorist
attacks. This condition applies when an incident occurs or intelligence is
received indicating that some form of malevolent or terrorist action against
personnel and facilities is imminent. Implementation of measures in this
Part 1, Section B DOE M 470.4-1
B-8 8-26-05
security condition for more than a short period probably will create
hardship and affect the routine activities of the site and its personnel. For
measures requiring an increase in the frequency of a specific action, the
new frequency is to be more often than in the lower level SECON. The
following measures should be implemented.
Section 26
(a) Measure 30. Continue all SECON 4, Guarded Condition (Blue)
and SECON 3, Elevated Condition (Yellow) measures or introduce
those that have not already been implemented.
(b) Measure 31. Recall staff representatives and initiate 24-hour
operation of the EMT. Place the Special Response Team (SRT) on
standby alert. Keep all personnel responsible for implementing
special/response contingency plans at their places of duty. Review
site evacuation plans.
(c) Measure 32. Reduce site access points to the absolute minimum
necessary for continued operation.
(d) Measure 33. Verify the identity of all personnel entering the
site/facilities, including appropriate offsite facilities under DOE
control. Inspect all security badges for tampering. On a random
basis, visually inspect the interior of all vehicles and the exterior of
all suitcases, briefcases, and other containers. Increase the
frequency of detailed vehicle inspections (trunk, undercarriage,
glove compartments, etc.) and the frequency of inspections of
suitcases, briefcases, and other containers.
(e) Measure 34. Implement centralized parking and shuttle bus
service, where required.
(f) Measure 35. Ensure that security personnel have been briefed
concerning policies governing the rules of engagement, use of
force, and fresh pursuit, particularly criteria for use of deadly
force. Ensure that non-security supervisory personnel are familiar
with above policies and procedures, if applicable. Ensure that
special equipment and ammunition are available for immediate
issue.
(g) Measure 36. Increase security patrol activity to the maximum
level sustainable. The concept of continuing random security
patrol activity is encouraged.
(h) Measure 37. Position security force personnel in the vicinity of
critical facilities.
(i) Measure 38. Erect barriers required to control direction of traffic
DOE M 470.4-1 Part 1, Section B
8-26-05 B-9
flow and to protect facilities vulnerable to bomb attack by parked
or moving vehicles.
(j) Measure 39. Consult local authorities about closing public roads
and facilities that might make sites more vulnerable to terrorist
attacks.
(k) Measure 40. Consider canceling public events.
(l) Measure 41. Consider initiating Continuity of Operations plans
(m) Measure 42. Reserve for site/facility use.
(5) SECON 1, SEVERE CONDITION (RED). A SECON 1, Severe
Condition (Red) reflects a severe risk of terrorist attacks. This condition
applies in the immediate area where a malevolent or terrorist attack has
occurred that may affect the site or when an attack is initiated on the site.
Implementing SECON 1, Severe Condition (Red) will create hardship and
affect the activities of the site and its personnel. Normally, this SECON is
declared as a localized response. For measures requiring an increase in
the frequency of a specific action, the new frequency is to be more often
than in the lower-level SECON. The following measures should be
implemented.
(a) Measure 43. Continue all previous SECON measures and
introduce those that have not already been implemented.
(b) Measure 44. Augment security forces to ensure absolute control
over access to the site, facilities, and other potential target areas.
Establish surveillance points; use night-vision devices.
Section 27
(c) Measure 45. Working closely with facility management, identify
the owners of all vehicles already on the site. In those cases where
the presence of a vehicle cannot be explained (owner is not present
and the vehicle has no obvious site affiliation), inspect the vehicle
for explosives; incendiary, chemical, or biological devices; or other
dangerous items and remove the vehicle from the vicinity of
facilities, soft targets, and other sensitive areas as soon as possible.
(d) Measure 46. Inspect all vehicles entering the site. Inspections
should include cargo storage areas, undercarriage, glove boxes,
and other areas where explosives, incendiary, chemical, or
biological devices or other dangerous items could be concealed.
(e) Measure 47. Limit access to the site, facilities, and other areas to
those personnel with a legitimate and verifiable need to enter.
Implement positive identification of all personnel. No exceptions.
Part 1, Section B DOE M 470.4-1
B-10 8-26-05
(f) Measure 48. Inspect all baggage such as suitcases, packages, and
briefcases brought on the site for explosives, incendiary, chemical,
or biological devices, or other dangerous items.
(g) Measure 49. Implement frequent inspections of the exterior of
buildings (including roof areas) and parking areas. Conduct
inspections at facilities and in the vicinity of soft targets.
(h) Measure 50. Coordinate with the Operations Division/Center to
establish communications, responsibilities, and authorities before,
during, and after attack.
(i) Measure 51. Request that local authorities close those public roads
and facilities in the vicinity of the site/facilities that might facilitate
execution of a malevolent or terrorist attack.
(j) Measure 52. Cancel public events.
(k) Measure 53. Execute Continuity of Operations plans.
(l) Measure 54. Reserve for site/facility use.
DOE M 470.4-1 Part 1, Section C
8-26-05 C-1
SECTION C—SITE SAFEGUARDS AND SECURITY PLANS
1. OBJECTIVE. The Site Safeguards and Security Plan (SSSP) is a risk management
document that provides summary information used to describe safeguards and security
(S&S) programs and vulnerability and risk assessments at applicable sites. The objective
of this section is to delineate SSSP content and establish a standard approach to
presenting site protection information and vulnerability assessment (VA) results. The
results and conclusions contained in the plan are intended to guide long-term planning for
site S&S operations. This is accomplished during plan development by identifying: key
site protection elements; annually (at least every 12 months) evaluating site protection in
terms of its adequacy to meet continued mission and threat parameters; and, identifying
resource requirements.
2. APPLICATION. The SSSP is used to evaluate site and facility program elements and
resources as they relate to identified threats and risks. The protection measures identified
in approved SSSPs become the basis for executing and reviewing site protection
programs.
3. SCOPE. The approved SSSP provides assurance that S&S measures address identified
threats and risks. To provide this assurance, the plan must reiterate the assumptions
identified to, and agreed upon, by line management. These assumptions must include
reference to the contract under which the site is operated and those contractual issues that
may impact S&S, applicable Department of Energy (DOE) directives, the threat upon
which VAs are based, the methodology used to conduct VAs, deviations and proposed
deviations, and any unique S&S impacting issues and assumptions that were addressed,
and agreed to, by the responsible parties.
Section 28
4. PURPOSE. The SSSP describes the graded protection of DOE assets required to be
implemented by line management. The SSSP identifies site risks, cost-benefit analyses,
and comparison of proposed upgrades. The resource plan (RP) must identify near- and
long-term resource requirements needed to ensure the integrity of existing and planned
S&S upgrades. The annual (at least every 12 months) review serves as the basis for
tracking the implementation of protection measures and strategies necessary to maintain
system effectiveness and identifies unfunded requirements.
5. PLAN COMPOSITION. The SSSP includes:
a. references to implementing documents and evidence files;
b. descriptions of site protection strategies, key site S&S programs, approved and
pending deviations, plans and procedures designed to implement, manage and
maintain S&S programs;
c. system effectiveness determinations for the protection of special nuclear material
(SNM), prevention or mitigation of sabotage events, and prevention and/or timely
detection of the loss of classified information or matter based on the status of
Part 1, Section C DOE M 470.4-1
C-2 8-26-05
performance indicators, such as results of VAs, performance tests, surveys,
inspections, and evaluations of personnel qualifications and training;
d. proposed S&S program upgrades;
e. VAs results that support conclusions reported in the SSSP;
f. assumptions used as part of the VA process;
g. threat parameters used for VAs that are described in the current Design Basis
Threat (DBT), regional threat assessments, and impacts made by local area threat
assessments, if applicable;
h. the details of the changes in the protection through the spectrum of Security
Conditions (SECON) (1-5), to include effects on the calculated baseline system
effectiveness;
i. a description of the evidence files containing material that supports the VAs; and
j. an RP that describes S&S upgrades programmed for completion, upgrades being
introduced as a result of planned and unplanned site changes impacting the
protection program or deficiencies identified as a result of the annual (at least
every 12 months) review of the SSSP, a description of the funding source to
implement the upgrades, and unfunded requirements.
6. EVIDENCE FILES. Supporting documentation that validates data/information used in
the VA process and in other protection program planning presented in the plan and that
may require corroboration must be available in evidence files. Evidence files must be
maintained to provide VA process and other protection program planning documentation
in a logical and readily retrievable form to validate assumptions, modeling input data, test
results, and other data that may be used to support protection system design or
conclusions regarding protection effectiveness.
7. DATA COLLECTION. The effective date (snapshot in time) of the data contained in the
SSSP must be specified.
8. FORMAT. Information provided in the SSSP should be brief, accurate, and concise.
Implementing plans and procedures should be referenced in the plan where appropriate.
A brief overview of a plan or procedure is adequate.
Duplication of information should be avoided. Information already included in other
sections of the plan may be referenced or summarized for clarity.
A cover letter must be attached to the plan indicating that the plan has been reviewed,
risks acknowledged and accepted (if appropriate), and signed by line management. For
example, the SSSP should be approved by the Head of Field Element and submitted for
concurrence to the Departmental element. If high or marginal risk acceptance is needed,
Section 29
DOE M 470.4-1 Part 1, Section C
8-26-05 C-3
the correspondence must be routed for signature to the Secretary or Deputy Secretary or
Under Secretaries, respectively.
The use of charts, plats, graphs, drawings, videos, photographs, and matrixes is
encouraged wherever appropriate to clarify or satisfy the intent of plan objectives.
References to sources of information and the location of supporting documentation
should be provided to assist in verifying information contained in the plan.
The SSSP is divided into 12 chapters. Each chapter provides specific information
relevant to site security. Use of this layout will ensure a uniform SSSP for review and
comment or during an emergency.
a. Chapter 1, Site Description and Mission.
(1) Site Mission Statement. Describe the site mission and how the mission
relates to national security and the health and safety of the public,
employees, and the environment. Describe the major programs or
activities performed at the site in terms of mission and their relationship to
the DOE national security mission.
(2) Site Description and Area Layout. Describe the physical and geographical
area in which the site and the S&S program are located. Provide a map,
photograph, or drawing of the site that identifies locations of Category I
facilities, facilities with a credible roll-up of SNM to a Category I
quantity, the central alarm station (CAS) and secondary alarm stations
(SAS), security-related communications facilities, and other facilities of
security interest. Show the location of barriers defining the site Protected
Area (PA). A small-scale map or drawing should be used to show the
relationship of the site to the surrounding area and be of sufficient detail to
orient the user.
(3) Management Organization, Planning Assumptions and Evidence File.
(a) Site Management Organizations. Identify the contract name,
number, and other information that describes the authority under
which the contractor executes management functions. Identify site
contractors responsible for S&S programs and describe their S&S
activities. Provide Federal and contractor organization charts and
identify key positions and the relationships between the
organizations for S&S activities. Provide a list of roles and
responsibilities for key positions. Describe Federal and contractor
involvement in the development of S&S resource requirements.
(b) Management and Planning Assumptions. Describe those
assumptions that were addressed and agreed to during the SSSP
scoping, preparation, or other SSSP management-related meetings.
Part 1, Section C DOE M 470.4-1
C-4 8-26-05
Describe all relevant S&S-related planning assumptions that were
formerly agreed to and included in a Memorandum of Agreement
(MOA) by the responsible organization representatives who are
party to the development and review of the SSSP. These
assumptions should address the following issues:
1 site SECON;
2 VA methodology used for insider, neutralization, outsider,
and collusion analyses;
3 identified credible targets;
4 protection strategies;
5 approved compensatory measures; and
6 performance testing conducted or to be conducted.
(c) Evidence Files. Describe and identify the contents, location, and
control mechanisms for the SSSP evidence files. Reference
approved standard operating procedures (SOPs) as applicable.
Supporting documentation that validates data/information used in
the VA process should not be included in the SSSP. However, this
data/documentation should be available in a logical and readily
retrievable arrangement in evidence files, for use in review and
validation of the SSSP.
Section 30
b. Chapter 2, Site Threat Description and Target Identification.
(1) Threat Description. Establish a graded approach to protection for
Category I SNM and SNM facilities with credible roll-up of SNM to a
Category I quantity, and facilities having radiological, biological, or
chemical, sabotage event potential and facilities having disruption of
critical mission sabotage event potential. Use the DBT as the baseline for
threat determination, along with higher levels of threat dictated by local
and regional threats (when available), and describe the site-specific threats
used as the basis for conducting VAs and for which the protection
program is designed.
(2) Target Identification. Identify, describe, and prioritize targets of security
interest that meet the following criteria.
(a) Category I quantities of SNM and the facilities with credible roll-
up of SNM to a Category I quantity.
DOE M 470.4-1 Part 1, Section C
8-26-05 C-5
(b) A radiological, biological or chemical sabotage inventory that, if
released, would cause an unacceptable impact on national security
or the health and safety of employees, the public, or the
environment.
(c) Critical national security facilities, and assets (as defined in the
DBT), designated by the Department (e.g., or each disruption of
critical mission target) that would impact DOE programs
supporting national defense and security.
(d) Those facilities possessing automated information systems that
process or contain Sensitive Compartmented Information (SCI),
Special Access Program (SAP), weapon data classified Secret
Restricted Data (S/RD) Sigma 1, 2, 14 and 15 or higher.
(e) Temporary recurring targets. When predictable programmatic
operations can reasonably be expected to present temporary SNM,
sabotage, or information targets such as those permanent locations
previously described, these targets must be described and analyzed
at the same level of detail and in the same manner as permanent
locations.
Provide a brief introductory description of the targets and a chart or list,
such as shown below, that indicates the type of target, its location,
attractiveness level, size, and configuration. Include SNM theft/diversion
targets; radiological, biological, and chemical targets; and disruption of
critical mission targets and those facilities possessing automated
information systems that process SCI, SAP, weapon data classified S/RD
Sigma 1, 2, 14, and 15 or higher.
(3) Theft or Diversion of SNM. Describe how Category I SNM targets and
SNM facilities that roll-up to a credible Category I quantity have been
identified and evaluated as potential abrupt theft targets. Also, describe
how these SNM targets have been identified and assessed for protracted
theft (diversion), if applicable.
For each identified SNM target, provide a description of the following,
using a table similar to Table C-1, SNM Theft/Diversion Targets:
physical location of identified SNM; the type of material, as described
under the several material listings in DOE M 470.4-6, Nuclear Material
Control and Accountability, such as pure products, high-grade material,
weapons, including pits, ingots, oxide fuel elements, etc.; and the
Category (I through II) and attractiveness level (A through C) of the target
material.
Part 1, Section C DOE M 470.4-1
C-6 8-26-05
Table C-1. SNM Theft/Diversion Targets
Location SNM Type
Category/
Attractiveness
Level
Goal Quantity/
Portability
Bldg. 1, Vault Pu-239 ingots Cat. I/B 2 ingots/
man portable
Section 31
Bldg. 1, Assay
Room
Pu-239 ingots Cat. I/B 2 ingots/
man portable
Bldg. 1,
Fabrication Room
Pu-238 oxide
powder
Cat. II/D 2 canisters/
man portable
Bldg. 2
U-235 fuel
elements
Cat. II, roll-up to
Cat. I/C
20 fuel element/
not man portable
Bldg. 3
U-235 fuel
elements
Cat. II, roll-up to
Cat. I/C
20 fuel element/
not man portable
(4) Radiological Sabotage. Indicate the process or methodology used to
identify and evaluate radiological sabotage targets.
For each identified radiological sabotage target, provide a description
using a table similar to Table C-2, Radiological Sabotage Targets, of the
following: the physical location of all identified targets; the type of
material; the maximum inventory level; and the material size and
configuration.
Table C-2. Radiological Sabotage Targets
Location Material Type
Maximum
Inventory
Material Size and
Configuration
Bldg. 1,
Fabrication
Room
Pu-238 oxide
powder
10 kg Paint Cans, at 50 g each
Bldg. 4 H3 gas 10 kg Cylinders, at 500 g each
(5) Biological or Chemical Sabotage. Describe the methodology used to
evaluate biological or chemical targets. Using the criteria referenced in
the DBT, determine the sabotage threat level (STL) for each location.
Reference the plans and procedures that govern the biological or chemical
sabotage assessment program.
For each identified target type not addressed by the commercial
equivalency protection program, provide a description of the following
using a table similar to Table C-3, Biological/Chemical Sabotage Targets:
the physical location of additional identified biological or chemical
DOE M 470.4-1 Part 1, Section C
8-26-05 C-7
sabotage material targets; the type of material; the maximum inventory
level; the material size and configuration; and, the exposure level at the
near-site boundary (NSB) for maximum inventory release.
Table C-3. Biological/Chemical Sabotage Targets
Location
Material
Type
Maximum
Inventory
Material Size
and
Configuration
Exposure
Level at NSB
Bldg. 5 Chlorine 10,000 lb
55-gal drums, at
350 lb each
>ERPG III
Levels
(6) Disruption of Critical Mission Sabotage. Describe how potential
disruption of critical mission sabotage production and process components
(machinery, equipment, flow process, power sources, ventilation, waste
handling, etc.) have been identified and evaluated for inclusion as
disruption of critical mission targets. Ensure that the evaluation includes
how the sabotage event would affect production (at the facility, on
intersite processes, and on overall national level inventory needs) and, if
so, what areas, processes, and/or components within the facility affect
those necessary production level capabilities and inventory needs.
For each disruption of critical mission target, provide a description, using
a chart similar to Table C-4, Disruption of Critical Mission Targets, of the
following: the physical location of essential production components; the
type of equipment, process, power sources, or vital components; and the
dollar value or production capability loss.
Table C-4. Disruption of Critical Mission Targets
Location Equipment Type Loss of DOE Mission Capability and
Mission Impact
Bldg. 1,
Fabrication
Room
Fuel Fabrication
Presses
100 percent loss of capability for 360 days
with moderate mission impact
Lab. A Laser Tunnel
100 percent loss of capability for 360 days
with low mission impact
Section 32
(7) Intra-Site Transportation of SNM. Describe, in a brief narrative, the
Category I SNM targets and credible Category II SNM targets that roll up
to Category I quantity that are moved from one location to another on the
site on a recurring basis.
Part 1, Section C DOE M 470.4-1
C-8 8-26-05
Using a chart, identify the type of SNM, attractiveness level, and size and
configuration of the material.
c. Chapter 3, Site Protection Strategies. Identify the protection strategies employed
that address the overall protection program and enhance the concept of graded
protection. Describe the protection program strategies employed. The basic
strategies pertaining to protection are denial of access, denial of task, and
containment that upon failure could evolve into recapture/recovery or pursuit
strategies. Protection programs and tactical deployments designed to prevent
unauthorized control of material and devices and to prevent acts of radiological,
biological, chemical, and disruption of critical mission must be integrated with
protection strategies. These activities could include protection layers of intrusion
detection systems (IDS) and concentric security areas, access control measures,
compartmentalization, insider protection programs, and procedural measures.
The plan should clearly convey the strategy to be employed, and plan reviewers
will anticipate that procedures are available to ensure implementation of these
strategies. Display in a chart similar to Table C-5, Site-Wide Protection
Strategies, the protection strategy used, the facility and target involved, and the
title and responsible office for each plan or procedure. Ensure the information
provided is consistent with that found in Chapter 2, Site Threat Description and
Target Identification.
Table C-5. Site-Wide Protection Strategies
Protection
Strategy
Facility or
Activity
Target Type
Implementing
Plan or
Procedure
Responsible
Office
Denial of
Access
Facility ABC
Cat. I: Pu metal
oxide
Cat. II: nitrate UF6
Plan ABC 1.3
Protective
Force Manager
Containment
Vault storage
Areas 301,
302, and
303
Weapon parts and
Pu metallic
buttons
Plan ADC.1
Protective
Force Manager
Denial of
Task
SNM in
transit
Weapon parts Plan CFE 1.5
Protective
Force Manager
DOE M 470.4-1 Chg 1 Part 1, Section C
3-7-06 C-9
Vertical line denotes change.
d. Chapter 4, Physical Protection Systems.
(1) Summary of Physical Protection Systems Used for Category I and
Credible Roll-up Quantities of SNM to a Category I Quantity, Sabotage,
Classified Information or Matter, and Classified Automated Information
Protection. Describe the physical protection systems for each facility that
has Category I quantities of SNM; credible roll-up quantities of SNM to a
Category I quantity; radiological, biological, chemical and sabotage
targets (including disruption of critical mission), and those facilities
possessing automated information systems that process or contain SCI,
SAP, weapon data classified S/RD Sigma 1, 2, 14 and 15, or higher.
Provide a narrative description of the physical protection systems and how
these systems are integrated at the site and facility level. Describe how
physical protection systems (access control, intrusion detection,
assessment, etc.) are implemented to allow the protective force (PF) to
focus resources on its primary mission of defeating an armed terrorist
threat. Describe how the barriers are protected by an IDS, security
lighting, protective force (PF), and assessment systems and how structures
located in or on the barrier are protected so as not to degrade protective
systems. Describe the design of barrier systems used to deny vehicle
approach routes to critical targets.
Section 33
Following the narrative, complete a chart similar to Table C-6, Facility
Protection Systems, that includes the following facility protection systems:
security areas and their barriers, access controls (automated card access
for both interior and exterior locations and contraband screening by the PF
at protected and material access areas); assessment [closed circuit
television (CCTV) and/or PFs both interior and exterior]; security
computer system integrator/ processor; CAS and SAS; CCTV cameras
monitoring and switching systems; security lighting; electrical and back-
up power sources (emergency batteries and/or generators); and
communications. In the chart, list the major physical protection systems,
the location of the systems, and a brief description of the type of
equipment installed.
(2) Physical Protection Measures for Category I and Credible Roll-Up
Quantities of SNM to a Category I Quantity in Transit (Onsite). Describes
the types, frequency, and protection measures used for the intra-site
shipment of Category I SNM and credible roll-up quantities to a
Category I quantity. Provide a narrative that describes the typical physical
protection measures taken to ensure the integrity of those shipments from
their point of loading, through transit, and at the off-load destination. If
other materials are transported on site that would represent an STL 1
concern, provide a narrative that describes the typical physical protection
measures from their point of loading, through transit, and at the off-load
destination.
Part 1, Section C DOE M 470.4-1 Chg 1
C-10 3-7-06
Vertical line denotes change.
Table C-6. Facility Protection Systems
Protection System
Equipment
Description
Location
Responsible
Office
Exterior Intrusion
Detection
“H” Field
Protected Area
Perimeter
Associated Areas
Office of the
Plant Engineer
Exterior Assessment/
CCTV
Microwave
Taut Wire
CCTV System
Protected Area
Perimeter
Associated Areas
Office of the
Plant Engineer
Interior Intrusion
Detection
Volumetric Infrared
Motion Detectors
All Material Access
Areas
Office of the
Plant Engineer
e. Chapter 5, Site Protective Force.
(1) PF Mission, Organization, and Capabilities. Describe the PF organization
and equipment deployed to perform 24-hour-per-day protection. Confirm
that the basis for PF organization and planning is based on the identified
site threat. Provide a narrative summary of the PF mission(s), capabilities,
and deployment concepts used for site protection. Describe the methods
used to review and prioritize post assignment priorities and eliminate posts
that detract from combat readiness at high priority sites. Indicate the
availability of plans and procedures that address normal and emergency
deployment. Describe the PF equipment used including firearms,
communications, vehicles, and any special items. Provide an organization
chart of the PF, including response forces, showing the management and
organization structure and key organizational interface positions with the
cognizant security authorities and site operations and safety organizations.
Using a schematic, display the PF communications network and include
available secure networks and linkages to offsite law enforcement
organizations with whom support agreements exist. In a chart, show the
weapons and special equipment assigned to PF personnel, including
members of the response force.
Section 34
(2) Qualifications and Training. Indicate that the qualifications for hire and
training of the PF conform to current policy requirements. In a chart
similar to Table C-7, Qualifications and Training, list the titles and offices
responsible for implementing and maintaining the plans or procedures that
describe the following pertaining to the PF: qualifications for employment
and the hiring process; initial, specialized and advanced training; tactical
performance testing program; and other relevant written documentation,
such as post and general orders that enhance the efficiency and
effectiveness of the PF.
DOE M 470.4-1 Part 1, Section C
8-26-05 C-11
Table C-7. Qualifications and Training
Plan/Procedures Title Responsible Office
Specialized Training Plan Training Department
Tactical Response Plans Department
(3) Special Response Teams (SRTs) and Plans. Ensure the availability of
SRTs and current response plans and procedures for implementing
site-specific S&S program strategies and tactics for denial of access,
denial of task, containment, recapture/recovery, pursuit, and contingency
operations, as described in current DOE policy. Indicate that
requalification training and exercises are used to verify the effectiveness
of SRTs. Identify and document agreements and MOUs with local, State,
and Federal law enforcement agencies regarding requests for on-site
support during a contingency event. Ensure that a VA was used to assist
management in determining the equipment and deployment of SRTs. In a
brief narrative, confirm the availability of personnel and response plans
and procedures that provide assurance of adequate protection. Indicate
that contingency plans and procedures are available to respond to the
activities listed below.
(a) Containment/denial of access/denial of task (includes a range of
tactical options designed to either preclude adversary force access
to nuclear weapons/materials or to deny unauthorized removal).
(b) Recapture/recovery or pursuit operations (used when containment/
denial fail and could involve SRTs and other force options
including the use of off-site law enforcement agencies).
Describe the organization, equipment, and training provided to SRTs and
how training and performance testing are used to verify the effectiveness
of SRT planning in the strategies described above. Describe the role of
VA in determining SRT deployment, equipment, and training.
In a chart similar to Table C-7, list tactical response plans and procedures
and the office responsible for implementing and maintaining them.
Use a similar chart to list memoranda or letters of understanding and other
agreements with local, State, or Federal law enforcement agencies
regarding requests for onsite support during a contingency event.
f. Chapter 6, MC&A Program.
Describe the MC&A management program and summarize the results of the
MC&A VA and other MC&A program planning activities. Describe the mission
of the site MC&A organization. Summarize current and planned nuclear
Part 1, Section C DOE M 470.4-1
C-12 8-26-05
materials processing and storage activities. Using an organization chart, show the
MC&A organization and management structure and the lines of authority and
points of interface with other S&S programs, facility operations, and the
cognizant security authorities’ MC&A organization. Describe the functions and
responsibilities of safeguards personnel and indicate how MC&A activities are
integrated with those of site protection programs and other facility organizations;
include organizational responsibilities for those program elements that support
multiple S&S programs (e.g., portal monitors and access controls). Confirm that
MC&A personnel complete required training.
Section 35
List, in a chart similar to Table C-8, MC&A Plans and Procedures, the facilities
required to develop and maintain MC&A plans and procedures, the titles of those
plans and procedures, and the office(s) responsible for approving and maintaining
them.
Table C-8. MC&A Plans and Procedures
Facility Name Plan/Procedure Title
Responsible
Office(s)
ABC Facility
ABC Facility
MC&A Plan, 1/1/99
S&S Director
XYZ Facility
XYZ Facility
MC&A Plan, 6/9/99
S&S Director
Give the name(s) and date(s) of reports of MC&A VAs and other planning
exercises. Summarize the results of these assessment(s). Identify those
components of the MC&A system that provide the greatest effectiveness against
theft and diversion. Describe actions taken to remediate identified program
deficiencies or to prepare for planned changes in facility nuclear materials
processing and storage activities.
g. Chapter 7, Site Personnel Security and Human Reliability Programs. Describes
the site-wide program for personnel security that, in conjunction with information
and physical security programs, ensures only authorized access to classified
information or matter, or SNM and confirms that the personnel security program
is in conformance with and implements the requirements prescribed in current
DOE policy. Describe the key elements of the site-wide personnel security
program for access authorizations and, if applicable, the key elements of the site’s
Human Reliability Program (HRP). Describe the method(s) used at the site to
ensure the appropriate level of access authorizations are issued for the category of
material processed or stored at the site and for approving justification, processing,
and reevaluating the need for such access authorizations. Indicate how the
effectiveness of the program is assessed. Indicate the site procedures that require
contractors to perform pre-hire checks to ensure proper qualifications and
suitability of the applicant before submitting requests for access authorizations.
DOE M 470.4-1 Part 1, Section C
8-26-05 C-13
Briefly describe the programs used to mitigate the effectiveness of potential
“insider” activities and the application of these programs in addressing insider
concerns. Provide an organization chart showing the location of the personnel
security organization in relationship to the cognizant security authority and other
contractor S&S organizations. Provide an organization chart identifying the
designated HRP management official in relationship to the cognizant security
authority and the designated HRP certifying official. Verify that the site has a
current HRP implementation plan. List, in a chart similar to Table C-9, Personnel
Security/Human Reliability Program Implementation, the titles of site-wide
personnel security-related plans and procedures, the HRP implementation plan, if
applicable, and the office(s) responsible for implementing and maintaining them.
Table C-9. Personnel Security/Human Reliability
Program Implementation
Plan/Procedure Title Responsible Office
XYZ Implementation Plan Security Department
h. Chapter 8, Automated Information Security Program. Briefly describe the
automated information systems for those facilities possessing automated
information systems that process SCI, SAP, weapon data classified S/RD Sigma
1, 2, 14, and 15 or higher. Provide an organization chart showing the responsible
automated information systems security program and its relationship to the
cognizant security authority and contractor organizations.
Section 36
In a chart similar to Table C-10, list the title of the automated information systems
security program plans and procedures with the associated office responsible for
implementing and maintaining the plan and procedures, the plans and procedures
governing the automated information system VAs with the associated office
responsible for implementing and maintaining the plan and procedures, and the
reports containing the results of the VAs.
Table C-10. Automated Information Systems Security Programs
Plan/Procedure/Report
Title
Responsible Office Date
(if pertinent)
Part 1, Section C DOE M 470.4-1 Chg 1
C-14 3-7-06
Vertical line denotes change.
i. Chapter 9, S&S Equipment Maintenance and Testing Programs. Describe
maintenance and testing programs and life cycle planning, designed to enhance
the continuous operability of S&S-related equipment used in the protection of
Category I SNM (including areas with credible roll up of SNM to a Category I
quantity), and classified automated information systems. Summarize in a
narrative the maintenance and testing programs in use that ensure the availability
and operability of S&S-related equipment and systems. Indicate the availability
of compensatory measures/procedures that are used when equipment is taken out
of service or otherwise not available. Describe how S&S maintenance and testing
programs are incorporated into the Performance Assurance Program Plans.
Indicate how the performance testing and other S&S site and facility maintenance
programs comply with DOE policy.
Describe the life cycle planning conducted for major S&S equipment and
component replacement. Relate how this planning is used to support and validate
S&S equipment budget requirements.
In a chart similar to Table C-11, list the maintenance, testing, and records
management programs; the relevant plans and procedures that implement the
programs; and the responsible office, as these programs apply to equipment used
by the PF, security related systems, and equipment and instrumentation used for
MC&A. Many of these may be addressed in a single maintenance and testing
program.
Describe the records management program used for scheduling, recording, and
tracking identified S&S maintenance requirements, deficiencies, and testing
schedules.
j. Chapter 10, Site Protection Evaluation Program. Chapter 10 is designed to ensure
the availability and use of testing and evaluation programs for site S&S programs
and systems.
In a narrative, describe the programs available and used to evaluate the
effectiveness of S&S protection programs and the interaction of these evaluation
tools (i.e., surveys may focus on shortfalls found in security inspections). Include
in this narrative an outline of the PF tactical performance testing program
describing the evaluation mechanisms used by line management. At a minimum,
the programs described in Chapters 4, 5, 6, and 8 of the SSSP should be addressed
and the evaluation plan or procedure identified. In a chart similar to Table C-12,
Site Protection Program Evaluation Program, list the names of the evaluation
plans/procedures used by the cognizant security authority to assist in determining
the effectiveness of site and facility protection programs and systems. List the
office responsible for the evaluation plan/procedure and its purpose.
DOE M 470.4-1 Part 1, Section C
8-26-05 C-15
Section 37
Indicate, in a brief description, that performance testing is used to verify the
effectiveness of S&S systems/programs and to validate VA activities.
Additionally, briefly describe barriers and other systems that cannot be adequately
performance tested to demonstrate protection capabilities and their integration
into protection strategies due to physical, operational, or policy parameters.
k. Chapter 11, Deviations from DOE Directives. List all deviations that have been
approved. In a table similar to Table C-13, Deviations from DOE Directives, list
the deviation, the officially assigned deviation number, the directive reference
(DOE directive and section within the directive), and the dates the deviation was
approved and expires.
Provide similar information for those deviations pending approval. This
information should be displayed in a chart similar to Table C-14, Pending
Deviations from DOE Directives.
l. Chapter 12, Summary of VA and Risk Assessment Results.
(1) Executive Summary. Summarize the VA and risk assessments results for
Category I SNM, Category II SNM (including credible roll up of SNM to
a Category I quantity), theft targets, radiological, biological, and chemical
sabotage targets, and disruption of critical missions.
Confirm in the narrative that performance testing was used to validate VA
input data and the results of the VA. Following the narrative, complete a
matrix similar to Table C-15, Summary of Identified Risks, which
identifies the risk associated with the results of the VA. In part 10 of the
matrix, summarize the proposed corrective actions or upgrades. For line
item construction project (LICP) work or other major capital expenditures,
cite the source of the required funding. Use the RP information as the
basis for this summary.
(2) Scope. Describe the targets to be covered, the items/issues to be excluded,
and the limits on the conduct of the VAs in this SSSP.
(3) Methodology.
(a) Theft or Diversion of SNM. Identify the SNM targets subject to
theft and/or diversion. Describe the rationale and mechanism used
to identify these targets.
Using a table similar to Table C-16, SNM Theft/Diversion Targets,
provide a description for each identified SNM target consisting of
the following: the physical location of identified SNM; the type of
material (such as pure products, high grade material, weapons,
etc.) which could include pits, ingots, oxide fuel elements, etc.; the
Part 1, Section C DOE M 470.4-1
C-16 8-26-05
Category (I through II) and attractiveness level (A through E) of
the target material; and the size and portability of the theft target.
Table C-11. S&S-Related Maintenance, Testing, and Records Management Programs
Program Area
Plan/Procedure
Title
Test Plan or
Management Plan
Responsible
Office/Organization
PF
- Equipment
- Training Courses
- Firearms Qualification
- Other
Vehicles/Aircraft
Communications
MC&A
Security Systems
- Personnel Access and
Inspection Equipment
- Security Lighting
- Intrusion Detection and
Assessment Systems
- Electrical Power Supplies
Sensitive Area Access Control
Survey/Inspection Deficiencies
Table C-12. Site Protection Program Evaluation Program
Plan/Procedure
Name Or Title
Responsible Office
Plan or Procedure
Goal/Purpose
Performance Assurance Program Contractor Manager
Establish/confirm system
effectiveness
DOE/Contractor
Self-Assessment Program
Program Manager
Identify program
strengths/weaknesses
Facility Approval, Security
Surveys
Section 38
Cognizant Security
Authority
Confirm availability and
adequacy of required S&S
programs
Force on Force Exercises Contractor Manager Confirm system effectiveness
Limited Scope Performance Tests Contractor Manager Confirm system effectiveness
Joint Tactical Simulation Model Contractor Manager Confirm system effectiveness
DOE M 470.4-1 Part 1, Section C
8-26-05 C-17
Table C-13. Deviations from DOE Directives
Deviation
Description
Deviation
Number
Directive
Reference
Approval and
Expiration Dates
Table C-14. Pending Deviations from DOE Directives
Deviation
Description
Deviation
Number
Directive
Reference
Approval And
Expiration Dates
(b) Radiological Sabotage. Identify the radiological targets subject to
sabotage. Describe the rationale and mechanism used to identify
these targets. A key source of information to assist in the
identification and/or elimination of radiological targets is the
facility safety analysis report.
Using a table similar to Table C-17, Credible Radiological
Sabotage Targets, provide a description for each identified
radiological sabotage target consisting of the following: the
physical location of all identified targets, the type of material, the
maximum inventory level, and the material size and configuration.
(c) Biological Sabotage. Identify the biological targets subject to
sabotage. Describe the rationale and mechanism used to identify
these targets. Reference any policy and analyses external to the
SSSP that address biological targets.
Using a table similar to Table C-18, Credible Biological Sabotage
Targets, provide a description for each identified biological
sabotage target consisting of the following: the physical location
of all identified targets, the type of material, the maximum
inventory level, and the material size and configuration.
(d) Chemical Sabotage. Identify the chemical targets subject to
sabotage. Describe the rationale and mechanism used to identify
these targets. Indicate whether security protection provided for
chemical sabotage targets is comparable to that provided by the
commercial sector for similar materials. A key source of
Part 1, Section C DOE M 470.4-1
C-18 8-26-05
information to assist in the identification and/or elimination of
chemical targets is the facility safety analysis report. Reference
any policy and analyses external to the SSSP that address chemical
targets.
Using a table similar to Table C-19, Credible Chemical Sabotage
Targets, provide a description for each identified chemical
sabotage target consisting of the following: the physical location
of all identified chemical sabotage targets, the type of material, the
maximum inventory level, how the security provided is not
comparable to that of the commercial sector, the material size and
configuration, and the exposure level at the NSB for maximum
inventory release.
(e) Disruption of Critical Mission. Identify the disruption of critical
mission targets. Describe the rationale and mechanism used to
identify these targets. Ensure that the evaluation includes how the
disruption would cause an unacceptable impact on national
security.
Using a table similar to Table C-20, Disruption of Critical Mission
Targets, provide a description for each identified target consisting
of the following: the physical location of the target, a description
of the function of the target, the impact to national security, and the
estimated time for recovery.
Section 39
(f) VA Parameters and Planning Assumptions. Describe/list the
baseline parameters and planning assumptions used in conducting
the VAs. Provide a summary list of parameters and planning
assumptions used in completing VAs. These should include
assumptions discussed and concurred in by appropriate DOE
offices or planning assumptions identified as a result of data
collection/discovery during the VA process.
D
O
E
M
470.4-1
P
art 1, S
ection C
8-26-05
C
-19
Table C-15. Summary of Identified Risks
Target
Number
Target Location
and
Description
Threat Type and
Number
Risk Rating (High, Moderate, Low)
Remarks
Analyses
Validated by Perf.
Testing
Base
Case
Current
Modif. Rating
(date)
Protected Action
and Adjusted
Rating: Near-Term
(<2 yr)
(date)
Protected Action
and Adjusted
Rating: Long-
Term
(>2 yr)
(date)
(1) (2) (3) (4) (5) (6) (7) (8) (9) (10) (11)
SNM Theft Targets
1
2
Glovebox 112-A
Bldg. 222
Test samples in
NDA room, Bldg.
222
Terrorist, X outsiders
with help of insider
Criminal Insiders
High
High
High
High
Relocate SI to
access door
Enhance HRP for
NDA technicians
and supervisors
Mod
High
Harden
access portal
Install CCTV
recording for
post-review
of activities
in NDA
room
Low
Mod
Install hardware to allow
SL relocation (FY-89
GPP)
SNM protection
unchanged, but probability
of attempt reduced thru
HRP and delayed
assessment capability
Yes
Yes
Radiological Sabotage Targets
3 Test reactor #5
North Area, Bldg.
408
Insider Mod Mod Reinforce SI
number when in
use
Low None Low Use overtime when reactor
in use-3 times per year
No
Chemical Sabotage Targets
4 Laboratory Bldg. 4 Insider Mod Mod None Low None Low None No
Biological Sabotage Targets
5 Fabrication Room,
Bldg. 1
Insider Mod Mod None Low None Low None No
Disruption of Critical Mission Targets
6
7
Access port 4 D-line
process line, Bldg.
460
Extrusion
equipment in fuel
manufacturing area,
Bldg. 97
Disgruntled employee
Psychotic employee
High
High
Mod
High
Implement 2-man
rule
Establish spares
inventory for
long lead time
parts
Low
Mod
Harden and
remote
control of
portal
Identify
alternate
extrusion
capability
off-site
Low
Low
Install hardware to reduce
high manpower costs (use
FY-92 GPP)
Additional physical
protection not cost-
effective. Improved spares
also provide repair
capability for non-sabotage
outages
Yes
Yes
Part 1, Section C DOE M 470.4-1
C-20 8-26-05
Table C-16. SNM Theft/Diversion Targets
Location SNM Type
Category/
Attractiveness Level
Quantity/
Portability
Bldg. 1, Vault Pu-239 ingots Cat. I,/B
2 ingots/man
portable
Bldg. 1, Assay
Room
Pu-239 ingots Cat. I,/B
2 ingots/man
portable
Bldg. 1,
Fabrication Room
Pu-238 oxide
powder
Cat. II/D
2 canisters/man
portable
Bldg. 2
U-235 fuel
elements
Cat. II, roll-up to Cat. I/
C
20 fuel elements/not
man portable
Bldg. 3
U-235 fuel
elements
Cat. II, roll-up to Cat. I/
C
20 fuel elements/not
man portable
Table C-17. Credible Radiological Sabotage Targets
Location
Material
Type
Maximum
Inventory
Material Size and
Configuration
Bldg. 1,
Fabrication
Room
Pu-238 oxide
powder
10 kg
Paint Cans, at 50 g
each
Bldg. 4 H3 gas 10 kg
Cylinders, at 500 g
each
Table C-18. Credible Biological Sabotage Targets
Location
Material
Type
Maximum
Inventory
Material Size and
Configuration
Bldg. 1,
Fabrication
Room
Anthrax
solution
10 g
20 petri dish at
0.5 g each
Bldg. 4
Botulism
aerosol
20 g
10 2-liter cylinders,
at 5 kg each
Section 40
Table C-19. Credible Chemical Sabotage Targets
Location
Material
Type
Maximum
Inventory
Commercial
Sector Security
Difference
Material Size &
Configuration
Exposure
Level at
NSB
Bldg. 5 Chlorine 10,000 lb
Lack of access
control
55-gallon
drums, at 350 lb
each
>ERPG III
levels
DOE M 470.4-1 Part 1, Section C
8-26-05 C-21
Table C-20. Disruption of Critical Mission Targets
(g) Critical Path Protection Elements. Describe the process used to
identify critical path protection elements and the types of tests to
which site protection elements are subjected (procedural,
simulation, barrier, equipment, PF, etc.). Using a table similar to
Table C-21, Performance Testing Results of Site Specific Essential
Protection Element Values, provide a list of: physical security
system components for each protection layer [Limited Area (LA),
PA, material access area (MAA), and Target Area], the critical
protection element tested, if any, as determined from performance
testing. Also, indicate the number of tests conducted to obtain
results and the testing frequency used to monitor the protection
element specific value.
(h) Single Point Failure Analysis. Describe the analyses used to
determine any single-point failures identified during the VA.
Describe/list the single-point failure(s) to include the nature of the
vulnerability, measures to mitigate the vulnerability and the
potential exploitability by an adversary.
(i) Critical Path Scenarios. Describe and provide the critical path
scenarios, including the bounding scenarios, developed during the
VA for each target. Identify the protection system effectiveness
(PE) value for each of these targets. Describe and identify the
critical detection points along each adversary path.
Should multiple targets exist within the same security area, such as
several SNM targets within the same MAA and same building,
bounding critical path scenarios may be described. Provide
justification that supports bounding cases.
For each critical path scenario provide floor plans, diagrams,
sketches, or an adversary path description (as shown in
Table C-22) or, if appropriate, refer to the descriptions that may
have been used previously to illustrate the critical path and
protection elements described in the scenarios.
Identify and describe the point along the adversary path at which
detection is required to allow for sufficient response time for
adversary neutralization to be effected for each of the critical path
scenarios (i.e., critical detection point).
Location Target Function
Impact to National
Security
Estimated time for
Recovery
Site A, Bldg. 4
Fuel cell
production
Increased reliance on
fossil fuels
180 days
Part 1, Section C DOE M 470.4-1
C-22 8-26-05
Table C-21. Performance Testing Results of Site-Specific Essential Protection Element
Values
Protection Layer and
Physical Security
System Components
Tested
Critical Elements
Tested
No. of Tests
Used as Basis
for VA values
Test
Frequency
Value used
in VA
PA - Identification and
Intrusion Element
Attempt to smuggle
firearms through
Portal 1.
36 Quarterly 0.6
Attempt to defeat
door contacts Bldg.
1, door 3.
34 Quarterly 0.7
MAA - Search
Component
Attempt to smuggle
firearms through
MAA portal
24
Once every
2 months 0.8
Target Area -
Identification Component
Attempt to gain
unauthorized vault
access
48 Monthly 0.9
Section 41
(j) Protection System Effectiveness. Verify that the PE values
identified for each critical path scenario were used to calculate
conditional risk for each identified target. Using tables similar to
those on the following pages (Table C-23, Protection Effectiveness
PE for Theft or Diversion of SNM; Table C-24, Protection
Effectiveness (PE) for Radiological Sabotage; Table C-25,
Protection Effectiveness (PE) for Biological Sabotage; Table C-26,
Protection Effectiveness (PE) for Chemical Sabotage; Table C-27,
Protection Effectiveness (PE) for Disruption of Critical Missions;
Table C-28, Protection Effectiveness (PE) for Theft or Espionage
of Classified Information or Matter; and Table C-29, Protection
Effectiveness (PE) for Other Losses), show the targets and PE
values for each target.
(k) Neutralization Analyses. Identify and describe the mechanism(s)
used to determine/calculate the neutralization value(s) used in the
risk evaluation. Identify and describe the basis for the
neutralization values, parameters that impact the neutralization
calculations and any site-specific issues that modify neutralization
calculations.
(l) Insider Analysis. Describe the analysis for determining the insider
threat for each target class included in the SSSP. This analysis
must include the programs supporting the elimination/mitigation of
select insider groups from the threat spectrum, identification of the
potential insider population, and insider protection programs that
were not included in other protection system elements. Describe
DOE M 470.4-1 Part 1, Section C
8-26-05 C-23
the programs that are factored into the VA process and provide
justification for their use. Identify by position and title the
participants in the HRP.
(m) Conclusions. Provide a summary of system effectiveness for the
identified targets. Document VA analyst’s observations and
recommendations developed as a result of the VA process.
Summarize the system effectiveness using a table similar to C-30,
System Effectiveness Summary.
Part 1, Section C DOE M 470.4-1
C-24 8-26-05
Table C-22. Critical Path Scenarios
Scenario Title: Base Case 1 Results
Facility: Building XYZ PI .
Target Location: Room,123 State, Open PN
Adversary Threat/Adversary: Terrorist w/insider: X# outsider, Y# insiders
Goal Type/Quantity: Oxide, Xx kg PE
VA Path Analysis Tool: ASSESS C
Computer File ID: .PPS, .OUT; .NEU Syst. Eff.:
Neutralization Tool: JTS Syst. Eff.:
Time (Sec) SCENARIO ACTIONS
Total ADV PF
Adversary pre-positions escape vehicles
Adversary mails weapons and explosives into PA (No x-ray or explosives detection
capability)
Adversary proceeds to access control portal
0 20
Adversary attempt to deceit through portal (PD = 0.xx – badge check with xxxx at
access portal). If detected, adversary begins overt actions.
CRITICAL DETECTION POINT
25 CAS receives alert and begins to annunciate alert
20 25 Adversary proceeds to target building XYZ, door 7 on the NE corner
25 Protective Force units begin response
70 Unit A responds to NE corner of building XYZ
55 Unit B responds to SE corner of building XYZ
80 Unit C responds to SE corner of building XYZ
60 Unit D responds to SE corner of building XYZ
45 5
Adversary reaches door 7 to building XYZ, insider opens door 7 into building XYZ
(PD = 0.xx – BMS)
50 5
Adversaries enter building XYZ and transverse to vault room 123. CAS receives BMS
door alarm and annunciates the alarm
Section 42
55 50 Adversaries collect target material
80 Unit B reaches response position
85 Unit D reaches response position
95 Unit A reaches response position
105 5 Adversaries proceed to door 7 to exit building XYZ. Unit C reaches response position.
110 Adversary exits building XYZ via door 7. (PD = xxx - , )
112 Unit A engages adversary
Etc.
D
O
E
M
470.4-1
P
art 1, S
ection C
8-26-05
C
-25
Table C-23. Protection Effectiveness (PE) for Theft or Diversion of SNM
Location Material Type
Facility
Condition
Adversary
Type
Adversary Scenario Summary
Protective Force Response
Summary
PE Value
Bldg. 1,
Vault
Pu-239 ingots Open Terrorist Vault open. Outsiders deceit into PA.
Insider crashes out of Bldg. 1 MAA
with material. Hands off to outsiders.
Adversaries leave PA/site by vehicle.
Armed response to BMS door
alarm. Containment at MAA
boundary. Positioning of
blocking forces at PA boundary if
MAA containment defeated.
Pursuit in PPA if escape from
facility.
.7
Bldg. 1,
Assay Room
Pu-239 ingots Open Terrorist Scenario same as vault open scenario. Scenario same as vault open
scenario.
.7
Bldg. 1,
Fabrication
Room
Pu-238 oxide
powder
Open Terrorist Scenario same as vault open scenario. Scenario same as vault open
scenario.
.7
Table C-24. Protection Effectiveness (PE) for Radiological Sabotage
Location Material Type
Facility
Condition
Adversary
Type
Adversary Scenario Summary
Protective Force Response
Summary
PE Value
Bldg. 1,
Fabrication
Room
Pu-238 oxide
powder
Open Terrorist Building open. Outsiders deceit into
PA. Outsiders force MAA boundary by
foot. Insider allows access into Bldg. 1
Outsiders enter fabrication room,
obtain Pu-238 oxide, defeat HEPA
filters, and vent material to
environment through building
ventilation.
Armed response to MAA
boundary alarm.
.4
Bldg. 4 H3 gas Open Terrorist Building open. Outsiders deceit into
PA. Outsiders force MAA boundary
by foot. Insider allows access into
Bldg. 4. Outsiders disperse H3 to the
environment with explosives.
Armed response to MAA
boundary alarm.
.4
P
art 1, S
ection C
D
O
E
M
470.4-1
C
-26
8-26-05
Table C-25. Protection Effectiveness (PE) for Biological Sabotage
Location Material Type Facility Condition Adversary
Type
Adversary Scenario Summary Protective Force Response
Summary
PE Value
Bldg. 5
Anthrax Open Terrorist Building open. Outsiders deceit into
PA. Insider allows access into Bldg.
5. Outsiders disperse anthrax to the
environment with explosives.
Building Containment .2
Closed Terrorist Outsiders deceit into PA. Outsiders
breach door into Bldg. 5. Outsiders
disperse anthrax to the environment
with explosives.
Building Containment .2
Table C-26. Protection Effectiveness (PE) for Chemical Sabotage
Location Material
Type
Facility
Condition
Adversary
Type
Adversary Scenario Summary Protective Force Response Summary PE Value
Bldg. 5
Chlorine Open Terrorist Building open. Outsiders deceit into PA.
Insider allows access into Bldg. 5. Outsiders
disperse chlorine to the environment with
explosives.
Building Containment .2
Closed Terrorist Outsiders deceit into PA. Outsiders breach
door into Bldg. 5. Outsiders disperse
chlorine to the environment with explosives.
Building Containment .2
Table C-27. Protection Effectiveness (PE) for Disruption of Critical Missions
Location Equipment
Type
Facility
Condition
Adversary
Type
Adversary Scenario Summary Protective Force Response Summary PE Value
Section 43
Bldg. 1,
Fabricatio
n Room
Fuel
Fabrication
Open Nonviolent
Insider
Insider enters Fab. Room. Starts fire to
destroy equipment located in room.
Building Containment .2
D
O
E
M
470.4-1
P
art 1, S
ection C
8-26-05
C
-27 (and C
-28)
Table C-28. Protection Effectiveness (PE) for Theft or Espionage of Classified Information or Matter
Location Classified
Information or
Matter
Facility
Condition
Adversary
Type
Worst-case Scenario Summary Protective Force Response
Summary
PE Value
Bldg. 5,
Office
Area
TSRD
Documents
Open Nonviolent
Insider
Insider obtains TSRD, makes copies,
encloses copies in envelope, and hand-
carries out of Bldg. 5. Insider mails
classified documents out of PA to off-site
location.
None .2
Table C-29. Protection Effectiveness (PE) for Other Losses
Location Item Facility
Condition
Adversary
Type
Worst-case Scenario Summary Protective Force Response
Summary
PE Value
Bldg. 5,
Lab Area
R&D Laboratory Open Nonviolent
Insider
Insider starts fire in laboratory. Building Containment .2
Table C-30. System Effectiveness Summary
Goal Target Location Operations PE
Theft of SNM Bldg. 1 Vault Day Shift .8
Theft of SNM Bldg. 1 Assay Room Day Shift .8
Theft of SNM Bldg. 1 Fab. Room Day Shift .75
Rad. Sabotage Bldg. 1 Fab. Room Day Shift .85
Rad. Sabotage Bldg. 4 Bldg. 4 Day Shift .9
Chem. Sabotage Bldg. 5 Laboratory Day Shift .8
Bio. Sabotage Bldg. 5 Laboratory Day Shift .8
Indust. Sabotage Bldg. 1 Fab. Room Day Shift .8
Espionage of Classified Bldg. 5 Office Area Day Shift .8
Other Losses Bldg. 5 Laboratory Day Shift .8
DOE M 470.4-1 Part 1, Section D
8-26-05 D-1
SECTION D—SITE SAFEGUARDS AND SECURITY PLAN
RESOURCE PLAN
1. OBJECTIVE. The Resource Plan (RP) identifies safeguards and security (S&S)
resources necessary to ensure protection of Department assets and identifies changes in
resource requirements (i.e., operational requirements, capital equipment, general plant
projects (GPPs) and line item construction projects (LICPs) that directly impact risk,
indirectly impact risk, or derive from changing S&S policy, directives, guidance, or other
Department or other Departmental direction.
a. Operational Requirements. Briefly describe operational requirements relating to
S&S operations that would require increments or decrements to operational
accounts (e.g., program direction, operational support, etc.). Operational
requirements must include, but are not limited to, material consolidation, facility
mission changes, changes in the Design Basis Threat (DBT) impacting site
operations, protective force (PF) redeployments, maintenance and testing
changes, PF manning levels, procuring technical expertise and support personnel,
and additional training requirements. Summarize the pertinent information in a
table such as outlined in Table D-1, Operational Requirements. The table and
supporting narrative must include the following:
(1) the title of each operational requirement;
(2) the basis of the requirement (drivers behind the requirement);
(3) the funding profile and the impacts if not funded (if possible, state the
impact in terms of probability of system effectiveness (PE) and indicate if
this is a new resource requirement); and
(4) provide a status of operational requirements that were previously
authorized but have not yet been completed.
Provide a separate section for each operational requirement.
Table D-1. Operational Requirements
Requirement
(section)
Basis
Funding Request/Profile Currently
Section 44
in Budget
(Y or N)
Type of
Expense
FY xxxx
(current year)
FY + 1 FY + 2 FY + 3 FY + 4 FY + 5
b. Capital Equipment. Briefly describe identified/proposed capital equipment
procurements and funding requirements that are not part of a LICP or GPP, and
Part 1, Section D DOE M 470.4-1
D-2 8-26-05
support S&S programs and operations. These procurements could include, but
are not limited to, alarm and assessment system components, material control and
accountability (MC&A) systems, access control system components, and
equipment necessary to complete the S&S mission (e.g., breaching tools, vehicles,
PF armaments, additional capabilities necessary to address changes in the DBT).
Summarize the pertinent information in a table as outlined in Table D-2, Capital
Equipment. The table and supporting narrative must include the following:
(1) a title for each capital equipment procurement;
(2) the basis of the requirement (drivers behind the requirement);
(3) the funding profile and the impacts if not funded (if possible, state the
impact in terms PE, and indicate if this is a new resource requirement); and
(4) a status of capital equipment upgrades that were previously authorized but
have not yet been completed.
Provide a separate section for each capital equipment procurement.
Table D-2. Capital Equipment
Capital
Equipment
(section)
Basis
Funding Request/Profiles Currently
in Budget
(Y or N)
FY xxxx
(current year)
FY + 1 FY + 2 FY + 3 FY + 4 FY + 5
c. GPP. Describe significant identified/proposed GPPs that are not part of an LICP
or capital equipment expense but that are necessary to support S&S programs and
operations. These GPPs could include, but are not limited to, alarm and
assessment systems/components, MC&A systems, access control
systems/components, or infrastructure improvements. Summarize the pertinent
information in a table as outlined in Table D-3, General Plan Projects. The table
and supporting narrative must include:
(1) a title for each GPP;
(2) the basis of the requirement (drivers behind the requirement);
(3) the funding profile and the impacts if not funded (if possible, state the
impact in terms PE, and indicate if this is a new resource requirement);
(4) a status of general plan project upgrades that were previously authorized
but have not yet been completed.
DOE M 470.4-1 Part 1, Section D
8-26-05 D-3
Provide a separate section for each GPP.
Table D-3. General Plant Projects
General Plant
Projects
(section)
Basis
Funding Request/Profiles Currently
in Budget
(Y or N)
FY xxxx
(current year)
FY + 1 FY + 2 FY + 3 FY + 4 FY + 5
d. LICPs. Describe current and proposed LICPs that are not part of a GPP or capital
equipment procurement but are necessary to support S&S programs and
operations. Summarize the pertinent information in a table as outlined in Table
D-4, Line Item Construction Projects. The table and supporting narrative must
include:
(1) a title for each LICP;
(2) the basis of the requirement (drivers behind the requirement);
(3) the funding profile and the impacts if not funded (if possible, state the
impact in terms PE, and indicate if this is a new resource requirement); and
(4) the status of S&S upgrades that were authorized but have not yet been
completed. Discuss any changes to cost estimates [i.e., total estimated
cost (TEC) versus total project cost (TPC)] identified in the previous RP.
Provide a separate section for each LICP.
P
art 1, S
ection D
D
O
E
M
470.4-1
D
-4
8-26-05
Section 45
Table D-4. Line Item Construction Projects
LICP Title
(section)
Basis
Funding Request/Profiles Total Costs Schedule Currently
in Budget
(Y or N)
FY xxxx
(current year)
FY + 1 FY + 2 FY + 3 FY + 4 FY + 5 TEC TPC Start Date
Finish
Date
Table D-5. Unfunded/Unsupported Requirements
Requirement
(section)
Basis
Resource
Type
Base
FY
Original Funding Request/Profiles
Impact
FY xxxx FY + 1 FY + 2 FY + 3 FY + 4 FY + 5
DOE M 470.4-1 Part 1, Section D
8-26-05 D-5
2. UNFUNDED/UNSUPPORTED REQUIREMENTS. Briefly describe proposed S&S
operational requirements, capital equipment procurements, GPPs, or LICPs that had been
previously identified and have not been funded supported. Summarize the pertinent
information in a table such as Table D-5, Unfunded/Unsupported Requirements. The
table and supporting narrative must include:
a. a title for each unfunded requirement;
b. the basis for the requirement (drivers behind the requirement);
c. the type of resource requested (operating expense, capital equipment, GPP, or
LICP);
d. the fiscal year the requirement was originally identified;
e. the proposed funding profile and impacts due to lack of funding (if possible, state
the impact in terms of PE).
Provide a separate section for each unfunded requirement.
3. REFERENCES FOR THE RESOUCE PLAN.
a. Facility SSSP. Provide a reference to the most recent/current SSSP.
b. Programmatic Documentation. Provide a reference (include title, date, and
responsible organization) for any programmatic policy, directive, or guidance
necessitating the allocation of additional resources.
4. HEADINGS AND TERMS FOR TABLES D-1 THROUGH D-5. Following are the
types of data to be included in the RP.
a. Basis.
(1) Compliance.
(2) Risk reduction.
(3) SSSP derived.
(4) Cost-efficiency.
(5) Operational efficiency.
(6) Enhanced operations.
(7) DBT change.
b. Type of expense.
(1) Operational = annual recurring cost that will need to be added to the
budget baseline.
(2) Single = one time only expense paid from operating dollars.
c. Total Costs.1
1As defined in DOE O 413.3, Chg 1, Project Management for the Acquisition of Capital Assets.
Part 1, Section D DOE M 470.4-1
D-6 8-26-05
(1) TEC = Total estimated cost.
(2) TPC = Total project cost.
d. Resource Type.
(1) OE = operational expense.
(2) CE = capital expense.
(3) GPP = general plant project.
(4) LICP = line item construction project.
(5) BASE FY = fiscal year in which the resources were identified and
requested.
e. Impact.
(1) Continued risk.
(2) Cost escalation.
(3) Unable to comply with xxxx (list applicable directive).
(4) Programmatic impact.
(5) Operational impact.
(6) Other (list).
DOE M 470.4-1 Chg 1 Part 1, Section E
3-7-06 E-1
Vertical line denotes change.
SECTION E—VULNERABILITY ASSESSMENT PROGRAM
1. OBJECTIVE. The Vulnerability Assessment (VA) Program must consider other
programs such as protective force (PF), material control and accountability (MC&A),
emergency operations, safety, maintenance, facility operations, personnel security,
physical protection, and information security.
2. CONDUCTING VULNERABILITY ASSESSMENTS. The process of conducting a VA
includes gathering data that describe the physical and operational characteristics of a
safeguards and security (S&S) system, assigning values such as delay and detection, and
analyzing the results to determine the relative effectiveness in conjunction with the
adversary’s capabilities as identified in the Design Basis Threat (DBT) and the Adversary
Capabilities List (ACL). Below is a description of the VA process.
Section 46
a. Assumptions. Assumptions and scoping agreements must be defined. All
assumptions must be documented in the VA report.
b. Threat. The person responsible for the conduct of VAs, hereinafter referred to as
the analyst (see paragraph 9 of this section), must understand how the DBT relates
to VAs. The analyst performing the VA must apply DOE Headquarters (HQ),
regional and local threat guidance.
(1) DOE HQ Threat.
(a) The DBT must be used to define threat against which VA analysts
evaluate the protection system
(b) The site’s protective systems must be analyzed against the ACL.
(2) Regional and local threats must be considered during the conduct of VAs.
c. Targets. All security interests whose loss, theft, compromise, and/or unauthorized
use will affect the national security and/or the health and safety of DOE and
contractor employees, the public, the environment, or DOE programs are potential
targets. The analyst must consider target configurations and conditions, as well as
operational conditions and acquisition times.
d. Modeling. Modeling is used to analyze S&S programs, interests, assets, and the
effectiveness of program implementation. Modeling can include computer-based
tools and simulations, table-top analyses, and subject matter expert analyses.
Section E, Appendix 3, VA Modeling Tools, lists those modeling tools approved
by DOE. Methods to ensure that the models accurately reflect the facility posture
must be part of the final VA results. The modeling process must establish critical
pathways. The following must be considered:
(1) facility characterization;
Part 1, Section E DOE M 470.4-1 Chg 1
E-2 3-7-06
Vertical line denotes change.
(2) System effectiveness models and equations must be used. Section E,
Appendix 4, System Performance Effectiveness Equation, delineates the
system effectiveness equation;
(3) response force times;
(4) the probability of neutralization (PN) must be calculated using data
available regarding the PF response and their ability to interrupt and
neutralize an adversary. The methods used must be documented and
retained as part of the evidence file. The calculated number for PN must
be derived from more than one source, one of which must be joint tactical
simulation (JTS), joint conflict and tactical simulation (JCATS), or
force-on-force (FoF) exercises;
(5) blast effect modeling must consider blast effects on barrier breaching, a
force multiplier, and target buildings;
(6) table-top methods used to determine system effectiveness must be
documented and a means provided to allow for validation or verification;
(7) radiological sabotage must be fully analyzed against the DBT and ACL.
Existing information from safety analyses can be used but must be
analyzed to consider deliberate rather than accidental release;
(8) chemical and biological sabotage must be analyzed against the DBT and
ACL;
(9) the analysis must use the thresholds stated in DOE O 470.3, Design Basis
Threat (DBT) Policy; and
(10) the use of chemical and biological agents must be analyzed as a force
multiplier. Methods of release and mitigation measures must be a part of
the analysis.
e. Performance Testing. If conducted, the results of the following tests (including
validation) must be considered in determining system effectiveness:
(1) FoF exercises;
(2) limited scope performance tests (LSPTs);
(3) alarm response and assessment performance tests (ARAPTs);
(4) breaching test data; and
(5) critical system element tests.
Section 47
DOE M 470.4-1 Part 1, Section E
8-26-05 E-3
f. Results. The results of VAs indicate PE. The VA results must be used for
determining:
(1) protection system effectiveness reporting;
(2) S&S upgrades;
(3) manning/armament levels for the PF; and
(4) justifications for waivers of and exceptions to S&S policy.
g. VA Practitioner Training. VA practitioners must successfully complete VA
Program training within 2 years of appointment. This requirement can be met
through the National Training Center (NTC).
3. QUALITY ASSURANCE. The analyst must verify the data used for the analyses. These
data include:
a. modeling data to include detection, assessment, delay, interruption, neutralization,
PF response times, etc.;
b. all facility modeling characterization direct settings, rationales, and
documentation;
c. performance test results and documentation; and
d. sensitivity analyses such as single point failure and critical system element
analyses.
4. VULNERABILITY ASSESSMENT. All information used to support or document VAs
must be maintained and made available upon request. Examples include:
a. modeling inputs;
b. PF response;
c. adversary capabilities;
d. blast effects;
e. sabotage data;
f. timeline data; and
g. neutralization data.
5. ASSIGNING FIGURES OF MERIT. “Figures of merit” is defined as numerical values
and/or qualitative ratings assigned to component systems and personnel associated with
Part 1, Section E DOE M 470.4-1 Chg 1
E-4 3-7-06
Vertical line denotes change.
the protection system. Collectively the qualitative and/or quantitative measures provide
the basis for determining system effectiveness. Approved reference materials must be
used to provide initial data and to calculate accurate detection and delay numbers. A list
of approved references is provided in DOE M 470.4-7, Safeguards and Security Program
References. Reference materials are to be used only as a basis for the relative figures of
merit. Non-default figures of merit must be documented and based on performance
testing or engineering studies.
6. CRITICAL SYSTEM ELEMENTS. Critical system elements are components or
subcomponents of an S&S protection system that directly affects the ability of the system
to perform a required function. Critical system elements may be equipment, procedures,
or personnel. Failure of a critical system element would result in the protection system
effectiveness of the target being reduced to levels requiring management action. Critical
system elements must be:
a. identified for every target that requires a VA;
b. specifically delineated such that specific performance tests can be performed to
determine the ability of the protection measures to perform their intended
function; and
c. tested, documented, and the results analyzed to validate element effectiveness.
7. VULNERABILITY ASSESSMENT REPORTS. The vulnerability assessment report
(VAR) documents the results of a VA. The VARs must include targets analyzed,
methodology used, system effectiveness results, parameters and assumptions under which
the VA was conducted, and reference to evidence files. VARs published in support of an
SSSP should conform to the suggested format given in Section E, Appendix 5, Suggested
VA Report Format. The approval chain for VARs is below.
a. The analyst responsible for the VA must sign the report.
b. Line management responsible for the facility/site VA Program must approve the
report.
Section 48
c. DOE line management responsible for the VA Program must concur with the
report.
d. The DOE cognizant security authority must concur with the report.
8. SYSTEM EFFECTIVENESS. Only the Secretary of Energy or the Deputy Secretary can
accept low protection system effectiveness that results in high risk. Cognizant Under
Secretaries can accept marginal protection system effectiveness that results in moderate
risk. If the results of a VA, survey, self-assessment, audit, or inspection conducted by the
cognizant security authority, Departmental element, Office of Security, or Office of
Independent Oversight and Performance Assurance indicate a decreased (low or
marginal) protection system effectiveness that is not mitigated by compensatory measures
DOE M 470.4-1 Part 1, Section E
8-26-05 E-5
based on a risk management determination (see Section A, paragraph 2e), the following
actions must be initiated:
a. Low Protection System Effectiveness.
(1) Once a low protection system effectiveness condition that results in high
risk is identified, that condition must be reported to the responsible
Departmental element within 4 hours.
(2) A corrective action plan must be submitted to the responsible
Departmental element within 8 hours, with a copy to the Office of
Security.
(3) The Departmental element must make formal notification to the Secretary
or Deputy Secretary within 24 hours.
(4) The Departmental element in consultation with the Office of Security must
provide comments on the protection system effectiveness and
recommendations to the Secretary/Deputy Secretary within 36 hours.
(5) The responsible Departmental element must update the Secretary or
Deputy Secretary on low protection system effectiveness conditions every
30 days with an information copy to the Office of Security.
b. Marginal Protection System Effectiveness.
(1) Once a marginal protection system effectiveness condition that results in
moderate risk is identified, that condition must be reported to the
responsible Departmental element within 2 working days.
(2) The Departmental element must notify the appropriate Under Secretary
within 3 working days.
(3) A corrective action plan with recommendations must be submitted to the
responsible Departmental element within 5 working days with a copy to
the Office of Security.
(4) The Office of Security must provide comments to the Departmental
element within 5 working days.
(5) The responsible Departmental element must update the Secretary or
Deputy Secretary and appropriate Under Secretary on marginal protection
system effectiveness conditions every 90 days with an information copy to
the Office of Security.
Part 1, Section E DOE M 470.4-1
E-6 8-26-05
9. TRAINING AND CERTIFICATION.
a. The analyst responsible for the conduct of Vulnerability Assessments must
complete the Department-approved training program (scheduled to be fully
implemented by 2008).
b. The analyst must be certified as outlined in the Vulnerability Assessment
Certification Program Manual which is currently under development.
c. Any person currently conducting VAs may be “grandfathered” until such time as
the Vulnerability Assessment Certification Program Manual is issued.
DOE M 470.4-1 Chg 1 Part 1, Section E
3-7-06 Appendix 3, 3-1 (and 3-2)
Vertical line denotes change.
SECTION E
APPENDIX 3—VULNERABILITY ASSESSMENT MODELING TOOLS
1. ASSESS—Analytic System and Software for Evaluating Safeguards and Security.
2. ATLAS—Adversary Time Line Analysis System.
Section 49
3. BATLE—Brief Adversary Threat Loss Estimator.
4. JTS—Joint Tactical Simulation.
5. JCATS—Joint Conflict and Tactical Simulation.
6. AT Planner—Anti-Terrorist Planner.
7. BLAST X—Explosive Effects Analysis Software.
8. BLAST FX—Explosive Effects Analysis Software.
9. ConWEP—Conventional Weapons Effects Program.
10. BEEM—Blast Effects Estimation Model.
11. HOTSPOT—HOTSPOT Health Physics Code provides the capability to calculate the
radiation effects associated with the short-term (less than 24 hours) atmospheric release
of radioactive materials.
12. RSAC—Radiological Safety Analysis Computer program calculates the consequences of
a release of radionuclides to the atmosphere.
13. ACATS—Airborne Chromatograph for Atmospheric Trace Species.
14. ISA—Iterative Site Analysis.
15. VISA—Vulnerability of Integrated Security Analysis.
16. VISA II—Vulnerability of Integrated Security Analysis II.
17. ERAD—Explosive Release Atmospheric Dispersion.
18. ALOHA—Area Locations of Hazardous Atmospheres.
19. ARAC—Atmospheric Release Advisory Capability.
20. ACCS 2—Accident Consequence Code System for the calculation of the health and
economic consequences of accidental atmospheric radiological releases.
21. HPAC—Hazard Prediction Analysis Code provides the capability to accurately predict
the effects of hazardous material releases into the atmosphere.
DOE M 470.4-1 Chg 1 Part 1, Section E
3-7-06 Appendix 4, 4-1
Vertical line denotes change.
SECTION E
APPENDIX 4—SYSTEM PERFORMANCE EFFECTIVENESS EQUATION
The methodology requires the determination of the probability of sensing, probability of
assessment, and probability of detection at each layer. These are then combined to determine the
contribution to overall system effectiveness represented by each layer. Mathematically, this can
be expressed as the equation:
PEL = PIL x PNL = PDL * PNL = PAL * PSL * PNL
Where:
PEL is the system effectiveness contribution for layer L;
PIL – Probability of Interruption given first detection at layer L, PIL = PDL if detection on
layer L is timely, and is equal to 0 (PIL = 0) if detection is not timely;
PDL – Probability of Detection at layer L, PDL = PSL x PAL on layer L. PDL is the
probability of first detection at layer L, given that detection has not occurred at an earlier
layer, multiplied by the probability of sensing at an earlier layer, multiplied by the
probability of sensing at layer L (PSL) and the probability of assessment at layer L (PAL);
PSL – Probability of Sensing on layer L;
PAL – Probability of Assessment on layer L; and
PNL – Probability of Neutralization given first detection at layer L.
L is defined as the number of detection layers in the system before the critical detection
point (CDP) in the adversary path(s). Detection after the CDP cannot not be counted.
PE is defined as the system effectiveness of the layer. The system effectiveness of the
layer is the product of the probability of interruption of the layer and the probability of
neutralization given that detection occurred at that layer (PI x PN). The probability of
neutralization is determined discretely for each layer given detection at the layer. The
neutralization determination is made if detection (regardless of the extent) takes place at
the layer in question. Neutralization will occur sometime past the detection point and
would be valid for the probability of neutralization of that specific layer.
Section 50
PD of the layer is defined as the product of the probability of sensing and the probability
of assessment of the layer (PS x PA). Note that detection and assessment will be different
between the elements of the layer and between layers.
PIL of the layer is defined as PIL = PDL if detection on layer L is timely, and is equal to 0
(PIL = 0) if detection is not timely.
The symbol is the summation of terms. The summation symbol is defined as:
Part 1, Section E DOE M 470.4-1
Appendix 4, 4-2 8-26-05
n
n
i
i kkkk
...21
1
The symbol is the product of terms. The product symbol is defined by:
n
n
i
i ffff
...2
1
1
For those protection systems based on sensing, assessment, detection, interruption, and active
neutralization of an adversary, credit can only be taken up to the “point on the pathway” at which
the total of the adversary task time, engagement times, and delay times exceeds the protective
force response times. This limiting criteria eliminates credit being taken for protection system
capabilities that are not engaged prior to the adversary completing their objective. For denial
based protection systems, the point on the pathway is the critical detection point. The critical
detection point is defined as the point at which the protective force must have timely detection,
assessment, and response to initiate a response to have a high probability of success in the
neutralization of the adversary or denial of the adversary’s task/objective. Therefore, for a
facility employing multiple, complementary layers of protection, the representative total
protection system effectiveness is calculated up to the point at which the protection systems can
still effectively engage an adversary prior to completion of the objective.
The contributions of each layer along the adversary pathway are then combined to determine the
overall system effectiveness, where the overall system effectiveness is provided by the sum of
the contributions of each layer (only those encountered along the adversary pathway) to the
system effectiveness.
An example of the system effectiveness equations for a three-layer system protecting SNM
would be as follows:
In extended notation, the Overall System Effectiveness is:
PE = (PA1 x PS1 x PN1) + [(1 – (PA1 x PS1)) x (PA2 x PS2 x PN2)] + {(1 – ((PA1 x PS1) + [(1 –
(PA1 x PS1)) x (PA2 x PS2)])) x (PA3 x PS3 x PN3)}
Which reduces to:
PE = (PD1 x PN1) + [(1 – PD1) x (PD2 x PN2)] + {(1 – (PD1 + [(1 – PD1) x PD2])) x (PD3 x
PN3)},
and since PIL = PDL when detection is timely,
PE = (PI1 x PN1) + [(1 – PI1) x (PI2 x PN2)] + {(1 – (PI1 + [(1 – PI1) x PI2])) x (PI3 x PN3)}
PE = PE1 + [(1 – PI1) x PE2] + {(1 – (PI1 + [(1 – PI1) x PI2])) x PE3)}
DOE M 470.4-1 Chg 1 Part 1, Section E
3-7-06 Appendix 5, 5-1
Vertical line denotes change.
SECTION E
APPENDIX 5—SUGGESTED VULNERABILITY ASSESSMENT REPORT FORMAT
1.0 Executive Summary
Objective
Purpose and Summary of Protection Effectiveness
2.0 Introduction
Scope
Changes in the VAR
Methodology and Assumptions
3.0 Target Identification and Description
Theft or Diversion
Sabotage (Radiological)
Sabotage (Chemical and/or Biological)
Theft or Espionage of Classified Information or Matter
Other Losses
4.0 Threat Definition
Adversary Type(s)
Adversary Attributes
5.0 S&S Protection Elements
Physical Security Systems
Protective Forces (Response Strategies, Interruption, Neutralization)
Section 51
Material Control and Accountability
Reliability Program
Part 1, Section E DOE M 470.4-1
Appendix 5, 5-2 8-26-05
6.0 Performance Testing
Program Description
Site Protection Elements
Critical Protection Elements
7.0 S&S Protection Effectiveness
Scenario
Protection Effectiveness
Validation Testing
8.0 Summary of S&S Protection Effectiveness
Protection Effectiveness
Recommendations
DOE M 470.4-1 Chg 1 Part 1, Section F
3-7-06 F-1
Vertical line denotes change.
SECTION F—PERFORMANCE ASSURANCE PROGRAM
1. OBJECTIVE. To demonstrate the effectiveness of the protection provided Departmental
safeguards and security (S&S) interests by systematically evaluating all protection
program essential elements.
2. REQUIREMENTS. Each performance assurance program must be developed to validate
the performance of all essential S&S protection elements.
a. Operability and Effectiveness. Performance assurance programs must provide for
operability and effectiveness testing of each protection program essential element
or component.
(1) Operability tests provide measures of integrity and must check the
essential elements or total system to confirm operability.
(2) Performance tests provide comprehensive assurance that protection
program elements are performing as designed and provide the required
levels of protection.
(a) Performance tests results are used to validate the effectiveness of
all elements of a layered S&S system.
(b) Performance tests are not substitutes for compliance with
requirements.
b. Continuity. Performance assurance programs must evaluate operational
continuity of all S&S essential elements. Limited Scope Performance Tests
(LSPTs) and/or force-on-force (FoF) tests may be used as a means of meeting
specific performance assurance testing requirements. Performance assurance
programs must be evaluated as part of the DOE survey and the facility
self-assessment programs as described in Section G of this Manual.
(1) New protection program essential elements and components must be
validated through acceptance testing before operational use.
(2) Essential elements that have been repaired or undergone maintenance
must be validated through testing before use.
(3) The protective force (PF) must be performance tested both individually
and in small tactical units.
(4) Performance tests must ensure that approved protection strategies of
denial, containment, recapture, recovery, and pursuit can be accomplished
by the PF.
(5) Essential elements of the protection program security systems and
subsystems are performance tested to ensure that system detection,
Part 1, Section F DOE M 470.4-1
F-2 8-26-05
assessment, and response to alarms and adversarial actions meet stated
requirements.
c. Reliability. Each essential element whose failure would reduce protection to an
unacceptable level must be tested at frequencies that provide high assurance of
operability and reliability.
(1) Testing frequencies must reflect site-specific conditions and operational
needs.
(2) Testing frequencies must be documented for each essential element.
d. Performance Tests. At least every 365 days, an integrated performance test
encompassing all essential protection elements associated with a comprehensive
site or facility threat scenario must be conducted to evaluate the overall facility
S&S effectiveness.
(1) Those Category I facilities requiring denial protection strategies must
conduct integrated performance testing on a quarterly basis (at least every
3 months).
Section 52
OR
(2) Those sites with multiple Category I facilities requiring denial protection
strategies may rotate quarterly performance testing so that at least one
facility is tested on a quarterly basis (at least every 3 months). However,
an integrated performance test for all Category I facilities must occur at
least once every 365 days.
e. Documentation.
(1) Performance Assurance Program Plan. This plan must be an integral part
of the site safeguards and security plan (SSSP)/site security plan (SSP), or
material control and accountability (MC&A) plan, as applicable. The
performance assurance program plan must describe the program and its
administration and implementation by:
(a) identifying protection elements for the protection of Category I and
II special nuclear material (SNM) and Top Secret matter;
(b) describing how the performance of these elements is to be ensured,
including the manner in which credit is taken for activities
performed by external oversight organizations;
(c) addressing how deficiencies identified during performance
assurance activities are to be corrected.
DOE M 470.4-1 Part 1, Section F
8-26-05 F-3 (and F-4)
(2) Performance Assurance Reports. The results of performance assurance
program testing must be documented.
(3) Document Retention. Record keeping systems must provide an audit trail
for performance assurance activities and reports.
DOE M 470.4-1 Part 1, Section G
8-26-05 G-1
SECTION G—SURVEY, REVIEW, AND SELF-ASSESSMENT PROGRAMS
1. OBJECTIVES.
a. Provide assurance to the Secretary of Energy, Departmental elements, and other
government agencies (OGAs) that safeguards and security (S&S) interests and
activities are protected at the required levels.
b. Provide a basis for line management to make decisions regarding S&S program
implementation activities, including allocation of resources, acceptance of risk,
and mitigation of vulnerabilities. The results must provide a compliance- and
performance-based documented evaluation of the S&S program.
c. Identify S&S program strengths and weaknesses, develop and complete a process
improvement schedule, and use the results to correct and improve the overall S&S
program.
d. Provide documentation of oversight and assessment activities.
2. REQUIREMENTS.
a. Types and Frequencies of Surveys and Assessments.
(1) Initial Surveys. Initial surveys must be conducted at facilities where there
will be a facility clearance established for a facility with an importance
rating of: A, B, C, or PP (see Section I, Chapter II). Survey activities
must be comprehensive and result in a satisfactory composite rating prior
to a facility clearance (FCL) being granted.
(2) Periodic Surveys. Periodic surveys are conducted for all facilities and
must cover all applicable topics to ensure survey program objectives are
met. The periodic survey may be composed of multiple special survey
reports, providing all the requirements of this section are met. Integration
of internal and external reports including quality assurance, property
appraisals, performance assurance, and other evaluation reports may be
used to augment the requirement for a periodic survey. A DOE Federal
facility (e.g. site office) conducting a periodic survey fulfills the
self-assessment requirement as noted in paragraph 2a(6) below.
(a) Facilities with importance ratings of A, B, or C must be surveyed
once every 12 months [with the exception of Category IV special
nuclear material (SNM) only facilities—see paragraph 2a(2)(c)
below].
Section 53
(b) Facilities with an importance rating of PP must be surveyed once
every 24 months.
Part 1, Section G DOE M 470.4-1
G-2 8-26-05
(c) For facilities with Category IV SNM and nuclear material,
including source material, the nuclear material control and
accountability (MC&A) topical area must be surveyed at least
every 24 months.
(d) Facilities with importance ratings of D, NP, or E do not require
surveys but do require periodic reviews [see paragraph 2(a)(5)
below].
(3) Special Surveys. Special surveys may be conducted at facilities for
specific limited purposes. Examples include extended survey activities,
technical security activities, “for cause” reviews, line management
direction, shipment of nuclear and/or classified information or matter, or a
change in the contractor operating a government-owned facility.
(4) Termination Surveys. Termination surveys must be conducted to verify
the termination of Departmental activities and appropriate disposition of
S&S interests. Examples of survey activities include: the appropriate
disposition, destruction, or return of classified information or matter,
SNM, hazardous material, property, security badge retrieval, debriefings,
and verification of the termination or transfer of Department of Energy
(DOE) access authorizations.
(a) Onsite termination surveys must be conducted at facilities
possessing Top Secret matter, sensitive compartmented
information (SCI)/ special access program (SAP) information or
matter, or SNM.
(b) Onsite or correspondence termination surveys must be
accomplished for all other possessing facilities.
(5) Periodic Reviews. A documented review of entities (D, NP, and E
facilities) such as subcontractors, consultants, and common carriers must
be performed by the DOE cognizant security authority at least every
5 years.
(6) Self-Assessments. Self-assessments must be conducted between the
periodic surveys conducted by the cognizant security authority and include
all applicable facility S&S program elements. The self-assessment must
ensure the S&S objectives are met (see paragraph 1 above). Federal
facilities may use the self-assessment to substitute for the Periodic Survey
requirement. NP facilities are not required to conduct self-assessments.
However, sponsoring organizations (Federal or contractor) must include in
their self-assessments a thorough review of their registration program for
NP facilities which may result in a program review of identified
subcontractors.
DOE M 470.4-1 Part 1, Section G
8-26-05 G-3
(7) Reviews or Inspections by Other DOE Elements or OGAs.
Reviews/inspections conducted by other DOE elements (including site
quality assurance programs) or OGAs may be used to meet survey
requirements. When using reviews/inspections conducted by other
organizations to meet the requirements of the survey, the guidelines below
must be followed.
(a) The review/inspection must have been conducted within the survey
period.
(b) Applicable portions of the review/inspection must be attached to
the survey report.
(c) Portions of topical and subtopical areas not covered by the
review/inspection must be surveyed.
(d) If ratings were not assigned during the review/inspection, the
surveying office must analyze the impact of any deficiencies and
assign ratings.
(8) Extension of Frequency. The results of previous surveys may affect the
frequency of future surveys. The interval between periodic surveys may
be increased up to 24 months by the DOE cognizant security authority.
Documentation of the justification for increases in the interval of periodic
surveys must be maintained by the DOE cognizant security authority.
Section 54
(a) The following conditions must be met for extensions:
1 the facility was rated satisfactory during the most recent
survey activity;
2 the facility has no unmitigated deficiencies that impact the
security posture of the facility, and all applicable topical
area ratings are satisfactory from the previous survey; and
3 all applicable topical area ratings from the most recent
self-assessment are satisfactory, and the DOE cognizant
security authority concurs with the ratings.
(b) Increasing the interval between surveys for a facility possessing
Category I SNM or with credible roll-up to Category I SNM must
be approved, in writing, by the Associate Administrator for
Defense Nuclear Security or the Under Secretary for Energy,
Science, and Environment.
(c) All modifications to survey frequency requirements must be
documented in the Safeguards and Security Information
Management System (SSIMS).
Part 1, Section G DOE M 470.4-1
G-4 8-26-05
b. Scope and Methodologies. Surveys and self-assessments must provide an
integrated evaluation of all topical and subtopical areas to determine the overall
status of the S&S program and ensure the objectives of this section are met (see
paragraph 1 above). The integrated evaluation is a comprehensive synergistic
approach using multiple S&S program elements that ensures total system
effectiveness and, if properly implemented, will meet the objectives identified in
paragraph 1 above. The scope of these activities and the methods used must
include those listed below.
(1) Compliance. Compliance reflects the status of the S&S program as
measured against implementation of applicable Federal statutes,
regulations, policies, approved site safeguards and security plans
(SSSPs)/site security plans (SSPs), and other approved security plans.
(2) Performance. Performance indicates the degree to which the elements of
the S&S program meet protection objectives based on the operational
testing of program elements.
(3) Comprehensiveness. Comprehensiveness identifies the breadth of
protection afforded all activities and interests within a facility. This is
accomplished by an evaluation of the adequacy and effectiveness of
programs and a thorough examination of the implementation of policies,
practices, and procedures to ensure compliance and performance. All
applicable topical areas identified on DOE Form (F) 470.8,
“Survey/Inspection Report” Form must be evaluated.
(4) Other. The scope of special and termination surveys is determined by the
DOE cognizant security authority in coordination with the surveying
office. Determinations of survey scope are predicated on the nature or
status of operations at the facility, activity, or element being surveyed.
These surveys may not cover all topical areas identified on DOE F 470.8.
3. CONDUCT. Local survey and self-assessment procedures implementing this section
must be developed, documented, and approved by the cognizant security authority.
Procedures must ensure completion of the objectives contained in paragraph 1 above and
must include the requirements listed below.
a. Team Composition. Survey and self-assessment team personnel must possess
qualifications, experience, and training sufficient to review and inspect the
topical/subtopical areas of the survey/self-assessment. The National Training
Center (NTC) provides training courses for survey team leaders and team
members.
(1) Survey teams must be led by a Federal employee and may be composed of
Departmental Federal and contractor personnel.
Section 55
DOE M 470.4-1 Part 1, Section G
8-26-05 G-5
(2) Self-assessments must include at least one person from the cognizant
security authority.
b. Planning, Scheduling, and Integration. Surveys and self-assessments must be
planned, scheduled, and conducted in an integrated manner to achieve the
objectives identified in paragraph 1 above. If topical and subtopical area
evaluations are performed separately, the surveying office must document and
integrate the results of each into a single (periodic) survey report that includes a
composite facility rating. The frequency between topical and subtopical areas
cannot exceed the frequency for the single (periodic) survey.
c. Validation. Results must be validated by methods including, but not limited to,
document reviews, performance testing, and interview analyses and observations.
d. Exit Briefing. An exit briefing must be conducted with the surveyed or assessed
organization to include the minimum facts:
(1) program strengths and weaknesses, including all findings;
(2) corrective action reporting requirements for all open findings, regardless
of source; and
(3) topical and composite ratings. For less than satisfactory ratings, the
communication of the composite rating initiates the actions required in
paragraph 8 of this section.
4. FINDINGS.
a. Identification and Documentation. Findings are any validated program deficiency
(failure to meet a performance or compliance requirement) regardless of source.
Findings may be reflected in documents resulting from internal and external
reviews, audits, appraisals, and other sources [e.g., the Office of Independent
Oversight and Performance Assurance (OA), the Government Accountability
Office (GAO), the Office of the Inspector General (IG), previous surveys,
self-assessments, etc.].
All open findings must be reviewed during the survey or self-assessment to
validate the status of corrective action and to evaluate the impact on the existing
S&S program.
Findings identified during the current survey or self-assessment must be reported
immediately to the Departmental element and contractor line management if a
vulnerability to national security, classified information or matter, nuclear
materials, or Department property results, or may result, in a programmatic
impact to the Department. Findings identified during a survey or self-assessment,
even if closed during the survey or self-assessment activity, must be documented
in the associated report.
Part 1, Section G DOE M 470.4-1
G-6 8-26-05
b. Tracking. Findings and deficiencies, regardless of source, and corrective action
plans (milestones and estimated completion dates) must be entered into SSIMS in
accordance with SSIMS guidelines and tracked until closed. Quarterly status
reports must be entered into SSIMS by January 15, April 15, July 15, and
October 15, of each year. Self-assessment deficiencies are not required to be
entered into SSIMS; however, a local mechanism/system must be used to track
these deficiencies and corrective action until closed.
c. Trending. Trending evaluations must be considered in the resolution of findings
in the subtopical area of program management to determine if systemic and
systematic causal factors exist within the S&S program. Results of this
evaluation that indicate negative trends must be analyzed to ensure corrective
action plans address root causes and the need to ensure continuous improvement
of the S&S program.
5. RATINGS.
Section 56
a. Types. Ratings must be based on the effectiveness and adequacy of the program
at a facility and reflect a balance of performance and compliance results as well as
the impact of the deficiency(ies) (e.g., findings, IG recommendations, etc.) and
mitigating factors. The ratings listed below must be used for all surveys (except
termination), reviews, and self-assessments. Does Not Apply (DNA) and Not
Rated (NR) may also be used in applicable situations.
(1) Types of Ratings.
(a) Satisfactory. The element being evaluated meets protection
objectives or provides reasonable assurance that protection
objectives are being met.
(b) Marginal. The element being evaluated partially meets protection
objectives or provides questionable assurance that protection
objectives are being met.
(c) Unsatisfactory. The element being evaluated does not meet
protection objectives or does not provide adequate assurance that
protection objectives are being met.
(d) Inspection Ratings. “Effective Performance,