Archives of Directives

Archive

DOE M 470.4-1, Safeguards and Security Program Planning and Management

Functional areas: Program Planning and Management, Safeguards, Security, and Emergency Management, Work Processes

Establishes program planning and management requirements for the Departments Safeguards and Security (S&S) Program. Cancels: DOE N 473.9 and DOE M 470.1-1
m4704-1.pdf1.80MB
Version history and related documents

Superseded by

A newer version replaces this document.

Supersedes

Earlier documents this one replaced.

View full version history

Document text

Text extracted from the attached file. Refer to the original document for the authoritative version.

Section 1

AVAILABLE ONLINE AT: INITIATED BY: www.directives.doe.gov Office of Security and Safety Performance Assurance Approved: 08-26-05 Review: 08-26-07 SAFEGUARDS AND SECURITY PROGRAM PLANNING AND MANAGEMENT U.S. DEPARTMENT OF ENERGY Office of Security and Safety Performance Assurance DOE M 470.4-1 CANCELE D DOE M 470.4-1 08-26-05 1 SAFEGUARDS AND SECURITY PROGRAM PLANNING AND MANAGEMENT 1. PURPOSE. To establish program planning and management requirements for the Department’s Safeguards and Security (S&S) Program. 2. OBJECTIVES. a. Effect the policy in DOE P 470.1, Integrated Safeguards and Security Management (ISSM) Policy, by integrating program planning and management into Department of Energy (DOE) operations as determined by line management, and according to sound risk management practices. (DOE P 470.1, Integrated Safeguards and Security Management [ISSM] Policy, is the Department’s philosophical approach to the management of the S&S Program. A principal objective of the ISSM Program is to integrate S&S into management and work practices at all levels, based on program line management’s risk management- based decisions, so that missions may be accomplished without security events, such as interruption, disruption or compromise. This approach includes individual responsibility and implementation of the security requirements found in this Manual.) b. Establish individual responsibilities to fulfill the requirements in this Manual. c. Establish requirements for S&S planning and evaluations. d. Establish requirements for S&S management. e. Promulgate the requirements of the National Industrial Security Program. 3. PROGRAM INTEGRATION. S&S program planning and management must be integrated with other programs such as physical protection, protective force (PF), information security, personnel security, and nuclear material control & accountability (MC&A). Mechanisms must also exist to assure that S&S program planning is fully integrated with overall site strategic and near-term operational planning. Additionally, the activities and requirements in the weapons surety, foreign visits and assignments, safety, emergency management, cyber security, and intelligence and counterintelligence programs should also be considered in the implementation of this Manual. 4. CANCELLATIONS. The directives listed below are canceled. Cancellation of a directive does not by itself modify or otherwise affect any contractual obligation to comply with the directive. Canceled directives that are incorporated by reference in a contract remain in effect until the contract is modified to delete the reference to the requirements in the canceled directives. The publication of this Manual incorporates or cancels all previous memoranda or letters that were issued by the Office of Security or its predecessor organizations that established policy. CANCELE D DOE M 470.4-1 08-26-05 2 a. DOE N 473.9, Security Conditions, dated 7-8-04. b. DOE M 470.1-1, Safeguards and Security Awareness Program, dated 10-02-02. 5. APPLICABILITY. a. Departmental Elements. Except for the exclusion in paragraph 5.c., this Manual applies to all Departmental elements, listed on Attachment 1. This Manual automatically applies to Departmental elements created after it is issued. The Administrator of the National Nuclear Security Administration (NNSA) will assure that NNSA employees and contractors comply with their respective responsibilities under this Manual.

Section 2

b. Contractors. (1) The Contractor Requirements Document (CRD), Attachment 2, sets forth requirements of this Manual that will apply to site/facility management contracts that include the CRD. (2) The CRD must be included in the site/facility management contracts that involve classified information or matter, or nuclear materials and contain DOE Acquisition Regulation (DEAR) clause 952.204-2, titled Security Requirements. (a) Departmental elements must notify contracting officers of affected site/facility management contracts to incorporate this directive into those contracts. (b) Once notified, contracting officers are responsible for incorporating this directive into the affected contracts via the Laws, Regulations, and DOE Directives clause of the contracts. (3) A violation of the provisions of the CRD relating to the safeguarding or security of Restricted Data or other classified information may result in a civil penalty pursuant to subsection a. of section 234B, of the Atomic Energy Act of 1954 (42 U.S.C. 228b.). The procedures for the assessment of civil penalties are set forth in Title 10, Code of Federal Regulations (CFR), Part 824, Procedural Rules for the Assessment of Civil Penalties for Classified Information Security Violations, (10 CFR Part 824). (4) As stated in DEAR clause 970.5204-2, titled Laws, Regulations, and DOE Directives, regardless of the performer of the work, site/facility contractors with the CRD incorporated into their contracts are responsible for compliance with the CRD. Affected site/facility management contractors are responsible for flowing down the requirements of the CRD to subcontracts at any tier to the extent necessary to ensure compliance CANCELE D DOE M 470.4-1 08-26-05 3 with the requirements. In doing so, contractors must not unnecessarily or imprudently flow down requirements to subcontracts. That is, contractors must both ensure that they and their subcontractors comply with the requirements of this CRD and incur only costs that would be incurred by a prudent person in the conduct of competitive business. (5) This Manual does not automatically apply to other than site/facility management contracts. Application of any of the requirements in this Manual to other than site/facility management contracts will be communicated as follows. (a) Heads of Field Elements and Headquarters Departmental Elements. Review procurement requests for new non-site/facility management contracts that involve classified information or matter, or nuclear materials and contain DEAR clause 952.204-2, titled Security Requirements. If appropriate, ensure that the requirements of the CRD of this Manual are included in the contract. (b) Contracting Officers. Assist originators of procurement requests who want to incorporate the requirements of the CRD of this Manual in new non-site/facility management contracts, as appropriate. c. Exclusion. In accordance with the responsibilities and authorities assigned by Executive Order 12344 and to ensure consistency throughout the joint Navy and DOE organization of the Naval Nuclear Propulsion Program, the Deputy Administrator for Naval Reactors will implement and oversee all requirements and practices pertaining to this Manual for activities under the Deputy Administrator’s cognizance. d. Exemption.

Section 3

(1) Requirements in this Manual that overlap or duplicate requirements of the, Nuclear Regulatory Commission (NRC) related to radiation protection, nuclear safety (including quality assurance), and safeguards and security of nuclear material, do not apply to the design, construction, operation, and decommissioning of the Office of Civilian Radioactive Waste Management (RW) facilities. (2) This exemption does not apply to requirements for which the NRC defers to DOE or does not exercise regulatory jurisdiction. 6. DEVIATIONS. Deviations from requirements must be processed in accordance with Section M. 7. DEFINITIONS. Terms commonly used in the program are defined in the S&S Glossary CANCELE D DOE M 470.4-1 08-26-05 4 located in DOE M 470.4-7, Safeguards and Security Program References. In addition to those in the Glossary, the following definitions are provided for use in this Manual. a. DOE line management refers to DOE and NNSA Federal employees who have been granted the authority to commit resources or direct the allocation of personnel or approve implementation plans and procedures in the accomplishment of specific work activities. b. Line management refers to DOE and NNSA Federal and contractor employees who have been granted the authority to commit resources or direct the allocation of personnel or approve implementation plans and procedures in the accomplishment of specific work activities. c. DOE cognizant security authority refers to DOE and NNSA Federal employees who have been granted the authority to commit security resources or direct the allocation of security personnel or approve security implementation plans and procedures in the accomplishment of specific work activities. d. Cognizant security authority refers to DOE and NNSA Federal and contractor employees who have been granted the authority to commit security resources or direct the allocation of security personnel or approve security implementation plans and procedures in the accomplishment of specific work activities. e. For the purposes of this Manual, the Office of Security refers to the DOE Office of Security, Office of Security and Safety Performance Assurance. 8. IMPLEMENTATION. Requirements that cannot be implemented within 6 months of the effective date of this Manual or within existing resources must be documented by the cognizant security authority and submitted to the relevant program officers: the Under Secretary for Energy, Science and Environment or the Under Secretary for Nuclear Security/Administrator, NNSA; and the Office of Security. The documentation must include timelines and resources needed to fully implement this Manual. The documentation must also include a description of the vulnerabilities and impacts created by the delayed implementation of the requirements. 9. CONTACT. Questions concerning this Manual should be directed to the Office of Security at (202) 586-3345. BY ORDER OF THE SECRETARY OF ENERGY: CLAY SELL Deputy Secretary CANCELE D DOE M 470.4-1 08-26-05 i CONTENTS PART 1 PLANNING AND EVALUATIONS SECTION A – SAFEGUARDS AND SECURITY PROGRAM PLANNING 1. OBJECTIVE ........................................................................................................................1 2. REQUIREMENTS...............................................................................................................1 3. PLANNING .........................................................................................................................3

Section 4

APPENDIX 1 – SAFEGUARDS AND & SECURITY MANAGEMENT PLAN 1. EXECUTIVE SUMMARY ............................................................................ Appendix 1-1 2. PART 1 – ORGANIZATIONAL STRUCTURE AND ACCOUNTABILITY ................................................................................... Appendix 1-1 3. PART 2 – ROLES, RESPONSIBILITIES, DELEGATIONS, AND AUTHORITIES .................................................................................. Appendix 1-2 4. PART 3 – S&S PROGRAM IMPLEMENTATION ...................................... Appendix 1-2 5. PART 4 – PLANNING AND BUDGET (INCLUDING PERSONNEL RESOURCES) .............................................................................................. Appendix 1-3 SECTION B – SECURITY CONDITIONS 1. OBJECTIVE ........................................................................................................................1 2. THREAT INDICATORS.....................................................................................................1 3. SECURITY CONDITIONS.................................................................................................2 SECTION C – SITE SAFEGUARDS AND SECURITY PLANS 1. OBJECTIVE ........................................................................................................................1 2. APPLICATION ...................................................................................................................1 3. SCOPE .................................................................................................................................1 4. PURPOSE............................................................................................................................1 5. PLAN COMPOSITION.......................................................................................................1 6. EVIDENCE FILES..............................................................................................................2 7. DATA COLLECTION ........................................................................................................2 CANCELE D DOE M 470.4-1 08-26-05 ii 8. FORMAT.............................................................................................................................2 SECTION C – TABLES Table C-1. SNM Theft/Diversion Targets ....................................................................................6 Table C-2. Radiological Sabotage Targets ...................................................................................6 Table C-3. Biological/Chemical Sabotage Targets.......................................................................7 Table C-4. Disruption of Critical Mission Targets .......................................................................7 Table C-5. Site-Wide Protection Strategies..................................................................................8 Table C-6. Facility Protection Systems ........................................................................................9 Table C-7. Qualification and Training........................................................................................10 Table C-8. MC&A Plans and Procedures ...................................................................................11 Table C-9. Personnel Security/Human Reliability Program Implementation ............................12

Section 5

Table C-10. Automated Information Systems Security Programs................................................13 Table C-11. S&S-Related Maintenance, Testing and Records Management Programs ..............14 Table C-12. Site Protection Program Evaluation Program...........................................................15 Table C-13. Deviations from DOE Directives..............................................................................15 Table C-14. Pending Deviations from DOE Directives ...............................................................15 Table C-15. Summary of Identified Risks ....................................................................................17 Table C-16. SNM Theft/Diversion Targets ..................................................................................18 Table C-17. Credible Radiological Sabotage Targets ..................................................................19 Table C-18. Credible Biological Sabotage Targets ......................................................................19 Table C-19. Credible Chemical Sabotage Targets........................................................................20 Table C-20. Disruption of Critical Mission Targets .....................................................................20 Table C-21. Performance Testing Results of Site-Specific Essential Protection Element Values .....................................................................21 Table C-22. Critical Path Scenarios..............................................................................................22 Table C-23. Protection Effectiveness (PE) for Theft or Diversion of SNM .................................24 CANCELE D DOE M 470.4-1 08-26-05 iii Table C-24. Protection Effectiveness (PE) for Radiological Sabotage .........................................24 Table C-25. Protection Effectiveness (PE) for Biological Sabotage.............................................25 Table C-26. Protection Effectiveness (PE) for Chemical Sabotage ..............................................25 Table C-27. Protection Effectiveness (PE) for Disruption of Critical Missions ...........................25 Table C-28. Protection Effectiveness (PE) for Theft or Espionage of Classified Matter .............26 Table C-29. Protection Effectiveness (PE) for Other Losses ........................................................26 Table C-30. System Effectiveness Summary................................................................................26 SECTION D – SITE SAFEGUARDS AND SECURITY PLAN/RESOURCE PLAN 1. OBJECTIVE ........................................................................................................................1 2. UNFUNDED/UNSUPPORTED REQUIREMENTS..........................................................5 3. REFERENCES FOR THE RESOURCE PLAN..................................................................5 4. HEADINGS AND TERMS FOR TABLES D-1 THROUGH D-5 .....................................5 SECTION D – TABLES Table D-1. Operational Requirements ............................................................................................1 Table D-2. Capital Equipment ........................................................................................................2 Table D-3. General Plant Projects ..................................................................................................3

Section 6

Table D-4. Line Item Construction Projects ...................................................................................4 Table D-5. Unfunded/Unsupported Requirements .........................................................................4 SECTION E – VULNERABILITY ASSESSMENT PROGRAM 1. OBJECTIVE ........................................................................................................................1 2. CONDUCTING VULNERABILITY ASSESSMENTS .....................................................1 3. QUALITY ASSURANCE ...................................................................................................3 4. VULNERABILITY ASSESSMENT DOCUMENTATION...............................................3 5. ASSIGNING FIGURES OF MERIT...................................................................................3 6. CRITICAL SYSTEM ELEMENTS ....................................................................................4 7. VULNERABILITY ASSESSMENT REPORTS ................................................................4 CANCELE D DOE M 470.4-1 08-26-05 iv 8. SYSTEM EFFECTIVENESS..............................................................................................4 9. TRAINING AND CERTIFICATION .................................................................................6 APPENDIX 2 – VULNERABILITY ASSESSMENT MODELING TOOLS........... Appendix 2-1 APPENDIX 3 – SYSTEM PERFORMANCE EFFECTIVENESS EQUATION ...... Appendix 3-1 APPENDIX 4 – SUGGESTED VULNERABILITY ASSESSMENT REPORT FORMAT ....................................................................................................... Appendix 4-1 SECTION F – PERFORMANCE ASSURANCE PROGRAM 1. OBJECTIVE ........................................................................................................................1 2. REQUIREMENTS...............................................................................................................1 SECTION G – SURVEY, REVIEW, AND SELF-ASSESSMENT PROGRAMS 1. OBJECTIVES......................................................................................................................1 2. REQUIREMENTS...............................................................................................................1 3. CONDUCT ..........................................................................................................................4 4. FINDINGS...........................................................................................................................5 5. RATINGS ............................................................................................................................6 6. REPORT CONTENT...........................................................................................................7 7. DISTRIBUTION................................................................................................................10 8. NOTIFICATIONS AND ACTIONS FOR LESS THAN SATISFACTORY SURVEY COMPOSITE RATINGS................................................................................11 9. NOTIFICATIONS AND ACTIONS FOR LESS THAN SATISFACTORY SELF- ASSESSMENT COMPOSITE RATINGS ........................................................................11 10. CORRECTIVE ACTIONS ................................................................................................12 11. UPGRADE OF COMPOSITE RATINGS.........................................................................12

Section 7

12. RECORDS RETENTION..................................................................................................13 13. CONTINUOUS IMPROVEMENT PROCESS.................................................................13 PART 2 – SAFEGUARDS AND SECURITY MANAGEMENT SECTION H – FOREIGN OWNERSHIP, CONTROL, OR INFLUENCE PROGRAM CANCELE D DOE M 470.4-1 08-26-05 v 1. OBJECTIVE ........................................................................................................................1 CHAPTER I, GENERAL FOCI PROGRAM INFORMATION 1. GENERAL REQUIREMENTS ........................................................................................I-1 2. APPLICABILITY.............................................................................................................I-2 3. CONTRACT AWARD MUST NOT BE MADE PRIOR TO FCL ISSUANCE.............I-3 4. ELECTRONIC SUBMISSION/PROCESSING WEB SITE............................................I-3 CHAPTER II, FOCI ACTIVITIES 1. DETERMINING THE SECURITY REQUIREMENTS OF THE CONTRACT/AGREEMENT ......................................................................................... II-1 2. DETERMINING THE FCL STATUS OF THE APPLICANT...................................... II-1 3. ACCEPTING A FOCI DETERMINATION RENDERED BY ANOTHER FEDERAL AGENCY................................................................................. II-1 4. CLASSIFIED CONTRACT ........................................................................................... II-1 5. ADJUDICATION........................................................................................................... II-3 6. COMMITTEE ON FOREIGN INVESTMENT IN THE UNITED STATES................ II-6 CHAPTER III, REPORTING REQUIREMENTS 1. FOCI CHANGES OCCUR FOLLOWING SUBMISSION OF AN SF 328 AND BEFORE CONTRACT AWARD.................................................................................. III-1 2. UPDATES...................................................................................................................... III-1 3. ANNUAL CERTIFICATION ....................................................................................... III-3 CHAPTER IV, FOCI MITIGATION ACTION PLANS 1. GENERAL..................................................................................................................... IV-1 2. MITIGATION ACTION PLANS.................................................................................. IV-1 3. FOREIGN OWNERSHIP.............................................................................................. IV-1 4. ANNUAL COMPLIANCE MEETING....................................................................... IV-11 5. NON-COMPLIANCE WITH MITIGATION PLANS................................................ IV-11 APPENDIX 5 – FOCI MATRIX CHART ................................................................ Appendix 5-1 CANCELE D DOE M 470.4-1 08-26-05 vi SECTION I – FACILITY CLEARANCES AND REGISTRATION OF SAFEGUARDS AND SECURITY ACTIVITIES 1. OBJECTIVE ........................................................................................................................1 CHAPTER I – FCL PROGRAM 1. GENERAL........................................................................................................................I-1 2. EXCEPTIONS TO REGISTRATION IN SSIMS............................................................I-3 CHAPTER II – IMPORTANCE RATINGS

Section 8

1. FACILITY IMPORTANCE RATINGS ......................................................................... II-1 2. UPGRADING AND DOWNGRADING A FACILITY’S ASSIGNED IMPORTANCE RATING ............................................................................................ II-2 CHAPTER III – ORGANIZATIONAL STRUCTURES AND FCLs 1. FCL FOR SINGLE LEGAL ENTITIES........................................................................ III-1 2. PARENT – SUBSIDIARY RELATIONSHIP .............................................................. III-2 CHAPTER IV – INTERIM AND LIMITED FCLs 1. INTERIM FCL............................................................................................................... IV-1 2. LIMITED FCL............................................................................................................... IV-1 CHAPTER V – ACCESS AUTHORIZATIONS AND EXCLUSION PROCEDURES REQUIRED IN CONNECTION WITH FCLs 1. ACCESS AUTHORIZATIONS REQUIRED IN CONNECTION WITH THE FCL ............................................................................................................................ V-1 2. MFOs .............................................................................................................................. V-1 3. ACCESS AUTHORIZATIONS CONCURRENT WITH THE FCL............................. V-1 4. EXCLUSION PROCEDURES....................................................................................... V-2 CHAPTER VI – FACILITY CLEARANCE 1. REQUIREMENTS.........................................................................................................VI-1 2. ISSUANCE OF FCLs ....................................................................................................VI-2 3. CHANGED CONDITIONS AFFECTING THE FCL...................................................VI-2 4. INTERFACE WITH FOCI REQUIREMENTS ............................................................VI-2 CANCELE D DOE M 470.4-1 08-26-05 vii CHAPTER VII – PROCESS FOR FCL AND SECURITY ACTIVITY REGISTRATION 1. ACCEPTING OGA FCLs.............................................................................................VII-1 2. OGA VERIFICATION REQUESTS............................................................................VII-5 3. REGISTERING OGA FCLs.........................................................................................VII-5 4. REGISTRATION OF OGA CONTRACTORS IN SSIMS..........................................VII-6 5. REGISTERING WORK FOR OTHERS (WFO) ACTIVITIES ..................................VII-6 6. REGISTRATION OF DOE FCLs ................................................................................VII-7 7. REGISTRATION OF SECURITY ACTIVITIES......................................................VII-10 SECTION J – SAFEGUARDS AND SECURITY TRAINING PROGRAM 1. OBJECTIVE ........................................................................................................................1 2. REQUIREMENTS...............................................................................................................1 SECTION K – SAFEGUARDS AND SECURITY AWARENESS PROGRAM 1. OBJECTIVE ........................................................................................................................1 2. REQUIREMENTS...............................................................................................................1

Section 9

3. PROGRAM DESIGN AND DEVELOPMENT..................................................................1 4. BRIEFINGS.........................................................................................................................1 5. CLASSIFIED INFORMATION NONDISCLOSURE AGREEMENT (SF-312)...............5 6. SUPPLEMENTARY AWARENESS ACTIVITIES ...........................................................6 SECTION L – CONTROL OF CLASSIFIED VISITS PROGRAM 1. OBJECTIVE ........................................................................................................................1 2. REQUIREMENTS...............................................................................................................1 APPENDIX 6 – ACCESS TO RESTRICTED DATA IN POSSESSION OF OTHER FEDERAL AGENCIES ........................................................................ Appendix 6-1 SECTION M – DEVIATIONS 1. OBJECTIVE ........................................................................................................................1 2. REQUIREMENTS...............................................................................................................1 CANCELE D DOE M 470.4-1 08-26-05 viii SECTION M - TABLES Table M-1. Deviation Approval Process ........................................................................................1 APPENDIX 7 – FORMAT FOR DEVIATION REQUESTS ................................... Appendix 7-1 SECTION N – INCIDENTS OF SECURITY CONCERN 1. OBJECTIVE ........................................................................................................................1 2. REQUIREMENTS...............................................................................................................1 CHAPTER I – IDENTIFICATION AND REPORTING REQUIREMENTS 1. GENERAL........................................................................................................................I-1 2. INCIDENT IDENTIFICATION AND CATEGORIZATION.........................................I-1 3. REPORTING REQUIREMENTS ....................................................................................I-8 4. INQUIRY OFFICIALS ..................................................................................................I-14 5. FEDERAL, STATE, OR LOCAL LAW ENFORCEMENT PERSONNEL..................I-15 6. CONDUCT OF INQUIRIES ..........................................................................................I-16 7. INQUIRY REPORT CONTENT/CLOSURE CONSIDERATIONS.............................I-19 8. ADMINISTRATIVE ACTIONS ....................................................................................I-21 9. RECORDS RETENTION...............................................................................................I-21 SECTION N – TABLES AND FIGURES Table N-1. Reportable Categories of Incidents of Security Concern, Impact Measurement Index 1 (IMI-1) ....................................................................................................3 Table N-2. Reportable Categories of Incidents of Security Concern, Impact Measurement Index 2 (IMI-2) ....................................................................................................4 Table N-3. Reportable Categories of Incidents of Security Concern, Impact Measurement Index 3 (IMI-3) ....................................................................................................5

Section 10

Table N-4. Reportable Categories of Incidents of Security Concern, Impact Measurement Index 4 (IMI-4) ....................................................................................................7 Figure 1. Incidents of Security Concern ....................................................................................I-10 Figure 2. Example Chain of Custody Form...............................................................................I-17 CANCELE D DOE M 470.4-1 08-26-05 ix CHAPTER II, INCIDENTS OF SECURITY CONCERN INVOLVING COMPROMISE OR POTENTIAL COMPROMISE OF CLASSIFIED INFORMATION 1. INQUIRIES INTO COMPROMISE OF POTENTIAL COMPROMISE OF, OR MISSING CLASSIFIED INFORMATION ................................................................... II-1 2. DAMAGE ASSESSMENTS .......................................................................................... II-2 3. CONDUCT OF DAMAGE ASSESSMENTS................................................................ II-3 4. PROCEDURES............................................................................................................... II-3 5. CONTENT OF DAMAGE ASSESSMENT REPORTS ................................................ II-3 6. COMBINING SIMILAR INCIDENTS.......................................................................... II-4 7. CASES INVOLVING OTHER GOVERNMENT AGENCY INFORMATION........... II-4 8. CASES INVOLVING FOREIGN GOVERNMENT INFORMATION ........................ II-4 9. JOINT DAMAGE ASSESSMENT WITH ANOTHER GOVERNMENT AGENCY...................................................................................................................... II-5 SECTION O – RESTRICTIONS ON THE TRANSFER OF SECURITY-FUNDED TECHNOLOGIES OUTSIDE THE DEPARTMENT AND ITS OPERATIONAL FACILITIES 1. OBJECTIVE ........................................................................................................................1 2. REQUIREMENTS...............................................................................................................1 APPENDIX 8 – TECHNOLOGY TRANSFER Approval Requests ...................................................................................................... Appendix 8-1 ATTACHMENTS Attachment 1 Departmental Elements to which DOE M 470.4-1 Applies.............Attachment 1-1 Attachment 2 Contractor Requirements Document ...............................................Attachment 2-1 CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section A 1 PART 1 - PLANNING AND EVALUATIONS SECTION A - SAFEGUARDS AND SECURITY PROGRAM PLANNING 1. OBJECTIVE. To establish a standardized approach for protection program planning that will provide an information baseline for use in integrating Departmental safeguards and security (S&S) considerations, facilitating management evaluation of program elements, determining resources for needed improvements, and establishing cost-benefit bases for analyses and comparisons. 2. REQUIREMENTS. The following are essential elements for planning for S&S programs. a. S&S Philosophy. S&S interests and activities must be protected from theft, diversion, terrorist attack, industrial sabotage, radiological sabotage, chemical sabotage, biological sabotage, espionage, unauthorized access, compromise, and other acts that may have an adverse impact on national security; the environment; or pose significant danger to the health and safety of Department of Energy (DOE) Federal and contractor employees or the public.

Section 11

b. S&S Management Plan. This Plan must provide a description of the implementation of S&S policy and provide detailed information on the assignment of roles, responsibilities, and authorities, as well as the development of budgets and allocation of resources. The S&S Management Plan must be updated annually (at least every 12 months) and must document: (1) roles, responsibilities, delegations, and authorities for the S&S program; (2) organizational structure and accountability; and (3) planning and budget (including personnel resources). See Appendix 1, S&S Management Plan, for content requirements and suggested format. However, if a Functions, Responsibilities, and Authorities Manual for S&S has been approved and issued, and it meets the requirements stated above, it can be used in place of a S&S Management Plan. c. S&S Program Operations. Actions must be taken to ensure an acceptable S&S program, including curtailment or suspension of operations when such operations would result in an immediate and unacceptable impact to national security, the environment, or the health and safety of the public or employees. (1) Site-Specific Characterization. Protection programs must be tailored to address specific site characteristics and requirements, current technology, ongoing programs, and operational needs to achieve acceptable protection levels that reduce risks in a cost-effective manner. CANCELE D DOE M 470.4-1 08-26XX-05 Part 1, Section A 2 (2) Threat Policy/Guidance. DOE O 470.3, Design Basis Threat (DBT) Policy must be used with local threat guidance during the conduct of vulnerability assessments (VAs) for protection and control program planning. The DBT must be the baseline threat definition but local threat guidance may be used to increase the level of threat to be analyzed. (3) Targeted Protection Strategies. (a) Strategies for the physical protection of special nuclear materials (SNM) and vital equipment must incorporate the applicable requirements established in DOE M 470.4-2, Physical Protection. (b) Protection strategies must be implemented as specified in the DBT. (c) Protection program elements must be designed to prevent and/or mitigate the consequences of acts of radiological, chemical, or biological sabotage that would cause unacceptable impact to national security, the environment, or the health and safety of the public or employees. (d) Strategies for the protection and control of classified information or matter must incorporate the applicable requirements established in DOE M 470.4-4, Information Security. (e) Security systems must be used that prevent, detect, or deter unauthorized access, modification, or loss of classified and unclassified controlled matter and its unauthorized removal from a site or facility. (f) Strategies for the protection of government property not covered above must reflect a graded approach. DOE offices, facilities, and property protection areas (PPAs) must meet or exceed General Services Administration (GSA) minimum security standards. (g) Security countermeasures for explosive threats must address a range of activities including hand-carried, mailed, and vehicle-transported devices.

Section 12

d. Graded Protection. The Department recognizes that risks must be accepted (i.e., that actions cannot be taken to reduce the potential for or consequences of all malevolent events to zero); however, an acceptable level of risk must be determined based on evaluation of a variety of facility-specific goals and considerations. By a graded approach, the Department intends that the highest level of protection be given to security interests and activities whose loss, theft, compromise, and/or unauthorized use would seriously affect the national security, the environment, Departmental programs, and/or the health and safety of the CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section A 3 public or employees. Protection of other interests and activities must be graded accordingly. e. Risk Management. S&S programs must be based on the results of vulnerability and risk assessments, the results of which are used to design and provide graded protection in accordance with an asset’s importance or the impact of its loss, destruction, or misuse. The results of the assessments, to include the determination of system effectiveness, are one of the key considerations the manager must evaluate when establishing the level of risk. For example, if it is determined that there is high risk that is not being mitigated by compensatory measures, reporting must be made to the Secretary of Energy or the Deputy Secretary who can accept high risk. Cognizant Under Secretaries can accept moderate risk. (1) Vulnerability and risk assessments must be conducted and documented to support the identification of risks to be accepted by the Department. (2) To determine the appropriate level of protection against risk, line management must consider the threat, the vulnerability of the potential target, and the potential consequences of an adversarial act. f. Site-Specific Programs. (1) S&S programs must address site-specific characteristics. (2) Performance assurance programs must be developed, managed, and implemented to ensure that S&S programs and protection program elements protect security interests and activities. (3) A management and planning process to achieve integrated, site-specific protection from unauthorized actions must be implemented. This process must be based on a graded approach that implements the integrated concepts of deterrence, prevention, detection, and response. (4) The DBT must be used as the basis for planning protection programs. 3. PLANNING. a. S&S Plans. S&S plans must be developed for facilities with any of the following S&S interests: (1) Category I quantities of SNM or credible roll-up quantities of SNM to a Category I quantity; (2) Category II, Category III, or Category IV SNM; (3) radiological, chemical, or biological sabotage threats; CANCELE D DOE M 470.4-1 08-26XX-05 Part 1, Section A 4 (4) critical mission disruption threats; (5) intra-/inter-site transportation of SNM; (6) classified information or matter; (7) facilities engaged in the protection of government property; (8) facilities that the Secretary, Deputy Secretary, or Under Secretaries deem appropriate. b. Site Safeguards and Security Plan (SSSP). The SSSP is a 5-year master planning document that must be prepared for sites with facilities described in paragraphs 3.a. (1), (3), (4), or (8), above. The SSSP must depict the existing condition of site protection programs and, when the DBT performance standard cannot be met, establish improvement priorities and resource requirements for the necessary improvements. Plan composition is reflected in Part 1, Section C, 5.

Section 13

c. Site Security Plan (SSP). At locations where an SSSP is not required because of the limited scope of interests (i.e., criteria contained in 3.a. (2), (5), (6), or (7) above, apply), an SSP must be developed to describe the protection program. SSPs must be approved by the local DOE cognizant security authority. In addition, specialized plans must be developed to address protection programs for other protection operations. Requirements for specialized plans that may or may not be components of the SSP are set forth in the applicable DOE directives. d. Planning Inputs. The documents listed below must be used to support program forecasts and information input used in the protection program planning process. (1) Applicable Departmental directives, guidance, and intelligence assessment information developed and disseminated by line management or the Office of Security. (2) Programmatic guidance and forecasts of significant changes planned in site operations as communicated through line management. (3) Current and projected operational constraints and resources. (4) Analysis of cost and effectiveness of security technologies versus traditional protection methodologies. e. Plan Review and Approval. (1) The SSSP requires approval by DOE line management and concurrence by the cognizant Head of the Departmental Element (see Attachment 1). Such approval authority must be formally delegated to line management. CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section A 5 (a) Copies of approved SSSPs must be provided to the Office of Security for review and comment. (b) Other security plans may be approved as stipulated in the applicable directive. If approving authority is not otherwise stipulated, these security plans may be approved by DOE line management. (2) The SSSP must be submitted to DOE line management within 150 days of the termination date of data collection and approved within 120 days of the submittal date. Directive changes, facility reconfiguration, a new VA, or other activities that occur after the stated effective date will not be considered for purposes of reviewing/approving the plan. (3) The SSSP must be reviewed annually (at least every 12 months). Updates to the SSSP that may significantly alter the agreed-upon protection philosophy or performance standards of protection systems must be subjected to the formal VA process, and if changes are shown to significantly alter system effectiveness performance, the update(s) will be subject to the same concurrence and approval as stated in paragraph (1), above. (4) An information copy of approved modifications must be provided to the Office of Security. CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section A Appendix 1-1 SECTION A APPENDIX 1 – SAFEGUARDS & SECURITY MANAGEMENT PLAN The Safeguards and Security (S&S) Management Plan provides a description of the implementation of S&S policy and provides detailed information on the assignment of roles, responsibilities, and authorities, as well as the development of budgets and allocation of resources. The following outline delineates the content requirements and provides a suggested format. 1. EXECUTIVE SUMMARY. a. Program Mission Statement. Briefly describe the program mission and how the mission relates to national security. Describe the major elements or activities performed in terms of program mission and its relationship to the DOE national security mission.

Section 14

b. S&S Program Structure. Briefly describe the strategy and organizational elements used to implement the S&S program under their cognizance. c. Management and Planning Assumptions. Briefly describe those assumptions that affect the management and planning of the implementation of the S&S program. These assumptions should include items such as: (1) future of the program (mission, staffing levels, site status, etc.); (2) current and planned S&S projects; and (3) status of the organization’s S&S budget. 2. PART 1 - ORGANIZATIONAL STRUCTURE AND ACCOUNTABILITY a. Line Management Organization. Describe the structure and relationship of line management. Identify the roles, responsibilities, and authorities of these line management elements to include organizational charts. b. Cognizant Security Authority Organization. Describe the structure of line management that is specifically responsible for implementing the Departmental element’s S&S program. Identify the individuals and positions responsible for committing resources and directing the activities of personnel associated with the S&S program. (1) Headquarters Organizational Structure. For the Headquarters elements, provide an organizational chart to show the S&S organization and management structure and the lines of authority and points of interface with other programs which affect S&S (e.g., safety, facility operations, and the cognizant security authority’s material control and accountability CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section A Appendix 1-2 (MC&A) organization, if independent of the security organization). Describe the functions and responsibilities of S&S personnel and indicate how S&S activities are integrated with those of other facility organizations; include organizational responsibilities for line management overseeing the program as well as the interface points with the respective Departmental element. (2) Field Organizational Structure. For the Field elements, provide an organizational chart to show the S&S organization and management structure and the lines of authority and points of interface with other programs which affect S&S (e.g., safety, facility operations, and the cognizant security authorities’ MC&A organization, if independent of the security organization). Describe the functions and responsibilities of S&S personnel and indicate how S&S activities are integrated with those of other facility organizations; include organizational responsibilities for line management overseeing the program as well as the interface points with the respective Departmental element. c. Contractor Sites. Provide the contract name, number, and other information that describes the authority under which the contractor executes management functions for facilities under the cognizance of a Departmental element. Identify the site contractor elements responsible for S&S programs and describe their S&S activities. Provide Federal and contractor organization charts and identify key positions and the relationships between the organizations responsible for S&S activities. Describe Federal and contractor involvement in the development of S&S resource requirements. 3. PART 2 - ROLES, RESPONSIBILITIES, DELEGATIONS, AND AUTHORITIES. Delegations must be documented in writing and delineate all assigned S&S roles, responsibilities, and authorities for the S&S program. This section: a. documents offices/positions affected by the S&S Management Plan;

Section 15

b. establishes the approval chain for S&S plans, procedures and implementation policy; c. establishes the approval chain for S&S policy deviations; d. assigns reporting requirements for incidents of security concern; and e. provides a list of roles and responsibilities for key positions and the delegated authorities for each. 4. PART 3 – S&S PROGRAM IMPLEMENTATION. This section of the S&S Management Plan documents the processes and methods used to implement the Department’s security policies. This section identifies: CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section A Appendix 1-3 a. the methods used for ensuring all applicable programmatic requirements are implemented throughout the organizational element; b. the methods used for ensuring effective integration of S&S programmatic elements; and c. SSSPs and SSPs used to implement S&S policy requirements. 5. PART 4 - PLANNING AND BUDGET (INCLUDING PERSONNEL RESOURCES). This section of the S&S Management Plan documents the key processes of planning and budgeting, including strategic planning, budget formulation, budget execution, and program evaluation. a. Describe the strategic planning assumptions used to ensure the S&S program will meet mission objectives. b. Provide a 5-year plan that describes the budget formulation priorities for future S&S resources and programs. c. Provide the current year plan for executing the S&S budget. This plan details the allocation of resources that support S&S functions and missions. d. Provide a program evaluation plan that details how the cognizant security authority will assess the implementation of the S&S program and the organization’s progress toward meeting established missions/goals. The program evaluation plan must cover both the Federal and contractor elements of the Departmental element. This plan can be used to support award fee decisions by the Departmental element. e. Briefly describe any changes to operational requirements which affect S&S program operations or would require increments or decrements to operational accounts (e.g., program direction, operational support, etc.). CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section B 1 SECTION B - SECURITY CONDITIONS 1. OBJECTIVE. To ensure that the Department uniformly meets the requirements of the Homeland Security Advisory System outlined in Homeland Security Presidential Directive-3, (HSPD-3), dated 3-11-02, and provides the responses specified in Presidential Decision Directive 39, U.S. Policy on Counterterrorism (U), dated 6-21-95. 2. THREAT INDICATORS. While the Design Basis Threat (DBT) provides specific description of threats that all components of the safeguards and security (S&S) system must be capable of defeating, analysis of terrorism should be an ongoing process. Although each analysis relies on information included in previous assessments, judgments with respect to threats to Federal and Department of Energy (DOE)-affiliated personnel, facilities, and assets begin anew with each analysis.

Section 16

a. Homeland Security Threat Conditions (known in DOE as Security Conditions [SECONs]) are established based on the analysis of a continuous and timely flow of integrated all-source threat assessments and reporting provided to Executive Branch decision-makers. A threat indicator is a condition that, when present, increases the possibility of a terrorist incident. Seldom does one single indicator suggest that the threat is imminent, but, when a number of indicators are present, the level of concern should increase correspondingly. A decision on assigning SECONs must integrate a variety of considerations. This integration will rely on qualitative assessment, not quantitative calculation. Higher SECONs indicate greater risk of a terrorist act, with risk including both probability and gravity. Despite best efforts, there can be no guarantee that, at any given SECON, a terrorist attack will not occur. An initial and important factor is the quality of the threat information itself. The evaluation of this threat information includes, but is not limited to, the following factors. (1) To what degree is the threat information credible? (2) To what degree is the threat information corroborated? (3) To what degree is the threat specific and/or imminent? (4) How grave are the potential consequences of the threat? b. Local and site-specific threat analysis is a dynamic process because the threat and the countermeasures used to combat the threat are constantly changing. To keep up with possible changes in the threat, security professionals should develop a predetermined list of general and specific threat indicators. Threat indicators should be revised according to site/facility situations and needs. They should be reviewed at least every 6 months or when a significant incident or change in conditions indicates that the threat level is increasing or decreasing. Examples of threat indicators that can be used to develop a site/facility-specific assessment are listed below. (1) International incidents or indicators against U.S. interests, personnel, or CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section B 2 facilities. (2) Domestic incidents or indicators against Federal or State interests countrywide. (3) Local incidents or indicators directed against Federal or DOE interests. (4) Specific targeting of DOE personnel, facilities, or materials. 3. SECURITY CONDITIONS. The DOE SECON system has been aligned with the Homeland Security Advisory System. a. The DOE SECON system describes a progressive level of common sense protective measures that may be implemented in response to a malevolent or terrorist threat to any or all DOE facilities, assets, and personnel. The purpose of the SECON system is to establish standardized protective measures for a wide range of threats and to help disseminate appropriate, timely, and standardized information for the coordination and support of DOE crisis or contingency activities. Once a SECON level is declared, the associated protective measures should be implemented as soon as possible to the extent they apply to the individual site or facility. Cognizant security authorities must coordinate SECON status through their DOE points of contact, as appropriate, and notify the DOE Headquarters (HQ) Operations Center (OC) and Departmental element of the site/facility SECON status. Measures associated with each SECON are not prioritized but should be initiated concurrently when practical.

Section 17

b. National Nuclear Security Administration (NNSA) facilities must be prepared to respond to SECON directives provided by the Under Secretary for Nuclear Security/Administrator, NNSA. Non-NNSA facilities must be prepared to respond to SECON directives provided by the Under Secretary for Energy, Science and Environment for their individual facilities. Headquarters facilities must be prepared to respond to SECON directives provided by the Director, Office of Security. At their discretion, DOE line management may increase protection measures for facilities under their cognizance if they determine that the local threat situation warrants additional security. In this event, the DOE HQ OC and Departmental element must be notified of the SECON level. If DOE line management or Departmental elements believe that their facilities’ SECON levels should be less than those issued by the Under Secretary for Energy, Science and Environment or the Under Secretary for Nuclear Security/Administrator, NNSA, a request for exception must be submitted for consideration (see paragraph 3.c., below). c. Any departure from the requirements of this section must be considered an exception which must be approved in accordance with the requirements set forth in Section M. No exception is permitted to the protective measures when under SECON 1, Severe Condition (Red). CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section B 3 d. To the extent possible throughout each increase or decrease in SECON, the cognizant security authority must: (1) keep employees informed; (2) coordinate when appropriate with State and local officials’ actions taken regarding security and emergency planning; and (3) at each level of SECON, review security plans, vulnerability assessments (VAs), emergency response procedures, public affairs guidance and plans, legal authorities, and Continuity of Operations Plans. e. A record of specific actions taken for each measure must be maintained. A description of each SECON, including the necessary circumstances for implementing, the impact on operations, and the purpose of each protective posture, is outlined below. (1) SECON 5, LOW CONDITION (GREEN). This condition is declared when there is a low risk of terrorist attacks. SECON 5, Low Condition (Green) exists when a general threat of possible malevolent or terrorist activity exists, but warrants only a routine security posture. (2) SECON 4, GUARDED CONDITION (BLUE). This condition is declared when there is a general risk of terrorist attacks. SECON 4, Guarded Condition (Blue) applies when there is an increased general threat of possible malevolent or terrorist activity against personnel and facilities, the nature and extent of which are unpredictable, and circumstances do not justify full implementation of SECON 3, Elevated Condition (Yellow) measures. It may be necessary, however, to implement certain selected measures from higher SECONs to address intelligence received or to act as a deterrent. All measures selected for use under SECON 4, Guarded Condition (Blue) must be capable of being maintained indefinitely. (a) Measure 1. At regular intervals, warn all personnel to report the following to security: 1 suspicious personnel, particularly those carrying suitcases or other containers, or those observing, photographing, or asking questions about site operations or security measures; 2 unidentified vehicles parked or operated in a suspicious manner on or in the vicinity of the site or near site facilities;

Section 18

3 abandoned parcels or suitcases; and CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section B 4 4 any other activity considered suspicious. (b) Measure 2. 1 Ensure that security personnel have immediate access to building floor plans and emergency/evacuation plans for all site facilities. 2 Ensure that security personnel are able to seal off an area immediately. 3 Ensure that key personnel required to implement security plans are on-call and readily available. 4 Maintain the site Emergency Management Team (EMT) on 2-hour recall. 5 Expand Operations Security measures. 6 Exercise bomb threat procedures. (c) Measure 3. Secure and seal buildings, rooms, and storage areas not in regular use. Maintain a list of secured facilities. (d) Measure 4. Increase unannounced security spot checks (inspection of personal identification; vehicle registration; and the contents of vehicles, suitcases, briefcases, and other containers) at access points for the site and facilities. (e) Measure 5. Reduce the number of access points for vehicles and personnel to minimum levels consistent with the requirement to maintain a reasonable flow of traffic. (f) Measure 6. As a deterrent, randomly apply measures 14, 15, 16, 17, or 18 from SECON 3, Elevated Condition (Yellow) either individually or in combination. (g) Measure 7. Review all operations plans, personnel details, and logistics requirements that pertain to implementing higher SECONs. (h) Measure 8. Review security measures for critical/sensitive personnel (e.g., directors, managers, members of special access/ security programs, etc.) and implement additional measures warranted by the threat and existing vulnerabilities (e.g., identified personnel should alter established patterns of behavior when traveling in public areas). CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section B 5 (i) Measure 9. Increase liaison with local law enforcement, intelligence community, security agencies, and the Federal Bureau of Investigation, (FBI) to monitor the threat to site personnel and facilities. Notify local law enforcement agencies and the FBI concerning SECON 3, Elevated Condition (Yellow) measures that, if implemented, could affect their operations in the local community. (j) Measure 10. Reserve for site/facility use. (3) SECON 3, ELEVATED CONDITION (YELLOW). A SECON 3, Elevated Condition (Yellow) is declared when there is a significant risk of terrorist attack. Elevated Condition (Yellow) applies when an increased and more predictable threat of malevolent or terrorist activity exists. The measures in this SECON must be capable of being maintained for lengthy periods without causing undue hardship, affecting operational capability, or aggravating relations with the local community. For measures requiring an increase in the frequency of a specific action, the new frequency is to be more often than in the lower-level security condition. In addition to the measures required by SECON 4, Guarded Condition (Blue), the following measures should be implemented. (a) Measure 11. Increase the frequency of warnings required by Measure 1 and inform personnel of additional unclassified threat information, if available. Encourage increased community security awareness of suspicious persons, vehicles, and activities. (b) Measure 12. Maintain EMT personnel on 2-hour recall; periodically exercise recall to ensure readiness. Keep all other personnel involved in implementing special response/contingency plans on call. Identify, contact, and brief specialists that may be required for unique contingencies; coordinate lines of communication.

Section 19

(c) Measure 13. Review provisions of all operations plans and orders and special operating procedures associated with implementing SECON 2, High Condition (Orange). (d) Measure 14. Move automobiles and objects such as trash containers, newspaper boxes, crates, etc., at least 30 yards from all facilities, particularly buildings of a sensitive or prestigious nature. Identify any areas where an improvised explosive device could be hidden (i.e., pallet stacks, trash piles, stacked construction supplies, etc.). If the configuration of the facility or area precludes implementation of this measure, take appropriate compensatory measures per local plans (frequent inspection by Explosive Ordnance Disposal [EOD] teams, if available, controlled access to CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section B 6 parking areas, etc.). Consider centralized parking. (e) Measure 15. Secure, seal, and regularly inspect all buildings, rooms, and storage areas that can be isolated with minimum site impact. (f) Measure 16. At the beginning and end of each work day and at frequent intervals, inspect the interior and exterior of buildings in regular use for suspicious activity or unattended packages and for signs of tampering or indications of unauthorized entry. (g) Measure 17. Implement screening procedures for all incoming official mail to identify possible explosive or incendiary devices or other dangerous material. If available, have EOD-trained teams inspect suspicious items and screen mail periodically. Provide guidance concerning suspicious packages. Encourage employees to inspect their individual mail, report suspicious items to security, and refrain from handling such items until cleared by the appropriate authority. (h) Measure 18. Inspect other deliveries and locally designated common-use facilities to identify explosives and incendiary, biological, or chemical devices. Use EOD-trained teams for some screening inspections when available. Instruct site personnel to report suspicious packages to security and refrain from handling them until cleared by the appropriate authority. (i) Measure 19. Increase both overt and covert security force surveillance of locally designated soft targets to improve deterrence and build confidence among site personnel. (Covert surveillance must comply with DOE directives and appropriate regulatory restrictions.) (j) Measure 20. Inform employees of the general threat situation. Limit visitors and escorted uncleared personnel. Periodically update all personnel as the situation changes to stop rumors and prevent unnecessary alarm. (k) Measure 21. Brief representatives of all activities on the site concerning the threat and security measures implemented in response to the threat. Explain reasons for actions. Implement procedures to provide periodic updates for these activity representatives. (l) Measure 22. Verify the identity of all personnel entering property protection areas (PPAs) and other sensitive activities specified in local plans (i.e., inspect identification badges and grant access CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section B 7 based on visual recognition). Use of automated access control systems at interior security areas is acceptable and encouraged, where practical. On a random basis, visually inspect the interior of all vehicles and the exterior of all suitcases, briefcases, packages, and other containers. Increase the frequency of detailed vehicle inspections (trunk, undercarriage, glove boxes, etc.) and the frequency of detailed inspections of suitcases, briefcases, and other containers.

Section 20

(m) Measure 23. Increase the frequency of random identity checks (inspection of security badges and vehicle registration documents) conducted by security force patrols on the site. (n) Measure 24. Remind all personnel to lock parked vehicles and inspect vehicles for suspicious items before entering and driving them. (o) Measure 25. Implement additional security measures for critical/sensitive personnel in accordance with existing plans. (p) Measure 26. Brief all security force personnel concerning the threat and policies governing rules of engagement, use of deadly force, and fresh pursuit. Ensure there is no misunderstanding of these instructions. Repeat this briefing on a periodic basis. (q) Measure 27. Increase liaison with local police, intelligence, security agencies, and the FBI to monitor the threat to site personnel and facilities. Notify local police agencies concerning SECON 2, High Condition (Orange) or SECON 1, Severe Condition (Red) measures that, if implemented, could affect their operations in the local community. (r) Measure 28. Survey the surrounding area to determine whether operational activities near the area might create emergencies or contingencies that could affect the site/facility (e.g., airports, military/other government facilities, industrial facilities, railroads or pipelines, etc.). (s) Measure 29. Reserve for site/facility use. (4) SECON 2, HIGH CONDITION (ORANGE). A SECON 2, High Condition (Orange) is declared when there is a high risk of terrorist attacks. This condition applies when an incident occurs or intelligence is received indicating that some form of malevolent or terrorist action against personnel and facilities is imminent. Implementation of measures in this security condition for more than a short period probably will create CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section B 8 hardship and affect the routine activities of the site and its personnel. For measures requiring an increase in the frequency of a specific action, the new frequency is to be more often than in the lower level SECON. The following measures should be implemented. (a) Measure 30. Continue all SECON 4, Guarded Condition (Blue) and SECON 3, Elevated Condition (Yellow) measures or introduce those that have not already been implemented. (b) Measure 31. Recall staff representatives and initiate 24-hour operation of the EMT. Place the Special Response Team (SRT) on standby alert. Keep all personnel responsible for implementing special/response contingency plans at their places of duty. Review site evacuation plans. (c) Measure 32. Reduce site access points to the absolute minimum necessary for continued operation. (d) Measure 33. Verify the identity of all personnel entering the site/facilities, including appropriate offsite facilities under DOE control. Inspect all security badges for tampering. On a random basis, visually inspect the interior of all vehicles and the exterior of all suitcases, briefcases, and other containers. Increase the frequency of detailed vehicle inspections (trunk, undercarriage, glove compartments, etc.) and the frequency of inspections of suitcases, briefcases, and other containers. (e) Measure 34. Implement centralized parking and shuttle bus service, where required.

Section 21

(f) Measure 35. Ensure that security personnel have been briefed concerning policies governing the rules of engagement, use of force, and fresh pursuit, particularly criteria for use of deadly force. Ensure that non-security supervisory personnel are familiar with above policies and procedures, if applicable. Ensure that special equipment and ammunition are available for immediate issue. (g) Measure 36. Increase security patrol activity to the maximum level sustainable. The concept of continuing random security patrol activity is encouraged. (h) Measure 37. Position security force personnel in the vicinity of critical facilities. (i) Measure 38. Erect barriers required to control direction of traffic flow and to protect facilities vulnerable to bomb attack by parked CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section B 9 or moving vehicles. (j) Measure 39. Consult local authorities about closing public roads and facilities that might make sites more vulnerable to terrorist attacks. (k) Measure 40. Consider canceling public events. (l) Measure 41. Consider initiating Continuity of Operations plans (m) Measure 42. Reserve for site/facility use. (5) SECON 1, SEVERE CONDITION (RED). A SECON 1, Severe Condition (Red) reflects a severe risk of terrorist attacks. This condition applies in the immediate area where a malevolent or terrorist attack has occurred that may affect the site or when an attack is initiated on the site. Implementing SECON 1, Severe Condition (Red) will create hardship and affect the activities of the site and its personnel. Normally, this SECON is declared as a localized response. For measures requiring an increase in the frequency of a specific action, the new frequency is to be more often than in the lower-level SECON. The following measures should be implemented. (a) Measure 43. Continue all previous SECON measures and introduce those that have not already been implemented. (b) Measure 44. Augment security forces to ensure absolute control over access to the site, facilities, and other potential target areas. Establish surveillance points; use night-vision devices. (c) Measure 45. Working closely with facility management, identify the owners of all vehicles already on the site. In those cases where the presence of a vehicle cannot be explained (owner is not present and the vehicle has no obvious site affiliation), inspect the vehicle for explosives; incendiary, chemical, or biological devices; or other dangerous items and remove the vehicle from the vicinity of facilities, soft targets, and other sensitive areas as soon as possible. (d) Measure 46. Inspect all vehicles entering the site. Inspections should include cargo storage areas, undercarriage, glove boxes, and other areas where explosives, incendiary, chemical, or biological devices or other dangerous items could be concealed. (e) Measure 47. Limit access to the site, facilities, and other areas to those personnel with a legitimate and verifiable need to enter. Implement positive identification of all personnel. No exceptions. CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section B 10 (f) Measure 48. Inspect all baggage such as suitcases, packages, and briefcases brought on the site for explosives, incendiary, chemical, or biological devices, or other dangerous items. (g) Measure 49. Implement frequent inspections of the exterior of buildings (including roof areas) and parking areas. Conduct inspections at facilities and in the vicinity of soft targets.

Section 22

(h) Measure 50. Coordinate with the Operations Division/Center to establish communications, responsibilities, and authorities before, during, and after attack. (i) Measure 51. Request that local authorities close those public roads and facilities in the vicinity of the site/facilities that might facilitate execution of a malevolent or terrorist attack. (j) Measure 52. Cancel public events. (k) Measure 53. Execute Continuity of Operations plans. (l) Measure 54. Reserve for site/facility use. CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section C 1 SECTION C - SITE SAFEGUARDS AND SECURITY PLANS 1. OBJECTIVE. The Site Safeguards and Security Plan (SSSP) is a risk management document that provides summary information used to describe safeguards and security (S&S) programs and vulnerability and risk assessments at applicable sites. The objective of this section is to delineate SSSP content and establish a standard approach to presenting site protection information and vulnerability assessment (VA) results. The results and conclusions contained in the plan are intended to guide long-term planning for site S&S operations. This is accomplished during plan development by identifying: key site protection elements; annually (at least every 12 months) evaluating site protection in terms of its adequacy to meet continued mission and threat parameters; and, identifying resource requirements. 2. APPLICATION. The SSSP is used to evaluate site and facility program elements and resources as they relate to identified threats and risks. The protection measures identified in approved SSSPs become the basis for executing and reviewing site protection programs. 3. SCOPE. The approved SSSP provides assurance that S&S measures address identified threats and risks. To provide this assurance, the plan must reiterate the assumptions identified to, and agreed upon, by line management. These assumptions must include reference to the contract under which the site is operated and those contractual issues that may impact S&S, applicable Department of Energy (DOE) directives, the threat upon which VAs are based, the methodology used to conduct VAs, deviations and proposed deviations, and any unique S&S impacting issues and assumptions that were addressed, and agreed to, by the responsible parties. 4. PURPOSE. The SSSP describes the graded protection of DOE assets required to be implemented by line management. The SSSP identifies site risks, cost-benefit analyses, and comparison of proposed upgrades. The resource plan (RP) must identify near- and long-term resource requirements needed to ensure the integrity of existing and planned S&S upgrades. The annual (at least every 12 months) review serves as the basis for tracking the implementation of protection measures and strategies necessary to maintain system effectiveness and identifies unfunded requirements. 5. PLAN COMPOSITION. The SSSP includes: a. references to implementing documents and evidence files; b. descriptions of site protection strategies, key site S&S programs, approved and pending deviations, plans and procedures designed to implement, manage and maintain S&S programs; c. system effectiveness determinations for the protection of special nuclear material (SNM), prevention or mitigation of sabotage events, and prevention and/or timely detection of the loss of classified information or matter based on the status of CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section C 2

Section 23

performance indicators, such as results of VAs, performance tests, surveys, inspections, and evaluations of personnel qualifications and training; d. proposed S&S program upgrades; e. VAs results that support conclusions reported in the SSSP; f. assumptions used as part of the VA process; g. threat parameters used for VAs that are described in the current Design Basis Threat (DBT), regional threat assessments, and impacts made by local area threat assessments, if applicable; h. the details of the changes in the protection through the spectrum of Security Conditions (SECON) (1-5), to include effects on the calculated baseline system effectiveness; i. a description of the evidence files containing material that supports the VAs; and j. an RP that describes S&S upgrades programmed for completion, upgrades being introduced as a result of planned and unplanned site changes impacting the protection program or deficiencies identified as a result of the annual (at least every 12 months) review of the SSSP, a description of the funding source to implement the upgrades, and unfunded requirements. 6. EVIDENCE FILES. Supporting documentation that validates data/information used in the VA process and in other protection program planning presented in the plan and that may require corroboration must be available in evidence files. Evidence files must be maintained to provide VA process and other protection program planning documentation in a logical and readily retrievable form to validate assumptions, modeling input data, test results, and other data that may be used to support protection system design or conclusions regarding protection effectiveness. 7. DATA COLLECTION. The effective date (snapshot in time) of the data contained in the SSSP must be specified. 8. FORMAT. Information provided in the SSSP should be brief, accurate, and concise. Implementing plans and procedures should be referenced in the plan where appropriate. A brief overview of a plan or procedure is adequate. Duplication of information should be avoided. Information already included in other sections of the plan may be referenced or summarized for clarity. A cover letter must be attached to the plan indicating that the plan has been reviewed, risks acknowledged and accepted (if appropriate), and signed by line management. For example, the SSSP should be approved by the Head of Field Element and submitted for concurrence to the Departmental element. If high or marginal risk acceptance is needed, the correspondence must be routed for signature to the Secretary or Deputy Secretary or CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section C 3 Under Secretaries, respectively. The use of charts, plats, graphs, drawings, videos, photographs, and matrixes is encouraged wherever appropriate to clarify or satisfy the intent of plan objectives. References to sources of information and the location of supporting documentation should be provided to assist in verifying information contained in the plan. The SSSP is divided into 12 chapters. Each chapter provides specific information relevant to site security. Use of this layout will ensure a uniform SSSP for review and comment or during an emergency. a. Chapter 1, Site Description and Mission. (1) Site Mission Statement. Describe the site mission and how the mission relates to national security and the health and safety of the public, employees, and the environment. Describe the major programs or activities performed at the site in terms of mission and their relationship to the DOE national security mission.

Section 24

(2) Site Description and Area Layout. Describe the physical and geographical area in which the site and the S&S program are located. Provide a map, photograph, or drawing of the site that identifies locations of Category I facilities, facilities with a credible roll-up of SNM to a Category I quantity, the central alarm station (CAS) and secondary alarm stations (SAS), security-related communications facilities, and other facilities of security interest. Show the location of barriers defining the site Protected Area (PA). A small-scale map or drawing should be used to show the relationship of the site to the surrounding area and be of sufficient detail to orient the user. (3) Management Organization, Planning Assumptions and Evidence File. (a) Site Management Organizations. Identify the contract name, number, and other information that describes the authority under which the contractor executes management functions. Identify site contractors responsible for S&S programs and describe their S&S activities. Provide Federal and contractor organization charts and identify key positions and the relationships between the organizations for S&S activities. Provide a list of roles and responsibilities for key positions. Describe Federal and contractor involvement in the development of S&S resource requirements. (b) Management and Planning Assumptions. Describe those assumptions that were addressed and agreed to during the SSSP scoping, preparation, or other SSSP management-related meetings. CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section C 4 Describe all relevant S&S-related planning assumptions that were formerly agreed to and included in a Memorandum of Agreement (MOA) by the responsible organization representatives who are party to the development and review of the SSSP. These assumptions should address the following issues: 1 site SECON; 2 VA methodology used for insider, neutralization, outsider, and collusion analyses; 3 identified credible targets; 4 protection strategies; 5 approved compensatory measures; and 6 performance testing conducted or to be conducted. (c) Evidence Files. Describe and identify the contents, location, and control mechanisms for the SSSP evidence files. Reference approved standard operating procedures (SOPs) as applicable. Supporting documentation that validates data/information used in the VA process should not be included in the SSSP. However, this data/documentation should be available in a logical and readily retrievable arrangement in evidence files, for use in review and validation of the SSSP. b. Chapter 2, Site Threat Description and Target Identification. (1) Threat Description. Establish a graded approach to protection for Category I SNM and SNM facilities with credible roll-up of SNM to a Category I quantity, and facilities having radiological, biological, or chemical, sabotage event potential and facilities having disruption of critical mission sabotage event potential. Use the DBT as the baseline for threat determination, along with higher levels of threat dictated by local and regional threats (when available), and describe the site-specific threats used as the basis for conducting VAs and for which the protection program is designed. (2) Target Identification. Identify, describe, and prioritize targets of security interest that meet the following criteria. (a) Category I quantities of SNM and the facilities with credible roll- up of SNM to a Category I quantity.

Section 25

(b) A radiological, biological or chemical sabotage inventory that, if released, would cause an unacceptable impact on national security CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section C 5 or the health and safety of employees, the public, or the environment. (c) Critical national security facilities, and assets (as defined in the DBT), designated by the Department (e.g., or each disruption of critical mission target) that would impact DOE programs supporting national defense and security. (d) Those facilities possessing automated information systems that process or contain Sensitive Compartmented Information (SCI), Special Access Program (SAP), weapon data classified Secret Restricted Data (S/RD) Sigma 1, 2, 14 and 15 or higher. (e) Temporary recurring targets. When predictable programmatic operations can reasonably be expected to present temporary SNM, sabotage, or information targets such as those permanent locations previously described, these targets must be described and analyzed at the same level of detail and in the same manner as permanent locations. Provide a brief introductory description of the targets and a chart or list, such as shown below, that indicates the type of target, its location, attractiveness level, size, and configuration. Include SNM theft/diversion targets, radiological, biological, and chemical targets, and disruption of critical mission targets, and those facilities possessing automated information systems that process SCI, SAP, weapon data classified S/RD Sigma 1, 2, 14 and 15 or higher. (3) Theft or Diversion of SNM. Describe how Category I SNM targets and SNM facilities that roll-up to a credible Category I quantity have been identified and evaluated as potential abrupt theft targets. Also, describe how these SNM targets have been identified and assessed for protracted theft (diversion), if applicable. For each identified SNM target, provide a description of the following, using a table similar to Table C-1, SNM Theft/Diversion Targets: physical location of identified SNM; the type of material, as described under the several material listings in DOE M 470.4-6, Nuclear Material Control and Accountability, such as pure products, high-grade material, weapons, including pits, ingots, oxide fuel elements, etc.; and the Category (I through II) and attractiveness level (A through C) of the target material. CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section C 6 Table C-1. SNM Theft/Diversion Targets Location SNM Type Category/ Attractiveness Level Goal Quantity/ Portability Bldg. 1, Vault Pu-239 ingots Cat. I/B 2 ingots/ man portable Bldg. 1, Assay Room Pu-239 ingots Cat. I/B 2 ingots/ man- portable Bldg. 1, Fabrication Room Pu-238 oxide powder Cat. II/D 2 canisters/ man- portable Bldg. 2 U-235 fuel elements Cat. II, roll-up to Cat. I/C 20 fuel element/ not man portable Bldg. 3 U-235 fuel elements Cat. II, roll-up to Cat. I/C 20 fuel element/ not man- portable (4) Radiological Sabotage. Indicate the process or methodology used to identify and evaluate radiological sabotage targets. For each identified radiological sabotage target, provide a description using a table similar to Table C-2, Radiological Sabotage Targets, of the following: the physical location of all identified targets; the type of material; the maximum inventory level; and the material size and configuration. Table C-2. Radiological Sabotage Targets Location Material Type Maximum Inventory

Section 26

Material Size and Configuration Bldg. 1, Fabrication Room Pu-238 oxide powder 10 kg Paint Cans, at 50 g each Bldg. 4 H3 gas 10 kg Cylinders, at 500 g each (5) Biological or Chemical Sabotage. Describe the methodology used to evaluate biological or chemical targets. Using the criteria referenced in the DBT, determine the sabotage threat level (STL) for each location. Reference the plans and procedures that govern the biological or chemical sabotage assessment program. For each identified target type not addressed by the commercial equiva- lency protection program, provide a description of the following using a table similar to Table C-3, Biological/Chemical Sabotage Targets: the physical location of additional identified biological or chemical sabotage material targets; the type of material; the maximum inventory level; the material size and configuration; and, the exposure level at the near-site boundary (NSB) for maximum inventory release. CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section C 7 Table C-3. Biological/Chemical Sabotage Targets Location Material Type Maximum Inventory Material Size and Configuration Exposure Level at NSB Bldg. 5 Chlorine 10,000 lb 55-gal drums, at 350 lb each >ERPG III Levels (6) Disruption of Critical Mission Sabotage. Describe how potential dis- ruption of critical mission sabotage production and process components (machinery, equipment, flow process, power sources, ventilation, waste handling, etc.) have been identified and evaluated for inclusion as dis- ruption of critical mission targets. Ensure that the evaluation includes how the sabotage event would affect production (at the facility, on inter- site processes, and on overall national level inventory needs) and, if so, what areas, processes, and/or components within the facility affect those necessary production level capabilities and inventory needs. For each disruption of critical mission target, provide a description, using a chart similar to Table C-4, Disruption of Critical Mission Targets, of the following: the physical location of essential production components; the type of equipment, process, power sources or vital components; and the dollar value or production capability loss. Table C-4. Disruption of Critical Mission Targets Location Equipment Type Loss of DOE Mission Capability and Mission Impact Bldg. 1, Fabrication Room Fuel Fabrication Presses 100 percent loss of capability for 360 days with moderate mission impact Lab. A Laser Tunnel 100 percent loss of capability for 360 days with low mission impact (7) Intra-Site Transportation of SNM. Describe, in a brief narrative, the Category I SNM targets and credible Category II SNM targets that roll up to Category I quantity that are moved from one location to another on the site on a recurring basis. Using a chart, identify the type of SNM, attractiveness level, and size and configuration of the material. c. Chapter 3, Site Protection Strategies. Identify the protection strategies employed that address the overall protection program and enhance the concept of graded protection. Describe the protection program strategies employed. The basic strategies pertaining to protection are denial of access, denial of task, and containment that upon failure could evolve into recapture/recovery or pursuit CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section C 8

Section 27

strategies. Protection programs and tactical deployments designed to prevent unauthorized control of material and devices and to prevent acts of radiological, biological, chemical, and disruption of critical mission must be integrated with protection strategies. These activities could include protection layers of intrusion detection systems (IDS) and concentric security areas, access control measures, compartmentalization, insider protection programs, and procedural measures. The plan should clearly convey the strategy to be employed, and plan reviewers will anticipate that procedures are available to ensure implementation of these strategies. Display in a chart similar to Table C-5, Site-Wide Protection Strategies, the protection strategy used, the facility and target involved, and the title and responsible office for each plan or procedure. Ensure the information provided is consistent with that found in Chapter 2, Site Threat Description and Target Identification. Table C-5. Site-Wide Protection Strategies Protection Strategy Facility or Activity Target Type Implementing Plan or Procedure Responsible Office Denial of Access Facility ABC Cat. I: Pu metal oxide Cat. II: nitrate UF6 Plan ABC 1.3 Protective Force Manager Containment Vault storage Areas 301, 302 and 303 Weapon parts and Pu metallic buttons Plan ADC.1 Protective Force Manager Denial of Task SNM in transit Weapon parts Plan CFE 1.5 Protective Force Manager d. Chapter 4, Physical Protection Systems. (1) Summary of Physical Protection Systems Used for Category I and Credible Roll-up Quantities of SNM to a Category I Quantity, Sabotage, Classified Information or Matter, and Classified Automated Information Protection. Describe the physical protection systems for each facility that has Category I quantities of SNM, credible roll-up quantities of SNM to a Category I quantity, radiological, biological, chemical sabotage targets (including disruption of critical mission), and those facilities possessing automated information systems that process or contain SCI, SAP, weapon data classified S/RD Sigma 1, 2, 14 and 15, or higher. Provide a narrative description of the physical protection systems and how the systems are integrated at the site and facility level. Describe how the barriers are protected by an IDS, security lighting, protective force (PF), and assessment systems and how structures located in or on the barrier are protected so as not to degrade protective systems. CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section C 9 Following the narrative, complete a chart similar to Table C-6, Facility Protection Systems, that includes the following facility protection systems: security areas and their barriers, access controls (badge checks and contraband screening by the protective force, and automated card access for both interior and exterior); assessment (closed circuit television [CCTV] and/or protective forces both interior and exterior); security computer system integrator/ processor; CAS and SAS; CCTV cameras monitoring and switching systems; security lighting; electrical and back- up power sources (emergency batteries and/or generators); and communications. In the chart, list the major physical protection systems, the location of the systems, and a brief description of the type of equipment installed. Table C-6. Facility Protection Systems Protection System Equipment Description Location Responsible Office Exterior Intrusion Detection “H” Field

Section 28

Protected Area Perimeter Associated Areas Office of the Plant Engineer Exterior Assessment/ CCTV Microwave Taut Wire CCTV System Protected Area Perimeter Associated Areas Office of the Plant Engineer Interior Intrusion Detection Volumetric Infrared Motion Detectors All Material Access Areas Office of the Plant Engineer (2) Physical Protection Measures for Category I and Credible Roll-up Quantities of SNM to a Category I Quantity in Transit (Onsite). Describes the types, frequency, and protection measures used for the intra-site shipment of Category I SNM and credible roll-up quantities to a Category I quantity. Provide a narrative that describes the typical physical protection measures taken to ensure the integrity of those shipments from their point of loading, through transit, and at the off-load destination. If other materials are transported on site that would represent an STL 1 concern, provide a narrative that describes the typical physical protection measures from their point of loading, through transit, and at the off-load destination. e. Chapter 5, Site Protective Force. (1) Protective Force Mission, Organization, and Capabilities. Describe the PF organization and equipment deployed to perform 24-hour-per-day, site- wide protection. Confirm that the basis for PF organization and planning is based on the identified site threat. Provide a narrative summary of the PF mission(s), capabilities, and deployment concepts used for site protection. Indicate the availability of plans and procedures that address normal and emergency deployment. Describe the PF equipment used CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section C 10 including firearms, communications, vehicles, and any special items. Provide an organization chart of the PF, including response forces, showing the management and organization structure and key organizational interface positions with the cognizant security authorities and site operations and safety organizations. Using a schematic, display the PF communications network and include available secure networks and linkages to offsite law enforcement organizations with whom support agreements exist. In a chart, show the weapons and special equipment assigned to PF personnel, including members of the response force. (2) Qualifications and Training. Indicate that the qualifications and training of the PF conform to current policy requirements. In a chart similar to Table C-7, Qualifications and Training, list the titles and offices responsible for implementing and maintaining any plans or procedures that describe the following pertaining to the PF: qualifications for employment; the hiring process; initial, specialized and advanced training; and, other relevant written documentation, such as post and general orders.. Table C-7. Qualifications and Training Plan/Procedures Title Responsible Office Specialized Training Plan Training Department Tactical Response Plans Department (3) Special Response Teams (SRT) and Plans. Ensure the availability of SRTs and current response plans and procedures for implementing site- specific S&S program strategies and tactics for denial of access, denial of task, containment, recapture/recovery, pursuit and contingency operations, as described in current DOE policy. Indicate that requalification training and exercises are used to verify the effectiveness of SRTs. Identify and document agreements and MOUs with local, state, and Federal law enforcement agencies regarding requests for on-site support during a contingency event. Ensure that a VA was used to assist management in determining the equipment and deployment of SRTs. In a brief narrative, confirm the availability of personnel and response plans and procedures that provide assurance of adequate protection. Indicate that contingency plans and procedures are available to respond to the activities listed below.

Section 29

(a) Containment/denial of access/denial of task (includes a range of tactical options designed to either preclude adversary force access to nuclear weapons/materials or to deny unauthorized removal). (b) Recapture/recovery or pursuit operations (used when containment/ denial fail and could involve SRTs and other force options including the use of off-site law enforcement agencies). CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section C 11 Describe the organization, equipment, and training provided to SRTs and how training and performance testing are used to verify the effectiveness of SRT planning in the strategies described above. Describe the role of VA in determining SRT deployment, equipment, and training. In a chart similar to Table C-7, list tactical response plans and procedures and the office responsible for implementing and maintaining them. Use a similar chart to list memoranda or letters of understanding and other agreements with local, State, or Federal law enforcement agencies regarding requests for onsite support during a contingency event. f. Chapter 6, MC&A Program. Describe the MC&A management program and summarize the results of the MC&A VA and other MC&A program planning activities. Describe the mission of the site MC&A organization. Summarize current and planned nuclear materials processing and storage activities. Using an organization chart, show the MC&A organization and management structure and the lines of authority and points of interface with other S&S programs, facility operations, and the cognizant security authorities’ MC&A organization. Describe the functions and responsibilities of safeguards personnel and indicate how MC&A activities are integrated with those of site protection programs and other facility organizations; include organizational responsibilities for those program elements that support multiple S&S programs (e.g., portal monitors and access controls). Confirm that MC&A personnel complete required training. List, in a chart similar to Table C-8, MC&A Plans and Procedures, the facilities required to develop and maintain MC&A plans and procedures, the titles of those plans and procedures, and the office(s) responsible for approving and maintaining them. Table C-8. MC&A Plans and Procedures Facility Name Plan/Procedure Title Responsible Office(s) ABC Facility ABC Facility MC&A Plan, 1/1/99 S&S Director XYZ Facility XYZ Facility MC&A Plan, 6/9/99 S&S Director Give the name(s) and date(s) of reports of MC&A VAs and other planning exercises. Summarize the results of these assessment(s). Identify those components of the MC&A system that provide the greatest effectiveness against theft and diversion. Describe actions taken to remediate identified program deficiencies or to prepare for planned changes in facility nuclear materials processing and storage activities. CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section C 12

Section 30

g. Chapter 7, Site Personnel Security and Human Reliability Programs. Describes the site-wide program for personnel security that, in conjunction with information and physical security programs, ensures only authorized access to classified information or matter, or SNM and confirms that the personnel security program is in conformance with and implements the requirements prescribed in current DOE policy. Describe the key elements of the site-wide personnel security program for access authorizations and, if applicable, the key elements of the site’s Human Reliability Program (HRP). Describe the method(s) used at the site to ensure the appropriate level of access authorizations are issued for the category of material processed or stored at the site and for approving justification, processing, and reevaluating the need for such access authorizations. Indicate how the effectiveness of the program is assessed. Indicate the site procedures that require contractors to perform pre-hire checks to ensure proper qualifications and suitability of the applicant before submitting requests for access authorizations. Briefly describe the programs used to mitigate the effectiveness of potential “insider” activities and the application of these programs in addressing insider concerns. Provide an organization chart showing the location of the personnel security organization in relationship to the cognizant security authority and other contractor S&S organizations. Provide an organization chart identifying the designated HRP management official in relationship to the cognizant security authority and the designated HRP certifying official. Verify that the site has a current HRP implementation plan. List, in a chart similar to Table C-9, Personnel Security/Human Reliability Program Implementation, the titles of site-wide personnel security-related plans and procedures, the HRP implementation plan, if applicable, and the office(s) responsible for implementing and maintaining them. Table C-9. Personnel Security/Human Reliability Program Implementation Plan/Procedure Title Responsible Office XYZ Implementation Plan Security Department h. Chapter 8, Automated Information Security Program. Briefly describe the automated information systems for those facilities possessing automated information systems that process SCI, SAP, weapon data classified S/RD Sigma 1, 2, 14, and 15, or higher. Provide an organization chart showing the responsible automated information systems security program and its relationship to the cognizant security authority and contractor organizations. List, in a chart similar to Table C-10, Automated Information Systems Security Programs, the title of the automated information systems security program plans and procedures with the associated office responsible for implementing and maintaining the plan and procedures, the plans and procedures governing the automated information system VAs with the associated office responsible for implementing and maintaining the plan and procedures, and the reports containing the results of the VAs. CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section C 13 Table C-10. Automated Information Systems Security Programs Plan/Procedure/Report Title Responsible Office Date (if pertinent)

Section 31

i. Chapter 9, S&S Equipment Maintenance and Testing Programs. Describe maintenance and testing programs and life cycle planning, designed to enhance the continuous operability of S&S-related equipment used in the protection of Category I SNM (including areas with credible roll up of SNM to a Category I quantity), and classified automated information systems. Summarize in a narrative the maintenance and testing programs in use that ensure the availability and operability of S&S-related equipment and systems. Indicate the availability of compensatory measures/procedures that are used when equipment is taken out of service or otherwise not available. Describe how S&S maintenance and testing programs are incorporated into the Performance Assurance Program Plans. Indicate how the performance testing and other S&S site and facility maintenance programs comply with DOE policy. Describe the life cycle planning conducted for major S&S equipment and component replacement. Relate how this planning is used to support and validate S&S equipment budget requirements. List, in a chart similar to Table C-11, the maintenance, testing, and records management programs, the relevant plans and procedures that implement the programs, and the responsible office, as these programs apply to equipment used by the PF, security related systems, and equipment and instrumentation used for MC&A. Many of these may be addressed in a single maintenance and testing program. Describe the records management program used for scheduling, recording, and tracking identified S&S maintenance requirements, deficiencies, and testing schedules. CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section C 14 Table C-11. S&S-Related Maintenance, Testing and Records Management Programs Program Area Plan/ Procedure Title Test Plan or Management Plan Responsible Office/Organization PF - Equipment - Training Courses - Firearms Qualification - Other Vehicles/Aircraft Communications MC&A Security Systems - Personnel Access and Inspection Equipment - Security Lighting - Intrusion Detection and Assessment Systems - Electrical Power Supplies Sensitive Area Access Control Survey/Inspection Deficiencies j. Chapter 10, Site Protection Evaluation Program. Chapter 10 is designed to ensure the availability and use of testing and evaluation programs for site S&S programs and systems. In a narrative, describe the programs available and used to evaluate the effective- ness of S&S protection programs and the interaction of these evaluation tools (i.e., surveys may focus on shortfalls found in security inspections). At a minimum, the programs described in Chapters 4, 5, 6, and 8 of the SSSP should be addressed and the evaluation plan or procedure identified. In a chart similar to Table C-12, Site Protection Program Evaluation Program, list the names of the evaluation plans/procedures used by the cognizant security authority to assist in determining the effectiveness of site and facility protection programs and systems. List the office responsible for the evaluation plan/procedure and its purpose. Indicate, in a brief description, that performance testing is used to verify the effectiveness of S&S systems/programs and to validate VA activities. Additionally, briefly describe barriers and other systems that cannot be adequately performance tested to demonstrate protection capabilities and their integration into protection strategies due to physical, operational, or policy parameters.

Section 32

CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section C 15 Table C-12. Site Protection Program Evaluation Program Plan/Procedure Name Or Title Responsible Office Plan or Procedure Goal/Purpose Performance Assurance Program Contractor Manager Establish/confirm system effectiveness DOE/Contractor Self-Assessment Program Program Manager Identify program strengths/weaknesses Facility Approval, Security Surveys Cognizant Security Authority Confirm availability and adequacy of required S&S programs Force on Force Exercises Contractor Manager Confirm system effectiveness Limited Scope Performance Tests Contractor Manager Confirm system effectiveness Joint Tactical Simulation Model Contractor Manager Confirm system effectiveness k. Chapter 11, Deviations from DOE Directives. List all deviations that have been approved. In a table similar to Table C-13, Deviations from DOE Directives, list the deviation, the officially assigned deviation number, the directive reference (DOE directive and section within the directive), and the dates the deviation was approved and expires. Table C-13. Deviations from DOE Directives Deviation Description Deviation Number Directive Reference Approval and Expiration Dates Provide similar information for those deviations pending approval. This information should be displayed in a chart similar to Table C-14, Pending Deviations from DOE Directives. Table C-14. Pending Deviations from DOE Directives Deviation Description Deviation Number Directive Reference Approval And Expiration Dates l. Chapter 12, Summary of VA and Risk Assessment Results. (1) Executive Summary. Summarize the VA and risk assessments results for Category I SNM, Category II SNM (including credible roll up of SNM to a Category I quantity), theft targets, radiological, biological, and chemical sabotage targets, and disruption of critical missions. CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section C 16 Confirm in the narrative that performance testing was used to validate VA input data and the results of the VA. Following the narrative, complete a matrix similar to Table C-15, Summary of Identified Risks, which identifies the risk associated with the results of the VA. In part 10 of the matrix, summarize the proposed corrective actions or upgrades. For line item construction project (LICP) work or other major capital expenditures, cite the source of the required funding. Use the RP information as the basis for this summary. (2) Scope. Describe the targets to be covered, the items/issues to be excluded, and the limits on the conduct of the VAs in this SSSP. CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section C 17 Table C-15. Summary of Identified Risks Risk Rating (High, Moderate, Low) Target Number Target Location and Description Threat Type and Number Base Case Current Modif. Rating (date) Protected Action and Adjusted Rating: Near-Term (<2 yr) (date) Protected Action and Adjusted Rating: Long- Term (>2 yr) (date) Remarks Analyses Validated by Perf. Testing (1) (2) (3) (4) (5) (6) (7) (8) (9) (10) (11) SNM Theft Targets 1 2 Glovebox 112-A Bldg. 222 Test samples in NDA room, Bldg. 222 Terrorist, X outsiders with help of insider Criminal Insiders High High High High Relocate SI to access door Enhance HRP for NDA technicians and supervisors Mod High Harden access portal Install CCTV recording for post-review of activities in NDA room Low Mod

Section 33

Install hardware to allow SL relocation (FY-89 GPP) SNM protection unchanged, but probability of attempt reduced thru HRP and delayed assessment capability Yes Yes Radiological Sabotage Targets 3 Test reactor #5 North Area, Bldg. 408 Insider Mod Mod Reinforce SI number when in use Low None Low Use overtime when reactor in use-3 times per year No Chemical Sabotage Targets 4 Laboratory Bldg. 4 Insider Mod Mod None Low None Low None No Biological Sabotage Targets 5 Fabrication Room, Bldg. 1 Insider Mod Mod None Low None Low None No Disruption of Critical Mission Targets 6 7 Access port 4 D-line process line, Bldg. 460 Extrusion equipment in fuel manufacturing area, Bldg. 97 Disgruntled employee Psychotic employee High High Mod High Implement 2-man rule Establish spares inventory for long lead time parts Low Mod Harden and remote control of portal Identify alternate extrusion capability off-site Low Low Install hardware to reduce high manpower costs (use FY-92 GPP) Additional physical protection not cost-effective. Improved spares also provide repair capability for non- sabotage outages Yes Yes CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section C 18 (3) Methodology. (a) Theft or Diversion of SNM. Identify the SNM targets subject to theft and/or diversion. Describe the rationale and mechanism used to identify these targets. Using a table similar to Table C-16, SNM Theft/Diversion Targets, provide a description for each identified SNM target consisting of the following: the physical location of identified SNM; the type of material (such as pure products, high grade material, weapons, etc.) which could include pits, ingots, oxide fuel elements, etc.; the Category (I through II) and attractiveness level (A through E) of the target material; and the size and portability of the theft target. Table C-16. SNM Theft/Diversion Targets Location SNM Type Category/ Attractiveness Level Quantity/ Portability Bldg. 1, Vault Pu-239 ingots Cat. I,/B 2 ingots/man portable Bldg. 1, Assay Room Pu-239 ingots Cat. I,/B 2 ingots/man portable Bldg. 1, Fabrication Room Pu-238 oxide powder Cat. II/D 2 canisters/man portable Bldg. 2 U-235 fuel elements Cat. II, roll-up to Cat. I/ C 20 fuel elements/not man portable Bldg. 3 U-235 fuel elements Cat. II, roll-up to Cat. I/ C 20 fuel elements/not man portable (b) Radiological Sabotage. Identify the radiological targets subject to sabotage. Describe the rationale and mechanism used to identify these targets. A key source of information to assist in the identification and/or elimination of radiological targets is the facility safety analysis report. Using a table similar to Table C-17, Credible Radiological Sabotage Targets, provide a description for each identified radiological sabotage target consisting of the following: the physical location of all identified targets, the type of material, the maximum inventory level, and the material size and configuration. CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section C 19 Table C-17. Credible Radiological Sabotage Targets Location Material Type Maximum Inventory Material Size and Configuration Bldg. 1, Fabrication Room Pu-238 oxide powder 10 kg Paint Cans, at 50 g each Bldg. 4 H3 gas 10 kg Cylinders, at 500 g each (c) Biological Sabotage. Identify the biological targets subject to sabotage. Describe the rationale and mechanism used to identify these targets. Reference any policy and analyses external to the SSSP that address biological targets.

Section 34

Using a table similar to Table C-18, Credible Biological Sabotage Targets, provide a description for each identified biological sabotage target consisting of the following: the physical location of all identified targets, the type of material, the maximum inventory level, and the material size and configuration. Table C-18. Credible Biological Sabotage Targets Location Material Type Maximum Inventory Material Size and Configuration Bldg. 1, Fabrication Room Anthrax solution 10 g 20 petri dish @ 0.5 g each Bldg. 4 Botulism aerosol 20 g 10 2-liter cylinders, at 5 kg each (d) Chemical Sabotage. Identify the chemical targets subject to sabotage. Describe the rationale and mechanism used to identify these targets. Indicate whether security protection provided for chemical sabotage targets is comparable to that provided by the commercial sector for similar materials. A key source of information to assist in the identification and/or elimination of chemical targets is the facility safety analysis report. Reference any policy and analyses external to the SSSP that address chemical targets. Using a table similar to Table C-19, Credible Chemical Sabotage Targets, provide a description for each identified chemical sabotage target consisting of the following: the physical location of all identified chemical sabotage targets, the type of material, the maximum inventory level, how the security provided is not comparable to that of the commercial sector, the material size and CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section C 20 configuration, and the exposure level at the NSB for maximum inventory release. Table C-19. Credible Chemical Sabotage Targets Location Material Type Maximum Inventory Commercial Sector Security Difference Material Size & Configuration Exposure Level at NSB Bldg. 5 Chlorine 10,000 lb Lack of access control 55-gallon drums, at 350 lb each >ERPG III levels (e) Disruption of Critical Mission. Identify the disruption of critical mission targets. Describe the rationale and mechanism used to identify these targets. Ensure that the evaluation includes how the disruption would cause an unacceptable impact on national security. Using a table similar to Table C-20, Disruption of Critical Mission Targets, provide a description for each identified target consisting of the following: the physical location of the target, a description of the function of the target, the impact to national security, and the estimated time for recovery. Table C-20. Disruption of Critical Mission Targets (f) VA Parameters and Planning Assumptions. Describe/list the baseline parameters and planning assumptions used in conducting the VAs. Provide a summary list of parameters and planning assumptions used in completing VAs. These should include assumptions discussed and concurred in by appropriate DOE offices or planning assumptions identified as a result of data collection/discovery during the VA process. (g) Critical Path Protection Elements. Describe the process used to identify critical path protection elements and the types of tests to which site protection elements are subjected (procedural, simulation, barrier, equipment, PF, etc.). Using a table similar to Table C-21, Performance Testing Results of Site Specific Essential Protection Element Values, provide a list of: physical security system components for each protection layer (Limited Area [LA], PA, material access area [MAA], and Target Area), the critical protection element tested, if any, as determined from performance testing. Also, indicate the number of tests conducted to obtain results and the testing frequency used to monitor the protection

Section 35

Location Target Function Impact to National Security Estimated time for Recovery Site A, Bldg. 4 Fuel cell production Increased reliance on fossil fuels 180 days CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section C 21 element specific value. Table C-21. Performance Testing Results of Site-SpecificEssential Protection Element Values Protection Layer and Physical Security System Components Tested Critical Elements Tested No. of Tests Used as Basis for VA values Test Frequency Value used in VA Attempt to smuggle firearms through Portal 1. 36 Quarterly 0.6 PA - Identification and Intrusion Element Attempt to defeat door contacts Bldg. 1, door 3. 34 Quarterly 0.7 MAA - Search Component Attempt to smuggle firearms through MAA portal 24 Once every 2 months 0.8 Target Area - Identification Component Attempt to gain unauthorized vault access 48 Monthly 0.9 (h) Single Point Failure Analysis. Describe the analyses used to determine any single-point failures identified during the VA. Describe/list the single-point failure(s) to include the nature of the vulnerability, measures to mitigate the vulnerability and the potential exploitability by an adversary. (i) Critical Path Scenarios. Describe and provide the critical path scenarios, including the bounding scenarios, developed during the VA for each target. Identify the protection system effectiveness (PE) value for each of these targets. Describe and identify the critical detection points along each adversary path. Should multiple targets exist within the same security area, such as several SNM targets within the same MAA and same building, bounding critical path scenarios may be described. Provide justification that supports bounding cases. For each critical path scenario provide floor plans, diagrams, sketches, or an adversary path description (as shown in Table C- 22) or, if appropriate, refer to the descriptions that may have been used previously to illustrate the critical path and protection elements described in the scenarios. CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section C 22 Table C-22. Critical Path Scenarios Scenario Title: Base Case 1 Results Facility: Building XYZ PI . Target Location: Room,123 State, Open PN Adversary Threat/Adversary: Terrorist w/insider: X# outsider, Y# insiders Goal Type/Quantity: Oxide, Xx kg PE VA Path Analysis Tool: ASSESS C Computer File ID: .PPS, .OUT; .NEU Syst. Eff.: Neutralization Tool: JTS Syst. Eff.: Time (Sec) SCENARIO ACTIONS Total ADV PF Adversary pre-positions escape vehicles Adversary mails weapons and explosives into PA (No x-ray or explosives detection capability) Adversary proceeds to access control portal 0 20 Adversary attempt to deceit through portal (PD = 0.xx – badge check with xxxx at access portal). If detected, adversary begins overt actions. CRITICAL DETECTION POINT 25 CAS receives alert and begins to annunciate alert 20 25 Adversary proceeds to target building XYZ, door 7 on the NE corner 25 Protective Force units begin response 70 Unit A responds to NE corner of building XYZ 55 Unit B responds to SE corner of building XYZ 80 Unit C responds to SE corner of building XYZ 60 Unit D responds to SE corner of building XYZ 45 5 Adversary reaches door 7 to building XYZ, insider opens door 7 into building XYZ (PD = 0.xx – BMS)

Section 36

50 5 Adversaries enter building XYZ and transverse to vault room 123. CAS receives BMS door alarm and annunciates the alarm 55 50 Adversaries collect target material 80 Unit B reaches response position 85 Unit D reaches response position 95 Unit A reaches response position 105 5 Adversaries proceed to door 7 to exit building XYZ. Unit C reaches response position. 110 Adversary exits building XYZ via door 7. (PD = xxx - , ) 112 Unit A engages adversary Etc. CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section C 23 Identify and describe the point along the adversary path at which detection is required to allow for sufficient response time for adversary neutralization to be effected for each of the critical path scenarios (i.e., critical detection point). (j) Protection System Effectiveness. Verify that the PE values identified for each critical path scenario were used to calculate conditional risk for each identified target. Using tables similar to those on the following pages (Table C-23, Protection Effectiveness PE for Theft or Diversion of SNM; Table C-24, Protection Effectiveness (PE) for Radiological Sabotage; Table C-25, Protection Effectiveness (PE) for Biological Sabotage; Table C-26, Protection Effectiveness (PE) for Chemical Sabotage; Table C-27, Protection Effectiveness (PE) for Disruption of Critical Missions; Table C-28, Protection Effectiveness (PE) for Theft or Espionage of Classified Information or Matter; and Table C-29, Protection Effectiveness (PE) for Other Losses), show the targets and PE values for each target. (k) Neutralization Analyses. Identify and describe the mechanism(s) used to determine/calculate the neutralization value(s) used in the risk evaluation. Identify and describe the basis for the neutralization values, parameters that impact the neutralization calculations and any site-specific issues that modify neutralization calculations. (l) Insider Analysis. Describe the analysis for determining the insider threat for each target class included in the SSSP. This analysis must include the programs supporting the elimination/mitigation of select insider groups from the threat spectrum, identification of the potential insider population, and insider protection programs that were not included in other protection system elements. Describe the programs that are factored into the VA process and provide justification for their use. Identify by position and title the participants in the HRP. (m) Conclusions. Provide a summary of system effectiveness for the identified targets. Document VA analyst’s observations and recommendations developed as a result of the VA process. Summarize the system effectiveness using a table similar to C-30, System Effectiveness Summary. CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section C 24 Table C-23. Protection Effectiveness (PE) for Theft or Diversion of SNM Location Material Type Facility Condition Adversary Type Adversary Scenario Summary Protective Force Response Summary PE Value Bldg. 1, Vault Pu-239 ingots Open Terrorist Vault open. Outsiders deceit into PA. Insider crashes out of Bldg. 1 MAA with material. Hands off to outsiders. Adversaries leave PA/site by vehicle. Armed response to BMS door alarm. Containment at MAA boundary. Positioning of blocking forces at PA boundary if MAA containment defeated. Pursuit in PPA if escape from facility. .7 Bldg. 1, Assay Room Pu-239 ingots Open Terrorist Scenario same as vault open scenario.

Section 37

Scenario same as vault open scenario. .7 Bldg. 1, Fabrication Room Pu-238 oxide powder Open Terrorist Scenario same as vault open scenario. Scenario same as vault open scenario. .7 Table C-24. Protection Effectiveness (PE) for Radiological Sabotage Location Material Type Facility Condition Adversary Type Adversary Scenario Summary Protective Force Response Summary PE Value Bldg. 1, Fabrication Room Pu-238 oxide powder Open Terrorist Building open. Outsiders deceit into PA. Outsiders force MAA boundary by foot. Insider allows access into Bldg. 1. Outsiders enter fabrication room, obtain Pu-238 oxide, defeat HEPA filters, and vent material to environment through building ventilation. Armed response to MAA boundary alarm. .4 Bldg. 4 H3 gas Open Terrorist Building open. Outsiders deceit into PA. Outsiders force MAA boundary by foot. Insider allows access into Bldg. 4. Outsiders disperse H3 to the environment with explosives. Armed response to MAA boundary alarm. .4 CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section C 25 Table C-25. Protection Effectiveness (PE) for Biological Sabotage Location Material Type Facility Condition Adversary Type Adversary Scenario Summary Protective Force Response Summary PE Value Open Terrorist Building open. Outsiders deceit into PA. Insider allows access into Bldg. 5. Outsiders disperse anthrax to the environment with explosives. Building Containment .2 Bldg. 5 Anthrax Closed Terrorist Outsiders deceit into PA. Outsiders breach door into Bldg. 5. Outsiders disperse anthrax to the environment with explosives. Building Containment .2 Table C-26. Protection Effectiveness (PE) for Chemical Sabotage Location Material Type Facility Condition Adversary Type Adversary Scenario Summary Protective Force Response Summary PE Value Open Terrorist Building open. Outsiders deceit into PA. Insider allows access into Bldg. 5. Outsiders disperse chlorine to the environment with explosives. Building Containment .2 Bldg. 5 Chlorine Closed Terrorist Outsiders deceit into PA. Outsiders breach door into Bldg. 5. Outsiders disperse chlorine to the environment with explosives. Building Containment .2 Table C-27. Protection Effectiveness (PE) for Disruption of Critical Missions Location Equipment Type Facility Condition Adversary Type Adversary Scenario Summary Protective Force Response Summary PE Value Bldg. 1, Fabrication Room Fuel Fabrication Open Non-Violent Insider Insider enters Fab. Room. Starts fire to destroy equipment located in room. Building Containment .2 CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section C 26 Table C-28. Protection Effectiveness (PE) for Theft or Espionage of Classified Information or Matter Location Classified Information or Matter Facility Condition Adversary Type Worst-case Scenario Summary Protective Force Response Summary PE Value Bldg. 5, Office Area TSRD Documents Open Non-Violent Insider Insider obtains TSRD, makes copies, encloses copies in envelope, and hand- carries out of Bldg. 5. Insider mails classified documents out of PA to off-site location. None .2 Table C-29. Protection Effectiveness (PE) for Other Losses Location Item Facility Condition Adversary Type Worst-case Scenario Summary Protective Force Response Summary PE Value Bldg. 5, Lab Area R&D Laboratory Open Non-Violent Insider Insider starts fire in laboratory. Building Containment .2 Table C-30. System Effectiveness Summary

Section 38

Goal Target Location Operations PE Theft of SNM Bldg. 1 Vault Day Shift .8 Theft of SNM Bldg. 1 Assay Room Day Shift .8 Theft of SNM Bldg. 1 Fab. Room Day Shift .75 Rad. Sabotage Bldg. 1 Fab. Room Day Shift .85 Rad. Sabotage Bldg. 4 Bldg. 4 Day Shift .9 Chem. Sabotage Bldg. 5 Laboratory Day Shift .8 Bio. Sabotage Bldg. 5 Laboratory Day Shift .8 Indust. Sabotage Bldg. 1 Fab. Room Day Shift .8 Espionage of Classified Bldg. 5 Office Area Day Shift .8 Other Losses Bldg. 5 Laboratory Day Shift .8 CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section D 1 SECTION D - SITE SAFEGUARDS AND SECURITY PLAN RESOURCE PLAN 1. OBJECTIVE. The Resource Plan (RP) identifies safeguards and security (S&S) resources necessary to ensure protection of Department assets and identifies changes in resource requirements (i.e., operational requirements, capital equipment, general plant projects (GPPs) and line item construction projects (LICPs) that directly impact risk, indirectly impact risk, or derive from changing S&S policy, directives, guidance, or other Department or other Departmental direction. a. Operational Requirements. Briefly describe operational requirements relating to S&S operations that would require increments or decrements to operational accounts (e.g., program direction, operational support, etc.). Operational requirements must include, but are not limited to, material consolidation, facility mission changes, changes in the Design Basis Threat (DBT) impacting site operations, protective force (PF) redeployments, maintenance and testing changes, PF manning levels, procuring technical expertise and support personnel, and additional training requirements. Summarize the pertinent information in a table such as outlined in Table D-1, Operational Requirements. The table and supporting narrative must include the following: (1) the title of each operational requirement; (2) the basis of the requirement (drivers behind the requirement); (3) the funding profile and the impacts if not funded (if possible, state the impact in terms of probability of system effectiveness (PE) and indicate if this is a new resource requirement); and (4) provide a status of operational requirements that were previously authorized but have not yet been completed. Provide a separate section for each operational requirement. Table D-1. Operational Requirements Funding Request/Profile Requirement (section) Basis FY xxxx (current year) FY + 1 FY + 2 FY + 3 FY + 4 FY + 5 Currently in Budget (Y or N) Type of Expense b. Capital Equipment. Briefly describe identified/proposed capital equipment procurements and funding requirements that are not part of a LICP or GPP, and support S&S programs and operations. These procurements could include, but CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section D 2 are not limited to, alarm and assessment system components, material control and accountability (MC&A) systems, access control system components, and equipment necessary to complete the S&S mission (e.g., breaching tools, vehicles, PF armaments, additional capabilities necessary to address changes in the DBT). Summarize the pertinent information in a table as outlined in Table D-2, Capital Equipment. The table and supporting narrative must include the following: (1) a title for each capital equipment procurement; (2) the basis of the requirement (drivers behind the requirement); (3) the funding profile and the impacts if not funded (if possible, state the impact in terms PE, and indicate if this is a new resource requirement); and

Section 39

(4) provide a status of capital equipment upgrades that were previously authorized but have not yet been completed. Provide a separate section for each capital equipment procurement. Table D-2. Capital Equipment Funding Request/Profiles Capital Equipment (section) Basis FY xxxx (current year) FY + 1 FY + 2 FY + 3 FY + 4 FY + 5 Currently in Budget (Y or N) c. GPP. Describe significant identified/proposed GPPs that are not part of an LICP or capital equipment expense but that are necessary to support S&S programs and operations. These GPPs could include, but are not limited to, alarm and assessment systems/components, MC&A systems, access control systems/components, or infrastructure improvements. Summarize the pertinent information in a table as outlined in Table D-3, General Plan Projects. The table and supporting narrative must include: (1) a title for each GPP; (2) the basis of the requirement (drivers behind the requirement); (3) the funding profile and the impacts if not funded (if possible, state the impact in terms PE, and indicate if this is a new resource requirement); (4) a status of general plan project upgrades that were previously authorized but have not yet been completed. Provide a separate section for each GPP. CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section D 3 Table D-3. General Plant Projects Funding Request/Profiles General Plant Projects (section) Basis FY xxxx (current year) FY + 1 FY + 2 FY + 3 FY + 4 FY + 5 Currently in Budget (Y or N) d. LICPs. Describe current and proposed LICPs that are not part of a GPP or capital equipment procurement but are necessary to support S&S programs and operations. Summarize the pertinent information in a table as outlined in Table D-4, Line Item Construction Projects. The table and supporting narrative must include: (1) a title for each LICP; (2) the basis of the requirement (drivers behind the requirement); (3) the funding profile and the impacts if not funded (if possible, state the impact in terms PE, and indicate if this is a new resource requirement); and (4) provide status of S&S upgrades that were authorized but have not yet been completed. Discuss any changes to cost estimates (i.e. total estimated cost [TEC] versus total project cost [TPC]) identified in the previous RP. Provide a separate section for each LICP. CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section D 4 Table D-4. Line Item Construction Projects Funding Request/Profiles Total Costs Schedule LICP Title (section) Basis FY xxxx (current year) FY + 1 FY + 2 FY + 3 FY + 4 FY + 5 TEC TPC Start Date Finish Date Currently in Budget (Y or N) Table D-5. Unfunded/Unsupported Requirements Original Funding Request/Profiles Requirement (section) Basis Resource Type Base FY FY xxxx FY + 1 FY + 2 FY + 3 FY + 4 FY + 5 Impact CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section D 5 2. UNFUNDED/UNSUPPORTED REQUIREMENTS. Briefly describe proposed S&S operational requirements, capital equipment procurements, GPPs, or LICPs that had been previously identified and have not been funded supported. Summarize the pertinent information in a table such as Table D-5, Unfunded/Unsupported Requirements. The table and supporting narrative must include: a. a title for each unfunded requirement; b. the basis for the requirement (drivers behind the requirement); c. the type of resource requested (operating expense, capital equipment, GPP, or LICP); d. the fiscal year the requirement was originally identified;

Section 40

e. the proposed funding profile and impacts due to lack of funding (if possible, state the impact in terms of PE). Provide a separate section for each unfunded requirement. 3. REFERENCES FOR THE RESOUCE PLAN. a. Facility SSSP. Provide a reference to the most recent/current SSSP. b. Programmatic Documentation. Provide a reference (include title, date, and responsible organization) for any programmatic policy, directive, or guidance necessitating the allocation of additional resources. 4. HEADINGS AND TERMS FOR TABLES D-1 THROUGH D-5. Following are the types of data to be included in the RP. a. Basis. (1) Compliance. (2) Risk reduction. (3) SSSP derived. (4) Cost-efficiency. (5) Operational efficiency. (6) Enhanced operations. (7) DBT change. CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section D 6 b. Type of expense. (1) Operational = annual recurring cost that will need to be added to the budget baseline. (2) Single = one time only expense paid from operating dollars. c. Total Costs1. (1) TEC = Total estimated cost. (2) TPC = Total project cost. d. Resource Type. (1) OE = operational expense. (2) CE = capital expense. (3) GPP = general plant project. (4) LICP = line item construction project. (5) BASE FY = fiscal year in which the resources were identified and requested. e. Impact. (1) Continued risk. (2) Cost escalation. (3) Unable to comply with xxxx (list applicable directive). (4) Programmatic impact. (5) Operational impact. (6) Other (list). 1 As defined in DOE O 413.3, Chg 1, Project Management for the Acquisition of Capital Assets. CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section E 1 SECTION E - VULNERABILITY ASSESSMENT PROGRAM 1. OBJECTIVE. The Vulnerability Assessment (VA) Program must consider other programs such as protective force (PF), material control and accountability (MC&A), emergency operations, safety, maintenance, facility operations, personnel security, physical protection, and information security. 2. CONDUCTING VULNERABILITY ASSESSMENTS. The process of conducting a VA includes gathering data that describe the physical and operational characteristics of a safeguards and security (S&S) system, assigning values such as delay and detection, and analyzing the results to determine the relative effectiveness in conjunction with the adversary’s capabilities as identified in the Design Basis Threat (DBT) and the Adversary Capabilities List (ACL). Below is a description of the VA process. a. Assumptions. Assumptions and scoping agreements must be defined. All assumptions must be documented in the VA report. b. Threat. The person responsible for the conduct of VAs, hereinafter referred to as the analyst (see paragraph 9. of this Section), must understand how the DBT relates to VAs. The analyst performing the VA must apply DOE Headquarters (HQ), regional and local threat guidance. (1) DOE HQ Threat. (a) The DBT must be used to define threat against which VA analysts evaluate the protection system (b) The site’s protective systems must be analyzed against the ACL. (2) Regional and local threats must be considered during the conduct of VAs. c. Targets. All security interests whose loss, theft, compromise, and/or unauthorized use will affect the national security and/or the health and safety of DOE and contractor employees, the public, the environment, or DOE programs are potential targets. The analyst must consider target configurations and conditions, as well as operational conditions and acquisition times.

Section 41

d. Modeling. Modeling is used to analyze S&S programs, interests, assets, and the effectiveness of program implementation. Modeling can include computer-based tools and simulations, table-top analyses, and subject matter expert analyses. Section E, Appendix 2, VA Modeling Tools, lists those modeling tools approved by DOE. Methods to ensure that the models accurately reflect the facility posture must be part of the final VA results. The modeling process must establish critical pathways. The following must be considered: (1) facility characterization; CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section E 2 (2) system effectiveness models and equations must be used. Section E, Appendix 3, System Performance Effectiveness Equation, delineates the system effectiveness equation; (3) response force times; (4) the probability of neutralization (PN) must be calculated using data available regarding the PF response and their ability to interrupt and neutralize an adversary. The methods used must be documented and retained as part of the evidence file. The calculated number for PN must be derived from more than one source, one of which must be joint tactical simulation (JTS), joint conflict and tactical simulation (JCATS), or force- on-force (FoF) exercises; (5) blast effect modeling must consider blast effects on barrier breaching, a force multiplier, and target buildings; (6) table-top methods used to determine system effectiveness must be documented and a means provided to allow for validation or verification; (7) radiological sabotage must be fully analyzed against the DBT and ACL. Existing information from safety analyses can be used but must be analyzed to consider deliberate rather than accidental release; (8) chemical and biological sabotage must be analyzed against the DBT and ACL; (9) the analysis must use the thresholds stated in DOE O 470.3, Design Basis Threat (DBT) Policy; and (10) the use of chemical and biological agents must be analyzed as a force multiplier. Methods of release and mitigation measures must be a part of the analysis. e. Performance Testing. If conducted, the results of the following tests (including validation) must be considered in determining system effectiveness: (1) FoF exercises; (2) limited scope performance tests (LSPTs); (3) alarm response and assessment performance tests (ARAPTs); (4) breaching test data; and (5) critical system element tests. CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section E 3 f. Results. The results of VAs indicate PE. The VA results must be used for determining: (1) protection system effectiveness reporting; (2) S&S upgrades; (3) manning/armament levels for the PF; and (4) justifications for waivers of and exceptions to S&S policy. g. VA Practitioner Training. VA practitioners must successfully complete VA Program training within 2 years of appointment. This requirement can be met through the National Training Center (NTC). 3. QUALITY ASSURANCE. The analyst must verify the data used for the analyses. These data include: a. modeling data to include detection, assessment, delay, interruption, neutralization, PF response times, etc.; b. all facility modeling characterization direct settings, rationales, and documentation; c. performance test results and documentation; and d. sensitivity analyses such as single point failure and critical system element analyses. 4. VULNERABILITY ASSESSMENT. All information used to support or document VAs must be maintained and made available upon request. Examples include:

Section 42

a. modeling inputs; b. PF response; c. adversary capabilities; d. blast effects; e. sabotage data; f. timeline data; and g. neutralization data. 5. ASSIGNING FIGURES OF MERIT. “Figures of merit” is defined as numerical values and/or qualitative ratings assigned to component systems and personnel associated with the protection system. Collectively the qualitative and/or quantitative measures provide CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section E 4 the basis for determining system effectiveness. Approved reference materials must be used to provide initial data and to calculate accurate detection and delay numbers. A list of approved references is provided in DOE M 470.4-7, Safeguards and Security Program References. Reference materials are to be used only as a basis for the relative figures of merit. Non-default figures of merit must be documented and based on performance testing or engineering studies. 6. CRITICAL SYSTEM ELEMENTS. Critical system elements are components or subcomponents of an S&S protection system that directly affects the ability of the system to perform a required function. Critical system elements may be equipment, procedures, or personnel. Failure of a critical system element would result in the protection system effectiveness of the target being reduced to levels requiring management action. Critical system elements must be: a. identified for every target that requires a VA; b. specifically delineated such that specific performance tests can be performed to determine the ability of the protection measures to perform their intended function; and c. tested, documented, and the results analyzed to validate element effectiveness. 7. VULNERABILITY ASSESSMENT REPORTS. The vulnerability assessment report (VAR) documents the results of a VA. The VARs must include targets analyzed, methodology used, system effectiveness results, parameters and assumptions under which the VA was conducted, and reference to evidence files. VARs published in support of an SSSP should conform to the suggested format given in Section E, Appendix 4, Suggested VA Report Format. The approval chain for VARs is below. a. The analyst responsible for the VA must sign the report. b. Line management responsible for the facility/site VA Program must approve the report. c. DOE line management responsible for the VA Program must concur with the report. d. The DOE cognizant security authority must concur with the report. 8. SYSTEM EFFECTIVENESS. Only the Secretary of Energy or the Deputy Secretary can accept low protection system effectiveness that results in high risk. Cognizant Under Secretaries can accept marginal protection system effectiveness that results in moderate risk. If the results of a VA, survey, self-assessment, audit, or inspection conducted by the cognizant security authority, Departmental element, Office of Security, or Office of Independent Oversight and Performance Assurance indicate a decreased (low or marginal) protection system effectiveness that is not mitigated by compensatory CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section E 5 measures based on a risk management determination (see Section A, 2.e.), the following actions must be initiated: a. Low Protection System Effectiveness. (1) Once a low protection system effectiveness condition that results in high risk is identified, that condition must be reported to the responsible Departmental element within 4 hours.

Section 43

(2) A corrective action plan must be submitted to the responsible Departmental element within 8 hours, with a copy to the Office of Security. (3) The Departmental element must make formal notification to the Secretary or Deputy Secretary within 24 hours. (4) The Departmental element in consultation with the Office of Security must provide comments on the protection system effectiveness and recommendations to the Secretary/Deputy Secretary within 36 hours. (5) The responsible Departmental element must update the Secretary or Deputy Secretary on low protection system effectiveness conditions every 30 days with an information copy to the Office of Security. b. Marginal Protection System Effectiveness. (1) Once a marginal protection system effectiveness condition that results in moderate risk is identified, that condition must be reported to the responsible Departmental element within 2 working days. (2) The Departmental element must notify the appropriate Under Secretary within 3 working days. (3) A corrective action plan with recommendations must be submitted to the responsible Departmental element within 5 working days with a copy to the Office of Security. (4) The Office of Security must provide comments to the Departmental element within 5 working days. (5) The responsible Departmental element must update the Secretary or Deputy Secretary and appropriate Under Secretary on marginal protection system effectiveness conditions every 90 days with an information copy to the Office of Security. CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section E 6 9. TRAINING AND CERTIFICATION. a. The analyst responsible for the conduct of Vulnerability Assessments must complete the Department-approved training program (scheduled to be fully implemented by 2008). b. The analyst must be certified as outlined in the Vulnerability Assessment Certification Program Manual which is currently under development. c. Any person currently conducting VAs may be “grandfathered” until such time as the Vulnerability Assessment Certification Program Manual is issued. CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section E Appendix 2-1 SECTION E APPENDIX 2 – VULNERABILITY ASSESSMENT MODELING TOOLS 1. ASSESS – Analytic System and Software for Evaluating Safeguards and Security. 2. ATLAS – Adversary Time Line Analysis System. 3. BATLE – Brief Adversary Threat Loss Estimator. 4. JTS – Joint Tactical Simulation. 5. JCATS – Joint Conflict and Tactical Simulation. 6. AT Planner – Anti-Terrorist Planner. 7. BLAST X – Explosive Effects Analysis Software. 8. BLAST FX – Explosive Effects Analysis Software. 9. ConWEP – Conventional Weapons Effects Program. 10. BEEM – Blast Effects Estimation Model. 11. HOTSPOT – HOTSPOT Health Physics Code provides the capability to calculate the radiation effects associated with the short-term (less than 24 hours) atmospheric release of radioactive materials. 12. RSAC – Radiological Safety Analysis Computer program calculates the consequences of a release of radionuclides to the atmosphere. 13. ACATS – Airborne Chromatograph for Atmospheric Trace Species. 14. ISA – Iterative Site Analysis. 15. VISA – Vulnerability of Integrated Security Analysis. 16. VISA II – Vulnerability of Integrated Security Analysis II. 17. ERAD – Explosive Release Atmospheric Dispersion. 18. ALOHA – Area Locations of Hazardous Atmospheres. 19. ARAC – Atmospheric Release Advisory Capability.

Section 44

20. ACCS 2 – Accident Consequence Code System for the calculation of the health and economic consequences of accidental atmospheric radiological releases. CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section E Appendix 2-2 21. HPAC – Hazard Prediction Analysis Code provides the capability to accurately predict the effects of hazardous material releases into the atmosphere. CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section E Appendix 3-1 SECTION E APPENDIX 3 - SYSTEM PERFORMANCE EFFECTIVENESS EQUATION The methodology requires the determination of the probability of sensing, probability of assessment, and probability of detection at each layer. These are then combined to determine the contribution to overall system effectiveness represented by each layer. Mathematically, this can be expressed as the equation: PEL = PIL x PNL = PDL * PNL = PAL * PSL * PNL Where: PEL is the system effectiveness contribution for layer L; PIL – Probability of Interruption given first detection at layer L, PIL = PDL if detection on layer L is timely, and is equal to 0 (PIL = 0) if detection is not timely; PDL – Probability of Detection at layer L, PDL = PSL x PAL on layer L. PDL is the probability of first detection at layer L, given that detection has not occurred at an earlier layer, multiplied by the probability of sensing at an earlier layer, multiplied by the probability of sensing at layer L (PSL) and the probability of assessment at layer L (PAL); PSL – Probability of Sensing on layer L; PAL – Probability of Assessment on layer L; and PNL – Probability of Neutralization given first detection at layer L. L is defined as the number of detection layers in the system before the critical detection point (CDP) in the adversary path(s). Detection after the CDP cannot not be counted. PE is defined as the system effectiveness of the layer. The system effectiveness of the layer is the product of the probability of interruption of the layer and the probability of neutralization given that detection occurred at that layer (PI x PN). The probability of neutralization is determined discretely for each layer given detection at the layer. The neutralization determination is made if detection (regardless of the extent) takes place at the layer in question. Neutralization will occur sometime past the detection point and would be valid for the probability of neutralization of that specific layer. PD of the layer is defined as the product of the probability of sensing and the probability of assessment of the layer (PS x PA). Note that detection and assessment will be different between the elements of the layer and between layers. PIL of the layer is defined as PIL = PDL if detection on layer L is timely, and is equal to 0 (PIL = 0) if detection is not timely. The Σ symbol is the summation of terms. The summation symbol is defined as: CANCELE D DOE M 470.4-1 DRAFT XX-XX-05 Part 1, Section E Appendix 3-2 n n i i kkkk +++≡∑ = ...21 1 The Π symbol is the product of terms. The product symbol is defined by: n n i i ffff ×××≡∏ = ...2 1 1

Section 45

For those protection systems based on sensing, assessment, detection, interruption, and active neutralization of an adversary, credit can only be taken up to the “point on the pathway” at which the total of the adversary task time, engagement times, and delay times exceeds the protective force response times. This limiting criteria eliminates credit being taken for protection system capabilities that are not engaged prior to the adversary completing their objective. For denial based protection systems, the “point on the pathway” is the critical detection point. The critical detection point is defined as the point at which the protective force must have timely detection, assessment, and response to initiate a response to have a high probability of success in the neutralization of the adversary or denial of the adversary’s task/objective. Therefore, for a facility employing multiple, complementary layers of protection, the representative total protection system effectiveness is calculated up to the point at which the protection systems can still effectively engage an adversary prior to completion of the objective. The contributions of each layer along the adversary pathway are then combined to determine the overall system effectiveness, where the overall system effectiveness is provided by the sum of the contributions of each layer (only those encountered along the adversary pathway) to the system effectiveness. An example of the system effectiveness equations for a three-layer system protecting SNM would be as follows: In extended notation, the Overall System Effectiveness is: PE = (PA1 x PS1 x PN1) + [(1 – (PA1 x PS1)) x (PA2 x PS2 x PN2)] + {(1 – ((PA1 x PS1) + [(1 – (PA1 x PS1)) x (PA2 x PS2)])) x (PA3 x PS3 x PN3)} Which reduces to: PE = (PD1 x PN1) + [(1 – PD1) x (PD2 x PN2)] + {(1 – (PD1 + [(1 – PD1) x PD2])) x (PD3 x PN3)}, and since PIL = PDL when detection is timely, PE = (PI1 x PN1) + [(1 – PI1) x (PI2 x PN2)] + {(1 – (PI1 + [(1 – PI1) x PI2])) x (PI3 x PN3)} PE = PE1 + [(1 – PI1) x PE2] + {(1 – (PI1 + [(1 – PI1) x PI2])) x PE3)} CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section E Appendix 4-1 SECTION E APPENDIX 4 - SUGGESTED VULNERABILITY ASSESSMENT REPORT FORMAT 1.0 Executive Summary Objective Purpose and Summary of Protection Effectiveness 2.0 Introduction Scope Changes in the VAR Methodology and Assumptions 3.0 Target Identification and Description Theft or Diversion Sabotage (Radiological) Sabotage (Chemical and/or Biological) Theft or Espionage of Classified Information or Matter Other Losses 4.0 Threat Definition Adversary Type(s) Adversary Attributes 5.0 S&S Protection Elements Physical Security Systems Protective Forces (Response Strategies, Interruption, Neutralization) Material Control and Accountability Reliability Program 6.0 Performance Testing Program Description Site Protection Elements Critical Protection Elements CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section E Appendix 4-2 7.0 S&S Protection Effectiveness Scenario Protection Effectiveness Validation Testing 8.0 Summary of S&S Protection Effectiveness Protection Effectiveness Recommendations CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section F 1 SECTION F - PERFORMANCE ASSURANCE PROGRAM 1. OBJECTIVE. To demonstrate the effectiveness of the protection provided Departmental safeguards and security (S&S) interests by systematically evaluating all protection program essential elements.

Section 46

2. REQUIREMENTS. Each performance assurance program must be developed to validate the performance of all essential S&S protection elements. a. Operability and Effectiveness. Performance assurance programs must provide for operability and effectiveness testing of each protection program essential element or component. (1) Operability tests provide measures of integrity and must check the essential elements or total system to confirm operability. (2) Performance tests provide comprehensive assurance that protection program elements are performing as designed and provide the required levels of protection. (a) Performance tests results are used to validate the effectiveness of all elements of a layered S&S system. (b) Performance tests are not substitutes for compliance with requirements. b. Continuity. Performance assurance programs must evaluate operational continuity of all S&S essential elements. Limited Scope Performance Tests (LSPTs) and/or force-on-force (FoF) tests may be used as a means of meeting specific performance assurance testing requirements. Performance assurance programs require that: (1) new protection program essential elements and components must be validated through acceptance testing before operational use; (2) essential elements that have been repaired or undergone maintenance must be validated through testing before use; (3) the protective force (PF) is performance tested to ensure that approved protection strategies of denial, containment, recapture, recovery, and pursuit can be accomplished; and (4) essential elements of the protection program security systems and subsystems are performance tested to ensure that system detection, assessment, and response to alarms and adversarial actions meet stated requirements. CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section F 2 c. Reliability. Each essential element whose failure would reduce protection to an unacceptable level must be tested at frequencies that provide high assurance of operability and reliability. (1) Testing frequencies must reflect site-specific conditions and operational needs. (2) Testing frequencies must be documented for each essential element. d. Performance Tests. At least every 365 days, an integrated performance test encompassing all essential protection elements associated with a comprehensive site or facility threat scenario must be conducted to evaluate the overall facility S&S effectiveness. (1) Those Category I facilities requiring denial protection strategies must conduct integrated performance testing on a quarterly basis (at least every 3 months). OR (2) Those sites with multiple Category I facilities requiring denial protection strategies may rotate quarterly performance testing so that at least one facility is tested on a quarterly basis (at least every 3 months). However, an integrated performance test for all Category I facilities must occur at least once every 365 days. e. Documentation. (1) Performance Assurance Program Plan. This plan must be an integral part of the site safeguards and security plan (SSSP)/site security plan (SSP), or material control and accountability (MC&A) plan, as applicable. The performance assurance program plan must describe the program and its administration and implementation by: (a) identifying protection elements for the protection of Category I and II special nuclear material (SNM) and Top Secret matter;

Section 47

(b) describing how the performance of these elements is to be ensured, including the manner in which credit is taken for activities performed by external oversight organizations; (c) addressing how deficiencies identified during performance assurance activities are to be corrected. (2) Performance Assurance Reports. The results of performance assurance program testing must be documented. CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section F 3 (3) Document Retention. Record keeping systems must provide an audit trail for performance assurance activities and reports. CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section G 1 SECTION G - SURVEY, REVIEW, AND SELF-ASSESSMENT PROGRAMS 1. OBJECTIVES. a. Provide assurance to the Secretary of Energy, Departmental elements, and other government agencies (OGAs) that safeguards and security (S&S) interests and activities are protected at the required levels. b. Provide a basis for line management to make decisions regarding S&S program implementation activities, including allocation of resources, acceptance of risk, and mitigation of vulnerabilities. The results must provide a compliance- and performance-based documented evaluation of the S&S program. c. Identify S&S program strengths and weaknesses, develop and complete a process improvement schedule, and use the results to correct and improve the overall S&S program. d. Provide documentation of oversight and assessment activities. 2. REQUIREMENTS. a. Types and Frequencies of Surveys and Assessments. (1) Initial Surveys. Initial surveys must be conducted at facilities where there will be a facility clearance established for a facility with an importance rating of: A, B, C, or PP (see Section I, Chapter II). Survey activities must be comprehensive and result in a satisfactory composite rating prior to a facility clearance (FCL) being granted. (2) Periodic Surveys. Periodic surveys are conducted for all facilities and must cover all applicable topics to ensure survey program objectives are met. The periodic survey may be composed of multiple special survey reports, providing all the requirements of this Section are met. Integration of internal and external reports including quality assurance, property appraisals, performance assurance, and other evaluation reports may be used to augment the requirement for a periodic survey. A DOE Federal facility (e.g. site office) conducting a periodic survey are is required to perform self-assessment as noted in 6, below. (a) Facilities with importance ratings of A, B, or C must be surveyed once every 12 months (with the exception of Category IV SNM only facilities – see (c) below). (b) Facilities with an importance rating of PP must be surveyed once every 24 months. CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section G 2 (c) For facilities with Category IV special nuclear material (SNM) and nuclear material, including source material, the nuclear material control and accountability (MC&A) topical area must be surveyed at least every 24 months. (d) Facilities with importance ratings of D, NP, or E do not require surveys but do require periodic reviews (see (5), below). (3) Special Surveys. Special surveys may be conducted at facilities for specific limited purposes. Examples include extended survey activities, technical security activities, “for cause” reviews, line management direction, shipment of nuclear and/or classified information or matter, or a change in the contractor operating a government-owned facility.

Section 48

(4) Termination Surveys. Termination surveys must be conducted to verify the termination of Departmental activities and appropriate disposition of S&S interests. Examples of survey activities include: the appropriate disposition, destruction, or return of classified information or matter, SNM, hazardous material, property, security badge retrieval, debriefings, and verification of the termination or transfer of Department of Energy (DOE) access authorizations. (a) Onsite termination surveys must be conducted at facilities possessing Top Secret matter, sensitive compartmented information (SCI)/ special access program (SAP) information or matter, or SNM. (b) Onsite or correspondence termination surveys must be accomplished for all other possessing facilities. (5) Periodic Reviews. A documented review of entities (D, NP, and E facilities) such as subcontractors, consultants, and common carriers must be performed by the DOE cognizant security authority at least every 5 years. (6) Self-Assessments. Self-assessments must be conducted between the periodic surveys conducted by the cognizant security authority and include all applicable facility S&S program elements. The self- assessment must ensure the S&S objectives are met (see paragraph 1., above). Federal facilities may use the self-assessment to substitute for the Periodic Survey requirement. NP facilities are not required to conduct self-assessments. However, sponsoring organizations (Federal or contractor) must include in their self-assessments a thorough review of their registration program for NP facilities which may result in a program review of identified subcontractors. CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section G 3 (7) Reviews or Inspections by Other DOE Elements or OGAs. Reviews/inspections conducted by other DOE elements (including site quality assurance programs) or OGAs may be used to meet survey requirements. When using reviews/inspections conducted by other organizations to meet the requirements of the survey, the guidelines below must be followed. (a) The review/inspection must have been conducted within the survey period. (b) Applicable portions of the review/inspection must be attached to the survey report. (c) Portions of topical and subtopical areas not covered by the review/inspection must be surveyed. (d) If ratings were not assigned during the review/inspection, the surveying office must analyze the impact of any deficiencies and assign ratings. (8) Extension of Frequency. The results of previous surveys may affect the frequency of future surveys. The interval between periodic surveys may be increased up to 24 months by the DOE cognizant security authority. Documentation of the justification for increases in the interval of periodic surveys must be maintained by the DOE cognizant security authority. (a) The following conditions must be met for extensions: 1 the facility was rated satisfactory during the most recent survey activity; 2 the facility has no unmitigated deficiencies that impact the security posture of the facility, and all applicable topical area ratings are satisfactory from the previous survey; and 3 all applicable topical area ratings from the most recent self- assessment are satisfactory, and the DOE cognizant security authority concurs with the ratings. (b) Increasing the interval between surveys for a facility possessing Category I SNM or with credible roll-up to Category I SNM must be approved, in writing, by the Associate Administrator for Defense Nuclear Security or the Under Secretary for Energy, Science, and Environment.

Section 49

CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section G 4 (c) All modifications to survey frequency requirements must be documented in the Safeguards and Security Information Management System (SSIMS). b. Scope and Methodologies. Surveys and self-assessments must provide an integrated evaluation of all topical and subtopical areas to determine the overall status of the S&S program and ensure the objectives of this Section are met (see paragraph 1., above). The integrated evaluation is a comprehensive synergistic approach using multiple S&S program elements that ensures total system effectiveness and, if properly implemented, will meet the objectives identified in paragraph 1., above. The scope of these activities and the methods used must include those listed below. (1) Compliance. Compliance reflects the status of the S&S program as measured against implementation of applicable Federal statutes, regulations, policies, approved site safeguards and security plans (SSSPs)/site security plans (SSPs), and other approved security plans. (2) Performance. Performance indicates the degree to which the elements of the S&S program meet protection objectives based on the operational testing of program elements. (3) Comprehensiveness. Comprehensiveness identifies the breadth of protection afforded all activities and interests within a facility. This is accomplished by an evaluation of the adequacy and effectiveness of programs and a thorough examination of the implementation of policies, practices, and procedures to ensure compliance and performance. All applicable topical areas identified on DOE Form (F) 470.8, “Survey/Inspection Report” Form must be evaluated. (4) Other. The scope of special and termination surveys is determined by the DOE cognizant security authority in coordination with the surveying office. Determinations of survey scope are predicated on the nature or status of operations at the facility, activity, or element being surveyed. These surveys may not cover all topical areas identified on DOE F 470.8. 3. CONDUCT. Local survey and self-assessment procedures implementing this Section must be developed, documented, and approved by the cognizant security authority. Procedures must ensure completion of the objectives contained in paragraph 1., above and must include the requirements listed below. a. Team Composition. Survey and self-assessment team personnel must possess qualifications, experience, and training sufficient to review and inspect the topical/subtopical areas of the survey/self-assessment. The National Training Center (NTC) provides training courses for survey team leaders and team members. CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section G 5 (1) Survey teams must be led by a Federal employee and may be composed of Departmental Federal and contractor personnel. (2) Self-assessments must include at least one person from the cognizant security authority. b. Planning, Scheduling, and Integration. Surveys and self-assessments must be planned, scheduled, and conducted in an integrated manner to achieve the objectives identified in paragraph 1., above. If topical and subtopical area evaluations are performed separately, the surveying office must document and integrate the results of each into a single (periodic) survey report that includes a composite facility rating. The frequency between topical and subtopical areas cannot exceed the frequency for the single (periodic) survey.

Section 50

c. Validation. Results must be validated by methods including, but not limited to, document reviews, performance testing, and interview analyses and observations. d. Exit Briefing. An exit briefing must be conducted with the surveyed or assessed organization to include the minimum facts: (1) program strengths and weaknesses, including all findings; (2) corrective action reporting requirements for all open findings, regardless of source; and (3) topical and composite ratings. For less than satisfactory ratings, the communication of the composite rating initiates the actions required in paragraph 8. of this Section. 4. FINDINGS. a. Identification and Documentation. Findings are any validated program deficiency (failure to meet a performance or compliance requirement) regardless of source. Findings may be reflected in documents resulting from internal and external reviews, audits, appraisals, and other sources (e.g., the Office of Independent Oversight and Performance Assurance [OA], the Government Accountability Office [GAO], the Office of the Inspector General (IG), previous surveys, self assessments, etc.). All open findings must be reviewed during the survey or self-assessment to validate the status of corrective action and to evaluate the impact on the existing S&S program. Findings identified during the current survey or self-assessment must be reported immediately to the Departmental element and contractor line management if a vulnerability to national security, classified information or matter, nuclear materials, or Department property results, or may result, in a programmatic CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section G 6 impact to the Department. Findings identified during a survey or self-assessment, even if closed during the survey or self-assessment activity, must be documented in the associated report. b. Tracking. Findings and deficiencies, regardless of source, and corrective action plans (milestones and estimated completion dates) must be entered into SSIMS in accordance with SSIMS guidelines and tracked until closed. Quarterly status reports must be entered into SSIMS by January 15, April 15, July 15, and October 15, of each year. Self-assessment deficiencies are not required to be entered into SSIMS; however, a local mechanism/system must be used to track these deficiencies and corrective action until closed. c. Trending. Trending evaluations must be considered in the resolution of findings in the subtopical area of program management to determine if systemic and systematic causal factors exist within the S&S program. Results of this evaluation that indicate negative trends must be analyzed to ensure corrective action plans address root causes and the need to ensure continuous improvement of the S&S program. 5. RATINGS. a. Types. Ratings must be based on the effectiveness and adequacy of the program at a facility and reflect a balance of performance and compliance results as well as the impact of the deficiency(ies) (e.g., findings, IG recommendations, etc.) and mitigating factors. The ratings listed below must be used for all surveys (except termination), reviews, and self-assessments. Does Not Apply (DNA) and Not Rated (NR) may also be used in applicable situations. (1) Types of Ratings. (a) Satisfactory. The element being evaluated meets protection objectives or provides reasonable assurance that protection objectives are being met.

Section 51

(b) Marginal. The element being evaluated partially meets protection objectives or provides questionable assurance that protection objectives are being met. (c) Unsatisfactory. The element being evaluated does not meet protection objectives or does not provide adequate assurance that protection objectives are being met. (d) Inspection Ratings. “Effective Performance,” “Needs Improvement,” and “Significant Weaknesses” are indicators of a management system performance level as outlined in DOE O 470.2B, Independent Oversight and Assurance Program, dated 10- 31-02. CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section G 7 (2) Rating Determinations. (a) Existing Conditions. Ratings must be based on existing conditions at the end of the survey and not future or planned corrective actions or conditions. (b) Impact. Ratings must be based on the impact of all open deficiencies, regardless of source. (c) Marginal or Unsatisfactory Ratings. Less than satisfactory ratings in any topical area must be based on validated weaknesses in the S&S system or deficiencies in performance. (d) Topical Area Ratings. A topical area rating must not be marginal for consecutive survey periods and will be assigned an unsatisfactory rating unless one of the following conditions applies. 1 The current survey of the topical area results in a satisfactory rating. 2 The previous survey that resulted in a marginal rating identified different deficiencies and reasons for the rating. 3 The deficiencies and reasons that were the basis for the previous marginal rating were related to the completion of a line item construction project or upgrade program. In that case, acceptable interim measures must have been implemented, physically validated pending completion of the project, and documented in the survey report. (e) Subtopical Ratings. The decision whether or not to use all subtopical ratings must be documented in local procedures.2 Regardless of the rating method used, the report must include the evaluation of all required subtopical areas which must be used as part of the appropriate topical area rating justification and rationale. (f) Justification and Rationale. All ratings must be supported and documented to include the rating justification and rationale. 6. REPORT CONTENT. a. Initial/Periodic Survey Reports and Self-Assessment Reports. Reports must contain the following items. 2 A minimum of one subtopical area rating must be used to effect the rating for the topical area in SSIMS. CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section G 8 (1) A completed DOE F 470.8 (or equivalent for self-assessments). (2) An executive summary containing: (a) the scope, methodology, period of coverage, duration, date of the exit briefing to management; (b) a brief overview of the facility, function, scope of operations, and contractual information (e.g., contract number, award and expiration dates, contract type, identification of security clauses, identification of the security and overall scores assigned to the most recent contract appraisal); (c) a brief synopsis of major strengths and weaknesses that impact the effectiveness of the facility’s overall S&S program, including identification of any topical areas rated less than satisfactory; (d) the overall composite facility rating with supporting rationale; and (e) a reference to a list of findings identified during the survey or self- assessment. (3) An introduction containing:

Section 52

(a) the scope, methodology, period of coverage, duration, date of the exit briefing to management; and (b) a description of the facility, its function and scope of operations, security interests, and contractual information (e.g., contract number, award and expiration dates, contract type, identification of security clauses, identification of the security and overall scores assigned to the most recent contract appraisal). (4) Narrative for all rated topical and subtopical areas that includes: (a) a description of the site’s implementation of the program element; (b) the scope of the evaluation; (c) a description of activities conducted; (d) the evaluation results and associated issues (including other Department elements or OGA review or inspection results related to this topic/subtopic that were included in the survey); (e) the identification of all findings, including new and previously identified open findings, regardless of source (e.g., OA, IG, GAO), and their current corrective action status; and CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section G 9 (f) an analysis that provides a justification and rationale of the factors responsible for the rating. (5) Attachments, including: (a) a copy of the current DOE F 470.2, “Facility Data and Approval Record” (FDAR); (b) a listing of all active DOE F 470.1, “Contract Security Classification Specification” (CSCS), or DD F 254, “Contract Security Classification Specification;” (c) a listing of all new findings resulting from the survey/self- assessment; (d) a listing of all previous findings that are open, to include the current status of corrective action; (e) a listing of team members including names, employer, and their assigned area(s) of evaluation; and (f) a listing of all source documentation used to support the survey/self-assessment conduct and results (e.g., GAO, IG, OA, and similar assessment documents). b. Special Survey Reports. Special survey reports must follow the format and content for initial and periodic survey/self-assessment reports except that an executive summary is not required. Attachments must be included as appropriate to the scope of the special survey. c. Reports for Non-Possessing Facilities. Reports for non-possessing facilities must include: (1) a completed DOE F 470.8; (2) a copy of the DOE F 470.2 FDAR; (3) a list of each active DOE F 470.1 CSCS or DD F 254; (4) an evaluation of the foreign ownership, control, or influence (FOCI) status; (5) a determination that employees and subcontractors possess appropriate access authorizations; (6) a review to ensure that individuals no longer employed on the contract have had their access authorizations terminated and security badges have been accounted for; and CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section G 10 (7) other topical/sub-topical areas identified on DOE F 470.8 as required by the DOE cognizant security authority. d. Termination Survey Reports. Termination survey reports must include: (1) verification of non-possession of classified information or matter, SNM, hazardous material presenting a potential sabotage threat, or Government property; (2) verification that all DOE access authorizations have been terminated or transferred and that termination statements have been completed and security badges have been accounted for; (3) validation that all findings have been closed in SSIMS; (4) verification of termination of all S&S activities; (5) a copy of the terminating DOE F 470.2 FDAR; and

Section 53

(6) a completed certificate of non-possession. e. Memorandum Report Content. Memorandum reports for DOE programmatic entities and OGAs are generated when it is inappropriate to transmit a copy of the survey report due to need-to-know issues. Reports must contain: (1) a notification of inclusion of their activity in the survey; (2) the date of the survey; (3) ratings and rationale for the ratings associated with the activity; and (4) all findings applicable to that activity. 7. DISTRIBUTION. a. The surveying office must send a copy of the survey report to the appropriate Departmental elements and support offices, including the Office of Security. b. The surveying office must send any memorandum report to applicable DOE program offices and OGAs. c. Survey/memorandum reports must be distributed within 60 working days of the exit briefing. d. Self-assessment reports must be distributed to the applicable senior managers, personnel responsible for corrective actions, and other personnel, as deemed appropriate. CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section G 11 8. NOTIFICATIONS AND ACTIONS FOR LESS THAN SATISFACTORY SURVEY COMPOSITE RATINGS. When the survey composite ratings are less than satisfactory the following notifications and actions must occur. a. Marginal Ratings. Within 15 working days of the determination of a marginal composite rating, the DOE cognizant security authority must ensure SSIMS is updated and provide the applicable Departmental elements and OGAs with the following: (1) a statement identifying the vulnerabilities and the rationale for the rating; (2) description of the corrective action/compensatory measures taken to date; (3) a statement acknowledging physical validation of the adequacy of items listed in 8.a. (2), above. (4) If the surveying office is not the same as the DOE cognizant security authority, the surveying office must notify the DOE cognizant security authority of results prior to departure from the site. b. Unsatisfactory Ratings. Within 24 hours of determination of an overall composite rating of Unsatisfactory, the DOE cognizant security authority must coordinate with the Departmental element to take the following actions: (1) Suspend the activity and/or the Facility Clearance (FCL) pending remedial action. OR (2) Provide the justification for continuing this critical operation to the Office of Security, the Departmental element, and as directed, other applicable Department elements. In addition to providing the rationale, the DOE cognizant security authority must identify and evaluate those immediate interim corrective actions being undertaken to mitigate identified risks or vulnerabilities. NOTE: If the surveying office is not the same as the DOE cognizant security authority, the surveying office must notify the DOE cognizant security authority of the results immediately. If the surveying office is unable to contact the DOE cognizant security authority, action must be taken to protect activities until the DOE cognizant security authority can be notified. Subsequent action must be taken on the basis of agreement between the two organizations and must be fully documented in the survey report. 9. NOTIFICATIONS AND ACTIONS FOR LESS THAN SATISFACTORY SELF- ASSESSMENT COMPOSITE RATINGS. Actions required in response to less than satisfactory self-assessment composite ratings are listed below: CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section G 12

Section 54

a. Marginal Ratings. Within 15 working days of the determination of a marginal composite rating, notification must be made to line management that includes: (1) a statement identifying the vulnerability and rationale for the rating; (2) a description of the corrective action/compensatory measures taken to date; and (3) a statement acknowledging physical validation of the adequacy of items listed in paragraph 9.a. (2), above. b. Unsatisfactory Ratings. Within 24 hours of determination of an overall composite rating of unsatisfactory, the cognizant security authority must coordinate with the DOE cognizant security authority, which in turn must coordinate with the Departmental element to take the following actions: (1) suspend the activity and/or recommend suspension of the FCL pending remedial action; (2) provide justification for continuing operations to the DOE cognizant security authority. In addition to providing the rationale, the cognizant security authority must evaluate those immediate interim corrective actions being undertaken to mitigate identified risks or vulnerabilities; and (3) if the results of a self-assessment identify an incident of security concern; it must be reported in accordance with Section N. 10. CORRECTIVE ACTIONS. Corrective action plans must be developed for all open survey and self-assessment findings. Corrective action plans for survey and self- assessments must be submitted and reported within 30 working days after the date of the exit briefing. If a finding is corrected during the survey, it will be identified in the survey report with a description of the closure/validation performed by the survey/self- assessment team. Quarterly reports of the status of corrective actions for each finding must be provided to the DOE cognizant security authority. All survey and self- assessment corrective actions must: a. be based on documented root cause analyses, risk assessments, and cost-benefit analyses to ensure the survey/self-assessment program objectives are met (see paragraph 1., above); b. be reported, entered, tracked, and updated until completed, validated, and closed in SSIMS, where applicable (see paragraph 4.b., above). 11. UPGRADE OF COMPOSITE RATINGS. When line management determines that the composite rating should be upgraded, the survey/self-assessment team must physically verify the completion and adequacy of corrective actions and make notification of the rating upgrade in accordance with approved local procedures. CANCELE D DOE M 470.4-1 08-26-05 Part 1, Section G 13 12. RECORDS RETENTION. Documentation associated with the conduct of survey and self-assessments must be retained in accordance with approved procedures and appropriate records inventory disposition schedules. 13. CONTINUOUS IMPROVEMENT PROCESS. The cognizant security authority must conduct an annual evaluation of their survey or self-assessment processes. This evaluation must ensure any identified process improvements (i.e., lessons learned) are incorporated in the S&S survey/self-assessment process. CANCELE D DOE M 470.4-1 08-26-05 Part 2, Section H 1 PART 2 - SAFEGUARDS AND SECURITY MANAGEMENT SECTION H - FOREIGN OWNERSHIP, CONTROL, OR INFLUENCE PROGRAM 1. OBJECTIVE. To establish the Foreign Ownership, Control or Influence (FOCI) program requirements and criteria to facilitate the initial and continued facility clearance (FCL) eligibility of U.S. companies with foreign involvement. CANCELE D

Section 55

DOE M 470.4-1 08-26-05 Part 2, Section H I-1 CHAPTER I - GENERAL FOCI PROGRAM INFORMATION 1. GENERAL REQUIREMENTS. a. Evaluation and adjudication of FOCI compose an essential and critical ongoing element of the FCL program. A contractor cannot be under FOCI to such a degree that granting or continuing an FCL would be inconsistent with U.S. national security interests. An FCL may not be granted until all relevant aspects of FOCI have been resolved and, if necessary, favorably adjudicated. If a company with an existing FCL is determined to be under FOCI, the FCL must be suspended or terminated unless security measures are taken to remove the possibility of unauthorized access or adverse impacts to classified contract performance.3 b. The determination of whether a U.S. company is under FOCI, its eligibility for an FCL, and the security measures deemed necessary to negate FOCI impacts must be made on a case-by-case basis. The following factors must be considered in the aggregate to determine whether a company is under FOCI, is eligible for an FCL, and the protective measures required: (1) foreign intelligence threat; (2) risk of unauthorized technology transfer; (3) type and sensitivity of classified information or matter, or special nuclear material (SNM); (4) nature, source, and extent of FOCI, including identification of immediate, intermediate, and ultimate parent organizations; (5) record of compliance with pertinent laws, regulations, and contracts; and (6) nature of bilateral and multilateral security and information exchange agreements that may be relevant. c. Development of security measures to mitigate the impact of unacceptable FOCI must be based on the concept of risk management. DOE has the obligation to impose any security method, safeguard, or restriction it believes necessary to ensure that unauthorized access to classified information or matter, or SNM is effectively precluded and the performance of classified contracts is not adversely affected. d. Changed conditions, such as a change in ownership, indebtedness, or foreign intelligence threat, may justify certain adjustments to the security requirements under which a company is operating or require that a different FOCI mitigation 3 Classified contract is defined as any contract, license, or other agreement requiring access authorizations. CANCELE D DOE M 470.4-1 08-26-05 Part 2, Section H I-2 method be used. A changed condition may result in a determination that a company is no longer considered to be under FOCI or, conversely, that a company is no longer eligible for an FCL. 2. APPLICABILITY. a. The entities4 listed below are required to obtain FOCI determinations. (1) Applicants, including industrial, educational, commercial, or any other entity, grantee, or licensee, including an individual, that have or anticipate executing a classified contract. This includes subcontractors of any tier, consulting firms, agents, grantees, and cooperative research and development agreement participants who require access authorizations. (2) All tier parents located in the U.S., Puerto Rico, or a U.S. possession or trust territory b. A FOCI determination is not required for an individual performing work under a consulting agreement (e.g., an individual awarded a contract).5 This does not include individuals contracting as a business.

Section 56

c. When the applicant is a local, state, or Federal agency or department, the contract must contain a security clause. The security clause must state that if the government agency or department subcontracts any work requiring access to classified information or matter by a commercial entity, its acquisition regulation, including FOCI policies, must be followed. If the government agency or department does not have its own FOCI policies or an agreement with the Secretary of Defense for industrial security services, DOE will render the FOCI determination. d. When contracts involve access to SNM, DOE will render the FOCI determination. e. Contractors with existing U.S. Government FCLs are identified in Safeguards and Security Information Management System (SSIMS) and the Department of Defense (DoD) Defense Security Service/Central Verification Activity System (DSS/CVA). f. No further FOCI review is required for an applicant holding an equal or higher U.S. Government FCL, based upon a favorable FOCI determination. g. Information submitted with a FOCI package is used for the sole purpose of evaluating FOCI and must be treated by DOE, to the extent permitted by law, as business/financial information submitted in confidence. The information must be protected as Official Use Only (OUO). 4 The entities listed are referred to as “applicants” throughout this Section. 5 The self-employed individual’s or consultant’s foreign involvement is determined through the background investigation conducted to determine the individual’s eligibility for an access authorization. CANCELE D DOE M 470.4-1 08-26-05 Part 2, Section H I-3 h. Personnel responsible for the FOCI program can successfully meet FOCI competencies through training courses offered at the National Training Center (NTC). 3. CONTRACT AWARD MUST NOT BE MADE PRIOR TO FCL ISSUANCE. The DOE Acquisition Regulation (DEAR) prohibits the award of a classified contract until an FCL has been granted. When an existing contract that does not require access authorizations is modified to require access authorizations, the contract modification cannot take effect until an FCL is granted. Contract award/modification cannot be made until: a. all relevant aspects of FOCI have been resolved and, if necessary, are favorably adjudicated; b. the signed DOE F 470.1, “Contract Security Classification Specification” (CSCS) is accepted by the cognizant security authority; and c. the appropriate DEAR security clauses have been incorporated in the contract. 4. ELECTRONIC SUBMISSION/PROCESSING WEB SITE. The Department has an electronic system for applicants to submit FOCI information to DOE in an electronic format. To ensure confidentiality of the information submitted and stored on the system, the site is protected with 128-bit encryption. a. Applicants may use this system for the submission of FOCI packages, including changes to update their FOCI information. The FOCI web site maybe accessed via an Internet browser at https://foci.td.anl.gov. Electronic signatures are not accepted; therefore a signed original SF 328, “Certificate Pertaining to Foreign Interests,” executed in accordance with the instructions on the certification section of the SF 328, must be submitted to the DOE cogniza

Something wrong with this record? Tell us