DOE M 470.4-1, Safeguards and Security Program Planning and Management
Functional areas: Program Planning and Management, Safeguards, Security, and Emergency Management, Work Processes
Establishes program planning and management requirements for the Departments Safeguards and Security (S&S) Program.
Cancels: DOE N 473.9 and DOE M 470.1-1
Supersedes:
DOE M 470.1-1, Safeguard Security and Awareness Program on Aug 26, 2005
DOE N 473.9, Security Conditions on Aug 26, 2005
Superseded By:
Version history and related documents
Superseded by
A newer version replaces this document.
Supersedes
Earlier documents this one replaced.
- DOE M 470.1-1Safeguard Security and Awareness Program (Aug 26, 2005)
- DOE N 473.9Security Conditions (Aug 26, 2005)
Document text
Text extracted from the attached file. Refer to the original document for the authoritative version.
Section 1
AVAILABLE ONLINE AT: INITIATED BY:
www.directives.doe.gov Office of Security and Safety
Performance Assurance
Approved: 08-26-05
Review: 08-26-07
SAFEGUARDS AND SECURITY
PROGRAM PLANNING AND
MANAGEMENT
U.S. DEPARTMENT OF ENERGY
Office of Security and Safety Performance Assurance
DOE M 470.4-1
CANCELE
D
DOE M 470.4-1
08-26-05
1
SAFEGUARDS AND SECURITY PROGRAM PLANNING AND MANAGEMENT
1. PURPOSE. To establish program planning and management requirements for the
Department’s Safeguards and Security (S&S) Program.
2. OBJECTIVES.
a. Effect the policy in DOE P 470.1, Integrated Safeguards and Security
Management (ISSM) Policy, by integrating program planning and management
into Department of Energy (DOE) operations as determined by line management,
and according to sound risk management practices. (DOE P 470.1, Integrated
Safeguards and Security Management [ISSM] Policy, is the Department’s
philosophical approach to the management of the S&S Program. A principal
objective of the ISSM Program is to integrate S&S into management and work
practices at all levels, based on program line management’s risk management-
based decisions, so that missions may be accomplished without security events,
such as interruption, disruption or compromise. This approach includes
individual responsibility and implementation of the security requirements found
in this Manual.)
b. Establish individual responsibilities to fulfill the requirements in this Manual.
c. Establish requirements for S&S planning and evaluations.
d. Establish requirements for S&S management.
e. Promulgate the requirements of the National Industrial Security Program.
3. PROGRAM INTEGRATION. S&S program planning and management must be
integrated with other programs such as physical protection, protective force (PF),
information security, personnel security, and nuclear material control & accountability
(MC&A). Mechanisms must also exist to assure that S&S program planning is fully
integrated with overall site strategic and near-term operational planning. Additionally,
the activities and requirements in the weapons surety, foreign visits and assignments,
safety, emergency management, cyber security, and intelligence and counterintelligence
programs should also be considered in the implementation of this Manual.
4. CANCELLATIONS. The directives listed below are canceled. Cancellation of a
directive does not by itself modify or otherwise affect any contractual obligation to
comply with the directive. Canceled directives that are incorporated by reference in a
contract remain in effect until the contract is modified to delete the reference to the
requirements in the canceled directives. The publication of this Manual incorporates or
cancels all previous memoranda or letters that were issued by the Office of Security or its
predecessor organizations that established policy.
CANCELE
D
DOE M 470.4-1
08-26-05
2
a. DOE N 473.9, Security Conditions, dated 7-8-04.
b. DOE M 470.1-1, Safeguards and Security Awareness Program, dated 10-02-02.
5. APPLICABILITY.
a. Departmental Elements. Except for the exclusion in paragraph 5.c., this Manual
applies to all Departmental elements, listed on Attachment 1. This Manual
automatically applies to Departmental elements created after it is issued.
The Administrator of the National Nuclear Security Administration (NNSA) will
assure that NNSA employees and contractors comply with their respective
responsibilities under this Manual.
Section 2
b. Contractors.
(1) The Contractor Requirements Document (CRD), Attachment 2, sets forth
requirements of this Manual that will apply to site/facility management
contracts that include the CRD.
(2) The CRD must be included in the site/facility management contracts that
involve classified information or matter, or nuclear materials and contain
DOE Acquisition Regulation (DEAR) clause 952.204-2, titled Security
Requirements.
(a) Departmental elements must notify contracting officers of affected
site/facility management contracts to incorporate this directive into
those contracts.
(b) Once notified, contracting officers are responsible for
incorporating this directive into the affected contracts via the
Laws, Regulations, and DOE Directives clause of the contracts.
(3) A violation of the provisions of the CRD relating to the safeguarding or
security of Restricted Data or other classified information may result in a
civil penalty pursuant to subsection a. of section 234B, of the Atomic
Energy Act of 1954 (42 U.S.C. 228b.). The procedures for the assessment
of civil penalties are set forth in Title 10, Code of Federal Regulations
(CFR), Part 824, Procedural Rules for the Assessment of Civil Penalties
for Classified Information Security Violations, (10 CFR Part 824).
(4) As stated in DEAR clause 970.5204-2, titled Laws, Regulations, and DOE
Directives, regardless of the performer of the work, site/facility
contractors with the CRD incorporated into their contracts are responsible
for compliance with the CRD. Affected site/facility management
contractors are responsible for flowing down the requirements of the CRD
to subcontracts at any tier to the extent necessary to ensure compliance
CANCELE
D
DOE M 470.4-1
08-26-05
3
with the requirements. In doing so, contractors must not unnecessarily or
imprudently flow down requirements to subcontracts. That is, contractors
must both ensure that they and their subcontractors comply with the
requirements of this CRD and incur only costs that would be incurred by a
prudent person in the conduct of competitive business.
(5) This Manual does not automatically apply to other than site/facility
management contracts. Application of any of the requirements in this
Manual to other than site/facility management contracts will be
communicated as follows.
(a) Heads of Field Elements and Headquarters Departmental
Elements. Review procurement requests for new non-site/facility
management contracts that involve classified information or
matter, or nuclear materials and contain DEAR clause 952.204-2,
titled Security Requirements. If appropriate, ensure that the
requirements of the CRD of this Manual are included in the
contract.
(b) Contracting Officers. Assist originators of procurement requests
who want to incorporate the requirements of the CRD of this
Manual in new non-site/facility management contracts, as
appropriate.
c. Exclusion. In accordance with the responsibilities and authorities assigned by
Executive Order 12344 and to ensure consistency throughout the joint Navy and
DOE organization of the Naval Nuclear Propulsion Program, the Deputy
Administrator for Naval Reactors will implement and oversee all requirements
and practices pertaining to this Manual for activities under the Deputy
Administrator’s cognizance.
d. Exemption.
Section 3
(1) Requirements in this Manual that overlap or duplicate requirements of the,
Nuclear Regulatory Commission (NRC) related to radiation protection,
nuclear safety (including quality assurance), and safeguards and security
of nuclear material, do not apply to the design, construction, operation,
and decommissioning of the Office of Civilian Radioactive Waste
Management (RW) facilities.
(2) This exemption does not apply to requirements for which the NRC defers
to DOE or does not exercise regulatory jurisdiction.
6. DEVIATIONS. Deviations from requirements must be processed in accordance with
Section M.
7. DEFINITIONS. Terms commonly used in the program are defined in the S&S Glossary
CANCELE
D
DOE M 470.4-1
08-26-05
4
located in DOE M 470.4-7, Safeguards and Security Program References. In addition to
those in the Glossary, the following definitions are provided for use in this Manual.
a. DOE line management refers to DOE and NNSA Federal employees who have
been granted the authority to commit resources or direct the allocation of
personnel or approve implementation plans and procedures in the accomplishment
of specific work activities.
b. Line management refers to DOE and NNSA Federal and contractor employees
who have been granted the authority to commit resources or direct the allocation
of personnel or approve implementation plans and procedures in the
accomplishment of specific work activities.
c. DOE cognizant security authority refers to DOE and NNSA Federal employees
who have been granted the authority to commit security resources or direct the
allocation of security personnel or approve security implementation plans and
procedures in the accomplishment of specific work activities.
d. Cognizant security authority refers to DOE and NNSA Federal and contractor
employees who have been granted the authority to commit security resources or
direct the allocation of security personnel or approve security implementation
plans and procedures in the accomplishment of specific work activities.
e. For the purposes of this Manual, the Office of Security refers to the DOE Office
of Security, Office of Security and Safety Performance Assurance.
8. IMPLEMENTATION. Requirements that cannot be implemented within 6 months of the
effective date of this Manual or within existing resources must be documented by the
cognizant security authority and submitted to the relevant program officers: the Under
Secretary for Energy, Science and Environment or the Under Secretary for Nuclear
Security/Administrator, NNSA; and the Office of Security. The documentation must
include timelines and resources needed to fully implement this Manual. The
documentation must also include a description of the vulnerabilities and impacts created
by the delayed implementation of the requirements.
9. CONTACT. Questions concerning this Manual should be directed to the Office of
Security at (202) 586-3345.
BY ORDER OF THE SECRETARY OF ENERGY:
CLAY SELL
Deputy Secretary
CANCELE
D
DOE M 470.4-1
08-26-05
i
CONTENTS
PART 1 PLANNING AND EVALUATIONS
SECTION A – SAFEGUARDS AND SECURITY PROGRAM PLANNING
1. OBJECTIVE ........................................................................................................................1
2. REQUIREMENTS...............................................................................................................1
3. PLANNING .........................................................................................................................3
Section 4
APPENDIX 1 – SAFEGUARDS AND & SECURITY MANAGEMENT PLAN
1. EXECUTIVE SUMMARY ............................................................................ Appendix 1-1
2. PART 1 – ORGANIZATIONAL STRUCTURE AND
ACCOUNTABILITY ................................................................................... Appendix 1-1
3. PART 2 – ROLES, RESPONSIBILITIES, DELEGATIONS,
AND AUTHORITIES .................................................................................. Appendix 1-2
4. PART 3 – S&S PROGRAM IMPLEMENTATION ...................................... Appendix 1-2
5. PART 4 – PLANNING AND BUDGET (INCLUDING PERSONNEL
RESOURCES) .............................................................................................. Appendix 1-3
SECTION B – SECURITY CONDITIONS
1. OBJECTIVE ........................................................................................................................1
2. THREAT INDICATORS.....................................................................................................1
3. SECURITY CONDITIONS.................................................................................................2
SECTION C – SITE SAFEGUARDS AND SECURITY PLANS
1. OBJECTIVE ........................................................................................................................1
2. APPLICATION ...................................................................................................................1
3. SCOPE .................................................................................................................................1
4. PURPOSE............................................................................................................................1
5. PLAN COMPOSITION.......................................................................................................1
6. EVIDENCE FILES..............................................................................................................2
7. DATA COLLECTION ........................................................................................................2
CANCELE
D
DOE M 470.4-1
08-26-05
ii
8. FORMAT.............................................................................................................................2
SECTION C – TABLES
Table C-1. SNM Theft/Diversion Targets ....................................................................................6
Table C-2. Radiological Sabotage Targets ...................................................................................6
Table C-3. Biological/Chemical Sabotage Targets.......................................................................7
Table C-4. Disruption of Critical Mission Targets .......................................................................7
Table C-5. Site-Wide Protection Strategies..................................................................................8
Table C-6. Facility Protection Systems ........................................................................................9
Table C-7. Qualification and Training........................................................................................10
Table C-8. MC&A Plans and Procedures ...................................................................................11
Table C-9. Personnel Security/Human Reliability Program Implementation ............................12
Section 5
Table C-10. Automated Information Systems Security Programs................................................13
Table C-11. S&S-Related Maintenance, Testing and Records Management Programs ..............14
Table C-12. Site Protection Program Evaluation Program...........................................................15
Table C-13. Deviations from DOE Directives..............................................................................15
Table C-14. Pending Deviations from DOE Directives ...............................................................15
Table C-15. Summary of Identified Risks ....................................................................................17
Table C-16. SNM Theft/Diversion Targets ..................................................................................18
Table C-17. Credible Radiological Sabotage Targets ..................................................................19
Table C-18. Credible Biological Sabotage Targets ......................................................................19
Table C-19. Credible Chemical Sabotage Targets........................................................................20
Table C-20. Disruption of Critical Mission Targets .....................................................................20
Table C-21. Performance Testing Results of Site-Specific
Essential Protection Element Values .....................................................................21
Table C-22. Critical Path Scenarios..............................................................................................22
Table C-23. Protection Effectiveness (PE) for Theft or Diversion of SNM .................................24
CANCELE
D
DOE M 470.4-1
08-26-05
iii
Table C-24. Protection Effectiveness (PE) for Radiological Sabotage .........................................24
Table C-25. Protection Effectiveness (PE) for Biological Sabotage.............................................25
Table C-26. Protection Effectiveness (PE) for Chemical Sabotage ..............................................25
Table C-27. Protection Effectiveness (PE) for Disruption of Critical Missions ...........................25
Table C-28. Protection Effectiveness (PE) for Theft or Espionage of Classified Matter .............26
Table C-29. Protection Effectiveness (PE) for Other Losses ........................................................26
Table C-30. System Effectiveness Summary................................................................................26
SECTION D – SITE SAFEGUARDS AND SECURITY PLAN/RESOURCE PLAN
1. OBJECTIVE ........................................................................................................................1
2. UNFUNDED/UNSUPPORTED REQUIREMENTS..........................................................5
3. REFERENCES FOR THE RESOURCE PLAN..................................................................5
4. HEADINGS AND TERMS FOR TABLES D-1 THROUGH D-5 .....................................5
SECTION D – TABLES
Table D-1. Operational Requirements ............................................................................................1
Table D-2. Capital Equipment ........................................................................................................2
Table D-3. General Plant Projects ..................................................................................................3
Section 6
Table D-4. Line Item Construction Projects ...................................................................................4
Table D-5. Unfunded/Unsupported Requirements .........................................................................4
SECTION E – VULNERABILITY ASSESSMENT PROGRAM
1. OBJECTIVE ........................................................................................................................1
2. CONDUCTING VULNERABILITY ASSESSMENTS .....................................................1
3. QUALITY ASSURANCE ...................................................................................................3
4. VULNERABILITY ASSESSMENT DOCUMENTATION...............................................3
5. ASSIGNING FIGURES OF MERIT...................................................................................3
6. CRITICAL SYSTEM ELEMENTS ....................................................................................4
7. VULNERABILITY ASSESSMENT REPORTS ................................................................4
CANCELE
D
DOE M 470.4-1
08-26-05
iv
8. SYSTEM EFFECTIVENESS..............................................................................................4
9. TRAINING AND CERTIFICATION .................................................................................6
APPENDIX 2 – VULNERABILITY ASSESSMENT MODELING TOOLS........... Appendix 2-1
APPENDIX 3 – SYSTEM PERFORMANCE EFFECTIVENESS EQUATION ...... Appendix 3-1
APPENDIX 4 – SUGGESTED VULNERABILITY ASSESSMENT REPORT
FORMAT ....................................................................................................... Appendix 4-1
SECTION F – PERFORMANCE ASSURANCE PROGRAM
1. OBJECTIVE ........................................................................................................................1
2. REQUIREMENTS...............................................................................................................1
SECTION G – SURVEY, REVIEW, AND SELF-ASSESSMENT PROGRAMS
1. OBJECTIVES......................................................................................................................1
2. REQUIREMENTS...............................................................................................................1
3. CONDUCT ..........................................................................................................................4
4. FINDINGS...........................................................................................................................5
5. RATINGS ............................................................................................................................6
6. REPORT CONTENT...........................................................................................................7
7. DISTRIBUTION................................................................................................................10
8. NOTIFICATIONS AND ACTIONS FOR LESS THAN SATISFACTORY
SURVEY COMPOSITE RATINGS................................................................................11
9. NOTIFICATIONS AND ACTIONS FOR LESS THAN SATISFACTORY SELF-
ASSESSMENT COMPOSITE RATINGS ........................................................................11
10. CORRECTIVE ACTIONS ................................................................................................12
11. UPGRADE OF COMPOSITE RATINGS.........................................................................12
Section 7
12. RECORDS RETENTION..................................................................................................13
13. CONTINUOUS IMPROVEMENT PROCESS.................................................................13
PART 2 – SAFEGUARDS AND SECURITY MANAGEMENT
SECTION H – FOREIGN OWNERSHIP, CONTROL, OR INFLUENCE PROGRAM
CANCELE
D
DOE M 470.4-1
08-26-05
v
1. OBJECTIVE ........................................................................................................................1
CHAPTER I, GENERAL FOCI PROGRAM INFORMATION
1. GENERAL REQUIREMENTS ........................................................................................I-1
2. APPLICABILITY.............................................................................................................I-2
3. CONTRACT AWARD MUST NOT BE MADE PRIOR TO FCL ISSUANCE.............I-3
4. ELECTRONIC SUBMISSION/PROCESSING WEB SITE............................................I-3
CHAPTER II, FOCI ACTIVITIES
1. DETERMINING THE SECURITY REQUIREMENTS OF THE
CONTRACT/AGREEMENT ......................................................................................... II-1
2. DETERMINING THE FCL STATUS OF THE APPLICANT...................................... II-1
3. ACCEPTING A FOCI DETERMINATION RENDERED BY
ANOTHER FEDERAL AGENCY................................................................................. II-1
4. CLASSIFIED CONTRACT ........................................................................................... II-1
5. ADJUDICATION........................................................................................................... II-3
6. COMMITTEE ON FOREIGN INVESTMENT IN THE UNITED STATES................ II-6
CHAPTER III, REPORTING REQUIREMENTS
1. FOCI CHANGES OCCUR FOLLOWING SUBMISSION OF AN SF 328 AND
BEFORE CONTRACT AWARD.................................................................................. III-1
2. UPDATES...................................................................................................................... III-1
3. ANNUAL CERTIFICATION ....................................................................................... III-3
CHAPTER IV, FOCI MITIGATION ACTION PLANS
1. GENERAL..................................................................................................................... IV-1
2. MITIGATION ACTION PLANS.................................................................................. IV-1
3. FOREIGN OWNERSHIP.............................................................................................. IV-1
4. ANNUAL COMPLIANCE MEETING....................................................................... IV-11
5. NON-COMPLIANCE WITH MITIGATION PLANS................................................ IV-11
APPENDIX 5 – FOCI MATRIX CHART ................................................................ Appendix 5-1
CANCELE
D
DOE M 470.4-1
08-26-05
vi
SECTION I – FACILITY CLEARANCES AND REGISTRATION OF SAFEGUARDS
AND SECURITY ACTIVITIES
1. OBJECTIVE ........................................................................................................................1
CHAPTER I – FCL PROGRAM
1. GENERAL........................................................................................................................I-1
2. EXCEPTIONS TO REGISTRATION IN SSIMS............................................................I-3
CHAPTER II – IMPORTANCE RATINGS
Section 8
1. FACILITY IMPORTANCE RATINGS ......................................................................... II-1
2. UPGRADING AND DOWNGRADING A FACILITY’S ASSIGNED
IMPORTANCE RATING ............................................................................................ II-2
CHAPTER III – ORGANIZATIONAL STRUCTURES AND FCLs
1. FCL FOR SINGLE LEGAL ENTITIES........................................................................ III-1
2. PARENT – SUBSIDIARY RELATIONSHIP .............................................................. III-2
CHAPTER IV – INTERIM AND LIMITED FCLs
1. INTERIM FCL............................................................................................................... IV-1
2. LIMITED FCL............................................................................................................... IV-1
CHAPTER V – ACCESS AUTHORIZATIONS AND EXCLUSION PROCEDURES
REQUIRED IN CONNECTION WITH FCLs
1. ACCESS AUTHORIZATIONS REQUIRED IN CONNECTION WITH THE
FCL ............................................................................................................................ V-1
2. MFOs .............................................................................................................................. V-1
3. ACCESS AUTHORIZATIONS CONCURRENT WITH THE FCL............................. V-1
4. EXCLUSION PROCEDURES....................................................................................... V-2
CHAPTER VI – FACILITY CLEARANCE
1. REQUIREMENTS.........................................................................................................VI-1
2. ISSUANCE OF FCLs ....................................................................................................VI-2
3. CHANGED CONDITIONS AFFECTING THE FCL...................................................VI-2
4. INTERFACE WITH FOCI REQUIREMENTS ............................................................VI-2
CANCELE
D
DOE M 470.4-1
08-26-05
vii
CHAPTER VII – PROCESS FOR FCL AND SECURITY ACTIVITY REGISTRATION
1. ACCEPTING OGA FCLs.............................................................................................VII-1
2. OGA VERIFICATION REQUESTS............................................................................VII-5
3. REGISTERING OGA FCLs.........................................................................................VII-5
4. REGISTRATION OF OGA CONTRACTORS IN SSIMS..........................................VII-6
5. REGISTERING WORK FOR OTHERS (WFO) ACTIVITIES ..................................VII-6
6. REGISTRATION OF DOE FCLs ................................................................................VII-7
7. REGISTRATION OF SECURITY ACTIVITIES......................................................VII-10
SECTION J – SAFEGUARDS AND SECURITY TRAINING PROGRAM
1. OBJECTIVE ........................................................................................................................1
2. REQUIREMENTS...............................................................................................................1
SECTION K – SAFEGUARDS AND SECURITY AWARENESS PROGRAM
1. OBJECTIVE ........................................................................................................................1
2. REQUIREMENTS...............................................................................................................1
Section 9
3. PROGRAM DESIGN AND DEVELOPMENT..................................................................1
4. BRIEFINGS.........................................................................................................................1
5. CLASSIFIED INFORMATION NONDISCLOSURE AGREEMENT (SF-312)...............5
6. SUPPLEMENTARY AWARENESS ACTIVITIES ...........................................................6
SECTION L – CONTROL OF CLASSIFIED VISITS PROGRAM
1. OBJECTIVE ........................................................................................................................1
2. REQUIREMENTS...............................................................................................................1
APPENDIX 6 – ACCESS TO RESTRICTED DATA IN POSSESSION
OF OTHER FEDERAL AGENCIES ........................................................................ Appendix 6-1
SECTION M – DEVIATIONS
1. OBJECTIVE ........................................................................................................................1
2. REQUIREMENTS...............................................................................................................1
CANCELE
D
DOE M 470.4-1
08-26-05
viii
SECTION M - TABLES
Table M-1. Deviation Approval Process ........................................................................................1
APPENDIX 7 – FORMAT FOR DEVIATION REQUESTS ................................... Appendix 7-1
SECTION N – INCIDENTS OF SECURITY CONCERN
1. OBJECTIVE ........................................................................................................................1
2. REQUIREMENTS...............................................................................................................1
CHAPTER I – IDENTIFICATION AND REPORTING REQUIREMENTS
1. GENERAL........................................................................................................................I-1
2. INCIDENT IDENTIFICATION AND CATEGORIZATION.........................................I-1
3. REPORTING REQUIREMENTS ....................................................................................I-8
4. INQUIRY OFFICIALS ..................................................................................................I-14
5. FEDERAL, STATE, OR LOCAL LAW ENFORCEMENT PERSONNEL..................I-15
6. CONDUCT OF INQUIRIES ..........................................................................................I-16
7. INQUIRY REPORT CONTENT/CLOSURE CONSIDERATIONS.............................I-19
8. ADMINISTRATIVE ACTIONS ....................................................................................I-21
9. RECORDS RETENTION...............................................................................................I-21
SECTION N – TABLES AND FIGURES
Table N-1. Reportable Categories of Incidents of Security Concern, Impact
Measurement Index 1 (IMI-1) ....................................................................................................3
Table N-2. Reportable Categories of Incidents of Security Concern, Impact
Measurement Index 2 (IMI-2) ....................................................................................................4
Table N-3. Reportable Categories of Incidents of Security Concern, Impact
Measurement Index 3 (IMI-3) ....................................................................................................5
Section 10
Table N-4. Reportable Categories of Incidents of Security Concern, Impact
Measurement Index 4 (IMI-4) ....................................................................................................7
Figure 1. Incidents of Security Concern ....................................................................................I-10
Figure 2. Example Chain of Custody Form...............................................................................I-17
CANCELE
D
DOE M 470.4-1
08-26-05
ix
CHAPTER II, INCIDENTS OF SECURITY CONCERN INVOLVING COMPROMISE OR
POTENTIAL COMPROMISE OF CLASSIFIED INFORMATION
1. INQUIRIES INTO COMPROMISE OF POTENTIAL COMPROMISE OF, OR
MISSING CLASSIFIED INFORMATION ................................................................... II-1
2. DAMAGE ASSESSMENTS .......................................................................................... II-2
3. CONDUCT OF DAMAGE ASSESSMENTS................................................................ II-3
4. PROCEDURES............................................................................................................... II-3
5. CONTENT OF DAMAGE ASSESSMENT REPORTS ................................................ II-3
6. COMBINING SIMILAR INCIDENTS.......................................................................... II-4
7. CASES INVOLVING OTHER GOVERNMENT AGENCY INFORMATION........... II-4
8. CASES INVOLVING FOREIGN GOVERNMENT INFORMATION ........................ II-4
9. JOINT DAMAGE ASSESSMENT WITH ANOTHER GOVERNMENT
AGENCY...................................................................................................................... II-5
SECTION O – RESTRICTIONS ON THE TRANSFER OF SECURITY-FUNDED
TECHNOLOGIES OUTSIDE THE DEPARTMENT AND ITS OPERATIONAL
FACILITIES
1. OBJECTIVE ........................................................................................................................1
2. REQUIREMENTS...............................................................................................................1
APPENDIX 8 – TECHNOLOGY TRANSFER
Approval Requests ...................................................................................................... Appendix 8-1
ATTACHMENTS
Attachment 1 Departmental Elements to which DOE M 470.4-1 Applies.............Attachment 1-1
Attachment 2 Contractor Requirements Document ...............................................Attachment 2-1
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section A
1
PART 1 - PLANNING AND EVALUATIONS
SECTION A - SAFEGUARDS AND SECURITY PROGRAM PLANNING
1. OBJECTIVE. To establish a standardized approach for protection program planning that
will provide an information baseline for use in integrating Departmental safeguards and
security (S&S) considerations, facilitating management evaluation of program elements,
determining resources for needed improvements, and establishing cost-benefit bases for
analyses and comparisons.
2. REQUIREMENTS. The following are essential elements for planning for S&S
programs.
a. S&S Philosophy. S&S interests and activities must be protected from theft,
diversion, terrorist attack, industrial sabotage, radiological sabotage, chemical
sabotage, biological sabotage, espionage, unauthorized access, compromise, and
other acts that may have an adverse impact on national security; the environment;
or pose significant danger to the health and safety of Department of Energy
(DOE) Federal and contractor employees or the public.
Section 11
b. S&S Management Plan. This Plan must provide a description of the
implementation of S&S policy and provide detailed information on the
assignment of roles, responsibilities, and authorities, as well as the development
of budgets and allocation of resources. The S&S Management Plan must be
updated annually (at least every 12 months) and must document:
(1) roles, responsibilities, delegations, and authorities for the S&S program;
(2) organizational structure and accountability; and
(3) planning and budget (including personnel resources).
See Appendix 1, S&S Management Plan, for content requirements and suggested
format. However, if a Functions, Responsibilities, and Authorities Manual for
S&S has been approved and issued, and it meets the requirements stated above, it
can be used in place of a S&S Management Plan.
c. S&S Program Operations. Actions must be taken to ensure an acceptable S&S
program, including curtailment or suspension of operations when such operations
would result in an immediate and unacceptable impact to national security, the
environment, or the health and safety of the public or employees.
(1) Site-Specific Characterization. Protection programs must be tailored to
address specific site characteristics and requirements, current technology,
ongoing programs, and operational needs to achieve acceptable protection
levels that reduce risks in a cost-effective manner.
CANCELE
D
DOE M 470.4-1
08-26XX-05
Part 1, Section A
2
(2) Threat Policy/Guidance. DOE O 470.3, Design Basis Threat (DBT)
Policy must be used with local threat guidance during the conduct of
vulnerability assessments (VAs) for protection and control program
planning. The DBT must be the baseline threat definition but local threat
guidance may be used to increase the level of threat to be analyzed.
(3) Targeted Protection Strategies.
(a) Strategies for the physical protection of special nuclear materials
(SNM) and vital equipment must incorporate the applicable
requirements established in DOE M 470.4-2, Physical Protection.
(b) Protection strategies must be implemented as specified in the DBT.
(c) Protection program elements must be designed to prevent and/or
mitigate the consequences of acts of radiological, chemical, or
biological sabotage that would cause unacceptable impact to
national security, the environment, or the health and safety of the
public or employees.
(d) Strategies for the protection and control of classified information
or matter must incorporate the applicable requirements established
in DOE M 470.4-4, Information Security.
(e) Security systems must be used that prevent, detect, or deter
unauthorized access, modification, or loss of classified and
unclassified controlled matter and its unauthorized removal from a
site or facility.
(f) Strategies for the protection of government property not covered
above must reflect a graded approach. DOE offices, facilities, and
property protection areas (PPAs) must meet or exceed General
Services Administration (GSA) minimum security standards.
(g) Security countermeasures for explosive threats must address a
range of activities including hand-carried, mailed, and
vehicle-transported devices.
Section 12
d. Graded Protection. The Department recognizes that risks must be accepted
(i.e., that actions cannot be taken to reduce the potential for or consequences of
all malevolent events to zero); however, an acceptable level of risk must be
determined based on evaluation of a variety of facility-specific goals and
considerations. By a graded approach, the Department intends that the highest
level of protection be given to security interests and activities whose loss, theft,
compromise, and/or unauthorized use would seriously affect the national security,
the environment, Departmental programs, and/or the health and safety of the
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section A
3
public or employees. Protection of other interests and activities must be graded
accordingly.
e. Risk Management. S&S programs must be based on the results of vulnerability
and risk assessments, the results of which are used to design and provide graded
protection in accordance with an asset’s importance or the impact of its loss,
destruction, or misuse. The results of the assessments, to include the
determination of system effectiveness, are one of the key considerations the
manager must evaluate when establishing the level of risk. For example, if it is
determined that there is high risk that is not being mitigated by compensatory
measures, reporting must be made to the Secretary of Energy or the Deputy
Secretary who can accept high risk. Cognizant Under Secretaries can accept
moderate risk.
(1) Vulnerability and risk assessments must be conducted and documented to
support the identification of risks to be accepted by the Department.
(2) To determine the appropriate level of protection against risk, line
management must consider the threat, the vulnerability of the potential
target, and the potential consequences of an adversarial act.
f. Site-Specific Programs.
(1) S&S programs must address site-specific characteristics.
(2) Performance assurance programs must be developed, managed, and
implemented to ensure that S&S programs and protection program
elements protect security interests and activities.
(3) A management and planning process to achieve integrated, site-specific
protection from unauthorized actions must be implemented. This process
must be based on a graded approach that implements the integrated
concepts of deterrence, prevention, detection, and response.
(4) The DBT must be used as the basis for planning protection programs.
3. PLANNING.
a. S&S Plans. S&S plans must be developed for facilities with any of the following
S&S interests:
(1) Category I quantities of SNM or credible roll-up quantities of SNM to a
Category I quantity;
(2) Category II, Category III, or Category IV SNM;
(3) radiological, chemical, or biological sabotage threats;
CANCELE
D
DOE M 470.4-1
08-26XX-05
Part 1, Section A
4
(4) critical mission disruption threats;
(5) intra-/inter-site transportation of SNM;
(6) classified information or matter;
(7) facilities engaged in the protection of government property;
(8) facilities that the Secretary, Deputy Secretary, or Under Secretaries deem
appropriate.
b. Site Safeguards and Security Plan (SSSP). The SSSP is a 5-year master planning
document that must be prepared for sites with facilities described in paragraphs
3.a. (1), (3), (4), or (8), above. The SSSP must depict the existing condition of
site protection programs and, when the DBT performance standard cannot be met,
establish improvement priorities and resource requirements for the necessary
improvements. Plan composition is reflected in Part 1, Section C, 5.
Section 13
c. Site Security Plan (SSP). At locations where an SSSP is not required because of
the limited scope of interests (i.e., criteria contained in 3.a. (2), (5), (6), or (7)
above, apply), an SSP must be developed to describe the protection program.
SSPs must be approved by the local DOE cognizant security authority. In
addition, specialized plans must be developed to address protection programs for
other protection operations. Requirements for specialized plans that may or may
not be components of the SSP are set forth in the applicable DOE directives.
d. Planning Inputs. The documents listed below must be used to support program
forecasts and information input used in the protection program planning process.
(1) Applicable Departmental directives, guidance, and intelligence assessment
information developed and disseminated by line management or the Office
of Security.
(2) Programmatic guidance and forecasts of significant changes planned in
site operations as communicated through line management.
(3) Current and projected operational constraints and resources.
(4) Analysis of cost and effectiveness of security technologies versus
traditional protection methodologies.
e. Plan Review and Approval.
(1) The SSSP requires approval by DOE line management and concurrence
by the cognizant Head of the Departmental Element (see Attachment 1).
Such approval authority must be formally delegated to line management.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section A
5
(a) Copies of approved SSSPs must be provided to the Office of
Security for review and comment.
(b) Other security plans may be approved as stipulated in the
applicable directive. If approving authority is not otherwise
stipulated, these security plans may be approved by DOE line
management.
(2) The SSSP must be submitted to DOE line management within 150 days of
the termination date of data collection and approved within 120 days of
the submittal date. Directive changes, facility reconfiguration, a new VA,
or other activities that occur after the stated effective date will not be
considered for purposes of reviewing/approving the plan.
(3) The SSSP must be reviewed annually (at least every 12 months). Updates
to the SSSP that may significantly alter the agreed-upon protection
philosophy or performance standards of protection systems must be
subjected to the formal VA process, and if changes are shown to
significantly alter system effectiveness performance, the update(s) will be
subject to the same concurrence and approval as stated in paragraph (1),
above.
(4) An information copy of approved modifications must be provided to the
Office of Security.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section A
Appendix 1-1
SECTION A
APPENDIX 1 – SAFEGUARDS & SECURITY MANAGEMENT PLAN
The Safeguards and Security (S&S) Management Plan provides a description of the
implementation of S&S policy and provides detailed information on the assignment of roles,
responsibilities, and authorities, as well as the development of budgets and allocation of
resources. The following outline delineates the content requirements and provides a suggested
format.
1. EXECUTIVE SUMMARY.
a. Program Mission Statement. Briefly describe the program mission and how the
mission relates to national security. Describe the major elements or activities
performed in terms of program mission and its relationship to the DOE national
security mission.
Section 14
b. S&S Program Structure. Briefly describe the strategy and organizational
elements used to implement the S&S program under their cognizance.
c. Management and Planning Assumptions. Briefly describe those assumptions that
affect the management and planning of the implementation of the S&S program.
These assumptions should include items such as:
(1) future of the program (mission, staffing levels, site status, etc.);
(2) current and planned S&S projects; and
(3) status of the organization’s S&S budget.
2. PART 1 - ORGANIZATIONAL STRUCTURE AND ACCOUNTABILITY
a. Line Management Organization. Describe the structure and relationship of line
management. Identify the roles, responsibilities, and authorities of these line
management elements to include organizational charts.
b. Cognizant Security Authority Organization. Describe the structure of line
management that is specifically responsible for implementing the Departmental
element’s S&S program. Identify the individuals and positions responsible for
committing resources and directing the activities of personnel associated with the
S&S program.
(1) Headquarters Organizational Structure. For the Headquarters elements,
provide an organizational chart to show the S&S organization and
management structure and the lines of authority and points of interface
with other programs which affect S&S (e.g., safety, facility operations,
and the cognizant security authority’s material control and accountability
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section A
Appendix 1-2
(MC&A) organization, if independent of the security organization).
Describe the functions and responsibilities of S&S personnel and indicate
how S&S activities are integrated with those of other facility
organizations; include organizational responsibilities for line management
overseeing the program as well as the interface points with the respective
Departmental element.
(2) Field Organizational Structure. For the Field elements, provide an
organizational chart to show the S&S organization and management
structure and the lines of authority and points of interface with other
programs which affect S&S (e.g., safety, facility operations, and the
cognizant security authorities’ MC&A organization, if independent of the
security organization). Describe the functions and responsibilities of S&S
personnel and indicate how S&S activities are integrated with those of
other facility organizations; include organizational responsibilities for line
management overseeing the program as well as the interface points with
the respective Departmental element.
c. Contractor Sites. Provide the contract name, number, and other information that
describes the authority under which the contractor executes management
functions for facilities under the cognizance of a Departmental element. Identify
the site contractor elements responsible for S&S programs and describe their S&S
activities. Provide Federal and contractor organization charts and identify key
positions and the relationships between the organizations responsible for S&S
activities. Describe Federal and contractor involvement in the development of
S&S resource requirements.
3. PART 2 - ROLES, RESPONSIBILITIES, DELEGATIONS, AND AUTHORITIES.
Delegations must be documented in writing and delineate all assigned S&S roles,
responsibilities, and authorities for the S&S program. This section:
a. documents offices/positions affected by the S&S Management Plan;
Section 15
b. establishes the approval chain for S&S plans, procedures and implementation
policy;
c. establishes the approval chain for S&S policy deviations;
d. assigns reporting requirements for incidents of security concern; and
e. provides a list of roles and responsibilities for key positions and the delegated
authorities for each.
4. PART 3 – S&S PROGRAM IMPLEMENTATION. This section of the S&S
Management Plan documents the processes and methods used to implement the
Department’s security policies. This section identifies:
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section A
Appendix 1-3
a. the methods used for ensuring all applicable programmatic requirements are
implemented throughout the organizational element;
b. the methods used for ensuring effective integration of S&S programmatic
elements; and
c. SSSPs and SSPs used to implement S&S policy requirements.
5. PART 4 - PLANNING AND BUDGET (INCLUDING PERSONNEL RESOURCES).
This section of the S&S Management Plan documents the key processes of planning and
budgeting, including strategic planning, budget formulation, budget execution, and
program evaluation.
a. Describe the strategic planning assumptions used to ensure the S&S program will
meet mission objectives.
b. Provide a 5-year plan that describes the budget formulation priorities for future
S&S resources and programs.
c. Provide the current year plan for executing the S&S budget. This plan details the
allocation of resources that support S&S functions and missions.
d. Provide a program evaluation plan that details how the cognizant security
authority will assess the implementation of the S&S program and the
organization’s progress toward meeting established missions/goals. The program
evaluation plan must cover both the Federal and contractor elements of the
Departmental element. This plan can be used to support award fee decisions by
the Departmental element.
e. Briefly describe any changes to operational requirements which affect S&S
program operations or would require increments or decrements to operational
accounts (e.g., program direction, operational support, etc.).
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section B
1
SECTION B - SECURITY CONDITIONS
1. OBJECTIVE. To ensure that the Department uniformly meets the requirements of the
Homeland Security Advisory System outlined in Homeland Security Presidential
Directive-3, (HSPD-3), dated 3-11-02, and provides the responses specified in
Presidential Decision Directive 39, U.S. Policy on Counterterrorism (U), dated 6-21-95.
2. THREAT INDICATORS. While the Design Basis Threat (DBT) provides specific
description of threats that all components of the safeguards and security (S&S) system
must be capable of defeating, analysis of terrorism should be an ongoing process.
Although each analysis relies on information included in previous assessments,
judgments with respect to threats to Federal and Department of Energy (DOE)-affiliated
personnel, facilities, and assets begin anew with each analysis.
Section 16
a. Homeland Security Threat Conditions (known in DOE as Security Conditions
[SECONs]) are established based on the analysis of a continuous and timely flow
of integrated all-source threat assessments and reporting provided to Executive
Branch decision-makers. A threat indicator is a condition that, when present,
increases the possibility of a terrorist incident. Seldom does one single indicator
suggest that the threat is imminent, but, when a number of indicators are present,
the level of concern should increase correspondingly. A decision on assigning
SECONs must integrate a variety of considerations. This integration will rely on
qualitative assessment, not quantitative calculation. Higher SECONs indicate
greater risk of a terrorist act, with risk including both probability and gravity.
Despite best efforts, there can be no guarantee that, at any given SECON, a
terrorist attack will not occur. An initial and important factor is the quality of the
threat information itself. The evaluation of this threat information includes, but is
not limited to, the following factors.
(1) To what degree is the threat information credible?
(2) To what degree is the threat information corroborated?
(3) To what degree is the threat specific and/or imminent?
(4) How grave are the potential consequences of the threat?
b. Local and site-specific threat analysis is a dynamic process because the threat and
the countermeasures used to combat the threat are constantly changing. To keep
up with possible changes in the threat, security professionals should develop a
predetermined list of general and specific threat indicators. Threat indicators
should be revised according to site/facility situations and needs. They should be
reviewed at least every 6 months or when a significant incident or change in
conditions indicates that the threat level is increasing or decreasing. Examples of
threat indicators that can be used to develop a site/facility-specific assessment are
listed below.
(1) International incidents or indicators against U.S. interests, personnel, or
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section B
2
facilities.
(2) Domestic incidents or indicators against Federal or State interests
countrywide.
(3) Local incidents or indicators directed against Federal or DOE interests.
(4) Specific targeting of DOE personnel, facilities, or materials.
3. SECURITY CONDITIONS. The DOE SECON system has been aligned with the
Homeland Security Advisory System.
a. The DOE SECON system describes a progressive level of common sense
protective measures that may be implemented in response to a malevolent or
terrorist threat to any or all DOE facilities, assets, and personnel. The purpose of
the SECON system is to establish standardized protective measures for a wide
range of threats and to help disseminate appropriate, timely, and standardized
information for the coordination and support of DOE crisis or contingency
activities. Once a SECON level is declared, the associated protective measures
should be implemented as soon as possible to the extent they apply to the
individual site or facility. Cognizant security authorities must coordinate SECON
status through their DOE points of contact, as appropriate, and notify the DOE
Headquarters (HQ) Operations Center (OC) and Departmental element of the
site/facility SECON status. Measures associated with each SECON are not
prioritized but should be initiated concurrently when practical.
Section 17
b. National Nuclear Security Administration (NNSA) facilities must be prepared to
respond to SECON directives provided by the Under Secretary for Nuclear
Security/Administrator, NNSA. Non-NNSA facilities must be prepared to
respond to SECON directives provided by the Under Secretary for Energy,
Science and Environment for their individual facilities. Headquarters facilities
must be prepared to respond to SECON directives provided by the Director,
Office of Security. At their discretion, DOE line management may increase
protection measures for facilities under their cognizance if they determine that the
local threat situation warrants additional security. In this event, the DOE HQ OC
and Departmental element must be notified of the SECON level. If DOE line
management or Departmental elements believe that their facilities’ SECON levels
should be less than those issued by the Under Secretary for Energy, Science and
Environment or the Under Secretary for Nuclear Security/Administrator, NNSA,
a request for exception must be submitted for consideration (see paragraph 3.c.,
below).
c. Any departure from the requirements of this section must be considered an
exception which must be approved in accordance with the requirements set forth
in Section M. No exception is permitted to the protective measures when under
SECON 1, Severe Condition (Red).
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section B
3
d. To the extent possible throughout each increase or decrease in SECON, the
cognizant security authority must:
(1) keep employees informed;
(2) coordinate when appropriate with State and local officials’ actions taken
regarding security and emergency planning; and
(3) at each level of SECON, review security plans, vulnerability assessments
(VAs), emergency response procedures, public affairs guidance and plans,
legal authorities, and Continuity of Operations Plans.
e. A record of specific actions taken for each measure must be maintained. A
description of each SECON, including the necessary circumstances for
implementing, the impact on operations, and the purpose of each protective
posture, is outlined below.
(1) SECON 5, LOW CONDITION (GREEN). This condition is declared
when there is a low risk of terrorist attacks. SECON 5, Low Condition
(Green) exists when a general threat of possible malevolent or terrorist
activity exists, but warrants only a routine security posture.
(2) SECON 4, GUARDED CONDITION (BLUE). This condition is
declared when there is a general risk of terrorist attacks. SECON 4,
Guarded Condition (Blue) applies when there is an increased general
threat of possible malevolent or terrorist activity against personnel and
facilities, the nature and extent of which are unpredictable, and
circumstances do not justify full implementation of SECON 3, Elevated
Condition (Yellow) measures. It may be necessary, however, to
implement certain selected measures from higher SECONs to address
intelligence received or to act as a deterrent. All measures selected for use
under SECON 4, Guarded Condition (Blue) must be capable of being
maintained indefinitely.
(a) Measure 1. At regular intervals, warn all personnel to report the
following to security:
1 suspicious personnel, particularly those carrying suitcases
or other containers, or those observing, photographing, or
asking questions about site operations or security measures;
2 unidentified vehicles parked or operated in a suspicious
manner on or in the vicinity of the site or near site
facilities;
Section 18
3 abandoned parcels or suitcases; and
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section B
4
4 any other activity considered suspicious.
(b) Measure 2.
1 Ensure that security personnel have immediate access to
building floor plans and emergency/evacuation plans for all
site facilities.
2 Ensure that security personnel are able to seal off an area
immediately.
3 Ensure that key personnel required to implement security
plans are on-call and readily available.
4 Maintain the site Emergency Management Team (EMT) on
2-hour recall.
5 Expand Operations Security measures.
6 Exercise bomb threat procedures.
(c) Measure 3. Secure and seal buildings, rooms, and storage areas
not in regular use. Maintain a list of secured facilities.
(d) Measure 4. Increase unannounced security spot checks (inspection
of personal identification; vehicle registration; and the contents of
vehicles, suitcases, briefcases, and other containers) at access
points for the site and facilities.
(e) Measure 5. Reduce the number of access points for vehicles and
personnel to minimum levels consistent with the requirement to
maintain a reasonable flow of traffic.
(f) Measure 6. As a deterrent, randomly apply measures 14, 15, 16,
17, or 18 from SECON 3, Elevated Condition (Yellow) either
individually or in combination.
(g) Measure 7. Review all operations plans, personnel details, and
logistics requirements that pertain to implementing higher
SECONs.
(h) Measure 8. Review security measures for critical/sensitive
personnel (e.g., directors, managers, members of special access/
security programs, etc.) and implement additional measures
warranted by the threat and existing vulnerabilities (e.g., identified
personnel should alter established patterns of behavior when
traveling in public areas).
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section B
5
(i) Measure 9. Increase liaison with local law enforcement,
intelligence community, security agencies, and the Federal Bureau
of Investigation, (FBI) to monitor the threat to site personnel and
facilities. Notify local law enforcement agencies and the FBI
concerning SECON 3, Elevated Condition (Yellow) measures that,
if implemented, could affect their operations in the local
community.
(j) Measure 10. Reserve for site/facility use.
(3) SECON 3, ELEVATED CONDITION (YELLOW). A SECON 3,
Elevated Condition (Yellow) is declared when there is a significant risk of
terrorist attack. Elevated Condition (Yellow) applies when an increased
and more predictable threat of malevolent or terrorist activity exists. The
measures in this SECON must be capable of being maintained for lengthy
periods without causing undue hardship, affecting operational capability,
or aggravating relations with the local community. For measures
requiring an increase in the frequency of a specific action, the new
frequency is to be more often than in the lower-level security condition.
In addition to the measures required by SECON 4, Guarded Condition
(Blue), the following measures should be implemented.
(a) Measure 11. Increase the frequency of warnings required by
Measure 1 and inform personnel of additional unclassified threat
information, if available. Encourage increased community security
awareness of suspicious persons, vehicles, and activities.
(b) Measure 12. Maintain EMT personnel on 2-hour recall;
periodically exercise recall to ensure readiness. Keep all other
personnel involved in implementing special response/contingency
plans on call. Identify, contact, and brief specialists that may be
required for unique contingencies; coordinate lines of
communication.
Section 19
(c) Measure 13. Review provisions of all operations plans and orders
and special operating procedures associated with implementing
SECON 2, High Condition (Orange).
(d) Measure 14. Move automobiles and objects such as trash
containers, newspaper boxes, crates, etc., at least 30 yards from all
facilities, particularly buildings of a sensitive or prestigious nature.
Identify any areas where an improvised explosive device could be
hidden (i.e., pallet stacks, trash piles, stacked construction
supplies, etc.). If the configuration of the facility or area precludes
implementation of this measure, take appropriate compensatory
measures per local plans (frequent inspection by Explosive
Ordnance Disposal [EOD] teams, if available, controlled access to
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section B
6
parking areas, etc.). Consider centralized parking.
(e) Measure 15. Secure, seal, and regularly inspect all buildings,
rooms, and storage areas that can be isolated with minimum site
impact.
(f) Measure 16. At the beginning and end of each work day and at
frequent intervals, inspect the interior and exterior of buildings in
regular use for suspicious activity or unattended packages and for
signs of tampering or indications of unauthorized entry.
(g) Measure 17. Implement screening procedures for all incoming
official mail to identify possible explosive or incendiary devices or
other dangerous material. If available, have EOD-trained teams
inspect suspicious items and screen mail periodically. Provide
guidance concerning suspicious packages. Encourage employees
to inspect their individual mail, report suspicious items to security,
and refrain from handling such items until cleared by the
appropriate authority.
(h) Measure 18. Inspect other deliveries and locally designated
common-use facilities to identify explosives and incendiary,
biological, or chemical devices. Use EOD-trained teams for some
screening inspections when available. Instruct site personnel to
report suspicious packages to security and refrain from handling
them until cleared by the appropriate authority.
(i) Measure 19. Increase both overt and covert security force
surveillance of locally designated soft targets to improve
deterrence and build confidence among site personnel. (Covert
surveillance must comply with DOE directives and appropriate
regulatory restrictions.)
(j) Measure 20. Inform employees of the general threat situation.
Limit visitors and escorted uncleared personnel. Periodically
update all personnel as the situation changes to stop rumors and
prevent unnecessary alarm.
(k) Measure 21. Brief representatives of all activities on the site
concerning the threat and security measures implemented in
response to the threat. Explain reasons for actions. Implement
procedures to provide periodic updates for these activity
representatives.
(l) Measure 22. Verify the identity of all personnel entering property
protection areas (PPAs) and other sensitive activities specified in
local plans (i.e., inspect identification badges and grant access
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section B
7
based on visual recognition). Use of automated access control
systems at interior security areas is acceptable and encouraged,
where practical.
On a random basis, visually inspect the interior of all vehicles and
the exterior of all suitcases, briefcases, packages, and other
containers. Increase the frequency of detailed vehicle inspections
(trunk, undercarriage, glove boxes, etc.) and the frequency of
detailed inspections of suitcases, briefcases, and other containers.
Section 20
(m) Measure 23. Increase the frequency of random identity checks
(inspection of security badges and vehicle registration documents)
conducted by security force patrols on the site.
(n) Measure 24. Remind all personnel to lock parked vehicles and
inspect vehicles for suspicious items before entering and driving
them.
(o) Measure 25. Implement additional security measures for
critical/sensitive personnel in accordance with existing plans.
(p) Measure 26. Brief all security force personnel concerning the
threat and policies governing rules of engagement, use of deadly
force, and fresh pursuit. Ensure there is no misunderstanding of
these instructions. Repeat this briefing on a periodic basis.
(q) Measure 27. Increase liaison with local police, intelligence,
security agencies, and the FBI to monitor the threat to site
personnel and facilities. Notify local police agencies concerning
SECON 2, High Condition (Orange) or SECON 1, Severe
Condition (Red) measures that, if implemented, could affect their
operations in the local community.
(r) Measure 28. Survey the surrounding area to determine whether
operational activities near the area might create emergencies or
contingencies that could affect the site/facility (e.g., airports,
military/other government facilities, industrial facilities, railroads
or pipelines, etc.).
(s) Measure 29. Reserve for site/facility use.
(4) SECON 2, HIGH CONDITION (ORANGE). A SECON 2, High
Condition (Orange) is declared when there is a high risk of terrorist
attacks. This condition applies when an incident occurs or intelligence is
received indicating that some form of malevolent or terrorist action
against personnel and facilities is imminent. Implementation of measures
in this security condition for more than a short period probably will create
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section B
8
hardship and affect the routine activities of the site and its personnel. For
measures requiring an increase in the frequency of a specific action, the
new frequency is to be more often than in the lower level SECON. The
following measures should be implemented.
(a) Measure 30. Continue all SECON 4, Guarded Condition (Blue)
and SECON 3, Elevated Condition (Yellow) measures or introduce
those that have not already been implemented.
(b) Measure 31. Recall staff representatives and initiate 24-hour
operation of the EMT. Place the Special Response Team (SRT) on
standby alert. Keep all personnel responsible for implementing
special/response contingency plans at their places of duty. Review
site evacuation plans.
(c) Measure 32. Reduce site access points to the absolute minimum
necessary for continued operation.
(d) Measure 33. Verify the identity of all personnel entering the
site/facilities, including appropriate offsite facilities under DOE
control. Inspect all security badges for tampering. On a random
basis, visually inspect the interior of all vehicles and the exterior of
all suitcases, briefcases, and other containers. Increase the
frequency of detailed vehicle inspections (trunk, undercarriage,
glove compartments, etc.) and the frequency of inspections of
suitcases, briefcases, and other containers.
(e) Measure 34. Implement centralized parking and shuttle bus
service, where required.
Section 21
(f) Measure 35. Ensure that security personnel have been briefed
concerning policies governing the rules of engagement, use of
force, and fresh pursuit, particularly criteria for use of deadly
force. Ensure that non-security supervisory personnel are familiar
with above policies and procedures, if applicable. Ensure that
special equipment and ammunition are available for immediate
issue.
(g) Measure 36. Increase security patrol activity to the maximum
level sustainable. The concept of continuing random security
patrol activity is encouraged.
(h) Measure 37. Position security force personnel in the vicinity of
critical facilities.
(i) Measure 38. Erect barriers required to control direction of traffic
flow and to protect facilities vulnerable to bomb attack by parked
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section B
9
or moving vehicles.
(j) Measure 39. Consult local authorities about closing public roads
and facilities that might make sites more vulnerable to terrorist
attacks.
(k) Measure 40. Consider canceling public events.
(l) Measure 41. Consider initiating Continuity of Operations plans
(m) Measure 42. Reserve for site/facility use.
(5) SECON 1, SEVERE CONDITION (RED). A SECON 1, Severe
Condition (Red) reflects a severe risk of terrorist attacks. This condition
applies in the immediate area where a malevolent or terrorist attack has
occurred that may affect the site or when an attack is initiated on the site.
Implementing SECON 1, Severe Condition (Red) will create hardship and
affect the activities of the site and its personnel. Normally, this SECON is
declared as a localized response. For measures requiring an increase in
the frequency of a specific action, the new frequency is to be more often
than in the lower-level SECON. The following measures should be
implemented.
(a) Measure 43. Continue all previous SECON measures and
introduce those that have not already been implemented.
(b) Measure 44. Augment security forces to ensure absolute control
over access to the site, facilities, and other potential target areas.
Establish surveillance points; use night-vision devices.
(c) Measure 45. Working closely with facility management, identify
the owners of all vehicles already on the site. In those cases where
the presence of a vehicle cannot be explained (owner is not present
and the vehicle has no obvious site affiliation), inspect the vehicle
for explosives; incendiary, chemical, or biological devices; or
other dangerous items and remove the vehicle from the vicinity of
facilities, soft targets, and other sensitive areas as soon as possible.
(d) Measure 46. Inspect all vehicles entering the site. Inspections
should include cargo storage areas, undercarriage, glove boxes,
and other areas where explosives, incendiary, chemical, or
biological devices or other dangerous items could be concealed.
(e) Measure 47. Limit access to the site, facilities, and other areas to
those personnel with a legitimate and verifiable need to enter.
Implement positive identification of all personnel. No exceptions.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section B
10
(f) Measure 48. Inspect all baggage such as suitcases, packages, and
briefcases brought on the site for explosives, incendiary, chemical,
or biological devices, or other dangerous items.
(g) Measure 49. Implement frequent inspections of the exterior of
buildings (including roof areas) and parking areas. Conduct
inspections at facilities and in the vicinity of soft targets.
Section 22
(h) Measure 50. Coordinate with the Operations Division/Center to
establish communications, responsibilities, and authorities before,
during, and after attack.
(i) Measure 51. Request that local authorities close those public roads
and facilities in the vicinity of the site/facilities that might facilitate
execution of a malevolent or terrorist attack.
(j) Measure 52. Cancel public events.
(k) Measure 53. Execute Continuity of Operations plans.
(l) Measure 54. Reserve for site/facility use.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section C
1
SECTION C - SITE SAFEGUARDS AND SECURITY PLANS
1. OBJECTIVE. The Site Safeguards and Security Plan (SSSP) is a risk management
document that provides summary information used to describe safeguards and security
(S&S) programs and vulnerability and risk assessments at applicable sites. The objective
of this section is to delineate SSSP content and establish a standard approach to
presenting site protection information and vulnerability assessment (VA) results. The
results and conclusions contained in the plan are intended to guide long-term planning for
site S&S operations. This is accomplished during plan development by identifying: key
site protection elements; annually (at least every 12 months) evaluating site protection in
terms of its adequacy to meet continued mission and threat parameters; and, identifying
resource requirements.
2. APPLICATION. The SSSP is used to evaluate site and facility program elements and
resources as they relate to identified threats and risks. The protection measures identified
in approved SSSPs become the basis for executing and reviewing site protection
programs.
3. SCOPE. The approved SSSP provides assurance that S&S measures address identified
threats and risks. To provide this assurance, the plan must reiterate the assumptions
identified to, and agreed upon, by line management. These assumptions must include
reference to the contract under which the site is operated and those contractual issues that
may impact S&S, applicable Department of Energy (DOE) directives, the threat upon
which VAs are based, the methodology used to conduct VAs, deviations and proposed
deviations, and any unique S&S impacting issues and assumptions that were addressed,
and agreed to, by the responsible parties.
4. PURPOSE. The SSSP describes the graded protection of DOE assets required to be
implemented by line management. The SSSP identifies site risks, cost-benefit analyses,
and comparison of proposed upgrades. The resource plan (RP) must identify near- and
long-term resource requirements needed to ensure the integrity of existing and planned
S&S upgrades. The annual (at least every 12 months) review serves as the basis for
tracking the implementation of protection measures and strategies necessary to maintain
system effectiveness and identifies unfunded requirements.
5. PLAN COMPOSITION. The SSSP includes:
a. references to implementing documents and evidence files;
b. descriptions of site protection strategies, key site S&S programs, approved and
pending deviations, plans and procedures designed to implement, manage and
maintain S&S programs;
c. system effectiveness determinations for the protection of special nuclear material
(SNM), prevention or mitigation of sabotage events, and prevention and/or timely
detection of the loss of classified information or matter based on the status of
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section C
2
Section 23
performance indicators, such as results of VAs, performance tests, surveys,
inspections, and evaluations of personnel qualifications and training;
d. proposed S&S program upgrades;
e. VAs results that support conclusions reported in the SSSP;
f. assumptions used as part of the VA process;
g. threat parameters used for VAs that are described in the current Design Basis
Threat (DBT), regional threat assessments, and impacts made by local area threat
assessments, if applicable;
h. the details of the changes in the protection through the spectrum of Security
Conditions (SECON) (1-5), to include effects on the calculated baseline system
effectiveness;
i. a description of the evidence files containing material that supports the VAs; and
j. an RP that describes S&S upgrades programmed for completion, upgrades being
introduced as a result of planned and unplanned site changes impacting the
protection program or deficiencies identified as a result of the annual (at least
every 12 months) review of the SSSP, a description of the funding source to
implement the upgrades, and unfunded requirements.
6. EVIDENCE FILES. Supporting documentation that validates data/information used in
the VA process and in other protection program planning presented in the plan and that
may require corroboration must be available in evidence files. Evidence files must be
maintained to provide VA process and other protection program planning documentation
in a logical and readily retrievable form to validate assumptions, modeling input data, test
results, and other data that may be used to support protection system design or
conclusions regarding protection effectiveness.
7. DATA COLLECTION. The effective date (snapshot in time) of the data contained in the
SSSP must be specified.
8. FORMAT. Information provided in the SSSP should be brief, accurate, and concise.
Implementing plans and procedures should be referenced in the plan where appropriate.
A brief overview of a plan or procedure is adequate.
Duplication of information should be avoided. Information already included in other
sections of the plan may be referenced or summarized for clarity.
A cover letter must be attached to the plan indicating that the plan has been reviewed,
risks acknowledged and accepted (if appropriate), and signed by line management. For
example, the SSSP should be approved by the Head of Field Element and submitted for
concurrence to the Departmental element. If high or marginal risk acceptance is needed,
the correspondence must be routed for signature to the Secretary or Deputy Secretary or
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section C
3
Under Secretaries, respectively.
The use of charts, plats, graphs, drawings, videos, photographs, and matrixes is
encouraged wherever appropriate to clarify or satisfy the intent of plan objectives.
References to sources of information and the location of supporting documentation
should be provided to assist in verifying information contained in the plan.
The SSSP is divided into 12 chapters. Each chapter provides specific information
relevant to site security. Use of this layout will ensure a uniform SSSP for review and
comment or during an emergency.
a. Chapter 1, Site Description and Mission.
(1) Site Mission Statement. Describe the site mission and how the mission
relates to national security and the health and safety of the public,
employees, and the environment. Describe the major programs or
activities performed at the site in terms of mission and their relationship to
the DOE national security mission.
Section 24
(2) Site Description and Area Layout. Describe the physical and geographical
area in which the site and the S&S program are located. Provide a map,
photograph, or drawing of the site that identifies locations of Category I
facilities, facilities with a credible roll-up of SNM to a Category I
quantity, the central alarm station (CAS) and secondary alarm stations
(SAS), security-related communications facilities, and other facilities of
security interest. Show the location of barriers defining the site Protected
Area (PA). A small-scale map or drawing should be used to show the
relationship of the site to the surrounding area and be of sufficient detail to
orient the user.
(3) Management Organization, Planning Assumptions and Evidence File.
(a) Site Management Organizations. Identify the contract name,
number, and other information that describes the authority under
which the contractor executes management functions. Identify site
contractors responsible for S&S programs and describe their S&S
activities. Provide Federal and contractor organization charts and
identify key positions and the relationships between the
organizations for S&S activities. Provide a list of roles and
responsibilities for key positions. Describe Federal and contractor
involvement in the development of S&S resource requirements.
(b) Management and Planning Assumptions. Describe those
assumptions that were addressed and agreed to during the SSSP
scoping, preparation, or other SSSP management-related meetings.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section C
4
Describe all relevant S&S-related planning assumptions that were
formerly agreed to and included in a Memorandum of Agreement
(MOA) by the responsible organization representatives who are
party to the development and review of the SSSP. These
assumptions should address the following issues:
1 site SECON;
2 VA methodology used for insider, neutralization, outsider,
and collusion analyses;
3 identified credible targets;
4 protection strategies;
5 approved compensatory measures; and
6 performance testing conducted or to be conducted.
(c) Evidence Files. Describe and identify the contents, location, and
control mechanisms for the SSSP evidence files. Reference
approved standard operating procedures (SOPs) as applicable.
Supporting documentation that validates data/information used in
the VA process should not be included in the SSSP. However, this
data/documentation should be available in a logical and readily
retrievable arrangement in evidence files, for use in review and
validation of the SSSP.
b. Chapter 2, Site Threat Description and Target Identification.
(1) Threat Description. Establish a graded approach to protection for
Category I SNM and SNM facilities with credible roll-up of SNM to a
Category I quantity, and facilities having radiological, biological, or
chemical, sabotage event potential and facilities having disruption of
critical mission sabotage event potential. Use the DBT as the baseline for
threat determination, along with higher levels of threat dictated by local
and regional threats (when available), and describe the site-specific threats
used as the basis for conducting VAs and for which the protection
program is designed.
(2) Target Identification. Identify, describe, and prioritize targets of security
interest that meet the following criteria.
(a) Category I quantities of SNM and the facilities with credible roll-
up of SNM to a Category I quantity.
Section 25
(b) A radiological, biological or chemical sabotage inventory that, if
released, would cause an unacceptable impact on national security
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section C
5
or the health and safety of employees, the public, or the
environment.
(c) Critical national security facilities, and assets (as defined in the
DBT), designated by the Department (e.g., or each disruption of
critical mission target) that would impact DOE programs
supporting national defense and security.
(d) Those facilities possessing automated information systems that
process or contain Sensitive Compartmented Information (SCI),
Special Access Program (SAP), weapon data classified Secret
Restricted Data (S/RD) Sigma 1, 2, 14 and 15 or higher.
(e) Temporary recurring targets. When predictable programmatic
operations can reasonably be expected to present temporary SNM,
sabotage, or information targets such as those permanent locations
previously described, these targets must be described and analyzed
at the same level of detail and in the same manner as permanent
locations.
Provide a brief introductory description of the targets and a chart or list,
such as shown below, that indicates the type of target, its location,
attractiveness level, size, and configuration. Include SNM theft/diversion
targets, radiological, biological, and chemical targets, and disruption of
critical mission targets, and those facilities possessing automated
information systems that process SCI, SAP, weapon data classified S/RD
Sigma 1, 2, 14 and 15 or higher.
(3) Theft or Diversion of SNM. Describe how Category I SNM targets and
SNM facilities that roll-up to a credible Category I quantity have been
identified and evaluated as potential abrupt theft targets. Also, describe
how these SNM targets have been identified and assessed for protracted
theft (diversion), if applicable.
For each identified SNM target, provide a description of the following,
using a table similar to Table C-1, SNM Theft/Diversion Targets:
physical location of identified SNM; the type of material, as described
under the several material listings in DOE M 470.4-6, Nuclear Material
Control and Accountability, such as pure products, high-grade material,
weapons, including pits, ingots, oxide fuel elements, etc.; and the
Category
(I through II) and attractiveness level (A through C) of the target material.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section C
6
Table C-1. SNM Theft/Diversion Targets
Location SNM Type
Category/
Attractiveness
Level
Goal Quantity/
Portability
Bldg. 1, Vault Pu-239 ingots Cat. I/B 2 ingots/
man portable
Bldg. 1, Assay
Room Pu-239 ingots Cat. I/B 2 ingots/
man- portable
Bldg. 1,
Fabrication Room
Pu-238 oxide
powder Cat. II/D 2 canisters/
man- portable
Bldg. 2 U-235 fuel
elements
Cat. II, roll-up to
Cat. I/C
20 fuel element/
not man portable
Bldg. 3 U-235 fuel
elements
Cat. II, roll-up to
Cat. I/C
20 fuel element/
not man-
portable
(4) Radiological Sabotage. Indicate the process or methodology used to
identify and evaluate radiological sabotage targets.
For each identified radiological sabotage target, provide a description
using a table similar to Table C-2, Radiological Sabotage Targets, of the
following: the physical location of all identified targets; the type of
material; the maximum inventory level; and the material size and
configuration.
Table C-2. Radiological Sabotage Targets
Location Material Type Maximum
Inventory
Section 26
Material Size and
Configuration
Bldg. 1,
Fabrication
Room
Pu-238 oxide
powder 10 kg Paint Cans, at 50 g each
Bldg. 4 H3 gas 10 kg Cylinders, at 500 g each
(5) Biological or Chemical Sabotage. Describe the methodology used to
evaluate biological or chemical targets. Using the criteria referenced in
the DBT, determine the sabotage threat level (STL) for each location.
Reference the plans and procedures that govern the biological or chemical
sabotage assessment program.
For each identified target type not addressed by the commercial equiva-
lency protection program, provide a description of the following using a
table similar to Table C-3, Biological/Chemical Sabotage Targets: the
physical location of additional identified biological or chemical sabotage
material targets; the type of material; the maximum inventory level; the
material size and configuration; and, the exposure level at the near-site
boundary (NSB) for maximum inventory release.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section C
7
Table C-3. Biological/Chemical Sabotage Targets
Location Material
Type
Maximum
Inventory
Material Size
and
Configuration
Exposure
Level at NSB
Bldg. 5 Chlorine 10,000 lb 55-gal drums, at
350 lb each
>ERPG III
Levels
(6) Disruption of Critical Mission Sabotage. Describe how potential dis-
ruption of critical mission sabotage production and process components
(machinery, equipment, flow process, power sources, ventilation, waste
handling, etc.) have been identified and evaluated for inclusion as dis-
ruption of critical mission targets. Ensure that the evaluation includes
how the sabotage event would affect production (at the facility, on inter-
site processes, and on overall national level inventory needs) and, if so,
what areas, processes, and/or components within the facility affect those
necessary production level capabilities and inventory needs.
For each disruption of critical mission target, provide a description, using
a chart similar to Table C-4, Disruption of Critical Mission Targets, of the
following: the physical location of essential production components; the
type of equipment, process, power sources or vital components; and the
dollar value or production capability loss.
Table C-4. Disruption of Critical Mission Targets
Location Equipment Type Loss of DOE Mission Capability and
Mission Impact
Bldg. 1,
Fabrication
Room
Fuel Fabrication
Presses
100 percent loss of capability for 360
days with moderate mission impact
Lab. A Laser Tunnel 100 percent loss of capability for 360
days with low mission impact
(7) Intra-Site Transportation of SNM. Describe, in a brief narrative, the
Category I SNM targets and credible Category II SNM targets that roll up
to Category I quantity that are moved from one location to another on the
site on a recurring basis.
Using a chart, identify the type of SNM, attractiveness level, and size and
configuration of the material.
c. Chapter 3, Site Protection Strategies. Identify the protection strategies employed
that address the overall protection program and enhance the concept of graded
protection. Describe the protection program strategies employed. The basic
strategies pertaining to protection are denial of access, denial of task, and
containment that upon failure could evolve into recapture/recovery or pursuit
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section C
8
Section 27
strategies. Protection programs and tactical deployments designed to prevent
unauthorized control of material and devices and to prevent acts of radiological,
biological, chemical, and disruption of critical mission must be integrated with
protection strategies. These activities could include protection layers of intrusion
detection systems (IDS) and concentric security areas, access control measures,
compartmentalization, insider protection programs, and procedural measures.
The plan should clearly convey the strategy to be employed, and plan reviewers
will anticipate that procedures are available to ensure implementation of these
strategies. Display in a chart similar to Table C-5, Site-Wide Protection
Strategies, the protection strategy used, the facility and target involved, and the
title and responsible office for each plan or procedure. Ensure the information
provided is consistent with that found in Chapter 2, Site Threat Description and
Target Identification.
Table C-5. Site-Wide Protection Strategies
Protection
Strategy
Facility or
Activity Target Type
Implementing
Plan or
Procedure
Responsible
Office
Denial of
Access Facility ABC
Cat. I: Pu metal
oxide
Cat. II: nitrate UF6
Plan ABC 1.3 Protective
Force Manager
Containment
Vault storage
Areas 301,
302 and 303
Weapon parts and
Pu metallic buttons Plan ADC.1 Protective
Force Manager
Denial of
Task
SNM in
transit Weapon parts Plan CFE 1.5 Protective
Force Manager
d. Chapter 4, Physical Protection Systems.
(1) Summary of Physical Protection Systems Used for Category I and
Credible Roll-up Quantities of SNM to a Category I Quantity, Sabotage,
Classified Information or Matter, and Classified Automated Information
Protection. Describe the physical protection systems for each facility that
has Category I quantities of SNM, credible roll-up quantities of SNM to a
Category I quantity, radiological, biological, chemical sabotage targets
(including disruption of critical mission), and those facilities possessing
automated information systems that process or contain SCI, SAP, weapon
data classified S/RD Sigma 1, 2, 14 and 15, or higher. Provide a narrative
description of the physical protection systems and how the systems are
integrated at the site and facility level. Describe how the barriers are
protected by an IDS, security lighting, protective force (PF), and
assessment systems and how structures located in or on the barrier are
protected so as not to degrade protective systems.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section C
9
Following the narrative, complete a chart similar to Table C-6, Facility
Protection Systems, that includes the following facility protection
systems: security areas and their barriers, access controls (badge checks
and contraband screening by the protective force, and automated card
access for both interior and exterior); assessment (closed circuit television
[CCTV] and/or protective forces both interior and exterior); security
computer system integrator/ processor; CAS and SAS; CCTV cameras
monitoring and switching systems; security lighting; electrical and back-
up power sources (emergency batteries and/or generators); and
communications. In the chart, list the major physical protection systems,
the location of the systems, and a brief description of the type of
equipment installed.
Table C-6. Facility Protection Systems
Protection System Equipment
Description Location Responsible
Office
Exterior Intrusion
Detection “H” Field
Section 28
Protected Area
Perimeter
Associated Areas
Office of the
Plant Engineer
Exterior Assessment/
CCTV
Microwave
Taut Wire
CCTV System
Protected Area
Perimeter
Associated Areas
Office of the
Plant Engineer
Interior Intrusion
Detection
Volumetric Infrared
Motion Detectors
All Material Access
Areas
Office of the
Plant Engineer
(2) Physical Protection Measures for Category I and Credible Roll-up
Quantities of SNM to a Category I Quantity in Transit (Onsite). Describes
the types, frequency, and protection measures used for the intra-site
shipment of Category I SNM and credible roll-up quantities to a Category
I quantity. Provide a narrative that describes the typical physical
protection measures taken to ensure the integrity of those shipments from
their point of loading, through transit, and at the off-load destination. If
other materials are transported on site that would represent an STL 1
concern, provide a narrative that describes the typical physical protection
measures from their point of loading, through transit, and at the off-load
destination.
e. Chapter 5, Site Protective Force.
(1) Protective Force Mission, Organization, and Capabilities. Describe the PF
organization and equipment deployed to perform 24-hour-per-day, site-
wide protection. Confirm that the basis for PF organization and planning
is based on the identified site threat. Provide a narrative summary of the
PF mission(s), capabilities, and deployment concepts used for site
protection. Indicate the availability of plans and procedures that address
normal and emergency deployment. Describe the PF equipment used
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section C
10
including firearms, communications, vehicles, and any special items.
Provide an organization chart of the PF, including response forces,
showing the management and organization structure and key
organizational interface positions with the cognizant security authorities
and site operations and safety organizations. Using a schematic, display
the PF communications network and include available secure networks
and linkages to offsite law enforcement organizations with whom support
agreements exist. In a chart, show the weapons and special equipment
assigned to PF personnel, including members of the response force.
(2) Qualifications and Training. Indicate that the qualifications and training
of the PF conform to current policy requirements. In a chart similar to
Table C-7, Qualifications and Training, list the titles and offices
responsible for implementing and maintaining any plans or procedures
that describe the following pertaining to the PF: qualifications for
employment; the hiring process; initial, specialized and advanced training;
and, other relevant written documentation, such as post and general
orders..
Table C-7. Qualifications and Training
Plan/Procedures Title Responsible Office
Specialized Training Plan Training Department
Tactical Response Plans Department
(3) Special Response Teams (SRT) and Plans. Ensure the availability of
SRTs and current response plans and procedures for implementing site-
specific S&S program strategies and tactics for denial of access, denial of
task, containment, recapture/recovery, pursuit and contingency operations,
as described in current DOE policy. Indicate that requalification training
and exercises are used to verify the effectiveness of SRTs. Identify and
document agreements and MOUs with local, state, and Federal law
enforcement agencies regarding requests for on-site support during a
contingency event. Ensure that a VA was used to assist management in
determining the equipment and deployment of SRTs. In a brief narrative,
confirm the availability of personnel and response plans and procedures
that provide assurance of adequate protection. Indicate that contingency
plans and procedures are available to respond to the activities listed below.
Section 29
(a) Containment/denial of access/denial of task (includes a range of
tactical options designed to either preclude adversary force access
to nuclear weapons/materials or to deny unauthorized removal).
(b) Recapture/recovery or pursuit operations (used when containment/
denial fail and could involve SRTs and other force options
including the use of off-site law enforcement agencies).
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section C
11
Describe the organization, equipment, and training provided to SRTs and
how training and performance testing are used to verify the effectiveness
of SRT planning in the strategies described above. Describe the role of
VA in determining SRT deployment, equipment, and training.
In a chart similar to Table C-7, list tactical response plans and procedures
and the office responsible for implementing and maintaining them.
Use a similar chart to list memoranda or letters of understanding and other
agreements with local, State, or Federal law enforcement agencies
regarding requests for onsite support during a contingency event.
f. Chapter 6, MC&A Program.
Describe the MC&A management program and summarize the results of the
MC&A VA and other MC&A program planning activities. Describe the mission
of the site MC&A organization. Summarize current and planned nuclear
materials processing and storage activities. Using an organization chart, show the
MC&A organization and management structure and the lines of authority and
points of interface with other S&S programs, facility operations, and the
cognizant security authorities’ MC&A organization. Describe the functions and
responsibilities of safeguards personnel and indicate how MC&A activities are
integrated with those of site protection programs and other facility organizations;
include organizational responsibilities for those program elements that support
multiple S&S programs (e.g., portal monitors and access controls). Confirm that
MC&A personnel complete required training.
List, in a chart similar to Table C-8, MC&A Plans and Procedures, the facilities
required to develop and maintain MC&A plans and procedures, the titles of those
plans and procedures, and the office(s) responsible for approving and maintaining
them.
Table C-8. MC&A Plans and Procedures
Facility Name Plan/Procedure
Title
Responsible
Office(s)
ABC Facility ABC Facility
MC&A Plan, 1/1/99 S&S Director
XYZ Facility XYZ Facility
MC&A Plan, 6/9/99 S&S Director
Give the name(s) and date(s) of reports of MC&A VAs and other planning
exercises. Summarize the results of these assessment(s). Identify those
components of the MC&A system that provide the greatest effectiveness against
theft and diversion. Describe actions taken to remediate identified program
deficiencies or to prepare for planned changes in facility nuclear materials
processing and storage activities.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section C
12
Section 30
g. Chapter 7, Site Personnel Security and Human Reliability Programs. Describes
the site-wide program for personnel security that, in conjunction with information
and physical security programs, ensures only authorized access to classified
information or matter, or SNM and confirms that the personnel security program
is in conformance with and implements the requirements prescribed in current
DOE policy. Describe the key elements of the site-wide personnel security
program for access authorizations and, if applicable, the key elements of the site’s
Human Reliability Program (HRP). Describe the method(s) used at the site to
ensure the appropriate level of access authorizations are issued for the category of
material processed or stored at the site and for approving justification, processing,
and reevaluating the need for such access authorizations. Indicate how the
effectiveness of the program is assessed. Indicate the site procedures that require
contractors to perform pre-hire checks to ensure proper qualifications and
suitability of the applicant before submitting requests for access authorizations.
Briefly describe the programs used to mitigate the effectiveness of potential
“insider” activities and the application of these programs in addressing insider
concerns. Provide an organization chart showing the location of the personnel
security organization in relationship to the cognizant security authority and other
contractor S&S organizations. Provide an organization chart identifying the
designated HRP management official in relationship to the cognizant security
authority and the designated HRP certifying official. Verify that the site has a
current HRP implementation plan. List, in a chart similar to Table C-9, Personnel
Security/Human Reliability Program Implementation, the titles of site-wide
personnel security-related plans and procedures, the HRP implementation plan, if
applicable, and the office(s) responsible for implementing and maintaining them.
Table C-9. Personnel Security/Human Reliability Program Implementation
Plan/Procedure Title Responsible Office
XYZ Implementation Plan Security Department
h. Chapter 8, Automated Information Security Program. Briefly describe the
automated information systems for those facilities possessing automated
information systems that process SCI, SAP, weapon data classified S/RD Sigma
1, 2, 14, and 15, or higher. Provide an organization chart showing the responsible
automated information systems security program and its relationship to the
cognizant security authority and contractor organizations.
List, in a chart similar to Table C-10, Automated Information Systems Security
Programs, the title of the automated information systems security program plans
and procedures with the associated office responsible for implementing and
maintaining the plan and procedures, the plans and procedures governing the
automated information system VAs with the associated office responsible for
implementing and maintaining the plan and procedures, and the reports containing
the results of the VAs.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section C
13
Table C-10. Automated Information Systems Security Programs
Plan/Procedure/Report
Title Responsible Office Date
(if pertinent)
Section 31
i. Chapter 9, S&S Equipment Maintenance and Testing Programs. Describe
maintenance and testing programs and life cycle planning, designed to enhance
the continuous operability of S&S-related equipment used in the protection of
Category I SNM (including areas with credible roll up of SNM to a Category I
quantity), and classified automated information systems. Summarize in a
narrative the maintenance and testing programs in use that ensure the availability
and operability of S&S-related equipment and systems. Indicate the availability
of compensatory measures/procedures that are used when equipment is taken out
of service or otherwise not available. Describe how S&S maintenance and testing
programs are incorporated into the Performance Assurance Program Plans.
Indicate how the performance testing and other S&S site and facility maintenance
programs comply with DOE policy.
Describe the life cycle planning conducted for major S&S equipment and
component replacement. Relate how this planning is used to support and validate
S&S equipment budget requirements.
List, in a chart similar to Table C-11, the maintenance, testing, and records
management programs, the relevant plans and procedures that implement the
programs, and the responsible office, as these programs apply to equipment used
by the PF, security related systems, and equipment and instrumentation used for
MC&A. Many of these may be addressed in a single maintenance and testing
program.
Describe the records management program used for scheduling, recording, and
tracking identified S&S maintenance requirements, deficiencies, and testing
schedules.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section C
14
Table C-11. S&S-Related Maintenance, Testing and Records Management Programs
Program Area Plan/ Procedure
Title
Test Plan or
Management Plan
Responsible
Office/Organization
PF
- Equipment
- Training Courses
- Firearms Qualification
- Other
Vehicles/Aircraft
Communications
MC&A
Security Systems
- Personnel Access and
Inspection Equipment
- Security Lighting
- Intrusion Detection and
Assessment Systems
- Electrical Power Supplies
Sensitive Area Access Control
Survey/Inspection Deficiencies
j. Chapter 10, Site Protection Evaluation Program. Chapter 10 is designed to ensure
the availability and use of testing and evaluation programs for site S&S programs
and systems.
In a narrative, describe the programs available and used to evaluate the effective-
ness of S&S protection programs and the interaction of these evaluation tools
(i.e., surveys may focus on shortfalls found in security inspections). At a
minimum, the programs described in Chapters 4, 5, 6, and 8 of the SSSP should
be addressed and the evaluation plan or procedure identified. In a chart similar to
Table C-12, Site Protection Program Evaluation Program, list the names of the
evaluation plans/procedures used by the cognizant security authority to assist in
determining the effectiveness of site and facility protection programs and systems.
List the office responsible for the evaluation plan/procedure and its purpose.
Indicate, in a brief description, that performance testing is used to verify the
effectiveness of S&S systems/programs and to validate VA activities.
Additionally, briefly describe barriers and other systems that cannot be
adequately performance tested to demonstrate protection capabilities and their
integration into protection strategies due to physical, operational, or policy
parameters.
Section 32
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section C
15
Table C-12. Site Protection Program Evaluation Program
Plan/Procedure
Name Or Title Responsible Office Plan or Procedure
Goal/Purpose
Performance Assurance Program Contractor Manager Establish/confirm system
effectiveness
DOE/Contractor
Self-Assessment Program Program Manager Identify program
strengths/weaknesses
Facility Approval, Security
Surveys
Cognizant Security
Authority
Confirm availability and
adequacy of required S&S
programs
Force on Force Exercises Contractor Manager Confirm system effectiveness
Limited Scope Performance Tests Contractor Manager Confirm system effectiveness
Joint Tactical Simulation Model Contractor Manager Confirm system effectiveness
k. Chapter 11, Deviations from DOE Directives.
List all deviations that have been approved. In a table similar to Table C-13,
Deviations from DOE Directives, list the deviation, the officially assigned
deviation number, the directive reference (DOE directive and section within the
directive), and the dates the deviation was approved and expires.
Table C-13. Deviations from DOE Directives
Deviation
Description
Deviation
Number
Directive
Reference
Approval and
Expiration Dates
Provide similar information for those deviations pending approval. This
information should be displayed in a chart similar to Table C-14, Pending
Deviations from DOE Directives.
Table C-14. Pending Deviations from DOE Directives
Deviation
Description
Deviation
Number
Directive
Reference
Approval And
Expiration Dates
l. Chapter 12, Summary of VA and Risk Assessment Results.
(1) Executive Summary. Summarize the VA and risk assessments results for
Category I SNM, Category II SNM (including credible roll up of SNM to
a Category I quantity), theft targets, radiological, biological, and chemical
sabotage targets, and disruption of critical missions.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section C
16
Confirm in the narrative that performance testing was used to validate VA
input data and the results of the VA. Following the narrative, complete a
matrix similar to Table C-15, Summary of Identified Risks, which
identifies the risk associated with the results of the VA. In part 10 of the
matrix, summarize the proposed corrective actions or upgrades. For line
item construction project (LICP) work or other major capital expenditures,
cite the source of the required funding. Use the RP information as the
basis for this summary.
(2) Scope. Describe the targets to be covered, the items/issues to be excluded,
and the limits on the conduct of the VAs in this SSSP.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section C
17
Table C-15. Summary of Identified Risks
Risk Rating (High, Moderate, Low)
Target
Number
Target Location
and
Description
Threat Type and
Number Base
Case
Current
Modif. Rating
(date)
Protected Action and
Adjusted Rating:
Near-Term (<2 yr)
(date)
Protected Action
and Adjusted
Rating: Long-
Term
(>2 yr)
(date)
Remarks
Analyses
Validated by Perf.
Testing
(1) (2) (3) (4) (5) (6) (7) (8) (9) (10) (11)
SNM Theft Targets
1
2
Glovebox 112-A
Bldg. 222
Test samples in
NDA room, Bldg.
222
Terrorist, X outsiders
with help of insider
Criminal Insiders
High
High
High
High
Relocate SI to
access door
Enhance HRP for
NDA technicians
and supervisors
Mod
High
Harden
access portal
Install CCTV
recording for
post-review
of activities
in NDA
room
Low
Mod
Section 33
Install hardware to allow SL
relocation (FY-89 GPP)
SNM protection unchanged, but
probability of attempt reduced thru
HRP and delayed assessment
capability
Yes
Yes
Radiological Sabotage Targets
3 Test reactor #5
North Area, Bldg.
408
Insider Mod Mod Reinforce SI
number when in
use
Low None Low Use overtime when reactor in use-3
times per year
No
Chemical Sabotage Targets
4 Laboratory Bldg. 4 Insider Mod Mod None Low None Low None No
Biological Sabotage Targets
5 Fabrication Room,
Bldg. 1
Insider Mod Mod None Low None Low None No
Disruption of Critical Mission Targets
6
7
Access port 4 D-line
process line, Bldg.
460
Extrusion
equipment in fuel
manufacturing area,
Bldg. 97
Disgruntled employee
Psychotic employee
High
High
Mod
High
Implement 2-man
rule
Establish spares
inventory for
long lead time
parts
Low
Mod
Harden and
remote
control of
portal
Identify
alternate
extrusion
capability
off-site
Low
Low
Install hardware to reduce high
manpower costs (use FY-92 GPP)
Additional physical protection not
cost-effective. Improved spares also
provide repair capability for non-
sabotage outages
Yes
Yes
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section C
18
(3) Methodology.
(a) Theft or Diversion of SNM. Identify the SNM targets subject to
theft and/or diversion. Describe the rationale and mechanism used
to identify these targets.
Using a table similar to Table C-16, SNM Theft/Diversion Targets,
provide a description for each identified SNM target consisting of
the following: the physical location of identified SNM; the type of
material (such as pure products, high grade material, weapons,
etc.) which could include pits, ingots, oxide fuel elements, etc.; the
Category (I through II) and attractiveness level (A through E) of
the target material; and the size and portability of the theft target.
Table C-16. SNM Theft/Diversion Targets
Location SNM Type Category/
Attractiveness Level
Quantity/
Portability
Bldg. 1, Vault Pu-239 ingots Cat. I,/B 2 ingots/man
portable
Bldg. 1, Assay
Room Pu-239 ingots Cat. I,/B 2 ingots/man
portable
Bldg. 1,
Fabrication Room
Pu-238 oxide
powder Cat. II/D 2 canisters/man
portable
Bldg. 2 U-235 fuel
elements
Cat. II, roll-up to Cat. I/
C
20 fuel elements/not
man portable
Bldg. 3 U-235 fuel
elements
Cat. II, roll-up to Cat. I/
C
20 fuel elements/not
man portable
(b) Radiological Sabotage. Identify the radiological targets subject to
sabotage. Describe the rationale and mechanism used to identify
these targets. A key source of information to assist in the
identification and/or elimination of radiological targets is the
facility safety analysis report.
Using a table similar to Table C-17, Credible Radiological
Sabotage Targets, provide a description for each identified
radiological sabotage target consisting of the following: the
physical location of all identified targets, the type of material, the
maximum inventory level, and the material size and configuration.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section C
19
Table C-17. Credible Radiological Sabotage Targets
Location Material
Type
Maximum
Inventory
Material Size and
Configuration
Bldg. 1,
Fabrication
Room
Pu-238 oxide
powder 10 kg Paint Cans, at 50 g
each
Bldg. 4 H3 gas 10 kg Cylinders, at 500 g
each
(c) Biological Sabotage. Identify the biological targets subject to
sabotage. Describe the rationale and mechanism used to identify
these targets. Reference any policy and analyses external to the
SSSP that address biological targets.
Section 34
Using a table similar to Table C-18, Credible Biological Sabotage
Targets, provide a description for each identified biological
sabotage target consisting of the following: the physical location
of all identified targets, the type of material, the maximum
inventory level, and the material size and configuration.
Table C-18. Credible Biological Sabotage Targets
Location Material
Type
Maximum
Inventory
Material Size and
Configuration
Bldg. 1,
Fabrication
Room
Anthrax
solution 10 g 20 petri dish @
0.5 g each
Bldg. 4 Botulism
aerosol 20 g 10 2-liter cylinders,
at 5 kg each
(d) Chemical Sabotage. Identify the chemical targets subject to
sabotage. Describe the rationale and mechanism used to identify
these targets. Indicate whether security protection provided for
chemical sabotage targets is comparable to that provided by the
commercial sector for similar materials. A key source of
information to assist in the identification and/or elimination of
chemical targets is the facility safety analysis report. Reference
any policy and analyses external to the SSSP that address chemical
targets.
Using a table similar to Table C-19, Credible Chemical Sabotage
Targets, provide a description for each identified chemical
sabotage target consisting of the following: the physical location
of all identified chemical sabotage targets, the type of material, the
maximum inventory level, how the security provided is not
comparable to that of the commercial sector, the material size and
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section C
20
configuration, and the exposure level at the NSB for maximum
inventory release.
Table C-19. Credible Chemical Sabotage Targets
Location Material
Type
Maximum
Inventory
Commercial
Sector Security
Difference
Material Size &
Configuration
Exposure
Level at
NSB
Bldg. 5 Chlorine 10,000 lb Lack of access
control
55-gallon
drums, at 350 lb
each
>ERPG III
levels
(e) Disruption of Critical Mission. Identify the disruption of critical
mission targets. Describe the rationale and mechanism used to
identify these targets. Ensure that the evaluation includes how the
disruption would cause an unacceptable impact on national
security.
Using a table similar to Table C-20, Disruption of Critical Mission
Targets, provide a description for each identified target consisting
of the following: the physical location of the target, a description
of the function of the target, the impact to national security, and
the estimated time for recovery.
Table C-20. Disruption of Critical Mission Targets
(f) VA Parameters and Planning Assumptions. Describe/list the
baseline parameters and planning assumptions used in conducting
the VAs. Provide a summary list of parameters and planning
assumptions used in completing VAs. These should include
assumptions discussed and concurred in by appropriate DOE
offices or planning assumptions identified as a result of data
collection/discovery during the VA process.
(g) Critical Path Protection Elements. Describe the process used to
identify critical path protection elements and the types of tests to
which site protection elements are subjected (procedural,
simulation, barrier, equipment, PF, etc.). Using a table similar to
Table C-21, Performance Testing Results of Site Specific Essential
Protection Element Values, provide a list of: physical security
system components for each protection layer (Limited Area [LA],
PA, material access area [MAA], and Target Area), the critical
protection element tested, if any, as determined from performance
testing. Also, indicate the number of tests conducted to obtain
results and the testing frequency used to monitor the protection
Section 35
Location Target Function Impact to National
Security
Estimated time for
Recovery
Site A, Bldg. 4 Fuel cell
production
Increased reliance on
fossil fuels 180 days
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section C
21
element specific value.
Table C-21. Performance Testing Results of Site-SpecificEssential Protection
Element Values
Protection Layer and
Physical Security
System Components
Tested
Critical Elements
Tested
No. of Tests
Used as Basis
for VA values
Test
Frequency Value used
in VA
Attempt to smuggle
firearms through
Portal 1.
36 Quarterly 0.6
PA - Identification and
Intrusion Element Attempt to defeat
door contacts Bldg.
1, door 3.
34 Quarterly 0.7
MAA - Search
Component
Attempt to smuggle
firearms through
MAA portal
24 Once every
2 months 0.8
Target Area -
Identification Component
Attempt to gain
unauthorized vault
access
48 Monthly 0.9
(h) Single Point Failure Analysis. Describe the analyses used to
determine any single-point failures identified during the VA.
Describe/list the single-point failure(s) to include the nature of the
vulnerability, measures to mitigate the vulnerability and the
potential exploitability by an adversary.
(i) Critical Path Scenarios. Describe and provide the critical path
scenarios, including the bounding scenarios, developed during the
VA for each target. Identify the protection system effectiveness
(PE) value for each of these targets. Describe and identify the
critical detection points along each adversary path.
Should multiple targets exist within the same security area, such as
several SNM targets within the same MAA and same building,
bounding critical path scenarios may be described. Provide
justification that supports bounding cases.
For each critical path scenario provide floor plans, diagrams,
sketches, or an adversary path description (as shown in Table C-
22) or, if appropriate, refer to the descriptions that may have been
used previously to illustrate the critical path and protection
elements described in the scenarios.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section C
22
Table C-22. Critical Path Scenarios
Scenario Title: Base Case 1 Results
Facility: Building XYZ PI .
Target Location: Room,123 State, Open PN
Adversary Threat/Adversary: Terrorist w/insider: X# outsider, Y# insiders
Goal Type/Quantity: Oxide, Xx kg PE
VA Path Analysis Tool: ASSESS C
Computer File ID: .PPS, .OUT; .NEU Syst. Eff.:
Neutralization Tool: JTS Syst. Eff.:
Time (Sec) SCENARIO ACTIONS
Total ADV PF
Adversary pre-positions escape vehicles
Adversary mails weapons and explosives into PA (No x-ray or explosives detection
capability)
Adversary proceeds to access control portal
0 20
Adversary attempt to deceit through portal (PD = 0.xx – badge check with xxxx at
access portal). If detected, adversary begins overt actions.
CRITICAL DETECTION POINT
25 CAS receives alert and begins to annunciate alert
20 25 Adversary proceeds to target building XYZ, door 7 on the NE corner
25 Protective Force units begin response
70 Unit A responds to NE corner of building XYZ
55 Unit B responds to SE corner of building XYZ
80 Unit C responds to SE corner of building XYZ
60 Unit D responds to SE corner of building XYZ
45 5 Adversary reaches door 7 to building XYZ, insider opens door 7 into building XYZ
(PD = 0.xx – BMS)
Section 36
50 5 Adversaries enter building XYZ and transverse to vault room 123. CAS receives BMS
door alarm and annunciates the alarm
55 50 Adversaries collect target material
80 Unit B reaches response position
85 Unit D reaches response position
95 Unit A reaches response position
105 5 Adversaries proceed to door 7 to exit building XYZ. Unit C reaches response position.
110 Adversary exits building XYZ via door 7. (PD = xxx - , )
112 Unit A engages adversary
Etc.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section C
23
Identify and describe the point along the adversary path at which
detection is required to allow for sufficient response time for
adversary neutralization to be effected for each of the critical path
scenarios (i.e., critical detection point).
(j) Protection System Effectiveness. Verify that the PE values
identified for each critical path scenario were used to calculate
conditional risk for each identified target. Using tables similar to
those on the following pages (Table C-23, Protection Effectiveness
PE for Theft or Diversion of SNM; Table C-24, Protection
Effectiveness (PE) for Radiological Sabotage; Table C-25,
Protection Effectiveness (PE) for Biological Sabotage; Table C-26,
Protection Effectiveness (PE) for Chemical Sabotage; Table C-27,
Protection Effectiveness (PE) for Disruption of Critical Missions;
Table C-28, Protection Effectiveness (PE) for Theft or Espionage
of Classified Information or Matter; and Table C-29, Protection
Effectiveness (PE) for Other Losses), show the targets and PE
values for each target.
(k) Neutralization Analyses. Identify and describe the mechanism(s)
used to determine/calculate the neutralization value(s) used in the
risk evaluation. Identify and describe the basis for the
neutralization values, parameters that impact the neutralization
calculations and any site-specific issues that modify neutralization
calculations.
(l) Insider Analysis. Describe the analysis for determining the insider
threat for each target class included in the SSSP. This analysis
must include the programs supporting the elimination/mitigation of
select insider groups from the threat spectrum, identification of the
potential insider population, and insider protection programs that
were not included in other protection system elements. Describe
the programs that are factored into the VA process and provide
justification for their use. Identify by position and title the
participants in the HRP.
(m) Conclusions. Provide a summary of system effectiveness for the
identified targets. Document VA analyst’s observations and
recommendations developed as a result of the VA process.
Summarize the system effectiveness using a table similar to C-30,
System Effectiveness Summary.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section C
24
Table C-23. Protection Effectiveness (PE) for Theft or Diversion of SNM
Location Material Type Facility
Condition
Adversary
Type Adversary Scenario Summary Protective Force Response Summary PE Value
Bldg. 1, Vault Pu-239 ingots Open Terrorist Vault open. Outsiders deceit
into PA. Insider crashes out of
Bldg. 1 MAA with material.
Hands off to outsiders.
Adversaries leave PA/site by
vehicle.
Armed response to BMS door alarm.
Containment at MAA boundary.
Positioning of blocking forces at PA
boundary if MAA containment defeated.
Pursuit in PPA if escape from facility.
.7
Bldg. 1, Assay
Room
Pu-239 ingots Open Terrorist Scenario same as vault open
scenario.
Section 37
Scenario same as vault open scenario. .7
Bldg. 1,
Fabrication
Room
Pu-238 oxide
powder
Open Terrorist Scenario same as vault open
scenario.
Scenario same as vault open scenario. .7
Table C-24. Protection Effectiveness (PE) for Radiological Sabotage
Location Material Type Facility
Condition
Adversary
Type Adversary Scenario Summary Protective Force Response Summary PE Value
Bldg. 1,
Fabrication
Room
Pu-238 oxide
powder
Open Terrorist Building open. Outsiders deceit into
PA. Outsiders force MAA boundary by
foot. Insider allows access into Bldg. 1.
Outsiders enter fabrication room,
obtain Pu-238 oxide, defeat HEPA
filters, and vent material to
environment through building
ventilation.
Armed response to MAA boundary
alarm.
.4
Bldg. 4 H3 gas Open Terrorist Building open. Outsiders deceit into
PA. Outsiders force MAA boundary by
foot. Insider allows access into Bldg.
4. Outsiders disperse H3 to the
environment with explosives.
Armed response to MAA boundary
alarm.
.4
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section C
25
Table C-25. Protection Effectiveness (PE) for Biological Sabotage
Location Material Type Facility
Condition
Adversary
Type
Adversary Scenario Summary Protective Force Response Summary PE Value
Open Terrorist Building open. Outsiders deceit into PA.
Insider allows access into Bldg. 5.
Outsiders disperse anthrax to the
environment with explosives.
Building Containment .2 Bldg. 5
Anthrax
Closed Terrorist Outsiders deceit into PA. Outsiders
breach door into Bldg. 5. Outsiders
disperse anthrax to the environment with
explosives.
Building Containment .2
Table C-26. Protection Effectiveness (PE) for Chemical Sabotage
Location Material Type Facility
Condition
Adversary
Type
Adversary Scenario Summary Protective Force Response Summary PE Value
Open Terrorist Building open. Outsiders deceit into PA.
Insider allows access into Bldg. 5.
Outsiders disperse chlorine to the
environment with explosives.
Building Containment .2 Bldg. 5
Chlorine
Closed Terrorist Outsiders deceit into PA. Outsiders
breach door into Bldg. 5. Outsiders
disperse chlorine to the environment with
explosives.
Building Containment .2
Table C-27. Protection Effectiveness (PE) for Disruption of Critical Missions
Location Equipment Type Facility
Condition
Adversary
Type
Adversary Scenario Summary Protective Force Response Summary PE Value
Bldg. 1,
Fabrication
Room
Fuel Fabrication Open Non-Violent
Insider
Insider enters Fab. Room. Starts fire to
destroy equipment located in room.
Building Containment .2
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section C
26
Table C-28. Protection Effectiveness (PE) for Theft or Espionage of Classified Information or Matter
Location Classified
Information or
Matter
Facility
Condition
Adversary
Type
Worst-case Scenario Summary Protective Force Response Summary PE Value
Bldg. 5, Office
Area
TSRD
Documents
Open Non-Violent
Insider
Insider obtains TSRD, makes copies,
encloses copies in envelope, and hand-
carries out of Bldg. 5. Insider mails
classified documents out of PA to off-site
location.
None .2
Table C-29. Protection Effectiveness (PE) for Other Losses
Location Item Facility
Condition
Adversary
Type
Worst-case Scenario Summary Protective Force Response Summary PE Value
Bldg. 5, Lab
Area
R&D Laboratory Open Non-Violent
Insider
Insider starts fire in laboratory. Building Containment .2
Table C-30. System Effectiveness Summary
Section 38
Goal Target Location Operations PE
Theft of SNM Bldg. 1 Vault Day Shift .8
Theft of SNM Bldg. 1 Assay Room Day Shift .8
Theft of SNM Bldg. 1 Fab. Room Day Shift .75
Rad. Sabotage Bldg. 1 Fab. Room Day Shift .85
Rad. Sabotage Bldg. 4 Bldg. 4 Day Shift .9
Chem. Sabotage Bldg. 5 Laboratory Day Shift .8
Bio. Sabotage Bldg. 5 Laboratory Day Shift .8
Indust. Sabotage Bldg. 1 Fab. Room Day Shift .8
Espionage of Classified Bldg. 5 Office Area Day Shift .8
Other Losses Bldg. 5 Laboratory Day Shift .8
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section D
1
SECTION D - SITE SAFEGUARDS AND SECURITY PLAN
RESOURCE PLAN
1. OBJECTIVE. The Resource Plan (RP) identifies safeguards and security (S&S)
resources necessary to ensure protection of Department assets and identifies changes in
resource requirements (i.e., operational requirements, capital equipment, general plant
projects (GPPs) and line item construction projects (LICPs) that directly impact risk,
indirectly impact risk, or derive from changing S&S policy, directives, guidance, or other
Department or other Departmental direction.
a. Operational Requirements. Briefly describe operational requirements relating to
S&S operations that would require increments or decrements to operational
accounts (e.g., program direction, operational support, etc.). Operational
requirements must include, but are not limited to, material consolidation, facility
mission changes, changes in the Design Basis Threat (DBT) impacting site
operations, protective force (PF) redeployments, maintenance and testing
changes, PF manning levels, procuring technical expertise and support personnel,
and additional training requirements. Summarize the pertinent information in a
table such as outlined in Table D-1, Operational Requirements. The table and
supporting narrative must include the following:
(1) the title of each operational requirement;
(2) the basis of the requirement (drivers behind the requirement);
(3) the funding profile and the impacts if not funded (if possible, state the
impact in terms of probability of system effectiveness (PE) and indicate if
this is a new resource requirement); and
(4) provide a status of operational requirements that were previously
authorized but have not yet been completed.
Provide a separate section for each operational requirement.
Table D-1. Operational Requirements
Funding Request/Profile Requirement
(section) Basis FY xxxx
(current year) FY + 1 FY + 2 FY + 3 FY + 4 FY + 5
Currently
in Budget
(Y or N)
Type of
Expense
b. Capital Equipment. Briefly describe identified/proposed capital equipment
procurements and funding requirements that are not part of a LICP or GPP, and
support S&S programs and operations. These procurements could include, but
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section D
2
are not limited to, alarm and assessment system components, material control and
accountability (MC&A) systems, access control system components, and
equipment necessary to complete the S&S mission (e.g., breaching tools, vehicles,
PF armaments, additional capabilities necessary to address changes in the DBT).
Summarize the pertinent information in a table as outlined in Table D-2, Capital
Equipment. The table and supporting narrative must include the following:
(1) a title for each capital equipment procurement;
(2) the basis of the requirement (drivers behind the requirement);
(3) the funding profile and the impacts if not funded (if possible, state the
impact in terms PE, and indicate if this is a new resource requirement); and
Section 39
(4) provide a status of capital equipment upgrades that were previously
authorized but have not yet been completed.
Provide a separate section for each capital equipment procurement.
Table D-2. Capital Equipment
Funding Request/Profiles Capital
Equipment
(section)
Basis FY xxxx
(current year) FY + 1 FY + 2 FY + 3 FY + 4 FY + 5
Currently
in Budget
(Y or N)
c. GPP. Describe significant identified/proposed GPPs that are not part of an LICP
or capital equipment expense but that are necessary to support S&S programs and
operations. These GPPs could include, but are not limited to, alarm and
assessment systems/components, MC&A systems, access control
systems/components, or infrastructure improvements. Summarize the pertinent
information in a table as outlined in Table D-3, General Plan Projects. The table
and supporting narrative must include:
(1) a title for each GPP;
(2) the basis of the requirement (drivers behind the requirement);
(3) the funding profile and the impacts if not funded (if possible, state the
impact in terms PE, and indicate if this is a new resource requirement);
(4) a status of general plan project upgrades that were previously authorized
but have not yet been completed.
Provide a separate section for each GPP.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section D
3
Table D-3. General Plant Projects
Funding Request/Profiles General Plant
Projects
(section)
Basis FY xxxx
(current year) FY + 1 FY + 2 FY + 3 FY + 4 FY + 5
Currently
in Budget
(Y or N)
d. LICPs. Describe current and proposed LICPs that are not part of a GPP or capital
equipment procurement but are necessary to support S&S programs and
operations. Summarize the pertinent information in a table as outlined in Table
D-4, Line Item Construction Projects. The table and supporting narrative must
include:
(1) a title for each LICP;
(2) the basis of the requirement (drivers behind the requirement);
(3) the funding profile and the impacts if not funded (if possible, state the
impact in terms PE, and indicate if this is a new resource requirement); and
(4) provide status of S&S upgrades that were authorized but have not yet been
completed. Discuss any changes to cost estimates (i.e. total estimated cost
[TEC] versus total project cost [TPC]) identified in the previous RP.
Provide a separate section for each LICP.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section D
4
Table D-4. Line Item Construction Projects
Funding Request/Profiles Total Costs Schedule
LICP Title
(section) Basis FY xxxx
(current year) FY + 1 FY + 2 FY + 3 FY + 4 FY + 5 TEC TPC Start Date Finish
Date
Currently
in Budget
(Y or N)
Table D-5. Unfunded/Unsupported Requirements
Original Funding Request/Profiles Requirement
(section) Basis Resource
Type
Base
FY FY xxxx FY + 1 FY + 2 FY + 3 FY + 4 FY + 5
Impact
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section D
5
2. UNFUNDED/UNSUPPORTED REQUIREMENTS. Briefly describe proposed S&S
operational requirements, capital equipment procurements, GPPs, or LICPs that had been
previously identified and have not been funded supported. Summarize the pertinent
information in a table such as Table D-5, Unfunded/Unsupported Requirements. The
table and supporting narrative must include:
a. a title for each unfunded requirement;
b. the basis for the requirement (drivers behind the requirement);
c. the type of resource requested (operating expense, capital equipment, GPP, or
LICP);
d. the fiscal year the requirement was originally identified;
Section 40
e. the proposed funding profile and impacts due to lack of funding (if possible, state
the impact in terms of PE).
Provide a separate section for each unfunded requirement.
3. REFERENCES FOR THE RESOUCE PLAN.
a. Facility SSSP. Provide a reference to the most recent/current SSSP.
b. Programmatic Documentation. Provide a reference (include title, date, and
responsible organization) for any programmatic policy, directive, or guidance
necessitating the allocation of additional resources.
4. HEADINGS AND TERMS FOR TABLES D-1 THROUGH D-5. Following are the
types of data to be included in the RP.
a. Basis.
(1) Compliance.
(2) Risk reduction.
(3) SSSP derived.
(4) Cost-efficiency.
(5) Operational efficiency.
(6) Enhanced operations.
(7) DBT change.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section D
6
b. Type of expense.
(1) Operational = annual recurring cost that will need to be added to the
budget baseline.
(2) Single = one time only expense paid from operating dollars.
c. Total Costs1.
(1) TEC = Total estimated cost.
(2) TPC = Total project cost.
d. Resource Type.
(1) OE = operational expense.
(2) CE = capital expense.
(3) GPP = general plant project.
(4) LICP = line item construction project.
(5) BASE FY = fiscal year in which the resources were identified and
requested.
e. Impact.
(1) Continued risk.
(2) Cost escalation.
(3) Unable to comply with xxxx (list applicable directive).
(4) Programmatic impact.
(5) Operational impact.
(6) Other (list).
1 As defined in DOE O 413.3, Chg 1, Project Management for the Acquisition of Capital Assets.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section E
1
SECTION E - VULNERABILITY ASSESSMENT PROGRAM
1. OBJECTIVE. The Vulnerability Assessment (VA) Program must consider other
programs such as protective force (PF), material control and accountability (MC&A),
emergency operations, safety, maintenance, facility operations, personnel security,
physical protection, and information security.
2. CONDUCTING VULNERABILITY ASSESSMENTS. The process of conducting a VA
includes gathering data that describe the physical and operational characteristics of a
safeguards and security (S&S) system, assigning values such as delay and detection, and
analyzing the results to determine the relative effectiveness in conjunction with the
adversary’s capabilities as identified in the Design Basis Threat (DBT) and the Adversary
Capabilities List (ACL). Below is a description of the VA process.
a. Assumptions. Assumptions and scoping agreements must be defined. All
assumptions must be documented in the VA report.
b. Threat. The person responsible for the conduct of VAs, hereinafter referred to as
the analyst (see paragraph 9. of this Section), must understand how the DBT
relates to VAs. The analyst performing the VA must apply DOE Headquarters
(HQ), regional and local threat guidance.
(1) DOE HQ Threat.
(a) The DBT must be used to define threat against which VA analysts
evaluate the protection system
(b) The site’s protective systems must be analyzed against the ACL.
(2) Regional and local threats must be considered during the conduct of VAs.
c. Targets. All security interests whose loss, theft, compromise, and/or unauthorized
use will affect the national security and/or the health and safety of DOE and
contractor employees, the public, the environment, or DOE programs are potential
targets. The analyst must consider target configurations and conditions, as well as
operational conditions and acquisition times.
Section 41
d. Modeling. Modeling is used to analyze S&S programs, interests, assets, and the
effectiveness of program implementation. Modeling can include computer-based
tools and simulations, table-top analyses, and subject matter expert analyses.
Section E, Appendix 2, VA Modeling Tools, lists those modeling tools approved
by DOE. Methods to ensure that the models accurately reflect the facility posture
must be part of the final VA results. The modeling process must establish critical
pathways. The following must be considered:
(1) facility characterization;
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section E
2
(2) system effectiveness models and equations must be used. Section E,
Appendix 3, System Performance Effectiveness Equation, delineates the
system effectiveness equation;
(3) response force times;
(4) the probability of neutralization (PN) must be calculated using data
available regarding the PF response and their ability to interrupt and
neutralize an adversary. The methods used must be documented and
retained as part of the evidence file. The calculated number for PN must
be derived from more than one source, one of which must be joint tactical
simulation (JTS), joint conflict and tactical simulation (JCATS), or force-
on-force (FoF) exercises;
(5) blast effect modeling must consider blast effects on barrier breaching, a
force multiplier, and target buildings;
(6) table-top methods used to determine system effectiveness must be
documented and a means provided to allow for validation or verification;
(7) radiological sabotage must be fully analyzed against the DBT and ACL.
Existing information from safety analyses can be used but must be
analyzed to consider deliberate rather than accidental release;
(8) chemical and biological sabotage must be analyzed against the DBT and
ACL;
(9) the analysis must use the thresholds stated in DOE O 470.3, Design Basis
Threat (DBT) Policy; and
(10) the use of chemical and biological agents must be analyzed as a force
multiplier. Methods of release and mitigation measures must be a part of
the analysis.
e. Performance Testing. If conducted, the results of the following tests (including
validation) must be considered in determining system effectiveness:
(1) FoF exercises;
(2) limited scope performance tests (LSPTs);
(3) alarm response and assessment performance tests (ARAPTs);
(4) breaching test data; and
(5) critical system element tests.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section E
3
f. Results. The results of VAs indicate PE. The VA results must be used for
determining:
(1) protection system effectiveness reporting;
(2) S&S upgrades;
(3) manning/armament levels for the PF; and
(4) justifications for waivers of and exceptions to S&S policy.
g. VA Practitioner Training. VA practitioners must successfully complete VA
Program training within 2 years of appointment. This requirement can be met
through the National Training Center (NTC).
3. QUALITY ASSURANCE. The analyst must verify the data used for the analyses. These
data include:
a. modeling data to include detection, assessment, delay, interruption, neutralization,
PF response times, etc.;
b. all facility modeling characterization direct settings, rationales, and
documentation;
c. performance test results and documentation; and
d. sensitivity analyses such as single point failure and critical system element
analyses.
4. VULNERABILITY ASSESSMENT. All information used to support or document VAs
must be maintained and made available upon request. Examples include:
Section 42
a. modeling inputs;
b. PF response;
c. adversary capabilities;
d. blast effects;
e. sabotage data;
f. timeline data; and
g. neutralization data.
5. ASSIGNING FIGURES OF MERIT. “Figures of merit” is defined as numerical values
and/or qualitative ratings assigned to component systems and personnel associated with
the protection system. Collectively the qualitative and/or quantitative measures provide
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section E
4
the basis for determining system effectiveness. Approved reference materials must be
used to provide initial data and to calculate accurate detection and delay numbers. A list
of approved references is provided in DOE M 470.4-7, Safeguards and Security Program
References. Reference materials are to be used only as a basis for the relative figures of
merit. Non-default figures of merit must be documented and based on performance
testing or engineering studies.
6. CRITICAL SYSTEM ELEMENTS. Critical system elements are components or
subcomponents of an S&S protection system that directly affects the ability of the system
to perform a required function. Critical system elements may be equipment, procedures,
or personnel. Failure of a critical system element would result in the protection system
effectiveness of the target being reduced to levels requiring management action. Critical
system elements must be:
a. identified for every target that requires a VA;
b. specifically delineated such that specific performance tests can be performed to
determine the ability of the protection measures to perform their intended
function; and
c. tested, documented, and the results analyzed to validate element effectiveness.
7. VULNERABILITY ASSESSMENT REPORTS. The vulnerability assessment report
(VAR) documents the results of a VA. The VARs must include targets analyzed,
methodology used, system effectiveness results, parameters and assumptions under which
the VA was conducted, and reference to evidence files. VARs published in support of an
SSSP should conform to the suggested format given in Section E, Appendix 4, Suggested
VA Report Format. The approval chain for VARs is below.
a. The analyst responsible for the VA must sign the report.
b. Line management responsible for the facility/site VA Program must approve the
report.
c. DOE line management responsible for the VA Program must concur with the
report.
d. The DOE cognizant security authority must concur with the report.
8. SYSTEM EFFECTIVENESS. Only the Secretary of Energy or the Deputy Secretary can
accept low protection system effectiveness that results in high risk. Cognizant Under
Secretaries can accept marginal protection system effectiveness that results in moderate
risk. If the results of a VA, survey, self-assessment, audit, or inspection conducted by the
cognizant security authority, Departmental element, Office of Security, or Office of
Independent Oversight and Performance Assurance indicate a decreased (low or
marginal) protection system effectiveness that is not mitigated by compensatory
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section E
5
measures based on a risk management determination (see Section A, 2.e.), the following
actions must be initiated:
a. Low Protection System Effectiveness.
(1) Once a low protection system effectiveness condition that results in high
risk is identified, that condition must be reported to the responsible
Departmental element within 4 hours.
Section 43
(2) A corrective action plan must be submitted to the responsible
Departmental element within 8 hours, with a copy to the Office of
Security.
(3) The Departmental element must make formal notification to the Secretary
or Deputy Secretary within 24 hours.
(4) The Departmental element in consultation with the Office of Security
must provide comments on the protection system effectiveness and
recommendations to the Secretary/Deputy Secretary within 36 hours.
(5) The responsible Departmental element must update the Secretary or
Deputy Secretary on low protection system effectiveness conditions every
30 days with an information copy to the Office of Security.
b. Marginal Protection System Effectiveness.
(1) Once a marginal protection system effectiveness condition that results in
moderate risk is identified, that condition must be reported to the
responsible Departmental element within 2 working days.
(2) The Departmental element must notify the appropriate Under Secretary
within 3 working days.
(3) A corrective action plan with recommendations must be submitted to the
responsible Departmental element within 5 working days with a copy to
the Office of Security.
(4) The Office of Security must provide comments to the Departmental
element within 5 working days.
(5) The responsible Departmental element must update the Secretary or
Deputy Secretary and appropriate Under Secretary on marginal protection
system effectiveness conditions every 90 days with an information copy to
the Office of Security.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section E
6
9. TRAINING AND CERTIFICATION.
a. The analyst responsible for the conduct of Vulnerability Assessments must
complete the Department-approved training program (scheduled to be fully
implemented by 2008).
b. The analyst must be certified as outlined in the Vulnerability Assessment
Certification Program Manual which is currently under development.
c. Any person currently conducting VAs may be “grandfathered” until such time as
the Vulnerability Assessment Certification Program Manual is issued.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section E
Appendix 2-1
SECTION E
APPENDIX 2 – VULNERABILITY ASSESSMENT MODELING TOOLS
1. ASSESS – Analytic System and Software for Evaluating Safeguards and Security.
2. ATLAS – Adversary Time Line Analysis System.
3. BATLE – Brief Adversary Threat Loss Estimator.
4. JTS – Joint Tactical Simulation.
5. JCATS – Joint Conflict and Tactical Simulation.
6. AT Planner – Anti-Terrorist Planner.
7. BLAST X – Explosive Effects Analysis Software.
8. BLAST FX – Explosive Effects Analysis Software.
9. ConWEP – Conventional Weapons Effects Program.
10. BEEM – Blast Effects Estimation Model.
11. HOTSPOT – HOTSPOT Health Physics Code provides the capability to calculate the
radiation effects associated with the short-term (less than 24 hours) atmospheric release
of radioactive materials.
12. RSAC – Radiological Safety Analysis Computer program calculates the consequences of
a release of radionuclides to the atmosphere.
13. ACATS – Airborne Chromatograph for Atmospheric Trace Species.
14. ISA – Iterative Site Analysis.
15. VISA – Vulnerability of Integrated Security Analysis.
16. VISA II – Vulnerability of Integrated Security Analysis II.
17. ERAD – Explosive Release Atmospheric Dispersion.
18. ALOHA – Area Locations of Hazardous Atmospheres.
19. ARAC – Atmospheric Release Advisory Capability.
Section 44
20. ACCS 2 – Accident Consequence Code System for the calculation of the health and
economic consequences of accidental atmospheric radiological releases.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section E
Appendix 2-2
21. HPAC – Hazard Prediction Analysis Code provides the capability to accurately predict
the effects of hazardous material releases into the atmosphere.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section E
Appendix 3-1
SECTION E
APPENDIX 3 - SYSTEM PERFORMANCE EFFECTIVENESS EQUATION
The methodology requires the determination of the probability of sensing, probability of
assessment, and probability of detection at each layer. These are then combined to determine the
contribution to overall system effectiveness represented by each layer. Mathematically, this can
be expressed as the equation:
PEL = PIL x PNL = PDL * PNL = PAL * PSL * PNL
Where:
PEL is the system effectiveness contribution for layer L;
PIL – Probability of Interruption given first detection at layer L, PIL = PDL if detection on
layer L is timely, and is equal to 0 (PIL = 0) if detection is not timely;
PDL – Probability of Detection at layer L, PDL = PSL x PAL on layer L. PDL is the
probability of first detection at layer L, given that detection has not occurred at an earlier
layer, multiplied by the probability of sensing at an earlier layer, multiplied by the
probability of sensing at layer L (PSL) and the probability of assessment at layer L (PAL);
PSL – Probability of Sensing on layer L;
PAL – Probability of Assessment on layer L; and
PNL – Probability of Neutralization given first detection at layer L.
L is defined as the number of detection layers in the system before the critical detection
point (CDP) in the adversary path(s). Detection after the CDP cannot not be counted.
PE is defined as the system effectiveness of the layer. The system effectiveness of the
layer is the product of the probability of interruption of the layer and the probability of
neutralization given that detection occurred at that layer (PI x PN). The probability of
neutralization is determined discretely for each layer given detection at the layer. The
neutralization determination is made if detection (regardless of the extent) takes place at
the layer in question. Neutralization will occur sometime past the detection point and
would be valid for the probability of neutralization of that specific layer.
PD of the layer is defined as the product of the probability of sensing and the probability
of assessment of the layer (PS x PA). Note that detection and assessment will be different
between the elements of the layer and between layers.
PIL of the layer is defined as PIL = PDL if detection on layer L is timely, and is equal to 0
(PIL = 0) if detection is not timely.
The Σ symbol is the summation of terms. The summation symbol is defined as:
CANCELE
D
DOE M 470.4-1
DRAFT XX-XX-05
Part 1, Section E
Appendix 3-2
n
n
i
i kkkk +++≡∑
=
...21
1
The Π symbol is the product of terms. The product symbol is defined by:
n
n
i
i ffff ×××≡∏
=
...2
1
1
Section 45
For those protection systems based on sensing, assessment, detection, interruption, and active
neutralization of an adversary, credit can only be taken up to the “point on the pathway” at which
the total of the adversary task time, engagement times, and delay times exceeds the protective
force response times. This limiting criteria eliminates credit being taken for protection system
capabilities that are not engaged prior to the adversary completing their objective. For denial
based protection systems, the “point on the pathway” is the critical detection point. The critical
detection point is defined as the point at which the protective force must have timely detection,
assessment, and response to initiate a response to have a high probability of success in the
neutralization of the adversary or denial of the adversary’s task/objective. Therefore, for a
facility employing multiple, complementary layers of protection, the representative total
protection system effectiveness is calculated up to the point at which the protection systems can
still effectively engage an adversary prior to completion of the objective.
The contributions of each layer along the adversary pathway are then combined to determine the
overall system effectiveness, where the overall system effectiveness is provided by the sum of
the contributions of each layer (only those encountered along the adversary pathway) to the
system effectiveness.
An example of the system effectiveness equations for a three-layer system protecting SNM
would be as follows:
In extended notation, the Overall System Effectiveness is:
PE = (PA1 x PS1 x PN1) + [(1 – (PA1 x PS1)) x (PA2 x PS2 x PN2)] + {(1 – ((PA1 x PS1) + [(1 –
(PA1 x PS1)) x (PA2 x PS2)])) x (PA3 x PS3 x PN3)}
Which reduces to:
PE = (PD1 x PN1) + [(1 – PD1) x (PD2 x PN2)] + {(1 – (PD1 + [(1 – PD1) x PD2])) x (PD3 x
PN3)},
and since PIL = PDL when detection is timely,
PE = (PI1 x PN1) + [(1 – PI1) x (PI2 x PN2)] + {(1 – (PI1 + [(1 – PI1) x PI2])) x (PI3 x PN3)}
PE = PE1 + [(1 – PI1) x PE2] + {(1 – (PI1 + [(1 – PI1) x PI2])) x PE3)}
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section E
Appendix 4-1
SECTION E
APPENDIX 4 - SUGGESTED VULNERABILITY ASSESSMENT REPORT FORMAT
1.0 Executive Summary
Objective
Purpose and Summary of Protection Effectiveness
2.0 Introduction
Scope
Changes in the VAR
Methodology and Assumptions
3.0 Target Identification and Description
Theft or Diversion
Sabotage (Radiological)
Sabotage (Chemical and/or Biological)
Theft or Espionage of Classified Information or Matter
Other Losses
4.0 Threat Definition
Adversary Type(s)
Adversary Attributes
5.0 S&S Protection Elements
Physical Security Systems
Protective Forces (Response Strategies, Interruption, Neutralization)
Material Control and Accountability
Reliability Program
6.0 Performance Testing
Program Description
Site Protection Elements
Critical Protection Elements
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section E
Appendix 4-2
7.0 S&S Protection Effectiveness
Scenario
Protection Effectiveness
Validation Testing
8.0 Summary of S&S Protection Effectiveness
Protection Effectiveness
Recommendations
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section F
1
SECTION F - PERFORMANCE ASSURANCE PROGRAM
1. OBJECTIVE. To demonstrate the effectiveness of the protection provided Departmental
safeguards and security (S&S) interests by systematically evaluating all protection
program essential elements.
Section 46
2. REQUIREMENTS. Each performance assurance program must be developed to validate
the performance of all essential S&S protection elements.
a. Operability and Effectiveness. Performance assurance programs must provide for
operability and effectiveness testing of each protection program essential element
or component.
(1) Operability tests provide measures of integrity and must check the
essential elements or total system to confirm operability.
(2) Performance tests provide comprehensive assurance that protection
program elements are performing as designed and provide the required
levels of protection.
(a) Performance tests results are used to validate the effectiveness of
all elements of a layered S&S system.
(b) Performance tests are not substitutes for compliance with
requirements.
b. Continuity. Performance assurance programs must evaluate operational
continuity of all S&S essential elements. Limited Scope Performance Tests
(LSPTs) and/or force-on-force (FoF) tests may be used as a means of meeting
specific performance assurance testing requirements. Performance assurance
programs require that:
(1) new protection program essential elements and components must be
validated through acceptance testing before operational use;
(2) essential elements that have been repaired or undergone maintenance must
be validated through testing before use;
(3) the protective force (PF) is performance tested to ensure that approved
protection strategies of denial, containment, recapture, recovery, and
pursuit can be accomplished; and
(4) essential elements of the protection program security systems and
subsystems are performance tested to ensure that system detection,
assessment, and response to alarms and adversarial actions meet stated
requirements.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section F
2
c. Reliability. Each essential element whose failure would reduce protection to an
unacceptable level must be tested at frequencies that provide high assurance of
operability and reliability.
(1) Testing frequencies must reflect site-specific conditions and operational
needs.
(2) Testing frequencies must be documented for each essential element.
d. Performance Tests. At least every 365 days, an integrated performance test
encompassing all essential protection elements associated with a comprehensive
site or facility threat scenario must be conducted to evaluate the overall facility
S&S effectiveness.
(1) Those Category I facilities requiring denial protection strategies must
conduct integrated performance testing on a quarterly basis (at least every
3 months).
OR
(2) Those sites with multiple Category I facilities requiring denial protection
strategies may rotate quarterly performance testing so that at least one
facility is tested on a quarterly basis (at least every 3 months). However,
an integrated performance test for all Category I facilities must occur at
least once every 365 days.
e. Documentation.
(1) Performance Assurance Program Plan. This plan must be an integral part
of the site safeguards and security plan (SSSP)/site security plan (SSP), or
material control and accountability (MC&A) plan, as applicable. The
performance assurance program plan must describe the program and its
administration and implementation by:
(a) identifying protection elements for the protection of Category I and
II special nuclear material (SNM) and Top Secret matter;
Section 47
(b) describing how the performance of these elements is to be ensured,
including the manner in which credit is taken for activities
performed by external oversight organizations;
(c) addressing how deficiencies identified during performance
assurance activities are to be corrected.
(2) Performance Assurance Reports. The results of performance assurance
program testing must be documented.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section F
3
(3) Document Retention. Record keeping systems must provide an audit trail
for performance assurance activities and reports.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section G
1
SECTION G - SURVEY, REVIEW, AND SELF-ASSESSMENT PROGRAMS
1. OBJECTIVES.
a. Provide assurance to the Secretary of Energy, Departmental elements, and other
government agencies (OGAs) that safeguards and security (S&S) interests and
activities are protected at the required levels.
b. Provide a basis for line management to make decisions regarding S&S program
implementation activities, including allocation of resources, acceptance of risk,
and mitigation of vulnerabilities. The results must provide a compliance- and
performance-based documented evaluation of the S&S program.
c. Identify S&S program strengths and weaknesses, develop and complete a process
improvement schedule, and use the results to correct and improve the overall S&S
program.
d. Provide documentation of oversight and assessment activities.
2. REQUIREMENTS.
a. Types and Frequencies of Surveys and Assessments.
(1) Initial Surveys. Initial surveys must be conducted at facilities where there
will be a facility clearance established for a facility with an importance
rating of: A, B, C, or PP (see Section I, Chapter II). Survey activities
must be comprehensive and result in a satisfactory composite rating prior
to a facility clearance (FCL) being granted.
(2) Periodic Surveys. Periodic surveys are conducted for all facilities and
must cover all applicable topics to ensure survey program objectives are
met. The periodic survey may be composed of multiple special survey
reports, providing all the requirements of this Section are met. Integration
of internal and external reports including quality assurance, property
appraisals, performance assurance, and other evaluation reports may be
used to augment the requirement for a periodic survey. A DOE Federal
facility (e.g. site office) conducting a periodic survey are is required to
perform self-assessment as noted in 6, below.
(a) Facilities with importance ratings of A, B, or C must be surveyed
once every 12 months (with the exception of Category IV SNM
only facilities – see (c) below).
(b) Facilities with an importance rating of PP must be surveyed once
every 24 months.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section G
2
(c) For facilities with Category IV special nuclear material (SNM) and
nuclear material, including source material, the nuclear material
control and accountability (MC&A) topical area must be surveyed
at least every 24 months.
(d) Facilities with importance ratings of D, NP, or E do not require
surveys but do require periodic reviews (see (5), below).
(3) Special Surveys. Special surveys may be conducted at facilities for
specific limited purposes. Examples include extended survey activities,
technical security activities, “for cause” reviews, line management
direction, shipment of nuclear and/or classified information or matter, or a
change in the contractor operating a government-owned facility.
Section 48
(4) Termination Surveys. Termination surveys must be conducted to verify
the termination of Departmental activities and appropriate disposition of
S&S interests. Examples of survey activities include: the appropriate
disposition, destruction, or return of classified information or matter,
SNM, hazardous material, property, security badge retrieval, debriefings,
and verification of the termination or transfer of Department of Energy
(DOE) access authorizations.
(a) Onsite termination surveys must be conducted at facilities
possessing Top Secret matter, sensitive compartmented
information (SCI)/ special access program (SAP) information or
matter, or SNM.
(b) Onsite or correspondence termination surveys must be
accomplished for all other possessing facilities.
(5) Periodic Reviews. A documented review of entities (D, NP, and E
facilities) such as subcontractors, consultants, and common carriers must
be performed by the DOE cognizant security authority at least every 5
years.
(6) Self-Assessments. Self-assessments must be conducted between the
periodic surveys conducted by the cognizant security authority and
include all applicable facility S&S program elements. The self-
assessment must ensure the S&S objectives are met (see paragraph 1.,
above). Federal facilities may use the self-assessment to substitute for the
Periodic Survey requirement. NP facilities are not required to conduct
self-assessments. However, sponsoring organizations (Federal or
contractor) must include in their self-assessments a thorough review of
their registration program for NP facilities which may result in a program
review of identified subcontractors.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section G
3
(7) Reviews or Inspections by Other DOE Elements or OGAs.
Reviews/inspections conducted by other DOE elements (including site
quality assurance programs) or OGAs may be used to meet survey
requirements. When using reviews/inspections conducted by other
organizations to meet the requirements of the survey, the guidelines below
must be followed.
(a) The review/inspection must have been conducted within the survey
period.
(b) Applicable portions of the review/inspection must be attached to
the survey report.
(c) Portions of topical and subtopical areas not covered by the
review/inspection must be surveyed.
(d) If ratings were not assigned during the review/inspection, the
surveying office must analyze the impact of any deficiencies and
assign ratings.
(8) Extension of Frequency. The results of previous surveys may affect the
frequency of future surveys. The interval between periodic surveys may
be increased up to 24 months by the DOE cognizant security authority.
Documentation of the justification for increases in the interval of periodic
surveys must be maintained by the DOE cognizant security authority.
(a) The following conditions must be met for extensions:
1 the facility was rated satisfactory during the most recent
survey activity;
2 the facility has no unmitigated deficiencies that impact the
security posture of the facility, and all applicable topical
area ratings are satisfactory from the previous survey; and
3 all applicable topical area ratings from the most recent self-
assessment are satisfactory, and the DOE cognizant
security authority concurs with the ratings.
(b) Increasing the interval between surveys for a facility possessing
Category I SNM or with credible roll-up to Category I SNM must
be approved, in writing, by the Associate Administrator for
Defense Nuclear Security or the Under Secretary for Energy,
Science, and Environment.
Section 49
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section G
4
(c) All modifications to survey frequency requirements must be
documented in the Safeguards and Security Information
Management System (SSIMS).
b. Scope and Methodologies. Surveys and self-assessments must provide an
integrated evaluation of all topical and subtopical areas to determine the overall
status of the S&S program and ensure the objectives of this Section are met (see
paragraph 1., above). The integrated evaluation is a comprehensive synergistic
approach using multiple S&S program elements that ensures total system
effectiveness and, if properly implemented, will meet the objectives identified in
paragraph 1., above. The scope of these activities and the methods used must
include those listed below.
(1) Compliance. Compliance reflects the status of the S&S program as
measured against implementation of applicable Federal statutes,
regulations, policies, approved site safeguards and security plans
(SSSPs)/site security plans (SSPs), and other approved security plans.
(2) Performance. Performance indicates the degree to which the elements of
the S&S program meet protection objectives based on the operational
testing of program elements.
(3) Comprehensiveness. Comprehensiveness identifies the breadth of
protection afforded all activities and interests within a facility. This is
accomplished by an evaluation of the adequacy and effectiveness of
programs and a thorough examination of the implementation of policies,
practices, and procedures to ensure compliance and performance. All
applicable topical areas identified on DOE Form (F) 470.8,
“Survey/Inspection Report” Form must be evaluated.
(4) Other. The scope of special and termination surveys is determined by the
DOE cognizant security authority in coordination with the surveying
office. Determinations of survey scope are predicated on the nature or
status of operations at the facility, activity, or element being surveyed.
These surveys may not cover all topical areas identified on DOE F 470.8.
3. CONDUCT. Local survey and self-assessment procedures implementing this Section
must be developed, documented, and approved by the cognizant security authority.
Procedures must ensure completion of the objectives contained in paragraph 1., above
and must include the requirements listed below.
a. Team Composition. Survey and self-assessment team personnel must possess
qualifications, experience, and training sufficient to review and inspect the
topical/subtopical areas of the survey/self-assessment. The National Training
Center (NTC) provides training courses for survey team leaders and team
members.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section G
5
(1) Survey teams must be led by a Federal employee and may be composed of
Departmental Federal and contractor personnel.
(2) Self-assessments must include at least one person from the cognizant
security authority.
b. Planning, Scheduling, and Integration. Surveys and self-assessments must be
planned, scheduled, and conducted in an integrated manner to achieve the
objectives identified in paragraph 1., above. If topical and subtopical area
evaluations are performed separately, the surveying office must document and
integrate the results of each into a single (periodic) survey report that includes a
composite facility rating. The frequency between topical and subtopical areas
cannot exceed the frequency for the single (periodic) survey.
Section 50
c. Validation. Results must be validated by methods including, but not limited to,
document reviews, performance testing, and interview analyses and observations.
d. Exit Briefing. An exit briefing must be conducted with the surveyed or assessed
organization to include the minimum facts:
(1) program strengths and weaknesses, including all findings;
(2) corrective action reporting requirements for all open findings, regardless
of source; and
(3) topical and composite ratings. For less than satisfactory ratings, the
communication of the composite rating initiates the actions required in
paragraph 8. of this Section.
4. FINDINGS.
a. Identification and Documentation. Findings are any validated program deficiency
(failure to meet a performance or compliance requirement) regardless of source.
Findings may be reflected in documents resulting from internal and external
reviews, audits, appraisals, and other sources (e.g., the Office of Independent
Oversight and Performance Assurance [OA], the Government Accountability
Office [GAO], the Office of the Inspector General (IG), previous surveys, self
assessments, etc.).
All open findings must be reviewed during the survey or self-assessment to
validate the status of corrective action and to evaluate the impact on the existing
S&S program.
Findings identified during the current survey or self-assessment must be reported
immediately to the Departmental element and contractor line management if a
vulnerability to national security, classified information or matter, nuclear
materials, or Department property results, or may result, in a programmatic
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section G
6
impact to the Department. Findings identified during a survey or self-assessment,
even if closed during the survey or self-assessment activity, must be documented
in the associated report.
b. Tracking. Findings and deficiencies, regardless of source, and corrective action
plans (milestones and estimated completion dates) must be entered into SSIMS in
accordance with SSIMS guidelines and tracked until closed. Quarterly status
reports must be entered into SSIMS by January 15, April 15, July 15, and October
15, of each year. Self-assessment deficiencies are not required to be entered into
SSIMS; however, a local mechanism/system must be used to track these
deficiencies and corrective action until closed.
c. Trending. Trending evaluations must be considered in the resolution of findings
in the subtopical area of program management to determine if systemic and
systematic causal factors exist within the S&S program. Results of this
evaluation that indicate negative trends must be analyzed to ensure corrective
action plans address root causes and the need to ensure continuous improvement
of the S&S program.
5. RATINGS.
a. Types. Ratings must be based on the effectiveness and adequacy of the program
at a facility and reflect a balance of performance and compliance results as well as
the impact of the deficiency(ies) (e.g., findings, IG recommendations, etc.) and
mitigating factors. The ratings listed below must be used for all surveys (except
termination), reviews, and self-assessments. Does Not Apply (DNA) and Not
Rated (NR) may also be used in applicable situations.
(1) Types of Ratings.
(a) Satisfactory. The element being evaluated meets protection
objectives or provides reasonable assurance that protection
objectives are being met.
Section 51
(b) Marginal. The element being evaluated partially meets protection
objectives or provides questionable assurance that protection
objectives are being met.
(c) Unsatisfactory. The element being evaluated does not meet
protection objectives or does not provide adequate assurance that
protection objectives are being met.
(d) Inspection Ratings. “Effective Performance,” “Needs
Improvement,” and “Significant Weaknesses” are indicators of a
management system performance level as outlined in DOE O
470.2B, Independent Oversight and Assurance Program, dated 10-
31-02.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section G
7
(2) Rating Determinations.
(a) Existing Conditions. Ratings must be based on existing conditions
at the end of the survey and not future or planned corrective
actions or conditions.
(b) Impact. Ratings must be based on the impact of all open
deficiencies, regardless of source.
(c) Marginal or Unsatisfactory Ratings. Less than satisfactory ratings
in any topical area must be based on validated weaknesses in the
S&S system or deficiencies in performance.
(d) Topical Area Ratings. A topical area rating must not be marginal
for consecutive survey periods and will be assigned an
unsatisfactory rating unless one of the following conditions
applies.
1 The current survey of the topical area results in a
satisfactory rating.
2 The previous survey that resulted in a marginal rating
identified different deficiencies and reasons for the rating.
3 The deficiencies and reasons that were the basis for the
previous marginal rating were related to the completion of
a line item construction project or upgrade program. In that
case, acceptable interim measures must have been
implemented, physically validated pending completion of
the project, and documented in the survey report.
(e) Subtopical Ratings. The decision whether or not to use all
subtopical ratings must be documented in local procedures.2
Regardless of the rating method used, the report must include the
evaluation of all required subtopical areas which must be used as
part of the appropriate topical area rating justification and
rationale.
(f) Justification and Rationale. All ratings must be supported and
documented to include the rating justification and rationale.
6. REPORT CONTENT.
a. Initial/Periodic Survey Reports and Self-Assessment Reports. Reports must
contain the following items.
2 A minimum of one subtopical area rating must be used to effect the rating for the topical area in SSIMS.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section G
8
(1) A completed DOE F 470.8 (or equivalent for self-assessments).
(2) An executive summary containing:
(a) the scope, methodology, period of coverage, duration, date of the
exit briefing to management;
(b) a brief overview of the facility, function, scope of operations, and
contractual information (e.g., contract number, award and
expiration dates, contract type, identification of security clauses,
identification of the security and overall scores assigned to the
most recent contract appraisal);
(c) a brief synopsis of major strengths and weaknesses that impact the
effectiveness of the facility’s overall S&S program, including
identification of any topical areas rated less than satisfactory;
(d) the overall composite facility rating with supporting rationale; and
(e) a reference to a list of findings identified during the survey or self-
assessment.
(3) An introduction containing:
Section 52
(a) the scope, methodology, period of coverage, duration, date of the
exit briefing to management; and
(b) a description of the facility, its function and scope of operations,
security interests, and contractual information (e.g., contract
number, award and expiration dates, contract type, identification of
security clauses, identification of the security and overall scores
assigned to the most recent contract appraisal).
(4) Narrative for all rated topical and subtopical areas that includes:
(a) a description of the site’s implementation of the program element;
(b) the scope of the evaluation;
(c) a description of activities conducted;
(d) the evaluation results and associated issues (including other
Department elements or OGA review or inspection results related
to this topic/subtopic that were included in the survey);
(e) the identification of all findings, including new and previously
identified open findings, regardless of source (e.g., OA, IG, GAO),
and their current corrective action status; and
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section G
9
(f) an analysis that provides a justification and rationale of the factors
responsible for the rating.
(5) Attachments, including:
(a) a copy of the current DOE F 470.2, “Facility Data and Approval
Record” (FDAR);
(b) a listing of all active DOE F 470.1, “Contract Security
Classification Specification” (CSCS), or DD F 254, “Contract
Security Classification Specification;”
(c) a listing of all new findings resulting from the survey/self-
assessment;
(d) a listing of all previous findings that are open, to include the
current status of corrective action;
(e) a listing of team members including names, employer, and their
assigned area(s) of evaluation; and
(f) a listing of all source documentation used to support the
survey/self-assessment conduct and results (e.g., GAO, IG, OA,
and similar assessment documents).
b. Special Survey Reports. Special survey reports must follow the format and
content for initial and periodic survey/self-assessment reports except that an
executive summary is not required. Attachments must be included as appropriate
to the scope of the special survey.
c. Reports for Non-Possessing Facilities. Reports for non-possessing facilities must
include:
(1) a completed DOE F 470.8;
(2) a copy of the DOE F 470.2 FDAR;
(3) a list of each active DOE F 470.1 CSCS or DD F 254;
(4) an evaluation of the foreign ownership, control, or influence (FOCI)
status;
(5) a determination that employees and subcontractors possess appropriate
access authorizations;
(6) a review to ensure that individuals no longer employed on the contract
have had their access authorizations terminated and security badges have
been accounted for; and
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section G
10
(7) other topical/sub-topical areas identified on DOE F 470.8 as required by
the DOE cognizant security authority.
d. Termination Survey Reports. Termination survey reports must include:
(1) verification of non-possession of classified information or matter, SNM,
hazardous material presenting a potential sabotage threat, or Government
property;
(2) verification that all DOE access authorizations have been terminated or
transferred and that termination statements have been completed and
security badges have been accounted for;
(3) validation that all findings have been closed in SSIMS;
(4) verification of termination of all S&S activities;
(5) a copy of the terminating DOE F 470.2 FDAR; and
Section 53
(6) a completed certificate of non-possession.
e. Memorandum Report Content. Memorandum reports for DOE programmatic
entities and OGAs are generated when it is inappropriate to transmit a copy of the
survey report due to need-to-know issues. Reports must contain:
(1) a notification of inclusion of their activity in the survey;
(2) the date of the survey;
(3) ratings and rationale for the ratings associated with the activity; and
(4) all findings applicable to that activity.
7. DISTRIBUTION.
a. The surveying office must send a copy of the survey report to the appropriate
Departmental elements and support offices, including the Office of Security.
b. The surveying office must send any memorandum report to applicable DOE
program offices and OGAs.
c. Survey/memorandum reports must be distributed within 60 working days of the
exit briefing.
d. Self-assessment reports must be distributed to the applicable senior managers,
personnel responsible for corrective actions, and other personnel, as deemed
appropriate.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section G
11
8. NOTIFICATIONS AND ACTIONS FOR LESS THAN SATISFACTORY SURVEY
COMPOSITE RATINGS. When the survey composite ratings are less than satisfactory
the following notifications and actions must occur.
a. Marginal Ratings. Within 15 working days of the determination of a marginal
composite rating, the DOE cognizant security authority must ensure SSIMS is
updated and provide the applicable Departmental elements and OGAs with the
following:
(1) a statement identifying the vulnerabilities and the rationale for the rating;
(2) description of the corrective action/compensatory measures taken to date;
(3) a statement acknowledging physical validation of the adequacy of items
listed in 8.a. (2), above.
(4) If the surveying office is not the same as the DOE cognizant security
authority, the surveying office must notify the DOE cognizant security
authority of results prior to departure from the site.
b. Unsatisfactory Ratings. Within 24 hours of determination of an overall composite
rating of Unsatisfactory, the DOE cognizant security authority must coordinate
with the Departmental element to take the following actions:
(1) Suspend the activity and/or the Facility Clearance (FCL) pending remedial
action.
OR
(2) Provide the justification for continuing this critical operation to the Office
of Security, the Departmental element, and as directed, other applicable
Department elements. In addition to providing the rationale, the DOE
cognizant security authority must identify and evaluate those immediate
interim corrective actions being undertaken to mitigate identified risks or
vulnerabilities.
NOTE: If the surveying office is not the same as the DOE cognizant security
authority, the surveying office must notify the DOE cognizant security authority
of the results immediately. If the surveying office is unable to contact the DOE
cognizant security authority, action must be taken to protect activities until the
DOE cognizant security authority can be notified. Subsequent action must be
taken on the basis of agreement between the two organizations and must be fully
documented in the survey report.
9. NOTIFICATIONS AND ACTIONS FOR LESS THAN SATISFACTORY SELF-
ASSESSMENT COMPOSITE RATINGS. Actions required in response to less than
satisfactory self-assessment composite ratings are listed below:
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section G
12
Section 54
a. Marginal Ratings. Within 15 working days of the determination of a marginal
composite rating, notification must be made to line management that includes:
(1) a statement identifying the vulnerability and rationale for the rating;
(2) a description of the corrective action/compensatory measures taken to date;
and
(3) a statement acknowledging physical validation of the adequacy of items
listed in paragraph 9.a. (2), above.
b. Unsatisfactory Ratings. Within 24 hours of determination of an overall composite
rating of unsatisfactory, the cognizant security authority must coordinate with the
DOE cognizant security authority, which in turn must coordinate with the
Departmental element to take the following actions:
(1) suspend the activity and/or recommend suspension of the FCL pending
remedial action;
(2) provide justification for continuing operations to the DOE cognizant
security authority. In addition to providing the rationale, the cognizant
security authority must evaluate those immediate interim corrective
actions being undertaken to mitigate identified risks or vulnerabilities; and
(3) if the results of a self-assessment identify an incident of security concern;
it must be reported in accordance with Section N.
10. CORRECTIVE ACTIONS. Corrective action plans must be developed for all open
survey and self-assessment findings. Corrective action plans for survey and self-
assessments must be submitted and reported within 30 working days after the date of the
exit briefing. If a finding is corrected during the survey, it will be identified in the survey
report with a description of the closure/validation performed by the survey/self-
assessment team. Quarterly reports of the status of corrective actions for each finding
must be provided to the DOE cognizant security authority. All survey and self-
assessment corrective actions must:
a. be based on documented root cause analyses, risk assessments, and cost-benefit
analyses to ensure the survey/self-assessment program objectives are met (see
paragraph 1., above);
b. be reported, entered, tracked, and updated until completed, validated, and closed
in SSIMS, where applicable (see paragraph 4.b., above).
11. UPGRADE OF COMPOSITE RATINGS. When line management determines that the
composite rating should be upgraded, the survey/self-assessment team must physically
verify the completion and adequacy of corrective actions and make notification of the
rating upgrade in accordance with approved local procedures.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 1, Section G
13
12. RECORDS RETENTION. Documentation associated with the conduct of survey and
self-assessments must be retained in accordance with approved procedures and
appropriate records inventory disposition schedules.
13. CONTINUOUS IMPROVEMENT PROCESS. The cognizant security authority must
conduct an annual evaluation of their survey or self-assessment processes. This
evaluation must ensure any identified process improvements (i.e., lessons learned) are
incorporated in the S&S survey/self-assessment process.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 2, Section H
1
PART 2 - SAFEGUARDS AND SECURITY MANAGEMENT
SECTION H - FOREIGN OWNERSHIP, CONTROL, OR INFLUENCE PROGRAM
1. OBJECTIVE. To establish the Foreign Ownership, Control or Influence (FOCI) program
requirements and criteria to facilitate the initial and continued facility clearance (FCL)
eligibility of U.S. companies with foreign involvement.
CANCELE
D
Section 55
DOE M 470.4-1
08-26-05
Part 2, Section H
I-1
CHAPTER I - GENERAL FOCI PROGRAM INFORMATION
1. GENERAL REQUIREMENTS.
a. Evaluation and adjudication of FOCI compose an essential and critical ongoing
element of the FCL program. A contractor cannot be under FOCI to such a
degree that granting or continuing an FCL would be inconsistent with U.S.
national security interests. An FCL may not be granted until all relevant aspects
of FOCI have been resolved and, if necessary, favorably adjudicated. If a
company with an existing FCL is determined to be under FOCI, the FCL must be
suspended or terminated unless security measures are taken to remove the
possibility of unauthorized access or adverse impacts to classified contract
performance.3
b. The determination of whether a U.S. company is under FOCI, its eligibility for an
FCL, and the security measures deemed necessary to negate FOCI impacts must
be made on a case-by-case basis. The following factors must be considered in the
aggregate to determine whether a company is under FOCI, is eligible for an FCL,
and the protective measures required:
(1) foreign intelligence threat;
(2) risk of unauthorized technology transfer;
(3) type and sensitivity of classified information or matter, or special nuclear
material (SNM);
(4) nature, source, and extent of FOCI, including identification of immediate,
intermediate, and ultimate parent organizations;
(5) record of compliance with pertinent laws, regulations, and contracts; and
(6) nature of bilateral and multilateral security and information exchange
agreements that may be relevant.
c. Development of security measures to mitigate the impact of unacceptable FOCI
must be based on the concept of risk management. DOE has the obligation to
impose any security method, safeguard, or restriction it believes necessary to
ensure that unauthorized access to classified information or matter, or SNM is
effectively precluded and the performance of classified contracts is not adversely
affected.
d. Changed conditions, such as a change in ownership, indebtedness, or foreign
intelligence threat, may justify certain adjustments to the security requirements
under which a company is operating or require that a different FOCI mitigation
3 Classified contract is defined as any contract, license, or other agreement requiring access authorizations.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 2, Section H
I-2
method be used. A changed condition may result in a determination that a
company is no longer considered to be under FOCI or, conversely, that a
company is no longer eligible for an FCL.
2. APPLICABILITY.
a. The entities4 listed below are required to obtain FOCI determinations.
(1) Applicants, including industrial, educational, commercial, or any other
entity, grantee, or licensee, including an individual, that have or anticipate
executing a classified contract. This includes subcontractors of any tier,
consulting firms, agents, grantees, and cooperative research and
development agreement participants who require access authorizations.
(2) All tier parents located in the U.S., Puerto Rico, or a U.S. possession or
trust territory
b. A FOCI determination is not required for an individual performing work under a
consulting agreement (e.g., an individual awarded a contract).5 This does not
include individuals contracting as a business.
Section 56
c. When the applicant is a local, state, or Federal agency or department, the contract
must contain a security clause. The security clause must state that if the
government agency or department subcontracts any work requiring access to
classified information or matter by a commercial entity, its acquisition regulation,
including FOCI policies, must be followed. If the government agency or
department does not have its own FOCI policies or an agreement with the
Secretary of Defense for industrial security services, DOE will render the FOCI
determination.
d. When contracts involve access to SNM, DOE will render the FOCI determination.
e. Contractors with existing U.S. Government FCLs are identified in Safeguards and
Security Information Management System (SSIMS) and the Department of
Defense (DoD) Defense Security Service/Central Verification Activity System
(DSS/CVA).
f. No further FOCI review is required for an applicant holding an equal or higher
U.S. Government FCL, based upon a favorable FOCI determination.
g. Information submitted with a FOCI package is used for the sole purpose of
evaluating FOCI and must be treated by DOE, to the extent permitted by law, as
business/financial information submitted in confidence. The information must be
protected as Official Use Only (OUO).
4 The entities listed are referred to as “applicants” throughout this Section.
5 The self-employed individual’s or consultant’s foreign involvement is determined through the background
investigation conducted to determine the individual’s eligibility for an access authorization.
CANCELE
D
DOE M 470.4-1
08-26-05
Part 2, Section H
I-3
h. Personnel responsible for the FOCI program can successfully meet FOCI
competencies through training courses offered at the National Training Center
(NTC).
3. CONTRACT AWARD MUST NOT BE MADE PRIOR TO FCL ISSUANCE. The
DOE Acquisition Regulation (DEAR) prohibits the award of a classified contract until an
FCL has been granted. When an existing contract that does not require access
authorizations is modified to require access authorizations, the contract modification
cannot take effect until an FCL is granted. Contract award/modification cannot be made
until:
a. all relevant aspects of FOCI have been resolved and, if necessary, are favorably
adjudicated;
b. the signed DOE F 470.1, “Contract Security Classification Specification” (CSCS)
is accepted by the cognizant security authority; and
c. the appropriate DEAR security clauses have been incorporated in the contract.
4. ELECTRONIC SUBMISSION/PROCESSING WEB SITE. The Department has an
electronic system for applicants to submit FOCI information to DOE in an electronic
format. To ensure confidentiality of the information submitted and stored on the system,
the site is protected with 128-bit encryption.
a. Applicants may use this system for the submission of FOCI packages, including
changes to update their FOCI information. The FOCI web site maybe accessed
via an Internet browser at https://foci.td.anl.gov. Electronic signatures are not
accepted; therefore a signed original SF 328, “Certificate Pertaining to Foreign
Interests,” executed in accordance with the instructions on the certification
section of the SF 328, must be submitted to the DOE cogniza