Archives of Directives

Archive

DOE O 452.4C, Security and Use Control of Nuclear Explosives and Nuclear Weapons

Functional areas: Nuclear Explosives, Nuclear Weapons, Security, Safety, Weapon Surety

The order establishes requirements to implement the nuclear explosive security and use control elements of DOE O 452.1E to ensure authorized use, when directed by proper authority, and protect against deliberate unauthorized acts, deliberate unauthorized use, and denial of authorized use. Supersedes DOE O 452.4B, dated 1-22-10.
o452.4c.pdf127.30KB
Version history and related documents

Superseded by

A newer version replaces this document.

Supersedes

Earlier documents this one replaced.

View full version history

Document text

Text extracted from the attached file. Refer to the original document for the authoritative version.

Section 1

AVAILABLE ONLINE AT: INITIATED BY: www.directives.doe.gov National Nuclear Security Administration U.S. Department of Energy ORDER Washington, D.C. Approved: 8-28- 2015 SUBJECT: SECURITY AND USE CONTROL OF NUCLEAR EXPLOSIVES AND NUCLEAR WEAPONS 1. PURPOSE. This Department of Energy (DOE) Order establishes requirements to implement the nuclear explosive security and use control (UC) elements of DOE O 452.1E, Nuclear Explosive and Weapon Surety (NEWS) Program, to ensure authorized use, when directed by proper authority, and protect against deliberate unauthorized acts (DUAs), deliberate unauthorized use (DUU), and denial of authorized use (DAU). 2. CANCELLATION. DOE O 452.4B, Security and Control of Nuclear Explosives and Nuclear Weapons, dated 1-22-2010. Cancellation of a directive does not, by itself, modify or otherwise affect any contractual or regulatory obligation to comply with the directive. Contractor Requirements Documents that have been incorporated into a contract remain in effect throughout the term of the contract unless and until the contract or regulatory commitment is modified to either eliminate requirements that are no longer applicable or substitute a new set of requirements. 3. APPLICABILITY. a. Departmental Applicability. (1) This Order applies to all those Departmental elements that are involved in performing, managing, overseeing, or directly supporting NEWS, specific nuclear weapon programs or associated activities. (2) The Administrator will ensure that National Nuclear Security Administration (NNSA) employees and contractors comply with their respective responsibilities under this Order. Nothing in this Order will be construed to interfere with the NNSA Administrator’s authority under section 3212(d) of Public Law (P.L.) 106-65 to establish Administration specific policies, unless disapproved by the Secretary. b. DOE Contractors. Except for the equivalencies/exemptions in paragraph 3.c., the Contractor Requirements Document (CRD), Attachment 1, sets forth requirements of this Order that will apply to contracts that include the CRD. The CRD must be included in all contracts involving the performance, management, oversight, or directly supporting NEWS, specific nuclear weapon programs or associated activities. c. Equivalencies and Exemptions for DOE O 452.4C. (1) Requests for equivalencies and exemptions to this Order must be in memorandum form and sent to the Office of Nuclear Weapon Surety and Quality, Office of Stockpile Management, Defense Programs. DOE O 452.4C http://www.directives.doe.gov/ 2 DOE O 452.4C 8-28-2015 (a) The memorandum must briefly justify the reasons for the Equivalencies/Exemptions. (b) The memorandum must reference the offices, or localities, and requirements for which the equivalency/exemption is sought. (2) Exemptions. The following Departmental elements are exempted: Advanced Research Project Agency – Energy, Office of the Chief Financial Officer, Office of Congressional and Intergovernmental Affairs, Office of Economic Impact and Diversity, Energy Information Administration, Office of Electricity Delivery and Energy Reliability, Office of Energy Efficiency and Renewable Energy, Office of Environmental Management, Office of Fossil Energy, Office of Hearings and Appeals, Office of Human Capital Management, Office of International Affairs, Office of Indian Energy Policy and Programs, Office of Legacy Management, Loan Program Offices, Office of Management, Office of Nuclear Energy, Office of Public Affairs, Office of River Protection, Office of Science, Office of Small and Disadvantaged Business Utilization, Idaho National Laboratory, Idaho Operations Office, Bonneville Power Administration, Southeastern Power Administration, Southwestern Power Administration, and Western Area Power Administration.

Section 2

(3) Equivalency. In accordance with the responsibilities and authorities assigned by Executive Order 12344, codified at Title 50 United States Code (U.S.C.) sections 2406 and 2511 and to ensure consistency through the joint Navy/DOE Naval Nuclear Propulsion Program, the Deputy Administrator for Naval Reactors (Director) will implement and oversee requirements and practices pertaining to this Directive for activities under the Director's cognizance, as deemed appropriate. 4. REQUIREMENTS. a. Application of Nuclear Explosive Surety Standards. (1) All nuclear explosives and nuclear explosive operations (NEOs) must meet the qualitative Nuclear Explosive Surety Standards (hereafter known as the Standards) set forth in DOE O 452.1E, or its successors. (2) The UC element of nuclear explosives surety includes one unique requirement that is not explicitly captured by the Standards: to ensure use only when authorized and directed by proper authority. Because of this unique UC objective, some requirements in this Order emphasize a subset of nuclear explosives that are in the fully assembled Department of Defense (DoD) configuration as nuclear weapons. DOE O 452.4C 3 8-28-2015 (3) The protection of nuclear explosives and nuclear weapons must include a combination of administrative, process, and technical measures designed to ensure authorized use and prevent deliberate unauthorized use. (4) Controls implemented to support the Standards for one part of surety - safety, security, or UC - must also be evaluated for adverse impact on each of the other surety parts. (5) In the context of the Standards, “prevent” and “ensure” imply an absolute assurance, which cannot be guaranteed. Nonetheless, prevention of unintended/unauthorized nuclear detonation and unintended main charge High Explosive Violent Reaction (HEVR) and subversion of weapon functionality are primary goals in the design and performance of nuclear explosive operations. The objective is to drive the likelihood of the specified consequences as low as reasonably practicable. b. Nuclear Explosive Security. These requirements are specified in the 452- and 470-series directives. Safeguards and security measures must be documented in the site security plan. The Nuclear Explosive Security Standard from DOE O 452.1E must be met to ensure adequate nuclear explosive security for all NEOs conducted by the Department and its contractors. c. Nuclear Explosive and Nuclear Weapon Use Control. These requirements are specified in this directive. However, Joint DOE/NNSA and DoD directives relating to policies, requirements and technical procedures for handling and controlling logistics code and key material are implemented by Technical Manual TP 50-2, Procedures for the Use and Control of Logistics Codes and Permissive Action Link (PAL) Equipped Weapons. d. Nuclear Explosive and Weapon Security and Use Control Program. Consistent with the Standards, there must be a Nuclear Explosive and Weapon Security and Use Control Program (hereafter known as the Program) consisting of an integrated system composed of design; review; installation; and production of features, devices, and other measures to maintain control of nuclear explosives and nuclear weapons at all times throughout their life-cycle. The Program ensures use only when authorized and directed by proper authority and protects against deliberate unauthorized acts (DUA), deliberate unauthorized use (DUU), and denial of authorized use (DAU). Program elements related to nuclear weapon design must be consistent with DoD operational requirements.

Section 3

The Program must include the following major elements: (1) function and operation of UC features, devices and other measures will be integrated with security measures referenced in paragraph 4.b. above in order to maximize system effectiveness and minimize cost; 4 DOE O 452.4C 8-28-2015 (2) security and UC measures for nuclear explosives and nuclear weapons, including design features that are incorporated and used at the earliest practical point during assembly and removed at the latest practical point during disassembly or dismantlement; (3) security and UC upgrades will be implemented during weapon retrofit/alteration/refurbishment for all nuclear weapons, unless there are documented overriding reasons for not doing so; (4) design attributes, that may include a combination of administrative and technical measures, designed to prevent or delay DUU of nuclear explosives and nuclear weapons; (5) the Human Reliability Program (HRP) as required by Title 10 Code of Federal Regulations (CFR) Part 712, to ensure the reliability of DOE and contractor employees who require access to designated components, nuclear explosives, or nuclear weapons; (6) measures to prevent DUAs from degrading the effectiveness of UC measures incorporated in or used for nuclear explosives or nuclear weapons; (7) measures to prevent or delay DUU, DUAs, DAU, or loss of control during planned NEOs; (8) measures to assist the recapture and recovery (R&R) of lost or stolen nuclear explosives or nuclear weapons; (9) stockpile surveillance to ensure that UC devices and components meet specified requirements and have not been altered; (10) DUA, DUU, and DAU evaluations performed periodically that may be specific to a DOE nuclear weapon, nuclear explosive, NEO, class of operations, facility or site (see subparagraph 4.f. below); (11) measures that must be continually assessed against existing and emerging threats as well as technological opportunities for improvement; (12) Nuclear Enterprise Assurance (NEA) to ensure the security of the supply chain and protect against components with malicious content that could override or degrade UC or nuclear weapons functionality; (13) measures to ensure cyber security in all aspects of design, sourcing, procurement, and production to ensure that critical program information and systems are secure; (14) necessary measures for inter-agency information sharing and cooperation in threat identification, supplier vetting, and risk mitigation; DOE O 452.4C 5 8-28-2015 (15) documentation providing evidentiary trust that weapons systems, including associated systems and components, have not been subverted or corrupted; and (16) Research and Development (R&D) (described in paragraph 4.e. below). e. Research and Development (R&D). Consistent with the Standards and the Program, DOE/NNSA must provide resources and conduct R&D for security and UC measures that can protect against DUAs, DUU, and DAU of nuclear explosives and nuclear weapons. Recommendations from these R&D activities are provided for use by project managers, project teams, project officer groups, and decision-makers within DOE/NNSA. The objective of such improvements is to minimize the overall risk of DUU and DAU by providing an effective adversary delay or denial capability for the overall nuclear weapon system that either is inherent in the design or does not require human intervention. Specifically, security and UC R&D must:

Section 4

(1) pursue technologies that can enhance security and UC for new and existing systems; (2) pursue technologies that render the unauthorized use of U.S. nuclear weapons impossible without their remanufacture; (3) develop nuclear weapon measures to provide assurance of operation as designed when authorized for use; (4) design nuclear weapon features that enhance secure critical command and control communications; (5) develop technologies to aid in the R&R of weapons; (6) develop measures that minimize the risk of DUU by providing an integrated adversary delay or denial capability that either is inherent in the design or does not require human intervention; (7) develop approaches to efficiently detect subversion; and (8) when new improvements for security and UC measures are developed, cognizant security and UC R&D officials and/or cognizant managers must ensure that improvements and information related to them are appropriately protected and classified according to their sensitivity. f. DUA, DUU, and DAU Evaluations. To ensure that DUA, DUU, and DAU controls are adequate the evaluations must be performed for DOE/NNSA nuclear explosives, nuclear weapons, NEOs, and certain non-NEO production activities. The controls must be periodically evaluated and documented against credible 6 DOE O 452.4C 8-28-2015 existing and emerging threats and technological advancements. The evaluations assess the controls as they apply to the critical component, nuclear explosive, or nuclear weapons to ensure that they meet the UC elements of DOE O 452.1E Nuclear Explosive Surety Standards. In the context of this Order, the DUA, DUU, and DAU evaluations only address malevolent, unauthorized acts. Non-malevolent acts are adequately covered by the Nuclear Explosive Safety, Quality, and Surveillance programs. (1) NNSA Sites with NEOs. The DUA, DUU, and DAU evaluations will address NEO processes, testers, tooling, and facilities to help ensure that controls are adequate to meet the UC elements of DOE O 452.1E Nuclear Explosive Surety Standards applicable to NEOs. Additional direction for the conduct of DUA, DUU, and DAU evaluations was issued by the NNSA Administrator in NNSA Supplemental Directive (NA SD) 452.4, Implementation and Evaluation of Controls to Prevent Deliberate Unauthorized Use, dated 7-7-11. (2) NNSA Sites without NEOs. The DUA, DUU, and DAU evaluations will address DOE weapon component designs, testers, and subsystem/ component production to help ensure the integrity of product used in nuclear explosives and nuclear weapons is adequate so as to not jeopardize conformance with the UC elements of DOE O 452.1E Nuclear Explosive Surety Standards. Additional direction for the conduct of DUA, DUU, and DAU evaluations was issued by the NNSA Administrator in NA SD 452.4. g. Joint DOE and DoD DUU Protection. DOE/NNSA must cooperate with DoD and other Federal agencies as required to provide protection against DUU and to assess the effectiveness of surety features for all U.S. nuclear weapon systems throughout their life-cycles. These features must be consistent with DoD operational requirements and must continually be assessed against existing and emerging threats as well as technological opportunities for improvement. h. Command and Control. DOE/NNSA must assist DoD in designating nuclear command and control critical equipment and components to ensure that these items are developed and maintained to meet the criteria designated in National Security Directives and the Program above.

Section 5

5. RESPONSIBILITIES. a. Director, Office of Intelligence and Counterintelligence. (1) Provides intelligence and counterintelligence support for the NEA activity. (2) Nominates, in writing, a member to serve on the Nuclear Enterprise Assurance Steering Group (NEASG). DOE O 452.4C 7 8-28-2015 b. Associate Administrator for Emergency Operations. Establishes programs for coordinating and assisting in the R&R of U.S. nuclear explosives or nuclear weapons for which physical control has been lost. c. Chief of Defense Nuclear Security (CDNS). (1) Serves as the DOE Officially Designated Federal Security Official responsible for the development and implementation of security programs, operations, and facilities under the purview of NNSA, including physical security, personnel security, materials control and accountability, classified and controlled information protection, and technical security. (2) Advises the Assistant Deputy Administrator for Stockpile Management on safeguards and security requirements to implement the security element of the surety Standards as defined in the DOE NEWS Program. (3) Serves as a member of the Nuclear Enterprise Assurance Steering Group (NEASG). The CDNS may appoint member to act as the CDNS agent to the NEASG. d. Associate Administrator for Information Management and Chief Information Officer. (1) Provides cyber asset security and assurance for the NEA activity. (2) Nominates, in writing, a member to serve on the Nuclear Enterprise Assurance Steering Group (NEASG). e. Assistant Deputy Administrator for Stockpile Management. (1) Oversees the management and integration of all aspects of the Program. (2) Represents the Office of Defense Programs in coordinating and assisting DoD and other Federal agencies in the R&R of U.S. nuclear explosives or nuclear weapons for which physical control has been lost. (3) Represents DOE/NNSA regarding U.S. nuclear weapons and nuclear weapons systems UC to DoD and other Federal agencies. (4) Ensures active and continuous review of the nuclear stockpile is being conducted to identify Program concerns and ensures implementation of stockpile improvement or controls to address identified concerns. (5) Directs assessment of the effectiveness of UC features of U.S. nuclear weapons in DOE and DoD custody. (6) Approves designated components for Defense Programs (see subparagraphs 4.d. (5) and 4.h. above). 8 DOE O 452.4C 8-28-2015 (7) Establishes and oversees the Nuclear Enterprise Assurance activity within the Program to effectively address the “ensure authorized use” mission area of use control and to preclude denial of authorized use. (8) Charters and chairs the Nuclear Enterprise Assurance Steering Group (NEASG) to provide oversight and guidance for NEA activities, accepts NEASG member nominations, in writing, and makes final decision on issues when NEASG members cannot reach consensus. (9) Accepts risk for the Office of the Deputy Administrator for Defense Programs throughout product realization life-cycle for stockpile systems, life extension programs, alterations, including those identified by NEA activities. f. Assistant Deputy Administrator for Systems Engineering and Integration. Nominates, in writing, a member of the NEASG. g. Assistant Deputy Administrator for Major Modernization Programs. (1) Works with the Office of Stockpile Management to incorporate new UC features in the stockpile during weapon life extension programs, modifications, or alterations.

Section 6

(2) Enables the Nuclear Enterprise Assurance activity in assigned mission area to effectively address the “ensure authorized use” mission area of use control and to preclude denial of authorized use. (3) Nominates, in writing, a member of the NEASG. h. Office of Materials Management and Technology Maturation. (1) Manages the R&D aspects of the Program. (2) Conducts R&D on a broad range of surety methods and devices to significantly improve the security and UC of nuclear weapons and nuclear weapon systems. (3) Establishes security and UC priorities for R&D efforts and resources and designates critical components for UC development. (4) Allocates resources and pursues UC options with delay or denial capability that, at a minimum, are equivalent to that associated with current nonviolent disablement systems. (5) Allocates resources and pursues technologies that render the unauthorized use of U.S. nuclear weapons impossible without their remanufacture. DOE O 452.4C 9 8-28-2015 (6) Allocates R&D resources and directs R&D of controls to prevent DUAs, DUU, and DAU of nuclear explosives and nuclear weapons. (7) Works with the Office of Stockpile Management to establish programs to incorporate improved UC measures in the stockpile. j. Office of Nuclear Weapon Surety and Quality. (1) Manages all aspects of the Program with the exception of R&D. (2) Assists DoD and other Federal agencies in designating nuclear command and control critical equipment and ensuring that it is developed to meet criteria specified in National Security Directives. (3) Works with the Offices of Systems Engineering and Integration, Major Modernization Programs, Nuclear Weapon Stockpile, and Materials Management and Technology Maturation to establish programs to incorporate improved UC measures in the stockpile and promote those programs found to be cost effective and feasible. (4) Manages the periodic DUA, DUU, and DAU assessment of nuclear explosives and nuclear weapons to evaluate and document existing and emerging threats and technological advancements associated with DUAs, DUU, and DAU. (5) If requested by a Field Office, (a) assists with annual reviews of the programs under their purview. (b) helps ensure (based on competent, independent reviews) that DUA, DUU, and DAU reviews meet the requirements of this Order. k. Assistant Deputy Administrator for Secure Transportation. (1) Ensures active and continuous review of the aspects of the Program under his/her purview is conducted to identify Program concerns and ensures implementation of improvement or controls to address identified concerns. (2) Assesses the effectiveness of the integrated system of controls to protect nuclear explosives and nuclear weapons under his/her cognizance against DUAs. (3) Periodically evaluates and documents existing and emerging threats and technological advancements associated with DUAs. l. Assistant Deputy Administrator for Nuclear Safety and Operations. Ensures active and continuous review of the aspects of the Program under his/her purview is 10 DOE O 452.4C 8-28-2015 being conducted to identify Program concerns and ensures implementation of improvement or controls to address identified concerns. m. Managers of NNSA Field Offices. (1) Ensure implementation of the Program, including NEA activities where applicable.

Section 7

(2) Conduct annual Program reviews of the programs under their purview for the Assistant Deputy Administrator for Stockpile Management, the Assistant Deputy Administrator for Major Modernization Programs, the Assistant Deputy Administrator for Secure Transportation, the Assistant Deputy Administrator for Nuclear Safety and Operations, and other DOE senior-level managers. If a Field Office lacks qualified subject matter experts to perform the review, assistance may be requested from the Office of Stockpile Management. (3) Ensure (based on competent, independent reviews) that each NEO authorized meets the use control elements of DOE O 452.1E Nuclear Explosive Surety Standards applicable to NEOs. Retain documentation of these reviews, their conclusions, and resolution of findings. If a Field Office lacks qualified subject matter experts to perform the review, assistance may be requested from the Office of Stockpile Management. (4) Ensure (based on competent, independent reviews) that DUA, DUU, and DAU reviews for non-NEO production does not jeopardize conformance with UC elements of the DOE O 452.1E Nuclear Explosive Surety Standards. Retain documentation of these reviews, their conclusions, and resolution of findings. If a Field Office lacks qualified subject matter experts to perform the review, assistance may be requested from the Office of Stockpile Management. (5) Notify contracting officers of which contracts are affected by the CRD to this Order. n. Contracting Officers. Once notified, contracting officers are responsible for incorporating the CRD of this Order into each affected contract. 6. DEFINITIONS. Selected definitions from DOE O 452.1E are repeated here for ease of reference. a. Delay. The effect achieved by physical features, technical devices, security measures, or protective forces that impedes an adversary from gaining access to an asset being protected or from completing a malevolent act. DOE O 452.4C 11 8-28-2015 b. Deliberate Unauthorized Act (DUA). Any intentional action that has not been authorized and approved by proper authority. (1) In the context of the nuclear explosive surety Standards, a DUA is one that is not sanctioned as part of an approved nuclear explosive operation or associated activity, but which could affect a NE or main charge high explosive part collocated with a pit. (2) In the context of this Order, a DUA is of interest if it is performed with a malevolent intent to prevent authorized use (see DAU) of a nuclear weapon; create a nuclear detonation or other DUU; or to gain unauthorized control of a nuclear explosive. c. Deliberate Unauthorized Use (DUU). Any of the following consequences resulting from deliberate malevolent acts: (1) a nuclear detonation not authorized by the National Command Authorities; (2) a HEVR that could result in an unauthorized nuclear detonation, (3) theft of nuclear explosives. d. Denial of Authorized Use (DAU). Any unauthorized act, including DUAs, which would prevent the authorized use or intended functionality of a nuclear weapon. The resulting potential effects on the nuclear weapon include but are not limited to: (1) Actual alteration of system or critical component functionality and (2) Perception that system or critical components are not functioning properly. e. Facility. Any equipment, structure, system, process, or activity that fulfills a specific purpose. f. Measures. The total spectrum of characteristics, devices, equipment, procedures, and administrative processes used to:

Section 8

(1) ensure timely authorized use only when directed by national authority, and (2) increase the difficulty of or add to the delay in achieving the deliberate unauthorized use of a nuclear explosive. g. Nuclear Command and Control Critical Equipment. Specifically designated equipment, including software, used to build, encode, decode, transmit, or receive emergency action messages; identify nuclear targets, select nuclear weapons to be used against specific targets, and route nuclear-weapons-carrying platforms to 12 DOE O 452.4C 8-28-2015 appropriate launch points; and support or inhibit the delivery, arming, fusing, and firing of nuclear weapons themselves. This equipment includes positive control material and devices, and nuclear weapon hardware. h. Nuclear Enterprise Assurance (NEA). The NSE program established to prevent or mitigate potential consequences of nuclear weapon lifecycle deliberate unauthorized acts that may lead to denial of authorized use or degradation of weapon reliability or performance. NEA includes Weapon Trust Assurance (WTA) and Supply Chain Risk Management (SCRM). i. Nuclear Enterprise Assurance Steering Group (NEASG). A review and decision- making body for oversight and management of NEA activities formed from a limited number of senior Federal Officials from NNSA and DOE Headquarters. j. Nuclear Explosive. An assembly containing fissionable and/or fusionable materials and main charge high explosive parts or propellants capable of producing a nuclear detonation (for example, a nuclear weapon or test device). k. Nuclear Explosive Operation (NEO). Any activity involving a nuclear explosive including activities in which main charge high explosive parts and pit are collocated. l. Nuclear Security Enterprise (NSE). The NNSA organizations that manage nuclear weapon data and/or design, manufacture, or test nuclear weapons or nuclear weapon components. Included in the NSE are: (1) NNSA Headquarters, Albuquerque Complex and Field Offices, (2) Lawrence Livermore National Laboratory, (3) Los Alamos National Laboratory, (4) Sandia National Laboratories, (5) Pantex Plant, (6) Kansas City Plant, (7) Y-12 National Security Complex, (8) NNSA operations at the Savannah River Site, and (9) Nevada National Security Site. m. Nuclear Weapon. A nuclear explosive configured for Department of Defense use. DOE O 452.4C 13 8-28-2015 n. Recapture. Regaining control of a nuclear weapon and/or special nuclear material, which is under unauthorized possession, while still within the confines of a Departmental site/facility. o. Recovery. Regaining control of a nuclear weapon and/or special nuclear material, which is under unauthorized possession and has been removed from within the confines of a Departmental site/facility or Departmental possession. p. Security. An integrated system of activities, systems, programs, facilities, and policies for the protection of classified information and/or classified matter, unclassified controlled information, nuclear materials, nuclear weapons, nuclear weapon components, and/or the DOE’s and its contractors’ facilities, property, and equipment.

Section 9

q. Supply Chain Risk Management (SCRM). The systematic identification, assessment, quantification and mitigation of potential supply chain disruptions based on analysis of weapon vulnerabilities and adversarial threats. SCRM processes are designed to ensure that malicious hardware and/or software does not enter the NSE Supply Chain by managing evolving risks to the integrity of products and services throughout the entire supply chain and throughout the lifecycle of the weapon and weapon related components. It includes monitoring and mitigating threats from foreign intelligence entities and other adversaries that desire to compromise the NSE Supply Chain, through the introduction of counterfeit components, malicious hardware/software or actions to impact supplier performance. r. Surety. Safety, security, and use control of nuclear explosives and nuclear weapons. s. Use Control. The application of systems, devices, or procedures that ensure timely authorized use of a nuclear explosive while precluding or delaying unauthorized nuclear detonation. t. Weapon Trust Assurance (WTA). A series of evidentiary activities across the weapon lifecycle designed to prevent the Denial of Authorized Use of nuclear weapons. WTA ensures that the weapon, weapon-related components, cybersecurity and processes associated with research, design, development, production, testing, storage, maintenance, surveillance, dismantlement, and disposal are not subverted or compromised. 7. REFERENCES. a. Human Reliability Program rule, 10 CFR Part 712, the rule that defines a security and safety reliability program designed to ensure that individuals who occupy positions affording access to certain materials, nuclear explosive devices, facilities, and programs meet the highest standards of reliability and physical and mental suitability. 14 DOE O 452.4C 8-28-2015 b. National Security Presidential Directive 28, dated 06-20-03. c. Joint Policy Statement on Nuclear Weapons Surety, dated 6-27-91, signed by the Secretaries of Defense and Energy. d. Memorandum of Understanding Between the Department of Defense and Department of Energy on Objectives and Responsibilities for Joint Nuclear Weapon Activities, dated 1-17-83, which supplements previous agreements delineating DoD and DOE objectives, responsibilities, and measures to improve stockpile planning and acquisition and ensuring high-level attention to nuclear weapon safety, security, and use control. e. CJCSI 3260.01D (series), Joint Policy Governing Positive Control Material and Devices, is a directive that establishes National policy and procedures applicable to the Executive Branch for positive control material and devices. It is the source document and authorization for TP 50-2. f. Technical Manual TP 50-2, Procedures for the Use and Control of Logistics Codes for Permissive Action Link (PAL) Equipped Weapons, is a joint DOE and DoD directive that provides the policies, requirements and technical procedures for handling and controlling of logistics code and key material. g. DOE O 151.1C, Comprehensive Emergency Management System, dated 11-2-05, which establishes objectives, responsibilities, and requirements for a system that encompasses emergency planning, preparedness, readiness assurance, response, and recovery actions.

Section 10

h. DOE O 226.1B, Implementation of Department of Energy Oversight Policy, dated 4-25-11, which provides direction for implementing DOE P 226.1B, Department of Energy Oversight Policy, dated 4-25-11, which establishes DOE policy for assurance systems and processes established by DOE contractors and oversight programs performed by DOE line management and independent oversight organizations. i. DOE O 243.1B, Records Management Program, dated 3-11-13, with Administrative Change 1 dated 7-8-13 which describe requirements for managing records related to this program. j. DOE O 251.1C, Departmental Directives Program, dated 1-15-09, which details the process for requesting exemptions from directives requirements. k. DOE O 414.1D, Quality Assurance, dated 4-25-11, which ensures that DOE, including NNSA, products, and services meet or exceed customers’ requirements and expectations. l. DOE O 452.1E, Nuclear Explosive and Weapon Surety Program, dated 01-26-15, which establishes the DOE Nuclear Explosive Surety Standards and specifies DOE O 452.4C 15 8-28-2015 other requirements and responsibilities for the Nuclear Explosive and Weapon Surety Program to prevent unintended and unauthorized detonation and deliberate unauthorized use of nuclear explosives. m. DOE O 452.2E, Nuclear Explosive Safety, dated 01-26-15, which establishes DOE objectives, requirements, and responsibilities to implement nuclear explosive safety for routine and planned nuclear explosive operations. n. DOE O 452.7, Protection of Use Control Vulnerabilities and Designs, dated 5-14-10, establishes the policy, process and procedures for control of sensitive use control information in nuclear weapon data (NWD) categories Sigma 14 and Sigma 15 to ensure that dissemination of the information is restricted to individuals with valid need-to-know. o. NNSA SD 452.2, Nuclear Explosive Safety Evaluation Processes, dated 11-17-14, details the administrative and procedural requirements for nuclear explosive safety evaluations of nuclear explosive operations conducted by the DOE/NNSA and its contractors. p. DOE O 452.6A, Nuclear Weapon Surety Interface with the Department of Defense, dated 04-14-09, establishes DOE and NNSA requirements and responsibilities for addressing joint nuclear weapon and nuclear weapon system surety activities in conjunction with the Department of Defense (DoD). q. DOE O 461.1B, Packaging and Transportation for Offsite Shipment of Materials of National Security Interest, dated 12-16-10, which establishes the DOE requirements and responsibilities and implements the management and operation of the Transportation Safeguards System. r. DOE P 470.1A, Safeguards and Security Program, dated 12-29-2010, which ensures the DOE efficiently and effectively meets all its obligations to protect Special Nuclear Material, other nuclear materials, classified matter, sensitive information, government property, and the safety and security of employees, contractors, and the general public. s. NNSA Policy Letter NAP-24, Weapon Quality Policy, dated 6-20-13, which identifies the quality requirements applicable to weapon activities of the NNSA, NNSA contractors, and subcontractors. t. DOE O 470.3B, Graded Security Protection Policy, dated 8-12-08, classified. u. DOE O 470.4B, Safeguards and Security Program, dated 7-21-11, with Administrative Change 1 dated 2-15-13, which establishes responsibilities and program planning and management requirements for the DOE Safeguards and Security Program.

Section 11

16 DOE O 452.4C 8-28-2015 v. DOE O 471.6, Information Security, dated 6-20-11, with Administrative Change 1 dated 11-30-12 establishes requirements and responsibilities for DOE Departmental Elements, including the NNSA, to protect and control classified information as required by statutes, regulation, Executive Orders, government-wide policy directives and guidelines, and DOE policy and directives. w. NNSA Supplemental Directive (NASD) 452.4, Implementation and Evaluation of Controls to Prevent Deliberate Unauthorized Use, dated 7-7-11, supports this Order’s requirements to implement deliberate unauthorized use (DUU) preventive measures for nuclear explosive operations (NEO) and associated activities and to perform independent evaluations to determine if NEOs are adequately designed and controlled to satisfy the use control (UC) Standards. 8. CONTACT. Questions concerning this Order should be addressed to the Office of Nuclear Weapon Surety and Quality, 202-586-0377. BY ORDER OF THE SECRETARY OF ENERGY: ELIZABETH SHERWOOD-RANDALL Deputy Secretary DOE O 452.4C Attachment 1 8-28-2015 Page 1 CONTRACTOR REQUIREMENTS DOCUMENT DOE O 452.4C, Security and Use Control of Nuclear Explosives and Nuclear Weapons This Contractor Requirements Document (CRD) establishes the requirements for Department of Energy (DOE) contractors, including National Nuclear Security Administration (NNSA) contractors, whose contracts involve the performance, management, oversight, or direct support of DOE/NNSA nuclear explosive operations (NEOs) or associated activities. Regardless of the performer of the work, the contractor is responsible for compliance with the requirements of this CRD. The contractor is responsible for flowing down the requirements of this CRD to subcontracts at any tier to the extent necessary to ensure the contractor’s compliance with the requirements. All contractors with this CRD incorporated in their contracts must comply with the following requirements. 1. NUCLEAR EXPLOSIVE AND WEAPON SECURITY AND USE CONTROL PROGRAM. The Nuclear Explosive and Weapon Security and Use Control Program (hereafter known as the Program) comprises an integrated system of devices, design techniques, evaluations, and other methods to maintain control of Nuclear Explosives and Weapons at all times. These use control (UC) measures allow use when authorized and directed by proper authority and protect against Deliberate Unauthorized Acts (DUAs), Deliberate Unauthorized Use (DUU), and Denial of Authorized Use (DAU). Contractors must ensure that their Programs include the following: a. the Human Reliability Program (HRP) as required by Title 10 Code of Federal Regulations (CFR) Part 712, to ensure the reliability of Department of Energy (DOE) and contractor employees who require access to designated components, nuclear explosives or nuclear weapons; b. security and UC measures for nuclear explosives and nuclear weapons, including design features that are incorporated and used at the earliest practical point during assembly and removed at the latest practical point during disassembly or dismantlement; c. security and UC capabilities for all nuclear weapons upgraded to meet current surety requirements during weapon retrofit/alteration/refurbishment, unless there are documented overriding reasons for not doing so; d. design attributes, that may include a combination of administrative and technical measures, designed to prevent or delay DUU of nuclear weapons or nuclear explosives;

Section 12

e. UC measures to prevent DUAs, DUU, and DAU from degrading the effectiveness of UC measures incorporated in or used for nuclear explosives or nuclear weapons; Attachment 1 DOE O 452.4C Page 2 8-28-2015 f. UC measures to prevent or delay DUAs, DUU, and DAU, or loss of control during planned NEOs; g. measures to assist the recapture or recovery of lost or stolen nuclear explosives or nuclear weapons; h. stockpile surveillance to ensure that UC devices and components meet specified requirements and have not been altered; i. DUA, DUU, and DAU evaluations performed periodically that may be specific to a DOE nuclear weapon, nuclear explosive, nuclear explosive operation, class of operations, or a facility or site; j. measures that must be continually assessed against existing and emerging threats as well as technological opportunities for improvement; k. documentation providing evidentiary trust that weapons systems, including associated systems and components, have not been subverted or corrupted; l. function and operation of UC features, devices and other measures will be integrated with security measures referenced in the above Order paragraph 4.b. in order to maximize system effectiveness and minimize cost; m. Nuclear Enterprise Assurance (NEA) to ensure the security of the supply chain and protect against components with malicious content that could override or degrade UC or nuclear weapons functionality; n. measures to ensure cyber security in all aspects of design, sourcing, procurement, and production to ensure that critical program information and systems are secure; and o. necessary measures for inter-agency information sharing and cooperation in threat identification, supplier vetting, and risk mitigation. 2. APPLICATION OF DOE NUCLEAR EXPLOSIVE SURETY STANDARDS. a. Contractors must ensure that all nuclear explosives and nuclear explosive operations meet the qualitative Nuclear Explosive Surety Standards (hereafter known as the Standards) set forth in DOE O 452.1E. b. Contractors must comply with the UC element of nuclear explosive surety that includes the unique requirement not explicitly captured by the Standards: to ensure use when authorized and directed by proper authority. Because of this unique UC objective, some requirements in this Order emphasize a subset of nuclear explosives that are in the fully assembled Department of Defense (DoD) configuration as nuclear weapons. DOE O 452.4C Attachment 1 8-28-2015 Page 3 c. Contractor protection of nuclear explosives and nuclear weapons must include a combination of administrative, process, and technical measures designed to ensure authorized use and prevent deliberate unauthorized use. d. Contractors must ensure that controls implemented to support the Standards for one aspect of surety - safety, security, or UC - are also evaluated for adverse impact on each of the other surety aspects. e. In the context of the Standards, “prevent” and “ensure” imply an absolute assurance, which cannot be guaranteed. Nonetheless, prevention of unintended/unauthorized nuclear detonation and unintended main charge High Explosive Violent Reaction (HEVR) and subversion of weapon functionality are primary goals in the design and performance of nuclear explosive operations. The objective is to drive the likelihood of the specified consequences as low as reasonably practicable.

Section 13

3. NUCLEAR EXPLOSIVE SECURITY. Safeguards and security measures must be documented in the site security plan. The Nuclear Explosive Security Standard from DOE O 452.1E must be met to ensure adequate nuclear explosive security for all NEOs conducted by the Department and its contractors. 4. NUCLEAR EXPLOSIVE AND NUCLEAR WEAPON USE CONTROL. Joint DOE/NNSA and DoD directives relating to policies, requirements and technical procedures for handling and controlling logistics code and key material are implemented by Technical Manual TP 50-2, Procedures for the Use and Control of Logistics Codes and Permissive Action Link (PAL) Equipped Weapons. 5. RESEARCH AND DEVELOPMENT (R&D). Design Agency contractors must conduct R&D for UC measures that can protect against DUAs, DUU, and DAU of nuclear explosives and nuclear weapons. a. The nuclear weapons design laboratories (Los Alamos National Laboratory, Lawrence Livermore National Laboratory, and Sandia National Laboratories) must conduct research and development on a broad range of security and UC methods and devices for nuclear explosives and nuclear weapons to: (1) Pursue technologies that can enhance security and UC for new and existing systems; (2) Pursue technologies that render the unauthorized use of U.S. nuclear weapons impossible without their remanufacture; (3) Develop approaches to efficiently detect subversion. b. Nuclear weapon design measures must provide assurance of operation when authorized for use. Attachment 1 DOE O 452.4C Page 4 8-28-2015 c. Nuclear weapon design features must support secure critical command and control communications. d. Technologies to aid in the recapture and recovery (R&R) of weapons must be demonstrated and evaluated for integration in DOE nuclear explosives/nuclear weapons to minimize the overall DUU risk associated with the weapons. e. Surety recommendations and priorities are intended to provide guidance for project managers, project teams, project officer groups, and decision-makers. f. Develop measures that minimize the risk of DUU by providing an integrated adversary delay or denial capability that either is inherent in the design or does not require human intervention. 6. DUA, DUU, and DAU EVALUATIONS. To ensure that DUA, DUU, and DAU controls are adequate, contractors must have DUA, DUU, and DAU evaluations performed on their designs and production activities to ensure that their controls are adequate. a. The controls must be periodically evaluated and documented against credible existing and emerging threats and technological advancements. b. The evaluations must assess the controls as they apply to the critical component, nuclear explosive, or nuclear weapon to ensure that they meet the UC elements of DOE O 452.1E Nuclear Explosive Surety Standards. In the context of this CRD, the DUA, DUU, and DAU evaluations only address malevolent unauthorized acts. (1) NNSA Sites with NEOs. The evaluations must address NEO processes, testers, tooling, and facilities to help ensure that controls are adequate to meet the UC elements of DOE O 452.1E Nuclear Explosive Surety Standards. (2) NNSA Sites without NEOs. The evaluations must address DOE weapon component designs, testing, and subsystem/component production to help ensure the integrity of product used in nuclear explosives and nuclear weapons is adequate to meet the UC elements of DOE O 452.1E Nuclear Explosive Surety Standards.

Section 14

c. This evaluation may be conducted in conjunction with the vulnerability assessment concerning radiological sabotage perpetrated by an insider adversary as required by DOE O 470.3B. d. Additional direction for the conduct of DUA, DUU, and DAU evaluations will be issued in a supplemental directive by the NNSA Administrator. e. As requested by the Office of Stockpile Management, contractors will provide technical support for the DUU reviews and evaluations. DOE O 452.4C Attachment 1 8-28-2015 Page 5 (and Page 6) 7. JOINT DOE AND DOD DUU PROTECTION. Contractors must cooperate with DOE, DoD, and other Federal agencies as required to provide protection against DUU and to assess the effectiveness of surety features for all U.S. nuclear weapon systems throughout their life-cycles. These features must be consistent with DoD operational requirements and must continually be assessed against existing and emerging threats as well as technological opportunities for improvement. 8. COMMAND AND CONTROL. Contractors must assist DoD in designating nuclear command and control critical equipment and components to ensure these items are developed and maintained to meet the criteria designated in National Security Directives. 9. RECORDS. Contractors must maintain records according to National Archives and Records Administration-approved DOE or site-specific records retention schedules. Approved: 8-28- 2015 1. PURPOSE 2. CANCELLATION 3. APPLICABILITY a. Departmental Applicability. (1) This Order applies to all those Departmental elements that are involved in performing, managing, overseeing, or directly supporting NEWS, specific nuclear weapon programs or associated activities. (2) The Administrator will ensure that National Nuclear Security Administration (NNSA) employees and contractors comply with their respective responsibilities under this Order. Nothing in this Order will be construed to interfere with the NNSA Adminis... b. DOE Contractors. Except for the equivalencies/exemptions in paragraph 3.c., the Contractor Requirements Document (CRD), Attachment 1, sets forth requirements of this Order that will apply to contracts that include the CRD. The CRD must be included ... c. Equivalencies and Exemptions for DOE O 452.4C. (1) Requests for equivalencies and exemptions to this Order must be in memorandum form and sent to the Office of Nuclear Weapon Surety and Quality, Office of Stockpile Management, Defense Programs. (a) The memorandum must briefly justify the reasons for the Equivalencies/Exemptions. (b) The memorandum must reference the offices, or localities, and requirements for which the equivalency/exemption is sought. (2) Exemptions. The following Departmental elements are exempted: Advanced Research Project Agency – Energy, Office of the Chief Financial Officer, Office of Congressional and Intergovernmental Affairs, Office of Economic Impact and Diversity, Energy... (3) Equivalency. In accordance with the responsibilities and authorities assigned by Executive Order 12344, codified at Title 50 United States Code (U.S.C.) sections 2406 and 2511 and to ensure consistency through the joint Navy/DOE Naval Nuclear Prop...

Section 15

4. REQUIREMENTS a. Application of Nuclear Explosive Surety Standards (1) All nuclear explosives and nuclear explosive operations (NEOs) must meet the qualitative Nuclear Explosive Surety Standards (hereafter known as the Standards) set forth in DOE O 452.1E, or its successors. (2) The UC element of nuclear explosives surety includes one unique requirement that is not explicitly captured by the Standards: to ensure use only when authorized and directed by proper authority. Because of this unique UC objective, some requiremen... (3) The protection of nuclear explosives and nuclear weapons must include a combination of administrative, process, and technical measures designed to ensure authorized use and prevent deliberate unauthorized use. (4) Controls implemented to support the Standards for one part of surety - safety, security, or UC - must also be evaluated for adverse impact on each of the other surety parts. (5) In the context of the Standards, “prevent” and “ensure” imply an absolute assurance, which cannot be guaranteed. Nonetheless, prevention of unintended/unauthorized nuclear detonation and unintended main charge High Explosive Violent Reaction (HEVR... b. Nuclear Explosive Security. These requirements are specified in the 452- and 470-series directives. Safeguards and security measures must be documented in the site security plan. The Nuclear Explosive Security Standard from DOE O 452.1E must be met... c. Nuclear Explosive and Nuclear Weapon Use Control. These requirements are specified in this directive. However, Joint DOE/NNSA and DoD directives relating to policies, requirements and technical procedures for handling and controlling logistics code... d. Nuclear Explosive and Weapon Security and Use Control Program (1) function and operation of UC features, devices and other measures will be integrated with security measures referenced in paragraph 4.b. above in order to maximize system effectiveness and minimize cost; (2) security and UC measures for nuclear explosives and nuclear weapons, including design features that are incorporated and used at the earliest practical point during assembly and removed at the latest practical point during disassembly or dismantle... (3) security and UC upgrades will be implemented during weapon retrofit/alteration/refurbishment for all nuclear weapons, unless there are documented overriding reasons for not doing so; (4) design attributes, that may include a combination of administrative and technical measures, designed to prevent or delay DUU of nuclear explosives and nuclear weapons; (5) the Human Reliability Program (HRP) as required by Title 10 Code of Federal Regulations (CFR) Part 712, to ensure the reliability of DOE and contractor employees who require access to designated components, nuclear explosives, or nuclear weapons; (6) measures to prevent DUAs from degrading the effectiveness of UC measures incorporated in or used for nuclear explosives or nuclear weapons; (7) measures to prevent or delay DUU, DUAs, DAU, or loss of control during planned NEOs; (8) measures to assist the recapture and recovery (R&R) of lost or stolen nuclear explosives or nuclear weapons; (9) stockpile surveillance to ensure that UC devices and components meet specified requirements and have not been altered; (10) DUA, DUU, and DAU evaluations performed periodically that may be specific to a DOE nuclear weapon, nuclear explosive, NEO, class of operations, facility or site (see subparagraph 4.f. below); (11) measures that must be continually assessed against existing and emerging threats as well as technological opportunities for improvement; (12) Nuclear Enterprise Assurance (NEA) to ensure the security of the supply chain and protect against components with malicious content that could override or degrade UC or nuclear weapons functionality; (13) measures to ensure cyber security in all aspects of design, sourcing, procurement, and production to ensure that critical program information and systems are secure; (14) necessary measures for inter-agency information sharing and cooperation in threat identification, supplier vetting, and risk mitigation; (15) documentation providing evidentiary trust that weapons systems, including associated systems and components, have not been subverted or corrupted; and (16) Research and Development (R&D) (described in paragraph 4.e. below).

Section 16

e. Research and Development (R&D). Consistent with the Standards and the Program, DOE/NNSA must provide resources and conduct R&D for security and UC measures that can protect against DUAs, DUU, and DAU of nuclear explosives and nuclear weapons. Recom... Specifically, security and UC R&D must: (1) pursue technologies that can enhance security and UC for new and existing systems; (2) pursue technologies that render the unauthorized use of U.S. nuclear weapons impossible without their remanufacture; (3) develop nuclear weapon measures to provide assurance of operation as designed when authorized for use; (4) design nuclear weapon features that enhance secure critical command and control communications; (5) develop technologies to aid in the R&R of weapons; (6) develop measures that minimize the risk of DUU by providing an integrated adversary delay or denial capability that either is inherent in the design or does not require human intervention; (7) develop approaches to efficiently detect subversion; and (8) when new improvements for security and UC measures are developed, cognizant security and UC R&D officials and/or cognizant managers must ensure that improvements and information related to them are appropriately protected and classified according ... f. DUA, DUU, and DAU Evaluations. To ensure that DUA, DUU, and DAU controls are adequate the evaluations must be performed for DOE/NNSA nuclear explosives, nuclear weapons, NEOs, and certain non-NEO production activities. The controls must be periodic... (1) NNSA Sites with NEOs. The DUA, DUU, and DAU evaluations will address NEO processes, testers, tooling, and facilities to help ensure that controls are adequate to meet the UC elements of DOE O 452.1E Nuclear Explosive Surety Standards applicable to... (2) NNSA Sites without NEOs. The DUA, DUU, and DAU evaluations will address DOE weapon component designs, testers, and subsystem/ component production to help ensure the integrity of product used in nuclear explosives and nuclear weapons is adequate s... g. Joint DOE and DoD DUU Protection h. Command and Control. DOE/NNSA must assist DoD in designating nuclear command and control critical equipment and components to ensure that these items are developed and maintained to meet the criteria designated in National Security Directives and t... 5. RESPONSIBILITIES. a. Director, Office of Intelligence and Counterintelligence. (1) Provides intelligence and counterintelligence support for the NEA activity. (2) Nominates, in writing, a member to serve on the Nuclear Enterprise Assurance Steering Group (NEASG). b. Associate Administrator for Emergency Operations. Establishes programs for coordinating and assisting in the R&R of U.S. nuclear explosives or nuclear weapons for which physical control has been lost. c. Chief of Defense Nuclear Security (CDNS). (1) Serves as the DOE Officially Designated Federal Security Official responsible for the development and implementation of security programs, operations, and facilities under the purview of NNSA, including physical security, personnel security, mater... (2) Advises the Assistant Deputy Administrator for Stockpile Management on safeguards and security requirements to implement the security element of the surety Standards as defined in the DOE NEWS Program. (3) Serves as a member of the Nuclear Enterprise Assurance Steering Group (NEASG). The CDNS may appoint member to act as the CDNS agent to the NEASG.

Section 17

d. Associate Administrator for Information Management and Chief Information Officer. (1) Provides cyber asset security and assurance for the NEA activity. (2) Nominates, in writing, a member to serve on the Nuclear Enterprise Assurance Steering Group (NEASG). e. Assistant Deputy Administrator for Stockpile Management. (1) Oversees the management and integration of all aspects of the Program. (2) Represents the Office of Defense Programs in coordinating and assisting DoD and other Federal agencies in the R&R of U.S. nuclear explosives or nuclear weapons for which physical control has been lost. (3) Represents DOE/NNSA regarding U.S. nuclear weapons and nuclear weapons systems UC to DoD and other Federal agencies. (4) Ensures active and continuous review of the nuclear stockpile is being conducted to identify Program concerns and ensures implementation of stockpile improvement or controls to address identified concerns. (5) Directs assessment of the effectiveness of UC features of U.S. nuclear weapons in DOE and DoD custody. (6) Approves designated components for Defense Programs (see subparagraphs 4.d. (5) and 4.h. above). (7) Establishes and oversees the Nuclear Enterprise Assurance activity within the Program to effectively address the “ensure authorized use” mission area of use control and to preclude denial of authorized use. (8) Charters and chairs the Nuclear Enterprise Assurance Steering Group (NEASG) to provide oversight and guidance for NEA activities, accepts NEASG member nominations, in writing, and makes final decision on issues when NEASG members cannot reach cons... (9) Accepts risk for the Office of the Deputy Administrator for Defense Programs throughout product realization life-cycle for stockpile systems, life extension programs, alterations, including those identified by NEA activities. f. Assistant Deputy Administrator for Systems Engineering and Integration. Nominates, in writing, a member of the NEASG. g. Assistant Deputy Administrator for Major Modernization Programs. (1) Works with the Office of Stockpile Management to incorporate new UC features in the stockpile during weapon life extension programs, modifications, or alterations. (2) Enables the Nuclear Enterprise Assurance activity in assigned mission area to effectively address the “ensure authorized use” mission area of use control and to preclude denial of authorized use. (3) Nominates, in writing, a member of the NEASG. h. Office of Materials Management and Technology Maturation i. . (1) Manages the R&D aspects of the Program. (2) Conducts R&D on a broad range of surety methods and devices to significantly improve the security and UC of nuclear weapons and nuclear weapon systems. (3) Establishes security and UC priorities for R&D efforts and resources and designates critical components for UC development. (4) Allocates resources and pursues UC options with delay or denial capability that, at a minimum, are equivalent to that associated with current nonviolent disablement systems. (5) Allocates resources and pursues technologies that render the unauthorized use of U.S. nuclear weapons impossible without their remanufacture. (6) Allocates R&D resources and directs R&D of controls to prevent DUAs, DUU, and DAU of nuclear explosives and nuclear weapons. (7) Works with the Office of Stockpile Management to establish programs to incorporate improved UC measures in the stockpile.

Section 18

j. Office of Nuclear Weapon Surety and Quality. (1) Manages all aspects of the Program with the exception of R&D. (2) Assists DoD and other Federal agencies in designating nuclear command and control critical equipment and ensuring that it is developed to meet criteria specified in National Security Directives. (3) Works with the Offices of Systems Engineering and Integration, Major Modernization Programs, Nuclear Weapon Stockpile, and Materials Management and Technology Maturation to establish programs to incorporate improved UC measures in the stockpile an... (4) Manages the periodic DUA, DUU, and DAU assessment of nuclear explosives and nuclear weapons to evaluate and document existing and emerging threats and technological advancements associated with DUAs, DUU, and DAU. (5) If requested by a Field Office, (a) assists with annual reviews of the programs under their purview. (b) helps ensure (based on competent, independent reviews) that DUA, DUU, and DAU reviews meet the requirements of this Order. k. Assistant Deputy Administrator for Secure Transportation. (1) Ensures active and continuous review of the aspects of the Program under his/her purview is conducted to identify Program concerns and ensures implementation of improvement or controls to address identified concerns. (2) Assesses the effectiveness of the integrated system of controls to protect nuclear explosives and nuclear weapons under his/her cognizance against DUAs. (3) Periodically evaluates and documents existing and emerging threats and technological advancements associated with DUAs. l. Assistant Deputy Administrator for Nuclear Safety and Operations. Ensures active and continuous review of the aspects of the Program under his/her purview is being conducted to identify Program concerns and ensures implementation of improvement or ... m. Managers of NNSA Field Offices. (1) Ensure implementation of the Program, including NEA activities where applicable. (2) Conduct annual Program reviews of the programs under their purview for the Assistant Deputy Administrator for Stockpile Management, the Assistant Deputy Administrator for Major Modernization Programs, the Assistant Deputy Administrator for Secure ... (3) Ensure (based on competent, independent reviews) that each NEO authorized meets the use control elements of DOE O 452.1E Nuclear Explosive Surety Standards applicable to NEOs. Retain documentation of these reviews, their conclusions, and resolutio... (4) Ensure (based on competent, independent reviews) that DUA, DUU, and DAU reviews for non-NEO production does not jeopardize conformance with UC elements of the DOE O 452.1E Nuclear Explosive Surety Standards. Retain documentation of these reviews, ... (5) Notify contracting officers of which contracts are affected by the CRD to this Order. n. Contracting Officers. Once notified, contracting officers are responsible for incorporating the CRD of this Order into each affected contract. 6. DEFINITIONS a. Delay. The effect achieved by physical features, technical devices, security measures, or protective forces that impedes an adversary from gaining access to an asset being protected or from completing a malevolent act. b. Deliberate Unauthorized Act (DUA). Any intentional action that has not been authorized and approved by proper authority. (1) In the context of the nuclear explosive surety Standards, a DUA is one that is not sanctioned as part of an approved nuclear explosive operation or associated activity, but which could affect a NE or main charge high explosive part collocated with... (2) In the context of this Order, a DUA is of interest if it is performed with a malevolent intent to prevent authorized use (see DAU) of a nuclear weapon; create a nuclear detonation or other DUU; or to gain unauthorized control of a nuclear explosive.

Section 19

c. Deliberate Unauthorized Use (DUU). Any of the following consequences resulting from deliberate malevolent acts: (1) a nuclear detonation not authorized by the National Command Authorities; (2) a HEVR that could result in an unauthorized nuclear detonation, (3) theft of nuclear explosives. d. Denial of Authorized Use (DAU). Any unauthorized act, including DUAs, which would prevent the authorized use or intended functionality of a nuclear weapon. The resulting potential effects on the nuclear weapon include but are not limited to: (1) Actual alteration of system or critical component functionality and (2) Perception that system or critical components are not functioning properly. e. Facility. Any equipment, structure, system, process, or activity that fulfills a specific purpose. f. Measures. The total spectrum of characteristics, devices, equipment, procedures, and administrative processes used to: (1) ensure timely authorized use only when directed by national authority, and (2) increase the difficulty of or add to the delay in achieving the deliberate unauthorized use of a nuclear explosive. g. Nuclear Command and Control Critical Equipment. Specifically designated equipment, including software, used to build, encode, decode, transmit, or receive emergency action messages; identify nuclear targets, select nuclear weapons to be used agains... h. Nuclear Enterprise Assurance (NEA). The NSE program established to prevent or mitigate potential consequences of nuclear weapon lifecycle deliberate unauthorized acts that may lead to denial of authorized use or degradation of weapon reliability or... i. Nuclear Enterprise Assurance Steering Group (NEASG). A review and decision- making body for oversight and management of NEA activities formed from a limited number of senior Federal Officials from NNSA and DOE Headquarters. j. Nuclear Explosive. An assembly containing fissionable and/or fusionable materials and main charge high explosive parts or propellants capable of producing a nuclear detonation (for example, a nuclear weapon or test device). k. Nuclear Explosive Operation (NEO). Any activity involving a nuclear explosive including activities in which main charge high explosive parts and pit are collocated. l. Nuclear Security Enterprise (NSE). The NNSA organizations that manage nuclear weapon data and/or design, manufacture, or test nuclear weapons or nuclear weapon components. Included in the NSE are: (1) NNSA Headquarters, Albuquerque Complex and Field Offices, (2) Lawrence Livermore National Laboratory, (3) Los Alamos National Laboratory, (4) Sandia National Laboratories, (5) Pantex Plant, (6) Kansas City Plant, (7) Y-12 National Security Complex, (8) NNSA operations at the Savannah River Site, and (9) Nevada National Security Site.

Section 20

m. Nuclear Weapon. A nuclear explosive configured for Department of Defense use. n. Recapture. Regaining control of a nuclear weapon and/or special nuclear material, which is under unauthorized possession, while still within the confines of a Departmental site/facility. o. Recovery. Regaining control of a nuclear weapon and/or special nuclear material, which is under unauthorized possession and has been removed from within the confines of a Departmental site/facility or Departmental possession. p. Security. An integrated system of activities, systems, programs, facilities, and policies for the protection of classified information and/or classified matter, unclassified controlled information, nuclear materials, nuclear weapons, nuclear weapon... q. Supply Chain Risk Management (SCRM). The systematic identification, assessment, quantification and mitigation of potential supply chain disruptions based on analysis of weapon vulnerabilities and adversarial threats. SCRM processes are designed to ... r. Surety. Safety, security, and use control of nuclear explosives and nuclear weapons. s. Use Control. The application of systems, devices, or procedures that ensure timely authorized use of a nuclear explosive while precluding or delaying unauthorized nuclear detonation. t. Weapon Trust Assurance (WTA). A series of evidentiary activities across the weapon lifecycle designed to prevent the Denial of Authorized Use of nuclear weapons. WTA ensures that the weapon, weapon-related components, cybersecurity and processes as... 7. REFERENCES. a. Human Reliability Program rule, 10 CFR Part 712, the rule that defines a security and safety reliability program designed to ensure that individuals who occupy positions affording access to certain materials, nuclear explosive devices, facilities, ... b. National Security Presidential Directive 28, dated 06-20-03. c. Joint Policy Statement on Nuclear Weapons Surety, dated 6-27-91, signed by the Secretaries of Defense and Energy. d. Memorandum of Understanding Between the Department of Defense and Department of Energy on Objectives and Responsibilities for Joint Nuclear Weapon Activities, dated 1-17-83, which supplements previous agreements delineating DoD and DOE objectives, ... e. CJCSI 3260.01D (series), Joint Policy Governing Positive Control Material and Devices, is a directive that establishes National policy and procedures applicable to the Executive Branch for positive control material and devices. It is the source doc... f. Technical Manual TP 50-2, Procedures for the Use and Control of Logistics Codes for Permissive Action Link (PAL) Equipped Weapons, is a joint DOE and DoD directive that provides the policies, requirements and technical procedures for handling and c... g. DOE O 151.1C, Comprehensive Emergency Management System, dated 11-2-05, which establishes objectives, responsibilities, and requirements for a system that encompasses emergency planning, preparedness, readiness assurance, response, and recovery act... h. DOE O 226.1B, Implementation of Department of Energy Oversight Policy, dated 4-25-11, which provides direction for implementing DOE P 226.1B, Department of Energy Oversight Policy, dated 4-25-11, which establishes DOE policy for assurance systems a... i. DOE O 243.1B, Records Management Program, dated 3-11-13, with Administrative Change 1 dated 7-8-13 which describe requirements for managing records related to this program.

Section 21

j. DOE O 251.1C, Departmental Directives Program, dated 1-15-09, which details the process for requesting exemptions from directives requirements. k. DOE O 414.1D, Quality Assurance, dated 4-25-11, which ensures that DOE, including NNSA, products, and services meet or exceed customers’ requirements and expectations. l. DOE O 452.1E, Nuclear Explosive and Weapon Surety Program, dated 01-26-15, which establishes the DOE Nuclear Explosive Surety Standards and specifies other requirements and responsibilities for the Nuclear Explosive and Weapon Surety Program to pre... m. DOE O 452.2E, Nuclear Explosive Safety, dated 01-26-15, which establishes DOE objectives, requirements, and responsibilities to implement nuclear explosive safety for routine and planned nuclear explosive operations. n. DOE O 452.7, Protection of Use Control Vulnerabilities and Designs, dated 5-14-10, establishes the policy, process and procedures for control of sensitive use control information in nuclear weapon data (NWD) categories Sigma 14 and Sigma 15 to ensu... o. NNSA SD 452.2, Nuclear Explosive Safety Evaluation Processes, dated 11-17-14, details the administrative and procedural requirements for nuclear explosive safety evaluations of nuclear explosive operations conducted by the DOE/NNSA and its contract... p. DOE O 452.6A, Nuclear Weapon Surety Interface with the Department of Defense, dated 04-14-09, establishes DOE and NNSA requirements and responsibilities for addressing joint nuclear weapon and nuclear weapon system surety activities in conjunction ... q. DOE O 461.1B, Packaging and Transportation for Offsite Shipment of Materials of National Security Interest, dated 12-16-10, which establishes the DOE requirements and responsibilities and implements the management and operation of the Transportatio... r. DOE P 470.1A, Safeguards and Security Program, dated 12-29-2010, which ensures the DOE efficiently and effectively meets all its obligations to protect Special Nuclear Material, other nuclear materials, classified matter, sensitive information, gov... s. NNSA Policy Letter NAP-24, Weapon Quality Policy, dated 6-20-13, which identifies the quality requirements applicable to weapon activities of the NNSA, NNSA contractors, and subcontractors. t. DOE O 470.3B, Graded Security Protection Policy, dated 8-12-08, classified. u. DOE O 470.4B, Safeguards and Security Program, dated 7-21-11, with Administrative Change 1 dated 2-15-13, which establishes responsibilities and program planning and management requirements for the DOE Safeguards and Security Program. v. DOE O 471.6, Information Security, dated 6-20-11, with Administrative Change 1 dated 11-30-12 establishes requirements and responsibilities for DOE Departmental Elements, including the NNSA, to protect and control classified information as required... w. NNSA Supplemental Directive (NASD) 452.4, Implementation and Evaluation of Controls to Prevent Deliberate Unauthorized Use, dated 7-7-11, supports this Order’s requirements to implement deliberate unauthorized use (DUU) preventive measures for nucl...

Section 22

8. CONTACT. Questions concerning this Order should be addressed to the Office of Nuclear Weapon Surety and Quality, 202-586-0377. ATTACHMENT 1. CONTRACTOR REQUIREMENTS DOCUMENT DOE O 452.4C, Security and Use Control of Nuclear Explosives and Nuclear Weapons 1. NUCLEAR EXPLOSIVE AND WEAPON SECURITY AND USE CONTROL PROGRAM. The Nuclear Explosive and Weapon Security and Use Control Program (hereafter known as the Program) comprises an integrated system of devices, design techniques, evaluations, and other m... a. the Human Reliability Program (HRP) as required by Title 10 Code of Federal Regulations (CFR) Part 712, to ensure the reliability of Department of Energy (DOE) and contractor employees who require access to designated components, nuclear explosives or nuclear weapons; b. security and UC measures for nuclear explosives and nuclear weapons, including design features that are incorporated and used at the earliest practical point during assembly and removed at the latest practical point during disassembly or dismantlement; c. security and UC capabilities for all nuclear weapons upgraded to meet current surety requirements during weapon retrofit/alteration/refurbishment, unless there are documented overriding reasons for not doing so; d. design attributes, that may include a combination of administrative and technical measures, designed to prevent or delay DUU of nuclear weapons or nuclear explosives; e. UC measures to prevent DUAs, DUU, and DAU from degrading the effectiveness of UC measures incorporated in or used for nuclear explosives or nuclear weapons; f. UC measures to prevent or delay DUAs, DUU, and DAU, or loss of control during planned NEOs; g. measures to assist the recapture or recovery of lost or stolen nuclear explosives or nuclear weapons; h. stockpile surveillance to ensure that UC devices and components meet specified requirements and have not been altered; i. DUA, DUU, and DAU evaluations performed periodically that may be specific to a DOE nuclear weapon, nuclear explosive, nuclear explosive operation, class of operations, or a facility or site; j. measures that must be continually assessed against existing and emerging threats as well as technological opportunities for improvement; k. documentation providing evidentiary trust that weapons systems, including associated systems and components, have not been subverted or corrupted; l. function and operation of UC features, devices and other measures will be integrated with security measures referenced in the above Order paragraph 4.b. in order to maximize system effectiveness and minimize cost; m. Nuclear Enterprise Assurance (NEA) to ensure the security of the supply chain and protect against components with malicious content that could override or degrade UC or nuclear weapons functionality; n. measures to ensure cyber security in all aspects of design, sourcing, procurement, and production to ensure that critical program information and systems are secure; and o. necessary measures for inter-agency information sharing and cooperation in threat identification, supplier vetting, and risk mitigation.

Section 23

2. APPLICATION OF DOE NUCLEAR EXPLOSIVE SURETY STANDARDS. a. Contractors must ensure that all nuclear explosives and nuclear explosive operations meet the qualitative Nuclear Explosive Surety Standards (hereafter known as the Standards) set forth in DOE O 452.1E. b. Contractors must comply with the UC element of nuclear explosive surety that includes the unique requirement not explicitly captured by the Standards: to ensure use when authorized and directed by proper authority. Because of this unique UC objecti... c. Contractor protection of nuclear explosives and nuclear weapons must include a combination of administrative, process, and technical measures designed to ensure authorized use and prevent deliberate unauthorized use. d. Contractors must ensure that controls implemented to support the Standards for one aspect of surety - safety, security, or UC - are also evaluated for adverse impact on each of the other surety aspects. e. In the context of the Standards, “prevent” and “ensure” imply an absolute assurance, which cannot be guaranteed. Nonetheless, prevention of unintended/unauthorized nuclear detonation and unintended main charge High Explosive Violent Reaction (HEVR)... 3. NUCLEAR EXPLOSIVE SECURITY. Safeguards and security measures must be documented in the site security plan. The Nuclear Explosive Security Standard from DOE O 452.1E must be met to ensure adequate nuclear explosive security for all NEOs conducted by... 4. NUCLEAR EXPLOSIVE AND NUCLEAR WEAPON USE CONTROL. Joint DOE/NNSA and DoD directives relating to policies, requirements and technical procedures for handling and controlling logistics code and key material are implemented by Technical Manual TP 50-2... 5. RESEARCH AND DEVELOPMENT (R&D). Design Agency contractors must conduct R&D for UC measures that can protect against DUAs, DUU, and DAU of nuclear explosives and nuclear weapons. a. The nuclear weapons design laboratories (Los Alamos National Laboratory, Lawrence Livermore National Laboratory, and Sandia National Laboratories) must conduct research and development on a broad range of security and UC methods and devices for nuc... (1) Pursue technologies that can enhance security and UC for new and existing systems; (2) Pursue technologies that render the unauthorized use of U.S. nuclear weapons impossible without their remanufacture; (3) Develop approaches to efficiently detect subversion. b. Nuclear weapon design measures must provide assurance of operation when authorized for use. c. Nuclear weapon design features must support secure critical command and control communications. d. Technologies to aid in the recapture and recovery (R&R) of weapons must be demonstrated and evaluated for integration in DOE nuclear explosives/nuclear weapons to minimize the overall DUU risk associated with the weapons. e. Surety recommendations and priorities are intended to provide guidance for project managers, project teams, project officer groups, and decision-makers. f. Develop measures that minimize the risk of DUU by providing an integrated adversary delay or denial capability that either is inherent in the design or does not require human intervention.

Section 24

6. DUA, DUU, and DAU EVALUATIONS. To ensure that DUA, DUU, and DAU controls are adequate, contractors must have DUA, DUU, and DAU evaluations performed on their designs and production activities to ensure that their controls are adequate. a. The controls must be periodically evaluated and documented against credible existing and emerging threats and technological advancements. b. The evaluations must assess the controls as they apply to the critical component, nuclear explosive, or nuclear weapon to ensure that they meet the UC elements of DOE O 452.1E Nuclear Explosive Surety Standards. In the context of this CRD, the DUA,... (1) NNSA Sites with NEOs. The evaluations must address NEO processes, testers, tooling, and facilities to help ensure that controls are adequate to meet the UC elements of DOE O 452.1E Nuclear Explosive Surety Standards. (2) NNSA Sites without NEOs. The evaluations must address DOE weapon component designs, testing, and subsystem/component production to help ensure the integrity of product used in nuclear explosives and nuclear weapons is adequate to meet the UC eleme... c. This evaluation may be conducted in conjunction with the vulnerability assessment concerning radiological sabotage perpetrated by an insider adversary as required by DOE O 470.3B. d. Additional direction for the conduct of DUA, DUU, and DAU evaluations will be issued in a supplemental directive by the NNSA Administrator. e. As requested by the Office of Stockpile Management, contractors will provide technical support for the DUU reviews and evaluations. 7. JOINT DOE AND DOD DUU PROTECTION. Contractors must cooperate with DOE, DoD, and other Federal agencies as required to provide protection against DUU and to assess the effectiveness of surety features for all U.S. nuclear weapon systems throughout t... 8. COMMAND AND CONTROL. Contractors must assist DoD in designating nuclear command and control critical equipment and components to ensure these items are developed and maintained to meet the criteria designated in National Security Directives. 9. RECORDS. Contractors must maintain records according to National Archives and Records Administration-approved DOE or site-specific records retention schedules.

Something wrong with this record? Tell us