Archives of Directives

Archive

DOE O 470.4B Chg 3 (LtdChg), Safeguards and Security Program

To establish responsibilities for the U.S. Department of Energy (DOE) Safeguards and Security (S&S) Program, and to establish program planning and management requirements for the S&S Program. The requirements identified in this Order and its attachments and appendices are based on national policy promulgated in laws, regulations, Executive Orders, and national standards to prevent unacceptable adverse impacts on national security, the health and safety of DOE and contractor employees, the public, or the environment. Supersedes DOE O 470.4B Chg 2, dated 1-17-2017.
o470.4b_Chg3_LtdChg-20210923.pdf1.07MB
Version history and related documents
Document text

Text extracted from the attached file. Refer to the original document for the authoritative version.

Section 1

AVAILABLE ONLINE AT: INITIATED BY: www.directives.doe.gov Office of Environment, Health, Safety and Security U.S. Department of Energy ORDER Washington, DC Approved: 7-21-2011 Chg 1 (AdminChg): 2-15-2013 Chg 2 (MinChg): 1-17-2017 Chg 3 (LtdChg): 9-23-2021 SUBJECT: SAFEGUARDS AND SECURITY PROGRAM 1. PURPOSE. To establish responsibilities for the U.S. Department of Energy (DOE) Safeguards and Security (S&S) Program, and to establish program planning and management requirements for the S&S Program. The requirements identified in this Order and its attachments and appendices are based on national policy promulgated in laws, regulations, Executive Orders, and national standards to prevent unacceptable adverse impacts on national security, the health and safety of DOE and contractor employees, the public, or the environment. 2. CANCELLATIONS. DOE O 470.4B Chg 2 (MinChg), Safeguards and Security Program, dated 1-17-2017. Cancellation of a directive does not, by itself, modify or otherwise affect any contractual or regulatory obligation to comply with the directive. Contractor Requirements Documents (CRDs) that have been incorporated into a contract remain in effect throughout the term of the contract unless and until the contract or regulatory commitment is modified to either eliminate requirements that are no longer applicable or substitute a new set of requirements. 3. APPLICABILITY. a. Departmental Applicability. Except for the equivalencies/exemptions in paragraph 3.c., this Order applies to all Departmental elements. The Administrator of the National Nuclear Security Administration (NNSA) must ensure that NNSA employees comply with their responsibilities under this directive. Nothing in this directive will be construed to interfere with the NNSA Administrator’s authority under section 3212(d) of P.L. 106-65, National Nuclear Security Administration Act, to establish Administration specific policies, unless disapproved by the Secretary. The Administrator of the Bonneville Power Administration (BPA) must ensure that BPA employees and contractors comply with their respective responsibilities under this directive consistent with BPA’s procurement, self-financing, and statutory authorities. b. DOE Contractors. Except for the equivalencies/exemptions in paragraph 3.c., the CRD (Attachment 1) sets forth requirements of this Order that will apply to contracts that include the CRD. DOE O 470.4B http://www.directives.doe.gov/ 2 DOE O 470.4B 7-21-2011 (1) The CRD must be included in contracts that contain DOE Acquisition Regulation (DEAR) clause 952.204-2, Security Requirements. Heads of field elements and Headquarters Departmental elements must identify contracts that should incorporate the CRD and notify contracting officers to incorporate the CRD into those contracts. Contracting officers are responsible for incorporating the CRD into the affected contracts as appropriate. (2) A violation of the provisions of the CRD relating to the safeguarding or security of Restricted Data or other classified information may result in a civil penalty pursuant to subsection a of section 234B of the Atomic Energy Act (42 U.S.C. Section 2282b). The procedures for the assessment of civil penalties are set forth in Title 10, Code of Federal Regulations (CFR), Part 824, Procedural Rules for the Assessment of Civil Penalties for Classified Information Security Violations.

Section 2

c. Equivalencies/Exemptions for DOE O 470.4B Chg 3. Equivalencies and exemptions from the requirements of this Order are processed in accordance with DOE O 251.1C, Departmental Directives Program. (1) When conditions warrant equivalencies or exemptions from the requirements in this Order, requests must be supported by a vulnerability assessment (VA) when required by the assets being protected, or by sufficient analysis to form the basis for an informed risk management decision; the analysis must identify compensatory measures, if applicable, or alternative controls to be implemented. (2) All approved equivalencies and exemptions under this Order must be entered in the Safeguards and Security Information Management System (SSIMS) database and incorporated into the affected security plan(s). Approved equivalencies and exemptions become a valid basis for operation when they have been entered in SSIMS and documented in the appropriate security plan, and must be incorporated into site procedures at that time. (3) Many DOE S&S Program requirements are found in or based on regulations issued by Federal agencies, and codified in the CFR or other authorities, such as Executive Orders or Presidential Directives. In such cases, the process for deviating from those requirements found in the source document must be applied. If the source document does not include a deviation process, the DOE Office of the General Counsel, or NNSA Office of General Counsel if an NNSA element is involved, must be consulted to determine whether deviation from the source can be legally pursued. (4) Equivalency. In accordance with the responsibilities and authorities assigned by E.O. 12344, codified at 50 U.S.C. Sections 2406 and 2511 and DOE O 470.4B 3 7-21-2011 to ensure consistency through the joint Navy/DOE Naval Nuclear Propulsion Program, the Deputy Administrator for Naval Reactors (Director) will implement and oversee requirements and practices pertaining to this Directive for activities under the Director’s cognizance, as deemed appropriate. (5) Exemption. Requirements in this Order that overlap or duplicate requirements of the Nuclear Regulatory Commission (NRC) related to radiation protection, nuclear safety (including quality assurance), and safeguards and security of nuclear material, do not apply to the design, construction, operation, and decommissioning of the facilities of the former Office of Civilian Radioactive Waste Management (RW) now managed by the Office of Nuclear Energy. This exemption does not apply to requirements for which the NRC defers to DOE or does not exercise regulatory jurisdiction. 4. REQUIREMENTS. a. S&S programs must be developed and maintained that incorporate the responsibilities and requirements contained in this Order and its associated appendices and attachments. b. Programs associated with each topical area found in the appendices and attachments to this Order must be implemented in accordance with the requirements stated for that topic. c. Incidents of security concern must be addressed in accordance with the requirements found in Attachment 4 and reported in accordance with applicable laws and regulations.

Section 3

d. Interfaces and necessary interactions between S&S programs and other disciplines such as safety, emergency management, classification, counterintelligence, facility operations, cyber system operations and security, and business and budget operations including property management must be identified and clearly defined. These interfaces and interactions must be maintained throughout the lifecycle of protective measures to ensure that S&S planning and operations work together effectively with these disciplines. Sensitive Compartmented Information is under the purview of the Office of Intelligence and Counterintelligence; necessary interfaces and interactions between that office and S&S programs must also be identified, defined, and maintained. e. S&S programs must incorporate a risk-based approach to protect assets and activities against the consequences of attempted theft, diversion, terrorist attack, industrial sabotage, radiological sabotage, chemical sabotage, biological sabotage, espionage, unauthorized access, compromise, and other acts that may have an adverse impact on national security or the environment or that may pose 4 DOE O 470.4B 7-21-2011 significant danger to the health and safety of DOE Federal and contractor employees or the public. f. S&S programs must be tailored to address site-specific characteristics and requirements, current technology, ongoing programs, and operational needs to achieve acceptable protection levels that reduce risks in a cost-effective manner. 5. RESPONSIBILITIES. a. Secretary of Energy. (1) Ensures that an effective S&S Program is established and executed within DOE under the authorities granted by relevant Executive Orders; the U.S. Department of Energy Organization Act, as amended (42 U.S.C. Sections 7101 to 7352); and the Atomic Energy Act, as amended (42 U.S.C. Sections 2011 to 2286), and in accordance with P.L. 106-65, the National Nuclear Security Administration Act. (2) Designates senior Departmental officials to direct and administer the S&S Program. (3) Delegates, in writing, all responsibilities and authorities as necessary for the administration of the S&S Program. (4) Authorizes continuing operations of facilities/activities determined to be of high security risk. (5) Exercises sole authority to approve the imposition of requirements on Civilian Radioactive Waste Management programs and activities that are more stringent and/or comprehensive than those imposed by the NRC. (6) Designates the DOE program elements responsible for ensuring that foreign nationals’ visits requiring access to classified information are conducted in accordance with governing international agreements or treaties. b. Deputy Secretary. (1) Exercises responsibility, as Chief Operating Officer of the Department, for S&S policy development and operations. (2) Ensures that the S&S Program achieves excellence in performance, has internal compatibility, is graded in application, and integrates corporate programs and support activities with line programs consistent with the precepts of Integrated S&S Management. (3) Reviews all staff and support office S&S policies that affect Departmental elements. DOE O 470.4B 5 7-21-2011 (4) Establishes the Department-wide base Security Conditions (SECON) level in consultation with the Under Secretaries; the Deputy Under Secretary for Counterterrorism and Counterproliferation; the Director, Office of Intelligence and Counterintelligence; the Associate Under Secretary for Environment, Health, Safety and Security; and the Chief Security Officers.

Section 4

(5) In accordance with 50 U.S.C. Section 2656, ensures that the Committees on Armed Services of the U.S. House of Representatives and the U.S. Senate are notified of each significant nuclear defense intelligence loss. (6) Approves and issues the Design Basis Threat (DBT) Order. (7) Reviews and approves enhancements to Secretarial security policies identified by the Security Committee. (8) Appoints the Chair of the Security Committee, comprised of the Chief Security Officers from each Under Secretarial organization and other Departmental Federal leadership. (9) Approves site/facility management recommended deviation to lower from established Departmental SECON level. (10) Serves as chairman, or appoints a chairman, for the Senior SECON Decision Team. c. Under Secretary for Nuclear Security/ Administrator for the National Nuclear Security Administration. (1) Responsible for the management and implementation of S&S programs administered by NNSA and its subordinate offices, including provision of the appropriate level of authorities and resources to the NNSA Chief Security Officer to effectively manage and execute S&S responsibilities. (2) Authorizes continuing operations of NNSA facilities/activities determined to be of moderate security risk. (3) In coordination with the Under Secretaries for Science and Energy and Management and Performance, the Director, Office of Intelligence and Counterintelligence, the Deputy Under Secretary for Counterterrorism and Counterproliferation, the Associate Under Secretary for Environment, Health, Safety and Security, and the Chief Security Officers, provides recommendations on SECON levels to the Deputy Secretary. (4) Through the Associate Administrator for Emergency Operations, monitors the SECON level for the Department and for all DOE facilities and sites and advises DOE/NNSA officials of changes to the levels. 6 DOE O 470.4B 7-21-2011 (5) Through the Deputy Administrator for Defense Programs: (a) Ensures that all visits by foreign nationals and access to classified information in connection with the military application of atomic energy under 42 U.S.C. Section 2164 and 42 U.S.C. Section 2121 are conducted in accordance with governing international agreements or treaties. (b) Approves requests for classified visits and access to weapons programs, nuclear materials production facilities, sensitive nuclear materials production information, and classified information pertaining to Nuclear Weapons Data. (c) Delegates in writing to a senior Federal official at each site under (5)(b) above the authority to make, in connection with classified visits, an affirmative determination that permitting a U.S. citizen holding a clearance granted by another Federal agency to have access to Restricted Data will not endanger the common defense and security prior to granting such access in connection with a specific classified visit. (6) Through the Deputy Administrator for Defense Nuclear Nonproliferation, ensures that all foreign national visits and access to classified information in connection with nonproliferation, international security, or International Atomic Energy Agency requirements are conducted in accordance with governing international agreements or treaties. (7) Through the Deputy Administrator for Naval Reactors: (a) Ensures that all foreign national visits and access to classified information in connection with naval nuclear propulsion are conducted in accordance with governing international agreements or treaties.

Section 5

(b) Approves requests for classified visits and access to naval nuclear propulsion facilities. (8) Through the Associate Administrator for Defense Nuclear Security: (a) Serves as the NNSA Chief Security Officer responsible for the development and implementation of security programs, operations, and facilities under the purview of NNSA; exercises all responsibilities of a Chief Security Officer under this Order. (b) Oversees implementation of SECON levels for operations under the cognizance of NNSA. DOE O 470.4B 7 7-21-2011 (c) Acts as senior NNSA official responsible for the direction and administration of the NNSA implementation and compliance with the National Industrial Security Program. (d) Provides resources for conducting inquiries and damage assessments and for implementing corrective actions in incidents of security concern occurring at NNSA sites/facilities. (e) Acts as the senior NNSA official responsible for all classified visits except for those assigned in paragraph 5.d.(5)(b) above to the Deputy Administrator for Defense Programs; delegates in writing to a senior Federal official at each site under NNSA cognizance the authority to make, in connection with such classified visits, an affirmative determination that permitting a U.S. citizen holding a clearance granted by another Federal agency to have access to Restricted Data will not endanger the common defense and security prior to granting such access in connection with a specific classified visit. (f) Implements the DOE North Atlantic Treaty Organization (NATO) program for DOE and NNSA including access authorizations, policy, operations of the DOE Sub-Registry, and the conduct of DOE domestic inspections. d. Under Secretary for Science and Energy. (1) Responsible for management and implementation of S&S programs administered by the DOE Office of the Under Secretary for Science and Energy and its subordinate offices, including provision of the appropriate level of authorities and resources to the Under Secretary for Science and Energy Chief Security Officer to effectively manage and execute S&S responsibilities. (2) In coordination with the Under Secretary for Management and Performance, the NNSA Administrator, the Director, Office of Intelligence and Counterintelligence, the Deputy Under Secretary for Counterterrorism and Counterproliferation, the Associate Under Secretary for Environment, Health, Safety and Security, and the Chief Security Officers, provides recommendations on SECON levels to the Deputy Secretary. (3) Oversees implementation of SECON levels for operations under the cognizance of the Under Secretary for Science and Energy. (4) Provides resources for conducting inquiries and damage assessments and for implementing corrective actions in incidents of security concern occurring at Science and Energy sites/facilities. 8 DOE O 470.4B 7-21-2011 (5) Authorizes continuing operations of the Office of the Under Secretary for Science and Energy facilities/activities determined to be of moderate security risk. (6) Delegates in writing to a senior Federal official at each site under his/her cognizance the authority to make, in connection with classified visits, an affirmative determination that permitting a U.S. citizen holding a clearance granted by another Federal agency to have access to Restricted Data will not endanger the common defense and security prior to granting such access in connection with a specific classified visit.

Section 6

(7) Through the Assistant Secretary for Nuclear Energy: (a) Ensures that visits by foreign nationals to uranium enrichment plants or facilities and access to classified information on uranium enrichment technology development, including advanced isotope separation technology, are conducted in accordance with governing international agreements or treaties. (b) Approves requests for classified visits and access to uranium enrichment plants or facilities engaged in uranium enrichment technology development, including advanced isotope separation technology. e. Under Secretary for Management and Performance. (1) Responsible for management and implementation of S&S programs administered by the Office of the Under Secretary for Management and Performance and its subordinate offices, including provision of the appropriate level of authorities and resources to the Management and Performance Chief Security Officer to manage and execute S&S responsibilities. (2) In coordination with the Under Secretary for Science and Energy, the NNSA Administrator, the Deputy Under Secretary for Counterterrorism and Counterproliferation, the Director, Office of Intelligence and Counterintelligence, the Associate Under Secretary for Environment, Health, Safety and Security, and the Chief Security Officers, provides recommendations on SECON levels to the Deputy Secretary. (3) Oversees implementation of SECON levels for operations under the cognizance of the Under Secretary for Management and Performance. (4) Provides resources for conducting inquiries and damage assessments and for implementing corrective actions in incidents of security concern occurring at Management and Performance sites/facilities. DOE O 470.4B 9 7-21-2011 (5) Authorizes continuing operations of facilities/activities under the cognizance of the Office of the Under Secretary for Management and Performance determined to be of moderate security risk. (6) Delegates in writing to a senior Federal official at each site under his/her cognizance the authority to make, in connection with classified visits, an affirmative determination that permitting a U.S. citizen holding a clearance granted by another Federal agency to have access to Restricted Data will not endanger the common defense and security prior to granting such access in connection with a specific classified visit. (7) Through the Associate Under Secretary for Environment, Health, Safety and Security: (a) Develops the Department’s S&S Program consistent with strategies and policies governing the protection of national security and other critical assets entrusted to the Department and in accordance with laws, regulations, and national-level policies and standards. (b) Coordinates and promulgates the Department’s policies and procedures for a comprehensive S&S Program. (c) In coordination with the Under Secretaries, the NNSA Administrator, the Deputy Under Secretary for Counterterrorism and Counterproliferation, the Director, Office of Intelligence and Counterintelligence, and the Chief Security Officers, provides recommendations on SECON levels to the Deputy Secretary. (d) Directs the development and implementation of a security plan for the protection of the DOE Headquarters, its personnel, and its assets; oversees functions of the DOE cognizant security office for DOE Headquarters facilities, and delegates this authority in writing as appropriate.

Section 7

(e) Oversees implementation of the DOE Headquarters S&S Program, including the development of S&S implementation procedures and guidance for programs described in this Order and its appendices and attachments, to include the approval of Headquarters equivalencies and exemptions; provides oversight and technical direction for all DOE offices located in Headquarters facilities. (f) Ensures that the authorized SECON levels are implemented for operations under the cognizance of the Office of Environment, Health, Safety and Security (AU). 10 DOE O 470.4B 7-21-2011 (g) Provides advice and assistance to DOE organizations concerning S&S programs described in this Order and its appendices and attachments. (h) Serves as the executive agent responsible for the development of the DBT, ensures that the DBT is periodically reviewed and updated, staffs and obtains approval for the DBT through the offices of the Under Secretaries, and recommends action to approve the DBT to the Deputy Secretary. (i) Reviews procurement requests for new AU Headquarters contracts and ensures that the provisions of 48 CFR Section 952.204-2, Security Requirements, and the requirements of the CRD and its attachments in this Order are included in the contracts when required. (j) Acts as the senior Agency official responsible for directing and administering the DOE’s implementation of E.O. 12829, National Industrial Security Program, Section 203(a). (k) Maintains national-level liaison with Federal law enforcement, security, and intelligence agencies in support of the DOE S&S Program; and represents DOE in interagency efforts related to S&S activities. (l) Provides executive secretary support to the Security Committee. With guidance from the Chair, the Executive Secretary will be responsible for ensuring issues brought before the Committee are properly analyzed and prepared for decision, recording Committee decisions, and communicating decisions to the appropriate elements of the Department. (8) Through the Assistant Secretary for Environmental Management: (a) Provides resources for conducting inquiries and damage assessments and for implementing corrective actions in incidents of security concern occurring at EM sites/facilities. (b) Delegates in writing to a senior Federal official at each site under EM cognizance the authority to make, in connection with classified visits, an affirmative determination that permitting a U.S. citizen holding a clearance granted by another Federal agency to have access to Restricted Data will not endanger the common defense and security prior to granting such access in connection with a specific classified visit. DOE O 470.4B 11 7-21-2011 (c) Reviews procurement requests for new EM contracts and ensures that the provisions of 48 CFR Section 952.204-2, Security Requirements, and the requirements of the CRD and its attachments in this Order are included in the contracts when required. f. Heads of Field Elements and Headquarters Departmental Elements. (1) Oversee the development of S&S plans that describe S&S policy implementation in accordance with the requirements in this Order and its appendices and attachments and include detailed information on the assignment of roles, responsibilities, delegations, authorities, and development of budgets and allocation of resources. (2) Oversee the development of S&S implementation procedures and guidance for programs described in this Order and its appendices and attachments, implement the programs, and provide oversight and technical direction for the programs.

Section 8

(3) Develop and allocate S&S budgets for assigned programs including budgets for the infrastructure that supports S&S missions. (4) Ensure that line management implements the applicable provisions of programs described in this Order and its appendices and attachments. (5) When new DOE S&S directives are issued, oversee the development of and approve an implementation plan describing the steps and milestone dates that will lead to full implementation of new requirements and incorporation of CRDs into affected contracts. (6) Notify contracting officers of affected contracts that must include the CRD and attachments to this Order. (7) Ensure that procurement requests for new contracts require inclusion of appropriate language, including the clause at 48 CFR Section 952.204-2, Security Requirements, and the CRD and attachments to this Order in the resulting contracts, when applicable. (8) Ensure that contracting officers provide DOE F 470.1, Contract Security Classification Specification (CSCS), to the DOE cognizant security offices or their designees. (9) Curtail or suspend operations at facilities/sites under their cognizance when continued operations would result in an unacceptable risk to national security and/or to the health and safety of DOE and contractor employees, the public, or the environment. 12 DOE O 470.4B 7-21-2011 (10) Ensure that the authorized SECON levels are implemented at facilities/sites under their cognizance and that any local changes at affected facilities are reported to the Operations Center, Office of Emergency Operations. (11) Ensure that S&S personnel under their cognizance are managed, trained, and equipped and are provided with the resources and support services needed to maintain protection of S&S interests. (12) Ensure that contractors and subcontractors under their cognizance implement the provisions of the CRD and attachments to this Order when the CRD is incorporated in their contracts. (13) Ensure that line management at sites under their cognizance has been delegated the authority for oversight and monitoring of contractor performance of the requirements contained in the CRD and its attachments, and that appropriate oversight and monitoring activities are conducted, including a process to validate established objectives, standards, and criteria for security training programs conducted by organizations other than the National Training Center. (14) Ensure that a senior Federal official at each site under their cognizance has been delegated in writing the authority to make, in connection with classified visits, an affirmative determination that permitting a U.S. citizen holding a clearance granted by another Federal agency to have access to Restricted Data will not endanger the common defense and security prior to granting such access in connection with a specific classified visit. (15) Assesses the impact/potential impact (e.g., reduced operations, additional protective force or security personnel, searches, entry/exit screening, patrols, training, etc.) in response to elevated SECON level. (16) Establishes higher local SECON level at their respective site/facility; or to recommend a deviation to lower from the Departmental SECON upon notification to and approval by the Deputy Secretary. (a) Ensure the local SECON level is consistent with the threat or local conditions. (b) Changing the Local SECON Level.

Section 9

1 Through the DOE Watch Office notifies the cognizant Under Secretary, with a courtesy notification to the Senior SECON Decision Team, of any situation where site/facility management recommends a deviation to lower from the Departmental SECON level. DOE O 470.4B 13 7-21-2011 2 Briefs the Senior SECON Decision Team, as soon as possible, on any situation where site/facility management recommends a deviation to lower from the Departmental SECON. 3 Upon approval by the Deputy Secretary, in consultation with Senior SECON Team, notifies site/facility management of the local SECON level, and implements measures appropriate to the local SECON level. 4 Advises the DOE Watch Office as soon as actions appropriate to the local SECON have been implemented. (c) Elevating Site SECON Levels above the Departmental Level. In addition to 1.f.(16)(b)1-4 above: 1 Site/facility management must immediately notify the Operations Center, Office of Emergency Operations, of the elevated SECON level and keep the Operations Center informed of the status of the site/facility and SECON response plan implementation. 2 Determine when the site/facility local SECON level can return to the Departmental SECON level and advise the Senior SECON Decision Team. (17) Review/update SECON response plans, as deemed appropriate. (18) Issues direction for, and oversees implementation of SECON level for sites/facilities or operations under their cognizance. g. Director, Office of Enterprise Assessments. (1) Performs assessments and reports to the Secretary on the Department’s S&S programs. (2) Implements the procedures for the assessment of civil penalties set forth in 10 CFR Part 824, Procedural Rules for the Assessment of Civil Penalties for Classified Information Security Violations. (3) Develops S&S training programs, and provides S&S training to Departmental personnel, primarily through the National Training Center (NTC). (4) Through the NTC, certifies site implementation of NTC-developed courses, establishes the Training Approval Program (TAP) for S&S programs, and approves site training programs. 14 DOE O 470.4B 7-21-2011 (5) Through the NTC, supports the Federal Technical Capabilities Panel in the implementation of the DOE Technical Qualification Program to develop a technically competent workforce and support Safeguards and Security Leadership and executive development programs. Senior executives with responsibility for technical oversight are expected to complete Security Executive Leadership Training. Security Executive Leadership Training is an in-residence course that covers topics, such as Security Trends; Risk Management and Security Planning; Security Events and Incidents; Security Oversight; Managing Security in a Safety Basis Environment; Personnel Security and Human Reliability Programs; and Cyber Security Threats. The content is designed for executive-level employees. h. Chief Security Officers for NNSA, Science and Energy, and Management and Performance. (1) Responsible and accountable for the development and implementation of the S&S programs for personnel, facilities, and sites within their respective offices. (2) As members of the Security Committee, participate in the development of Departmental S&S policy. (3) Coordinate and manage the provision of S&S support services to their respective line management /program offices. (4) Through the Security Committee, identify opportunities to strengthen security strategies through enhancements to Secretarial security policies.

Section 10

(5) In coordination with the Under Secretaries, the NNSA Administrator, the Director, Office of Intelligence and Counterintelligence, the Deputy Under Secretary for Counterterrorism and Counterproliferation, and the Associate Under Secretary for Environment, Health, Safety and Security, provides recommendations on SECON levels to the Deputy Secretary. i. Director, Office of Intelligence and Counterintelligence. (1) Ensures that information developed through intelligence/ counterintelligence program activities that affects S&S operations is shared with AU and NNSA. (2) Notifies the DOE/NNSA cognizant security office of security incidents during the course of intelligence/counterintelligence activities. This notification will be upon discovery unless such notification would severely impede or negate intelligence activities or counterintelligence investigations, or further compromise classified/sensitive information. DOE O 470.4B 15 7-21-2011 (3) Ensures coordination with cognizant security offices, as appropriate, concerning security issues and other matters of mutual concern for inclusion in security awareness activities and develops and conducts briefings to present information on intelligence and counterintelligence issues. Such briefings may be in conjunction with security awareness briefings. (4) Ensures that all foreign national visits and access to classified information in connection with Sensitive Compartmented Information (SCI) are conducted in accordance with governing international agreements or treaties. (5) Ensures that information on relevant intelligence/counterintelligence concerns is provided to Departmental elements responsible for classified visits by non-U.S. citizens under international agreements and treaties and to individuals responsible for hosting classified visits by non-U.S. citizens to DOE facilities and sites. (6) In coordination with the Under Secretaries, the NNSA Administrator, the Deputy Under Secretary for Counterterrorism and Counterproliferation, the Associate Under Secretary for Environment, Health, Safety and Security, and the Chief Security Officers, provides recommendations on SECON levels to the Deputy Secretary. (7) Issues direction for and oversees the implementation of SECON levels for operations under the cognizance of the Office of Intelligence and Counterintelligence. j. Deputy Under Secretary for Counterterrorism and Counterproliferation. In coordination with the Under Secretaries, the NNSA Administrator, the Office of Intelligence and Counterintelligence, and the Associate Under Secretary for Environment, Health, Safety and Security, provides recommendations on SECON levels to the Deputy Secretary. k. General Counsel, Office of the General Counsel. Provides legal advice and assistance to AU regarding issues or changes in laws and regulations that may affect S&S interests and programs. l. Contracting Officers. (1) Upon notification by a DOE/NNSA line management official initiating a procurement activity, incorporate CRDs into affected contracts as appropriate. (2) Assist originators of procurement requests who want to incorporate the provisions of 48 CFR Part 952.204-2, Security Requirements, and appropriate CRDs in new contracts. 16 DOE O 470.4B 7-21-2011 (3) Provide written notification to DOE/NNSA cognizant security offices in accordance with Appendix B, Section 2, of this Order when contractual changes impacting a company’s foreign ownership, control, or influence occur.

Section 11

m. DOE Cognizant Security Offices. Responsibilities of the designated DOE cognizant security offices applicable to each topical area are found in the appendices. n. Senior SECON Decision Team. (1) Under Secretaries; Deputy Under Secretary for Counterterrorism and Counterproliferation; Associate Under Secretary for Environment, Health, Safety and Security; Director, Intelligence and Counterintelligence; and Chief Security Officers. (2) Serve as members of the Senior SECON Decision Team. (a) Monitors the National Terrorism Advisory System (NTAS) Alerts and Bulletins and assesses the impact/potential impact to the Departmental SECON level, and to DOE/NNSA sites/facilities under their cognizance. (b) Monitors the SECON level to assess the impact/potential impact of ongoing threats or specific incidents to DOE personnel, operations, or sites/facilities. (c) Informs the Secretary, as appropriate, of any recommended changes to Departmental SECON level, to include the factors supporting the change. (d) Notifies the DOE Emergency Operations Center if the Departmental SECON level is changed. (3) Advises the Deputy Secretary on the appropriate SECON level. (4) Ensures dissemination of NTAS Alerts and Bulletins to the Heads of Field Elements and Headquarters Departmental Elements. 6. REFERENCES. The following general references apply to this Order. Additional references applicable to each topical area in the appendices and attachments are listed under that topic for ease of identification. Complete reference information and links to the most current official version of each document or successor documents are available through the S&S Policy Information Resource (PIR) tool at https://pir.doe.gov/. a. 42 U.S.C. Sections 2011 to 2296, Atomic Energy Act of 1954, as amended. Establishes authorities and programs related to atomic energy, including programs DOE O 470.4B 17 7-21-2011 for Federal control of the possession, use, and production of nuclear energy and SNM whether owned by the U.S. Government or others. b. 42 U.S.C. Sections 7101 to 7352, Department of Energy Organization Act, as amended. Establishes DOE and its basic authorities and responsibilities, including the responsibility of the Secretary of Energy for developing and promulgating DOE security policies. c. 10 CFR Part 824, Procedural Rules for the Assessment of Civil Penalties for Classified Information Security Violations. Establishes rules to assess a penalty against contractors for violation of a directive relating to the protection of classified information. d. 10 CFR Part 1016, Safeguarding of Restricted Data. Establishes requirements for granting facility security approval to an access permittee. e. 10 CFR Part 1045, Nuclear Classification and Declassification. Establishes the program for managing, identifying, generating, reviewing, and declassifying Restricted Data and Formerly Restricted Data, and the sanctions for violations of the procedures. f. 32 CFR Chapter XX, Information Security Oversight Office, National Archives and Records Administration. Establishes implementation requirements and procedures for classified national security information and the National Industrial Security Program. g. 48 CFR Chapter 9, Department of Energy Acquisition Regulation. Supplements 48 CFR Chapter 1, Federal Acquisition Regulation, and includes the security provisions and clauses to be used in DOE solicitations and contracts when a facility security clearance and/or access to classified information will be necessary for the performance of the contract.

Section 12

h. E.O. 12829, National Industrial Security Program, dated 01-26-93. Establishes the National Industrial Security Program to protect classified information released by Federal agencies to their contractors. i. E.O. 13526, Classified National Security Information, dated 12-29-09. Establishes the requirements for protection of classified information. j. DOE P 226.1B, Department of Energy Oversight Policy, dated 4-25-11. Establishes a Department-wide oversight process to protect the public, workers, environment, and national security assets effectively through continuous improvement. k. DOE O 226.1B, Implementation of Department of Energy Oversight Policy, dated 4-25-11. Implements the policy that establishes a Department-wide oversight process to protect the public, workers, environment, and national security assets. 18 DOE O 470.4B 7-21-2011 l. DOE O 227.1A, Independent Oversight Program, dated 12-21-15. Prescribes the requirements and responsibilities for the Department’s Independent Oversight Program to ensure the program is implemented in a transparent, efficient, and constructive manner to support the safe and secure accomplishment of DOE’s missions. m. DOE O 414.1D, AdminChg 1, Quality Assurance, dated 4-25-11, which ensures that the quality of DOE/NNSA products and services meets or exceeds the customers’ requirements and expectations. n. DOE O 475.2B, Identifying Classified Information, dated 10-3-14. Establishes the program to identify information classified under the Atomic Energy Act or E.O. 13526 so that it can be protected against unauthorized disclosures. o. DOE O 475.1, Counterintelligence Program, dated 12-10-04, establishes the Counterintelligence (CI) Program requirements and responsibilities for the Department of Energy (DOE), including the National Nuclear Security Administration (NNSA), pursuant to Executive Order 12333 in order to detect and deter insiders who engage in activities on behalf of a foreign intelligence service or international terrorist entity. p. DOE O 243.1B, admin. change 1, Records Management Program, dated 03-11- 13, which sets forth requirements and responsibilities for implementing and maintaining a cost-effective records management program throughout the Department of Energy. q. 36 CFR Chapter XII, Subchapter B, Records Management. Establishes requirements for the creation, maintenance, and disposition of Federal records and penalties for unlawful or accidental removal, alteration, or destruction of records. r. Presidential Policy Directive (PPD)-21, Critical Infrastructure Security and Resilience, dated 2-12-13, which establishes a national policy advancing a unified effort to strengthen and maintain secure, functioning, and resilient critical infrastructure. s. PPD-7, National Terrorism Advisory System, dated 01-26-11. t. E.O. 13587, Structural Reforms to Improve the Security of Classified Networks and the Responsible Sharing and Safeguarding of Classified Information, dated October 7, 2011. u. Presidential Memorandum, National Insider Threat Policy and Minimum Standards for Executive Branch Insider Threat Programs, dated November 12, 2012. v. DOE O 470.5, Insider Threat Program, dated June 2, 2014. DOE O 470.4B 19 7-21-2011 w. Public Law 115-232, The John S. McCain National Defense Authorization Act for Fiscal Year 2019 x. DOE O 142.3B: Unclassified Foreign National Access Program, dated January 15, 2021 y. DOE O 483.1B: DOE Cooperative Research and Development Agreements, dated December 20, 2016

Section 13

z. DOE P 485.1A: Foreign Engagements with DOE National Laboratories, dated December 13, 2019 aa. DOE O 486.1A: Foreign Government Sponsored or Affiliated Activities, dated September 4, 2020 7. DEFINITIONS. a. Cognizant security office means the office assigned responsibility for a given security program or function. Where DOE cognizant security office is stated, the reference is to a Federal activity. b. Officially Designated Federal Security Authority (ODFSA) are Federal employees who possess the appropriate knowledge and responsibilities for each situation to which they are assigned through delegation. Delegation of authority for these positions is originated according to direction from the accountable Program Secretarial Officer (or the Secretary or Deputy Secretary for Departmental Elements not organized under a Program Secretarial Office), who also provides direction for which of the ODFSA positions may be further delegated. Each delegation must be documented in writing. It may be included in other security plans or documentation approved by or according to direction from the accountable principal. Each delegator remains responsible for the delegatee’s acts or omissions in carrying out the purpose of the delegation. c. Officially Designated Security Authority (ODSA) are Federal or contractor employees that possess the appropriate knowledge and responsibilities for each situation to which they are assigned through delegation. Delegation of authority for these positions is originated according to direction from the accountable Program Secretarial Officer (or the Secretary or Deputy Secretary for Departmental Elements not organized under a Program Secretarial Office), who also provides direction for which of the ODSA positions may be further delegated. Each delegation must be documented in writing. It may be included in other security plans or documentation approved by or according to direction from the accountable principal. Each delegator remains responsible for the delegatee’s acts or omissions in carrying out the purpose of the delegation. d. Chief Security Officer is the designated Under Secretarial official responsible and accountable for the implementation of the safeguards and security programs for 20 DOE O 470.4B 7-21-2011 personnel, facilities, and sites within their respective Offices. The Under Secretaries will provide their respective Chief Security Officers the appropriate level of authorities and resources to manage and execute the significant safeguards and security responsibilities being entrusted to them. e. Security Committee is a forum comprised of Chief Security Officers from each of the three Under Secretarial organizations, and other Departmental Federal employee leadership that participate in developing recommendations regarding Department-wide security policies, facilitate active coordination of effective security strategies across the Department, and provide a forum for addressing cross-organizational issues and challenges. f. Definitions applicable to each topical area are found in the appendices and attachments. Definitions for terms used in a general S&S context are available through the Safeguards and Security Policy Information Resource (PIR) tool at https://pir.doe.gov/. 8. CONTACT. Questions concerning this Order should be addressed to the Office of Security Policy, Office of Environment, Health, Safety and Security at 301-903-4642. BY ORDER OF THE SECRETARY OF ENERGY: DAVID M. TURK Deputy Secretary

Section 14

https://pir.doe.gov/ DOE O 470.4B i 7-21-2011 TABLE OF CONTENTS Appendix A. Safeguards and Security Program Planning ................................................... A-1 Section 1. Safeguards and Security Program Planning .................................................... 1-1 1. Objective ................................................................................................................ 1-1 2. Purpose ................................................................................................................... 1-1 3. Definitions.............................................................................................................. 1-1 4. References .............................................................................................................. 1-2 5. Requirements ......................................................................................................... 1-2 Chapter I. Security Plans ............................................................................................... I-1 1. General .................................................................................................................... I-1 2. Security Plan .......................................................................................................... I-2 3. Assessments and Analyses ...................................................................................... I-2 4. Security Plan Components ...................................................................................... I-2 5. Reviews and Updates .............................................................................................. I-3 Chapter II. Security Conditions .................................................................................. II-1 1. General ...................................................................................................................II-1 2. SECON Determinations .........................................................................................II-1 3. SECON Levels .......................................................................................................II-2 4. SECON Response Planning ...................................................................................II-3 5. Performance Testing ..............................................................................................II-3 6. Protection Measures ...............................................................................................II-3 7. Coordination ..........................................................................................................II-3 8. References ..............................................................................................................II-4 Chapter III. Performance Assurance .........................................................................III-1 1. General ................................................................................................................. III-1 2. Applicability ........................................................................................................ III-1 3. Performance Assurance Planning ........................................................................ III-1 4. Test Schedules ..................................................................................................... III-2 5. Results Analysis and Documentation .................................................................. III-2 6. System Degradation ............................................................................................. III-2 7. Reviews and Updates ........................................................................................... III-2

Section 15

Section 2. Survey, Review, and Self- Assessment Programs ............................................ 2-1 1. Objective ................................................................................................................ 2-1 2. Purpose ................................................................................................................... 2-1 3. Definitions.............................................................................................................. 2-1 4. References .............................................................................................................. 2-2 5. Requirements ......................................................................................................... 2-2 6. Surveys ................................................................................................................... 2-3 7. Self-Assessments ................................................................................................... 2-5 ii DOE O 470.4B 7-21-2011 8. Reports and Ratings ............................................................................................... 2-5 9. Findings and Corrective Actions ........................................................................... 2-5 10. Documentation ..................................................................................................... 2-6 Appendix B. Safeguards and Security Program Management Operations..........................B-1 Section 1. Facility Clearances and Registration of Safeguards and Security Activities.......................................................................................................................... 1-1 1. Objective ................................................................................................................ 1-1 2. Purpose ................................................................................................................... 1-1 3. Facility Definition .................................................................................................. 1-1 4. References .............................................................................................................. 1-1 5. Requirements ......................................................................................................... 1-2 Chapter I. Facility Clearance Program ........................................................................ I-1 1. General .................................................................................................................... I-1 2. Eligibility Requirements ......................................................................................... I-3 Chapter II. Importance Ratings .................................................................................. II-1 1. Facility Importance Ratings ...................................................................................II-1 2. Upgrading and Downgrading a Facility’s Assigned Importance Rating ...............II-2 Chapter III. Facility Clearance Approval Requirements ........................................III-1 1. Issuance of FCLs.................................................................................................. III-1 2. Contractor Facilities ............................................................................................ III-1 3. Facility Clearances for OGAs .............................................................................. III-2 4. Records ............................................................................................................... III-2

Section 16

Chapter IV. Interim and Limited Facility Clearances ............................................. IV-1 1. Interim FCLs ........................................................................................................ IV-1 2. Limited FCLs ....................................................................................................... IV-1 Chapter V. Personnel Security Clearances and Exclusion Procedures Required in Connection with Contractor Facility Clearances................................................. V-1 1. Security Clearances Required in Connection with the FCL ................................. V-1 2. Exclusion Procedures ............................................................................................ V-1 3. Security Clearances Concurrent with the FCL ..................................................... V-1 Chapter VI. Facility Clearances Granted by Other Government Agencies ........... VI-1 1. Accepting OGA FCLs.......................................................................................... VI-1 2. OGA Verification Requests ................................................................................. VI-3 3. OGA Contractors with no DOE Contracts ........................................................... VI-3 DOE O 470.4B iii 7-21-2011 Chapter VII. Documentation and Registration of Facility Clearances and Related Security Activities ................................................................................................ VII-1 1. Documentation of FCLs ...................................................................................... VII-1 2. Registration of Security Activities ...................................................................... VII-1 3. Registering Strategic Partnership Projects (SPP) Activities ............................... VII-2 4. Exceptions to Registration in SSIMS ................................................................. VII-3 Chapter VIII. Suspensions ....................................................................................... VIII-1 1. Reasons for Suspension .................................................................................... VIII-1 2. Actions .............................................................................................................. VIII-1 3. Non-Compliance with Mitigation Plans ........................................................... VIII-1 4. Continuation of Contract Performance Under Foreign Government Ownership ....................................................................................................... VIII-2 5. Reinstatement of A Suspended FCL ................................................................. VIII-2 Chapter IX. Facility Clearance Termination and Close Out ................................... IX-1 1. Contract Closeout/Facility Clearance Termination ............................................. IX-1 2. Reactivation ......................................................................................................... IX-1 Section 2. Foreign Ownership, Control, or Influence Programs ..................................... 2-1 1. Objective ................................................................................................................ 2-1 2. Purpose ................................................................................................................... 2-1 3. Definition ............................................................................................................... 2-1 4. References .............................................................................................................. 2-1 5. Requirements ......................................................................................................... 2-2

Section 17

Chapter I. General FOCI Program Information ......................................................... I-1 1. General .................................................................................................................... I-1 2. Applicability ........................................................................................................... I-2 3. Electronic Submission/Processing Web Site .......................................................... I-2 Chapter II. FOCI Processing ....................................................................................... II-1 1. Determining the Requirements for a FOCI Determination ....................................II-1 2. Final FOCI Determinations....................................................................................II-1 3. Adjudication ...........................................................................................................II-1 4. Committee on Foreign Investment in the United States ........................................II-2 5. Contracting Officers ...............................................................................................II-2 Chapter III. Changes to FOCI Information ..............................................................III-1 1. FOCI Changes that Occur Following Submission of an SF 328 and before Contract Award ................................................................................................................. III-1 2. Updates ................................................................................................................ III-1 3. Annual Review and Certification ......................................................................... III-1 iv DOE O 470.4B 7-21-2011 Chapter IV. FOCI Mitigation ..................................................................................... IV-1 1. General ................................................................................................................. IV-1 2. Mitigation Action Plans ....................................................................................... IV-1 3. FOCI Mitigation Instruments ............................................................................... IV-1 4. Noncompliance with Mitigation Plans................................................................. IV-5 Section 3. Safeguards and Security Awareness ................................................................. 3-1 1. Objective ................................................................................................................ 3-1 2. Purpose ................................................................................................................... 3-1 3. Definition ............................................................................................................... 3-1 4. References .............................................................................................................. 3-1 5. Requirements ......................................................................................................... 3-2 6. Briefings ................................................................................................................. 3-3 7. Classified Information Nondisclosure Agreement (SF312) .................................. 3-7 8. Supplementary Awareness Activities .................................................................... 3-8

Section 18

Section 4. Control of Classified Visits ................................................................................ 4-1 1. Objective ................................................................................................................ 4-1 2. Purpose ................................................................................................................... 4-1 3. Definitions.............................................................................................................. 4-1 4. References .............................................................................................................. 4-1 5. Requirements ......................................................................................................... 4-2 6. Visits to DOE Facilities by Cleared U.S. Citizens Other than DOE Personnel ..... 4-3 7. Visits by Cleared DOE Personnel to Other DOE Facilities ................................... 4-5 8. Classified Visits to DOE Facilities by Non-U.S. Citizens ..................................... 4-6 9. Documentation ....................................................................................................... 4-7 Section 5. Safeguards and Security Training Program .................................................... 5-1 1. Objective ................................................................................................................ 5-1 2. Purpose ................................................................................................................... 5-1 3. Definition ............................................................................................................... 5-1 4. References .............................................................................................................. 5-1 5. Requirements ......................................................................................................... 5-1 Section 6. Restrictions on the Transfer of Security-Funded Technologies ..................... 6-1 1. Objective ................................................................................................................ 6-1 2. Purpose ................................................................................................................... 6-1 3. References .............................................................................................................. 6-1 4. Requirements ......................................................................................................... 6-1 Attachment 1. Contractor Requirements Document DOE O 470.4B, Safeguards and Security Program ......................................................................................................................1 1. Requirements .............................................................................................................1 2. Equivalencies and Exemptions ..................................................................................2 DOE O 470.4B v 7-21-2011 3. Definitions..................................................................................................................2 Attachment 2. Contractor Requirements Document Safeguards and Security Program Planning ....................................................................................................................................1 Section 1. Safeguards and Security Program Planning .................................................... 1-1

Section 19

1. Objective ................................................................................................................ 1-1 2. Purpose ................................................................................................................... 1-1 3. Definitions.............................................................................................................. 1-1 4. References .............................................................................................................. 1-2 5. Requirements ......................................................................................................... 1-2 Chapter I. Security Plans ............................................................................................... I-1 1. General .................................................................................................................... I-1 2. Security Plan .......................................................................................................... I-2 3. Assessments and Analyses ...................................................................................... I-2 4. Security Plan Components ...................................................................................... I-2 5. Reviews and Updates .............................................................................................. I-3 Chapter II. Security Conditions .................................................................................. II-1 1. General ...................................................................................................................II-1 2. SECON Determinations .........................................................................................II-1 3. SECON Levels .......................................................................................................II-2 4. SECON Response Planning ...................................................................................II-3 5. Performance Testing ..............................................................................................II-3 6. Protection Measures ...............................................................................................II-3 7 Coordination ...........................................................................................................II-3 8. References ..............................................................................................................II-4 Chapter III. Performance Assurance .........................................................................III-1 1. General ................................................................................................................. III-1 2. Applicability ........................................................................................................ III-1 3. Performance Assurance Planning ........................................................................ III-1 4. Test Schedules ..................................................................................................... III-2 5. Results Analysis and Documentation .................................................................. III-2 6. System Degradation ............................................................................................. III-2 7. Reviews and Updates ........................................................................................... III-2

Section 20

Section 2. Survey, Review and Self-Assessment Programs .............................................. 2-1 1. Objective ................................................................................................................ 2-1 2. Purpose ................................................................................................................... 2-1 3. Definitions.............................................................................................................. 2-1 4. References .............................................................................................................. 2-2 5. Requirements ......................................................................................................... 2-2 6. Surveys ................................................................................................................... 2-3 vi DOE O 470.4B 7-21-2011 7. Self-Assessments ................................................................................................... 2-3 8. Findings and Corrective Actions ........................................................................... 2-4 9. Documentation ....................................................................................................... 2-4 Attachment 3. Contractor Requirements Document Safeguards and Security Program Management Operations .........................................................................................................1 Section 1. Facility Clearances and Registration of Safeguards and Security Activities.......................................................................................................................... 1-1 1. Objective ................................................................................................................ 1-1 2. Purpose ................................................................................................................... 1-1 3. Facility Definition .................................................................................................. 1-1 4. References .............................................................................................................. 1-1 5. Requirements ......................................................................................................... 1-2 Chapter I. Facility Clearance Program ........................................................................ I-1 1. General .................................................................................................................... I-1 2. Eligibility Requirements ......................................................................................... I-2 Chapter II. Importance Ratings .................................................................................. II-1 1. Facility Importance Ratings ...................................................................................II-1 2. Upgrading and Downgrading a Facility’s Assigned Importance Rating ...............II-2 Chapter III. Facility Clearance Approval Requirements ........................................III-1 1. Issuance of FCLs.................................................................................................. III-1 2. Contractor Facilities ............................................................................................. III-1

Section 21

Chapter IV. Interim and Limited FCLS.................................................................... IV-1 1. Interim FCL ......................................................................................................... IV-1 2. Limited FCL......................................................................................................... IV-1 Chapter V. Personnel Security Clearances and Exclusion Procedures Required in Connection with Contractor FCLS ....................................................................... V-1 1. Security Clearances Required in Connection with the FCL ................................. V-1 2. Exclusion Procedures ............................................................................................ V-1 3. Security Clearances Concurrent with the FCL ..................................................... V-1 Chapter VI. Reporting Requirements........................................................................ VI-1 1. General ................................................................................................................. VI-1 2. Updates ................................................................................................................ VI-1 3. Other Reportable Changes ................................................................................... VI-4 Chapter VII. Suspensions .......................................................................................... VII-1 1. Reasons for Suspensions ..................................................................................... VII-1 DOE O 470.4B vii 7-21-2011 2. Actions ................................................................................................................ VII-1 3. Noncompliance with Mitigation Plans................................................................ VII-1 4. Continuation of Contract Performance under Foreign Government Ownership ......................................................................................................... VII-2 5. Reinstatement of a Suspended FCI ..................................................................... VII-2 Chapter VIII. Facility Clearance Termination and Close Out ............................. VIII-1 1. Contract Closeout/Facility Clearance Termination .......................................... VIII-1 2. Reactivation ...................................................................................................... VIII-2 Section 2. Foreign Ownership, Control, or Influence Program ...................................... 2-1 1. Objective ................................................................................................................ 2-1 2. Purpose ................................................................................................................... 2-1 3. Definition ............................................................................................................... 2-1 4. References .............................................................................................................. 2-1 5. Requirements ......................................................................................................... 2-2

Section 22

Chapter I. General FOCI Program Information ......................................................... I-1 1. General .................................................................................................................... I-1 2. Applicability ........................................................................................................... I-2 3. Electronic Submission/Processing Web Site .......................................................... I-2 4. Committee on Foreign Investment in the United States ......................................... I-2 Chapter II. FOCI Mitigation ....................................................................................... II-1 1. General ...................................................................................................................II-1 2. FOCI Mitigation Instruments .................................................................................II-1 3. Trustees, Proxy Holders, and Outside Directors ....................................................II-5 4. Government Security Committee ..........................................................................II-5 5. Technology Control Plan .......................................................................................II-6 Section 3. Safeguards and Security Awareness ................................................................. 3-1 1. Objective ................................................................................................................ 3-1 2. Purpose ................................................................................................................... 3-1 3. Definition ............................................................................................................... 3-1 4. References .............................................................................................................. 3-1 5. Requirements ......................................................................................................... 3-2 6. Briefings ................................................................................................................. 3-3 7. Classified Information Nondisclosure Agreement (SF 312) ................................. 3-7 8. Supplementary Awareness Activities .................................................................... 3-8 Section 4. Control of Classified Visits ................................................................................ 4-1 1. Objective ................................................................................................................ 4-1 2. Purpose ................................................................................................................... 4-1 3. Definitions.............................................................................................................. 4-1 viii DOE O 470.4B 7-21-2011 4. References .............................................................................................................. 4-1 5. Requirements ......................................................................................................... 4-2 6. Visits to DOE Facilities by Cleared U.S. Citizens Other than DOE Personnel ..... 4-3 7. Visits by Cleared DOE Personnel to Other DOE Facilities ................................... 4-5 8. Classified Visits to DOE Facilities by Non-U.S. Citizens ..................................... 4-5 9. Documentation ....................................................................................................... 4-7

Section 23

Section 5. Safeguards and Security Training Program .................................................... 5-1 1. Objective ................................................................................................................ 5-1 2. Purpose ................................................................................................................... 5-1 3. Definition ............................................................................................................... 5-1 4. References .............................................................................................................. 5-1 5. Requirements ......................................................................................................... 5-1 Section 6. Restrictions on the Transfer of Security-Funded Technologies ..................... 6-1 1. Objective ................................................................................................................ 6-1 2. Purpose ................................................................................................................... 6-1 3. References .............................................................................................................. 6-1 4. Requirements ......................................................................................................... 6-1 Attachment 4. Incidents of Security Concern .............................................................................1 1. Objective ....................................................................................................................1 2. Purpose .......................................................................................................................1 3. Definitions..................................................................................................................1 4. References ..................................................................................................................2 5. Roles and Responsibilities .........................................................................................5 Section 1. Incident Identification and Reporting Requirements ..................................... 1-1 1. General ................................................................................................................... 1-1 2. Incident Identification and Categorization ............................................................. 1-1 3. Preliminary Inquiry, Categorization, and Reporting .............................................. 1-4 4. Conduct of Inquiries .............................................................................................. 1-8 5. Inquiry Officials ..................................................................................................... 1-8 6. Incident Closure ..................................................................................................... 1-9 7. Administrative Actions ........................................................................................ 1-10 DOE O 470.4B Appendix A DRAFT XX-XX-XXXX A-1 (and A-2) APPENDIX A. SAFEGUARDS AND SECURITY PROGRAM PLANNING This appendix establishes the U.S. Department of Energy (DOE) requirements for developing facility and site security plans and for ensuring that plans are current and address the actual operating conditions at the covered location through performance assurance testing and a program of regular periodic surveys. Section 1 addresses planning activities. Section 2 covers activities to be implemented in connection with surveys.

Section 24

DOE O 470.4B Appendix A, Section 1 7-21-2011 1-1 SECTION 1. SAFEGUARDS AND SECURITY PROGRAM PLANNING 1. OBJECTIVE. To establish a safeguards and security (S&S) planning approach that will provide facilities and sites with a consistent method for identifying, developing and documenting sound risk mitigation strategies by identifying all critical S&S performance, technical, schedule, and cost elements. 2. PURPOSE. S&S planning activities are conducted to ensure that an S&S plan describing the assumptions and approved operating conditions necessary to protect national security and property assets, as well as the public, DOE employees, and contractor employees, from malevolent actions by adversaries is prepared for each facility and site and approved by an appropriate Federal authority. 3. DEFINITIONS. a. Facility. A facility consists of one or more security interests under a single security management responsibility or authority and a single facility security officer within a defined boundary that encompasses all the security assets at that location. A facility operates under a security plan that allows security management to maintain daily supervision of its operations, including day-to-day observations of the security program. b. Site. A site consists of one or more facilities operating under a centralized security management, including a site security officer with consolidated authority and responsibility for the facilities, and covered by a site security plan that may consolidate or replace, wholly or partially, individual facility plans. c. S&S Interest(s) and/or Assets. A general term for any Departmental resource or property that requires protection from malevolent acts. It includes but is not limited to Federal and contractor personnel; classified information and/or matter; sensitive compartmented information facilities; automated data processing centers; facilities storing, processing, and transmitting classified information and/or matter; vital equipment; special nuclear material (SNM); other nuclear materials; certain radiological chemical or biological materials; sensitive unclassified information; or other Departmental property. d. Essential Elements. Protection and assurance elements necessary for the overall success of the S&S program at a facility or site, the failure of any one of which would result in protection effectiveness being significantly reduced or which would require performance of other elements to be significantly better than expected in order to mitigate the failure. Essential elements can include but are not limited to equipment, procedures, and personnel. 4. REFERENCES. a. DOE P 470.1B, Safeguards and Security Program, dated 07-21-11. Appendix A, Section 1 DOE O 470.4B 1-2 7-21-2011 b. DOE O 470.3C, Design Basis Threat (DBT) Order, dated 11-23-16. c. 48 CFR Section 952.204-2, Security Requirements, and Section 952.204-73(c), Facility Clearance, d. E.O. 12977, Interagency Security Committee, dated 10-19-95. e. Interagency Security Committee (ISC) Standard. Risk Management Process, August 2013, 1st Edition. f. ISC, Design-Basis Threat Report. The Risk Management Process for Federal Facilities: An Interagency Security Committee Standard. February 2016, 10th Edition, 1st Revision. g. DOE-STD 1192-2010, Vulnerability Assessment Standard, dated 03-03-10. h. PDD 39, U.S. Policy on Counterterrorism, dated 06-21-95. i. PPD-7, National Terrorism Advisory System, dated 01-26-11.

Section 25

j. 32 CFR 117, National Industrial Security Program Operating Manual (NISPOM), dated 12-21-20. k. DOE O 150.1A, Continuity Programs, dated 03-31-14. l. PPD-21, Critical Infrastructure Security and Resilience, dated 02-12-13. m. E.O. 13587, Structural Reforms to Improve the Security of Classified Networks and the Responsible Sharing and Safeguarding of Classified Information, dated October 7, 2011. n. Presidential Memorandum, National Insider Threat Policy and Minimum Standards for Executive Branch Insider Threat Programs, dated November 12, 2012. o. DOE Order 470.5, Insider Threat Program, dated June 2, 2014. 5. REQUIREMENTS. DOE cognizant security offices, as designated by the Program Secretarial Office or, for NNSA, the Office of the Administrator through the Chief, Defense Nuclear Security, are responsible for ensuring that the following security planning activities are accomplished for facilities and sites under their cognizance. a. Ensure that planning activities support the Department’s Strategic Plan, the facility’s/site’s mission, forecasts of significant changes to facility/site operations, and current and projected operational and fiscal constraints. b. Review and approve contractor security plans, establishing a Federally approved authorization for site security operations. DOE O 470.4B Appendix A, Section 1 7-21-2011 1-3 (and 1-4) c. Ensure that Officially Designated Federal Security Authority (ODFSA) approval officials with authority for security plans explicitly accept any residual risk involved in operations under the requirements of approved security plans. d. Ensure that approved security plans continue to accurately describe site/facility S&S procedures and requirements. e. Ensure that site operations are conducted in compliance with approved security plans. f. Monitor progress on completion of implementation plans to ensure that approved actions are completed within the approved time frames. g. Ensure that assessments of protection effectiveness are conducted at a level of detail and rigor appropriate to the assets and security interests being protected and in accordance with national standards and DOE directives, and ensure that documentation of such analyses are maintained in support of the security plan. h. Provide assurances for safeguarding against loss, theft, diversion, unauthorized access, misuse, or sabotage of radioactive materials and radioactive sealed sources that could adversely affect national security and the health and safety of employees, the public, and the environment in accordance with DOE O 470.3B, Design Basis Threat (DBT) Order, DOE O 231.1B, Admin Chg 1, Environment, Safety and Health Reporting, and 10 CFR Part 835, Occupational Radiation Protection, Subpart M and Appendix E. i. Develop Security Condition (SECON) response plans that can be immediately implemented when there is a change in either the Department’s or a specific facility’s/site’s SECON status. DOE O 470.4B Appendix A, Section 1, Chapter I 7-21-2011 I-1 CHAPTER I. SECURITY PLANS 1. GENERAL. All facilities and sites under DOE cognizance must have a security plan that reflects the assets, security interests, approved S&S program implementation at that location and any residual risks associated with operation under the security plan. a. DOE site security managers, in consultation with contractor security managers, will determine and define the facilities under their cognizance and how or if a group of facilities will be consolidated into a site. This decision is made locally in order to facilitate the security management at each location.

Section 26

b. For those facilities that do not have security assets (e.g., classified information or matter, SNM, or other assets requiring a facility security clearance (FCL) in accordance with the Facility Clearance section in Appendix B), the security plan must be developed to address the protection of employees and Government- owned or leased property. c. For all U.S. Government owned or leased properties that do not have security assets (e.g., classified information or matter, SNM, or other assets requiring an FCL in accordance with the Facility Clearance section of this directive), but to which DOE Federal employees are assigned, the standards set forth by the ISC under E.O. 12977, Interagency Security Committee, must be used as the baseline for developing the security plan. d. While the ISC standards do not apply to contractor owned or leased facilities in which Federal employees are not routinely assigned, they should be used to establish the basis for planning for the protection of employees and Government- owned or leased property at contractor facilities that do not have security assets (e.g., classified information or matter, SNM, or other assets requiring an FCL in accordance with the Facility Clearance section of this directive). e. Facilities with security interests that require an FCL but that do not fall under the provisions of the Design Basis Threat (DBT) Order must develop security plans that, in addition to the protection of employees and property, address the protection of security interests at that location and meet the requirements in national-level policy and DOE directives for the protection of those interests. Non-possessing facilities must develop a security plan in sufficient detail to address how the contractor will fulfill its responsibilities (reporting requirements, management of employee clearances, etc.) under the Facility Clearance Program. f. For facilities under the cognizance of the Power Marketing Administrations, which do not fall under the provisions of the DBT but must meet specific critical infrastructure requirements, security plans will be developed under locally determined field element security levels and will be approved by the Chief Security Officer for each Power Marketing Administration. Appendix A, Section 1, Chapter I DOE O 470.4B I-2 7-21-2011 g. Facilities with security interests to which DBT performance standards or other requirements apply must develop security plans that comply with the requirements in the DBT and with the requirements in national-level policy and DOE directives for the protection of any security interests not covered by the DBT performance standards, and in addition to the protection of employees and property. 2. SECURITY PLAN. The security plan is the approved method for conducting security operations at a facility or site and therefore must reflect security operations at that facility or site at all times. The plan must describe in detail, either in its content or in combination with other explicitly referenced documents, all aspects of S&S operations occurring at the location and must include documentation of any deviations from national or DOE requirements. At those locations where management has determined that several facilities can be consolidated into a site, the site security plan may consolidate or replace individual facility security plans in whole or in part but must establish a unified approach to conducting site operations. Security plans must be based on in-depth analysis of considerations specific to the location and the assets and interests to be protected.

Section 27

3. ASSESSMENTS AND ANALYSES. Security plans must be supported by a sufficient analytical basis to establish that protection requirements will be met if the plan is completely and effectively executed. The analytical basis must include, as applicable, qualitative and quantitative simulations, performance test results, and/or expert analysis that reflect the complexity of facility/site operations and the consequences of loss or unauthorized access or use of the security assets present. When facility/site security assets include Category I (or credible rollup to Category I) SNM, vulnerability assessments (VAs), force-on-force system performance tests, other applicable performance tests, and expert analysis must be used in combination to establish the requirements for specific security measures and equipment, the effectiveness of the proposed security posture, and the requirements for improvements in the protection of Category I SNM documented in the approved security plan(s). Documentation of all such assessment activities should be retained on file to demonstrate how the security plan was developed and evaluated. However, these analyses need not be included or specifically referenced in the approved plan. 4. SECURITY PLAN COMPONENTS. All security plans must include the following: A listing and prioritization of the assets and security interests at the facility or site; a description of how the protection program is managed; and a description of how national and DOE S&S requirements are met, including any deviations from requirements; and As required, implementation plans for meeting changes in national or DOE policies or other changes (such as the addition or removal of security interests) that may require an extended time frame to implement because of financial or DOE O 470.4B Appendix A, Section 1, Chapter I 7-21-2011 I-3 (and I-4) other resource considerations, including an implementation schedule and planned contingency measures in case the requirements cannot be met as scheduled. Implementation plans and contingency measures may be included in the security plan by reference. DOE cognizant security offices must monitor contractors’ implementation plans to ensure that requirements are implemented without unnecessary delays. 5. REVIEWS AND UPDATES. Security plans must be reviewed as required to ensure that the plans are current and reflect the actual operating conditions at the covered location. Changes to approved security plans must be approved by the DOE cognizant security office, and the Federal office may require more frequent reviews or may direct a contractor to review the contractor’s plan at any time. Updates to security plans must be made whenever any of the following conditions apply: a. Changes in baseline security requirements in national-level or DOE policy; b. Changes in facility operators/contractors; c. Changes in assets or security interests; d. Changes in facilities included in a site security plan; e. Changes in the security posture of a facility or site; f. Planned changes to the security program at the facility or site; or g. Changes in operations at a facility or site that require modification to approved security measures. DOE O 470.4B Appendix A, Section 1, Chapter II 7-21-2011 II-1 CHAPTER II. SECURITY CONDITIONS

Section 28

1. GENERAL. DOE Security Condition (SECON) levels reflect a multitude of conditions that may adversely impact Departmental and/or facility and site security. SECONs may include terrorist activity, continuity conditions, environmental (fire, chemical, radiological, etc.) and/or severe weather conditions. The day-to-day DOE security readiness state is informed by the Department of Homeland Security’s (DHS) NTAS. NTAS alerts are established based on the analysis of a continuous and timely flow of integrated, all-source threat assessments and reporting provided to Executive Branch decision-makers. The SECON will be managed by a Senior SECON Decision Team, chaired by the Deputy Secretary, with membership comprised of the Under Secretaries, the Deputy Under Secretary for Counterterrorism and Counterproliferation, the Associate Under Secretary for Environment, Health, Safety and Security, the Director, Office of Intelligence and Counterintelligence and Chief Security Officers. This chapter details DOE requirements for responding to changes in the Departmental SECON levels and NTAS alerts. 2. SECON DETERMINATION. a. Departmental SECON Level. Department-wide SECON levels are established by the Deputy Secretary of Energy in consultation with the SECON Decision Team. Departmental SECON levels will be determined using existing threat, environmental, Continuity of Government Readiness Condition (COGCON) levels as specified in DOE O 150.1A, Continuity Programs, NTAS bulletins and alerts, and other program considerations for HQ and field activities, such as those in DOE O 151.1D Comprehensive Emergency Management System. Changes in the COGCON level 1 will require concurrent changes in the SECON level. Under conditions other than COGCON 1, any member of the Senior SECON Decision Team can activate the team by convening a meeting of the team by teleconference or face-to-face to evaluate the threat and determine the appropriate SECON for the Department or any component thereof. If the determination is made that the Departmental SECON level should change notification will be made through the Emergency Operations Center. b. Local SECON Levels. Local SECON levels may differ from the Departmental SECON level and are established by site/facility management with the concurrence of the cognizant Under Secretary or, in the case of DOE Headquarters, the Associate Under Secretary for Environment, Health, Safety, and Security. (1) Elevated. If the determination is made to elevate a site/facility SECON level from the Departmental SECON, site/facility management must immediately notify the cognizant Under Secretary and the DOE Operations Center, Office of Emergency Operations of the changed Appendix A, Section 1, Chapter II DOE O 470.4B II-2 7-21-2011 condition and keep the Operations Center informed of the status of the facility and the SECON response plan implementation. (2) Lowered. If the determination is made to lower a site/facility SECON level from the Departmental SECON, site/facility management must notify the DOE Watch Office and the appropriate Under Secretary. When approval has been obtained from the Deputy Secretary, on the recommendation of the Senior SECON Decision Team, the local SECON level may be lowered. Table 1. Relationship of Notification System Levels DOE SECON DHS NTAS COGCON Description of Threat SECON 5 Normal Conditions COGCON 4 Low risk of terrorist activity/attack SECON 4 Bulletin COGCON 3 Broad, non-specific threat

Section 29

SECON 3 Alert – elevated COGCON 2 Credible threat information, general timing, target / predictable threat SECON 2 Alert – Imminent COGCON 1 Credible, specific threat, impending / imminent SECON 1 Conditions have occurred that may affect a DOE facility/site or an attack has been initiated on the facility/site 3. SECON LEVELS. DOE has five SECON levels with SECON 5 being the lowest level of readiness and SECON 1 the highest. The correlation between DOE SECON levels, DHS NTAS, and COGCON are described in Table 1. If a site/facility obtains approval from the Deputy Secretary to implement SECON level 4 or SECON level 5, status updates are not required unless there is an occurrence that drives the SECON level back to SECON 3, or higher. The following are the SECON levels used by DOE to establish the current security readiness state: a. SECON 5, Low Condition. This condition is declared when there is a low risk of terrorist activity, continuity conditions, environmental, and/or severe weather conditions. SECON 5 exists when a minimal SECON concern exists but warrants only a routine security posture. b. SECON 4, Guarded Condition. This condition is declared when there is a general risk of terrorist activity, continuity conditions, environmental, and/or severe weather conditions. SECON 4 applies when there is a broad, non-specific threat of a possible event, the nature and extent of which are unpredictable. All measures selected for use under SECON 4 must be capable of being maintained indefinitely. c. SECON 3, Elevated Condition. SECON 3 is declared when there is a significant risk of terrorist activity, continuity conditions, environmental, and/or severe weather conditions. SECON 3 applies when an increased and more predictable threat against DOE facilities exists. The measures used in SECON 3 must be DOE O 470.4B Appendix A, Section 1, Chapter II 7-21-2011 II-3 capable of being maintained for lengthy periods without causing undue hardship, affecting operational capability, or aggravating relations with the local community. d. SECON 2, High Condition. SECON 2 is declared when there is a high risk of terrorist activity, continuity conditions, environmental, and/or severe weather conditions. This condition may apply when an incident occurs or intelligence is received indicating that some form of action against DOE personnel and facilities is imminent. Implementation of measures in this security condition for more than a short period will probably create hardship and affect the routine activities of the facility/site and its personnel. e. SECON 1, Severe Condition. This condition reflects a severe risk of terrorist activity, continuity conditions environmental, and/or severe weather conditions. SECON 1 applies in the immediate area where conditions have occurred that may affect a DOE facility/site or when an attack is initiated on the facility/site. Implementing SECON 1 will create hardship and affect the activities of the location and its personnel. Normally, this condition will be declared as a localized response. 4. SECON RESPONSE PLANNING. Contractor and Federal cognizant security offices must develop SECON response plans that can be immediately implemented when there is a change in either the Department’s or a specific facility/site’s SECON status. The SECON response plan should document the communication process implemented when a change in SECON level (increase or decrease) has been approved. Each facility or site must identify and document the specific measures that will most efficiently and effectively implement the required increases in readiness at each SECON level. Protection measures listed in Attachment 1 may be used to develop SECON response plans. SECON response plan should be part of the approved security plan.

Section 30

5. PERFORMANCE TESTING. The SECON implementation process must be evaluated. Sites/facilities must determine performance metrics that assure SECON protection measures can be immediately implemented. Performance measures should be captured in the SECON response plan and/or performance assurance plan. This is especially true if additional protective force (PF) patrols or barriers are included in the protection measures. 6. PROTECTION MEASURES. The SECON response plan should include site-specific protection measures such as those outlined in Attachment 1. Attachment 1 also includes the NTAS levels associated with each SECON level. When a new SECON level is implemented the SECON response plan should be reviewed and updated as appropriate. 7. COORDINATION. It is essential the SECON response plan, to include the barrier plan, be coordinated with protective force, emergency management, key operations managers, and other stakeholders. Not every measure in every SECON level needs to be Appendix A, Section 1, Chapter II DOE O 470.4B II-4 7-21-2011 implemented. The SECON response plan is a site/facility dependent, event driven security response tool and should be formulated to allow decision makers to use flexibility in their actions. The key is to have a plan that can be used in conjunction with emergency management tools such as Continuity of Operations and COGCON plans or severe weather/catastrophic event response plans. 8. REFERENCES. a. DOE O 151.1D, Comprehensive Emergency Management System, dated 08-11- 2016. b. DOE O 150.1A, Continuity Programs, dated 3-31-2014. c. U.S. Department of Homeland Security, National Terrorism Advisory System, https://www.dhs.gov/national-terrorism-advisory-system . d. U.S. Department of Homeland Security, Federal Emergency Management, National Continuity Policy Implementation Plan, August 2007. https://www.fema.gov/guidance-directives https://www.dhs.gov/national-terrorism-advisory-system https://www.fema.gov/guidance-directives DOE O 470.4B Appendix A, Section 1, Chapter II 7-21-2011 II-5 ATTACHMENT 1. SECON Suggested Protection Measures. NTAS Levels SECON Suggested Protection Measures Normal Conditions. Low risk of terrorist activity/attack. SECON 5. Low condition. 1. Normal operations. No special actions need be taken. 2. Conduct security operations in accordance with approved security plans. 3. Develop tools to communicate relevant information during each threat condition to DOE personnel and operations. 4. Ensure DOE personnel receive training on NTAS site/facility-specific protective measures. 5. Develop procedures and periodically train personnel to maintain ability to respond to a hostage or duress situation. 6. Determine the potential the effect on the site/facility and evacuation strategies from damage from nearby hazardous facilities, dams and other nearby sites/facilities and modify procedures and equipment, as necessary. 7. Assess site/facility for vulnerabilities and take measures to reduce them. Bulletin Broader or more general trends and current developments regarding threats of terrorism. SECON 4. Guarded condition. (A broad, non-specific threat of a possible event, the nature and extent of which are unpredictable.) 8. Warn affected DOE personnel. 9. Security plans should be implemented appropriate to the SECON level. 10. Normal operations can continue while security measures are adjusted to address the anticipated threat. 11. Review contingency response procedures to include additional

Section 31

strategies to address events involving an increased terrorist threat. 12. Review protective strategies, training, and deployment of responders and security force personnel to strengthen response to protect against a heightened threat of an attack. 13. Review emergency plan procedures for readiness and perform drills to ensure DOE personnel are familiar with emergency plan duties. 14. Review the readiness and adequacy of systems and processes to activate site emergency response orders, facilities, and equipment. 15. Review actions taken under “Elevated” and “High” Conditions and consider the need to revise. 16. Review and consider enhancements to, integrated response plans with local, State and Federal law enforcement agencies. Alert – Elevated. Credible terrorist threat, generally in both timing and target. SECON 3. Elevated Condition. Current SECON level. (There is an increased and more predictable threat against DOE facilities.) 17. Brief site/facility management, as well as security personnel on the changes to the threat environment. 18. Implement tools previously developed to warn affected DOE personnel and operations. 19. Notify affected DOE personnel to terminate some or all mission functions to allow the site or facility to respond to the threat. 20. Communicate change in threat condition to State representatives, local law enforcement agencies (LLEAs), and public officials (as appropriate) based on existing site procedures. 21. Security plans (COOP, security incident response plans, etc.) should be implemented appropriate to the SECON level. Appendix A, Section 1, Chapter II DOE O 470.4B II-6 7-21-2011 NTAS Levels SECON Suggested Protection Measures 22. Assess whether the threat requires further refinement of preplanned protective measures. 23. Assess the need for additional patrols and security posts and implement, if warranted. 24. Assess the need to deploy armed responders and security personnel in excess of those required by the approved security plan to strengthen response to the heightened threat of attack. Increase security force personnel, as necessary. 25. Verify the operation of communications with the Federal Bureau of Investigation, Federal Aviation Administration, Federal Emergency Management Agency, or other Federal agencies. 26. Review procedures for interface between security, operations, fire protection and emergency preparedness in light of the current threat and modify, as appropriate. 27. Establish communications with additional fire and emergency medical services departments in the region based on current threat information. 28. Verify communications between the site/facility and the LLEA in accordance with contingency response strategies. 29. Initiate the integrated response strategy for offsite support, including LLEA, State agencies, and Federal resources, as appropriate. 30. Verify physical protection system operability, to include backup power supplies. 31. Coordinate additional security resources with local and State agencies. 32. Increase defense-in-depth at access points through the addition of movable barriers (e.g., parked vehicle, portable barriers, etc.). 33. Allow only vehicles on essential operational duties to enter security areas. 34. Restrict access to the site/facility to essential personnel only. 35. Limit deliveries and hazardous material shipments and receipt. Consider additional limits on access to hazardous material storage. Consider additional limits on quantities of hazardous materials within security areas.

Section 32

36. Provide enhanced priority maintenance to activities related to fire- protection and security-related items. 37. Escort all vehicles delivering hazardous materials while inside the security area. Use armed security personnel, as appropriate. 38. Advise offsite fire and medical support to be prepared in the event of a hostile-action causing personnel injury. 39. Limit access to site/facility website to those areas providing pertinent situational information to DOE personnel. Ensure safeguards are in place to protect against a cyber-attack. 40. Terminate all non-essential construction and maintenance activities. 41. Heighten awareness of members of site/facility emergency response organization of advisory status and the potential need to respond. 42. Evaluate the current threat and consider shutting down site/facility operations. 43. Secure buildings, rooms, and storage not in regular use. 44. Increase security inspection of packages. 45. Check all deliveries at mailrooms and shipping/receiving departments. 46. Periodically test emergency communications with command locations. DOE O 470.4B Appendix A, Section 1, Chapter II 7-21-2011 II-7 NTAS Levels SECON Suggested Protection Measures 47. Monitor visitors. 48. Curtail special events and visitors. 49. Increase surveillance of critical locations. 50. Review actions taken under “High” Condition and consider the need to revise. 51. Record each action taken and decision reached. Report these to the Senior SECON Decision Team through the DOE Emergency Operations Center. 52. Conduct an after-action review to capture how the current security and contingency response plans addressed the threat and adjust the protective measures, as appropriate. Alert – Imminent. (Credible, specific and impending terrorist threat.) SECON 2. High condition. (A high risk of terrorist activity, continuity conditions, environmental, and/or severe weather conditions.) 53. Suspend all Real ID Act 2005 non-compliant licenses and identification that has secondary means of gaining entry until the implementation of a lower SECON. 54. Warn affected DOE personnel and keep personnel informed. 55. Implement security plans appropriate to the SECON level. 56. Coordinate with appropriate Federal, State and local response agencies to ascertain their ability to carry out rapid response of available assets. 57. Maintain open communications with LLEA, State and Federal agencies to coordinate offsite emergency response actions and support. If the site/facility is completely evacuated, reestablish communications, as soon as practical from offsite. 58. Activate and staff emergency response facilities with key members of the emergency response organization. 59. Evacuate site/facility personnel, as appropriate. Ensure retention of essential personnel. 60. Activate staffing plans to ensure safe operation of the site/facility with minimum personnel necessary to enable effective response to an event. 61. If the site/facility does not have an emergency operations facility offsite, establish and staff an alternative or backup response facility at an offsite location and staff with key members of the emergency response organization. 62. Declare at least a notification of alert in accordance with emergency plan. 63. Request offsite support, including LLEA, State agencies, and Federal resources, as appropriate. 64. As far as practical, initiate shut down of site/facility systems processing bulk quantities of hazardous materials and maintain the site/facility in a stable configuration.

Section 33

65. Stop all shipments of hazardous materials. 66. Inspect all incoming packages at a centralized receiving point. 67. Establish random security checkpoints. 68. Cancel special events. 69. Perform a search on all entering vehicles and conduct random exiting vehicle searches. 70. Limit entry and exit to a single point. Appendix A, Section 1, Chapter II DOE O 470.4B II-8 7-21-2011 NTAS Levels SECON Suggested Protection Measures 71. Conduct frequent inspections of exterior of buildings and parking areas for suspicious items and activity. 72. Record each action taken and decision reached. Report these to the Senior SECON Decision Team through the Emergency Operations Center. 73. Conduct an after-action review to capture how the current security and contingency response plans addressed the threat and adjust the protective measures, as appropriate. SECON 1. Severe Condition. (Severe condition exists when a malevolent act or terrorist incident occurs.) 74. Warn affected DOE personnel and keep personnel informed. 75. All shipments are stopped. 76. Implement security plans appropriate to the SECON level. 77. Coordinate as appropriate with Federal, State and local officials. 78. Record each action taken and decision reached. Report these to the Senior SECON Decision Team through the DOE Emergency Operations Center. 79. Conduct an after-action review to capture how the current security and contingency response plans addressed the threat and adjust the protective measures, as appropriate. DOE O 470.4B Appendix A, Section 1, Chapter III 7-21-2011 III-1 CHAPTER III. PERFORMANCE ASSURANCE 1. GENERAL. An acceptable level of performance must be established and maintained to ensure that all elements of a facility/site protection program are workable and function as designed and in accordance with the overall protection goals established by local facility/site management. A performance assurance program must be developed that identifies the essential elements of the protection program and establishes monitoring and testing activities with sufficient rigor to ensure that the program elements are at all times operational, functioning as intended, and interacting in such a way as to identify and preclude the occurrence of adverse activity before security is irreversibly compromised. The intent of the performance assurance program is not to duplicate monitoring and testing activities conducted under ongoing quality assurance and S&S operations, but to include them in a comprehensive approach to assuring system effectiveness. Implementation activities and schedules for performance assurance plans must be included in the facility or site security plan. 2. APPLICABILITY. All facilities/sites with assets requiring a facility security clearance must conduct performance assurance activities. These activities must be tailored to the assets at the location and the elements that compose the total system in place at the location. At all locations, testing will include at a minimum the following: a. Operability tests to confirm, without any indication of effectiveness, that a system element or total system is operating as expected; and b. Effectiveness tests to provide assurance that essential elements of the system are working as expected, separately or in coordination, to meet protection program objectives.

Section 34

3. PERFORMANCE ASSURANCE PLANNING. Facilities and sites must implement and maintain a program that ensures that essential elements used to protect DOE S&S interests meet established requirements for reliability, operability, readiness, and performance prior to and during operational use. The assurance plan must: a. Encompass all S&S topical areas relating to Program Management Operations, Physical Protection, Protective Force, Information Security, Personnel Security, and Materials Control and Accountability that are relevant to protection of assets at the facility/site; b. Identify the essential elements relevant to protection of assets at the facility/site; c. Describe how essential elements relevant to the protection of assets were determined; d. Describe how each essential element and the facility/site security program as a whole will be tested, including type of test, evaluation criteria (test objectives and performance criteria that define both success and failure), frequency, and number of tests; Appendix A, Section 1, Chapter III DOE O 470.4B III-2 7-21-2011 e. Establish the testing schedule for essential elements and note whether any testing requirements established in other applicable DOE directives are to be integrated with this schedule; f. Describe the process for managing, tracking, and integrating results and addressing any deficiencies identified during the tests; and g. Describe actions that must be initiated in the event of a failure of any essential element or the program as a whole. 4. TEST SCHEDULES. Essential elements must be periodically tested to verify their continued functionality, operability, effectiveness, and/or performance. Testing frequency may be based as applicable on manufacturer’s recommendations, consensus standards, facility-/site-specific conditions and operational needs, or other criteria that will ensure program effectiveness. Testing of elements that are not prone to failure and that are not subject to compromise without noticeable tampering, such as walls and fences, is not required as long as it can be documented that tampering with such elements would be detected in time to prevent compromise of overall protection. 5. RESULTS ANALYSIS AND DOCUMENTATION. Each test must be documented in a test report that includes a narrative description of the testing activity and an analysis of test results. Issues requiring corrective action must be documented and tracked until resolved. When unsatisfactory results of a test indicate that national security and/or the health and safety of facility/site employees or the public is jeopardized, immediate compensatory measures must be taken until the issue is resolved and normal reporting procedures must be followed. 6. SYSTEM DEGRADATION. When an essential element is under repair or is in an inoperative or ineffective state, the overall S&S program must be considered to be in a degraded mode until testing confirms that all applicable elements have returned to full operability. The facility or site must implement compensatory measures during such degraded modes adequate to ensure that protection of assets is maintained. 7. REVIEWS AND UPDATES. Performance assurance plans must be reviewed and updated when essential elements are affected due to: a. Changes in facility/site mission, programmatic activities, or S&S interests and/or assets;

Section 35

b. Changes in the operation or physical configuration of a facility or site, such as a building addition; new work processes or systems; construction of fences, roads, buildings, etc.; demolition of buildings; or reconfigurations of fences, roads, etc.; c. Completion of S&S upgrades or downgrades; d. Changes in protection strategy, risk or vulnerability analysis, protective force deployment, or other significant revisions to the applicable security plan; or DOE O 470.4B Appendix A, Section 1, Chapter III 7-21-2011 III-3 (and III-4) e. Changes in S&S policies, including DOE Order 470.3B, Design Basis Threat (DBT) Order. DOE O 470.4B Appendix A, Section 2 7-21-2011 2-1 SECTION 2. SURVEY, REVIEW, AND SELF-ASSESSMENT PROGRAMS 1. OBJECTIVE. a. Provide assurance to the Secretary, Departmental Elements, and other government agencies that S&S interests and activities are protected at the required levels. b. Provide DOE line management with the information necessary to make informed decisions regarding the allocation of resources, acceptance of risk, and mitigation of S&S vulnerabilities. 2. PURPOSE. Surveys, self-assessments, and review programs are conducted to ensure that S&S systems and processes at facilities/sites are operating in compliance with Departmental and national-level policies, requirements, and standards for the protection of security assets and interests. These programs provide the means for timely identification and correction of deficiencies and noncompliant conditions to prevent adverse events, and validate the effectiveness of corrective actions implemented to address identified deficiencies. 3. DEFINITIONS. a. Safeguards and Security Survey. An integrated performance and compliance based evaluation of all applicable topics to determine the overall status of the S&S program at a facility or site and to ensure that S&S systems and processes at the location are operating in compliance with Departmental and national-level policies, requirements, and standards. Surveys are conducted or supervised by Federal security personnel. b. Initial Survey. A comprehensive review of the security status at a facility that is a candidate for an FCL, conducted to determine whether the facility in question meets established standards for the protection of the security interests and activities to be covered by the FCL. c. Periodic Survey. A survey conducted for all cleared facilities in accordance with established schedules that covers all applicable topics to meet the objectives of the S&S survey. d. Termination Survey. A survey of a cleared facility conducted to verify the termination of Departmental activities and the appropriate disposition of S&S interests at that facility. The termination survey confirms that all S&S activities have been terminated or awarded to another contractor, that access authorizations have been properly terminated or dispositioned, and that no DOE property, classified information or matter, and nuclear and other hazardous material presenting a potential radiological or toxicological sabotage threat remains. e. Self-Assessment. An internal integrated evaluation of all applicable S&S topical areas at a contractor facility or site, conducted by contractor security personnel at Appendix A, Section 2 DOE O 470.4B 2-2 7-21-2011 intervals consistent with risk management principles, to determine the overall status of the S&S program at that location and verify that S&S objectives are met. The DOE cognizant security office may direct a specific self-assessment interval and may direct that self-assessment reports be provided to DOE.

Section 36

f. Finding. A factual statement of identified issues and deficiencies (failure to meet a documented legal, regulatory, performance, compliance, or other applicable requirement) in the S&S program at a facility, resulting from an inspection, survey, self-assessment, or any other S&S review activity. 4. REFERENCES. a. E.O. 13526, Classified National Security Information, dated 12-29-09. b. E.O. 12829, National Industrial Security Program, dated 01-26-93. c. Department of Defense (DoD) 5220.22-R, Industrial Security Regulation, dated December 1985 d. 32 CFR 117, National Industrial Security Program Operating Manual (NISPOM), dated 12-21-20 e. DoD Defense Counterintelligence and Security Agency (DCSA) Industrial Security Letters (ISLs), available at https://www.dcsa.mil/mc/ctp/tools/ (Note: ISLs do not automatically impose requirements on DOE, but may contain useful clarifications of existing NISPOM provisions.). f. 10 CFR Part 1016, Safeguarding of Restricted Data, 01-01-16 Edition g. 10 CFR Part 824, Procedural Rules for the Assessment of Civil Penalties for Classified Information Security Violations, dated 02-23-2005 h. 32 CFR Part 2001, Classified National Security Information, dated 10-13-99 i. 48 CFR Chapter 9, Department of Energy Acquisition Regulation, dated 07-22-09 j. DOE P 226.1B, Department of Energy Oversight Policy, dated 4-25-11. k. DOE O 226.1B, Implementation of Department of Energy Oversight Policy, dated 4-25-11. l. DOE O 475.1, Counterintelligence Program, dated 12-10-04. m. DOE-STD-1217-2016, The Safeguards and Security Survey and Self-Assessment Planning, Conduct, and Reporting Technical Standard, dated February 2016. 5. REQUIREMENTS. DOE cognizant security offices, as designated by the Program Secretarial Office, or for NNSA, the Office of the Administrator through the Chief, https://www.dcsa.mil/mc/ctp/tools/ DOE O 470.4B Appendix A, Section 2 7-21-2011 2-3 Defense Nuclear Security, are responsible for ensuring that the following activities are accomplished for the surveys and self-assessments program for facilities and sites under their cognizance and for ensuring that contractors under their cognizance accomplish their responsibilities under this program at contractor facilities. Procedures applicable to the surveys and self-assessments program must be documented in facility or site security plans. Identified interfaces and integration with the contractor assurance system must also be documented in facility or site security plans. a. Establish and maintain a schedule for conducting surveys in accordance with applicable national and DOE policy standards. b. Ensure that surveys are conducted as scheduled and/or as required for security activities such as the granting or termination of an FCL. c. Ensure that contractors issued an FCL review their security programs on a continuing basis and conduct formal self-assessments at intervals consistent with risk management principles. d. Ensure that contractors under their cognizance prepare formal reports of self- assessments and related findings and corrective actions. e. Advise contractors under their cognizance of the appropriateness of the self- assessment and its expected coverage and use. f. Provide an evaluation of contractor self-assessment processes and recommend changes as necessary to ensure that DOE objectives are met.

Section 37

g. Ensure that both surveys and contractor self-assessments evaluate all S&S topics relating to Program Management Operations, Physical Protection, Protective Force, Information Security, Personnel Security, and Materials Control and Accountability that are applicable at the facility/site being surveyed. h. Ensure that all findings identified during surveys and self-assessments are tracked until the issues are resolved. i. Ensure that the results of surveys are reported in the DOE Safeguards and Security Information Management System (SSIMS). j. Ensure that corrective actions for issues identified in surveys and self-assessments are implemented in a timely and effective manner, and validate the effectiveness of corrective actions to prevent recurrence of the issues. 6. SURVEYS. Surveys are conducted to confirm that a Federal or contractor facility meets all security requirements appropriate to the activities conducted at that facility, to inform Federal line management of the effectiveness of the facility security program, to identify any issues or concerns with the security program so that these can be addressed and Appendix A, Section 2 DOE O 470.4B 2-4 7-21-2011 corrected, and to allow both contractor and Federal managers to manage risk in an informed and rational manner. a. Initial Surveys. A favorable survey is required as one of the conditions for granting a facility security clearance. This initial survey must be completed not more than 6 months prior to the granting of the FCL if the facility will possess classified information or matter or SNM, or will have a facility importance rating of “PP”. b. Periodic Surveys. Periodic surveys must be conducted for all cleared facilities to ensure that S&S measures employed by the facility are adequate for the protection of security assets and interests. The National Industrial Security Program specifies that surveys of contractor facilities will be conducted not more often than once every 12 months unless special circumstances exist. 32 CFR Part 2001.60 establishes a requirement for an annual survey specifically for the assessment of activities related to classified information. At the discretion of the DOE cognizant security office, other topics may be combined with this requirement to meet the periodic survey requirement. For facilities which do not have classified interests or SNM, the frequency of the periodic survey may be established consistent with risk management principles and documented in the applicable security plan with a description of the reasons for the schedule (e.g., good performance on past surveys and self-assessments, regular satisfactory performance assurance testing, non-possessing facilities, etc.). c. Termination Surveys. When a contract for which an FCL has been granted is terminated or otherwise ended (e.g., suspended), a termination survey must be conducted to verify the termination of security activities and the appropriate disposition of S&S interests. Examples of survey activities include: the appropriate disposition, destruction, or return of classified information or matter, SNM, hazardous material, or property; the signing of a certificate of possession if classified is to be retained by the contractor for the allowable period; security badge retrieval; verification of debriefings or verification of the transfer of access authorizations to other DOE interests. Surveys must be conducted onsite at facilities possessing Top Secret classified information or matter, Restricted Data, Sensitive Compartmented Information or special access program information or matter, or SNM. For all other facilities, termination surveys may be conducted either onsite or through any other means established by the cognizant security office.

Section 38

7. SELF-ASSESSMENTS. Self-assessments are conducted by contractors at their facilities to ensure that at any point the facility is in compliance with all security requirements appropriate to the activities, information, and conditions at the location. Assessments are conducted at intervals consistent with risk management principles and/or as directed by the DOE cognizant security office, and reports are provided to that office. Federal facilities are required to conduct self-assessments under this Order; however, if a survey DOE O 470.4B Appendix A, Section 2 7-21-2011 2-5 was conducted, it may be used in lieu of a self-assessment as long as it satisfies the requirements of a self-assessment under this Order. 8. REPORTS AND RATINGS. For each rated area, the survey report must contain a description of each element reviewed, how the review was conducted including any samples and tests used in the evaluation, a summary of the observations made, and an analysis of the results that support the ratings awarded. Ratings must be based upon the effectiveness and adequacy of the security programs at the subject facility. The ratings listed below must be used for all surveys, self-assessments, and reviews. When a topic does not apply at a given facility, or if a topic is not rated, the survey report must contain this information. All ratings must be supported and documented with the rating justification and rationale. a. Satisfactory. The element being evaluated meets protection objectives or provides reasonable assurance that protection objectives are being met. b. Marginal. The element being evaluated partially meets protection objectives or provides questionable assurance that protection objectives are being met. c. Unsatisfactory. The element being evaluated does not meet protection objectives or does not provide adequate assurance that protection objectives are being met. 9. FINDINGS AND CORRECTIVE ACTIONS. a. All open S&S findings from any source (previous surveys and assessments; inspections, reviews, and reports by other organizations such as the Government Accountability Office or the Office of the Inspector General; etc.) must be reviewed during surveys to validate the status of corrective actions and to evaluate the impact on the current operation of the facility’s S&S program. Findings closed during the survey period must be reviewed for sustainability of the closing action. b. Findings from all surveys must be documented in the associated report and entered into SSIMS in accordance with guidelines issued by the SSIMS database manager. Findings must be tracked until closed and monitored on an established schedule to ensure that corrective action plans to address the issue are being implemented in a timely and effective manner. Trending assessment activities based on findings must be conducted to establish if findings represent an isolated issue or a systemic problem with a specific topical element or with the S&S program as a whole. c. Corrective action plans must be developed for all open survey findings. For all identified findings, corrective actions must be implemented in a timely and effective manner. The effectiveness of corrective actions must be validated during subsequent surveys to ensure that the action taken has been sufficient to prevent recurrence of the issue that resulted in the finding. Corrective actions must be reported in SSIMS and the current status of the action must be reported in SSIMS until the associated finding is closed.

Section 39

Appendix A, Section 2 DOE O 470.4B 2-6 7-21-2011 10. DOCUMENTATION. Reports of surveys, self-assessments, and review activities must be maintained in accordance with DOE Administrative Records Schedule 18, paragraphs 9 and 10. DOE O 470.4B Appendix B 7-21-2011 B-1 (and B-2) APPENDIX B. SAFEGUARDS AND SECURITY PROGRAM MANAGEMENT OPERATIONS This appendix establishes the U.S. Department of Energy (DOE) requirements for conducting management activities connected with the operation of cleared facilities within the DOE complex. Section 1 addresses obtaining a facility clearance (FCL) and establishing the safeguards and security (S&S) activities connected with that facility. Section 2 covers the foreign ownership, control, or influence determinations that are necessary to establish and maintain a facility clearance. Section 3 covers security awareness activities, including required personnel briefings. Section 4 addresses the handling of classified visits to and from DOE facilities, including foreign classified visits. Section 5 deals with S&S training to be provided for employees at cleared facilities. Section 6 covers restrictions imposed on the transfer of security funded technologies outside the United States. DOE O 470.4B Appendix B, Section 1 7-21-2011 1-1 SECTION 1. FACILITY CLEARANCES AND REGISTRATION OF SAFEGUARDS AND SECURITY ACTIVITIES 1. OBJECTIVE. To ensure that DOE, DOE contractor, and other (Federal) government agency (OGA) facilities and their contractors engaged in DOE activities are eligible for access to, and meet the requirements to possess and secure, classified information or matter or special nuclear material (SNM); and, as applicable, to protect other assets and conduct other security activities on behalf of DOE. 2. PURPOSE. The FCL program regulates DOE approval of a Federal or contractor facility’s eligibility to access, receive, generate, reproduce, store, transmit, or destroy classified information or matter; SNM; other hazardous material presenting a potential radiological, chemical, or biological sabotage threat; and/or DOE property of significant monetary value, exclusive of facilities and land values (hereinafter referred to as security assets and activities). 32 CFR 117, National Industrial Security Program Operating Manual (NISPOM), serves as a national standard to establish the baseline requirements for contractor FCLs when contractors are engaged in activities requiring the protection of national security information classified at the Confidential, Secret, or Top Secret level. The NISPOM requirements are incorporated in this directive and are supplemented with requirements for the protection of DOE-specific assets, Restricted Data, SNM, and other security activities not covered by the NISPOM. 3. FACILITY DEFINITION. For purposes of granting and registering an FCL code under this program, an entity (contractor or Federal) and its classified or high value security activities will be registered with one FCL code if the following criteria are met: a. A centrally directed security program is maintained that covers all security activities (i.e., under the same name, single mailing address, single security plan applicable at all locations, and all security matters under single management control). b. The distance between the security activities is such that the contractor or Federal entity is able to maintain daily supervision of its operations, including day-to-day observations of the security program. 4. REFERENCES.

Section 40

a. E.O. 12829, National Industrial Security Program, dated 01-26-93. b. E.O. 13549, Classified National Security Information Program for State, Local, Tribal, and Private Sector Entities, dated 8-18-10. c. 42 U.S.C. Sections 2011 through 2296, Atomic Energy Act of 1954. d. 32 CFR Part 2001, Classified National Security Information, dated 10-13-99 e. 32 CFR Part 2004, National Industrial Security Program, dated 05-07-2018 Appendix B, Section 1 DOE O 470.4B 1-2 7-21-2011 f. 10 CFR Part 1016, Safeguarding of Restricted Data, 01-01-16 Edition g. 10 CFR Part 1045, Nuclear Classification and Declassification, dated January 2009 h. DoD 5220.22-R, Industrial Security Regulation, dated December 1985 i. 32 CFR 117, National Industrial Security Program Operating Manual (NISPOM), dated 12-21-20 j. DCSA ISLs, available at https://www.dcsa.mil/mc/ctp/tools/ (Note: ISLs do not automatically impose requirements on DOE, but may contain useful clarifications of existing NISPOM provisions.) k. Directive-Type Memoranda (DTM) issued by the Office of the Under Secretary of Defense, available at https://www.esd.whs.mil/DD/DoD-Issuances/DTM/. Note: DTMs, which may be issued periodically on a variety of topics, do not automatically impose requirements on DOE, but may contain useful information applicable to existing NISP programs. l. 10 U.S.C. Section 2536, Award of certain contracts to entities controlled by a foreign government: prohibition, dated 09-23-1996 m. 48 CFR Chapter 9, Department of Energy Acquisition Regulation, dated 12-29-10 n. DOE O 475.2B, Identifying Classified Information, dated 10-3-14 o. Public Law 115-232, The John S. McCain National Defense Authorization Act for Fiscal Year 2019 p. DOE O 142.3B: Unclassified Foreign National Access Program, dated January 15, 2021 q. DOE O 483.1B: DOE Cooperative Research and Development Agreements, dated December 20, 2016 r. DOE P 485.1A: Foreign Engagements with DOE National Laboratories, dated December 13, 2019 s. DOE O 486.1A: Foreign Government Sponsored or Affiliated Activities, dated September 4, 2020 5. REQUIREMENTS. DOE cognizant security offices, as designated by the Program Secretarial Office, or for NNSA, the Office of the Administrator through the Chief, Defense Nuclear Security, are responsible for ensuring that the following activities are accomplished for the FCL program for facilities and sites under their cognizance and for ensuring that contractors under their cognizance accomplish their responsibilities under https://www.dcsa.mil/mc/ctp/tools/ https://www.esd.whs.mil/DD/DoD-Issuances/DTM/ DOE O 470.4B Appendix B, Section 1 7-21-2011 1-3 this program at contractor facilities. Procedures applicable to the FCL program must be documented in facility or site security plans. a. Establish and maintain FCLs by registering, updating, suspending, reinstating, and terminating FCLs and related security activities under their cognizance in accordance with the requirements contained in this Order. b. Ensure that organizations seeking FCLs meet all the eligibility requirements applicable to the type of organization prior to being processed for an FCL. c. Ensure that all items required by the DEAR as the basis for approval of a contractor FCL have been completed and favorably adjudicated/approved prior to granting the final FCL. d. Ensure that accurate facility importance ratings are assigned and that ratings are updated as necessary to reflect changes in security activities.

Section 41

e. Establish and apply procedures to ensure that coordination is accomplished between the FCL and Foreign Ownership, Control, or Influence (FOCI) programs for all contractor FCLs. f. Determine on a case-by-case basis the necessity for branch offices of a multiple- facility organization to be cleared, based upon the performance of security activities. g. Determine the necessity for the corporate tier parent in a parent-subsidiary relationship to be excluded or cleared as a possessing or non-possessing facility. h. Ensure that prime contractors have appropriately implemented provisions pertaining to subcontractors and that all subcontractors are processed for FCLs when required and terminated or transferred to the cognizance of a new management and operations contractor as appropriate. i. Ensure that all key management personnel (KMP) are properly identified, processed for, and granted access authorizations at the appropriate level or are formally excluded from access, duties, and influence that would otherwise cause them to be identified as KMP prior to granting a final FCL. j. Ensure that procedures are in place to verify changes in an organization’s KMP as they occur and that access authorizations are immediately processed for new KMP. k. Receive and evaluate contractor reports of changes that may impact the FCL, and take any necessary action to suspend or terminate the FCL if such action is warranted. Appendix B, Section 1 DOE O 470.4B 1-4 7-21-2011 l. Notify the appropriate DOE contracting officer, the contractor, and/or the Federal entity applying for or holding an FCL in writing of the level of FCL granted. m. In conjunction with the responsible surveying offices, as identified by DOE Federal management, ensure that the S&S Information Management System (SSIMS) database accurately reflects established facilities, security assets, and activities under their jurisdiction; ensure that updates and changes to such information are recorded in SSIMS immediately; and ensure that accurate forms are submitted for this purpose. n. When a contract ends and/or an FCL is no longer necessary, complete a termination survey and ensure that appropriate forms are submitted and SSIMS is updated to enact the termination. o. Ensure that upon termination of a contract, all security clearances (access authorizations) connected to the FCL are terminated and all DOE property; classified information; and/or nuclear and other hazardous material presenting a potential radiological, chemical or biological sabotage threat is appropriately reallocated, disposed of, destroyed, or returned to an appropriate DOE or cleared DOE contractor organization. DOE O 470.4B Appendix B, Section 1, Chapter I 7-21-2011 I-1 CHAPTER I. FACILITY CLEARANCE PROGRAM 1. GENERAL. a. Facilities Eligible for the FCL Program. (1) An industrial, educational, commercial, or other contractor entity will require an FCL if the terms of a contract awarded under the DEAR include the security activities described in paragraph 2 of Section 1 above. A contractor requiring an FCL must be sponsored by: (a) a Government Contracting Activity (GCA; i.e., a contracting officer); or (b) a cleared contractor acting as the prime contractor for an uncleared subcontractor. A contractor cannot sponsor itself for an FCL.

Section 42

(2) OGAs may be registered as having a DOE FCL when a mission or programmatic need for such an action has been established by DOE line management. Verification of the clearance and security capability of an OGA must be based on a written statement of security assurance from that agency submitted to the DOE cognizant security office. State, local, tribal, and other similar governmental authorities do not have authority to self- certify clearance and security capability for handling classified information; therefore, they must not be registered as OGAs. These entities must be handled in accordance with E.O. 13549, Classified National Security Information Program for State, Local, Tribal, and Private Sector Entities, and its implementing directives. DOE Federal facilities are registered with a facility code under the FCL program and are subject to survey requirements. b. In accordance with the DEAR, section 952.204-2(l), FCLs are required for subcontractors requiring personnel security clearances. The prime contractor is responsible for implementation of the provisions of 32 CFR 117, National Industrial Security Program Operating Manual (NISPOM) (Subpart 117.17, “Subcontracting”), all DOE security requirements for their subcontractors, and for termination of the subcontracts upon completion of activities. Prime contractors must ensure that all subcontracts are terminated if the prime contract is terminated, or for management and operations subcontracts, transferred to the cognizance of the new management and operations contractor as appropriate. c. All company officials who occupy positions with the authority to affect the organization’s policies or practices in security activities conducted under the contract, as determined by the DOE cognizant security office, must be designated as KMP. As a minimum, KMP must include the senior management official responsible for all aspects of contract performance and the designated facility Appendix B, Section 1, Chapter I DOE O 470.4B I-2 7-21-2011 security officer (FSO). KMP must possess final active security clearances in order for a contractor to be eligible for a final FCL involving classified information or matter, or SNM. Interim security clearances may be granted to KMP once their background investigations are in process and appropriate additional checks as required in DOE O 472.2, Personnel Security, change 1, have been conducted. Until all investigative requirements have been completed and final security clearances have been granted to the designated KMP, only an interim facility clearance can be granted. d. In accordance with the DEAR, section 952.204-73(e), a contractor that will not possess or handle classified information or matter, or SNM, at the contractor’s place of business but will require DOE personnel security clearances for the contractor’s employees to perform work at other cleared facilities must be processed for an FCL as a non-possessing facility. Employees of a non-possessing contractor must adhere to the security plans of the facilities where they are afforded access to classified information or matter, or SNM.

Section 43

e. A self-employed individual not doing business as a company, or a consultant who will not retain classified information or matter at his/her place of business, does not require an FCL provided the individual or consultant is the sole employee requiring a security clearance. For security administration activities, to include processing for a personnel security clearance, the individual will be considered an employee of the possessing facility where he/she is afforded access to classified information or matter. These individuals are required to complete the same security awareness briefings and requirements as other cleared employees. A self- employed individual or consultant who will retain classified information or matter at their place of business must be processed for and granted an FCL that applies to the premises where the individual or consultant will store, handle, or process classified information or matter. f. For Multiple Facility Organizations (MFOs), the home office facility must have an FCL at the same or higher level as that of any cleared facility within the MFO. g. In a corporate tier parent-subsidiary relationship, the parent and each of its subsidiaries are separate legal entities and must be processed separately for an FCL. Because the parent controls the subsidiary, the general rule in the U.S. Government is that the parent must have an FCL at the same or higher level as that of the subsidiary. However, DOE will determine the necessity for the parent to be cleared or excluded from access. DOE will advise the companies as to what action is necessary for processing the FCL. When a parent or its cleared subsidiaries are collocated, a formal written agreement to use common security services may be executed by the two firms, subject to DOE approval. h. A contractor granted an FCL by an OGA may be granted a DOE FCL for receiving, processing, using, or storing classified information or matter under a DOE contract at the same clearance level, based on reciprocity. DOE O 470.4B Appendix B, Section 1, Chapter I 7-21-2011 I-3 (and I-4) 2. ELIGIBILITY REQUIREMENTS. The following eligibility requirements must be met prior to being processed for an FCL. a. A contractor or prospective contractor must: (1) Be selected to perform tasks under a contract containing the DEAR security clauses found at 48 CFR Part 952; (2) Be organized under the laws of one of the 50 States, the District of Columbia, or Puerto Rico and must be located in the United States or a U.S. territorial area or possession; (3) Have a reputation for integrity and lawful conduct in its business dealings; (4) Not have been barred from participating in U.S. Government contracts (this includes KMP on the contract); and (5) Not be under FOCI to a degree that the granting or continuation of the FCL would be inconsistent with the national interest. b. An OGA must: (1) Have a documented need for an FCL as established in writing by DOE line management; (2) Submit a written statement of security assurance to the DOE cognizant security office, verifying the security capability of the agency as it applies to the DOE activity; and (3) When Restricted Data (RD) or Formerly Restricted Data (FRD) is involved, include in the written statement of security assurance procedures to limit the manner in which the RD or FRD is to be disseminated and ensure that appropriate clearances for access to RD or FRD are in place.

Section 44

c. For DOE facilities, cognizant security offices for DOE Federal activities must establish and document a security plan describing an adequate level of protection for DOE security interests. DOE O 470.4B Appendix B, Section 1, Chapter II 7-21-2011 II-1 CHAPTER II. IMPORTANCE RATINGS 1. FACILITY IMPORTANCE RATINGS. Importance ratings are used to establish a risk- based system for identifying the level of protection applicable to security assets and activities of facilities. Each facility granted an FCL must be assigned an importance rating. Each facility’s assigned importance rating must be recorded on DOE F 470.2, Facility Data and Approval Record (FDAR). Importance rating criteria are as follows. a. “A” Importance Ratings. An “A” importance rating must be assigned to those facilities that meet any of the following criteria: (1) Engaged in administrative activities considered essential to the direction and continuity of the overall DOE nuclear weapons program, as determined by the Program Secretarial Office or for NNSA, the Office of the Administrator; (2) Authorized to possess Top Secret RD/FRD or Top Secret national security information, or possess Special Access Program (SAP) matter, or designated as Field Intelligence Elements; (3) Authorized to possess Category I quantities of SNM (including facilities with credible rollup quantities of SNM to a Category I quantity); or (4) Operate critical infrastructure programs determined to be essential by DOE line management. b. “B” Importance Ratings. A “B” importance rating must be assigned to those facilities that meet any of the following criteria: (1) Engaged in activities other than those categorized as “A” and authorized to possess Secret RD and/or weapon data matter; (2) Authorized to possess Category II quantities of SNM; or (3) Authorized to possess certain categories of biological agents. c. “C” Importance Ratings. A “C” importance rating must be assigned to those facilities that meet any of the following criteria: (1) Authorized to possess Categories III and IV quantities of SNM or other nuclear materials requiring safeguards controls or special accounting procedures; or (2) Authorized to possess classified information or matter other than the type categorized for “A” and “B” facilities. d. “D” Importance Ratings. A “D” importance rating must be assigned to those facilities that provide common carrier, commercial carrier, or mail service and are Appendix B, Section 1, Chapter II DOE O 470.4B II-2 7-21-2011 not authorized to store classified information or matter, or nuclear material during non-working hours. (Carriers who store classified information or matter, or nuclear material must be assigned an “A,” “B,” or “C” importance rating.) e. “E” (Excluded Parent) Importance Ratings. An “E” importance rating must be assigned to a corporate tier parent of a contractor organization when the parent has been barred from participation in the activities related to a contract with DOE. f. “PP” (Property Protection) Importance Ratings. A “PP” importance rating must be assigned to those facilities that meet any of the following criteria: (1) Government property of a significant monetary value (suggested threshold of $5 million); (2) Nuclear materials requiring safeguards controls or special accounting procedures other than those categorized as types “A,” “B,” or “C”; (3) Responsibility for DOE program continuity; (4) National security considerations; or

Section 45

(5) Responsibilities for protection of the health and safety of the public and employees. g. “NP” (Non-Possessing) Importance Ratings. An “NP” rating must be assigned to those facilities whose staff have authorized access to classified information or matter, or SNM at other approved locations, but which do not themselves possess any classified information or matter, or SNM, or meet any of the other criteria listed for the other ratings above. 2. UPGRADING AND DOWNGRADING A FACILITY’S ASSIGNED IMPORTANCE RATING. As security activities are added or changed, the importance rating of the approved facility may change (i.e., it may be either upgraded or downgraded). Upgrading or downgrading a facility’s importance rating may also require transfer of the DOE cognizant security office functions. Changes to the facility importance rating must be registered in SSIMS by the submission of DOE F 470.2, Facility Data and Approval Record (FDAR). DOE O 470.4B Appendix B, Section 1, Chapter III 7-21-2011 III-1 CHAPTER III. FACILITY CLEARANCE APPROVAL REQUIREMENTS 1. ISSUANCE OF FCLs. All eligibility requirements listed below must be satisfied prior to the issuance of an FCL. The DEAR prohibits the award of a classified contract until an FCL has been granted and issued. When an existing unclassified contract is modified to require classified work, the contract modification cannot take effect until an FCL is issued and the appropriate DEAR security clause is inserted in the contract. 2. CONTRACTOR FACILITIES. In accordance with the provisions of the DEAR, approval of a contractor final FCL must be based on the following items: a. A favorable FOCI determination based upon all information available to the cognizant security office including information on Standard Form (SF) 328 and any required supporting documentation; b. A contract or proposed contract containing the appropriate security clauses found in the DEAR; c. S&S plans, developed in accordance with DOE policy in Attachment 2 of this Order, that describe protective measures appropriate to the activities being performed at the facility and approved by the DOE cognizant security office; d. If access to nuclear material is involved, an established Reporting Identification Symbol code for the Nuclear Materials Management and Safeguards Reporting System (NMMSS); e. A comprehensive survey conducted no more than 6 months before the FCL approval date with a composite facility rating of satisfactory, if the facility will possess classified information or special nuclear material at its location or if the facility has an importance rating of “PP”; f. Appointment of an FSO, who must possess or be in the process of obtaining an access authorization (security clearance) equivalent to the level of the facility clearance (note that only an interim FCL can be granted until the FSO’s access authorization is finalized); g. If applicable, appointment of a Materials Control and Accountability Representative; and h. Access authorizations for KMP who will be determined on a case-by-case basis and must possess or be in the process of obtaining final access authorizations equivalent to the level of the facility clearance. (NOTE: until the required KMP access authorizations are finalized, only an interim FCL can be granted. In support of an interim FCL, KMP who do not possess clearances must be granted interim access authorizations.) Appendix B, Section 1, Chapter III DOE O 470.4B III-2 7-21-2011

Section 46

3. FACILITY CLEARANCES FOR OGAs. Federal government facilities are eligible to be registered with a DOE FCL if the OGA is involved in activities that impact DOE security interests such as possession and/or storage of RD or other mission or programmatic needs as identified and documented by DOE line management. Approval of an OGA FCL must be based upon a written statement of security assurance from the OGA that protection of DOE security interests is adequately ensured. The statement of security interest must include the following information: a. An approved classified mailing address for the facility; b. The highest level and most restrictive category of classified information the facility is authorized to receive and store; c. A statement that national security classified information will be afforded protection according to E.O. 13526, Classified National Security Information, and all implementing directives issued by the Information Security Oversight Office (ISOO), to include the requirements of 32 CFR Part 2001, Classified National Security Information; d. A statement that the requirements of 10 CFR Part 1045, Nuclear Classification and Declassification, will be met for RD and FRD; and e. Assurance that the requirements of the Atomic Energy Act, including the mandatory access authorization requirements, will be met for access to RD and FRD. 4. RECORDS. For DOE Federal and contractor facilities, the DOE cognizant security office must maintain a copy of the facility’s S&S plans, survey reports, FOCI documentation including notification of a favorable FOCI determination if applicable, pertinent correspondence, and copies of DOE F 470.2, Facility Data and Approval Record (FDAR), created for the facility. For FCL termination of all registered facilities, a copy of the certificate of non-possession or security certification must be maintained. DOE O 470.4B Appendix B, Section 1, Chapter IV 7-21-2011 IV-1 CHAPTER IV. INTERIM AND LIMITED FACILITY CLEARANCES 1. INTERIM FCLs. Interim FCLs are granted on a temporary basis, pending completion of full investigative and approval requirements, including but not limited to the completion of background investigations for final access authorizations for those individuals required to be cleared in connection with the FCL (such as KMP). Interim FCLs may be granted only to avoid unacceptable delays in pre-contract negotiation or in performance on a contract, and must be granted only after DOE has made a FOCI determination and granted interim access authorizations to KMP and other facility personnel requiring immediate access to classified information or matter. a. When final access authorizations have been granted to all facility personnel required to be cleared in connection with the FCL, a final FCL must be granted and registered in SSIMS via an updated DOE F 470.2, Facility Data and Approval Record (FDAR). b. When an interim access authorization for an individual KMP is withdrawn, the interim FCL must also be withdrawn unless action is taken to remove the individual from the position requiring access. c. Foreign owned or controlled companies and those with non-U.S. citizens as KMP are not eligible for interim FCLs.

Section 47

2. LIMITED FCLs. The United States has entered into agreements with certain foreign governments that establish arrangements whereby a foreign-owned U.S. company may be considered eligible for an FCL without any additional FOCI negation or mitigation instrument. To ensure that release of information or access to SNM is in accordance with the U.S. National Disclosure Policy, a limited FCL must be restricted to one security activity involving classified information or SNM. Award of another security activity to the same facility involving such information requires separate FCL registration, under another limited FCL or under an FCL without restrictions, if appropriate. Issuance of a limited FCL requires imposing strict access restrictions to limit access to the scope of the contract. The clearance and exclusion requirements for KMP apply to all FCLs, including a limited FCL. a. A limited FCL may be granted upon satisfaction of the following criteria. (1) Verification of an agreement authorizing the exchange of the classified information or matter involved to the country from which the foreign ownership is derived. (a) Access to classified information or matter will be limited to performance on a contract, subcontract, or program involving the government of the country from which foreign ownership is derived. Appendix B, Section 1, Chapter IV DOE O 470.4B IV-2 7-21-2011 (b) Release of classified information or matter must be in conformity with the U.S. National Disclosure Policy. (2) In extraordinary circumstances, a limited FCL may also be granted when the criteria listed above cannot be satisfied, provided there exists a compelling need to do so consistent with national security interests. b. Limited FCL Compelling Need Statement. Each request for clearance under a limited FCL must be accompanied by a statement of compelling need from the GCA. The GCA’s compelling need statement must be signed by the head of the cognizant DOE program office and include the following: (1) Acknowledgment that the company will be under FOCI (i.e., FOCI will not be mitigated); (2) Acknowledgment that the GCA/Departmental element accepts the risks inherent in the granting of an FCL where FOCI is not mitigated; and (3) A foreign disclosure determination stating the basis for determining that release of classified to the foreign government involved is in conformity with U.S. National Disclosure Policy. DOE O 470.4B Appendix B, Section 1, Chapter V 7-21-2011 V-1 (and V-2) CHAPTER V. PERSONNEL SECURITY CLEARANCES AND EXCLUSION PROCEDURES REQUIRED IN CONNECTION WITH CONTRACTOR FACILITY CLEARANCES 1. SECURITY CLEARANCES REQUIRED IN CONNECTION WITH THE FCL. Certain officials (typically the owners, officers, directors, partners, regents, trustees, and/or executive personnel [KMP]) with the ability to affect the organization’s policies or practices in security activities conducted under the contract must be cleared to the level of the FCL or formally excluded from access as appropriate. For multiple facility organizations, each subordinate cleared facility’s KMP must also be cleared or excluded. Changes in an organization’s KMP must be reported as they occur, and access authorizations must be processed for new KMP immediately. 2. EXCLUSION PROCEDURES. When officials are to be excluded from or cleared at a level not commensurate with the FCL, compliance with one or both of the exclusion actions listed below is mandatory before issuance of an FCL. Exclusion actions must be made a matter of record by the organization’s executive body. A copy of the resolution must be provided to the DOE cognizant security office.

Section 48

a. When formal exclusion action is required, the organization’s governing body must affirm that specific KMP (designated by name) will not require, will not have, and can be effectively excluded from access to all classified information or matter, or nuclear or other hazardous material presenting a potential radiological, chemical, or biological sabotage threat, that is entrusted to or held by the organization. Additionally, the governing body must affirm that the specific KMP (designated by name) do not occupy positions that would enable them to adversely affect the organization’s policies or practices in the performance of classified contracts. b. When officials are to be cleared at a level below that of the FCL, the organization’s governing body must affirm that such KMP (designated by name) will not require, will not have, and can be effectively denied access to higher- level classified information (specified by level), and do not occupy positions that would enable them to adversely affect the organization’s policies or practices in the performance of higher-level classified contracts. 3. SECURITY CLEARANCES CONCURRENT WITH THE FCL. Contractors may designate employees who require access to classified information or matter during the negotiation of a contract or the preparation of a bid or quotation pertaining to a prime contract or a subcontract to be processed for security clearances concurrent with the FCL. The granting of an FCL is not dependent on the security clearance of such employees. DOE O 470.4B Appendix B, Section 1, Chapter VI 7-21-2011 VI-1 CHAPTER VI. FACILITY CLEARANCES GRANTED BY OTHER GOVERNMENT AGENCIES 1. ACCEPTING OGA FCLs. a. General. A contractor with an equal or higher FCL granted by another Federal government agency under the National Industrial Security Program (NISP) may be accepted by DOE for accessing, receiving, generating, reproducing, storing, transmitting, or destroying classified information or matter, contingent on the conditions listed below. Reciprocity between DOE and the OGA must be documented in a written letter or memorandum of agreement (MOA) between the DOE cognizant security office and the cognizant OGA that establishes the responsibilities of each party for assurance and verification of the protection afforded the DOE assets. (1) Classification Level/Category and Special Conditions. The FCL granted by the OGA must be at the appropriate classification level and category and must encompass the DOE activity. (a) Limited or interim FCLs granted by an OGA cannot be accepted. (b) If cleared under a Voting Trust Agreement, Proxy Agreement, Special Security Agreement, or Security Control Agreement, the DOE cognizant security office must obtain a copy of the FOCI mitigation plan from the cognizant OGA. The mitigation plan must be submitted to the DOE Office of Environment, Health, Safety and Security or, for NNSA activities, to the Office of Defense Nuclear Security, for review. (c) For DOE contracts involving proscribed information (i.e., Top Secret, COMSEC, SCI), the following requirements, as appropriate, must be met before accepting an FCL granted in conjunction with a Special Security Agreement or Security Control Agreement. 1 When the company is controlled by a foreign government: a DOE must have entered into an agreement with the foreign government involved that covers the proscribed information to be released under the contract; and

Section 49

b A waiver must be granted by the cognizant Secretary (i.e., the Secretary of Energy and/or the Secretary of Defense) in accordance with the provisions of 10 U.S.C. Section 2536, Award of certain contracts to entities controlled by a foreign Appendix B, Section 1, Chapter VI DOE O 470.4B VI-2 7-21-2011 government: prohibition, which prohibits contract awards involving proscribed information to foreign government-controlled companies unless such a waiver is granted. 2 For contracts involving RD/FRD, the additional requirements set forth below in paragraphs 3 and (6)(a)–(d) must be met or addressed as appropriate. 3 When a company is not controlled by a foreign government, and is operating under a Special Security Agreement, a national interest determination (NID) for the specific program/project/contract must be approved by DOE and/or the OGA as appropriate; provided, however, that in accordance with Section 842 of Public Law 115-232 (Reference o), covered National Technology and Industrial Base (NTIB) entities (as defined at Section 842(c)(1) of Public Law 115-232) shall not be required to obtain a NID as a condition for access to proscribed information. (d) An OGA Top Secret facility clearance transfers to a DOE Secret/RD possessing interest, and an OGA Secret facility clearance transfers to a DOE Secret/RD non-possessing interest as long as DOE grants the security clearances to KMPs and all individuals requiring access to Secret/RD under the DOE contract(s). (e) Final FCLs granted by OGAs for access to national security information (NSI), when no proscribed information is involved, will be accepted by DOE on a reciprocal basis with no additional requirements. (2) Notification of Cancellation. An assurance must be obtained from the OGA that the FCL will not be canceled prior to the DOE cognizant security office being notified. (3) Protective Measures. Confirmation must be obtained from the OGA that the facility’s protective measures and procedures are adequate for the protection of the DOE activity, and results of the agency’s last survey of the facility are satisfactory in those areas that could affect the DOE interest. (4) Surveys. The facility’s survey frequency must be confirmed by the OGA, and assurance must be obtained that copies of each of the OGA’s periodic survey reports or memoranda covering the status of the protection of the DOE activity will be furnished to the DOE cognizant security office following each scheduled survey. DOE O 470.4B Appendix B, Section 1, Chapter VI 7-21-2011 VI-3 (5) Access authorizations. Each employee to be granted access to RD or SNM must have an appropriate access authorization. (6) RD/FRD. If RD or FRD is involved, the following must be considered: (a) An assurance must be obtained from the OGA that the facility complies with the requirements of 10 CFR Part 1045, Nuclear Classification and Declassification. (b) When the DOE contract involves RD, an assurance must be obtained from the OGA that the facility’s protective measures and procedures meet the requirements of 32 CFR 117, National Industrial Security Program Operating Manual (NISPOM), including any appendices or supplements applicable to RD. (c) FCLs not meeting the requirements in (a) and (b) above may be accepted if the DOE activity requires that the contractor establish upgraded protective measures that meet DOE requirements. For FCL upgrades, the agreement between DOE and the OGA must cover reimbursement for upgrade costs incurred by the OGA or contractor.

Section 50

(d) When DOE accepts an FCL based on an OGA-approved Voting Trust Agreement, Proxy Agreement, Special Security Agreement, or Security Control Agreement, an assurance must be obtained from the OGA that it will invite and permit DOE to attend the annual meeting if such attendance is determined necessary by either the OGA or DOE. b. Contractor’s Tier Parent(s). If the parent(s) of a company that DOE is processing for an FCL holds an FCL granted by another Federal agency, the tier parent(s) does not need to provide DOE with a FOCI package, provided reciprocity is accomplished with the OGA. Reciprocity between the DOE cognizant security office and the OGA must be documented in a written agreement with the appropriate provisions as outlined above. The written agreement must contain an assurance from the OGA that security cognizance will be transferred to DOE for any tier parent no longer requiring the OGA FCL. 2. OGA VERIFICATION REQUESTS. If an OGA requests verification of an existing DOE FCL, a copy of the facility’s current DOE F 470.2, Facility Data and Approval Record (FDAR), must be provided. 3. OGA CONTRACTORS WITH NO DOE CONTRACTS. Classified mail channels must be registered in SSIMS for an OGA contractor organization where the Department does not have a contractual interest but must communicate or exchange classified information with the OGA contractor. To establish an address for the classified mail channel, a statement of security assurance or a form comparable in content must be completed and Appendix B, Section 1, Chapter VI DOE O 470.4B VI-4 7-21-2011 signed by the DOE cognizant security office and by the authorizing government official for the OGA contractor. The establishment of this type of registration in SSIMS cannot be used as a basis for registering additional security activities. DOE O 470.4B Appendix B, Section 1, Chapter VII 7-21-2011 VII-1 CHAPTER VII. DOCUMENTATION AND REGISTRATION OF FACILITY CLEARANCES AND RELATED SECURITY ACTIVITIES 1. DOCUMENTATION OF FCLs. SSIMS must be used by all DOE cognizant security offices to register FCL information for which they have cognizant security authority, survey cognizance, or responsibility for registered security activities. Each registered FCL must identify the highest security activity approved for the registered facility. a. DOE F 470.1, Contract Security Classification Specification (CSCS), is used to register information in SSIMS concerning contract vehicles; a DD 254 used by an OGA sponsoring an activity can be submitted in lieu of the DOE F 470.1 if it is annotated with the DOE facility code. DOE F 470.2, Facility Data and Approval Record (FDAR), is used to record approvals, changes, and deletions of facility security information and other facility changes for entry into SSIMS. These forms are available on the website of the DOE Office of the Chief Information Officer ( https://www.energy.gov/cio/office-chief-information-officer/services/forms). b. If more than one Departmental element has a registered security activity at a facility, the element responsible for the security activity involving the highest classification level and category is the responsible DOE cognizant security office, to include being the processing personnel security office. This responsibility may be delegated, by mutual agreement, to another Departmental element with a registered security activity at that facility. The Special Security Officer, Office of Intelligence and Counterintelligence, must also sign the DOE F 470.1 for contracts involving access to Sensitive Compartmented Information.

Section 51

c. Any change in the responsible DOE cognizant security office or survey office must include a transfer of appropriate documentation (e.g., S&S plans; construction project status; FOCI files; etc.). 2. REGISTRATION OF SECURITY ACTIVITIES. Security activities are specific, unrelated tasks or contract elements involving S&S interests at a facility. Security activities must be registered in association with a specific FCL. a. Security Activities for Existing FCLs. The DOE cognizant security office must: (1) Determine and validate the security requirements, including personnel security clearances, for the proposed security activity. (2) Determine the FCL status through SSIMS or the DCSA National Industrial Security System (NISS) NISS, which can be accessed through National Industrial Security Program (NISP) Central Access Information Security System (NCAISS) at https://ncaiss.dss.mil/. (3) Compare the security requirements for the activity to the approved FCL in the following situations and ensure that: https://www.energy.gov/cio/office-chief-information-officer/services/forms https://ncaiss.dss.mil/ Appendix B, Section 1, Chapter VII DOE O 470.4B VII-2 7-21-2011 (a) When the contractor FCL is granted by an OGA, the requirements for accepting an OGA FCL are met. (b) When the contractor FCL is granted by DOE: 1 The new activity will be protected adequately under the facility’s existing S&S program as outlined in the facility’s approved security plan. 2 The existing FCL is compatible with the level and category of the new security activity. 3 The facility holds a composite facility rating of satisfactory on the basis of the last S&S survey report. 4 If applicable, coordination is accomplished with the DOE and/or OGA cognizant security agency for any tier parent(s) of the contractor holding a DOE or OGA FCL to ensure compliance with national requirements (e.g., FOCI determination, exclusion resolutions for KMP, etc.). b. Registering New Security Activities. The procurement request originator will submit a DOE F 470.1, Contract Security Classification Specification (CSCS), or DD 254 to the DOE contracting official, who will forward the completed DOE F 470.1 to the DOE cognizant security office. The DOE cognizant security office will verify the information and ensure that the new security activity can be performed within the existing FCL. If no issues are identified, the cognizant security office will approve the form and return it to the contracting officer so that the contract can be awarded. When a new activity will exceed the current FCL, or if there is no FCL, all actions required to upgrade the current level or obtain an FCL must be completed prior to contract award. c. Terminating Security Activities. When a registered security activity is terminated, the organization that established the security activity must ensure that all access authorizations associated with the activity are terminated and all DOE property, classified information or matter, and/or nuclear and other hazardous material is appropriately reallocated, disposed of, destroyed, or returned to the appropriate DOE or cleared DOE contractor organization. A certificate of non-possession must be obtained from the organization responsible for the terminating activity and must be maintained by the DOE cognizant security office that established the security activity. A final CSCS form must be submitted and SSIMS must be updated to show the termination.

Section 52

3. REGISTERING STRATEGIC PARTNERSHIP PROJECTS (SPP) ACTIVITIES. The requirements of DOE O 481.1, Strategic Partnership Projects [Formerly Known as Work for Others (Non-Department of Energy Funded Work)], current version, must be met DOE O 470.4B Appendix B, Section 1, Chapter VII 7-21-2011 VII-3 before an SPP project or any “out of scope” modifications to existing SPP agreements are accepted. SPP activities must be registered in SSIMS. a. SPP Performed at DOE-Owned or DOE-Operated Facilities. Before acceptance of SPP activities, the DOE and the requesting agency must exchange classification and protection information, including the DOE F 470.1, Contract Security Classification Specification (CSCS) or DD Form 254. The exchange of classification and protection information must be documented and may also include a formal agreement that includes reimbursement of any additional S&S costs (above minimum security requirements) incurred by the Department. b. SPP Performed at Other Than DOE-Owned or DOE-Operated Facilities. When an OGA stipulates that SPP activities are to be performed by a DOE contractor at locations other than DOE-owned or DOE-operated facilities, an FCL is required. If the FCL is issued by an OGA, the requirements for accepting OGA FCLs apply. The SPP activity must be registered in SSIMS. Before the activity can be registered, all applicable requirements of DOE O 481.1, current version, must be met, and the DOE cognizant security office must review and certify that the sponsoring organization has complied with the applicable provisions of DOE O 475.2B, Identifying Classified Information. c. Subcontracting in Connection with SPP. When subcontracting is required in connection with SPP, the subcontractor can be registered based on DOE F 470.2, Facility Data and Approval Record (FDAR), and verification of the FCL. In this instance, a security cognizance agreement is not required. If the subcontractor has a DOE FCL at the appropriate level, the SPP activity must be registered. If the subcontractor has an FCL issued by an OGA, the considerations for the acceptance of OGA FCLs, as outlined in Chapter VI of this Section, apply. A separate letter or memorandum of understanding between DOE and the OGA is not required provided that all considerations are addressed in the SPP agreement. 4. EXCEPTIONS TO REGISTRATION IN SSIMS. Foreign intelligence information, SCI, SAPs, and other sensitive activities requiring special access or procedures associated with receipt, storage, processing, and/or handling must conform to the applicable protection provisions of Executive Orders and to applicable Director of Central Intelligence directives. Because these activities are not regulated under S&S policy, they are not registered in SSIMS. Exceptions to the registration requirements are identified below. a. SAPs. SAPs are not registered in SSIMS. SAPs are registered in accordance with DOE O 471.5, Special Access Programs, dated 3-29-11. b. SCI. SCI security activities are not registered in SSIMS; however, each accredited SCI facility (SCIF) must be recorded in SSIMS using DOE F 470.2, Facility Data and Approval Record (FDAR). c. Classified or Sensitive Activities. Details concerning sensitive or classified activities the publication of which in SSIMS would compromise mission Appendix B, Section 1, Chapter VII DOE O 470.4B VII-4 7-21-2011

Section 53

completion of such activities or classified information are not registered in SSIMS. The DOE cognizant security office must notify the appropriate Program Secretarial office or, for NNSA, the Office of the Administrator before granting the FCL. DOE O 470.4B Appendix B, Section 1, Chapter VIII 7-21-2011 VIII-1 CHAPTER VIII. SUSPENSIONS 1. REASONS FOR SUSPENSION. When the following conditions occur, the DOE cognizant security office must suspend the FCL, document the action on an updated DOE F 470.2 (Facility Data and Approval Record [FDAR]), and immediately update SSIMS to reflect the suspension: a. When a company with an FCL is determined to be under FOCI that has not been mitigated, the FCL must be suspended. Contract performance on activities involving proscribed information may not continue until all applicable FOCI requirements are met. b. When findings or other deficiencies in a survey, self-assessment, inquiry, inspection, or evaluation indicate suspension of an FCL is necessary, the DOE cognizant security office will determine whether the FCL must be suspended pending validated corrective actions. 2. ACTIONS. When a decision is made to suspend the FCL of a company that has current access to classified information or SNM, the following actions must be taken: a. The facility subject to the suspension action must be notified in writing that its FCL has been suspended, including the reason for the suspension; that award of new contracts to the facility will not be permitted until the facility has been restored to a fully valid status; and that termination of the FCL may result if the issues causing the suspension are not rectified within a time frame and manner specified by DOE. Notification must include instructions for immediately securing classified material and/or SNM at an approved cleared facility pending restoration of the suspended facility to a fully valid status. b. GCAs must be notified and must make the final decision regarding a contractor’s continued performance on existing contracts other than the contract activity for which the suspension is in effect. Continued possession of classified information or SNM associated with those contracts retained under GCA authorizations must be evaluated by the DOE cognizant security office to determine whether appropriate security requirements are being met. c. All affected DOE elements and, if applicable, affected OGAs must be notified by the DOE cognizant security office of the suspension action. 3. NON-COMPLIANCE WITH MITIGATION PLANS. When the DOE cognizant security office determines that a cleared contractor or its tier parent is out of compliance with an approved FOCI mitigation plan, the DOE cognizant security office must analyze the non- compliance and evaluate the overall impact to the protection of security interests. The cognizant contracting officer must be notified immediately and one or more of the following actions must be taken: Appendix B, Section 1, Chapter VIII DOE O 470.4B VIII-2 7-21-2011 a. Request a corrective action and implementation plan from the contractor to bring it into compliance with the approved mitigation plan. b. Suspend the FCL. c. Terminate the FCL.

Section 54

4. CONTINUATION OF CONTRACT PERFORMANCE UNDER FOREIGN GOVERNMENT OWNERSHIP. In accordance with the intent of 10 U.S.C. Section 2536, Award of certain contracts to entities controlled by a foreign government: prohibition, when an existing contractor becomes foreign-government owned but execution of a novation agreement is not required by the DEAR clause, the continued performance by that contractor on existing classified contracts or contracts for environmental restoration, remediation, or waste management that involve proscribed information may only continue under FCL suspension if: a. The contractor is eligible for continuation on such work by Secretarial and/or OGA Secretarial waiver under 10 U.S.C. Section 2536(b)(1)(A) or 10 U.S.C. Section 2536(b)(1)(B), as applicable; b. Each GCA takes immediate action to request a waiver under 10 U.S.C. Section 2536(b)(1)(A) or 10 U.S.C. Section 2536(b)(1)(B), as applicable, and also takes interim actions to safeguard the classified information associated with its classified contracts. 5. REINSTATEMENT OF A SUSPENDED FCL. When the conditions that resulted in the suspension have been resolved in a manner determined acceptable by DOE management, the FCL may be reinstated. The reinstatement must be based on the necessity to complete or continue work associated with the original FCL. DOE O 470.4B Appendix B, Section 1, Chapter IX 7-21-2011 IX-1 (and IX-2) CHAPTER IX. FACILITY CLEARANCE TERMINATION AND CLOSE OUT 1. CONTRACT CLOSEOUT/FACILITY CLEARANCE TERMINATION. a. General. When a contract ends and/or an FCL is no longer necessary, the DOE cognizant security office must complete a termination survey, a DOE F 470.2, Facility Data and Approval Record (FDAR), and update SSIMS to enact the termination. All security clearances connected to the facility clearance must be terminated and all DOE property, classified information or matter, and/or nuclear and other hazardous material presenting a potential radiological, chemical or biological sabotage threat must be appropriately reallocated, disposed of, destroyed, or returned to an appropriate DOE or cleared DOE contractor organization. b. Contract Completion. Upon completion or termination of a contract, the possessing contractor must submit to the DOE cognizant security office either a certificate of non-possession or a certificate of possession (of classified matter). A non-possessing contractor must submit a security activity closeout certification. Closure of the contract must be documented with a final DOE F 470.1, Contract Security Classification Specification (CSCS). Forms and certificates must be maintained with the records pertaining to the facility clearance. 2. REACTIVATION. Reactivations of terminated FCLs must be based on programmatic or mission need and the implementation of current security requirements. The DOE cognizant security office must validate that all security requirements have been implemented, must complete a DOE F 470.2, Facility Data and Approval Record (FDAR), and must update SSIMS to complete the reactivation. DOE O 470.4B Appendix B, Section 2 7-21-2011 2-1 SECTION 2. FOREIGN OWNERSHIP, CONTROL, OR INFLUENCE PROGRAM

Section 55

1. OBJECTIVE. Foreign investment can play an important role in maintaining the vitality of the U.S. industrial base. Therefore, it is the policy of the U.S. Government to allow foreign investment consistent with the national security interests of the United States. The DOE Foreign Ownership, Control, or Interest (FOCI) policy for U.S. companies subject to an FCL determination is intended to facilitate foreign investment by ensuring that foreign firms cannot undermine U.S. security and export controls to gain unauthorized access to critical technology and/or classified information or matter, including RD, FRD, and SNM. 2. PURPOSE. The FOCI program regulates DOE determinations of the degree to which a contractor facility is under foreign ownership, control, or influence. In accordance with 48 CFR Chapter 9, the DOE Acquisition Regulation (DEAR), DOE must obtain information about FOCI that is sufficient to help the Department determine whether award of a contract to a person or firm, or the continued performance of a contract by a person or firm, may pose undue risk to the common defense and security. A contractor cannot be under FOCI to such a degree that granting or continuing an FCL would be inconsistent with U.S. national security interests. The requirements of the National Industrial Security Program (NISP) form the baseline for this program, supplemented with requirements for the protection of DOE-specific assets, Restricted Data, SNM, and other security activities. 3. DEFINITION. A U.S. company is considered under FOCI whenever a foreign interest has the power, direct or indirect, whether or not exercised, and whether or not exercisable through the ownership of the U.S. company’s securities, by contractual arrangements or other means, to direct or decide matters affecting the management or operations of that company in a manner which may result in unauthorized access to classified information or may adversely affect the performance of a classified contract. 4. REFERENCES. a. E.O. 12829, National Industrial Security Program, dated 01-26-93. b. 32 CFR Part 2004, National Industrial Security Program, dated 05-07-2018 c. DoD 5220.22-R, Industrial Security Regulation, dated December 1985 d. 32 CFR 117, National Industrial Security Program Operating Manual (NISPOM), dated 12-21-20 e. DCSA ISLs, available at https://www.dcsa.mil/mc/ctp/tools/ (Note: ISLs do not automatically impose requirements on DOE, but may contain useful clarifications of existing NISPOM provisions.). f. DTM issued by the Office of the Under Secretary of Defense, available at https://www.esd.whs.mil/DD/DoD-Issuances/DTM/. (Note: DTMs, which may be https://www.dcsa.mil/mc/ctp/tools/ https://www.esd.whs.mil/DD/DoD-Issuances/DTM/ Appendix B, Section 2 DOE O 470.4B 2-2 7-21-2011 issued periodically on a variety of topics, do not automatically impose requirements on DOE, but may contain useful information applicable to existing NISP programs.) g. 10 U.S.C. Section 2536, Award of certain contracts to entities controlled by a foreign government: prohibition, dated 09-23-96 h. 48 CFR Chapter 9, Department of Energy Acquisition Regulation, dated 12-29-10 i. DOE Order 475.1, Counterintelligence Program, dated 12-10-04. j. Public Law 115-232, The John S. McCain National Defense Authorization Act for Fiscal Year 2019 k. DOE O 142.3B: Unclassified Foreign National Access Program, dated January 15, 2021 l. DOE O 483.1B: DOE Cooperative Research and Development Agreements, dated December 20, 2016

Section 56

m. DOE P 485.1A: Foreign Engagements with DOE National Laboratories, dated December 13, 2019 n. DOE O 486.1A: Foreign Government Sponsored or Affiliated Activities, dated September 4, 2020 5. REQUIREMENTS. DOE cognizant security offices, as designated by the Program Secretarial Office or, for NNSA, the Office of the Administrator through the Chief, Defense Nuclear Security, are responsible for ensuring that the following activities are accomplished under the FOCI program for facilities and sites under their cognizance and for ensuring that contractors under their cognizance accomplish their responsibilities under this program at contractor facilities. Procedures applicable to the FOCI program must be documented in facility or site security plans. a. Ensure that determinations are rendered under the FOCI program concerning foreign ownership, control or influence factors on all contractors and their tier parents as applicable, in accordance with national and DOE requirements when the contract will involve or is likely to involve classified information or SNM. b. Establish and apply procedures to ensure that coordination is accomplished between the FCL and FOCI programs for all contractor FCLs. c. Ensure that all relevant aspects of FOCI are resolved and, if necessary, appropriately mitigated prior to the granting of an interim or final FCL. d. Ensure that contractors under their cognizance meet reporting requirements as established in DOE directives and national standards. DOE O 470.4B Appendix B, Section 2 7-21-2011 2-3 e. Establish and determine the circumstances under which a contractor will be requested to complete a new FOCI package. f. Ensure that contractors under FOCI mitigation comply with all requirements imposed by the mitigation instrument. g. Ensure that procedures are in place for verification of the original signature on the Standard Form (SF) 328, Certificate Pertaining to Foreign Interest, prior to finalizing a FOCI determination. h. Ensure that counterintelligence threat and technology transfer risk assessments and updates are obtained and evaluated as necessary in the administration of the FOCI program. i. Ensure that annual review and certification requirements established in 32 CFR 117, National Industrial Security Program Operating Manual (NISPOM), or alternative methods as permitted by this Order, for contractors under a FOCI mitigation instrument, are met for all such contractors under their cognizance. j. Ensure that when factors not related to ownership are present, contractors take appropriate positive measure to assure that the foreign interest can be effectively mitigated and cannot otherwise adversely affect performance on contracts. k. Approve trustees, proxy holders, and outside directors nominated by contractors in connection with FOCI mitigation plans, and approve specific measures such as technology control plans developed and implemented by contractors as part of FOCI mitigation plans. l. Evaluate changes in FOCI information submitted by contractors holding an FCL, and make changes in mitigation methods or security requirements, or suspend or terminate the facility clearance, as warranted to address changed conditions. DOE O 470.4B Appendix B, Section 2, Chapter I 7-21-2011 I-1 CHAPTER I. GENERAL FOCI PROGRAM INFORMATION 1. GENERAL. a. An FCL must not be granted until all relevant aspects of FOCI have been resolved and, if necessary, appropriately mitigated. Appropriate procedures must be in place to ensure coordination between the FOCI and FCL programs under the jurisdiction of each DOE program office. b. The determination of whether a U.S. company is under FOCI must be made on a case-by-case basis. In instances where the company is unable to identify a foreign owner (e.g., the participating investors in a foreign investment or hedge fund cannot be identified), DOE may determine that the company is not eligible for an FCL. The following are examples of factors that must be considered to determine whether a company is under FOCI, is eligible for an FCL in spite of FOCI issues, and the protective measures required to mitigate FOCI: (1) Foreign intelligence threat, including record of economic and government espionage against U.S. targets;

Something wrong with this record? Tell us