Archives of Directives

Archive

DOE O 470.4B, Safeguards and Security Program

Functional areas: Safety, Safety and Security, Security, Work Processes

To establish responsibilities for the U.S. Department of Energy (DOE) Safeguards and Security (S&S) Program, and to establish program planning and management requirements for the S&S Program. Cancels DOE O 470.4A, DOE M 470.4-1, Chg. 2, and DOE O 142.1.
o470.4b_Final_7-21-11.pdf796.05KB
Version history and related documents
Document text

Text extracted from the attached file. Refer to the original document for the authoritative version.

Section 1

ORDER Approved: 7-21-2011 SAFEGUARDS AND SECURITY PROGRAM U.S. DEPARTMENT OF ENERGY Office of Health, Safety and Security DOE O 470.4B DOE O 470.4B 1 7-21-11 SAFEGUARDS AND SECURITY PROGRAM 1. PURPOSE. To establish responsibilities for the U.S. Department of Energy (DOE) Safeguards and Security (S&S) Program, and to establish program planning and management requirements for the S&S Program. The requirements identified in this Order and its attachments and appendices are based on national policy promulgated in laws, regulations, Executive Orders, and national standards to prevent unacceptable adverse impacts on national security, the health and safety of DOE and contractor employees, the public, or the environment. 2. CANCELLATIONS. DOE O 470.4A, Safeguards and Security Program, dated 5-25-07; DOE M 470.4-1 chg 2, Safeguards and Security Program Planning and Management, dated 10-20-10; and DOE O 142.1, Classified Visits Involving Foreign Nationals, dated 1-13-04. Cancellation of a directive does not, by itself, modify or otherwise affect any contractual or regulatory obligation to comply with the directive. Contractor Requirements Documents (CRDs) that have been incorporated into a contract remain in effect throughout the term of the contract unless and until the contract or regulatory commitment is modified to either eliminate requirements that are no longer applicable or substitute a new set of requirements. 3. APPLICABILITY. a. Departmental Applicability. Except for the equivalencies/exemptions in paragraph 3.c., this Order applies to all Departmental elements. The Administrator of the National Nuclear Security Administration (NNSA) must ensure that NNSA employees comply with their responsibilities under this directive. Nothing in this directive will be construed to interfere with the NNSA Administrator’s authority under section 3212(d) of P.L. 106-65, National Nuclear Security Administration Act, to establish Administration specific policies, unless disapproved by the Secretary. The Administrator of the Bonneville Power Administration (BPA) must ensure that BPA employees and contractors comply with their respective responsibilities under this directive consistent with BPA’s procurement, self-financing, and statutory authorities. b. DOE Contractors. Except for the equivalencies/exemptions in paragraph 3.c., the CRD (Attachment 1) sets forth requirements of this Order that will apply to contracts that include the CRD. The CRD must be included in contracts that contain DOE Acquisition Regulation (DEAR) clause 952.204-2, Security. Heads of field elements and Headquarters Departmental elements must identify contracts that should incorporate the CRD 2 DOE O 470.4B 7-21-11 and notify contracting officers to incorporate the CRD into those contracts. Contracting officers are responsible for incorporating the CRD into the affected contracts as appropriate. A violation of the provisions of the CRD relating to the safeguarding or security of Restricted Data or other classified information may result in a civil penalty pursuant to subsection a of section 234B of the Atomic Energy Act (42 U.S.C. Section 2282b). The procedures for the assessment of civil penalties are set forth in Title 10, Code of Federal Regulations (CFR), Part 824, Procedural Rules for the Assessment of Civil Penalties for Classified Information Security Violations. c. Equivalencies/Exemptions for DOE O 470.4B. Equivalencies and exemptions

Section 2

from the requirements of this Order are processed in accordance with DOE O 251.1C, Departmental Directives Program. When conditions warrant equivalencies or exemptions from the requirements in this Order, requests must be supported by a vulnerability assessment (VA) when required by the assets being protected, or by sufficient analysis to form the basis for an informed risk management decision; the analysis must identify compensatory measures, if applicable, or alternative controls to be implemented. All approved equivalencies and exemptions under this Order must be entered in the Safeguards and Security Information Management System (SSIMS) database and incorporated into the affected security plan(s). Approved equivalencies and exemptions become a valid basis for operation when they have been entered in SSIMS and documented in the appropriate security plan, and must be incorporated into site procedures at that time. Many DOE S&S Program requirements are found in or based on regulations issued by Federal agencies, and codified in the CFR or other authorities, such as Executive Orders or Presidential Directives. In such cases, the process for deviating from those requirements found in the source document must be applied. If the source document does not include a deviation process, the DOE Office of the General Counsel, or NNSA Office of General Counsel if an NNSA element is involved, must be consulted to determine whether deviation from the source can be legally pursued. (1) Equivalency. In accordance with the responsibilities and authorities assigned by E.O. 12344, codified at 50 U.S.C. Sections 2406 and 2511 and to ensure consistency through the joint Navy/DOE Naval Nuclear Propulsion Program, the Deputy Administrator for Naval Reactors (Director) will implement and oversee requirements and practices pertaining to this Directive for activities under the Director’s cognizance, as deemed appropriate. DOE O 470.4B 3 7-21-11 (2) Exemption. Requirements in this Order that overlap or duplicate requirements of the Nuclear Regulatory Commission (NRC) related to radiation protection, nuclear safety (including quality assurance), and safeguards and security of nuclear material, do not apply to the design, construction, operation, and decommissioning of the facilities of the former Office of Civilian Radioactive Waste Management (RW) now managed by the Office of Nuclear Energy. This exemption does not apply to requirements for which the NRC defers to DOE or does not exercise regulatory jurisdiction. 4. REQUIREMENTS. a. S&S programs must be developed and maintained that incorporate the responsibilities and requirements contained in this Order and its associated appendices and attachments. b. Programs associated with each topical area found in the appendices and attachments to this Order must be implemented in accordance with the requirements stated for that topic. c. The DOE Tactical Doctrine (Attachment 4) must be applied at facilities/sites possessing nuclear weapons and components, Category I special nuclear material (SNM), or targets subject to radiological or toxicological sabotage. d. Incidents of security concern must be addressed in accordance with the requirements found in Attachment 5 and reported in accordance with applicable laws and regulations. e. Interfaces and necessary interactions between S&S programs and other disciplines such as safety, emergency management, classification, counterintelligence,

Section 3

facility operations, cyber system operations and security, and business and budget operations including property management must be identified and clearly defined. These interfaces and interactions must be maintained throughout the lifecycle of protective measures to ensure that S&S planning and operations work together effectively with these disciplines. Sensitive Compartmented Information is under the purview of the Office of Intelligence and Counterintelligence; necessary interfaces and interactions between that office and S&S programs must also be identified, defined, and maintained f. S&S programs must incorporate a risk-based approach to protect assets and activities against the consequences of attempted theft, diversion, terrorist attack, industrial sabotage, radiological sabotage, chemical sabotage, biological sabotage, espionage, unauthorized access, compromise, and other acts that may have an adverse impact on national security or the environment or that may pose significant danger to the health and safety of DOE Federal and contractor employees or the public. 4 DOE O 470.4B 7-21-11 g. S&S programs must be tailored to address site-specific characteristics and requirements, current technology, ongoing programs, and operational needs to achieve acceptable protection levels that reduce risks in a cost-effective manner. 5. RESPONSIBILITIES. a. Secretary of Energy. (1) Ensures that an effective S&S Program is established and executed within DOE under the authorities granted by relevant Executive Orders; the U.S. Department of Energy Organization Act, as amended (42 U.S.C. Sections 7101 to 7352); and the Atomic Energy Act, as amended (42 U.S.C. Sections 2011 to 2286), and in accordance with P.L. 106-65, the National Nuclear Security Administration Act. (2) Designates senior Departmental officials to direct and administer the S&S Program. (3) Delegates, in writing, all responsibilities and authorities as necessary for the administration of the S&S Program. (4) Authorizes continuing operations of facilities/activities determined to be of high security risk. (5) Exercises sole authority to approve the imposition of requirements on Civilian Radioactive Waste Management programs and activities that are more stringent and/or comprehensive than those imposed by the NRC. (6) Designates the DOE program elements responsible for ensuring that foreign nationals’ visits requiring access to classified information are conducted in accordance with governing international agreements or treaties. b. Deputy Secretary. (1) Exercises responsibility, as Chief Operating Officer of the Department, for S&S policy development and operations. (2) Ensures that the S&S Program achieves excellence in performance, has internal compatibility, is graded in application, and integrates corporate programs and support activities with line programs consistent with the precepts of Integrated S&S Management. (3) Reviews all staff and support office S&S policies that affect Departmental elements. DOE O 470.4B 5 7-21-11 (4) Establishes the Department-wide base Security Conditions (SECON) level in consultation with the Under Secretaries; the Director, Office of Intelligence and Counterintelligence; and the Chief Health, Safety, and Security. (5) In accordance with 50 U.S.C. Section 2656, ensures that the Committees on Armed Services of the U.S. House of Representatives and the U.S.

Section 4

Senate are notified of each significant nuclear defense intelligence loss. (6) Approves and issues the Graded Security Protection (GSP) Policy. c. Under Secretary for Nuclear Security/ Administrator for the National Nuclear Security Administration. (1) Responsible for the management and implementation of S&S programs administered by NNSA. (2) Authorizes continuing operations of NNSA facilities/activities determined to be of moderate security risk. (3) In coordination with the Under Secretaries, the Office of Intelligence and Counterintelligence, and the Chief Health, Safety and Security Officer, provides recommendations on SECON levels to the Deputy Secretary. (4) Through the Associate Administrator for Emergency Operations, monitors the SECON level for the Department and for all DOE facilities and sites. (5) Through the Deputy Administrator for Defense Programs: (a) Ensures that all visits by foreign nationals and access to classified information in connection with the military application of atomic energy under 42 U.S.C. Section 2164 and 42 U.S.C. Section 2121 are conducted in accordance with governing international agreements or treaties. (b) Approves requests for classified visits and access to weapons programs, nuclear materials production facilities, sensitive nuclear materials production information, and classified information pertaining to Nuclear Weapons Data. (c) Delegates in writing to a senior Federal official at each site under NNSA cognizance the authority to make, in connection with classified visits, an affirmative determination that permitting a U.S. citizen holding a clearance granted by another Federal agency to have access to Restricted Data will not endanger the common defense and security prior to granting such access in connection with a specific classified visit. 6 DOE O 470.4B 7-21-11 (6) Through the Deputy Administrator for Defense Nuclear Nonproliferation, ensures that all foreign national visits and access to classified information in connection with nonproliferation, international security, or International Atomic Energy Agency requirements are conducted in accordance with governing international agreements or treaties. (7) Through the Deputy Administrator for Naval Reactors: (a) Ensures that all foreign national visits and access to classified information in connection with naval nuclear propulsion are conducted in accordance with governing international agreements or treaties. (b) Approves requests for classified visits and access to naval nuclear propulsion facilities. (8) Through the Associate Administrator for Defense Nuclear Security: (a) Serves as the DOE cognizant security officer responsible for the development and implementation of security programs, operations, and facilities under the purview of NNSA. (b) Delegates authority to serve as the cognizant security office in writing as appropriate to subordinate NNSA line managers; delegations must be reflected in the affected facility/site security plans. (c) Issues direction for and oversees implementation of SECON levels for operations under the cognizance of NNSA. (d) Acts as senior NNSA official responsible for the direction and administration of the NNSA implementation and compliance with the National Industrial Security Program. (e) Establishes procedures for reporting incidents of security concern, and provides resources for conducting inquiries and damage assessments and for implementing corrective actions.

Section 5

(f) Directs the implementation of S&S programs in accordance with the requirements of this Order, including development of procedures and guidance on how to apply the requirements of the Order and its appendices and attachments at NNSA facilities and sites. (g) Acts as the senior NNSA official responsible for all classified visits except for those assigned in Section 5c(5)(b) above to the Deputy Administrator for Defense Programs; delegates in writing DOE O 470.4B 7 7-21-11 to a senior Federal official at each site under NNSA cognizance the authority to make, in connection with such classified visits, an affirmative determination that permitting a U.S. citizen holding a clearance granted by another Federal agency to have access to Restricted Data will not endanger the common defense and security prior to granting such access in connection with a specific classified visit. (h) Ensures that facility and/or site defensive plans for the protection of nuclear weapons and components, Category I SNM, or targets subject to radiological or toxicological sabotage are developed in accordance with the DOE Tactical Doctrine. (i) Implements the DOE North Atlantic Treaty Organization (NATO) program for DOE and NNSA including access authorizations, policy, operations of the DOE Sub-Registry, and the conduct of DOE domestic inspections. d. Under Secretary for Science. (1) Responsible for management and implementation of S&S programs administered by the DOE Office of Science. (2) Serves as the DOE cognizant security officer responsible for the development and implementation of security programs, operations, and facilities under the purview of the Office of Science. (3) Delegates authority to serve as the cognizant security office in writing as appropriate to subordinate line management within the Office of Science; delegations must be reflected in the affected facility/site security plans. (4) In coordination with the Under Secretary for Energy, the NNSA Administrator, the Office of Intelligence and Counterintelligence, and the Chief Health, Safety and Security Officer, provides recommendations on SECON levels to the Deputy Secretary. (5) Issues direction for and oversees the implementation of SECON levels for operations under the cognizance of the Office of Science. (6) Directs the implementation of S&S programs in accordance with the requirements of this Order, including development of procedures and guidance on how to apply the requirements of the Order and its appendices and attachments at facilities and sites under the cognizance of the Office of Science. 8 DOE O 470.4B 7-21-11 (7) Establishes procedures for reporting incidents of security concern and provides resources for conducting inquiries and damage assessments and for implementing corrective actions. (8) Authorizes continuing operations of Office of Science facilities/activities determined to be of moderate security risk. (9) Ensures that facility and/or site defensive plans for the protection of nuclear weapons and components, Category I SNM, or targets subject to radiological or toxicological sabotage are developed in accordance with the DOE Tactical Doctrine. (10) Delegates in writing to a senior Federal official at each site under his/her cognizance the authority to make, in connection with classified visits, an affirmative determination that permitting a U.S. citizen holding a clearance granted by another Federal agency to have access to Restricted

Section 6

Data will not endanger the common defense and security prior to granting such access in connection with a specific classified visit. e. Under Secretary for Energy. (1) Responsible for management and implementation of S&S programs administered by the DOE Offices of Energy Efficiency and Renewable Energy, Environmental Management, Electricity Delivery and Energy Reliability, Fossil Energy, Nuclear Energy, and Legacy Management. (2) Serves as the DOE cognizant security office responsible for the development and implementation of security programs, operations and facilities under the purview of the Offices in paragraph (1). (3) Delegates authority to serve as the cognizant security office in writing as appropriate to subordinate line management within the Departmental Offices in paragraph (1); delegations must be reflected in the affected facility/site security plans. (4) In coordination with the Under Secretary for Science, the NNSA Administrator, the Office of Intelligence and Counterintelligence, and the Chief Health, Safety and Security Officer, provides recommendations on SECON levels to the Deputy Secretary. (5) Issues direction for and oversees the implementation of SECON levels for operations under the cognizance of the Departmental Offices in paragraph (1). (6) Directs the implementation of S&S programs in accordance with the requirements of this Order, including development of procedures and guidance on how to apply the requirements of the Order and its appendices DOE O 470.4B 9 7-21-11 and attachments at facilities and sites under the cognizance of the Offices in paragraph (1). (7) Establishes procedures for reporting incidents of security concern, and provides resources for conducting inquiries and damage assessments and for implementing corrective actions. (8) Authorizes continuing operations of facilities/activities under the cognizance of the Departmental Offices in paragraph (1) determined to be of moderate security risk. (9) Ensures that facility and/or site defensive plans for the protection of nuclear weapons and components, Category I SNM, or targets subject to radiological or toxicological sabotage are developed in accordance with the DOE Tactical Doctrine. (10) Through the Assistant Secretary for Nuclear Energy: (a) Ensures that visits by foreign nationals to uranium enrichment plants or facilities and access to classified information on uranium enrichment technology development, including advanced isotope separation technology, are conducted in accordance with governing international agreements or treaties. (b) Approves requests for classified visits and access to uranium enrichment plants or facilities engaged in uranium enrichment technology development, including advanced isotope separation technology. (11) Delegates in writing to a senior Federal official at each site under his/her cognizance the authority to make, in connection with classified visits, an affirmative determination that permitting a U.S. citizen holding a clearance granted by another Federal agency to have access to Restricted Data will not endanger the common defense and security prior to granting such access in connection with a specific classified visit. f. Heads of Field Elements and Headquarters Departmental Elements. (1) Oversee the development of S&S plans that describe S&S policy implementation in accordance with the requirements in this Order and its

Section 7

appendices and attachments and include detailed information on the assignment of roles, responsibilities, delegations, authorities, and development of budgets and allocation of resources. (2) Oversee the development of S&S implementation procedures and guidance for programs described in this Order and its appendices and 10 DOE O 470.4B 7-21-11 attachments, implement the programs, and provide oversight and technical direction for the programs. (3) Develop and allocate S&S budgets for assigned programs including budgets for the infrastructure that supports S&S missions. (4) Ensure that line management implements the applicable provisions of programs described in this Order and its appendices and attachments. (5) Notify contracting officers of affected contracts that must include the CRD and attachments to this Order. (6) Ensure that procurement requests for new contracts require inclusion of appropriate language, including the clause at 48 CFR Section 952.204-2, Security, and the CRD and attachments to this Order in the resulting contracts, when applicable. (7) Ensure that contracting officers provide DOE F 470.1, Contract Security Classification Specification (CSCS), to the DOE cognizant security offices or their designees. (8) Curtail or suspend operations at facilities/sites under their cognizance when continued operations would result in an unacceptable risk to national security and/or to the health and safety of DOE and contractor employees, the public, or the environment. (9) Ensure that the authorized SECON levels are implemented at facilities/sites under their cognizance and that any local changes at affected facilities are reported to the Operations Center, Office of Emergency Operations. (10) Ensure that S&S personnel under their cognizance are managed, trained, and equipped and are provided with the resources and support services needed to maintain protection of S&S interests. (11) Ensure that contractors and subcontractors under their cognizance implement the provisions of the CRD and attachments to this Order when the CRD is incorporated in their contracts. (12) Ensure that line management at sites under their cognizance has been delegated the authority for oversight and monitoring of contractor performance of the requirements contained in the CRD and its attachments, and that appropriate oversight and monitoring activities are conducted, including a process to validate established objectives, standards, and criteria for security training programs conducted by organizations other than the National Training Center. DOE O 470.4B 11 7-21-11 (13) Ensure that a senior Federal official at each site under their cognizance has been delegated in writing the authority to make, in connection with classified visits, an affirmative determination that permitting a U.S. citizen holding a clearance granted by another Federal agency to have access to Restricted Data will not endanger the common defense and security prior to granting such access in connection with a specific classified visit. g. Chief Health, Safety, and Security Officer. (1) Develops the Department’s S&S Program consistent with strategies and policies governing the protection of national security and other critical assets entrusted to the Department and in accordance with laws, regulations, and national-level policies and standards. (2) Coordinates and promulgates the Department’s policies and procedures for

Section 8

a comprehensive S&S Program. (3) In coordination with the Under Secretaries, the NNSA Administrator, and the Office of Intelligence and Counterintelligence, provides recommendations on SECON levels to the Deputy Secretary. (4) Directs the development and implementation of a security program for the protection of the DOE Headquarters, its personnel, and its assets; serves as the DOE cognizant security officer for DOE Headquarters facilities, and delegates this authority in writing as appropriate. (5) Oversees implementation of the DOE Headquarters S&S Program, including the development of S&S implementation procedures and guidance for programs described in this Order and its appendices and attachments, to include the approval of Headquarters equivalencies and exemptions; provides oversight and technical direction for all DOE offices located in Headquarters facilities. (6) Ensures that the authorized SECON levels are implemented for operations under the cognizance of the Office of Health, Safety and Security. (7) Provides advice and assistance to DOE organizations concerning S&S programs described in this Order and its appendices and attachments. (8) Implements the procedures for the assessment of civil penalties set forth in 10 CFR Part 824, Procedural Rules for the Assessment of Civil Penalties for Classified Information Security Violations. (9) Serves as the executive agent responsible for the development of the GSP, ensures that the GSP is periodically reviewed and updated, staffs and obtains approval for the GSP through the offices of the Under Secretaries, and recommends action to approve the GSP to the Deputy Secretary. 12 DOE O 470.4B 7-21-11 (10) Reviews procurement requests for new HSS Headquarters contracts and ensures that the provisions of 48 CFR Section 952.204-2, Security, and the requirements of the CRD and its attachments in this Order are included in the contracts when required. (11) Through the HSS Deputy Chief for Operations: (a) Formulates and promulgates Departmental S&S policy. (b) Acts as the senior Agency official responsible for directing and administering the DOE’s implementation of E.O. 12829, National Industrial Security Program, Section 203(a). (c) Maintains national-level liaison with Federal law enforcement, security, and intelligence agencies in support of the DOE S&S Program; and represents DOE in interagency efforts related to S&S activities. (d) Develops S&S training programs, and provides S&S training to Departmental personnel, primarily through the National Training Center. h. Director, Office of Intelligence and Counterintelligence. (1) Ensures that information developed through intelligence/ counterintelligence program activities that affects S&S operations is shared with HSS and NNSA. (2) Notifies the DOE/NNSA cognizant security office of security incidents during the course of intelligence/counterintelligence activities. This notification will be upon discovery unless such notification would severely impede or negate intelligence activities or counterintelligence investigations, or further compromise classified/sensitive information. (3) Ensures coordination with cognizant security offices, as appropriate, concerning security issues and other matters of mutual concern for inclusion in security awareness activities and develops and conducts briefings to present information on intelligence and counterintelligence

Section 9

issues. Such briefings may be in conjunction with security awareness briefings. (4) Ensures that all foreign national visits and access to classified information in connection with Sensitive Compartmented Information (SCI) are conducted in accordance with governing international agreements or treaties. DOE O 470.4B 13 7-21-11 (5) Ensures that information on relevant intelligence/counterintelligence concerns is provided to Departmental elements responsible for classified visits by non-U.S. citizens under international agreements and treaties and to individuals responsible for hosting classified visits by non-U.S. citizens to DOE facilities and sites. (6) In coordination with the Under Secretaries, the NNSA Administrator, and the Office of Intelligence and Counterintelligence, provides recommendations on SECON levels to the Deputy Secretary. (7) Issues direction for and oversees the implementation of SECON levels for operations under the cognizance of the Office of Intelligence and Counterintelligence. i. General Counsel, Office of the General Counsel. Provides legal advice and assistance to HSS regarding issues or changes in laws and regulations that may affect S&S interests and programs. j. Contracting Officers. (1) Upon notification by a DOE/NNSA line management official initiating a procurement activity, incorporate CRDs into affected contracts as appropriate. (2) Assist originators of procurement requests who want to incorporate the provisions of 48 CFR Part 952.204-2, Security, and appropriate CRDs in new contracts. (3) Provide written notification to DOE/NNSA cognizant security offices in accordance with Appendix B, Section 2, of this Order when contractual changes impacting a company’s foreign ownership, control, or influence occur. k. DOE Cognizant Security Offices. Responsibilities of the designated DOE cognizant security offices applicable to each topical area are found in the appendices. 6. REFERENCES. The following general references apply to this Order. Additional references applicable to each topical area in the appendices and attachments are listed under that topic for ease of identification. Complete reference information and links to the most current official version of each document or successor documents are available through the S&S Policy Information Resource (PIR) tool at http://pir.pnl.gov/. a. 42 U.S.C. Sections 2011 to 2296, Atomic Energy Act of 1954, as amended. Establishes authorities and programs related to atomic energy, including programs for Federal control of the possession, use, and production of nuclear energy and SNM whether owned by the U.S. Government or others. http://pir.pnl.gov/ 14 DOE O 470.4B 7-21-11 b. 42 U.S.C. Sections 7101 to 7352, Department of Energy Organization Act, as amended. Establishes DOE and its basic authorities and responsibilities, including the responsibility of the Secretary of Energy for developing and promulgating DOE security policies. c. 10 CFR Part 824, Procedural Rules for the Assessment of Civil Penalties for Classified Information Security Violations. Establishes rules to assess a penalty against contractors for violation of a directive relating to the protection of classified information. d. 10 CFR Part 1016, Safeguarding of Restricted Data. Establishes requirements for granting facility security approval to an access permittee. e. 10 CFR Part 1045, Nuclear Classification and Declassification. Establishes the

Section 10

program for managing, identifying, generating, reviewing, and declassifying Restricted Data and Formerly Restricted Data, and the sanctions for violations of the procedures. f. 32 CFR Chapter XX, Information Security Oversight Office, National Archives and Records Administration. Establishes implementation requirements and procedures for classified national security information and the National Industrial Security Program. g. 48 CFR Chapter 9, Department of Energy Acquisition Regulation. Supplements 48 CFR Chapter 1, Federal Acquisition Regulation, and includes the security provisions and clauses to be used in DOE solicitations and contracts when a facility security clearance and/or access to classified information will be necessary for the performance of the contract. h. E.O. 12829, National Industrial Security Program, dated 01-26-93. Establishes the National Industrial Security Program to protect classified information released by Federal agencies to their contractors. i. E.O. 13526, Classified National Security Information, dated 12-29-09. Establishes the requirements for protection of classified information. j. DOE P 226.1B, Department of Energy Oversight Policy, dated 4-25-11. Establishes a Department-wide oversight process to protect the public, workers, environment, and national security assets effectively through continuous improvement. k. DOE O 226.1B, Implementation of Department of Energy Oversight Policy, dated 4-25-11. Implements the policy that establishes a Department-wide oversight process to protect the public, workers, environment, and national security assets. DOE O 470.4B 15 7-21-11 l. DOE O 414.1D, Quality Assurance, dated 4-25-11, which ensures that the quality of DOE/NNSA products and services meets or exceeds the customers’ requirements and expectations. m. DOE O 475.2A, Identifying Classified Information, dated 2-1-11. Establishes the program to identify information classified under the Atomic Energy Act or E.O. 13526 so that it can be protected against unauthorized disclosures. n. DOE Order 475.1, Counterintelligence Program, dated 10-04-04, establishes the Counterintelligence (CI) Program requirements and responsibilities for the Department of Energy (DOE), including the National Nuclear Security Administration (NNSA), pursuant to Executive Order 12333 in order to detect and deter insiders who engage in activities on behalf of a foreign intelligence service or international terrorist entity. o. DOE Order 243.1, Records Management Program, dated 2-3-06, which sets forth requirements and responsibilities for implementing and maintaining a cost- effective records management program throughout the Department of Energy. p. 36 CFR Chapter XII, Subchapter B, Records Management. Establishes requirements for the creation, maintenance, and disposition of Federal records and penalties for unlawful or accidental removal, alteration, or destruction of records. q. Homeland Security Presidential Directive-7, Critical Infrastructure Identification, Prioritization, and Protection, dated 12-17-03, which establishes a national policy for Federal departments and agencies to identify and prioritize United States critical infrastructure and key resources and to protect them from terrorist attacks. 7. DEFINITIONS. a. Cognizant security office means the office assigned responsibility for a given security program or function. Where DOE cognizant security office is stated, the

Section 11

reference is to a Federal activity. b. Definitions applicable to each topical area are found in the appendices and attachments. Definitions for terms used in a general S&S context are available through the Safeguards and Security Policy Information Resource (PIR) tool at http://pir.pnl.gov/. http://pir.pnl.gov/ 16 DOE O 470.4B 7-21-11 8. CONTACT. Questions concerning this Order should be addressed to the Office of Security Policy, Office of Health, Safety and Security at 301-903-4642. BY ORDER OF THE SECRETARY OF ENERGY: DANIEL B. PONEMAN Deputy Secretary DOE O 470.4B 17 7-21-11 TABLE OF CONTENTS Appendix A. Safeguards and Security Program Planning................................................... A-1 Section 1. Safeguards and Security Program Planning ................................................... 1-1 1. Objective ............................................................................................................... 1-1 2. Purpose .................................................................................................................. 1-1 3. Definitions............................................................................................................. 1-1 4. References ............................................................................................................. 1-2 5. Requirements ........................................................................................................ 1-2 Chapter I. Security Plans .............................................................................................. I-1 1. General ................................................................................................................... I-1 2. Security Plan ......................................................................................................... I-2 3. Assessments and Analyses ..................................................................................... I-2 4. Security Plan Components ..................................................................................... I-2 5. Reviews and Updates ............................................................................................. I-3 Chapter II. Security Conditions ................................................................................. II-1 1. General ..................................................................................................................II-1 2. SECON Levels ......................................................................................................II-1 3. SECON Planning ..................................................................................................II-2 4. Establishment of SECON Level ...........................................................................II-2 5. Coordination .........................................................................................................II-2 Chapter III. Performance Assurance ........................................................................III-1 1. General ................................................................................................................ III-1 2. Applicability ....................................................................................................... III-1 3. Performance Assurance Planning ....................................................................... III-1

Section 12

4. Test Schedules .................................................................................................... III-2 5. Results Analysis and Documentation ................................................................. III-2 6. System Degradation ............................................................................................ III-3 7. Reviews and Updates .......................................................................................... III-3 Section 2. Survey, Review, and Self- Assessment Programs ........................................... 2-1 1. Objective ............................................................................................................... 2-1 2. Purpose .................................................................................................................. 2-1 3. Definitions............................................................................................................. 2-1 4. References ............................................................................................................. 2-2 5. Requirements ........................................................................................................ 2-2 6. Surveys .................................................................................................................. 2-3 7. Self-Assessments .................................................................................................. 2-4 8. Reports and Ratings .............................................................................................. 2-4 18 DOE O 470.4B 7-21-11 9. Findings and Corrective Actions .......................................................................... 2-5 10. Documentation .................................................................................................... 2-6 Appendix B. Safeguards and Security Program Management Operations ........................B-1 Section 1. Facility Clearances and Registration of Safeguards and Security Activities.......................................................................................................................... 1-1 1. Objective ............................................................................................................... 1-1 2. Purpose .................................................................................................................. 1-1 3. Facility Definition ................................................................................................. 1-1 4. References ............................................................................................................. 1-1 5. Requirements ........................................................................................................ 1-2 Chapter I. Facility Clearance Program ....................................................................... I-1 1. General ................................................................................................................... I-1 2. Eligibility Requirements ........................................................................................ I-3 Chapter II. Importance Ratings ................................................................................. II-1 1. Facility Importance Ratings ..................................................................................II-1

Section 13

2. Upgrading and Downgrading a Facility’s Assigned Importance Rating ..............II-2 Chapter III. Facility Clearance Approval Requirements .......................................III-1 1. Issuance of FCLs................................................................................................. III-1 2. Contractor Facilities ........................................................................................... III-1 3. Facility Clearances for OGAs ............................................................................. III-1 4. Records .............................................................................................................. III-2 Chapter IV. Interim and Limited Facility Clearances ............................................ IV-1 1. Interim FCLs ....................................................................................................... IV-1 2. Limited FCLs ...................................................................................................... IV-1 Chapter V. Personnel Security Clearances and Exclusion Procedures Required in Connection with Contractor Facility Clearances ................................................. V-1 1. Security Clearances Required in Connection with the FCL ................................ V-1 2. Exclusion Procedures ........................................................................................... V-1 3. Security Clearances Concurrent with the FCL .................................................... V-1 Chapter VI. Facility Clearances Granted by Other Government Agencies.......... VI-1 1. Accepting OGA FCLs......................................................................................... VI-1 2. OGA Verification Requests ................................................................................ VI-3 3. OGA Contractors with no DOE Contracts.......................................................... VI-3 Chapter VII. Documentation and Registration of Facility Clearances and Related Security Activities ................................................................................................ VII-1 DOE O 470.4B 19 7-21-11 1. Documentation of FCLs ..................................................................................... VII-1 2. Registration of Security Activities ..................................................................... VII-1 3. Registering Work for Others (WFO) Activities ................................................. VII-2 4. Exceptions to Registration in SSIMS ................................................................ VII-3 Chapter VIII. Suspensions ...................................................................................... VIII-1 1. Reasons for Suspension ................................................................................... VIII-1 2. Actions ............................................................................................................. VIII-1 3. Non-Compliance with Mitigation Plans .......................................................... VIII-1 4. Continuation of Contract Performance Under Foreign Government Ownership ....................................................................................................... VIII-2 5. Reinstatement of A Suspended FCL ................................................................ VIII-2 Chapter IX. Facility Clearance Termination and Close Out .................................. IX-1

Section 14

1. Contract Closeout/Facility Clearance Termination ............................................ IX-1 2. Reactivation ........................................................................................................ IX-1 Section 2. Foreign Ownership, Control, or Influence Programs .................................... 2-1 1. Objective ............................................................................................................... 2-1 2. Purpose .................................................................................................................. 2-1 3. Definition .............................................................................................................. 2-1 4. References ............................................................................................................. 2-1 5. Requirements ........................................................................................................ 2-2 Chapter I. General FOCI Program Information ........................................................ I-1 1. General ................................................................................................................... I-1 2. Applicability .......................................................................................................... I-2 3. Electronic Submission/Processing Web Site ......................................................... I-2 Chapter II. FOCI Processing ...................................................................................... II-1 1. Determining the Requirements for a FOCI Determination...................................II-1 2. Final FOCI Determinations...................................................................................II-1 3. Adjudication ..........................................................................................................II-1 4. Committee on Foreign Investment in the United States .......................................II-2 5. Contracting Officers..............................................................................................II-2 Chapter III. Changes to FOCI Information .............................................................III-1 1. FOCI Changes that Occur Following Submission of an SF 328 and before Contract Award .................................................................................................. III-1 2. Updates ............................................................................................................... III-1 3. Annual Review and Certification........................................................................ III-2 Chapter IV. FOCI Mitigation .................................................................................... IV-1 20 DOE O 470.4B 7-21-11 1. General ................................................................................................................ IV-1 2. Mitigation Action Plans ...................................................................................... IV-1 3. FOCI Mitigation Instruments .............................................................................. IV-1 4. Noncompliance with Mitigation Plans................................................................ IV-5 Section 3. Safeguards and Security Awareness ................................................................ 3-1

Section 15

1. Objective ............................................................................................................... 3-1 2. Purpose .................................................................................................................. 3-1 3. Definition .............................................................................................................. 3-1 4. References ............................................................................................................. 3-1 5. Requirements ........................................................................................................ 3-2 6. Briefings ................................................................................................................ 3-3 7. Classified Information Nondisclosure Agreement (SF312) ................................. 3-7 8. Supplementary Awareness Activities ................................................................... 3-8 Section 4. Control of Classified Visits ............................................................................... 4-1 1. Objective ............................................................................................................... 4-1 2. Purpose .................................................................................................................. 4-1 3. Definitions............................................................................................................. 4-1 4. References ............................................................................................................. 4-1 5. Requirements ........................................................................................................ 4-2 6. Visits to DOE Facilities by Cleared U.S. Citizens Other than DOE Personnel.... 4-3 7. Visits by Cleared DOE Personnel to Other DOE Facilities .................................. 4-5 8. Classified Visits to DOE Facilities by Non-U.S. Citizens .................................... 4-6 9. Documentation ...................................................................................................... 4-7 Section 5. Safeguards and Security Training Program ................................................... 5-1 1. Objective ............................................................................................................... 5-1 2. Purpose .................................................................................................................. 5-1 3. Definition .............................................................................................................. 5-1 4. References ............................................................................................................. 5-1 5. Requirements ........................................................................................................ 5-1 Section 6. Restrictions on the Transfer of Security-Funded Technologies .................... 6-1 1. Objective ............................................................................................................... 6-1 2. Purpose .................................................................................................................. 6-1 3. References ............................................................................................................. 6-1

Section 16

4. Requirements ........................................................................................................ 6-1 Attachment 1. Contractor Requirements Document DOE O 470.4B, Safeguards and Security Program ......................................................................................................................1 1. Requirements ............................................................................................................1 2. Equivalencies and Exemptions .................................................................................2 3. Definitions.................................................................................................................2 DOE O 470.4B 21 7-21-11 Attachment 2. Contractor Requirements Document Safeguards and Security Program Planning ....................................................................................................................................1 Section 1. Safeguards and Security Program Planning ................................................... 1-1 1. Objective ............................................................................................................... 1-1 2. Purpose .................................................................................................................. 1-1 3. Definitions............................................................................................................. 1-1 4. References ............................................................................................................. 1-2 5. Requirements ........................................................................................................ 1-2 Chapter I. Security Plans .............................................................................................. I-1 1. General ................................................................................................................... I-1 2. Security Plan ......................................................................................................... I-2 3. Assessments and Analyses ..................................................................................... I-2 4. Security Plan Components ..................................................................................... I-2 5. Reviews and Updates ............................................................................................. I-3 Chapter II. Security Conditions ................................................................................. II-1 1. General ..................................................................................................................II-1 2. SECON Levels ......................................................................................................II-1 3. SECON Planning ..................................................................................................II-2 4. Establishment of SECON Level ...........................................................................II-2 5. Coordination .........................................................................................................II-2 Chapter III. Performance Assurance ........................................................................III-1 1. General ................................................................................................................ III-1

Section 17

2. Applicability ....................................................................................................... III-1 3. Performance Assurance Planning ....................................................................... III-1 4. Test Schedules .................................................................................................... III-2 5. Results Analysis and Documentation ................................................................. III-2 6. System Degradation ............................................................................................ III-3 7. Reviews and Updates .......................................................................................... III-3 Section 2. Survey, Review and Self-Assessment Programs ............................................. 2-1 1. Objective ............................................................................................................... 2-1 2. Purpose .................................................................................................................. 2-1 3. Definitions............................................................................................................. 2-1 4. References ............................................................................................................. 2-2 5. Requirements ........................................................................................................ 2-2 6. Surveys .................................................................................................................. 2-3 7. Self-Assessments .................................................................................................. 2-3 8. Findings and Corrective Actions .......................................................................... 2-4 9. Documentation ...................................................................................................... 2-4 22 DOE O 470.4B 7-21-11 Attachment 3. Contractor Requirements Document Safeguards and Security Program Management Operations .........................................................................................................1 Section 1. Facility Clearances and Registration of Safeguards and Security Activities.......................................................................................................................... 1-1 1. Objective ............................................................................................................... 1-1 2. Purpose .................................................................................................................. 1-1 3. Facility Definition ................................................................................................. 1-1 4. References ............................................................................................................. 1-1 5. Requirements ........................................................................................................ 1-2 Chapter I. Facility Clearance Program ....................................................................... I-1 1. General ................................................................................................................... I-1 2. Eligibility Requirements ........................................................................................ I-2

Section 18

Chapter II. Importance Ratings ................................................................................. II-1 1. Facility Importance Ratings ..................................................................................II-1 2. Upgrading and Downgrading a Facility’s Assigned Importance Rating ..............II-2 Chapter III. Facility Clearance Approval Requirements .......................................III-1 1. Issuance of FCLs................................................................................................. III-1 2. Contractor Facilities ............................................................................................ III-1 Chapter IV. Interim and Limited FCLS................................................................... IV-1 1. Interim FCL ........................................................................................................ IV-1 2. Limited FCL........................................................................................................ IV-1 Chapter V. Personnel Security Clearances and Exclusion Procedures Required in Connection with Contractor FCLS ....................................................................... V-1 1. Security Clearances Required in Connection with the FCL ................................ V-1 2. Exclusion Procedures ........................................................................................... V-1 3. Security Clearances Concurrent with the FCL .................................................... V-1 Chapter VI. Reporting Requirements....................................................................... VI-1 1. General ................................................................................................................ VI-1 2. Updates ............................................................................................................... VI-1 3. Other Reportable Changes .................................................................................. VI-4 Chapter VII. Suspensions ......................................................................................... VII-1 1. Reasons for Suspensions .................................................................................... VII-1 2. Actions ............................................................................................................... VII-1 3. Noncompliance with Mitigation Plans............................................................... VII-1 DOE O 470.4B 23 7-21-11 4. Continuation of Contract Performance under Foreign Government Ownership ......................................................................................................... VII-2 5. Reinstatement of a Suspended FCI .................................................................... VII-2 Chapter VIII. Facility Clearance Termination and Close Out............................ VIII-1 1. Contract Closeout/Facility Clearance Termination ......................................... VIII-1 2. Reactivation ..................................................................................................... VIII-2 Section 2. Foreign Ownership, Control, or Influence Program ..................................... 2-1 1. Objective ............................................................................................................... 2-1 2. Purpose .................................................................................................................. 2-1

Section 19

3. Definition .............................................................................................................. 2-1 4. References ............................................................................................................. 2-1 5. Requirements ........................................................................................................ 2-2 Chapter I. General FOCI Program Information ........................................................ I-1 1. General ................................................................................................................... I-1 2. Applicability .......................................................................................................... I-2 3. Electronic Submission/Processing Web Site ......................................................... I-2 4. Committee on Foreign Investment in the United States ........................................ I-3 Chapter II. FOCI Mitigation ...................................................................................... II-1 1. General ..................................................................................................................II-1 2. FOCI Mitigation Instruments ................................................................................II-1 3. Trustees, Proxy Holders, and Outside Directors ...................................................II-5 4. Government Security Committee .........................................................................II-5 5. Technology Control Plan ......................................................................................II-6 Section 3. Safeguards and Security Awareness ................................................................ 3-1 1. Objective ............................................................................................................... 3-1 2. Purpose .................................................................................................................. 3-1 3. Definition .............................................................................................................. 3-1 4. References ............................................................................................................. 3-1 5. Requirements ........................................................................................................ 3-2 6. Briefings ................................................................................................................ 3-3 7. Classified Information Nondisclosure Agreement (SF 312) ................................ 3-7 8. Supplementary Awareness Activities ................................................................... 3-8 Section 4. Control of Classified Visits ............................................................................... 4-1 1. Objective ............................................................................................................... 4-1 2. Purpose .................................................................................................................. 4-1 3. Definitions............................................................................................................. 4-1 4. References ............................................................................................................. 4-1 24 DOE O 470.4B 7-21-11

Section 20

5. Requirements ........................................................................................................ 4-2 6. Visits to DOE Facilities by Cleared U.S. Citizens Other than DOE Personnel.... 4-3 7. Visits by Cleared DOE Personnel to Other DOE Facilities .................................. 4-5 8. Classified Visits to DOE Facilities by Non-U.S. Citizens .................................... 4-5 9. Documentation ...................................................................................................... 4-7 Section 5. Safeguards and Security Training Program ................................................... 5-1 1. Objective ............................................................................................................... 5-1 2. Purpose .................................................................................................................. 5-1 3. Definition .............................................................................................................. 5-1 4. References ............................................................................................................. 5-1 5. Requirements ........................................................................................................ 5-1 Section 6. Restrictions on the Transfer of Security-Funded Technologies .................... 6-1 1. Objective ............................................................................................................... 6-1 2. Purpose .................................................................................................................. 6-1 3. References ............................................................................................................. 6-1 4. Requirements ........................................................................................................ 6-1 Attachment 4. Department of Energy Tactical Doctrine ..........................................................1 1. Introduction ...............................................................................................................1 2. References .................................................................................................................1 3. Tactical Doctrine .......................................................................................................2 4. Management Considerations ...................................................................................10 Attachment 5. Incidents of Security Concern ............................................................................1 1. Objective ...................................................................................................................1 2. Purpose ......................................................................................................................1 3. Definitions.................................................................................................................1 4. References .................................................................................................................3 5. Roles and Responsibilities ........................................................................................5 Section 1. Incident Identification and Reporting Requirements .................................... 1-1 1. General .................................................................................................................. 1-1

Section 21

2. Incident Identification and Categorization ............................................................ 1-1 3. Preliminary Inquiry, Categorization, and Reporting............................................. 1-4 4. Conduct of Inquiries ............................................................................................. 1-8 5. Inquiry Officials .................................................................................................... 1-8 6. Incident Closure .................................................................................................... 1-9 7. Administrative Actions ....................................................................................... 1-10 DOE O 470.4B Appendix A 7-21-11 A-1 APPENDIX A. SAFEGUARDS AND SECURITY PROGRAM PLANNING This appendix establishes the U.S. Department of Energy (DOE) requirements for developing facility and site security plans and for ensuring that plans are current and address the actual operating conditions at the covered location through performance assurance testing and a program of regular periodic surveys. Section 1 addresses planning activities. Section 2 covers activities to be implemented in connection with surveys. DOE O 470.4B Appendix A, Section 1 7-21-11 1-1 SECTION 1. SAFEGUARDS AND SECURITY PROGRAM PLANNING 1. OBJECTIVE. To establish a safeguards and security (S&S) planning approach that will provide facilities and sites with a consistent method for identifying, developing and documenting sound risk mitigation strategies by identifying all critical S&S performance, technical, schedule, and cost elements. 2. PURPOSE. S&S planning activities are conducted to ensure that an S&S plan describing the assumptions and approved operating conditions necessary to protect national security and property assets, as well as the public, DOE employees, and contractor employees, from malevolent actions by adversaries is prepared for each facility and site and approved by an appropriate Federal authority. 3. DEFINITIONS. a. Facility. A facility consists of one or more security interests under a single security management responsibility or authority and a single facility security officer within a defined boundary that encompasses all the security assets at that location. A facility operates under a security plan that allows security management to maintain daily supervision of its operations, including day-to-day observations of the security program. b. Site. A site consists of one or more facilities operating under a centralized security management, including a site security officer with consolidated authority and responsibility for the facilities, and covered by a site security plan that may consolidate or replace, wholly or partially, individual facility plans. c. S&S Interest(s) and/or Assets. A general term for any Departmental resource or property that requires protection from malevolent acts. It includes but is not limited to Federal and contractor personnel; classified information and/or matter; sensitive compartmented information facilities; automated data processing centers; facilities storing, processing, and transmitting classified information and/or matter; vital equipment; special nuclear material (SNM); other nuclear materials; certain radiological chemical or biological materials; sensitive unclassified information; or other Departmental property. d. Essential Elements. Protection and assurance elements necessary for the overall

Section 22

success of the S&S program at a facility or site, the failure of any one of which would result in protection effectiveness being significantly reduced or which would require performance of other elements to be significantly better than expected in order to mitigate the failure. Essential elements can include but are not limited to equipment, procedures, and personnel. Appendix A, Section 1 DOE O 470.4B 1-2 7-21-11 4. REFERENCES. a. DOE P 470.1A, Safeguards and Security Program, dated 12-29-10. b. DOE O 470.3B, Graded Security Protection (GSP) Policy, dated 8-12-08. c. 48 CFR Section 952.204-2, Security, and Section 952.204-73(c), Facility Clearance. d. E.O. 12977, Interagency Security Committee, dated 10-19-95. e. Interagency Security Committee (ISC) Standard, Physical Security Criteria for Federal Facilities. f. ISC Standard, Facility Security Level Determinations for Federal Facilities. g. ISC Report, The Design Basis Threat (DBT). h. DOE-STD 1192-2010, Vulnerability Assessment Standard. i. PDD 39, U.S. Policy on Counterterrorism. j. HSPD 3, Homeland Security Advisory System. k. DoD 5220.22-M, National Industrial Security Program Operating Manual (NISPOM). l. DOE O 150.1, Continuity Programs, dated 5-8-08. m. HSPD-7, Critical Infrastructure Identification, Prioritization, and Protection. 5. REQUIREMENTS. DOE cognizant security offices, as designated by the Program Secretarial Office or, for NNSA, the Office of the Administrator through the Chief, Defense Nuclear Security, are responsible for ensuring that the following security planning activities are accomplished for facilities and sites under their cognizance. a. Ensure that planning activities support the Department’s Strategic Plan, the facility’s/site’s mission, forecasts of significant changes to facility/site operations, and current and projected operational and fiscal constraints. b. Review and approve contractor security plans, establishing a Federally approved authorization for site security operations. c. Ensure that designated Federal approval officials with authority for security plans explicitly accept any residual risk involved in operations under the requirements of approved security plans. DOE O 470.4B Appendix A, Section 1 7-21-11 1-3 d. Ensure that approved security plans continue to accurately describe site/facility S&S procedures and requirements. e. Ensure that site operations are conducted in compliance with approved security plans. f. Monitor progress on completion of implementation plans to ensure that approved actions are completed within the approved time frames. g. Ensure that facilities/sites that possess nuclear weapons and components, Category I SNM, or targets subject to radiological or toxicological sabotage develop and implement defense strategies and Security Incident Response Plans in accordance with the DOE Tactical Doctrine contained in Attachment 4. h. Ensure that assessments of protection effectiveness are conducted at a level of detail and rigor appropriate to the assets and security interests being protected and in accordance with national standards and DOE directives, and ensure that documentation of such analyses are maintained in support of the security plan. i. Provide assurances for safeguarding against loss, theft, diversion, unauthorized access, misuse, or sabotage of radioactive materials and radioactive sealed sources that could adversely affect national security and the health and safety of

Section 23

employees, the public, and the environment in accordance with DOE O 470.3B, Graded Security Protection (GSP) Policy, DOE M 231.1A chg 2, Environment, Safety and Health Reporting Manual, and 10 CFR Part 835, Occupational Radiation Protection, Subpart M and Appendix E. j. Develop Security Condition (SECON) response plans that can be immediately implemented when there is a change in either the Department’s or a specific facility’s/site’s SECON status. DOE O 470.4B Appendix A, Section 1, Chapter I 7-21-11 I-1 CHAPTER I. SECURITY PLANS 1. GENERAL. All facilities and sites under DOE cognizance must have a security plan that reflects the assets, security interests, approved S&S program implementation at that location and any residual risks associated with operation under the security plan. a. DOE site security managers, in consultation with contractor security managers, will determine and define the facilities under their cognizance and how or if a group of facilities will be consolidated into a site. This decision is made locally in order to facilitate the security management at each location. b. For those facilities that do not have security assets (e.g., classified information or matter, SNM, or other assets requiring a facility security clearance (FCL) in accordance with the Facility Clearance section in Appendix B), the security plan must be developed to address the protection of employees and Government- owned or leased property. c. For all U.S. Government owned or leased properties that do not have security assets (e.g., classified information or matter, SNM, or other assets requiring an FCL in accordance with the Facility Clearance section of this directive), but to which DOE Federal employees are assigned, the standards set forth by the ISC under E.O. 12977, Interagency Security Committee, must be used as the baseline for developing the security plan. d. While the ISC standards do not apply to contractor owned or leased facilities in which Federal employees are not routinely assigned, they should be used to establish the basis for planning for the protection of employees and Government- owned or leased property at contractor facilities that do not have security assets (e.g., classified information or matter, SNM, or other assets requiring an FCL in accordance with the Facility Clearance section of this directive). e. Facilities with security interests that require an FCL but that do not fall under the provisions of the Graded Security Protection (GSP) policy must develop security plans that, in addition to the protection of employees and property, address the protection of security interests at that location and meet the requirements in national-level policy and DOE directives for the protection of those interests. Non-possessing facilities must develop a security plan in sufficient detail to address how the contractor will fulfill its responsibilities (reporting requirements, management of employee clearances, etc.) under the Facility Clearance Program. f. For facilities under the cognizance of the Power Marketing Administrations, which do not fall under the provisions of the GSP but must meet specific critical infrastructure requirements, security plans will be developed under locally Appendix A, Section 1, Chapter I DOE O 470.4B I-2 7-21-11 determined field element security levels and will be approved by the Chief Security Officer for each Power Marketing Administration.

Section 24

g. Facilities with security interests to which GSP performance standards or other requirements apply must develop security plans that comply with the requirements in the GSP and incorporate the DOE Tactical Doctrine in addition to complying with the requirements in national-level policy and DOE directives for the protection of any security interests not covered by the GSP performance standards, and in addition to the protection of employees and property. 2. SECURITY PLAN. The security plan is the approved method for conducting security operations at a facility or site and therefore must reflect security operations at that facility or site at all times. The plan must describe in detail, either in its content or in combination with other explicitly referenced documents, all aspects of S&S operations occurring at the location and must include documentation of any deviations from national or DOE requirements. At those locations where management has determined that several facilities can be consolidated into a site, the site security plan may consolidate or replace individual facility security plans in whole or in part but must establish a unified approach to conducting site operations. Security plans must be based on in-depth analysis of considerations specific to the location and the assets and interests to be protected. 3. ASSESSMENTS AND ANALYSES. Security plans must be supported by a sufficient analytical basis to establish that protection requirements will be met if the plan is completely and effectively executed. The analytical basis must include, as applicable, qualitative and quantitative simulations, performance test results, and/or expert analysis that reflect the complexity of facility/site operations and the consequences of loss or unauthorized access or use of the security assets present. When facility/site security assets include Category I (or credible rollup to Category I) SNM, vulnerability assessments (VAs), force-on-force system performance tests, other applicable performance tests, and expert analysis must be used in combination to establish the requirements for specific security measures and equipment, the effectiveness of the proposed security posture, and the requirements for improvements in the protection of Category I SNM documented in the approved security plan(s). Documentation of all such assessment activities should be retained on file to demonstrate how the security plan was developed and evaluated. However, these analyses need not be included or specifically referenced in the approved plan. 4. SECURITY PLAN COMPONENTS. All security plans must include the following: a. A listing and prioritization of the assets and security interests at the facility or site; a description of how the protection program is managed; and a description of how national and DOE S&S requirements are met, including any deviations from requirements; and DOE O 470.4B Appendix A, Section 1, Chapter I 7-21-11 I-3 b. As required, implementation plans for meeting changes in national or DOE policies or other changes (such as the addition or removal of security interests) that may require an extended time frame to implement because of financial or other resource considerations, including an implementation schedule and planned contingency measures in case the requirements cannot be met as scheduled. Implementation plans and contingency measures may be included in the security

Section 25

plan by reference. DOE cognizant security offices must monitor contractors’ implementation plans to ensure that requirements are implemented without unnecessary delays. 5. REVIEWS AND UPDATES. Security plans must be reviewed as required to ensure that the plans are current and reflect the actual operating conditions at the covered location. Changes to approved security plans must be approved by the DOE cognizant security office, and the Federal office may require more frequent reviews or may direct a contractor to review the contractor’s plan at any time. Updates to security plans must be made whenever any of the following conditions apply: a. Changes in baseline security requirements in national-level or DOE policy; b. Changes in facility operators/contractors; c. Changes in assets or security interests; d. Changes in facilities included in a site security plan; e. Changes in the security posture of a facility or site; f. Planned changes to the security program at the facility or site; or g. Changes in operations at a facility or site that require modification to approved security measures. DOE O 470.4B Appendix A, Section 1, Chapter II 7-21-11 II-1 CHAPTER II. SECURITY CONDITIONS 1. GENERAL. DOE SECON levels reflect a multitude of conditions that may adversely impact Departmental and/or facility and site security. SECONs may include terrorist activity, continuity conditions, environmental (fire, chemical, radiological, etc.) and/or severe weather conditions. The day-to-day DOE security readiness state is informed by the Homeland Security National Terrorism Advisory System (NTAS). NTAS alerts are established based on the analysis of a continuous and timely flow of integrated, all-source threat assessments and reporting provided to Executive Branch decision-makers. This chapter details DOE requirements for responding to changes in the NTAS alerts and the Departmental SECON levels. 2. SECON LEVELS. The following are the SECON levels used by DOE to establish the current security readiness state: a. SECON 5, Low Condition. This condition is declared when there is a low risk of terrorist activity, continuity conditions, environmental, and/or severe weather conditions. SECON 5 exists when a minimal SECON concern exists but warrants only a routine security posture. b. SECON 4, Guarded Condition. This condition is declared when there is a general risk of terrorist activity, continuity conditions, environmental, and/or severe weather conditions. SECON 4 applies when there is a broad, non-specific threat of a possible event, the nature and extent of which are unpredictable. All measures selected for use under SECON 4 must be capable of being maintained indefinitely. c. SECON 3, Elevated Condition. SECON 3 is declared when there is a significant risk of terrorist activity, continuity conditions, environmental, and/or severe weather conditions. SECON 3 applies when an increased and more predictable threat against DOE facilities exists. The measures used in SECON 3 must be capable of being maintained for lengthy periods without causing undue hardship, affecting operational capability, or aggravating relations with the local community. d. SECON 2, High Condition. SECON 2 is declared when there is a high risk of terrorist activity, continuity conditions, environmental, and/or severe weather conditions. This condition may apply when an incident occurs or intelligence is

Section 26

received indicating that some form of action against DOE personnel and facilities is imminent. Implementation of measures in this security condition for more than a short period will probably create hardship and affect the routine activities of the facility/site and its personnel. Appendix A, Section 1, Chapter II DOE O 470.4B II-2 7-21-11 e. SECON 1, Severe Condition. This condition reflects a severe risk of terrorist activity, continuity conditions, environmental, and/or severe weather conditions. SECON 1 applies in the immediate area where conditions have occurred that may affect a DOE facility/site or when an attack is initiated on the facility/site. Implementing SECON 1 will create hardship and affect the activities of the location and its personnel. Normally, this condition will be declared as a localized response. 3. SECON PLANNING. Both contractor and Federal site security offices must develop SECON response plans that can be immediately implemented when there is a change in either the Department’s or a specific facility/site’s SECON status. Each facility or site must identify the specific measures that will most efficiently and effectively implement the required increases in readiness at each SECON level. Protection measures listed in HSPD-3 and the DOE SECON Quick Reference tool (http://www.hss.energy.gov/Referencebook/secon.html) may be used to develop response plans, which must describe the specific actions to be taken for each SECON level. SECON response plans must be made a part of the facility or site security plan. 4. ESTABLISHMENT OF SECON LEVEL. a. Departmental SECON Level. Department-wide SECON levels are established by the Deputy Secretary of Energy in consultation with the Under Secretaries, the Director, Office of Intelligence and Counterintelligence, and the Chief Health, Safety and Security Officer. Departmental SECON levels will be determined using existing threat, environmental, COGCON levels as specified in DOE O 150.1, Continuity Programs, and/or other program considerations/factors for Headquarters and field activities. Changes in the COGCON level may require concurrent changes in the SECON level. b. Local SECON Levels. Local SECON levels may differ from the Departmental SECON level and are established by site/facility management with the concurrence of the cognizant Under Secretary or, in the case of DOE Headquarters, the Chief Health, Safety and Security Officer. 5. COORDINATION. If the determination is made that a site/facility SECON level should differ from the Departmental SECON, site/facility management must immediately notify the Operations Center, Office of Emergency Operations, Office of the Associate Administrator for Emergency Operations, NNSA, of the changed condition and keep the Operations Center informed of the status of the facility and the SECON response plan implementation. http://www.hss.energy.gov/Referencebook/secon.html DOE O 470.4B Appendix A, Section 1, Chapter III 7-21-11 III-1 CHAPTER III. PERFORMANCE ASSURANCE 1. GENERAL. An acceptable level of performance must be established and maintained to ensure that all elements of a facility/site protection program are workable and function as designed and in accordance with the overall protection goals established by local facility/site management. A performance assurance program must be developed that identifies the essential elements of the protection program and establishes monitoring and

Section 27

testing activities with sufficient rigor to ensure that the program elements are at all times operational, functioning as intended, and interacting in such a way as to identify and preclude the occurrence of adverse activity before security is irreversibly compromised. The intent of the performance assurance program is not to duplicate monitoring and testing activities conducted under ongoing quality assurance and S&S operations, but to include them in a comprehensive approach to assuring system effectiveness. Implementation activities and schedules for performance assurance plans must be included in the facility or site security plan. 2. APPLICABILITY. All facilities with assets requiring a facility security clearance must conduct performance assurance activities. These activities must be tailored to the assets at the location and the elements that compose the total system in place at the location. At all locations, testing will include at a minimum the following: a. Operability tests to confirm, without any indication of effectiveness, that a system element or total system is operating as expected; and b. Effectiveness tests to provide assurance that essential elements of the system are working as expected, separately or in coordination, to meet protection program objectives. 3. PERFORMANCE ASSURANCE PLANNING. Facilities and sites must implement and maintain a program that ensures that essential elements used to protect DOE S&S interests meet established requirements for reliability, operability, readiness, and performance prior to and during operational use. The assurance plan must: a. Encompass all S&S topical areas relating to Program Management Operations, Physical Protection, Protective Force, Information Security, Personnel Security, and Materials Control and Accountability that are relevant to protection of assets at the facility/site; b. Identify the essential elements relevant to protection of assets at the facility/site; c. Describe how essential elements relevant to the protection of assets were determined; d. Describe how each essential element and the facility/site security program as a whole will be tested, including type of test, evaluation criteria (test objectives and Appendix A, Section 1, Chapter III DOE O 470.4B III-2 7-21-11 performance criteria that define both success and failure), frequency, and number of tests; e. Establish the testing schedule for essential elements and note whether any testing requirements established in other applicable DOE directives are to be integrated with this schedule; f. Describe the process for managing, tracking, and integrating results and addressing any deficiencies identified during the tests; and g. Describe actions that must be initiated in the event of a failure of any essential element or the program as a whole. 4. TEST SCHEDULES. a. Essential elements must be periodically tested to verify their continued functionality, operability, effectiveness, and/or performance. Testing frequency may be based as applicable on manufacturer’s recommendations, consensus standards, facility-/site-specific conditions and operational needs, or other criteria that will ensure program effectiveness. Testing of elements that are not prone to failure and that are not subject to compromise without noticeable tampering, such as walls and fences, is not required as long as it can be documented that tampering

Section 28

with such elements would be detected in time to prevent compromise of overall protection. b. In addition to the testing of essential elements, at least once every 12 months, a comprehensive facility or site threat scenario test must be performed at facilities/sites with Category I special nuclear material (SNM); with identified credible radiological, biological, or chemical sabotage targets; or that have been identified as critical national security facilities/assets to demonstrate overall facility/site S&S system effectiveness. Comprehensive threat scenarios must be consistent with DOE O 470.3B, Graded Security Protection (GSP) Policy. c. Facilities/sites with denial protection strategies must conduct, in addition to the tests noted above, protective force exercises quarterly with a rotational schedule for multiple facilities requiring denial protection strategies. One of these quarterly tests may be combined with the annual comprehensive threat scenario test. 5. RESULTS ANALYSIS AND DOCUMENTATION. Each test must be documented in a test report that includes a narrative description of the testing activity and an analysis of test results. Issues requiring corrective action must be documented and tracked until resolved. When unsatisfactory results of a test indicate that national security and/or the health and safety of facility/site employees or the public is jeopardized, immediate compensatory measures must be taken until the issue is resolved and normal reporting procedures must be followed. DOE O 470.4B Appendix A, Section 1, Chapter III 7-21-11 III-3 6. SYSTEM DEGRADATION. When an essential element is under repair or is in an inoperative or ineffective state, the overall S&S program must be considered to be in a degraded mode until testing confirms that all applicable elements have returned to full operability. The facility or site must implement compensatory measures during such degraded modes adequate to ensure that protection of assets is maintained. 7. REVIEWS AND UPDATES. Performance assurance plans must be reviewed and updated when essential elements are affected due to: a. Changes in facility/site mission, programmatic activities, or S&S interests and/or assets; b. Changes in the operation or physical configuration of a facility or site, such as a building addition; new work processes or systems; construction of fences, roads, buildings, etc.; demolition of buildings; or reconfigurations of fences, roads, etc.; c. Completion of S&S upgrades or downgrades; d. Changes in protection strategy, risk or vulnerability analysis, protective force deployment, or other significant revisions to the applicable security plan; or e. Changes in S&S policies, including DOE Order 470.3B, Graded Security Protection (GSP) Policy. DOE O 470.4B Appendix A, Section 2 7-21-11 2-1 SECTION 2. SURVEY, REVIEW, AND SELF-ASSESSMENT PROGRAMS 1. OBJECTIVE. a. Provide assurance to the Secretary, Departmental Elements, and other government agencies that S&S interests and activities are protected at the required levels. b. Provide DOE line management with the information necessary to make informed decisions regarding the allocation of resources, acceptance of risk, and mitigation of S&S vulnerabilities. 2. PURPOSE. Surveys, self-assessments, and review programs are conducted to ensure that S&S systems and processes at facilities/sites are operating in compliance with

Section 29

Departmental and national-level policies, requirements, and standards for the protection of security assets and interests. These programs provide the means for timely identification and correction of deficiencies and noncompliant conditions to prevent adverse events, and validate the effectiveness of corrective actions implemented to address identified deficiencies. 3. DEFINITIONS. a. Safeguards and Security Survey. An integrated performance and compliance based evaluation of all applicable topics to determine the overall status of the S&S program at a facility or site and to ensure that S&S systems and processes at the location are operating in compliance with Departmental and national-level policies, requirements, and standards. Surveys are conducted or supervised by Federal security personnel. b. Initial Survey. A comprehensive review of the security status at a facility that is a candidate for an FCL, conducted to determine whether the facility in question meets established standards for the protection of the security interests and activities to be covered by the FCL. c. Periodic Survey. A survey conducted for all cleared facilities in accordance with established schedules that covers all applicable topics to meet the objectives of the S&S survey. d. Termination Survey. A survey of a cleared facility conducted to verify the termination of Departmental activities and the appropriate disposition of S&S interests at that facility. The termination survey confirms that all S&S activities have been terminated or awarded to another contractor, that access authorizations have been properly terminated or dispositioned, and that no DOE property, classified information or matter, and nuclear and other hazardous material presenting a potential radiological or toxicological sabotage threat remains. Appendix A, Section 2 DOE O 470.4B 2-2 7-21-11 e. Self-Assessment. An internal integrated evaluation of all applicable S&S topical areas at a contractor facility or site, conducted by contractor security personnel at intervals consistent with risk management principles, to determine the overall status of the S&S program at that location and verify that S&S objectives are met. The DOE cognizant security office may direct a specific self-assessment interval and may direct that self assessment reports be provided to DOE. f. Finding. A factual statement of identified issues and deficiencies (failure to meet a documented legal, regulatory, performance, compliance, or other applicable requirement) in the S&S program at a facility, resulting from an inspection, survey, self-assessment, or any other S&S review activity. 4. REFERENCES. a. E.O. 13526, Classified National Security Information, dated 12-29-09. b. E.O. 12829, National Industrial Security Program, dated 01-26-93. c. DoD 5220.22-R, Industrial Security Regulation. d. DoD 5220.22-M, National Industrial Security Program Operating Manual (NISPOM). e. DoD Defense Security Service (DSS) Industrial Security Letters (ISLs), available at http://www.dss.mil/isp/fac_clear/download_nispom.html (Note: ISLs do not automatically impose requirements, but may contain useful clarifications of existing NISPOM provisions.). f. 10 CFR Part 1016, Safeguarding of Restricted Data. g. 10 CFR Part 824, Procedural Rules for the Assessment of Civil Penalties for Classified Information Security Violations. h. 32 CFR Part 2001, Classified National Security Information.

Section 30

i. 48 CFR Chapter 9, Department of Energy Acquisition Regulation. j. DOE P 226.1B, Department of Energy Oversight Policy, dated 4-25-11. k. DOE O 226.1B, Implementation of Department of Energy Oversight Policy, dated 4-25-11. l. DOE O 475.1, Counterintelligence Program, dated 10-04-04. 5. REQUIREMENTS. DOE cognizant security offices, as designated by the Program Secretarial Office, or for NNSA, the Office of the Administrator through the Chief, Defense Nuclear Security, are responsible for ensuring that the following activities are http://www.dss.mil/isp/fac_clear/download_nispom.html DOE O 470.4B Appendix A, Section 2 7-21-11 2-3 accomplished for the surveys and self-assessments program for facilities and sites under their cognizance and for ensuring that contractors under their cognizance accomplish their responsibilities under this program at contractor facilities. Procedures applicable to the surveys and self-assessments program must be documented in facility or site security plans. Identified interfaces and integration with the contractor assurance system must also be documented in facility or site security plans. a. Establish and maintain a schedule for conducting surveys in accordance with applicable national and DOE policy standards. b. Ensure that surveys are conducted as scheduled and/or as required for security activities such as the granting or termination of an FCL. c. Ensure that contractors issued an FCL review their security programs on a continuing basis and conduct formal self-assessments at intervals consistent with risk management principles. d. Ensure that contractors under their cognizance prepare formal reports of self- assessments and related findings and corrective actions. e. Advise contractors under their cognizance of the appropriateness of the self- assessment and its expected coverage and use. f. Provide an evaluation of contractor self-assessment processes and recommend changes as necessary to ensure that DOE objectives are met. g. Ensure that both surveys and contractor self-assessments evaluate all S&S topics relating to Program Management Operations, Physical Protection, Protective Force, Information Security, Personnel Security, and Materials Control and Accountability that are applicable at the facility/site being surveyed. h. Ensure that all findings identified during surveys and self-assessments are tracked until the issues are resolved. i. Ensure that the results of surveys are reported in the DOE Safeguards and Security Information Management System (SSIMS). j. Ensure that corrective actions for issues identified in surveys and self-assessments are implemented in a timely and effective manner, and validate the effectiveness of corrective actions to prevent recurrence of the issues. 6. SURVEYS. Surveys are conducted to confirm that a Federal or contractor facility meets all security requirements appropriate to the activities conducted at that facility, to inform Federal line management of the effectiveness of the facility security program, to identify any issues or concerns with the security program so that these can be addressed and corrected, and to allow both contractor and Federal managers to manage risk in an informed and rational manner. Appendix A, Section 2 DOE O 470.4B 2-4 7-21-11 a. Initial Surveys. A favorable survey is required as one of the conditions for granting a facility security clearance. This initial survey must be completed not

Section 31

more than 6 months prior to the granting of the FCL if the facility will possess classified information or matter or SNM, or will have a facility importance rating of “PP”. b. Periodic Surveys. Periodic surveys must be conducted for all cleared facilities to ensure that S&S measures employed by the facility are adequate for the protection of security assets and interests. The National Industrial Security Program specifies that surveys of contractor facilities will be conducted not more often than once every 12 months unless special circumstances exist. 32 CFR Part 2001.60 establishes a requirement for an annual survey specifically for the assessment of activities related to classified information. At the discretion of the DOE cognizant security office, other topics may be combined with this requirement to meet the periodic survey requirement. For facilities which do not have classified interests or SNM, the frequency of the periodic survey may be established consistent with risk management principles and documented in the applicable security plan with a description of the reasons for the schedule (e.g., good performance on past surveys and self-assessments, regular satisfactory performance assurance testing, non-possessing facilities, etc.). c. Termination Surveys. When a contract for which an FCL has been granted is terminated or otherwise ended (e.g., suspended), a termination survey must be conducted to verify the termination of security activities and the appropriate disposition of S&S interests. Examples of survey activities include: the appropriate disposition, destruction, or return of classified information or matter, SNM, hazardous material, or property; the signing of a certificate of possession if classified is to be retained by the contractor for the allowable period; security badge retrieval; verification of debriefings or verification of the transfer of access authorizations to other DOE interests. Surveys must be conducted onsite at facilities possessing Top Secret classified information or matter, Restricted Data, Sensitive Compartmented Information or special access program information or matter, or SNM. For all other facilities, termination surveys may be conducted either onsite or through any other means established by the cognizant security office. 7. SELF-ASSESSMENTS. Self-assessments are conducted by contractors at their facilities to ensure that at any point the facility is in compliance with all security requirements appropriate to the activities, information, and conditions at the location. Assessments are conducted at intervals consistent with risk management principles and/or as directed by the DOE cognizant security office, and reports are provided to that office. Federal facilities are not required to conduct self-assessments in addition to surveys under this Order. 8. REPORTS AND RATINGS. For each rated area, the survey report must contain a description of each element reviewed, how the review was conducted including any DOE O 470.4B Appendix A, Section 2 7-21-11 2-5 samples and tests used in the evaluation, a summary of the observations made, and an analysis of the results that support the ratings awarded. Ratings must be based upon the effectiveness and adequacy of the security programs at the subject facility. The ratings listed below must be used for all surveys, self-assessments, and reviews. When a topic

Section 32

does not apply at a given facility, or if a topic is not rated, the survey report must contain this information. All ratings must be supported and documented with the rating justification and rationale. a. Satisfactory. The element being evaluated meets protection objectives or provides reasonable assurance that protection objectives are being met. b. Marginal. The element being evaluated partially meets protection objectives or provides questionable assurance that protection objectives are being met. c. Unsatisfactory. The element being evaluated does not meet protection objectives or does not provide adequate assurance that protection objectives are being met. 9. FINDINGS AND CORRECTIVE ACTIONS. a. All open S&S findings from any source (previous surveys and assessments; inspections, reviews, and reports by other organizations such as the Government Accountability Office or the Office of the Inspector General; etc.) must be reviewed during surveys to validate the status of corrective actions and to evaluate the impact on the current operation of the facility’s S&S program. Findings closed during the survey period must be reviewed for sustainability of the closing action. b. Findings from all surveys must be documented in the associated report and entered into SSIMS in accordance with guidelines issued by the SSIMS database manager. Findings must be tracked until closed and monitored on an established schedule to ensure that corrective action plans to address the issue are being implemented in a timely and effective manner. Trending assessment activities based on findings must be conducted to establish if findings represent an isolated issue or a systemic problem with a specific topical element or with the S&S program as a whole. c. Corrective action plans must be developed for all open survey findings. For all identified findings, corrective actions must be implemented in a timely and effective manner. The effectiveness of corrective actions must be validated during subsequent surveys to ensure that the action taken has been sufficient to prevent recurrence of the issue that resulted in the finding. Corrective actions must be reported in SSIMS and the current status of the action must be reported in SSIMS until the associated finding is closed. Appendix A, Section 2 DOE O 470.4B 2-6 7-21-11 10. DOCUMENTATION. Reports of surveys, self-assessments, and review activities must be maintained in accordance with DOE Administrative Records Schedule 18, paragraphs 9 and 10. DOE O 470.4B Appendix B 7-21-11 B-1 APPENDIX B. SAFEGUARDS AND SECURITY PROGRAM MANAGEMENT OPERATIONS This appendix establishes the U.S. Department of Energy (DOE) requirements for conducting management activities connected with the operation of cleared facilities within the DOE complex. Section 1 addresses obtaining a facility clearance (FCL) and establishing the safeguards and security (S&S) activities connected with that facility. Section 2 covers the foreign ownership, control, or influence determinations that are necessary to establish and maintain a facility clearance. Section 3 covers security awareness activities, including required personnel briefings. Section 4 addresses the handling of classified visits to and from DOE facilities, including foreign classified visits. Section 5 deals with S&S training to be provided for employees at cleared facilities. Section 6 covers restrictions imposed on the transfer of

Section 33

security funded technologies outside the United States. DOE O 470.4B Appendix B, Section 1 7-21-11 1-1 SECTION 1. FACILITY CLEARANCES AND REGISTRATION OF SAFEGUARDS AND SECURITY ACTIVITIES 1. OBJECTIVE. To ensure that DOE, DOE contractor, and other (Federal) government agency (OGA) facilities and their contractors engaged in DOE activities are eligible for access to, and meet the requirements to possess and secure, classified information or matter or special nuclear material (SNM); and, as applicable, to protect other assets and conduct other security activities on behalf of DOE. 2. PURPOSE. The FCL program regulates DOE approval of a Federal or contractor facility’s eligibility to access, receive, generate, reproduce, store, transmit, or destroy classified information or matter; SNM; other hazardous material presenting a potential radiological, chemical, or biological sabotage threat; and/or DOE property of significant monetary value, exclusive of facilities and land values (hereinafter referred to as security assets and activities). DoD 5220.22-M, National Industrial Security Program Operating Manual (NISPOM), serves as a national standard to establish the baseline requirements for contractor FCLs when contractors are engaged in activities requiring the protection of national security information classified at the Confidential, Secret, or Top Secret level. The NISPOM requirements are incorporated in this directive and are supplemented with requirements for the protection of DOE-specific assets, Restricted Data, SNM, and other security activities not covered by the NISPOM. 3. FACILITY DEFINITION. For purposes of granting and registering an FCL code under this program, an entity (contractor or Federal) and its classified or high value security activities will be registered with one FCL code if the following criteria are met: a. A centrally directed security program is maintained that covers all security activities (i.e., under the same name, single mailing address, single security plan applicable at all locations, and all security matters under single management control). b. The distance between the security activities is such that the contractor or Federal entity is able to maintain daily supervision of its operations, including day-to-day observations of the security program. 4. REFERENCES. a. E.O. 12829, National Industrial Security Program, dated 01-26-93. b. E.O. 13549, Classified National Security Information Program for State, Local, Tribal, and Private Sector Entities, dated 8-18-10. c. 42 U.S.C. Sections 2011 through 2296, Atomic Energy Act of 1954. d. 32 CFR Part 2001, Classified National Security Information. Appendix B, Section 1 DOE O 470.4B 1-2 7-21-11 e. 32 CFR Part 2004, National Industrial Security Program Directive No. 1. f. 10 CFR Part 1016, Safeguarding of Restricted Data. g. 10 CFR Part 1045, Nuclear Classification and Declassification. h. DoD 5220.22-R, Industrial Security Regulation. i. DoD 5220.22-M, National Industrial Security Program Operating Manual (NISPOM). j. DoD Defense Security Service (DSS) Industrial Security Letters (ISLs), available at http://www.dss.mil/isp/fac_clear/download_nispom.html (Note: ISLs do not automatically impose requirements, but may contain useful clarifications of existing NISPOM provisions.) k. Directive-Type Memoranda (DTM) issued by the Office of the Under Secretary of Defense, (e.g., DTM 09-019, “Policy Guidance for Foreign Ownership,

Section 34

Control, or Influence (FOCI” available at http://www.dtic.mil/whs/directives/corres/dir3.html. Note: DTMs, which may be issued periodically on a variety of topics, do not automatically impose requirements, but may contains useful information applicable to existing NISP programs.) l. 10 U.S.C. Section 2536, Award of certain contracts to entities controlled by a foreign government: prohibition. m. 48 CFR Chapter 9, Department of Energy Acquisition Regulation. n. DOE O 475.2A, Identifying Classified Information, dated 2-1-11. 5. REQUIREMENTS. DOE cognizant security offices, as designated by the Program Secretarial Office, or for NNSA, the Office of the Administrator through the Chief, Defense Nuclear Security, are responsible for ensuring that the following activities are accomplished for the FCL program for facilities and sites under their cognizance and for ensuring that contractors under their cognizance accomplish their responsibilities under this program at contractor facilities. Procedures applicable to the FCL program must be documented in facility or site security plans. a. Establish and maintain FCLs by registering, updating, suspending, reinstating, and terminating FCLs and related security activities under their cognizance in accordance with the requirements contained in this Order. b. Ensure that organizations seeking FCLs meet all the eligibility requirements applicable to the type of organization prior to being processed for an FCL. http://www.dss.mil/isp/fac_clear/download_nispom.html http://www.dtic.mil/whs/directives/corres/dir3.html DOE O 470.4B Appendix B, Section 1 7-21-11 1-3 c. Ensure that all items required by the DEAR as the basis for approval of a contractor FCL have been completed and favorably adjudicated/approved prior to granting the final FCL. d. Ensure that accurate facility importance ratings are assigned and that ratings are updated as necessary to reflect changes in security activities. e. Establish and apply procedures to ensure that coordination is accomplished between the FCL and Foreign Ownership, Control, or Influence (FOCI) programs for all contractor FCLs. f. Determine on a case-by-case basis the necessity for branch offices of a multiple- facility organization to be cleared, based upon the performance of security activities. g. Determine the necessity for the corporate tier parent in a parent-subsidiary relationship to be excluded or cleared as a possessing or non-possessing facility. h. Ensure that prime contractors have appropriately implemented provisions pertaining to subcontractors and that all subcontractors are processed for FCLs when required and terminated or transferred to the cognizance of a new management and operations contractor as appropriate. i. Ensure that all key management personnel (KMP) are properly identified, processed for, and granted access authorizations at the appropriate level or are formally excluded from access, duties, and influence that would otherwise cause them to be identified as KMP prior to granting a final FCL. j. Ensure that procedures are in place to verify changes in an organization’s KMP as they occur and that access authorizations are immediately processed for new KMP. k. Receive and evaluate contractor reports of changes that may impact the FCL, and take any necessary action to suspend or terminate the FCL if such action is warranted. l. Notify the appropriate DOE contracting officer, the contractor, and/or the Federal

Section 35

entity applying for or holding an FCL in writing of the level of FCL granted. m. In conjunction with the responsible surveying offices, as identified by DOE Federal management, ensure that the S&S Information Management System (SSIMS) database accurately reflects established facilities, security assets, and activities under their jurisdiction; ensure that updates and changes to such information are recorded in SSIMS immediately; and ensure that accurate forms are submitted for this purpose. Appendix B, Section 1 DOE O 470.4B 1-4 7-21-11 n. When a contract ends and/or an FCL is no longer necessary, complete a termination survey and ensure that appropriate forms are submitted and SSIMS is updated to enact the termination. o. Ensure that upon termination of a contract, all security clearances (access authorizations) connected to the FCL are terminated and all DOE property; classified information; and/or nuclear and other hazardous material presenting a potential radiological, chemical or biological sabotage threat is appropriately reallocated, disposed of, destroyed, or returned to an appropriate DOE or cleared DOE contractor organization. DOE O 470.4B Appendix B, Section 1, Chapter I 7-21-11 I-1 CHAPTER I. FACILITY CLEARANCE PROGRAM 1. GENERAL. a. Facilities Eligible for the FCL Program. (1) An industrial, educational, commercial, or other contractor entity will require an FCL if the terms of a contract awarded under the DEAR include the security activities described in paragraph 2 of Section 1 above. A contractor requiring an FCL must be sponsored by: (a) a Government Contracting Activity (GCA; i.e., a contracting officer); or (b) a cleared contractor acting as the prime contractor for an uncleared subcontractor. A contractor cannot sponsor itself for an FCL. (2) OGAs may be registered as having a DOE FCL when a mission or programmatic need for such an action has been established by DOE line management. Verification of the clearance and security capability of an OGA must be based on a written statement of security assurance from that agency submitted to the DOE cognizant security office. State, local, tribal, and other similar governmental authorities do not have authority to self-certify clearance and security capability for handling classified information; therefore, they must not be registered as OGAs. These entities must be handled in accordance with E.O. 13549, Classified National Security Information Program for State, Local, Tribal, and Private Sector Entities, and its implementing directives. (3) DOE Federal facilities are registered with a facility code under the FCL program and are subject to survey requirements. b. In accordance with the DEAR, section 952.204-2(l), FCLs are required for subcontractors requiring personnel security clearances. The prime contractor is responsible for implementation of the provisions of DoD 5220.22-M, National Industrial Security Program Operating Manual (NISPOM) (Chapter 7, “Subcontracting”), all DOE security requirements for their subcontractors, and for termination of the subcontracts upon completion of activities. Prime contractors must ensure that all subcontracts are terminated if the prime contract is terminated, or for management and operations subcontracts, transferred to the cognizance of the new management and operations contractor as appropriate. c. All company officials who occupy positions with the authority to affect the

Section 36

organization’s policies or practices in security activities conducted under the contract, as determined by the DOE cognizant security office, must be designated Appendix B, Section 1, Chapter I DOE O 470.4B I-2 7-21-11 as KMP. As a minimum, KMP must include the senior management official responsible for all aspects of contract performance and the designated facility security officer (FSO). KMP must be in process for or possess active security clearances in order for a contractor to be eligible for an FCL involving classified information or matter, or SNM. Until all investigative requirements have been completed and final security clearances have been granted to the designated KMP, only an interim facility clearance can be granted. d. In accordance with the DEAR, section 952.204-73(e), a contractor that will not possess or handle classified information or matter, or SNM, at the contractor’s place of business but will require DOE personnel security clearances for the contractor’s employees to perform work at other cleared facilities must be processed for an FCL as a non-possessing facility. Employees of a non- possessing contractor must adhere to the security plans of the facilities where they are afforded access to classified information or matter, or SNM. e. A self-employed individual not doing business as a company, or a consultant who will not retain classified information or matter at his/her place of business, does not require an FCL provided the individual or consultant is the sole employee requiring a security clearance. For security administration activities, to include processing for a personnel security clearance, the individual will be considered an employee of the possessing facility where he/she is afforded access to classified information or matter. These individuals are required to complete the same security awareness briefings and requirements as other cleared employees. A self-employed individual or consultant who will retain classified information or matter at their place of business must be processed for and granted an FCL that applies to the premises where the individual or consultant will store, handle, or process classified information or matter. f. For Multiple Facility Organizations (MFOs), the home office facility must have an FCL at the same or higher level as that of any cleared facility within the MFO. g. In a corporate tier parent-subsidiary relationship, the parent and each of its subsidiaries are separate legal entities and must be processed separately for an FCL. Because the parent controls the subsidiary, the general rule in the U.S. Government is that the parent must have an FCL at the same or higher level as that of the subsidiary. However, DOE will determine the necessity for the parent to be cleared or excluded from access. DOE will advise the companies as to what action is necessary for processing the FCL. When a parent or its cleared subsidiaries are collocated, a formal written agreement to use common security services may be executed by the two firms, subject to DOE approval. h. A contractor granted an FCL by an OGA may be granted a DOE FCL for receiving, processing, using, or storing classified information or matter under a DOE contract at the same clearance level, based on reciprocity. DOE O 470.4B Appendix B, Section 1, Chapter I 7-21-11 I-3 2. ELIGIBILITY REQUIREMENTS. The following eligibility requirements must be met

Section 37

prior to being processed for an FCL. a. A contractor or prospective contractor must: (1) Be selected to perform tasks under a contract containing the DEAR security clauses found at 48 CFR Part 952; (2) Be organized under the laws of one of the 50 States, the District of Columbia, or Puerto Rico and must be located in the United States or a U.S. territorial area or possession; (3) Have a reputation for integrity and lawful conduct in its business dealings; (4) Not have been barred from participating in U.S. Government contracts (this includes KMP on the contract); and (5) Not be under FOCI to a degree that the granting or continuation of the FCL would be inconsistent with the national interest. b. An OGA must: (1) Have a documented need for an FCL as established in writing by DOE line management; (2) Submit a written statement of security assurance to the DOE cognizant security office, verifying the security capability of the agency as it applies to the DOE activity; and (3) When Restricted Data (RD) or Formerly Restricted Data (FRD) is involved, include in the written statement of security assurance procedures to limit the manner in which the RD or FRD is to be disseminated and ensure that appropriate clearances for access to RD or FRD are in place. c. For DOE facilities, cognizant security offices for DOE Federal activities must establish and document a security plan describing an adequate level of protection for DOE security interests. DOE O 470.4B Appendix B, Section 1, Chapter II 7-21-11 II-1 CHAPTER II. IMPORTANCE RATINGS 1. FACILITY IMPORTANCE RATINGS. Importance ratings are used to establish a risk- based system for identifying the level of protection applicable to security assets and activities of facilities. Each facility granted an FCL must be assigned an importance rating. Each facility’s assigned importance rating must be recorded on DOE F 470.2, Facility Data and Approval Record (FDAR). Importance rating criteria are as follows. a. “A” Importance Ratings. An “A” importance rating must be assigned to those facilities that meet any of the following criteria: (1) Engaged in administrative activities considered essential to the direction and continuity of the overall DOE nuclear weapons program, as determined by the Program Secretarial Office or for NNSA, the Office of the Administrator; (2) Authorized to possess Top Secret RD/FRD or Top Secret national security information, or possess Special Access Program (SAP) matter, or designated as Field Intelligence Elements; (3) Authorized to possess Category I quantities of SNM (including facilities with credible rollup quantities of SNM to a Category I quantity); or (4) Operate critical infrastructure programs determined to be essential by DOE line management. b. “B” Importance Ratings. A “B” importance rating must be assigned to those facilities that meet any of the following criteria: (1) Engaged in activities other than those categorized as “A” and authorized to possess Secret RD and/or weapon data matter; (2) Authorized to possess Category II quantities of SNM; or (3) Authorized to possess certain categories of biological agents. c. “C” Importance Ratings. A “C” importance rating must be assigned to those facilities that meet any of the following criteria: (1) Authorized to possess Categories III and IV quantities of SNM or other nuclear materials requiring safeguards controls or special accounting procedures; or

Section 38

(2) Authorized to possess classified information or matter other than the type categorized for “A” and “B” facilities. Appendix B, Section 1, Chapter II DOE O 470.4B II-2 7-21-11 d. “D” Importance Ratings. A “D” importance rating must be assigned to those facilities that provide common carrier, commercial carrier, or mail service and are not authorized to store classified information or matter, or nuclear material during non-working hours. (Carriers who store classified information or matter, or nuclear material must be assigned an “A,” “B,” or “C” importance rating.) e. “E” (Excluded Parent) Importance Ratings. An “E” importance rating must be assigned to a corporate tier parent of a contractor organization when the parent has been barred from participation in the activities related to a contract with DOE. f. “PP” (Property Protection) Importance Ratings. A “PP” importance rating must be assigned to those facilities that meet any of the following criteria: (1) Government property of a significant monetary value (suggested threshold of $5 million); (2) Nuclear materials requiring safeguards controls or special accounting procedures other than those categorized as types “A,” “B,” or “C”; (3) Responsibility for DOE program continuity; (4) National security considerations; or (5) Responsibilities for protection of the health and safety of the public and employees. g. “NP” (Non-Possessing) Importance Ratings. An “NP” rating must be assigned to those facilities whose staff have authorized access to classified information or matter, or SNM at other approved locations, but which do not themselves possess any classified information or matter, or SNM, or meet any of the other criteria listed for the other ratings above. 2. UPGRADING AND DOWNGRADING A FACILITY’S ASSIGNED IMPORTANCE RATING. As security activities are added or changed, the importance rating of the approved facility may change (i.e., it may be either upgraded or downgraded). Upgrading or downgrading a facility’s importance rating may also require transfer of the DOE cognizant security office functions. Changes to the facility importance rating must be registered in SSIMS by the submission of DOE F 470.2, Facility Data and Approval Record (FDAR). DOE O 470.4B Appendix B, Section 1, Chapter III 7-21-11 III-1 CHAPTER III. FACILITY CLEARANCE APPROVAL REQUIREMENTS 1. ISSUANCE OF FCLs. All eligibility requirements listed below must be satisfied prior to the issuance of an FCL. The DEAR prohibits the award of a classified contract until an FCL has been granted and issued. When an existing unclassified contract is modified to require classified work, the contract modification cannot take effect until an FCL is issued and the appropriate DEAR security clause is inserted in the contract. 2. CONTRACTOR FACILITIES. In accordance with the provisions of the DEAR, approval of a contractor final FCL must be based on the following items: a. A favorable FOCI determination based upon all information available to the cognizant security office including information on Standard Form (SF) 328 and any required supporting documentation; b. A contract or proposed contract containing the appropriate security clauses found in the DEAR; c. S&S plans, developed in accordance with DOE policy in Attachment 2 of this Order, that describe protective measures appropriate to the activities being performed at the facility and approved by the DOE cognizant security office;

Section 39

d. If access to nuclear material is involved, an established Reporting Identification Symbol code for the Nuclear Materials Management and Safeguards Reporting System (NMMSS); e. A comprehensive survey conducted no more than 6 months before the FCL approval date with a composite facility rating of satisfactory, if the facility will possess classified information or special nuclear material at its location or if the facility has an importance rating of “PP”; f. Appointment of an FSO, who must possess or be in the process of obtaining an access authorization (security clearance) equivalent to the level of the facility clearance (note that only an interim FCL can be granted until the FSO’s access authorization is finalized); g. If applicable, appointment of a Materials Control and Accountability Representative; and h. Access authorizations for KMP who will be determined on a case-by-case basis and must possess or be in the process of obtaining access authorizations equivalent to the level of the facility clearance. (NOTE: until the required KMP access authorizations are finalized, only an interim FCL can be granted.) 3. FACILITY CLEARANCES FOR OGAs. Federal government facilities are eligible to be registered with a DOE FCL if the OGA is involved in activities that impact DOE security Appendix B, Section 1, Chapter III DOE O 470.4B III-2 7-21-11 interests such as possession and/or storage of RD or other mission or programmatic needs as identified and documented by DOE line management. Approval of an OGA FCL must be based upon a written statement of security assurance from the OGA that protection of DOE security interests is adequately ensured. The statement of security interest must include the following information: a. An approved classified mailing address for the facility; b. The highest level and most restrictive category of classified information the facility is authorized to receive and store; c. A statement that national security classified information will be afforded protection according to E.O. 13526, Classified National Security Information, and all implementing directives issued by the Information Security Oversight Office (ISOO), to include the requirements of 32 CFR Part 2001, Classified National Security Information; d. A statement that the requirements of 10 CFR Part 1045, Nuclear Classification and Declassification, will be met for RD and FRD; and e. Assurance that the requirements of the Atomic Energy Act, including the mandatory access authorization requirements, will be met for access to RD and FRD. 4. RECORDS. For DOE Federal and contractor facilities, the DOE cognizant security office must maintain a copy of the facility’s S&S plans, survey reports, FOCI documentation including notification of a favorable FOCI determination if applicable, pertinent correspondence, and copies of DOE F 470.2, Facility Data and Approval Record (FDAR), created for the facility. For FCL termination of all registered facilities, a copy of the certificate of non-possession or security certification must be maintained. DOE O 470.4B Appendix B, Section 1, Chapter IV 7-21-11 IV-1 CHAPTER IV. INTERIM AND LIMITED FACILITY CLEARANCES 1. INTERIM FCLs. Interim FCLs are granted on a temporary basis, pending completion of full investigative and approval requirements, including but not limited to the completion of background investigations for final access authorizations for those individuals required

Section 40

to be cleared in connection with the FCL (such as KMP). Interim FCLs may be granted only to avoid unacceptable delays in pre-contract negotiation or in performance on a contract, and must be granted only after DOE has made a FOCI determination and granted interim access authorizations to KMP and other facility personnel requiring immediate access to classified information or matter. a. When final access authorizations have been granted to all facility employees, a final FCL must be granted and registered in SSIMS via an updated DOE F 470.2, Facility Data and Approval Record (FDAR). b. When an interim access authorization for an individual KMP is withdrawn, the interim FCL must also be withdrawn unless action is taken to remove the individual from the position requiring access. c. Foreign owned or controlled companies and those with non-U.S. citizens as KMP are not eligible for interim FCLs. 2. LIMITED FCLs. The United States has entered into agreements with certain foreign governments that establish arrangements whereby a foreign-owned U.S. company may be considered eligible for an FCL without any additional FOCI negation or mitigation instrument. To ensure that release of information or access to SNM is in accordance with the U.S. National Disclosure Policy, a limited FCL must be restricted to one security activity involving classified information or SNM. Award of another security activity to the same facility involving such information requires separate FCL registration, under another limited FCL or under an FCL without restrictions, if appropriate. Issuance of a limited FCL requires imposing strict access restrictions to limit access to the scope of the contract. The clearance and exclusion requirements for KMP apply to all FCLs, including a limited FCL. a. A limited FCL may be granted upon satisfaction of the following criteria. (1) Verification of an agreement authorizing the exchange of the classified information or matter involved to the country from which the foreign ownership is derived. (a) Access to classified information or matter will be limited to performance on a contract, subcontract, or program involving the government of the country from which foreign ownership is derived. Appendix B, Section 1, Chapter IV DOE O 470.4B IV-2 7-21-11 (b) Release of classified information or matter must be in conformity with the U.S. National Disclosure Policy. (2) In extraordinary circumstances, a limited FCL may also be granted when the criteria listed above cannot be satisfied, provided there exists a compelling need to do so consistent with national security interests. b. Limited FCL Compelling Need Statement. Each request for clearance under a limited FCL must be accompanied by a statement of compelling need from the GCA. The GCA’s compelling need statement must be signed by the head of the cognizant DOE program office and include the following: (1) Acknowledgment that the company will be under FOCI (i.e., FOCI will not be mitigated); (2) Acknowledgment that the GCA/Departmental element accepts the risks inherent in the granting of an FCL where FOCI is not mitigated; and (3) A foreign disclosure determination stating the basis for determining that release of classified to the foreign government involved is in conformity with U.S. National Disclosure Policy. DOE O 470.4B Appendix B, Section 1, Chapter V 7-21-11 V-1 CHAPTER V. PERSONNEL SECURITY CLEARANCES AND EXCLUSION

Section 41

PROCEDURES REQUIRED IN CONNECTION WITH CONTRACTOR FACILITY CLEARANCES 1. SECURITY CLEARANCES REQUIRED IN CONNECTION WITH THE FCL. Certain officials (typically the owners, officers, directors, partners, regents, trustees, and/or executive personnel [KMP]) with the ability to affect the organization’s policies or practices in security activities conducted under the contract must be cleared to the level of the FCL or formally excluded from access as appropriate. For multiple facility organizations, each subordinate cleared facility’s KMP must also be cleared or excluded. Changes in an organization’s KMP must be reported as they occur, and access authorizations must be processed for new KMP immediately. 2. EXCLUSION PROCEDURES. When officials are to be excluded from or cleared at a level not commensurate with the FCL, compliance with one or both of the exclusion actions listed below is mandatory before issuance of an FCL. Exclusion actions must be made a matter of record by the organization’s executive body. A copy of the resolution must be provided to the DOE cognizant security office. a. When formal exclusion action is required, the organization’s governing body must affirm that specific KMP (designated by name) will not require, will not have, and can be effectively excluded from access to all classified information or matter, or nuclear or other hazardous material presenting a potential radiological, chemical, or biological sabotage threat, that is entrusted to or held by the organization. Additionally, the governing body must affirm that the specific KMP (designated by name) do not occupy positions that would enable them to adversely affect the organization’s policies or practices in the performance of classified contracts. b. When officials are to be cleared at a level below that of the FCL, the organization’s governing body must affirm that such KMP (designated by name) will not require, will not have, and can be effectively denied access to higher- level classified information (specified by level), and do not occupy positions that would enable them to adversely affect the organization’s policies or practices in the performance of higher-level classified contracts. 3. SECURITY CLEARANCES CONCURRENT WITH THE FCL. Contractors may designate employees who require access to classified information or matter during the negotiation of a contract or the preparation of a bid or quotation pertaining to a prime contract or a subcontract to be processed for security clearances concurrent with the FCL. The granting of an FCL is not dependent on the security clearance of such employees. DOE O 470.4B Appendix B, Section 1, Chapter VI 7-21-11 VI-1 CHAPTER VI. FACILITY CLEARANCES GRANTED BY OTHER GOVERNMENT AGENCIES 1. ACCEPTING OGA FCLs. a. General. A contractor with an equal or higher FCL granted by another Federal government agency under the National Industrial Security Program (NISP) may be accepted by DOE for accessing, receiving, generating, reproducing, storing, transmitting, or destroying classified information or matter, contingent on the conditions listed below. Reciprocity between DOE and the OGA must be documented in a written letter or memorandum of agreement (MOA) between the DOE cognizant security office and the cognizant OGA that establishes the responsibilities of each party for assurance and verification of the protection afforded the DOE assets.

Section 42

(1) Classification Level/Category and Special Conditions. The FCL granted by the OGA must be at the appropriate classification level and category and must encompass the DOE activity. (a) Limited or interim FCLs granted by an OGA cannot be accepted. (b) If cleared under a Voting Trust Agreement, Proxy Agreement, Special Security Agreement, or Security Control Agreement, the DOE cognizant security office must obtain a copy of the FOCI mitigation plan from the cognizant OGA. The mitigation plan must be submitted to the DOE Office of Health, Safety and Security or, for NNSA activities, to the Office of Defense Nuclear Security, for review. (c) For DOE contracts involving proscribed information (i.e., Top Secret, COMSEC, RD/FRD), the following requirements, as appropriate, must be met before accepting an FCL granted in conjunction with a Special Security Agreement or Security Control Agreement. 1 When the company is controlled by a foreign government: a DOE must have entered into an agreement with the foreign government involved that covers the proscribed information to be released under the contract; and b A waiver must be granted by the cognizant Secretary (i.e., the Secretary of Energy and/or the Secretary of Defense) in accordance with the Appendix B, Section 1, Chapter VI DOE O 470.4B VI-2 7-21-11 provisions of 10 U.S.C. Section 2536, Award of certain contracts to entities controlled by a foreign government: prohibition, which prohibits contract awards involving proscribed information to foreign government-controlled companies unless such a waiver is granted. 2 When a company is not controlled by a foreign government a national interest determination (NID) for the specific program/project/contract must be approved by DOE and/or the OGA as appropriate. 3 For contracts involving RD/FRD, the additional requirements set forth below in paragraphs (6)(a)–(d) must be met or addressed as appropriate. (d) An OGA Top Secret facility clearance transfers to a DOE Secret/RD possessing interest, and an OGA Secret facility clearance transfers to a DOE Secret/RD non-possessing interest as long as DOE grants the security clearances to KMPs and all individuals requiring access to Secret/RD under the DOE contract(s). (e) Final FCLs granted by OGAs for access to national security information (NSI), when no proscribed information is involved, will be accepted by DOE on a reciprocal basis with no additional requirements. (2) Notification of Cancellation. An assurance must be obtained from the OGA that the FCL will not be canceled prior to the DOE cognizant security office being notified. (3) Protective Measures. Confirmation must be obtained from the OGA that the facility’s protective measures and procedures are adequate for the protection of the DOE activity, and results of the agency’s last survey of the facility are satisfactory in those areas that could affect the DOE interest. (4) Surveys. The facility’s survey frequency must be confirmed by the OGA, and assurance must be obtained that copies of each of the OGA’s periodic survey reports or memoranda covering the status of the protection of the DOE activity will be furnished to the DOE cognizant security office following each scheduled survey. (5) Access authorizations. Each employee to be granted access to RD or SNM must have an appropriate access authorization. DOE O 470.4B Appendix B, Section 1, Chapter VI 7-21-11 VI-3

Section 43

(6) RD/FRD. If RD or FRD is involved, the following must be considered: (a) An assurance must be obtained from the OGA that the facility complies with the requirements of 10 CFR Part 1045, Nuclear Classification and Declassification. (b) When the DOE contract involves RD, an assurance must be obtained from the OGA that the facility’s protective measures and procedures meet the requirements of DoD 5220.22-M, National Industrial Security Program Operating Manual (NISPOM), including any appendices or supplements applicable to RD. (c) FCLs not meeting the requirements in (a) and (b) above may be accepted if the DOE activity requires that the contractor establish upgraded protective measures that meet DOE requirements. For FCL upgrades, the agreement between DOE and the OGA must cover reimbursement for upgrade costs incurred by the OGA or contractor. (d) When DOE accepts an FCL based on an OGA-approved Voting Trust Agreement, Proxy Agreement, Special Security Agreement, or Security Control Agreement, an assurance must be obtained from the OGA that it will invite and permit DOE to attend the annual meeting if such attendance is determined necessary by either the OGA or DOE. b. Contractor’s Tier Parent(s). If the parent(s) of a company that DOE is processing for an FCL holds an FCL granted by another Federal agency, the tier parent(s) does not need to provide DOE with a FOCI package, provided reciprocity is accomplished with the OGA. Reciprocity between the DOE cognizant security office and the OGA must be documented in a written agreement with the appropriate provisions as outlined above. The written agreement must contain an assurance from the OGA that security cognizance will be transferred to DOE for any tier parent no longer requiring the OGA FCL. 2. OGA VERIFICATION REQUESTS. If an OGA requests verification of an existing DOE FCL, a copy of the facility’s current DOE F 470.2, Facility Data and Approval Record (FDAR), must be provided. 3. OGA CONTRACTORS WITH NO DOE CONTRACTS. Classified mail channels must be registered in SSIMS for an OGA contractor organization where the Department does not have a contractual interest but must communicate or exchange classified information with the OGA contractor. To establish an address for the classified mail channel, a statement of security assurance or a form comparable in content must be completed and signed by the DOE cognizant security office and by the authorizing government official Appendix B, Section 1, Chapter VI DOE O 470.4B VI-4 7-21-11 for the OGA contractor. The establishment of this type of registration in SSIMS cannot be used as a basis for registering additional security activities. DOE O 470.4B Chapter VII 7-21-11 VII-1 CHAPTER VII. DOCUMENTATION AND REGISTRATION OF FACILITY CLEARANCES AND RELATED SECURITY ACTIVITIES 1. DOCUMENTATION OF FCLs. SSIMS must be used by all DOE cognizant security offices to register FCL information for which they have cognizant security authority, survey cognizance, or responsibility for registered security activities. Each registered FCL must identify the highest security activity approved for the registered facility. a. DOE F 470.1, Contract Security Classification Specification (CSCS), is used to register information in SSIMS concerning contract vehicles; a DD 254 used by an OGA sponsoring an activity can be submitted in lieu of the DOE F 470.1 if it is

Section 44

annotated with the DOE facility code. DOE F 470.2, Facility Data and Approval Record (FDAR), is used to record approvals, changes, and deletions of facility security information and other facility changes for entry into SSIMS. These forms are available on the website of the DOE Office of the Chief Information Officer (http://cio.energy.gov/records-management/forms.htm). b. If more than one Departmental element has a registered security activity at a facility, the element responsible for the security activity involving the highest classification level and category is the responsible DOE cognizant security office, to include being the processing personnel security office. This responsibility may be delegated, by mutual agreement, to another Departmental element with a registered security activity at that facility. The Special Security Officer, Office of Intelligence and Counterintelligence, must also sign the DOE F 470.1 for contracts involving access to Sensitive Compartmented Information. c. Any change in the responsible DOE cognizant security office or survey office must include a transfer of appropriate documentation (e.g., S&S plans; construction project status; FOCI files; etc.). 2. REGISTRATION OF SECURITY ACTIVITIES. Security activities are specific, unrelated tasks or contract elements involving S&S interests at a facility. Security activities must be registered in association with a specific FCL. a. Security Activities for Existing FCLs. The DOE cognizant security office must: (1) Determine and validate the security requirements, including personnel security clearances, for the proposed security activity. (2) Determine the FCL status through SSIMS or the Defense Security Service/Industrial Security Facilities Database (DSS/ISFD). (3) Compare the security requirements for the activity to the approved FCL in the following situations and ensure that: http://cio.energy.gov/records-management/forms.htm Chapter VII DOE O 470.4B VII-2 7-21-11 (a) When the contractor FCL is granted by an OGA, the requirements for accepting an OGA FCL are met. (b) When the contractor FCL is granted by DOE: 1 The new activity will be protected adequately under the facility’s existing S&S program as outlined in the facility’s approved security plan. 2 The existing FCL is compatible with the level and category of the new security activity. 3 The facility holds a composite facility rating of satisfactory on the basis of the last S&S survey report. 4 If applicable, coordination is accomplished with the DOE and/or OGA cognizant security agency for any tier parent(s) of the contractor holding a DOE or OGA FCL to ensure compliance with national requirements (e.g., FOCI determination, exclusion resolutions for KMP, etc.). b. Registering New Security Activities. The procurement request originator will submit a DOE F 470.1, Contract Security Classification Specification (CSCS), or DD 254 to the DOE contracting official, who will forward the completed DOE F 470.1 to the DOE cognizant security office. The DOE cognizant security office will verify the information and ensure that the new security activity can be performed within the existing FCL. If no issues are identified, the cognizant security office will approve the form and return it to the contracting officer so that the contract can be awarded. When a new activity will exceed the current FCL, or if there is no FCL, all actions required to upgrade the current level or obtain an

Section 45

FCL must be completed prior to contract award. c. Terminating Security Activities. When a registered security activity is terminated, the organization that established the security activity must ensure that all access authorizations associated with the activity are terminated and all DOE property, classified information or matter, and/or nuclear and other hazardous material is appropriately reallocated, disposed of, destroyed, or returned to the appropriate DOE or cleared DOE contractor organization. A certificate of non- possession must be obtained from the organization responsible for the terminating activity and must be maintained by the DOE cognizant security office that established the security activity. A final CSCS form must be submitted and SSIMS must be updated to show the termination. 3. REGISTERING WORK FOR OTHERS (WFO) ACTIVITIES. The requirements of DOE O 481.1C, Work for Others (Non-Department of Energy Funded Work), dated 1-24- DOE O 470.4B Chapter VII 7-21-11 VII-3 05 must be met before a WFO project or any “out of scope” modifications to existing WFO agreements are accepted. WFO activities must be registered in SSIMS. a. WFO Performed at DOE-Owned or DOE-Operated Facilities. Before acceptance of WFO activities, the DOE and the requesting agency must exchange classification and protection information, including the DOE F 470.1, Contract Security Classification Specification (CSCS) or DD Form 254. The exchange of classification and protection information must be documented and may also include a formal agreement that includes reimbursement of any additional S&S costs (above minimum security requirements) incurred by the Department. b. WFO Performed at Other Than DOE-Owned or DOE-Operated Facilities. When an OGA stipulates that WFO activities are to be performed by a DOE contractor at locations other than DOE-owned or DOE-operated facilities, an FCL is required. If the FCL is issued by an OGA, the requirements for accepting OGA FCLs apply. The WFO activity must be registered in SSIMS. Before the activity can be registered, all applicable requirements of DOE O 481.1C, Work for Others (Non-Department of Energy Funded Work), must be met, and the DOE cognizant security office must review and certify that the sponsoring organization has complied with the applicable provisions of DOE O 475.2A, Identifying Classified Information. c. Subcontracting in Connection with WFO. When subcontracting is required in connection with WFO, the subcontractor can be registered based on DOE F 470.2, Facility Data and Approval Record (FDAR), and verification of the FCL. In this instance, a security cognizance agreement is not required. If the subcontractor has a DOE FCL at the appropriate level, the WFO activity must be registered. If the subcontractor has an FCL issued by an OGA, the considerations for the acceptance of OGA FCLs, as outlined in Chapter VI of this Section, apply. A separate letter or memorandum of understanding between DOE and the OGA is not required provided that all considerations are addressed in the WFO agreement. 4. EXCEPTIONS TO REGISTRATION IN SSIMS. Foreign intelligence information, SCI, SAPs, and other sensitive activities requiring special access or procedures associated with receipt, storage, processing, and/or handling must conform to the applicable protection provisions of Executive Orders and to applicable Director of Central Intelligence

Section 46

directives. Because these activities are not regulated under S&S policy, they are not registered in SSIMS. Exceptions to the registration requirements are identified below. a. SAPs. SAPs are not registered in SSIMS. SAPs are registered in accordance with DOE O 471.5, Special Access Programs, dated 3-29-11. b. SCI. SCI security activities are not registered in SSIMS; however, each accredited SCI facility (SCIF) must be registered in SSIMS using DOE F 470.2, Facility Data and Approval Record (FDAR). Chapter VII DOE O 470.4B VII-4 7-21-11 c. Classified or Sensitive Activities. Details concerning sensitive or classified activities the publication of which in SSIMS would compromise mission completion of such activities or classified information are not registered in SSIMS. The DOE cognizant security office must notify the appropriate Program Secretarial office or, for NNSA, the Office of the Administrator before granting the FCL. DOE O 470.4B Appendix B, Section 1, Chapter VIII 7-21-11 VIII-1 CHAPTER VIII. SUSPENSIONS 1. REASONS FOR SUSPENSION. When the following conditions occur, the DOE cognizant security office must suspend the FCL, document the action on an updated DOE F 470.2 (Facility Data and Approval Record [FDAR]), and immediately update SSIMS to reflect the suspension: a. When a company with an FCL is determined to be under FOCI that has not been mitigated, the FCL must be suspended. Contract performance on activities involving proscribed information may not continue until all applicable FOCI requirements are met. b. When findings or other deficiencies in a survey, self-assessment, inquiry, inspection, or evaluation indicate suspension of an FCL is necessary, the DOE cognizant security office will determine whether the FCL must be suspended pending validated corrective actions. 2. ACTIONS. When a decision is made to suspend the FCL of a company that has current access to classified information or SNM, the following actions must be taken: a. The facility subject to the suspension action must be notified in writing that its FCL has been suspended, including the reason for the suspension; that award of new contracts to the facility will not be permitted until the facility has been restored to a fully valid status; and that termination of the FCL may result if the issues causing the suspension are not rectified within a time frame and manner specified by DOE. Notification must include instructions for immediately securing classified material and/or SNM at an approved cleared facility pending restoration of the suspended facility to a fully valid status. b. GCAs must be notified and must make the final decision regarding a contractor’s continued performance on existing contracts other than the contract activity for which the suspension is in effect. Continued possession of classified information or SNM associated with those contracts retained under GCA authorizations must be evaluated by the DOE cognizant security office to determine whether appropriate security requirements are being met. c. All affected DOE elements and, if applicable, affected OGAs must be notified by the DOE cognizant security office of the suspension action. 3. NON-COMPLIANCE WITH MITIGATION PLANS. When the DOE cognizant security office determines that a cleared contractor or its tier parent is out of compliance with an approved FOCI mitigation plan, the DOE cognizant security office must analyze the non-

Section 47

compliance and evaluate the overall impact to the protection of security interests. The cognizant contracting officer must be notified immediately and one or more of the following actions must be taken: Appendix B, Section 1, Chapter VIII DOE O 470.4B VIII-2 7-21-11 a. Request a corrective action and implementation plan from the contractor to bring it into compliance with the approved mitigation plan. b. Suspend the FCL. c. Terminate the FCL. 4. CONTINUATION OF CONTRACT PERFORMANCE UNDER FOREIGN GOVERNMENT OWNERSHIP. In accordance with the intent of 10 U.S.C. Section 2536, Award of certain contracts to entities controlled by a foreign government: prohibition, when an existing contractor becomes foreign-government owned but execution of a novation agreement is not required by the DEAR clause, the continued performance by that contractor on existing classified contracts or contracts for environmental restoration, remediation, or waste management that involve proscribed information may only continue under FCL suspension if: a. The contractor is eligible for continuation on such work by Secretarial and/or OGA Secretarial waiver under 10 U.S.C. Section 2536(b)(1)(A) or 10 U.S.C. Section 2536(b)(1)(B), as applicable; b. Each GCA takes immediate action to request a waiver under 10 U.S.C. Section 2536(b)(1)(A) or 10 U.S.C. Section 2536(b)(1)(B), as applicable, and also takes interim actions to safeguard the classified information associated with its classified contracts. 5. REINSTATEMENT OF A SUSPENDED FCL. When the conditions that resulted in the suspension have been resolved in a manner determined acceptable by DOE management, the FCL may be reinstated. The reinstatement must be based on the necessity to complete or continue work associated with the original FCL. DOE O 470.4B Appendix B, Section 1, Chapter IX 7-21-11 IX-1 CHAPTER IX. FACILITY CLEARANCE TERMINATION AND CLOSE OUT 1. CONTRACT CLOSEOUT/FACILITY CLEARANCE TERMINATION. a. General. When a contract ends and/or an FCL is no longer necessary, the DOE cognizant security office must complete a termination survey, a DOE F 470.2, Facility Data and Approval Record (FDAR), and update SSIMS to enact the termination. All security clearances connected to the facility clearance must be terminated and all DOE property, classified information or matter, and/or nuclear and other hazardous material presenting a potential radiological, chemical or biological sabotage threat must be appropriately reallocated, disposed of, destroyed, or returned to an appropriate DOE or cleared DOE contractor organization. b. Contract Completion. Upon completion or termination of a contract, the possessing contractor must submit to the DOE cognizant security office either a certificate of non-possession or a certificate of possession (of classified matter). A non-possessing contractor must submit a security activity closeout certification. Closure of the contract must be documented with a final DOE F 470.1, Contract Security Classification Specification (CSCS). Forms and certificates must be maintained with the records pertaining to the facility clearance. 2. REACTIVATION. Reactivations of terminated FCLs must be based on programmatic or mission need and the implementation of current security requirements. The DOE cognizant security office must validate that all security requirements have been implemented, must complete a DOE F 470.2, Facility Data and Approval Record

Section 48

(FDAR), and must update SSIMS to complete the reactivation. DOE O 470.4B Appendix B, Section 2 7-21-11 2-1 SECTION 2. FOREIGN OWNERSHIP, CONTROL, OR INFLUENCE PROGRAM 1. OBJECTIVE. Foreign investment can play an important role in maintaining the vitality of the U.S. industrial base. Therefore, it is the policy of the U.S. Government to allow foreign investment consistent with the national security interests of the United States. The DOE Foreign Ownership, Control, or Interest (FOCI) policy for U.S. companies subject to an FCL determination is intended to facilitate foreign investment by ensuring that foreign firms cannot undermine U.S. security and export controls to gain unauthorized access to critical technology and/or classified information or matter, including RD, FRD, and SNM. 2. PURPOSE. The FOCI program regulates DOE determinations of the degree to which a contractor facility is under foreign ownership, control, or influence. In accordance with 48 CFR Chapter 9, the DOE Acquisition Regulation (DEAR), DOE must obtain information about FOCI that is sufficient to help the Department determine whether award of a contract to a person or firm, or the continued performance of a contract by a person or firm, may pose undue risk to the common defense and security. A contractor cannot be under FOCI to such a degree that granting or continuing an FCL would be inconsistent with U.S. national security interests. The requirements of the National Industrial Security Program (NISP) form the baseline for this program, supplemented with requirements for the protection of DOE-specific assets, Restricted Data, SNM, and other security activities. 3. DEFINITION. A U.S. company is considered under FOCI whenever a foreign interest has the power, direct or indirect, whether or not exercised, and whether or not exercisable through the ownership of the U.S. company’s securities, by contractual arrangements or other means, to direct or decide matters affecting the management or operations of that company in a manner which may result in unauthorized access to classified information or may adversely affect the performance of a classified contract. 4. REFERENCES. a. E.O. 12829, National Industrial Security Program, dated 01-26-93. b. 32 CFR Part 2004, National Industrial Security Program Directive No. 1. c. DoD 5220.22-R, Industrial Security Regulation. d. DoD 5220.22-M, National Industrial Security Program Operating Manual (NISPOM). e. DoD Defense Security Service (DSS) Industrial Security Letters (ISLs), available at http://www.dss.mil/isp/fac_clear/download_nispom.html (Note: ISLs do not automatically impose requirements, but may contain useful clarifications of existing NISPOM provisions.). http://www.dss.mil/isp/fac_clear/download_nispom.html Appendix B, Section 2 DOE O 470.4B 2-2 7-21-11 f. Directive-Type Memorandum 09-019 (DTM) “Policy Gudance for Foreign Ownership, Control, or Influence,” issued by the Office of the Under Secretary of Defense, available at http://www.dtic.mil/whs/directives/corres/dir3.html. (Note: DTMs, which may be issued periodically on a variety of topics, do not automatically impose requirements, but may contains useful information applicable to existing NISP programs.) g. 10 U.S.C. Section 2536, Award of certain contracts to entities controlled by a foreign government: prohibition. h. 48 CFR Chapter 9, Department of Energy Acquisition Regulation.

Section 49

i. DOE Order 475.1, Counterintelligence Program, dated 10-04-04. 5. REQUIREMENTS. DOE cognizant security offices, as designated by the Program Secretarial Office or, for NNSA, the Office of the Administrator through the Chief, Defense Nuclear Security, are responsible for ensuring that the following activities are accomplished under the FOCI program for facilities and sites under their cognizance and for ensuring that contractors under their cognizance accomplish their responsibilities under this program at contractor facilities. Procedures applicable to the FOCI program must be documented in facility or site security plans. a. Ensure that determinations are rendered under the FOCI program concerning foreign ownership, control or influence factors on all contractors and their tier parents as applicable, in accordance with national and DOE requirements when the contract will involve or is likely to involve classified information or SNM. b. Establish and apply procedures to ensure that coordination is accomplished between the FCL and FOCI programs for all contractor FCLs. c. Ensure that all relevant aspects of FOCI are resolved and, if necessary, appropriately mitigated prior to the granting of an interim or final FCL. d. Ensure that contractors under their cognizance meet reporting requirements as established in DOE directives and national standards. e. Establish and determine the circumstances under which a contractor will be requested to complete a new FOCI package. f. Ensure that contractors under FOCI mitigation comply with all requirements imposed by the mitigation instrument. g. Ensure that procedures are in place for verification of the original signature on the Standard Form (SF) 328, Certificate Pertaining to Foreign Interest, prior to finalizing a FOCI determination. http://www.dtic.mil/whs/directives/corres/dir3.html DOE O 470.4B Appendix B, Section 2 7-21-11 2-3 h. Ensure that counterintelligence threat and technology transfer risk assessments and updates are obtained and evaluated as necessary in the administration of the FOCI program. i. Ensure that annual review and certification requirements established in DoD 5220.22-M, National Industrial Security Program Operating Manual (NISPOM), or alternative methods as permitted by this Order, for contractors under a FOCI mitigation instrument, are met for all such contractors under their cognizance. j. Ensure that when factors not related to ownership are present, contractors take appropriate positive measure to assure that the foreign interest can be effectively mitigated and cannot otherwise adversely affect performance on contracts. k. Approve trustees, proxy holders, and outside directors nominated by contractors in connection with FOCI mitigation plans, and approve specific measures such as technology control plans developed and implemented by contractors as part of FOCI mitigation plans. l. Evaluate changes in FOCI information submitted by contractors holding an FCL, and make changes in mitigation methods or security requirements, or suspend or terminate the facility clearance, as warranted to address changed conditions. DOE O 470.4B Appendix B, Section 2, Chapter I 7-21-11 I-1 CHAPTER I. GENERAL FOCI PROGRAM INFORMATION 1. GENERAL. a. An FCL must not be granted until all relevant aspects of FOCI have been resolved and, if necessary, appropriately mitigated. Appropriate procedures must be in

Section 50

place to ensure coordination between the FOCI and FCL programs under the jurisdiction of each DOE program office. b. The determination of whether a U.S. company is under FOCI must be made on a case-by-case basis. In instances where the company is unable to identify a foreign owner (e.g., the participating investors in a foreign investment or hedge fund cannot be identified), DOE may determine that the company is not eligible for an FCL. The following are examples of factors that must be considered to determine whether a company is under FOCI, is eligible for an FCL in spite of FOCI issues, and the protective measures required to mitigate FOCI: (1) Foreign intelligence threat, including record of economic and government espionage against U.S. targets; (2) Risk of unauthorized technology transfer; (3) Type and sensitivity of classified information or matter, or special nuclear material (SNM) to be accessed; (4) The nature, source, and extent of FOCI, including whether foreign interests hold a majority or substantial minority position in the company, taking into consideration all immediate, intermediate, and ultimate parent companies; (5) Record of compliance with pertinent U.S. laws, regulations, and contracts; (6) Nature of bilateral and multilateral security and information exchange agreements that may be relevant; (7) Whether the government of the foreign interest has industrial security and export control regimes in place that are comparable to those of the United States; and (8) Ownership or control, in whole or in part, by a foreign government. c. Development of security measures to mitigate the impact of unacceptable FOCI must be based on the concept of risk management. Appendix B, Section 2, Chapter I DOE O 470.4B I-2 7-21-11 d. If there is a change in a company with an existing FCL that impacts a favorable FOCI determination, the FCL must be suspended or terminated unless security measures are taken to remove the possibility of unauthorized access or adverse impacts to contract performance. e. Any doubt that unacceptable FOCI can be effectively mitigated to the point that affording the applicant access to classified information or matter is clearly consistent with national security must be resolved in favor of the national security. 2. APPLICABILITY. a. FOCI determinations must be rendered on the following: (1) Applicants, including industrial; educational; commercial; or any other entity, grantee, or licensee that have or anticipate executing a contract requiring access authorizations, including individuals contracting as a business. This includes subcontractors of any tier, consulting firms, agents, grantees, and cooperative research and development agreement participants who require security clearances. (2) All tier parents of applicants when the parent is located in the United States, Puerto Rico, or a U.S. possession or trust territory (DEAR, section 925.204-73[f]). b. A FOCI determination is not required for an individual performing work under a consulting agreement (e.g., an individual awarded a contract who has not contracted as a business). Foreign involvement for such individuals is determined and adjudicated through the background investigation conducted for the security clearance. c. When a local, State, or Federal agency or department is granted an FCL, there must be an agreement containing a security clause, which must state that if the

Section 51

government agency or department subcontracts any work requiring access to classified information or matter by a commercial entity in connection with the FCL, a FOCI determination is required. If the government agency or department does not have its own FOCI policies or an agreement with the Secretary of Defense for industrial security services, DOE will render the FOCI determination. d. Contractors with existing U.S. Government FCLs are identified in SSIMS and/or DSS/ISFD. No further FOCI review is required for an applicant registered in either of these systems holding an equal or higher U.S. Government FCL based upon a favorable FOCI determination. 3. ELECTRONIC SUBMISSION/PROCESSING WEB SITE. The Department has an electronic system for submission of FOCI information to DOE. To ensure confidentiality DOE O 470.4B Appendix B, Section 2, Chapter I 7-21-11 I-3 of the information submitted and stored on the system, the site is protected with 128-bit encryption. a. Applicants must use this system for the submission of FOCI packages, including changes to update their FOCI information. The FOCI Web site may be accessed via an Internet browser at https://foci.anl.gov. Electronic signatures are not accepted; therefore, a signed original SF 328, Certificate Pertaining to Foreign Interests, executed in accordance with the instructions on the certification section of the SF 328, must either be submitted to the DOE cognizant security office, or retained by the applicant and inspected by the DOE cognizant security office at the applicant’s place of business prior to rendering the final FOCI determination. b. Federal employees and supporting contractors use the Electronic Submission Processing System Web site at https://doefoci.anl.gov. https://foci.anl.gov/ https://doefoci.anl.gov/ DOE O 470.4B Appendix B, Section 2, Chapter II 7-21-11 II-1 CHAPTER II. FOCI PROCESSING 1. DETERMINING THE REQUIREMENTS FOR A FOCI DETERMINATION. If the procurement request requires security clearances, the DEAR security clauses found at 48 CFR Part 952.204-2, Security, will be included in the contract. For all such contracts a DOE F 470.1, Contract Security Classification Specification (CSCS), must be completed by the procurement request originator. A DD Form 254 may be used by a Federal agency sponsoring a contract activity, provided it is annotated with the DOE facility code. FOCI information and forms required under the security clauses will be submitted via the electronic FOCI website. 2. FINAL FOCI DETERMINATIONS. a. When insufficient lead time is expected between selection and contract award for the processing of the FOCI determination, the contracting officer may request a preliminary review, not a final FOCI determination, of the SF 328 submissions of each applicant in the competitive range. b. A final FOCI determination will only be rendered for the successful applicant. 3. ADJUDICATION. a. Adjudication Level. (1) The DOE cognizant security office renders the FOCI determination under the following conditions: (a) the responses to the FOCI questions do not exceed the thresholds in the FOCI Implementation reference tool in the e-FOCI system; (b) exclusion procedures are invoked when the applicant is controlled by a parent(s) not requiring security clearances or requiring a lower level of access to classified information or matter. (2) The Office of Health, Safety, and Security (HSS), or for NNSA the Office

Section 52

of Defense Nuclear Security, will render FOCI determinations that exceed established thresholds. The DOE cognizant security office will forward the FOCI submission(s) to HSS or NNSA with: (a) the justification for clearance or exclusion, including full details pertaining to the proposed contract, and (b) the DOE cognizant security office’s analysis, including a clear statement of the reason why a Headquarters determination is required. The Headquarters office, in coordination with the Office Appendix B, Section 2, Chapter II DOE O 470.4B II-2 7-21-11 of General Counsel when appropriate, will provide a final FOCI determination to the submitting office. b. Counterintelligence (CI) Threat Assessment and Technology Transfer Risk Assessment. A counterintelligence threat assessment and technology transfer risk assessment must be obtained and considered prior to a final decision to grant an FCL to an applicant under FOCI or to restore an FCL previously suspended because of unacceptable FOCI. The DOE cognizant security office must coordinate with the appropriate counterintelligence office to ensure that the threat assessment and technology transfer risk assessments and updates are accomplished. 4. COMMITTEE ON FOREIGN INVESTMENT IN THE UNITED STATES. a. The Committee on Foreign Investment in the United States (CFIUS) is an interagency committee chaired by the Department of the Treasury under Section 721 of the Defense Production Act of 1950 (50 U.S.C. App. 2170). CFIUS review is a voluntary process which affords an opportunity for foreign investors and U.S. persons entering into a covered transaction to submit the transaction for review by CFIUS to assess the impact of the transaction on national security. DOE policy with regard to CFIUS is found in DOE O 142.5, Committee on Foreign Investment in the United States, dated 10-8-10. b. The CFIUS review and the FOCI and FCL processing actions are carried out in two parallel but separate processes with different time constraints and considerations. 5. CONTRACTING OFFICERS. Contracting officers must provide electronic or written notification to the DOE cognizant security office when: a. they become aware of any changes to an applicant’s FOCI status; b. a requested FOCI review is no longer needed; c. a FOCI determination was rendered on an applicant that was not awarded a contract; d. all work on a contract for which a FOCI determination was rendered is within 30 days of termination or completion; e. security clearances are no longer required in performance of the contract. DOE O 470.4B Appendix B, Section 2, Chapter III 7-21-11 III-1 CHAPTER III. CHANGES TO FOCI INFORMATION 1. FOCI CHANGES THAT OCCUR FOLLOWING SUBMISSION OF AN SF 328 AND BEFORE CONTRACT AWARD. When an applicant has submitted a comprehensive FOCI package to the contracting officer and changes have occurred in the FOCI of the company prior to contract award, the applicant must submit an updated SF 328 and associated documents. DOE cognizant security offices must review the updated information and take any necessary steps to resolve FOCI concerns before the contract is awarded. 2. UPDATES. Changed conditions, such as a change in ownership, indebtedness, or foreign intelligence threat, may justify adjustments to the security requirements under which a company is operating or require that a different FOCI mitigation method be used. A

Section 53

changed condition may result in a determination that a company is no longer considered to be under FOCI or, conversely, that a company is no longer eligible for an FCL. Contractors holding an FCL based upon a favorable FOCI determination must submit written reports of changed conditions and anticipated changes which affect the FCL. Changes must be analyzed by the DOE cognizant security office to ensure that the contractor continues to meet the standards for holding an FCL. DOE cognizant security offices may request updated information, including the submission of a new FOCI package, at any time outside the normal cycle of package submission requirements. Significant changes that warrant a new FOCI determination include the following: a. a new threshold or factor exists that did not exist when the previous determination was made; b. a previously reported threshold or factor that was favorably adjudicated by the DOE cognizant security office has increased to a level requiring a determination by HSS or NNSA; c. a previously reported financial threshold or factor that was favorably adjudicated has increased by 5 percent or more; or a shift has occurred of 5 percent or more by country location, end user, or lenders; d. a previously reported foreign ownership threshold or factor that was favorably adjudicated has increased to the extent that a FOCI mitigation method or a different FOCI mitigation method is required; and e. any changes in ownership or control. f. Incidents of counterintelligence interest or concern identified and reported to the cognizant security office by the servicing counterintelligence office after the initial FOCI determination may also warrant a new determination. Appendix B, Section 2, Chapter III DOE O 470.4B III-2 7-21-11 3. ANNUAL REVIEW AND CERTIFICATION. The DOE cognizant security office will develop procedures to ensure that contractors provide adequate information to enable the DOE office to conduct a meaningful evaluation of compliance with annual review and certification requirements. a. Each contractor holding an FCL under a FOCI mitigation instrument must provide written annual certification to the DOE cognizant security office that no changes have occurred which would impact the contractor’s ability to protect classified information or matter or otherwise impact the national security. The certification report must include: (1) a detailed description of the manner in which the contractor is carrying out its obligations under the agreement; (2) changes to security procedures, implemented or proposed, and the reasons for the changes; (3) a detailed description of any acts of noncompliance, whether inadvertent or intentional, with a discussion of steps that were taken to prevent such acts from recurring; (4) any changes or impending changes of key management personnel or key board members, including the reasons for the changes’ (5) any changes or impending changes in the organizational structure or ownership, including any acquisitions, mergers, or divestitures; and (6) any other issues that could have a bearing on the effectiveness of the applicable agreement. b. Any contractor controlled by a parent organization(s) that has/have been excluded by formal resolution must provide written certification on an annual basis to the DOE cognizant security office acknowledging the continued effectiveness of the resolution. c. Any contractor that has executed a Board Resolution to reduce FOCI in non-

Section 54

controlling foreign ownership situations must provide annual written certification to the DOE cognizant security office acknowledging that the resolution remains in effect. d. Representatives of the DOE cognizant security office must meet annually (at least every 12 months) with the senior management officials who comprise the Government Security Committee (GSC) of organizations operating under a Voting Trust Agreement, Proxy Agreement, Special Security Agreement, or Security Control Agreement to review the effectiveness of the pertinent security arrangement and to establish a common understanding of the operating requirements and their implementation. If annual meetings cannot be conducted, DOE O 470.4B Appendix B, Section 2, Chapter III 7-21-11 III-3 DOE cognizant security offices must establish other methods, such as the submission of a new FOCI package for review, to accomplish the same ends. Reviews must include examination of the following: (1) acts of compliance or noncompliance with the approved security arrangement, standard rules, and applicable laws and regulations; (2) problems or impediments associated with the practical application or utility of the security arrangement; and (3) whether security controls, practices, or procedures warrant adjustment. DOE O 470.4B Appendix B, Section 2, Chapter IV 7-21-11 IV-1 CHAPTER IV. FOCI MITIGATION 1. GENERAL. If DOE determines that a company is under FOCI, DOE will determine the extent to which and the manner in which the FOCI may result in unauthorized access to classified information or SNM and the types of actions that will be necessary to mitigate the associated risks to a level deemed acceptable to DOE. DOE cognizant security offices will ensure that the following are considered in every FOCI evaluation: a. Record of economic and government espionage against U.S. targets; b. Record of enforcement and/or engagement in unauthorized technology transfer; c. Record of compliance with pertinent U.S. laws, regulations, and contracts; d. Type and sensitivity of the information to be accessed; e. Source, nature, and extent of FOCI, including but not limited to whether foreign persons hold a majority or substantial minority position in the company, taking into consideration all immediate, intermediate, and ultimate parent companies; f. Nature of any bilateral and multilateral security and information exchange agreements that may pertain; g. Ownership or control, in whole or in part, by a foreign government; and, h. Any other factor that indicates or demonstrates a capability on the part of the foreign interests to control or influence the operations or management of the business organization concerned. 2. MITIGATION ACTION PLANS. If there are any affirmative answers on the Certificate Pertaining to Foreign Interests, or other information is received which indicates that the applicant may be under FOCI, the DOE cognizant security office must review the case to determine the relative significance of the information in regard to the following factors: a. Whether the applicant is under FOCI; b. The extent to which and manner in which the FOCI may result in unauthorized access to classified information or adversely impact classified contract performance; c. The type of actions, if any, that would be necessary to mitigate or negate the effects of the FOCI to a level deemed acceptable to the Federal Government.

Section 55

3. FOCI MITIGATION INSTRUMENTS. The affected organization or its legal representatives may propose a plan to negate or reduce unacceptable FOCI; however, Appendix B, Section 2, Chapter IV DOE O 470.4B IV-2 7-21-11 DOE has the right and obligation to impose any security method, safeguard, or restriction it believes necessary to ensure that unauthorized access to classified information or matter, or SNM, is precluded. An organization that will not implement the security measures determined necessary by DOE to mitigate its foreign involvement to an acceptable level is ineligible for a FOCI determination and an FCL. Under all methods of FOCI mitigation, management positions requiring security clearances in conjunction with the FCL must be filled by U.S. citizens residing in the United States. a. Secretarial Waiver Authority. In accordance with 10 U.S.C. Section 2536, a contract under a national security program may not be awarded to an entity controlled by a foreign government if it is necessary for the entity to be given access to proscribed information unless a waiver has been granted by the Secretary concerned (i.e., the Secretary of Energy or the Secretary of Defense). Further, if the Secretary decides to grant a waiver under 10 U.S.C. Section 2536(b)(1)(B) for an environmental restoration, remediation, or waste management contract, the Secretary must notify Congress of this decision. The contract may be awarded or the novation agreement executed only after the end of a 45-day period, beginning on the date notification is received by the Senate Committee on Armed Services and the House Committee on National Security. b. Controlling Foreign Ownership. A controlling foreign ownership is one in which a non-U.S. citizen(s) owns a majority of the voting securities of the U.S. organization or, if less than 50 percent is foreign-owned, it can be reasonably determined that non-U.S. citizens or their representatives are in a position to effectively control the business management of the U.S. organization. Where the FOCI stems from majority foreign ownership or control, a FOCI mitigation plan may consist of one of the following methods: (1) Voting Trust Agreement. Under this type of agreement, the foreign owner relinquishes most rights associated with ownership of the company to cleared U.S. citizens approved by the U.S. Government. Foreign owners must transfer legal title of the company to the Trustees. The Voting Trust Agreement does not impose any restrictions on the organization’s eligibility to have access to classified information or matter or to compete for classified contracts. A Government Security Committee (GSC) must be established under the Voting Trust to oversee classified, SNM, and export control activities. (a) All Trustees must become members of the company’s governing board (b) The arrangement must provide for the exercise of all prerogatives of ownership by the Trustees with complete freedom to act independently from the foreign owners, except as provided in the agreement, which may limit the authority of the Trustees by DOE O 470.4B Appendix B, Section 2, Chapter IV 7-21-11 IV-3 requiring approval from the foreign owners with respect to matters such as: 1 the sale or disposal of the company’s assets or a substantial part thereof; 2 pledges, mortgages, or other encumbrances on the company’s assets, capital stock or ownership interests; 3 mergers, consolidations, or reorganizations;

Section 56

4 dissolution of the company; and, 5 filing of a bankruptcy petition. (c) The Trustees assume full responsibility for the foreign owner’s voting interests and for exercising all management prerogatives relating thereto in such a way as to ensure that the foreign owner will be insulated from the company and will solely retain the status of a beneficiary. (d) The company must be organized, structured, and financed to be capable of operating as a viable business entity independent from the foreign owner. (2) Proxy Agreement. Like the Voting Trust Agreement, under this arrangement, the foreign owner relinquishes most rights associated with ownership of the company to cleared U.S. citizens approved by the U.S. Government. Under a Proxy Agreement, the foreign owner’s voting rights are conveyed to the Proxy Holders by the irrevocable Proxy Agreement. Legal title to the shares remains with the non-U.S. citizen(s). All provisions of a Voting Trust Agreement applicable to Trustees, including authorized limitations on the powers of the Trustees, must apply to the Proxy Holders. The Proxy Agreement does not impose any restrictions on the organization’s eligibility to have access to classified information or matter or to compete for classified contracts. The company must be organized, structured, and financed to be capable of operating as a viable entity independent from the foreign owner. Use of a Proxy Agreement requires the establishment of a GSC to oversee classified, SNM, and export control activities. (3) Special Security Agreement. A Special Security Agreement may be considered when a U.S. organization is effectively owned or controlled by a foreign interest and the Federal Government has entered into a general security agreement with the foreign government involved. The Special Security Agreement preserves the foreign shareholder’s right to be Appendix B, Section 2, Chapter IV DOE O 470.4B IV-4 7-21-11 represented on the governing body with a direct voice in the business and management of the company while denying unauthorized access to classified information or matter, or SNM by imposing substantial security and export control measures within an institutionalized set of corporate practices and procedures. SSAs must: (a) require active involvement in security matters of senior management and certain Board members (outside directors), who must be cleared U.S. citizens; (b) provide for the establishment of a GSC to oversee classified, SNM, and export control activities; (c) be based on a Secretarial Waiver as described above if the contract will require access to proscribed information; and (d) require a National Interest Determination (NID) prior to release of proscribed information to the contractor or its cleared employees to certify that release of such information is consistent with the national security interests of the United States. The NID can be program, project, or contract specific. c. Non-controlling Foreign Ownership. A non-controlling foreign ownership is one in which a non-U.S. citizen(s) owns less than a majority of the voting securities of the U.S. organization and/or is not in a position to effectively control the business management of the U.S. organization. Where the FOCI stems from non- controlling foreign ownership or control, a FOCI mitigation plan must consist of either Board Resolution or Security Control Agreement methods. (1) Board Resolution. When a foreign interest does not own voting interests sufficient to elect, or otherwise is not entitled to representation on the company’s governing board, a resolution by the governing board will normally be adequate to mitigate the FOCI concerns. The resolution must identify the foreign shareholder and describe the type and number of foreign-owned shares; acknowledge the company’s obligation to comply with all security and export control requirements; and certify that the foreign owner does not require, will not have, and can be effectively precluded from unauthorized access to all clas

Something wrong with this record? Tell us