Archives of Directives

DOE O 470.6 Chg 1 (MinChg), Technical Security Program - Change Chart

DOE O 470.6 MinChg 1 Change Chart.pdf102.33KB
Document text

Text extracted from the attached file. Refer to the original document for the authoritative version.

Section 1

U.S. Department of Energy MINOR CHANGE Washington, D.C. Approved: 9-2-15 Chg 1: 1-11-17 SUBJECT: MINOR CHANGE TO DOE O 470.6, Technical Security Program 1. EXPLANATION OF CHANGES. The minor change ensures that the Order and DOE Order 205.1B, Department of Energy Cyber Security Program, complement and do not contradict either each other or the delegations and authorities of the Chief Information Officer (CIO) and the Associate Under Secretary for Environment, Health, Safety and Security. The change also removed the requirement for contractors to comply with Attachment 2 (References), and clarified the attachment through a reorganization of the references. 2. LOCATIONS OF CHANGES: Page Paragraph Changed To 1 1.a No change in content, separated into two paragraphs 1 1.b.(3) No change in content, Note removed 1 1.b.(4) No change in content, Note removed 2 3.b. ….. The CRD must be included in contracts that involve classified and/or Sensitive But Unclassified (SBU)/Controlled Unclassified Information (CUI). ….. The CRD must be included in contracts that involve classified information, and be evaluated for inclusion in contracts that involve Sensitive But Unclassified (SBU)/Controlled Unclassified Information (CUI). 3 3.f …. Equivalencies and exemptions dealing with COMSEC issues can only be granted by the Central Office of Record. Removed. Requirement established in applicable National Policies and within DOE O 470.6. DOE O 470.6 Page Paragraph Changed To 3 3.g. Added g. Relationship to DOE Cyber Security Order, DOE O 205.1 DOE Order 205.1B and DOE Order 470.6 complement each other in the security protections each Order addresses, both for the Cyber Security Program and the TSP as defined in each Order. Additionally, the Orders complement, and do not contradict, the delegations and authorities of the Chief Information Officer (CIO) and the Associate Under Secretary for Environment, Health, Safety and Security. A risk management approach is applicable for the implementation of cyber security and technical security, except for those requirements within the TSP that require compliance based on laws, regulations, Executive Orders, and other cognizant government agency Orders. When a deviation from a non-DOE requirement is identified, it must be resolved in accordance with the appropriate governing instruction. Inability to comply must be brought to the attention of the TSP Director and the appropriate authority such as the respective Program Secretarial Officer and CIO for matters involving cyber security. 4 4.a Only properly trained and certified individuals will conduct TSP operational program activities, such as TSCM services, TSP Reviews, COMSEC utilization determinations, or TEMPEST reviews in accordance with this Order. Only trained and certified individuals will conduct TSP operational program activities, such as TSCM services, TSP Reviews, COMSEC utilization determinations, or TEMPEST reviews in accordance with this Order and National Requirements. 3 4.b All classified and sensitive unclassified information in all forms must be protected in accordance with all applicable laws, regulations, policies, and directives. Removed. Established in Law, National Policies and Applicable DOE Directives. 4 4.c No change in content Paragraph 4.b. Page Paragraph Changed To

Section 2

4 4.d Documentation relevant to the TSP and this Order must be maintained and upon request provided to the Director, TSP. Distribution of the classified TSP Annexes is limited to the TSP programmatic channels, their designees, or others as determined by the Director, TSP, based upon a need-to-know determination. 4.c. Information required by this Order relevant to the TSP and this Order must be maintained and, upon request, provided to the Director, TSP. Distribution of the classified TSP Annexes is limited to the TSP programmatic channels, their designees, or others as determined by the Director, TSP, based upon a need-to-know determination. 4 4.e.-4.h. No change in content Re-ordered to 4.d.-4.g. 5 5.b.(1) Establishes, funds and maintains a TSP. Ensures that an adequate number of qualified personnel and the appropriate equipment are available to effectively support the TSP mission requirements within the NNSA. Ensures that an adequate number of qualified personnel and the appropriate equipment are available to effectively support the TSP mission requirements within the NNSA. 5 5.b.(3) The NNSA TSP must report any unauthorized electronic device or technology discovery, or suspect anomaly/potential compromise to the DOE TSP immediately. NNSA must report any unauthorized electronic device or technology discovery, or suspect anomaly/potential compromise to the DOE TSP immediately. 5 5.e. Associate Undersecretary for Health, Safety and Security. Associate Under Secretary for Environment, Health, Safety and Security 6 5.g.(1) Authorizes appropriate DOE organizations to conduct TSP services, acquire and possess TSP equipment, and have TSCM/TEMPEST Service practitioners. Provides Concurrence or Non- Concurrence to appropriate DOE organization/program office to conduct TSP services, acquire and possess TSP equipment, and to have TSCM/TEMPEST Service practitioners. 7 5.g.(13) Approves TSCM and TEMPEST specific training content and equipment purchases. Approves TSCM and TEMPEST specific training content, and coordinates with programs to ensure an enterprise approach to equipment procurement. 7 5.g.(16) Added Coordinate with DOE CIO on the development of TSP policy that directly or indirectly affects the implementation of departmental cyber policies. Page Paragraph Changed To 7 5.g.(17) Added Alert CIOs and Authorizing Officials of potential impacts to cyber programs within sites that fall under TSP. Assist in developing remediation strategies consistent with federal law and departmental risk management strategies. 7 5.g.(18) Added Coordinates with CIOs to facilitate exchange of information specific to threats to information systems. 8 5.i.(1) No change in content Re-ordered to 5.i.(7) 8 5.i.(1) Added The CIO recognizes intrinsic relationship between TSP and cyber and the need for increased security for systems under TSP. Any deviation from federal requirements will be handled in accordance with governing directives and in coordination through the appropriate Program Office. The roles and responsibilities of the DOE CIO are defined in DOE Order 205.1B 8 5.i.(2)-(5) Removed 8 5.i.(2) Added Coordinate with the TSP Director on the development of TSP policy that directly or indirectly affects the implementation of Departmental cyber policies. 8 5.i.(3) Added Develop Departmental response to potential cyber impacts to sites that fall under TSP. Assist appropriate Program Offices in developing remediation strategies consistent with federal law and Departmental risk management strategies.

Section 3

8 5.i.(4) Added Coordinates with DOE TSP to facilitate exchange of information specific to threats to information systems. Page Paragraph Changed To 9 5.i.(5) Added Represent the Department’s cyber position as it relates to TSP. Any official representation or responses to Other Government Agencies (OGAs) on cyber issues related to CIO authorities must be coordinated through DOE CIO as applicable. 9 5.i.(6) Added Alerts Director TSP of potential cyber issues that may impact technical security and operations. Assist in developing remediation strategies consistent with federal regulation and departmental risk management strategies. 9 5.i.(8) Added Coordinates between TSP and OGAs for cyber related issues affecting TSP activities. 10 6.b. Cognizant Security Authority. See definition for Officially Designated Federal Security Authority (ODFSA). Cognizant Security Authority/Officer. An entity charged with responsibility for physical, technical, personnel, and information security affecting that organization. (Within DOE this is defined as the ODFSA. See definition for ODFSA). Attachment 1 2 Regardless of the performer of the work, contractors must comply with the requirements of attachments 2, 3 (including its Classified annex), 4 and 5 to DOE 470.6 referenced in and made part of this CRD and providing program requirements and information applicable to contracts in which this CRD is inserted. Contractors must also comply with DOE program offices and NNSA direction provided through the contract. Regardless of who performs the work, contractors must comply with the requirements of Attachments 3 (including its Classified annex), 4, and 5 to DOE 470.6 referenced in and made part of this CRD and provide program requirements and information applicable to contracts in which this CRD is inserted. Attachment 1 3 No Change in content, Moved to Paragraph 6. Paragraph 6 Page Paragraph Changed To Attachment 1 4 Contractors must comply with applicable laws, regulations, policies, directives and other requirements as directed through contract by the NNSA or other DOE program office(s). The contractor must establish and maintain an effective assurance system that provides appropriate transparency to Federal oversight regarding TSP programs and overall performance. Paragraph 3 Contractors must comply with applicable laws, regulations, policies, directives and other requirements as directed through contract by the NNSA or other DOE program office(s). Attachment 1 5 No change in Content Paragraph 7. Attachment 1 6 ….. CUI Registry, must develop and maintain a graded risk process and assessment for the protection of SBU/CUI in accordance with the requirements of attachments 2, 3, 4 and 5 to DOE Order 470.6.The graded risk process and assessment must be available to the responsible ODFSA, upon request. Moved to Paragraph 8 and ….. CUI Registry, must develop and maintain a graded risk process and an assessment for the protection of SBU/CUI in accordance with the requirements of attachments, 3, 4 and 5 to DOE Order 470.6. The graded risk process and assessment must be available to the responsible ODFSA, upon request. Attachment 1 Added Paragraph 4 – In performing work under this contract, the Contractor shall comply with the requirements of applicable federal, state, and local laws and regulations (including DOE regulations), unless relief has been granted in writing by the appropriate regulatory agency. A list of laws, regulations and references to assist in implementing this Order are identified in attachment 2 for informational purposes. Omission of any applicable law or regulation from attachment 2 does not affect the obligation of the Contractor to comply with such law or regulation pursuant to this Order.

Section 4

Page Paragraph Changed To Attachment 1 Added Paragraph 5 Contractors must also comply with DOE program offices and NNSA direction provided through the contract Attachment 2 Page 1 1.a.-1.c. Added 1. PURPOSE: a. This attachment provides information for use in implementing the programs implemented by this Order. b. Implementation of this Order shall comply with the requirements of applicable Federal, State, and local laws and regulations (including DOE regulations), unless relief has been granted in writing by the appropriate regulatory agency. c. Omission of any applicable law or regulation from this attachment does not affect the obligation of to comply with current or future laws and regulations pursuant to this Order. Page Paragraph Changed To Attachment 2 Page 1 1 1. OBJECTIVE. The following list of references is provided to assist in implementing this Directive. The requirements contained in these national-level documents are to be adhered to unless the appropriate equivalency or exemption has been approved. This list is not exhaustive and other National TSP policies, to include those with titles that are either Official Use Only or classified are not contained in this list, but are still required to be fully implemented. Any successor documents to these references must also be adhered to. 1. PURPOSE: d. A list of Other Government Requirements and Reference Information to assist in implementing the topics covered by this Order are identified in section 2 and 3. e. This attachment includes documents from various sources, each having differing conventions for denoting requirements. Federal and contractor personnel must consult the governing document system to determine the language used to distinguish requirements from recommended practices. f. Where the document system does not include such a description, common usage prevails. If a question arises regarding whether a specific provision is a requirement, contact the TSP Office for clarification. g. The documents listed within sections 2 and 3 should be construed to include any superseding issuance. h. This attachment only identifies unclassified, publicly releasable titles. Official Use Only (OUO) and Classified titled documents may be obtained by contacting the TSP. Attachment 2 2. 2.a.-2.o. 2.e. and 3.f. References re-ordered for clarity and format. References remain the same. Attachment 2 Page 1-2 2. Added. 2. OTHER GOVERNING REQUIREMENTS a. This section provides a listing of documents that include requirements that are binding upon DOE personnel and contractors independent of this Order. b. This section also includes related Departmental Directives which are binding upon Federal personnel as specified in their applicability sections, and are binding upon contractors when their CRDs are included in the contract. c. This section also includes public laws, Executive Orders, and issuances of the governing security authorities that serve as conditions for the use of the security systems that DOE employs. These requirements are made mandatory for DOE Federal and Contractor personnel by means other than this Order and must be followed when implementing the requirements of this Order.

Section 5

d. Committee on National Security Systems (CNSS) issuances are directed at those entities that own and/or are users of national security systems. The Heads of the Executive Departments and Agencies are responsible for ensuring that CNSS policies and directives are implemented within their departments or agencies. CNSS instructions provide guidance and technical criteria for specific Information Assurance (IA) issues. Contractors supporting the Executive Departments and Agencies are required to protect National Security Systems consistent with the CNSS requirements. (1) CNSS Policies address national security systems Page Paragraph Changed To issues from a broad perspective. They establish national-level goals and objectives, all of which are binding upon all U.S. Government departments and agencies. (2) CNSS Directives address national security systems issues that go beyond the general policy documented under CNSS the policies topic. These directives provide details for achieving CNSS policies and are binding upon all U.S. Government departments and agencies. (3) CNSS Instructions provide guidance and establish technical criteria for specific national security systems issues. These instructions include technical or implementation guidelines, restrictions, doctrines, and procedures applicable to information assurance. All instructions are binding upon all U.S. Government departments and agencies. Page Paragraph Changed To Attachment 2 Pages 3. Added 3. REFERENCE INFORMATION a. This section provides a documents and website that provide useful information, strategies, guidance, industry standards, best practices and policies. b. These documents may not be binding requirements as standalone documents, but the documents maybe invoked as required to be utilized by other issuance in specific instances, such as Certified TEMPEST Technical Authority (CTTA) evaluations and testing requirements. c. If not invoked within this Order or Other Governing Requirements, these documents should be considered and used as guides in the development of programs covered by this Order. d. Although not invoked as requirements by this Order, deviations from these documents should be justified. e. The listing of websites provides location where related information and some of the requirements documents associated with this Order may be located. These websites are provided to assist in locating information for implementation of the programs. The websites are not invoked as requirements by this Order.

Something wrong with this record? Tell us