National Industrial Security Program Operating Manual (NISPOM)
Federal RegisterDec 21, 2020
Ask Donna
What actually matters in this document.
Text
DEPARTMENT OF DEFENSE
Office of the Secretary
32 CFR Part 117
[Docket ID: DOD-2020-OS-0045]
RIN 0790-AK85
National Industrial Security Program Operating Manual (NISPOM)
AGENCY:
Office of the Under Secretary of Defense for Intelligence & Security, Department of Defense (DoD).
ACTION:
Final rule with request for comment.
SUMMARY:
The Department of Defense (DoD) is codifying the National Industrial Security Program Operating Manual (NISPOM) in regulation. The NISPOM establishes requirements for the protection of classified information disclosed to or developed by contractors, licensees, grantees, or certificate holders (hereinafter referred to as contractors) to prevent unauthorized disclosure. In addition to adding the NISPOM to the Code of Federal Regulations (CFR), this rule incorporates the requirements of Security Executive Agent Directive (SEAD) 3, “Reporting Requirements for Personnel with Access to Classified Information or Who Hold a Sensitive Position.” SEAD 3 requires reporting by all contractor cleared personnel who have been granted eligibility for access to classified information. This NISPOM rule provides for a single nation-wide implementation plan which will, with this rule, include SEAD 3 reporting by all contractor cleared personnel to report specific activities that may adversely impact their continued national security eligibility, such as reporting of foreign travel and foreign contacts. NISP Cognizant Security Agencies (CSAs) shall conduct an analysis of such reported activities to determine whether they pose a potential threat to national security and take appropriate action. Finally, the rule also implements the provisions of Section 842 of Public Law 115-232, which removes the requirement for a covered National Technology and Industrial Base (NTIB) entity operating under a special security agreement pursuant to the NISP to obtain a national interest determination as a condition for access to proscribed information.
DATES:
Effective date:
This rule is effective February 24, 2021. Comments must be received by February 19, 2021.
ADDRESSES:
You may submit comments, identified by docket number and/or Regulatory Information Number (RIN) and title, by any of the following methods:
• Federal Rulemaking Portal: http://www.regulations.gov.
Follow the instructions for submitting comments.
•
Mail:
DoD cannot receive written comments at this time due to the COVID-19 pandemic. Comments should be sent electronically to the docket listed above.
Instructions:
All submissions received must include the agency name and docket number or RIN for this
Federal Register
document. The general policy for comments and other submissions from members of the public is to make these submissions available for public viewing at
http://www.regulations.gov
as they are received without change, including any personal identifiers or contact information.
FOR FURTHER INFORMATION CONTACT:
Valerie Heil, 703-692-3754.
SUPPLEMENTARY INFORMATION:
I. Overview of the NISP and NISPOM
In April 1990, President George Bush directed the National Security Council to explore the creation of a single, integrated industrial security program to improve security protection and provide cost savings. Prior to this, contractors doing business with different U.S. Government (USG) agencies which required access to classified information had to meet different requirements to protect the same levels of classified information,
e.g.,
the type of safe to protect a specific classified item could vary across both contracts and agencies. The diversity of industrial security requirements levied on contractors by an estimated 21 USG agencies created a significant burden on both industry and government and increased the cost of the goods and services provided to the USG.
Representatives from government and industry participated in an initiative which led to the creation of Executive Order (E.O.) 12829 “National Industrial Security Program (NISP)” (available at
https://www.archives.gov/files/isoo/policy-documents/eo-12829-with-eo-13691-amendments.pdf
). With the National Security Council providing overall policy direction, this E.O. established the NISP as the single integrated program to protect classified information and preserve our Nation's economic and technological interests. Nothing in the E.O. shall supersede the authority of the Secretary of Energy or the Nuclear Regulatory Commission under the Atomic Energy Act of 1954, as amended, or the authority of the Director of National Intelligence (or any Intelligence Community element) under the Intelligence Reform and Terrorism Prevention Act of 2004, the National Security Act of 1947, as amended, or Executive Order No. 12333 of December 8, 1981, as amended, or the authority of the Secretary of Homeland Security, as the Executive Agent for the Classified National Security Information Program established under Executive Order 13549 of August 18, 2010 (Classified National Security Information Program for State, Local, Tribal, and Private Sector Entities). The Information Security Oversight Office (ISOO), a component of the National Archives and Records Administration (NARA), was tasked with overseeing overall implementation of the NISP with the goal of:
• Holding classification activity to the minimum necessary to protect the national security;
• ensuring the safeguarding of classified national security information in both USG and industry in a cost-effective and efficient manner; and
• promoting declassification and public access to information as soon as national security considerations permit.
ISOO issues implementing directives and produces an annual report to the President on the NISP. E.O. 12829 also established the National Industrial Security Program Policy Advisory Committee (NISPPAC), a federal advisory committee comprised of both Government and industry representatives, which is responsible for recommending changes in industrial security policy. The NISPPAC, chaired by the Director of the ISOO, also advises ISOO on all issues concerning the policies of the NISP, including recommended changes to those policies, and serves as a forum to discuss policy issues in dispute. The NISPPAC industry members represent all types and sizes of NISP cleared entities, whose scope of operations range from a one person entity, having a single classified contract to some of the largest U.S. entities, having numerous classified contracts. All NISPPAC industry members have expertise comprising the primary functions of an industrial security program, to include information, personnel, physical, and information system security.
Five USG executive branch agencies—DoD, DOE, the Nuclear Regulatory Commission (NRC), the Office of the Director of National Intelligence (ODNI), and the Department of Homeland Security (DHS)—have been designated as Cognizant Security Agencies (CSAs) and have specific responsibilities within the NISP. For DoD, the Defense Counterintelligence and Security Agency (DCSA) is the Cognizant
Security Office (CSO) for DoD Components and non-DoD agencies where an industrial security agreement is in place. DCSA, as the DoD CSO, DOE, and NRC each has the following responsibilities:
• Administers the NISP.
• provides security oversight.
• conducts security review actions.
• provides security education and training.
• provides supplementary procedures for unique mission requirements (
e.g.
DoD publishes industrial security letters (ISLs), which provide DoD-specific guidance and clarification on NISP policies and supplementary procedures to its unique CSO mission requirements (available at:
https://www.dcsa.mil/mc/ctp/tools/
)).
• assesses, authorizes and oversees contractor information systems used to process classified information.
• makes temporary national security eligibility determinations pursuant to SEAD 8, Temporary Eligibility (available at:
https://www.dni.gov/files/NCSC/documents/Regulations/SEAD-8_Temporary_Eligibility_U.pdf
), for contractor personnel who require access to classified information.
DHS receives NISP industrial security services from DoD due to its industrial security services agreement and also has the following responsibilities:
• Prescribes procedures for the portions of this rule that pertain to the CCIPP.
• retains authority over access to information under the CCIPP.
• inspects and monitors contractor, licensee, certificate holder, and grantee programs and facilities that involve access to CCIPP.
ODNI has the following responsibilities:
• Prescribes procedures for the portions of this rule pertaining to intelligence sources, methods, and activities, including, but not limited to, SCI.
• retains authority over access to intelligence sources, methods, and activities, including SCI.
• provides guidance on the security requirements for intelligence sources and methods of information, including, but not limited to, SCI.
DOE and NRC provide similar industrial security oversight actions, including national security eligibility determinations for contractor personnel, authorization of contractor information systems to process classified information, as well as monitoring and inspecting those contractors under DOE or NRC security cognizance, respectively. In 2004, the Intelligence Reform and Terrorism Prevention Act (IRTPA) (Pub. L. 108-458) created the position of the Director of National Intelligence (DNI) and recognized the ODNI as a CSA. E.O. 13691 “Promoting Private Sector Cybersecurity Information Sharing,” February 13, 2015 (available at
https://obamawhitehouse.archives.gov/the-press-office/2015/02/13/executive-order-promoting-private-sector-cybersecurity-information-sharing
), amended E.O. 12829 to make DHS the fifth CSA in 2015.
II. NISP Implementation
DoD is the Executive Agent of the NISP and has the largest NISP contractor population of the five CSAs. DCSA inspects and monitors cleared entities, also referred to as contractors, who require access to classified information during all phases of the contracting, licensing, and grant (hereinafter referred to as contracting or contract) process to include the preparation and submission of bids and proposals, negotiation, award, performance, and termination. It also determines eligibility for access to classified information for contractors performing on classified contracts with DoD and with those USG agencies which have an industrial security agreement with DoD. The Department currently has industrial security agreements with 33 agencies (list available at:
https://www.dcsa.mil/mc/ctp/nisp/
). DCSA field elements provide oversight of contractor compliance, authorize contractor information systems to process classified information, and conduct security review actions for approximately 12,500 cleared contractor entities which includes headquarters, divisions, subsidiaries and branch offices of industrial, educational, commercial, or other non-USG entities which are performing on classified contracts.
Under the NISP, the USG establishes requirements for the protection of classified information to be safeguarded in a manner equivalent to its protection within the executive branch of USG, where practicable. When bound by contract, industry must comply with the NISPOM and any CSA-specific supplementary guidance for unique CSA mission requirements. Industry implements those requirements for the protection of classified information with advice, assistance, and oversight from the applicable CSA.
When a Government Contracting Activity (GCA), an element of an agency that has authority regarding acquisition or grant functions, awards a contract that has been determined to require access to classified information, the contract is considered to be a “classified contract.” The GCA checks with its applicable CSA to determine if the awarded legal entity already has an entity eligibility determination (also referred to as a facility security clearance (FCL)). GCAs will ordinarily include enough lead-time in the acquisition cycle to accomplish all required security actions. In many instances, advanced planning can ensure that access to classified information will not be required in the pre-award process. This would preclude processing an entire bidder list for FCLs. When access to classified information is not a factor in the pre-award phase, but will be required for contract performance, only the successful bidder or offeror will be processed for an FCL.
Before an entity can have access to classified information during its contract performance, it must have an FCL. If the legal entity does not already have an FCL when awarded a classified contract, a GCA must sponsor the entity for an FCL. Or, an entity already part of the NISP (
i.e.,
a prime contractor) may sponsor another entity in order to subcontract part of its classified business. To sponsor an entity, the GCA or prime contractor puts in a request, often referred to as a sponsorship letter, to the appropriate CSA for the entity to access classified information in connection with a legitimate government requirement, which may include a foreign government requirement.
With an approved FCL, an entity is then eligible for access to information classified at the level of the FCL (
i.e.,
TOP SECRET, SECRET or CONFIDENTIAL) when competing for a classified contract. Among other requirements, an entity must have sponsorship based on a valid government requirement for access to classified information. The USG agency sponsoring an entity for an FCL must include the applicable security requirements clause or equivalent in the contract (
e.g.
, for DoD this is the Federal Acquisition Regulation (FAR) 52.204-2 “Security Requirements,” or the terms and conditions of a grant award under 2 CFR part 200.210) to require compliance with the NISPOM.
A GCA provides the security requirements for a classified contract in a contract security classification specification as part of the contract. For DoD, the DD form 254, “Department of Defense Contract Security Classification Specification,” OMB Control number 0704-0567, is part of the classified contract and provides the contractor (or a subcontractor) with security requirements and the classification
guidance necessary to execute a specific classified contract. See
https://www.esd.whs.mil/Portals/54/Documents/DD/forms/dd/dd0254.pdf
and available at
https://www.dcsa.mil/is/nccs/
) for the current version of this collection. A contract security classification specification with its attachments, supplements, and incorporated references, provides security classification guidance (lists the applicable security classification guides for a contractor to use) to a contractor in connection with a classified contract. It is designed to identify the classified areas of information involved in the classified effort and, particularly, to identify the specific items of information within these areas that require protection. This rule provides NISP contractors security requirements which align to 32 CFR part 2001, in a manner equivalent to the protection of classified information within the executive branch of the USG. If a GCA determines that additional safeguards are essential in specific contracts, the GCA can impose more operational security provisions above the requirements of this rule. The GCA can also determine that additional physical or technical security requirements are needed in a contract above the requirements of this rule. Even though the contract security classification is contract-specific, it is not always all-inclusive. Additional security requirements are sometimes included in other parts of a contract. All related materials for approved information collection are available at:
https://www.reginfo.gov/public/do/PRAMain.
In addition, specific locations for finalized collection instruments, to include the designated OMB Control Number is included where information collections are cited in this rule.
In addition, depending upon the CSA with security cognizance, an entity's legal headquarters may need to implement additional information collections, such as:
• DD Form 441, “DoD Security Agreement” for DoD is an agreement between DCSA and the cleared legal entity for the entity to comply with the NISPOM security requirements, to be subject to inspections and to allow for a 30 day notice by the entity or DCSA to terminate the agreement (
e.g.,
if there is no longer a valid USG requirement for access to classified information (available at
https://www.esd.whs.mil/Portals/54/Documents/DD/forms/dd/dd0441_2020.pdf
);
• NRC Form 441, “Security Agreement” for NRC, the provisions of the NRC Form 441 are similar to those included in the DD Form 441 (available at
https://www.nrc.gov/reading-rm/doc-collections/forms/nrc441info.html
).
• DOE does not have a separate Form 441, but instead, binds the contractor to the FCL (and security requirements) via the contract, along with meeting all other requirements in this rule.
As part of FCL processing, an entity must complete a Standard Form (SF) 328, “Certificate Pertaining to Foreign Interest,” OMB Control number 0704-0579, (available at
https://www.gsa.gov/forms-library/certificate-pertaining-foreign-interests,
for a CSA to review and make a determination whether the entity is under foreign ownership, control or influence (FOCI) to a degree that renders it ineligible for an FCL. The CSA will consider a U.S. entity to be under FOCI when a foreign interest has the power to direct or decide issues affecting the entity's management or operations in a manner that could either result in unauthorized access to classified information; or adversely affect performance of a classified contract or agreement. The U.S. entity may also be considered to be under FOCI when a foreign interest or government is currently exercising, or could exercise, that power, whether directly or indirectly, such as through ownership of the U.S. entity's securities, by contractual arrangements, or other means. Further, if a foreign interest or government has the ability to control or influence the election or appointment of members of the entity's governing board, the entity may be considered to be under FOCI. When a CSA has determined that an entity is under FOCI, the primary consideration will be the protection of classified information. The CSA will take whatever action is necessary to protect classified information, in coordination with other affected agencies as appropriate. A U.S. entity that is in process for an FCL for access to classified information and subsequently determined to be under FOCI, is ineligible for access to classified information unless and until effective security measures have been put in place to negate or mitigate FOCI to the satisfaction of the CSA.
Once an entity becomes a contractor in the NISP with an existing FCL, a GCA can select and award a classified contract to the entity as part of the acquisition process. The GCA attaches the “Contract Security Classification Specification: (
e.g.,
for DoD, it is the DD Form 254, available at
https://www.esd.whs.mil/Portals/54/Documents/DD/forms/dd/dd0254.pdf
and available at
https://www.dcsa.mil/is/nccs/
), to all such contracts requiring access to classified information.
II. SEAD 3 Requirements and the NISPOM
In 2008, with the publication of E.O. 13467, “Reforming Processes Related to Suitability for Government Employment, Fitness for Contractor Employees, and Eligibility for Access to Classified National Security Information” (available at
https://obamawhitehouse.archives.gov/the-press-office/2016/09/29/executive-order-amending-executive-order-13467-establish-roles-and
), the DNI was assigned the role of the Security Executive Agent (SecEA), for the development, implementation, and oversight of effective, efficient, and uniform policies and procedures governing the conduct of investigations and adjudications for eligibility for access to classified information and eligibility to hold a sensitive position.
In December 2016, the SecEA issued SEAD 3, “Reporting Requirements for Personnel with Access to Classified Information or Who Hold a Sensitive Position” (available at
https://www.dni.gov/files/NCSC/documents/Regulations/SEAD-3-Reporting-U.pdf
), to executive branch agencies or covered individuals with an effective date of June 12, 2017. SEAD 3 defines covered individuals as:
• A person who performs work for or on behalf of the executive branch who has been granted access to classified information or holds a sensitive positions, but does not include the President or the Vice President.
• a person who performs work for or on behalf of a state, local, tribal, or private sector entity, as defined in E.O. 13549, who has been granted access to classified information or holds a sensitive position, but does not include duly elected or appointed governors of a state or territory, or an official who has succeeded to that office under applicable law; and
• a person working in or for the legislative or judicial branches who has been granted access to classified information or holds a sensitive position and the investigation or determination was conducted by the executive branch, but does not include members of Congress, Justices of the Supreme Court, or Federal judges appointed by the President.
• covered individuals are not limited to government employees and include all persons, not excluded under paragraphs D.5(a), (b), or (c) of SEAD 3, who have access to classified information or who hold sensitive positions, including, but not limited to, contractors, subcontractors, licensees, certificate holders, grantees, experts,
consultants, and government employees.
SEAD 3 identifies required reporting of data elements that are contained in the Standard Form-86, “Questionnaire for National Security Positions” (available at
https://www.opm.gov/forms/pdf_fill/sf86.pdf
), which applicants and clearance holders complete during the initial and periodic reinvestigation processes, respectively. SEAD 3 requires these elements to be reported prior to participation in such activities or otherwise as soon as possible following the start of their involvement. Most notably, SEAD 3 requires covered individuals to obtain prior agency approval before conducting unofficial foreign travel.
For this rule, SEAD 3 applies only for those contractor personnel who have been granted eligibility for access to classified information through the NISP. In accordance with paragraph E.4 of SEAD 3, NISP CSAs, acting on behalf of Heads of agencies or designees, for the NISP contractors under their security cognizance may determine that operational and mission needs preclude strict adherence to these reporting requirements. In those instances, a NISP CSA may provide CSA guidance to supplement unique CSA mission requirements to the contractors under its security cognizance of equivalent notification, briefing and reporting to be accomplished.
III. Requirements From Section 842 of Public Law 115-232
Currently, the NISPOM and 32 CFR part 2004 require that GCAs, in coordination with the applicable CSAs and controlling agencies (ODNI for Sensitive Compartmented Information (SCI), DOE for Restricted Data (RD) or NSA for Communications Security (COMSEC)), complete a National Interest Determination (NID) before granting access to proscribed information to an entity that is owned or controlled by a foreign interest and cleared under a Special Security Agreement (SSA). The term “proscribed information” means information that is—
(A) classified at the level of top secret;
(B) communications security information (excluding controlled cryptographic items when un-keyed or utilized with unclassified keys);
(C) Restricted Data (as defined in section 11 of the Atomic Energy Act of 1954, as amended (42 United States Code (U.S.C.) 2014));
(D) special access program information under section 4.3 of E.O. 13526 (75 FR 707; 50 U.S.C. 3161 note) or successor order; or
(E) designated as sensitive compartmented information, as defined in Intelligence Community Directive 703, “Protection of National Intelligence, Including Sensitive Compartmented Information” (available at
https://www.dni.gov/files/documents/ICD/ICD%20703.pdf
).
An SSA is one of the mechanisms used by the USG to mitigate FOCI to an acceptable level as determined by the CSA. A company is considered to be operating under FOCI whenever a foreign interest has the power, direct or indirect, whether or not exercised, and whether or not exercisable, to direct or decide matters affecting the management or operations of that company in a manner which may result in unauthorized access to classified information or may adversely affect the performance of classified contracts. The following factors relating to a company, the foreign interest, and the government of the foreign interest are reviewed in the aggregate in determining whether a company is under FOCI:
Record of economic and government espionage against U.S. targets
Record of enforcement and/or engagement in unauthorized technology transfer
The type and sensitivity of the information that shall be accessed
The source, nature and extent of FOCI
Record of compliance with pertinent U.S. laws, regulations and contracts
The nature of any bilateral and multilateral security and information exchange agreements that may pertain
Ownership or control, in whole or in part, by a foreign government.
Section 842 of Public Law 115-232 and this final rule provide that a covered NTIB entity operating under an SSA pursuant to the NISP, shall not be required to obtain a NID as a condition for access to proscribed information, effective October 1, 2020. DoD notified the DoD components and 33 non-DoD agencies with which DoD has industrial security agreements that NIDs pursuant to the provisions of Section 842 of Public Law 115-232 are no longer required as of October 1, 2020. DCSA is no longer submitting NID requests to ODNI for SCI, DOE for RD, or NSA for COMSEC, respectively that fall within the provisions of Section 842 of Public Law 115-232.
As provided for in the law, the Under Secretary of Defense for Intelligence and Security, on behalf of the Secretary, granted waivers of NIDs for those categories of proscribed information under the control of the Secretary of Defense, to 20 contractors that met the criteria in summer 2019 with the waivers expiring as of October 1, 2020, since the statute went into effect. Those contractors, pursuant to Section 842 of Public Law 115-232 had to meet the following criteria as part of the waiver determination:
(1) A demonstrated successful record of compliance with the NISP assessed by the CSA; and
(2) previously been approved for access to proscribed information as indicated in CSA FCL records.
The law is limited to “a person that is a subsidiary located in the United States—
(A) for which the ultimate parent entity and any intermediate parent entities of such subsidiary are located in a country that is part of the national technology and industrial base (as defined in section 2500 of title 10, United States Code); and
(B) that is subject to the FOCI requirements of the NISP.”
Legal Authority for the NISP
In addition to E.O. 12829, which, establishes the NISP and requires the Secretary of Defense to issue and maintain the NISPOM, the following are other relevant authorities for the program.
• E.O. 10865 “Safeguarding Classified Information within Industry,” February 20, 1960, as amended (available at
https://www.archives.gov/federal-register/codification/executive-order/10865.html
), addresses the protection of classified information that is disclosed to, or developed by contractors.
• E.O. 12968, “Access to Classified Information,” August 2, 1995, as amended (available at
https://www.govinfo.gov/content/pkg/FR-1995-08-07/pdf/95-19654.pdf
), establishes a uniform personnel security program for individuals who will be considered for initial or continued access to classified information.
• E.O. 13526, “Classified National Security Information,” December 29, 2009 (available at
https://www.archives.gov/files/isoo/pdf/cnsi-eo.pdf
), prescribes a uniform system for classifying, safeguarding and declassifying national security information.
• E.O. 13587, “Structural Reforms to Improve the Security of Classified Networks and the Responsible Sharing and Safeguarding of Classified Information,” October 7, 2011 (available at
https://www.govinfo.gov/app/details/CFR-2012-title3-vol1/CFR-2012-title3-vol1-eo13587
), directs structural reforms to ensure responsible sharing and safeguarding of classified information on computer networks consistent with
appropriate protection for privacy and civil liberties.
• E.O. 13691; Promoting Private Sector Cybersecurity Information Sharing,” February 13, 2015 (available at
https://obamawhitehouse.archives.gov/the-press-office/2015/02/13/executive-order-promoting-private-sector-cybersecurity-information-sharing
), encourages the voluntary formation of organizations engaged in the sharing of information related to cybersecurity risks and incidents to establish mechanisms to continually improve their capabilities and functions as well as to better allow them to partner with the Federal government on a voluntary basis.
• E.O. 12333; “United States Intelligence Activities,” December 4, 1981, as amended (available at
https://www.archives.gov/federal-register/codification/executive-order/12333.html,
provides general principles that in addition to and consistent with applicable laws are intended to achieve the proper balance between the acquisition of essential information and the protection of individual interests.
• Title 42 U.S.C. 2011
et seq.
(also known as and referred to in this rule as “The Atomic Energy Act of 1954,” as amended (AEA));
• Title 50 U.S.C. chapter 44 (also known as “The National Security Act of 1947, as amended);
• Title 50 U.S.C. 3501
et seq.
(also known as “The Central Intelligence Agency Act of 1949,” as amended);
• Public Law 108-458 (also known as the “Intelligence Reform and Terrorism Prevention Act of 2004”), which includes development of uniform and consistent policies and procedures to ensure effective, efficient and timely completion of security clearances.
• Finally, 32 CFR part 2004 “National Industrial Security Program,” May 7, 2018, establishes uniform standards for the NISP, and helps agencies implement requirements in E.O. 12829, and establishes agency responsibilities for implementing the insider threat provisions of E.O. 13587.
III. Changes Made by This Rule and Expected Impact
The NISPOM was first published in 1995 as DoD Manual 5220.22. Updates to the NISPOM have included Conforming Change 1, March 28, 2013 and NISPOM Change 2 in May 21, 2016. The most current version of the NISPOM (Change 2) is available at
https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodm/522022M.pdf?ver=2019-06-06-145530-170.
In addition to codifying the NISPOM in the CFR and adding the requirements of SEAD 3 and Section 842 of Public Law 115-232, DoD is also removing 32 CFR part 117, subpart C, “National Industrial Security Program” because it is duplicative of 32 CFR part 2004, “National Industrial Security Program” and removing 32 CFR part 117, subpart B, because it is also duplicative of other industrial security provisions set forth in 32 CFR part 2004. These administrative removals support a recommendation from the DoD Regulatory Reform Task Force created under E.O. 13777, Enforcing the Regulatory Reform Agenda (available at
https://www.govinfo.gov/content/pkg/FR-2017-03-01/pdf/2017-04107.pdf
), and by themselves create no changes in current DoD policy. Upon the effective date of 32 CFR part 117, DoD will no longer publish the DoD Manual 5220.22, NISPOM as a DoD policy issuance.
Specific changes in this rule that are not in the current NISPOM, include the following.
•
§ 117.8: Reporting Requirements. § 117.8(a) General
includes that contractors must submit reports pursuant to this rule, SEAD 3 and CSA guidance to supplement unique CSA mission requirements. SEAD 3 reporting establishes a single nationwide implementation plan for covered individuals, which for this rule provides reporting by contractors and their employees eligible for access to classified information. SEAD 3 requirements will be implemented for all contractor cleared personnel to report specific activities that may adversely impact their continued national security eligibility. Contractor cleared personnel must be aware of risks associated with foreign intelligence operations and/or possible terrorist activities directed against them in the United States and abroad, and have a responsibility to recognize and avoid personal behaviors and activities that adversely affect their national security eligibility. NISP CSAs shall conduct an analysis of such reported activities, such as foreign travel or foreign contacts, to determine whether they pose a potential threat to national security and take appropriate action. Contractors will be responsible for collecting the foreign travel data from cleared employees, providing pre- and post-travel briefings to those cleared employees when necessary, and tracking and reporting those foreign travel activities of its cleared employees through the CSA designated system of record for personnel security clearance data.
•
§ 117.9(m) Limited entity eligibility determination (Non-FOCI)
and,
§ 117.11(e) Limited entity eligibility determination due to FOCI.
In accordance with 32 CFR part 2004, “NISP Directive,” provisions for granting two new types of limited entity facility clearance eligibility determinations (FCLs) to meet government requirements for narrowly scoped requirements for a companies to access classified information.
•
§ 117.11(d)(2)(iii)(A) Requirement for National Interest Determinations (NIDs):
This paragraph provides for the implementation of the provisions of Section 842 of Public Law 115-232, which was effective on October 1, 2020, and eliminates requirements for a covered NTIB entity operating under an SSA to obtain a NID for access to proscribed information: Top Secret, Special Access Program, Communications Security, Sensitive Compartmented Information, and Restricted Data. This provision will allow covered NTIB entities to begin performing on contracts that require access to proscribed information without having to wait on a NID, and thus removing costly contract performance delays.
•
§ 117.15(e)(2) TOP SECRET Information:
Permits specific determinations by a CSA with respect to requirements for TOP SECRET accountability (
e.g.,
the CSA can determine that TOP SECRET material stored in an electronic format on an authorized classified information system does not need to be individually numbered in series provided the contractor has in place controls in place to address accountability, need to know and retention). As stated in this paragraph: “. . . Contractors will establish controls for TOP SECRET information and material to validate procedures are in place to address accountability, need to know and retention,
e.g.,
demonstrating that TOP SECRET material stored in an electronic format on an authorized classified information system does not need to be individually numbered in series. These controls are in addition to the information management system and must be applied, unless otherwise directed by the applicable CSA, regardless of the media of the TOP SECRET information, to include information processed and stored on authorized information systems. Unless otherwise directed by the applicable CSA, the contractor will establish the following additional controls . . .”
•
§ 117.15(d)(4) Installation:
Clarifies that an Intrusion Detection System (IDS) shall be installed by a Nationally Recognized Testing Laboratory (NRTL)-approved entity to make it clear that any NRTL-approved entity may do such
installations. “The IDS will be installed by a NRTL-approved entity or by an entity approved in writing by the CSA . . .”
•
§ 117.7(b)(2) Senior Management Official:
Clarifies responsibilities of the Senior Management Official of each cleared entity to better reflect the critical role and accountability of this position for entity compliance with the NISPOM. This change further emphasizes the essential role of the Senior Management Official with the entity's security staff to ensure NISPOM compliance.
•
§ 117.13(d)(5)
Clarifies to the contractor that upon completion of a classified contract, the “contractor must return all government provided or deliverable information to the custody of the government. Such clarification ensures the contractor is not retaining official government records without specific authorization from the government customer. “(i) If the GCA does not advise to the contrary, the contractor may retain copies of the government material for a period of 2 years following the completion of the contract. The contract security classification specification, or equivalent, will continue in effect for this 2-year period. (ii) If the GCA determines the contractor has a continuing need for the copies of the government material beyond the 2-year period, the GCA will issue a final contract security classification specification, or equivalent, for the classified contract and will include disposition instructions for the copies.”
Costs
The DoD invites comment from the members of the public on the costs estimated to implement this rule.
A. Baseline
The Defense Counterintelligence and Security Agency (DCSA), as the DoD designated NISP cognizant security office, has collected information about baseline costs using an OMB-approved information collection process employing statistical methods for contractors' NISP implementation (OMB Control Number 0704-0458, “Industry Cost Collection Report Survey.” The most recent data collected by DCSA on contractors' NISP implementation costs are for fiscal year (FY) 2017 and reported in the ISOO 2017 annual report to the President. DCSA has used this survey collection methodology for contractors' NISP implementation under DoD security cognizance for over 11 years. A NISP government and industry working group developed the survey in 1995 and predecessor office to the OUSD(I&S) initially ran the annual survey. The Information Security Oversight Office (ISOO) placed a moratorium on conducting this survey after 2017 until a new NISP survey methodology is developed.
DCSA began the costs analysis for the baseline costs for fiscal year 2017 by randomly selecting active NISP contractor facilities that have existing DoD approval for classified storage at their own physical locations and having those facilities submit security costs. The randomly selected contractor facilities also have an active facility security clearance and a permanent Commercial and Government Entity (CAGE) Code. In addition to the randomly selected cleared facilities having approved classified storage, DCSA categorizes these contractor facilities for the survey based on the size, scope, and complexity of each contractor's security program.
The general methodology used to estimate security costs incurred by contractor cleared facilities with approved storage of classified information is based on the costs incurred by respondent contractors for the protection of classified information. The methodology captures the most significant portion of industry's costs, which is labor. Security labor in the survey is defined as personnel whose positions exist to support operations and staff in the implementation of government security requirements for the protection of classified information. Guards who are required as supplemental controls are included in security labor. The respondent contractors are requested to compile their cleared facility's current annual security labor cost in burdened, current year dollars with the most recent data being from the 2017 survey. The labor cost, when identified as an estimated percent of each contractor's total security costs, enables the respondent contractors to calculate their total security costs.
Information collected is compiled to create an aggregate estimated cost of NISP classification-related activities. Only the aggregate data is reported. There is a 95% confidence that the full enterprise industrial security total baseline cost does not exceed $1.486 billion for fiscal year 2017.
NISP cost estimates
(2017)
Benefits of NISP rule
Number of Facilities with Approved Classified Storage (Of Over 12,000 NISP Cleared Facilities):
3658
A single, integrated, cohesive industrial security program to protect classified information and to preserve our Nation's economic and technological interests.
Facilities Randomly Selected and Responding to Data Collection:
1038
Maximum uniformity and consistency by contractors who support the Executive branch to effectively protect and safeguard classified information through all phases of the contracting process for any classified information an Agency releases to a contractor.
Estimated Total NISP Security Costs for Facilities with Approved Classified Storage (With 95% Margin of Error to give 95% Upper Confidence Limit):
$1,413,150,249 + $72,968,977 = $1,486,119,226
Contractors must comply, when levied by the FAR security requirements clause or equivalent clauses in contracts involving access to classified information, with uniform procedures for the proper safeguarding of classified information to reduce the risk of unauthorized disclosure of classified information.
Based on the data collected from the survey, we can be 95% confident the true 2017 total NISP security cost for contractor facilities with approved classified storage is less than $1.486B.
Assumptions and Notes:
• Of over 12,000 NISP cleared facilities, 3,658 facilities are approved for classified storage and 1,038 responded to the survey.
• Companies were selected at random according to survey methodology.
• The applicable NISP CSA, based on a valid requirement for access to classified information (
e.g.,
contract or bid), funds the costs for evaluating and processing a contractor for an entity eligibility determination (facility clearance) and the costs of personnel security vetting requirements for required access to classified information by any contractor employees.
• The security cost profile for non-responding companies is assumed to be similar to that of responding companies.
• Outlying survey data points were removed from data analysis.
• Overall DoD contract spending for 2017 was $331 billion; but DoD does not have such data for these contractor cleared facilities in the NISP for performance on contracts requiring access to classified information.
• DoD has not collected security costs from those contractor cleared facilities that are not authorized to store classified information at their own contractor locations.
DoD noted that the largest contractor cleared facilities account for the highest security costs, and skew the average security costs for non-small businesses much higher. The average security cost for the largest contractor cleared facilities is approximately $4.8 million per facility. If the largest facilities are removed from the cost estimate, then the average security cost for a non-small business with approval for storage of classified information is reduced to $432,312 from $864,662. Of the approximately 1,000 facilities selected for the small entities analysis described in section 4 of this initial regulatory flexibility analysis, about 68% were contractor cleared facilities that were not included in the 2017 NISP cost estimate because they don't have approval to store classified information or process classified information on an information system or network at the contractors' own cleared facilities. DoD estimated the costs impacting small entities from the approximately 32% of the remaining small businesses, as those would have approval to store classified information or process classified information on an information system or network at one of the contractor's own cleared facilities. Those security costs are estimated to be approximately $316 million or 21% of the $1.486 billion of the estimated NISP costs to contractors in 2017. When contractor cleared facilities' responses to the ISOO cost collection survey were cross referenced with the DoD small business analysis (using the Small Business Administration (SBA) Dynamic Small Business Search), DoD estimated an average security cost for a small business with approved storage of classified information of $133,612. One of the requirements for a facility security clearance is a security agreement between the applicable NISP CSA and the contractor legal entity. Such a security agreement sets forth compliance, oversight and administration termination provisions. The agreement also indicates that it does not obligate USG funds and the USG shall not be liable for any costs or claims of the contractor arising out of the security agreement. It is recognized, however, the parties may provide in other written contracts with GCAs for security costs, which may be properly chargeable, if so determined by the applicable GCA. This rule provides that a contractor must implement changes no later than 6 months from the date of a published change to this rule to allow the contractor to discuss what impact, if any, the changes have on existing classified contracts with the applicable GCAs.
B. Public Cost Analysis of the Changes to the Baseline From This Rule
1.
Projected Public Costs.
In summary, the estimated public costs are present value costs of 150.26 million and annualized costs estimated to be $10.52 million.
2.
Cost Analysis.
Throughout, labor rates are adjusted upward by 100% to account for overhead and benefits.
a.
Regulatory Familiarization.
There will be an initial step to become familiar with the format of the rule, the changed requirements and what actions the cleared entities must take to comply with the changes in this rule. To become familiar with the rule format and the new requirements, cleared entities will review the
Federal Register
notice with the new 32 CFR part 117. It is estimated that 12,400 cleared entities will need to become familiar with the rule. Of those approximately 12,400 cleared entities, an estimated 8,036 are small business entities and 4,348 are large business entities. The FSO at each entity (small or large) must become familiar with the rule to be able to use it on a daily basis in the FSO role to supervise and direct security measures necessary for implementing the applicable security requirements to ensure the protection of classified information. Using the published Office of Personnel Management General Schedule (GS) salary schedule for fiscal year (FY) 2020, the estimated labor rate for an FSO of a small business entity firm is the equivalent of a GS11 step 5 and for an FSO of a large business entity as the equivalent of a GS13, step 5. It is estimated that it will take 10 hours in the first year, 5 hours in years 2 and 3, 3 hours in years 4 to 7, and then 2 hours annually up to year 20 for an FSO to become familiar with the rule, as this will be the first time that the NISPOM is in a rule format instead of as a DoD policy issuance, as well as familiarization with the changes. These assumptions imply costs of $9.89 million in year one; $4.95 million in years 2 and 3; $2.97 million in each year 4 through 7; and, $1.98 million in each year 8 through 20.
b.
Evaluation of Existing Classified Contracts To Implement Changes No Later than Six Months from Effective Date.
Each of the legal U.S. cleared entities must comply no more than six months from the effective date of this NISPOM rule. During that six months, each legal cleared entity has the opportunity to review existing classified contracts to determine if there is any impact that they want to discuss with the applicable GCAs about possible equitable adjustment. Decisions on any requests for equitable adjustment will be made by the applicable contracting officer. Legal entities enter into contracts, licenses or grants; it is estimated that the average of 8,036 small business cleared entities are each a legal entity. It is estimated that each of those small business cleared legal entities will review an average of 3 existing classified contracts for possible equitable adjustment for a total of 24,108 contracts requiring 3 hours each for review in 2021. Using the published Office of Personnel Management GS salary schedule for FY20, the estimated labor rate for an FSO of a small business entity firm is the equivalent of a GS11 step 5 and for an FSO of a large business entity as the equivalent of a GS13, step 5. Of the large business entities, it is estimated that 2,100 large business cleared entities are legal entities, while the remaining large business entities are divisions or branch offices. It is estimated that each of those large business cleared legal entities will review an average of 30 existing classified contracts for possible equitable adjustment for a total of 63,000 contracts requiring 8 hours each for review in 2021. It is estimated that it will take more time for review by the
large business cleared entities due to more complicated contracts. These assumptions imply costs of $54.96 million in year one and no further costs as this action is taken only in the first year.
c.
Train SECRET cleared employees on requirements to submit foreign travel reports.
The FSO at each entity (small or large) must ensure that its SECRET cleared employees are trained on the requirements. Such training by the FSO is estimated to take 1 hour in 2021 and a half an hour in each of the following years up to year 20. Using the published Office of Personnel Management GS salary schedule for FY20, the estimated labor rate for an FSO of a small business entity firm is the equivalent of a GS11 step 5 and for an FSO of a large business entity as the equivalent of a GS13, step 5. These assumptions imply total costs of $0.99 million in 2021 as year one; and, $0.49 million in each year 2 through 20.
d.
Submit foreign travel reports and receive any pre-travel threat briefings or post travel briefings based on the threat.
All cleared employees must submit foreign travel reports and receive any pre-travel briefings or post travel briefings from the FSO-based on threat according to this rule, SEAD 3 and CSA-provided guidance for unique mission requirements. It is estimated that the number of foreign travel reports submitted annually will be 483,681 to comply with this rule. That estimate is based on analysis of calendar year 2019 unofficial foreign travel reported by DoD civilians and military in the DoD Aircraft and Personnel Automated Clearance System (APACS), a web-based tool for the creation, submission and approval of aircraft diplomatic clearances and personnel travel clearances (
i.e.
Country, Theater and Special Area, as applicable with individual DoD Foreign Clearance Guide (FCG),
https://www.fcg.pentagon.mil
country pages) designed to aid USG travelers on official government and unofficial (
i.e.,
leave) travel. For calendar year 2019, there were 126,131 travelers and 113,214 travel requests submitted into APACS. APACS requirements are published on the DoD Foreign Clearance Guide (FCG),
https://www.fcg.pentagon.mil.
Thus an annual estimate of .89 expected foreign travel trips by traveler (113,214 divided by 126,131). In the small business analysis, there were a total of 18,242 cleared employees in the 658 small entities sampled and 63,598 cleared employees in the remaining 356 non-small businesses. Of the total cleared employees in the small business analysis (as reported in the National Industrial Security System), approximately 22.3% were at small entities and 77.7% were at non-small businesses. Known number of new travelers expected to be effected by this rule is 543,462 SECRET cleared contractor personnel under DoD security cognizance and the estimated trips at .89 per traveler is (543,462 × .89 = 483,681 estimated trips). Assuming the ratio for those employees reporting foreign travel into APACS is the same as SECRET cleared employees would report, of the estimated 483,681 foreign trips by SECRET cleared employees, it can be estimated that approximately 107,812 (22.3% of 483,681) will be taken by contractors at small entities, and 375,869 (77.7% of 483,681) by contractors at non-small businesses. It is estimated that it will take a half an hour for a SECRET cleared employee to report foreign travel in 2021 and in each of the following years up to year 20 to report foreign travel and receive any pre-travel or post-travel briefings. The estimated average labor rate for a SECRET cleared employee to report foreign travel is the equivalent of a GS11 step 5. These assumptions imply costs of $16.81 million in each year one through 20.
e.
Fewer contract performance delays by the small number of U.S. contractors with NTIB ownership operating under an SSA.
Section 842 of Public Law 115-232, is limited to a small number of U.S. cleared legal entities in the NISP for which the ultimate parent entity and any intermediate parent entities of such subsidiary are located in a country that is part of the NTIB; and that is subject to the FOCI requirements of the NISP. There are currently 20 U.S. cleared legal entities with their associated cleared divisions, subsidiaries or branch (estimated to be another 100 cleared entities) to whom Section 842 of Public Law 115-232 applies. Section 881 of Public Law 114-328 expanded the legal definition of the NTIB to include the United Kingdom and Australia. The NTIB is comprised of the United States, the United Kingdom of Great Britain and Northern Ireland, Canada and Australia. NTIB is based on the principle that defense trade between the United States and its closest allies enables a host of benefits, including increased access to innovation, economies of scale, and interoperability (10 U.S.C. 2500).
Section 842 of Public Law 115-232 is deregulatory by statute and this rule. There are no estimated costs to the small number of entities impacted because they are required already to submit any new or change to FOCI information for their initial and continued FCL, respectively, via the SF 328, Certificate Pertaining to Foreign Interests in the NISP as do all other U.S. cleared legal entities. 32 CFR part 2004 provides a CSA up to 30 days to assess the submitted NID and then another 30 days for a controlling agency to make a NID for the type of proscribed information under the purview of each (ODNI for SCI, DOE for RD or NSA for COMSEC). Thus, with Section 842 of Public Law 115-232, there has been minimum 60 day delay for a NID involving an NTIB covered entity which has impacted the timeliness of contract performance. There are estimated costs savings as this small number of cleared entities and their entity cleared employees designated to work on specific classified contracts involving proscribed information will no longer have to wait at least 60 days for NIDs after contract award for access to proscribed information when all other requirements have been met for access to classified information and contract performance. Using the published Office of Personnel Management GS salary schedule for FY20, the labor rate for an FSO and an estimated 8 cleared employees in each of the 2 small business entities impacted is the equivalent of a GS11 step 5 with a time savings of 320 hours for each year 1 through 20. The labor rate for an FSO and an estimated 19 cleared employees in each of the 18 large business entities impacted is the equivalent of a GS13 step 5 with a time savings of 320 hours for each year 1 through 20. These assumptions imply cost savings of $11.81 million in each year.
C. USG Cost Analysis of the Changes to the Baseline From This Rule
1.
Projected USG Cost/Cost Savings.
In summary, the estimated USG cost/cost savings are present value costs of $10.82 million and annualized costs of $0.76 million. Throughout, labor rates are adjusted upward by 100% to account for overhead and benefits.
2.
Cost analysis.
a. Regulatory Familiarization.
There will be an initial step to become familiar with the clause requirements and what actions the USG executive branch agencies must take to comply with the changes in this rule. To become familiar with the new requirements, USG executive branch agencies may review the
Federal Register
notice with the new 32 CFR part 117. It is estimated that 38 USG executive branch agencies will become familiar with the rule (
i.e.,
the five Cognizant Security Agencies (DoD, DOE, NRC, ODNI, DHS) and the 33 USG agencies which currently have an industrial security services agreement
with DoD pursuant to 32 CFR part 2004). The estimated labor rate used for the cost calculation is the equivalent of a GS12 step 5 for the designated NISP lead at each of those 38 agencies. It is estimated that it will take 8 hours in the first year as well as in each of the following through year 20 to become familiar and remain familiar with the rule, as this will be the first time that the NISPOM is in a rule format instead of as a DoD policy issuance, as well as familiarization with the changes. These assumptions imply costs of approximately $25 thousand each year.
b.
Training the USG civilian employees of NISP CSAs who provide oversight of contractor compliance with this rule.
It is estimated that the NISP CSAs (
i.e.,
DoD, DOE, NRC, ODNI and DHS) must train a total of 800 personnel who provide oversight of contractor compliance with this rule in the first year with annual refresher training in subsequent years. The largest number of personnel would be trained by DoD. The initial training is estimated to take 24 hours in 2021 to ensure those government personnel conducting oversight are versed in the changed requirements to assess compliance by cleared entities. The second year refresher training will be 16 hours with 8 hours of refresher training in each of years 3 through 20. The average labor rate for these 800 government headquarters and field personnel is estimated to be a GS13 step 5. These assumptions imply costs of $1.90 million in year one; $1.27 million in year 2; and, $0.63 million in each year 3 through 20.
c.
Accepting submissions of foreign travel reports by SECRET cleared entity personnel.
DoD, with the largest population of cleared entity personnel, already has the data fields for foreign travel reporting in the Defense Information System for Security and will not have to make more changes to that automated system to accept submission of these reports. There are no expected costs or costs savings.
d.
No longer draft, coordinate and submit proposed national interest determinations (NIDs) for access to proscribed information for the small number of U.S. contractors with NTIB ownership operating under an SSA.
There will be a small cost savings because DoD Components (
i.e.,
Departments of the Army, Navy and Air Force, DARPA, DIA, NGA, NRO, NSA and assorted smaller organizations) will no longer have to take an estimated 40 hours a year to draft, coordinate and submit NIDs for the small number of U.S. contractors with NTIB ownership operating under an SSA. There will be minimal administrative changes to the DoD information system to remove the NID requirement for the small number of NTIB covered entities. DoD already must evaluate any changes submitted to FOCI information for U.S. cleared legal entities under its security cognizance which would include a determination if one of these cleared legal entities remains a covered NTIB entity. On average, DoD receives an estimated one FOCI changed condition report annually from an NTIB covered cleared legal entity. An estimated 10 government personnel with an estimated labor rate of a GS11 step 5 would save 40 hours in year 1 through year 20. These assumptions imply costs saving of approximately $28 thousand each year.
e.
Update training materials, job aids and associated tools for U.S. cleared legal entities and USG agencies on these changes to the NISPOM.
CSAs will have to update existing training materials and products used by U.S. cleared legal entities and USG agencies so that they have all needed information on the changes being implemented in this NISPOM rule. Examples of those training materials and products range from online or in person training, job aids and web tools. DoD provides NISP training materials to the largest population, to include USG agencies and U.S. cleared legal entities, and estimates the time impact in year one is 1,128 hours for each of six individuals to update all the training materials with 564 hours in year two and 282 hours each year for maintenance of those materials in year 3 through year 20. The labor rate for those 6 personnel is estimated to be a GS13 step 5. These assumptions imply costs of $0.67 million in year one; $0.34 million in year 2; and $0.17 million in each year 3 through 20.
C. Total Costs/Cost Savings
In summary the estimated public and USG costs/cost savings are (1) present value costs of $150.26 million and annualized costs of $10.52 million for the public; and, (2) present value cost of $10.82 million and annualized costs of $0.76 million for the USG. Throughout, labor rates are adjusted upward by 100% to account for overhead and benefits.
Benefits
Following the September 2013 Navy Yard shooting, the President directed the Office of Management and Budget (OMB) to lead a review of suitability and security clearance procedures for Federal employees and contractors (see
https://www.archives.gov/files/isoo/oversight-groups/nisp/2014-suitability-and-processes-report.pdf
). This review assessed USG policies, programs, processes, and procedures involving determinations of federal employee suitability, contractor fitness, and personnel security. The interagency working group also evaluated the collection, sharing, processing, and storage of information used to make suitability, credentialing, and security decisions. It found the need for
• better information sharing,
• increased oversight over background investigations, and
• consistent application of standards and policies for both Federal employees and contractors.
The report identified 13 recommendations to improve how the Government performed suitability determinations and security clearances and the creation of SEAD 3 is a partial response to recommendation A.2. SEAD-3 requires enhanced additional reporting of foreign travel, foreign contacts and conduct/behavior that might jeopardize an individual from maintaining access or eligibility to access classified information. Many of the requirements are a direct result of recent national security breaches by trusted insiders who have disclosed classified information to news media or foreign entities causing significant harm to the interests of the United States.
SEAD 3 was designed to strengthen the safeguarding of national security equities, such as national security information, personnel, facilities, and technologies. These reporting requirements are important because individuals who incur a continuing security obligation need to be aware of the risks associated with foreign intelligence operations and/or possible terrorist activities directed against them in the U.S. and abroad, and to be aware they possess or have access to information that is highly sought after by foreign adversaries and competitors, including, but not limited to:
• Classified or sensitive information vital to national and economic security
• Emerging technologies and pioneering research and development
• Information relating to critical infrastructure sectors
• Proprietary secrets
• Security or counterintelligence information
In particular, the risk of becoming an intelligence target increases greatly during foreign travel, be it for official or unofficial purposes. NISP Contractor cleared personnel can become the target of a foreign intelligence or security service at any time in any country.
Collecting additional information on travel will help ensure basic counterintelligence awareness is implemented to effectively protect both the individual and the USG against foreign attempts to collect sensitive, proprietary, or classified information. Such measures could include arranging a pre-travel briefing from the entity Facility Security Officer. Reminders include, but are not limited to the following, which can be provided to:
• Do not leave items that would be of value to a foreign intelligence service unattended in hotel rooms or stored in hotel safes.
• Limit sensitive discussions—hotel rooms or other public places are not suitable locations to discuss sensitive information.
• Not use computer or facsimile equipment at foreign hotels or business centers for sensitive matters.
• Not divulge information to anyone unauthorized to hear it.
• Ignore or deflect intrusive inquiries or conversation about business or personal matters.
• Keep a laptop computer as carry-on baggage—never check it with other luggage and, if possible, remove or control storage media. Confirm before the foreign travel whether it is necessary or even advisable to take a laptop computer.
• Report any suspicious contacts or incidents to the entity FSO to report to the applicable CSA.
Contractors in the NISP also have a responsibility for recognizing and avoiding personal behaviors and activities that may impact their continued eligibility for access to classified information. This includes, but is not limited to the following activities which may be of potential security, insider threat, or counterintelligence concern
• An unwillingness to comply with rules, regulations, or security requirements
• Unexplained affluence or excessive indebtedness
• Alcohol abuse
• Illegal use or misuse of drugs or drug activity
• Apparent or suspected mental health issues where there is reason to believe it may impact the individual's ability to protect classified information or other information prohibited by law from disclosure
• Criminal conduct
• Any activity that raises doubts as to whether the individual's continued national security eligibility is clearly consistent with national security interests
• Misuse of U.S. Government property or information systems
This rule will result in fewer contract performance delays by the small number of U.S. contractors with NTIB ownership operating under an SSA. With Section 842 of Public Law 115-232 implemented there will no longer be at least a 60 day minimum delay for USG contracting activities and NTIB covered entities to wait for NIDs after contract award for access to proscribed information when all other requirements have been met. When a GCA submits a NID to the applicable CSA, there is an initial 30 days to process the request, which includes verification of the NID requirement. If the NID also includes a requirement for controlling agency concurrence (
i.e.,
ODNI for SCI, DOE for RD or NSA for COMSEC), the CSA submits the request to the applicable controlling agencies who then have 30 more days for its analysis and decision. Section 842 of Public Law 115-232 is deregulatory by statute as reflected in this rule. Congress required that the NTIB policy framework foster a defense free-trade area among the defense-related research and development sectors of the United States, Canada, Australia and the United Kingdom. Section 881 of Public Law 114-328 (the National Defense Authorization Act for Fiscal Year 2017) expanded the legal definition of the NTIB to include the United Kingdom and Australia. Congress expanded the NTIB in 2017 based on the principle that defense trade between the United States and its closest allies enables a host of benefits, including increased access to innovation, economies of scale, interoperability, and to reduce the barriers to the seamless integration between the NTIB which supplies defense articles to the Armed Forces and enhances allied interoperability of forces. Section 842 of Public Law 115-232 also continues the congressional intent to remove barriers to the seamless integration of the transfer of knowledge, goods, and services among the persons and organizations of the NTIB for national security challenges across a variety of technology areas.
Alternatives
No action. If there were no action (
i.e.,
no NISPOM rule nor DoD Manual 5220.22), USG agencies would not have single set of requirements to be levied on contractors through a FAR security requirements clause or equivalent to protect classified information in contracts. Without that single set of requirements consistently levied for classified contracts by USG agencies, there would be a loss of classified information to adversaries. There would not be a streamlined process for clearing contractors to work on contracts involving classified information. This would leave each USG agency to clear its own contractors, which could take months or years. The ability for the USG to fill crucial mission gaps using contractors would be severely impacted. There would be no standardized way under which contractors would be required to physically store classified information. The USG would have no insight into insider threats from contractor personnel who have access to the USG's most sensitive and critical programs. There would be an adverse impact on national security. The results of this alternative are not preferred.
Next Best Alternative. Each USG agency would establish a rule for contractor protection of classified information disclosed or released to contractors. Differing standards will result in inconsistent standards, confusion, and higher costs for compliance if a contractor has contracts requiring access to classified information with multiple USG agencies and has to comply with different agency requirements. Further, such an alternative would result in additional time needed for contractors to put in place mechanisms to meet multiple and differing sets of requirements. This inconsistency and confusion due to differing standards also increases the likelihood of loss of classified information and insider threats going undetected. The results of this alternative are not preferred.
The Preferred Alternative. This final rule provides a single statement of requirements for contractors to comply with for maximum uniformity and consistency, for the protection of classified information, to include the reporting of foreign travel and foreign contacts by cleared contractor personnel in accordance with Security Executive Agent policies. This final rule provides for the proper protection of classified information disclosed or released by U.S. agencies in all phases of the contracting, license or grant processes. This rule will prevent the theft of classified national security assets and information by adversaries and insider threats. This is the preferred alternative.
IV. Exception to Notice and Comment
This rule directly involves matters relating to public grants or contracts, and is therefore expressly exempt from notice and comment procedures under 5 U.S.C. 553(a)(2). Compliance with this rule is levied by a Federal Acquisition Regulation security requirements clause
or equivalent. It establishes requirements for the protection of classified information disclosed to or developed by contractors, licensees, grantees, or certificate holders. Industry implements these requirements to protect national security interests, cleared persons, and the integrity of the classified information. Although DoD has determined that an exception to the notice and comment requirements of § 553 applies, it still seeks public comments on this rule. Thereafter, DoD will consider comments received on this rule in determining whether to make any changes in a subsequent rule.
V. Regulatory Analysis
Executive Order 12866, “Regulatory Planning and Review” and E.O. 13563, “Improving Regulation and Regulatory Review”
E.O.s 12866 and 13563 direct agencies to assess all costs and benefits of available regulatory alternatives and, if regulation is necessary, to select regulatory approaches that maximize net benefits (including potential economic, environmental, public health and safety effects, distribute impacts, and equity). E.O. 13563 emphasizes the importance of quantifying both costs and benefits, of reducing costs, of harmonizing rules, and of promoting flexibility. Accordingly, the rule has been reviewed by the Office of Management and Budget (OMB) under the requirements of these E.O.s. This rule has been designated a significant regulatory action and determined to be economically significant, under section 3(f) of E.O. 12866 as it has an annual effect on the economy of $100 million or more or affects in a material way the economy or a sector of the economy. Security costs relate specifically to protection of classified information by cleared U.S. entities.
Executive Order 13771, “Reducing Regulation and Controlling Regulatory Costs”
This rule is not subject to the requirements of E.O. 13771, because the rule is issued with respect to a national security function of the United States.
Public Law 96-354, “Regulatory Flexibility Act” (5 U.S.C. 601)
The DoD certifies that this final rule would not, if promulgated, have a significant economic impact on a substantial number of small business entities in accordance with the Regulatory Flexibility Act (5 U.S.C. 601) requirements since a contractor cleared legal entity may, in entering into contracts requiring access to classified information, negotiate for security costs determined to be properly chargeable by a GCA. The DoD invites comment from members of the public who believe there will be a significant impact.
Small entities to which this rule will apply provide products and services to the executive branch,
e.g.,
in the areas of administration, consulting, information security and technology, cybersecurity, research and development, design, production and manufacturing, including circumstances where physical security measures cannot preclude aural or visual access to classified information. These small business entities, as well as non-small business entities, have entered into a contract, license or grant for which access to classified information is required. Compliance with this rule, also referred to as the NISPOM, is levied by a FAR security requirements clause or equivalent. The requirements for an entity eligibility determination do not include USG collection of applicable North American Industry Classification System (NAICS) codes. While this type of information is available in the Federal Procurement Data System (FPDS), entity eligibility determinations (often referred to as facility clearances) are not available in FPDS. DoD has no efficient mechanism to cross check NAICS codes from FPDS with facility clearance data. DoD assesses there are a wide variety of NAICS codes associated with contracts requiring access to classified information. For example, the following NAICS codes may be associated with contracts requiring access to classified information: 561720 janitorial services; 561210 facility support services; 541611 administrative management and general management services; 561110 office administrative services; 541690 other scientific and technical consulting services; 541330 engineering services; 561611 investigation services; and likely many others, since contracts that require a facility clearance for access to classified information are not industry specific.
Based on the number of small businesses registered within the SBA Dynamic Small Business Search, the overall industrial base of federal government small businesses is 313,651. Approximately 1,000 facilities were randomly selected from the NISP to determine if the selected facilities were registered within the SBA Dynamic Small Business Search. With 95% confidence, it can be estimated that there are between 7,672 and 8,400 small entities impacted by this rule. The general methodology to determine a random sample and the estimated number of small business entities impacted by this rule is outlined in the following table. The random selection is dependent on the contractor facility having an active facility security clearance and permanent CAGE Code.
NISP small entities estimate
Total cleared contractor facilities enrolled in the DoD National Industrial Security System (NISS) as of May 14, 2020:
12,384
Randomly Selected facilities from the current cleared contractor population:
1,014
The proportion of cleared contractor facilities in the simple random sample enrolled in the SBA Database:
658/1,014 = 64.89%
Equates to 8,036 facilities as small business entities.
Margin of Error for proportion enrolled in SBA database (95% confidence):
±2.94%
Equates to ±364 facilities cleared contractor facilities.
The interval estimate for the number of small businesses in the NISP:
8,036 ±364 =
7,672 to 8,400 cleared contractor facilities.
Based on the simple random sample, we can be 95% confident that the true proportion of active cleared contractor facilities enrolled in the SBA database is between 62.0% and 67.8%. Based on cleared contractor enrollment as of May 14, 2020, the percentages equate to an interval estimate between 7,672 and 8,400 small business entities which are cleared contractor facilities and impacted by this rule.
Assumptions and Notes:
• Facilities self-enrolled in the SBA database are, in fact, small businesses. The following link was used to determine if a facility was a small business by searching CAGE codes showing all NAICS for which a business is a small business:
https://web.sba.gov/pro-net/search/dsp_dsbs.cfm.
• The SBA database is generally a self-certifying database. The SBA does not make any representation as to the accuracy of any of the data included, other than certifications relating to 8(a) Business Development, HUBZone or Small Disadvantaged Business status. The SBA strongly recommends that contracting officers diligently review a bidder's small business self-certification before awarding a contract.
• Facilities were selected from the active NISS population using a simple random sample (1,014 selected of 12,384 enrolled facilities).
• Selection of each facility is independent of all other facilities selected (N * .10 >n).
• The sample is large enough (n = 1014) that we can assume the sampling distribution of sample proportions is approximately normal (n * p>10 and n * (1−p) >10).
Congressional Review Act
The Congressional Review Act, 5 U.S.C. 801
et seq.,
as amended by the Small Business Regulatory Enforcement Fairness Act of 1996, generally provides that before a rule may take effect, the agency promulgating the rule must submit a rule report, which includes a copy of the rule, to each House of the Congress and to the Comptroller General of the United States. We will submit a report containing this rule and other required information to the U.S. Senate, the U.S. House of Representatives, and the Comptroller General of the United States. A major rule cannot take effect until 60 days after it is published in the
Federal Register
. This final rule is a “major rule” as defined by 5 U.S.C. 804(2) because it is also economically significant under section 3(f) of E.O. 12866 with an annual effect on the economy of $100 million or more.
Sec. 202, Public Law 104-4, “Unfunded Mandates Reform Act”
Section 202 of the Unfunded Mandates Reform Act of 1995 (UMRA) (2 U.S.C. 1532) requires agencies to assess anticipated costs and benefits before issuing any rule whose mandates require spending in any 1 year of $100 million in 1995 dollars, updated annually for inflation. This final rule will not mandate any requirements for State, local, or tribal governments, nor will it affect private sector costs.
Public Law 96-511, “Paperwork Reduction Act” (44 U.S.C. Chapter 35)
It has been determined that 32 CFR part 117 does impose reporting or recordkeeping requirements under the Paperwork Reduction Act of 1995. DoD is not proposing changes to the DoD collections based on this final rule, nor have any of the other NISP CSAs indicated proposed changes based on this rule. The DOE and NRC have collections based on their respective authorities as a NISP CSA; but neither has a collection for a Contract Security Classification Specification because DOE and NRC each complete that specification for both prime contracts and subcontracts. By accepting the contract, the contractor obligates itself to fulfill the requirements specified in applicable DOE Acquisition Regulation (DEAR) clauses (available at
https://www.energy.gov/management/downloads/searchable-electronic-department-energy-acquisition-regulation
) and identified DOE Directives. The DOE Directives contain a contractor requirements document that conveys security obligations and the statutes for civil penalties for security violations. The Nuclear Regulatory Commission Acquisition Regulation part 2052.204-70 includes the security requirements levied on the contractor (available at
https://www.acquisition.gov/nrcar/nrcar-part-2052-solicitation-provisions-and-contract-clauses#P41_1774
). For ease of review of this rule, the collections are discussed below. Materials associated with all of the collections can reviewed at
www.reginfo.gov.
• OMB Control Number 0704-0194, DD Form 441,
DoD Security Agreement.
• OMB Control Number: 0704-0571,
National Industrial Security System,
is a DoD information collection used to conduct its monitoring and oversight of contractors.
• OMB Control Number 0704-0567, DoD
Contract Security Classification Specification,
this collection is used by both DoD and agencies which have an industrial security agreement with DoD.
• OMB Control Number 0704-0573,
Defense Information System for Security,
is a DoD automated system for personnel security, providing a common, comprehensive medium to record, document, and identify personal security actions within DoD including submitting adverse information, verification of security clearance status, requesting investigations, and supporting continuous evaluation activities. It requires personal data collection to facilitate the initiation, investigation and adjudication of information relevant to DoD security clearances and employment suitability determinations for active duty military, civilian employees and contractors seeking such credentials.
• OMB Control Number 0704-0496,
Joint Personnel Adjudication System,
an information system which requires personal data collection to facilitate the initiation, investigation and adjudication of information relevant to DoD security clearances and employment suitability determinations for active duty military, civilian employees and contractors seeking such credentials.
• OMB Control Number 0704-0579,
Certificate Pertaining to Foreign Interests SF (328)
which is a common form which can be used by all CSAs.
• OMB Control Number 3150-0047,
10 CFR part 95, Facility Security Clearance and Safeguarding of National Security Information and Restricted Data,
is an NRC information collection used to obtain an FCL and for safeguarding Secret and Confidential National Security Information and Restricted Data. Licensees under 10 CFR part 95 fall within two categories, those who possess, use or transmit classified matter at their site or a cleared contractor site, and those licensees and contractors who only need access to classified matter at a government or appropriately cleared non-government site.
• OMB Control Number 1910-1800,
Security Package,
is a DOE information collection used by DOE to conduct its monitoring and oversight of contractors under its security cognizance and to provide a platform for other CSAs, GCAs or prime contractors to verify whether a contractor has a DOE-granted FCL.
Executive Order 13132, “Federalism”
E.O. 13132 establishes certain requirements that an agency must meet when it promulgates an final rule (and subsequent final rule) that imposes substantial direct requirement costs on
State and local governments, preempts State law, or otherwise has Federalism implications. This final rule will not have a substantial effect on State and local governments.
List of Subjects in 32 CFR Part 117
Classified information; Government contracts; USG contracts, National Industrial Program (NISP); Prime contractor, Subcontractor.
Accordingly, the Department of Defense amends chapter I of title 32 of the CFR by adding part 117 to read as follows:
PART 117—NATIONAL INDUSTRIAL SECURITY PROGRAM OPERATING MANUAL (NISPOM)
Sec.
117.1
Purpose.
117.2
Applicability.
117.3
Definitions.
117.4
Policy.
117.5
Information collections.
117.6
Responsibilities.
117.7
Procedures.
117.8
Reporting requirements.
117.9
Entity eligibility determination for access to classified information.
117.10
Determination of eligibility for access to classified information for contractor employees.
117.11
Foreign Ownership, Control, or Influence (FOCI).
117.12
Security training and briefings.
117.13
Classification.
117.14
Marking requirements.
117.15
Safeguarding classified information.
117.16
Visits and meetings.
117.17
Subcontracting.
117.18
Information system security.
117.19
International security requirements.
117.20
Critical Nuclear Weapon Design Information (CNWDI).
117.21
COMSEC.
117.22
DHS CCIPP.
117.23
Supplement to this rule: Security Requirements for Alternative Compensatory Control Measures (ACCM), Special Access Programs (SAPs), SCI, RD, Formerly Restricted Data (FRD), Transclassified Foreign Nuclear Information (TFNI), and Naval Nuclear Propulsion Information (NNPI).
117.24
Cognizant Security Office information.
Authority:
32 CFR part 2004; E.O. 10865; E.O. 12333; E.O. 12829; E.O. 12866; E.O. 12968; E.O. 13526; E.O. 13563; E.O. 13587; E.O. 13691; Public Law 108-458; Title 42 U.S.C. 2011
et seq.
; Title 50 U.S.C. Chapter 44; Title 50 U.S.C. 3501
et seq.
§ 117.1
Purpose.
(a) This rule implements policy, assigns responsibilities, establishes requirements, and provides procedures, consistent with E.O. 12829, “National Industrial Security Program”; E.O. 10865, “Safeguarding Classified Information within Industry”; 32 CFR part 2004; and DoD Instruction (DoDI) 5220.22, “National Industrial Security Program (NISP)” (available at
https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/522022p.pdf?ver=2018-05-01-073158-710
) for the protection of classified information that is disclosed to, or developed by contractors of the U.S. Government (USG) (hereinafter referred to in this rule as contractors).
(b) This rule, also in accordance with E.O. 12829, E.O. 13587,”Structural Reforms To Improve the Security of Classified Networks and the Responsible Sharing and Safeguarding of Classified Information”; E.O. 13691, “Promoting Private Sector Cybersecurity Information Sharing”; E.O. 12333, “United States Intelligence Activities”; 42 U.S.C. 2011
et seq.
(also known as and referred to in this rule as the “AEA of 1954,” as amended); ” 50 U.S.C. Ch. 44 (also known as the “National Security Act of 1947,” as amended); 50 U.S.C. 3501
et seq.
(also known as the “Central Intelligence Agency Act of 1949,” as amended); Public Law 108-458 (also known as the “Intelligence Reform and Terrorism Prevention Act of 2004”); and 32 CFR part 2004:
(1) Prescribes industrial security procedures and practices, under E.O. 12829 or successor orders, to safeguard USG classified information that is developed by or disclosed to contractors of the USG.
(2) Prescribes requirements, restrictions, and other safeguards to prevent unauthorized disclosure of classified information and protect special classes of classified information.
(3) Prescribes that contractors will implement the provisions of this rule no later than 6 months from the effective date of this rule.
§ 117.2
Applicability.
(a) This rule applies to:
(1) The Office of the Secretary of Defense, the Military Departments, the Office of the Chairman of the Joint Chiefs of Staff and the Joint Staff, the Combatant Commands, the Office of the Inspector General of the Department of Defense, the Defense Agencies, the DoD Field Activities, and all other organizational entities within the DoD (referred to collectively in this rule as the “DoD Components”).
(2) All executive branch departments and agencies.
(3) All industrial, educational, commercial, or other non-USG entities granted access to classified information by the USG executive branch departments and agencies or by foreign governments.
(4) The release of classified information by the USG to contractors, who are required to safeguard classified information released during all phases of the contracting, agreement (including cooperative research and development agreements), licensing, and grant processes,
i.e.,
the preparation and submission of bids and proposals, negotiation, award, performance, and termination. Also, it applies in situations involving a contract, agreement, license, or grant when actual knowledge of classified information is not required, but reasonable physical security measures cannot be employed to prevent aural or visual access to classified information, because there is the ability and opportunity to gain knowledge of classified information. It also applies to any other situation in which classified information or FGI that is furnished to a contractor requires protection in the interest of national security, but which is not released under a contract, license, certificate or grant.
(b) This rule does not:
(1) Limit in any manner the authority of USG executive branch departments and agencies to grant access to classified information under the cognizance of their department or agency to any individual designated by them. The granting of such access is outside the scope of the NISP and is accomplished pursuant to E.O. 12968, E.O. 13526, E.O. 13691, the AEA, and applicable disclosure policies.
(2) Apply to criminal proceedings in the courts or authorize contractors or their employees to disclose classified information in connection with any criminal proceedings. Defendants and their representative in criminal proceedings in U.S. District Courts, Courts of Appeal, and the U.S. Supreme Court may gain access to classified information in accordance with 18 U.S.C. Appendix 3, Section 1, also known as and referred to in this rule as the “Classified Information Procedures Act,” as amended.
§ 117.3
Acronyms and Definitions.
(a) Acronyms. Unless otherwise noted, these acronyms and their terms are for the purposes of this rule.
ACCM
alternative compensatory control measures
AEA
Atomic Energy Act of 1954, as amended
AUS
Australia
CAGE
commercial and government entity
CCIPP
classified critical infrastructure protection program
CDC
cleared defense contractor
CFIUS
Committee on Foreign Investment in the United States
CFR
Code of Federal Regulations
CI
Counterintelligence
CIA
Central Intelligence Agency
CNSS
Committee on National Security Systems
CNWDI
critical nuclear weapons design information
COMSEC
communications security
COR
central office of record
CSA
cognizant security agency
CSO
cognizant security office
CUSR
Central United States Registry
DCSA
Defense Counterintelligence and Security Agency
DD
Department of Defense (forms only)
DDTC
Directorate of Defense Trade Controls
DGR
designated government representative
DHS
Department of Homeland Security
DNI
Director of National Intelligence
DoD
Department of Defense
DoDD
Department of Defense Directive
DoDI
Department of Defense Instruction
DoDM
Department of Defense Manual
DOE
Department of Energy
ECP
electronic communications plan
E.O.
Executive order
FBI
Federal Bureau of Investigation
FCL
facility (security) clearance
FGI
foreign government information
FOCI
foreign ownership, control, or influence
FRD
Formerly Restricted Data
FSCC
Facility Security Clearance Certificate (NATO)
FSO
facility security officer
GCA
government contracting activity
GCMS
government contractor monitoring station
GSA
General Services Administration
GSC
government security committee
IDE
intrusion detection equipment
IDS
intrusion detection system
IFB
invitation for bid
ISOO
Information Security Oversight Office
ISSM
information system security manager
ISSO
information systems security officer
ITAR
International Traffic in Arms Regulations
ITPSO
insider threat program senior official
KMP
key management personnel
LAA
limited access authorization
MFO
multiple facility organization
NATO
North Atlantic Treaty Organization
NDA
nondisclosure agreement
NIAG
NATO Industrial Advisory Group
NID
national interest determination
NISP
National Industrial Security Program
NISPOM
National Industrial Security Program Operating Manual
NIST
National Institute for Standards and Technology
NNPI
Naval Nuclear Propulsion Information
NNSA
National Nuclear Security Administration
NPLO
NATO Production Logistics Organization
NRC
Nuclear Regulatory Commission
NRTL
nationally recognized testing laboratory
NSA
National Security Agency
NSI
national security information
NTIB
National Technology and Industrial Base
OCA
original classification authority
OMB
Office of Management and Budget
PA
proxy agreement
PCL
personnel (security) clearance
RD
Restricted Data
RFP
request for proposal
RFQ
request for quotation
SAP
special access program
SCA
security control agreement
SCI
sensitive compartmented information
SD
Secretary of Defense (forms only)
SEAD
Security Executive Agent directive
SF
standard form
SMO
senior management official
SSA
special security agreement
SSP
systems security plan
TCP
technology control plan
TFNI
Transclassified Foreign Nuclear Information
TP
transportation plan
UK
United Kingdom
UL
Underwriters' Laboratories
U.S.C.
United States Code
USD (I&S)
Under Secretary of Defense for Intelligence and Security
USG
United States Government
USML
United States Munitions List
VAL
visit authorization letter
VT
voting trust
(b) Definitions. Unless otherwise noted, these terms and their definitions are for the purposes of this rule.
Access
means the ability and opportunity to gain knowledge of classified information.
Access Permittee
means the holder of an Access Permit issued pursuant to the regulations set forth in 10 CFR part 725, “Permits For Access to Restricted Data.”
ACCM
are security measures used by USG agencies to safeguard classified intelligence or operations when normal measures are insufficient to achieve strict need-to-know controls and where SAP controls are not required.
Adverse information
means any information that adversely reflects on the integrity or character of a cleared employee, that suggests that his or her ability to safeguard classified information may be impaired, that his or her access to classified information clearly may not be in the interest of national security, or that the individual constitutes an insider threat.
Affiliate
means each entity that directly or indirectly controls, is directly or indirectly controlled by, or is under common control with, the ultimate parent entity.
Agency(ies)
means any “Executive agency” as defined in 5 U.S.C. 105; any “Military department” as defined in 5 U.S.C. 102; and any other entity within the executive branch that releases classified information to private sector entities. This includes component agencies under another agency or under a cross-agency oversight office (such as ODNI with CIA), which are also agencies for purposes of this rule.
Alarm service company
means an entity or branch office from which all of the installation, service, and maintenance of alarm systems are provided, and the monitoring and investigation of such systems are either provided by its own personnel or with personnel assigned by this location.
Alarm system description form
means a form describing an alarm system and monitoring information.
Approved security container
means a GSA approved security container originally procured through the Federal Supply system. The security containers bear the GSA Approval label on the front face of the container, which identifies them as meeting the testing requirements of the assigned federal specification and having been maintained according to Federal Standard 809.
Approved vault
means a vault built to Federal Standard 832 and approved by the CSA.
AUS community
consists of the Government of Australia entities and Australian non-governmental facilities identified on the DDTC website (
https://pmddtc.state.gov/
) at the time of export or transfer.
Authorized person
means a person who has a favorable determination of eligibility for access to classified information, has signed an approved nondisclosure agreement, and has a need-to-know.
Branch office
means an office of an entity which is located somewhere other than the entity's main office location. A branch office is simply another location of the same legal business entity, and is still involved in the business activities of the entity.
CCIPP
means security sharing of classified information under a designated critical infrastructure protection program with such authorized individuals and organizations as determined by the Secretary of Homeland Security.
CDC
means a subset of contractors cleared under the NISP who have classified contracts with the DoD.
Certification
means comprehensive evaluation of an information system component that establishes the extent to which a particular design and implementation meets a set of specified security requirements.
Classification guide
means a document issued by an authorized original classifier that identifies the elements of information regarding a specific subject that must be classified and prescribes the level and duration of classification and appropriate declassification instructions.
Classified contract
means any contract, license, agreement, or grant requiring access to classified information by a contractor and its
employees for performance. A contract is referred to in this rule as a “classified contract” even when the contract document and the contract provisions are not classified. The requirements prescribed for a “classified contract” also are applicable to all phases of precontract, license or grant activity, including solicitations (bids, quotations, and proposals), precontract negotiations, post-contract activity, or other government contracting activity (GCA) programs or projects which require access to classified information by a contractor.
Classified covered information system
means an information system that is owned or operated by or for a cleared defense contractor and that processes, stores, or transmits information created by or for the DoD with respect to which such contractor is required to apply enhanced protection (
e.g.,
classified information). A classified covered information system is a type of covered network consistent with the requirements of Section 941 of Public Law 112-239 and 10 U.S.C. 391.
Classified information
means information that has been determined, pursuant to E.O. 13526, or any predecessor or successor order, and the AEA of 1954, as amended, to require protection against unauthorized disclosure in the interest of national security and which has been so designated. The term includes NSI, RD, and FRD.
Classified meetings
means a conference, seminar, symposium, exhibit, convention, training course, or other such gathering during which classified information is disclosed.
Classified visit
means a visit during which a visitor will require, or is expected to require, access to classified information.
Classifier
means any person who makes a classification determination and applies a classification category to information or material. The determination may be an original classification action or it may be a derivative classification action. Contractors make derivative classification determinations based on classified source material, a security classification guide, or a contract security classification specification, or equivalent.
Cleared commercial carrier
means a carrier that is authorized by law, regulatory body, or regulation to transport SECRET and CONFIDENTIAL material and has been granted a SECRET facility clearance in accordance with the NISP.
Cleared employees
means all employees of industrial or commercial contractors, licensees, certificate holders, or grantees of an agency, as well as all employees of subcontractors and personal services contractor personnel, and who are granted favorable eligibility determinations for access to classified information by a CSA or are being processed for eligibility determinations for access to classified information by a CSA. A contractor may give an employee access to classified information in accordance with the provisions of § 117.10(a)(1)(iii).
Closed area
means an area that meets the requirements of this rule for safeguarding classified material that, because of its size, nature, or operational necessity, cannot be adequately protected by the normal safeguards or stored during nonworking hours in approved containers.
CNWDI
means a DoD category of TOP SECRET RD or SECRET RD information that reveals the theory of operation or design of the components of a thermonuclear or fission bomb, warhead, demolition munition, or test device. Specifically excluded is information concerning arming, fusing, and firing systems; limited life components; and total contained quantities of fissionable, fusionable, and high explosive materials by type. Among these excluded items are the components that DoD personnel set, maintain, operate, test or replace.
Compromise
means an unauthorized disclosure of classified information.
COMSEC
means the protective measures taken to deny unauthorized persons information derived from USG telecommunications relating to national security and to ensure the authenticity of such communications.
CONFIDENTIAL
means the classification level applied to information, the unauthorized disclosure of which reasonably could be expected to cause damage to the national security that the original classification authority (OCA) is able to identify or describe.
Consignee
means a person, firm, or Government (
i.e.,
USG or foreign government) activity named as the receiver of a shipment; one to whom a shipment is consigned.
Consignor
means a person, firm, or Government (
i.e.,
USG or foreign government) activity by which articles are shipped. The consignor is usually the shipper.
Constant surveillance service
means a transportation protective service provided by a commercial carrier qualified by the Surface Deployment and Distribution Command to transport CONFIDENTIAL shipments. The service requires constant surveillance of the shipment at all times by a qualified carrier representative; however, an FCL is not required for the carrier. The carrier providing the service must maintain a signature and tally record for the shipment.
Consultant
means an individual under contract, and compensated directly, to provide professional or technical assistance to a contractor in a capacity requiring access to classified information.
Continuous evaluation
as defined in SEAD 6 is a personnel security investigative process to review the background of a covered individual who has been determined to be eligible for access to classified information or to hold a sensitive position at any time during the period of eligibility. Continuous evaluation leverages a set of automated records checks and business rules, to assist in the ongoing assessment of an individual's continued eligibility. It supplements, but does not replace, the established personnel security program for scheduled periodic reinvestigations of individuals for continuing eligibility.
Continuous monitoring program
means a system that facilitates ongoing awareness of threats, vulnerabilities, and information security to support organizational risk management decisions.
Contracting officer
means a USG official who, in accordance with departmental or agency procedures, has the authority to enter into and administer contracts, licenses or grants and make determinations and findings with respect thereto, or any part of such authority. The term also includes the designated representative of the contracting officer acting within the limits of his or her authority.
Contractor
means any industrial, educational, commercial, or other entity that has been granted an entity eligibility determination by a CSA. This term also includes licensees, grantees, or certificate holders of the USG with an entity eligibility determination granted by a CSA. As used in this rule, “contractor” does not refer to contractor employees or other personnel.
Cooperative agreement
means a legal instrument which, consistent with 31 U.S.C. 6305, is used to enter into the same kind of relationship as a grant (see definition of “grant” in this subpart), except that substantial involvement is expected between USG and the recipient when carrying out the activity contemplated by the cooperative agreement. The term does not include “cooperative research and development agreements” as defined in 15 U.S.C. 3710a.
Cooperative research and development agreement
means any agreement between one or more Federal laboratories and one or more non-Federal parties under which the Government, through its laboratories, provides personnel, services, facilities, equipment, intellectual property, or other resources with or without reimbursement (but not funds to non-Federal parties) and the non-Federal parties provide funds, personnel, services, facilities, equipment, intellectual property, or other resources toward the conduct of specified research or development efforts which are consistent with the missions of the laboratory; except that such term does not include a procurement contract or cooperative agreement as those terms are used in sections 6303, 6304, and 6305 of title 31.
Corporate family
means an entity, its parents, subsidiaries, divisions, and branch offices.
Counterintelligence
means information gathered and activities conducted to protect against espionage, other intelligence activities, sabotage, or assassinations conducted for or on behalf of foreign powers, organizations or persons, or international terrorist activities, but not including personnel, physical, document or communications security programs.
Courier
means a cleared employee, designated by the contractor, whose principal duty is to transmit classified material to its destination, ensuring that the classified material remains under their constant and continuous protection and that they make direct point-to-point delivery.
CRYPTO
means the marking or designator that identifies unencrypted COMSEC keying material used to secure or authenticate telecommunications carrying classified or sensitive USG or USG-derived information. This includes non-split keying material used to encrypt or decrypt COMSEC critical software and software based algorithms.
CSA
means an agency designated as having NISP implementation and security responsibilities for its own agencies (including component agencies) and any entities and non-CSA agencies under its cognizance. The CSAs are: DoD; DOE; NRC; ODNI; and DHS.
CSO
means an organizational unit to which the head of a CSA delegates authority to administer industrial security services on behalf of the CSA.
CUI
means information the USG creates or possesses, or that an entity creates or possesses for or on behalf of the USG, that a law, regulation, or USG-wide policy requires or permits an agency to handle using safeguarding or dissemination controls. However, CUI does not include classified information or information a non-executive branch entity possesses and maintains in its own systems that did not come from, or was not created or possessed by or for, an executive branch agency or an entity acting for an agency.
Custodian
means an individual who has possession of, or is otherwise charged with, the responsibility for safeguarding classified information.
Cybersecurity
means prevention of damage to, protection of, and restoration of computers, electronic communications systems, electronic communications services, wire communication, and electronic communication, including information contained therein, to ensure its availability, integrity, authentication, confidentiality, and nonrepudiation.
Cyber incident
means actions taken through the use of computer networks that result in an actual or potentially adverse effect on an information system or the information residing therein.
Declassification
means a date or event which coincides with the lapse of the information's national security sensitivity, as determined by the OCA. Declassification occurs when the OCA has determined that the classified information no longer requires, in the interest of national security, any degree of protection against unauthorized disclosure, and the information has had its classification designation removed or cancelled.
Defense articles
means those articles, services, and related technical data, including software, in tangible or intangible form, which are listed on the United States Munitions List (USML) of the International Traffic in Arms Regulations (ITAR), as modified or amended. Defense articles exempt from the scope of ITAR section 126.17 are identified in Supplement No. 1 to Part 126 of the ITAR.
Defense services
means:
(1) Furnishing assistance (including training) to foreign persons, whether in the United States or abroad, in the design, development, engineering, manufacture, production, assembly, testing, repair, maintenance, modification, operation, demilitarization, destruction, processing or use of defense articles;
(2) Furnishing to foreign persons any controlled technical data, whether in the United States or abroad; or
(3) Providing military training of foreign units and forces, regular and irregular, including formal or informal instruction of foreign persons in the United States or abroad or by correspondence courses, technical, educational, or information publications and media of all kinds, training aid, orientation, training exercise, and military advice.
Derivative classification
means the incorporating, paraphrasing, restating, or generating in new form information that is already classified, and marking the newly developed material consistent with the classification markings that apply to the source information. Derivative classification includes classifying information based on classification guidance. Duplicating or reproducing existing classified information is not derivative classification.
Document
means any recorded information, regardless of the nature of the medium, or the method or circumstances of recording.
Downgrade
means a determination by a declassification authority that information classified and safeguarded at a specified level will be classified and safeguarded at a lower level.
Embedded system
means an information system that performs or controls a function, either in whole or in part, as an integral element of a larger system or subsystem, such as, ground support equipment, flight simulators, engine test stands, or fire control systems.
Empowered official
is defined in 22 CFR part 120.
Entity
is a generic and comprehensive term which may include sole proprietorships, partnerships, corporations, limited liability companies, societies, associations, institutions, contractors, licensees, grantees, certificate holders, and other organizations usually established and operating to carry out a commercial, industrial, educational, or other legitimate business, enterprise, or undertaking, or parts of these organizations. It may reference an entire organization, a prime contractor, parent organization, a branch or division, another type of sub-element, a sub-contractor, subsidiary, or other subordinate or connected entity (referred to as “sub-entities” when necessary to distinguish such entities from prime or parent entities). It may also reference a specific location or facility, or the headquarters or official business location of the organization, depending upon the organization's business structure, the access needs involved, and the responsible CSA's procedures. The term “entity” as used in this rule refers to the particular entity to which an agency might release, or is releasing, classified information, whether that entity is a parent or
subordinate organization. The term “entity” in this rule includes contractors.
Entity eligibility determination
means an assessment by the CSA as to whether an entity is eligible for access to classified information of a certain level (and all lower levels). Entity eligibility determinations may be broad or limited to specific contracts, sponsoring agencies, or circumstances. A favorable entity eligibility determination results in eligibility to access classified information under the cognizance of the responsible CSA to the level approved. When the entity would be accessing categories of information such as RD or SCI for which the CSA for that information has set additional requirements, CSAs must also assess whether the entity is eligible for access to that category of information. Some CSAs refer to their favorable entity eligibility determinations as FCLs. However, a favorable entity eligibility determination for the DHS CCIPP is not equivalent to an FCL and does not meet the requirements for FCL reciprocity. A favorable entity eligibility determination does not convey authority to store classified information.
Escort
means a cleared person, designated by the contractor, who accompanies a shipment of classified material to its destination. The classified material does not remain in the personal possession of the escort but the conveyance in which the material is transported remains under the constant observation and control of the escort.
Extent of protection
means the designation (such as “Complete”) used to describe the degree of alarm protection installed in an alarmed area.
Facility
means a plant, laboratory, office, college, university, or commercial structure with associated warehouses, storage areas, utilities, and components, that, when related by function and location, form an operating entity.
FCL
means an administrative determination that, from a security viewpoint, an entity is eligible for access to classified information of a certain level (and all lower levels) (
e.g.,
a type of favorable entity eligibility determination used by some CSAs). An entity eligibility determination for the DHS CCIPP is not the equivalent of an FCL and does not meet the requirements for FCL reciprocity.
FGI
means information that is:
(1) Provided to the United States by a foreign government or governments, an international organization of governments, or any element thereof with the expectation, expressed or implied, that the information, the source of the information, or both, are to be held in confidence; or
(2) Produced by the United States pursuant to, or as a result of, a joint arrangement with a foreign government or governments, an international organization of governments, or any element thereof, requiring that the information, the arrangement, or both are to be held in confidence.
Foreign interest
means any foreign government, agency of a foreign government, or representative of a foreign government; any form of business enterprise or legal entity organized, chartered or incorporated under the laws of any country other than the United States or its territories, and any person who is not a citizen or national of the United States.
Foreign national
means any person who is not a citizen or national of the United States.
Foreign person
is defined in 31 CFR 800.224 for CFIUS purposes.
FRD
means classified information removed from the Restricted Data category upon a joint determination by the DOE and DoD that such information relates primarily to the military utilization of atomic weapons and that such information can be adequately safeguarded as classified defense information.
Freight forwarder (transportation agent)
means any agent or facility designated to receive, process, and transship U.S. material to foreign recipients. In the context of this rule, it means an agent or facility cleared specifically to perform these functions for the transfer of U.S. classified material to foreign recipients.
GCA
means an element of an agency that the agency head has designated and delegated broad authority regarding acquisition functions. A foreign government may also be a GCA.
Governing board
means an entity's board of directors, board of managers, board of trustees, or equivalent governing body.
Grant
means a legal instrument which, consistent with 31 U.S.C. 6304, is used to enter into a relationship: (a) Of which the principal purpose is to transfer a thing of value to the recipient to carry out a public purpose of support or stimulation authorized by a law of the United States, rather than to acquire property or services for the USG's direct benefit or use; or, (b) In which substantial involvement is not expected between DoD and the recipient when carrying out the activity contemplated by the award. Throughout this rule, the term grant will include both the grant and cooperative agreement.
Grantee
means the entity that receives a grant or cooperative agreement.
Hand carrier
means a cleared employee, designated by the contractor, who occasionally hand carries classified material to its destination in connection with a classified visit or meeting. The classified material remains in the personal possession of the hand carrier except for authorized overnight storage.
Home office
means the headquarters of a multiple facility entity.
Industrial security
means that portion of information security concerned with the protection of classified information in the custody of U.S. industry.
Information
means any knowledge that can be communicated or documentary material, regardless of its physical form or characteristics.
Information security
means the system of policies, procedures, and requirements established pursuant to executive order, statute, or regulation to protect information that, if subjected to unauthorized disclosure, could reasonably be expected to cause damage to national security. The term also applies to policies, procedures, and requirements established to protect unclassified information that may be withheld from release to the public.
Information system
means an assembly of computer hardware, software, and firmware configured for the purpose of automating the functions of calculating, computing, sequencing, storing, retrieving, displaying, communicating, or otherwise manipulating data, information and textual material.
Insider
means cleared contractor personnel with authorized access to any USG or contractor resource, including personnel, facilities, information, equipment, networks, and systems.
Insider threat
means the likelihood, risk, or potential that an insider will use his or her authorized access, wittingly or unwittingly, to do harm to the national security of the United States. Insider threats may include harm to contractor or program information, to the extent that the information impacts the contractor or agency's obligations to protect classified NSI.
Joint venture
means an association of two or more persons or entities engaged in a single defined project with all parties contributing assets and efforts, and sharing in the management, profits and losses, in accordance with the terms of an agreement among the parties.
KMP
means an entity's senior management official (SMO), facility security officer (FSO), insider threat program senior official (ITPSO), and all other entity officials who either hold majority interest or stock in, or have
direct or indirect authority to influence or decide issues affecting the management or operations of, the entity or classified contract performance.
L access authorization
means an access determination that is granted by DOE or NRC based on a Tier 3 or successor background investigation as set forth in applicable national-level requirements and DOE directives. Within DOE and NRC, an “L” access authorization permits an individual who has an official “need to know” to access Confidential Restricted Data, Secret and Confidential Formerly Restricted Data, Secret and Confidential Transclassified Foreign Nuclear Information, or Secret and Confidential National Security Information, required in the performance of official duties. An “L” access authorization determination is required for individuals with a need to know outside of DOE, NRC, DoD, and in limited cases NASA, to access Confidential Restricted Data.
LAA
means security access authorization to CONFIDENTIAL or SECRET information granted to non-U.S. citizens requiring only limited access in the course of their regular duties.
Material
means any product or substance on or in which information is embodied.
Matter
means anything in physical form that contains or reveals classified information.
Media
means physical devices or writing surfaces including but not limited to, magnetic tapes, optical disks, magnetic disks, large-scale integration memory chips, and printouts (but not including display media) onto which information is recorded, stored, or printed within an information system.
MFO
means a legal entity (single proprietorship, partnership, association, trust, or corporation) composed of two or more entities (facilities).
National of the United States
means a person who owes permanent allegiance to the United States. All U.S. citizens are U.S. nationals; however, not all U.S. nationals are U.S. citizens (for example, persons born in American Samoa or Swains Island).
NATO information
means information bearing NATO markings, indicating the information is the property of NATO, access to which is limited to representatives of NATO and its member nations unless NATO authority has been obtained to release outside of NATO.
NATO visits
means visits by personnel representing a NATO entity and relating to NATO contracts and programs.
Need-to-know
means a determination made by an authorized holder of classified information that a prospective recipient has a requirement for access to, knowledge of, or possession of the classified information to perform tasks or services essential to the fulfillment of a classified contract or program.
Network
means a system of two or more information systems that can exchange data or information.
NNPI
is classified or unclassified information concerning the design, arrangement, development, manufacture, testing, operation, administration, training, maintenance, and repair of the propulsion plants of naval nuclear-powered ships and prototypes, including the associated shipboard and shore-based nuclear support facilities.
Non-DoD executive branch agencies
means the non-DoD agencies that have entered into agreements with DoD to receive NISP industrial security services from DoD. A list of these agencies is on the Defense Counterintelligence and Security Agency website at
https://www.dcsa.mil.
Non-Federal information system
is defined in 32 CFR part 2002.
NRTL
means a private sector organizations recognized by the Occupational Safety and Health Administration to perform certification for certain products to ensure that they meet the requirements of both the construction and general industry Occupational Safety and Health Administration electrical standards. Each NRTL is recognized for a specific scope of test standards.
NSI
means information that has been determined pursuant to E.O. 13526 or predecessor order to require protection against unauthorized disclosure and marked to indicate its classified status.
NTIB
means the industrial bases of the United States and Australia, Canada, and the United Kingdom.
NTIB entity
means a person that is a subsidiary located in the United States for which the ultimate parent entity and any intermediate parent entities of such subsidiary are located in a country that is part of the national technology and industrial base (as defined in section 2500 of title 10, United States Code); and that is subject to the foreign ownership, control, or influence requirements of the National Industrial Security Program.
Nuclear weapon data
means Restricted Data or Formerly Restricted Data concerning the design, manufacture, or utilization (including theory, development, storage, characteristics, performance and effects) of nuclear explosives, nuclear weapons or nuclear weapon components, including information incorporated in or related to nuclear explosive devices. Nuclear weapon data is matter in any combination of documents or material, regardless of physical form or characteristics.
OCA
means an individual authorized in writing, either by the President, the Vice President, or by agency heads or other officials designated by the President, to classify information in the first instance.
Original classification
means an initial determination that information requires, in the interest of national security, protection against unauthorized disclosure. Only USG officials who have been designated in writing may apply an original classification to information.
Parent
means an entity that owns at least a majority of another entity's voting securities.
PCL
means an administrative determination that an individual is eligible, from a security point of view, for access to classified information of the same or lower category as the level of the personnel clearance being granted.
Prime contract
means a contract awarded by a GCA to a contractor for a legitimate USG purpose.
Prime contractor
means the contractor who receives a prime contract from a GCA.
Privileged user
means a user that is authorized (and, therefore, trusted) to perform security-relevant functions that ordinary users are not authorized to perform.
Proscribed information
means:
(1) TOP SECRET information;
(2) COMSEC information or material, excluding controlled cryptographic items when unkeyed or utilized with unclassified keys.
(3) RD;
(4) SAP information; or.
(5) SCI.
Protective security service
means a transportation protective service provided by a cleared commercial carrier qualified by DoD's Surface Deployment and Distribution Command to transport SECRET shipments.
Q access authorization
means an access determination that is granted by DOE or NRC based on a Tier 5 or successor background investigation as set forth in applicable national-level requirements and DOE directives. Within DOE and the NRC, a “Q” access authorization permits an individual with an official “need to know” to access Top Secret, Secret and Confidential Restricted Data, Formerly Restricted Data, Transclassified Foreign
Nuclear Information, National Security Information, or special nuclear material in Category I or II quantities, as required in the performance of official duties. A “Q” access authorization is required for individuals with a need to know outside of DOE, NRC, DoD, and in a limited case NASA, to access Top Secret and Secret Restricted Data.
Remote terminal
means a device communicating with an automated information system from a location that is not within the central computer facility.
Restricted area
means a controlled access area established to safeguard classified material that, because of its size or nature, cannot be adequately protected during working hours by the usual safeguards, but is capable of being stored during non-working hours in an approved repository or secured by other methods approved by the CSA.
RD
means all data concerning (1) design, manufacture, or utilization of atomic weapons; (2) the production of special nuclear material; or (3) the use of special nuclear material in the production of energy, but does not include data declassified or removed from the RD category pursuant to section 142 of the AEA.
SAP
means any program that is established to control access and distribution and to provide protection for particularly sensitive classified information beyond that normally required for TOP SECRET, SECRET, or CONFIDENTIAL information. A SAP can be created or continued only as authorized by a senior agency official delegated such authority pursuant to E.O. 13526.
Schedule 13D
means a form required by the Securities and Exchange Commission when a person or group of persons acquires beneficial ownership of more than 5% of a voting class of a company's equity securities registered under Section 12 of the “Securities Exchange Act of 1934” (available at:
https://www.sec.gov/fast-answers/answerssched13htm.html
).
SCI
means a subset of classified national intelligence concerning or derived from intelligence sources, methods or analytical processes that is required to be protected within formal access control systems established by the DNI.
SECRET
means the classification level applied to information, the unauthorized disclosure of which reasonably could be expected to cause serious damage to the national security that the OCA is able to identify or describe.
Security in depth
means a determination made by the CSA that a contractor's security program consists of layered and complementary security controls sufficient to deter and detect unauthorized entry and movement within the facility. Examples include, but are not limited to, use of perimeter fences, employee and visitor access controls, use of an Intrusion Detection System (IDS), random guard patrols throughout the facility during nonworking hours, closed circuit video monitoring, or other safeguards that mitigate the vulnerability of open storage areas without alarms and security storage cabinets during nonworking hours.
Security violation
means failure to comply with the policy and procedures established by this part that reasonably could result in the loss or compromise of classified information.
Shipper
means one who releases custody of material to a carrier for transportation to a consignee. (See also “Consignor.”)
SMO
is the contractor's official responsible for the entity policy and strategy. The SMO is an entity employee occupying a position in the entity with ultimate authority over the facility's operations and the authority to direct actions necessary for the safeguarding of classified information in the facility. This includes the authority to direct actions necessary to safeguard classified information when the access to classified information by the facility's employees is solely at other contractor facilities or USG locations.
Source document
means an existing document that contains classified information that is incorporated, paraphrased, restated, or generated in new form into a new document.
Standard practice procedures
means a document prepared by a contractor that implements the applicable requirements of this rule for the contractor's operations and involvement with classified information at the contractor's facility.
Subcontract
means any contract entered into by a contractor to furnish supplies or services for performance of a prime contract or a subcontract. It includes a contract, subcontract, purchase order, lease agreement, service agreement, request for quotation (RFQ), request for proposal (RFP), invitation for bid (IFB), or other agreement or procurement action between contractors that requires or will require access to classified information to fulfill the performance requirements of a prime contract.
Subcontractor
means a supplier, distributor, vendor, or firm that enters into a contract with a prime contractor to furnish supplies or services to or for the prime contractor or another subcontractor. For the purposes of this rule, each subcontractor will be considered as a prime contractor in relation to its subcontractors.
Subsidiary
means an entity in which another entity owns at least a majority of its voting securities.
System software
means computer programs that control, monitor, or facilitate use of the information system; for example, operating systems, programming languages, communication, input-output controls, sorts, security packages, and other utility-type programs. Also includes off-the-shelf application packages obtained from manufacturers and commercial vendors, such as for word processing, spreadsheets, data base management, graphics, and computer-aided design.
Technical data
means:
(1) Information, other than software, which is required for the design, development, production, manufacture, assembly, operation, repair, testing, maintenance or modification of defense articles. This includes information in the form of blueprints, drawings, photographs, plans, instructions or documentation.
(2) Classified information relating to defense articles and defense services on the U.S. Munitions List and 600-series items controlled by the Commerce Control List.
(3) Information covered by an invention secrecy order.
(4) Software directly related to defense articles.
TFNI
means classified information concerning the nuclear energy programs of other nations (including subnational entities) removed from the RD category under section 142(e) of the AEA after the DOE and the Director of National Intelligence jointly determine that it is necessary to carry out intelligence-related activities under the provisions of the National Security Act of 1947, as amended, and that it can be adequately safeguarded as NSI instead. This includes information removed from the RD category by past joint determinations between DOE and the CIA. TFNI does not include information transferred to the United States under an Agreement for Cooperation under the Atomic Energy Act or any other agreement or treaty in which the United States agrees to protect classified information.
TOP SECRET
means the classification level applied to information, the unauthorized disclosure of which reasonably could be expected to cause exceptionally grave damage to the national security that the OCA is able to identify or describe.
Transmission
means sending information from one place to another by radio, microwave, laser, or other non-connective methods, as well as by cable, wire, or other connective medium. Transmission also includes movement involving the actual transfer of custody and responsibility for a document or other classified material from one authorized addressee to another.
Transshipping activity
means a government activity to which a carrier transfers custody of freight for reshipment by another carrier to the consignee.
UK community
consists of the UK Government entities with facilities and UK non-governmental facilities identified on the DDTC website (
https://www.pmddtc.state.gov/
) at the time of export.
Unauthorized person
means a person not authorized to have access to specific classified information in accordance with the requirements of this rule.
United States
means the 50 states and the District of Columbia.
United States and its territorial areas
means the 50 states, the District of Columbia, Puerto Rico, Guam, American Samoa, the Virgin Islands, Wake Island, Johnston Atoll, Kingman Reef, Palmyra Atoll, Baker Island, Howland Island, Jarvis Island, Midway Islands, Navassa Island, and Northern Mariana Islands.
Upgrade
means a determination that certain classified information, in the interest of national security, requires a higher degree of protection against unauthorized disclosure than currently provided, coupled with a change to the classification designation to reflect the higher degree.
U.S. classified cryptographic information
means a cryptographic key and authenticators that are classified and are designated as TOP SECRET CRYPTO or SECRET CRYPTO. This means all cryptographic media that embody, describe, or implement classified cryptographic logic, to include, but not limited to, full maintenance manuals, cryptographic descriptions, drawings of cryptographic logic, specifications describing a cryptographic logic, and cryptographic software, firmware, or repositories of such software such as magnetic media or optical disks.
U.S. person
means a United States citizen, an alien known by the intelligence agency concerned to be a permanent resident alien, an unincorporated association substantially composed of United States citizens or permanent resident aliens, or a corporation incorporated in the United States, except for a corporation directed and controlled by a foreign government or governments.
Voting securities
means any securities that presently entitle the owner or holder thereof to vote for the election of directors of the issuer or, with respect to unincorporated entities, individuals exercising similar functions.
Working hours
means the period of time when:
(1) There is present in the specific area where classified material is located, a work force on a regularly scheduled shift, as contrasted with employees working within an area on an overtime basis outside of the scheduled work shift; and
(2) The number of employees in the scheduled work force is sufficient in number and so positioned to be able to detect and challenge the presence of unauthorized personnel. This would, therefore, exclude janitors, maintenance personnel, and other individuals whose duties require movement throughout the facility.
Working papers
means documents or materials, regardless of the media, which are expected to be revised prior to the preparation of a finished product for dissemination or retention.
§ 117.4
Policy.
E.O. 12829 established the NISP to serve as a single, integrated, cohesive industrial security program to protect classified information and preserve our Nation's economic and technological interests.
(a) When contracts, licenses, agreements, and grants to contractors require access to classified information, national security requires that this information be safeguarded in a manner equivalent to its protection within the executive branch of the USG.
(b) National security requires that the industrial security program promote the economic and technological interests of the United States. Redundant, overlapping, or unnecessary requirements impede those interests.
§ 117.5
Information collections.
The information collection requirements are:
(a)
Standard Form (SF) 328
“Certificate Pertaining to Foreign Interest” (available at:
https://www.gsa.gov/forms-library/certificate-pertaining-foreign-interests
) in § 117.8 and § 117.11, is assigned Office of Management and Budget (OMB) Control Number 0704-0579. The expiration date of this information collection is listed in the DoD Information Collections System at
https://apps.sp.pentagon.mil/sites/dodiic/Pages/default.aspx.
(b)
NRC collection.
“Facility Security Clearance and Safeguarding of National Security Information and Restricted Data,” is assigned OMB Control Number: 3150-0047. Under this collection, NRC-regulated facilities and other organizations are required to provide information and maintain records to ensure that an adequate level of protection is provided to NRC-classified information and material.
(c)
DOE collection.
“Security,” a NISP CSA information collection, is assigned OMB Control Number: 1910-1800. This information collection, which includes facility security clearance information, is used by the DOE to exercise management, oversight, and control over its contractors' management and operation of DOE's Government-owned contractor-operated facilities, and over its offsite contractors. The contractor management, oversight, and control functions relate to the ways in which DOE contractors provide goods and services for DOE organizations and activities in accordance with the terms of their contracts and the applicable statutory, regulatory, and mission support requirements of the Department. Information collected from private industry and private individuals is used to protect national security and critical assets entrusted to the Department.
(d)
DoD collection.
“DoD Security Agreement,” is assigned OMB Control Number: 0704-0194. “National Industrial Security System,” a CSA information collection, is assigned OMB Control Number: 0704-0571, and is a DoD information collection used to conduct its monitoring and oversight of contractors. Department of Defense “Contract Security Classification Specification,” (available at:
https://www.esd.whs.mil/Portals/54/Documents/DD/forms/dd/dd0254.pdf
and available at:
https://www.dcsa.mil/is/nccs/
), is assigned OMB Control Number 0704-0567 and used by both DoD and agencies which have an industrial security agreement with DoD. “Defense Information System for Security,” is assigned OMB Control Number: 0704-0573. Defense Information System for Security is a DoD automated system for personnel security, providing a common, comprehensive medium to record, document, and identify personal security actions within DoD including submitting adverse information, verification of security clearance status, requesting investigations, and supporting continuous evaluation activities. It requires personal data collection to facilitate the initiation, investigation and adjudication of information relevant to DoD security clearances and employment suitability
determinations for active duty military, civilian employees and contractors seeking such credentials. Joint Personnel Adjudicative System is assigned OMB Control Number: 0704-0496. Joint Personnel Adjudicative System is an information system which requires personal data collection to facilitate the initiation, investigation and adjudication of information relevant to DoD security clearances and employment suitability determinations for active duty military, civilian employees and contractors seeking such credentials.
§ 117.6
Responsibilities.
(a)
Under Secretary of Defense for Intelligence & Security (USD(I&S)).
The USD(I&S), on behalf of the Secretary of Defense, and in accordance with E.O. 12829, 32 CFR part 2004, and DoDI 5220.22:
(1) Carries out the direction in section 201 of E.O. 12829 that the Secretary of Defense issue and maintain this rule and changes to it. The USD(I&S) does so in consultation with all affected agencies (E.O. 12829 section 201), with the concurrence of the Secretary of Energy, the Chairman of the NRC, the DNI, and the Secretary of Homeland Security (E.O.12829 section 201), and in consultation with the ISOO Director (E.O. 12829 section 102).
(2) Acts as the CSA for DoD.
(3) Provides policy and management of the NISP for non-DoD executive branch agencies who enter into inter-agency security agreements with DoD to provide industrial security services required when classified information is disclosed to contractors in accordance with E.O. 12829, as amended.
(b)
Director, DCSA.
Under the authority, direction, and control of the USD(I&S), and in accordance with DoDI 5220.22 and DoD Directive (DoDD) 5105.42, “Defense Security Service (DSS)”
1
(available at:
https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodd/510542p.pdf?ver=2019-01-14-090012-283
) the Director, DCSA:
1
On June 20, 2020, the Secretary of Defense re-named the Defense Security Service (DSS) as the Defense Counterintelligence and Security Agency (DCSA), as required by Executive Oder 13467, section 2.6(b)(i) (as amended by Executive Order 13968, Apr. 24, 2019, 84 FR 18125). Pursuant to Section 4 of E.O. 13968, references to DSS in DoD issuances should be deemed or construed to refer to DCSA.
(1) Oversees and manages DCSA, which serves as the DoD CSO.
(2) Administers the NISP as a separate program element on behalf of DoD GCAs and those agencies with agreements with DoD for security services.
(3) Provides security oversight of the NISP as the DoD CSO on behalf of DoD components and those non-DoD executive branch agencies who enter into agreements with DoD as noted in paragraph (a)(3) of this section. The Director, DCSA, will be relieved of this oversight function for DoD special access programs (SAPs) when the Secretary of Defense or the Deputy Secretary of Defense approves a carve-out provision in accordance with DoDD 5205.07, “DoD SAP Policy” (available at:
https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodd/520507p.pdf?ver=2020-02-04-142942-827
).
(c)
Secretary of Energy.
In addition to the responsibilities in paragraph (h) of this section, the Secretary of Energy:
(1) Prescribes procedures for the portions of this rule pertaining to information classified under the AEA (
i.e.,
RD, FRD, and TFNI), as nothing in the rule shall be construed to supersede the authority of the Secretary of Energy under the AEA.
(2) Retains authority over access to information classified under the AEA.
(3) Inspects and monitors contractor, licensee, certificate holder, and grantee programs and facilities that involve access to information classified under the AEA, as necessary.
(d)
Chairman of the NRC.
In addition to the responsibilities in paragraph (h) of this section, the Chairman of the NRC:
(1) Prescribes procedures for the portions of this rule that pertain to information under NRC programs classified under the AEA, other federal statutes, and executive orders.
(2) Retains authority over access to information under NRC programs classified under the AEA, other federal statutes, and executive orders.
(3) Inspects and monitors contractor, licensee, certificate holder, and grantee programs and facilities that involve access to information under NRC programs classified pursuant to the AEA, other federal statutes, and executive orders where appropriate.
(e)
DNI.
In addition to the responsibilities in paragraph (h) of this section, the DNI:
(1) Prescribes procedures for the portions of this rule pertaining to intelligence sources, methods, and activities, including, but not limited to, SCI.
(2) Retains authority over access to intelligence sources, methods, and activities, including SCI.
(3) Provides guidance on the security requirements for intelligence sources and methods of information, including, but not limited to, SCI.
(f)
Secretary of Homeland Security.
In accordance with E.O. 12829, E.O. 13691, and in addition to the responsibilities in paragraph (h) of this section, the Secretary of Homeland Security:
(1) Prescribes procedures for the portions of this rule that pertain to the CCIPP.
(2) Retains authority over access to information under the CCIPP.
(3) Inspects and monitors contractor, licensee, certificate holder, and grantee programs and facilities that involve access to CCIPP.
(g)
All the CSA heads.
The CSA heads:
(1) Oversee the security of classified contracts and activities under their purview.
(2) Provide oversight of contractors under their security cognizance.
(3) Minimize redundant and duplicative security review and audit activities of contractors, including such activities conducted at contractor locations where multiple CSAs have equities.
(4) Execute appropriate intra-agency and inter-agency agreements to avoid redundant and duplicate reviews.
(5) Designate one or more CSOs for security administration.
(6) Designate subordinate officials, in accordance with governing policies, to act as the authorizing official. Authorizing officials will:
(i) Assess and authorize contractors to process classified information on information systems.
(ii) Conduct oversight of such information system processing and provide information system security guidelines in accordance with Federal information system security control policies, standards, and procedures. Minimize redundant and duplicative security review and audit activity of contractors, including such activity conducted at contractor locations where multiple CSAs have equities.
(h)
Heads of component agencies.
In accordance with applicable CSA direction, the component agency heads:
(1) Oversee compliance with procedures identified by the applicable CSA or designated CSO.
(2) Provide oversight of contractor personnel visiting or working on USG installations.
(3) Promptly apprise the CSO of information received or developed that could adversely affect a cleared contractor, licensee, or grantee, and their employees, to hold an FCL or PCL, or that otherwise raises substantive doubt about their ability to safeguard classified information entrusted to them.
(4) Propose changes to this rule as deemed appropriate and provide them
to the applicable CSA for submission to the OUSD(I&S) Counterintelligence, Law Enforcement and Security Directorate.
(i)
Director, ISOO.
The Director, ISOO:
(1) Oversees the NSIP and agency compliance with it, in accordance with E.O. 12829.
(2) Issues and maintains the NISP implementing directive (32 CFR part 2004), in accordance with E.O. 12829, to provide guidance to the CSAs and USG agencies under the NISP.
(3) Chairs the NISP Policy Advisory Committee. Addresses complaints and suggestions from contractors, as detailed in the NISP Policy Advisory Committee bylaws.
§ 117.7
Procedures.
(a)
General.
Contractors will protect all classified information that they are provided access to or that they possess. This responsibility applies at both contractor and USG locations.
(b)
Contractor Security Officials.
Contractors will appoint security officials who are U.S. citizens, except in exceptional circumstances (see § 117.9(m) and § 117.11(e)).
(1) Appointed security officials listed in paragraphs (b)(2), (b)(3), and (b)(4) of this section must:
(i) Oversee the implementation of the requirements of this rule. Depending upon the size and complexity of the contractor's security operations, a single contractor employee may serve in more than one position.
(ii) Undergo the same security training that is required for all other contractor employees pursuant to § 117.12, in addition to their position specific training.
(iii) Be designated in writing with their designation documented in accordance with CSA guidance.
(iv) Undergo a personnel security investigation and national security eligibility determination for access to classified information at the level of the entity's eligibility determination for access to classified information (
e.g.,
FCL level) and be on the KMP list for the cleared entity.
(2)
SMO.
The SMO will:
(i) Ensure the contractor maintains a system of security controls in accordance with the requirements of this rule.
(ii) Appoint a contractor employee or employees, in writing, as the FSO and appoint the same employee or a different employee as the ITPSO. The SMO may appoint a single employee for both roles or may appoint one employee as the FSO and a different employee as the ITPSO.
(iii) Remain fully informed of the facility's classified operations.
(iv) Make decisions based on classified threat reporting and their thorough knowledge, understanding, and appreciation of the threat information and the potential impacts caused by a loss of classified information.
(v) Retain accountability for the management and operations of the facility without delegating that accountability to a subordinate manager.
(3)
FSO.
The FSO will:
(i) Supervise and direct security measures necessary for implementing the applicable requirements of this rule and the related USG security requirements to ensure the protection of classified information.
(ii) Complete security training pursuant to § 117.12 and as deemed appropriate by the CSA.
(4)
ITPSO.
The ITPSO will establish and execute an insider threat program.
(i) If the appointed ITPSO is not also the FSO, the ITPSO will ensure that the FSO is an integral member of the contractor's insider threat program.
(ii) The ITPSO will complete training pursuant to § 117.12.
(iii) An entity family may choose to establish an entity family-wide insider threat program with one senior official appointed, in writing, to establish, and execute the program as the ITPSO. Each cleared entity using the entity-wide ITPSO must separately appoint that person as its ITPSO for that facility. The ITPSO will provide an implementation plan to the CSA for executing the insider threat program across the entity family.
(5)
ISSM.
Contractors who are, or will be, processing classified information on an information system located at the contractor facility will appoint an employee to serve as the ISSM. The ISSM must be eligible for access to classified information to the highest level of the information processed on the system(s) under their responsibility. The contractor will ensure that the ISSM is adequately trained and possesses technical competence commensurate with the complexity of the contractor's classified information system. The contractor will notify the applicable CSA if there is a change in the ISSM. The ISSM will oversee development, implementation, and evaluation of the contractor's classified information system program. ISSM responsibilities are in § 117.18.
(6)
Employees performing security duties.
Those employees whose official duties include performance of NISP-related security functions will complete security training tailored to the security functions performed. This training requirement also applies to consultants whose official duties include security functions.
(c)
Other KMP.
In addition to the SMO, the FSO, and the ITPSO, the contractor will include on the KMP list, subject to CSA concurrence, any other officials who either hold majority interest or stock in the entity, or who have direct or indirect authority to influence or decide issues affecting the management or operations of the contractor or issues affecting classified contract performance. The CSA may either:
(1) Require these KMP to be determined to be eligible for access to classified information as a requirement for the entity's eligibility determination or;
(2) Allow the entity to formally exclude these KMP from access to classified information. The entity's governing board will affirm the exclusion by issuing a formal action (see table), and provide a copy of the exclusion action to the CSA. The entity's governing board will document this exclusion action.
Table 1 to Paragraph (
c
)(2)—Exclusion Resolutions
Type of affirmation
Language to be used in exclusion action
Affirmation for Exclusion from Access to Classified Information
[Insert name and address of entity or name and position of officer, director, partner, or similar entity official or officials] will not require, will not have, and can be effectively and formally excluded from, access to all classified information disclosed to the entity and does not occupy a position that would enable them to adversely affect the organization's policies or practices in the performance of classified contracts.
Affirmation for Exclusion from Higher-level Classified Information
[Insert name and address of entity or name and position of officer, director, partner, or similar entity official or officials] will not require, will not have, and can be effectively and formally excluded from access to [insert SECRET or TOP SECRET] classified information and does not occupy a position that would enable them to adversely affect the organization's policies or practices in the performance of [insert SECRET or TOP SECRET] classified contracts.
(d)
Insider Threat Program.
Pursuant to this rule and CSA provided guidance to supplement unique CSA mission requirements, the contractor will establish and maintain an insider threat program to gather, integrate, and report relevant and available information indicative of a potential or actual insider threat, consistent with E.O. 13587 and Presidential Memorandum “National Insider Threat Policy and Minimum Standards for Executive Branch Insider Threat Programs.”
(e)
Standard practice procedures.
The contractor will implement all applicable provisions of this rule at each of its cleared facility locations. The contractor will prepare written procedures when the CSA determines them to be necessary to reasonably exclude the possibility of loss or compromise of classified information, and in accordance with additional CSA-provided guidance, as applicable.
(f)
Cooperation with Federal agencies.
Contractors will cooperate with Federal agencies and their officially credentialed USG or contractor representatives during official reviews, investigations concerning the protection of classified information, or personnel security investigations of present or former employees and others (
e.g.,
consultants or visitors). At a minimum, cooperation includes:
(1) Providing suitable arrangements within the facility for conducting private interviews with employees during normal working hours;
(2) Providing, when requested, relevant employment or personnel files, security records, supervisory files, records pertinent to insider threat (
e.g.,
security, cybersecurity, and human resources) and any other records pertai
This text is long and has been trimmed here. Open the source document for the complete record.
This is a copy of a public record, reproduced as it was published. It is not legal advice, and it may not be the version a court would rely on. Check the official source before you cite it.