INTERNATIONAL INDUSTRIAL SECURITY REQUIREMENTS GUIDANCE ANNEX

Similar documents
PREPARATION OF A DD FORM 254 FOR SUBCONTRACTING. Cal Stewart ISP

A Guide. Preparation. DD Form 254. for the. of a. National Classification Management Society. Defense Security Service

Contract Security Classification Specification. DD-254 Guidance

Student Guide: North Atlantic Treaty Organization

The DD254 & You (SBIR)

CHAPTER 9 THE MULTINATIONAL INDUSTRIAL SECURITY WORKING GROUP (MISWG) A. INTRODUCTION. International Programs Security Handbook 9-1

International Programs Security Handbook T-1

SYNOPSIS of an INDUSTRIAL SECURITY MANUAL

DEPARTMENT OF DEFENSE CONTRACT SECURITY CLASSIFICATION SPECIFICATION

SUMMARY FOR CONFORMING CHANGE #1 TO DoDM , National Industrial Security Program Operating Manual (NISPOM)

B. ACCESS, STORAGE, CUSTODY, CONTROL AND TRANSMISSION OF CLASSIFIED INFORMATION

(Revised January 15, 2009) DISCLOSURE OF INFORMATION (DEC 1991)

Department of Defense DIRECTIVE

Security Classification Guidance v3

Department of Defense MANUAL

Department of Health and Human Services (HHS) National Security Information Manual, February 1, 2005

Industrial Security Program

Derivative Classifier Training

Acquisitions and Contracting Basics in the National Industrial Security Program (NISP)

DOE B, SAFEGUARDS AGREEMENT WITH THE INTERNATIONAL ATOMIC SYMBOL, AND OTHER CHANGES HAVE BEEN BY THE REVISIONS,

Department of Defense INSTRUCTION

Department of Defense DIRECTIVE

KDOT Procurement Guidelines for STP/CMAQ Funded Planning, Education, and Outreach Projects Effective 10/1/12

UNCLASSIFIED. Information Technology Security Guidance for Purchasing CSEC-Approved Cryptographic Equipment from the United States Government ITSG-26

Construction Management (CM) Procedures

INTEGRATING OPSEC INTO CONTRACTS. A Companion Guide to the OPSEC Practitioner s Toolbox

February 11, 2015 Incorporating Change 4, August 23, 2018

Department of Defense DIRECTIVE

Procurement Processes Policy

DISTRICT OF COLUMBIA WATER AND SEWER AUTHORITY (DC WATER) REQUEST FOR QUOTE RFQ 18-PR-DIT-27

Department of Defense INSTRUCTION

DEFENSE LOGISTICS AGENCY HEADQUARTERS CAMERON STATION ALEXANDRIA, VA 22314

DoD M OPERATING MANUAL. February

Commercial Solutions Opening (CSO) Office of the Secretary of Defense Defense Innovation Unit (Experimental)

REQUEST FOR PROPOSAL After Hours Answering Services

DEPUTY SECRETARY OF DEFENSE 1010 DEFENSE PENTAGON WASHINGTON, DC

CITY OF MIAMI SECTION 3 ECONOMIC OPPORTUNITY PLAN QUESTIONS

REPORT ON COST ESTIMATES FOR SECURITY CLASSIFICATION ACTIVITIES FOR 2005

Department of Defense DIRECTIVE. SUBJECT: Disclosure of Classified Military Information to Foreign Governments and International Organizations

CHAPTER 7 VISITS AND PERSONNEL EXCHANGES A. INTRODUCTION B. POLICY. International Programs Security Handbook 7-1

BY ORDER OF THE SECRETARY OF THE AIR FORCE AIR FORCE HEADQUARTERS OPERATING INSTRUCTION APRIL Security

Department of Defense INSTRUCTION. SUBJECT: DoD Information Security Program and Protection of Sensitive Compartmented Information

Request for Proposals (RFP) Strategic Advisor, Diversity in Children s Content Production May 2016 FILING DEADLINE: June 22, 2016

This page left blank.

Department of Defense INSTRUCTION

Identification and Protection of Unclassified Controlled Nuclear Information

Student Guide: Controlled Unclassified Information

Commercial Solutions Opening (CSO) Office of the Secretary of Defense Defense Innovation Unit (Experimental)

Q-53 Security Training: Transmitting and Transporting Classified Information, Part I

TOPIC: CONTRACTS STATE OF MISSISSIPPI DEPARTMENT OF EDUCATION SECTION 17.0 PAGE 1 OF 38 EFFECTIVE DATE: MAY 1, 2017 REVISION #4: MARCH 1, 2017

REQUEST FOR PROPOSAL (RFP) PROJECT MANAGEMENT CEDAR BAND TRAVEL PLAZA ENTERPRISE

Suggested Contractor File Folder Headings

NATO SECURITY INDOCTRINATION

Department of Defense INSTRUCTION. Access to and Dissemination of Restricted Data and Formerly Restricted Data

Request for Proposals. For RFP # 2011-OOC-KDA-00

Department of Defense INSTRUCTION. DoD Unclassified Controlled Nuclear Information (UCNI)

il~l IL 20 I I11 AD-A February 20, DIRECTIVE Department of Defense

TERREBONNE PARISH REQUEST FOR QUALIFICATIONS FOR ENGINEERING SERVICES. Generator Sizing and Installation

Export-Controlled Technology at Contractor, University, and Federally Funded Research and Development Center Facilities (D )

DEPARTMENT OF DEFENSE DIRECTIVES SYSTEM TRANSMITTAL. July 31, 1997 INSTRUCTIONS FOR RECIPIENTS

NNPI TERMS AND CONDITIONS

Georgia Lottery Corporation ("GLC") PROPOSAL. PROPOSAL SIGNATURE AND CERTIFICATION (Authorized representative must sign and return with proposal)

PRIVACY IMPACT ASSESSMENT (PIA) For the

Department of the Army TRADOC Memorandum Headquarters, United States Army Training and Doctrine Command Fort Eustis, Virginia

Department of Defense INSTRUCTION. SUBJECT: Security of Unclassified DoD Information on Non-DoD Information Systems

8/15/2013. Security Incidents Involving Special Circumstances. Information Security Webinar. Danny Jennings. DCO Meeting Room Navigation

APPENDIX N. GENERIC DOCUMENT TEMPLATE, DISTRIBUTION STATEMENTS AND DOCUMENT DATA SHEET and THE IMPORTANCE OF MARKING DOCUMENTS

NATO UNCLASSIFIED ARCHIVES COMMITTEE. Directive on the Public Disclosure of NATO Information

Question Distractors References Linked Competency

SECURITY OF CLASSIFIED MATERIALS B STUDENT HANDOUT

Self-Inspection Handbook for NISP Contractors

Introduction to Industrial Security, v3

Department of Defense DIRECTIVE. SUBJECT: Security Requirements for Automated Information Systems (AISs)

Foreign Disclosure and Contacts with Foreign Representatives

NAVSEA STANDARD ITEM CFR Part 61, National Emission Standards for Hazardous Air Pollutants

Student Guide Course: Original Classification

Department of Defense INSTRUCTION

Department of Defense INSTRUCTION

SERIES 1100 UNDER SECRETARY OF DEFENSE FOR INTELLIGENCE (USD(I)) ASSISTANT SECRETARY OF DEFENSE FOR NETWORKS AND INFORMATION INTEGRATION (ASD(NII))

Department of Defense DIRECTIVE. SUBJECT: Department of Defense Unclassified Controlled Nuclear Information (DoD UCNI)

Department of Defense MANUAL

PRIVACY IMPACT ASSESSMENT (PIA) For the

Question Distractors References Linked Competency

Department of Defense DIRECTIVE

ADMINISTRATIVE INSTRUCTION

Revised Mar Standard Practice Procedures For Security Services. George Mason University 4400 University Drive, MSN 6D4, Fairfax, Virginia 22030

GAO INDUSTRIAL SECURITY. DOD Cannot Provide Adequate Assurances That Its Oversight Ensures the Protection of Classified Information

MAY 2017 GUIDELINES FOR PREPARATION AND SUBMISSION OF SBIR PHASE II PROPOSALS

Director of Central Intelligence Directive 1/7 (1) Security Controls on the Dissemination of Intelligence Information

GLAST ITAR Briefing. Rachel Claus, University Counsel for SLAC 21 April 2003

PROPOSAL INSTRUCTIONS AND REQUIREMENTS

NATIONAL INDUSTRIAL SECURITY PROGRAM OPERATING MANUAL

Army Regulation Security. Department of the Army. Information Security Program. Headquarters. Washington, DC 29 September 2000 UNCLASSIFIED

Department of Defense INSTRUCTION

DODEA ADMINISTRATIVE INSTRUCTION , VOLUME 1 DODEA PERSONNEL SECURITY AND SUITABILITY PROGRAM

August Initial Security Briefing Job Aid

MASSACHUSETTS INSTITUTE OF TECHNOLOGY. Policy for Cost Sharing and Matching Funds on Sponsored Projects Effective July 1, 1998

Subj: RELEASE OF COMMUNICATIONS SECURITY MATERIAL TO U.S. INDUSTRIAL FIRMS UNDER CONTRACT TO THE DEPARTMENT OF THE NAVY

PRIVACY IMPACT ASSESSMENT (PIA) For the

DoD H, November 1999

Transcription:

AA-1 APPENDIX AA INTERNATIONAL INDUSTRIAL SECURITY REQUIREMENTS GUIDANCE ANNEX MULTINATIONAL INDUSTRIAL SECURITY WORKING GROUP MISWG Document Number 18 1 November 2007 INTERNATIONAL INDUSTRIAL SECURITY REQUIREMENTS GUIDANCE ANNEX INTRODUCTION 1. The International Industrial Security Requirements Guidance Annex, hereinafter referred to as the Annex, is designed to provide a contractor with the security requirements and classification guidance required for the performance of a classified contract with respect to international pre-contractual negotiations, tenders and contracts, including subcontracts. RESPONSIBILITY 1. The originating contracting authority is responsible for ensuring a completed Annex becomes part of the prime contract document. Procedures will be established by the NSA/DSAs to ensure that a copy of the completed Annex and relevant security clauses will be provided to the NSA/DSA of the prospective foreign contractor. The contracting authority is also responsible for issuing a revised Annex to the prime contractor any time the security requirements change. The contracting authority is also responsible for issuing a Final Annex upon completion of the contract. 2. Based on the security requirements and classification guidance specified in the Annex of the prime contract, the contractor is responsible for developing and incorporating an Annex for each classified subcontract awarded under the prime contract. The contractor is also responsible for issuing a revised Annex to all subcontractors when the security requirements change. Every effort will be made to ensure the completed Annex remains unclassified. GUIDELINES FOR THE COMPLETION OF THE INTERNATIONAL INDUSTRIAL SECURITY REQUIREMENTS GUIDANCE ANNEX 1. The Annex is an important document to be used whenever international pro-contractual negotiations, tenders and contracts, including subcontracts, will result in the release or disclosure of classified information material to a contractor. 2. Completion of the Annex will be coordinated and approved in accordance with the laws and regulations of the government contracting authority. It is a means of providing security requirements and classification guidance. It should be written as specifically as possible and should include only that information that pertains to the contract for which it is issued. It should

AA-2 not contain references to internal directives and instructions. If such documents provide guidance applicable to the contract, the pertinent portions should be extracted and provided as attachments. 3. The following information corresponds to the items on the International Industrial Security Requirements Guidance Annex. The item numbers refer to information requested for the completion of the Annex. Item 1. This International Industrial Security Requirements Guidance Annex is: An Original Annex will be included with each Request for tender, proposal or quotation or other solicitation to ensure the prospective contractor is aware of the security requirements and can plan accordingly. A Revised Annex will be issued as necessary during the lifetime of the contract when the security requirements change. A Revised Annex takes precedence over the Original. A Final Annex will be issued upon completion of the contract. Item 2. This Contract Security Requirements Annex is for: Enter an X in the appropriate box. title. Item 3. Program, Project or Contract Title: Enter the Program Project or Contract Item 4. Prime Contract Number or other Identification Number: Enter the Prime Contract number or other identification number if the Annex relates to pre-contractual negotiations, requests for tender, proposal or quotation. Ensure the Prime Contract number is also indicated for all subcontracts. Item 5. Is this a follow-on Contract?: This Item pertains to follow-on contracts. The contract must be awarded to the contractor for the same item or service as the preceding contract. If this is true, enter an X in the Yes box, and enter the preceding contract number. This item authorizes the contractor to transfer classified material received or generated under the preceding contract to the current contract. It is assumed the contractor will require access to the same information or material for the performance of the follow-on contract as was required for the previous contract. If this is not a follow-on contract, enter an X in the No box. Item 6. Level of Security Clearance required: In Item 6a, insert the highest level of Facility Clearance required for the performance of the contract. Use only the words SECRET or CONFIDENTIAL. Special caveats are not appropriate in this item. In Item 6b, insert the highest level of safeguarding capability required for the performance of the contract. The classification level shown in 6b may not be higher than that shown in 6a. If the contractor will not be required to possess classified information at the cleared facility enter Not Applicable (N/A). Item 7. Participating countries: Identify all countries to which this International Industrial Security Requirements Guidance Annex pertains. NOTE: A separate Annex is required for each contract or subcontract in each participating country.

AA-3 Item 8. Facility associated with pre-contractual negotiations, etc.: Item 8 is to be used by the contracting authority in considering possible contractors. In Item 8a insert the Facility Clearance level of potential contractor. Item 9 & 10. Name and address of Prime or Subcontractor: In Item 9 indicate the name and address of the prime contractor and the Facility Clearance level in 9a. In Item 10 indicate the name and address of the subcontractor and the Facility Clearance level in 10a. Item 11. Public release: To complete this item, direct the contractor(s) to the participating National/Designated Security Authority(ies) for approval of public release. Item 12. Access and contractor requirements: (attach additional pages as necessary) 12a. Access to classified information ONLY at another contractor s facility or a government activity. This means there will be no access to classified information at the contractor s facility. The contractor will not be required to have safeguarding capability at its facility. 12b. Receive classified documents ONLY. This means the contractor will receive classified documents only and is not expected to generate classified information that will require detailed guidance. The classification markings on the documents received will provide the classification guidance necessary for safeguarding. 12c. Receive and generate classified material. This means the contractor is expected to receive and generate classified material (documents and/or hardware) and will require detailed security classification guidance. If YES is marked for this item, detailed security classification guidance must be provided. 12d. Fabricate, modify, or store classified hardware. If YES, include as much information as possible to indicate if secure areas will be required. How much hardware is involved? How large? 12e. Access to Communications Security (COMSEC) information. If the contractor will require access to any communication security (COMSEC) information, enter an X in the YES box. Access to COMSEC information requires a government Facility Clearance and a COMSEC account at the appropriate level. 12f. Access to NATO classified information. This means material belonging to, and circulated by, the North Atlantic Treaty Organization (NATO). Access to NATO classified information requires a government Facility Clearance at the appropriate level. 12g. Electronically process classified information. This means the contractor will be required to process classified information using Automated Data Processing (ADP) or Electronic Data Processing (EDP) Systems and/or networks. (refer to MISWG Document No. 13 Automated Data Processing (ADP) Security Plan for additional guidance.)

AA-4 12h. Access to Controlled Unclassified Information. This item includes unclassified information that requires access controls as a result of national laws or regulations. Such information may be provided or generated under a cooperative program and must be protected form unauthorized disclosure. (refer to MISWG Document No. 8. Controlled Unclassified Information Clauses for additional guidance.) 12i. Access to non-participating country(ies ) information. This item includes any non-participating country s information, except NATO. If YES, release authority is required from the owner of the information. 12j. On-site access required by foreign nationals in excess of 30 consecutive working days? This item includes visits over a specified period of time, normally for up to one year or for the duration of a government approved program, project or contract. (refer to MISWG Document No. 7 International Visit Procedures for additional guidance.) 12k. Hand carriage of classified material. This item involves the transfer of classified material between participants by hand carriage. (Refer to MISWG Document No. 1 Arrangements for the International Hand Carriage of Classified Documents, Equipment and/or Components for additional guidance.) 12l. Transportation of classified material by commercial carrier. This item includes the transfer of classified documents and equipment of components as freight. (refer to MISWG Document No. 15 International Transportation by Commercial Carriers of Classified Documents and Equipment or Components as Freight for additional guidance.) 12m. Use of Cryptographic systems. This item includes the electronic and electromagnetic transmission of classified information. (refer to MISWG document No. 3 Use of Cryptographic Systems for additional guidance.) Item 13. Security Classification Guidance: Use this item to identify applicable guides, to provide narrative guidance which identifies the specific types of information to be classified, to provide any special instructions, explanations, comments or statements required for information or to clarify any other items identified in the Annex. Each contract is unique in its performance requirements. Use additional pages as necessary to expand or explain the guidance. Security classification guidance provides detailed information that relates what information requires classification and what level of classification to assign. In completing this item ask the following questions: What classified (Secret, Confidential, Restricted) and/or Controlled Unclassified Information will the contractor require in the performance of this contract?

AA-5 What guidance will the contractor need to protect the information? Will classified hardware be furnished to or generated by the contractor? What information makes the hardware classified? Will the hardware being generated require classification? What technical information requires protection? Item 14. Instructions on declassification and downgrading: Use this item to provide appropriate declassification or downgrading instructions. Item 15. Instructions on the destruction or return of furnished or generated documents: Use this item to specify the methods and procedures for the destruction or return of any and all material either furnished or generated pursuant to this contract. Item 16. Frequency of review: The International Industrial Security Requirements Guidance Annex will be reviewed as necessary during the lifetime of the contract, when the security requirements change. Item 17. Additional security requirements: This item applies any time security requirements are imposed on a contractor that are in addition to the requirements specified under normal circumstances. Prior approval of the contracting authority is required prior to imposing additional security requirements on a contractor. Item 18. Certification and Signature of Contracting Authority or Facility Security Officer (if applicable): Item 18 will contain the name, title, address, telephone and facsimile number, signature, and date of the Contracting Authority or Facility Security Officer, as and if applicable, certifying that the security requirements are complete and adequate for the performance of the classified contract. Item 19. National/Designated Security Authority (if applicable): Item 19 will contain the name, title, physical address, email address, telephone and facsimile number, signature and date, if applicable, of the National/Designated Security Authority of the participating contractor. Item 20. Table of Equivalency: Complete the table by indicating the level of classification that equates to the level of classification in the participating countries.

AA-6 CLASSIFICATION PROTOTYPE 1. Original Date: Revised Date: Final Date: 2. THE INTERNATIONAL INDUSTRIAL SECURITY REQUIREMENTS GUIDANCE ANNEX IS FOR: Precontractual Negotiations Request for : Tender (RFT), Proposal (RFP), or Quote (RFQ) Prime contract Subcontract Request for Information 3. PROGRAM, PROJECT OR CONTRACT TITLE: 4. PRIME CONTRACT NUMBER OR OTHER IDENTIFICATION NUMBER: (The Prime contract number must be shown for all subcontracts): Prime Contact Number: Subcontract or other Identification Number: 5. IS THIS A FOLOW-ON CONTRACT? CONTRACT SECURITY CLAUSES ATTACHED? YES Provide preceding contract number: Date completed: NO 6. LEVEL OF SECURITY CLEARANCE REQUIRED: 6a. Facility clearance 6b. Safeguarding 7. PARTICIPATING COUNTRIES: 8. NAME AND ADDRESS OF FACILITY ASSOCIATED WITH PRECONTRACTUAL NEGOTIATIONS, RFT,RFP, OR RFQ: (Attach a list if applicable) 8a. FACILITY CLEARANCE SECRET LEVEL 9. NAME AND ADDRESS OF PRIME CONTRACTOR: CONFIDENTIAL 9a.. FACILITY CLEARANCE SECRET LEVEL: 10. NAME AND ADDRESS OF SUBCONTRACTOR: CONFIDENTIAL 10a. FACILITY CLEARANCE LEVEL: SECRET CONFIDENTIAL 11. PUBLIC RELEASE: Information pertaining to classified programs, projects or contracts, including unclassified controlled information will not be released for public dissemination except as authorized by the cognizant NSA/DSA 12. ACCESS and CONTRACTOR REQUIREMENTS: a. Access to Classified Information ONLY at another contractor s or Government facility YES NO b. Receive classified documents ONLY. YES NO c. Receive and Generate classified material YES NO d. Fabricate, modify, or store classified hardware. YES NO e. Access to Communications Security (COMSEC) information YES NO f. Access to NATO information. YES NO g. Electronically process classified information. YES NO h. Access to Controlled Unclassified Information involved. (If YES, an export license may be required) YES NO

AA-7 CLASSIFICATION PROTOTYPE i. Access to non-participating country(ies ) information. If YES, release authority is required) YES NO j. On site access required by foreign nationals in excess of 30 consecutive working days. YES NO k. Hand carriage of classified material. YES NO l. Transportation of classified material by commercial carrier. YES NO m. Use of Cryptographic systems. YES NO 13. SECURITY CLASSIFICATION GUIDANCE: 13a. SECRET (NOTE: THIS BLOCK WILL IDENTIFY CONTRACT RELATED INFORMATION AND MATERIAL CLASSIFIED SECRET) 13b. CONFIDENTIAL (NOTE: THIS BLOCK WILL IDENTIFY CONTRACT RELATED INFORMATION AND MATERIAL CLASSIFIED CONFIDENTIAL) 13c. RESTRICTED (NOTE: THIS BLOCK WILL CONTAIN CONTRACT RELATED INFORMATION AND MATERIAL CLASSIFIED RESTRICTED) 13d. CONTROLLED UNCLASSIFIED INFORMATION (NOTE: THIS BLOCK WILL CONTAIN CONTRACT RELATED INFORMATION AND MATERIAL DESIGNATED AS CONTROLLED UNCLASSIFIED INFORMATION) 14. INSTRUCTIONS ON DECLASSIFICATION AND DOWNGRADING: 15. INSTRUCTIONS ON THE DESTRUCTION OR RETURN OF FURNISHED OR GENERATED DOCUMENTS:

AA-8 CLASSIFICATION PROTOTYPE 16. FREQUENCY OF REVIEW (of this annex) 17. ADDITIONAL SECURITY REQUIREMENTS: 18. CERTIFICATION AND SIGNATURE: OF CONTRACTING AUTHORITY OR FACILITY SECURITY OFFICER (as and if applicable) NAME TITLE TELEPHONE NUMBER FAX NUMBER PHYSICAL AND EMAIL ADDRESS SIGNATURE: DATE: 19.NATIONAL/DESIGNATED SECURITY AUTHORITY (if applicable) NAME TITLE TELEPHONE NUMBER FACSIMILE NUMBER PHYSICAL AND EMAIL ADDRESS SIGNATURE: DATE: 20. TABLE OF EQUIVALENCY CLASSIFICATION COUNTRY CLASSIFICATION COUNTRY