Classified Matter Channel (CMC)

Slides:



Advertisements
Similar presentations
Annual Security Refresher Briefing Note: All classified markings contained within this presentation are for training purposes.
Advertisements

Section Six: Foreign Ownership, Control, or Influence (FOCI)
Defense Security Service Facility Clearance Branch (FCB)
Protected Critical Infrastructure Information (PCII) Program
Section Four: Employee and Visitor Access Controls Note: All classified markings contained within this presentation are for training purposes only.
Joint Personnel Adjudication System (JPAS) Overview
Supportive Services for Veteran Families (SSVF) Data
SAND Number: P Sandia is a multi-program laboratory operated by Sandia Corporation, a Lockheed Martin Company, for the United States Department.
NOVATION AND CHANGE OF NAME AGREEMENTS “WHAT THEY MEAN IN REALITY AND IN SAP” LEVEL 1 PIP KIMBER RUSSELL JUNE 1, 2006.
FAR Part 4 Overview Administrative Matters. FAR 4.1 Contract Execution Only contracting officers (CO) shall sign contracts on behalf of the United.
CHANGES TO OTPS OBJECT CODES FY12 UPDATED 2/22/13 DCP 2/22/2013.
CUI Statistical: Collaborative Efforts of Federal Statistical Agencies Eve Powell-Griner National Center for Health Statistics.
SWIS Digital Inspections Project (SWIS DIP) Chris Allen, Information Management Branch California Integrated Waste Management Board November 5, 2008 The.
By: Carol Martineau, Acting Assistant Manager, Aircraft Maintenance Division, AFS-301 Date: June 7, 2015 Federal Aviation Administration ASA Conference.
OFFICE OF THE UNDER SECRETARY OF DEFENSE FOR INTELLIGENCE CI & SECURITY DIRECTORATE, DDI(I&S) Valerie Heil March 20, 2015 UNCLASSIFIED Industrial Security.
DoD Acquisition Domain (Sourcing) (DADS) Analysis of Alternatives (AoA) E-Business/SPS Joint Users’ Conference November 15-19, 2004 Houston, TX.
Section Five: Security Inspections and Reviews Note: All classified markings contained within this presentation are for training purposes only.
1 Defense Health Agency Privacy and Civil Liberties Office Data Sharing Program Overview Ms. Rita DeShields DHA Data Sharing Compliance Manager August.
Information Sharing Challenges, Trends and Opportunities
Office of Research & Sponsored Programs (ORSP) Darren McCants, Director David Azbill, Assistant Director Cindy Brown, Program Mgr, Corporate Research Robbie.
Phoenix Convention Center Phoenix, Arizona ANDREA L. KINCAID DLA Energy Track 5 Project FinanceSession 6 Renewables Through Private Financing.
DEFENSE SECURITY SERVICE DSS Role in International Security.
Improving Team Collaboration Across Multidisciplinary Teams Through Web-based Knowledge Portals 1 National Laboratories Information Technology Conference.
SWIS Digital Inspections Project Chris Allen, Information Management Branch California Integrated Waste Management Board August 22, 2008.
SECURITY BRIEFING A threat awareness briefing A defensive security briefing An overview of the security classification system Employee reporting obligations.
Managing a “Data Spill”
April 23, 2008 Electronic Certified Payroll Sandia National Laboratories.
Small Business Programs Tatia Evelyn-Bellamy Director Small Business Division Small Business Center February 2016.
You are accessing a U.S. Government (USG) Information System (IS) that is provided for USG-authorized use only. By using this IS (which includes any device.
SF-182 Survey Results (March 2016). Q1: Which of the following data elements on the SF-182 help you prioritize future training investments?
Community of Practice K Lead Project Team: الالتزامالتحفيز التفكير المؤسسي المرونةالتميزالشراكةالاستقامة.
Joint Statistical Research Program Update. Joint Statistical Research Program Seeks to increase partnerships between IRS and external researchers Goals:
1 WARFIGHTER SUPPORT STEWARDSHIP EXCELLENCE WORKFORCE DEVELOPMENT WARFIGHTER-FOCUSED, GLOBALLY RESPONSIVE, FISCALLY RESPONSIBLE SUPPLY CHAIN LEADERSHIP.
Safeguarding CDI - compliance with DFARS
LCLS-II ES&H Requirements: Subcontractors
DSQR Training Reliance System
Finance Committee Update
Texas Process: UI Claimant Work Search
State Coordinator Intervention
2017 International Logistics Meeting (ILM)
Streamline your HR document management processes
Data Security Policies
Microsoft 365 Get help with regulatory compliance
Improving Mission Effectiveness By Exploiting the Command’s Implementation Of the DoD Enterprise Services Management Framework - DESMF in the [name the.
Introduction to the Federal Defense Acquisition Regulation
Partnering Opportunities ERDC actively engages in research and development with government, academic, and industrial entities:   Potential Partners Agreement.
DOE Nuclear Safety Research and Development Program
HPCMP New Users’ Guide “How Do I Obtain a User Account?”
Derivative Classification Overview
U.S. Small Business Administration South Florida District Office
Electronic Fingerprints
Red Flags Rule An Introduction County College of Morris
DFARS Cybersecurity Requirements
The University of Texas at Arlington
Cybersecurity Special Public Meeting/Commission Workshop for Natural Gas Utilities September 27, 2018.
What is the UL QFCP? FCIA Webinar Presenters:
Welcome to the FERPA training for Faculty and Staff.
AN OVERVIEW OF THE INDUSTRIAL SECURITY PROGRAM
U.S. Department of Defense U.S. – Finnish Industry Day
EDUCAUSE Security Professionals Conference 2018 Jason Pufahl, CISO
Centralization of Texas State Contract Compliance Functions
BCS Template Presentation February 22, 2018
Creating a University IT Service Portfolio
Product Service Code Selection Tool User Training
DOTD Form September 4, 2014.
HQ Expectations of DOE Site IRBs
Understanding: Wide Area Workflow Payment
Project Management Method and PMI ® PMBOK ® Roles
Innovative Readiness Training
STEPS FOR HIRING A STUDENT
Presentation transcript:

Classified Matter Channel (CMC) Presented by CMPC - Maretta King SAND2019-4056 PE

Objectives Review federal policies for classified mail channels Discuss classified mail channel challenges Discuss how your sites manage these challenges

Federal Requirements DOE O 471.6, Chg. 2, Information Security

Federal Requirements DOE O 470.4B, Chg. 2, Safeguards and Security Appendix B

Facility Clearances United States Department of Energy: Safeguards & Security Information Management System Facility Data and Approval Record (FDAR) Statement of Security Assurance (SSA) Defense Security Service (DSS) Portal: National Industrial Security Program (NISP) Central Access Information Security System (NCAISS) National Industrial Security System (NISS) United States Department of Energy, National Nuclear Security Administration, Office of Secure Transportation Certification Program Directory (CPD)

Safeguards & Security Information Management System (SSIMS) Statement of Security Assurance (SSA) Facility Data and Approval Record (FDAR)

National Industrial Security System (NISS) DSS/NISS Notification SSA When FedEx Address not on NISS Notification

Certification Program Directory (CPD) Email Notification Certificate

Classified Mail Channel Challenges: Lack of Training and Policy Guidance: Who is our federal SME? Training: other than SSIMS training, no other training offered on how to process requests. When new staff at contractors sites are assigned, acquiring the knowledge, skills and abilities is significantly challenging due to lack of training. Required form management (e.g., Statement of Security Assurance [SSA], Facility Data Approval Record [FDAR]): Example #1- An SSA submittal by SNL was rejected by NA-10 because it was not on the new version of the form. Nobody communicated the update to the contractors. Example #2- Who do contractors contact if they need assistance with interpreting fields on the FDAR (e.g., Storage vs. Processing in SSIMS; CNWDI vs. WD field)

Classified Mail Channel Challenges (cont’d): SSIMS Database Challenges: The FDAR and CSCS sections of SSIMS being hosted on an SRD classified network creates access challenges (e.g., data retrieved must always be reviewed by a DC). DSS/NISS (DoD facility clearance database) is unclassified and more user friendly. Process to verify data is manual in SSIMS (run reports to identify discrepancies). DSS/NISS provides email notifications (more time efficient).

Classified Mail Channel Challenges (cont’d): Processing Challenges: Many facility security officers (FSOs) are untrained and have no knowledge of the process and/or required forms. In most federal audits of CMPC (EA-22), the assessment process is minimal. Auditors recognize the process and forms are complicated. Approval times (may impact mission) NA-10 requires 30 days notice for CNWDI and Sigmas NA-70 requires 10 working days for FDAR entry into SSIMS

Classified Mail Channel Challenges (cont’d): Logistics Challenges: External entities not following information provided in SSIMS (e.g.., using incorrect addresses, not following approved special instructions). Handling the above problems when the external entity is an OGA or OGAC. External entities providing shipping information that is not captured in the federal approved system (e.g., SSIMS, DSS/NISS). DoD and their contractors do not have access to SSIMS. Call NNSA/DOE contractors saying they can’t find us in their DSS/NISS (e.g., cage code).

Discussion Questions for the group: What are the biggest challenges at your site related to classified mail channels? Does your site integrate procurement (e.g., work agreements/contracts) into your classified mail channel process? How do you handle logistic issues from external entities (OGAs and OGACs)?

Questions & Answers

Work Agreements/Contracts Not a Federal requirement, but a local requirement. Helps manage the movement of classified matter. Manager certifies/approves via CMCD that the transmission of classified matter is required by the specific terms of the Work Agreement/Contract for the performance of official or contractual duties. Types of Work Agreements/Contracts utilized at Sandia National Laboratories NTESS Prime Contract No. DE-NA0003525 SNL’s subcontractors (suppliers)/Oracle CRADA Strategic Partnership Projects Strategic Intelligence Partnership Program

Work Agreements in Detail NTESS Prime Contract When work does not fall under any of the other contracts, such as quarterly classified meetings to share information with contractors as directed by DOE or classified conferences. SNL’s Subcontractors/Oracle Financial Contract Oracle PO Contract any purchase order that is issued in the Oracle database and contracts that Sandia issues to its sub-contractors. If being used in conjunction with CMC, the facility must be a possessing site. CRADA Agreement between one or more laboratories and one or more non-federal entities (CRADA Participants), including industry, that facilities private-sector collaboration utilizing laboratories’ technologies, processes, R&D capabilities, or technical know-how. Strategic Partnership Projects SPP is designed to provide research, development, and technical assistance for non-DOE/NNSA sponsors that are not directly funded by DOE/NNSA. If a SPP project is classified, a Contract Security Classification Specification (CSCS) form  (SF 7643-WFO) is required to document the exchange of classification and protection of information and record applicable classification guidance provided by the sponsor. Strategic Intelligence Partnership Program When the SPP involves Intelligence work

Approvals SNL Management DOE NNSA, Weapon Security and Control Division, NA-10 SRD/CNWDI/Sigma’s FCL/FOCI, DOE NNSA, Facility and Personnel Clearance Processing Division, NA-70 SRD/CNWDI/Sigma’s, after NA-10 approval SFRD and below w/SSA and not in DSS/NISS Data Entry for SNL CMC Coordinator SFRD and below and in DSS/NISS

Time Frame Expedited Standard Factors ~ 1 day to 3 days ~1 day to many months Factors Category, Level, and/or caveats Contracts Personnel Approvals Designated Responsible Office (DRO’s)

How are SNL Channels created? Facility Clearance Facility Information Facility Name Facility Security Officer Name Contact Information (Phone Number and Email) Channel Information Delivery Types Clearance Information (Category/Level/Caveats) Work Agreements/Contracts Contract Type Approving Manager Requester Classification Authorized Users/Orgs Delivery Type Approvals

CMCD and other Applications Sandia Directory Strategic Partnership Projects Application Contract Security Management Personnel Clearance Office Company Data Web Shipper (SNL’s Shipping & Receiving)

2010 Flowchart – New CMC

2010 Flowchart - Renew

Classified Matter Channel Directory (CMCD) FCL + Work Agreement/Contract = CMC

What is the CMC Directory (CMCD)? Provides a directory of available facilities that are authorized to receive & store classified matter. Used when sending classified matter externally (different facility code from SNL). Provides mailing information: inner and outer addresses, special instructions, and including SNL’s return address utilizing the FDAR, ISFD, or CPD Facility Clearances (FCL). Lists contracts authorized to use channel (including Level/Category/Caveat and authorized Orgs).