FAS | Gov't Secrecy | SPB Docs ||| Index | Search |


GUIDELINES FOR
THE IMPLEMENTATION AND OVERSIGHT
OF THE POLICY ON RECIPROCITY OF USE
AND INSPECTIONS OF FACILITIES

Section I - General

1. Redundant, overlapping, and duplicative policies and practices that govern the co-use of facilities for classified purposes have resulted in excessive protection and unnecessary expenditure of funds. Lack of reciprocity has also impeded achievement of national security objectives and adversely affected economic and technological interests.

2. Interagency reciprocal acceptance of security policies and procedures for approving, accrediting, and maintaining the secure posture of shared facilities will reduce the aggregate costs, promote interoperability of agency security systems, preserve the vitality of the US industrial base, and advance national security objectives.

3. Agency heads, or their designee, are encouraged to periodically issue written affirmations in support of the policies and procedures prescribed herein and in the Security Policy Board (SPB) policy, entitled "Reciprocity of Use and Inspections of Facilities."

4. The policies and procedures prescribed herein shall be applicable to all agencies. This document does not supersede the authority of the Secretary of Defense under Executive Order 12829; the Secretary of Energy or the Chairman of the Nuclear Regulatory Commission under the Atomic Energy Act of 1954, as amended; the Secretary of State under the Omnibus Diplomatic Security and Anti-Terrorism Act of 1986; the Secretaries of the military departments and military department installation Commanders under the Internal Security Act of 1950; the Director of Central Intelligence under the National Security Act of 1947, as amended, or Executive Order 12333; the Director of the Information Security Oversight Office under Executive Order 12829 or Executive Order 12958; or substantially similar authority instruments assigned to any other agency head.

Section II - Policy

1. Agency heads, or their designee, shall ensure that security policies and procedures for which they are responsible are reasonable, effective, and efficient, and that those policies and procedures enable and promote interagency reciprocity.

2. To the extent reasonable and practical, and consistent with US law, Presidential decree, and bilateral and international obligations of the United States, the security requirements, restrictions, and safeguards applicable to industry shall be equivalent to those applicable within the Executive Branch of government.

3. Once a facility is authorized, approved, certified, or accredited, all government organizations desiring to conduct classified programs at the facility at the same security level shall accept the authorization, approval, certification, or accreditation without change, enhancements, or upgrades.

Section III - Definitions

1. Agency - Means any "executive agency," as defined in 5 U.S.C. 105; any "Military department" as defined in 5 U.S.C. 102; and any other entity within the Executive Branch that comes into possession of classified information.

2. Classified Information - Means all information that requires protection under Executive Order 12958, or any of its antecedent orders, and the Atomic Energy Act of 1954, as amended.

3. Cognizant Security Agency (CSA) - Means those agencies that have been authorized by Executive Order 12829 to establish an industrial security program for the purpose of safeguarding classified information disclosed or released to industry.

4. Cognizant Security Office (CSO) - Means the office or offices delegated by the head of a CSA to administer industrial security in a contractor’s facility on behalf of the CSA.

5. Facility - An activity of a government agency or cleared contractor authorized by appropriate authority to conduct classified operations or to perform classified work.

6. Industry - Means contractors, licensees, grantees, and certificate holders obligated by contract or other written agreement to protect classified information under the National Industrial Security Program.

7. National Security - Means the national defense and foreign relations of the United States.

8. Senior Agency Official - Means those officials, pursuant to Executive Order 12958, designated by the agency head who are assigned the responsibility to direct and administer the agency’s information security program.

Section IV - Responsibilities

1. Each Senior Agency Official shall ensure that adequate reciprocity provisions are incorporated within his or her regulatory issuances that prescribe agency safeguards for protecting classified information.

2. Each Senior Agency Official shall develop, implement, and oversee a program that ensures agency personnel adhere to the policies and procedures prescribed herein and the reciprocity provisions of the National Industrial Security Program Operating Manual (NISPOM).

3. Each Senior Agency Official must ensure that implementation encourages reporting of instances of non-compliance, without fear of reprisal, and each reported instance is aggressively acted upon.

4. The Director, Information Security Oversight Office (ISOO), consistent with his assigned responsibilities under Executive Order 12829, serves as the central point of contact within Government to consider and take action on complaints and suggestions from industry concerning alleged violations of the reciprocity provisions of the NISPOM.

5. The Director, Security Policy Board Staff (D/SPBS) or his/her designee, shall serve as the central point of contact within Government to receive from Federal Government employees alleged violations of the reciprocity provisions prescribed herein and the policy "Reciprocity of Use and Inspections of Facilities" of the SPB.

Section V - Procedures

1. Agencies that authorize, approve, certify, or accredit facilities shall provide to the SPB Staff a points of contact list to include names and telephone numbers of personnel to be contacted for verification of the status of facilities. The SPB Staff will publish a comprehensive directory of agency points of contact.

2. After initial security authorization, approval, certification, or accreditation, subsequent reviews shall normally be conducted no more frequently than annually. Additionally, such reviews shall be aperiodic or random, and be based upon risk-management principles. Security Reviews may be conducted "for cause", to follow up on previous findings, or to accomplish close-out actions.

3. The procedures employed to maximize interagency reciprocity shall be based primarily upon existing organizational reporting channels. These channels should be used to address alleged departures from established reciprocity requirements and should resolve all, including the most egregious instances of non-compliance.

4. Two complementary mechanisms are hereby established to augment existing organizational channels.

A. An accessible and responsive venue for reporting and resolving complaints/reported instances of non-compliance. Government and industry reporting channels shall be as follows:

B. An annual survey administered to a representative sampling of agency and private sector facilities to assess overall effectiveness of agency adherence to applicable reciprocity requirements.

5. Agencies will continue to review and assess the potential value added to the process of co-use of facilities by development of electronic data retrieval across government.




FAS | Gov't Secrecy | SPB Docs ||| Index | Search |