Current

DOE-STD-1217-2020, Safeguards and Security Survey and Self-Assessment Planning, Conduct, and Reporting

This document provides the Department of Energy (DOE) with a standard methodology for adapting the Department’s requirements to conduct and report Safeguards and Security (S&S) surveys and self-assessments to organization-specific needs in a coherent, consistent, and repeatable fashion. It describes a consistent and acceptable approach to planning, conducting, and reporting the results for S&S surveys and self-assessments. Appendix A, Safeguards and Security (S&S) Survey and Self-Assessment Toolkit, provides guidance and useful templates for planning, conducting, and reporting surveys and self-assessments.
DOE-STD-1217-2020.pdf4.01MB
Version history and related documents
Document text

Text extracted from the attached file. Refer to the original document for the authoritative version.

Section 1

DOE-STD-1217-2020 FEBRUARY 2020 DOE STANDARD SAFEGUARDS AND SECURITY SURVEY AND SELF-ASSESSMENT PLANNING, CONDUCT, AND REPORTING U.S. Department of Energy Washington, D.C. 20585 DISTRIBUTION STATEMENT A. Approved for public release; distribution is unlimited. NOT MEASUREMENT SENSITIVE DOE-STD-1217-2020/Rev FEBRUARY 2020 ii THIS PAGE INTENTIONALLY LEFT BLANK DOE-STD-1217-2020/Rev FEBRUARY 2020 iii FOREWORD This Department of Energy Technical Standard is for use by all Departmental elements. Email any beneficial comments (recommendations, additions, and deletions) and pertinent data that may improve this document to natasha.sumter@hq.doe.gov or mail to: U.S. Department of Energy Office of Environment, Health, Safety, and Security Office of Security Policy, GTN/AU-51 1000 Independence Ave., SW Washington, D.C. 20585-1290 Department of Energy Technical Standards do not establish requirements. However, all or part of the provisions in this Technical Standard can become requirements under the following circumstances:  They are explicitly stated to be requirements in a Department of Energy requirements document (e.g., a purchase requisition).  The organization makes a commitment to meet a standard in a contract, implementation plan, or program plan.  This Technical Standard is incorporated into a contract. Throughout this standard, the word “must” or “shall” are used to denote actions that must be performed if the objectives of this standard are to be met. If the provisions in this Standard are made requirements through one of the three ways discussed above, then the “shall” statements would become requirements. Goals or intended functionality are indicated by “will,” “may,” or “should.” It is not appropriate to consider that “should” statements would automatically be converted to “shall” statements as this action would violate the consensus process used to approve this standard. This Technical Standard was prepared following requirements for due process, consensus, and approval as required by the U.S. Department of Energy Standards Program. Consensus is established when substantial agreement has been reached by all members of the writing team and the Technical Standard has been approved through the Department of Energy directives approval process (REVCOM). Substantial agreement means much more than a simple majority, but not necessarily unanimity. Consensus requires that all views and objections be considered, and that a concerted effort be made toward their resolution. mailto:natasha.sumter@hq.doe.gov DOE-STD-1217-2020/Rev FEBRUARY 2020 iv THIS PAGE INTENTIONALLY LEFT BLANK DOE-STD-1217-2020/Rev FEBRUARY 2020 v CONTENTS DOE Survey Form ............................................................................................................................ 6 EFCOG Self-assessment Tool Kit .................................................................................................... 6 Survey Team Leader ........................................................................................................................ 7 Survey Topical Lead ........................................................................................................................ 9 Survey Team Members ................................................................................................................... 10 Self-assessment Team Leads and Members ................................................................................... 11

Section 2

Cyclic Planning for Surveys and Self-Assessments ....................................................................... 14 Planning a Facility Survey or Self-Assessment. ............................................................................. 15 Pre-Planning ........................................................................................................................... 15 Preliminary Coordination ....................................................................................................... 15 Planning Survey and Self-Assessment Activities .................................................................. 17 In-Briefing ...................................................................................................................................... 17 Maintaining Communication .......................................................................................................... 18 Data Collection ............................................................................................................................... 18 Performance Tests .................................................................................................................. 20 Data Validation ...................................................................................................................... 21 Data Analysis ......................................................................................................................... 21 Ratings .................................................................................................................................... 23 Exit Briefing ................................................................................................................................... 25 DOE-STD-1217-2020/Rev FEBRUARY 2020 vi Corrective Action Program............................................................................................................. 28 Process Improvement ..................................................................................................................... 29 Step 1: Understand and Map the Current Process .................................................................. 29 Step 2: Complete a Value Added Analysis ............................................................................ 31 Step 3: Develop an Improved Process .................................................................................... 33 Step 4: Update Documentation and Develop Metrics ............................................................ 34 Step 5: Measure for Success and Return to Step 1. ................................................................ 34 (1) TEST OBJECTIVE ................................................................................................................ 56 (2) SCENARIO DESCRIPTION ................................................................................................. 56 (3) TEST METHODOLOGY AND EVALUATION CRITERIA .............................................. 56 (4) PASS/FAIL CRITERIA ......................................................................................................... 56 (5) TEST CONTROLS ................................................................................................................ 57 (6) RESOURCE REQUIREMENTS ........................................................................................... 57

Section 3

(7) TEST COORDINATION REQUIREMENTS ....................................................................... 57 (8) OPERATIONAL IMPACT(S) OF TESTING PROGRAM .................................................. 57 (9) COMPENSATORY MEASURES ......................................................................................... 58 (10) COORDINATION AND APPROVAL PROCESS ............................................................... 58 (11) REFERENCES ....................................................................................................................... 58 1.1 Overview of Site ........................................................................................................................... 237 1.1.1 Mission ................................................................................................................................. 237 1.1.2 Location/Address ................................................................................................................. 237 1.2 Scope ......................................................................................................................................... 237 1.3 Purpose ......................................................................................................................................... 237 2.1 Program Office ............................................................................................................................. 237 2.2 Field/Site Office ........................................................................................................................... 237 2.3 Contractors ................................................................................................................................... 237 2.4 ODFSA/ODSA Delegations ......................................................................................................... 237 3.1 Federal Approval of Security Plan ............................................................................................... 237 DOE-STD-1217-2020/Rev FEBRUARY 2020 vii 4.1 Identification of Residual Risk ..................................................................................................... 237 4.1.1 Basis for residual risk determination .................................................................................... 237 4.2 Federal Acceptance of Residual Risk ........................................................................................... 237 5.1 List of Assets ................................................................................................................................ 237 5.2 Prioritization of Assets ................................................................................................................. 237 6.1 Analytical Basis ............................................................................................................................ 237 6.1.1 Plan based on DOE O 470.3C .............................................................................................. 238 6.1.2 DOE Tactical Doctrine, as applicable .................................................................................. 238 6.1.3 Security Risk Assessment / Vulnerability Assessment Overview ....................................... 238 6.2 Review and Update ...................................................................................................................... 238

Section 4

6.2.1 Review – procedures regarding plan review ........................................................................ 238 6.2.2 Update – procedures to provide updates and revisions to the plan ...................................... 238 7.1 PPM Overview ............................................................................................................................. 238 7.1.1 Federal Oversight (Field and Program Office) ..................................................................... 238 7.1.2 Contractors ........................................................................................................................... 238 7.1.3 Work-for Others ................................................................................................................... 238 7.2 Facility Clearance Program .......................................................................................................... 238 7.2.1 Procedures applicable to the FCL program .......................................................................... 238 7.3 Foreign Ownership, Control, or Influence ................................................................................... 238 7.3.1 Procedures applicable to the FOCI program ........................................................................ 238 7.4 Classified Visits ............................................................................................................................ 238 7.4.1 Procedures applicable to classified visits and assignments .................................................. 238 7.5 Unclassified Foreign Visitors and Assignments ........................................................................... 238 7.5.1 Procedures applicable to unclassified foreign visits and assignments ................................. 238 7.6 Incident of Security Concern ........................................................................................................ 238 7.6.1 Overview of the Incident of Security Concern program ...................................................... 238 7.7 Equivalencies and Exemptions ..................................................................................................... 238 7.7.1 Overview of the process ....................................................................................................... 238 7.7.2 List of Approved Equivalencies and Exemptions incorporated in Security Plan ................. 238 7.8 Memorandums of Agreement/Understanding .............................................................................. 238 7.8.1 Approval process .................................................................................................................. 238 DOE-STD-1217-2020/Rev FEBRUARY 2020 viii 7.8.2 Review Process .................................................................................................................... 238 7.8.3 List of all MOAs/MOUs ...................................................................................................... 238 7.9 SECON ......................................................................................................................................... 238 7.9.1 Overview of the SECON plan and procedures ..................................................................... 238 7.10 Performance Assurance ................................................................................................................ 239

Section 5

7.10.1 Performance Assurance planning ......................................................................................... 239 7.10.2 Performance testing .............................................................................................................. 239 7.10.3 System degradation .............................................................................................................. 239 7.10.4 Reviews and updates ............................................................................................................ 239 7.11 Safeguards and Security Training ................................................................................................ 239 7.11.1 Overview of the Safeguards and Security Training program ............................................... 239 7.12 Security Awareness Program ....................................................................................................... 239 7.12.1 Overview of the Security Awareness program ..................................................................... 239 7.13 Security-Funded Technologies, if applicable ............................................................................... 239 7.13.1 Overview of the process to transfer security-funded technologies ...................................... 239 7.14 Demonstrator and Protestor Plan .................................................................................................. 239 7.14.1 Responsibilities .................................................................................................................... 239 7.14.2 Memoranda of Agreement or Understanding ....................................................................... 239 7.14.3 Event notification ................................................................................................................. 239 7.14.4 Minimum requirements ........................................................................................................ 239 7.15 Workplace Violence Plan ............................................................................................................. 239 7.15.1 Responsibilities .................................................................................................................... 239 7.15.2 Memoranda of Agreement or Understanding ....................................................................... 239 7.15.3 Event notification ................................................................................................................. 239 7.15.4 Minimum requirements ........................................................................................................ 239 8.1 General Site Access ...................................................................................................................... 239 8.1.1 Employees ............................................................................................................................ 239 8.1.2 Visitors ................................................................................................................................. 239 8.1.3 Other Federal Agency Badges .............................................................................................. 239 8.2 Prohibited and Controlled Articles ............................................................................................... 239

Section 6

8.2.1 Prohibited Articles................................................................................................................ 239 8.2.2 Controlled Articles ............................................................................................................... 239 8.3 Entry and Exit Inspections............................................................................................................ 240 DOE-STD-1217-2020/Rev FEBRUARY 2020 ix 8.3.1 Entry Inspections procedures ............................................................................................... 240 8.3.2 Exit inspection procedures ................................................................................................... 240 8.3.3 Property Removal ................................................................................................................. 240 8.4 Security Areas (as applicable) ...................................................................................................... 240 8.4.1 General Access Areas ........................................................................................................... 240 8.4.2 Property Protection Areas .................................................................................................... 240 8.4.3 Limited Areas ....................................................................................................................... 240 8.4.4 Vaults/Vault-Type Rooms .................................................................................................... 241 8.4.5 Sensitive Compartmented Information Facilities ................................................................. 242 8.4.6 Special Access Program Facilities ....................................................................................... 242 8.4.7 Protected Areas .................................................................................................................... 242 8.4.8 Material Access Areas .......................................................................................................... 243 8.5 Lock and Key Program ................................................................................................................. 244 8.5.1 Overview of lock and key program ...................................................................................... 244 8.5.2 Inventory system .................................................................................................................. 245 9.1 Management ................................................................................................................................. 245 9.1.1 Overview of Pro Force management .................................................................................... 245 9.1.2 Non-uniformed staffing ........................................................................................................ 245 9.2 Training ........................................................................................................................................ 245 9.2.1 Initial .................................................................................................................................... 245 9.2.2 Annual .................................................................................................................................. 245 9.2.3 Firearms ................................................................................................................................ 245

Section 7

9.3 Certification .................................................................................................................................. 245 9.3.1 Medical & Physical .............................................................................................................. 245 9.4 Staffing ......................................................................................................................................... 245 9.4.1 Security Officer .................................................................................................................... 245 9.4.2 Fixed Post ............................................................................................................................. 245 9.4.3 Security Police Officer (SPO) Is .......................................................................................... 245 9.4.4 SPO IIs ................................................................................................................................. 245 9.4.5 SPO IIIs ................................................................................................................................ 245 9.5 Duties ......................................................................................................................................... 245 9.5.1 Normal duties ....................................................................................................................... 245 9.5.2 Emergency duties ................................................................................................................. 245 DOE-STD-1217-2020/Rev FEBRUARY 2020 x 9.6 Equipment .................................................................................................................................... 245 9.6.1 Duty Equipment ................................................................................................................... 245 9.6.2 Vehicles ................................................................................................................................ 246 10.1 Characterization of the Nuclear Control and Accountability program ......................................... 246 10.1.1 Shall address probability of detection of loss of Category I SNM with 95% probability, if applicable ........................................................................................................................................... 246 10.1.2 Shall define loss detection capability for other Categories of SNM .................................... 246 11.1 Procedures for new clearances ..................................................................................................... 246 11.2 Clearance transfers, extensions, upgrades, downgrades, and cancellations ................................. 246 11.3 Reporting requirements ................................................................................................................ 246 12.1 Procedures applicable to the Insider Threat Mitigation Program ................................................. 246 12.2 Description of Local Insider Threat Working Group (LITWG) ................................................... 246 12.3 Human Reliability Program, if applicable .................................................................................... 246 12.3.1 Overview of HRP program .................................................................................................. 246

Section 8

12.3.2 Roles and Responsibilities ................................................................................................... 246 12.3.3 HRP Certification ................................................................................................................. 246 12.3.4 HRP Removal ....................................................................................................................... 246 13.1 Classified Matter Protection and Control ..................................................................................... 246 13.1.1 Procedures utilized to protect classified matter, to include: ................................................. 246 13.2 Controlled Unclassified Information ............................................................................................ 247 13.2.1 Procedures utilized to protect CUI information ................................................................... 247 14.1 Overview of cyber security program ............................................................................................ 247 14.2 Roles and Responsibilities ............................................................................................................ 247 14.2.1 Authorizing Official ............................................................................................................. 247 15.1 Overview of the Operations Security program ............................................................................. 247 15.2 Identification and release of controlled information .................................................................... 247 16.1 Overview of the Technical Security program............................................................................... 247 DOE-STD-1217-2020/Rev FEBRUARY 2020 xi 17.1 Surveys ......................................................................................................................................... 247 17.1.1 Site Office ............................................................................................................................ 247 17.1.2 Program Office ..................................................................................................................... 247 17.2 Self-Assessments .......................................................................................................................... 247 17.3 Findings and Corrective Actions .................................................................................................. 247 17.4 Reviews, Reports and Ratings ...................................................................................................... 247 LIST OF FIGURES Figure 8:1 Portable Universal Quality System Audit Template .................................................................. 13 Figure 12:1 Initial Notification Memo Process Map ................................................................................... 31 Figure 12:2 Initial Notification Memo Color-Coded Process Map ............................................................. 32 Figure 12:3 Notification Memo Improved Process Map ............................................................................. 33 LIST OF TABLES Table E-1 Example of SNM Theft/Diversion Targets ............................................................................... 250 Table E-2. Example of Radiological Sabotage Targets ............................................................................. 251

Section 9

Table E-3. Example of Biological/Chemical Sabotage Targets ................................................................ 251 Table E-4. Example of Disruption of Critical Mission Targets................................................................. 252 Table E-5. Example of Site-Wide Protection Strategies ........................................................................... 253 Table E-6. Example of Facility Protection Systems .................................................................................. 254 Table E-7. Example of Qualifications and Training .................................................................................. 255 Table E-8. Example of MC&A Plans and Procedures .............................................................................. 256 Table E-9. Example of Personnel Security/Human Reliability ................................................................. 257 Table E-10. Example of Automated Information Systems Security Programs ......................................... 258 Table E-11. Example of S&S-Related Maintenance, Testing, and Records Management Programs ....... 260 Table E-12. Example of Site Protection Program Evaluation Program .................................................... 260 Table E-13. Example of Deviations from DOE Contractor Requirements ............................................... 261 Table E-14. Example of Pending Deviations from DOE Contractor Requirements ................................. 261 Table E-15. Example of Identified Risks Summary .................................................................................. 263 Table E-16. SNM Theft/Diversion Targets ............................................................................................... 263 Table E-17. Example of Credible Radiological Sabotage Targets ............................................................ 263 Table E-18. Example of Credible Biological Sabotage Targets ................................................................ 264 Table E-19. Example of Credible Chemical Sabotage Targets ................................................................. 264 Table E-20. Example of Disruption of Critical Mission Targets Table..................................................... 264 DOE-STD-1217-2020/Rev FEBRUARY 2020 xii Table E-21. Example of Performance Testing Results of Site-Specific .................................................... 266 Table E-22. Example of Critical Path Scenarios ....................................................................................... 267 Table E-23. Example of Protection Effectiveness (PE) for Theft or Diversion of SNM .......................... 268 Table E-24. Example of Protection Effectiveness (PE) for Radiological Sabotage .................................. 268 Table E-25. Example of Protection Effectiveness (PE) for Biological Sabotage ...................................... 269 Table E-26. Example of Protection Effectiveness (PE) for Chemical Sabotage ....................................... 269 Table E-27. Example of Protection Effectiveness (PE) for Disruption of Critical Missions .................... 269 Table E-28. Example of Protection Effectiveness (PE) for Theft/Espionage of Classified Information/Matter .................................................................................................................................... 270

Section 10

Table E-29. Example of Protection Effectiveness (PE) for Other Losses ................................................. 270 Table E-30. Example of System Effectiveness Summary ......................................................................... 270 DOE-STD-1217-2020/Rev FEBRUARY 2020 1 ACRONYMS AND ABBREVIATIONS CAP Corrective Action Plan CAS Central Alarm Station CDCO Classified Document Control Office CDCS Classified Document Control Station CI Critical Information CMPC Classified Matter Protection and Control COMSEC Communications Security CPCI Central Personnel Clearance Index CSCS Contract Security Classification Specification DBT Design Basis Threat DEAR DOE Acquisition Regulation DNA Does Not Apply DOE Department of Energy ECD Estimated Completion Date EOC Emergency Operations Center FACTS Foreign Access Central Tracking System FCL Facility Clearance Level FDAR Facility Data and Approval Record FEMA Federal Emergency Management Agency FN Foreign national FOCI Foreign Ownership, Control or Influence FOF Force-on-force FSL Facility security level DOE-STD-1217-2020/Rev FEBRUARY 2020 2 FSC Facility Security Committee FSO Facility Security Officer GSP Graded Security Protection HRP Human Reliability Program ID Inventory difference IDS Intrusion detection system IOSC Incident of Security Concern ISC Interagency Security Committee JTA Job Task Analysis KMP Key Management Personnel LLEA Local law enforcement agencies LOI Lines of Inquiry LSPT Limited scope performance test MAA Material Access Area MBA Material Balance Area MC&A Material Control and Accountability MOA Memoranda of Agreement MOU Memoranda of understanding N/A Not Applicable NMMSS Nuclear Material Management and Safeguards System NTC National Training Center NR Not Rated ODFSA Officially Designated Federal Security Authority ODSA Officially Designed Security Authority DOE-STD-1217-2020/Rev FEBRUARY 2020 3 OFI Opportunities for Improvement OGA Other government agency OPSEC Operations Security PF Protective Force REVCOM Review and Comment RIS Reporting Identification Symbol RMP Risk Management Process S&S Safeguards and Security SAP Special Access Program SAS Secondary Alarm Station SEC Securities and Exchange Commission SECON Security condition SNM Special nuclear material SP Security plan SRA Security Risk Assessment SRD Secret Restricted Data SRT Special Response Team SSD Safeguards and Security Division SSIMS Safeguards and Security Information Management System SSPS Safeguards and Security Periodic Survey TID Tamper-Indicating Device TSCM Technical Surveillance Countermeasures TSCMO TSCM Officer TSCMOM TSCM Operations Managers DOE-STD-1217-2020/Rev FEBRUARY 2020 4 UCNI Unclassified Controlled Nuclear Information UFVA Unclassified Foreign Visitors and Assignments VA Vulnerability Analysis DOE-STD-1217-2020/Rev FEBRUARY 2020 5 SCOPE This document provides the Department of Energy (DOE) with a standard methodology for adapting the Department’s requirements to conduct and report Safeguards and Security (S&S) surveys and self-assessments to organization-specific needs in a coherent, consistent, and repeatable fashion. It describes a consistent and acceptable approach to planning, conducting, and reporting the results for S&S surveys and self-assessments. Appendix A, Safeguards and Security (S&S) Survey and Self-Assessment Toolkit, provides guidance and

Section 11

useful templates for planning, conducting, and reporting surveys and self-assessments. PURPOSE The purpose of this Technical Standard is to provide federal and contractor personnel who have S&S oversight responsibilities with an accepted, compliance and performance-based process to conduct and report S&S surveys and self-assessments prescribed in DOE Order (O) 470.4B Minor Change 2. APPLICABILITY This Technical Standard is intended for use by DOE federal and contractor S&S organizations conducting either S&S surveys or S&S self-assessments. REFERENCES DOE Guide 414.1-1C, Management and Independent Assessments Guide, March 27, 2014 DOE Manual 471.3-1, Administrative Change 1, Identifying and Protecting Official Use Only Information, January 13, 2011 DOE Order 142.3A Limited Change 2, Unclassified Foreign Visits and Assignments Program, January 18, 2017 DOE Order 226.1B, Implementation of Department of Energy Oversight Policy, April 25, 2011 DOE Order 413.3B, Minor Change 5, Program and Project Management for the Acquisition of Capital Assets, April 12, 2018 DOE Order 452.8, Control of Nuclear Weapon Data, July 21, 2011 DOE Order 470.3C, Design Basis Threat, November 23, 2016 DOE Order 470.4B, Minor Change 2, Safeguards and Security Program, January 17, 2017 DOE-STD-1217-2020/Rev FEBRUARY 2020 6 DOE Order 470.6 Minor Change 1, Technical Security Program, January 11, 2017 DOE Order 471.1B, Identification and Protection of Unclassified Controlled Nuclear Information, March 1, 2010 DOE Order 471.3, Administrative Change 1, Identifying and Protecting Official Use Only Information, January 13, 2011 DOE Order 471.5, Special Access Programs, March 29, 2011 DOE Order 471.6, Administrative Change 3, Information Security, September 12, 2019 DOE Order 472.2, Page Change 1 (Certified), Personnel Security, July 16, 2015 DOE Order 473.3A, Minor Change 1, Protection Program Operations, January 2, 2018 DOE Order 475.1, Counterintelligence Program, December 10, 2004 DOE Order 475.2B, Identifying Classified Information, October 3, 2014 DOE Policy 470.1B, Safeguards and Security Program, February 10, 2016 The Risk Management Process for Federal Facilities: An Interagency Security Committee Standard, 2nd Edition, November 2016 Title 10, Code of Federal Regulations Part 824, Procedural Rules for the Assessment of Civil Penalties for Classified Information Security Violations Title 32 Code of Federal Regulations Part 2004, National Industrial Security Program Title 32 Code of Federal Regulations, Part 2001, Classified National Security Information INTERNET SOURCES OF REFERENCE MATERIALS DOE Survey Form: https://www.energy.gov/cio/downloads/doe-f-4708 EFCOG Self-assessment Tool Kit: https://efcog.org/wp- content/uploads/Wgs/Safeguards%20and%20Security%20Working%20Group/Documents/2014- SSWG%20PPM-Toolkit-S%26S%20Self-Assessment.pdf https://www.energy.gov/cio/downloads/doe-f-4708 https://efcog.org/wp-content/uploads/Wgs/Safeguards%20and%20Security%20Working%20Group/Documents/2014-SSWG%20PPM-Toolkit-S%26S%20Self-Assessment.pdf https://efcog.org/wp-content/uploads/Wgs/Safeguards%20and%20Security%20Working%20Group/Documents/2014-SSWG%20PPM-Toolkit-S%26S%20Self-Assessment.pdf https://efcog.org/wp-content/uploads/Wgs/Safeguards%20and%20Security%20Working%20Group/Documents/2014-SSWG%20PPM-Toolkit-S%26S%20Self-Assessment.pdf DOE-STD-1217-2020/Rev FEBRUARY 2020 7 DEFINITIONS

Section 12

Definitions commonly used in the Safeguards and Security Program can be found in the Office of Environment, Health, Safety and Security Policy Information Resource located at https://pir.doe.gov/. Definitions that have unique meanings in this Technical Standard include: a. Deficiency: An inadequacy in the implementation of an applicable requirement or performance standard that is found during an appraisal. Deficiencies may serve as the basis for findings. b. Observation: An item for management attention noted in a survey or self- assessment report that identifies a potential deficiency if not addressed or a possibility for program enhancement that shall be further studied before implementation. c. Opportunity for Improvement: A term used by some oversight activities to identify an item for management attention noted in a survey or self-assessment that identifies a possibility for program enhancement that shall be further studied before implementation. Opportunities for Improvement (OFI) may also be identified as Suggestions, Recommendations, Findings, Weakness, or other site- specific terminology. d. Strength: A term used to identify in a survey or self-assessment that the program or item in review is operating better than required by the Order. Strengths may also be known as noteworthy practices, or other site-specific terminology. e. Weakness: A term used to identify in a survey or self-assessment that the program or item in review is operating less than optimum as required by the Order. Weakness may also be known as an opportunity for improvement, or other site-specific terminology DUTIES, RESPONSIBILITIES, AND TRAINING Survey Team Leader The DOE cognizant security office line management shall appoint a federal employee as the Survey Team Leader for surveys of facilities with an importance rating of “A”, “B,” or “C”. For other facilities, the Survey Team Leader may be a contractor acting under the supervision of a federal employee designated by line management of the DOE cognizant security office. The Survey Team Leader is responsible for the successful completion of the survey. This person shall have a comprehensive understanding of S&S programs, have previous survey experience (preferably as a Survey Topical Lead or Survey Team Leader), and be especially capable of integrating topical area results into a comprehensive assessment of facility security. It is highly desirable that the Survey Team Leader has completed DOE-STD-1217-2020/Rev FEBRUARY 2020 8 training courses offered by the National Training Center (NTC) on survey conduct and management. The Survey Team Leader is responsible for managing the efforts of the survey team and for keeping the participants informed of all matters affecting the team and/or the facility during the survey. The Survey Team Leader is responsible for team planning and logistics, coordination of team activities, focusing the activities of the team, ensuring that deliverables are prepared and provided according to the schedule, promoting integration among topical teams, and acting as a team spokesperson during meetings and briefings. In particular, the team leader needs to ensure that all pertinent elements of the S&S program are reviewed, that analysis is particularly focused upon the most critical elements, and that any concerns or deficiencies identified are fully supported by documented and validated data. Survey Team Leader responsibilities may include the following:

Section 13

a. Develops the survey plan. b. Prepares and maintains an Annual Master Survey Schedule. c. Is trained by DOE NTC (or another training institution/organization), or qualified by their Program Office to lead a survey team. d. Appoints Survey Team members for each evaluation. The selections shall achieve a balance of technical knowledge, experience, writing ability, survey experience, survey ability, and availability. Employees who are technical area specialists may augment the staff and could include direct support contractors, other employees, other organization employees, or other site employees. e. Ensures the survey team conducts security surveys of facilities under their cognizant authority in a timely manner. f. Conducts Survey in-briefings, daily management meetings and closeout briefings. g. Ensures survey data is entered in the Safeguards and Security Information Management System (SSIMS); in accordance with SSIMS data entry procedures and DOE line management direction. h. Ensures Initial Surveys are conducted for all new facilities with a security interest prior to granting facility approval. i. Ensures Periodic Surveys are conducted according to the established risk-based management process, j. Ensures Termination Surveys are conducted for all facilities that no longer have a security interest. DOE-STD-1217-2020/Rev FEBRUARY 2020 9 k. Ensures the importance rating for approved facilities is updated as necessary. l. Consolidates all staffing resource requirements, to include such items as overtime requirements for federal staff, requests for assistance from other Program Managers or other organizations, typing and editing support, and contractor support. Presents the consolidated schedule, staffing requirements, and scope of the survey to the appropriate leadership. m. Ensures that all necessary logistical arrangements are made, including the availability of adequate workstations, classified computers, security containers, and authorized Derivative Classifiers as deemed necessary. Also coordinates with appropriate organizations for the proper access control, site-specific training requirements, and issuance of safety equipment. n. Prepares the data call letter with input from the Topical Leads and forwards that letter to the organization(s) to be surveyed or assessed at least 30 days prior to the beginning of the survey. o. Conducts daily meetings with the Topical Leads and with the appropriate management of the organization(s) being surveyed to keep them informed of concerns resulting from the day’s data-collection activities. p. Review and approves Topical Lines of Inquiry (LOIs) q. Reviews Topical Area Survey Reports; including survey results from previous surveys. r. Provides guidance to Topical Leads and Survey Team members as necessary. s. Provides guidance to federal and contractor personnel in the preparation of corrective action plans (CAPs) for findings issued to their organization. t. Maintains reports in accordance with DOE requirements u. Employ a risk analysis methodology to define the scope and critical topical areas of interest to review during the survey (see Attachment 1). Survey Topical Leader A topical lead for each topical area to be surveyed should either be appointed by the same authority appointing the Survey Team Leader or, alternately, be designated by the Survey Team Leader. The topical lead must be an expert in his or her assigned topical area. In some

Section 14

cases, it may be necessary to select a contractor as topical lead because of his or her outstanding technical qualifications, with the understanding that a contractor cannot supervise the work of federal employees. The topical leads work closely with the Survey Team Leader to complete pre-planning, to ensure that each topical area team collects the DOE-STD-1217-2020/Rev FEBRUARY 2020 10 data required for preparation of the survey report, and to ensure that written and verbal deliverables assigned to the topical area teams are of high quality and are delivered according to the schedule. Each topical lead conducts, with the assistance of the topical area team, a topical area analysis of results, and recommends topical area and sub-topical ratings to the Survey Team Leader. It is highly desirable that topical leads have completed the training courses offered by the NTC on survey conduct and management. a. Trained through the DOE NTC or other organization b. Responsible for the activities of Survey Team members assigned to their topical area c. Responsible for meeting all deliverable deadlines in a timely manner. d. Develops Topical Area LOIs for their areas and provides to the Survey Team Leader for approval. e. Responsible for ensuring that Survey Team members integrate and coordinate their activities with other topical area teams as appropriate. f. Conduct daily meetings with their Survey Team members on data-collection activities and concerns. g. Brief the Survey Team Leader on data-collection activities and concerns. h. Ensures notes are reviewed for classification and appropriately marked, and then submitted to the Survey Team Leader. i. Provide the consolidated Topical Area Report, including the suggested ratings and accurate reference citations, to the Survey Team Leader. j. Incorporate changes to the Topical Area Report as required by the Survey Team Leader. k. Ensure that all notes, working papers, and other data-collection materials are collected from survey team members for retention. Survey Team Members Selection of survey team members shall be coordinated among the Survey Team Leader, topical leads, and the organizations for which the individuals work. Team members shall be selected for technical competence, professionalism, and experience, with particular emphasis on interpersonal skills that will allow them to interact with facility personnel to collect and analyze data without creating an unnecessary burden on operations or controversy with facility personnel. Team members shall have previous experience and demonstrated expertise in the topical area or sub-topical area topical area to which they are assigned, DOE-STD-1217-2020/Rev FEBRUARY 2020 11 unless they are specifically selected for the purpose of training and/or furthering their professional development. Team members selected for training or professional development shall perform under the direct supervision of an individual with previous experience and demonstrated expertise in the topical area or sub-topical area. Unless they are specifically selected for training or professional development, it is highly desirable that survey team members have completed training courses offered by the NTC on survey conduct and management. a. Keep Topical Leads or Team Leader informed of data-collection activities and concerns. b. Keep notes in sufficient detail for briefing and report development. c. Meet deadlines for all deliverables.

Section 15

d. Prepare their portion of the final report in the proper format, including recommended ratings and findings. e. Provide accurate reference citations for all findings to ensure that the finding is consistent with DOE Orders and other requirements. f. Write findings such that corrective actions can be completed. g. Process classified information only on accredited computers. h. Discuss potential survey results only with other individuals on the Team to confirm if a potential finding shall be a finding in the final survey report. The Survey Team Leader will provide the surveyed organization’s management a daily briefing on the status of activities and concerns. Self-assessment Team Leads and Members Self-assessment team leaders, topical leads, and team members shall be chosen using the same criteria as listed above for Survey Team Leaders, topical leads, and team members. However, as self-assessments are a contractor activity, it is not necessary to have federal employees as survey and topical area team leaders. SURVEY AND SELF-ASSESSMENT OVERVIEW Surveys, self-assessments, and review programs are conducted to ensure that S&S systems and processes at facilities/sites are operating in compliance with Departmental and national- level policies, requirements, standards, and approved deviations for the protection of security assets and interests. Without an adequate S&S survey program, line managers cannot effectively manage the S&S programs for which they are responsible. Surveys compare planned S&S program performance to the actual achievement. The survey report presents accumulated data and provides an analysis of S&S program effectiveness for the DOE-STD-1217-2020/Rev FEBRUARY 2020 12 areas surveyed/assessed at the surveyed location. The survey activity provides two vital components to the federal management of an S&S program – measurement of the degree to which actual implementation matches planned implementation, and feedback indicating actions needed to make program implementation match program planning and/or needed changes to program planning and implementation to better achieve mission objectives. Management support and commitment to the S&S survey program are critical to ensuring the time and resources required to produce a useful survey product are available. To provide the best possible information for management consideration, the S&S survey needs to include a significant sample of the local S&S mission elements. The resulting report needs to contain a logical and thorough presentation of the survey results, accompanied by a complete and logical analysis of those results that leads to conclusions regarding the status of program implementation, reflected in the ratings awarded, and identification of needed actions. These conclusions regarding the status, accompanied by measurements and analysis supporting the conclusions, inform not only local federal management, but also line management at higher levels about the current status of the S&S program at the surveyed site or facility. Surveys and self-assessments must focus on both performance and compliance. When possible, the survey and self-assessment efforts must ensure compliance with requirements and performance of personnel and systems demonstrating that Departmental and national assets are protected; and that resources are used responsibly, and in the best interest of the nation. For this reason, survey and self-assessment teams shall be familiar with basic survey

Section 16

techniques as well as process improvement techniques, some of which are presented in this document. As there are many available improvement techniques those presented in this document are only some of the recommended options the site may elect to adopt. The Portable Universal Quality System described in Auditing Beyond Compliance by Janet Bautista Smith, outlines at a high level how this process of assessing performance could work as shown in Figure 8.1 DOE-STD-1217-2020/Rev FEBRUARY 2020 13 Figure 8:1 Portable Universal Quality System Audit Template S&S programs have traditionally been considered to be logically divided into topical areas and, within each topical area, sub-elements known as sub-topical areas. While this organizational structure might be considered to be somewhat arbitrary, it forms a useful way to organize data collection and to report the results of a survey or self-assessment. This division into topical areas and sub-topical areas are reflected on the DOE Form 470.8, Survey/Inspection Report Form (see Attachment 2), and this topical area and sub-topical area structure or a similar format shall be used in discussion of the survey and self- assessment process to follow. In addition to providing a structural reference for this technical standard, the form is often used to provide a means of summarizing the results of a comprehensive survey or self-assessment and is the appropriate data entry form for entering survey and self-assessment data into the SSIMS. Modifications of this form might be DOE-STD-1217-2020/Rev FEBRUARY 2020 14 beneficial to capture site-specific information but shall allow for entry of information into SSIMS at least at the topical area level where applicable. Self-assessments provide the same management information to local contractor managers on a more frequent basis than the survey or at a time between surveys. The need for documentation of self-assessment activities leading to a periodic comprehensive report is no less than for surveys. The benefits of these self-assessments are several:  Local managers receive notification of program weaknesses on a more timely basis, thereby allowing them to address and correct the issues sooner than might be possible using only an external review;  Local S&S personnel are encouraged to be self-critical, allowing them to be more proactive in providing adequate security to local assets; and,  Employees who have security duties but are not security professionals are provided a more comprehensive view of the security program. SURVEY AND SELF-ASSESSMENT PLANNING Survey and self-assessment planning consists of two components—cyclic program planning and planning for a survey of a particular facility or a particular self-assessment. Effective planning requires the planner to fully understand the assets at each facility to be reviewed during a planning period, the operations and characteristics of each facility, the S&S directives that apply at each facility, and the past performance of each facility on previous surveys, facility self-assessments, and recent external reviews. Cyclic Planning for Surveys and Self-Assessments Comprehensive planning is key to the success of a survey or self-assessment program. Review activities may be scheduled around a one-time evaluation, ongoing observations during the reporting interval, a combination of the two, or as otherwise required in the

Section 17

interest of national security. Each activity conducting surveys or self-assessments shall establish a planning cycle that best allows the allocation of resources and assures that surveys or self-assessments are scheduled to meet the requirements of DOE O 470.4B Minor Change 2. A survey or self-assessment plan shall be prepared for the selected planning cycle to reflect the approach used for data collection and report preparation, a schedule of planned surveys or self- assessments during the planning period, and an initial assessment of personnel and other resources required to complete the planned activities. Personnel requirements, both the number of personnel and their skills, will be a function of the particular facilities scheduled for that planning period. Planning shall include an identification of the information needed to conduct a comprehensive evaluation at each facility, including the identification of topical area and sub-topical area as required. If information is to be collected over an extended period, for example by observing particular operations during the time period, the plan will need to consider whether the information DOE-STD-1217-2020/Rev FEBRUARY 2020 15 collected remains completely reliable or is somewhat degraded by the passage of time between the observation and final report preparation. Planning must identify sampling or verification methods that ensure perishable information gathered early in a survey or self- assessment planning period remains valid at the time the report is completed. Planning a Facility Survey or Self-Assessment. Comprehensive survey and self-assessment planning involves gathering and analyzing large amounts of information from many sources, making decisions based on the analysis, and preparing survey activities based on the decisions. Because there is only a limited amount of time available onsite to collect the data necessary to characterize the status of the programs being surveyed, planning shall focus on determining what program elements to review and how best to survey those elements to help ensure the most effective use of that time. For those elements the plan shall specify the additional data necessary to assess the applicability and accuracy of data obtained from periodic sampling during the final phase of survey conduct. Planning activities include identifying personnel and other support requirements for all phases of the survey. Pre-Planning Pre-planning includes determining the scope and objectives of the review. Information such as the facility importance rating, S&S interests, and security contract requirements provide the basis for the scope and objectives of the assessment, but other factors such as previous performance, recent site operational changes, and new missions are also important in establishing the scope of the review. Aspects of the impact of these elements can be assessed qualitatively and quantitatively using a risk assessment process similar to that found in Attachment 1. This form of analysis can define what expertise is required for the assessment and on what topical areas the survey shall focus resources. Once this risk assessment is complete, the team leader develops an initial schedule and considers whether a preliminary visit is needed. To assist in the scheduling of the survey from pre-planning to completion of report, a survey a checklist, like that presented in Attachment 3 Survey Prep and Report,

Section 18

Checklist, might be useful. Additionally, a survey/self-assessment plan is vital to ensuring a properly planned and executed survey, to capture at a high level the focus of the survey efforts (see Attachment 4, Survey Plan Template). As with many aspects of the survey/self- assessment process, the formality and comprehensiveness of information may vary based on the familiarity of the survey team and the facility or organization assessed. Preliminary Coordination Before data collection begins, the following activities shall be conducted:  Coordinating the proposed schedule with the site/facility and other responsible parties; DOE-STD-1217-2020/Rev FEBRUARY 2020 16  Identifying basic information needed in the data collection, such as a site or facility security plan, assessment/ inspection reports, approved deviations (including equivalencies/exemptions for DOE policy and deviations from national policy), and contract data;  Sending the notification letter or other agreed upon notification;  Team member selection and coordination with members’ management;  If a data call is deemed necessary to support a team planning meeting, determining the documents needed, preparing a list, and requesting the listed documents from their respective sources. (Refer to Attachment 6, Data Call Information)  Conducting a team planning meeting;  Establishing a schedule and topical area assignments;  Gathering facility data (e.g., location, S&S interests, queries of SSIMS, EFOCI, and other databases to obtain information regarding the facility clearance, importance rating, key positions, assets, current S&S plans, and active deviations);  Establishing protocols, including a schedule for team meetings, a procedure for communicating schedule changes or additional support requirements, a process for managing classification concerns and issues, a determination of the validation process to be used, a consolidated document call, a report outline reflecting the desired format for the report, LOIs, and a compilation of logistical information (travel dates, hotel arrangements, rental cars, site access, in-briefing time/location);  Providing the format for plans, reports, findings, process improvements, and corrective actions;  Providing official notification; and,  Preparing an overall plan for the survey or self-assessment. The level of pre-planning required for a survey or self-assessment that includes ongoing data collection such as surveillances or shadowing of key activities will be even more stringent, since specific measures for validation of such data will need to be identified, and methods for inclusion of these data sets into the analysis leading to topical area ratings and facility ratings will need to be specified. The communication formality vary based on the scope and relationship of the surveying team and the facility or organization. Attachment 5, Notification Memo, provides a formal notification memo sample. This sample may not benefit a self-assessment or survey of the local contractor performed by the federal staff. DOE-STD-1217-2020/Rev FEBRUARY 2020 17 Planning Survey and Self-Assessment Activities After completing the pre-planning and preliminary coordination activities, the team lead shall:  Review data received from data call  Review LOIs  Review and assess SP for required information and note approved deviations to DOE policies (See Attachment 12. Note: Appendices B through H accompany

Section 19

Attachment 12 and otherwise have no bearing on this Technical Standard);  Planning for performance tests, as needed  Identify who to interview  Determine what work to observe  Associate data-collection methods with each line of inquiry chosen SURVEY AND SELF-ASSESSMENT CONDUCT Valid sampling and accurate evaluation shall be the focus of all survey and self- assessment activities during the conduct of the review. This focus shall be apparent during all phases of the review activity so that, as far as possible, the review is a joint exercise between reviewers and reviewed to identify and correct program issues, with the goal of improving the local S&S program. Methodologies typically used to measure compliance include, but are not limited to, document review, testing, observation, and interviews. Effective planning, data collection, validation, and analysis of the information comprises the measurement of performance used to improve the local S&S program and may reduce the potential for differing opinions about the survey or self-assessment results. Additionally, the level of assessment beyond compliance may also be limited based on the authority conducting the assessment and the scope of their assessment. In-Briefing A formal in-briefing has traditionally been the initial onsite activity of the type of review that one might call a “snapshot in time,” during which all data is collected in a relatively brief interval – one day to a few weeks depending on the complexity of the site. More recently, comprehensive survey and self-assessment reports have often been based, partially or completely, upon data collected over an extended period, perhaps as long as a year. Even in the case of the more extended data-collection effort, an in-briefing at the beginning of the review period shall be conducted to assist in establishing and maintaining effective communication with the site. A carefully prepared in-briefing can ensure a positive start for the assessment, create a good first impression, and provide an opportunity to reduce the DOE-STD-1217-2020/Rev FEBRUARY 2020 18 stress and tension associated with the survey or self-assessment. Items to be covered during the facility in-briefing shall include (but are not limited to):  Survey or self-assessment scope and objectives;  Survey or self-assessment approach and methodology (with respect to data- collection methods), including whether all data will be collected during one site visit, whether the final report will be based on a set of observations conducted throughout the assessment cycle, or some combination of these approaches;  For surveys, the level of reliance on the contractor assurance system and how data derived from the contractor assurance system will be verified by the survey team and included in the analysis of survey data;  Outline schedule of events and communication such as end-of-day meetings, exit briefing date and time, expected completion date of report;  General introductions of team members; and,  Schedule of survey or self-assessment activities. During this meeting or immediately following, the site subject matter experts and points of contact shall collaborate with survey team members to streamline communication and data gathering efforts. Maintaining Communication The team leader and topical leads shall plan on meeting frequently during the course of the survey or self-assessment. The frequency of the meetings will be partially dictated by the

Section 20

assessment approach – snapshot or extended. The meetings ensure that the team leader and topical leads understand the status of data collection to meet the selected LOIs; understand information of interest for their respective topical area that was identified by other teams; and maintain an awareness of emerging concerns. The team also shall emphasize communication with the assessed site. Again, the frequency of planned communications with site points of contact and site management will depend on the pace of data collection. However, it is vital to effective communication with the site, and therefore to the success of the assessment, that the points of contact and site management remain informed concerning the progress of data collection and have early notice of potential issues, particularly as they relate to rolling or shadow assessments if these techniques are a portion of the survey or self- assessment procedure. Data Collection All members of the survey or self-assessment team work to collect data. Members of one topical area often collect data that supports other topical areas. This data should be shared DOE-STD-1217-2020/Rev FEBRUARY 2020 19 with the other interested topical area teams. For example, data collected about physical security systems could also be useful to the analysis of protective force and nuclear material control, as they are each elements of the overall protection design. Data-collection efforts as well as analysis efforts shall always remain focused on the effectiveness of the entire S&S program in providing appropriate security for national security assets. The selected LOIs always guide data collection. Within a line of inquiry, data collection can be prioritized to allow schedule adjustments if complications or unforeseen events do not permit completion of all planned activities. If this occurs, the team can concentrate on gathering the data deemed most critical. Attachment 7, Sample LOIs form will assist survey teams in the designation of order requirements that are critical to the effectiveness of the program. High-priority data-collection activities shall be scheduled early in the process to ensure that they are accomplished. When a full line of inquiry is endangered by data- collection issues, the team leader will decide the best course of action. All working papers and data-collection records, notes, checklists, and other documentation accumulated during data collection shall be retained as backup documentation to the final report. Ensure that all items are either reviewed by an authorized Derivative Classifier and appropriately marked and protected, or are protected and marked at a level and category specified by the team lead until review by an authorized Derivative Classifier can be performed. Working papers are used to support the validity of findings and as a source of information for future reviews. These papers also can be used for assessing the progress of the review, especially if an extended data-collection methodology is employed. Working papers are maintained at least until the completion of the following survey or self-assessment. If deemed useful for extended tracking and trending of issues, they may be retained for longer periods. Data-collection methods and techniques are chosen based upon their utility in addressing the selected LOIs. Each method and technique has an associated purpose and cost (both to the

Section 21

team and the facility). It is important to know when and where to use each method. For example, running an expensive force-on-force performance test would not be cost-effective if the data were available through an interview, observation, or limited scope performance test (LSPT). An essential step that shall be accomplished in the planning phase is to associate data-collection methods with each line of inquiry chosen. The results of previous federal and contractor reviews, including facility description, security interests examined, and findings and suggestions, shall be considered as a valuable data source. The CAPs and resolution of the previous findings also are indicative of the quality of the program and level of management support the program receives. In particular, the review of past findings can reveal significant indicators of the effectiveness of S&S program management. Concerns about open or repeat findings or the inability to establish and implement effective CAPs in a particular topical area shall be discussed with the entire DOE-STD-1217-2020/Rev FEBRUARY 2020 20 team. The determination of whether similar concerns exist in other topical areas will give those performing the program management evaluation important indicators as to whether the issues extend beyond the topical area in which they were first identified. It is always desirable to minimize impacts to the facility. For example, procedures, such as special nuclear material (SNM) transfers, security alarm preventive maintenance checks, or portal monitor checks, shall, whenever possible, be observed during regularly scheduled times rather than at the team’s request for a special demonstration. However, the need for data to inform the analysis of a line of inquiry is primary. For example, if an operation such as a nuclear material inventory is not scheduled during the survey or assessment and observing the operation is critical to evaluating system operations, then initiating an inventory through a performance test is appropriate. Performance Tests Performance testing is a key data-collection technique deserving special mention. While compliance with specific directive requirements is one of the primary interests of a review team, the actual performance of processes, personnel, and systems in providing protection to national security assets shall be measured to provide an appropriate level of assurance that assets are adequately protected. Performance tests are typically onsite exercises of the personnel, equipment, and/or procedures of selected portions of S&S systems to determine system effectiveness. Performance tests are not limited to the systems protecting SNM or classified matter; they can be conducted to assess any portion of the facility security design. In all cases, they must focus on the elements of a topical area or sub-topical area that are critical to the effectiveness of that topical area or sub-topical area. Performance tests may also be in written form if the material is difficult or hazardous to test. Performance tests will not necessarily reflect the overall state of security at a facility because the observed result of a performance test usually reflects only on the security element tested, not the full protection system. Further, the outcome of a single performance test can reflect temporary or unusual conditions existing at the time of the test. Therefore, while the results of a single

Section 22

performance test are valid data, performance test data shall be placed in context with other findings, observations, and conclusions. Performance tests shall be designed to provide objective data to assist the team in determining whether:  Personnel know and follow procedures;  Procedures are effective;  Plans and procedures accurately describe operations conduct;  The processes described in procedures produce the expected product;  Personnel know how to operate equipment; DOE-STD-1217-2020/Rev FEBRUARY 2020 21  Personnel and equipment interact effectively;  Equipment is functional, operational and effective;  Equipment has adequate sensitivity; and/or,  Equipment meets design objectives. If the facility has a program for conducting performance tests, the team shall consider requesting that the facility conduct one of its performance tests rather than, or in addition to, one designed by the team. Observing the facility conduct a performance test provides information concerning the facility's own assessment program as well as providing the needed data about the protection element being tested. An additional source of performance data is the routine documentation maintained in the course of implementing an S&S program. Performance data reflected in facility documentation such as inventory records, files, classified documents, reports, and access logs are useful in assessing the effectiveness of control processes. Attachment 8 provides a Performance Test Safety Plan template and Attachment 9 provides a Performance Test Plan template. Data Validation An essential component of data collection is data validation. When any data is collected, it is imperative that the data collector determine whether site personnel observing the same event perceive the same outcome as the data collector. If they do not, it is essential to understand why not and to inform the site observer why the data collector has a different perception. It is also essential to share this perception because of the limited sample set that is collected during a review. If site personnel understand that the data collector perceives the result of an observation differently than they do, it provides them an opportunity to supply additional data that provides a fuller context to the data collector’s view of the result. For this reason, it is preferable that two survey team members are present during data review. Similarly, it is important for the team to share perceptions with site management on a periodic basis. The Survey or Self-Assessment Team Leader shall inform the Site management when the assessment team is moving toward a conclusion in a particular area, whether that conclusion is positive or negative. Again, site management might be able to offer additional information that would modify the team’s view of the situation. When final conclusions are reached in the survey or self-assessment report, they shall be based upon a set of facts agreed to by both the review team and the site. However, the analysis of those facts, and the subsequent assessment of site protection effectiveness, is always the sole prerogative of the review team. Data Analysis After all data is collected and verified to be current and accurate, it shall be compiled and analyzed to determine the effectiveness of protection by overall facility, by topical area, DOE-STD-1217-2020/Rev FEBRUARY 2020 22 and/or by sub-topical area, as appropriate. The facts established during the data collection

Section 23

and validated by the site and the team’s analysis of those facts form the basis for observations and findings in the final report. Even when no findings or observations are made, the presentation of validated data and the logical interpretation of that data is a valuable contribution to management understanding of site status and shall never be neglected in the final report. Key facts and the team analysis of them shall be documented in the report immediately before an observation or finding is made and additional supporting information, if any, shall be contained in the retained working papers. The logical path from facts to the finding or observation needs to be clear in the final report, even if some detail is omitted. Findings and observations shall be clearly identifiable in the final report and shall be highlighted during the close out briefing. It is often helpful to repeat all findings and observations from all topical areas in a single appendix or attachment to the report. Tracking and trending of results is enhanced by the assignment of a unique tracking number to a finding or observation, especially findings, to assist in tracking and reporting on actions developed or taken in response. For findings in particular, since they must be entered into the SSIMS database, a tracking number is needed that conforms to the SSIMS finding format. An example would be 34-NOV-01-HQ-0123-SSIS-PM-001.18298, where 34-NOV- 01 is the end date of the survey, HQ is the cognizant security office, 0123 is the facility code for the surveyed facility, SSIS is the type of survey (see DOE O 470.4B Minor Change 2, Appendix A, Section 2, paragraph 3), PM is the topical area in which the finding is made, 001 is a sequential number of the finding within the topical area, and 12898 is the facility code responsible for correcting the finding. The terms finding, observation, opportunity for improvement (OFI), and others are used in surveys and self-assessment reports to indicate issues that require management attention. The term finding is defined in DOE policy and is always used to identify any validated program deficiency (a failure to meet a performance or compliance requirement derived either from internal or external directives or the approved site/facility security plan.) The term observation is used to identify areas where the review team perceives a need for particular management attention, even if DOE requirements and security plan performance elements have been met. Observations also may be used to identify potential areas for program enhancement. In some cases, survey and self-assessment programs have used the term OFI. OFI are similar in intent to an observation, but are used to clearly separate potentially positive results from potentially negative ones. Usually this distinction is made when management believes both findings and observations are indicators that program improvements are needed whereas an OFI indicates that the review team has identified a potential program improvement which local security management might consider. Findings, observations, opportunities for improvement (OFI), or any other conclusion reached during data analysis shall be based upon validated data collected during the various activities comprising the review. DOE-STD-1217-2020/Rev FEBRUARY 2020 23 Ratings Upon completion of survey or self-assessment data collection, a recommended rating for

Section 24

each topical area and sub-topical area reviewed shall be determined, usually by the topical area team members. When considering a topical area rating, the topical area team shall consider the results from each sub-topical area and topical area and the relative contribution of each sub-topical area and topical area to the success of the overall topic within the local context. The logic and determinations supporting the recommended ratings shall be included in the draft survey or self-assessment report to support the topical area rating proposed to the team leader. The team leader, in consultation with topical leads and team members, shall determine the composite facility rating and the topical area and sub-topical area ratings, based upon the results of the survey or self-assessment. The team leader shall ensure that the basis for the rating determinations is explained in the survey or self-assessment report. A composite facility rating shall be based upon the topical area and sub-topical area ratings and an analysis of the relative importance of each topical area and sub-topical area in the overall protection design of the site/facility. As with each of the topical area and sub-topical area ratings, the logic and considerations leading to the award of the composite facility rating shall be explicitly addressed in the survey report. The ratings listed below are used for all surveys (except termination), reviews, and self- assessments. Does Not Apply and Not Applicable (NR) shall also be used in lieu of a rating when appropriate.  Satisfactory. The element being evaluated meets protection objectives or provides reasonable assurance that protection objectives are being met.  Marginal. The element being evaluated partially meets protection objectives or provides questionable assurance that protection objectives are being met.  Unsatisfactory. The element being evaluated does not meet protection objectives or does not provide adequate assurance that protection objectives are being met. A topical area or sub-topical area shall be rated Satisfactory if all aspects of the topical area or sub-topical area are found to be as depicted in the approved security plan, including any approved equivalences or exemptions, and observed performance is sufficient to provide assurance that the topical area or sub-topical area elements are providing the level of protection assumed in the approved site/facility security plan. In particular, any security element within the topical area or sub-topical area that is identified as an essential element shall demonstrate performance at least equal to that required to support overall security effectiveness, as documented in the approved security plan. A topical area or sub-topical area shall also be rated Satisfactory if, for any measure not met, documented and approved compensatory measures are in place to provide comparable protection and action is either under way to return the security elements comprising the topical area or sub-topical area to DOE-STD-1217-2020/Rev FEBRUARY 2020 24 full capability or an approved plan to restore the security elements is being satisfactorily pursued. In some instances, a topical area or sub-topical area might be rated Satisfactory when some component element fails to meet an applicable measure but, in the judgment of the topical area experts and the Survey Team Leader, the impact of that shortfall does not

Section 25

erode the contribution of the topical area or sub-topical area to the effectiveness of S&S under the approved security plan. The logic underlying such a decision shall be included in the survey report. Notwithstanding the Satisfactory rating, however, the component shall be brought to full effectiveness as soon as possible in all cases. Noncompliance with one or more requirements of the approved security plan shall result in a rating of Marginal or Unsatisfactory for a survey or self-assessment topical area or sub- topical area when the observed shortcoming(s) reduces the assurance that the S&S program, as depicted in the approved security plan, represents the actual S&S practices at the site or facility. If performance testing indicates that a significant question regarding adequate protection exists, even when the site/facility is in full compliance with the approved security plans, a topical area shall be rated no higher than Marginal. Assignment of one or more sub-topical area ratings of Marginal or Unsatisfactory shall lead the topical area team to carefully analyze the seriousness and multiplicity of findings in a sub-topical area against the definitions for Marginal or Unsatisfactory before assigning a rating to a topical. If less-than-satisfactory sub-topical area ratings exist within a topical area rated Satisfactory, the survey or self-assessment report shall explain why the impact of these sub-topical area ratings do not justify a reduced topical area rating. A topical area or sub-topical area shall be rated Unsatisfactory if limited compliance with the approved security plan and/or performance testing results indicate that the topical area or sub-topical area contributions to the approved security plan fall short of the performance required to protect security assets. Performance shall consider the adequacy of any compensatory measures in place when the rating is determined, since adequate compensatory measures supported by a plan to restore the planned functionality can result in a satisfactory rating. However, an unsatisfactory rating shall also be awarded if no plan exists for restoring security element function and removing current compensatory measures, even if the compensatory measures provide a temporary mitigation of the security concern. After ratings have been assigned to all topical areas and sub-topical areas, a rating shall be assigned to the site/facility. While the same three ratings are available – Satisfactory, Marginal, and Unsatisfactory – the context is somewhat different. The site/facility rating shall be based upon an integrated view of the entire security program, taking into consideration the topical area ratings. The site/facility rating is the team leader’s certification to the appointing official regarding the security status of the site/facility. A Satisfactory rating indicates that the site/facility is operating in accordance with the approved security plans and that the demonstrated S&S performance is at least equal to that required to adequately protect all site/facility security assets. A Marginal rating indicates that action is needed to advance the site/facility toward compliance with the approved security plans and/or to fully achieve the performance anticipated when the security plans were approved. DOE-STD-1217-2020/Rev FEBRUARY 2020 25 An Unsatisfactory rating conveys the team’s judgment that immediate management attention

Section 26

is needed to ensure continued protection of one or more of the national security assets located at the site/facility or to ensure that adequate progress will be maintained toward achieving a satisfactory status. Exit Briefing At the conclusion of the survey or self-assessment, an exit briefing shall be conducted with management officials of the organization reviewed. The briefing shall include at least a summary of the following areas:  Program findings, observations, OFI, and strengths;  Corrective action reporting requirements for all open findings, regardless of source; and,  Topical area, sub-topical area, and facility ratings. The team leader shall prepare an agenda for the exit briefing. Because of the potential for confrontation during the briefing, it is generally best for the team leader to provide the briefing and, if necessary, to ask the topical leads to assist with technical details. Agreements and commitments made during the conduct of the survey shall be summarized during the exit briefing. This provides an opportunity to identify potential misconceptions before they are presented formally to management outside the surveyed facility. Agreements and commitments must be documented in writing as soon as possible. REPORT PREPARATION As soon as possible after the survey or self-assessment is completed, a formal report of the results shall be finalized, Appendix A provides an extensive sample report format. The individual team members and topical area and sub-topical leads shall ensure that a complete, concise, and accurate final report of the results is compiled in a timely manner. The report preparation shall be overseen by the team leader, who has ultimate responsibility for its completion and accuracy. Reports and all working papers and other retained material shall be evaluated and reviewed by an authorized Derivative Classifier before publication of the final report. Before this review, the working drafts shall be protected and marked as working papers classified at a level determined by the team leader to be the highest likely classification of the final report, including paragraph markings as appropriate. Required protection and control shall be provided for classified or sensitive information. Even if the overall report is determined to be Restricted Data (thereby eliminating the requirement for paragraph marking), each finding shall be marked with its classification level and category to ensure that the information will continue to be protected appropriately when the finding is extracted from the report. DOE-STD-1217-2020/Rev FEBRUARY 2020 26 Team meetings shall be held as necessary to facilitate the finalization of the survey report and evaluate lessons learned from the review. During these meetings the following actions shall be undertaken as necessary:  Review draft report or report section(s);  Review lessons learned;  Identify trends that might indicate areas of interest for the next review;  Identify helpful information sources and resources to consider in the next review;  Review and summarize agreements and commitments made during the conduct of the review and the exit briefing;  Determine final report content, especially for areas of contention;  Document any unique organizational structures/functions or item of potential use to those planning the next review; and, prepare for briefings on the review results to DOE and contractor management, as appropriate.

Section 27

The survey report shall consider all available data in its analysis. Depending upon the survey methods used, this may include data that reflect:  documented observations of activities at the surveyed facility;  full and limited scope performance tests;  documented data collection conducted during the survey period;  the results of any documented federal shadowing of contractor self-assessments;  targeted data collection conducted to satisfy remaining data requirements late in the survey period (particularly as required to verify accuracy of information acquired during rolling assessments, contractor shadow activities, or derived from contractor reports);  any other documented, objective data that the survey team determines is pertinent. The resulting report provides measurement results, an analysis of those results, including ratings, and specific identification of areas needing improvement, in the form of findings, observations, and/or suggestions to management. When possible and appropriate, the appointing authority responsible for the conduct of the survey or self-assessment shall require that a review board be established to review the draft report and make recommendations to the team leader to improve the report. Such a board DOE-STD-1217-2020/Rev FEBRUARY 2020 27 can significantly improve the final product by verifying that there is a clear, logical presentation of results. Questions regarding what assets were present at the facility, what data-collection methods were used, what facts were discovered using those methods, what facts were considered and with what relative weight to arrive at findings and ratings, and what factors support the overall facility rating shall all be clearly addressed in the report. Use of a review board can ensure that all these questions are adequately addressed and logically presented in the final report. After the report has been completed, SSIMS data entries have been made, and the report has been distributed, the team leader shall document and file lessons learned. These lessons learned shall identify what processes were effective, observations of team dynamics, and specific recommendations for the next review. The team leader shall include lessons learned as reported by topical leads and their teams. These lessons learned shall be provided to the appointing authority for information and evaluation to improve the survey process. ISSUES MANAGEMENT PROGRAM A survey or self-assessment activity only fulfills a portion of its objective if the reviewed organization lacks a robust issues management process. DOE directives require DOE organizations to have an issues management process that is capable of categorizing findings based on risk and priority, to ensure relevant line management findings are effectively communicated to the contractors, and ensure problems are evaluated and corrected on a timely basis. The issues management process, at a minimum, shall include the following for issues categorized as high significance findings:  A thorough analysis of the underlying causal factors;  Implementation of identified corrective action(s)/CAP that address the cause(s) of the findings to prevent recurrence;  An effectiveness review conducted by trained and qualified personnel to verify the corrective action/CAP was effectively implemented and prevented recurrences. The review shall include the following: o documentation of the analysis process and the results of identified underlying

Section 28

causal factors o maintenance tracking, in a readily accessible system, of corrective actions/CAPs; including schedules for the effectiveness reviews;  Appointment of a mutually agreed upon lead office when findings and/or corrective actions apply to more than one Program Secretarial Office/Departmental Element DOE-STD-1217-2020/Rev FEBRUARY 2020 28 Corrective Action Program Findings are deficiencies that warrant a high level of attention on the part of management. If a finding is left uncorrected, it could adversely affect the DOE mission, the environment, worker safety or health, the public or national security. Findings define the specific nature of the deficiency, whether it is localized or indicative of a systemic problem, and identify which organization is responsible for corrective actions. A corrective action program shall include, at a minimum:  Causal analysis appropriate to the complexity of the issue identified (the rigor of causal analysis must not be based upon the perceived consequence of protection element failure – sometimes very serious issues have readily apparent root causes and sometimes important lessons can be learned from issues that have little immediate protection impact – but on the difficulty in identifying the root causes) Attachment 11 Corrective Action and Causal Analysis provides helpful examples for forms and a process for defining the root cause analysis;  Identification and implementation of compensatory measures required to maintain required performance levels while corrective actions are in progress;  Identification and implementation of priorities for completion of corrective actions if all cannot be pursued simultaneously (priorities might be based on availability of resources, costs of associated compensatory measures, and many other factors);  Identification and implementation of necessary validation testing when corrective actions are complete and before compensatory measures are removed; and,  A means of tracking and trending causal factors to allow identification of possible systemic management issues that are only discernible when viewing the results of multiple reviews. It must be noted that tracking in SSIMS is required for survey findings. To maximize the value of surveys and self-assessments, it may also be desirable to go beyond the basic requirements applicable to findings and corrective actions. For example, observations do not specifically require action on the part of the site management, but the careful consideration of observations can lead to improvements in S&S program effectiveness and/or efficiency. Other considerations noted in the survey or self-assessment report or even in supporting working papers may be useful as well, even if the team did not believe they should be highlighted as a finding or an observation at the time of the final report. An examination of these additional factors in conjunction with the findings may contribute to the development of more effective corrective actions or lead to more in-depth improvements which will strengthen and enhance the overall security posture at the site. DOE-STD-1217-2020/Rev FEBRUARY 2020 29 Process Improvement When the scope of the survey and resources allow, assessing the effectiveness of the program and identifying resource savings is the desirable outcome of a survey. While compliance audits have a place in the protection of nuclear assets, personnel, and classified

Section 29

matter, performance effectiveness is ensuring the required protection is present while making the best use of resources and expertise. When time permits, the process outlined below shall be completed and submitted as part of the final report. As this effort requires resources and a focus on program management, the assessment team shall never conduct these efforts without support by the managers of the program assessed. Review of this level is time consuming and resource intense; it is not beneficial or expected that survey teams assess every topical area and sub-topical area. Process improvement shall focus on those topical area and sub-topical areas that have the greatest impact to security and the most potential for saved resources. The steps to process improvement and the tools provided below align to this concept. The five steps of the survey process improvement technique are:  Step 1. understanding and map the current process;  Step 2, complete a value added analysis;  Step 3. develop an improved process;  Step 4. update documentation and develop metrics; and  Step 5. measure for success and return to step 1. Step 1: Understand and Map the Current Process Survey team members work with subject matter experts to outline the process in a systematic method. This can work best in an outline form or in a flow chart such as the example below. There are numerous types of flowcharts and ways to complete the charts. The Cross Functional Flow chart was selected not only to document the flow information but also who was responsible, allowing for identification of information loops which impact the process. There are a few basic steps and best practices that can help in describing and mapping the process:  Form a team with members from any area or organization that provides inputs, manages, or contributes to the process. This helps ensure that all aspects of the process are considered and accounted for. Although not necessary, it may also be beneficial to get input from any downstream process owners. DOE-STD-1217-2020/Rev FEBRUARY 2020 30  Identify the steps in the process. It is usually best to start with the beginning and end steps, including the inputs and outputs, and then work to fill in the steps in-between. It is very important to clearly define where the process being mapped begins and ends.  Identify who owns each step, by job title and/or organization.  Organize the steps in sequential order from beginning to end. Use this information to draw the baseline process map for the current process using whatever type of map the team has selected. The example in Figure 12.1 maps the process to establish initial communication through a formal memo and data call as part of the initial planning. DOE-STD-1217-2020/Rev FEBRUARY 2020 31 Figure 12:1 Initial Notification Memo Process Map Step 2: Complete a Value Added Analysis Review the documented process identify in each step if it is specifically required by the order, performed to meet order requirements, or other. Analyze all steps identified as ‘other’ for whether they are inconsistencies, bottlenecks or are unnecessary, or whether the steps are necessary due to requirements, internal or external, outside of orders. Necessary/required steps should be analyzed further to determine if there are opportunities for optimization, such as improvements in efficiency or effectiveness through delegation of authority to an employee or deploying new technology.

Section 30

DOE-STD-1217-2020/Rev FEBRUARY 2020 32 Continuing with the example, Figure 12.2, below uses the colors green, blue, and red accordingly. Figure 12:2 Initial Notification Memo Color-Coded Process Map DOE-STD-1217-2020/Rev FEBRUARY 2020 33 Step 3: Develop an Improved Process All steps required by order or to meet order requirements must be retained in the improved process. Remove all steps determined to be unnecessary. Revise all other steps determined to be necessary/required, incorporating any optimization and/or new owners identified in Step 2. Reconnect all of the required and necessary steps in sequential order from beginning to end, and draw the improved process map, below in Figure 12.3. Figure 12:3 Notification Memo Improved Process Map DOE-STD-1217-2020/Rev FEBRUARY 2020 34 Step 4: Update Documentation and Develop Metrics Using the new process, update standard operating procedures and desktop procedures to align with the improved process. Ensure that leadership and employees are aware of the proposed process. Although the survey team and subject matter experts have developed this process there may be resource constraints or impact to other programs with which they are not aware. Additionally, develop qualitative or quantitative metrics to ensure the process is actually successful. Measurements such as time, money, space are all very quantifiable although subjective measures such as employee and customer delight should not be ignored. Step 5: Measure for Success and Return to Step 1. At this stage, the process has been turned over to the responsible process owners and subject matter experts, who will monitor the process for efficiency and effectiveness. Additional support from the survey team may be necessary if the new process experiences problems, or if further optimization is possible or necessary. If this is the case, the 5-step process improvement technique can be repeated, beginning again at Step 1. DOE-STD-1217-2020/Rev FEBRUARY 2020 31 ATTACHMENT 1: RISK BASED ASSESSMENT SCHEDULING PROCESS file://///Doe.local/dfsfr/ORG_AU/AU-50/AU-51/PPM/Conference Room Materials (470_4B)/Survey and Assessments Tech Standard/2019 Rplacement Charts and Notes/DOE-STD-1217-2016 ATTM 1-1 - Risk Based Assessment Scheduling Process.xlsx DOE-STD-1217-2020/Rev FEBRUARY 2020 32 DOE-STD-1217-2020/Rev FEBRUARY 2020 33 DOE-STD-1217-2020/Rev FEBRUARY 2020 34 ATTACHMENT 2: DOE FORM 470.8 SURVEY/INSPECTION REPORT FORM DOE-STD-1217-2020/Rev FEBRUARY 2020 35 ATTACHMENT 3: .SURVEY PREPPARATION AND REPORT CHECKLIST Survey Site: Travel Dates: ______________ Survey Date: ________________ Team Members: Survey Prep TM  ECD COMMENTS Contact Site POC to establish date of assessment (70 days prior) Draft Data Call Memo (65 days prior) Forward Final Data Call Memo to Site POC (50 days prior) Review previous survey report (30 days prior) Review previous areas of Concerns/Findings (30 days prior) Review CAPS (30 days prior) Using previous information and data call develop Site-Specific LOIs for Topical area Areas (20 days prior) Develop survey timeline (15 days prior) Request CPCI Listing from PerSec Request Incident Reports from Security Officer Forward timeline for site approval (10 days prior) Coordinate interviews with site POC (10 days prior) Coordinate performance testing with site POC (10 days prior) Send site final LOIs (5 days prior) In-brief presentation (first day)

Section 31

Conduct assessment activities Out-brief presentation (last day) DOE-STD-1217-2020/Rev FEBRUARY 2020 36 Drafting Report/Review  ECD COMMENTS Initial Draft Team Member: (30 days) Reviewing Team Member: (10 days) Final Reviewing Team Member: (10 days) Team Lead: (5 days) Initial Draft Team Member reconciles Team Lead comments (5 days) Contract POC: (10 days) Team reconciles Contract POC comments (10 days) Program Manager: (10 days) Team reconciles Program Manager comments (10 days) Submit report to Admin for correction and submission for approval Input issues into Survey database (5 days) Input Findings into SSIMS (5 days) Report Attachments  COMMENTS Survey Report Cover Memo (5 days) DOE Form 470.8 Report Form DOE Form 470.1 CSCS DOE Form 470.2 FDAR Open Findings (SSIMS) DOE-STD-1217-2020/Rev FEBRUARY 2020 37 ATTACHMENT 4: SURVEY PLAN TEMPLATE 1. Title of survey 2. Location of facility 3. Purpose of survey 4. Survey dates 5. General site/facility information /description a. Site/Facility data b. Work/activities performed c. Operating organization (contractor) d. S&S interests e. Strategic Partnership Projects or other security activities 6. Scope of survey a. Period of review, including extended observation or data collection if applicable b. Objectives c. Topical areas to be included/excluded and justification for each d. Topical areas with findings from previous surveys, inspections reports, audits and appraisals (e.g. Government Accountability Office (GAO)/ Inspector General (IG)) e. Special areas/items of interest/concern 7. Survey planning and preparation a. Performance tests (associated safety plans) b. Survey guide information c. Pre-survey information 8. Survey conduct—approach and methodology a. Documents to be reviewed b. Performance tests DOE-STD-1217-2020/Rev FEBRUARY 2020 38 c. Individuals to be interviewed d. Sampling activities, including extended observation, shadowing or surveillance if applicable 9. Schedule of activities a. Survey schedule b. In-briefing information c. Coordinating instructions d. Exit briefing e. Schedule for report development 10. Team composition/assignments a. Team members b. Assignments/responsibilities c. Contractor support d. Points of contact at the facility 11. Authority/governing documents a. Directives b. References (unclassified/classified) 12. Survey report format 13. Administration, support, and logistics a. Work facilities b. Transportation c. Computer support d. Administrative support e. Classification support f. Training requirements DOE-STD-1217-2020/Rev FEBRUARY 2020 39 14. Appendices a. Performance tests (including Safety Plans) b. Survey guides c. Forms DOE-STD-1217-2020/Rev FEBRUARY 2020 40 ATTACHMENT 5: NOTIFICATION MEMO DATE: TO: FROM: SUBJECT: Safeguards and Security Periodic Survey (SSPS) The (Surveying Organization) will conduct an SSPS of the (Organization to be Surveyed) during the period of (Date). This will be a comprehensive survey and will be conducted in accordance with (Appendix, Section, Chapter, etc.) of DOE O XXX, (Title). The survey will examine the performance of safeguards and security programs to ensure that S&S measures employed by the facility are adequate for the protection of security assets and interests and will encompass all topical areas on DOE F 470.8, Survey/Inspection Report Form. To aid in the planning process, you are requested to provide the documentation listed in the

Section 32

Attachment. These documents are to be provided to (Survey Team Leader) not later than close of business (Day, Date). In addition, please provide points-of-contact information for each topical area, including pagers/cellphone and phone numbers. The names of (Surveying Organization)’s Survey Team Leader and Topical Leads will be forwarded to your organization under separate cover. Survey activities will begin with an in-briefing at (Time, Date), in (Place). Points of contact representing your organization in each topical area should plan to attend. If you have any questions or require additional information, please contact (Survey Team Leader) on (phone number). DOE-STD-1217-2020/Rev FEBRUARY 2020 41 ATTACHMENT 6: DATA CALL INFORMATION All documentation provided shall include the past 12 months unless otherwise noted. (The following is a list of documentation that may be considered for review during survey conduct. Whether or not to include these documents as part of the data call or to review during the Conduct phase will be determined based on the focus of each topical area supported by the initial risk assessment (Attachment 1), as outlined in the survey plan. The list is not comprehensive; other documents may be available which shall also be considered) a. Program Planning and Management  Organization charts depicting the Safeguards and Security (S&S) management structure and S&S functional structure  Documents depicting responsibilities and authorities of S&S management, including all delegations of authority and designations of Officially Designated Federal Security Authority (ODFSA) and Officially Designated Security Authority (ODSA)  Position descriptions for S&S management  Program Office and local instructions for the implementation of S&S programs  Supplemental documents and guidance for implementing S&S programs  Site/Facility security plan (SP) and any referenced or supplemental plans and documentation  Emergency management and security condition (SECON) plans  Survey reports, inspection reports, Government Accountability Office and Inspector General audit/appraisal reports, self-assessment reports  Staff training records  Contract(s), including Statement of Work  List of all subcontractors and consultants conducting work for the contractor  List of U.S. Department of Energy (DOE) directives and security clauses that have been incorporated into applicable contracts DOE-STD-1217-2020/Rev FEBRUARY 2020 42  Approved and pending equivalencies/exemptions to DOE directives and any deviations to national drivers (e.g., Code of Federal Regulations)  Copy of the facility registration  Applicable memoranda of understanding (MOU)/agreement (MOA)  Completed Foreign Ownership, Control or Influence (FOCI) questionnaire (SF 328)  Key Management Personnel (KMP) list  Dates of all applicable FOCI determinations and copies of any mitigation agreements  A copy of the contractor's records of all contracts and subcontracts involving access authorizations  Vulnerability Analysis (VA) reports  Security Risk Assessment (SRA) reports  Contingency plans  Survey and self-assessment program procedures  Issues management plans and procedures  CAPs and status updates for all open deficiencies  Finding/deficiency corrective action validation and closing procedures  Incidents of Security Concern procedure, including initial notification and inquiry reports

Section 33

 Contract Security Classification Specification (CSCS) forms  Facility Data and Approval Record (FDAR) forms  Copy of the approved Performance Assurance Program Plan  List of essential elements documented in the Performance Assurance program and the testing schedule for each  Documentation of the integrated contractor assurance system DOE-STD-1217-2020/Rev FEBRUARY 2020 43 b. Protective Force (PF)  Organization and function charts  PF general, special and post orders  PF shift schedules and post assignments  PF standard equipment issuance (Security Police Officer (SPO) I, II, III, and Special Response Team (SRT))  PF weapons and ammunition inventories  Weapons maintenance logs  MOU with local law enforcement agencies and documentation of exercises conducted with those agencies  Integration of crisis management personnel into procedures  PF training records which include:  A list of PF personnel who are subject to weapons qualification within 90 days of the start date of the survey  A list of PF personnel who are medically certified to participate in the physical fitness program  All documentation of PF exercises conducted since the last S&S survey  Instructor certification  Job analysis  Job task analyses  Security Emergency Response Plan (SERP)  Security Incident Response Plan (SIRP)  Site/Facility Evacuation Response Plans  Security Contingency Response Plans  Target folders DOE-STD-1217-2020/Rev FEBRUARY 2020 44  Schedule for performance testing (results of recent tests)  Compensatory measures currently in place (including pertinent documentation)  Procedures (administrative, training, non-response-related operational requirements)  Access/badge control  Information containing, at a minimum, policies/procedures for issuing, replacing, and recovering passes/badges  Inventories (since last S&S survey) of passes/badges made, issued, lost, recovered, returned, and destroyed  Shipment security plans  Shipment procedures  In-transit emergency plan  Shipment emergency response plan c. Physical Protection  Organization and function charts  Lock and key records and procedures  Automated access control system records and procedures (including biometric access input) as well as access credential issuances (e.g., keycards, tokens)  Barrier maintenance procedures/records  Property control procedures  Access control procedures  Local performance testing plans and procedures  Physical security system description(s) and location(s)  Intrusion detection system (IDS) maintenance and testing records and procedures  IDS Analysis and Evaluation Report DOE-STD-1217-2020/Rev FEBRUARY 2020 45  Unscheduled alarm reports  Central Alarm Station (CAS)/Secondary Alarm Station (SAS) procedures (interface description)  Emergency response for CAS/SAS recovery  Emergency power systems (uninterruptible power supply system)  Compensatory procedures for equipment outages  Security container documentation and maintenance records  Automated systems description and procedures  Manual  Procedures  Controls  Calibration and testing procedures and records (e.g., X-ray, metal detectors, IDS)  Inspection procedures  Limited Scope Performance Test (LSPT) results d. Information Security  Organization and function charts  Training records  Technical surveillance countermeasure (TSCM) survey reports  Site inventory of accredited systems, showing property tag number, the

Section 34

accrediting authority, and most recent accreditation date for each  Formal assignments of TSCM personnel  TSCM activity support memoranda (if applicable)  Local TSCM implementation guidance  TSCM Officer (TSCMO) service schedules, files, and corrective action reports DOE-STD-1217-2020/Rev FEBRUARY 2020 46  TSCM team equipment maintenance and calibration files  TSCM team training and certification records  Operations Security (OPSEC) Plan  OPSEC procedures  OPSEC program files  Local threat statement  Critical Program Information  Counter-Imagery Program Plan (if applicable)  Number of derivative classifiers and declassifiers  Appointment letters (e.g., Inquiry Officer, custodians)  Training records, reports, and lesson plans  Classification guidance  Classified Matter Protection and Control (CMPC) procedures  Control station procedures  List of classified holdings, including documents, electronic media, and matter  Number of Special Access Programs (SAPs) e. Personnel Security  Local procedures for terminations, leave of absences, reinstating clearances, clearance processing, exit briefing process  Contractor access authorization requests  Sample initial, comprehensive, refresher, and termination briefing materials  Previous findings and CAPs  Reciprocal access authorization documentation  Awareness tools (posters, newsletters) DOE-STD-1217-2020/Rev FEBRUARY 2020 47  Security infraction and violation records  Requests for visit or access approval (notification and approval of incoming and outgoing classified visits records and records of cleared non-DOE personnel granted access to RD)  Written delegation of senior federal official authorized to make determinations on access to Restricted Data by non-DOE personnel in connection with a classified visit  Visitor control logs  Local visitor control procedures  Central Personnel Clearance Index (CPCI) list of individuals overdue for reinvestigation  Drug testing/handling procedures  Drug testing records  Human Reliability Program (HRP) participants  HRP criteria/plans/procedures  Random test procedures  List of individuals on leaves of absence and the associated procedures for tracking  List of inactive classified contracts  List of personnel with access authorizations and the associated contract(s)  List of clearances terminated during the survey period  List of all access authorizations held by the contractor, including all contractors and subcontractors that have cleared employees conducting work at the facility. This list can come from the DOE CPCI of access authorizations held by the contractor. The CPCI and contractor lists, including the current KMP list, shall be compared for discrepancies. f. Insider Threat Program (ITP)  Local Insider Threat Working Group (LITWG) charter DOE-STD-1217-2020/Rev FEBRUARY 2020 48  ITP Standard Operating Procedures (SOP) or other guidance  ITP records management procedures  Name/Position/Title of LITWG Chair  List of LITWG members  ITP Training Records for Cleared Employees  Copies of ITP Training and Awareness Materials g. Foreign Visitors and Assignments  List of foreign visitors from sensitive countries during the survey period  Specific security plans for foreign visitors from sensitive countries  Escort procedures  Local procedures for requesting, processing, and approving visits and assignments

Section 35

 List of foreign visitors or assignees, including hosts, during survey period  Incident reports involving foreign nationals  Requests for foreign national visits  Indices checks  Documentation authorizing approval for specific categories of visits and assignments  Sensitive country listings  Equivalencies/exemptions pertinent to visits and assignments  Personnel assignment agreements h. Nuclear Material Control and Accountability (MC&A)  MC&A plans and procedures  Training records, reports, and lesson plans DOE-STD-1217-2020/Rev FEBRUARY 2020 49  Performance tests  Categorization process documentation  Incident reporting process and procedures  Emergency response plans and facility procedures  Database descriptions  Material Balance Area (MBA) account structure  Material transfer records  Internal control procedures  Nuclear Material Management and Safeguards System (NMMSS) reports  Shipper/receiver difference procedures and records  Material control indicator program  Inventory difference program  Materials containment documentation  Facility procedures  Material access program  Authorization access lists  Search procedures  Material surveillance procedures  Portal monitor records and procedures  Daily administrative check program and procedures  Tamper-indicating device program DOE-STD-1217-2020/Rev FEBRUARY 2020 50 ATTACHMENT 7: SAMPLE LINE OF INQUIRY FORM DOE-STD-1217-2020/Rev FEBRUARY 2020 51 ATTACHMENT 8: PERFORMANCE TEST SAFETY PLAN EXAMPLE PERFORMANCE TEST SAFETY PLAN I, , acknowledge receipt of the attached safety plan. I understand it is my responsibility to become familiar and comply with the contents of this safety plan. Acknowledgment of the receipt of this safety plan is a requirement to participate in or observe this exercise. This page shall be signed and returned no later than . Name Signature Position Date (1) Detection of Contraband and Prohibited Items (Type of Performance Test) (2) Ongoing 365 Days per Year; 24 Hours per Day (Performance Test Date and Time) (3) Detection of Contraband and Prohibited Items, John Doe (Safety Plan Name and Person Preparing) (4) ALL LIMITED SCOPE PERFORMANCE TESTS (LSPTs) WILL BE CONDUCTED IN CONFORMANCE WITH THIS SAFETY PLAN AND ONLY AFTER SPECIFIC APPROVAL TO CONDUCT THE LSPTs HAS BEEN GRANTED BY A RESPONSIBLE U.S. DEPARTMENT OF ENERGY OFFICIAL. PERSONNEL SERVING AS CONTROLLERS WILL BE FULLY QUALIFIED IN ALL ASPECTS OF THE LSPT. Scenario: The ongoing LSPTs are conducted to test the ability of Protective Force (PF) personnel to detect and prevent contraband and prohibited items from being introduced into Limited Areas, Vault- Type Room, Protected Areas, and Material Access Areas. LSPTs will be conducted on X-ray machines, metal detectors, and hand and vehicle searches. Security and non-security personnel will try to enter and exit the above-mentioned areas with contraband and prohibited items. Using personnel with whom PF personnel are unfamiliar will ensure credible and realistic test results. The person attempting to introduce the contraband or prohibited item will use only contraband test items that have been approved by the DOE cognizant security office. Once the entry is initiated, DOE-STD-1217-2020/Rev FEBRUARY 2020 52 the person attempting the entry will only proceed after being cleared to do so by the security officer conducting the search. The persons attempting the entry will wear clothing that would

Section 36

make the concealment of any weapons on their person virtually impossible, and they will keep their hands open and in plain view at all times. The persons attempting to enter or exit any of the aforementioned areas will strictly follow all instructions given by the DOE controller and obey all instructions given by PF personnel. The DOE controller will announce the LSPT to PF personnel once the contraband or prohibited item has been detected/undetected by the PF. The sole purpose of the LSPTs is to evaluate the ability of the PF to detect contraband and prohibited items prior to their release into the aforementioned areas. The LSPTs are not designed to test what actions the PF undertakes once they detect or fail to detect the contraband or prohibited item. (5) IN THE EVENT OF AN ACTUAL SECURITY ALARM OR SECURITY INCIDENT, THE CONTROLLER WILL IMMEDIATELY ANNOUNCE AND CONCLUDE THE LSPT, TAKE POSSESSION OF THE TEST ITEM/CONTAINER, AND FOLLOW ALL INSTRUCTIONS ISSUED BY PF PERSONNEL. Requirements: 1. DOE Controller 2. Person to carry contraband or prohibited item into the area 3. Contraband and prohibited item(s) 4. Support items, such as lunch boxes, purses, notebooks, gym bags, vehicles (6) PF Response: Yes No If a no-notice PF response is desired, check the following measures being taken to ensure safety during the response. Drill announcements will be made on all PF networks immediately after PF response is initiated, and periodically thereafter. X Controller is located in the PF CAS. The PF is informed that an exercise will take place and that they are to follow the safety and health requirements contained in this plan and in the site procedures. This instruction will be provided by site representatives briefing the PF prior to the shift during which the performance test will take place. X Controllers are located at the exercise location. If PF response is not desired, check those measures being taken to preclude response. DOE-STD-1217-2020/Rev FEBRUARY 2020 53 Prior notification of CAS. Prior notification of PF. Presence of non-playing PF personnel briefed on the scenario at the performance test location. X Controller located in the CAS. A second controller will be located in the CAS with a final approved copy of this LSPT Safety Plan and LSPT Safety Briefing. This controller will be able to provide positive identification of the onsite controller and any support personnel participating in the LSPT. The onsite controller will ensure that the CAS controller is physically located in the CAS prior to departure for the area in which the LSPT will be conducted. X Controller located in the immediate vicinity (within sight and hearing of the PF and support personnel) of the LSPT. (7) List other specific safety measures below: 1. All personnel attempting to gain entrance into one of the identified areas will be briefed on the LSPT objectives and how they should conduct themselves during the LSPT. 2. All contraband or prohibited items will be photographed prior to the initiation of the LSPT. 3. All personnel attempting to gain entry or exit with contraband items will be photographed prior to the initiation of the LSPT. 4. All personnel attempting to gain entry or exit with contraband or prohibited items will be instructed to keep their hands in plain view, not to make any sudden moves, and comply with all instructions given by PF personnel.

Section 37

5. Only epoxy–encased, DOE cognizant security office-approved test weapons will be used in LSPTs requiring weapons. 6. All support personnel attempting to gain entrance or exit with contraband or prohibited items will be briefed and required to read and sign the attached rules of exercise. (8) Performance Test Boundaries: X Applicable The immediate area of the security post where the LSPT is being conducted. X Not applicable If applicable, describe the performance tests boundaries and the restrictions on performance test participant movements in detail: DOE-STD-1217-2020/Rev FEBRUARY 2020 54 (9) Off-Limit Areas: Applicable X Not applicable If applicable, describe the off-limit areas and how they will be designated: (10) Safety Equipment: Controller Radios PF Radios Orange Vests “Glow Sticks” First Aid Kit Other required safety equipment: (11) Specific Safety Hazards Not Covered Elsewhere: Applicable X Not applicable These LSPTs are being conducted with armed PF personnel. As with all such exercises, the remote possibility exists that weapons may be drawn if the exercise plan is not adhered to, or if PF personnel are not properly trained. However, because of the constraints placed upon the exercise controllers by this plan and the level of preparation of the DOE participants, the level of risk is actually below that experienced during normal day-to-day operations. (12) Radiation Safety Provisions: Applicable X Not applicable If yes, check those applicable to this LSPT: Personnel participating in the LSPT have been briefed concerning radiation safety requirements for the area with which the LSPT will be conducted. Personnel will be continuously escorted while in the radiation areas in which the LSPT will be conducted. DOE-STD-1217-2020/Rev FEBRUARY 2020 55 List any other specific radiation safety provisions for this LSPT: (13) Personnel Assignments (list below): The names of the DOE controller and the person carrying the contraband or prohibited items will be filled in prior to conducting the LSPT. (14) Protective Force Appendix Required: Yes X No (15) DOE Safety Review: List any pertinent safety procedures concerning this LSPT that are not addressed in this plan. Normally, the PF will not be notified in advance of the specifics of the LSPT being conducted. The shift captain will be notified upon termination of the LSPT. APPROVALS: Director, Safety and Health Organization DOE Cognizant Security Office Date Contractor Safety and Health Representative Date Director, Security Organization DOE Cognizant Security Office Date DOE-STD-1217-2020/Rev FEBRUARY 2020 56 ATTACHMENT 9: PERFORMANCE TEST PLAN (1) TEST OBJECTIVE This performance test is designed to test individual employee response to finding an unattended Secret Restricted Data (SRD) document, verify compliance with the notification process to Classified Document Control Office (CDCO), and verify PF compliance with the procedure for responding to this incident. (2) SCENARIO DESCRIPTION A simulated SRD document will be left unattended in an area accessed by “L”-cleared employees. This document will be marked as a formal SRD document. Personnel recovering and responding to the simulated classified document shall have no indication that the contents of the document are actually unclassified. (3) TEST METHODOLOGY AND EVALUATION CRITERIA

Section 38

a. A simulated SRD document consisting of approximately five pages of unclassified text and drawings shall be placed on the table next to a copy machine located in Building xxx, Room zzz. The document shall be placed in the designated location at approximately 7:30 am. b. Upon notification of the unattended “classified” document, the CDCO will verify that the individual finding the document completed the following actions: a) Xxxx b) Xxxx c) Xxxx The Document Control Center shall also verify that the PF completed the following actions: a) Xxxx b) Xxxx c) Xxxx (4) PASS/FAIL CRITERIA In order to successfully complete the performance test, the following must occur:  CDCO is notified within three hours of placement.  Individual locating the unattended document adheres to all protection and notification requirements.  PF officer responding to the incident adheres to all protection and notification requirements. DOE-STD-1217-2020/Rev FEBRUARY 2020 57 (5) TEST CONTROLS The following controls will be adhered to during conduct of this performance test.  Only survey team members involved with the conduct and evaluation of this performance test will be made aware of all information surrounding the conduct of the test.  There are no additional safety requirements for this performance test. All current facility safety requirements will be adhered to during this performance test.  This will be a no-notice exercise; therefore, the surveyed organization will not be given any information regarding the conduct of this performance test prior to the test.  The simulated SRD document used during this exercise will consist of an unclassified document marked at the SRD level with all appropriate markings and covers. There will be no indications to a casual observer that the document is not classified. (6) RESOURCE REQUIREMENTS The following resources are needed to conduct this performance test.  Simulated SRD document  Identified location to place the document  Three survey team members to be assigned the following: 1. Monitor the document 2. Monitor the PF response 3. Monitor the CDCO (7) TEST COORDINATION REQUIREMENTS No coordination requirements are necessary since this is a no-notice exercise. Survey team members monitoring the various aspects of the performance test will identify themselves to participants only when it becomes necessary. (8) OPERATIONAL IMPACT(S) OF TESTING PROGRAM Since this performance test is being conducted during normal duty hours, there will be no need for additional funds for overtime payments, and there is no expectation of a loss of productive time for personnel who will be participating in the exercise. DOE-STD-1217-2020/Rev FEBRUARY 2020 58 (9) COMPENSATORY MEASURES There are no compensatory measures required for the conduct of this exercise. (10) COORDINATION AND APPROVAL PROCESS The following steps and documentation will be followed in the conduct of this exercise.  This test plan will be approved by the survey team leader prior to the conduct of the performance test. Approval of this test plan will be documented by the Survey Team Leader’s signature and date on this test plan.  A participant log containing name, job title, organization, telephone number, and date will be completed by all participants of this exercise.  A data-collection form containing the date, performance test type, name of evaluator, and chronological description of actions observed will be completed by all survey team members

Section 39

participating in the evaluation of this performance test. (11) REFERENCES The following references will be used in the conduct and evaluation of this performance test.  DOE O XXX.X, Information Security  Information Security Standard Operating Procedure #  PF Standard Operating Procedure #  PF Post Order # SURVEY TEAM LEADER: DATE (Signature of Approval) DOE-STD-1217-2020/Rev FEBRUARY 2020 59 ATTACHMENT 10: SAMPLE SURVEY REPORT TEMPLATE SAMPLE INITIAL/PERIODIC SURVEY REPORT FORMAT A. Report Format. The report may be formatted with a cover page, table of contents, ratings, executive summary, introduction, description of facility and interests, narrative (including topical area description of the program), conclusions, synopsis of findings, and appendices. The DOE 470.8, Survey/Inspection Report Form, if used, shall be included in the report. B. Report Content. 1. Initial and Periodic Survey Reports and Self-Assessment Reports. Reports shall contain the following items. (a) An executive summary containing: i. The scope, methodology, period of coverage, duration, date of the exit briefing to management; ii. A brief overview of the facility, function, scope of operations, and contractual information (e.g., contract number, award and expiration dates, contract type, identification of security clauses, and overall scores assigned to the most recent contract appraisal); iii. A brief synopsis of major strengths and weaknesses that impact the effectiveness of the facility’s overall S&S program, including identification of any topical areas rated less than satisfactory; iv. The overall composite facility rating with supporting rationale; and v. A reference to a list of findings identified during the survey or self- assessment. (b) An introduction containing: i. The scope, methodology, period of coverage, duration, date of the exit briefing to management; and ii. A description of the facility, its function and scope of operations, security interests, and contractual information (e.g., contract number, award and expiration dates, contract type, identification of security clauses, and overall scores assigned to the most recent contract appraisal). (c) Narrative for all rated topical area and sub-topical areas that includes: i. A description of the site’s implementation of the topical area/sub-topical area element; DOE-STD-1217-2020/Rev FEBRUARY 2020 60 ii. The scope of the evaluation; iii. A description of activities conducted; iv. The evaluation results and associated issues (including other Department elements or other government agency (OGA) review or inspection results related to the topical areas/sub-topical areas that were included in the survey); v. The identification of all findings, including new and previously identified open findings, regardless of source (e.g., EA, IG, GAO), and their current corrective action status; and vi. An analysis that provides a justification and rationale of the factors responsible for the rating. (d) Attachments, including, for example: i. A copy of the current DOE F 470.2, Facility Data and Approval Record (FDAR); ii. A listing of all active DOE F 470.1, Contract Security Classification Specification (CSCS), or DD F 254, Contract Security Classification Specification; iii. A listing of all new findings resulting from the survey/self-assessment; iv. A listing of all previous findings that are open, to include the current status of corrective actions;

Section 40

v. A listing of team members including names, employer, and their assigned area(s) of evaluation; and vi. A listing of all source documentation used to support the survey/self- assessment conduct and results. Narrative: The narrative section of the report shall clearly describe the surveyed facility – its Safeguards and Security (S&S) interests and activities, its protective measures, and the status of the S&S program at the time the survey or self-assessment activity was completed. The report shall also explain how the protection measures were evaluated. Use of statistical data will help describe the facility’s S&S interests and the survey effort. Such data might include numbers of employees with each level of access authorization, the number of classified documents in each level and category, and the number of documents sampled for compliance/performance.  The report shall reflect the compliance and performance segments of the survey. Reports shall explain what the S&S program is supposed to do, what was surveyed, DOE-STD-1217-2020/Rev FEBRUARY 2020 61 how the survey data was compiled (e.g., extended data collection or within a few days), and what was found. Suggested content includes:  The status (e.g., approved, pending, under revision) of any required planning documents (e.g., Facility/Site Security Plan, Material Control and Accountability (MC&A) plans, local implementation procedures, etc.).  All new findings must be identified. Open findings from the previous survey shall be identified in the narrative portion of the survey report. Open findings maintain their original finding number. A new finding, including one that is a repeat of a closed finding, receives a new SSIMS-compatible finding number. When a finding is a repeat of a closed finding, reference to the closed finding shall be included in the body of the narrative.  Findings, observations, opportunities for improvement, and suggestions, along with supporting data for each, shall be clearly described. The term “finding” refers to a factual statement of issues and deficiencies representing a failure to meet a documented legal, regulatory, performance, compliance, or other applicable requirement found during the survey or self- assessment.  Descriptions of the facility's strengths and weaknesses shall correlate to the survey results and establish the basis for the ratings. The survey report shall reflect validated and defensible ratings. The narrative description shall be consistent with and support the composite and topical area ratings (including “Does Not Apply”).  The report shall identify findings corrected on the spot. These findings and corrective actions shall be clearly described in the narrative.  The status of corrective actions for open findings and findings from the previous survey shall be included in the narrative.  A concluding analysis of each topical area shall be included in the narrative.  Reasons for a less-than-satisfactory rating shall be explained in detail. DOE-STD-1217-2020/Rev FEBRUARY 2020 62 ATTACHMENT 11: CORRECTIVE ACTION AND CAUSAL ANALYSIS PART I CORRECTIVE ACTION ELEMENTS Action Plan Cover Sheet Finding Number: Facility Code: Responsible Program Office: Topical Area: Sub-topical Area: Reference(s) (i.e., Orders, Requirements, etc.): Description of Deficiency: Information above provided by Surveying organization PART II Root Cause Analysis Process Used: Cause Code(s):

Section 41

Corrective Action Description: DOE-STD-1217-2020/Rev FEBRUARY 2020 63 Estimated Completion Date: Revised Completion Date: Reason for Revised Completion Date: Completion Date: Responsible Manager: Print Name Signature Date DOE-STD-1217-2020/Rev FEBRUARY 2020 64 Instructions for Completing Corrective Action Plan Cover Sheet The Surveying Organization will fill in Part I of the Corrective Action Plan Cover Sheet. The organization assigned the finding will be responsible for completing Part II of the form. PART II Root Cause Analysis Process Used: Identify the technique used to identify the Cause Code. There are a number of acceptable tools to include but not limited to, the five whys, fishbone, tree, failure modes effects analysis. The preferred tool is the fishbone chart as well as using the causal analysis tree to help in identifying the root cause outlined below. Please attach the completed tool(s) showing how the root cause was identified. Cause Code(s): Cause code identified by Root Cause Analysis, code, description, and examples are available in DOE-STD-1197-2011 Occurrence Reporting Causal Analysis. More than one code is acceptable but not common, except if one of the codes is human error, which is generally supported by a second code. Corrective Action Description: High-level description of corrective action to include compensatory measures required. Milestones (numbered) are to be included in the Corrective Action Description section of the cover sheet, or at a minimum, reference that there are “X” number of milestones to be met in completing the corrective action. Estimated Completion Date: First expected completion date assuming all resources are available and the corrective action activities are not disrupted. Revised Completion Date: Update completion date, initial form submission will not have information in this block, however additional submissions may include adjustments required by a delay in corrective action efforts. Reason for Revised Completion Date: A brief narrative on why the date must be revised, not for the purposes of approval by the surveying organization but for informational purposes. Completion Date: Date the corrective action was completed, necessary so surveying organization can review the effectiveness of the efforts implemented. Responsible Manager: Information by responsible manager for completing the corrective action. Print Name Signature Date DOE-STD-1217-2020/Rev FEBRUARY 2020 65 CORRECTIVE ACTION PLAN MILESTONES SHEET Finding Number: Date: Milestone: No.: Milestone Description: Deliverables/Completion Criteria: Milestone Due Date: Date Milestone Completed: Milestone Manager (print and sign): Milestone: No.: Milestone Description: Deliverables/Completion Criteria: Milestone Due Date: Date Milestone Completed: Milestone Manager (print and sign): DOE-STD-1217-2020/Rev FEBRUARY 2020 66 Instructions for Completing Corrective Action Plan Milestones Sheet CORRECTIVE ACTION ELEMENTS Action Plan Milestones Instructions SECTION INSTRUCTIONS Finding Number Enter the finding number. Milestone Number Enter milestone number (consecutive starting with 1). Milestone Description  Write milestones with clear deliverables that solve the problem. Ensure that milestones address and correct the deficiency.  Limit individual milestone instructions to brief, concise statements describing logical segments of the specified

Section 42

milestone. Include milestones for recurrence control.  Write realistic and achievable milestones that can be verified.  Do not overextend milestones beyond your control. Ensure that resources are available.  Identify the milestone manager responsible for completion of each milestone and the respective program element.  Identify only one milestone if only a single action is required to correct the deficiency.  If completion of milestones is required by persons outside of the responsible manager’s authority, the responsible manager coordinates the milestone with the supporting program element. Deliverables/ Completion Criteria Include completion criteria that are discrete, finite, and verifiable. Milestone Due Date Enter the due date for each milestone. Date Milestone Completed Enter the actual date each milestone was completed. Milestone Manager Milestone managers sign for concurrence of each assigned milestone. DOE-STD-1217-2020/Rev FEBRUARY 2020 67 Root Cause Scenario Background: Carl has been a DOE employee for about 3 years, working in an office administrative position. Although he has a Q clearance, he very rarely handled classified documents in his position. Another employee in his organization, the Classified Document Control Station (CDCS) custodian, was retiring soon and had given two weeks’ notice. The position needed to be filled immediately due to the high volume of access the CDCS goes through each day. Shortly after his retirement, an annual inventory of all classified documents was scheduled to take place. The Director tasked Carl’s supervisor to fill this position as soon as possible. Since Carl has a clearance and is familiar with the organization, he was offered the new position as the CDCS Custodian. Carl was somewhat familiar on how to handle classified matter, but had not gone through CMPC training for CDCS training since there were no classes held at the time. Given his 3 years with DOE, the supervisor believed this would not be an issue and filling the position was more important due the upcoming inventory. The Director was not aware of the lack of training Carl had. Incident: Carl has now been in this new position for about 3 weeks, and has been assisting with the inventory of the classified documents stored in the security containers in the CDCS. Carl was leaving early on Wednesday for a long weekend and would be out until the Monday of the following week. On his way out he told another employee, who was working on the inventory, that the SF 700 Part 2s were being stored in his desk drawer, in case they needed to access a security container. Problem: SF 700 Part 2 was stored in an employee’s desk drawer instead of a security container. How the Root Cause Analysis was determined for this finding: A Safeguards and Security Periodic Survey was conducted and a finding was assigned with a CAP response due within 30 days after survey date (example provided). The team involved in determining the root cause of the finding, consisted of the elements HSO, AHSO, and management not directly involved with the finding. The team reviewed and discussed the scenario above. Interviews with the employees involved helped obtain additional information of the events leading up to the issuance of a finding. The team collected all the information and used the Root Cause Tool 1 (see example) to determine the possible topical area where the root cause may fall under

Section 43

(i.e. A4 Management), which can be determined through group discussion. The Casual Analysis Table was used to assist with breaking down the root cause by topic. There were sections that did not apply to this situation, so the team placed a Not Applicable (N/A) in those sections. The team continued to work their way through all the levels of the table (A1-A7, and down through the “B’s” and “C’s” of each of those sections). Once the team has exhausted all possibilities, Root Cause Tool 1 was then complete. In filling in Tool 1, the group noticed that there is the potential to have DOE-STD-1217-2020/Rev FEBRUARY 2020 68 more than one root cause for each section (see ‘A4’ in example). If this happens then capture all suspected causes that apply. After completing Root Cause Tool 1, the team analyzed the information to select the top or most critical issues. Once those were established, we transferred the selections over to the Root Cause Tool 2 table under ‘Suspected Cause.’ The team then rated the Suspected Causes for ‘Areas of Impact’ in a scale of 1-5 (5 = Highest impact; 1 = Lowest impact). Once completed, we totaled up the ratings assigned to determine the overall score that had the greatest impact, giving us our root cause. If there are two or more areas of impact that have the same scoring number then the Subject Matter Expert and the team shall discuss which area of impact outweighs the other. For example, if it is a matter of mission vs. resources, the team may decide to use the Mission Area of Impact number versus the resource number for this CAP. If the same finding occurs in the following year, then the organization may decide to use the resource areas of impact as the root cause for the finding. For this reason, all records that were used to determine root cause shall be retained to document the analysis that was conducted for each root cause. DOE-STD-1217-2020/Rev FEBRUARY 2020 69 Figure ATTM 11.1 Blank Root Cause Analysis Tool 1Template DOE-STD-1217-2020/Rev FEBRUARY 2020 70 Figure ATTM 11. 2 Example of a Completed Root Cause Tool 1 DOE-STD-1217-2020/Rev FEBRUARY 2020 71 Figure ATTM 11. 3 Blank Root Cause Tool 2 Template Suspected Cause Areas of Impact Mission Resource Quality Safety/Envir. Total Steps: 1. Input ‘Suspected Cause’ from Root Cause Tool 1 2. Rate the impact (1-5 (5 = Highest impact; 1 = Lowest impact)) of each cause for each ‘Area of Impact’ (use ‘N/A’ if not applicable) 3. Total the ratings for an overall score to determine cause with greatest impact Definitions Mission – the overall program or organization mission agenda Resources – budget and personnel are typically referenced as resources; however, other items may also apply (e.g. hardware/equipment) Quality – to the level of work Safety/Environment – Affecting ability to work in ideal conditions, or impact to public safety DOE-STD-1217-2020/Rev FEBRUARY 2020 72 Figure 11.4 Example of a Completed Root Cause Tool 2 Suspected Cause Areas of Impact Mission Resource Quality Safety/ Envir. Total Sufficient training was not available. (B1,C02) 5 N/A N/A N/A 5 Supervisor did not communicate with the Director the lack of training the employee had with CDCS responsibilities. (B4,C06) 5 2 4 N/A 11 Lack of manpower rushed the hiring process; hiring underqualified employee. (B2,C03) 4 3 5 N/A 12 Employee ignored the policy of securing the SF- 700 just for convenience (employee Negligence). (B2,C02)

Section 44

5 N/A 4 1 10 Steps: 1. Input ‘Suspected Cause’ from Root Cause Tool 1 2. Rate the impact (1-5 (5 = Highest impact; 1 = Lowest impact)) of each cause for each ‘Area of Impact’ (use ‘N/A’ if not applicable) 3. Total the ratings for an overall score to determine cause with greatest impact Definitions DOE-STD-1217-2020/Rev FEBRUARY 2020 73 Mission – the overall program or organization mission agenda Resources – budget and personnel are typically referenced as resources; however, other items may also apply (e.g. hardware/equipment) Quality – to the level of work Safety/Environment – Affecting ability to work in ideal conditions or impact to public safety DOE-STD-1217-2020/Rev FEBRUARY 2020 75 SAFEGUARDS AND SECURITY SURVEY AND SELF-ASSESSMENT TOOLKIT Introduction This Toolkit was created to augment the Safeguards and Security (S&S) Survey and Self- Assessment Technical Standard by providing a variety of samples and tools that may be used to complement the overall survey/self-assessment process. The Toolkit is not meant to be all-inclusive, but rather to provide a starting point that can be expanded and built upon. The Toolkit is divided into three sections: Planning, Conduct, and Post-Survey Activities. The Planning section provides tools associated with survey notification, planning, and in- briefings. The Conduct section is broken down into topical areas and their respective sub- topical areas. Each topical area contains information, such as areas to be considered in the survey, sample interview questions, etc., that may assist the surveyor in conducting the survey. The Post-Survey Activities section includes sample survey formats, exit briefing slides, transmittal memos, sample CAPs, and DOE F 470.8, Survey/Inspection Report. Planning Tools This section addresses the logistics and notifications associated with conducting a survey or self- assessment and provides sample documents for survey notification, planning and in-briefings. The following specific areas are addressed: Sample In-Briefing Sample Survey Plan Format Documents For Possible Review Sample Notification Memos Sample Accommodation Request DOE-STD-1217-2020/Rev FEBRUARY 2020 76 A.2.1.1 Sample In-Briefing (Customize for specific survey objectives, activities, etc.) DOE-STD-1217-2020/Rev FEBRUARY 2020 77 DOE-STD-1217-2020/Rev FEBRUARY 2020 78 DOE-STD-1217-2020/Rev FEBRUARY 2020 79 A.2.1.2 Sample Survey Plan Format Title of survey Location of facility Purpose of survey Survey dates General facility information /description Facility data Work/activities performed Operating organization (contractor) S&S interests Strategic Partnership Projects or other security activities Scope of survey Period of review, including extended observation or data collection if applicable Objectives DOE-STD-1217-2020/Rev FEBRUARY 2020 80 Topical areas to be included/excluded and justification for each Topical areas with findings from previous surveys, inspections reports, audits and appraisals (e.g. Government Accountability Office (GAO)/ Inspector General (IG)) Special areas/items of interest/concern Survey planning and preparation Performance tests (associated safety plans) Survey guide information Pre-survey information Survey conduct—approach and methodology Documents to be reviewed Performance tests Individuals to be interviewed Sampling activities, including extended observation, shadowing or surveillance if applicable

Section 45

Schedule of activities Survey schedule In-briefing information Coordinating instructions Exit briefing Schedule for report development Team composition/assignments Team members Assignments/responsibilities Contractor support Points of contact at the facility Authority/governing documents DOE-STD-1217-2020/Rev FEBRUARY 2020 81 Directives References (unclassified/classified) Survey report format Administration, support, and logistics Work facilities Transportation Computer support Administrative support Classification support Training requirements Appendices Performance tests (including Safety Plans) Survey guides Forms A.2.1.3 Documents for Possible Review The following is a list of documentation that may be considered for review during survey conduct. Whether or not to include these documents as part of the data call or to review during the Conduct phase will be determined based on the focus of each topical area, as outlined in the survey plan. The list is not comprehensive; other documents may be available which shall also be considered. Program Planning and Management Organization charts depicting the Safeguards and Security (S&S) management structure and S&S functional structure Documents depicting responsibilities and authorities of S&S management, including all delegations of authority and designations of Officially Designated Federal Security Authority (ODFSA) and Officially Designated Security Authority (ODSA) Position descriptions for S&S management Program Office and local instructions for the implementation of S&S programs DOE-STD-1217-2020/Rev FEBRUARY 2020 82 Supplemental documents and guidance for implementing S&S programs Facility/site security plan (SP) and any referenced or supplemental plans and documentation Emergency management and security condition (SECON) plans Survey reports, inspection reports, Government Accountability Office and Inspector General audit/appraisal reports, self-assessment reports Staff raining records Contract(s), including Statement of Work List of all subcontractors and consultants conducting work for the contractor List of U.S. Department of Energy (DOE) directives and security clauses that have been incorporated into applicable contracts Approved and pending equivalencies/exemptions to DOE directives and any deviations to national drivers (e.g., Code of Federal Regulations) Copy of the facility registration Applicable memoranda of understanding (MOU)/Agreement (MOA) Completed Foreign Ownership, Control or Influence (FOCI) questionnaire (SF 328) Key Management Personnel (KMP) list Dates of all applicable FOCI determinations and copies of any mitigation agreements A copy of the contractor's records of all contracts and subcontracts involving access authorizations Vulnerability Analysis (VA) reports Security Risk Assessment (SRA) reports Contingency plans Survey and self-assessment program procedures Issues management plans and procedures CAPs and status updates for all open deficiencies Finding/deficiency corrective action validation and closing procedures Incidents of Security Concern procedure, including initial notification and inquiry reports DOE-STD-1217-2020/Rev FEBRUARY 2020 83 Contract Security Classification Specification (CSCS) forms Facility Data and Approval Record (FDAR) forms Copy of the approved Performance Assurance Program Plan

Section 46

List of essential elements documented in the Performance Assurance program and the testing schedule for each Documentation of the integrated contractor assurance system Protective Force (PF) Organization and function charts PF general, special and post orders PF shift schedules and post assignments PF standard equipment issuance (Security Police Officer (SPO) I, II, III, and Special Response Team (SRT)) PF weapons and ammunition inventories Weapons maintenance logs MOU with local law enforcement agencies and documentation of exercises conducted with those agencies Integration of crisis management personnel into procedures PF training records which include: A list of PF personnel who are subject to weapons qualification within 90 days of the start date of the survey A list of PF personnel who are medically certified to participate in the physical fitness program All documentation of PF exercises conducted since the last S&S survey Instructor certification Job analysis Job task analyses Security Emergency Response Plan (SERP) DOE-STD-1217-2020/Rev FEBRUARY 2020 84 Security Incident Response Plan (SIRP) Facility Evacuation Response Plans Security Contingency Response Plans Target folders Schedule for performance testing (results of recent tests) Compensatory measures currently in place (including pertinent documentation) Procedures (administrative, training, non-response-related operational requirements) Access/badge control Information containing, at a minimum, policies/procedures for issuing, replacing, and recovering passes/badges Inventories (since last S&S survey) of passes/badges made, issued, lost, recovered, returned, and destroyed Shipment security plans Shipment procedures In-transit emergency plan Shipment emergency response plan Physical Protection Organization and function charts Lock and key records and procedures Automated access control system records and procedures (including biometric access input) as well as access credential issuances (e.g., keycards, tokens) Barrier maintenance procedures/records Property control procedures Access control procedures Local performance testing plans and procedures Physical security system description(s) and location(s) DOE-STD-1217-2020/Rev FEBRUARY 2020 85 IDS maintenance and testing records and procedures IDS Analysis and Evaluation Report Unscheduled alarm reports Central Alarm Station (CAS)/Secondary Alarm Station (SAS) procedures (interface description) Emergency response for CAS/SAS recovery Emergency power systems (uninterruptible power supply system) Compensatory procedures for equipment outages Security container documentation and maintenance records Automated systems description and procedures Manual Procedures Controls Calibration and testing procedures and records (e.g., X-ray, metal detectors, IDS) Inspection procedures Limited Scope Performance Test (LSPT) results Information Security Organization and function charts Training records Technical surveillance countermeasure (TSCM) survey reports Site inventory of accredited systems, showing property tag number, the accrediting authority, and most recent accreditation date for each Formal assignments of TSCM personnel TSCM activity support memoranda (if applicable) Local TSCM implementation guidance TSCMO service schedules, files, and corrective action reports DOE-STD-1217-2020/Rev FEBRUARY 2020

Section 47

86 TSCM team equipment maintenance and calibration files TSCM team training and certification records Operations Security (OPSEC) Plan OPSEC procedures OPSEC program files Local threat statement Critical Program Information Counter-Imagery Program Plan (if applicable) Number of derivative classifiers and declassifiers Appointment letters (e.g., Inquiry Officer, custodians) Training records, reports, and lesson plans Classification guidance Classified Matter Protection and Control (CMPC) procedures Control station procedures List of classified holdings, including documents, electronic media, and matter Number of Special Access Programs (SAPs) Personnel Security Local procedures for terminations, leave of absences, reinstating clearances, clearance processing, exit briefing process Contractor access authorization requests Sample initial, comprehensive, refresher, and termination briefing materials Previous findings and CAPs Reciprocal access authorization documentation Awareness tools (posters, newsletters) Security infraction and violation records DOE-STD-1217-2020/Rev FEBRUARY 2020 87 Requests for visit or access approval (notification and approval of incoming and outgoing classified visits records and records of cleared non-DOE personnel granted access to RD) Written delegation of senior federal official authorized to make determinations on access to Restricted Data by non-DOE personnel in connection with a classified visit Visitor control logs Local visitor control procedures Central Personnel Clearance Index (CPCI) list of individuals overdue for reinvestigation Drug testing/handling procedures Drug testing records Human Reliability Program (HRP) participants HRP criteria/plans/procedures Random test procedures List of individuals on leaves of absence and the associated procedures for tracking List of inactive classified contracts List of personnel with access authorizations and the associated contract(s) List of clearances terminated during the survey period List of all access authorizations held by the contractor, including all contractors and subcontractors that have cleared employees conducting work at the facility. This list can come from the DOE CPCI of access authorizations held by the contractor. The CPCI and contractor lists, including the current KMP list, shall be compared for discrepancies. Foreign Visits and Assignments List of foreign visitors from sensitive countries during the survey period Specific security plans for foreign visitors from sensitive countries Escort procedures Local procedures for requesting, processing, and approving visits and assignments List of foreign visitors or assignees, including hosts, during survey period Incident reports involving foreign nationals DOE-STD-1217-2020/Rev FEBRUARY 2020 88 Requests for foreign national visits Indices checks Documentation authorizing approval for specific categories of visits and assignments Sensitive country listings Equivalencies/exemptions pertinent to visits and assignments Personnel assignment agreements Nuclear Material Control and Accountability (MC&A) MC&A plans and procedures Training records, reports, and lesson plans Performance tests Categorization process documentation Incident reporting process and procedures Emergency response plans and facility procedures Database descriptions Material Balance Area (MBA) account structure

Section 48

Material transfer records Internal control procedures Nuclear Material Management and Safeguards System (NMMSS) reports Shipper/receiver difference procedures and records Material control indicator program Inventory difference program Materials containment documentation Facility procedures Material access program DOE-STD-1217-2020/Rev FEBRUARY 2020 89 Access authorization lists Search procedures Material surveillance procedures Portal monitor records and procedures Daily administrative check program and procedures Tamper-indicating device program DOE-STD-1217-2020/Rev FEBRUARY 2020 90 Sample Notification Memos A.2.2.1 Notification and Data Call DATE: TO: FROM: SUBJECT: Notification and Data Call Request – S&S Survey of XYZ Facility This memorandum is to formally notify you that a representative of the (Surveying Organization) will conduct a S&S survey of the XYZ facility and its satellite offices during the period (Date–Date), in accordance with the requirements of DOE O XXX, (Title), (Appendix, Section, Chapter, etc.). The topical areas to be evaluated include:  Program Planning and Management  Protective Force  Physical Security  Information Protection  Personnel Security  Foreign Visits and Assignments  Nuclear Materials Control and Accountability. A list of personnel participating in the survey is reflected in Attachment 1. The Survey Team Leader is John Doe. This survey involves a review and evaluation of the S&S program as implemented by the XYZ facility. System performance tests will be conducted during this survey in several topical areas. Attachment 2 contains the data call. Please ensure the data call items are available for the survey team’s review no later than (Date). Items can be sent electronically to the Survey Team Leader or in hardcopy form to Room XXX, Building XXX. The in-briefing will be held on (Day, Date), in Room XXX, Building XXX. The exit briefings are scheduled for (Day, Date), in (place) at time(s) to be announced at a later date. If you or your staff have any questions or require additional information, please contact John Doe on (phone number) or by pager (pager number). 2 Attachments DOE-STD-1217-2020/Rev FEBRUARY 2020 91 A.2.2.2 Safeguards and Security Periodic Survey DATE: TO: FROM: SUBJECT: Safeguards and Security Periodic Survey (SSPS) The (Surveying Organization) will conduct an SSPS of the (Organization to be Surveyed) during the period of (Date–Date). This will be a comprehensive survey and will be conducted in accordance with (Appendix, Section, Chapter, etc.) of DOE O XXX, (Title). The survey will examine the performance of safeguards and security programs to ensure that S&S measures employed by the facility are adequate for the protection of security assets and interests and will encompass all topical areas on DOE F 470.8, Survey/Inspection Report Form. To aid in the planning process, you are requested to provide the documentation listed in the Attachment. These documents are to be provided to (Survey Team Leader) not later than close of business (Day, Date). In addition, please provide points-of-contact information for each topical area, including pagers/cellphone and phone numbers. The names of (Surveying Organization)’s Survey Team Leader and Topical Leads will be forwarded to your organization under separate cover. Survey activities will begin with an in-briefing at (Time, Date), in (Place). Points of

Section 49

contact representing your organization in each topical area shall plan to attend. If you have any questions or require additional information, please contact (Survey Team Leader) on (phone number). Attachment DOE-STD-1217-2020/Rev FEBRUARY 2020 92 (Sample Attachment – Documentation Request) Attachment 1 All documentation provided shall include the past 12 months unless otherwise noted. Program Planning and Management Organization chart(s) or listings with brief description of organizations functions and responsibilities Current site security plan with all referenced or supplemental plans Recent self-assessment report(s) Copy of findings/CAP tracking procedures Current status of all open and closed findings/CAPs since the last survey (including Office of Independent Enterprise Assessments, Government Accountability Office and Inspector General) List of and current status of all approved policy equivalencies and exemptions and any approved deviations from national policy (e.g., Code of Federal Regulations) List of all subcontractors performing work (name of company, contract number, names of individuals with access authorizations) Copies of all CSCS and FDAR forms related to the facility clearance Protective Force Facility security plans Emergency security operation procedures Security emergency response plan Memoranda of Agreement/Understanding (e.g., with local law enforcement) Physical Protection Security systems test procedures Security systems maintenance procedures Lock and key records and procedures Access control procedures DOE-STD-1217-2020/Rev FEBRUARY 2020 93 Unscheduled alarm reports for the past three months Information Security List of locations where classified matter is stored and the name and telephone number of the responsible custodian List of locations where classified matter is used/processed List of total number of classified materials and documents in accountability, including level and category OPSEC plans All training materials to support the OPSEC program (have available on request) All documents that support OPSEC briefings for contractor personnel (have available on request) All other internal program procedures that support OPSEC List of derivative classifiers Personnel Security List of all assigned (cleared) employees/subcontractors who have traveled to sensitive countries (official and unofficial) List of all visits and assignments of foreign nationals List of all subcontractors List of uncleared visitors List of outgoing classified visits List of all incoming classified visitors List of HRP participants List of terminated clearances (including name, date termination statement signed, date clearance terminated, CPCI number) Foreign Visits and Assignments List of visits List of foreign national (FN) visitors from sensitive countries DOE-STD-1217-2020/Rev FEBRUARY 2020 94 Specific security plans for FNs visiting from sensitive countries Escort procedures Local procedures for requesting, processing, and approving visits and assignments Nuclear MC&A Categorization process documentation Material Balance Area account structure Inventory difference program plans MC&A plan/procedures (may be part of site security plan or separate document(s)) DOE-STD-1217-2020/Rev FEBRUARY 2020 95 A.2.2.3 Initial Safeguards and Security Survey Date: To: From: Subject: S&S Survey of XYZ Company

Section 50

This memorandum confirms informal arrangements between (Surveying Office) and (Organization to be Surveyed) Safeguards and Security Organization personnel that established (Date–Date) as the dates for the (Surveying Office) S&S survey of the (Organization to be Surveyed) facility. The survey is conducted in accordance with Title 48 Code of Federal Regulations Subpart 952.204.73 (c) and the requirements of DOE O XXX, (Title), (Appendix, Section, Chapter, etc.). An informal and brief preliminary meeting is requested for (Date, Time) with S&S management and selected survey personnel. The survey process will be discussed during this meeting. Enclosure 1 is a pre-survey questionnaire/data call that identifies the preliminary information required in the topical areas to be surveyed. Please provide this information to (Surveying Office) by (Date). This material will be distributed to team members for review and familiarization prior to the survey. Enclosure 2 identifies the accommodations requested for the team’s use during the survey. If there are any questions regarding survey activities, please contact (Survey Team Leader) on (phone number). Your assistance is appreciated. Enclosures DOE-STD-1217-2020/Rev FEBRUARY 2020 96 (Sample Enclosure - Pre-Survey Questionnaire/ Data Call) Enclosure 1 The survey team needs the following to be delivered to Room XXX no later than (Date) for the XYZ facility and satellite office buildings: Program Planning and Management A list reflecting security staffing since (month, year). This list shall include name of person, date of hire/termination, job title, and security functions (responsibilities) Copies of all MOU and management agreements relating to S&S programs A copy of all internal operations procedures/practices, with index Copies of the most recent S&S security risk assessments, including documentation reflecting risk determination methodology A list of all security training courses that have been approved as part of the training approval plan process A list that reflects the training courses taken by personnel responsible for security functions. Include name, title of course, number of hours, and date of completion Copies of any procedures or other guidance pertaining to the identification and development of S&S training A list of all facilities (copies of Facility Data and Approval Records are acceptable) where the XXX DOE Office is identified as the Designated Responsible Office. A list of all classified activities (including the contract), classification level and category of the activity, identification by office and/or Cognizant Security Office, identification by contract number, purchase order number, task statement, or proposal number (including classified Strategic Partnership Projects) (Note: Copies of the CSCS form may be used in lieu of a listing.) List of all terminated and completed contracts since (month, year). This listing shall identify the company/vendor, address/location, Contracting Officer name, organization, office location, and telephone number (Note: Copies of terminated CSCS forms may be used in lieu of a listing.) List of pending FOCI determinations List of FOCI determinations completed since (month, year) DOE-STD-1217-2020/Rev FEBRUARY 2020 97 List of FOCI approved companies, including the FOCI determination date, mitigation types if any, and date of the latest FOCI update

Section 51

A copy of any desktop procedures or other formal XYZ-originated guidance documentation used for the development of the facility/site security plan and other security-related planning documents A list that reflects all S&S plans (e.g., response, emergency, and contingency plans) including title, date, and approval vehicle. Also list any draft plans and plans pending approval Copies of all XYZ-generated guidance or direction (hardcopy or electronic) provided for the conduct of self-assessments and other internal evaluations List of all open findings List of open findings pending validation Copy of Incidents of Security Concern program procedures A list of all security incidents, including computer security incidents, occurring since (month, year). This list shall identify the date of the incident, the date of the inquiry report, and the nature of the incident Copies of award fee data (Award Fee Plan, performance criteria) PF Copies of all security emergency plans (response, facility evacuation). If this information is not available from this office, please provide the name, organization, office location, and telephone number of the responsible person Copies of all post and general orders, as well as implementing instructions for various program activities (e.g., key control, alarm testing and maintenance, training program development). If this is not applicable to the area being surveyed check here N/A. If this is applicable, but the records are not available from this organization, please identify the name, organization, office location, and telephone number of the responsible person Copies of all MOUs/Memoranda of Agreement (MOAs) with local law enforcement agencies (LLEAs) or other organizations/agencies relating to security programs at the XYZ facility and satellite office buildings. If this is not applicable to the area being surveyed, check here: N/A DOE-STD-1217-2020/Rev FEBRUARY 2020 98 List of all PF personnel, identified by rank, and supervisors. Also provide a separate listing including PF management name, rank (if applicable), and responsibility (e.g., Lt. John Smith, Supervisor, IMF Instructor, Firearms Instructor) A list of training documentation including, but not limited to, Job Task Analyses, lesson plans, core topical s, individual records, physical fitness maintenance. Samples of each shall be available for review during the survey Copy of any DOE approval of the PF job analysis Copy of the last (and immediately preceding) annual review of the PF job analysis. Copy of the most recent approved Training Plan If available, an approved Training Approval Program Assessment Report A list of permanent and temporary security posts including post number and hours staffed If existing, a copy of all duty checklists used by the PF during routine and/or emergency operations (e.g., vehicle inspection checklist, incident reports, field interview reports, pre- duty inspection checklists, equipment checklists, CAS logs and radio checks, weapons issue, weapons maintenance, weapons cleaning, emergency call-out) Copy of plans documenting the physical configuration of security posts Copy of traffic/parking procedures (safety or security PF interface/enforcement) Copy of general and specific patrol orders that define patrol intervals and routes for classified repositories, vaults, and vault-type rooms Weapons inventory list, including serial number and storage location.

Section 52

Quality Assurance program documentation Communications equipment inventory list, including quantity, make, model, and auxiliary equipment, as well as interface capabilities with LLEA Auxiliary equipment inventory list including quantity, make, model of assigned equipment (e.g., gas masks, protective vests) Copy with pictures (if possible) of patrol and other vehicles used under the contract by the PF. A list including vehicle make, model, vehicle identification number, mileage, condition, unit number, license number, equipment (emergency and standard), owner (company, DOE, or leased from XYZ agency), maintenance agreement, and DOE-STD-1217-2020/Rev FEBRUARY 2020 99 identification of location of maintenance records (a sample of maintenance records would be helpful) Physical Protection Copy of key control and property pass procedures Copy of documentation that reflects the total value of capital and sensitive/equipment items (include precious metals as applicable) Listing of all controlled substances and locations, including copies of Drug Enforcement Agency certificates Listing that identifies all security alarm transmission and monitoring systems, including type, model, manufacturer, and purpose for each (i.e., describe the DOE assets being protected) List of all alarm points identified by system application (e.g., Argus, Litton) and location that provides protection for classified matter and property Copy of the approved alarm test plan and a copy of the DOE approval correspondence Copy of the procedures for making changes to alarm transmission/monitoring systems databases or software Copies of reports since (month, year) of unscheduled alarm activations Copy of false alarm rate and nuisance alarm rate since (month, year) Copies of maintenance procedures and test results since (month, year) Copies of IDS Analysis and Evaluation report since (month, year) Information Security A list of all current XYZ original and derivative classifiers A list of reviewing officials, including name, title, organization, office location, and telephone number A list of all classification guides, including title and date A list of all XYZ shipping/mailroom logs pertaining to the transmission of classified matter since (month, year) DOE-STD-1217-2020/Rev FEBRUARY 2020 100 A list of all areas authorized for processing and storage of classified information/matter, including the classification level authorized and functions performed in each area List of all CDCSs, including the custodian names, organization, location, and telephone extension. Copy of CMPC procedures (marking, destruction) List of all classified material accountability records Copy of DOE-approved Technical Surveillance Countermeasures (TSCM) Plan Copy of the TSCM officers appointment memoranda Copy of the site-wide procedures for the control and use of potential TSCM equipment Copy of the procedures controlling TSCM equipment, the DOE approval for purchasing and controlling TSCM equipment, and an inventory listing, if appropriate Copy of OPSEC Plan Copy of OPSEC assessment and review reports conducted since (month, year) List of contractors (on- and offsite) under the OPSEC program Copy of OPSEC working group meeting minutes for meetings conducted since (month, year) Personnel Security A list of all cleared personnel whose access authorization has been terminated since

Section 53

(month, year) (Note: This list shall include the date of termination, name of person, and organization for which the individual worked.) A list of names of all consultants/vendors issued security clearances that conduct business with XYZ A list of all individuals by name and clearance number terminated for cause A list of individuals by name and clearance number who have had clearances canceled/terminated prior to completion of the background investigation A list by name and clearance number of all FNs who are/were clearance applicants or incumbents. Include in the listing the country of origin and level of clearance DOE-STD-1217-2020/Rev FEBRUARY 2020 101 A list by name and clearance number of all dual citizens processed for access authorization (clearance) since (month, year) A list of individuals on leave of absence or extended leave. This list shall include name, clearance number, reason for leave, date leave commenced, expected date of return to duty, and/or date of termination Have available each report submitted for derogatory information since (month, year) Copy of attendance records for initial, comprehensive, and termination briefings for all contractor employees since (month, year) Copies of most current security education briefing/lesson plans for initial, comprehensive, refresher, and termination briefings since (month, year) Copy of the compliance verification numbers associated with the most recent refresher briefing Documentation describing the badging system and operating procedures for classified visits. Provide examples of all badge types in use Copy of the procedures for administering incoming and outgoing classified visits Copies of incoming visit requests since (month, year) Classified visitor logs since (month, year) Copies or log of classified visitor badge requests since (month, year) A listing of the number and dates of each positive substance abuse test report A copy of drug test policy A list of all personnel, by name and clearance number, enrolled in the HRP or other performance assurance program List of all individuals, by name and clearance number, removed from the HRP since (month, year) Justifications for HRP positions and date of last review Procedures for Personal Identify Verification process Foreign Visits and Assignments Lists of all host reports submitted since (month, year) including date submitted DOE-STD-1217-2020/Rev FEBRUARY 2020 102 Local procedures for requesting, processing, and approving visits and assignments List of foreign visitors or assignees, including names of hosts, for survey period Incident reports involving FNs Requests for FN visits Indices checks Documentation authorizing approval for specific categories of visits and assignments Sensitive country listings Nuclear MC&A MC&A Plan Performance test data Categorization documentation Internal control procedures Inventory difference program Shipper/receiver difference procedures and records DOE-STD-1217-2020/Rev FEBRUARY 2020 103 Sample Accommodation Request The following items will need to be made available to the survey team for the duration of the survey period:  Two conference rooms or a two-office suite with tables and seating for 15 to 20 people  Four desktop computers running Microsoft® Windows® (current operating system), loaded with Microsoft Word (current version) and two Hewlett-Packard LaserJet printers

Section 54

 Telephones with outside lines and official site phone books or listings  White board and associated supplies  U.S. General Services Administration-approved security container (with appropriate markings and required forms)  Office supplies (staplers, scissors, tape, disks, etc.)  Copies of XYZ procedures and policy manuals related to survey topical s, security plans, Vulnerability Assessments, and applicable DOE directives. Conduct Tools This section contains tools that have been developed and field-tested by survey and self- assessment teams. They are provided as examples only; other tools may be developed and used as necessary. Sample Survey Worksheet Instructions for Completing the Sample Survey Worksheet Sample Performance Test Safety Plan Sample Performance Test Plan DOE-STD-1217-2020/Rev FEBRUARY 2020 104 A.3.1.1 Sample Survey Worksheet CLASSIFICATION WORKSHEET ORIGINATION DATE: RESPONSIBLE AGENCY: FINDING NUMBER: CONCERN: COMPLIANCE PERFORMANCE BOTH TOPICAL AREA: SUB-TOPICAL AREA: FINDING DESCRIPTION: FINDING SYNOPSIS: IMPACT if not corrected: DOE DIRECTIVE: OTHER (Plan or Procedure Citation): ORIGINATOR’S NAME/PHONE: POINT-OF-CONTACT NAME/PHONE: POINT-OF-CONTACT SIGNATURE: CLASSIFICATION DOE-STD-1217-2020/Rev FEBRUARY 2020 105 INSTRUCTIONS FOR COMPLETING THE SAMPLE SURVEY WORKSHEET ORIGINATION DATE: Date form completed. RESPONSIBLE AGENCY: Agency responsible for implementing corrective actions. FINDING NUMBER: Each finding identified in the survey report shall have a unique identification number assigned, which shall be used throughout the reporting and tracking process. The following number system provides consistency with the Safeguards and Security Information Management System (SSIMS). A number in this format shall be system-generated upon entry of the finding into SSIMS. Example of a finding number: 04OCT15-HQ-12345-SSPS-PF.1-001-5789 | | | | | | | 1 2 3 4 5 6 7 the date of the survey/inspection (year/month/day) the office responsible for correcting the finding the facility code of the facility surveyed/inspected the type of survey (e.g., S&S Initial Survey, Office of Enterprise Assessments, Inspector Government Accountability Office) the sub-topical area code the sequential number of an individual finding within the topical area the facility code of another facility if a finding was issued to it during the survey The acronyms used to identify the new topical areas for findings are as follows: PMS Program Management Support PF Protective Force PSS Physical Protection IP Information Security PSP Personnel Security Program FVA Foreign Visits and Assignments NMCAA Nuclear MC&A DOE-STD-1217-2020/Rev FEBRUARY 2020 106 CODE TYPES OF SURVEY DOCUMENTS EPR Excluded Parent Review GAO Government Accountability Office Reports IG Inspector General Reports NPR Non-possessing Review EA Office of Security Assessment inspections/reviews SA Self-Assessments SPEC Special Surveys SSIS Safeguards and Security Initial Surveys SSPS Safeguards and Security Periodic Surveys SSTS Safeguards and Security Termination Surveys TSCM TSCM Reports FINDING DESCRIPTION: The finding description shall be used to provide a clear understanding of what was observed or discovered. It is not adequate to reiterate the requirement. The description shall clearly identify the pertinent facts, circumstances, and observations surrounding the finding or leading to the finding.

Section 55

Findings shall be clear, focused, and based on the perceived underlying cause of the protection shortfall, to the most reasonable extent possible; rather than merely stating the occurrence of a protection element failure or weakness. A finding shall be written in such a manner that it is actionable by the responsible agency, i.e., that action can be taken that will close the finding and the action will correct the observed deficiency. A well-worded finding is one that is readily closeable when the cause or source is corrected and impossible to close without correcting the cause or source. Necessary and pertinent information shall be presented regarding the finding in order to clearly identify what was found, how the information was collected, and any other background information. The discussions shall attempt to correlate the data collected and focus on the root cause of the deficiency. The nature of the data (e.g., observations, interviews, tests) shall be described, as well as any quantifying data that will put the results in perspective. For example: DOE-STD-1217-2020/Rev FEBRUARY 2020 107 A review was conducted of all current classified contracts at XYZ. This list was compared to a current badge listing, dated 3-1-15, which showed employees, by company, who currently hold a DOE access authorization. This comparison revealed that individuals holding access authorizations are employed by organizations that do not have FOCI determinations on file. Based on the FOCI report provided by XYZ personnel, dated 3-1-15, and the employee list by contractor, dated 3-1-15; TCY Company currently holds 7 “Q” clearances and Smith Manufacturing currently holds five “Q” clearances. Neither organization has a FOCI determination on file. FINDING SYNOPSIS: Each finding shall be concisely described in a synopsis format. The SSIMS allows a maximum of 2,000 alpha/numeric characters and spaces. Each finding is to have a separate, stand-alone classification level and category. A separate field is provided for the finding classification level and category. The symbols “S” for Secret, “C” for Confidential, “U” for Unclassified, “OUO” for Official Use Only, and “UCNI” for Unclassified Controlled Nuclear Information shall be used for the classification level. For example: Not all organizations employing cleared staff members have an approved FOCI determination. IMPACT STATEMENT: Clearly identify the impact of the deficiency. DOE DIRECTIVE: Each finding is to have alpha/numeric references to the DOE directive(s), or other documents that identify the requirement(s) not being met in the finding. This reference shall be written as DOE O XXX.XX, followed by the specific identification numbers and/or letters (e.g., DOE O 470.4B, Minor Change 2, Appendix A, Section 2, paragraph 6.(b)). OTHER: Identify alternative sources stating the requirement (e.g., section of the Code of Federal Regulations, specific local procedures, site security plan). ORIGINATOR’S NAME/PHONE: Print your name and telephone number. POINT-OF-CONTACT NAME/PHONE: Print the name and phone of the POC witnessing the activity. POINT-OF-CONTACT SIGNATURE: Obtain the POC’s signature. DOE-STD-1217-2020/Rev FEBRUARY 2020 108 A.3.1.2 Sample Performance Test Safety Plan PERFORMANCE TEST SAFETY PLAN I, acknowledge receipt of the attached safety plan. I understand it is my responsibility to become familiar and comply with the contents of this safety plan.

Section 56

Acknowledgment of the receipt of this safety plan is a requirement to participate in or observe this exercise. This page shall be signed and returned no later than . Name Signature Position Date Detection of Contraband and Prohibited Items (Type of Performance Test) Ongoing 365 Days per Year; 24 Hours per Day (Performance Test Date and Time) Detection of Contraband and Prohibited Items, John Doe (Safety Plan Name and Person Preparing) ALL LSPTs WILL BE CONDUCTED IN CONFORMANCE WITH THIS SAFETY PLAN AND ONLY AFTER SPECIFIC APPROVAL TO CONDUCT THE LSPTs HAS BEEN GRANTED BY A RESPONSIBLE U.S. DEPARTMENT OF ENERGY OFFICIAL. PERSONNEL SERVING AS CONTROLLERS WILL BE FULLY QUALIFIED IN ALL ASPECTS OF THE LSPT. Scenario: The ongoing LSPTs are conducted to test the ability of PF personnel to detect and prevent contraband and prohibited items from being introduced into Limited Areas, Vault-Type Room, Protected Areas, and Material Access Areas. LSPTs will be conducted on X-ray machines, metal detectors, and hand and vehicle searches. Security and non-security personnel will try to enter and exit the above-mentioned areas with contraband and prohibited items. Using personnel with whom PF personnel are unfamiliar will ensure credible and realistic test results. The person attempting to introduce the contraband or prohibited item will use only contraband test items that have been approved by the DOE cognizant security office. Once the entry is initiated, the person attempting the entry will only proceed after being cleared to do so by the security officer conducting the search. The persons attempting the entry will wear clothing that would make the concealment of any DOE-STD-1217-2020/Rev FEBRUARY 2020 109 weapons on their person virtually impossible, and they will keep their hands open and in plain view at all times. The persons attempting to enter or exit any of the aforementioned areas will strictly follow all instructions given by the DOE controller and obey all instructions given by PF personnel. The DOE controller will announce the LSPT to PF personnel once the contraband or prohibited item has been detected/undetected by the PF. The sole purpose of the LSPTs is to evaluate the ability of the PF to detect contraband and prohibited items prior to their release into the aforementioned areas. The LSPTs are not designed to test what actions the PF undertakes once they detect or fail to detect the contraband or prohibited item. IN THE EVENT OF AN ACTUAL SECURITY ALARM OR SECURITY INCIDENT, THE CONTROLLER WILL IMMEDIATELY ANNOUNCE AND CONCLUDE THE LSPT, TAKE POSSESSION OF THE TEST ITEM/CONTAINER, AND FOLLOW ALL INSTRUCTIONS ISSUED BY PF PERSONNEL. Requirements: DOE Controller Person to carry contraband or prohibited item into the area Contraband and prohibited item(s) Support items, such as lunch boxes, purses, notebooks, gym bags, vehicles. PF Response: Yes No If a no-notice PF response is desired, check the following measures being taken to ensure safety during the response. Drill announcements will be made on all PF networks immediately after PF response is initiated, and periodically thereafter. X Controller is located in the PF Central Alarm Station (CAS). The PF is informed that an exercise will take place and that they are to follow the safety and health requirements contained in this plan and in the site procedures. This instruction will be provided by s

Something wrong with this record? Tell us