DOE-STD-1217-2020, Safeguards and Security Survey and Self-Assessment Planning, Conduct, and Reporting
This document provides the Department of Energy (DOE) with a standard methodology for adapting the Department’s requirements to conduct and report Safeguards and Security (S&S) surveys and self-assessments to organization-specific needs in a coherent, consistent, and repeatable fashion. It describes a consistent and acceptable approach to planning, conducting, and reporting the results for S&S surveys and self-assessments. Appendix A, Safeguards and Security (S&S) Survey and Self-Assessment Toolkit, provides guidance and useful templates for planning, conducting, and reporting surveys and self-assessments.
Supersedes:
Version history and related documents
Supersedes
Earlier documents this one replaced.
Document text
Text extracted from the attached file. Refer to the original document for the authoritative version.
Section 1
DOE-STD-1217-2020
FEBRUARY 2020
DOE STANDARD
SAFEGUARDS AND SECURITY
SURVEY AND SELF-ASSESSMENT
PLANNING, CONDUCT, AND
REPORTING
U.S. Department of Energy
Washington, D.C. 20585
DISTRIBUTION STATEMENT A. Approved for public release; distribution is unlimited.
NOT MEASUREMENT
SENSITIVE
DOE-STD-1217-2020/Rev FEBRUARY 2020
ii
THIS PAGE INTENTIONALLY LEFT BLANK
DOE-STD-1217-2020/Rev FEBRUARY 2020
iii
FOREWORD
This Department of Energy Technical Standard is for use by all Departmental elements.
Email any beneficial comments (recommendations, additions, and deletions) and pertinent
data that may improve this document to natasha.sumter@hq.doe.gov or mail to:
U.S. Department of Energy
Office of Environment, Health, Safety, and Security
Office of Security Policy, GTN/AU-51
1000 Independence Ave., SW
Washington, D.C. 20585-1290
Department of Energy Technical Standards do not establish requirements. However, all or
part of the provisions in this Technical Standard can become requirements under the
following circumstances:
They are explicitly stated to be requirements in a Department of Energy
requirements document (e.g., a purchase requisition).
The organization makes a commitment to meet a standard in a contract,
implementation plan, or program plan.
This Technical Standard is incorporated into a contract.
Throughout this standard, the word “must” or “shall” are used to denote actions that must be
performed if the objectives of this standard are to be met. If the provisions in this Standard
are made requirements through one of the three ways discussed above, then the “shall”
statements would become requirements. Goals or intended functionality are indicated by
“will,” “may,” or “should.” It is not appropriate to consider that “should” statements would
automatically be converted to “shall” statements as this action would violate the consensus
process used to approve this standard.
This Technical Standard was prepared following requirements for due process, consensus,
and approval as required by the U.S. Department of Energy Standards Program. Consensus is
established when substantial agreement has been reached by all members of the writing team
and the Technical Standard has been approved through the Department of Energy directives
approval process (REVCOM). Substantial agreement means much more than a simple
majority, but not necessarily unanimity. Consensus requires that all views and objections be
considered, and that a concerted effort be made toward their resolution.
mailto:natasha.sumter@hq.doe.gov
DOE-STD-1217-2020/Rev FEBRUARY 2020
iv
THIS PAGE INTENTIONALLY LEFT BLANK
DOE-STD-1217-2020/Rev FEBRUARY 2020
v
CONTENTS
DOE Survey Form ............................................................................................................................ 6
EFCOG Self-assessment Tool Kit .................................................................................................... 6
Survey Team Leader ........................................................................................................................ 7
Survey Topical Lead ........................................................................................................................ 9
Survey Team Members ................................................................................................................... 10
Self-assessment Team Leads and Members ................................................................................... 11
Section 2
Cyclic Planning for Surveys and Self-Assessments ....................................................................... 14
Planning a Facility Survey or Self-Assessment. ............................................................................. 15
Pre-Planning ........................................................................................................................... 15
Preliminary Coordination ....................................................................................................... 15
Planning Survey and Self-Assessment Activities .................................................................. 17
In-Briefing ...................................................................................................................................... 17
Maintaining Communication .......................................................................................................... 18
Data Collection ............................................................................................................................... 18
Performance Tests .................................................................................................................. 20
Data Validation ...................................................................................................................... 21
Data Analysis ......................................................................................................................... 21
Ratings .................................................................................................................................... 23
Exit Briefing ................................................................................................................................... 25
DOE-STD-1217-2020/Rev FEBRUARY 2020
vi
Corrective Action Program............................................................................................................. 28
Process Improvement ..................................................................................................................... 29
Step 1: Understand and Map the Current Process .................................................................. 29
Step 2: Complete a Value Added Analysis ............................................................................ 31
Step 3: Develop an Improved Process .................................................................................... 33
Step 4: Update Documentation and Develop Metrics ............................................................ 34
Step 5: Measure for Success and Return to Step 1. ................................................................ 34
(1) TEST OBJECTIVE ................................................................................................................ 56
(2) SCENARIO DESCRIPTION ................................................................................................. 56
(3) TEST METHODOLOGY AND EVALUATION CRITERIA .............................................. 56
(4) PASS/FAIL CRITERIA ......................................................................................................... 56
(5) TEST CONTROLS ................................................................................................................ 57
(6) RESOURCE REQUIREMENTS ........................................................................................... 57
Section 3
(7) TEST COORDINATION REQUIREMENTS ....................................................................... 57
(8) OPERATIONAL IMPACT(S) OF TESTING PROGRAM .................................................. 57
(9) COMPENSATORY MEASURES ......................................................................................... 58
(10) COORDINATION AND APPROVAL PROCESS ............................................................... 58
(11) REFERENCES ....................................................................................................................... 58
1.1 Overview of Site ........................................................................................................................... 237
1.1.1 Mission ................................................................................................................................. 237
1.1.2 Location/Address ................................................................................................................. 237
1.2 Scope ......................................................................................................................................... 237
1.3 Purpose ......................................................................................................................................... 237
2.1 Program Office ............................................................................................................................. 237
2.2 Field/Site Office ........................................................................................................................... 237
2.3 Contractors ................................................................................................................................... 237
2.4 ODFSA/ODSA Delegations ......................................................................................................... 237
3.1 Federal Approval of Security Plan ............................................................................................... 237
DOE-STD-1217-2020/Rev FEBRUARY 2020
vii
4.1 Identification of Residual Risk ..................................................................................................... 237
4.1.1 Basis for residual risk determination .................................................................................... 237
4.2 Federal Acceptance of Residual Risk ........................................................................................... 237
5.1 List of Assets ................................................................................................................................ 237
5.2 Prioritization of Assets ................................................................................................................. 237
6.1 Analytical Basis ............................................................................................................................ 237
6.1.1 Plan based on DOE O 470.3C .............................................................................................. 238
6.1.2 DOE Tactical Doctrine, as applicable .................................................................................. 238
6.1.3 Security Risk Assessment / Vulnerability Assessment Overview ....................................... 238
6.2 Review and Update ...................................................................................................................... 238
Section 4
6.2.1 Review – procedures regarding plan review ........................................................................ 238
6.2.2 Update – procedures to provide updates and revisions to the plan ...................................... 238
7.1 PPM Overview ............................................................................................................................. 238
7.1.1 Federal Oversight (Field and Program Office) ..................................................................... 238
7.1.2 Contractors ........................................................................................................................... 238
7.1.3 Work-for Others ................................................................................................................... 238
7.2 Facility Clearance Program .......................................................................................................... 238
7.2.1 Procedures applicable to the FCL program .......................................................................... 238
7.3 Foreign Ownership, Control, or Influence ................................................................................... 238
7.3.1 Procedures applicable to the FOCI program ........................................................................ 238
7.4 Classified Visits ............................................................................................................................ 238
7.4.1 Procedures applicable to classified visits and assignments .................................................. 238
7.5 Unclassified Foreign Visitors and Assignments ........................................................................... 238
7.5.1 Procedures applicable to unclassified foreign visits and assignments ................................. 238
7.6 Incident of Security Concern ........................................................................................................ 238
7.6.1 Overview of the Incident of Security Concern program ...................................................... 238
7.7 Equivalencies and Exemptions ..................................................................................................... 238
7.7.1 Overview of the process ....................................................................................................... 238
7.7.2 List of Approved Equivalencies and Exemptions incorporated in Security Plan ................. 238
7.8 Memorandums of Agreement/Understanding .............................................................................. 238
7.8.1 Approval process .................................................................................................................. 238
DOE-STD-1217-2020/Rev FEBRUARY 2020
viii
7.8.2 Review Process .................................................................................................................... 238
7.8.3 List of all MOAs/MOUs ...................................................................................................... 238
7.9 SECON ......................................................................................................................................... 238
7.9.1 Overview of the SECON plan and procedures ..................................................................... 238
7.10 Performance Assurance ................................................................................................................ 239
Section 5
7.10.1 Performance Assurance planning ......................................................................................... 239
7.10.2 Performance testing .............................................................................................................. 239
7.10.3 System degradation .............................................................................................................. 239
7.10.4 Reviews and updates ............................................................................................................ 239
7.11 Safeguards and Security Training ................................................................................................ 239
7.11.1 Overview of the Safeguards and Security Training program ............................................... 239
7.12 Security Awareness Program ....................................................................................................... 239
7.12.1 Overview of the Security Awareness program ..................................................................... 239
7.13 Security-Funded Technologies, if applicable ............................................................................... 239
7.13.1 Overview of the process to transfer security-funded technologies ...................................... 239
7.14 Demonstrator and Protestor Plan .................................................................................................. 239
7.14.1 Responsibilities .................................................................................................................... 239
7.14.2 Memoranda of Agreement or Understanding ....................................................................... 239
7.14.3 Event notification ................................................................................................................. 239
7.14.4 Minimum requirements ........................................................................................................ 239
7.15 Workplace Violence Plan ............................................................................................................. 239
7.15.1 Responsibilities .................................................................................................................... 239
7.15.2 Memoranda of Agreement or Understanding ....................................................................... 239
7.15.3 Event notification ................................................................................................................. 239
7.15.4 Minimum requirements ........................................................................................................ 239
8.1 General Site Access ...................................................................................................................... 239
8.1.1 Employees ............................................................................................................................ 239
8.1.2 Visitors ................................................................................................................................. 239
8.1.3 Other Federal Agency Badges .............................................................................................. 239
8.2 Prohibited and Controlled Articles ............................................................................................... 239
Section 6
8.2.1 Prohibited Articles................................................................................................................ 239
8.2.2 Controlled Articles ............................................................................................................... 239
8.3 Entry and Exit Inspections............................................................................................................ 240
DOE-STD-1217-2020/Rev FEBRUARY 2020
ix
8.3.1 Entry Inspections procedures ............................................................................................... 240
8.3.2 Exit inspection procedures ................................................................................................... 240
8.3.3 Property Removal ................................................................................................................. 240
8.4 Security Areas (as applicable) ...................................................................................................... 240
8.4.1 General Access Areas ........................................................................................................... 240
8.4.2 Property Protection Areas .................................................................................................... 240
8.4.3 Limited Areas ....................................................................................................................... 240
8.4.4 Vaults/Vault-Type Rooms .................................................................................................... 241
8.4.5 Sensitive Compartmented Information Facilities ................................................................. 242
8.4.6 Special Access Program Facilities ....................................................................................... 242
8.4.7 Protected Areas .................................................................................................................... 242
8.4.8 Material Access Areas .......................................................................................................... 243
8.5 Lock and Key Program ................................................................................................................. 244
8.5.1 Overview of lock and key program ...................................................................................... 244
8.5.2 Inventory system .................................................................................................................. 245
9.1 Management ................................................................................................................................. 245
9.1.1 Overview of Pro Force management .................................................................................... 245
9.1.2 Non-uniformed staffing ........................................................................................................ 245
9.2 Training ........................................................................................................................................ 245
9.2.1 Initial .................................................................................................................................... 245
9.2.2 Annual .................................................................................................................................. 245
9.2.3 Firearms ................................................................................................................................ 245
Section 7
9.3 Certification .................................................................................................................................. 245
9.3.1 Medical & Physical .............................................................................................................. 245
9.4 Staffing ......................................................................................................................................... 245
9.4.1 Security Officer .................................................................................................................... 245
9.4.2 Fixed Post ............................................................................................................................. 245
9.4.3 Security Police Officer (SPO) Is .......................................................................................... 245
9.4.4 SPO IIs ................................................................................................................................. 245
9.4.5 SPO IIIs ................................................................................................................................ 245
9.5 Duties ......................................................................................................................................... 245
9.5.1 Normal duties ....................................................................................................................... 245
9.5.2 Emergency duties ................................................................................................................. 245
DOE-STD-1217-2020/Rev FEBRUARY 2020
x
9.6 Equipment .................................................................................................................................... 245
9.6.1 Duty Equipment ................................................................................................................... 245
9.6.2 Vehicles ................................................................................................................................ 246
10.1 Characterization of the Nuclear Control and Accountability program ......................................... 246
10.1.1 Shall address probability of detection of loss of Category I SNM with 95% probability, if
applicable ........................................................................................................................................... 246
10.1.2 Shall define loss detection capability for other Categories of SNM .................................... 246
11.1 Procedures for new clearances ..................................................................................................... 246
11.2 Clearance transfers, extensions, upgrades, downgrades, and cancellations ................................. 246
11.3 Reporting requirements ................................................................................................................ 246
12.1 Procedures applicable to the Insider Threat Mitigation Program ................................................. 246
12.2 Description of Local Insider Threat Working Group (LITWG) ................................................... 246
12.3 Human Reliability Program, if applicable .................................................................................... 246
12.3.1 Overview of HRP program .................................................................................................. 246
Section 8
12.3.2 Roles and Responsibilities ................................................................................................... 246
12.3.3 HRP Certification ................................................................................................................. 246
12.3.4 HRP Removal ....................................................................................................................... 246
13.1 Classified Matter Protection and Control ..................................................................................... 246
13.1.1 Procedures utilized to protect classified matter, to include: ................................................. 246
13.2 Controlled Unclassified Information ............................................................................................ 247
13.2.1 Procedures utilized to protect CUI information ................................................................... 247
14.1 Overview of cyber security program ............................................................................................ 247
14.2 Roles and Responsibilities ............................................................................................................ 247
14.2.1 Authorizing Official ............................................................................................................. 247
15.1 Overview of the Operations Security program ............................................................................. 247
15.2 Identification and release of controlled information .................................................................... 247
16.1 Overview of the Technical Security program............................................................................... 247
DOE-STD-1217-2020/Rev FEBRUARY 2020
xi
17.1 Surveys ......................................................................................................................................... 247
17.1.1 Site Office ............................................................................................................................ 247
17.1.2 Program Office ..................................................................................................................... 247
17.2 Self-Assessments .......................................................................................................................... 247
17.3 Findings and Corrective Actions .................................................................................................. 247
17.4 Reviews, Reports and Ratings ...................................................................................................... 247
LIST OF FIGURES
Figure 8:1 Portable Universal Quality System Audit Template .................................................................. 13
Figure 12:1 Initial Notification Memo Process Map ................................................................................... 31
Figure 12:2 Initial Notification Memo Color-Coded Process Map ............................................................. 32
Figure 12:3 Notification Memo Improved Process Map ............................................................................. 33
LIST OF TABLES
Table E-1 Example of SNM Theft/Diversion Targets ............................................................................... 250
Table E-2. Example of Radiological Sabotage Targets ............................................................................. 251
Section 9
Table E-3. Example of Biological/Chemical Sabotage Targets ................................................................ 251
Table E-4. Example of Disruption of Critical Mission Targets................................................................. 252
Table E-5. Example of Site-Wide Protection Strategies ........................................................................... 253
Table E-6. Example of Facility Protection Systems .................................................................................. 254
Table E-7. Example of Qualifications and Training .................................................................................. 255
Table E-8. Example of MC&A Plans and Procedures .............................................................................. 256
Table E-9. Example of Personnel Security/Human Reliability ................................................................. 257
Table E-10. Example of Automated Information Systems Security Programs ......................................... 258
Table E-11. Example of S&S-Related Maintenance, Testing, and Records Management Programs ....... 260
Table E-12. Example of Site Protection Program Evaluation Program .................................................... 260
Table E-13. Example of Deviations from DOE Contractor Requirements ............................................... 261
Table E-14. Example of Pending Deviations from DOE Contractor Requirements ................................. 261
Table E-15. Example of Identified Risks Summary .................................................................................. 263
Table E-16. SNM Theft/Diversion Targets ............................................................................................... 263
Table E-17. Example of Credible Radiological Sabotage Targets ............................................................ 263
Table E-18. Example of Credible Biological Sabotage Targets ................................................................ 264
Table E-19. Example of Credible Chemical Sabotage Targets ................................................................. 264
Table E-20. Example of Disruption of Critical Mission Targets Table..................................................... 264
DOE-STD-1217-2020/Rev FEBRUARY 2020
xii
Table E-21. Example of Performance Testing Results of Site-Specific .................................................... 266
Table E-22. Example of Critical Path Scenarios ....................................................................................... 267
Table E-23. Example of Protection Effectiveness (PE) for Theft or Diversion of SNM .......................... 268
Table E-24. Example of Protection Effectiveness (PE) for Radiological Sabotage .................................. 268
Table E-25. Example of Protection Effectiveness (PE) for Biological Sabotage ...................................... 269
Table E-26. Example of Protection Effectiveness (PE) for Chemical Sabotage ....................................... 269
Table E-27. Example of Protection Effectiveness (PE) for Disruption of Critical Missions .................... 269
Table E-28. Example of Protection Effectiveness (PE) for Theft/Espionage of Classified
Information/Matter .................................................................................................................................... 270
Section 10
Table E-29. Example of Protection Effectiveness (PE) for Other Losses ................................................. 270
Table E-30. Example of System Effectiveness Summary ......................................................................... 270
DOE-STD-1217-2020/Rev FEBRUARY 2020
1
ACRONYMS AND ABBREVIATIONS
CAP Corrective Action Plan
CAS Central Alarm Station
CDCO Classified Document Control Office
CDCS Classified Document Control Station
CI Critical Information
CMPC Classified Matter Protection and Control
COMSEC Communications Security
CPCI Central Personnel Clearance Index
CSCS Contract Security Classification Specification
DBT Design Basis Threat
DEAR DOE Acquisition Regulation
DNA Does Not Apply
DOE Department of Energy
ECD Estimated Completion Date
EOC Emergency Operations Center
FACTS Foreign Access Central Tracking System
FCL Facility Clearance Level
FDAR Facility Data and Approval Record
FEMA Federal Emergency Management Agency
FN Foreign national
FOCI Foreign Ownership, Control or Influence
FOF Force-on-force
FSL Facility security level
DOE-STD-1217-2020/Rev FEBRUARY 2020
2
FSC Facility Security Committee
FSO Facility Security Officer
GSP Graded Security Protection
HRP Human Reliability Program
ID Inventory difference
IDS Intrusion detection system
IOSC Incident of Security Concern
ISC Interagency Security Committee
JTA Job Task Analysis
KMP Key Management Personnel
LLEA Local law enforcement agencies
LOI Lines of Inquiry
LSPT Limited scope performance test
MAA Material Access Area
MBA Material Balance Area
MC&A Material Control and Accountability
MOA Memoranda of Agreement
MOU Memoranda of understanding
N/A Not Applicable
NMMSS Nuclear Material Management and Safeguards System
NTC National Training Center
NR Not Rated
ODFSA Officially Designated Federal Security Authority
ODSA Officially Designed Security Authority
DOE-STD-1217-2020/Rev FEBRUARY 2020
3
OFI Opportunities for Improvement
OGA Other government agency
OPSEC Operations Security
PF Protective Force
REVCOM Review and Comment
RIS Reporting Identification Symbol
RMP Risk Management Process
S&S Safeguards and Security
SAP Special Access Program
SAS Secondary Alarm Station
SEC Securities and Exchange Commission
SECON Security condition
SNM Special nuclear material
SP Security plan
SRA Security Risk Assessment
SRD Secret Restricted Data
SRT Special Response Team
SSD Safeguards and Security Division
SSIMS Safeguards and Security Information Management System
SSPS Safeguards and Security Periodic Survey
TID Tamper-Indicating Device
TSCM Technical Surveillance Countermeasures
TSCMO TSCM Officer
TSCMOM TSCM Operations Managers
DOE-STD-1217-2020/Rev FEBRUARY 2020
4
UCNI Unclassified Controlled Nuclear Information
UFVA Unclassified Foreign Visitors and Assignments
VA Vulnerability Analysis
DOE-STD-1217-2020/Rev FEBRUARY 2020
5
SCOPE
This document provides the Department of Energy (DOE) with a standard methodology for
adapting the Department’s requirements to conduct and report Safeguards and Security
(S&S) surveys and self-assessments to organization-specific needs in a coherent, consistent,
and repeatable fashion. It describes a consistent and acceptable approach to planning,
conducting, and reporting the results for S&S surveys and self-assessments. Appendix A,
Safeguards and Security (S&S) Survey and Self-Assessment Toolkit, provides guidance and
Section 11
useful templates for planning, conducting, and reporting surveys and self-assessments.
PURPOSE
The purpose of this Technical Standard is to provide federal and contractor personnel who
have S&S oversight responsibilities with an accepted, compliance and performance-based
process to conduct and report S&S surveys and self-assessments prescribed in DOE Order
(O) 470.4B Minor Change 2.
APPLICABILITY
This Technical Standard is intended for use by DOE federal and contractor S&S
organizations conducting either S&S surveys or S&S self-assessments.
REFERENCES
DOE Guide 414.1-1C, Management and Independent Assessments Guide, March 27,
2014
DOE Manual 471.3-1, Administrative Change 1, Identifying and Protecting Official
Use Only Information, January 13, 2011
DOE Order 142.3A Limited Change 2, Unclassified Foreign Visits and Assignments
Program, January 18, 2017
DOE Order 226.1B, Implementation of Department of Energy Oversight Policy, April
25, 2011
DOE Order 413.3B, Minor Change 5, Program and Project Management for the
Acquisition of Capital Assets, April 12, 2018
DOE Order 452.8, Control of Nuclear Weapon Data, July 21, 2011
DOE Order 470.3C, Design Basis Threat, November 23, 2016
DOE Order 470.4B, Minor Change 2, Safeguards and Security Program, January 17,
2017
DOE-STD-1217-2020/Rev FEBRUARY 2020
6
DOE Order 470.6 Minor Change 1, Technical Security Program, January 11, 2017
DOE Order 471.1B, Identification and Protection of Unclassified Controlled Nuclear
Information, March 1, 2010
DOE Order 471.3, Administrative Change 1, Identifying and Protecting Official Use
Only Information, January 13, 2011
DOE Order 471.5, Special Access Programs, March 29, 2011
DOE Order 471.6, Administrative Change 3, Information Security, September 12,
2019
DOE Order 472.2, Page Change 1 (Certified), Personnel Security, July 16, 2015
DOE Order 473.3A, Minor Change 1, Protection Program Operations, January 2,
2018
DOE Order 475.1, Counterintelligence Program, December 10, 2004
DOE Order 475.2B, Identifying Classified Information, October 3, 2014
DOE Policy 470.1B, Safeguards and Security Program, February 10, 2016
The Risk Management Process for Federal Facilities: An Interagency Security
Committee Standard, 2nd Edition, November 2016
Title 10, Code of Federal Regulations Part 824, Procedural Rules for the Assessment
of Civil Penalties for Classified Information Security Violations
Title 32 Code of Federal Regulations Part 2004, National Industrial Security
Program
Title 32 Code of Federal Regulations, Part 2001, Classified National Security
Information
INTERNET SOURCES OF REFERENCE MATERIALS
DOE Survey Form: https://www.energy.gov/cio/downloads/doe-f-4708
EFCOG Self-assessment Tool Kit: https://efcog.org/wp-
content/uploads/Wgs/Safeguards%20and%20Security%20Working%20Group/Documents/2014-
SSWG%20PPM-Toolkit-S%26S%20Self-Assessment.pdf
https://www.energy.gov/cio/downloads/doe-f-4708
https://efcog.org/wp-content/uploads/Wgs/Safeguards%20and%20Security%20Working%20Group/Documents/2014-SSWG%20PPM-Toolkit-S%26S%20Self-Assessment.pdf
https://efcog.org/wp-content/uploads/Wgs/Safeguards%20and%20Security%20Working%20Group/Documents/2014-SSWG%20PPM-Toolkit-S%26S%20Self-Assessment.pdf
https://efcog.org/wp-content/uploads/Wgs/Safeguards%20and%20Security%20Working%20Group/Documents/2014-SSWG%20PPM-Toolkit-S%26S%20Self-Assessment.pdf
DOE-STD-1217-2020/Rev FEBRUARY 2020
7
DEFINITIONS
Section 12
Definitions commonly used in the Safeguards and Security Program can be found in the
Office of Environment, Health, Safety and Security Policy Information Resource located at
https://pir.doe.gov/. Definitions that have unique meanings in this Technical Standard
include:
a. Deficiency: An inadequacy in the implementation of an applicable requirement
or performance standard that is found during an appraisal. Deficiencies may
serve as the basis for findings.
b. Observation: An item for management attention noted in a survey or self-
assessment report that identifies a potential deficiency if not addressed or a
possibility for program enhancement that shall be further studied before
implementation.
c. Opportunity for Improvement: A term used by some oversight activities to
identify an item for management attention noted in a survey or self-assessment
that identifies a possibility for program enhancement that shall be further studied
before implementation. Opportunities for Improvement (OFI) may also be
identified as Suggestions, Recommendations, Findings, Weakness, or other site-
specific terminology.
d. Strength: A term used to identify in a survey or self-assessment that the program
or item in review is operating better than required by the Order. Strengths may
also be known as noteworthy practices, or other site-specific terminology.
e. Weakness: A term used to identify in a survey or self-assessment that the
program or item in review is operating less than optimum as required by the
Order. Weakness may also be known as an opportunity for improvement, or other
site-specific terminology
DUTIES, RESPONSIBILITIES, AND TRAINING
Survey Team Leader
The DOE cognizant security office line management shall appoint a federal employee as the
Survey Team Leader for surveys of facilities with an importance rating of “A”, “B,” or “C”.
For other facilities, the Survey Team Leader may be a contractor acting under the
supervision of a federal employee designated by line management of the DOE cognizant
security office. The Survey Team Leader is responsible for the successful completion of the
survey. This person shall have a comprehensive understanding of S&S programs, have
previous survey experience (preferably as a Survey Topical Lead or Survey Team Leader),
and be especially capable of integrating topical area results into a comprehensive assessment
of facility security. It is highly desirable that the Survey Team Leader has completed
DOE-STD-1217-2020/Rev FEBRUARY 2020
8
training courses offered by the National Training Center (NTC) on survey conduct and
management.
The Survey Team Leader is responsible for managing the efforts of the survey team and for
keeping the participants informed of all matters affecting the team and/or the facility during
the survey. The Survey Team Leader is responsible for team planning and logistics,
coordination of team activities, focusing the activities of the team, ensuring that deliverables
are prepared and provided according to the schedule, promoting integration among topical
teams, and acting as a team spokesperson during meetings and briefings. In particular, the
team leader needs to ensure that all pertinent elements of the S&S program are reviewed,
that analysis is particularly focused upon the most critical elements, and that any concerns or
deficiencies identified are fully supported by documented and validated data.
Survey Team Leader responsibilities may include the following:
Section 13
a. Develops the survey plan.
b. Prepares and maintains an Annual Master Survey Schedule.
c. Is trained by DOE NTC (or another training institution/organization), or qualified
by their Program Office to lead a survey team.
d. Appoints Survey Team members for each evaluation. The selections shall
achieve a balance of technical knowledge, experience, writing ability, survey
experience, survey ability, and availability. Employees who are technical area
specialists may augment the staff and could include direct support contractors,
other employees, other organization employees, or other site employees.
e. Ensures the survey team conducts security surveys of facilities under their
cognizant authority in a timely manner.
f. Conducts Survey in-briefings, daily management meetings and closeout
briefings.
g. Ensures survey data is entered in the Safeguards and Security Information
Management System (SSIMS); in accordance with SSIMS data entry procedures
and DOE line management direction.
h. Ensures Initial Surveys are conducted for all new facilities with a security interest
prior to granting facility approval.
i. Ensures Periodic Surveys are conducted according to the established risk-based
management process,
j. Ensures Termination Surveys are conducted for all facilities that no longer have a
security interest.
DOE-STD-1217-2020/Rev FEBRUARY 2020
9
k. Ensures the importance rating for approved facilities is updated as necessary.
l. Consolidates all staffing resource requirements, to include such items as overtime
requirements for federal staff, requests for assistance from other Program
Managers or other organizations, typing and editing support, and contractor
support. Presents the consolidated schedule, staffing requirements, and scope of
the survey to the appropriate leadership.
m. Ensures that all necessary logistical arrangements are made, including the
availability of adequate workstations, classified computers, security containers,
and authorized Derivative Classifiers as deemed necessary. Also coordinates with
appropriate organizations for the proper access control, site-specific training
requirements, and issuance of safety equipment.
n. Prepares the data call letter with input from the Topical Leads and forwards that
letter to the organization(s) to be surveyed or assessed at least 30 days prior to
the beginning of the survey.
o. Conducts daily meetings with the Topical Leads and with the appropriate
management of the organization(s) being surveyed to keep them informed of
concerns resulting from the day’s data-collection activities.
p. Review and approves Topical Lines of Inquiry (LOIs)
q. Reviews Topical Area Survey Reports; including survey results from previous
surveys.
r. Provides guidance to Topical Leads and Survey Team members as necessary.
s. Provides guidance to federal and contractor personnel in the preparation of
corrective action plans (CAPs) for findings issued to their organization.
t. Maintains reports in accordance with DOE requirements
u. Employ a risk analysis methodology to define the scope and critical topical areas
of interest to review during the survey (see Attachment 1).
Survey Topical Leader
A topical lead for each topical area to be surveyed should either be appointed by the same
authority appointing the Survey Team Leader or, alternately, be designated by the Survey
Team Leader. The topical lead must be an expert in his or her assigned topical area. In some
Section 14
cases, it may be necessary to select a contractor as topical lead because of his or her
outstanding technical qualifications, with the understanding that a contractor cannot
supervise the work of federal employees. The topical leads work closely with the Survey
Team Leader to complete pre-planning, to ensure that each topical area team collects the
DOE-STD-1217-2020/Rev FEBRUARY 2020
10
data required for preparation of the survey report, and to ensure that written and verbal
deliverables assigned to the topical area teams are of high quality and are delivered
according to the schedule. Each topical lead conducts, with the assistance of the topical area
team, a topical area analysis of results, and recommends topical area and sub-topical ratings
to the Survey Team Leader. It is highly desirable that topical leads have completed the
training courses offered by the NTC on survey conduct and management.
a. Trained through the DOE NTC or other organization
b. Responsible for the activities of Survey Team members assigned to their topical
area
c. Responsible for meeting all deliverable deadlines in a timely manner.
d. Develops Topical Area LOIs for their areas and provides to the Survey Team
Leader for approval.
e. Responsible for ensuring that Survey Team members integrate and coordinate
their activities with other topical area teams as appropriate.
f. Conduct daily meetings with their Survey Team members on data-collection
activities and concerns.
g. Brief the Survey Team Leader on data-collection activities and concerns.
h. Ensures notes are reviewed for classification and appropriately marked, and then
submitted to the Survey Team Leader.
i. Provide the consolidated Topical Area Report, including the suggested ratings
and accurate reference citations, to the Survey Team Leader.
j. Incorporate changes to the Topical Area Report as required by the Survey Team
Leader.
k. Ensure that all notes, working papers, and other data-collection materials are
collected from survey team members for retention.
Survey Team Members
Selection of survey team members shall be coordinated among the Survey Team Leader,
topical leads, and the organizations for which the individuals work. Team members shall be
selected for technical competence, professionalism, and experience, with particular emphasis
on interpersonal skills that will allow them to interact with facility personnel to collect and
analyze data without creating an unnecessary burden on operations or controversy with
facility personnel. Team members shall have previous experience and demonstrated
expertise in the topical area or sub-topical area topical area to which they are assigned,
DOE-STD-1217-2020/Rev FEBRUARY 2020
11
unless they are specifically selected for the purpose of training and/or furthering their
professional development. Team members selected for training or professional development
shall perform under the direct supervision of an individual with previous experience and
demonstrated expertise in the topical area or sub-topical area. Unless they are specifically
selected for training or professional development, it is highly desirable that survey team
members have completed training courses offered by the NTC on survey conduct and
management.
a. Keep Topical Leads or Team Leader informed of data-collection activities and
concerns.
b. Keep notes in sufficient detail for briefing and report development.
c. Meet deadlines for all deliverables.
Section 15
d. Prepare their portion of the final report in the proper format, including
recommended ratings and findings.
e. Provide accurate reference citations for all findings to ensure that the finding is
consistent with DOE Orders and other requirements.
f. Write findings such that corrective actions can be completed.
g. Process classified information only on accredited computers.
h. Discuss potential survey results only with other individuals on the Team to
confirm if a potential finding shall be a finding in the final survey report. The
Survey Team Leader will provide the surveyed organization’s management a
daily briefing on the status of activities and concerns.
Self-assessment Team Leads and Members
Self-assessment team leaders, topical leads, and team members shall be chosen using the
same criteria as listed above for Survey Team Leaders, topical leads, and team members.
However, as self-assessments are a contractor activity, it is not necessary to have federal
employees as survey and topical area team leaders.
SURVEY AND SELF-ASSESSMENT OVERVIEW
Surveys, self-assessments, and review programs are conducted to ensure that S&S systems
and processes at facilities/sites are operating in compliance with Departmental and national-
level policies, requirements, standards, and approved deviations for the protection of
security assets and interests. Without an adequate S&S survey program, line managers
cannot effectively manage the S&S programs for which they are responsible. Surveys
compare planned S&S program performance to the actual achievement. The survey report
presents accumulated data and provides an analysis of S&S program effectiveness for the
DOE-STD-1217-2020/Rev FEBRUARY 2020
12
areas surveyed/assessed at the surveyed location. The survey activity provides two vital
components to the federal management of an S&S program – measurement of the degree to
which actual implementation matches planned implementation, and feedback indicating
actions needed to make program implementation match program planning and/or needed
changes to program planning and implementation to better achieve mission objectives.
Management support and commitment to the S&S survey program are critical to ensuring
the time and resources required to produce a useful survey product are available.
To provide the best possible information for management consideration, the S&S survey
needs to include a significant sample of the local S&S mission elements. The resulting
report needs to contain a logical and thorough presentation of the survey results,
accompanied by a complete and logical analysis of those results that leads to conclusions
regarding the status of program implementation, reflected in the ratings awarded, and
identification of needed actions. These conclusions regarding the status, accompanied by
measurements and analysis supporting the conclusions, inform not only local federal
management, but also line management at higher levels about the current status of the S&S
program at the surveyed site or facility.
Surveys and self-assessments must focus on both performance and compliance. When
possible, the survey and self-assessment efforts must ensure compliance with requirements
and performance of personnel and systems demonstrating that Departmental and national
assets are protected; and that resources are used responsibly, and in the best interest of the
nation. For this reason, survey and self-assessment teams shall be familiar with basic survey
Section 16
techniques as well as process improvement techniques, some of which are presented in this
document. As there are many available improvement techniques those presented in this
document are only some of the recommended options the site may elect to adopt. The
Portable Universal Quality System described in Auditing Beyond Compliance by Janet
Bautista Smith, outlines at a high level how this process of assessing performance could
work as shown in Figure 8.1
DOE-STD-1217-2020/Rev FEBRUARY 2020
13
Figure 8:1 Portable Universal Quality System Audit Template
S&S programs have traditionally been considered to be logically divided into topical areas
and, within each topical area, sub-elements known as sub-topical areas. While this
organizational structure might be considered to be somewhat arbitrary, it forms a useful way
to organize data collection and to report the results of a survey or self-assessment. This
division into topical areas and sub-topical areas are reflected on the DOE Form 470.8,
Survey/Inspection Report Form (see Attachment 2), and this topical area and sub-topical
area structure or a similar format shall be used in discussion of the survey and self-
assessment process to follow. In addition to providing a structural reference for this
technical standard, the form is often used to provide a means of summarizing the results of a
comprehensive survey or self-assessment and is the appropriate data entry form for entering
survey and self-assessment data into the SSIMS. Modifications of this form might be
DOE-STD-1217-2020/Rev FEBRUARY 2020
14
beneficial to capture site-specific information but shall allow for entry of information into
SSIMS at least at the topical area level where applicable.
Self-assessments provide the same management information to local contractor managers on
a more frequent basis than the survey or at a time between surveys. The need for
documentation of self-assessment activities leading to a periodic comprehensive report is no
less than for surveys. The benefits of these self-assessments are several:
Local managers receive notification of program weaknesses on a more timely basis,
thereby allowing them to address and correct the issues sooner than might be
possible using only an external review;
Local S&S personnel are encouraged to be self-critical, allowing them to be more
proactive in providing adequate security to local assets; and,
Employees who have security duties but are not security professionals are provided
a more comprehensive view of the security program.
SURVEY AND SELF-ASSESSMENT PLANNING
Survey and self-assessment planning consists of two components—cyclic program planning
and planning for a survey of a particular facility or a particular self-assessment. Effective
planning requires the planner to fully understand the assets at each facility to be reviewed
during a planning period, the operations and characteristics of each facility, the S&S
directives that apply at each facility, and the past performance of each facility on previous
surveys, facility self-assessments, and recent external reviews.
Cyclic Planning for Surveys and Self-Assessments
Comprehensive planning is key to the success of a survey or self-assessment program.
Review activities may be scheduled around a one-time evaluation, ongoing observations
during the reporting interval, a combination of the two, or as otherwise required in the
Section 17
interest of national security. Each activity conducting surveys or self-assessments shall
establish a planning cycle that best allows the allocation of resources and assures that
surveys or self-assessments are scheduled to meet the requirements of DOE O 470.4B Minor
Change 2. A survey or self-assessment plan shall be prepared for the selected planning cycle
to reflect the approach used for data collection and report preparation, a schedule of planned
surveys or self- assessments during the planning period, and an initial assessment of
personnel and other resources required to complete the planned activities. Personnel
requirements, both the number of personnel and their skills, will be a function of the
particular facilities scheduled for that planning period. Planning shall include an
identification of the information needed to conduct a comprehensive evaluation at each
facility, including the identification of topical area and sub-topical area as required. If
information is to be collected over an extended period, for example by observing particular
operations during the time period, the plan will need to consider whether the information
DOE-STD-1217-2020/Rev FEBRUARY 2020
15
collected remains completely reliable or is somewhat degraded by the passage of time
between the observation and final report preparation. Planning must identify sampling or
verification methods that ensure perishable information gathered early in a survey or self-
assessment planning period remains valid at the time the report is completed.
Planning a Facility Survey or Self-Assessment.
Comprehensive survey and self-assessment planning involves gathering and analyzing large
amounts of information from many sources, making decisions based on the analysis, and
preparing survey activities based on the decisions. Because there is only a limited amount of
time available onsite to collect the data necessary to characterize the status of the programs
being surveyed, planning shall focus on determining what program elements to review and
how best to survey those elements to help ensure the most effective use of that time.
For those elements the plan shall specify the additional data necessary to assess the
applicability and accuracy of data obtained from periodic sampling during the final phase of
survey conduct. Planning activities include identifying personnel and other support
requirements for all phases of the survey.
Pre-Planning
Pre-planning includes determining the scope and objectives of the review. Information such
as the facility importance rating, S&S interests, and security contract requirements provide
the basis for the scope and objectives of the assessment, but other factors such as previous
performance, recent site operational changes, and new missions are also important in
establishing the scope of the review. Aspects of the impact of these elements can be assessed
qualitatively and quantitatively using a risk assessment process similar to that found in
Attachment 1. This form of analysis can define what expertise is required for the assessment
and on what topical areas the survey shall focus resources. Once this risk assessment is
complete, the team leader develops an initial schedule and considers whether a preliminary
visit is needed. To assist in the scheduling of the survey from pre-planning to completion of
report, a survey a checklist, like that presented in Attachment 3 Survey Prep and Report,
Section 18
Checklist, might be useful. Additionally, a survey/self-assessment plan is vital to ensuring a
properly planned and executed survey, to capture at a high level the focus of the survey
efforts (see Attachment 4, Survey Plan Template). As with many aspects of the survey/self-
assessment process, the formality and comprehensiveness of information may vary based on
the familiarity of the survey team and the facility or organization assessed.
Preliminary Coordination
Before data collection begins, the following activities shall be conducted:
Coordinating the proposed schedule with the site/facility and other responsible
parties;
DOE-STD-1217-2020/Rev FEBRUARY 2020
16
Identifying basic information needed in the data collection, such as a site or facility
security plan, assessment/ inspection reports, approved deviations (including
equivalencies/exemptions for DOE policy and deviations from national policy), and
contract data;
Sending the notification letter or other agreed upon notification;
Team member selection and coordination with members’ management;
If a data call is deemed necessary to support a team planning meeting, determining
the documents needed, preparing a list, and requesting the listed documents from
their respective sources. (Refer to Attachment 6, Data Call Information)
Conducting a team planning meeting;
Establishing a schedule and topical area assignments;
Gathering facility data (e.g., location, S&S interests, queries of SSIMS, EFOCI, and
other databases to obtain information regarding the facility clearance, importance
rating, key positions, assets, current S&S plans, and active deviations);
Establishing protocols, including a schedule for team meetings, a procedure for
communicating schedule changes or additional support requirements, a process for
managing classification concerns and issues, a determination of the validation
process to be used, a consolidated document call, a report outline reflecting the
desired format for the report, LOIs, and a compilation of logistical information
(travel dates, hotel arrangements, rental cars, site access, in-briefing time/location);
Providing the format for plans, reports, findings, process improvements, and
corrective actions;
Providing official notification; and,
Preparing an overall plan for the survey or self-assessment.
The level of pre-planning required for a survey or self-assessment that includes ongoing data
collection such as surveillances or shadowing of key activities will be even more stringent,
since specific measures for validation of such data will need to be identified, and methods
for inclusion of these data sets into the analysis leading to topical area ratings and facility
ratings will need to be specified. The communication formality vary based on the scope and
relationship of the surveying team and the facility or organization. Attachment 5,
Notification Memo, provides a formal notification memo sample. This sample may not
benefit a self-assessment or survey of the local contractor performed by the federal staff.
DOE-STD-1217-2020/Rev FEBRUARY 2020
17
Planning Survey and Self-Assessment Activities
After completing the pre-planning and preliminary coordination activities, the team lead
shall:
Review data received from data call
Review LOIs
Review and assess SP for required information and note approved deviations to
DOE policies (See Attachment 12. Note: Appendices B through H accompany
Section 19
Attachment 12 and otherwise have no bearing on this Technical Standard);
Planning for performance tests, as needed
Identify who to interview
Determine what work to observe
Associate data-collection methods with each line of inquiry chosen
SURVEY AND SELF-ASSESSMENT CONDUCT
Valid sampling and accurate evaluation shall be the focus of all survey and self- assessment
activities during the conduct of the review. This focus shall be apparent during all phases of
the review activity so that, as far as possible, the review is a joint exercise between
reviewers and reviewed to identify and correct program issues, with the goal of improving
the local S&S program. Methodologies typically used to measure compliance include, but
are not limited to, document review, testing, observation, and interviews. Effective planning,
data collection, validation, and analysis of the information comprises the measurement of
performance used to improve the local S&S program and may reduce the potential for
differing opinions about the survey or self-assessment results. Additionally, the level of
assessment beyond compliance may also be limited based on the authority conducting the
assessment and the scope of their assessment.
In-Briefing
A formal in-briefing has traditionally been the initial onsite activity of the type of review
that one might call a “snapshot in time,” during which all data is collected in a relatively
brief interval – one day to a few weeks depending on the complexity of the site. More
recently, comprehensive survey and self-assessment reports have often been based, partially
or completely, upon data collected over an extended period, perhaps as long as a year. Even
in the case of the more extended data-collection effort, an in-briefing at the beginning of the
review period shall be conducted to assist in establishing and maintaining effective
communication with the site. A carefully prepared in-briefing can ensure a positive start for
the assessment, create a good first impression, and provide an opportunity to reduce the
DOE-STD-1217-2020/Rev FEBRUARY 2020
18
stress and tension associated with the survey or self-assessment. Items to be covered during
the facility in-briefing shall include (but are not limited to):
Survey or self-assessment scope and objectives;
Survey or self-assessment approach and methodology (with respect to data-
collection methods), including whether all data will be collected during one site
visit, whether the final report will be based on a set of observations conducted
throughout the assessment cycle, or some combination of these approaches;
For surveys, the level of reliance on the contractor assurance system and how data
derived from the contractor assurance system will be verified by the survey team
and included in the analysis of survey data;
Outline schedule of events and communication such as end-of-day meetings, exit
briefing date and time, expected completion date of report;
General introductions of team members; and,
Schedule of survey or self-assessment activities.
During this meeting or immediately following, the site subject matter experts and points of
contact shall collaborate with survey team members to streamline communication and data
gathering efforts.
Maintaining Communication
The team leader and topical leads shall plan on meeting frequently during the course of the
survey or self-assessment. The frequency of the meetings will be partially dictated by the
Section 20
assessment approach – snapshot or extended. The meetings ensure that the team leader and
topical leads understand the status of data collection to meet the selected LOIs; understand
information of interest for their respective topical area that was identified by other teams;
and maintain an awareness of emerging concerns.
The team also shall emphasize communication with the assessed site. Again, the frequency
of planned communications with site points of contact and site management will depend on
the pace of data collection. However, it is vital to effective communication with the site, and
therefore to the success of the assessment, that the points of contact and site management
remain informed concerning the progress of data collection and have early notice of
potential issues, particularly as they relate to rolling or shadow assessments if these
techniques are a portion of the survey or self- assessment procedure.
Data Collection
All members of the survey or self-assessment team work to collect data. Members of one
topical area often collect data that supports other topical areas. This data should be shared
DOE-STD-1217-2020/Rev FEBRUARY 2020
19
with the other interested topical area teams. For example, data collected about physical
security systems could also be useful to the analysis of protective force and nuclear material
control, as they are each elements of the overall protection design.
Data-collection efforts as well as analysis efforts shall always remain focused on the
effectiveness of the entire S&S program in providing appropriate security for national
security assets.
The selected LOIs always guide data collection. Within a line of inquiry, data collection can
be prioritized to allow schedule adjustments if complications or unforeseen events do not
permit completion of all planned activities. If this occurs, the team can concentrate on
gathering the data deemed most critical. Attachment 7, Sample LOIs form will assist survey
teams in the designation of order requirements that are critical to the effectiveness of the
program. High-priority data-collection activities shall be scheduled early in the process to
ensure that they are accomplished. When a full line of inquiry is endangered by data-
collection issues, the team leader will decide the best course of action.
All working papers and data-collection records, notes, checklists, and other documentation
accumulated during data collection shall be retained as backup documentation to the final
report. Ensure that all items are either reviewed by an authorized Derivative Classifier and
appropriately marked and protected, or are protected and marked at a level and category
specified by the team lead until review by an authorized Derivative Classifier can be
performed. Working papers are used to support the validity of findings and as a source of
information for future reviews.
These papers also can be used for assessing the progress of the review, especially if an
extended data-collection methodology is employed. Working papers are maintained at least
until the completion of the following survey or self-assessment. If deemed useful for
extended tracking and trending of issues, they may be retained for longer periods.
Data-collection methods and techniques are chosen based upon their utility in addressing the
selected LOIs. Each method and technique has an associated purpose and cost (both to the
Section 21
team and the facility). It is important to know when and where to use each method. For
example, running an expensive force-on-force performance test would not be cost-effective
if the data were available through an interview, observation, or limited scope performance
test (LSPT). An essential step that shall be accomplished in the planning phase is to
associate data-collection methods with each line of inquiry chosen.
The results of previous federal and contractor reviews, including facility description,
security interests examined, and findings and suggestions, shall be considered as a valuable
data source. The CAPs and resolution of the previous findings also are indicative of the
quality of the program and level of management support the program receives. In particular,
the review of past findings can reveal significant indicators of the effectiveness of S&S
program management. Concerns about open or repeat findings or the inability to establish
and implement effective CAPs in a particular topical area shall be discussed with the entire
DOE-STD-1217-2020/Rev FEBRUARY 2020
20
team. The determination of whether similar concerns exist in other topical areas will give
those performing the program management evaluation important indicators as to whether the
issues extend beyond the topical area in which they were first identified.
It is always desirable to minimize impacts to the facility. For example, procedures, such as
special nuclear material (SNM) transfers, security alarm preventive maintenance checks, or
portal monitor checks, shall, whenever possible, be observed during regularly scheduled
times rather than at the team’s request for a special demonstration. However, the need for
data to inform the analysis of a line of inquiry is primary. For example, if an operation such
as a nuclear material inventory is not scheduled during the survey or assessment and
observing the operation is critical to evaluating system operations, then initiating an
inventory through a performance test is appropriate.
Performance Tests
Performance testing is a key data-collection technique deserving special mention. While
compliance with specific directive requirements is one of the primary interests of a review
team, the actual performance of processes, personnel, and systems in providing protection to
national security assets shall be measured to provide an appropriate level of assurance that
assets are adequately protected. Performance tests are typically onsite exercises of the
personnel, equipment, and/or procedures of selected portions of S&S systems to determine
system effectiveness. Performance tests are not limited to the systems protecting SNM or
classified matter; they can be conducted to assess any portion of the facility security design.
In all cases, they must focus on the elements of a topical area or sub-topical area that are
critical to the effectiveness of that topical area or sub-topical area. Performance tests may
also be in written form if the material is difficult or hazardous to test. Performance tests will
not necessarily reflect the overall state of security at a facility because the observed result of
a performance test usually reflects only on the security element tested, not the full protection
system. Further, the outcome of a single performance test can reflect temporary or unusual
conditions existing at the time of the test. Therefore, while the results of a single
Section 22
performance test are valid data, performance test data shall be placed in context with other
findings, observations, and conclusions.
Performance tests shall be designed to provide objective data to assist the team in
determining whether:
Personnel know and follow procedures;
Procedures are effective;
Plans and procedures accurately describe operations conduct;
The processes described in procedures produce the expected product;
Personnel know how to operate equipment;
DOE-STD-1217-2020/Rev FEBRUARY 2020
21
Personnel and equipment interact effectively;
Equipment is functional, operational and effective;
Equipment has adequate sensitivity; and/or,
Equipment meets design objectives.
If the facility has a program for conducting performance tests, the team shall consider
requesting that the facility conduct one of its performance tests rather than, or in addition to,
one designed by the team. Observing the facility conduct a performance test provides
information concerning the facility's own assessment program as well as providing the
needed data about the protection element being tested. An additional source of performance
data is the routine documentation maintained in the course of implementing an S&S
program. Performance data reflected in facility documentation such as inventory records,
files, classified documents, reports, and access logs are useful in assessing the effectiveness
of control processes. Attachment 8 provides a Performance Test Safety Plan template and
Attachment 9 provides a Performance Test Plan template.
Data Validation
An essential component of data collection is data validation. When any data is collected, it is
imperative that the data collector determine whether site personnel observing the same event
perceive the same outcome as the data collector. If they do not, it is essential to understand
why not and to inform the site observer why the data collector has a different perception. It
is also essential to share this perception because of the limited sample set that is collected
during a review. If site personnel understand that the data collector perceives the result of an
observation differently than they do, it provides them an opportunity to supply additional
data that provides a fuller context to the data collector’s view of the result. For this reason, it
is preferable that two survey team members are present during data review.
Similarly, it is important for the team to share perceptions with site management on a
periodic basis. The Survey or Self-Assessment Team Leader shall inform the Site
management when the assessment team is moving toward a conclusion in a particular area,
whether that conclusion is positive or negative. Again, site management might be able to
offer additional information that would modify the team’s view of the situation.
When final conclusions are reached in the survey or self-assessment report, they shall be
based upon a set of facts agreed to by both the review team and the site. However, the
analysis of those facts, and the subsequent assessment of site protection effectiveness, is
always the sole prerogative of the review team.
Data Analysis
After all data is collected and verified to be current and accurate, it shall be compiled and
analyzed to determine the effectiveness of protection by overall facility, by topical area,
DOE-STD-1217-2020/Rev FEBRUARY 2020
22
and/or by sub-topical area, as appropriate. The facts established during the data collection
Section 23
and validated by the site and the team’s analysis of those facts form the basis for
observations and findings in the final report. Even when no findings or observations are
made, the presentation of validated data and the logical interpretation of that data is a
valuable contribution to management understanding of site status and shall never be
neglected in the final report. Key facts and the team analysis of them shall be documented in
the report immediately before an observation or finding is made and additional supporting
information, if any, shall be contained in the retained working papers. The logical path from
facts to the finding or observation needs to be clear in the final report, even if some detail is
omitted.
Findings and observations shall be clearly identifiable in the final report and shall be
highlighted during the close out briefing. It is often helpful to repeat all findings and
observations from all topical areas in a single appendix or attachment to the report. Tracking
and trending of results is enhanced by the assignment of a unique tracking number to a
finding or observation, especially findings, to assist in tracking and reporting on actions
developed or taken in response. For findings in particular, since they must be entered into
the SSIMS database, a tracking number is needed that conforms to the SSIMS finding
format. An example would be 34-NOV-01-HQ-0123-SSIS-PM-001.18298, where 34-NOV-
01 is the end date of the survey, HQ is the cognizant security office, 0123 is the facility code
for the surveyed facility, SSIS is the type of survey (see DOE O 470.4B Minor Change 2,
Appendix A, Section 2, paragraph 3), PM is the topical area in which the finding is made,
001 is a sequential number of the finding within the topical area, and 12898 is the facility
code responsible for correcting the finding.
The terms finding, observation, opportunity for improvement (OFI), and others are used in
surveys and self-assessment reports to indicate issues that require management attention.
The term finding is defined in DOE policy and is always used to identify any validated
program deficiency (a failure to meet a performance or compliance requirement derived
either from internal or external directives or the approved site/facility security plan.) The
term observation is used to identify areas where the review team perceives a need for
particular management attention, even if DOE requirements and security plan performance
elements have been met.
Observations also may be used to identify potential areas for program enhancement. In some
cases, survey and self-assessment programs have used the term OFI. OFI are similar in
intent to an observation, but are used to clearly separate potentially positive results from
potentially negative ones.
Usually this distinction is made when management believes both findings and observations
are indicators that program improvements are needed whereas an OFI indicates that the
review team has identified a potential program improvement which local security
management might consider. Findings, observations, opportunities for improvement (OFI),
or any other conclusion reached during data analysis shall be based upon validated data
collected during the various activities comprising the review.
DOE-STD-1217-2020/Rev FEBRUARY 2020
23
Ratings
Upon completion of survey or self-assessment data collection, a recommended rating for
Section 24
each topical area and sub-topical area reviewed shall be determined, usually by the topical
area team members. When considering a topical area rating, the topical area team shall
consider the results from each sub-topical area and topical area and the relative contribution
of each sub-topical area and topical area to the success of the overall topic within the local
context. The logic and determinations supporting the recommended ratings shall be included
in the draft survey or self-assessment report to support the topical area rating proposed to the
team leader.
The team leader, in consultation with topical leads and team members, shall determine the
composite facility rating and the topical area and sub-topical area ratings, based upon the
results of the survey or self-assessment. The team leader shall ensure that the basis for the
rating determinations is explained in the survey or self-assessment report. A composite
facility rating shall be based upon the topical area and sub-topical area ratings and an
analysis of the relative importance of each topical area and sub-topical area in the overall
protection design of the site/facility. As with each of the topical area and sub-topical area
ratings, the logic and considerations leading to the award of the composite facility rating
shall be explicitly addressed in the survey report.
The ratings listed below are used for all surveys (except termination), reviews, and self-
assessments. Does Not Apply and Not Applicable (NR) shall also be used in lieu of a rating
when appropriate.
Satisfactory. The element being evaluated meets protection objectives or provides
reasonable assurance that protection objectives are being met.
Marginal. The element being evaluated partially meets protection objectives or
provides questionable assurance that protection objectives are being met.
Unsatisfactory. The element being evaluated does not meet protection objectives or
does not provide adequate assurance that protection objectives are being met.
A topical area or sub-topical area shall be rated Satisfactory if all aspects of the topical area
or sub-topical area are found to be as depicted in the approved security plan, including any
approved equivalences or exemptions, and observed performance is sufficient to provide
assurance that the topical area or sub-topical area elements are providing the level of
protection assumed in the approved site/facility security plan. In particular, any security
element within the topical area or sub-topical area that is identified as an essential element
shall demonstrate performance at least equal to that required to support overall security
effectiveness, as documented in the approved security plan. A topical area or sub-topical
area shall also be rated Satisfactory if, for any measure not met, documented and approved
compensatory measures are in place to provide comparable protection and action is either
under way to return the security elements comprising the topical area or sub-topical area to
DOE-STD-1217-2020/Rev FEBRUARY 2020
24
full capability or an approved plan to restore the security elements is being satisfactorily
pursued. In some instances, a topical area or sub-topical area might be rated Satisfactory
when some component element fails to meet an applicable measure but, in the judgment of
the topical area experts and the Survey Team Leader, the impact of that shortfall does not
Section 25
erode the contribution of the topical area or sub-topical area to the effectiveness of S&S
under the approved security plan. The logic underlying such a decision shall be included in
the survey report. Notwithstanding the Satisfactory rating, however, the component shall be
brought to full effectiveness as soon as possible in all cases.
Noncompliance with one or more requirements of the approved security plan shall result in a
rating of Marginal or Unsatisfactory for a survey or self-assessment topical area or sub-
topical area when the observed shortcoming(s) reduces the assurance that the S&S program,
as depicted in the approved security plan, represents the actual S&S practices at the site or
facility. If performance testing indicates that a significant question regarding adequate
protection exists, even when the site/facility is in full compliance with the approved security
plans, a topical area shall be rated no higher than Marginal.
Assignment of one or more sub-topical area ratings of Marginal or Unsatisfactory shall lead
the topical area team to carefully analyze the seriousness and multiplicity of findings in a
sub-topical area against the definitions for Marginal or Unsatisfactory before assigning a
rating to a topical. If less-than-satisfactory sub-topical area ratings exist within a topical area
rated Satisfactory, the survey or self-assessment report shall explain why the impact of these
sub-topical area ratings do not justify a reduced topical area rating.
A topical area or sub-topical area shall be rated Unsatisfactory if limited compliance with
the approved security plan and/or performance testing results indicate that the topical area or
sub-topical area contributions to the approved security plan fall short of the performance
required to protect security assets. Performance shall consider the adequacy of any
compensatory measures in place when the rating is determined, since adequate
compensatory measures supported by a plan to restore the planned functionality can result in
a satisfactory rating. However, an unsatisfactory rating shall also be awarded if no plan
exists for restoring security element function and removing current compensatory measures,
even if the compensatory measures provide a temporary mitigation of the security concern.
After ratings have been assigned to all topical areas and sub-topical areas, a rating shall be
assigned to the site/facility. While the same three ratings are available – Satisfactory,
Marginal, and Unsatisfactory – the context is somewhat different. The site/facility rating
shall be based upon an integrated view of the entire security program, taking into
consideration the topical area ratings. The site/facility rating is the team leader’s certification
to the appointing official regarding the security status of the site/facility. A Satisfactory
rating indicates that the site/facility is operating in accordance with the approved security
plans and that the demonstrated S&S performance is at least equal to that required to
adequately protect all site/facility security assets. A Marginal rating indicates that action is
needed to advance the site/facility toward compliance with the approved security plans
and/or to fully achieve the performance anticipated when the security plans were approved.
DOE-STD-1217-2020/Rev FEBRUARY 2020
25
An Unsatisfactory rating conveys the team’s judgment that immediate management attention
Section 26
is needed to ensure continued protection of one or more of the national security assets
located at the site/facility or to ensure that adequate progress will be maintained toward
achieving a satisfactory status.
Exit Briefing
At the conclusion of the survey or self-assessment, an exit briefing shall be conducted with
management officials of the organization reviewed. The briefing shall include at least a
summary of the following areas:
Program findings, observations, OFI, and strengths;
Corrective action reporting requirements for all open findings, regardless of source;
and,
Topical area, sub-topical area, and facility ratings.
The team leader shall prepare an agenda for the exit briefing. Because of the potential for
confrontation during the briefing, it is generally best for the team leader to provide the
briefing and, if necessary, to ask the topical leads to assist with technical details.
Agreements and commitments made during the conduct of the survey shall be summarized
during the exit briefing. This provides an opportunity to identify potential misconceptions
before they are presented formally to management outside the surveyed facility. Agreements
and commitments must be documented in writing as soon as possible.
REPORT PREPARATION
As soon as possible after the survey or self-assessment is completed, a formal report of the
results shall be finalized, Appendix A provides an extensive sample report format. The
individual team members and topical area and sub-topical leads shall ensure that a complete,
concise, and accurate final report of the results is compiled in a timely manner. The report
preparation shall be overseen by the team leader, who has ultimate responsibility for its
completion and accuracy.
Reports and all working papers and other retained material shall be evaluated and reviewed
by an authorized Derivative Classifier before publication of the final report. Before this
review, the working drafts shall be protected and marked as working papers classified at a
level determined by the team leader to be the highest likely classification of the final report,
including paragraph markings as appropriate. Required protection and control shall be
provided for classified or sensitive information. Even if the overall report is determined to
be Restricted Data (thereby eliminating the requirement for paragraph marking), each
finding shall be marked with its classification level and category to ensure that the
information will continue to be protected appropriately when the finding is extracted from
the report.
DOE-STD-1217-2020/Rev FEBRUARY 2020
26
Team meetings shall be held as necessary to facilitate the finalization of the survey report
and evaluate lessons learned from the review. During these meetings the following actions
shall be undertaken as necessary:
Review draft report or report section(s);
Review lessons learned;
Identify trends that might indicate areas of interest for the next review;
Identify helpful information sources and resources to consider in the next review;
Review and summarize agreements and commitments made during the conduct of
the review and the exit briefing;
Determine final report content, especially for areas of contention;
Document any unique organizational structures/functions or item of potential use to
those planning the next review; and, prepare for briefings on the review results to
DOE and contractor management, as appropriate.
Section 27
The survey report shall consider all available data in its analysis. Depending upon the survey
methods used, this may include data that reflect:
documented observations of activities at the surveyed facility;
full and limited scope performance tests;
documented data collection conducted during the survey period;
the results of any documented federal shadowing of contractor self-assessments;
targeted data collection conducted to satisfy remaining data requirements late in the
survey period (particularly as required to verify accuracy of information acquired
during rolling assessments, contractor shadow activities, or derived from contractor
reports);
any other documented, objective data that the survey team determines is pertinent.
The resulting report provides measurement results, an analysis of those results, including
ratings, and specific identification of areas needing improvement, in the form of findings,
observations, and/or suggestions to management.
When possible and appropriate, the appointing authority responsible for the conduct of the
survey or self-assessment shall require that a review board be established to review the draft
report and make recommendations to the team leader to improve the report. Such a board
DOE-STD-1217-2020/Rev FEBRUARY 2020
27
can significantly improve the final product by verifying that there is a clear, logical
presentation of results. Questions regarding what assets were present at the facility, what
data-collection methods were used, what facts were discovered using those methods, what
facts were considered and with what relative weight to arrive at findings and ratings, and
what factors support the overall facility rating shall all be clearly addressed in the report.
Use of a review board can ensure that all these questions are adequately addressed and
logically presented in the final report.
After the report has been completed, SSIMS data entries have been made, and the report has
been distributed, the team leader shall document and file lessons learned. These lessons
learned shall identify what processes were effective, observations of team dynamics, and
specific recommendations for the next review. The team leader shall include lessons learned
as reported by topical leads and their teams. These lessons learned shall be provided to the
appointing authority for information and evaluation to improve the survey process.
ISSUES MANAGEMENT PROGRAM
A survey or self-assessment activity only fulfills a portion of its objective if the reviewed
organization lacks a robust issues management process. DOE directives require DOE
organizations to have an issues management process that is capable of categorizing findings
based on risk and priority, to ensure relevant line management findings are effectively
communicated to the contractors, and ensure problems are evaluated and corrected on a
timely basis.
The issues management process, at a minimum, shall include the following for issues
categorized as high significance findings:
A thorough analysis of the underlying causal factors;
Implementation of identified corrective action(s)/CAP that address the cause(s) of the
findings to prevent recurrence;
An effectiveness review conducted by trained and qualified personnel to verify the
corrective action/CAP was effectively implemented and prevented recurrences. The
review shall include the following:
o documentation of the analysis process and the results of identified underlying
Section 28
causal factors
o maintenance tracking, in a readily accessible system, of corrective
actions/CAPs; including schedules for the effectiveness reviews;
Appointment of a mutually agreed upon lead office when findings and/or corrective
actions apply to more than one Program Secretarial Office/Departmental Element
DOE-STD-1217-2020/Rev FEBRUARY 2020
28
Corrective Action Program
Findings are deficiencies that warrant a high level of attention on the part of management. If
a finding is left uncorrected, it could adversely affect the DOE mission, the environment,
worker safety or health, the public or national security. Findings define the specific nature
of the deficiency, whether it is localized or indicative of a systemic problem, and identify
which organization is responsible for corrective actions. A corrective action program shall
include, at a minimum:
Causal analysis appropriate to the complexity of the issue identified (the rigor of
causal analysis must not be based upon the perceived consequence of protection
element failure – sometimes very serious issues have readily apparent root causes
and sometimes important lessons can be learned from issues that have little
immediate protection impact – but on the difficulty in identifying the root causes)
Attachment 11 Corrective Action and Causal Analysis provides helpful examples
for forms and a process for defining the root cause analysis;
Identification and implementation of compensatory measures required to maintain
required performance levels while corrective actions are in progress;
Identification and implementation of priorities for completion of corrective actions
if all cannot be pursued simultaneously (priorities might be based on availability of
resources, costs of associated compensatory measures, and many other factors);
Identification and implementation of necessary validation testing when corrective
actions are complete and before compensatory measures are removed; and,
A means of tracking and trending causal factors to allow identification of possible
systemic management issues that are only discernible when viewing the results of
multiple reviews. It must be noted that tracking in SSIMS is required for survey
findings.
To maximize the value of surveys and self-assessments, it may also be desirable to go
beyond the basic requirements applicable to findings and corrective actions. For example,
observations do not specifically require action on the part of the site management, but the
careful consideration of observations can lead to improvements in S&S program
effectiveness and/or efficiency. Other considerations noted in the survey or self-assessment
report or even in supporting working papers may be useful as well, even if the team did not
believe they should be highlighted as a finding or an observation at the time of the final
report. An examination of these additional factors in conjunction with the findings may
contribute to the development of more effective corrective actions or lead to more in-depth
improvements which will strengthen and enhance the overall security posture at the site.
DOE-STD-1217-2020/Rev FEBRUARY 2020
29
Process Improvement
When the scope of the survey and resources allow, assessing the effectiveness of the
program and identifying resource savings is the desirable outcome of a survey. While
compliance audits have a place in the protection of nuclear assets, personnel, and classified
Section 29
matter, performance effectiveness is ensuring the required protection is present while
making the best use of resources and expertise. When time permits, the process outlined
below shall be completed and submitted as part of the final report. As this effort requires
resources and a focus on program management, the assessment team shall never conduct
these efforts without support by the managers of the program assessed. Review of this level
is time consuming and resource intense; it is not beneficial or expected that survey teams
assess every topical area and sub-topical area. Process improvement shall focus on those
topical area and sub-topical areas that have the greatest impact to security and the most
potential for saved resources.
The steps to process improvement and the tools provided below align to this concept. The
five steps of the survey process improvement technique are:
Step 1. understanding and map the current process;
Step 2, complete a value added analysis;
Step 3. develop an improved process;
Step 4. update documentation and develop metrics; and
Step 5. measure for success and return to step 1.
Step 1: Understand and Map the Current Process
Survey team members work with subject matter experts to outline the process in a
systematic method. This can work best in an outline form or in a flow chart such as the
example below. There are numerous types of flowcharts and ways to complete the charts.
The Cross Functional Flow chart was selected not only to document the flow information
but also who was responsible, allowing for identification of information loops which impact
the process.
There are a few basic steps and best practices that can help in describing and mapping the
process:
Form a team with members from any area or organization that provides inputs,
manages, or contributes to the process. This helps ensure that all aspects of the
process are considered and accounted for. Although not necessary, it may also be
beneficial to get input from any downstream process owners.
DOE-STD-1217-2020/Rev FEBRUARY 2020
30
Identify the steps in the process. It is usually best to start with the beginning and end
steps, including the inputs and outputs, and then work to fill in the steps in-between.
It is very important to clearly define where the process being mapped begins and
ends.
Identify who owns each step, by job title and/or organization.
Organize the steps in sequential order from beginning to end. Use this information
to draw the baseline process map for the current process using whatever type of map
the team has selected.
The example in Figure 12.1 maps the process to establish initial communication through a
formal memo and data call as part of the initial planning.
DOE-STD-1217-2020/Rev FEBRUARY 2020
31
Figure 12:1 Initial Notification Memo Process Map
Step 2: Complete a Value Added Analysis
Review the documented process identify in each step if it is specifically required by the
order, performed to meet order requirements, or other. Analyze all steps identified as ‘other’
for whether they are inconsistencies, bottlenecks or are unnecessary, or whether the steps are
necessary due to requirements, internal or external, outside of orders. Necessary/required
steps should be analyzed further to determine if there are opportunities for optimization,
such as improvements in efficiency or effectiveness through delegation of authority to an
employee or deploying new technology.
Section 30
DOE-STD-1217-2020/Rev FEBRUARY 2020
32
Continuing with the example, Figure 12.2, below uses the colors green, blue, and red
accordingly.
Figure 12:2 Initial Notification Memo Color-Coded Process Map
DOE-STD-1217-2020/Rev FEBRUARY 2020
33
Step 3: Develop an Improved Process
All steps required by order or to meet order requirements must be retained in the improved
process. Remove all steps determined to be unnecessary. Revise all other steps determined
to be necessary/required, incorporating any optimization and/or new owners identified in
Step 2. Reconnect all of the required and necessary steps in sequential order from beginning
to end, and draw the improved process map, below in Figure 12.3.
Figure 12:3 Notification Memo Improved Process Map
DOE-STD-1217-2020/Rev FEBRUARY 2020
34
Step 4: Update Documentation and Develop Metrics
Using the new process, update standard operating procedures and desktop procedures to
align with the improved process. Ensure that leadership and employees are aware of the
proposed process. Although the survey team and subject matter experts have developed this
process there may be resource constraints or impact to other programs with which they are
not aware. Additionally, develop qualitative or quantitative metrics to ensure the process is
actually successful. Measurements such as time, money, space are all very quantifiable
although subjective measures such as employee and customer delight should not be ignored.
Step 5: Measure for Success and Return to Step 1.
At this stage, the process has been turned over to the responsible process owners and subject
matter experts, who will monitor the process for efficiency and effectiveness. Additional
support from the survey team may be necessary if the new process experiences problems, or
if further optimization is possible or necessary. If this is the case, the 5-step process
improvement technique can be repeated, beginning again at Step 1.
DOE-STD-1217-2020/Rev FEBRUARY 2020
31
ATTACHMENT 1: RISK BASED ASSESSMENT SCHEDULING PROCESS
file://///Doe.local/dfsfr/ORG_AU/AU-50/AU-51/PPM/Conference Room Materials (470_4B)/Survey and Assessments Tech Standard/2019 Rplacement Charts and Notes/DOE-STD-1217-2016 ATTM 1-1 - Risk Based Assessment Scheduling Process.xlsx
DOE-STD-1217-2020/Rev FEBRUARY 2020
32
DOE-STD-1217-2020/Rev FEBRUARY 2020
33
DOE-STD-1217-2020/Rev FEBRUARY 2020
34
ATTACHMENT 2: DOE FORM 470.8 SURVEY/INSPECTION REPORT FORM
DOE-STD-1217-2020/Rev FEBRUARY 2020
35
ATTACHMENT 3: .SURVEY PREPPARATION AND REPORT CHECKLIST
Survey Site: Travel Dates: ______________
Survey Date: ________________
Team Members:
Survey Prep TM ECD COMMENTS
Contact Site POC to establish date of assessment
(70 days prior)
Draft Data Call Memo (65 days prior)
Forward Final Data Call Memo to Site POC (50
days prior)
Review previous survey report (30 days prior)
Review previous areas of Concerns/Findings (30
days prior)
Review CAPS (30 days prior)
Using previous information and data call develop
Site-Specific LOIs for Topical area Areas (20
days prior)
Develop survey timeline (15 days prior)
Request CPCI Listing from PerSec
Request Incident Reports from Security Officer
Forward timeline for site approval (10 days prior)
Coordinate interviews with site POC (10 days
prior)
Coordinate performance testing with site POC (10
days prior)
Send site final LOIs (5 days prior)
In-brief presentation (first day)
Section 31
Conduct assessment activities
Out-brief presentation (last day)
DOE-STD-1217-2020/Rev FEBRUARY 2020
36
Drafting Report/Review ECD COMMENTS
Initial Draft Team Member:
(30 days)
Reviewing Team Member:
(10 days)
Final Reviewing Team Member:
(10 days)
Team Lead:
(5 days)
Initial Draft Team Member reconciles
Team Lead comments (5 days)
Contract POC:
(10 days)
Team reconciles Contract POC
comments (10 days)
Program Manager:
(10 days)
Team reconciles Program Manager
comments (10 days)
Submit report to Admin for correction
and submission for approval
Input issues into Survey database (5
days)
Input Findings into SSIMS (5 days)
Report Attachments COMMENTS
Survey Report Cover Memo (5 days)
DOE Form 470.8 Report Form
DOE Form 470.1 CSCS
DOE Form 470.2 FDAR
Open Findings (SSIMS)
DOE-STD-1217-2020/Rev FEBRUARY 2020
37
ATTACHMENT 4: SURVEY PLAN TEMPLATE
1. Title of survey
2. Location of facility
3. Purpose of survey
4. Survey dates
5. General site/facility information /description
a. Site/Facility data
b. Work/activities performed
c. Operating organization (contractor)
d. S&S interests
e. Strategic Partnership Projects or other security activities
6. Scope of survey
a. Period of review, including extended observation or data collection if applicable
b. Objectives
c. Topical areas to be included/excluded and justification for each
d. Topical areas with findings from previous surveys, inspections reports, audits and appraisals
(e.g. Government Accountability Office (GAO)/ Inspector General (IG))
e. Special areas/items of interest/concern
7. Survey planning and preparation
a. Performance tests (associated safety plans)
b. Survey guide information
c. Pre-survey information
8. Survey conduct—approach and methodology
a. Documents to be reviewed
b. Performance tests
DOE-STD-1217-2020/Rev FEBRUARY 2020
38
c. Individuals to be interviewed
d. Sampling activities, including extended observation, shadowing or surveillance if applicable
9. Schedule of activities
a. Survey schedule
b. In-briefing information
c. Coordinating instructions
d. Exit briefing
e. Schedule for report development
10. Team composition/assignments
a. Team members
b. Assignments/responsibilities
c. Contractor support
d. Points of contact at the facility
11. Authority/governing documents
a. Directives
b. References (unclassified/classified)
12. Survey report format
13. Administration, support, and logistics
a. Work facilities
b. Transportation
c. Computer support
d. Administrative support
e. Classification support
f. Training requirements
DOE-STD-1217-2020/Rev FEBRUARY 2020
39
14. Appendices
a. Performance tests (including Safety Plans)
b. Survey guides
c. Forms
DOE-STD-1217-2020/Rev FEBRUARY 2020
40
ATTACHMENT 5: NOTIFICATION MEMO
DATE:
TO:
FROM:
SUBJECT: Safeguards and Security Periodic Survey (SSPS)
The (Surveying Organization) will conduct an SSPS of the (Organization to be Surveyed)
during the period of (Date). This will be a comprehensive survey and will be conducted in
accordance with (Appendix, Section, Chapter, etc.) of DOE O XXX, (Title). The survey will
examine the performance of safeguards and security programs to ensure that S&S measures
employed by the facility are adequate for the protection of security assets and interests and
will encompass all topical areas on DOE F 470.8, Survey/Inspection Report Form.
To aid in the planning process, you are requested to provide the documentation listed in the
Section 32
Attachment. These documents are to be provided to (Survey Team Leader) not later than
close of business (Day, Date). In addition, please provide points-of-contact information for
each topical area, including pagers/cellphone and phone numbers. The names of (Surveying
Organization)’s Survey Team Leader and Topical Leads will be forwarded to your
organization under separate cover.
Survey activities will begin with an in-briefing at (Time, Date), in (Place). Points of contact
representing your organization in each topical area should plan to attend.
If you have any questions or require additional information, please contact (Survey Team
Leader) on (phone number).
DOE-STD-1217-2020/Rev FEBRUARY
2020
41
ATTACHMENT 6: DATA CALL INFORMATION
All documentation provided shall include the past 12 months unless otherwise noted.
(The following is a list of documentation that may be considered for review during
survey conduct. Whether or not to include these documents as part of the data call or to
review during the Conduct phase will be determined based on the focus of each topical
area supported by the initial risk assessment (Attachment 1), as outlined in the survey
plan. The list is not comprehensive; other documents may be available which shall also
be considered)
a. Program Planning and Management
Organization charts depicting the Safeguards and Security (S&S) management
structure and S&S functional structure
Documents depicting responsibilities and authorities of S&S management,
including all delegations of authority and designations of Officially Designated
Federal Security Authority (ODFSA) and Officially Designated Security
Authority (ODSA)
Position descriptions for S&S management
Program Office and local instructions for the implementation of S&S programs
Supplemental documents and guidance for implementing S&S programs
Site/Facility security plan (SP) and any referenced or supplemental plans and
documentation
Emergency management and security condition (SECON) plans
Survey reports, inspection reports, Government Accountability Office and
Inspector General audit/appraisal reports, self-assessment reports
Staff training records
Contract(s), including Statement of Work
List of all subcontractors and consultants conducting work for the contractor
List of U.S. Department of Energy (DOE) directives and security clauses that
have been incorporated into applicable contracts
DOE-STD-1217-2020/Rev FEBRUARY
2020
42
Approved and pending equivalencies/exemptions to DOE directives and any
deviations to national drivers (e.g., Code of Federal Regulations)
Copy of the facility registration
Applicable memoranda of understanding (MOU)/agreement (MOA)
Completed Foreign Ownership, Control or Influence (FOCI) questionnaire (SF
328)
Key Management Personnel (KMP) list
Dates of all applicable FOCI determinations and copies of any mitigation
agreements
A copy of the contractor's records of all contracts and subcontracts involving
access authorizations
Vulnerability Analysis (VA) reports
Security Risk Assessment (SRA) reports
Contingency plans
Survey and self-assessment program procedures
Issues management plans and procedures
CAPs and status updates for all open deficiencies
Finding/deficiency corrective action validation and closing procedures
Incidents of Security Concern procedure, including initial notification and
inquiry reports
Section 33
Contract Security Classification Specification (CSCS) forms
Facility Data and Approval Record (FDAR) forms
Copy of the approved Performance Assurance Program Plan
List of essential elements documented in the Performance Assurance program
and the testing schedule for each
Documentation of the integrated contractor assurance system
DOE-STD-1217-2020/Rev FEBRUARY
2020
43
b. Protective Force (PF)
Organization and function charts
PF general, special and post orders
PF shift schedules and post assignments
PF standard equipment issuance (Security Police Officer (SPO) I, II, III, and
Special Response Team (SRT))
PF weapons and ammunition inventories
Weapons maintenance logs
MOU with local law enforcement agencies and documentation of exercises
conducted with those agencies
Integration of crisis management personnel into procedures
PF training records which include:
A list of PF personnel who are subject to weapons qualification within 90 days of
the start date of the survey
A list of PF personnel who are medically certified to participate in the physical
fitness program
All documentation of PF exercises conducted since the last S&S survey
Instructor certification
Job analysis
Job task analyses
Security Emergency Response Plan (SERP)
Security Incident Response Plan (SIRP)
Site/Facility Evacuation Response Plans
Security Contingency Response Plans
Target folders
DOE-STD-1217-2020/Rev FEBRUARY
2020
44
Schedule for performance testing (results of recent tests)
Compensatory measures currently in place (including pertinent documentation)
Procedures (administrative, training, non-response-related operational
requirements)
Access/badge control
Information containing, at a minimum, policies/procedures for issuing, replacing,
and recovering passes/badges
Inventories (since last S&S survey) of passes/badges made, issued, lost,
recovered, returned, and destroyed
Shipment security plans
Shipment procedures
In-transit emergency plan
Shipment emergency response plan
c. Physical Protection
Organization and function charts
Lock and key records and procedures
Automated access control system records and procedures (including biometric
access input) as well as access credential issuances (e.g., keycards, tokens)
Barrier maintenance procedures/records
Property control procedures
Access control procedures
Local performance testing plans and procedures
Physical security system description(s) and location(s)
Intrusion detection system (IDS) maintenance and testing records and procedures
IDS Analysis and Evaluation Report
DOE-STD-1217-2020/Rev FEBRUARY
2020
45
Unscheduled alarm reports
Central Alarm Station (CAS)/Secondary Alarm Station (SAS) procedures
(interface description)
Emergency response for CAS/SAS recovery
Emergency power systems (uninterruptible power supply system)
Compensatory procedures for equipment outages
Security container documentation and maintenance records
Automated systems description and procedures
Manual
Procedures
Controls
Calibration and testing procedures and records (e.g., X-ray, metal detectors, IDS)
Inspection procedures
Limited Scope Performance Test (LSPT) results
d. Information Security
Organization and function charts
Training records
Technical surveillance countermeasure (TSCM) survey reports
Site inventory of accredited systems, showing property tag number, the
Section 34
accrediting authority, and most recent accreditation date for each
Formal assignments of TSCM personnel
TSCM activity support memoranda (if applicable)
Local TSCM implementation guidance
TSCM Officer (TSCMO) service schedules, files, and corrective action reports
DOE-STD-1217-2020/Rev FEBRUARY
2020
46
TSCM team equipment maintenance and calibration files
TSCM team training and certification records
Operations Security (OPSEC) Plan
OPSEC procedures
OPSEC program files
Local threat statement
Critical Program Information
Counter-Imagery Program Plan (if applicable)
Number of derivative classifiers and declassifiers
Appointment letters (e.g., Inquiry Officer, custodians)
Training records, reports, and lesson plans
Classification guidance
Classified Matter Protection and Control (CMPC) procedures
Control station procedures
List of classified holdings, including documents, electronic media, and matter
Number of Special Access Programs (SAPs)
e. Personnel Security
Local procedures for terminations, leave of absences, reinstating clearances,
clearance processing, exit briefing process
Contractor access authorization requests
Sample initial, comprehensive, refresher, and termination briefing materials
Previous findings and CAPs
Reciprocal access authorization documentation
Awareness tools (posters, newsletters)
DOE-STD-1217-2020/Rev FEBRUARY
2020
47
Security infraction and violation records
Requests for visit or access approval (notification and approval of incoming and
outgoing classified visits records and records of cleared non-DOE personnel
granted access to RD)
Written delegation of senior federal official authorized to make determinations
on access to Restricted Data by non-DOE personnel in connection with a
classified visit
Visitor control logs
Local visitor control procedures
Central Personnel Clearance Index (CPCI) list of individuals overdue for
reinvestigation
Drug testing/handling procedures
Drug testing records
Human Reliability Program (HRP) participants
HRP criteria/plans/procedures
Random test procedures
List of individuals on leaves of absence and the associated procedures for
tracking
List of inactive classified contracts
List of personnel with access authorizations and the associated contract(s)
List of clearances terminated during the survey period
List of all access authorizations held by the contractor, including all contractors
and subcontractors that have cleared employees conducting work at the facility.
This list can come from the DOE CPCI of access authorizations held by the
contractor. The CPCI and contractor lists, including the current KMP list, shall be
compared for discrepancies.
f. Insider Threat Program (ITP)
Local Insider Threat Working Group (LITWG) charter
DOE-STD-1217-2020/Rev FEBRUARY
2020
48
ITP Standard Operating Procedures (SOP) or other guidance
ITP records management procedures
Name/Position/Title of LITWG Chair
List of LITWG members
ITP Training Records for Cleared Employees
Copies of ITP Training and Awareness Materials
g. Foreign Visitors and Assignments
List of foreign visitors from sensitive countries during the survey period
Specific security plans for foreign visitors from sensitive countries
Escort procedures
Local procedures for requesting, processing, and approving visits and
assignments
Section 35
List of foreign visitors or assignees, including hosts, during survey period
Incident reports involving foreign nationals
Requests for foreign national visits
Indices checks
Documentation authorizing approval for specific categories of visits and
assignments
Sensitive country listings
Equivalencies/exemptions pertinent to visits and assignments
Personnel assignment agreements
h. Nuclear Material Control and Accountability (MC&A)
MC&A plans and procedures
Training records, reports, and lesson plans
DOE-STD-1217-2020/Rev FEBRUARY
2020
49
Performance tests
Categorization process documentation
Incident reporting process and procedures
Emergency response plans and facility procedures
Database descriptions
Material Balance Area (MBA) account structure
Material transfer records
Internal control procedures
Nuclear Material Management and Safeguards System (NMMSS) reports
Shipper/receiver difference procedures and records
Material control indicator program
Inventory difference program
Materials containment documentation
Facility procedures
Material access program
Authorization access lists
Search procedures
Material surveillance procedures
Portal monitor records and procedures
Daily administrative check program and procedures
Tamper-indicating device program
DOE-STD-1217-2020/Rev FEBRUARY 2020
50
ATTACHMENT 7: SAMPLE LINE OF INQUIRY FORM
DOE-STD-1217-2020/Rev FEBRUARY
2020
51
ATTACHMENT 8: PERFORMANCE TEST SAFETY PLAN EXAMPLE
PERFORMANCE TEST SAFETY PLAN
I, , acknowledge receipt of the attached safety plan. I
understand it is my responsibility to become familiar and comply with the contents of this safety
plan.
Acknowledgment of the receipt of this safety plan is a requirement to participate in or observe this
exercise. This page shall be signed and returned no later than .
Name
Signature
Position
Date
(1) Detection of Contraband and Prohibited Items
(Type of Performance Test)
(2) Ongoing 365 Days per Year; 24 Hours per Day
(Performance Test Date and Time)
(3) Detection of Contraband and Prohibited Items, John Doe
(Safety Plan Name and Person Preparing)
(4) ALL LIMITED SCOPE PERFORMANCE TESTS (LSPTs) WILL BE CONDUCTED IN
CONFORMANCE WITH THIS SAFETY PLAN AND ONLY AFTER SPECIFIC APPROVAL
TO CONDUCT THE LSPTs HAS BEEN GRANTED BY A RESPONSIBLE U.S.
DEPARTMENT OF ENERGY OFFICIAL. PERSONNEL SERVING AS CONTROLLERS
WILL BE FULLY QUALIFIED IN ALL ASPECTS OF THE LSPT.
Scenario:
The ongoing LSPTs are conducted to test the ability of Protective Force (PF) personnel to detect
and prevent contraband and prohibited items from being introduced into Limited Areas, Vault-
Type Room, Protected Areas, and Material Access Areas. LSPTs will be conducted on X-ray
machines, metal detectors, and hand and vehicle searches. Security and non-security personnel
will try to enter and exit the above-mentioned areas with contraband and prohibited items. Using
personnel with whom PF personnel are unfamiliar will ensure credible and realistic test results.
The person attempting to introduce the contraband or prohibited item will use only contraband test
items that have been approved by the DOE cognizant security office. Once the entry is initiated,
DOE-STD-1217-2020/Rev FEBRUARY
2020
52
the person attempting the entry will only proceed after being cleared to do so by the security
officer conducting the search. The persons attempting the entry will wear clothing that would
Section 36
make the concealment of any weapons on their person virtually impossible, and they will keep
their hands open and in plain view at all times. The persons attempting to enter or exit any of the
aforementioned areas will strictly follow all instructions given by the DOE controller and obey all
instructions given by PF personnel. The DOE controller will announce the LSPT to PF personnel
once the contraband or prohibited item has been detected/undetected by the PF. The sole purpose
of the LSPTs is to evaluate the ability of the PF to detect contraband and prohibited items prior to
their release into the aforementioned areas. The LSPTs are not designed to test what actions the PF
undertakes once they detect or fail to detect the contraband or prohibited item.
(5) IN THE EVENT OF AN ACTUAL SECURITY ALARM OR SECURITY INCIDENT, THE
CONTROLLER WILL IMMEDIATELY ANNOUNCE AND CONCLUDE THE LSPT, TAKE
POSSESSION OF THE TEST ITEM/CONTAINER, AND FOLLOW ALL INSTRUCTIONS
ISSUED BY PF PERSONNEL.
Requirements:
1. DOE Controller
2. Person to carry contraband or prohibited item into the area
3. Contraband and prohibited item(s)
4. Support items, such as lunch boxes, purses, notebooks, gym bags, vehicles
(6) PF Response:
Yes No
If a no-notice PF response is desired, check the following measures being taken to ensure safety
during the response.
Drill announcements will be made on all PF networks immediately after PF response
is initiated, and periodically thereafter.
X Controller is located in the PF CAS.
The PF is informed that an exercise will take place and that they are to follow the
safety and health requirements contained in this plan and in the site procedures. This instruction
will be provided by site representatives briefing the PF prior to the shift during which the
performance test will take place.
X Controllers are located at the exercise location.
If PF response is not desired, check those measures being taken to preclude response.
DOE-STD-1217-2020/Rev FEBRUARY
2020
53
Prior notification of CAS.
Prior notification of PF.
Presence of non-playing PF personnel briefed on the scenario at the performance test
location.
X Controller located in the CAS. A second controller will be located in the CAS with a final
approved copy of this LSPT Safety Plan and LSPT Safety Briefing. This controller will be able to
provide positive identification of the onsite controller and any support personnel participating in
the LSPT. The onsite controller will ensure that the CAS controller is physically located in the
CAS prior to departure for the area in which the LSPT will be conducted.
X Controller located in the immediate vicinity (within sight and hearing of the PF and support
personnel) of the LSPT.
(7) List other specific safety measures below:
1. All personnel attempting to gain entrance into one of the identified areas will be briefed on the
LSPT objectives and how they should conduct themselves during the LSPT.
2. All contraband or prohibited items will be photographed prior to the initiation of the LSPT.
3. All personnel attempting to gain entry or exit with contraband items will be photographed prior
to the initiation of the LSPT.
4. All personnel attempting to gain entry or exit with contraband or prohibited items will be
instructed to keep their hands in plain view, not to make any sudden moves, and comply with
all instructions given by PF personnel.
Section 37
5. Only epoxy–encased, DOE cognizant security office-approved test weapons will be used in
LSPTs requiring weapons.
6. All support personnel attempting to gain entrance or exit with contraband or prohibited items
will be briefed and required to read and sign the attached rules of exercise.
(8) Performance Test Boundaries:
X Applicable
The immediate area of the security post where the LSPT is being conducted.
X Not applicable
If applicable, describe the performance tests boundaries and the restrictions on performance test
participant movements in detail:
DOE-STD-1217-2020/Rev FEBRUARY
2020
54
(9) Off-Limit Areas:
Applicable
X Not applicable
If applicable, describe the off-limit areas and how they will be designated:
(10) Safety Equipment:
Controller Radios
PF Radios
Orange Vests
“Glow Sticks”
First Aid Kit
Other required safety equipment:
(11) Specific Safety Hazards Not Covered Elsewhere:
Applicable
X Not applicable
These LSPTs are being conducted with armed PF personnel. As with all such exercises, the remote
possibility exists that weapons may be drawn if the exercise plan is not adhered to, or if PF
personnel are not properly trained. However, because of the constraints placed upon the exercise
controllers by this plan and the level of preparation of the DOE participants, the level of risk is
actually below that experienced during normal day-to-day operations.
(12) Radiation Safety Provisions:
Applicable
X Not applicable
If yes, check those applicable to this LSPT:
Personnel participating in the LSPT have been briefed concerning radiation safety
requirements for the area with which the LSPT will be conducted.
Personnel will be continuously escorted while in the radiation areas in which the
LSPT will be conducted.
DOE-STD-1217-2020/Rev FEBRUARY
2020
55
List any other specific radiation safety provisions for this LSPT:
(13) Personnel Assignments (list below):
The names of the DOE controller and the person carrying the contraband or prohibited items will
be filled in prior to conducting the LSPT.
(14) Protective Force Appendix Required:
Yes
X No
(15) DOE Safety Review:
List any pertinent safety procedures concerning this LSPT that are not addressed in this plan.
Normally, the PF will not be notified in advance of the specifics of the LSPT being conducted.
The shift captain will be notified upon termination of the LSPT.
APPROVALS:
Director, Safety and Health Organization
DOE Cognizant Security Office
Date
Contractor Safety and Health Representative Date
Director, Security Organization
DOE Cognizant Security Office
Date
DOE-STD-1217-2020/Rev FEBRUARY 2020
56
ATTACHMENT 9: PERFORMANCE TEST PLAN
(1) TEST OBJECTIVE
This performance test is designed to test individual employee response to finding an unattended Secret
Restricted Data (SRD) document, verify compliance with the notification process to Classified Document
Control Office (CDCO), and verify PF compliance with the procedure for responding to this incident.
(2) SCENARIO DESCRIPTION
A simulated SRD document will be left unattended in an area accessed by “L”-cleared employees. This
document will be marked as a formal SRD document. Personnel recovering and responding to the simulated
classified document shall have no indication that the contents of the document are actually unclassified.
(3) TEST METHODOLOGY AND EVALUATION CRITERIA
Section 38
a. A simulated SRD document consisting of approximately five pages of unclassified text and drawings
shall be placed on the table next to a copy machine located in Building xxx, Room zzz. The document
shall be placed in the designated location at approximately 7:30 am.
b. Upon notification of the unattended “classified” document, the CDCO will verify that the individual
finding the document completed the following actions:
a) Xxxx
b) Xxxx
c) Xxxx
The Document Control Center shall also verify that the PF completed the following actions:
a) Xxxx
b) Xxxx
c) Xxxx
(4) PASS/FAIL CRITERIA
In order to successfully complete the performance test, the following must occur:
CDCO is notified within three hours of placement.
Individual locating the unattended document adheres to all protection and notification requirements.
PF officer responding to the incident adheres to all protection and notification requirements.
DOE-STD-1217-2020/Rev FEBRUARY 2020
57
(5) TEST CONTROLS
The following controls will be adhered to during conduct of this performance test.
Only survey team members involved with the conduct and evaluation of this performance test will be
made aware of all information surrounding the conduct of the test.
There are no additional safety requirements for this performance test. All current facility safety
requirements will be adhered to during this performance test.
This will be a no-notice exercise; therefore, the surveyed organization will not be given any
information regarding the conduct of this performance test prior to the test.
The simulated SRD document used during this exercise will consist of an unclassified document
marked at the SRD level with all appropriate markings and covers. There will be no indications to a
casual observer that the document is not classified.
(6) RESOURCE REQUIREMENTS
The following resources are needed to conduct this performance test.
Simulated SRD document
Identified location to place the document
Three survey team members to be assigned the following:
1. Monitor the document
2. Monitor the PF response
3. Monitor the CDCO
(7) TEST COORDINATION REQUIREMENTS
No coordination requirements are necessary since this is a no-notice exercise. Survey team members
monitoring the various aspects of the performance test will identify themselves to participants only
when it becomes necessary.
(8) OPERATIONAL IMPACT(S) OF TESTING PROGRAM
Since this performance test is being conducted during normal duty hours, there will be no need for
additional funds for overtime payments, and there is no expectation of a loss of productive time for
personnel who will be participating in the exercise.
DOE-STD-1217-2020/Rev FEBRUARY 2020
58
(9) COMPENSATORY MEASURES
There are no compensatory measures required for the conduct of this exercise.
(10) COORDINATION AND APPROVAL PROCESS
The following steps and documentation will be followed in the conduct of this exercise.
This test plan will be approved by the survey team leader prior to the conduct of the performance
test. Approval of this test plan will be documented by the Survey Team Leader’s signature and date
on this test plan.
A participant log containing name, job title, organization, telephone number, and date will be
completed by all participants of this exercise.
A data-collection form containing the date, performance test type, name of evaluator, and
chronological description of actions observed will be completed by all survey team members
Section 39
participating in the evaluation of this performance test.
(11) REFERENCES
The following references will be used in the conduct and evaluation of this performance test.
DOE O XXX.X, Information Security
Information Security Standard Operating Procedure #
PF Standard Operating Procedure #
PF Post Order #
SURVEY TEAM LEADER:
DATE
(Signature of Approval)
DOE-STD-1217-2020/Rev FEBRUARY 2020
59
ATTACHMENT 10: SAMPLE SURVEY REPORT TEMPLATE
SAMPLE INITIAL/PERIODIC SURVEY REPORT FORMAT
A. Report Format. The report may be formatted with a cover page, table of contents, ratings,
executive summary, introduction, description of facility and interests, narrative (including
topical area description of the program), conclusions, synopsis of findings, and appendices.
The DOE 470.8, Survey/Inspection Report Form, if used, shall be included in the report.
B. Report Content.
1. Initial and Periodic Survey Reports and Self-Assessment Reports. Reports shall contain the
following items.
(a) An executive summary containing:
i. The scope, methodology, period of coverage, duration, date of the exit briefing to
management;
ii. A brief overview of the facility, function, scope of operations, and contractual
information (e.g., contract number, award and expiration dates, contract type,
identification of security clauses, and overall scores assigned to the most recent
contract appraisal);
iii. A brief synopsis of major strengths and weaknesses that impact the effectiveness
of the facility’s overall S&S program, including identification of any topical areas
rated less than satisfactory;
iv. The overall composite facility rating with supporting rationale; and
v. A reference to a list of findings identified during the survey or self- assessment.
(b) An introduction containing:
i. The scope, methodology, period of coverage, duration, date of the exit briefing to
management; and
ii. A description of the facility, its function and scope of operations, security
interests, and contractual information (e.g., contract number, award and expiration
dates, contract type, identification of security clauses, and overall scores assigned
to the most recent contract appraisal).
(c) Narrative for all rated topical area and sub-topical areas that includes:
i. A description of the site’s implementation of the topical area/sub-topical area
element;
DOE-STD-1217-2020/Rev FEBRUARY 2020
60
ii. The scope of the evaluation;
iii. A description of activities conducted;
iv. The evaluation results and associated issues (including other Department elements
or other government agency (OGA) review or inspection results related to the
topical areas/sub-topical areas that were included in the survey);
v. The identification of all findings, including new and previously identified open
findings, regardless of source (e.g., EA, IG, GAO), and their current corrective
action status; and
vi. An analysis that provides a justification and rationale of the factors responsible for
the rating.
(d) Attachments, including, for example:
i. A copy of the current DOE F 470.2, Facility Data and Approval Record (FDAR);
ii. A listing of all active DOE F 470.1, Contract Security Classification Specification
(CSCS), or DD F 254, Contract Security Classification Specification;
iii. A listing of all new findings resulting from the survey/self-assessment;
iv. A listing of all previous findings that are open, to include the current status of
corrective actions;
Section 40
v. A listing of team members including names, employer, and their assigned area(s) of
evaluation; and
vi. A listing of all source documentation used to support the survey/self- assessment
conduct and results.
Narrative: The narrative section of the report shall clearly describe the surveyed facility –
its Safeguards and Security (S&S) interests and activities, its protective measures, and the
status of the S&S program at the time the survey or self-assessment activity was
completed. The report shall also explain how the protection measures were evaluated. Use
of statistical data will help describe the facility’s S&S interests and the survey effort. Such
data might include numbers of employees with each level of access authorization, the
number of classified documents in each level and category, and the number of documents
sampled for compliance/performance.
The report shall reflect the compliance and performance segments of the survey.
Reports shall explain what the S&S program is supposed to do, what was surveyed,
DOE-STD-1217-2020/Rev FEBRUARY 2020
61
how the survey data was compiled (e.g., extended data collection or within a few
days), and what was found. Suggested content includes:
The status (e.g., approved, pending, under revision) of any required planning
documents (e.g., Facility/Site Security Plan, Material Control and Accountability
(MC&A) plans, local implementation procedures, etc.).
All new findings must be identified. Open findings from the previous survey shall be
identified in the narrative portion of the survey report. Open findings maintain their
original finding number. A new finding, including one that is a repeat of a closed
finding, receives a new SSIMS-compatible finding number. When a finding is a repeat
of a closed finding, reference to the closed finding shall be included in the body of the
narrative.
Findings, observations, opportunities for improvement, and suggestions, along with
supporting data for each, shall be clearly described. The term “finding” refers to a
factual statement of issues and deficiencies representing a failure to meet a
documented legal, regulatory, performance, compliance, or other applicable
requirement found during the survey or self- assessment.
Descriptions of the facility's strengths and weaknesses shall correlate to the survey
results and establish the basis for the ratings. The survey report shall reflect validated
and defensible ratings. The narrative description shall be consistent with and support
the composite and topical area ratings (including “Does Not Apply”).
The report shall identify findings corrected on the spot. These findings and corrective
actions shall be clearly described in the narrative.
The status of corrective actions for open findings and findings from the previous
survey shall be included in the narrative.
A concluding analysis of each topical area shall be included in the narrative.
Reasons for a less-than-satisfactory rating shall be explained in detail.
DOE-STD-1217-2020/Rev FEBRUARY 2020
62
ATTACHMENT 11: CORRECTIVE ACTION AND CAUSAL ANALYSIS
PART I
CORRECTIVE ACTION ELEMENTS
Action Plan Cover Sheet
Finding Number:
Facility Code:
Responsible Program Office:
Topical Area:
Sub-topical Area:
Reference(s) (i.e., Orders, Requirements, etc.):
Description of Deficiency:
Information above provided by Surveying organization
PART II
Root Cause Analysis Process Used:
Cause Code(s):
Section 41
Corrective Action Description:
DOE-STD-1217-2020/Rev FEBRUARY 2020
63
Estimated Completion Date:
Revised Completion Date:
Reason for Revised Completion Date:
Completion Date:
Responsible Manager:
Print Name Signature Date
DOE-STD-1217-2020/Rev FEBRUARY 2020
64
Instructions for Completing Corrective Action Plan Cover Sheet
The Surveying Organization will fill in Part I of the Corrective Action Plan Cover
Sheet. The organization assigned the finding will be responsible for completing Part II
of the form.
PART II
Root Cause Analysis Process Used: Identify the technique used to identify the Cause Code. There are a
number of acceptable tools to include but not limited to, the five whys, fishbone, tree, failure modes
effects analysis. The preferred tool is the fishbone chart as well as using the causal analysis tree to help
in identifying the root cause outlined below. Please attach the completed tool(s) showing how the root
cause was identified.
Cause Code(s): Cause code identified by Root Cause Analysis, code, description, and examples are
available in DOE-STD-1197-2011 Occurrence Reporting Causal Analysis. More than one code is
acceptable but not common, except if one of the codes is human error, which is generally supported by a
second code.
Corrective Action Description: High-level description of corrective action to include compensatory
measures required. Milestones (numbered) are to be included in the Corrective Action Description
section of the cover sheet, or at a minimum, reference that there are “X” number of milestones to be met
in completing the corrective action.
Estimated Completion Date: First expected completion date assuming all resources are available and
the corrective action activities are not disrupted.
Revised Completion Date: Update completion date, initial form submission will not have information in
this block, however additional submissions may include adjustments required by a delay in corrective
action efforts.
Reason for Revised Completion Date: A brief narrative on why the date must be revised, not for the
purposes of approval by the surveying organization but for informational purposes.
Completion Date: Date the corrective action was completed, necessary so surveying organization can
review the effectiveness of the efforts implemented.
Responsible Manager: Information by responsible manager for completing the corrective action.
Print Name Signature Date
DOE-STD-1217-2020/Rev FEBRUARY 2020
65
CORRECTIVE ACTION PLAN MILESTONES SHEET
Finding Number:
Date:
Milestone:
No.:
Milestone Description:
Deliverables/Completion Criteria:
Milestone Due Date:
Date Milestone Completed:
Milestone Manager (print and sign):
Milestone:
No.:
Milestone Description:
Deliverables/Completion Criteria:
Milestone Due Date:
Date Milestone Completed:
Milestone Manager (print and sign):
DOE-STD-1217-2020/Rev FEBRUARY 2020
66
Instructions for Completing Corrective Action Plan Milestones Sheet
CORRECTIVE ACTION ELEMENTS
Action Plan Milestones Instructions
SECTION INSTRUCTIONS
Finding Number Enter the finding number.
Milestone Number Enter milestone number (consecutive starting with 1).
Milestone Description Write milestones with clear deliverables that solve the
problem. Ensure that milestones address and correct the
deficiency.
Limit individual milestone instructions to brief, concise
statements describing logical segments of the specified
Section 42
milestone. Include milestones for recurrence control.
Write realistic and achievable milestones that can be
verified.
Do not overextend milestones beyond your control. Ensure
that resources are available.
Identify the milestone manager responsible for completion
of each milestone and the respective program element.
Identify only one milestone if only a single action is
required to correct the deficiency.
If completion of milestones is required by persons outside
of the responsible manager’s authority, the responsible
manager coordinates the milestone with the supporting
program element.
Deliverables/
Completion Criteria
Include completion criteria that are discrete, finite, and
verifiable.
Milestone Due Date Enter the due date for each milestone.
Date Milestone
Completed
Enter the actual date each milestone was completed.
Milestone Manager Milestone managers sign for concurrence of each assigned
milestone.
DOE-STD-1217-2020/Rev FEBRUARY 2020
67
Root Cause Scenario
Background: Carl has been a DOE employee for about 3 years, working in an office
administrative position. Although he has a Q clearance, he very rarely handled classified
documents in his position.
Another employee in his organization, the Classified Document Control Station (CDCS) custodian,
was retiring soon and had given two weeks’ notice. The position needed to be filled immediately
due to the high volume of access the CDCS goes through each day. Shortly after his retirement, an
annual inventory of all classified documents was scheduled to take place.
The Director tasked Carl’s supervisor to fill this position as soon as possible. Since Carl has a
clearance and is familiar with the organization, he was offered the new position as the CDCS
Custodian. Carl was somewhat familiar on how to handle classified matter, but had not gone
through CMPC training for CDCS training since there were no classes held at the time. Given his 3
years with DOE, the supervisor believed this would not be an issue and filling the position was
more important due the upcoming inventory. The Director was not aware of the lack of training
Carl had.
Incident: Carl has now been in this new position for about 3 weeks, and has been assisting with
the inventory of the classified documents stored in the security containers in the CDCS. Carl was
leaving early on Wednesday for a long weekend and would be out until the Monday of the
following week. On his way out he told another employee, who was working on the inventory, that
the SF 700 Part 2s were being stored in his desk drawer, in case they needed to access a security
container.
Problem: SF 700 Part 2 was stored in an employee’s desk drawer instead of a security container.
How the Root Cause Analysis was determined for this finding:
A Safeguards and Security Periodic Survey was conducted and a finding was assigned with a CAP
response due within 30 days after survey date (example provided). The team involved in
determining the root cause of the finding, consisted of the elements HSO, AHSO, and management
not directly involved with the finding. The team reviewed and discussed the scenario above.
Interviews with the employees involved helped obtain additional information of the events leading
up to the issuance of a finding. The team collected all the information and used the Root Cause
Tool 1 (see example) to determine the possible topical area where the root cause may fall under
Section 43
(i.e. A4 Management), which can be determined through group discussion. The Casual Analysis
Table was used to assist with breaking down the root cause by topic. There were sections that did
not apply to this situation, so the team placed a Not Applicable (N/A) in those sections. The team
continued to work their way through all the levels of the table (A1-A7, and down through the “B’s”
and “C’s” of each of those sections). Once the team has exhausted all possibilities, Root Cause
Tool 1 was then complete. In filling in Tool 1, the group noticed that there is the potential to have
DOE-STD-1217-2020/Rev FEBRUARY 2020
68
more than one root cause for each section (see ‘A4’ in example). If this happens then capture all
suspected causes that apply.
After completing Root Cause Tool 1, the team analyzed the information to select the top or most
critical issues. Once those were established, we transferred the selections over to the Root Cause
Tool 2 table under ‘Suspected Cause.’ The team then rated the Suspected Causes for ‘Areas of
Impact’ in a scale of 1-5 (5 = Highest impact; 1 = Lowest impact). Once completed, we totaled up
the ratings assigned to determine the overall score that had the greatest impact, giving us our root
cause.
If there are two or more areas of impact that have the same scoring number then the Subject Matter
Expert and the team shall discuss which area of impact outweighs the other. For example, if it is a
matter of mission vs. resources, the team may decide to use the Mission Area of Impact number
versus the resource number for this CAP. If the same finding occurs in the following year, then the
organization may decide to use the resource areas of impact as the root cause for the finding. For
this reason, all records that were used to determine root cause shall be retained to document the
analysis that was conducted for each root cause.
DOE-STD-1217-2020/Rev FEBRUARY 2020
69
Figure ATTM 11.1 Blank Root Cause Analysis Tool 1Template
DOE-STD-1217-2020/Rev FEBRUARY 2020
70
Figure ATTM 11. 2 Example of a Completed Root Cause Tool 1
DOE-STD-1217-2020/Rev FEBRUARY 2020
71
Figure ATTM 11. 3 Blank Root Cause Tool 2 Template
Suspected Cause
Areas of Impact
Mission Resource Quality Safety/Envir. Total
Steps:
1. Input ‘Suspected Cause’ from Root Cause Tool 1
2. Rate the impact (1-5 (5 = Highest impact; 1 = Lowest impact)) of each cause for each ‘Area of
Impact’ (use ‘N/A’ if not applicable)
3. Total the ratings for an overall score to determine cause with greatest impact
Definitions
Mission – the overall program or organization mission agenda
Resources – budget and personnel are typically referenced as resources; however, other items may also
apply (e.g. hardware/equipment)
Quality – to the level of work
Safety/Environment – Affecting ability to work in ideal conditions, or impact to public safety
DOE-STD-1217-2020/Rev FEBRUARY 2020
72
Figure 11.4 Example of a Completed Root Cause Tool 2
Suspected Cause
Areas of Impact
Mission Resource Quality
Safety/
Envir. Total
Sufficient training was not
available. (B1,C02)
5 N/A N/A N/A 5
Supervisor did not communicate
with the Director the lack of
training the employee had with
CDCS responsibilities. (B4,C06)
5 2 4 N/A 11
Lack of manpower rushed the
hiring process; hiring
underqualified employee.
(B2,C03)
4 3 5 N/A
12
Employee ignored the policy of
securing the SF- 700 just for
convenience (employee
Negligence). (B2,C02)
Section 44
5 N/A 4 1 10
Steps:
1. Input ‘Suspected Cause’ from Root Cause Tool 1
2. Rate the impact (1-5 (5 = Highest impact; 1 = Lowest impact)) of each cause for each ‘Area of
Impact’ (use ‘N/A’ if not applicable)
3. Total the ratings for an overall score to determine cause with greatest impact
Definitions
DOE-STD-1217-2020/Rev FEBRUARY 2020
73
Mission – the overall program or organization mission agenda
Resources – budget and personnel are typically referenced as resources; however, other items may also
apply (e.g. hardware/equipment)
Quality – to the level of work
Safety/Environment – Affecting ability to work in ideal conditions or impact to public safety
DOE-STD-1217-2020/Rev FEBRUARY 2020
75
SAFEGUARDS AND SECURITY SURVEY
AND SELF-ASSESSMENT TOOLKIT
Introduction
This Toolkit was created to augment the Safeguards and Security (S&S) Survey and Self-
Assessment Technical Standard by providing a variety of samples and tools that may be
used to complement the overall survey/self-assessment process. The Toolkit is not meant to
be all-inclusive, but rather to provide a starting point that can be expanded and built upon.
The Toolkit is divided into three sections: Planning, Conduct, and Post-Survey Activities.
The Planning section provides tools associated with survey notification, planning, and in-
briefings. The Conduct section is broken down into topical areas and their respective sub-
topical areas. Each topical area contains information, such as areas to be considered in the
survey, sample interview questions, etc., that may assist the surveyor in conducting the
survey. The Post-Survey Activities section includes sample survey formats, exit briefing
slides, transmittal memos, sample CAPs, and DOE F 470.8, Survey/Inspection Report.
Planning Tools
This section addresses the logistics and notifications associated with conducting a survey
or self- assessment and provides sample documents for survey notification, planning and
in-briefings. The following specific areas are addressed:
Sample In-Briefing
Sample Survey Plan Format
Documents For Possible Review
Sample Notification Memos
Sample Accommodation Request
DOE-STD-1217-2020/Rev FEBRUARY 2020
76
A.2.1.1 Sample In-Briefing (Customize for specific survey objectives, activities, etc.)
DOE-STD-1217-2020/Rev FEBRUARY 2020
77
DOE-STD-1217-2020/Rev FEBRUARY 2020
78
DOE-STD-1217-2020/Rev FEBRUARY 2020
79
A.2.1.2 Sample Survey Plan Format
Title of survey
Location of facility
Purpose of survey
Survey dates
General facility information /description
Facility data
Work/activities performed
Operating organization (contractor)
S&S interests
Strategic Partnership Projects or other security activities
Scope of survey
Period of review, including extended observation or data collection if applicable
Objectives
DOE-STD-1217-2020/Rev FEBRUARY 2020
80
Topical areas to be included/excluded and justification for each
Topical areas with findings from previous surveys, inspections reports, audits and appraisals (e.g.
Government Accountability Office (GAO)/ Inspector General (IG))
Special areas/items of interest/concern
Survey planning and preparation
Performance tests (associated safety plans)
Survey guide information
Pre-survey information
Survey conduct—approach and methodology
Documents to be reviewed
Performance tests
Individuals to be interviewed
Sampling activities, including extended observation, shadowing or surveillance if applicable
Section 45
Schedule of activities
Survey schedule
In-briefing information
Coordinating instructions
Exit briefing
Schedule for report development
Team composition/assignments
Team members
Assignments/responsibilities
Contractor support
Points of contact at the facility
Authority/governing documents
DOE-STD-1217-2020/Rev FEBRUARY 2020
81
Directives
References (unclassified/classified)
Survey report format
Administration, support, and logistics
Work facilities
Transportation
Computer support
Administrative support
Classification support
Training requirements
Appendices
Performance tests (including Safety Plans)
Survey guides
Forms
A.2.1.3 Documents for Possible Review
The following is a list of documentation that may be considered for review during survey conduct.
Whether or not to include these documents as part of the data call or to review during the Conduct
phase will be determined based on the focus of each topical area, as outlined in the survey plan. The list
is not comprehensive; other documents may be available which shall also be considered.
Program Planning and Management
Organization charts depicting the Safeguards and Security (S&S) management structure and S&S
functional structure
Documents depicting responsibilities and authorities of S&S management, including all
delegations of authority and designations of Officially Designated Federal Security Authority
(ODFSA) and Officially Designated Security Authority (ODSA)
Position descriptions for S&S management
Program Office and local instructions for the implementation of S&S programs
DOE-STD-1217-2020/Rev FEBRUARY 2020
82
Supplemental documents and guidance for implementing S&S programs
Facility/site security plan (SP) and any referenced or supplemental plans and documentation
Emergency management and security condition (SECON) plans
Survey reports, inspection reports, Government Accountability Office and Inspector General
audit/appraisal reports, self-assessment reports
Staff raining records
Contract(s), including Statement of Work
List of all subcontractors and consultants conducting work for the contractor
List of U.S. Department of Energy (DOE) directives and security clauses that have been
incorporated into applicable contracts
Approved and pending equivalencies/exemptions to DOE directives and any deviations to national
drivers (e.g., Code of Federal Regulations)
Copy of the facility registration
Applicable memoranda of understanding (MOU)/Agreement (MOA)
Completed Foreign Ownership, Control or Influence (FOCI) questionnaire (SF 328)
Key Management Personnel (KMP) list
Dates of all applicable FOCI determinations and copies of any mitigation agreements
A copy of the contractor's records of all contracts and subcontracts involving access authorizations
Vulnerability Analysis (VA) reports
Security Risk Assessment (SRA) reports
Contingency plans
Survey and self-assessment program procedures
Issues management plans and procedures
CAPs and status updates for all open deficiencies
Finding/deficiency corrective action validation and closing procedures
Incidents of Security Concern procedure, including initial notification and inquiry reports
DOE-STD-1217-2020/Rev FEBRUARY 2020
83
Contract Security Classification Specification (CSCS) forms
Facility Data and Approval Record (FDAR) forms
Copy of the approved Performance Assurance Program Plan
Section 46
List of essential elements documented in the Performance Assurance program and the testing
schedule for each
Documentation of the integrated contractor assurance system
Protective Force (PF)
Organization and function charts
PF general, special and post orders
PF shift schedules and post assignments
PF standard equipment issuance (Security Police Officer (SPO) I, II, III, and Special Response
Team (SRT))
PF weapons and ammunition inventories
Weapons maintenance logs
MOU with local law enforcement agencies and documentation of exercises conducted with those
agencies
Integration of crisis management personnel into procedures
PF training records which include:
A list of PF personnel who are subject to weapons qualification within 90 days of the start date of
the survey
A list of PF personnel who are medically certified to participate in the physical fitness program
All documentation of PF exercises conducted since the last S&S survey
Instructor certification
Job analysis
Job task analyses
Security Emergency Response Plan (SERP)
DOE-STD-1217-2020/Rev FEBRUARY 2020
84
Security Incident Response Plan (SIRP)
Facility Evacuation Response Plans
Security Contingency Response Plans
Target folders
Schedule for performance testing (results of recent tests)
Compensatory measures currently in place (including pertinent documentation)
Procedures (administrative, training, non-response-related operational requirements)
Access/badge control
Information containing, at a minimum, policies/procedures for issuing, replacing, and recovering
passes/badges
Inventories (since last S&S survey) of passes/badges made, issued, lost, recovered, returned, and
destroyed
Shipment security plans
Shipment procedures
In-transit emergency plan
Shipment emergency response plan
Physical Protection
Organization and function charts
Lock and key records and procedures
Automated access control system records and procedures (including biometric access input) as
well as access credential issuances (e.g., keycards, tokens)
Barrier maintenance procedures/records
Property control procedures
Access control procedures
Local performance testing plans and procedures
Physical security system description(s) and location(s)
DOE-STD-1217-2020/Rev FEBRUARY 2020
85
IDS maintenance and testing records and procedures
IDS Analysis and Evaluation Report
Unscheduled alarm reports
Central Alarm Station (CAS)/Secondary Alarm Station (SAS) procedures (interface description)
Emergency response for CAS/SAS recovery
Emergency power systems (uninterruptible power supply system)
Compensatory procedures for equipment outages
Security container documentation and maintenance records
Automated systems description and procedures
Manual
Procedures
Controls
Calibration and testing procedures and records (e.g., X-ray, metal detectors, IDS)
Inspection procedures
Limited Scope Performance Test (LSPT) results
Information Security
Organization and function charts
Training records
Technical surveillance countermeasure (TSCM) survey reports
Site inventory of accredited systems, showing property tag number, the accrediting authority, and
most recent accreditation date for each
Formal assignments of TSCM personnel
TSCM activity support memoranda (if applicable)
Local TSCM implementation guidance
TSCMO service schedules, files, and corrective action reports
DOE-STD-1217-2020/Rev FEBRUARY 2020
Section 47
86
TSCM team equipment maintenance and calibration files
TSCM team training and certification records
Operations Security (OPSEC) Plan
OPSEC procedures
OPSEC program files
Local threat statement
Critical Program Information
Counter-Imagery Program Plan (if applicable)
Number of derivative classifiers and declassifiers
Appointment letters (e.g., Inquiry Officer, custodians)
Training records, reports, and lesson plans
Classification guidance
Classified Matter Protection and Control (CMPC) procedures
Control station procedures
List of classified holdings, including documents, electronic media, and matter
Number of Special Access Programs (SAPs)
Personnel Security
Local procedures for terminations, leave of absences, reinstating clearances, clearance processing,
exit briefing process
Contractor access authorization requests
Sample initial, comprehensive, refresher, and termination briefing materials
Previous findings and CAPs
Reciprocal access authorization documentation
Awareness tools (posters, newsletters)
Security infraction and violation records
DOE-STD-1217-2020/Rev FEBRUARY 2020
87
Requests for visit or access approval (notification and approval of incoming and outgoing
classified visits records and records of cleared non-DOE personnel granted access to RD)
Written delegation of senior federal official authorized to make determinations on access to
Restricted Data by non-DOE personnel in connection with a classified visit
Visitor control logs
Local visitor control procedures
Central Personnel Clearance Index (CPCI) list of individuals overdue for reinvestigation
Drug testing/handling procedures
Drug testing records
Human Reliability Program (HRP) participants
HRP criteria/plans/procedures
Random test procedures
List of individuals on leaves of absence and the associated procedures for tracking
List of inactive classified contracts
List of personnel with access authorizations and the associated contract(s)
List of clearances terminated during the survey period
List of all access authorizations held by the contractor, including all contractors and subcontractors
that have cleared employees conducting work at the facility. This list can come from the DOE
CPCI of access authorizations held by the contractor. The CPCI and contractor lists, including the
current KMP list, shall be compared for discrepancies.
Foreign Visits and Assignments
List of foreign visitors from sensitive countries during the survey period
Specific security plans for foreign visitors from sensitive countries
Escort procedures
Local procedures for requesting, processing, and approving visits and assignments
List of foreign visitors or assignees, including hosts, during survey period
Incident reports involving foreign nationals
DOE-STD-1217-2020/Rev FEBRUARY 2020
88
Requests for foreign national visits
Indices checks
Documentation authorizing approval for specific categories of visits and assignments
Sensitive country listings
Equivalencies/exemptions pertinent to visits and assignments
Personnel assignment agreements
Nuclear Material Control and Accountability (MC&A)
MC&A plans and procedures
Training records, reports, and lesson plans
Performance tests
Categorization process documentation
Incident reporting process and procedures
Emergency response plans and facility procedures
Database descriptions
Material Balance Area (MBA) account structure
Section 48
Material transfer records
Internal control procedures
Nuclear Material Management and Safeguards System (NMMSS) reports
Shipper/receiver difference procedures and records
Material control indicator program
Inventory difference program
Materials containment documentation
Facility procedures
Material access program
DOE-STD-1217-2020/Rev FEBRUARY 2020
89
Access authorization lists
Search procedures
Material surveillance procedures
Portal monitor records and procedures
Daily administrative check program and procedures
Tamper-indicating device program
DOE-STD-1217-2020/Rev FEBRUARY 2020
90
Sample Notification Memos
A.2.2.1 Notification and Data Call
DATE:
TO:
FROM:
SUBJECT: Notification and Data Call Request – S&S Survey of XYZ Facility
This memorandum is to formally notify you that a representative of the (Surveying
Organization) will conduct a S&S survey of the XYZ facility and its satellite offices during
the period (Date–Date), in accordance with the requirements of DOE O XXX, (Title),
(Appendix, Section, Chapter, etc.). The topical areas to be evaluated include:
Program Planning and Management
Protective Force
Physical Security
Information Protection
Personnel Security
Foreign Visits and Assignments
Nuclear Materials Control and Accountability.
A list of personnel participating in the survey is reflected in Attachment 1. The Survey
Team Leader is John Doe. This survey involves a review and evaluation of the S&S
program as implemented by the XYZ facility.
System performance tests will be conducted during this survey in several topical areas.
Attachment 2 contains the data call. Please ensure the data call items are available for the
survey team’s review no later than (Date). Items can be sent electronically to the Survey
Team Leader or in hardcopy form to Room XXX, Building XXX. The in-briefing will be
held on (Day, Date), in Room XXX, Building XXX. The exit briefings are scheduled for
(Day, Date), in (place) at time(s) to be announced at a later date.
If you or your staff have any questions or require additional information, please contact
John Doe on (phone number) or by pager (pager number).
2 Attachments
DOE-STD-1217-2020/Rev FEBRUARY 2020
91
A.2.2.2 Safeguards and Security Periodic Survey
DATE:
TO:
FROM:
SUBJECT: Safeguards and Security Periodic Survey (SSPS)
The (Surveying Organization) will conduct an SSPS of the (Organization to be Surveyed)
during the period of (Date–Date). This will be a comprehensive survey and will be
conducted in accordance with (Appendix, Section, Chapter, etc.) of DOE O XXX, (Title).
The survey will examine the performance of safeguards and security programs to ensure
that S&S measures employed by the facility are adequate for the protection of security
assets and interests and will encompass all topical areas on DOE F 470.8,
Survey/Inspection Report Form.
To aid in the planning process, you are requested to provide the documentation listed in the
Attachment. These documents are to be provided to (Survey Team Leader) not later than
close of business (Day, Date). In addition, please provide points-of-contact information for
each topical area, including pagers/cellphone and phone numbers. The names of
(Surveying Organization)’s Survey Team Leader and Topical Leads will be forwarded to
your organization under separate cover.
Survey activities will begin with an in-briefing at (Time, Date), in (Place). Points of
Section 49
contact representing your organization in each topical area shall plan to attend.
If you have any questions or require additional information, please contact (Survey Team
Leader) on (phone number).
Attachment
DOE-STD-1217-2020/Rev FEBRUARY 2020
92
(Sample Attachment – Documentation Request)
Attachment 1
All documentation provided shall include the past 12 months unless otherwise noted.
Program Planning and Management
Organization chart(s) or listings with brief description of organizations functions and
responsibilities
Current site security plan with all referenced or supplemental plans
Recent self-assessment report(s)
Copy of findings/CAP tracking procedures
Current status of all open and closed findings/CAPs since the last survey (including
Office of Independent Enterprise Assessments, Government Accountability Office and
Inspector General)
List of and current status of all approved policy equivalencies and exemptions and any
approved deviations from national policy (e.g., Code of Federal Regulations)
List of all subcontractors performing work (name of company, contract number,
names of individuals with access authorizations)
Copies of all CSCS and FDAR forms related to the facility clearance
Protective Force
Facility security plans
Emergency security operation procedures
Security emergency response plan
Memoranda of Agreement/Understanding (e.g., with local law enforcement)
Physical Protection
Security systems test procedures
Security systems maintenance procedures
Lock and key records and procedures
Access control procedures
DOE-STD-1217-2020/Rev FEBRUARY 2020
93
Unscheduled alarm reports for the past three months
Information Security
List of locations where classified matter is stored and the name and telephone number
of the responsible custodian
List of locations where classified matter is used/processed
List of total number of classified materials and documents in accountability, including
level and category
OPSEC plans
All training materials to support the OPSEC program (have available on request)
All documents that support OPSEC briefings for contractor personnel (have available
on request)
All other internal program procedures that support OPSEC
List of derivative classifiers
Personnel Security
List of all assigned (cleared) employees/subcontractors who have traveled to sensitive
countries (official and unofficial)
List of all visits and assignments of foreign nationals
List of all subcontractors
List of uncleared visitors
List of outgoing classified visits
List of all incoming classified visitors
List of HRP participants
List of terminated clearances (including name, date termination statement signed, date
clearance terminated, CPCI number)
Foreign Visits and Assignments
List of visits
List of foreign national (FN) visitors from sensitive countries
DOE-STD-1217-2020/Rev FEBRUARY 2020
94
Specific security plans for FNs visiting from sensitive countries
Escort procedures
Local procedures for requesting, processing, and approving visits and assignments
Nuclear MC&A
Categorization process documentation
Material Balance Area account structure
Inventory difference program plans
MC&A plan/procedures (may be part of site security plan or separate document(s))
DOE-STD-1217-2020/Rev FEBRUARY 2020
95
A.2.2.3 Initial Safeguards and Security Survey
Date:
To:
From:
Subject: S&S Survey of XYZ Company
Section 50
This memorandum confirms informal arrangements between (Surveying Office) and
(Organization to be Surveyed) Safeguards and Security Organization personnel that
established (Date–Date) as the dates for the (Surveying Office) S&S survey of the
(Organization to be Surveyed) facility. The survey is conducted in accordance with Title
48 Code of Federal Regulations Subpart 952.204.73 (c) and the requirements of DOE O
XXX, (Title), (Appendix, Section, Chapter, etc.).
An informal and brief preliminary meeting is requested for (Date, Time) with S&S
management and selected survey personnel. The survey process will be discussed during
this meeting.
Enclosure 1 is a pre-survey questionnaire/data call that identifies the preliminary
information required in the topical areas to be surveyed. Please provide this information to
(Surveying Office) by (Date). This material will be distributed to team members for review
and familiarization prior to the survey. Enclosure 2 identifies the accommodations
requested for the team’s use during the survey.
If there are any questions regarding survey activities, please contact (Survey Team Leader)
on (phone number). Your assistance is appreciated.
Enclosures
DOE-STD-1217-2020/Rev FEBRUARY 2020
96
(Sample Enclosure - Pre-Survey Questionnaire/ Data Call)
Enclosure 1
The survey team needs the following to be delivered to Room XXX no later than (Date) for
the XYZ facility and satellite office buildings:
Program Planning and Management
A list reflecting security staffing since (month, year). This list shall include name of
person, date of hire/termination, job title, and security functions (responsibilities)
Copies of all MOU and management agreements relating to S&S programs
A copy of all internal operations procedures/practices, with index
Copies of the most recent S&S security risk assessments, including documentation
reflecting risk determination methodology
A list of all security training courses that have been approved as part of the training
approval plan process
A list that reflects the training courses taken by personnel responsible for security
functions. Include name, title of course, number of hours, and date of completion
Copies of any procedures or other guidance pertaining to the identification and
development of S&S training
A list of all facilities (copies of Facility Data and Approval Records are acceptable)
where the XXX DOE Office is identified as the Designated Responsible Office.
A list of all classified activities (including the contract), classification level and
category of the activity, identification by office and/or Cognizant Security Office,
identification by contract number, purchase order number, task statement, or proposal
number (including classified Strategic Partnership Projects) (Note: Copies of the
CSCS form may be used in lieu of a listing.)
List of all terminated and completed contracts since (month, year). This listing shall
identify the company/vendor, address/location, Contracting Officer name,
organization, office location, and telephone number (Note: Copies of terminated
CSCS forms may be used in lieu of a listing.)
List of pending FOCI determinations
List of FOCI determinations completed since (month, year)
DOE-STD-1217-2020/Rev FEBRUARY 2020
97
List of FOCI approved companies, including the FOCI determination date, mitigation
types if any, and date of the latest FOCI update
Section 51
A copy of any desktop procedures or other formal XYZ-originated guidance
documentation used for the development of the facility/site security plan and other
security-related planning documents
A list that reflects all S&S plans (e.g., response, emergency, and contingency plans)
including title, date, and approval vehicle. Also list any draft plans and plans pending
approval
Copies of all XYZ-generated guidance or direction (hardcopy or electronic) provided
for the conduct of self-assessments and other internal evaluations
List of all open findings
List of open findings pending validation
Copy of Incidents of Security Concern program procedures
A list of all security incidents, including computer security incidents, occurring since
(month, year). This list shall identify the date of the incident, the date of the inquiry
report, and the nature of the incident
Copies of award fee data (Award Fee Plan, performance criteria)
PF
Copies of all security emergency plans (response, facility evacuation). If this
information is not available from this office, please provide the name, organization,
office location, and telephone number of the responsible person
Copies of all post and general orders, as well as implementing instructions for various
program activities (e.g., key control, alarm testing and maintenance, training program
development). If this is not applicable to the area being surveyed check here N/A. If
this is applicable, but the records are not available from this organization, please
identify the name, organization, office location, and telephone number of the
responsible person
Copies of all MOUs/Memoranda of Agreement (MOAs) with local law enforcement
agencies (LLEAs) or other organizations/agencies relating to security programs at the
XYZ facility and satellite office buildings. If this is not applicable to the area being
surveyed, check here: N/A
DOE-STD-1217-2020/Rev FEBRUARY 2020
98
List of all PF personnel, identified by rank, and supervisors. Also provide a separate
listing including PF management name, rank (if applicable), and responsibility (e.g.,
Lt. John Smith, Supervisor, IMF Instructor, Firearms Instructor)
A list of training documentation including, but not limited to, Job Task Analyses,
lesson plans, core topical s, individual records, physical fitness maintenance. Samples
of each shall be available for review during the survey
Copy of any DOE approval of the PF job analysis
Copy of the last (and immediately preceding) annual review of the PF job analysis.
Copy of the most recent approved Training Plan
If available, an approved Training Approval Program Assessment Report
A list of permanent and temporary security posts including post number and hours
staffed
If existing, a copy of all duty checklists used by the PF during routine and/or
emergency operations (e.g., vehicle inspection checklist, incident reports, field
interview reports, pre- duty inspection checklists, equipment checklists, CAS logs and
radio checks, weapons issue, weapons maintenance, weapons cleaning, emergency
call-out)
Copy of plans documenting the physical configuration of security posts
Copy of traffic/parking procedures (safety or security PF interface/enforcement)
Copy of general and specific patrol orders that define patrol intervals and routes for
classified repositories, vaults, and vault-type rooms
Weapons inventory list, including serial number and storage location.
Section 52
Quality Assurance program documentation
Communications equipment inventory list, including quantity, make, model, and
auxiliary equipment, as well as interface capabilities with LLEA
Auxiliary equipment inventory list including quantity, make, model of assigned
equipment (e.g., gas masks, protective vests)
Copy with pictures (if possible) of patrol and other vehicles used under the contract by
the PF. A list including vehicle make, model, vehicle identification number, mileage,
condition, unit number, license number, equipment (emergency and standard), owner
(company, DOE, or leased from XYZ agency), maintenance agreement, and
DOE-STD-1217-2020/Rev FEBRUARY 2020
99
identification of location of maintenance records (a sample of maintenance records
would be helpful)
Physical Protection
Copy of key control and property pass procedures
Copy of documentation that reflects the total value of capital and sensitive/equipment
items (include precious metals as applicable)
Listing of all controlled substances and locations, including copies of Drug
Enforcement
Agency certificates
Listing that identifies all security alarm transmission and monitoring systems,
including type, model, manufacturer, and purpose for each (i.e., describe the DOE
assets being protected)
List of all alarm points identified by system application (e.g., Argus, Litton) and
location that provides protection for classified matter and property
Copy of the approved alarm test plan and a copy of the DOE approval correspondence
Copy of the procedures for making changes to alarm transmission/monitoring systems
databases or software
Copies of reports since (month, year) of unscheduled alarm activations
Copy of false alarm rate and nuisance alarm rate since (month, year)
Copies of maintenance procedures and test results since (month, year)
Copies of IDS Analysis and Evaluation report since (month, year)
Information Security
A list of all current XYZ original and derivative classifiers
A list of reviewing officials, including name, title, organization, office location, and
telephone number
A list of all classification guides, including title and date
A list of all XYZ shipping/mailroom logs pertaining to the transmission of classified
matter since (month, year)
DOE-STD-1217-2020/Rev FEBRUARY 2020
100
A list of all areas authorized for processing and storage of classified
information/matter, including the classification level authorized and functions
performed in each area
List of all CDCSs, including the custodian names, organization, location, and
telephone extension.
Copy of CMPC procedures (marking, destruction)
List of all classified material accountability records
Copy of DOE-approved Technical Surveillance Countermeasures (TSCM) Plan
Copy of the TSCM officers appointment memoranda
Copy of the site-wide procedures for the control and use of potential TSCM
equipment
Copy of the procedures controlling TSCM equipment, the DOE approval for
purchasing and controlling TSCM equipment, and an inventory listing, if appropriate
Copy of OPSEC Plan
Copy of OPSEC assessment and review reports conducted since (month, year)
List of contractors (on- and offsite) under the OPSEC program
Copy of OPSEC working group meeting minutes for meetings conducted since
(month, year)
Personnel Security
A list of all cleared personnel whose access authorization has been terminated since
Section 53
(month, year) (Note: This list shall include the date of termination, name of person,
and organization for which the individual worked.)
A list of names of all consultants/vendors issued security clearances that conduct
business with XYZ
A list of all individuals by name and clearance number terminated for cause
A list of individuals by name and clearance number who have had clearances
canceled/terminated prior to completion of the background investigation
A list by name and clearance number of all FNs who are/were clearance applicants or
incumbents. Include in the listing the country of origin and level of clearance
DOE-STD-1217-2020/Rev FEBRUARY 2020
101
A list by name and clearance number of all dual citizens processed for access
authorization (clearance) since (month, year)
A list of individuals on leave of absence or extended leave. This list shall include
name, clearance number, reason for leave, date leave commenced, expected date of
return to duty, and/or date of termination
Have available each report submitted for derogatory information since (month, year)
Copy of attendance records for initial, comprehensive, and termination briefings for
all contractor employees since (month, year)
Copies of most current security education briefing/lesson plans for initial,
comprehensive, refresher, and termination briefings since (month, year)
Copy of the compliance verification numbers associated with the most recent refresher
briefing
Documentation describing the badging system and operating procedures for classified
visits. Provide examples of all badge types in use
Copy of the procedures for administering incoming and outgoing classified visits
Copies of incoming visit requests since (month, year)
Classified visitor logs since (month, year)
Copies or log of classified visitor badge requests since (month, year)
A listing of the number and dates of each positive substance abuse test report
A copy of drug test policy
A list of all personnel, by name and clearance number, enrolled in the HRP or other
performance assurance program
List of all individuals, by name and clearance number, removed from the HRP since
(month, year)
Justifications for HRP positions and date of last review
Procedures for Personal Identify Verification process
Foreign Visits and Assignments
Lists of all host reports submitted since (month, year) including date submitted
DOE-STD-1217-2020/Rev FEBRUARY 2020
102
Local procedures for requesting, processing, and approving visits and assignments
List of foreign visitors or assignees, including names of hosts, for survey period
Incident reports involving FNs
Requests for FN visits
Indices checks
Documentation authorizing approval for specific categories of visits and assignments
Sensitive country listings
Nuclear MC&A
MC&A Plan
Performance test data
Categorization documentation
Internal control procedures
Inventory difference program
Shipper/receiver difference procedures and records
DOE-STD-1217-2020/Rev FEBRUARY 2020
103
Sample Accommodation Request
The following items will need to be made available to the survey team for the duration of
the survey period:
Two conference rooms or a two-office suite with tables and seating for 15 to 20
people
Four desktop computers running Microsoft® Windows® (current operating
system), loaded with Microsoft Word (current version) and two Hewlett-Packard
LaserJet printers
Section 54
Telephones with outside lines and official site phone books or listings
White board and associated supplies
U.S. General Services Administration-approved security container (with
appropriate markings and required forms)
Office supplies (staplers, scissors, tape, disks, etc.)
Copies of XYZ procedures and policy manuals related to survey topical s, security
plans, Vulnerability Assessments, and applicable DOE directives.
Conduct Tools
This section contains tools that have been developed and field-tested by survey and self-
assessment teams. They are provided as examples only; other tools may be developed and
used as necessary.
Sample Survey Worksheet
Instructions for Completing the Sample Survey Worksheet
Sample Performance Test Safety Plan
Sample Performance Test Plan
DOE-STD-1217-2020/Rev FEBRUARY 2020
104
A.3.1.1 Sample Survey Worksheet
CLASSIFICATION
WORKSHEET
ORIGINATION DATE:
RESPONSIBLE AGENCY:
FINDING NUMBER:
CONCERN: COMPLIANCE PERFORMANCE BOTH
TOPICAL AREA: SUB-TOPICAL AREA:
FINDING DESCRIPTION:
FINDING SYNOPSIS:
IMPACT if not corrected:
DOE DIRECTIVE:
OTHER (Plan or Procedure Citation):
ORIGINATOR’S NAME/PHONE:
POINT-OF-CONTACT NAME/PHONE:
POINT-OF-CONTACT SIGNATURE:
CLASSIFICATION
DOE-STD-1217-2020/Rev FEBRUARY 2020
105
INSTRUCTIONS FOR COMPLETING THE SAMPLE SURVEY WORKSHEET
ORIGINATION DATE: Date form completed.
RESPONSIBLE AGENCY: Agency responsible for implementing corrective actions.
FINDING NUMBER: Each finding identified in the survey report shall have a unique
identification number assigned, which shall be used throughout the reporting and tracking
process. The following number system provides consistency with the Safeguards and
Security Information Management System (SSIMS). A number in this format shall be
system-generated upon entry of the finding into SSIMS.
Example of a finding number:
04OCT15-HQ-12345-SSPS-PF.1-001-5789
| | | | | | |
1 2 3 4 5 6 7
the date of the survey/inspection (year/month/day)
the office responsible for correcting the finding
the facility code of the facility surveyed/inspected
the type of survey (e.g., S&S Initial Survey, Office of Enterprise Assessments,
Inspector Government Accountability Office)
the sub-topical area code
the sequential number of an individual finding within the topical area
the facility code of another facility if a finding was issued to it during the survey
The acronyms used to identify the new topical areas for findings are as follows:
PMS Program Management Support
PF Protective Force
PSS Physical Protection
IP Information Security
PSP Personnel Security Program
FVA Foreign Visits and Assignments
NMCAA Nuclear MC&A
DOE-STD-1217-2020/Rev FEBRUARY 2020
106
CODE TYPES OF SURVEY DOCUMENTS
EPR Excluded Parent Review
GAO Government Accountability Office Reports
IG Inspector General Reports
NPR Non-possessing Review
EA Office of Security Assessment inspections/reviews
SA Self-Assessments
SPEC Special Surveys
SSIS Safeguards and Security Initial Surveys
SSPS Safeguards and Security Periodic Surveys
SSTS Safeguards and Security Termination Surveys
TSCM TSCM Reports
FINDING DESCRIPTION: The finding description shall be used to provide a clear
understanding of what was observed or discovered. It is not adequate to reiterate the
requirement. The description shall clearly identify the pertinent facts, circumstances, and
observations surrounding the finding or leading to the finding.
Section 55
Findings shall be clear, focused, and based on the perceived underlying cause of the
protection shortfall, to the most reasonable extent possible; rather than merely stating the
occurrence of a protection element failure or weakness. A finding shall be written in such a
manner that it is actionable by the responsible agency, i.e., that action can be taken that
will close the finding and the action will correct the observed deficiency. A well-worded
finding is one that is readily closeable when the cause or source is corrected and impossible
to close without correcting the cause or source.
Necessary and pertinent information shall be presented regarding the finding in order to
clearly identify what was found, how the information was collected, and any other
background information. The discussions shall attempt to correlate the data collected and
focus on the root cause of the deficiency. The nature of the data (e.g., observations,
interviews, tests) shall be described, as well as any quantifying data that will put the results
in perspective.
For example:
DOE-STD-1217-2020/Rev FEBRUARY 2020
107
A review was conducted of all current classified contracts at XYZ. This list was compared
to a current badge listing, dated 3-1-15, which showed employees, by company, who
currently hold a DOE access authorization. This comparison revealed that individuals
holding access authorizations are employed by organizations that do not have FOCI
determinations on file.
Based on the FOCI report provided by XYZ personnel, dated 3-1-15, and the employee list
by contractor, dated 3-1-15; TCY Company currently holds 7 “Q” clearances and Smith
Manufacturing currently holds five “Q” clearances. Neither organization has a FOCI
determination on file.
FINDING SYNOPSIS: Each finding shall be concisely described in a synopsis format.
The SSIMS allows a maximum of 2,000 alpha/numeric characters and spaces. Each finding
is to have a separate, stand-alone classification level and category. A separate field is
provided for the finding classification level and category. The symbols “S” for Secret, “C”
for Confidential, “U” for Unclassified, “OUO” for Official Use Only, and “UCNI” for
Unclassified Controlled Nuclear Information shall be used for the classification level.
For example:
Not all organizations employing cleared staff members have an approved FOCI
determination.
IMPACT STATEMENT: Clearly identify the impact of the deficiency.
DOE DIRECTIVE: Each finding is to have alpha/numeric references to the DOE
directive(s), or other documents that identify the requirement(s) not being met in the
finding. This reference shall be written as DOE O XXX.XX, followed by the specific
identification numbers and/or letters (e.g., DOE O 470.4B, Minor Change 2, Appendix A,
Section 2, paragraph 6.(b)).
OTHER: Identify alternative sources stating the requirement (e.g., section of the Code of
Federal Regulations, specific local procedures, site security plan).
ORIGINATOR’S NAME/PHONE: Print your name and telephone number.
POINT-OF-CONTACT NAME/PHONE: Print the name and phone of the POC
witnessing the activity.
POINT-OF-CONTACT SIGNATURE: Obtain the POC’s signature.
DOE-STD-1217-2020/Rev FEBRUARY 2020
108
A.3.1.2 Sample Performance Test Safety Plan
PERFORMANCE TEST SAFETY PLAN
I, acknowledge receipt of the attached safety plan. I understand it is my responsibility to become
familiar and comply with the contents of this safety plan.
Section 56
Acknowledgment of the receipt of this safety plan is a requirement to participate in or observe this
exercise. This page shall be signed and returned no later than .
Name
Signature
Position
Date
Detection of Contraband and Prohibited Items
(Type of Performance Test)
Ongoing 365 Days per Year; 24 Hours per Day
(Performance Test Date and Time)
Detection of Contraband and Prohibited Items, John Doe
(Safety Plan Name and Person Preparing)
ALL LSPTs WILL BE CONDUCTED IN CONFORMANCE WITH THIS SAFETY PLAN AND
ONLY AFTER SPECIFIC APPROVAL TO CONDUCT THE LSPTs HAS BEEN GRANTED BY
A RESPONSIBLE U.S. DEPARTMENT OF ENERGY OFFICIAL. PERSONNEL SERVING AS
CONTROLLERS WILL BE FULLY QUALIFIED IN ALL ASPECTS OF THE LSPT.
Scenario:
The ongoing LSPTs are conducted to test the ability of PF personnel to detect and prevent
contraband and prohibited items from being introduced into Limited Areas, Vault-Type Room,
Protected Areas, and Material Access Areas. LSPTs will be conducted on X-ray machines, metal
detectors, and hand and vehicle searches. Security and non-security personnel will try to enter and
exit the above-mentioned areas with contraband and prohibited items. Using personnel with whom
PF personnel are unfamiliar will ensure credible and realistic test results. The person attempting to
introduce the contraband or prohibited item will use only contraband test items that have been
approved by the DOE cognizant security office. Once the entry is initiated, the person attempting
the entry will only proceed after being cleared to do so by the security officer conducting the search.
The persons attempting the entry will wear clothing that would make the concealment of any
DOE-STD-1217-2020/Rev FEBRUARY 2020
109
weapons on their person virtually impossible, and they will keep their hands open and in plain view
at all times. The persons attempting to enter or exit any of the aforementioned areas will strictly
follow all instructions given by the DOE controller and obey all instructions given by PF personnel.
The DOE controller will announce the LSPT to PF personnel once the contraband or prohibited item
has been detected/undetected by the PF. The sole purpose of the LSPTs is to evaluate the ability of
the PF to detect contraband and prohibited items prior to their release into the aforementioned areas.
The LSPTs are not designed to test what actions the PF undertakes once they detect or fail to detect
the contraband or prohibited item.
IN THE EVENT OF AN ACTUAL SECURITY ALARM OR SECURITY INCIDENT, THE
CONTROLLER WILL IMMEDIATELY ANNOUNCE AND CONCLUDE THE LSPT, TAKE
POSSESSION OF THE TEST ITEM/CONTAINER, AND FOLLOW ALL INSTRUCTIONS
ISSUED BY PF PERSONNEL.
Requirements:
DOE Controller
Person to carry contraband or prohibited item into the area
Contraband and prohibited item(s)
Support items, such as lunch boxes, purses, notebooks, gym bags, vehicles.
PF Response:
Yes No
If a no-notice PF response is desired, check the following measures being taken to ensure safety
during the response.
Drill announcements will be made on all PF networks immediately after PF response is initiated,
and periodically thereafter.
X Controller is located in the PF Central Alarm Station (CAS).
The PF is informed that an exercise will take place and that they are to follow the safety and
health requirements contained in this plan and in the site procedures. This instruction will be
provided by s