ENCLOSURE 2. RESPONSIBILITIES
DoDM 5105.21-V1, October 19, 2012 Change 2, 10/06/2020 ENCLOSURE 2 7 ENCLOSURE 2
RESPONSIBILITIES
1. UNDER SECRETARY OF DEFENSE FOR INTELLIGENCE AND SECURITY (USD(I&S)). The USD(I&S), in accordance with Reference (b), serves as the senior DoD official for oversight of implementation of SCI security policies and procedures within the DoD. As such, the USD(I&S) represents the Secretary of Defense when coordinating SCI security policies and procedures established by the DNI. The USD(I&S) has established the Defense Special Security System (DSSS) to administer the SCI program within the DoD.
2. DIRECTOR, DIA. The Director, DIA, serves as the Director of a Defense Agency, as the Head of a DoD Component, and as the Head of an Intelligence Community Element (HICE). In accordance with Reference (c), and under the authority, direction, and control of the USD(I&S), the Director, DIA, shall:
a. Administer the DoD SCI security policies and procedures consistent with DNI policies and procedures to protect intelligence and intelligence sources and methods.
b. Develop and implement standards for and oversee the operations of all SCI compartments for the DoD Components. In this capacity, the Director, DIA, shall:
(1) Direct, manage, and oversee the DSSS.
(2) Appoint a cognizant security authority (CSA) to serve as the authority for all aspects of security program management for the protection of SCI. This individual will also act as the CSA for OSD, the Chairman of the Joint Chiefs of Staff and Joint Staff, the DoD Field Activities, and the Combatant Commands and may delegate CSA responsibilities as necessary.
(3) Review and approve proposals for establishing new SCI security offices under the DIA CSA.
(4) Provide SCI security program direction, management, and oversight to the Military Departments.
(5) Administer SCI security support to other Federal agencies by special agreement as required.
(6) Administer uniform DoD SCI policy on the interrelated disciplines of information security, personnel security, physical security, technical security (e.g. TEMPEST and technical surveillance countermeasures (TSCM)), information assurance (IA), security education and awareness, and contractor SCI program administration to implement and supplement National Intelligence Board (NIB) and DNI SCI policy.
DoDM 5105.21-V1, October 19, 2012 Change 2, 10/06/2020 ENCLOSURE 2 8 (7) Enforce DoD compliance with DoD and DNI SCI policy, correct deficiencies, and conduct inspections of DoD SCI facilities.
(8) Establish procedures with the Military Department HICEs to coordinate and accomplish program reviews and inspections to eliminate scheduling conflicts.
(9) Provide centralized physical security and TEMPEST accreditation for the DoD Components and DoD contractors except those under the security cognizance of NSA/CSS, NGA, and NRO. This authority may be delegated to a single official, who shall serve as the Accrediting Official.
(10) Validate and maintain records of waivers for DoD SCI facilities.
(11) Establish, manage, and conduct training programs for SCI security officials and other security personnel.
(12) Establish an SCI Policy Coordination Committee (SCIPCCOM).
(13) Develop and publish uniform SCI briefing materials for SCI indoctrination, debriefing, and execution of nondisclosure agreements (NdA) and nondisclosure statements (NdS) for the DoD Components. The indoctrination and debriefing materials shall emphasize awareness of unauthorized disclosure processes and individual reporting responsibilities. On a periodic basis, produce SCI security education materials for the DoD Components.
3. HEADS OF DoD COMPONENTS THAT ARE NOT ELEMENTS OF THE INTELLIGENCE COMMUNITY. The Heads of DoD Components that are not elements of the intelligence community shall appoint, at an appropriate level, a senior intelligence official (SIO) who shall be responsible for the overall management of SCI programs and that portion of the DSSS within their Component. This appointment shall be reported to DIA and the USD(I&S).
4. HEADS OF THE INTELLIGENCE COMMUNITY ELEMENTS OF THE MILITARY DEPARTMENTS. The HICEs for the Military Departments shall:
a. Administer the SCI security programs for their respective Departments and component commands of the Combatant Commands. Military Department execution will be based upon guidance in this Manual.
b. Provide implementing instructions for the operation and administration of SCI securi ty programs for their respective agencies, departments, and components, including subordinate commands of the Combatant Commands, in accordance with this manual.
c. Assist the Director, DIA, in developing and recommending appropriate SCI security policy and procedures. Appoint a knowledgeable SCI security policy representative to the SCIPCCOM.
DoDM 5105.21-V1, October 19, 2012 Change 2, 10/06/2020 ENCLOSURE 2 9 d. Appoint a CSA to m anage, operate, and administer for their respective Military Departments a special security officer (SSO) system that is part of the DSSS and approve concept proposals for establishing new SCI security missions and facilities under their authority.
e. Conduct a continuing review of their Military Department SCI security programs, including oversight and evaluations. Review and evaluation of SCI security programs shall include site visits and direct contact or visitation with site personnel. Oversight visits shall include oversight of compliance with this Manual. Deficiencies shall be documented and reports of the status of corrections provided to the CSA.
f. Establish, manage, and conduct training programs for Military Department SCI security officials to enable them to perform the duties and meet the requirements contained in the appropriate regulations and directives.
g. Establish procedures to properly investigate security violations, compromises, and unauthorized disclosures of SCI in accordance with Intelligence Community Directive (ICD) 701 (Reference (f)) and to refer results to the supporting counterintelligence agency in accordance with DoDD 5240.06 (Reference (g)).
h. Provide SSO- related resources (e.g. funding and manpower) and resource management guidance to facilities under their authority for the proper administration of SCI security programs within their Departments. Provide for the dedicated funds and manpower needed to manage and operate their special security offices.
i. Establish, manage, and conduct formal continuing security awareness training, and education programs to ensure complete, common, and continuing understanding and application of SCI security under this manual.
5. CSAs. The CSAs shall, as delegated by the HICE, have authority over and responsibility for all aspects of management and oversight of the security program established for the protection of intelligence sources and methods, and for implementation of SCI security policy and procedures defined in DNI policies for the activities under their purview. CSAs may formally delegate this responsibility to specific elements within their organization
6. DoD COMPONENT SIO. The DoD Component SIO shall:
a. Be responsible for the command’s SCI security program. The SIO or his delegated designee shall appoint in writing a Component SSO to directly support the SIO and all primary and alternate SSOs, special security representatives (SSRs), IA managers (IAMs), IA officers (IAOs), and control officers as required for all authorized SCI compartments (e.g., Talent Keyhole, GAMMA, Human Intelligence (HUMINT) control system). Appointments shall be maintained locally. The Component SSO will be functionally subordinate to the SIO and be a member of the SIO staff. The Component SSO shall be responsible for a component’s SCIFs,
DoDM 5105.21-V1, October 19, 2012 Change 2, 10/06/2020 ENCLOSURE 2 10 provide direct support to other SSOs, SSRs, or contractor SSOs and have direct access to the SIO.
b. Provide proper protection, use, and dissemination of SCI documents and material by enforcing SCI, information, personnel, physical, communications, industrial, and IA security rules and by developing standard operating procedures (SOPs) and practices.
c. Maintain the integrity of the SCI control system. SSO and contractor special security officer (CSSO) personnel shall not perform duties or details that conflict or interfere with their SCI security responsibilities or with the security of SCI.
d. Approve or validate the need to know for individuals (military, civilian Government employee, or contractor) requiring SCI access and validate the need to establish SCIFs, SCI communications, and IS.
e. Identify required communications electronics and communications security (COMSEC) equipment to local supporting communications elements. Establish a memorandum of agreement (MOA) with the supporting communications element to provide timely communications support to the intelligence mission, if necessary.
f. Establish MOAs with other organizations, as necessary, on SCI areas of responsibility, training, operational needs, support, and services. Implement SOPs as required for further definition and clarification of security responsibilities.
g. Establish a co-utilization agreement (CUA) between the SSO and the local program security officer for any special access program (SAP) operating in the SCIF and monitor compliance with the CUA.
h. Train SSOs and SSRs to perform their respective duties and responsibilities.
i. Provide sufficient qualified personnel, funds, work space, facilities, and logistical support to effectively operate the SCI security program.
j. Evaluate and send to the Defense Messaging System requests to use the Defense Special Security Communication System (DSSCS) for SAPs and other special programs or projects.
k. Request that DoD Component counterparts responsible for military police activities direct subordinate military police activities to provide SSOs all derogatory information on SCI- indoctrinated personnel.
l. Keep the SSO informed of issues having SCI implications such as facilities utilization, IS requirements, base security, or base or post resource protection.
m. Designate SCI couriers for hand-carrying SCI outside the United States. The SIO may delegate this authority to the SSO except for couriering aboard foreign-flag aircraft.
DoDM 5105.21-V1, October 19, 2012 Change 2, 10/06/2020 ENCLOSURE 2 11 n. Coordinate and approve or disapprove requests for waivers as designated in this Manual.
o. Validate the need to establish SSOs or SSRs at locations under their authority.
p. Provide direction to Contracting O fficer’s Representatives involved in SCI contracts to coordinate DD Form 254, “Contract Security Classification Specification” with the SSO for proper approval. (DD Forms and Standard Forms (SFs) can be obtained on the Internet at http://www.dtic.mil/whs/directives/infomgt/forms/formsprogram.htm.)
q. Request that DoD Component counterparts responsible for medical services dire ct subordinate medical services activities to:
(1) Provide SSOs information about a person’s medical condition affecting their continued eligibility for SCI access and information concerning treatment that may temporarily affect an individual’s ability to perform SCI duties in accordance with DoDM 6025.18 (Reference (h)).
(2) Facilitate requests for such information from non-DoD sources in accordance with Parts 160 and 164 of title 45, Code of Federal Regulations (Reference (i)).
SSOs must provide such information to the appropriate central adjudication facility (CAF) for a determination of SCI eligibility.
r. Properly investigate security incidents, compromises, and unauthorized disclosure of SCI in accordance with Appendix 1, Enclosure 5, Volume 3 of this Manual; Reference (f); DoDD 5210.50 (Reference (j)) and DoDM 5200.01 (Reference (k)), and refer results to the supporting counterintelligence agency in accordance with Reference (g).
7. COMMANDERS AND CORPORATE OFFICIALS. Commanders and responsible corporate officers whose unit or organization does not have an assigned SIO and operates a SCIF are responsible for the proper management and oversight of that SCIF. These individuals will:
a. Approve all SOPs and Emergency Action Plans (EAPs) pertaining to their SCIFs.
b. Appoint in writing all SCI s ecurity officials within their organizations.
c. Oversee the protection of SCI through a comprehensive inspection program that includes self-inspections and random command/corporate-level reviews.
8. SECURITY OFFICIALS. Security officials provide SCI advice and assistance and normally have day-to-day SCI security cognizance over their offices or subordinate SCIFs. Assignment as the SSO or CSSO is a primary duty and they will not be assigned duties or details that conflict or interfere with performance of SCI control responsibilities. Assignment of an SSO in an S-2, G-2, N-2, J-2, or command security office position does not constitute a conflict of interest.
DoDM 5105.21-V1, October 19, 2012 Change 2, 10/06/2020 ENCLOSURE 2 12 9. SSOs AND CSSOs. SSOs and CSSOs manage the SCI security program and oversee SCI security functions for subordinate SCIFs. Contractors can only serve as a CSSO under a valid contract and must always coordinate their actions through that contract’s COR. SSOs will be military commissioned officers, warrant officers, non-commissioned officers (E-7 or above), or civilians (GS-9 or above). CSSOs will have the skills, training, and experience to fulfill the specified duties. The senior corporate officer responsible for the SCI security program at the contracting corporation will endorse CSSO nominations. This official may nominate himself or herself as a CSSO. All references to SSOs throughout the remainder of this Manual are inclusive of CSSOs unless otherwise noted. SSOs will be indoctrinated for all SCI compartments that their activity is authorized. SSOs shall:
a. Supervise the operation of the special security office and administer the SCI security program to include SCI security oversight for other SCIFs under the organization’s security cognizance.
b. Maintain applicable SCI directives, regulations, manuals, and guidelines to adequately discharge SSO duties and responsibilities.
c. Properly account for, control, transmit, transport, package, and safeguard SCI. Provide for destruction of SCI by authorized means and in accordance with this Manual and DD Form 254, as appropriate.
d. Disseminate SCI only to persons authorized access to the material and having an established need to know.
e. Serve as the official channel for certifying and receiving SCI visitor clearances and accesses.
f. Maintain the Joint Personnel Adjudication System (JPAS) to accurately reflect all personnel under their cognizance.
g. Conduct or otherwise manage SCI personnel, information, physical, and technical security (e.g. TEMPEST and TSCM) actions and procedures in accordance with this Manual.
h. Provide guidance and assistance for processing SCI position and eligibility requests.
i. Perform all aspects of the SCI Personnel Security Program to include, but not limited to, nomination interviews, validation of SCI access requirements, submission of investigative requests, conduct SCI security briefings; obtain signed NdA and NdS; and perform other related personnel security actions. (Supporting SSOs will provide this service for contractors unless it is specifically delegated to the CSSO by the owning SSO of the contract.) Provide a briefing on local SCI security procedures to newly-arrived personnel and those receiving initial SCI indoctrination. Emphasize unauthorized disclosure awareness, management, and reporting during indoctrination and termination briefings and day-to-day security program execution.
DoDM 5105.21-V1, October 19, 2012 Change 2, 10/06/2020 ENCLOSURE 2 13 j. Direct each subordinate SCI official to conduct an annual self assessment and forwards it for SSO review within 14 days of completion. SSOs shall annually report to the DIA Deputy Director for Mission Services, Counterintelligence and Security Office (DAC) the results of the self-inspections along with action taken to address any shortcomings.
k. Report and investigate all unauthorized disclosures of classified intelligence information in accordance with this Manual and References (f), (j) and (k).
l. Interface with telecommunications centers, IS facilities, computer centers, and similar offices to establish and maintain SCI security operational channels. Provide telecommunications centers, watch centers, and the appropriate command centers with the non-duty telephone numbers of, and instructions for, contacting special security office personnel.
m. Conduct a continuing SCI security education training and awareness program to ensure all SCI-indoctrinated individuals are kept apprised of the requirements and guidelines for protecting SCI. Annual training of original classification authorities and biennial training derivative classifiers required by Executive Order 13526 (Reference (l)) will be included in this program.
n. Maintain appropriate accreditation documentation for each SCIF, communications system, and IS under the organization's security cognizance.
o. Review all reported derogatory information on SCI-indoctrinated personnel. Take appropriate action as required by applicable DoD personnel security regulations described in Enclosure 1 of Volume 3 of this Manual.
p. Manage, supervise, and provide support to s pecial access programs (SAPs) based on approved co-utilization agreements.
q. Provide SSO support to DoD SCI contractors in accordance with applicable contracts, including processing, reviewing, and validating DD Form 254. Support provided to contractors of other components will be provided as agreed to in MOAs with user agencies. (This duty does not apply to CSSOs.)
r. Maintain continuing liaison, as required, with non-SCI security officials.
10. SSRs and CONTRACTOR SPECIAL SECURITY REPRESENTATIVES (CSSRs). SSRs and CSSRs, under the direction of their supporting SSOs, are responsible for the day-to-day management and implementation of the facility’s SCI security program for subordinate SCIFs. For all SCIFs in which no SSO is resident, an SSR shall be appointed in writing. SSRs and CSSRs perform one or more of the SSO duties listed above as delegated and agreed to by their SSOs. SSRs will be SCI-indoctrinated military commissioned officers, warrant officers, non- commissioned officers (E-5 or above), or civilians (GS-7 or above). CSSRs will have the skills, training, and experience to fulfill the specific duties. The cognizant SIO may appoint SSRs at a lower grade level without further waiver with sufficient justification.
DoDM 5105.21-V1, October 19, 2012 Change 2, 10/06/2020 ENCLOSURE 2 14 11. COR/ CONTRACTING OFFICER TECHNICAL REPRESENTATIVE (COTR). A COR/COTR who is responsible for overseeing performance of contracts involving SCI information or material shall be SCI-indoctrinated Government personnel who are familiar with the daily operational requirements of contract execution. The COR/COTR shall:
a. Provide DD Form 254 to the supporting organizational SSO for approval prior to incorporation in the contract.
b. In conjunction with t he designated contractor representative or CSSO, prepare the initial request for establishment of a contractor SCIF, if required by the DD Form 254.
c. If a Defense Courier Division (DCD) account is required by the SCI contract, prepare a Defense Courier Account Record form and have the supporting SSO sign as the certifying official. Forward the original U.S. Transportation Command Defense Courier Account Record form and a copy of the DD Form 254 (if applicable) to the servicing DCD facility.
12. INDIVIDUALS WITH SCI ACCESS. Each individual who has access to SCI shall:
a. Report to proper authorities (SSO, security official, supervisor) any information that could reflect on their trustworthiness or on that of other individuals who have access to SCI, such as, but not limited to things such as:
(1) Violation of security regulations.
(2) Unexplained affluence, financial delinquency, garnishment of wages, lien placed on property for failure to pay a creditor, bankruptcy, or excessive indebtedness.
(3) Unlawful acts, except for traffic offenses where fines are less than $300 and do not involve alcohol or drugs.
(4) Apparent mental or emotional problems.
(5) Coercion or harassment attempts.
(6) Blackmail attempts.
(7) On-going contacts with foreign nationals.
(8) Planned or actual cohabitation with or marriage to a foreign national.
(9) Foreign travel (official and unofficial).
(10) Arrests, whether or not found guilty.
(11) Alcohol incidents, DUI arrest, obtaining alcohol abuse counseling or treatment.
DoDM 5105.21-V1, October 19, 2012 Change 2, 10/06/2020 ENCLOSURE 2 15 (12) Use, possession, or acquisition of illegal or illicit substances; misuse of prescription drugs.
b. Immediately report an actual or potential security violation or compromise to an SCI security official (SSO/SSR). In addition, individuals shall report any unauthorized disclosure or exposure of SCI that might reasonably be expected to result in the publication of SCI in the public media such as newspapers, books, television, radio, and internet blogs.