Archive

NA-1 SD M 226.1A, NNSA Line Oversight and Contractor Assurance System Supplemental Directive

The Line Oversight and Contractor Assurance System (LOCAS) is the National Nuclear Security Administration (NSSA) management system that drives mission performance and operational excellence. It requires the implementation of effective contractor self-assurance systems. coupled with focused Federal oversight. It allows efficient use of personnel and budgets. This Supplemental Directive, in conjunction with the requirements of Department of Energy (DOE) P 226.1A, DOE Oversight Policy, and DOE O 226.1A: Implementation of DOE Oversight Policy, establishes the broad framework for executing NNSA's overall oversight system. This Supplemental Directive provides requirements and guidance for the NNSA line oversight and contractor assurance systems and additional requirements and expectations for specific functional areas.
M 226.1A.pdf727.45KB
Version history and related documents
Document text

Text extracted from the attached file. Refer to the original document for the authoritative version.

Section 1

MANUAL Approved: 10-1 7-08 NNSA Line Oversight and Contractor Assurance System Supplemental Directive U.S. DEPARTMENT OF ENERGY National Nuclear Security Administration AVAILABLE ONLINE AT: Iink to NNSA Policicsisupplementa1 directives This page is intentionally blank. NNSA LINE OVERSIGHT AND CONTRACTOR ASSUWNCE SYSTEM SUPPLEMENTAL DIRECTIVE 1. PURPOSE. 'The Line Oversight and Contractor Assurance System (1,OCAS) is the National Nuclear Security Administration (NSSA) management system that drives mission performance and operational excellence. It requires the implementation of effective contractor self-assurance systems. coupled with focused Federal oversight. It allows efficient use of personnel and budgets. This Supplemental Directive, in conjunction with the requirements of Department of Energy (DOE) P 226.1A, DOE Oversight Policy, and 001; O 226.1A: Itnplementurion qf'll)OE Oversight Policy. establishes the broad framework for executing NNSA's overall oversight system. This Supplemental Directive provides requirements and guidance for the NNSA line oversight and contractor assurance systems and additional requirements and expectations for specific functional areas. 'I -. CAKCH,LATIO. None. 9 3. AI'PLICABILITY. a. Departmental Elements. Except for the exclusions in paragraph 3.cl this Supplemental Directive applies to all KNSA Departmental elements. b. NNSA Contractors. Except for the exclusions in paragraph 3.c, Attachment 1 of the Contractor Requirements Document (CRD) sets forth the requirements of this Supplemental Directive that apply to contractors. This Supplemental Directive applies only to Management and Operating contracts, prime security contractors. and other prime contractors as identified by the Site Office Manager or Contracting Officer. Once notified, the Contracting Officer 1s respons~ble for incorporating the applicable requirements ofthe CRI) into the laws, regulations, and DOE Directives clause of each contract fbr contractors that perform work at or for any KNSA facility affected by this Supplemental Directne. Regardless of tile performer of the work, the prime contractor is responsible for compliance with the requirements ofthe CRD that are incorporated in its contract. The prime contractor is responsible for flowing down the requirements of the CRD to subcontractors at any tier to the extent necessary to ensure the subcontractor's compliance with the requirements and the safe performance of work at or for any NNSA facility. c. Exclusions. This Supplemental Directive applies to all KNSA elements except for the Office of Naval Reactors (NA-30) unless the NNSA element or contractor has an exemption granted in writing from the NXSA Administrator. Requirements of this Supplenlental Directive do not apply to oversight of contractors in functional areas where the contractor is externally regulated by NA-I SD 226.1A 10-1 7-08 agencies such as the Kuclcar Regulatory Commission or the Occupational Safety and IIealth Administration. 1. REQUIREMENTS. Line oversight and contractor assurance system activities confirm adequate performance, identify areas of needed improvement, and address previously identified issues. Oversight processes must balance efforts among these objectives. The following requiremellts and the requirements in the applicable attachments to this Supplemental Directive (CRD Attachment 1 and Attachments 2 through 7. which impose additional requirements for nuclear safety. environment, sarety, and health (ES&H), safeguards and security, cyher security, emergency management, and business management, respectively) supplement, or provide further definition to- DOE O 226.1A. In the event of a conflict between this Supplemental Directive and a DOE Order or blanual, the DOE Order or Manual takes precedence.

Section 2

a. Contractor Assurance System. (1) In addition to the requirements and expectations set forth in DOE O 226.1A or successor directives and applicable contract requirements, the Contractor Assurance System (CAS) must meet the requirements in Attachment 1 to the CRD. b. NNSA Site Office Line Oversight. This section provides specific direction supplelnental to DOE O 226.1.4 for Site Office line oversight activities. Each Site Office oversight program must include the threc elements discussed below. ( I ) Evaluation of the Contractor's Assurance System: The Site Office must assess the effectiveness of the CAS using a variety of methods. These methods may include shadowing contractor assessments. comparing contractor assessment results and performance metrics with the results of similar assessments conducted by NNSA or credible outside evaluators, and evaluating contractor performance in resolving previously identified issues. Information regarding CAS effectiveness may he used to support contract management and to tailor Site Office oversight of contractor overall performance, as discussed in section 4.b(2) below. (2) Evaluation of Overall Contractor Performance: Each Site Office must develop and document an oversight program and annual implementation plan and schedule for evaluating overall contractor performance. The oversight program must include the use and the evaluation of CAS. The Site Office inust reference its oversight processes or procedures in its Contract Management Plan (CMP) as required by h e DOE Acquisition Guide. or in an equivalent document. 'The CMP is an overarching document that incorporates or references documents that describe how tlie Site Office manages its contracts and evaluates contractor performance. The Site Office oversight program. as described in the CMP, must establish requirements for a contractor oversight process that complies with DOE O 226.1A. This program must also establish requirements for the frequency, approach, and level of effort of' Site Office assessments based on criteria that are defined in the oversight program. These criteria should reflect a tailored approach that considers such factors as the significance ofthe requirement. the uniqueness and complexity of contractor operations, and the potential consequences of failing to meet contract requirements. Line oversight activities should focus on the areas of weakness in the contractor's program as evidenced by a tailored, risk- informed evaluation. Site Offices should use this tailored approach to conserve Federal resources in areas where there is documented evidence that the CAS is performing well or where the consequences oS performance deficiencies are minimal. This allows Federal resources to be focused on those areas where consequences of failure are high or where more rigorous assessments to drive contractor perSormance improvement provide the most value. I . The effectiveness of the CAS is a factor in tailoring Site Office oversight. Site Office oversight of contractor perfornlance should rely on the CAS only to the extent justified by documented Site Office evaluations of the CAS. . . n. The Site Office oversight program may take into consideration information provided by external sources, including information from contractor self-assessments, internal audits. and other assurance systems, as well as from independent sources. ... 111. Site Office assessment activities that satisfy the assessment

Section 3

requirements in Attachments 2 through 7 include the following: (a) Formal I>Ok or NNSA line management assessments conducted according to documented review plans; (b) Routine oversight by Headquarters or Site Office personnel where the documented results of the overs~ght clearly ~dentify the scope of the oversight. the requirements against which the contractor was evaluated. and the rcsults of the oversight activitj; and (c) Contractor assessment activities where Site Office personnel participated in or observed the assessment and NA-I SD 226.1 A 10-17-08 documented the results of their participation, including an evaluation of the efkctiveness of the contractor assessment. (3) Each Site Ofiice must develop and implement a procedure that defines its approach to self-assessment that complies with the self-assessment requirements in DOE O 226.1A. Site Offices must develop annual schedules for executing their self-assessment procedures. Attachments 2 through 7 to this Supplemental Directive contain requirements specific to individual functional areas. s- . NNSA Ileadquarters. NNSA Headquarters must develop an oversight program for evaluating Site Office performance. NNSA Headquarters Functional Management Plans (FMPs) are developed to define the NNSA oversight program for each functional area covered by this Supplemeiltal Directive. For each functional area, the FMP describes the implementation of DOE O 226.1A and this Supplemental Directive in that area. The FbIP may reference other procedures to document specific oversight processes. Each FMP, along with an associated assessment or review schedule, must be submitted to the NNSA Principal Deputy Administrator for approval on an annual basis. Prior to its being submitted for approval, each FMP should be coordinated with all NNSA organizations assigned oversight and assessment responsibilities and with the Site Office Manager. I h e responsible functional area managers and the scope of each functional area are defined below: (1 ) Nuclear Safetj - The NNSA functional leader for nuclear safety is the Chief of Defense Nuclear Safety. This functional area encompasses those requirements and policies defined in DOE O 410.1, Central Technical Authority Responsibilities Regarding Nuclear Safety Requirements. (2) Environment, Safety, and lIealth -The NNSA functional leader for ES&H is the Senior ES&H Advisor. This functional area includes all ES&H requirements except nuclear safety requirements. as defined in D O 1 3 410.1. (3) Safeguards and Security - The functional leader for safeguards and security is the Chief of Defense Nueleax Security. This functional area includes all physical security program elements. (4) Cyber Security - She functional leader for cyber security is the m l S A Chief Information Officer. This functional area includes all cyber security program elements. ( 5 ) Emergency Management - The functional leader for emergency management is the Associate Administrator for Emergency Operations This functional area includes all emergency management program requirements, as defined in DOE O 15 1.1 C, C'onzprehensive Eme~gency Mu??ugemenl Sy.stenz. (6) Business Management - The functional leader for business management is the Associate Administrator for Management and .4dministration. This functional area includes the business areas of procurement. finance, personal property, small business. contractor human resources. and contract administration.

Section 4

In each functional area, the FMP must define an VKS.4 Headquarters oversight program consisting of three elements: evaluation of Site Office performance (which may include limited assessment of contractor operations, primarily for nuclear safety, safeguards and security, cqber security, and other high-hazard activities), operational amareness of program and facility operations, and NNSA Headquarters self-assessment. These elements are discussed further below. (1) Evaluation of Site Office Performance: Each FMP must contain an approach for conducting and evaluating the effectiveness ofthe NNSA Site Office oversight programs in that functional area. Unless otherwise required in I)OE 0 226.1A or this Supplemental Directive, the lead for each functioilal area may rely on a review of Site Office self-assessment results in evaluating Site Office oversight, considering such factors as past performance. the significance of the requirement, the uniqueness and complexity of operations, and the potential consequences of failing to meet rccjuirements. (2) Operational Awareness: Each FMP must describe the operational awareness approach within that functional area. Specilic requirements for NNSrt Headquarters limited oversight of contractor high-hazard operations are addressed in Attachments 2 through 7 of this Supplemental Directive. Unless otherwise required in DOT: 0 226.1 A or this Supplemental Directive, the lead for each functional area may choose to rely on Site OStice oversight of the management and operating contractor to obtain operational awareness information on contractor performance. (3) Self-Assessnient: Each KNSA Headquarters organization must conduct a biennial self-assessment of its oversight and line management roles and responsibilities. The self-assessments must be consistent with the requirements in DOE O 226.1.4. Each organization must develop a procedure for its self-assessment program that is approved by the appropriate Deputy or Associate Administrator. For organizations within the immediate Office ofthe Administrator, these self-assessment procedures must be approved by the Principal Deputy Administrator. a. Principal Deputy Administrator. (1) Develops and maintains this Supplemental Directive (2) Approves the NNSA Ifeadquarters functional area FMPs and annual assessment and review schedules. (3) Approves the self-assessment procedure for NNSA IIeadyuarters organizations within the immediate Office of the Administrator. b. Deputy and Associate Administrators (1) Ensure that the requirements in this Supplemental Directive are implemented for facilities, activities. or programs under their cogni~ance. (2) Appro~es the self-assessment procedures for NNSA Headquarters organi~ations within their purvieu . (3) Comply with the FLIPS for NNSA Headquarters oversight for the programs, facilities. and operations within their purview. c. Functional Leaders (1) Develop NNSA Headquarters functional area FMPs for their assigned functional areas. (2) Develop assessment and review schedules for their assigned functional areas. d. Heads of Field Elements (1) Fnsure that the facilities, activities. and programs uiihin their purview comply w ~ t h the requirements of this Supplemental Directive and the CRD. (2) Coordinate with Contracting Officers to revise contracts to comply with the requirements of this Supplemental Directike and to require contractors to appropriately flow down requirements to subcontractors.

Section 5

(3) I;,nsure that procurement requcsts include applicable CRD requirements to be applied to awards or subauards. (4) Review and approve (through the Contracting Office as necessary) the detailed program descriptions for the contractor's CAS and subsequent updates reflecting significant changes. ( 5 ) Approve the CMP, 1,inc Opersight Plans, and annual execution schedules. 6. REFERENCES. b DOE P 226.1A, Del~urtnzent of E n e r a Overright Polley c. DOE Acquisition Guide d. Guide to Creating a Contract Management Plan," March 2002 7. DEFINITIONS. a. Assessment: This definition, taken from the Nuclear Safety PMP. describes the Site Office activities that constitute assessments: formal Site Office assessments conducted according to documented review plans; routine facility representative coverage where the results of the facility representative observations clearly document the activities ohsenred, the requirements being evaluated, and the results of the observations; routine oversight by safety system oversight personnel where the documented results of the oversight clearly identify the scope of the oversight, the requirements against which the contractor was being evaluated. and the results of the oversight activity; and contractor assessment activities where Site Office personnel participated in or observed the assessment and documented the results of their participation, including an evaluation of thc effectiveness of the contractor assessment. b. Contract Management Plan: A plan that summarizes how contract oversight responsibilities will be conducted. It does not identify ever] action that the Site Office or contractor must complete or perform, but rather sets forth the higher- level contract requirements, deliverables. and performance activities. c. Finding: 4 violation of an identified requirement d. Functional Management Plan: A plan that summarizes the meihodolog> of uslng individual or integrated functional oversight plans to meet Headquarters requirements for line overs~ght of Site Offices. e. High-Risk Activity: Activities that involve nuclear safety. nuclear material safeguards and security, or cyber security. Other activities are evaluated on a case-by-case basis to determine risk. An activity that may be considered high-risk is a Biosafety Levei 3 operation. f. Preventive Action: A change implemented to address a weakness in a management system that has not yet resulted in a finding. g. System-Based Oversight: Oversight activities that assess contractor performance through evaluating the contractor's processes and management systems and the &data normally generated by these systems. h. Transactional-Based Oversight: Oversight activities that assess contractor performance through evaluating contractor activities at the work, task, or facility level: direct interaction with personnel at any level within the contractor organization; and direct independent Federal staff evaluation of activities. physical conditions, and contractor documentation. 1. Weakness: A situation that. while not a direct violation of an identified requirement, may, if not resolved. lead to degradation in performance. Management attention is recommended to evaluate the situation and take action as deemed appropriate. 8. CONTACT. Questions concerning this Supplemental Directive should be should be addressed to James McConnell at (202) 586-4379. . ~ o M A ' s P. I) 'AGOSTI~O Administrator ix (and xf CONTENTS

Section 6

Contractor Assurance System CRD ............................................................................. Attachment 1 Nuclear Safety ............................................................................................................. T4ttacl~mcnt 2 Environment. Safety. and Health ................................................................................. Attachment 3 Safeguards and Security .............................................................................................. Attachment 4 Cyber Security ............................................................................................................. Attachment 5 Emergency hlanage~nent ............................................................................................. Attachment 6 Business Management ................................................................................................. Attachment 7 This page is intentionally blank. Attachment 1 CONTRACTOR ASSCRAKCE SYSTEM CONTRACTOR REQUIREMENTS DOCUMENT Attachment 1 Page 1 (and 2) The contractor must submit a detailed contractor assurance system (CAS) program description to the Site Oftice Manager for review and approval that addresses, at a minimum, the following aspects of operations: (I) nuclear safety; (2) environment, safety, and health. (3) safeguards and security; (3) emergency management; (5) cyber security; and (6) business management. The contractor must submit any updates to the detailed CAS program description to the Site Office Manager for revieu and approval whenever significant changes occur. rhe contractor shall facilitate effective sharing of all CAS information with NNSA. including electronic access. , I . his page is intentionally blank NA-I SI) 226.1 X 10-1 7-08 Attachment 2 Page 1 Attachment 2 NUCLEAR SAFETY 1. PURPOSE. This Attachment establishes the specific rcquirements and guidance for NNSA nuclear safety line oversight. 2. CANCELLA TION. None a. Departmental Elements. Except for the exclusion in paragraph 3.b. this Chapter applies to all NNSA Departmental elements that are responsible for. or manage, nuclear facilities as defined in 10 CFR 830, h'ucleur Sufity Munugernent. b. Exclusion. This Attachment applies to all NWSA elements except for the Office of Naval Reactors, KA-30. a. NKSA Sitc Oftice Line Oversight Systems. (I) Nuclear safety oversight must be conducted with the frequency, level of comprehensiveness, and rigor appropriate to ensure safety of the workers, the public, and the environment. One of the primary goals of nuclear safety obersight is to preclude, not just minimize the potential for, catastrophic nuclear accidents ( 2 ) NNSA Site Office oversight of nuclear safety should take advantage of the information provided by external sources. but the Site Office's nuclear safety oversight program must be sufficiently comprehensi~e to allow the Site Office Manager to accurately exaluate and communicate contractor performance against all nuclear safety requirements, identify nuclear safety performance issues in a timelq manner, and effectively resolve nuclear safety issues without relying on external oversight. b. Site Oftjce oversight of nuclear safety can be tailored to account for the contractor assurance sqstem (CAS) to the extent that the Site Office has ~erified and documented the adequacy of the CAS.

Section 7

c. For nuclear safety. the Site Office oversight program must assess the adequac) of contractor programs and procedure? and the implementation of those programs and procedures. Assessing the implementation of contractor programs and procedures must involve direct obsenrat~on of contractor performance or a revle* of specific work products resulting from the contractor programs and procedures. Attachment 2 Page 2 d. At a minimum, the Site Office program ibr oversight of nuclear safety must include the following elements (in addition to the specific requirements in DOE 0 226.111): (1) Assessments that validate the continuing, effective implementation of technical safety requirements (TSRs) for Hazard Category 2 and 3 nuclear facilities. The number of assessments should bc sufficient to draw a meaningful conclusion regarding the status of fSR implementation on an annual basis. (2) Assessments of equipment configuration, material condition. and maintenance of safety-class and safety-significant systems. structurcs, and components (SSCs). An assessment of each safety-class SSC should occur at least once every three years. An assessment of each safety- significant SSC should occur at least once every five years. Assessments of a representative sample of similar systems arc acceptable provided that the systems are of similar age. design. and classificat~on. (3) Assessments of the safety management programs defined in documented safety analyses for Hazard Category 2 and 3 nuclear facilities. An assessment of each safety management program should occur at least once every five years. Where a site-wide safety management program covers a number of facilities, it is sufticient to sample the implementation in a subset ofthe facilities, provided that at least one safety management program in each Huard Category 2 and 3 nuclear facility is assessed over a given five-year period. [4) Assessments that, over a period not to exceed five years, ensure the effective implementation of nuclear safety requirements in the directives listed in Attachment 1 to DOE O 41 0.1, C:enlrul Technical Authoriry Re.spon.sibilities Regurding l\~uclear Sufi@ Requi~.ements, that are not covered by the assessments described above. (1) For nuclear safety, direct assessment of contractors by SNSA Headquarters organizations consists of the following: 1. Biennial review of Site Office nuclear safety performance - although these are primarily reviews of Site Off7ce performance; they contain an element of direct contractor assessment to validate the results of Site Office oversight and assessment activities. Attachment 2 Page 3 (and 4) . . n. For-cause reviews - from time to time. NNSA Headquarters organizations may conduct for-cause reviews, accident or incident investigations, or direct assessments responding to inquiries from external stakeholders. 'These reviews must have the approval of the appropriate NNSA line mdnager (Assistant Deputy Administrator for Nuclear Safety and Operations or Site Office Manager) or of the Chief of Defense Nuclear Safety. Each review should be coordinated with the appropriate Site Office Manager. . . ' in. Reviews requested by the Site Office Manager iv. Support of Site Office assessments - NNSA Headquarters organizations may provide support for Site Office assessments of contractor nuclear safety programs.

Section 8

(2) The primary mechanism for oversight of Site Office performance in the area of nuclear safety is the NKSA biennial review process. Biennial reviews are conducted according to a protocol approved by the NNSA Administrator or Principal Deputy Administrator. From time to time, the Administrator. Principal Deputy Administrator, or Deputy Administrator for Defense Programs may direct specific for-cause reviews of Site Office performance issues in thc area of nuclear safety. Such reviews are outside the planned scope of the Functional Management Plan (FMP) for nuclear safety. (3) The nuclear safety FMP will describe the routine operational awareness programs for the Deputy Administrator for Defense Programs and tile Chief of Defense Nuclear Safety Collectively, these operational awareness programs should meet the requirements in DOI: O 226.1A. Specific operational awareness activities must include oversight of corrective actions. including metrics, periodic status reporting, and rollups of NNSA correctibe action tracking Attachment 3 Page I Attachment 3 ENVIRONMENT, SAFETY, AND HEALTH 1. PURPOSE. rhis Attachment establishes the specific requirements and guidance for line NNSA line oversight concerning environment, safety, and health (ES&II). 2. CAr\lCEI,I.ATION. hone a. Departmental Elements. Except for the exclusion in paragraph 3.b. rhis Chapter applies to all NNSA Llepartmental elements. b. Exclusion. This Attachment is applicable to all NNSA elements except for the Office of Naval Reactors. NA-30. a. NXSA Site Office Line Oversight Systems. 1) ES&II oversight must be conducted with the frequency. level of comprehensiveness, and rigor appropriate to ensure safety of the workers, the public, and the environment. 2 ) NNSA Site Office ES&H oversight should take advantage ofthe information provided by external sources, but the Site Office's ES&H oversight program must be sufficiently comprehensive to allow the Site Office Manager to accurately evaluate contractor performance against all ES&II requirements and communicate resulrs; identi@ ES&H performance issues in a timely manner; and effectively resolve ES&H issues without relying on external oversight. a) Site Office ES&H oversight can be tailored based on assessment results of the contractor assurance system (CAS) only to the extent that the Site Office has herified and documented its adequacy. b) Site Office ES&l1 oversight should primarily be accomplished through rnonitor~ng and evaluatmg the contractor's CAS. The level and nature of Site Off& I:S&IJ oversight. l.e., transactional vs. systemic. should be based on the significance of the ha/ard and performance by the contractor. including performartce of the CAS c) Once the CAS has been deemed fully operational, the Site Office Manager may continue to perform transactional oversight of specific non-nuclear operations mvolving high risks to the environment or to worker and public safet] and health (e.g.. Attachment 3 Page 2 Biosafcty Level 3 operations). The designation of non-nuclear operations as high-hazard and the associated oversight plan must be included in the annual Site Office schedule of planned assessments and focus areas for operational awareness. Transactional oversight may also be a necessary component of any for-cause evaluation. d) At a minimum, the Site Office ES&H oversight program must include assessments of aspects of the following program elements (in addition to the specific requirements in DOE O 226. I A,):

Section 9

1. -1 he contractor's 10 CI'R Part 85 1 -compliant Worker . . Safety and Health Program. 11. The contractor's t:nv~ronmental Management System . . . 111. The contractor's Work Planning and Control System. 3 ) Site Offices should develop a self-assessment plan to ensure that major aspects of all ES&EI programs are evaluated at least every three years. Site Office ES&II self-assessments should include an evaluation of its Federal Employee Occupational Safety and Health (FEOSH) Program. 4) NNSA is responsible for maintaining operational awareness of contractor ES&II activities. In addition to scheduled oversight, Site Offices maintam daily interactions. conduct meetings regularly with contractor personnel to monitor the status of issues and initiatives, and routinely observe contractor activities. I ) NNSA Headquarters ES&H oversight shall include: a) Quadrennial assessments of Site Office FEOSH Programs b) Quadrennial reviews of Sitc Office ES&H performance - Although these are primarily reviews of Site Office performance. they may contain an element of direct contractor assessment to validate the results of Site Office oversight and assessment activities. 2) For-Cause Reviews: When conditions warrant, NNSA Headquarters organizations may conduct for-cause reviews. accident or incident investigations, or direct assessments responding to inquiries from external stakeholders. These reviews must have the approval of the appropriate NNSA line manager (i.e., the Assistant Deputy Administrator or above). Each review should be coordinated with the appropriate NNSA Site Office Manager. Attachment 4 Page 1 Attachment 1 SAFEGUARDS AND SECURITY 1. PURPOSE. This Attachment establishes the specific requirements and guidance for NNSA line oversight concerning safeguards and security. 2. CANCEL,I,ATION. None. a. Departmental Elements. Except for the exclusion in paragraph 3.b, this Attachment applies to all NNSA Departmental elements. b. E.uclusion. rhis Attachment is applicable to all NNSA elements except the Office of Naval Reactors. NA-30. 4. REOLIREMENTS. a. General. 1) The Implementation Plan (IP) describes NNSA requirements expectations and the methodology by which compliance is verified. Corrective action planning is also incorporated in the IP. All expectations are graded with respect to risk importance. 2) The contractor's trend analyses of security incidents arc used to detem~ine and implement preventive measures that contribute to improved NNSA policies. 3) All security specialists conducting oversight must participate in the 'Technical Qualification Program (TQP). All Federal security staff members should complete the training recommended in DOE-STD-I 171 - 2003. .Yuft;guuril.s undSecurity Fzmctionul ilreu Stundurd and DOE-STD- 1 146-2007, Generul Echnicul Bu.se Quwl~ficu~ion, per the TQP. b. XNSA Site Office Oversight I ) The NNSA Site Officedefines its expectations for the roles of system- based and transactional-based oversight of the management and operating contractor or. if applicable. protective forces security contractor. 2) Thc Site Office is responsible for conducting direct line management okersight. such as inspect~ons. reLiews, surveillances, surveys. operational awareness, and ualkthroughs that evaluate programs and management systems. '4ttachment 4 Page 2 3) Security Surveys

Section 10

a) The Site Office is required to complete an annual comprehensive evaluation report of the contractor security program that assigns overall and topical area performance ratings. Site Offices should develop a survey activity schedule for evaluations occurring throughout the year. with consideration being given to other evaluation activities such as the contractor's self-assessment. Self- assessment deficiencies and weaknesses are documented in the Pegasus issues management system (or comparative system) and subject to corrective action processes. The evaluations are based on compliance with requirements (e.g., laws, regulations, and DOE directives) and on contractual objectives performance. b) The Site Office security survey focuses on contractor performa~ice. I'llis includes contractor effectiveness in conducting self- assessments and completing corrective actions. c) The Site Office is responsible for approving and validating closure of contractor corrective action plans. Corrective action planning involves performing causal analyses and identifying security risks. Findings and corrective action plan milestones are reported in the DOE Safeguards and Security Lnformation hlailagement System (SSIMS). d) Site Office responsibility for the security program includes evaluating findings based on the huard and risk associated with the underlying activities. Findings and the status of corrective action planning are reported to the Associate Deputy Administrator for Defense Nuclear Security (NA-70) as part of the contractor assurance system. 4. NNSA is responsible for maintaining operational awareness of contractor security program activities. In addition to scheduled survey activities, Site Oftices maintain on-going interactions. conduct regular meetings with contractor security managers to monitor the status of issues and initiatives, and routinely observe contractor activities. Attachment 4 Page 3 (and 4) 'She Chief of Defense Nuclear Security (C!DNS) is the NNSA Cognizant Security Authority, with responsibility for security Sine management oversight of the Site Offices. C/I)US implements overarching security actions for line oversight processes and management systems that provide infomation concerning security programs and transaction-based oversight for Federal assessments (e.g., inspections and observations). Attachment 5 CYBER SECURlTY Attachment 5 Page 1 1. PIJRPOSE. This Attachment establishes the specific requirements and guidance for NNSA line oversight concerning cyber security. 2. CANCE1,LATION. None a. Departmental Elements. Except for the exclusion in paragraph 3.b., this Attachment applies to all NNSA Departmental elements. h. Exclusion. This Attachment is applicable to all Nh'SA elenlents except for the Office of Naval Reactors, NA-30. 4. REQUIREMENTS. a. NNSA Site Office Line Oversight Systems. 1) Site Office oversight of cyber security can be tailored to account for site- specific requirements and results of the contractor assurance system (CAS) to the extcnt that the Site Office has verified and documented its adequacy. 2) The Site Office cyber security oversight program must assess the adequacy of contractor programs and procedures as well as the implementation of those programs and procedures. i\ssessments of the implementation of contractor programs and procedures must involve direct observation of contractor performance or a review of specific work products resulting from the contractor programs and procedures.

Section 11

a) At a mininlum. the Site Office program for oversight of cyber securit) must include the following elements (in addition to the specific requirements in DOE O 205 1 A, Depuriment ojEner'y (>her Securrty ~ ~ n u g e n z e n t ) : i Assessments that validate the continuing, effective implementation of technical, managcment. and administrative cyber security controls. The nuinber of assessments should be sufficient to draw a meaningful conclusion regarding the status of implementation of these controls on an annual basis; ii Assessments of the configuration management process; and Attach~iient 5 Page 2 ... 111 Annual assessments of the cyber security management program as defined in NNSA Cyber Security Policy 14.lC and the Cyber Security Strategic Plan. Where a site-wide security management program covers a number of programs, it is sufficient to sample the implementation in a subset of the cyber secunty program. b. NNSA Headauarters. 1) For cyber security. direct assessment of NNSA contractors by NASA Ifeadquarters organizations consists of the following: a) Annual revieus of Site Office cyber security programs. Although these are primanlq reviews of S ~ t e Office performance, they contain an element of direct contractor assessment to validate the results of Site Office oversight and assessment activities: b) For-cause reviews. From time to time, the NNSA Office of the Chief Information Officer (OCIO) may conduct for-cause reviews, cyber incident reviews, or direct assessments in response to inquiries from external stakeholders. These reviews must have the approval of the appropriate NNSA line manager (Site Office Manager). Chief Information Officer (CIO), or the Chief of Defense Nuclear Security (CiDNS). Each review will be coordinated with the appropriate NNSA Site Office h4anager: c) Reviews requested by the Site Office Manager; and d) l'he NNSA OCIO may provide support for Site Office assessments of contractor cyber security programs. 2) The primary mechanism for oversight of Site Office performance in the area of cyber security is the NNSA OCIO annual cyber security site assessment visit (SAV), which is conducted according to a protocol approved by the NNSA C1O. l'hc Administrator, Principal Deputy Administrator, or C/I>NS may also direct specific reviews of Site Office performance issues in the area of cyber security. Such reviews are outside the planned scope of the SAV for cyber security. 3) The NXSA Cyber Security Program Cyber Security Plan (PCSP) describes the routine operational awareness programs for the CIO and the C/DNS with regard to cyber security. Collectively, these operational awareness programs meet the requirenients in I>OE O 205.1A. Specific operational awareness activities must include oversight of corrective actions, including metrics, periodic status reporting, and rollups of NNSA corrective action tracking. NA- 1 SD 226.1 A 10- 17-08 Attachment 6 Page 1 Attachment 6 EMERGENCY MANAGEMENT 1. I'URPOSE. This Attachment establishes the specific requirements and guidance for NNSA line oversight concerning emergency management. 2. CANCELLATION. None. a. NNSA Elements. Except for the e.tclusions in paragraph 3.b. this Chapter applies to all NNSA elements that are responsible for emergency management under DOE O l j l . l C , C'onzprel?etzclve Et7~er,oency Wunugement Sy\yrtenz. and other applicable standards and plans. b. Exclusion. This Attachment is applicable to all NNSA elements except for the Service Center and the Office of Naval Reactors, NrZ-30.

Section 12

a. Site Office Line Oversight Svstems. 1 ) At a minimuin, the NNSA Site Office oversight program must include the elements of DOE 0 151.1C. 2) Non-mandatory assessment tools or guides to NKSA Site Offices to assist in the planning and conduct of emergency management self-assessments and contractor assessments. b. NKSA IIeadquarters. 1 ) The Office of NNSA Emergency Management Implementat~on (NA-43) is the IIeadquarters organ~zation responsible for coordinating and implementing line oversight in the area of emergcncy management for NNSA sltes, facilities. and operations. 2) NA-43 develops and Issues assessment and review schedules for emergency management okersight of NNSA field elements and prepares a Functional Management Plan (1-MI') to document the approach for implementing emergency management line oversight functions and conducting IIeadquaners seli'assessments and Site Office assessments. - The FMP describes line oversight acti%ities for emergency management and protocols for issues management and communicating results. 3) NA-43 uses a systematic approach for conducting 1-Ieadquarters line oversight of Site Offices through its fktdyuarters ilssessment Guide.fi)r Attachment 6 Page 2 Site Ofices ' Emergency ~Zil~mugemenr Progrums and accompanying checklists. This Guide uses goals and criteria froin the Emergency Munugemerzt Guide (DOE 61 5 I . 1 - 1) and DOE O 15 I . 1 C. Included as part of the toolkit is an Oversight SclzeduIe qfAnnuuI E~nergency ~tlcmugemenr Acriviries. 'I'his schedule lists critical functional areas and the associated oversight responsibilities and can be used to organize and schedule oversight activities for the entire year. Due dates and specific review and update requirements are also provided. 4) 'I'he FMP for emergency management describes the use of the following programs. processes, and operational awareness activities to monitor and evaluate compliance and performance: I Support the Chief of Defense Nuclear Safety (CDNS) in implementing its review process to ensure safet) and emergency preparedness at nuclear sites and facilities. These reviews are conducted according to a protocol approved by the NNSA Administrator. . . 11 Coordinate with, and assist. the Site Offices in evaluating contractor performance through the Corporate Performance Evaluation Plan (CPEP) process for management and operating contractors. iii Support Site Offices in conducting assessments. performance reviews, and exercise evaluations. iv Assist field elements in validating and verifying corrective actions. v IJse site-specific Emergency Readiness Assurance Plans (ER4Ps) to prepare the Annual Report on the Status of Emergency blanagement Programs at YNSA Sites, Facilities. and Operat~ons. Attachment 7 Page 1 Attachment 7 BUSINESS MANAGEMENT I . PLJRPOSE: 1 his Attachment establishes the specific requirements and guidance for line overs~ght with~n the buslness management function. 2. CANCELLATION: None a. Departmental Elements. Except for the exclusion in paragraph 3.c, this i\ttachment applies to all NKSA Departmental elements that are responsible for performing business management functions as defined in paragraph 4 below. b. NSSA Contractors. Except for the exclusion in paragraph 3.c, the Contractor Reauirements Document (CRD) sets forth the requirements that apply to contracts that include the CRD. c. Exclusion. This Attachment is applicable to all NKSA elements except for the Office of Naval Reactors, NA-30.

Section 13

4. REOUIREMEK I S. a. NiXSt-\ Site Office 1-ine Oversight. 1) Site Offices use a Contract Management Plan (CMP) combined with internal oversight plans, procedures, and processes to administer contracts and to conduct contractor oversight. b. SKSA Headquarters. I ) The NNSA Office of .4cquisition and Supply Management (KA-63) provides oversight of the business management functions at the Site Offices and the Service Center. The functional oversight responsibilities are to monitor, evaluate. and report on the efficiency and effectiveness of the Site Office and Service Center in properly performing their Federal oversight responsibilities to ensure that contractors meet their contractual requirements. NA-63 fulfills these responsibilities through the review and analysis of selected internal perfornmance indicators and results of assessment activities, and through direct observation of Site Office performance. 2) 'fhe NUSA Business Management Functional Oversight Plan describes the procedures for conducting oversight and surveillance activities. The Plan details the processes and methodologies to be used to verify effective Site Attachment 7 Page 2 Office operations in Procurement, Finance, Property, Small Business. Contractor Human Resources, and Contract Administration. c. XNSA Service Center 'The NXSA Service Center provides technical assistance and support to NNSA Headquarters and the Site Offices in overseeing hf&O contractor business management systems. The Service Center is continuously involved in operational awareness of hl&0 contractor business management systems, validating reported performance. recommending process changes as required, and providing feedback to the contractor on an agreed-upon basis. 'The Service Center is responsible for maintaining all documentation associated with systems reviews, operational awareness, recommended corrective actions, and recommendations to the Site Contracting Officer for systems or conditional approval or disapproval.

Something wrong with this record? Tell us