SD 200.1, Information Resources Management
This Supplemental Directive (SD) defines the authorities, requirements, and responsibilities for the management of information technology (IT), including national security systems (NSS), information systems, operational technology (OT), and the application of information policies within the National Nuclear Security Administration (NNSA). This SD delineates authorities provided to the Associate Administrator for Information Management and Chief Information Officer (NA-IM CIO) by the NNSA Administrator (Administrator) through Delegation Order No. NA-005.01, dated 2-11-2019, which establishes responsibilities for the management of information resources across all NNSA mission and functional elements. NA-IM will implement policy for the oversight of information resources that align with the requirements outlined in executive, congressional, and delegated authorities.
Associated DOE Directive:
Version history and related documents
Superseded by
A newer version replaces this document.
- SD 200.1 Admin Chg. 1Information Resources Management (Sep 18, 2024)
Document text
Text extracted from the attached file. Refer to the original document for the authoritative version.
Section 1
CONTROLLED DOCUMENT OFFICE OF PRIMARY INTEREST (OPI):
AVAILABLE ONLINE AT: Office of the Chief Information Officer
http://directives.nnsa.doe.gov
printed copies are uncontrolled
SUPPLEMENTAL DIRECTIVE
Approved: 12-14-2023
Recertification Due: 12-14-2026
INFORMATION RESOURCES
MANAGEMENT
NATIONAL NUCLEAR SECURITY ADMINISTRATION
Office of the Associate Administrator for Information
Management and Chief Information Officer
NNSA SD 200.1
http://directives.nnsa.doe.gov/
THIS PAGE INTENTIONALLY LEFT BLANK
NNSA SD 200.1 1
12-14-2023
INFORMATION RESOURCES MANAGEMENT
1. PURPOSE. This Supplemental Directive (SD) defines the authorities, requirements, and
responsibilities for the management of information technology (IT), including national
security systems (NSS), information systems, operational technology (OT), and the
application of information policies within the National Nuclear Security Administration
(NNSA). This SD delineates authorities provided to the Associate Administrator for
Information Management and Chief Information Officer (NA-IM CIO) by the NNSA
Administrator (Administrator) through Delegation Order No. NA-005.01, dated 2-11-
2019, which establishes responsibilities for the management of information resources
across all NNSA mission and functional elements. NA-IM will implement policy for the
oversight of information resources that align with the requirements outlined in executive,
congressional, and delegated authorities.
2. AUTHORITY. Selected authorities are identified within this section. See Attachment 6,
References, for additional information and authorities.
a. Department of Energy (DOE) Order (O) 200.1A Chg. 1 (MinChg.), Information
Technology Management, dated 1-13-2017.
b. Delegation Order No. NA-005.01, dated 2-11-2019.
c. 40 United States Code (U.S.C.) §§ 11315, 11316 and 11319 (2021).
d. 44 U.S.C. §§ 3101 and 3102 (2021).
e. 44 U.S.C. §§ 3505-3507, 3510-3511, 3513, 3515, 3517, 3518, 3520, 3552-3559,
3561-3564, 3571-2, 3576, and 3581-3583 (2021).
f. 44 U.S.C. §§ 3601-3606 (2021).
3. CANCELLATIONS. Redelegation Order No. NA-005.01-01 to the Deputy
Administrator for Defense Programs, dated 3-25-2019, and the NNSA Federal
Information Technology Acquisition Reform Act Implementation Framework, dated 9-
25-2019.
4. APPLICABILITY.
a. Federal. This SD and its Attachments apply to all NNSA federal entities that
acquire, operate, maintain, or dispose of IT, including NSS, information systems,
and OT.
b. Contractor. Except for the equivalencies and exemptions in paragraph 4.d., the
Contractor Requirements Document (CRD), Attachment 1, and Attachments 2-5
set forth requirements that apply to site and facility management contracts. The
CRD and Attachments 2-5 must be included in the management and operating
2 NNSA SD 200.1
12-14-2023
(M&O) contracts and the subcontracts to the M&O contracts that manage
information systems, including NSS and OT. M&O contracts must include DOE
Acquisition Regulation clause 952.204-77, Computer Security.
c. Systems. This SD applies to a broad range of technologies. This SD uses
statutory definitions with a recognition that modern technology does not always
fit within a singular definition. NNSA must make risk-based decisions to manage
technology using the best information and the most appropriate process available.
This SD identifies those processes and responsibilities that are applicable to
certain NSS and OT.
Section 2
d. Equivalency/Exemptions.
(1) Equivalency. In accordance with the responsibilities and authorities
assigned by Executive Order (E.O.) 12344, Naval Nuclear Propulsion
Program, codified at 50 U.S.C. §§ 2406 and 2511, and to ensure
consistency throughout the joint Navy/DOE Naval Nuclear Propulsion
Program, the Deputy Administrator for Naval Reactors (Director) will
implement and oversee requirements and practices pertaining to this
Directive for activities under the Director’s cognizance.
(2) Exemption. This SD does not apply to the Sensitive Compartmented
Information (SCI) IT and information systems located at NNSA sites. SCI
systems must comply with Director of National Intelligence Directives
and Orders and E.O. 12333, United States Intelligence Activities,
accordingly, as advised by the DOE Director of Intelligence and
Counterintelligence. Nothing in this SD will alter or supersede the
existing authorities of the Director of National Intelligence.
5. BACKGROUND. This SD provides guidance to ensure the appropriate management and
oversight for the acquisition, operation, maintenance, and disposal of NNSA’s
information resources.
6. REQUIREMENTS. NNSA information resources consisting of IT (including NSS,
information systems, and OT), must be acquired, operated, maintained, and disposed of
consistent with NNSA mission needs and all statutory, regulatory, DOE and NNSA
Directive requirements.
7. RESPONSIBILITIES.
a. Director, Office of Policy and Strategic Planning (NA-1.1).
(1) Develops annual IT Planning Guidance, in coordination with NA-IM to
ensure alignment with the planning phases of Planning, Programming,
Budgeting, and Evaluation (PPBE) process.
NNSA SD 200.1 3
12-14-2023
(2) Conducts planning studies on information resources issues, including
cybersecurity, as appropriate, in collaboration with NA-IM.
b. Office of Cost Estimating and Program Evaluation (NA-1.3).
(1) Issues the NNSA Planning, Programming, and Fiscal Guidance to include
the budgetary resources for investments in IT in coordination with the
Associate Administrator for Management and Budget (NA-MB).
(2) Reviews cost estimates for IT-related federal and contractor procurements
and assists NA-IM in determining the budget and cost estimates of IT
investments, as appropriate, and ensures budget requests that include
investments in IT are reviewed and approved by NA-IM prior to
submission to the Office of Management and Budget (OMB).
(3) Participates in reviews of IT investments governed by DOE O 413.3B,
Program and Project Management for the Acquisition of Capital Assets,
and provides input regarding IT projects and investments to NA-IM, as
applicable.
c. Associate Administrator for Information Management and Chief Information
Officer (NA-IM).
(1) Uses enterprise architecture to conduct information resources management
strategic planning in alignment with the PPBE process to align resources
to NNSA mission requirements.
(2) Conducts IT portfolio management (ITPfM) to review and approve IT and
information system investments, as appropriate, in accordance with the
responsibilities outlined in DOE O 200.1A, and OMB Circular A-11,
Preparation, Submission, and Execution of the Budget, § 55, Information
Technology Investments.
(3) Supports the development of policies and procedures for IT and
information system investment management including project oversight,
in coordination with the Associate Administrator for Partnership and
Section 3
Acquisition Services (NA-PAS).
(4) Ensures that the operation, management, and use of IT and information
systems complies with applicable statutes, regulations, policies, and
directives to meet NNSA mission requirements, in coordination with the
cognizant NNSA Contracting Officer or Contracting Officer’s
Representative, as needed.
(5) Develops information management policies and procedures that increases
program efficiency, improves the integrity, quality, and utility of
4 NNSA SD 200.1
12-14-2023
information across NNSA, implements appropriate security and
classification controls, and enables the trustworthy use of decision-making
systems.
(6) Establishes, maintains, and enforces the governance of IT policies and
processes to enable the secure sharing of information and the performance
of IT services, including information assurance, discovery, accessibility,
and dissemination (including unclassified IT and information system
policy releasability) requirements.
(7) Develops and conducts performance measurement assessments and
reviews to evaluate the use of information resources and makes
recommendations, as necessary, to the Administrator.
(8) Develops a comprehensive IT investment and acquisition review process
in accordance with DOE O 200.1A and DOE O 413.3B, ensuring
adherence to the following parameters:
(a) Sits on the Energy System Acquisition Advisory Board (ESAAB)
as a full member to provide guidance and gain insight into the IT
and information system portions of major capital asset projects.
(b) Ensures acquisitions not subject to review by the ESAAB follow
the appropriate investment and procurement approval process in
Attachment 2.
(c) Ensures NNSA IT and information system investments are
reviewed by the DOE Information Management Governance
Board, as appropriate.
(d) Adheres to the requirements and processes of DOE O 413.3B for
IT and information system investments based on the thresholds
identified in that Order.
(9) Authorizes Program and Functional Offices to manage OT, as appropriate.
(10) Ensures applicable mobile device management procedures are
implemented in a manner per DOE O 203.2, Mobile Technology
Management, to reduce risks to an acceptable level while supporting
mission requirements, incorporating authorization, accountability,
monitoring, training, and reporting requirements for users.
(11) Establishes and chairs the NNSA IT Investment Review Board (IRB). As
prescribed by DOE, reviews and approves proposed Major IT and
information system investments that meet or exceed the thresholds
established in Attachment 2.
NNSA SD 200.1 5
12-14-2023
(12) Serves on boards, committees, and other groups pertaining to the assigned
NA-IM responsibilities. Represents the Administrator on matters
regarding IT resources outside of NNSA.
(13) Establishes or uses existing governance bodies and processes to ensure
information policies and systems, along with IT, align with NNSA
objectives and do not pose any undue risk to NNSA. Entrusts the
governance bodies with performing the functions of reviewing and
analyzing information and IT investments, addressing issues, and
elevating unresolved matters.
(14) Ensures that IT investments meet the Government Performance and
Results Act of 1993 (GPRA 1993) and the GPRA Modernization Act of
2010 performance goals and reporting requirements, as appropriate.
(15) Develops guidance to support telework, implements new and emerging
Section 4
telework technologies for enterprise use, and develops guidelines for
protecting government furnished equipment and personally owned
equipment used to access NNSA information systems for purposes of
telework.
(16) Approves information and communications technology and services
supply chain risk management practices and processes, in accordance with
SD 205.1, Baseline Cybersecurity Program.
(17) Develops policies for use of Internet Domains for NNSA networks.
(18) Promotes the use of enterprise purchasing agreements for Commercial
Off-The-Shelf IT products or capabilities to focus resources on efficient
and effective supplier management, where applicable.
d. Deputy Administrator for Defense Programs (NA-10).
Develops and implements policies, processes, and procedures for the federal and
contractor acquisition, operation, maintenance, digital assurance, and disposition
of national security systems under their cognizance needed for the operations of
defense programs, including, but not limited to:
(1) Nuclear weapons IT involving equipment that is an integral part of a
weapon or weapon system.
(2) High performance computing systems (HPCs) and associated software
running on HPCs that are critical to the fulfillment of the nuclear security
mission.
6 NNSA SD 200.1
12-14-2023
(3) Command, control, and communications systems integral for the safe and
secure transport of special nuclear materials.
e. Associate Administrator for Partnership and Acquisition Services (NA-PAS).
(1) Coordinates with NA-IM regarding reviews of IT and IT-related
acquisition plans, strategies, cost estimates, contractual actions,
memorandums of understanding, and interagency agreements that involve
plan, contract, or agreement modifications or result in substantial changes
to IT resources within the scope of NA-PAS’ authority.
(2) Ensures procurement requests are supported by cost estimates that have
been reviewed by NA-IM, or the appropriate Program Office. Ensures
that NA-IM or the appropriate Program Office approves IT procurements,
acquisitions, and major investments, and confirms that the acquisition
strategies and plans are consistent with existing IT policies.
(3) Coordinates with NA-IM and NA-MB to implement a NNSA-wide
process to ensure that any procurement or acquisition that includes IT or
IT-related systems, solutions, or services includes personnel with the
appropriate federal acquisition certification on the integrated project team.
(4) Updates program guidance, in coordination with NA-IM, to ensure
programs executed under DOE O 413.3B or DOE O 415.1B, Information
Technology Project Management, include NA-IM as a voting member on
all Critical Decision (CD) Gate review boards, and ensures NA-IM
reviews and approves IT investments within each gate review.
(5) Ensures contracts or interagency agreements that include IT have NA-IM
approval prior to execution or are consistent with the acquisition strategy
and plan approved by NA-IM.
f. Associate Administrator for Management and Budget (NA-MB).
(1) Updates and issues the NNSA Planning, Programming, and Fiscal
Guidance in coordination with NA-1.3, to include expenditures for
investments in IT. Ensures budget requests including IT investments are
reviewed and approved by NA-IM prior to submission to OMB.
(2) Provides the annual IT training and workforce certification requirements.
(3) Develops and implements workforce strategies and proficiency standards
Section 5
to ensure that the IT Management, Computer Engineering, Data Science,
and Security Administration position personnel possess the knowledge,
skills, and abilities to meet the requirements of the job category including
obtaining the appropriate certifications, as relevant to the position.
NNSA SD 200.1 7
12-14-2023
Coordinates with NA-IM to ensure cybersecurity workforce strategies are
in alignment with the National Institute of Standards and Technology
Special Publication 800-181, National Initiative for Cybersecurity
Education (NICE) Workforce Framework for Cybersecurity.
(4) Develops and implements procedures necessary to recruit and retain
cybersecurity professionals according to OMB Memorandum (M)-16-15,
Federal Cybersecurity Workforce Strategy, and the U.S. Office of
Personnel Management guide, Compensation Flexibilities to Recruit and
Retain Cybersecurity Professionals.
g. NNSA Program/Functional Offices.
(1) Plans, programs, budgets, and executes IT investments, to include the
acquisition, operations, maintenance, development, and disposal of the IT,
unless otherwise required by policies or procedures.
(2) Reviews, approves, and reports budget requests containing information
system and IT resources to NA-IM in accordance with the process
outlined in Attachment 2. Program and Functional offices must:
(a) Request an authorization assignment from NA-IM for the IT
Investment under Program Office or Functional Office’s
responsibility. ITPfM Investments attributed to a Program Office
that has not requested authorization assignments will be managed
by NA-IM.
(b) Ensure IT investments and OT procurements align with the
mission of NNSA and applicable IT and cybersecurity
requirements to include appropriate network architectures and
technology standards.
(c) Ensure IT investments comply with Attachment 3, as appropriate.
(d) Ensure reviews and assessments are performed for IT and OT
procurements under their cognizance. Ensure proper reporting for
IT procurements and investments.
(e) Consult with the appropriate Authorizing Official (AO) regarding
applicable cybersecurity requirements if the technology is expected
to connect to a NNSA network or to the internet directly.
Procurement expenditures that involve equipment that will be
operated within, connected to a cybersecurity accreditation
boundary, or will be connected to a network must be reported to
the Enterprise AO.
8 NNSA SD 200.1
12-14-2023
(3) Ensures all proceedings by a Program Office IT IRB, or similar IT
governance board, are sent to NNSA-OCIO-ITIRB@nnsa.doe.gov.
(4) Program/Functional Offices who fund and manage OT and national
security s must develop a plan, in coordination with NA-IM, that requires
OT to be managed throughout its lifecycle. The plan must, at a minimum:
(a) Grant programs the authority to manage OT per Program Office
leadership guidance;
(b) Define the scope of applicability of OT across the Federal or site
program;
(c) Demonstrate effective resource management by identifying
performance metrics and objectives, including budget, timeline,
and quality standards;
(d) Define a process for the sites to report to the Field Office OT that
connects to an accreditation boundary; and
(e) Ensure OT complies with appropriate cybersecurity statutes and
regulations.
(5) Implements processes and procedures for the federal and contractor
acquisition, operation, maintenance, digital assurance, and disposition of
OT and national security systems under their cognizance needed to
Section 6
implement their programs.
h. Critical Decision (CD) Gate Approval Authority.
(1) Approve all program/project CD gates for an assigned IT investment not
to exceed $25 million (M), or as authorized by NA-IM.
(2) Approve new requirements that were not included in the annual supporting
documentation for IT Investment budget submissions not to exceed $25M
unless authorized by NA-IM.
i. Field Office Manager (FOM).
(1) Reviews M&O IT purchases that meet or exceed the thresholds
established in Attachment 2.
(2) Supports and implements IT procurements and acquisitions, investment
reviews, sound resource management, program governance and oversight,
portfolio management, workforce strategies, and reporting requirements.
NNSA SD 200.1 9
12-14-2023
(3) Coordinates with NA-IM regarding oversight and review of the M&O-
managed IT.
(4) Delegates to equivalent federal personnel as needed.
j. Information Technology Program/Project Manager.
(1) Supports the development and refinement of IT performance metrics,
strategies, and other initiatives to support OMB’s IT portfolio
management reporting including data published on the Federal IT
Dashboard in coordination with NA-IM.
(2) Ensures IT investments are included in budget requests and includes
appropriate program management and project management items
necessary to properly manage IT investments.
(3) Approve minor changes to planned IT procurements as long as the
planned IT procurement:
(a) Is not already approved (following the submission of supporting
documentation and the bill of materials during the annual budget
approval process); and
(b) Does not exceed $1M for an individual purchase and $25M in
annual IT investment costs.
(4) Reviews and approves new IT investment requirements before requesting
their CD Gate Approval Authority’s approval to optimize the service
delivery of their IT Investment.
(5) Review IT procured as part of a Strategic Partnership Project.
k. NNSA Employees.
(1) In addition to the responsibilities identified in DOE O 203.1, Limited
Personal Use of Government Office Equipment, NNSA employees are
responsible for:
(a) Using government furnished technology in an appropriate manner,
and in accordance with related job requirements.
(b) Using personal devices (to include mobile devices) in a manner
that protects DOE/NNSA data and does not compromise IT assets.
(c) Refraining from using any DOE/NNSA IT system or network to
intentionally search, view, or receive digital content that:
10 NNSA SD 200.1
12-14-2023
(i) is sexually explicit, sexually oriented, or sexual in nature;
(ii) conducts or furthers any type of illicit or illegal activity.
(d) Reporting improper or unsafe use of IT to their immediate
manager.
l. Contracting Officers.
(1) Include the CRD, Attachment 1, in any contracts that involve the
acquisition of, or modification to IT and information systems in
conjunction with Program Office or Field Office.
(2) Ensure the Contractor Purchasing System Approval is updated to align
with the requirements of this SD.
(3) Ensure, prior to award of a contract, order, or work assignment for IT
products or services, that the site’s procurement:
(a) Is associated with a previously approved IT investment; and
(b) Has received appropriate approvals in accordance with this
Directive.
8. REFERENCES. See Attachment 5.
9. CONTACT. The Office of the Associate Administrator for Information Management and
Chief Information Officer at (202) 586-1729.
Section 7
BY ORDER OF THE ADMINISTRATOR:
Jill Hruby
Administrator
Attachments:
1. Attachment 1: Contractor Requirements Document (CRD)
2. Attachment 2: Investment and Procurement Approval Process
3. Attachment 3: IT Portfolio Management (ITPfM) Budget Process
4. Attachment 4: Definitions
5. Attachment 5: References
NNSA SD 200.1 Attachment 1
12-14-2023 AT1-1
ATTACHMENT 1: CONTRACTOR REQUIREMENTS DOCUMENT (CRD)
NNSA SD 200.1, INFORMATION RESOURCES MANAGEMENT
This CRD establishes the requirements for the National Nuclear Security Administration
(NNSA) contractors who manage, operate, and have access to NNSA and Department of Energy
(DOE) information systems. Contractors must comply with the requirements listed in this CRD
and all applicable Attachments. Regardless of the performer of the work, contractors are
responsible for complying with and incorporating the appropriate CRD requirements into
subcontractor contracts at any tier, to the extent necessary, to ensure the contractors comply with
the requirements. The contractors will ensure that they and their subcontractors incur only those
costs that are reasonable and would be incurred by a prudent person in the conduct of a
competitive business. Contractors and subcontractors are responsible for complying with any
Attachment referenced in and made a part of this CRD.
1. REQUIREMENTS. Contractors must:
a. Ensure that the procurement, acquisition, and management of information,
information systems, and information technology (IT) complies with all
applicable laws, regulations, and policies, including Office of Management and
Budget (OMB) directives and guidance, the E-Government Act of 2002, the
Federal Information Technology Acquisition Reform Act (FITARA), the Clinger
Cohen Act (CCA), the Federal Information Security Modernization Act (FISMA),
and the Department of Energy (DOE) Order (O) 200.1A, Information Technology
Management.
b. Ensure the procurement, acquisition, use, and management of IT, funded by, or
operated for the U.S. Government, meet U.S. Government program and mission
goals to promote sound resource management.
c. Itemize information collection and IT in all procurements to enable the Field
Office Manager (FOM), the managing Program Office, and the Office of the
Associate Administrator for Information Management and Chief Information
Officer (NA-IM) to review, assess, and approve the procurement or acquisition in
accordance with the established dollar thresholds in Attachment 2.
d. Develop applicable mobile device management procedures in a manner that cost-
effectively reduces risk to an acceptable level while supporting mission
requirements. The procedures must ensure:
(1) Employees are appropriately trained in the use of both government
furnished equipment (GFE) and personal mobile devices to access
information resources;
(2) Monitoring and reporting on the effectiveness of mobile device
management procedures; and
Attachment 1 NNSA SD 200.1
AT1-2 12-14-2023
(3) Overall accountability for mobile device use is retained.
e. Develop guidance to support telework, implement new and emerging telework
technologies for enterprise use, and protect IT GFE and personally owned
equipment used to remotely access NNSA information systems during telework
from malware, hacking, and other cybersecurity threats.
f. Develop an Internet Protocol Version 6 Implementation Plan and submit the plan
to DOE in accordance with OMB Memorandum (M)-21-07, Completing the
Section 8
Transition to Internet Protocol Version 6 (IPv6), and DOE O 200.1A.
g. Establish a site governance board to approve IT investment proposals, ensure
alignment with the NNSA Enterprise architecture, approve site IT budget
expenditures, and perform IT oversight. The site governance board must approve
and forward all investment proposals that meet or exceed the monetary thresholds
established in Attachment 2 to the NNSA IT Investment Review Board following
concurrent approvals from the Senior Acquisition Official (SAO) and FOM.
h. Develop a site-specific IT portfolio management plan consistent with the
guidelines established in Attachment 2. The plan must be periodically reviewed
and updated to incorporate objectives established in the NNSA IT and Cyber
Program Evaluation Guidance and NNSA and site-specific information resources
plans. The IT portfolio management plan must:
(1) Establish or identify an IT Governance Board.
(2) Establish roles, responsibilities, and procedures for appropriate review and
approval of IT acquisitions and procurements in accordance with the
process outlined in Attachment 2.
(3) Require reviews to evaluate information resources, as necessary, to ensure
the objectives and implementation factors identified in the annual IT PEG
are being met.
(4) Report all IT requirements in accordance with OMB Circular A-11,
Preparation, Submission and Execution of the Budget guidance.
i. For existing contracts, the implementation timeline for this CRD is 180 days from
publication if it is prior to the next contract award, renewal, or extension. For all
other contracts, requirements must be implemented in accordance with the
timelines established in DOE Acquisition Regulation clause 970.5204-2.
2. RESPONSIBILITIES.
a. Contractors supplying information systems and IT, including IT services, to
NNSA.
NNSA SD 200.1 Attachment 1
12-14-2023 AT1-3
Ensures the requirements of this CRD and Attachments 2-5 are followed.
b. Management and Operating (M&O) IT Investment Program/Project Managers.
(1) Approves minor changes to planned IT procurements as long as the
planned IT procurement:
(a) Is not already approved (following the submission of supporting
documentation and the bill of materials during the annual budget
approval process); and
(b) Does not exceed $1 million (M) for an individual purchase, or
$25M in annual IT investment costs.
(2) Reviews and approves new IT investment requirements prior to requesting
their CD Gate Approval Authority’s approval to optimize the service
delivery of their IT Investment.
(3) Reviews IT procured as part of a Strategic Partnership Project (deferring
to the sponsor for federal decisions, as applicable).
c. M&O Chief Information Officers, Information Technology Points of Contact, or
appointed delegates.
(1) Reviews and approves, per the Site IT Governance Board
recommendations, all contracts or other agreements for information,
information systems and IT, including services where the requestor is a
M&O contractor, the request is less than $25M, or the request does not fit
the definition of a Major IT Investment. The review and approval of the
IT investment can be delegated or assigned to a Program Manager or CD
Gate Approval Authority.
(2) Reviews their site’s proposed IT acquisition or procurement requirements
greater than or equal to $25M or that meet the definition of a Major IT
Investment and forward to their NNSA Element SAO and FOM for
Section 9
approval.
(3) Ensures data for all IT and operational technology acquisitions are made
available to the NNSA Element FOM. The IT acquisition must be
associated with an IT investment UII. All approvals under this section
must be sent to NNSA-OCIO-FITARA@nnsa.doe.gov.
d. Site IT Governance Review Board, or Similar IT Governance Board.
(1) Reviews all proposed investments in IT, IT contracts or other agreements
that will include the procurement of IT, including acquisition for
mailto:NNSA-OCIO-FITARA@nnsa.doe.gov
Attachment 1 NNSA SD 200.1
AT1-4 12-14-2023
information, information systems, and IT and services for investments that
are less than the monetary thresholds established in Attachment 2. When
proposed investments meet or exceed the monetary thresholds established
in Attachment 2, forward to NA-IM via the site’s SAO and FOM.
(2) Ensures all information and IT procurements and acquisitions are reported
to the NNSA FOM or designee prior to procurement or acquisition.
e. Site Senior Acquisition Official or Equivalent.
Reviews and validates IT procurements that meet or exceed the monetary
thresholds established in Attachment 2.
NNSA SD 200.1 Attachment 2
12-14-2023 AT2-1
ATTACHMENT 2: INVESTMENT AND PROCUREMENT APPROVAL
Note: This Attachment applies to National Nuclear Security Administration (NNSA) federal and
contractor organizations. In addition to the requirements set forth in the Contractor
Requirements Document (CRD), Attachment 1, contractors and subcontractors are responsible
for complying with this Attachment and must incorporate it into contracts and subcontracts that
include the CRD.
1. PURPOSE.
Pursuant to the authority provided to the agency Chief Information Officer (CIO) and key
bureau CIOs under the Federal Information Technology Acquisition Reform Act
(FITARA), NNSA Delegation Order No. NA-005.01, Department of Energy (DOE)
Order (O) 200.1A, Information Technology Management, and DOE O 415.1, Change 2,
Information Technology Project Management, this Attachment assigns information
technology (IT) management responsibilities to NNSA Program Office Officials,
Functional Office Officials, and Management and Operating (M&O) site Points of
Contact, provided that the Officials confirm that all procurements are associated with an
IT investment Unique Investment Identifier (UII) and are within the defined dollar
thresholds. The Office of the Associate Administrator for Information Management and
Chief Information Officer (NA-IM) may assign IT investment decisions to Program and
Functional Offices for mission-specific IT that is not managed directly by a M&O.
2. APPLICABILITY.
a. All IT acquisitions or procurements by Program Offices, Functional Offices, Field
Offices, and M&O site elements (NNSA Elements), including National Security
Systems (NSS) and information systems.
b. All acquisitions of IT equipment by a contractor under an existing contract (e.g.,
other direct costs) where both:
(1) The IT is used by the U.S. Government directly or used by a contractor
under a contract with the U.S. Government that requires the use of the IT
but does not include IT acquired by a contractor incidental to a federal
contract; and
(2) The equipment was not previously approved under this process.
c. Operational Technology does not require IT portfolio management reporting and
procurement approvals through IT Portfolio Management (ITPfM).
3. IT APPROVAL PROCESS.
Section 10
IT investment approval processes and procedures have been split into two parts:
Attachment 2 NNSA SD 200.1
AT2-2 12-14-2023
a. Guidance for investments in IT; and
b. Guidance for the authorization to procure those resources.
NNSA Elements are expected to exercise their associated IT management responsibilities
depending on the nature of the IT being procured and will need to demonstrate that they
can effectively manage an IT governance mechanism, in which case they may be granted
governance privileges over their IT. NNSA Elements that do not establish their own IT
Investment Review Board (IRB) or a similar IT governance board must forward new IT
investment proposal requests to the NNSA IT IRB at NNSA-OCIO-
ITIRB@nnsa.doe.gov.
3.1. IT INVESTMENT APPROVAL DECISION PROCESS.
NNSA Elements must divide their IT approvals into two categories:
a. Business Justification. This category evaluates whether the investments align
with NNSA’s strategy, goals, and objectives, and aligns with federal law and
policy. It also evaluates the investment’s potential return on investment.
b. Technical Impact. This category evaluates whether the investment is technically
feasible. It also evaluates the investment’s potential impact on NNSA’s existing
technology infrastructure.
For each IT Investment, NNSA Elements must assign an IT Investment Program
Manager (PM) to execute the development, deployment, integration, and management of
day-to-day operations. The NNSA Element CIO, or delegate, must oversee all stages of
the IT investment including authorizing new procurements, and any changes to the scope,
budget, and schedule, to ensure the IT investment stays within the approved cost and
implementation timeframe. Table 1AT2 below captures the applicable NNSA
Management Framework to be used for the authorization of IT Investments.
IT investments that are being acquired or procured for integration into existing ITPfM
investments must manage or transition their authorities according to the
investment/project value thresholds in Table 1AT2.
mailto:NNSA-OCIO-ITIRB@nnsa.doe.gov
mailto:NNSA-OCIO-ITIRB@nnsa.doe.gov
NNSA SD 200.1 Attachment 2
12-14-2023 AT2-3
Table 1AT2. Investment and Applicable Project Management Framework
Investment/Project Value Oversight Authority
$0-<$1 million (M) IT IRB assigned1
$1M-<$25M IT IRB assigned
$25M-<$50M Assigned by NNSA IT IRB/NA-IM
$50M+ As assigned by DOE O 413.3B2
3.1.1. IT INVESTMENT APPROVALS.
NNSA Elements must maintain an IT IRB or similar governance process to approve new
IT investments. The NNSA Element’s IRB, or delegate, must coordinate with NA-IM for
the creation of any new IT Investment in the Federal IT Dashboard. The NNSA
Element’s IRB, or delegate, is responsible for assigning an approval authority (see Table
1AT2) for the development of any new IT Investments and the approval of all subsequent
IT. All IT investment approvals require a memorandum indicating approval to proceed to
the next phase and supporting documentation to be used by the Office of Partnership and
Acquisition Services (NA-PAS) to permit the procurement.
Where IT investment proposals are $25M or greater, or are designated as Major IT
Investments,3 NNSA Elements must forward the IT investment business case analysis to
their Senior Acquisition Official and associated federal Field Office Manager (FOM) for
concurrence, and then forward the proposed investment to NA-IM for final approval prior
Section 11
to initiating any contractual actions.
The NNSA Element’s IT IRB, or similar governance board, must evaluate proposed IT
investments to ensure they align with organizational objectives, are achievable, and do
not conflict with other organizational limits and is responsible for the oversight of ITPfM
investments.
The NNSA Element’s IT IRB oversight activities should include:
1 The Program Office or Site’s IRB will assign a gate authority if a Program Office or Site IRB exists. Otherwise,
the NNSA IT IRB will assign the gate authority.
2 Although DOE O 413.3B is generally applied to capital projects, line-item IT Investments may be held to these
requirements for similar oversight as directed by NNSA leadership. Applicability and tailoring requirements will be
determined by the Critical Decision (CD) Gate Approval Authority.
3 DOE defines the criteria for a Major IT Investment as: Has a cumulative steady state or mixed lifecycle funding of
$25 million or more across the past year, current year, and budget year; Is an Office of Management and Budget-
directed portfolio IT investment; Is a Government-wide E-Government or Line of Business investment where DOE
is a Managing Partner; Is a Multi-Agency Collaboration or Inter-Agency Shared Services investment where DOE is
an Agency Lead; or Requires special management attention because of its importance to the mission or function of
the Agency.
Attachment 2 NNSA SD 200.1
AT2-4 12-14-2023
a. Monitoring IT investment progress by ensuring that performance measures are
met.
b. Ensuring the budget is fully developed.
c. Ensuring the IT Investment and any sub-tier investments are aligned with the
Technology Business Management Taxonomy.
d. Reporting all proceedings to NA-IM at NNSA-OCIO-ITIRB@nnsa.doe.gov.
New IT purchases that were not captured in the bill of materials (BOM) supporting
annual budget planning may be approved by the NNSA Element’s authority within their
assigned limits, which allows the ITPfM Investment PMs to approve administrative and
minor changes without additional approvals.
The IT Investment PM must evaluate purchases for organizational compliance and
impact, including:
a. Ensuring correct alignment with their ITPfM Investment and budget.
b. Evaluating for possible Foreign Ownership, Control, or Influence risk.
c. Suitability within the IT Operations environment/IT Service Management.
d. Cybersecurity architecture and monitoring requirements.
e. Records Management and Privacy.
f. Compliance with other federal laws.
g. Compatibility with enterprise license agreements.
3.2. IT PROCUREMENT PROCESS.
Procurement approval, required by FITARA as codified in 40 U.S.C. § 11319 and
implemented by NA-PAS, is principally performed by NA-IM as part of the annual
budget approval process by evaluating an investment’s supporting documentation (e.g.,
NA-IM FITARA request form, Summary, Statement of Work, Total Cost Estimate,
Request of Quotation, FOM approval), proposed BOM, and details of anticipated
modernization and enhancements.
NA-IM will provide a memorandum to NA-PAS at the conclusion of annual budget
planning indicating which IT Investments have conformed with sufficient supporting
documentation for their investment to enable NA-IM approval. IT procurements may
then be approved by NA-PAS.
mailto:NNSA-OCIO-ITIRB@nnsa.doe.gov
NNSA SD 200.1 Attachment 2
12-14-2023 AT2-5
For procurements not previously approved through the budget submission process, where
Section 12
supporting documentation stated above exceeds the authorization assignments of the
NNSA Element’s PM and/or appointed Approval Authority, and for procurements for a
ITPfM Major Investment, requests must be sent to NA-IM for approval at NNSA-OCIO-
FITARA@nnsa.doe.gov. Sufficient supporting documentation should be provided to
help facilitate timely approval. Otherwise, a notice of procurement must be sent to the
NNSA IT IRB at NNSA-OCIO-ITIRB@nnsa.doe.gov.
4. PROVISIONS.
a. The installation of any hardware or software on DOE networks must not introduce
additional cybersecurity risks and will be approved by the appropriate
Authorizing Official before integration to the IT network.
b. This Assignment must not be used to purchase IT components integral or
ancillary to any project, the entirety of which has not already been approved
through existing approval processes (e.g., NNSA or Element IT IRB).
c. All IT procured must be associated with an IT investment UII. IT reporting must
include this number to indicate the proper procurement to the CD Gate Approval
Authority.
5. LIMITATIONS.
a. In exercising the authority delegated in this Assignment, a delegate is governed
by the rules and regulations of the policies and procedures prescribed by the
Secretary of Energy or their delegate(s) and the NNSA Administrator or their
delegate(s).
b. Nothing in the Assignment precludes NA-IM from exercising the authority
delegated by the Administrator.
mailto:NNSA-OCIO-FITARA@nnsa.doe.gov
mailto:NNSA-OCIO-FITARA@nnsa.doe.gov
mailto:NNSA-OCIO-ITIRB@nnsa.doe.gov
NNSA SD 200.1 Attachment 3
12-14-2023 AT3-1
ATTACHMENT 3: INFORMATION TECHNOLOGY PORTFOLIO
MANAGEMENT (ITPfM) BUDGET PROCESS
Note: This Attachment applies to National Nuclear Security Administration (NNSA) federal and
contractor organizations. In addition to the requirements set forth in the Contractor
Requirements Document (CRD), Attachment 1, contractors and subcontractors are responsible
for complying with this Attachment and must incorporate it into contracts and subcontracts that
include the CRD.
1. INTRODUCTION.
The purpose of this Attachment is to describe NNSA’s Information Technology (IT)
investment reporting process to the Office of Management and Budget (OMB). OMB
Circular A-11, Preparation, Submission and Execution of the Budget, requires IT
investments to be reported annually to OMB and made public via the Federal IT
Dashboard. Figure 1, IT Portfolio Management (ITPfM) Budget Process, illustrates the
NNSA Office of the Associate Administrator for Information Management and Chief
Information Officer (NA-IM) process in complying with the OMB reporting requirement.
Figure 1: ITPfM Budget Process
2. PROCESS.
a. Requests for IT resources that require a Unique Investment Identifier (UII) that
identifies where the funding will be reported in the NNSA IT Portfolio.
b. IT resources currently associated with reported investments in the NNSA IT
Portfolio will already have a UII to complete the procurement request.
(1) The NNSA ITPfM Team will work with the responsible Point(s) of
Contact (POC) to ensure that the new funding amounts are updated in the
past year, current year, and budget year (BY) investment ledger tables in
the ITPfM tool.
Attachment 3 NNSA SD 200.1
AT3-2 12-14-2023
(2) If the associated investment is considered a Major or Standard Investment,
the NNSA ITPfM Team will also include updates regarding new projects,
Section 13
risks, metrics, and artifacts, as appropriate.
(3) IT resource requests originating from Management and Operating (M&O)
sites will follow the M&O approval process. M&O Chief Information
Officers’ (CIO) indirect spending should already have associated UIIs and
be reported in the ITPfM tool. IT spending outside of the M&O CIO’s
budget will need to be examined to determine whether it is being reported
in other investments. M&O CIOs will work with the NNSA ITPfM Team
and other NNSA Program Offices to update all investments at the M&O
site. Exceptions will be processed according to the following steps.
c. IT resources for programs not in compliance with ITPfM reporting requirements
will not have a UII to complete the procurement request. Note that reporting
requirements only pertain to IT and not operational technology.
(1) The NNSA ITPfM Team will work with the responsible POC(s) to initiate
an IT investment that creates a UII.
(2) The NNSA ITPfM Team will provide ITPfM training to the new POC(s).
(3) The responsible POC(s) will then complete the investment form prior to
the next reporting deadline, as established by the OMB.
(a) Draft – late August
(b) Pre-decisional – September/October
(c) President’s Budget/Passback (Final) – January/February
(4) Incomplete IT investment paperwork cannot be entered into the ITPfM
reporting process, and therefore will be excluded from the NNSA IT
Investment Portfolio.
d. All completed investments will be added to the NNSA IT Investment Portfolio,
which the NNSA ITPfM Team uses to perform updates, data calls, IT Dashboard
assessments, and account for in the annual OMB submission.
e. The NNSA ITPfM team provides the IT Portfolio to the NNSA Office of
Management and Budget (NA-MB), from which NA-MB will verify the accuracy
of the IT Portfolio to the IT portion of the approved budget request.
f. The NNSA ITPfM team collects BY IT Budget Requests and provides a high-
level IT Portfolio report to the NNSA CIO for approval. Upon approval, the IT
Portfolio is submitted to the Department of Energy (DOE) CIO for final review.
NNSA SD 200.1 Attachment 3
12-14-2023 AT3-3
g. The NNSA IT Portfolio is submitted by the DOE ITPfM team to OMB as a part
of the DOE IT Portfolio Submission Package.
h. NNSA will integrate government-wide cost structures, technologies, IT resources,
and solutions into NNSA ITPfM investments according to the implementation
requirements established by DOE and OMB’s Technology Business Management
taxonomy.
NNSA SD 200.1 Attachment 4
12-14-2023 AT4-1
ATTACHMENT 4: DEFINITIONS
Note: This Attachment applies to National Nuclear Security Administration (NNSA) federal and
contractor organizations. In addition to the requirements set forth in the Contractor
Requirements Document (CRD), Attachment 1, contractors and subcontractors are responsible
for complying with this Attachment and must incorporate it into contracts and subcontracts that
include the CRD.
a. Critical Decision Gate Approval Authority. Reviews and approves all program critical
decision gates, including emergent and new requirements, for an assigned information
technology (IT) investment not to exceed $25 million (M) or as authorized by the NNSA
Office of the Associate Administrator for Information Management and Chief
Information Officer (NA-IM).
b. Energy Systems Acquisition Advisory Board (ESAAB). Supports the Department of
Energy’s (DOE) and NNSA strategic objective of achieving and maintaining excellence
Section 14
in project management. The ESAAB advises the Secretary of Energy, Chief Executive
for Project Management, and Departmental Project Management Executives on
enterprise-wide project management policies and assists the Chief Executive on critical
decision milestones for Major System Projects and performance baseline deviation
dispositions with a Total Project Cost of $750M or greater, DOE Order 413.3B Change 6
(LtdChg), Program and Project Management for the Acquisition of Capital Assets, dated
1-12-2021.
c. Information. Any communication or representation of knowledge such as facts, data, or
opinions in any medium or form, including textual, numerical, graphic, cartographic,
narrative, or audiovisual, Committee on National Security Systems Instruction 4009,
National Information Assurance Glossary, dated 4-26-2010, and National Institute of
Standards and Technology Federal Information Processing Systems 199, Standards for
Security Categorization of Federal Information and Information Systems, dated 2-10-
2004.
d. Information and Communications Technology or Services. Any hardware, software, or
other product or service primarily intended to fulfill or enable the function of information
or data processing, storage, retrieval, or communication by electronic means, including
transmission, storage, and display, Executive Order 13873, Securing the Information and
Communications Technology and Services Supply Chain, dated 5-15-2019.
e. Information Resources. Refers to information and related resources, such as personnel,
equipment, funds, and information technology, 44 United States Code (U.S.C.) § 3502.
f. Information System. A discrete set of information resources organized for the collection,
processing, maintenance, use, sharing, dissemination, or disposition of information, 44
U.S.C. § 3502.
Attachment 4 NNSA SD 200.1
AT4-2 12-14-2023
g. Information Technology. With respect to an executive agency means (A) any equipment
or interconnected system or subsystem of equipment, used in the automatic acquisition,
storage, analysis, evaluation, manipulation, management, movement, control, display,
switching, interchange, transmission, or reception of data or information by the executive
agency, if the equipment is used by the executive agency directly or is used by a
contractor under a contract with the executive agency that requires the use (i) of that
equipment; or (ii) of that equipment to a significant extent in the performance of a service
or the furnishing of a product; (B) includes computers, ancillary equipment (including
imaging peripherals, input, output, and storage devices necessary for security and
surveillance), peripheral equipment designed to be controlled by the central processing
unit of a computer, software, firmware, and similar procedures, services (including
support services), and related resources; but (C) does not include any equipment acquired
by a federal contractor incidental to a federal contract, 40 U.S.C. §11101(6).
h. IT Investment Review Board, or Similar Governance Board. The final decision-making
body at a Program Office, Functional Office, or Management and Operating site element
that is assigned responsibility to ensure investments and expenditures on IT and IT
services align with the mission, vision, and needs of the organization by conducting
investment and procurement decision making, ongoing oversight, and oversight of
information technology acquisition and procurement.
Section 15
i. IT Investment Program Manager. An individual responsible for managing a portfolio or
program comprised of one or more projects, systems, solutions, or services. Although the
projects start and end, the program essentially continues indefinitely to support one or
more key mission functions. Reviews and approves minor and administrative changes to
planned IT procurements.
j. Major IT Investment. DOE defines the criteria for a Major IT Investment as:
a. Has a cumulative steady state or mixed lifecycle funding of $25 million or more
across the past year, current year, and budget year;
b. Is an OMB-directed portfolio IT investment;
c. Is a Government-wide E-Government or Line of Business investment where DOE
is a Managing Partner;
d. Is a Multi-Agency Collaboration or Inter-Agency Shared Services investment
where DOE is an Agency Lead; or
e. Requires special management attention because of its importance to the mission or
function of the Agency.
k. National Security System. A telecommunications or information system operated by the
Federal Government, where the function, operation, or use of which involves intelligence
activities; involves cryptologic activities related to national security; involves command
NNSA SD 200.1 Attachment 4
12-14-2023 AT4-3
and control of military forces; involves equipment that is an integral part of a weapon or
weapons system; or, subject to 40 U.S.C. § 11103(2), is critical to the direct fulfillment of
military or intelligence missions.
l. Nuclear Weapons Information Technology. The information system or components of an
information system integral to a nuclear weapon; surrogates for nuclear weapons used in
development, test, or training; and equipment connecting to nuclear weapons or their surrogates,
including war reserve units, developmental units, weapon components, test units, trainer units, and
weapon operational support equipment (e.g., systems that are directly involved in operational test,
configuration, security, and safety throughout the lifecycle).
m. Operational Technology. Hardware and software that detects or causes a change through
the direct monitoring or control of physical devices, processes, and events in the
Enterprise, 15 U.S.C. § 278g-3a (6).
n. Technology Business Management (TBM) Taxonomy. The TBM taxonomy is a
commercial standard to describe cost sources, technologies, IT resources (towers), and
solutions. The TBM taxonomy has been adopted as government-wide policy to describe
technology in common terms. The current TBM taxonomy is available at
www.tbmcouncil.org.
http://www.tbmcouncil.org/
NNSA SD 200.1 Attachment 5
12-14-2023 AT5-1
ATTACHMENT 5: REFERENCES
Note: This Attachment applies to National Nuclear Security Administration (NNSA) federal and
contractor organizations. In addition to the requirements set forth in the Contractor
Requirements Document (CRD), Attachment 1, contractors and subcontractors are responsible
for complying with this Attachment and must incorporate it into contracts and subcontracts that
include the CRD.
a. Executive Order 13556, Controlled Unclassified Information, dated 11-4-2010.
b. Clinger-Cohen Act of 1996, Public Law (Pub. L.) 104-106, 40 United States Code
(U.S.C.) § 11101, et seq.
c. Privacy Act of 1974, as amended, Pub. L. 93-579, 5 U.S.C. § 552a.
d. Section 508 of the Rehabilitation Act, Pub. L. 106-246, 29 U.S.C. § 798.
e. E-Government Act of 2002, Pub. L. 107-347, 44 U.S.C. §§ 3501-3531 and §§ 3551-3606.
Section 16
f. Freedom of Information Act, Pub. L. 110-175, 5 U.S.C. § 552.
g. Federal Information Security Modernization Act of 2014, Pub. L. 113-283, 44 U.S.C. §
3541 et seq.
h. MEGABYTE Act of 2016, Pub. L. No. 114-210, 40 U.S.C. § 11302 et seq.
i. Federal Information Technology Acquisition Reform Act. Pub. L. No. 113-291, dated 12-
19-2014.
j. National Defense Authorization Act for Fiscal Year 2018, Subtitle G, Modernizing
Government Technology (MGT Act), Pub. L. No. 115-91, 40 U.S.C. § 11301 et seq.
k. GPRA Modernization Act of 2010, Pub. L. No. 111-352, dated 1-4-2011.
l. Government Performance and Results Act of 1993, Pub. L. No. 103-62, dated 8-3-1993.
m. 48 Code of Federal Regulations (CFR), Federal Acquisition Regulation (FAR).
n. 48 CFR, Chapter 9, Department of Energy, Subchapter H, Clauses, and Forms.
o. 48 CFR, 970.5204–2, Laws, Regulations, and DOE Directives.
p. 36 CFR, Chapter 12, Subchapter B, Records Management.
q. 32 CFR, Part 2002, Controlled Unclassified Information.
Attachment 5 NNSA SD 200.1
AT5-2 12-14-2023
r. Office of Management and Budget (OMB) Memorandum (M) 23-03, Fiscal Year 2023
Guidance on Federal Information Security and Privacy Management Requirements.
s. OMB M-22-18, Enhancing the Security of the Software Supply Chain through Secure
Software Development Practices.
t. OMB M-22-16, Administration Cybersecurity Priorities for the FY 2024 Budget.
u. OMB M 21-30, Protecting Critical Software Through Enhanced Security Measures.
v. OMB M-21-07, Completing the Transition to Internet Protocol Version 6 (IPv6).
w. OMB M-21-05 Extension of Data Center Optimization Initiative (DCOI).
x. OMB M-19-26, Update to the Trusted Internet Connections (TIC) Initiative.
y. OMB M-19-19, Update to Data Center Optimization Initiative.
z. OMB M-19-18, Federal Data Strategy – A Framework for Consistency.
aa. OMB M-19-15, Improving Implementation of the Information Quality Act.
bb. OMB M-18-12, Implementation of the Modernizing Government Technology Act.
cc. OMB M-17-06, Policies for Federal Agency Public Websites and Digital Services.
dd. OMB M-16-20, Category Management Policy 16-3: Improving the Acquisition and
Management of Common Information Technology: Mobile Devices and Services.
ee. OMB M-16-19, Data Center Optimization Initiative.
ff. OMB M-16-14, Category Management Policy 16-2: Providing Comprehensive Identity
Protection Services, Identity Monitoring, and Data Breach Response.
gg. OMB M-16-12, Category Management Policy 16-1: Improving the Acquisition and
Management of Common Information Technology: Software Licensing.
hh. OMB M-15-14, Management and Oversight of Federal Information Technology.
ii. OMB M-15-13, Policy to Require Secure Connections across Federal Websites and Web
Services.
jj. OMB Circular A-11, Preparation, Submission and Execution of the Budget.
kk. OMB Circular No. A-123, Management’s Responsibility for Enterprise Risk
Management and Internal Control.
NNSA SD 200.1 Attachment 5
12-14-2023 AT5-3
ll. OMB Circular A-130, Managing Federal Information as a Strategic Resource.
mm. Committee on National Security Systems Instruction 4009, Committee on National
Security Systems (CNSS) Glossary, dated 4-6-2015.
nn. National Institute of Standards and Technology (NIST) Special Publication 800-53, Rev.
5, Assessing Security and Privacy Controls in Information Systems and Organizations.
oo. NIST Federal Information Processing Systems 199, Standards for Security
Section 17
Categorization of Federal Information and Information Systems.
pp. Department of Energy (DOE) Federal Information Technology Acquisition Reform Act
Common Baseline Implementation Plan and Self-Assessment, dated 6-24-2016.
qq. DOE Order (O) 471.7, Controlled Unclassified Information, dated 2-3-2022.
rr. DOE O 413.3B Chg 6 (LtdChg), Program and Project Management for the Acquisition
of Capital Assets, dated 1-12-2021.
ss. DOE O 205.1C Chg 1 (LtdChg), Department of Energy Cybersecurity Program, dated 2-
3-2022.
tt. DOE O 203.1, Limited Personal Use of Government Office Equipment Including
Information Technology, dated 4-23-2009.
uu. DOE O 203.2, Mobile Technology Management, dated 5-15-2014.
vv. DOE O 200.1A (LtdChg), Information Technology Management, dated 1-13-2017.
ww. DOE’s Federal Information Technology Acquisition Reform Act (FITARA)
Implementation Plan, dated 5-17-2016 (v.11).
xx. DOE Acquisition Guide, updated 6-20-2019.
yy. NNSA Delegation Order No. NA-005.01, effective 2-11-2019.
zz. NNSA Supplemental Directive (SD) 415.1A, Project Oversight for Information
Technology (PO-IT), dated 4-27-2021.
aaa. NNSA SD 413.3-6 Energy Systems Acquisition Advisory Board Equivalent Process,
dated 3-1-2022.
bbb. NNSA SD 205.1, Baseline Cybersecurity Program, dated 7-7-2017.
ccc. NNSA Policy 130.1B, Planning, Programming, Budgeting, and Evaluation (PPBE)
Process, dated 5-25-2021.
1. PURPOSE
2. AUTHORITY
3. CANCELLATIONS
4. APPLICABILITY
a. Federal
b. Contractor
c. Systems
d. Equivalency/Exemptions
5. BACKGROUND
6. REQUIREMENTS
7. RESPONSIBILITIES
a. Director, Office of Policy and Strategic Planning (NA-1.1).
b. Office of Cost Estimating and Program Evaluation (NA-1.3).
c. Associate Administrator for Information Management and Chief InformationOfficer (NA-IM).
d. Deputy Administrator for Defense Programs (NA-10).
e. Associate Administrator for Partnership and Acquisition Services (NA-PAS).
f. Associate Administrator for Management and Budget (NA-MB).
g. NNSA Program/Functional Offices.
h. Critical Decision (CD) Gate Approval Authority
i. Field Office Manager (FOM).
j. Information Technology Program/Project Manager
k. NNSA Employees
l. Contracting Officers
8. REFERENCES
9. CONTACT
ATTACHMENT 1: CONTRACTOR REQUIREMENTS DOCUMENT (CRD)
1. REQUIREMENTS
2. RESPONSIBILITIES
a. Contractors supplying information systems and IT, including IT services, toNNSA
b. Management and Operating (M&O) IT Investment Program/Project Managers
c. M&O Chief Information Officers, Information Technology Points of Contact, orappointed delegates.
d. Site IT Governance Review Board, or Similar IT Governance Board.
e. Site Senior Acquisition Official or Equivalent.
ATTACHMENT 2: INVESTMENT AND PROCUREMENT APPROVAL
1. PURPOSE
2. APPLICABILITY
3. IT APPROVAL PROCESS
3.1. IT INVESTMENT APPROVAL DECISION PROCESS
a. Business Justification
b. Technical Impact
3.1.1. IT INVESTMENT APPROVALS.
3.2. IT PROCUREMENT PROCESS
4. PROVISIONS
5. LIMITATIONS
ATTACHMENT 3: INFORMATION TECHNOLOGY PORTFOLIOMANAGEMENT (ITPfM) BUDGET PROCESS
1. INTRODUCTION.
2. PROCESS
ATTACHMENT 4: DEFINITIONSNote:
ATTACHMENT 5: REFERENCES