Archive

SD 200.1, Information Resources Management

This Supplemental Directive (SD) defines the authorities, requirements, and responsibilities for the management of information technology (IT), including national security systems (NSS), information systems, operational technology (OT), and the application of information policies within the National Nuclear Security Administration (NNSA). This SD delineates authorities provided to the Associate Administrator for Information Management and Chief Information Officer (NA-IM CIO) by the NNSA Administrator (Administrator) through Delegation Order No. NA-005.01, dated 2-11-2019, which establishes responsibilities for the management of information resources across all NNSA mission and functional elements. NA-IM will implement policy for the oversight of information resources that align with the requirements outlined in executive, congressional, and delegated authorities.
SD_200.1.pdf662.08KB
Version history and related documents

Superseded by

A newer version replaces this document.

View full version history

Document text

Text extracted from the attached file. Refer to the original document for the authoritative version.

Section 1

CONTROLLED DOCUMENT OFFICE OF PRIMARY INTEREST (OPI): AVAILABLE ONLINE AT: Office of the Chief Information Officer http://directives.nnsa.doe.gov printed copies are uncontrolled SUPPLEMENTAL DIRECTIVE Approved: 12-14-2023 Recertification Due: 12-14-2026 INFORMATION RESOURCES MANAGEMENT NATIONAL NUCLEAR SECURITY ADMINISTRATION Office of the Associate Administrator for Information Management and Chief Information Officer NNSA SD 200.1 http://directives.nnsa.doe.gov/ THIS PAGE INTENTIONALLY LEFT BLANK NNSA SD 200.1 1 12-14-2023 INFORMATION RESOURCES MANAGEMENT 1. PURPOSE. This Supplemental Directive (SD) defines the authorities, requirements, and responsibilities for the management of information technology (IT), including national security systems (NSS), information systems, operational technology (OT), and the application of information policies within the National Nuclear Security Administration (NNSA). This SD delineates authorities provided to the Associate Administrator for Information Management and Chief Information Officer (NA-IM CIO) by the NNSA Administrator (Administrator) through Delegation Order No. NA-005.01, dated 2-11- 2019, which establishes responsibilities for the management of information resources across all NNSA mission and functional elements. NA-IM will implement policy for the oversight of information resources that align with the requirements outlined in executive, congressional, and delegated authorities. 2. AUTHORITY. Selected authorities are identified within this section. See Attachment 6, References, for additional information and authorities. a. Department of Energy (DOE) Order (O) 200.1A Chg. 1 (MinChg.), Information Technology Management, dated 1-13-2017. b. Delegation Order No. NA-005.01, dated 2-11-2019. c. 40 United States Code (U.S.C.) §§ 11315, 11316 and 11319 (2021). d. 44 U.S.C. §§ 3101 and 3102 (2021). e. 44 U.S.C. §§ 3505-3507, 3510-3511, 3513, 3515, 3517, 3518, 3520, 3552-3559, 3561-3564, 3571-2, 3576, and 3581-3583 (2021). f. 44 U.S.C. §§ 3601-3606 (2021). 3. CANCELLATIONS. Redelegation Order No. NA-005.01-01 to the Deputy Administrator for Defense Programs, dated 3-25-2019, and the NNSA Federal Information Technology Acquisition Reform Act Implementation Framework, dated 9- 25-2019. 4. APPLICABILITY. a. Federal. This SD and its Attachments apply to all NNSA federal entities that acquire, operate, maintain, or dispose of IT, including NSS, information systems, and OT. b. Contractor. Except for the equivalencies and exemptions in paragraph 4.d., the Contractor Requirements Document (CRD), Attachment 1, and Attachments 2-5 set forth requirements that apply to site and facility management contracts. The CRD and Attachments 2-5 must be included in the management and operating 2 NNSA SD 200.1 12-14-2023 (M&O) contracts and the subcontracts to the M&O contracts that manage information systems, including NSS and OT. M&O contracts must include DOE Acquisition Regulation clause 952.204-77, Computer Security. c. Systems. This SD applies to a broad range of technologies. This SD uses statutory definitions with a recognition that modern technology does not always fit within a singular definition. NNSA must make risk-based decisions to manage technology using the best information and the most appropriate process available. This SD identifies those processes and responsibilities that are applicable to certain NSS and OT.

Section 2

d. Equivalency/Exemptions. (1) Equivalency. In accordance with the responsibilities and authorities assigned by Executive Order (E.O.) 12344, Naval Nuclear Propulsion Program, codified at 50 U.S.C. §§ 2406 and 2511, and to ensure consistency throughout the joint Navy/DOE Naval Nuclear Propulsion Program, the Deputy Administrator for Naval Reactors (Director) will implement and oversee requirements and practices pertaining to this Directive for activities under the Director’s cognizance. (2) Exemption. This SD does not apply to the Sensitive Compartmented Information (SCI) IT and information systems located at NNSA sites. SCI systems must comply with Director of National Intelligence Directives and Orders and E.O. 12333, United States Intelligence Activities, accordingly, as advised by the DOE Director of Intelligence and Counterintelligence. Nothing in this SD will alter or supersede the existing authorities of the Director of National Intelligence. 5. BACKGROUND. This SD provides guidance to ensure the appropriate management and oversight for the acquisition, operation, maintenance, and disposal of NNSA’s information resources. 6. REQUIREMENTS. NNSA information resources consisting of IT (including NSS, information systems, and OT), must be acquired, operated, maintained, and disposed of consistent with NNSA mission needs and all statutory, regulatory, DOE and NNSA Directive requirements. 7. RESPONSIBILITIES. a. Director, Office of Policy and Strategic Planning (NA-1.1). (1) Develops annual IT Planning Guidance, in coordination with NA-IM to ensure alignment with the planning phases of Planning, Programming, Budgeting, and Evaluation (PPBE) process. NNSA SD 200.1 3 12-14-2023 (2) Conducts planning studies on information resources issues, including cybersecurity, as appropriate, in collaboration with NA-IM. b. Office of Cost Estimating and Program Evaluation (NA-1.3). (1) Issues the NNSA Planning, Programming, and Fiscal Guidance to include the budgetary resources for investments in IT in coordination with the Associate Administrator for Management and Budget (NA-MB). (2) Reviews cost estimates for IT-related federal and contractor procurements and assists NA-IM in determining the budget and cost estimates of IT investments, as appropriate, and ensures budget requests that include investments in IT are reviewed and approved by NA-IM prior to submission to the Office of Management and Budget (OMB). (3) Participates in reviews of IT investments governed by DOE O 413.3B, Program and Project Management for the Acquisition of Capital Assets, and provides input regarding IT projects and investments to NA-IM, as applicable. c. Associate Administrator for Information Management and Chief Information Officer (NA-IM). (1) Uses enterprise architecture to conduct information resources management strategic planning in alignment with the PPBE process to align resources to NNSA mission requirements. (2) Conducts IT portfolio management (ITPfM) to review and approve IT and information system investments, as appropriate, in accordance with the responsibilities outlined in DOE O 200.1A, and OMB Circular A-11, Preparation, Submission, and Execution of the Budget, § 55, Information Technology Investments. (3) Supports the development of policies and procedures for IT and information system investment management including project oversight, in coordination with the Associate Administrator for Partnership and

Section 3

Acquisition Services (NA-PAS). (4) Ensures that the operation, management, and use of IT and information systems complies with applicable statutes, regulations, policies, and directives to meet NNSA mission requirements, in coordination with the cognizant NNSA Contracting Officer or Contracting Officer’s Representative, as needed. (5) Develops information management policies and procedures that increases program efficiency, improves the integrity, quality, and utility of 4 NNSA SD 200.1 12-14-2023 information across NNSA, implements appropriate security and classification controls, and enables the trustworthy use of decision-making systems. (6) Establishes, maintains, and enforces the governance of IT policies and processes to enable the secure sharing of information and the performance of IT services, including information assurance, discovery, accessibility, and dissemination (including unclassified IT and information system policy releasability) requirements. (7) Develops and conducts performance measurement assessments and reviews to evaluate the use of information resources and makes recommendations, as necessary, to the Administrator. (8) Develops a comprehensive IT investment and acquisition review process in accordance with DOE O 200.1A and DOE O 413.3B, ensuring adherence to the following parameters: (a) Sits on the Energy System Acquisition Advisory Board (ESAAB) as a full member to provide guidance and gain insight into the IT and information system portions of major capital asset projects. (b) Ensures acquisitions not subject to review by the ESAAB follow the appropriate investment and procurement approval process in Attachment 2. (c) Ensures NNSA IT and information system investments are reviewed by the DOE Information Management Governance Board, as appropriate. (d) Adheres to the requirements and processes of DOE O 413.3B for IT and information system investments based on the thresholds identified in that Order. (9) Authorizes Program and Functional Offices to manage OT, as appropriate. (10) Ensures applicable mobile device management procedures are implemented in a manner per DOE O 203.2, Mobile Technology Management, to reduce risks to an acceptable level while supporting mission requirements, incorporating authorization, accountability, monitoring, training, and reporting requirements for users. (11) Establishes and chairs the NNSA IT Investment Review Board (IRB). As prescribed by DOE, reviews and approves proposed Major IT and information system investments that meet or exceed the thresholds established in Attachment 2. NNSA SD 200.1 5 12-14-2023 (12) Serves on boards, committees, and other groups pertaining to the assigned NA-IM responsibilities. Represents the Administrator on matters regarding IT resources outside of NNSA. (13) Establishes or uses existing governance bodies and processes to ensure information policies and systems, along with IT, align with NNSA objectives and do not pose any undue risk to NNSA. Entrusts the governance bodies with performing the functions of reviewing and analyzing information and IT investments, addressing issues, and elevating unresolved matters. (14) Ensures that IT investments meet the Government Performance and Results Act of 1993 (GPRA 1993) and the GPRA Modernization Act of 2010 performance goals and reporting requirements, as appropriate. (15) Develops guidance to support telework, implements new and emerging

Section 4

telework technologies for enterprise use, and develops guidelines for protecting government furnished equipment and personally owned equipment used to access NNSA information systems for purposes of telework. (16) Approves information and communications technology and services supply chain risk management practices and processes, in accordance with SD 205.1, Baseline Cybersecurity Program. (17) Develops policies for use of Internet Domains for NNSA networks. (18) Promotes the use of enterprise purchasing agreements for Commercial Off-The-Shelf IT products or capabilities to focus resources on efficient and effective supplier management, where applicable. d. Deputy Administrator for Defense Programs (NA-10). Develops and implements policies, processes, and procedures for the federal and contractor acquisition, operation, maintenance, digital assurance, and disposition of national security systems under their cognizance needed for the operations of defense programs, including, but not limited to: (1) Nuclear weapons IT involving equipment that is an integral part of a weapon or weapon system. (2) High performance computing systems (HPCs) and associated software running on HPCs that are critical to the fulfillment of the nuclear security mission. 6 NNSA SD 200.1 12-14-2023 (3) Command, control, and communications systems integral for the safe and secure transport of special nuclear materials. e. Associate Administrator for Partnership and Acquisition Services (NA-PAS). (1) Coordinates with NA-IM regarding reviews of IT and IT-related acquisition plans, strategies, cost estimates, contractual actions, memorandums of understanding, and interagency agreements that involve plan, contract, or agreement modifications or result in substantial changes to IT resources within the scope of NA-PAS’ authority. (2) Ensures procurement requests are supported by cost estimates that have been reviewed by NA-IM, or the appropriate Program Office. Ensures that NA-IM or the appropriate Program Office approves IT procurements, acquisitions, and major investments, and confirms that the acquisition strategies and plans are consistent with existing IT policies. (3) Coordinates with NA-IM and NA-MB to implement a NNSA-wide process to ensure that any procurement or acquisition that includes IT or IT-related systems, solutions, or services includes personnel with the appropriate federal acquisition certification on the integrated project team. (4) Updates program guidance, in coordination with NA-IM, to ensure programs executed under DOE O 413.3B or DOE O 415.1B, Information Technology Project Management, include NA-IM as a voting member on all Critical Decision (CD) Gate review boards, and ensures NA-IM reviews and approves IT investments within each gate review. (5) Ensures contracts or interagency agreements that include IT have NA-IM approval prior to execution or are consistent with the acquisition strategy and plan approved by NA-IM. f. Associate Administrator for Management and Budget (NA-MB). (1) Updates and issues the NNSA Planning, Programming, and Fiscal Guidance in coordination with NA-1.3, to include expenditures for investments in IT. Ensures budget requests including IT investments are reviewed and approved by NA-IM prior to submission to OMB. (2) Provides the annual IT training and workforce certification requirements. (3) Develops and implements workforce strategies and proficiency standards

Section 5

to ensure that the IT Management, Computer Engineering, Data Science, and Security Administration position personnel possess the knowledge, skills, and abilities to meet the requirements of the job category including obtaining the appropriate certifications, as relevant to the position. NNSA SD 200.1 7 12-14-2023 Coordinates with NA-IM to ensure cybersecurity workforce strategies are in alignment with the National Institute of Standards and Technology Special Publication 800-181, National Initiative for Cybersecurity Education (NICE) Workforce Framework for Cybersecurity. (4) Develops and implements procedures necessary to recruit and retain cybersecurity professionals according to OMB Memorandum (M)-16-15, Federal Cybersecurity Workforce Strategy, and the U.S. Office of Personnel Management guide, Compensation Flexibilities to Recruit and Retain Cybersecurity Professionals. g. NNSA Program/Functional Offices. (1) Plans, programs, budgets, and executes IT investments, to include the acquisition, operations, maintenance, development, and disposal of the IT, unless otherwise required by policies or procedures. (2) Reviews, approves, and reports budget requests containing information system and IT resources to NA-IM in accordance with the process outlined in Attachment 2. Program and Functional offices must: (a) Request an authorization assignment from NA-IM for the IT Investment under Program Office or Functional Office’s responsibility. ITPfM Investments attributed to a Program Office that has not requested authorization assignments will be managed by NA-IM. (b) Ensure IT investments and OT procurements align with the mission of NNSA and applicable IT and cybersecurity requirements to include appropriate network architectures and technology standards. (c) Ensure IT investments comply with Attachment 3, as appropriate. (d) Ensure reviews and assessments are performed for IT and OT procurements under their cognizance. Ensure proper reporting for IT procurements and investments. (e) Consult with the appropriate Authorizing Official (AO) regarding applicable cybersecurity requirements if the technology is expected to connect to a NNSA network or to the internet directly. Procurement expenditures that involve equipment that will be operated within, connected to a cybersecurity accreditation boundary, or will be connected to a network must be reported to the Enterprise AO. 8 NNSA SD 200.1 12-14-2023 (3) Ensures all proceedings by a Program Office IT IRB, or similar IT governance board, are sent to NNSA-OCIO-ITIRB@nnsa.doe.gov. (4) Program/Functional Offices who fund and manage OT and national security s must develop a plan, in coordination with NA-IM, that requires OT to be managed throughout its lifecycle. The plan must, at a minimum: (a) Grant programs the authority to manage OT per Program Office leadership guidance; (b) Define the scope of applicability of OT across the Federal or site program; (c) Demonstrate effective resource management by identifying performance metrics and objectives, including budget, timeline, and quality standards; (d) Define a process for the sites to report to the Field Office OT that connects to an accreditation boundary; and (e) Ensure OT complies with appropriate cybersecurity statutes and regulations. (5) Implements processes and procedures for the federal and contractor acquisition, operation, maintenance, digital assurance, and disposition of OT and national security systems under their cognizance needed to

Section 6

implement their programs. h. Critical Decision (CD) Gate Approval Authority. (1) Approve all program/project CD gates for an assigned IT investment not to exceed $25 million (M), or as authorized by NA-IM. (2) Approve new requirements that were not included in the annual supporting documentation for IT Investment budget submissions not to exceed $25M unless authorized by NA-IM. i. Field Office Manager (FOM). (1) Reviews M&O IT purchases that meet or exceed the thresholds established in Attachment 2. (2) Supports and implements IT procurements and acquisitions, investment reviews, sound resource management, program governance and oversight, portfolio management, workforce strategies, and reporting requirements. NNSA SD 200.1 9 12-14-2023 (3) Coordinates with NA-IM regarding oversight and review of the M&O- managed IT. (4) Delegates to equivalent federal personnel as needed. j. Information Technology Program/Project Manager. (1) Supports the development and refinement of IT performance metrics, strategies, and other initiatives to support OMB’s IT portfolio management reporting including data published on the Federal IT Dashboard in coordination with NA-IM. (2) Ensures IT investments are included in budget requests and includes appropriate program management and project management items necessary to properly manage IT investments. (3) Approve minor changes to planned IT procurements as long as the planned IT procurement: (a) Is not already approved (following the submission of supporting documentation and the bill of materials during the annual budget approval process); and (b) Does not exceed $1M for an individual purchase and $25M in annual IT investment costs. (4) Reviews and approves new IT investment requirements before requesting their CD Gate Approval Authority’s approval to optimize the service delivery of their IT Investment. (5) Review IT procured as part of a Strategic Partnership Project. k. NNSA Employees. (1) In addition to the responsibilities identified in DOE O 203.1, Limited Personal Use of Government Office Equipment, NNSA employees are responsible for: (a) Using government furnished technology in an appropriate manner, and in accordance with related job requirements. (b) Using personal devices (to include mobile devices) in a manner that protects DOE/NNSA data and does not compromise IT assets. (c) Refraining from using any DOE/NNSA IT system or network to intentionally search, view, or receive digital content that: 10 NNSA SD 200.1 12-14-2023 (i) is sexually explicit, sexually oriented, or sexual in nature; (ii) conducts or furthers any type of illicit or illegal activity. (d) Reporting improper or unsafe use of IT to their immediate manager. l. Contracting Officers. (1) Include the CRD, Attachment 1, in any contracts that involve the acquisition of, or modification to IT and information systems in conjunction with Program Office or Field Office. (2) Ensure the Contractor Purchasing System Approval is updated to align with the requirements of this SD. (3) Ensure, prior to award of a contract, order, or work assignment for IT products or services, that the site’s procurement: (a) Is associated with a previously approved IT investment; and (b) Has received appropriate approvals in accordance with this Directive. 8. REFERENCES. See Attachment 5. 9. CONTACT. The Office of the Associate Administrator for Information Management and Chief Information Officer at (202) 586-1729.

Section 7

BY ORDER OF THE ADMINISTRATOR: Jill Hruby Administrator Attachments: 1. Attachment 1: Contractor Requirements Document (CRD) 2. Attachment 2: Investment and Procurement Approval Process 3. Attachment 3: IT Portfolio Management (ITPfM) Budget Process 4. Attachment 4: Definitions 5. Attachment 5: References NNSA SD 200.1 Attachment 1 12-14-2023 AT1-1 ATTACHMENT 1: CONTRACTOR REQUIREMENTS DOCUMENT (CRD) NNSA SD 200.1, INFORMATION RESOURCES MANAGEMENT This CRD establishes the requirements for the National Nuclear Security Administration (NNSA) contractors who manage, operate, and have access to NNSA and Department of Energy (DOE) information systems. Contractors must comply with the requirements listed in this CRD and all applicable Attachments. Regardless of the performer of the work, contractors are responsible for complying with and incorporating the appropriate CRD requirements into subcontractor contracts at any tier, to the extent necessary, to ensure the contractors comply with the requirements. The contractors will ensure that they and their subcontractors incur only those costs that are reasonable and would be incurred by a prudent person in the conduct of a competitive business. Contractors and subcontractors are responsible for complying with any Attachment referenced in and made a part of this CRD. 1. REQUIREMENTS. Contractors must: a. Ensure that the procurement, acquisition, and management of information, information systems, and information technology (IT) complies with all applicable laws, regulations, and policies, including Office of Management and Budget (OMB) directives and guidance, the E-Government Act of 2002, the Federal Information Technology Acquisition Reform Act (FITARA), the Clinger Cohen Act (CCA), the Federal Information Security Modernization Act (FISMA), and the Department of Energy (DOE) Order (O) 200.1A, Information Technology Management. b. Ensure the procurement, acquisition, use, and management of IT, funded by, or operated for the U.S. Government, meet U.S. Government program and mission goals to promote sound resource management. c. Itemize information collection and IT in all procurements to enable the Field Office Manager (FOM), the managing Program Office, and the Office of the Associate Administrator for Information Management and Chief Information Officer (NA-IM) to review, assess, and approve the procurement or acquisition in accordance with the established dollar thresholds in Attachment 2. d. Develop applicable mobile device management procedures in a manner that cost- effectively reduces risk to an acceptable level while supporting mission requirements. The procedures must ensure: (1) Employees are appropriately trained in the use of both government furnished equipment (GFE) and personal mobile devices to access information resources; (2) Monitoring and reporting on the effectiveness of mobile device management procedures; and Attachment 1 NNSA SD 200.1 AT1-2 12-14-2023 (3) Overall accountability for mobile device use is retained. e. Develop guidance to support telework, implement new and emerging telework technologies for enterprise use, and protect IT GFE and personally owned equipment used to remotely access NNSA information systems during telework from malware, hacking, and other cybersecurity threats. f. Develop an Internet Protocol Version 6 Implementation Plan and submit the plan to DOE in accordance with OMB Memorandum (M)-21-07, Completing the

Section 8

Transition to Internet Protocol Version 6 (IPv6), and DOE O 200.1A. g. Establish a site governance board to approve IT investment proposals, ensure alignment with the NNSA Enterprise architecture, approve site IT budget expenditures, and perform IT oversight. The site governance board must approve and forward all investment proposals that meet or exceed the monetary thresholds established in Attachment 2 to the NNSA IT Investment Review Board following concurrent approvals from the Senior Acquisition Official (SAO) and FOM. h. Develop a site-specific IT portfolio management plan consistent with the guidelines established in Attachment 2. The plan must be periodically reviewed and updated to incorporate objectives established in the NNSA IT and Cyber Program Evaluation Guidance and NNSA and site-specific information resources plans. The IT portfolio management plan must: (1) Establish or identify an IT Governance Board. (2) Establish roles, responsibilities, and procedures for appropriate review and approval of IT acquisitions and procurements in accordance with the process outlined in Attachment 2. (3) Require reviews to evaluate information resources, as necessary, to ensure the objectives and implementation factors identified in the annual IT PEG are being met. (4) Report all IT requirements in accordance with OMB Circular A-11, Preparation, Submission and Execution of the Budget guidance. i. For existing contracts, the implementation timeline for this CRD is 180 days from publication if it is prior to the next contract award, renewal, or extension. For all other contracts, requirements must be implemented in accordance with the timelines established in DOE Acquisition Regulation clause 970.5204-2. 2. RESPONSIBILITIES. a. Contractors supplying information systems and IT, including IT services, to NNSA. NNSA SD 200.1 Attachment 1 12-14-2023 AT1-3 Ensures the requirements of this CRD and Attachments 2-5 are followed. b. Management and Operating (M&O) IT Investment Program/Project Managers. (1) Approves minor changes to planned IT procurements as long as the planned IT procurement: (a) Is not already approved (following the submission of supporting documentation and the bill of materials during the annual budget approval process); and (b) Does not exceed $1 million (M) for an individual purchase, or $25M in annual IT investment costs. (2) Reviews and approves new IT investment requirements prior to requesting their CD Gate Approval Authority’s approval to optimize the service delivery of their IT Investment. (3) Reviews IT procured as part of a Strategic Partnership Project (deferring to the sponsor for federal decisions, as applicable). c. M&O Chief Information Officers, Information Technology Points of Contact, or appointed delegates. (1) Reviews and approves, per the Site IT Governance Board recommendations, all contracts or other agreements for information, information systems and IT, including services where the requestor is a M&O contractor, the request is less than $25M, or the request does not fit the definition of a Major IT Investment. The review and approval of the IT investment can be delegated or assigned to a Program Manager or CD Gate Approval Authority. (2) Reviews their site’s proposed IT acquisition or procurement requirements greater than or equal to $25M or that meet the definition of a Major IT Investment and forward to their NNSA Element SAO and FOM for

Section 9

approval. (3) Ensures data for all IT and operational technology acquisitions are made available to the NNSA Element FOM. The IT acquisition must be associated with an IT investment UII. All approvals under this section must be sent to NNSA-OCIO-FITARA@nnsa.doe.gov. d. Site IT Governance Review Board, or Similar IT Governance Board. (1) Reviews all proposed investments in IT, IT contracts or other agreements that will include the procurement of IT, including acquisition for mailto:NNSA-OCIO-FITARA@nnsa.doe.gov Attachment 1 NNSA SD 200.1 AT1-4 12-14-2023 information, information systems, and IT and services for investments that are less than the monetary thresholds established in Attachment 2. When proposed investments meet or exceed the monetary thresholds established in Attachment 2, forward to NA-IM via the site’s SAO and FOM. (2) Ensures all information and IT procurements and acquisitions are reported to the NNSA FOM or designee prior to procurement or acquisition. e. Site Senior Acquisition Official or Equivalent. Reviews and validates IT procurements that meet or exceed the monetary thresholds established in Attachment 2. NNSA SD 200.1 Attachment 2 12-14-2023 AT2-1 ATTACHMENT 2: INVESTMENT AND PROCUREMENT APPROVAL Note: This Attachment applies to National Nuclear Security Administration (NNSA) federal and contractor organizations. In addition to the requirements set forth in the Contractor Requirements Document (CRD), Attachment 1, contractors and subcontractors are responsible for complying with this Attachment and must incorporate it into contracts and subcontracts that include the CRD. 1. PURPOSE. Pursuant to the authority provided to the agency Chief Information Officer (CIO) and key bureau CIOs under the Federal Information Technology Acquisition Reform Act (FITARA), NNSA Delegation Order No. NA-005.01, Department of Energy (DOE) Order (O) 200.1A, Information Technology Management, and DOE O 415.1, Change 2, Information Technology Project Management, this Attachment assigns information technology (IT) management responsibilities to NNSA Program Office Officials, Functional Office Officials, and Management and Operating (M&O) site Points of Contact, provided that the Officials confirm that all procurements are associated with an IT investment Unique Investment Identifier (UII) and are within the defined dollar thresholds. The Office of the Associate Administrator for Information Management and Chief Information Officer (NA-IM) may assign IT investment decisions to Program and Functional Offices for mission-specific IT that is not managed directly by a M&O. 2. APPLICABILITY. a. All IT acquisitions or procurements by Program Offices, Functional Offices, Field Offices, and M&O site elements (NNSA Elements), including National Security Systems (NSS) and information systems. b. All acquisitions of IT equipment by a contractor under an existing contract (e.g., other direct costs) where both: (1) The IT is used by the U.S. Government directly or used by a contractor under a contract with the U.S. Government that requires the use of the IT but does not include IT acquired by a contractor incidental to a federal contract; and (2) The equipment was not previously approved under this process. c. Operational Technology does not require IT portfolio management reporting and procurement approvals through IT Portfolio Management (ITPfM). 3. IT APPROVAL PROCESS.

Section 10

IT investment approval processes and procedures have been split into two parts: Attachment 2 NNSA SD 200.1 AT2-2 12-14-2023 a. Guidance for investments in IT; and b. Guidance for the authorization to procure those resources. NNSA Elements are expected to exercise their associated IT management responsibilities depending on the nature of the IT being procured and will need to demonstrate that they can effectively manage an IT governance mechanism, in which case they may be granted governance privileges over their IT. NNSA Elements that do not establish their own IT Investment Review Board (IRB) or a similar IT governance board must forward new IT investment proposal requests to the NNSA IT IRB at NNSA-OCIO- ITIRB@nnsa.doe.gov. 3.1. IT INVESTMENT APPROVAL DECISION PROCESS. NNSA Elements must divide their IT approvals into two categories: a. Business Justification. This category evaluates whether the investments align with NNSA’s strategy, goals, and objectives, and aligns with federal law and policy. It also evaluates the investment’s potential return on investment. b. Technical Impact. This category evaluates whether the investment is technically feasible. It also evaluates the investment’s potential impact on NNSA’s existing technology infrastructure. For each IT Investment, NNSA Elements must assign an IT Investment Program Manager (PM) to execute the development, deployment, integration, and management of day-to-day operations. The NNSA Element CIO, or delegate, must oversee all stages of the IT investment including authorizing new procurements, and any changes to the scope, budget, and schedule, to ensure the IT investment stays within the approved cost and implementation timeframe. Table 1AT2 below captures the applicable NNSA Management Framework to be used for the authorization of IT Investments. IT investments that are being acquired or procured for integration into existing ITPfM investments must manage or transition their authorities according to the investment/project value thresholds in Table 1AT2. mailto:NNSA-OCIO-ITIRB@nnsa.doe.gov mailto:NNSA-OCIO-ITIRB@nnsa.doe.gov NNSA SD 200.1 Attachment 2 12-14-2023 AT2-3 Table 1AT2. Investment and Applicable Project Management Framework Investment/Project Value Oversight Authority $0-<$1 million (M) IT IRB assigned1 $1M-<$25M IT IRB assigned $25M-<$50M Assigned by NNSA IT IRB/NA-IM $50M+ As assigned by DOE O 413.3B2 3.1.1. IT INVESTMENT APPROVALS. NNSA Elements must maintain an IT IRB or similar governance process to approve new IT investments. The NNSA Element’s IRB, or delegate, must coordinate with NA-IM for the creation of any new IT Investment in the Federal IT Dashboard. The NNSA Element’s IRB, or delegate, is responsible for assigning an approval authority (see Table 1AT2) for the development of any new IT Investments and the approval of all subsequent IT. All IT investment approvals require a memorandum indicating approval to proceed to the next phase and supporting documentation to be used by the Office of Partnership and Acquisition Services (NA-PAS) to permit the procurement. Where IT investment proposals are $25M or greater, or are designated as Major IT Investments,3 NNSA Elements must forward the IT investment business case analysis to their Senior Acquisition Official and associated federal Field Office Manager (FOM) for concurrence, and then forward the proposed investment to NA-IM for final approval prior

Section 11

to initiating any contractual actions. The NNSA Element’s IT IRB, or similar governance board, must evaluate proposed IT investments to ensure they align with organizational objectives, are achievable, and do not conflict with other organizational limits and is responsible for the oversight of ITPfM investments. The NNSA Element’s IT IRB oversight activities should include: 1 The Program Office or Site’s IRB will assign a gate authority if a Program Office or Site IRB exists. Otherwise, the NNSA IT IRB will assign the gate authority. 2 Although DOE O 413.3B is generally applied to capital projects, line-item IT Investments may be held to these requirements for similar oversight as directed by NNSA leadership. Applicability and tailoring requirements will be determined by the Critical Decision (CD) Gate Approval Authority. 3 DOE defines the criteria for a Major IT Investment as: Has a cumulative steady state or mixed lifecycle funding of $25 million or more across the past year, current year, and budget year; Is an Office of Management and Budget- directed portfolio IT investment; Is a Government-wide E-Government or Line of Business investment where DOE is a Managing Partner; Is a Multi-Agency Collaboration or Inter-Agency Shared Services investment where DOE is an Agency Lead; or Requires special management attention because of its importance to the mission or function of the Agency. Attachment 2 NNSA SD 200.1 AT2-4 12-14-2023 a. Monitoring IT investment progress by ensuring that performance measures are met. b. Ensuring the budget is fully developed. c. Ensuring the IT Investment and any sub-tier investments are aligned with the Technology Business Management Taxonomy. d. Reporting all proceedings to NA-IM at NNSA-OCIO-ITIRB@nnsa.doe.gov. New IT purchases that were not captured in the bill of materials (BOM) supporting annual budget planning may be approved by the NNSA Element’s authority within their assigned limits, which allows the ITPfM Investment PMs to approve administrative and minor changes without additional approvals. The IT Investment PM must evaluate purchases for organizational compliance and impact, including: a. Ensuring correct alignment with their ITPfM Investment and budget. b. Evaluating for possible Foreign Ownership, Control, or Influence risk. c. Suitability within the IT Operations environment/IT Service Management. d. Cybersecurity architecture and monitoring requirements. e. Records Management and Privacy. f. Compliance with other federal laws. g. Compatibility with enterprise license agreements. 3.2. IT PROCUREMENT PROCESS. Procurement approval, required by FITARA as codified in 40 U.S.C. § 11319 and implemented by NA-PAS, is principally performed by NA-IM as part of the annual budget approval process by evaluating an investment’s supporting documentation (e.g., NA-IM FITARA request form, Summary, Statement of Work, Total Cost Estimate, Request of Quotation, FOM approval), proposed BOM, and details of anticipated modernization and enhancements. NA-IM will provide a memorandum to NA-PAS at the conclusion of annual budget planning indicating which IT Investments have conformed with sufficient supporting documentation for their investment to enable NA-IM approval. IT procurements may then be approved by NA-PAS. mailto:NNSA-OCIO-ITIRB@nnsa.doe.gov NNSA SD 200.1 Attachment 2 12-14-2023 AT2-5 For procurements not previously approved through the budget submission process, where

Section 12

supporting documentation stated above exceeds the authorization assignments of the NNSA Element’s PM and/or appointed Approval Authority, and for procurements for a ITPfM Major Investment, requests must be sent to NA-IM for approval at NNSA-OCIO- FITARA@nnsa.doe.gov. Sufficient supporting documentation should be provided to help facilitate timely approval. Otherwise, a notice of procurement must be sent to the NNSA IT IRB at NNSA-OCIO-ITIRB@nnsa.doe.gov. 4. PROVISIONS. a. The installation of any hardware or software on DOE networks must not introduce additional cybersecurity risks and will be approved by the appropriate Authorizing Official before integration to the IT network. b. This Assignment must not be used to purchase IT components integral or ancillary to any project, the entirety of which has not already been approved through existing approval processes (e.g., NNSA or Element IT IRB). c. All IT procured must be associated with an IT investment UII. IT reporting must include this number to indicate the proper procurement to the CD Gate Approval Authority. 5. LIMITATIONS. a. In exercising the authority delegated in this Assignment, a delegate is governed by the rules and regulations of the policies and procedures prescribed by the Secretary of Energy or their delegate(s) and the NNSA Administrator or their delegate(s). b. Nothing in the Assignment precludes NA-IM from exercising the authority delegated by the Administrator. mailto:NNSA-OCIO-FITARA@nnsa.doe.gov mailto:NNSA-OCIO-FITARA@nnsa.doe.gov mailto:NNSA-OCIO-ITIRB@nnsa.doe.gov NNSA SD 200.1 Attachment 3 12-14-2023 AT3-1 ATTACHMENT 3: INFORMATION TECHNOLOGY PORTFOLIO MANAGEMENT (ITPfM) BUDGET PROCESS Note: This Attachment applies to National Nuclear Security Administration (NNSA) federal and contractor organizations. In addition to the requirements set forth in the Contractor Requirements Document (CRD), Attachment 1, contractors and subcontractors are responsible for complying with this Attachment and must incorporate it into contracts and subcontracts that include the CRD. 1. INTRODUCTION. The purpose of this Attachment is to describe NNSA’s Information Technology (IT) investment reporting process to the Office of Management and Budget (OMB). OMB Circular A-11, Preparation, Submission and Execution of the Budget, requires IT investments to be reported annually to OMB and made public via the Federal IT Dashboard. Figure 1, IT Portfolio Management (ITPfM) Budget Process, illustrates the NNSA Office of the Associate Administrator for Information Management and Chief Information Officer (NA-IM) process in complying with the OMB reporting requirement. Figure 1: ITPfM Budget Process 2. PROCESS. a. Requests for IT resources that require a Unique Investment Identifier (UII) that identifies where the funding will be reported in the NNSA IT Portfolio. b. IT resources currently associated with reported investments in the NNSA IT Portfolio will already have a UII to complete the procurement request. (1) The NNSA ITPfM Team will work with the responsible Point(s) of Contact (POC) to ensure that the new funding amounts are updated in the past year, current year, and budget year (BY) investment ledger tables in the ITPfM tool. Attachment 3 NNSA SD 200.1 AT3-2 12-14-2023 (2) If the associated investment is considered a Major or Standard Investment, the NNSA ITPfM Team will also include updates regarding new projects,

Section 13

risks, metrics, and artifacts, as appropriate. (3) IT resource requests originating from Management and Operating (M&O) sites will follow the M&O approval process. M&O Chief Information Officers’ (CIO) indirect spending should already have associated UIIs and be reported in the ITPfM tool. IT spending outside of the M&O CIO’s budget will need to be examined to determine whether it is being reported in other investments. M&O CIOs will work with the NNSA ITPfM Team and other NNSA Program Offices to update all investments at the M&O site. Exceptions will be processed according to the following steps. c. IT resources for programs not in compliance with ITPfM reporting requirements will not have a UII to complete the procurement request. Note that reporting requirements only pertain to IT and not operational technology. (1) The NNSA ITPfM Team will work with the responsible POC(s) to initiate an IT investment that creates a UII. (2) The NNSA ITPfM Team will provide ITPfM training to the new POC(s). (3) The responsible POC(s) will then complete the investment form prior to the next reporting deadline, as established by the OMB. (a) Draft – late August (b) Pre-decisional – September/October (c) President’s Budget/Passback (Final) – January/February (4) Incomplete IT investment paperwork cannot be entered into the ITPfM reporting process, and therefore will be excluded from the NNSA IT Investment Portfolio. d. All completed investments will be added to the NNSA IT Investment Portfolio, which the NNSA ITPfM Team uses to perform updates, data calls, IT Dashboard assessments, and account for in the annual OMB submission. e. The NNSA ITPfM team provides the IT Portfolio to the NNSA Office of Management and Budget (NA-MB), from which NA-MB will verify the accuracy of the IT Portfolio to the IT portion of the approved budget request. f. The NNSA ITPfM team collects BY IT Budget Requests and provides a high- level IT Portfolio report to the NNSA CIO for approval. Upon approval, the IT Portfolio is submitted to the Department of Energy (DOE) CIO for final review. NNSA SD 200.1 Attachment 3 12-14-2023 AT3-3 g. The NNSA IT Portfolio is submitted by the DOE ITPfM team to OMB as a part of the DOE IT Portfolio Submission Package. h. NNSA will integrate government-wide cost structures, technologies, IT resources, and solutions into NNSA ITPfM investments according to the implementation requirements established by DOE and OMB’s Technology Business Management taxonomy. NNSA SD 200.1 Attachment 4 12-14-2023 AT4-1 ATTACHMENT 4: DEFINITIONS Note: This Attachment applies to National Nuclear Security Administration (NNSA) federal and contractor organizations. In addition to the requirements set forth in the Contractor Requirements Document (CRD), Attachment 1, contractors and subcontractors are responsible for complying with this Attachment and must incorporate it into contracts and subcontracts that include the CRD. a. Critical Decision Gate Approval Authority. Reviews and approves all program critical decision gates, including emergent and new requirements, for an assigned information technology (IT) investment not to exceed $25 million (M) or as authorized by the NNSA Office of the Associate Administrator for Information Management and Chief Information Officer (NA-IM). b. Energy Systems Acquisition Advisory Board (ESAAB). Supports the Department of Energy’s (DOE) and NNSA strategic objective of achieving and maintaining excellence

Section 14

in project management. The ESAAB advises the Secretary of Energy, Chief Executive for Project Management, and Departmental Project Management Executives on enterprise-wide project management policies and assists the Chief Executive on critical decision milestones for Major System Projects and performance baseline deviation dispositions with a Total Project Cost of $750M or greater, DOE Order 413.3B Change 6 (LtdChg), Program and Project Management for the Acquisition of Capital Assets, dated 1-12-2021. c. Information. Any communication or representation of knowledge such as facts, data, or opinions in any medium or form, including textual, numerical, graphic, cartographic, narrative, or audiovisual, Committee on National Security Systems Instruction 4009, National Information Assurance Glossary, dated 4-26-2010, and National Institute of Standards and Technology Federal Information Processing Systems 199, Standards for Security Categorization of Federal Information and Information Systems, dated 2-10- 2004. d. Information and Communications Technology or Services. Any hardware, software, or other product or service primarily intended to fulfill or enable the function of information or data processing, storage, retrieval, or communication by electronic means, including transmission, storage, and display, Executive Order 13873, Securing the Information and Communications Technology and Services Supply Chain, dated 5-15-2019. e. Information Resources. Refers to information and related resources, such as personnel, equipment, funds, and information technology, 44 United States Code (U.S.C.) § 3502. f. Information System. A discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information, 44 U.S.C. § 3502. Attachment 4 NNSA SD 200.1 AT4-2 12-14-2023 g. Information Technology. With respect to an executive agency means (A) any equipment or interconnected system or subsystem of equipment, used in the automatic acquisition, storage, analysis, evaluation, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information by the executive agency, if the equipment is used by the executive agency directly or is used by a contractor under a contract with the executive agency that requires the use (i) of that equipment; or (ii) of that equipment to a significant extent in the performance of a service or the furnishing of a product; (B) includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware, and similar procedures, services (including support services), and related resources; but (C) does not include any equipment acquired by a federal contractor incidental to a federal contract, 40 U.S.C. §11101(6). h. IT Investment Review Board, or Similar Governance Board. The final decision-making body at a Program Office, Functional Office, or Management and Operating site element that is assigned responsibility to ensure investments and expenditures on IT and IT services align with the mission, vision, and needs of the organization by conducting investment and procurement decision making, ongoing oversight, and oversight of information technology acquisition and procurement.

Section 15

i. IT Investment Program Manager. An individual responsible for managing a portfolio or program comprised of one or more projects, systems, solutions, or services. Although the projects start and end, the program essentially continues indefinitely to support one or more key mission functions. Reviews and approves minor and administrative changes to planned IT procurements. j. Major IT Investment. DOE defines the criteria for a Major IT Investment as: a. Has a cumulative steady state or mixed lifecycle funding of $25 million or more across the past year, current year, and budget year; b. Is an OMB-directed portfolio IT investment; c. Is a Government-wide E-Government or Line of Business investment where DOE is a Managing Partner; d. Is a Multi-Agency Collaboration or Inter-Agency Shared Services investment where DOE is an Agency Lead; or e. Requires special management attention because of its importance to the mission or function of the Agency. k. National Security System. A telecommunications or information system operated by the Federal Government, where the function, operation, or use of which involves intelligence activities; involves cryptologic activities related to national security; involves command NNSA SD 200.1 Attachment 4 12-14-2023 AT4-3 and control of military forces; involves equipment that is an integral part of a weapon or weapons system; or, subject to 40 U.S.C. § 11103(2), is critical to the direct fulfillment of military or intelligence missions. l. Nuclear Weapons Information Technology. The information system or components of an information system integral to a nuclear weapon; surrogates for nuclear weapons used in development, test, or training; and equipment connecting to nuclear weapons or their surrogates, including war reserve units, developmental units, weapon components, test units, trainer units, and weapon operational support equipment (e.g., systems that are directly involved in operational test, configuration, security, and safety throughout the lifecycle). m. Operational Technology. Hardware and software that detects or causes a change through the direct monitoring or control of physical devices, processes, and events in the Enterprise, 15 U.S.C. § 278g-3a (6). n. Technology Business Management (TBM) Taxonomy. The TBM taxonomy is a commercial standard to describe cost sources, technologies, IT resources (towers), and solutions. The TBM taxonomy has been adopted as government-wide policy to describe technology in common terms. The current TBM taxonomy is available at www.tbmcouncil.org. http://www.tbmcouncil.org/ NNSA SD 200.1 Attachment 5 12-14-2023 AT5-1 ATTACHMENT 5: REFERENCES Note: This Attachment applies to National Nuclear Security Administration (NNSA) federal and contractor organizations. In addition to the requirements set forth in the Contractor Requirements Document (CRD), Attachment 1, contractors and subcontractors are responsible for complying with this Attachment and must incorporate it into contracts and subcontracts that include the CRD. a. Executive Order 13556, Controlled Unclassified Information, dated 11-4-2010. b. Clinger-Cohen Act of 1996, Public Law (Pub. L.) 104-106, 40 United States Code (U.S.C.) § 11101, et seq. c. Privacy Act of 1974, as amended, Pub. L. 93-579, 5 U.S.C. § 552a. d. Section 508 of the Rehabilitation Act, Pub. L. 106-246, 29 U.S.C. § 798. e. E-Government Act of 2002, Pub. L. 107-347, 44 U.S.C. §§ 3501-3531 and §§ 3551-3606.

Section 16

f. Freedom of Information Act, Pub. L. 110-175, 5 U.S.C. § 552. g. Federal Information Security Modernization Act of 2014, Pub. L. 113-283, 44 U.S.C. § 3541 et seq. h. MEGABYTE Act of 2016, Pub. L. No. 114-210, 40 U.S.C. § 11302 et seq. i. Federal Information Technology Acquisition Reform Act. Pub. L. No. 113-291, dated 12- 19-2014. j. National Defense Authorization Act for Fiscal Year 2018, Subtitle G, Modernizing Government Technology (MGT Act), Pub. L. No. 115-91, 40 U.S.C. § 11301 et seq. k. GPRA Modernization Act of 2010, Pub. L. No. 111-352, dated 1-4-2011. l. Government Performance and Results Act of 1993, Pub. L. No. 103-62, dated 8-3-1993. m. 48 Code of Federal Regulations (CFR), Federal Acquisition Regulation (FAR). n. 48 CFR, Chapter 9, Department of Energy, Subchapter H, Clauses, and Forms. o. 48 CFR, 970.5204–2, Laws, Regulations, and DOE Directives. p. 36 CFR, Chapter 12, Subchapter B, Records Management. q. 32 CFR, Part 2002, Controlled Unclassified Information. Attachment 5 NNSA SD 200.1 AT5-2 12-14-2023 r. Office of Management and Budget (OMB) Memorandum (M) 23-03, Fiscal Year 2023 Guidance on Federal Information Security and Privacy Management Requirements. s. OMB M-22-18, Enhancing the Security of the Software Supply Chain through Secure Software Development Practices. t. OMB M-22-16, Administration Cybersecurity Priorities for the FY 2024 Budget. u. OMB M 21-30, Protecting Critical Software Through Enhanced Security Measures. v. OMB M-21-07, Completing the Transition to Internet Protocol Version 6 (IPv6). w. OMB M-21-05 Extension of Data Center Optimization Initiative (DCOI). x. OMB M-19-26, Update to the Trusted Internet Connections (TIC) Initiative. y. OMB M-19-19, Update to Data Center Optimization Initiative. z. OMB M-19-18, Federal Data Strategy – A Framework for Consistency. aa. OMB M-19-15, Improving Implementation of the Information Quality Act. bb. OMB M-18-12, Implementation of the Modernizing Government Technology Act. cc. OMB M-17-06, Policies for Federal Agency Public Websites and Digital Services. dd. OMB M-16-20, Category Management Policy 16-3: Improving the Acquisition and Management of Common Information Technology: Mobile Devices and Services. ee. OMB M-16-19, Data Center Optimization Initiative. ff. OMB M-16-14, Category Management Policy 16-2: Providing Comprehensive Identity Protection Services, Identity Monitoring, and Data Breach Response. gg. OMB M-16-12, Category Management Policy 16-1: Improving the Acquisition and Management of Common Information Technology: Software Licensing. hh. OMB M-15-14, Management and Oversight of Federal Information Technology. ii. OMB M-15-13, Policy to Require Secure Connections across Federal Websites and Web Services. jj. OMB Circular A-11, Preparation, Submission and Execution of the Budget. kk. OMB Circular No. A-123, Management’s Responsibility for Enterprise Risk Management and Internal Control. NNSA SD 200.1 Attachment 5 12-14-2023 AT5-3 ll. OMB Circular A-130, Managing Federal Information as a Strategic Resource. mm. Committee on National Security Systems Instruction 4009, Committee on National Security Systems (CNSS) Glossary, dated 4-6-2015. nn. National Institute of Standards and Technology (NIST) Special Publication 800-53, Rev. 5, Assessing Security and Privacy Controls in Information Systems and Organizations. oo. NIST Federal Information Processing Systems 199, Standards for Security

Section 17

Categorization of Federal Information and Information Systems. pp. Department of Energy (DOE) Federal Information Technology Acquisition Reform Act Common Baseline Implementation Plan and Self-Assessment, dated 6-24-2016. qq. DOE Order (O) 471.7, Controlled Unclassified Information, dated 2-3-2022. rr. DOE O 413.3B Chg 6 (LtdChg), Program and Project Management for the Acquisition of Capital Assets, dated 1-12-2021. ss. DOE O 205.1C Chg 1 (LtdChg), Department of Energy Cybersecurity Program, dated 2- 3-2022. tt. DOE O 203.1, Limited Personal Use of Government Office Equipment Including Information Technology, dated 4-23-2009. uu. DOE O 203.2, Mobile Technology Management, dated 5-15-2014. vv. DOE O 200.1A (LtdChg), Information Technology Management, dated 1-13-2017. ww. DOE’s Federal Information Technology Acquisition Reform Act (FITARA) Implementation Plan, dated 5-17-2016 (v.11). xx. DOE Acquisition Guide, updated 6-20-2019. yy. NNSA Delegation Order No. NA-005.01, effective 2-11-2019. zz. NNSA Supplemental Directive (SD) 415.1A, Project Oversight for Information Technology (PO-IT), dated 4-27-2021. aaa. NNSA SD 413.3-6 Energy Systems Acquisition Advisory Board Equivalent Process, dated 3-1-2022. bbb. NNSA SD 205.1, Baseline Cybersecurity Program, dated 7-7-2017. ccc. NNSA Policy 130.1B, Planning, Programming, Budgeting, and Evaluation (PPBE) Process, dated 5-25-2021. 1. PURPOSE 2. AUTHORITY 3. CANCELLATIONS 4. APPLICABILITY a. Federal b. Contractor c. Systems d. Equivalency/Exemptions 5. BACKGROUND 6. REQUIREMENTS 7. RESPONSIBILITIES a. Director, Office of Policy and Strategic Planning (NA-1.1). b. Office of Cost Estimating and Program Evaluation (NA-1.3). c. Associate Administrator for Information Management and Chief InformationOfficer (NA-IM). d. Deputy Administrator for Defense Programs (NA-10). e. Associate Administrator for Partnership and Acquisition Services (NA-PAS). f. Associate Administrator for Management and Budget (NA-MB). g. NNSA Program/Functional Offices. h. Critical Decision (CD) Gate Approval Authority i. Field Office Manager (FOM). j. Information Technology Program/Project Manager k. NNSA Employees l. Contracting Officers 8. REFERENCES 9. CONTACT ATTACHMENT 1: CONTRACTOR REQUIREMENTS DOCUMENT (CRD) 1. REQUIREMENTS 2. RESPONSIBILITIES a. Contractors supplying information systems and IT, including IT services, toNNSA b. Management and Operating (M&O) IT Investment Program/Project Managers c. M&O Chief Information Officers, Information Technology Points of Contact, orappointed delegates. d. Site IT Governance Review Board, or Similar IT Governance Board. e. Site Senior Acquisition Official or Equivalent. ATTACHMENT 2: INVESTMENT AND PROCUREMENT APPROVAL 1. PURPOSE 2. APPLICABILITY 3. IT APPROVAL PROCESS 3.1. IT INVESTMENT APPROVAL DECISION PROCESS a. Business Justification b. Technical Impact 3.1.1. IT INVESTMENT APPROVALS. 3.2. IT PROCUREMENT PROCESS 4. PROVISIONS 5. LIMITATIONS ATTACHMENT 3: INFORMATION TECHNOLOGY PORTFOLIOMANAGEMENT (ITPfM) BUDGET PROCESS 1. INTRODUCTION. 2. PROCESS ATTACHMENT 4: DEFINITIONSNote: ATTACHMENT 5: REFERENCES

Something wrong with this record? Tell us