Current

SD 452.4-1, Nuclear Enterprise Assurance (NEA)

To support implementation of Department of Energy (DOE) Order (0) 452.1, Nuclear Explosive and Weapon Surety (NEWS) Program, and DOE O 452.4, Security and Use Control of Nuclear Explosives and Nuclear Weapons. Consistent with the parent directive requirements, Nuclear Enterprise Assurance (NEA) is a Nuclear Security Enterprise (NSE) countersubversion program established to prevent, detect, and/or mitigate potential consequences of subversion of nuclear weapons (NW s) and NW enabling capabilities, including Deliberate Unauthorized Acts (DUAs), that may lead to Denial of Authorized Use (DAU) or degradation of NW reliability or performance.
SD_452.4-1.pdf765.90KB

Attachment 4 of NAP 401.1, Weapon Quality Policy has been cancelled by this directive. 

Document text

Text extracted from the attached file. Refer to the original document for the authoritative version.

Section 1

SUPPLEMENTAL DIRECTIVE NNSA SD 452.4-1 Approved: 01-27-22 Certification Due: 10-29-29 NUCLEAR ENTERPRISE ASSURANCE (NEA) '41\SM � I -: National Nuclear Security Administration NATIONAL NUCLEAR SECURITY ADMINISTRATION Office of Defense Programs CONTROLLED DOCUMENT AVAILABLE ONLINE AT: http:/ /directives.nnsa.doe.gov OFFICE OF PRIMARY INTEREST (OPI): Office of Stockpile Production Integration printed copies are uncontrolled THIS PAGE INTENTIONALLY LEFT BLANK NNSA SD 452.4-1 01-27-22 NUCLEAR ENTERPRISE ASSURANCE (NEA) I I. PURPOSE. To support implementation ofDepattment of Energy (DOE) Order (0) 452.1, Nuclear Explosive and Weapon Surety (NEWS) Program, and DOE O 452.4, Security and Use Control of Nuclear Explosives and Nuclear Weapons. Consistent with the parent directive requirements, Nuclear Enterprise Assurance (NEA) is a Nuclear Security Enterprise (NSE) countersubversion program established to prevent, detect, and/or mitigate potential consequences of subversion of nuclear weapons (NW s) and NW­ enabling capabilities, including Deliberate Unauthorized Acts (DUAs), that may lead to Denial of Authorized Use (DAU) or degradation of NW reliability or performance. Credible existing and emerging threats and technological advancements are evaluated, and controls and measures are implemented by federal and contractor NSE organizations, to manage NBA-related risks and provide assurance that NW s, NW-enabling capabilities, and NW crosscutting functions and programs, have not been subvetted throughout the NW lifecycle. The primary objectives of this SD include: a. Establishing concise NEA requirements to ensure consistent and coordinated NSE-wide federal and Management and Operating (M&O) contractor application ofNEA to: (!) NW programs throughout the NW lifecycle (new development, sustainment, modernization, and retirement); (2) NW-enabling capabilities, which include the infrastructure (facilities, utilities, and workforce), processes, equipment, materials and tools that provide the NSE the ability to ensure reliability and perfotmance of the NW Stockpile throughout its lifecycle, including those needed to support procurement, management, research and development (R&D), design, production, testing, surveillance, maintenance, transport, dismantlement, and disposition ofNWs or NW components; and (3) NW crosscutting functions and programs implemented across the NSE to suppott NW programs and enabling capabilities, such as supply chain risk management (SCRM), cybersecurity, information security, verification and acceptance, information management, logistics, physical security, and quality assurance. b. Expanding upon the roles and responsibilities of the Nuclear Enterprise Assurance Steering Group (NEASG) that was instituted by DOE O 452.4 to provide leadership for NEA activities; and c. Establishing the NEA Integration Wodcing Group (NIWG) as the principal M&O entity for developing, integrating, and coordinating NEA initiatives and activities across the NSE, including specifying the NIWG roles, responsibilities, and functions. 2 NNSA SD 452.4-1 01-27-22 2. AUTHORITY. This SD augments and aligns with DOE O 452.4, Security and Use Control of Nuclear Explosives and Nuclear Weapons, and DOE O 452.1, Nuclear Explosive and Weapon Surety (NEWS) Program. 3. CANCELLATIONS. a. NNSA Policy (NAP-401.1 ), Weapon Quality Policy, Attachment 4, Nuclear Enterprise Assurance (NEA), dated November 24, 2015.

Section 2

b. Memorandum, Donald Cook to NSE, Nuclear Ente1prise Assurance Program Guidance, 08-4-14. c. Memorandum, William S. Goodrnm to NSE, Nuclear Enterprise Assurance Guidance, 10-21-14. Cancellation of a directive does not, by itself, modify or otherwise affect any contractual obligation to comply with the directive listed above. Contractor Requirements Documents (CRDs) that have been incorporated into a contract remain in effect throughout the tenn of the contract until the contract or regulatory commitment is modified to either eliminate outdated requirements or substitute new requirements. 4. APPLICABILITY. a. Federal. This SD applies to all NNSA Federal organizations responsible for maintaining and enhancing the safety, reliability, and performance of the United States (U.S.) NW stockpile, including the ability to design, produce, and test NWs in order to meet national security requirements. b. Contractors. The Contractor Requirements Document (CRD), provided as Attachment 1, sets fmth requirements that apply to the M&O contractors. The CRD must be included in the contracts ofNSE M&O contractors that support the NNSA mission to maintain and enhance the safety, reliability, and perfmmance of the U.S. NW stockpile, including the ability to design, produce, and test NWs in order to meet national security requirements. c. Eguivalencies/Exemptions. (I) Equivalency. In accordance with the responsibilities and authorities assigned by Executive Order 12344, codified at 50 United States Code, sections 2406 and 2511, and to ensure consistency throughout the joint Navy/DOE Naval Nuclear Propulsion Program, the Deputy Administrator for Naval Reactors (Director) will implement and oversee requirements and practices pertaining to this Directive for activities under the Director's cognizance, as deemed appropriate. (2) Exemption. None. 5. SUMMARY OF CHANGES. Not applicable NNSA SD 452.4-1 01-27-22 6. BACKGROUND. 3 The world threat environment is continuously changing, requiring the NSE national laboratories and production facilities to respond accordingly. Government agencies have mobilized under a variety of national-level directives to protect critical security elements against a broad spectmm of adversarial threats. The U.S. Government is concerned about the globalization of today's NW supply chains, especially when coupled with increasingly sophisticated adversaries. Additional areas of concern include global development and sourcing of microelectronics and software, as well as the supply chains of other NW-related materials or products that could be maliciously altered. The increasing complexity of NW inf01mation technology presents challenges for organizations to assure the safety, reliability, and security of those technologies, due to their vulnerability to subversion, corruption, denial of service, and other cyberattacks. It is recognized that defensive measures must reflect an appreciation for the rapidly evolving, persistent, and aggressive approaches an adversary may employ in order to affect the NSE mission. NEA is the NSE program established to prevent, detect, and/or mitigate potential consequences of subversion, including DUA that may lead to DAU or degradation of weapon reliability or performance. NEA is intended to reduce the risk of subversion by advanced persistent threats and other adversaries that possess the expertise and resources that enable them to create and exploit subversion opp01tunities. NEA includes the systematic identification, assessment, and mitigation of subversion risks, based on analysis of vulnerabilities and adversarial threats, to provide assurance that NW s, NW­ enabling capabilities, and NW crosscutting functions and programs are not subverted or compromised throughout the NW lifecycle.

Section 3

7. REQUIREMENTS. When reviewing the following federal requirements, it is important to acknowledge, that in the context ofDOE/NNSA Directives/Policies, "prevent" and "ensure" imply an absolute assurance, which cannot be guaranteed. The objective is to evaluate credible existing and emerging threats and technological advancements and implement controls and measures to prevent, detect, and mitigate the consequences of subversion. This enables management ofNEA-related risks and provides reasonable assurance that the NW stockpile, enabling capabilities, and crosscutting functions and programs, including NSE supply chains, have not been subverted and that the NW stockpile is protected against DUA that may lead to DAU or loss of NW reliability or performance. a. NNSA must ensure NWs, NW-enabling capabilities and NW crosscutting functions and programs are secured from subversion throughout the NW lifecycle. b. NNSA must establish and implement oversight and monitoring/measuring of NEA assurance. c. Enterprise-wide policies and procedures must be developed and executed to ensure NEA implementation by federal organizations and M&O contractors 4 NNSA SD 452.4-1 01-27-22 throughout the NW lifecycle, including NW-enabling capabilities and crosscutting functions and programs, to include the following: (1) Common documented methodologies for implementing digital assurance processes; (2) Common documented methodologies for implementing NW system assurance processes; and (3) An NEA risk management methodology that: (a) Assesses threats, vulnerabilities, and consequences from credible existing and emerging adversarial subversion; (b) Identifies potential controls and measures to prevent, detect, and mitigate the consequences of subversion; and ( c) Is integrated with NNSA Defense Programs (DP) risk management processes and protocols to infonn decisions regarding NBA-related risks. d. NNSA must evaluate, prioritize, and oversee the implementation ofNEA controls and measures identified throughout the NW lifecycle by the M&O contractors for NWs, NW-enabling capabilities, and NW crosscutting functions and programs. e. Processes, controls, and measures must be established and implemented to protect against adversarial subversion within NSE supply chains. f. NW design must be innovated to enhance resiliency against threats and vulnerabilities to provide increased system assurance. g. NEA R&D activities must be conducted to develop and mature new methods, techniques, tools, and expertise to prevent, detect, and mitigate the effects of subversion. h. NBA-related risks must be evaluated, and controls and measures implemented, when designing, building, operating, or modifying NSE facilities for NW­ enabling capabilities. 1. An NEA Steering Group (NEASG) must be fo1med and implemented, consistent with DOE O 452.4, to perform the following functions: (1) Make NBA-related decisions and recommendations to sustain NEA implementation and drive uniformity and consistency within DP; (2) Work with other governmental entities, including the Department of Defense (DOD), to promote collaboration across acquisition; research, development, test, and evaluation (RDT &E); production, NNSA SD 452.4-1 01-27-22 operation; and sustainment efforts to facilitate effective planning, coordination and execution ofNEA capabilities, protections, and investments across the NSE throughout the NW lifecycle;

Section 4

(3) Promote coordination and sharing of info1mation between DOE, NNSA, DOD, and the necessary subject matter experts in order to enhance threat identification, supplier evaluation, and risk management ofNEA-related issues; and ( 4) Integrate and coordinate NEA activities across the NSE and address critical, high-priority NEA topics and areas, through the NIWG. J. An integrated approach to NEA activities must be established, including the capability to respond to enterprise-wide and site-level NEA issues. 5 k. NNSA must obtain intelligence and counterintelligence support for NEA activities from the DOE Office of Intelligence and Counterintelligence (DOE-IN), consistent with DOE O 452.4, to fulfill the requirements of this SD. I. Evidentiary infmmation must be required to demonstrate that NEA implementation is continually evaluated, managed, and documented throughout the NW lifecycle. m. NNSA must collaborate with the NIWG. n. NNSA must develop NEA training standards and ensure that con-esponding NEA training is developed and delivered to the NSE workforce to enable effective execution ofNEA requirements. 8. RESPONSIBILITIES. a. Assistant Deputy Administrator for Stockpile Management (ADASM/NA-12) In addition to the NEA responsibilities in DOE O 452.1 and DOE O 452.4, the ADASM is responsible for: (1) Ensming that DP NEA processes are developed, maintained, and managed to implement the requirements of this SD; and (2) Accepting NBA-related risks on behalf of the Deputy Administrator for Defense Programs throughout the NW lifecycle, e.g., sustainment of stockpile systems and stockpile modernization (life extension programs (LEPs), Alterations (Alts), and Modifications (Mods), unless othe1wise delegated. 6 b. C. NNSA SD 452.4-1 01-27-22 Office of Research, Development, Test, and Evaluation (RDT &E/NA-11) In addition to the NEA responsibilities in DOE O 452.1 and DOE O 452.4, the Office of RDT &E is responsible for: (1) Promoting development of innovative technologies for detecting, testing, analyzing, and protecting against vulnerabilities associated with adversarial subversion; and (2) Supporting expanded development ofNEA resources, including technology maturation, vulnerability analysis tools, and evidence-based practices. Office of Stockpile Production Integration (NA-121) In addition to the NEA responsibilities in DOE O 452.4, the Office of Stockpile Production Integration is responsible for: (I) Establishing, maintaining, and supporting the DOE/NNSA Directives that govern NEA implementation; (2) Developing, maintaining, and managing DP NEA processes to implement the requirements of this SD; (3) Monitoring and evaluating NNSA and M&O contractor perfo1mance of NEA requirements, in collaboration with the NNSA Field/Production Offices (F/POs); ( 4) Providing communications and information to the NEASG, as requested, and serving as the secretariat for the NEASG; (5) Establishing and implementing a response capability for enterprise-wide and site-level NEA issues; (6) Developing NEA standards and processes for NSE-wide NEA awareness, training, and skills development; (7) Collaborating with the NIWG, including providing communications, information, and other support; (8) Serving as the NEA federal integrator in collaboration with the NSE sites, the DOD, and other stakeholders; and (9) Coordinating with DOE-IN, as needed, to support NEA Program needs. NNSA SD 452.4-1 01-27-22 7 d. Federal Program Managers (FPMs)

Section 5

This SD applies to FPMs responsible for managing NW programs; NW-enabling capabilities; and NW crosscutting functions and programs, throughout the NW lifecycle. (1) FPMsfor the NW-enabling capabilities and NW crosscutting fimctions and programs are responsible for: (a) Evaluating NEA threats and vulnerabilities for their respective programs/projects/facilities against credible existing and emerging adversarial subversion. (b) Identifying NBA-related risks and implementing controls and measures to prevent, detect, and mitigate the effects of subversion. (2) FPMs for NW programs ( e.g., active stockpile, LEPs, Alts, Mods, new development, etc.) are responsible for: (a) Integrating innovated NEA concepts/components into the NW design{new and modified NWs). (b) Leveraging the NEA controls and measures being applied in the NW-enabling capabilities and crosscutting functions and programs, and evaluating their respective project/program in order to: l Evaluate NW threats and vulnerabilities to identify risks from credible existing and emerging adversarial subversion; ::?, Determine if the controls and measures being applied in the NW-enabling capabilities and crosscutting functions and programs provide adequate assurance that their respective NW program is secure from subversion; and .:1 Implement additional NEA controls and measures, as appropriate. ( c) Integrating and managing NEA subversion risks and associated controls and measures within their respective project/program risk management process( es). (3) Additionally, all FPMs are responsible for: (a) Including NEA requirements in program budgets and contracts; (b) Managing NEA-related risks for their respective program, capability or function throughout the NW lifecycle, including 8 NNSA SD 452.4-1 01-27-22 implementing NEA controls and measures to protect the NWs, NW-enabling capabilities and NW crosscutting functions and programs from subversion; ( c) Collaborating/partnering with other FPMs when there are common or overlapping NBA-related risks; ( d) Supporting implementation of innovative technologies for detecting, testing, analyzing, and protecting against vulnerabilities associated with adversarial subversion; where feasible; and (e) Accepting project/program NBA-related risks, if delegated from theADASM. e. Field/Production Office (F/PO) Contracting Officers (COs) Incorporate this SD into the "List of Applicable Directives" identified in the "Laws, Regulations, and DOE Directives" clause of the M&O contracts for NSE M&O Contractors that perfmm work in support of the NNSA mission to maintain and enhance the safety, reliability, and perfmmance of the U.S. NW stockpile, including the ability to design, produce, and test NW s in order to meet national security requirements. f. NEA Steering Group (NEASG) The NEASG is a review and decision-making body, instituted by DOE O 452.4, consisting of senior DOE and NNSA officials who provide leadership and promote successful execution ofNEA. As established by DOE O 452.4, the NEASG is overseen by the ADASM and consists of senior members from DOB­ IN, the NNSA Office of Defense Nuclear Security (NA-70), the NNSA Office of Information Management and Chiefinfmmation Officer (NA-IM), as well as the NNSA Defense Programs Associate Deputy Administrators. Other NEASG members can be added at the discretion of the ADASM. The NEASG is responsible for: (1) Decision-making for NBA-related initiatives or issues requiring unifmmity or consistency across the NSE;

Section 6

(2) Facilitating collaboration across acquisition, RDT &E, operation, and sustainment efforts to enable effective planning, coordination, and execution ofNEA capabilities and investments across the DOE/NNSA, DOD and, to the extent possible, with other U.S. Government partners; (3) Promoting coordination and sharing of information between DOE, NNSA, DOD, and the necessary subject matter experts in order to NNSA SD 452.4-1 DRAFT 10-26-21 enhance threat identification, supplier evaluation, and risk management ofNEA-related issues; and ( 4) Resolving conflicts between NNSA organizations at the appropriate management level. 9. DEFINITIONS. See Attachment 2. 10. ACRONYMS/ABBREVIATIONS. See Attachment 3. 11. REFERENCES. a. 50 U.S. Code 2401, Section 3202, The National Nuclear Security Administration Act. b. DOE O 452.lE, Nuclear Explosive and Weapon Surety Program, dated 01-26-15 c. DOE O 452.4C, Security and Use Control of Nuclear Explosives and Nuclear Weapons, dated 08-28-15. d. NAP 401.1, Weapon Quality Policy, Attachment 4, (Nuclear Enterprise Assurance), dated 11-24-15. 9 e. NAP 476.1, Atomic Energy Act Control of Import and Export Activities, dated 02- 09-15. f. NNSA Redelegation Order No. NA-005.01-01, dated 03-25-19 12. CONTACT. DOE/NNSA Nuclear Enterprise Assurance Division, NA-121.4, (505) 845-5750 BY ORDER OF THE ADMINISTRATOR: Attachments: 1. Contractor Requirements Document (CRD) 2. Definitions 3. Acronyms/ Abbreviations Jill Hruby Administrator THIS PAGE INTENTIONALLY LEFT BLANK NNSA SD 452.4-1 01-27-22 Attachment I ATl-1 ATTACHMENT 1: CONTRACTOR REQUIREMENTS DOCUMENT This Management and Operating (M&O) Contractor Requirements Document (CRD) establishes Nuclear Enterprise Assurance (NEA) requirements for M&O contractors within Nuclear Security Enterprise (NSE) sites or facilities that suppmt the National Nuclear Security Administration (NNSA) mission to maintain and enhance the safety, reliability, and performance of the U.S. Nuclear Weapon (NW) stockpile, including the ability to design, produce, and test NWs in order to meet national security requirements. The NSE M&O contractors with Supplemental Directive (SD) 452.4-1 on their contract are responsible for complying with the requirements of this CRD and for flowing down the requirements of this CRD to subcontractors, at any tier, to the extent necessary to ensure compliance with the requirements. When reviewing the following requirements, it is important to aclmowledge that in the context of DOE/NNSA Directives/Policies, "prevent" and "ensure" imply an absolute assurance, which cannot be guaranteed. The objective is to evaluate credible existing and emerging threats and technological advancements and implement controls and measures to prevent, detect, and mitigate the consequences of subversion in order to manage NEA-related risks and provide reasonable assurance that the NW stockpile, NW-enabling capabilities, and NW crosscutting functions and programs, are protected against Deliberate Unauthorized Acts (DUA) that may lead to Denial of Authorized Use (DAU) or loss of weapon reliability and/or performance. 1. REQUIREMENTS. a. M&O contractors must develop and implement common documented NSE methodologies that address the applicable elements needed to protect NWs, NW­ enabling capabilities, and NW crosscutting functions and programs, to include: (1) NEA digital assurance processes; (2) NW system assurance processes; and (3) Management ofNEA-related risks, including:

Section 7

(a) Evaluating risks from credible existing and emerging threats and technological advancements; (b) Identifying potential controls and measures to prevent, detect, and mitigate the consequences of subversion; and ( c) Integrating NEA-related risks with NSE risk management processes to inform NNSA NEA risk handling decisions. b. M&O contractors must establish self-governance processes and implement line management accountability for ensuring the implementation of this CRD at their respective sites, including their respective subcontractors. Attachment 1 ATl-2 C. d. e. f. g. NNSA SD 452.4-1 01-27-22 M&O contractors must innovate NW design to increase resiliency against adversarial subversion threats and provide increased system assurance. M&O contractors must establish and implement processes, controls, and measures to protect against adversarial subversion within the NSE supply chains. M&O contractors must develop and mature new technologies and capabilities for preventing, detecting, and minimizing the impacts of adversarial subversion. M&O contractors must evaluate NEA risk and implement controls and measures when designing, building, operating, or modifying NW-enabling capabilities. M&O contractors must support NEA Integration Working Group (NIWG) activities, including: (!) Appointing senior-level lmowledgeable personnel with decision-making authority to participate in the NIWG; (2) Providing NEA recommendations and guidance to NNSA; (3) Addressing critical, high-priority NEA topics/areas; ( 4) Integrating and coordinating NEA activities, controls, and measures across theNSE; (5) Facilitating communication ofNEA information, including best practices; and (6) Performing routine reviews ofNEA implementation activities at the NSE sites to identify best practices and areas for improvement. h. M&O contractors must develop NEA-related training that implements the NNSA­ developed NEA training standards, and train appropriate personnel, consistent with their respective NEA responsibilities. 1. M&O contractors must establish and document a process for NEA records management that complies with DOE Order (0) 243.1, Records Management Program. J. M&O contractors must coordinate, develop, and implement strategies for collaborating with NNSA, DOE Office ofintelligence and Counterintelligence (DOE-IN), and the intelligence community ( e.g., counterintelligence and the field intelligence element) to conduct NEA analyses related to NWs and NW-enabling capability requirements at their respective sites, consistent with DOE O 452.4C. k. M&O contractors must establish and implement processes for NSE-wide collaboration and infmmation sharing to facilitate threat identification, supplier vetting, and risk management ofNEA-related issues. NNSA SD 452.4-1 01-27-22 Attachment 1 ATI-3 I. M&O contractors must conduct NEA vulnerability assessments that consider credible existing and emerging threats and technological advancements to manage NEA protections/controls for NWs, NW-enabling capabilities, and NW crosscutting functions and programs. m. M&O contractors must document NEA controls and measures for NWs that leverage the vulnerability assessments of the NW-enabling capabilities and NW crosscutting functions and programs. n. M&O contractors must provide evidentiary info1mation to demonstrate that NEA implementation is continually evaluated, measured, managed, and documented throughout the NW lifecycle.

Section 8

o. M&O contractors must provide NEA support and personnel resources to the NSE Product Realization Process to ensure implementation ofNEA during the NW lifecycle, including the NW-enabling capabilities and NW crosscutting functions and programs. p. M&O contractors must implement a process to manage potential NBA-related anomalies and non-conf01mances with the consideration that the non­ conformance may have been the result of an intentional adversarial action, ensuring appropriate classification requirements and controls are used while evaluating and analyzing nonconforming conditions. q. M&O contractors must supp01t the NNSA-directed response capability to respond to enterprise and site-wide NEA issues, consistent with NNSA funding and resources. NNSA SD 452.4-1 01-27-22 ATTACHMENT 2: DEFINITIONS Attachment 2 AT2-1 Note: This attachment applies to NNSA federal and M&O contractor personnel. 1. Digital Assurance. Practices, measures, and/or controls applied to digital technologies that implement functions within a nuclear weapon (NW), or NW design, production, or test capability, in order to ensure functional, performance, and security-related requirements are met while protecting against potential compromise or subversion of these same systems from internal or external sources. Examples of digital technologies include software/fomware, processors, memory devices, application­ specific integrated circuits, field programmable gate airnys, digital systems on a chip, communication interfaces, communication buses, and transmission systems, etc. 2. Measures. The total spectrum of characteristics, devices, equipment, procedures, and administrative processes used to: a. Ensure timely authorized use only when directed by national authority, and b. Increase the difficulty of, or add to the delay in, achieving the deliberate unauthorized use of a nuclear explosive. 3. Nuclear Enterprise Assurance (NEA). A Nuclear Security Enterprise (NSE) countersubversion program established to prevent, detect, and/or mitigate potential consequences of subversion of NW s or the enabling capabilities throughout the NW lifecycle, including Deliberate Unauthorized Acts (DUA) that may lead to Denial of Authorized Use (DAU) and/or degradation of weapon reliability or performance. 4. Nuclear Ente1prise Assurance (NEA) Integration Working Group (NIWG). A collection of Management and Operating (M&O) contractor experts and leadership representing each of the NSE sites, that is responsible for providing NEA recommendations and guidance to NNSA, responding to NEA issues and challenges across the Nuclear Security Enterprise, integrating NEA activities, facilitating communication ofNEA best practices and information, and collaborating with a variety of organizations and groups (e.g., intelligence, counterintelligence, security, technical communities, and NNSA customers) in supp01t of protecting the nation's NW stockpile from subversion by adversarial threats. 5. Nuclear Enterprise Assurance Steering Group (NEASG). A review and decision-making body consisting of senior federal officials from NNSA and DOE Headquarters who provide leadership regarding NEA activities, including facilitating collaboration with the Department of Defense (DOD). 6. Nuclear Weapon (NW) crosscutting functions and programs. Functions and programs implemented across the NSE to enable and support NW capabilities, that use controls and measures to detect, prevent, and/or minimize the effects of subversion in supp01t ofNEA, such as supply chain risk management (SCRM), cybersecurity, information security, verification and acceptance, inf01mation management, logistics, physical security, and quality assurance.

Section 9

Attachment 2 AT2-2 NNSA SD 452.4-1 01-27-22 7. Nuclear Weapon (NW)-enabling capabilities. The infrastrncture (facilities, utilities, and workforce), processes, equipment, materials, and tools that provide the NSE the ability to ensure reliability and performance of the NW Stockpile throughout its lifecycle, including those needed to support procurement, management, research and development (R&D), design, production, testing, surveillance, maintenance, transpmi, dismantlement, and disposition ofNWs or NW components. 8. System Assurance. The justified confidence that the system functions as intended and is free of exploitable vulnerabilities, either intentionally or unintentionally designed or inserted as part of the system at any time during the lifecycle. (Source: NATO. 2010. Engineering for system assurance in NATO programs. DOD 5220.22M-NISPOM­ NATO-AEP-67. Febrnary 2010) NNSA SD 452.4-1 01-27-22 Attachment 3 AT3-1 ATTACHMENT 3: ACRONYMS/ABBREVIATIONS a. ADASM Assistant Deputy Administrator for Stockpile Management b. AEP Allied Engineering Procedure C. Alt Alteration d. CRD Contractor Requirements Document e. DAU Denial of Authorized Use f. DOE Department of Energy g. DP Defense Programs h. DUA Deliberate Unauthorized Act I. F/PO Field/Production Office J. FPM Federal Program Manager k. LEP Life Extension Program 1. M&O Management and Operating m. Mod Modification n. NA NNSA Office Designation 0. NAP NNSAPolicy p. NATO N mih Atlantic Treaty Organization q. NEA Nuclear Enterprise Assurance r. NEASG Nuclear Enterprise Assurance Steering Group s. NISPOM National Industrial Security Program Operating Manual t. NIWG NEA Integration Working Group u. NNSA National Nuclear Security Administration V. NSE Nuclear Security Enterprise Attachment 3 AT3-2 w. X. y. z. aa. NW R&D RDT&E SCRM SD Nuclear Weapon Research and Development Research, Development, Test, and Evaluation Supply Chain Risk Management Supplemental Directive NNSA SD 452.4-1 01-27-22 I. PURPOSE. 2. AUTHORITY. 3. CANCELLATIONS. 4. APPLICABILITY. 5. SUMMARY OF CHANGES. 6. BACKGROUND. 7. REQUIREMENTS. 8. RESPONSIBILITIES. a. Assistant Deputy Administrator for Stockpile Management (ADASM/NA-12) b. Office of Research, Development, Test, and Evaluation (RDT &E/NA-11) c. Office of Stockpile Production Integration (NA-121) d. Federal Program Managers (FPMs) e. Field/Production Office (F/PO) Contracting Officers (COs) f. NEA Steering Group (NEASG) 9. DEFINITIONS. 10. ACRONYMS/ABBREVIATIONS. 11. REFERENCES. 12. CONTACT. ATTACHMENT 1: CONTRACTOR REQUIREMENTS DOCUMENT 1. REQUIREMENTS. ATTACHMENT 2: DEFINITIONS ATTACHMENT 3: ACRONYMS/ABBREVIATIONS

Something wrong with this record? Tell us