§117.9. Entity eligibility determination for access to classified information. — Inbound Citations
32 C.F.R. § 117.9
Statutory Authority
Cited by 5 regulations in release Current.
Citations to §117.9(a)
-
(1) Before a prime contractor may release or disclose classified information to a subcontractor, or cause classified information to be generated by a subcontractor, a determination that access to classified information will be required and such access serves a legitimate USG requirement for the performance of a “classified contract” in accordance with § 117.9(a) must be made. Prime contractors are responsible for communicating the appropriate security requirements to all subcontractors.(i) A “security requirements clause” and a “Contract Security Classification Specification,” or equivalent, will be incorporated in the solicitation and in the subcontract. (See the “security requirements clause” in the prime contract.)(ii) The subcontractor must possess an appropriate entity eligibility determination and a classified information safeguarding capability if possession of classified information will be required.(A) If access to classified information will not be required in the pre-award phase, prospective subcontractors are not required to possess an entity eligibility determination to receive or bid on the solicitation.(B) If a prospective subcontractor requires access to classified information during the pre-award phase and does not have the appropriate entity eligibility determination or a classified information safeguarding capability, the prime contractor will request the CSA of the subcontractor to initiate the necessary action.(iii) If access to classified information will not be required, the contract is not a classified contract within the meaning of this rule. If the prime contract contains requirements for release or disclosure of protected information that is not classified, such as CUI, the requirements will be incorporated in the solicitation and the subcontract and are not covered by this rule.
Citations to §117.9(c)
-
(iii) The contractor meets all other entity eligibility requirements outlined in § 117.9(c) except that KMP, other than the FSO, may be citizens of the country from which the FOCI derives and the United States has obtained security assurances at the appropriate level from that country.
Citations to §117.9(g)
-
(C) Whether they have been temporarily excluded from access to classified information pending the determination of eligibility for access to classified information in accordance with § 117.9(g).
Citations to §117.9(m)
-
(1) In exceptional circumstances, when an entity is under FOCI, the CSA may decide that a limited entity eligibility determination is appropriate when the entity is unable or unwilling to implement FOCI mitigation or negation measures, and the conditions in paragraphs (e)(1)(i) through (iii) of this section are met. This is not the same as a limited entity eligibility determination for purposes not related to FOCI. Information on limited entity eligibility determinations for purposes other than FOCI can be found in § 117.9(m). A CSA may decide that a limited entity eligibility is appropriate for an entity under FOCI if:(i) The limited entity eligibility determination is in accordance with national security interests and a GCA has informed the CSA that access to classified information by the contractor is essential to contract or agreement performance.(ii) There is an industrial security agreement with the foreign government of the country from which the FOCI is derived.(iii) The contractor meets all other entity eligibility requirements outlined in § 117.9(c) except that KMP, other than the FSO, may be citizens of the country from which the FOCI derives and the United States has obtained security assurances at the appropriate level from that country.
-
(b) Contractors will appoint security officials who are U.S. citizens, except in exceptional circumstances (see § 117.9(m) and § 117.11(e)).(i) Depending upon the size and complexity of the contractor's security operations, a single contractor employee may serve in more than one position.(ii) Undergo the same security training that is required for all other contractor employees pursuant to § 117.12, in addition to their position specific training.(iv) Undergo a personnel security investigation and national security eligibility determination for access to classified information at the level of the entity's eligibility determination for access to classified information (e.g., FCL level) and be on the KMP list for the cleared entity.(2) The SMO will:(i) Ensure the contractor maintains a system of security controls in accordance with the requirements of this rule.(ii) Appoint a contractor employee or employees, in writing, as the FSO and appoint the same employee or a different employee as the ITPSO. The SMO may appoint a single employee for both roles or may appoint one employee as the FSO and a different employee as the ITPSO.(iv) Make decisions based on classified threat reporting and their thorough knowledge, understanding, and appreciation of the threat information and the potential impacts caused by a loss of classified information.(v) Retain accountability for the management and operations of the facility without delegating that accountability to a subordinate manager.(3) The FSO will:(i) Supervise and direct security measures necessary for implementing the applicable requirements of this rule and the related USG security requirements to ensure the protection of classified information.(ii) Complete security training pursuant to § 117.12 and as deemed appropriate by the CSA.(4) The ITPSO will establish and execute an insider threat program.(i) If the appointed ITPSO is not also the FSO, the ITPSO will ensure that the FSO is an integral member of the contractor's insider threat program.(ii) The ITPSO will complete training pursuant to § 117.12.(iii) An entity family may choose to establish an entity family-wide insider threat program with one senior official appointed, in writing, to establish, and execute the program as the ITPSO. Each cleared entity using the entity-wide ITPSO must separately appoint that person as its ITPSO for that facility. The ITPSO will provide an implementation plan to the CSA for executing the insider threat program across the entity family.(5) Contractors who are, or will be, processing classified information on an information system located at the contractor facility will appoint an employee to serve as the ISSM. The ISSM must be eligible for access to classified information to the highest level of the information processed on the system(s) under their responsibility. The contractor will ensure that the ISSM is adequately trained and possesses technical competence commensurate with the complexity of the contractor's classified information system. The contractor will notify the applicable CSA if there is a change in the ISSM. The ISSM will oversee development, implementation, and evaluation of the contractor's classified information system program. ISSM responsibilities are in § 117.18.(6) Those employees whose official duties include performance of NISP-related security functions will complete security training tailored to the security functions performed. This training requirement also applies to consultants whose official duties include security functions.