ML19266A395
| ML19266A395 | |
| Person / Time | |
|---|---|
| Site: | Nuclear Energy Institute |
| Issue date: | 09/18/2019 |
| From: | Gross B Nuclear Energy Institute |
| To: | Marissa Bailey Division of Security Operations |
| Hase D | |
| References | |
| NEI 18-11 | |
| Download: ML19266A395 (9) | |
Text
nei.org
© NEI 2019. All rights reserved.
NEI 18-11, Maintaining 10 CFR Part 95 Facility Clearances for Voluntary Program Participants, Revision 1 Prepared by the Nuclear Energy Institute September 2019
September 2019 nei.org
© NEI 2019. All rights reserved.
Acknowledgements This document was developed by the Nuclear Energy Institute. NEI acknowledges and appreciates the contributions of NEI members and other organizations in providing input, reviewing and commenting on the document including:
NEI Project Leads: William Gross and Hilary Lane LuAnn Bray Nebraska Public Power District Anne Cottingham Nuclear Energy Institute Margaret Earle Dominion Energy Walter Fulton STP Nuclear Operating Company Cynthia Heimbach Exelon Corporation Pat Jenny GE Hitachi Nuclear Energy Patrick Simpson Exelon Corporation Leonard Sueper Xcel Energy Timothy Tate Framatome Inc.
Michael Whitlock Dominion Energy Larry Wilson Dominion Energy Notice Neither NEI, nor any of its employees, members, supporting organizations, contractors, or consultants make any warranty, expressed or implied, or assume any legal responsibility for the accuracy or completeness of, or assume any liability for damages resulting from any use of, any information apparatus, methods, or process disclosed in this report or that such may not infringe privately owned rights.
September 2019 nei.org
© NEI 2019. All rights reserved.
Executive Summary Following the terrorist attacks in 2001, the U.S. Nuclear Regulatory Commission (NRC) invited certain facilities, including power reactors, certain fuel cycle facilities and NEI, to participate in a voluntary Facility Clearance (FCL) program that would allow access to classified information. Those licensees that agreed to participate in the voluntary program were required to obtain an FCL and personnel security clearances in accordance with the requirements in Title 10 of the Code of Federal Regulations (10 CFR)
Part 95, "Facility Security Clearance and Safeguarding of National Security Information and Restricted Data." These facilities do not possess classified information and do not require routine access to classified material. Rather, these facilities have personnel cleared for access to national security information in order to attend classified discussions, including periodic threat briefings.
NEI 18-11 is intended to provide guidance that may be used to maintain an NRC FCL issued in accordance with 10 CFR Part 95 for access to classified information granted to facilities participating in the Voluntary Security Clearance Program (VSCP).
September 2019 nei.org
© NEI 2019. All rights reserved.
Table of Contents 1
Introduction..................................................................................................................................... 1 1.1 Purpose................................................................................................................................. 1 1.2 Scope..................................................................................................................................... 1 1.3 Acronyms.............................................................................................................................. 2 1.4 References............................................................................................................................ 3 1.5 Change Summary.................................................................................................................. 3 2
Significant Events or Changes that May Affect Status Concerning FOCI......................................... 3 2.1 Changes to Ownership, Answers to the Original FOCI Questions and Indebtedness........... 4 2.2 Changes in the Required Form that Identifies Owners, Officers, Directors, and Executive Personnel......................................................................................................................................... 4 3
Key Management Personnel............................................................................................................ 4 4
Updates to Facility Clearances......................................................................................................... 5 5
Annual Certifications and Notifications........................................................................................... 5
September 2019 nei.org 1
© NEI 2019. All rights reserved.
1 INTRODUCTION 1.1 Purpose This document provides guidance that entities in the NRCs Voluntary Security Clearance Program may use to comply with 10 CFR Part 95 requirements related to maintaining an FCL. Specifically, NEI 18-11 is intended to provide a clear and uniform approach to addressing certain administrative requirements associated with maintaining an FCL. It is a further objective of this document to ensure that the facilitys Part 95 security program continues to protect national security information.
This document provides the following guidance:
Section 2, Significant Events or Changes That May Affect Status Concerning FOCI, provides approaches to meeting the Foreign Ownership, Control or Influence (FOCI), and Owners, Officers, Directors and Executive Personnel (OODEP) reporting requirements associated with the FCL.
Section 3, Key Management Personnel, describes approaches to the identification of Key Management Personnel (KMP) for both new applicants for an FCL under the VSCP and for existing VSCP participants.
Section 4, Updates to Facility Clearances, provides an approach for performing the five-year FCL update.
Section 5, Annual Certifications and Notifications, discusses annual certification and annual notification requirements.
1.2 Scope NEI 18-11 may be used by entities participating in the NRCs VSCP. This guidance is NOT intended for use by facilities that require access to classified national security information in order to perform NRC licensed activities. Please consult the NRC if you have questions regarding the applicability of this guidance to your facility.
Facilities maintaining an NRC issued FCL must comply with the requirements of 10 CFR Part 95. While NEI 18-11 does not address all FCL-related requirements in Part 95, it is intended to cover the following requirements:
Portions of 10 CFR 95.17(a)(1), Processing Facility Clearance, 10 CFR 95.18, Key Personnel, and 10 CFR 95.19(c), Changes to Security Practices and Procedures.
September 2019 nei.org 2
© NEI 2019. All rights reserved.
10 CFR Part 95 provisions related to maintaining the FCL that are not addressed in NEI 18-11 include but are not limited to:
10 CFR 95.19(a),
10 CFR 95.19(b), and 10 CFR 95.57.
In 2018, the NRC began notifying VSCP FCL holders by letter regarding 10 CFR Part 95 reporting requirements related to FOCI. In these letters the NRC informed FCL holders that, As a Cognizant Security Agency, the NRC is required to ensure that licensees receiving an FCL follow the applicable requirements in the National Industrial Security Program Operating Manual (NISPOM). The NISPOM contains additional reporting requirements beyond those in 10 CFR Part
- 95.
The letters state that the NRC expects FCL holders to comply with NISPOM [Ref. 5] reporting requirements. While NEI 18-11 specifically addresses Part 95 requirements, the guidance is consistent with and addresses corresponding NISPOM requirements related to maintaining the FCL, where applicable.
1.3 Acronyms The following acronyms, some of which are defined in 10 CFR 95.5, are used in NEI 18-11. To enhance readability for individuals familiar with FCL programs, these acronyms may not be defined on first use.
CSA - Cognizant Security Agency (the NRC is the CSA for voluntary program participants)
FCL - Facility Clearance FOCI - Foreign Ownership, Control or Influence FSO - Facility Security Officer KMP - Key Management Personnel NISPOM - National Industrial Security Program Operating Manual OODEP - Owners, Officers, Directors, and Executive Personnel PCL - Personnel Clearance SMO - Senior Management Official VSCP - Voluntary Security Clearance Program
September 2019 nei.org 3
© NEI 2019. All rights reserved.
1.4 References
- 1. 10 CFR Part 25, Access Authorization https://www.nrc.gov/reading-rm/doc-collections/cfr/part025/full-text.html
- 2. 10 CFR Part 95, Facility Security Clearance and Safeguarding of National Security Information and Restricted Data https://www.nrc.gov/reading-rm/doc-collections/cfr/part095/full-text.html
- 3. FCL Orientation Handbook, Defense Security Services, Industrial Security Field Operations https://www.dss.mil/documents/facility-clearances/FCL_Orientation_Handbook_18FEB15.pdf
- 4. Form 405F, List ALL Owners, Officers, Directors, and Executive Personnel (OODEP's), U.S. NRC https://www.nrc.gov/reading-rm/doc-collections/forms/nrc405f.pdf
- 5. National Industrial Security Program Operating Manual (NISPOM) Incorporating Change 2, May 18, 2016, Department of Defense (DoD 5220.22-M) https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodm/522022M.pdf
- 6. Standard Form 328 (SF 328), Certificate Pertaining to Foreign Interests.
Available from: https://www.gsa.gov/reference/forms 1.5 Change Summary Revision Description Revision 0 Initial document. This revision was not endorsed by the NRC.
Revision 1 Incorporates changes identified during the NRCs review of Revision 0 (see Agencywide Documents Access and Management System (ADAMS) Accession No, ML19148A541).
Notably, additional language was included to clarify that this guidance is intended for facilities in the VSCP and not for use by facilities that require access to classified national security information to conduct NRC licensed activities. Additionally, Section 2.1 and Section 3 were revised to provide additional clarity.
2 SIGNIFICANT EVENTS OR CHANGES THAT MAY AFFECT STATUS CONCERNING FOCI Section 2 provides guidance for complying with 10 CFR 95.17(a)(1) which states in part:
"The licensee, certificate holder, or other person must advise the NRC within 30 days of any significant events or changes that may affect its status concerning foreign ownership, control, or influence (e.g., changes in ownership; changes that affect the company's answers to original FOCI questions; indebtedness; and changes in the required form that identifies owners, officers, directors, and executive personnel).
September 2019 nei.org 4
© NEI 2019. All rights reserved.
2.1 Changes to Ownership, Answers to the Original FOCI Questions and Indebtedness Where a facility has implemented resolutions as a mitigation measure to exclude entities (e.g., parent companies, parent company/owner subsidiaries, subsidiary companies, boards of directors, etc.) from access to or influence over the facilitys VSCP, the licensee may meet 10 CFR 95.17(a)(1) by reporting any change to the organization that would require a review of mitigation measures, including existing board resolutions, to ensure they continue to effectively protect classified information. For example, if a nuclear power reactor is sold to another entity, the exclusion resolutions implemented may no longer be effective. This change (condition) should be reported in accordance with 10 CFR 95.17 and may be remediated by implementing new exclusion resolutions. Changes to an entity that would not challenge the effectiveness of mitigation measures, such as an increase in percentage of ownership for an already excluded entity beyond the existing threshold in SF 328 [Ref. 6], would not be considered significant for participants in the VSCP and need not be reported.
When developing exclusion resolutions, facilities may consider:
The resolution language in 10 CFR 95.18.
The example resolutions in Appendix C of the FCL Orientation Handbook [Ref. 3].
Engaging with the CSA to review draft exclusion language to ensure the resolution is sufficient to mitigate FOCI concerns.
2.2 Changes in the Required Form that Identifies Owners, Officers, Directors, and Executive Personnel Exclusion resolutions mitigate the potential for excluded entities or individuals to influence the Part 95 program. Exclusion resolutions may be used to exclude any entity or individual from access to or influence over classified information provided under the VSCP. Board resolutions are generally used to exclude members of boards of directors, owners and subsidiary companies.
As OODEPs associated with excluded entities cannot influence the Part 95 program, changes to OODEPs do not constitute significant events for facilities in the VSCP. Accordingly, changes to OODEPs associated with excluded entities need not be reported. By extension, OODEPs associated with parent entities of excluded entities, or subsidiaries of excluded entities, need not be reported. As discussed in Section 2.1, above, changes to the facility that would render the exclusion resolutions ineffective must be reported and remediated to ensure OODEPs are either excluded or reported to the CSA.
3 KEY MANAGEMENT PERSONNEL Section 3 provides guidance for complying with 10 CFR 95.18 which states in part:
The senior management official [SMO] and the Facility Security Officer [FSO] must always be cleared to a level commensurate with the Facility Clearance. Other key management officials, as determined by the CSA, must be granted an access authorization or be excluded from classified access.
September 2019 nei.org 5
© NEI 2019. All rights reserved.
For new applicants for a facility clearance under the VSCP: As per Part 95 requirements, new applicants will submit a list of owners, officers, directors, and executive personnel (NRC Form 405F [Ref. 4]) and designate the FSO and SMO for evaluation as KMP and that will be cleared to a level commensurate with the FCL.
For existing VSCP participants: Current participants may submit a notification to the NRC (facilities may use NRC Form 405F [Ref. 4]) identifying the FSO and SMO for evaluation as KMP and that will be cleared to a level commensurate with the FCL.
Excluded KMP may retain a national security clearance (PCL). When a PCL is no longer needed, the PCL should be terminated in accordance with 10 CFR 25.33, Termination of Access Authorizations.
Nuclear power plants that are organized in a fleet under a common business unit may re-evaluate the structure of their Part 95 program. The program could be structured or re-structured such that a single SMO and FSO have responsibility over a fleet program. For example, a fleet CNO may be the SMO, and an FSO in the corporate office may be identified. Cleared individuals at each station would no longer need to be identified as KMPsite-specific SMOs and/or FSOs would not be needed. Those individuals could retain their clearances as appropriate but would no longer be identified as KMP. It may be beneficial to discuss this type of change with the CSA in advance to ensure appropriate implementing protocols are followed.
4 UPDATES TO FACILITY CLEARANCES 10 CFR 95.19(c) states:
A licensee, certificate holder, or other person must update its NRC facility clearance every five years either by submitting a complete Standard Practice Procedures Plan or a certification that the existing plan is fully current to the Division of Security Operations.
This requirement may be met by submitting a letter conveying a copy of the currently effective SPPP.
Alternatively, the facility may submit a letter confirming that the most recently submitted version of the SPPP remains current.
5 ANNUAL CERTIFICATIONS AND NOTIFICATIONS 10 CFR Part 95 contains no requirements for annual certifications or annual notifications.
The NISPOM (section 2-303(a)) requires annual certifications for board resolutions implemented as a part of a FOCI action plan. The exclusion resolutions established by voluntary program participants (and discussed in Section 2, above) may not have been implemented to negate or mitigate FOCI. Accordingly, annual certification may not be necessary. Facilities may confirm the need for an annual certification with the CSA.