Bd. Min. 06-27-24; Amended Bd. Min. 11-20-24.
- Statement of Purpose
- This rule addresses The Curators of the 欧美口爆视频 of Missouri (a.k.a., the 欧美口爆视频 of Missouri 欧美口爆视频 (UM 欧美口爆视频)) compliance with U.S. industrial security policy, including applicable federal statutes, Executive Orders (E.O.), Code of Federal Regulations (CFR), Department of Defense Instructions (DoDI), and other applicable authorities. UM 欧美口爆视频 is committed to compliance for the protection of classified information disclosed to or developed by contractors of the U.S. Government (USG), employed or the responsibility of UM 欧美口爆视频 (contractors).
- This rule will be applied to achieve compliance with applicable federal authorities, including:
- E.O. 12829, National Industrial Security Program
- E.O. 10865, Safeguarding Classified Information within Industry
- 32 CFR Part 2004, National Industrial Security Program
- DoDI 5220.22, National Industrial Security Program
- 32 CFR Part 117, National Industrial Security Program Operating Manual (NISPOM)
- This rule implements policy, assigns responsibilities, and establishes requirements for the protection of classified information disclosed to, or developed by contractors across the UM 欧美口爆视频.
- Scope and Compliance Policy
- This rule applies to all cleared facilities (i.e., Facility Clearances or FCLs) within the UM 欧美口爆视频 holding a FCL, to all personnel whose personnel security clearances are held by a UM 欧美口爆视频 or subsidiary FCL, and to all personnel who hold roles related to ensuring compliance with the authorities outlined in subsection A.2 (e.g., Key Management Personnel or KMPs).
- The UM 欧美口爆视频 is the 鈥渃orporate family鈥 for all classified work taking place at any FCL within the 欧美口爆视频. Individual universities may have subsidiary Facility Clearances under the UM 欧美口爆视频 Facility Clearance if they have federal authorization to hold classified materials on-site, a secondary place-of- performance, or flow down to a sub-tier contractor.
- The UM 欧美口爆视频 shall implement a corporate-wide Insider Threat Program to address insider threats throughout the UM 欧美口爆视频.
- The President will appoint the following personnel to oversee and implement the UM 欧美口爆视频 industrial security program (ISP) (欧美口爆视频 ISP):
- Senior Management Official (SMO)
- Insider Threat Program Senior Management Official (ITPSO)
- Facility Security Officer (FSO)
- The personnel identified in subsection B.4 must:
- Oversee the implementation of the requirements of the NISPOM;
- Undergo the same security training that is required of all contractors, in addition to any position specific training;
- Be designated in writing; and
- Undergo a personnel security investigation and national security eligibility determination for access to classified information at the level of the entity鈥檚 eligibility determination for access to classified information.
- SMO: The President of the UM 欧美口爆视频 is the SMO for the UM 欧美口爆视频 FCL and for all subsidiary FCLs held by an individual university within the UM 欧美口爆视频. The SMO will:
- Ensure a system of security controls in accordance with the NISPOM;
- Appoint an UM 欧美口爆视频 ITPSO and FSO in writing;
- Remain fully informed of the UM 欧美口爆视频 ISP classified operations;
- Make decisions based on the threat reporting and information and the potential impacts to the UM 欧美口爆视频 ISP; and
- Retain accountability for the management and operations of the 欧美口爆视频鈥檚 ISP without delegating that accountability.
- ITPSO: The Director, Research Security and Compliance is the ITPSO and will be designated in writing by the SMO. The ITPSO will:
- Ensure the FSO(s) is part of the insider threat program;
- Complete training in accordance with the NISPOM; and
- Develop an insider threat program that meets the requirements of the NISPOM.
- FSO: An FSO will be appointed in writing by the SMO for any 欧美口爆视频 with an active FCL. Each FSO will:
- Supervise and direct security measures necessary for implementing the NISPOM to ensure the protection of classified information.
- Complete security training as deemed appropriate by the Cognizant Security Agency (CSA) who accredits the FCL. Both direct and reciprocity CSAs training must be met.
- Appoint an Information 欧美口爆视频 Security Manager (ISSM) if classified information will be processed on an information system at a 欧美口爆视频 with an FCL.
- ISSM: If classified information will be processed on an information system at a 欧美口爆视频 with an FCL, the FSO will appoint an ISSM. Each ISSM will:
- Be adequately trained and possess the technical competence required to operate, maintain, and secure the contractor鈥檚 classified information system; and
- Oversee development, implementation, and evaluation of the 欧美口爆视频's classified information system program.
- 欧美口爆视频 of Missouri Research Security and Compliance Team
- UM Research Security and Compliance Team
Each FCL within the UM 欧美口爆视频 will have an appointed FSO who reports to the UM 欧美口爆视频 Director of Research Security and Compliance. Each FSO shall be a member of the 欧美口爆视频 of Missouri Research Security and Compliance Team (鈥淯M RSC Team鈥). - Collaboration
Recognizing both the necessity and administrative efficiencies gained, the UM RSC Team shall work in collaboration with each other and with those also holding responsibilities for compliance with the authorities outlined in subsection A.2. to ensure that no single point of failure exists within the 欧美口爆视频. -
Accountability and Alignment
To ensure the accountability and alignment of the UM RSC Team, each Chancellor shall designate one of that 欧美口爆视频's Vice Chancellors to work with the UM 欧美口爆视频 Director for Research Security and Compliance, who will jointly approve the following as it relates to the FSO at each institution:- Recruitment and hiring decisions;
- Disciplinary and termination decisions; and,
- Annual performance evaluations and compensation decisions.
For situations in which concurrence is not reached, the collective decision will be made with the President.
- UM Research Security and Compliance Team
- Strategies
- The FSO(s) will develop the industrial security strategies for the UM 欧美口爆视频 to establish, document, and implement processes and procedures to ensure the 欧美口爆视频 remains in compliance with the authorities outlined in subsection A.2. These strategies will be brought before the UM RSC Team for approval before implementation.
- A Standard Practice Procedures (SPP) is developed and maintained by the UM RSC Team and maintained. This SPP documents the current processes and procedures used across the 欧美口爆视频. The SPP will contain information describing acceptable structures for the Security Executive Committee (SEC).
- 欧美口爆视频-specific appendices will be maintained within the SPP as needed.
- At least once annually, the Board of Curators will review and ratify a Security Resolution outlining the members of the SEC and those who are excluded from the SEC in alignment with the structure outlined in the SPP.
- Implementation
The FSOs and Insider Threat Program Senior Official on the UM RSC Team are responsible for the implementation of the industrial security programs and the Insider Threat Program for the UM 欧美口爆视频.