10.07.2015 Views

ANNEX IV.VI.B- SAL for Lot N. 2 - European GNSS Agency - Europa

ANNEX IV.VI.B- SAL for Lot N. 2 - European GNSS Agency - Europa

ANNEX IV.VI.B- SAL for Lot N. 2 - European GNSS Agency - Europa

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>ANNEX</strong> <strong>IV</strong>.<strong>VI</strong>.B to Draft Framework ContractGSA/OP/04/2012Without Appendix X and X to Annex X to the contract XXX – NOT CLASSIFIED.SECURITY ASPECTS LETTER <strong>Lot</strong> N. 2<strong>ANNEX</strong> <strong>IV</strong>.<strong>VI</strong>.B to Draft Framework ContractGSA/OP/04/2012Participants:Page 1 of 12GSAContractorWithout Appendix X and X to Annex X to the contract XXXX – NOT CLASSIFIED.<strong>European</strong> <strong>GNSS</strong> <strong>Agency</strong>. Rue de la Loi, 56, B-1049 Brussels, Belgium. Telephone: (32-2) 297.70.76,Fax: (32-2) 292.08.72. Email:lso@gsa.europa.eu (Local Security Officer)Website: http://www.gsa.europa.eu


<strong>ANNEX</strong> <strong>IV</strong>.<strong>VI</strong>.B to Draft Framework ContractGSA/OP/04/2012Without Appendix X and X to Annex X to the contract XXXX – NOT CLASSIFIEDTable of Contents1 Introduction 32 Background 33 Classification level 44 Security Instructions <strong>for</strong> Classified In<strong>for</strong>mation 44.1 General Principles 44.2 Release of contract in<strong>for</strong>mation 64.3 Security plan in event of termination 74.4 International Visits 74.5 Reporting and maintenance of security in<strong>for</strong>mation 74.6 Transmission of sensitive and/or classified in<strong>for</strong>mation 74.7 Encryption 74.8 Transportation plans 84.9 Security violations 85 Security-related notices or communication 96 Applicable documents 97 Reference documents 98 Appendix A: List of security cleared companies 109 Appendix B: Access to the GSA's premises 1110 Appendix C: Security Classification Guide (SCG) 12Page 2 of 12GSAContractorWithout Appendix X and X to Annex X to the contract XXXX – NOT CLASSIFIED.<strong>European</strong> <strong>GNSS</strong> <strong>Agency</strong>. Rue de la Loi, 56, B-1049 Brussels, Belgium. Telephone: (32-2) 295.84.26,Fax: (32-2) 292.08.72. Email:lso@gsa.europa.eu (Local Security Officer)Website: http://www.gsa.europa.eu


<strong>ANNEX</strong> <strong>IV</strong>.<strong>VI</strong>.B to Draft Framework ContractGSA/OP/04/2012Without Appendix X and X to Annex X to the contract XXX – NOT CLASSIFIED.1 IntroductionThis document is a Security Aspects Letter (<strong>SAL</strong>) issued by the GSA as part of contract XXXX. Itdefines the security contractual conditions issued by the GSA. These conditions <strong>for</strong>m an integralpart of the contract under which classified in<strong>for</strong>mation shall be accessed or generated.This document identifies those elements of the contract which involve classified in<strong>for</strong>mation whichrequires protection and identifies the essential security requirements. This <strong>SAL</strong> applies to any legalentity involved through this contract by contractual or pre-contractual activity. A lists of securitycleared companies and sites involved in the contract are at Appendix A. For a list of securityauthorities and National Project Offices refer to AD 2 <strong>European</strong> <strong>GNSS</strong> PSI.This document includes a Security Classification Guide (SCG), distributed as appendix to this <strong>SAL</strong>,which describes the classified elements of the Contract and specifies the applicable securityclassification levels. The SGC <strong>for</strong> contract XXX is XXX (Standalone Galileo Security ClassificationGuide/supplement specific to contract XXX, Appendix X to the present <strong>SAL</strong>). The SCG may beamended throughout the life of the Contract and the elements it contains may be reclassified ordowngraded.This document is intended to provide an overview of the essential security requirements that thecontractor must implement. These security provisions which are based on the <strong>European</strong> <strong>GNSS</strong> PSIprovide additional security requirements matching a specific contract. AD 2, the <strong>European</strong> <strong>GNSS</strong>PSI shall be considered as an applicable document <strong>for</strong> the present contract providing guidance <strong>for</strong>the <strong>European</strong> <strong>GNSS</strong> programmes on the interpretation and application of the security policies foundin Commission Decision 2006/548 and more specifically in paragraph 27 which deals with theCommon Minimum Standards on Industrial Security.In situations where provisions in national legislation and regulations differ from the provisions inthis <strong>SAL</strong>, the provisions in national legislation and regulations may be applied provided that theyare not less stringent than the provisions set out in this <strong>SAL</strong>. In all such cases the contractor shallin<strong>for</strong>m the GSA of the revised security procedures.The GSA is responsible <strong>for</strong> the approval of this <strong>SAL</strong> and any future modifications.Comments or questions on the interpretation of this <strong>SAL</strong> should be directed to the GSA or to thecontractor’s NSA/DSA.2 BackgroundRegulation (EU) No 912/2010 1 article 22, states "The <strong>Agency</strong> shall apply the security principlescontained in Commission Decision 2001/844/EC, ECSC, Euratom…". The Commission's CommonMinimum Standards on Industrial Security, RD 1 Commission Decision 2006/548, paragraph 27states that all classified contracts must include a <strong>SAL</strong> and a SCG.1Regulation (EU) No 912/2010 of the <strong>European</strong> Parliament and of the Council of 22 September 2010 setting up the <strong>European</strong> <strong>GNSS</strong> <strong>Agency</strong>,repealing Council Regulation (EC) No 1321/2004 on the establishment of structures <strong>for</strong> the management of the <strong>European</strong> satellite radio navigationprogrammes and amending Regulation (EC) No 683/2008 of the <strong>European</strong> Parliament and of the Council (OJ L 276, 20.10, p 11)Page 3 of 12Without Appendix X and X to Annex X to the contract XXXX – NOT CLASSIFIED.<strong>European</strong> <strong>GNSS</strong> <strong>Agency</strong>. Rue de la Loi, 56, B-1049 Brussels, Belgium. Telephone: (32-2) 297.70.76,Fax: (32-2) 292.08.72. Email:lso@gsa.europa.eu (Local Security Officer)Website: http://www.gsa.europa.euGSAContractor


<strong>ANNEX</strong> <strong>IV</strong>.<strong>VI</strong>.B to Draft Framework ContractGSA/OP/04/2012Without Appendix X and X to Annex X to the contract XXX – NOT CLASSIFIED.3 Classification levelReferring to article 27.2 (i) of Commission Decision 2001/844 (RD 1), the overall level of securityclassification of the contract is up to (XXX) as contractor’s staff may access security areasaccredited at the level (XXX) or access or provide in<strong>for</strong>mation or material classified up to (XXX),some of them being possibly marked ‘CRYPTO’, while per<strong>for</strong>ming their tasks.4 Security Instructions <strong>for</strong> Classified In<strong>for</strong>mation4.1 General Principles- [REQ 1] The contractor and sub-contractor (if any) shall be registered in a <strong>European</strong> <strong>GNSS</strong>PSI Participant (EU Member States, Norway and Switzerland). Each contractor and sub-contractor(if any) <strong>for</strong> whom an access to the classified in<strong>for</strong>mation provided by the ESA GalileoSatprogramme is required must further be registered in a Participant of the GalileoSat PSI.The participants to the GalileoSat Programme Security Instruction are Austria, Belgium, Denmark,Finland, France, Germany, Ireland, Italy, Luxembourg, The Netherlands, Norway, Portugal, Spain,Sweden, Switzerland, and the United Kingdom.- [REQ 2] Contractor's personnel as well as subcontractors' personnel involved in work underthis Contract shall be nationals of an <strong>European</strong> <strong>GNSS</strong> PSI Participant unless otherwise agreed inadvance with the GSA, and shall hold an appropriate valid PSC <strong>for</strong> accessing EU and, nationalclassified in<strong>for</strong>mation at the level of SECRET, should the need arise to access such nationalclassified in<strong>for</strong>mation. Whenever applicable they shall also be the holder of an appropriate CRYPTOauthorisation. Whenever an access to the classified in<strong>for</strong>mation provided by the ESA GalileoSatprogramme is required, they must further be nationals of a Participant of the GalileoSat PSI.- [REQ 3] The Contractor as well as subcontractors shall provide a list of those personnel inits offer including surname, first name, date of birth and nationality (including multiplenationalities).- [REQ 4] The documents referenced in section 6, Applicable Documents, in their latestversion shall be applicable to the contractor and subcontractors and the security principles theycontain shall govern the execution of the contract. The documents referenced in section 7,Reference Documents, in their latest version are additional guidance to the applicable documents.- [REQ 5] In<strong>for</strong>mation generated by the contractor or any subcontractor which requiresclassification shall be marked using the EU security classification markings and, if needed, a doublemarking detailed in the <strong>European</strong> <strong>GNSS</strong> PSI in accordance with the SCG at Appendix X. Whenrequired a CRYPTO or CCI marking shall be added in accordance with AD 3 Galileo COMSECSecurity Instructions.- [REQ 6] When a doubt arises about the classification level of in<strong>for</strong>mation generated undercontractual activity, the contractor or subcontractor(s) involved shall ask the GSA in writing aboutthe classification level to adopt. While waiting <strong>for</strong> the reply of the GSA, the in<strong>for</strong>mation shall beclassified SECRET UE and all parties shall handle it accordingly until the GSA has decided on theactual classification level and communicated it in writing to the contractor and/or subcontractor(s).Page 4 of 12GSAContractorWithout Appendix X and X to Annex X to the contract XXXX – NOT CLASSIFIED.<strong>European</strong> <strong>GNSS</strong> <strong>Agency</strong>. Rue de la Loi, 56, B-1049 Brussels, Belgium. Telephone: (32-2) 297.70.76,Fax: (32-2) 292.08.72. Email:lso@gsa.europa.eu (Local Security Officer)Website: http://www.gsa.europa.eu


<strong>ANNEX</strong> <strong>IV</strong>.<strong>VI</strong>.B to Draft Framework ContractGSA/OP/04/2012Without Appendix X and X to Annex X to the contract XXX – NOT CLASSIFIED.- [REQ 7] The contractor shall handle and protect classified in<strong>for</strong>mation or material providedto them or generated by the contractor pursuant to this Contract in accordance with itsclassification as described in AD 2, The <strong>European</strong> <strong>GNSS</strong> PSI or, provided they are no less stringent,in accordance with national regulations.- [REQ 8] If the contractor's responsible NSA/DSA identifies a failure by the contractor toobserve the security provisions described and Regulations referred to under this <strong>SAL</strong>, it shallin<strong>for</strong>m the GSA. If this failure is of such a nature as to result in the withdrawal of the contractor'sFacility Security Clearance (FSC) to handle classified documents as necessary <strong>for</strong> the execution ofthe Contract, the GSA shall have the right to terminate the Contract with immediate effect inaccordance with the relevant provisions of the General Terms and Conditions <strong>for</strong> Contracts awardedby the GSA, without prejudice to criminal and civil proceedings against the contractor.- [REQ 9] If the responsible NSA/DSA has identified such a failure to comply with therelevant security Regulations by any subcontractor resulting in the withdrawal of thesubcontractor's FSC, the GSA shall be entitled to require the contractor to terminate the subcontractwith immediate effect, without prejudice to the GSA's right to terminate the contract withimmediate effect and/or to initiate criminal and/or civil proceedings against the subcontractor.- [REQ 10] For work per<strong>for</strong>med on the GSA's premises, the contractor and its personnel shallcomply with the security requirements as described in Appendix B: Access to the GSA's premises.- [REQ 11] For work per<strong>for</strong>med on other locations than the GSA and the contractor’spremises, the contractor and its personnel shall comply with the local safety and security rulesprovided they are not less stringent than those of AD 2, the <strong>European</strong> <strong>GNSS</strong> PSI.- [REQ 12] The contractor shall not transmit any classified in<strong>for</strong>mation or material to asubcontractor without the prior written consent of the originator and the GSA.- [REQ 13] The ultimate responsibility <strong>for</strong> protecting classified in<strong>for</strong>mation within industrial orother entities rests with the management of those entities.- [REQ 14] It may be necessary <strong>for</strong> the contractor to negotiate classified subcontracts withsubcontractors at various levels. The contractor is responsible <strong>for</strong> ensuring that all subcontractingactivities are undertaken in accordance with the common minimum standards contained in this<strong>SAL</strong>. The procedures <strong>for</strong> subcontracting in AD 2, The <strong>European</strong> <strong>GNSS</strong> PSI will be applied to allpotential subcontracts.- [REQ 15] A Security Classification Guide (SCG) shall also be a part of each classifiedsubcontract, describing the specific elements which are classified and specifying the applicablesecurity classification levels.The provisions of both the <strong>SAL</strong> and SCG shall not be less stringent that the ones applicable to theprime contactor.- [REQ 16] Classified in<strong>for</strong>mation released to the contractor or subcontractor or generatedunder contractual activity shall not be used <strong>for</strong> purposes other than those defined by the classifiedcontract and shall not be disclosed to third parties without the prior written consent of theoriginator and of the GSA.Page 5 of 12GSAContractorWithout Appendix X and X to Annex X to the contract XXXX – NOT CLASSIFIED.<strong>European</strong> <strong>GNSS</strong> <strong>Agency</strong>. Rue de la Loi, 56, B-1049 Brussels, Belgium. Telephone: (32-2) 297.70.76,Fax: (32-2) 292.08.72. Email:lso@gsa.europa.eu (Local Security Officer)Website: http://www.gsa.europa.eu


<strong>ANNEX</strong> <strong>IV</strong>.<strong>VI</strong>.B to Draft Framework ContractGSA/OP/04/2012Without Appendix X and X to Annex X to the contract XXX – NOT CLASSIFIED.- [REQ 17] All industrial or other entities participating in classified contracts which involveaccess to in<strong>for</strong>mation classified CONFIDENTIEL UE or above shall hold a FSC. The FSC is granted bythe NSA/DSA of the participating State in which it is located to confirm that a facility can af<strong>for</strong>dand guarantee adequate security protection of classified in<strong>for</strong>mation to the appropriateclassification level. Questions regarding FSC’s should be addressed to the participant's NSA/DSA,details of which can be found in AD 2, the <strong>European</strong> <strong>GNSS</strong> PSI.- [REQ 18] If changes to the security requirements emerge during the per<strong>for</strong>mance of thecontract and if such changes significantly deviate from the initial arrangements, the contract shallbe amended accordingly or terminated, as appropriate.- [REQ 19] Where changes of security requirements result in additional security measures tobe taken or investments to be made by the contractor, a contract amendment shall be negotiatedon a fair and reasonable basis.- [REQ 20] In case the contractor cannot comply with increased security requirements, thecontract shall be terminated. However, any contract termination resulting from changes of thesecurity requirements shall not be by default the responsibility of the contractor, and thecontractor may be entitled to compensation by the GSA.- [REQ 21] The NSA/DSA of the participant in which the contractor is registered shall bein<strong>for</strong>med by the contractor and by the GSA Security Department separately of the award of aclassified contract.- [REQ 22] When a classified contract or a classified subcontract is terminated, the contractorand the GSA Security Department shall notify separately this termination in less than one month tothe NSA/DSA of the participants in which the contractor and subcontractors are registered.- [REQ 23] Throughout the life of the classified contract, compliance with all its securityprovisions shall be monitored by the GSA, in conjunction with the relevant NSA/DSA. Any securityincidents shall be reported, in accordance with the provisions laid down in the <strong>European</strong> <strong>GNSS</strong> PSI.Any change to or withdrawal of an FSC shall immediately be communicated to the GSA SecurityDepartment.- [REQ 24] The contractor shall - under penalty of termination of the contract - comply withany security requirements prescribed by the Contracting Authority as detailed in this SecurityAspects Letter.4.2 Release of contract in<strong>for</strong>mationThe unilateral release of classified in<strong>for</strong>mation or material used by or issued from the Contract toother than <strong>SAL</strong> participants' authorities and contractors is prohibited without the specific writtenapproval of the originator of the in<strong>for</strong>mation and the GSA. Requests <strong>for</strong> release shall be handled inaccordance with the procedures outlined in AD 2, The <strong>European</strong> <strong>GNSS</strong> PSI.The fact that any in<strong>for</strong>mation related to the Contract is not marked with a security classificationdoes not mean that it can be released to the public. Any release of in<strong>for</strong>mation requires the writtenauthorisation of the originator and the GSA and shall be done according to the provisions of thissection.Page 6 of 12GSAContractorWithout Appendix X and X to Annex X to the contract XXXX – NOT CLASSIFIED.<strong>European</strong> <strong>GNSS</strong> <strong>Agency</strong>. Rue de la Loi, 56, B-1049 Brussels, Belgium. Telephone: (32-2) 297.70.76,Fax: (32-2) 292.08.72. Email:lso@gsa.europa.eu (Local Security Officer)Website: http://www.gsa.europa.eu


<strong>ANNEX</strong> <strong>IV</strong>.<strong>VI</strong>.B to Draft Framework ContractGSA/OP/04/2012Without Appendix X and X to Annex X to the contract XXX – NOT CLASSIFIED.4.3 Security plan in event of terminationIn the event of the contract being terminated by either party, the procedures described in AD 2,The <strong>European</strong> <strong>GNSS</strong> PSI <strong>for</strong> the disposal of classified in<strong>for</strong>mation shall be implemented.4.4 International VisitsProcedures <strong>for</strong> international visits contained in AD 2, The <strong>European</strong> <strong>GNSS</strong> PSI shall be applied to allvisits necessary in the per<strong>for</strong>mance of this contract.The contractor and subcontractor if any are invited to make maximum use of recurrent andcollective Requests For Visit (RFV’s) when appropriate.4.5 Reporting and maintenance of security in<strong>for</strong>mation- [REQ 25] The contractor shall describe its security organisation in its bid and provide as wellthe details of the Contract Manager and the company Security Officer 2 .- [REQ 26] The details of the Contract Manager and the company Security Officer will bepublished in the <strong>European</strong> <strong>GNSS</strong> PSI on behalf of the GSA.- [REQ 27] Any subsequent changes shall be communicated in writing to the GSA usingNSA/DSA’s channels within 30 days of their occurrence.4.6 Transmission of sensitive and/or classified in<strong>for</strong>mation- [REQ 28] The procedures <strong>for</strong> transmission of classified in<strong>for</strong>mation contained in AD 2, The<strong>European</strong> <strong>GNSS</strong> PSI shall be applied to any transmission of classified in<strong>for</strong>mation as a result ofcontractual activities.- [REQ 29] In addition to the prescriptions of AD 2, The <strong>European</strong> <strong>GNSS</strong> PSI, classifiedin<strong>for</strong>mation, whenever stored on a digital media <strong>for</strong> transmission and whatever its classificationlevel, will be encrypted.- [REQ 30] Any sensitive in<strong>for</strong>mation related to the contract execution will preferably beencrypted be<strong>for</strong>e transmission.- [REQ 31] Details of transmission arrangements of classified in<strong>for</strong>mation at the levelCONFIDENTIEL UE or above are considered as sensitive and shall be encrypted when sent by e-mail.4.7 Encryption2The main function of Local Security Officer is to monitor the correct implementation of security rules applicable to its organisation. In particular,he/she ensures a proper handling, processing, storage and destruction of national or EU classified in<strong>for</strong>mation in line with applicable national or EUlegislation. It means that this classified in<strong>for</strong>mation has to be handled, processed, stored and destroyed in a facility to which a Facility SecurityClearance (FSC) has been delivered by the National Security Authority (NSA) of the Member State on the territory of which the company isestablished. He/she is also ensuring that access to this classified in<strong>for</strong>mation is only authorised to persons with demonstrated need to know and withvalid Personnel Security Clearance (PSC) certificate delivered by the National Security Authority.Page 7 of 12Without Appendix X and X to Annex X to the contract XXXX – NOT CLASSIFIED.<strong>European</strong> <strong>GNSS</strong> <strong>Agency</strong>. Rue de la Loi, 56, B-1049 Brussels, Belgium. Telephone: (32-2) 297.70.76,Fax: (32-2) 292.08.72. Email:lso@gsa.europa.eu (Local Security Officer)Website: http://www.gsa.europa.euGSAContractor


<strong>ANNEX</strong> <strong>IV</strong>.<strong>VI</strong>.B to Draft Framework ContractGSA/OP/04/2012Without Appendix X and X to Annex X to the contract XXX – NOT CLASSIFIED.- [REQ 32] Unless otherwise agreed in writing, the tool ‘Chiasmus <strong>for</strong> Windows’ developed bythe BSI shall be used <strong>for</strong> encryption- [REQ 33] The Contractor shall ensure they are licensed by the BSI to use the tool.BSI’s details:Bundesamt für Sicherheit in der In<strong>for</strong>mationstechnik (BSI)Refereat Z5 / VertriebPostfach 20 03 6353133 BonnGERMANYPhone: +49 228 9582 281 or 212Fax: +49 228 9582 4430E-mail: vertrieb@bsi.bund.de- [REQ 34] All parties involved in contractual activities shall handle the encryption tool andthe generated encrypted documents in accordance with the Security Operating Procedures(SecOPS) of the Authority providing the encryption tool or, provided they are not less stringent, inaccordance with national regulations.4.8 Transportation plans- [REQ 35] In addition to the requirements of AD 2, The <strong>European</strong> <strong>GNSS</strong> PSI and AD 3,Galileo COMSEC Security Instructions regarding transportation, the Contractor shall submit atransportation plan <strong>for</strong> any shipment of CCI and/or CRYPTO in<strong>for</strong>mation or material even when theshipment occurs only within one country.- [REQ 36] In addition to the submission of the transportation plan to the appropriate NSA’sor DSA’s, the Contractor shall send at the same time a copy of the plan to the GSA <strong>for</strong> in<strong>for</strong>mation.- [REQ 37] For shipments within one country, the submission of the transportation plan to theNSA/DSA shall be in accordance with national rules but, in any case, a plan shall be establishedand sent to the GSA at least 48 hours prior to the shipment.- [REQ 38] Transportation plans within the framework of this contract are considered sensitiveand shall be encrypted when sent by e-mail or transmitted on a digital media. They shall beclassified as appropriate.4.9 Security violations- [REQ 39] Security violations shall be handled as prescribed in in AD 2, The <strong>European</strong> <strong>GNSS</strong>PSI.- [REQ 40] Reports of security violations shall be sent to the GSA too.- [REQ 41] Reports of security violations shall be classified as appropriate and transmittedaccordingly. Should the classification of the report be higher than RESTREINT UE (or equivalent), asanitized report allowing a classification at the level RESTREINT UE of lower shall be established inorder to allow a quick transmission of it using appropriate channels and tools.Page 8 of 12GSAContractorWithout Appendix X and X to Annex X to the contract XXXX – NOT CLASSIFIED.<strong>European</strong> <strong>GNSS</strong> <strong>Agency</strong>. Rue de la Loi, 56, B-1049 Brussels, Belgium. Telephone: (32-2) 297.70.76,Fax: (32-2) 292.08.72. Email:lso@gsa.europa.eu (Local Security Officer)Website: http://www.gsa.europa.eu


<strong>ANNEX</strong> <strong>IV</strong>.<strong>VI</strong>.B to Draft Framework ContractGSA/OP/04/2012Without Appendix X and X to Annex X to the contract XXX – NOT CLASSIFIED.5 Security-related notices or communicationAny security-related notices or communication to the GSA shall be addressed to"<strong>European</strong> <strong>GNSS</strong> <strong>Agency</strong> (GSA),Security Department <strong>for</strong> the attention of the Local Security Officer,Rue de la Loi 56,B-1049 BrusselsBelgiume-mail: lso@gsa.europa.eu,fax-mail: fax-security@gsa.europa.eu,fax phone number: +32 2 292 08 72.Telephone: +32 2 29 740766 Applicable documentsAD 1 Regulation (EU) No 912/2010 of the <strong>European</strong> Parliament and of the Council of 22September 2010 setting up the <strong>European</strong> <strong>GNSS</strong> <strong>Agency</strong>, repealing Council Regulation (EC)No 1321/2004 on the establishment of structures <strong>for</strong> the management of the <strong>European</strong>satellite radio navigation programmes and amending Regulation (EC) No 683/2008 of the<strong>European</strong> Parliament and of the Council (OJ L 276, 20.10, p 11)AD 2AD 3AD 4AD 5The <strong>European</strong> <strong>GNSS</strong> PSI issued by the <strong>GNSS</strong> Security Board (<strong>GNSS</strong> SB); current version:Issue 2.0 Rev 1 dated 21.02.2011Galileo COMSEC Security Instructions issue 3.0, 28 June 2007 (RESTRICTED) (currentlyunder review)Galileo Stand alone Security Classification guide v2.1, 12 June 2008 (RESTREINT UE)Decision No 1104/2011/EU of the <strong>European</strong> Parliament and of the Council of 25 October2011 on the rules <strong>for</strong> access to the Public Regulated Service provided by the GlobalNavigation Satellite System established under the Galileo programme (OJ L 287,4.11.2011)7 Reference documentsRD 1Commission Decision 2001/844/EC, ECSC, Euratom published in OJ L 317 of 3.12.2001 aslast amended by Commission Decision 2006/548/EC, Euratom published in OJ L 215 p.38of 5.8.2006, amending its internal Rules of Procedure (COMMISSION PRO<strong>VI</strong>SIONS ONSECURITY)Amendments to Commission Decision 2001/844/EC, ECSC, EuratomCommission Decision 2005/94/EC, Euratom, of 3 February 2005 published in OJ L 31 of4.2.2005 amending Decision 2001/844/EC, ECSC, EuratomCommission Decision 2006/70/EC, Euratom, of 31 January 2006 published in OJ L 34 of7.2.2006 amending Decision 2001/844/EC, ECSC, EuratomPage 9 of 12GSAContractorWithout Appendix X and X to Annex X to the contract XXXX – NOT CLASSIFIED.<strong>European</strong> <strong>GNSS</strong> <strong>Agency</strong>. Rue de la Loi, 56, B-1049 Brussels, Belgium. Telephone: (32-2) 297.70.76,Fax: (32-2) 292.08.72. Email:lso@gsa.europa.eu (Local Security Officer)Website: http://www.gsa.europa.eu


<strong>ANNEX</strong> <strong>IV</strong>.<strong>VI</strong>.B to Draft Framework ContractGSA/OP/04/2012Without Appendix X and X to Annex X to the contract XXX – NOT CLASSIFIED.Commission Decision 2006/548/EC, Euratom, of 2 August 2006 published in OJ L 215 of5.8.2006 amending Decision 2001/844/EC, ECSC, EuratomRD 2 User Segment Classification Guide, GSA-595211 V1.0, 18 January 2012 RESTREINT UE8 Appendix A: List of security cleared companiesTo be completed after contract awardingCountryCompanyNameAddressSecurity Officer(Name, Tel, Fax, E-Mail)Project Leader(Name, Tel, Fax,E-Mail)Page 10 of 12GSAContractorWithout Appendix X and X to Annex X to the contract XXXX – NOT CLASSIFIED.<strong>European</strong> <strong>GNSS</strong> <strong>Agency</strong>. Rue de la Loi, 56, B-1049 Brussels, Belgium. Telephone: (32-2) 297.70.76,Fax: (32-2) 292.08.72. Email:lso@gsa.europa.eu (Local Security Officer)Website: http://www.gsa.europa.eu


<strong>ANNEX</strong> <strong>IV</strong>.<strong>VI</strong>.B to Draft Framework ContractGSA/OP/04/2012Without Appendix X and X to Annex X to the contract XXX – NOT CLASSIFIED.9 Appendix B: Access to the GSA's premises1. Contractors or subcontractors and their personnel shall comply with the GSA's internalsecurity and safety rules and Regulations and shall follow any instructions given by the GSA'sSecurity Department. They will be briefed accordingly by the GSA Local Security Officer. They shallgrant their full co-operation to prevent and report any (security) incident.2. Any failure to comply with the GSA's security or safety instructions may result in access tothe premises being denied or the personnel being expelled from the GSA premises.3. Unless otherwise agreed with the GSA, contractor or subcontractor personnel per<strong>for</strong>mingwork on the GSA's premises, except attendance at meetings with the GSA representatives, shallhold the nationality of an EU Member State and shall hold a security clearance at SECRET UE levelissued by the contractor's or subcontractor's responsible national security authority.4. The GSA may temporarily authorise, on a case-by-case basis, contractor or subcontractorpersonnel to per<strong>for</strong>m work on its premises <strong>for</strong> whom initial security checks have revealed noadverse in<strong>for</strong>mation and the security clearance procedure has been initiated or is still in progress.5. Any in<strong>for</strong>mation or material provided to the contractor's or subcontractor's personnel shall betreated as if supplied officially by the GSA.6. The contractor shall notify the GSA's Security Department at least 5 working days in advanceof any visit with the names, dates of birth and nationalities together with a certification of theindividual's security clearance and where appropriate the details of vehicles, <strong>for</strong> all contractor orsubcontractor personnel temporary per<strong>for</strong>ming work on the GSA's premises using the procedurelaid down in paragraph 4.4 of the <strong>SAL</strong>.7. The GSA shall be entitled to refuse access to its premises to any contractor or subcontractorpersonnel without giving justification, as deemed necessary <strong>for</strong> security reasons.Page 11 of 12GSAContractorWithout Appendix X and X to Annex X to the contract XXXX – NOT CLASSIFIED.<strong>European</strong> <strong>GNSS</strong> <strong>Agency</strong>. Rue de la Loi, 56, B-1049 Brussels, Belgium. Telephone: (32-2) 297.70.76,Fax: (32-2) 292.08.72. Email:lso@gsa.europa.eu (Local Security Officer)Website: http://www.gsa.europa.eu


<strong>ANNEX</strong> <strong>IV</strong>.<strong>VI</strong>.B to Draft Framework ContractGSA/OP/04/2012Without Appendix X and X to Annex X to the contract XXX – NOT CLASSIFIED.10 Appendix C: Security Classification Guide (SCG)1. The Security Classification Guide (SCG), <strong>for</strong> contract XXX is threefold: it is composed by AD 4,Standalone Galileo Security Classification Guide, Appendix X to this <strong>SAL</strong>, by RD 2, User SegmentSecurity Classification Guide, and of the supplement specific to contract XXXX, Appendix XX tothis <strong>SAL</strong>. The SCG may be amended throughout the life of the Contract and the elements itcontains may be reclassified or downgraded.2. All the parts of the SCG are provided as separate appendixesPage 12 of 12GSAContractorWithout Appendix X and X to Annex X to the contract XXXX – NOT CLASSIFIED.<strong>European</strong> <strong>GNSS</strong> <strong>Agency</strong>. Rue de la Loi, 56, B-1049 Brussels, Belgium. Telephone: (32-2) 297.70.76,Fax: (32-2) 292.08.72. Email:lso@gsa.europa.eu (Local Security Officer)Website: http://www.gsa.europa.eu

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!