A METHODOLOGY FOR INTEGRATING FACILITY INSIDER PROTECTION STRATEGY INTO THE CONDITIONAL RISK EQUATION

Year
1994
Author(s)
Joseph W. James - Science Applications International Corporation
W.F. Hensley - U.S. Department of Energy
J. D. Veatch - Science Applications International Corporation
T.H. Koch - Science Applications Interntional Corp.
Abstract
Department of Energy (DOE) Order 5630.13 A calls for preparation and submission of site/facility specific Master Safeguards and Security Agreements (MSSAs) and DOE Order 5630.14A requires the completion of the Site Safeguards and Security Plans (SSSPs). The guidance for the preparation of these planning documents provides for a risk management approach when assessing safeguards and security (S&S) performance against prescribed outsider and insider threats. The methodology currently used in quantifying the performance of facility S&S systems does not adequately address the benefits derived from the existing insider protection elements. In recognition of that fact, DOE Headquarters directed (via the 5-13- 88 memorandum entitled \"Insider Threat Policy Statement\") operations offices and facilities to: (1) assess site-specific insider protection program measures, (2) assess the contribution to overall system effectiveness these elements provide against potential insider threats, and (3) take credit, as appropriate, for these program elements. However, no specific methodology was provided to assure consistent and effective evaluation. This paper presents a methodology for integrating the insider protection elements with other physical security measures when evaluating overall facility risk at DOE sites.