09 Draft DD254 (Preliminary Apvl) -SEPS IDIQ.pdf
PDF 179 KB Posted
- Attached to
- SOF Enterprise Professional Services (SEPS) Federal contract opportunity
- Solicitation number
- H9240022R0008
- Issued by
- United States Special Operations Command
About this file
This document is a Draft DD254 security classification specification for the SOF Enterprise Professional Services (SEPS) contract. The SEPS contract will replace the expiring SWMS-C contract and provide special operations forces enterprise professional services from May 2022 through May 2027. The DD254 specifies that classified information up to the SECRET level is required to perform the contract and will be safeguarded at contractor and subcontractor facilities with TOP SECRET storage capabilities. Proposals for the SEPS contract are due to United States Special Operations Command by January 25, 2022 in response to solicitation H9240022R0008. The DD254 identifies SOF-related locations and government activities that will require access to classified information and outlines security guidance and additional requirements for protecting classified material.
View the file
Other files for this federal contract opportunity
Show all 35
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Please wait...
If this message is not eventually replaced by the proper contents of the document, your PDF viewer may not be able to display this type of document.
You can upgrade to the latest version of Adobe Reader for Windows®, Mac, or Linux® by visiting http://www.adobe.com/go/reader_download.
For more assistance with Adobe Reader visit http://www.adobe.com/go/acrreader.
Windows is either a registered trademark or a trademark of Microsoft Corporation in the United States and/or other countries. Mac is a trademark of Apple Inc., registered in the United States and other countries. Linux is the registered trademark of Linus Torvalds in the U.S. and other countries.
DRAFT
SAMPLE
PREVIOUS EDITION IS OBSOLETE.
Page of
DD FORM 254, MAY 2019
NEEDS DD67
DEPARTMENT OF DEFENSE
CONTRACT SECURITY CLASSIFICATION SPECIFICATION
(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)
OMB No. 0704-0567 OMB approval expires:
20220531 The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.
RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.
1. CLEARANCE AND SAFEGUARDING
2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)
3. THIS SPECIFICATION IS: (X and complete as applicable.)
a. ORIGINAL (Complete date in all cases.)
b. REVISED (Supersedes all previous specifications.)
4. IS THIS A FOLLOW-ON CONTRACT?
If yes, complete the following:
Classified material received or generated under
5. IS THIS A FINAL DD FORM 254?
If yes, complete the following:
6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)
7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor)
8. ACTUAL PERFORMANCE (Click button to add more locations.)
10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)
e. NATIONAL INTELLIGENCE INFORMATION:
11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)
12. PUBLIC RELEASE
Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)
13. SECURITY GUIDANCE
The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.
(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)
14. ADDITIONAL SECURITY REQUIREMENTS
Requirements, in addition to NISPOM requirements for classified information, are established for this contract.
If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)
15. INSPECTIONS
Elements of this contract are outside the inspection responsibility of the CSO.
If Yes, explain and identify specific areas and government activity responsible for inspections. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)
16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)
17. CERTIFICATION AND SIGNATURES
Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below. Upon digitally signing Item 17h, no changes can be made as the form will be locked.
18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL
9.0.0.2.20120627.2.874785 DD 254, DoD Contract Security Classification Specification whs.mc-alex.esd.mbx.formswebmaster@mail.mil
WHS
List of Attachments (All Files Must be Attached Prior to Signing, i.e., for any digital signature on the form)
| CurrentPage: |
| PageCount: |
| Classification: Unclassified |
| SerialNum: |
| a. Facility clearance level. Select one.: 1 |
| b. Level of safeguarding for classified information/material required at contractor facility. Select one.: 4 |
| Choose Yes or No: 1 |
| Choose Yes or No: 1 |
| Prime: H92400-22-R-0008 |
| Choose Yes or No: 0 |
| Choose Yes or No: 0 |
| Sub: SEE ITEM 13 |
| Choose Yes or No: 0 |
| Choose Yes or No: 0 |
| Soli: |
| DueDate: |
| dateA: 2021-12-16 |
| RevisionNum: |
| dateB: |
| Final: |
| dateC: |
| No: 1 |
| No: 1 |
| No: 0 |
| No: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 1 |
| Yes: 1 |
| Enter your name here.: |
| ReqDated: |
| Enter your name here.: |
| Name: TBD |
| Name: SEE ITEM 13 |
| Name: Fredette, John T. |
| Cage: TBD |
| Cage: N/A |
| Cage: N/A |
| CSO: TBD |
| CSO: HQ USSOCOM/SOCS-Z-SM |
7701 Tampa Point Blvd MacDill AFB, FL 33621 813-826-4333 IndustrialSecurity@socom.mil
| addrow: |
| Removerow: |
| Click to delete a row: |
| Location: USSOCOM |
7701 Tampa Point Blvd MacDill AFB, FL 33621 Block9: Special Operations Forces Enterprise Professional Services (SEPS) will be the replacement for the SWMS-C contract which expires next year.
Period of Performance: 17 May 2022 - 16 May 2027 (BIENNIAL DD FORM 254 REVIEW REQUIRED - SEE ITEM 13)
THIS DD FORM 254 IS TENTATIVELY APPROVED. Upon company selection, but prior to award and any classified release, this DD Form 254 with all pertinent information inserted in appropriate sections will be submitted to U.S. Special Operations Command Industrial Security for final review and approval.
| a: 0 |
| a: 1 |
| a: 1 |
| f: 0 |
| f: 0 |
| f: 1 |
| b: 0 |
| b: 0 |
| b: 0 |
| g: 0 |
| g: 0 |
| c: 0 |
| c: 0 |
| c: 1 |
| h: 0 |
| h: 0 |
| d: 0 |
| d: 0 |
| d: 0 |
| i: 0 |
| i: 0 |
| SCI: 0 |
| NonSCI: 0 |
| j: 1 |
| j: 0 |
| k: 1 |
| k: 0 |
| Enter your name here.: SEE ITEM 13 |
| Enter your name here.: SEE ITEM 13 |
| Enter your name here.: HQ USSOCOM SMO |
| e: 0 |
| e: 1 |
| l: 1 |
| m: 1 |
| direct: 0 |
| thru: 1 |
| Enter your name here.: SEE ITEM 13 |
| PublicAuthority: |
| AddSig: |
| RemoveSig: |
| text: The Contracting Officer’s Representative/Program Manager will provide a copy of all applicable security directives for this contract. Appropriate applicable HQ USSOCOM security directives, regulations, and standard operating procedures will be provided by the requiring agency (normally through the Performance Monitor or Component/Theater Special Operations Command COR/PM). Upon completion or termination of the classified contract, or sooner when the purpose of the release has been served, the contractor will return all classified information (furnished or generated) to the source from which received unless retention or other disposition instructions are authorized in writing by the USSOCOM Government Contracting Agency/Activity. Furthermore, the contractor will account for and return all Common Access Cards (CACs) to Contracting Officer's Representative, Program Manager, or Trusted Agent upon completion or termination of the classified contract, termination of employment, or suspension of classified clearance or access of any contractor employee. Security badges, installation entry passes/vehicle decals issued to contractor personnel will be returned to the appropriate issuing office as required. |
Ref 2b: Subcontracting/Flow-Down of this effort requires a Subcontract DD FM 254. Subcontract DD FM 254 must be approved by HQ USSOCOM prior to award. Forward requests and draft Subcontract DD FM 254s to the Contracting Officer’s Representative/Program Manager and USSOCOM Industrial Security (IndustrialSecurity@socom.mil). IAW USSOCOM R 380-9, Industrial Security, please allow 10 duty days for review/approval.
Ref 2b. Subcontractors with performance at HQ USSOCOM. Forward subcontractor Visit Requests to HQ USSOCOM Personnel Security (PERSEC) via DISS SMO Code MA3DF8X94. Visit Requests must not be submitted to HQ USSOCOM until the Subcontract DD FM 254 is approved. Failure to follow this guidance will result in the cancellation of the Visit Request
Ref 7: See guidance in Ref 2b.
Ref 9: Unless DD FORM 254 revision is required due to change in the security requirements of the effort or there is a change in the contractor’s Facility Clearance (FCL) status, the responsible Contracting Officer’s Representative/Program Manager (COR/PM) must conduct a review of the DD FORM 254 and associated Individual Work Plan, Performance Work Statement/Statement of Objectives/Statement of Work every 24 MONTHS (BIENNIALLY) in order to validate and/or update the requirements of the effort as required by DoDM 5220.22-V2, National Industrial Security Program: Industrial Security Procedures for Government Activities. Documentation of review (email is sufficient) should be forwarded to HQ USSOCOM Industrial Security via NIPRNet at IndustrialSecurity@socom.mil.
Ref 10j: Controlled Unclassified Information (CUI) provided under this contract shall be safeguarded as specified in the CUI Addendum included with this specification.
Ref 10k: NIPRNET/SIPRNET access required at government facilities only.
Ref 11a: Contractor performance is restricted to HQ USSOCOM, MacDill AFB, FL, unless otherwise specified in the TO. Government agency or activity will provide security classification guidance for performance of this contract. Submit visit request to COR and/or Security Management Office for need-to-know verification.
Ref 11l: Controlled Unclassified Information (CUI) provided under this contract shall be safeguarded as specified in the CUI Addendum included with this specification.
Ref 11m: Access to all USSOCOM facilities requires contractors to possess a minimum of a SECRET clearance.
Ref 11n: Contractor will be authorized to courier classified information up to the SECRET level in performance of official duties upon approval of and designation by the COR, PM and/or Security Manager.
Ref 12: Requests must be forwarded through the responsible Contracting Officer’s Representative/Program Manager, Contracting Official (Item 16) and the HQ USSOCOM Special Operations Communication Office (SOCS-SOCO) at Public.Affairs@socom.mil, (813) 826-4600, prior to public release.
PROTECTING “CONTROLLED UNCLASSIFIED INFORMATION” (CUI)
CUI Addendum (Updated March 2021)
1. GENERAL:
a. Controlled Unclassified Information (CUI) is not a security classification, but designates unclassified information that requires any safeguarding or dissemination control per DoD Instruction 5200.48, “Controlled Unclassified Information” (6 March 2020).
b. With the implementation of DoDI 5200.48, DoDM 5200.01, Volume 4, “DoD Information Security Program: Controlled Unclassified Information” (24 February 2012, as amended), has been cancelled and “For Official Use Only” (FOUO) and is no longer authorized. All new documents shall be marked in accordance with the guidance below.
c. In order to balance the need to safeguard CUI with the public interest the CUI Registry, established by DoDI 5200.48, lists categories of CUI Basic/Specified and identifies basis for controls, and includes guidance on handling procedures.
d. There are two subsets of CUI.
i. CUI Basic is the subset of CUI for which law, regulation, or government policy does not set out specific handling or dissemination controls. CUI Basic handling and dissemination controls are the same as previously used for FOUO.
ii. CUI Specified is the subset of CUI for which law, regulation, or government policy contains specific handling controls that differ from CUI Basic. The government will provide marking and handling guidance separately for CUI Specified.
e. Remarking legacy FOUO documents is not required as long as they remain under DoD control. When needed, FOUO information does not automatically become CUI, so the material must be reviewed by the information owner to determine if it meets the CUI requirements and marked appropriately.
f. When responding to FOIA requests, the responsible DoD agency must base its decision on the content of the information and applicability of any of the FOIA statutory exemptions regardless of whether an agency designates or marks the information as CUI.
2. DESIGNATION as CUI: Designating CUI occurs when an authorized holder, consistent with DoDI 5200.48 and the CUI Registry, determines that a specific item of information falls into a CUI category or subcategory. The information must be designated as either CUI Basic or CUI Specified and the authorized holder must ensure that appropriate markings are applied to documents to ensure recipients are aware of the CUI status. See the associated Security Classification Guide (SCG) or other guidance provided by the Government Contracting Agency (GCA) for specific categories of CUI related to this contract and guidance on storage, handling, and dissemination.
3. MARKING:
a. Unclassified documents containing CUI will be marked CUI at the top & bottom of each page. As a best practice each “portion” (i.e. titles, subject lines, paragraphs, bullets, charts, etc.) containing CUI may be Portion Marked (CUI). If portion marks are used then Unclassified portions will be Portion Marked (U). Do not use (U//CUI).
b. The government will provide marking, handling, and dissemination guidance separately for any CUI Specified information. For classified contracts, this guidance will be contained in the associated SCG.
c. The following CUI Designation Indicator information will be included on the first/title page or cover of all unclassified documents containing CUI:
Controlled by: [Name of DoD Component and Office] CUI Category: [List of Category or Categories of CUI] Distribution/Dissemination Control: [Use “None” for CUI Basic/As required for CUI Specified) POC: [Phone Number and/or E-mail]
d. Classified documents containing CUI will NOT include CUI in the banner marking at the top and bottom of each page. Each paragraph that contains only CUI will be portion marked (CUI). All other paragraphs will be marked according to their classification. Do not “co-mingle” CUI with classified information. The above CUI Designation Indicator information must be included on the first page or cover (same as unclassified documents). Additionally, the following statement must be included on the first page of documents that contain both CUI and classified information:
This content is classified at the [insert highest classification level of the document] level and may contain elements of controlled unclassified information (CUI), unclassified, or information classified at a lower level than the overall classification displayed. This content shall not be used as a source of derivative classification; refer to [cite specific reference or applicable Security Classification Guide]. It must be reviewed for both Classified National Security Information (CNSI) and CUI in accordance with DoDI 5230.09 prior to public release.
4. PROCESSING: Unclassified Automated Information Systems (AIS) used to process CUI under this contract must meet the basic security requirements listed in the NIST SP 800-171 REV 2, “Protecting Controlled Unclassified Information in Non-Federal Systems and Organizations”, 21 February 2020. AIS accredited and approved for processing classified information under this contract are also approved to process DoD CUI.
5. DISSEMINATION: CUI may be disseminated between officials of DoD Agencies, DoD contractors, consultants and grantees to conduct official business for the DoD provided the dissemination is consistent with controls imposed by a Distribution Statement or Limited Dissemination Controls (LDC). Guidance on Distribution Statements and LDCs will be provided separately by the government for any prescribed CUI Specified information. For classified contracts, this information will be contained in the program SCG. CUI always requires Foreign Disclosure Decision before release outside of DoD Agencies, DoD contractors, consultants and grantees.
6. STORAGE: During working hours, to prevent unauthorized access, do not leave CUI unattended, read or discuss around unauthorized personnel. CUI shall be placed in an out-of-sight location if the work area is accessible to persons who do not have a need for the information. During non-working hours, the information shall be stored to preclude unauthorized access. Filing such material with other unclassified records in unlocked files or desks, is adequate when internal building security is provided during non-working hours. When such internal security control is not exercised, locked buildings or rooms will provide adequate after-hours protection or the material can be stored in locked receptacles such as file cabinets, desks, or bookcases.
7. TRANSMISSION: CUI may be transmitted using the following:
a. Mail – CUI may be sent via first class mail or parcel post. Bulk shipments may be sent by fourth class mail. Contents must be properly marked, but no markings will appear on the outer wrapper.
b. Fax – Normally CUI may be sent via Facsimile equipment. To prevent unauthorized disclosure, coversheets should be used, the locations of both fax machines should be considered, and availability of an authorized recipient at the receiving end should be confirmed. Secure classified fax machines may be used without the above verifications.
c. E-Mail/Web Sites – E-mail may be used on approved secure communication systems or systems using other protective measures such as Public Key Infrastructure (PKI) or transport layer security (e.g., https). E-mail messages must be appropriately marked to identify CUI status. Personnel will not use unofficial or personal email accounts, messaging systems, or other non-DoD information systems, except approved government contractor systems to conduct official business involving CUI.
d. Video Teleconferencing – Only use Government Agency approved secure, encrypted video conferencing and collaborative platforms (i.e. SVTC, etc.). CUI may not be discussed over commercially available video conferencing applications.
e. Avoid wireless transmission unless no other means are available.
8. DESTRUCTION: When no longer needed, CUI must be disposed of in a way that will make it unreadable, indecipherable, and irrecoverable. Use of approved sensitive/classified material destruction devices is recommended. (ISOO CUI Notice 2019-03, “Destroying Controlled Unclassified Information in Paper Form”, 15 July 2019)
9. UNAUTHORIZED DISCLOSURE: Report misuse, mishandling, or Unauthorized Disclosure of CUI to the Unauthorized Disclosure Program Management Office, the Controlling Agency and the appropriate Military Department Counterintelligence Organization. While Unauthorized Disclosure of CUI does not constitute a security violation, a formal security inquiry/investigation is required if disciplinary action will be taken against the individual(s) responsible. Unauthorized Disclosure of certain CUI, such as export controlled-technical data, may also result in civil and criminal sanctions against responsible persons based on procedures codified in relevant law, regulation, or government-wide policy.
text: HQ USSOCOM/SOFM
813-826-9599/DSN 299-9599
robert.e.mcclintock.civ@socom.mil
| attachmentsList: |
| AddAttachment: |
| ViewAttachment: |
| RemoveAttachment: |
| rep: Robert McClintock |
Contracting Officer's Representative
| Sig: |
| Enter your name here.: While performing duties at USSOCOM, Component (JSOC, AFSOC, NSWC, MARSOC, or USASOC), Theater Special Operation Command (SOCNORTH, SOCCENT, SOCEUR, SOCPAC, SOCSOUTH, SOCAFRICA, or SOCKOR) or other U.S. Government owned and operated facilities, the contractor will adhere to the applicable Information Security Program, ADP and DODIIS Programs, Physical Security Program, Industrial Security Program, and SCI/SAP Program (if applicable). Prior approval of the contracting activity is required for subcontracting. Access to intelligence information requires special briefings and a U.S. Government clearance at the appropriate level. |
Training Requirement: Contractors performing on this contract at military installations are required to conduct command and unit specific security training (Initial/Refresher INFOSEC, OPSEC, EMSEC, AT/FP, Intelligence Oversight, etc.). This training will be provided by the responsible military organization.
IA requirements: Specific Information Assurance requirements may be mandated and are authorized by the responsible command/unit where primary performance location is identified.
| Enter your name here.: Defense Counterintelligence and Security Agency (DCSA) is relieved of all inspection responsibility within USSOCOM, Component (JSOC, AFSOC, NSWC, MARSOC, or USASOC), Theater Special Operation Command (SOCNORTH, SOCCENT, SOCEUR, SOCPAC, SOCSOUTH, SOCAFRICA, SOCKOR) and other U.S. Government owned and operated facilities. |
| GCAName: HQ USSOCOM/SOF AT&L-KH |
| AAC: H92222 |
| AAC: N/A |
| Address: HQ USSOCOM/SOF AT&L-KH |
7701 Tampa Point Blvd MacDill AFB, FL 33621 Address: HQ USSOCOM/SOCS-Z-SM 7701 Tampa Point Blvd MacDill AFB, FL 33621
| POCName: Carrie Eastburn |
| Phone: 8138264567 |
| Phone: 8138264333 |
| Email: carrie.eastburn@socom.mil |
| Email: john.fredette@socom.mil |
| Title: Industrial Security Program Manager |
| Enter the date using the format DD-Mon-YYYY: |
File details come from the government source that posted it. Updated .