09a Draft DD254 (Preliminary Apvl) - SARM Task Order.pdf

PDF 288 KB Posted

Attached to
SOF Enterprise Professional Services (SEPS) Federal contract opportunity
Solicitation number
H9240022R0008
Issued by
United States Special Operations Command

About this file

This document contains a Draft DD254 security classification specification and information related to a solicitation for the SOF Enterprise Professional Services (SEPS) acquisition. The DD254 specifies that classified material generated under the SEPS task order will require a SECRET facility clearance and safeguarding level. Performance will take place at USSOCOM and other locations as identified in the security guidance. Contractors will require access to Special Operations Forces information and operations. The solicitation seeks proposals due by January 25, 2022 to provide professional support services to USSOCOM through September 2027 with biennial security reviews. The United States Special Operations Command is the contracting agency.

View the file

Other files for this federal contract opportunity

Other files attached to SOF Enterprise Professional Services (SEPS), newest first.
File Type Posted
08 Responses to Draft RFP Questions (12 Jan 22)_AMD 0004.docx DOCX document
H9240022R0008_0004.pdf PDF
03 Work Sample Cover Sheet_AMD0004.docx DOCX document
02 HRTO Self Score Matrix_AMD 0004.xlsx XLSX spreadsheet
H9240022R0008 (Conformed through Amendment 0004).pdf PDF
05a SOW - USASOC SARM_AMD0004.docx DOCX document
04 SEPS Price Template_AMD0004.xlsx XLSX spreadsheet
05c SOW J3_AMD0004.docx DOCX document
H9240022R0008_0003.pdf PDF
H9240022R0008 (Conformed through 0003).pdf PDF
H9240022R0008_0001_(Conformed).pdf PDF
02 HRTO Self Score Matrix_AMD 0001.xlsx XLSX spreadsheet
11 DOD M 5220.22 VOL 2 NISP.pdf PDF
10 32 CFR Part 117.pdf PDF
08 Responses to Draft RFP Questions (2 Dec 21)_AMD 0001.docx DOCX document
H9240022R0008_0001.pdf PDF
H9240022R0008.pdf PDF
04 SEPS Price Template.xlsx XLSX spreadsheet
03 Work Sample Cover Sheet.docx DOCX document
01 SDS IDIQ-A.xlsx XLSX spreadsheet
Exhibit A-2 CDRL A001 - Submission Format.xlsx XLSX spreadsheet
Exhibit A CDRL A001 - Contract Status Report.pdf PDF
05c SOW J3 (21 Dec 2021).docx DOCX document
05a SOW - USASOC SARM (20 Dec 21).docx DOCX document
09 Draft DD254 (Preliminary Apvl) -SEPS IDIQ.pdf PDF
Exhibit A-1 CDRL A001 - Submission Format.docx DOCX document
08 Responses to Draft RFP Questions (2 Dec 21).docx DOCX document
05b SOW FIAR (17 Nov 21).docx DOCX document
Exhibit B-1 CDRL A002 - Submission Format.docx DOCX document
06 QnA Template.docx DOCX document
02 HRTO Self Score Matrix.xlsx XLSX spreadsheet
07 SEPS Industry Day Briefing (2 Dec 21).pptx PPTX presentation
09c Draft DD254 (Preliminary Apvl) - J3 Task Order.pdf PDF
Exhibit B CDRL A002 - Contractor Self-Assessment.pdf PDF
09b Draft DD254 (Preliminary Apvl) - FIAR Task Order.pdf PDF
Show all 35

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Please wait...

If this message is not eventually replaced by the proper contents of the document, your PDF viewer may not be able to display this type of document.

You can upgrade to the latest version of Adobe Reader for Windows®, Mac, or Linux® by visiting http://www.adobe.com/go/reader_download.

For more assistance with Adobe Reader visit http://www.adobe.com/go/acrreader.

Windows is either a registered trademark or a trademark of Microsoft Corporation in the United States and/or other countries. Mac is a trademark of Apple Inc., registered in the United States and other countries. Linux is the registered trademark of Linus Torvalds in the U.S. and other countries.

DRAFT

SAMPLE

PREVIOUS EDITION IS OBSOLETE.

Page of

DD FORM 254, MAY 2019

NEEDS DD67

DEPARTMENT OF DEFENSE

CONTRACT SECURITY CLASSIFICATION SPECIFICATION

(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)

OMB No. 0704-0567 OMB approval expires:

20220531 The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.

RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.

1. CLEARANCE AND SAFEGUARDING

2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)

3. THIS SPECIFICATION IS: (X and complete as applicable.)

a. ORIGINAL (Complete date in all cases.)

b. REVISED (Supersedes all previous specifications.)

4. IS THIS A FOLLOW-ON CONTRACT?

If yes, complete the following:

Classified material received or generated under

5. IS THIS A FINAL DD FORM 254?

If yes, complete the following:

6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)

7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor)

8. ACTUAL PERFORMANCE (Click button to add more locations.)

10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)

e. NATIONAL INTELLIGENCE INFORMATION:

11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)

12. PUBLIC RELEASE

Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)

13. SECURITY GUIDANCE

The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.

(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)

14. ADDITIONAL SECURITY REQUIREMENTS

Requirements, in addition to NISPOM requirements for classified information, are established for this contract.

If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)

15. INSPECTIONS

Elements of this contract are outside the inspection responsibility of the CSO.

If Yes, explain and identify specific areas and government activity responsible for inspections. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)

16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)

17. CERTIFICATION AND SIGNATURES

Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below. Upon digitally signing Item 17h, no changes can be made as the form will be locked.

18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL

9.0.0.2.20120627.2.874785 DD 254, DoD Contract Security Classification Specification whs.mc-alex.esd.mbx.formswebmaster@mail.mil

WHS

List of Attachments (All Files Must be Attached Prior to Signing, i.e., for any digital signature on the form)

CurrentPage:
PageCount:
Classification: Unclassified
SerialNum:
a. Facility clearance level. Select one.: 1
b. Level of safeguarding for classified information/material required at contractor facility. Select one.: 4
Choose Yes or No: 1
Choose Yes or No: 1
Prime: H92400-22D-0008 TO H92400-22F-0TBD
Choose Yes or No: 0
Choose Yes or No: 0
Sub: SEE ITEM 13
Choose Yes or No: 0
Choose Yes or No: 0
Soli:
DueDate:
dateA: 2021-12-16
RevisionNum:
dateB:
Final:
dateC:
No: 1
No: 1
No: 0
No: 0
Yes: 0
Yes: 0
Yes: 1
Yes: 1
Enter your name here.:
ReqDated:
Enter your name here.:
Name: TBD
Name: SEE ITEM 13
Name: Fredette, John T.
Cage: TBD
Cage: N/A
Cage: N/A
CSO: Defense Counterintelligence & Security Agency (DCSA)

TBD Field Office

CSO: HQ USSOCOM/SOCS-Z-SM

7701 Tampa Point Blvd MacDill AFB, FL 33621 813-826-4333 IndustrialSecurity@socom.mil

CSO: HQ USASOC G-2

AOIN-SOD

Fort Bragg, NC 28310-9110

addrow:
Removerow:
Click to delete a row:
Location: USSOCOM

7701 Tampa Point Blvd MacDill AFB, FL 33621 Location: HQ United States Army Special Operations Command Fort Bragg, NC 28310-9110 and other locations as identified in item 13.

Block9: Special Operations Forces Enterprise Professional Services (SEPS) will be the replacement for the SWMS-C contract which expires next year.

Period of Performance: 18 Sept 2022 - 17 Sept 2027 (BIENNIAL DD FORM 254 REVIEW REQUIRED - SEE ITEM 13)

THIS DD FORM 254 IS TENTATIVELY APPROVED. Upon company selection and a Task Order is identified, but prior to award and any classified release, this DD Form 254 with all pertinent information inserted in appropriate sections will be submitted to U.S. Special Operations Command Industrial Security for final review and approval.

a: 0
a: 1
a: 1
f: 1
f: 0
f: 1
b: 0
b: 0
b: 0
g: 1
g: 0
c: 0
c: 0
c: 1
h: 1
h: 0
d: 0
d: 0
d: 0
i: 1
i: 0
SCI: 1
NonSCI: 1
j: 1
j: 0
k: 1
k: 0
Enter your name here.: SEE ITEM 13
Enter your name here.: SEE ITEM 13
Enter your name here.: HQ USSOCOM SMO/SSO/SAPCO
e: 0
e: 1
l: 1
m: 1
direct: 0
thru: 1
Enter your name here.: SEE ITEM 13
PublicAuthority:
AddSig:
RemoveSig:
text: The Contracting Officer’s Representative/Program Manager will provide a copy of all applicable security directives for this contract. Appropriate applicable HQ USSOCOM security directives, regulations, and standard operating procedures will be provided by the requiring agency (normally through the Performance Monitor or Component/Theater Special Operations Command COR/PM). Upon completion or termination of the classified contract, or sooner when the purpose of the release has been served, the contractor will return all classified information (furnished or generated) to the source from which received unless retention or other disposition instructions are authorized in writing by the USSOCOM Government Contracting Agency/Activity. Furthermore, the contractor will account for and return all Common Access Cards (CACs) to Contracting Officer's Representative, Program Manager, or Trusted Agent upon completion or termination of the classified contract, termination of employment, or suspension of classified clearance or access of any contractor employee. Security badges, installation entry passes/vehicle decals issued to contractor personnel will be returned to the appropriate issuing office as required.

Ref 2b: Subcontracting/Flow-Down of this effort requires a Subcontract/Flow-Down DD FM 254. Subcontract/Flow-Down DD FM 254 must be approved by HQ USSOCOM prior to award. Forward requests and draft Subcontract DD FM 254s to the Contracting Officer’s Representative/Program Manager and USSOCOM Industrial Security (IndustrialSecurity@socom.mil). IAW USSOCOM R 380-9, Industrial Security, please allow 10 duty days for review/approval.

Ref 2b. Subcontractors with performance at HQ USSOCOM. Forward subcontractor Visit Requests to HQ USSOCOM Personnel Security (PERSEC) via DISS SMO Code MA3DF8X94. Visit Requests must not be submitted to HQ USSOCOM until the Subcontract DD FM 254 is approved. Failure to follow this guidance will result in the cancellation of the Visit Request

Ref 7: See guidance in Ref 2b.

Ref 9: Unless DD FORM 254 revision is required due to change in the security requirements of the effort or there is a change in the contractor’s Facility Clearance (FCL) status, the responsible Contracting Officer’s Representative/Program Manager (COR/PM) must conduct a review of the DD FORM 254 and associated Individual Work Plan, Performance Work Statement/Statement of Objectives/Statement of Work every 24 MONTHS (BIENNIALLY) in order to validate and/or update the requirements of the effort as required by DoDM 5220.22-V2, National Industrial Security Program: Industrial Security Procedures for Government Activities. Documentation of review (email is sufficient) should be forwarded to HQ USSOCOM Industrial Security via NIPRNet at IndustrialSecurity@socom.mil.

Ref 10e(1): See SCI Addendum.

Ref 10e (2): Access to intelligence information requires special briefings and a final US Government clearance at the appropriate level.

Ref 10f: See SAP Addendum.

Ref 10g. The contractor is permitted access to North Atlantic Treaty Organization (NATO) information in performance of this contract. Access to NATO information requires a final U.S. Government clearance at the appropriate level. The government program/project manager is the designated representative that will ensure the contractor security manager and concerned employees are NATO briefed prior to access being granted. The contractor will maintain strict compliance in regards to NATO information IAW NISPOM Chapter 10, Section 7. Prior approval from the contracting activity is required for subcontracting.

Ref 10h. The contractor is permitted access to Foreign Government Information in the performance of this contract. Access to Foreign Government Information requires a final U.S. Government clearance at the appropriate level. Contractor employees will be briefed, and acknowledge in writing, their responsibilities for handling Foreign Government Information prior to being granted access. The contractor will maintain strict compliance with NISPOM Chapter 10. Prior approval of the contracting activity is required for subcontracting.

Ref 10i. Alternative Compensatory Control Measures (ACCM) Program information is governed by DoD M 5200.01-V3, DoD Information Security Program: Protection of Classified Information, Enclosure 2, Section 18; CJCS Manual 3213.02D, Joint Staff Alternative Compensatory Control Measures Program Management Manual, and supporting documentation for each ACCM sub-system, including security classification guides, program security plans, and governing directives. Inspections of ACCM information in USSOCOM, Component (JSOC, AFSOC, NSWC, MARSOC, or USASOC), or Theater Special Operation Command (SOCNORTH, SOCAFRICA, SOCCENT, SOCEUR, SOCPAC, SOCSOUTH, or SOCKOR) owned and operated facilities are under the auspices of the respective Command or Component ACCM Coordinator/ACCM Program Control Officer (ACCM Coord/ACCM PCO). If applicable, ACCM material maintained by the Contractor within their facility must be afforded protection commensurate with DOD requirements and strictly controlled based on need-to-know and required briefings. DCSA personnel conducting inspections of the Contractor must be briefed on to the specific program by the appropriate government ACCM Coord/ACCM PCO responsible for the material prior to being granted access.

Ref 10j: Controlled Unclassified Information (CUI) provided under this contract shall be safeguarded as specified in the CUI Addendum included with this specification.

Ref 10k: NIPRNET/SIPRNET/JIANT/SAPNET access required at government facilities only.

Ref 11a: Contractor performance is restricted to MacDill AFB, FL, unless otherwise specified in the TO. Government agency or activity will provide security classification guidance for performance of this contract. Submit visit request to COR and/or Security Management Office for need-to-know verification.

Ref 11l: Controlled Unclassified Information (CUI) provided under this contract shall be safeguarded as specified in the CUI Addendum included with this specification.

Ref 11m: Access to all USSOCOM facilities requires contractors to possess a minimum of a SECRET clearance.

Ref 11n: Contractor will be authorized to courier classified information up to the SECRET level in performance of official duties upon approval of and designation by the COR..

Ref 12: Requests must be forwarded through the responsible Contracting Officer’s Representative/Program Manager, Contracting Official (Item 16) and the HQ USSOCOM Special Operations Communication Office (SOCS-SOCO) at Public.Affairs@socom.mil, (813) 826-4600, prior to public release.

SCI ADDENDUM

(14 September 2020)

This supplement applies to:

Prime Contract Number: H92400-22D-0008 Subcontract Number: N/A Delivery/Task Order Number: H92400-22F-0TBD Expiration Date: 17 Sept 2027

The following controls will apply to Sensitive Compartmented Information (SCI) provided under this contract.

1. Item 10e (2): Security clearances for contractors working within SCIF spaces must be adjudicated meeting Intelligence Community Policy Guidance (ICPG) 704.1, 704.2, 704.3, 704.4, 704.5 eligibility requirements. Prior approval of the contracting activity is required for sub-contracting. Access to intelligence information requires special briefings and a final U.S. Government clearance at the appropriate level.

2. Item 13: Department of Defense (DOD) Manual 5105.21, Volumes 1-3, Intelligence Community Policy Guidance (ICPG) 704.1, 704.2, 704.3, 704.4, 704.5, Intelligence Community Standard (ICS) 705-1&2 including the Technical Specifications for Construction and Management of Sensitive Compartmented Information Facilities (IC Tech Spec-for ICD/ICS 705, and Headquarters, United States Special Operations Command (HQ USSOCOM) 380-6, provide the necessary guidance for physical and information security measures and are part of the SCI security specifications for the contract.

3. Item 13: Inquiries pertaining to classification guidance will be directed to the responsible USSOCOM Contracting Officer’s Representative/Program Manager/Contract Monitor ((Ronnie Rafferty, 910-432-5822/ Robert McClintock, 813-826-9599/ TBD).

4. Item 13: All SCI furnished to the contractor in support of this contract / delivery / task order remains the property of the DOD or the agency or command that releases the information. Upon termination of the contract, all furnished SCI will be returned to the HQ USSOCOM Special Security Office (SSO) or the prime contractor.

5. Item 14: This IDIQ contract requires SEVEN (7) contract billets be established in order to fulfill the contractual obligations incurred. Access will be granted by the government agency. Upon completion or cancellation of the contract, the Contractor SSO (CSSO) will debrief or notify the HQ USSOCOM SSO to debrief all personnel not required for contract closeout and those billets will be disestablished.

6. Item 14: Names of contractor personnel requiring access to SCI and justification for SCI billets will be submitted to HQ USSOCOM SSO after contract monitor coordination. Billet justifications will include the contract statement of work. If a T5 investigation has not been completed upon approval of billets by the HQ USSOCOM SSO, the CSSO will submit necessary forms to the Vetting Risk Operations Center (VROC) for a T5 investigation. A T5 investigation and access to SCI will comply with the National Industrial Security Program Manual. Upon completion of the T5 investigation, a nomination for SCI access will be submitted to HQ USSOCOM SSO.

7. Item 14: The CSSO will advise HQ USSOCOM SSO, through the contract monitor, upon reassignment of personnel to other duties not associated with this contract. The Contract Monitor will also notify the SSO Office at SOCOM.SSO.PERSEC@SOCOM.MIL or 813-826-1287 so the SSO can remove their ownership of the contractor in DISS.

8. Item 14: The CSSO must coordinate with the SCI contract monitor before subcontracting any portion of SCI efforts involved in the contract. A separate DD Form 254 for the subcontractor will be processed and a copy provided to HQ USSOCOM SSO.

9. Item 14: The contractor will not use references to SCI access, even by unclassified acronyms, in advertisements, promotional efforts, or recruitment of employees.

10. Item 14: All SCI work will be performed at the locations specified below and in subsequent Task Orders.

a. HQ USSOCOM

11. Item 15: HQ USSOCOM SSO has exclusive security responsibility for all SCI released to the contractor or developed under this contract. Defense Intelligence Agency and HQ USSOCOM SSO retain authority for all inspections of the contractor to ensure compliance with SCI directives, regulations, and instructions.

12. In accordance with DODM 5105.21 Volume 1-3, the following activity is designated User Agency Special Security Office for SCI requirement:

HQ USSOCOM

Special Security Office (SSO) 7701 Tampa Point Boulevard Telephone: DSN 299-1287 SOCOM.SSO.INDUSEC@SOCOM.MIL MacDill AFB, Florida 33621-5323 Commercial: (813) 826-1287

PROTECTING SPECIAL ACCESS PROGRAM (SAP) INFORMATION

SAP ADDENDUM

(7 August 2019 Edition)

Special Access Program (SAP) discussion, storage, and processing associated with this effort will be conducted in SAP Facilities (SAPF) specifically approved, in writing, by the USSOCOM SAPCO or designated USSOCOM Program Security Officer (PSO). Contact the individual in Item 13 for approved SAPF locations.

SAP activities are governed by DOD Manual 5200.01 (DOD Information Security Program) Volumes 1-4, DOD Directive 5205.07 (Special Access Program Policy); DOD Manual 5205.07 (DOD Special Access Program Security Manual), Volumes 1-4; DOD Instruction 5205.11, (Joint SAP Implementation Guide (JSIG)); USSOCOM Manual 380-2 (SAP Security Guide); USSOCOM Manual 380-7 (USSOCOM Arms Control Readiness Inspection Program) and applicable program security classification guides and subsequent versions. Applicable documents will be provided to the contractor by the PSO under separate cover.

Access to SAP information requires employees to undergo additional personnel security screening and meet the requirements of DoD SAP accessing directives and policies in accordance with DODM 5205.07, Volume 2. The individual must meet applicable eligibility requirements and possess a final Secret or Top Secret security clearance depending on the level of access required in performance of this contract. Program Access Requests (PAR) for contractor personnel must be submitted by the Contractor’s Program Security Officer (CPSO) to the PSO for approval by the designated Access Approval Authority (AAA). Personnel approved for access will receive a program indoctrination briefing and must sign a SAP Indoctrination Agreement (PIA) prior to receiving access to program information or material. The CPSO will maintain the signed PIA and forward a copy to the PSO for entry into the appropriate database system.

SAP inspections and security oversight while in USSOCOM or Component government facilities are under the cognizance of the USSOCOM PSO or SAPCO representative, as appropriate. Additional Component SAP security requirements may apply for activities conducted at Service Component or Sub-unified command locations. The Performance Monitor or component command COR at these locations/facilities will provide specific or additional guidance. SAP reviews conducted at contractor facilities are under the security oversight of the Defense Counterintelligence and Security Agency (DCSA) unless officially relieved of oversight responsibilities.

OPSEC-sensitive or classified communication will be conducted via PSO-approved secure channels from within the SAPF. Transmission of documents via secure facsimile between terminals within SAPFs may be approved by the PSO. Only the U.S. Postal Service Register or Certified mail, if authorized, will be used to mail program material unless an alternate method is approved by the PSO. Briefed personnel are authorized to courier classified information within the continental United States with written approval from the CPSO or PSO. Two (program briefed) personnel are required to courier Top Secret material unless prior approval is obtained from the PSO. Couriers will be in the possession of PSO-issued courier authorization letters prior to travel. All material, to be mailed or carried, will be wrapped and transmitted in accordance with DODM 5205.07, Volume 1.

Prior to processing SAP information on any Automated Information System (AIS), the contractor will provide the PSO with a System Security Plan (SSP) and other documentation required in JSIG for Assessment & Authorization (A&A) from the Authorizing Official (AO), or subsequent policy. The PSO will issue program specific Security Authorization following verification of the A&A process. USSOCOM Special Access Program (SAP) Policy Memorandum: Removable Media and Two-Person Integrity Control Policy is applicable for this contract.

Destruction of program material will be conducted only by program indoctrinated personnel using destruction equipment and procedures approved by the PSO. A single person may destroy non-accountable classified material. Accountable material must be destroyed, and documented, by two program cleared individuals.

The PSO will be advised of any reports which affect the baseline facility clearance or any incident that has an adverse impact on a personnel security clearance. All briefed personnel are required to report any information that could have an impact on their ability to protect classified information. Reportable items include: foreign travel, contacts, or associations; criminal, civil, financial, or mental health issues; and changes in personal status such as marriage, divorce, or employment. CPSOs are reminded of their responsibilities to diligently report any significant action or any change in an employee’s eligibility to the PSO immediately.

Per DOD Manual 5205.07 Volume 1, Encl. 11, Sec 3. : “Any (contractual) relationship with a prospective subcontractor requires prior approval by the PSO.” All security requirements levied upon the prime contractor will “flow-down” to the subcontractor. SAP access and other requirements must be pre-coordinated and approved by the PSO prior to implementation.

IAW DODM 5200.01, Vol 3, Encl. 6, any security incident involving the potential loss, compromise, or suspected compromise of classified information must be reported to the PSO immediately using appropriate secure channels. Security infractions will be documented in the individuals personal security file and made available for review during PSO visits.

PROTECTING “CONTROLLED UNCLASSIFIED INFORMATION” (CUI)

CUI Addendum (Updated March 2021)

1. GENERAL:

a. Controlled Unclassified Information (CUI) is not a security classification, but designates unclassified information that requires any safeguarding or dissemination control per DoD Instruction 5200.48, “Controlled Unclassified Information” (6 March 2020).

b. With the implementation of DoDI 5200.48, DoDM 5200.01, Volume 4, “DoD Information Security Program: Controlled Unclassified Information” (24 February 2012, as amended), has been cancelled and “For Official Use Only” (FOUO) and is no longer authorized. All new documents shall be marked in accordance with the guidance below.

c. In order to balance the need to safeguard CUI with the public interest the CUI Registry, established by DoDI 5200.48, lists categories of CUI Basic/Specified and identifies basis for controls, and includes guidance on handling procedures.

d. There are two subsets of CUI.

i. CUI Basic is the subset of CUI for which law, regulation, or government policy does not set out specific handling or dissemination controls. CUI Basic handling and dissemination controls are the same as previously used for FOUO.

ii. CUI Specified is the subset of CUI for which law, regulation, or government policy contains specific handling controls that differ from CUI Basic. The government will provide marking and handling guidance separately for CUI Specified.

e. Remarking legacy FOUO documents is not required as long as they remain under DoD control. When needed, FOUO information does not automatically become CUI, so the material must be reviewed by the information owner to determine if it meets the CUI requirements and marked appropriately.

f. When responding to FOIA requests, the responsible DoD agency must base its decision on the content of the information and applicability of any of the FOIA statutory exemptions regardless of whether an agency designates or marks the information as CUI.

2. DESIGNATION as CUI: Designating CUI occurs when an authorized holder, consistent with DoDI 5200.48 and the CUI Registry, determines that a specific item of information falls into a CUI category or subcategory. The information must be designated as either CUI Basic or CUI Specified and the authorized holder must ensure that appropriate markings are applied to documents to ensure recipients are aware of the CUI status. See the associated Security Classification Guide (SCG) or other guidance provided by the Government Contracting Agency (GCA) for specific categories of CUI related to this contract and guidance on storage, handling, and dissemination.

3. MARKING:

a. Unclassified documents containing CUI will be marked CUI at the top & bottom of each page. As a best practice each “portion” (i.e. titles, subject lines, paragraphs, bullets, charts, etc.) containing CUI may be Portion Marked (CUI). If portion marks are used then Unclassified portions will be Portion Marked (U). Do not use (U//CUI).

b. The government will provide marking, handling, and dissemination guidance separately for any CUI Specified information. For classified contracts, this guidance will be contained in the associated SCG.

c. The following CUI Designation Indicator information will be included on the first/title page or cover of all unclassified documents containing CUI:

Controlled by: [Name of DoD Component and Office] CUI Category: [List of Category or Categories of CUI] Distribution/Dissemination Control: [Use “None” for CUI Basic/As required for CUI Specified) POC: [Phone Number and/or E-mail]

d. Classified documents containing CUI will NOT include CUI in the banner marking at the top and bottom of each page. Each paragraph that contains only CUI will be portion marked (CUI). All other paragraphs will be marked according to their classification. Do not “co-mingle” CUI with classified information. The above CUI Designation Indicator information must be included on the first page or cover (same as unclassified documents). Additionally, the following statement must be included on the first page of documents that contain both CUI and classified information:

This content is classified at the [insert highest classification level of the document] level and may contain elements of controlled unclassified information (CUI), unclassified, or information classified at a lower level than the overall classification displayed. This content shall not be used as a source of derivative classification; refer to [cite specific reference or applicable Security Classification Guide]. It must be reviewed for both Classified National Security Information (CNSI) and CUI in accordance with DoDI 5230.09 prior to public release.

4. PROCESSING: Unclassified Automated Information Systems (AIS) used to process CUI under this contract must meet the basic security requirements listed in the NIST SP 800-171 REV 2, “Protecting Controlled Unclassified Information in Non-Federal Systems and Organizations”, 21 February 2020. AIS accredited and approved for processing classified information under this contract are also approved to process DoD CUI.

5. DISSEMINATION: CUI may be disseminated between officials of DoD Agencies, DoD contractors, consultants and grantees to conduct official business for the DoD provided the dissemination is consistent with controls imposed by a Distribution Statement or Limited Dissemination Controls (LDC). Guidance on Distribution Statements and LDCs will be provided separately by the government for any prescribed CUI Specified information. For classified contracts, this information will be contained in the program SCG. CUI always requires Foreign Disclosure Decision before release outside of DoD Agencies, DoD contractors, consultants and grantees.

6. STORAGE: During working hours, to prevent unauthorized access, do not leave CUI unattended, read or discuss around unauthorized personnel. CUI shall be placed in an out-of-sight location if the work area is accessible to persons who do not have a need for the information. During non-working hours, the information shall be stored to preclude unauthorized access. Filing such material with other unclassified records in unlocked files or desks, is adequate when internal building security is provided during non-working hours. When such internal security control is not exercised, locked buildings or rooms will provide adequate after-hours protection or the material can be stored in locked receptacles such as file cabinets, desks, or bookcases.

7. TRANSMISSION: CUI may be transmitted using the following:

a. Mail – CUI may be sent via first class mail or parcel post. Bulk shipments may be sent by fourth class mail. Contents must be properly marked, but no markings will appear on the outer wrapper.

b. Fax – Normally CUI may be sent via Facsimile equipment. To prevent unauthorized disclosure, coversheets should be used, the locations of both fax machines should be considered, and availability of an authorized recipient at the receiving end should be confirmed. Secure classified fax machines may be used without the above verifications.

c. E-Mail/Web Sites – E-mail may be used on approved secure communication systems or systems using other protective measures such as Public Key Infrastructure (PKI) or transport layer security (e.g., https). E-mail messages must be appropriately marked to identify CUI status. Personnel will not use unofficial or personal email accounts, messaging systems, or other non-DoD information systems, except approved government contractor systems to conduct official business involving CUI.

d. Video Teleconferencing – Only use Government Agency approved secure, encrypted video conferencing and collaborative platforms (i.e. SVTC, etc.). CUI may not be discussed over commercially available video conferencing applications.

e. Avoid wireless transmission unless no other means are available.

8. DESTRUCTION: When no longer needed, CUI must be disposed of in a way that will make it unreadable, indecipherable, and irrecoverable. Use of approved sensitive/classified material destruction devices is recommended. (ISOO CUI Notice 2019-03, “Destroying Controlled Unclassified Information in Paper Form”, 15 July 2019)

9. UNAUTHORIZED DISCLOSURE: Report misuse, mishandling, or Unauthorized Disclosure of CUI to the Unauthorized Disclosure Program Management Office, the Controlling Agency and the appropriate Military Department Counterintelligence Organization. While Unauthorized Disclosure of CUI does not constitute a security violation, a formal security inquiry/investigation is required if disciplinary action will be taken against the individual(s) responsible. Unauthorized Disclosure of certain CUI, such as export controlled-technical data, may also result in civil and criminal sanctions against responsible persons based on procedures codified in relevant law, regulation, or government-wide policy.

text: HQ USASOC/DCSCMP

910-432-5822/DSN 299-5822

ronnie.rafferty@socom.mil text: HQ USSOCOM/J2-SSO

813-826-1287/DSN 299-1287

SOCOM.SSO.INDUSEC@socom.mil text: HQ USSOCOM/SOCS-CORB

813-826-4977/DSN 299-4977

SAPCO@socom.mil

attachmentsList:
AddAttachment:
ViewAttachment:
RemoveAttachment:
rep: Ronnie Rafferty

Contracting Officer's Representative rep: Daeun "Rachel" Jung HQ USSOCOM SSO Industrial Security rep: Deana Clark-Moller HQ USSOCOM SAPCO Industrial Security

Sig:
Enter your name here.: While performing duties at USSOCOM, Component (JSOC, AFSOC, NSWC, MARSOC, or USASOC), Theater Special Operation Command (SOCNORTH, SOCCENT, SOCEUR, SOCPAC, SOCSOUTH, SOCAFRICA, or SOCKOR) or other U.S. Government owned and operated facilities, the contractor will adhere to the applicable Information Security Program, ADP and DODIIS Programs, Physical Security Program, Industrial Security Program, and SCI/SAP Program (if applicable). Prior approval of the contracting activity is required for subcontracting. Access to intelligence information requires special briefings and a U.S. Government clearance at the appropriate level.

Training Requirement: Contractors performing on this contract at military installations are required to conduct command and unit specific security training (Initial/Refresher INFOSEC, OPSEC, EMSEC, AT/FP, Intelligence Oversight, etc.). This training will be provided by the responsible military organization.

IA requirements: Specific Information Assurance requirements may be mandated and are authorized by the responsible command/unit where primary performance location is identified.

In the event that no government employee or military service member is otherwise available, the contractor may be required to conduct security-related functions (traditionally considered inherently government functions) such as escorting cleared/un-cleared visitors, opening/closing of security containers, conducting end-of-day security checks, and arming/de-arming alarm security systems within open/non-open Collateral storage areas and Sensitive Compartmented Information Facilities (SCIFs) used for the safeguarding of classified information/material. In support of this, the contractor is approved to conduct the above actions for the following facilities and buildings/rooms/suites.

- USASOC HQ, Bldg. E-2929, Alarm/De-alarm and All CODES for all Rooms Sensitive Activities SCIF.

In the event that the contractor fails to properly conduct these responsibilities and a security violation/incident occurs, the government will have the option to take action against the company IAW U.S. law. In addition, the company will be responsible for reviewing preliminary inquiry reports for any security violation/incident for which an employee is found culpable and provide a written response to the Government Contracting Agency (GCA) and the responsible Industrial Security Program Manager for actions taken against the employee.

All security violations/incidents will be reported to the responsible Cognizant Security Office, Facility Security Officer, Contracting Officer, and contract officer representative (COR) for the contract.

Enter your name here.: Defense Counterintelligence and Security Agency (DCSA) is relieved of all inspection responsibility within USSOCOM, Component (JSOC, AFSOC, NSWC, MARSOC, or USASOC), Theater Special Operation Command (SOCNORTH, SOCCENT, SOCEUR, SOCPAC, SOCSOUTH, SOCAFRICA, SOCKOR) and other U.S. Government owned and operated facilities.
GCAName: HQ USSOCOM/SOF AT&L-KH
AAC: H92222
AAC: N/A
Address: HQ USSOCOM/SOF AT&L-KH

7701 Tampa Point Blvd MacDill AFB, FL 33621 Address: HQ USSOCOM/SOCS-Z-SM 7701 Tampa Point Blvd MacDill AFB, FL 33621

POCName: Carrie Eastburn
Phone: 8138264567
Phone: 8138264333
Email: carrie.eastburn@socom.mil
Email: john.fredette@socom.mil
Title: Industrial Security Program Manager
Enter the date using the format DD-Mon-YYYY: 20211220

File details come from the government source that posted it. Updated .