| 6.0 | SECURITY |
| 6.1 | All Key Personnel associated with this contract will be required to have at a minimum of a DoD “SECRET” clearance at time of award. The Contractor will have access to information and compartments with up to a “SECRET” classification. All deliverables associated with this contract are “unclassified” unless otherwise specified. Access to classified spaces and material and generation of classified material shall be in accordance with the attached DD Form 254. |
| 6.2 | The Department of Defense Contract Security Classification Specification (DD254) provides the security classification requirements for this effort. The Contractor shall obtain facility and personnel security clearance as required by the Department Industrial Security Program prior to starting to work on tasks requiring clearances. Access to classified spaces, material and generation of classified material shall be in accordance with the NISPOM 32 CFR Part 117 and the NSWCDD Command Security Manual. |
| 6.3 | The Contractor personnel shall possess at the time of contract award a current SECRET (S) clearance based on a T3/T3R completed within the last five (5) years. Contractor must comply with guidelines specified on the DD254. An interim SECRET (S) clearance is acceptable at time of award so long as a current clearance, respectively, is obtained within 180 calendar days subsequent to award unless further extended by prior written authorization by the Contracting Officer. The Contractor shall submit completed clearance packages within ten (10) calendar days or identification of any increased security requirements. |
| 6.4 | The Contractor shall possess and maintain a secret facility clearance as verified within the National Industrial Security System. |
| 6.5 | Safeguarding of classified material up to the SECRET level is authorized at the Contractor facility. |
| 6.6 | Electronic Spillages (ES) are unacceptable and pose a risk to national security. An electronic spillage is defined as classified data placed on an information system (IS), media or hardcopy document possessing insufficient security controls to protect the data at the required classification level, thus posing a risk to national security (e.g., sensitive compartmented information (SCI) onto collateral, Secret onto Unclassified, etc.). The Contractor's performance as it relates to ES will be evaluated by the Government. ES reflects on the overall security posture of NSWCDD and a lack of attention to detail with regard to the handling of classified information of IS security discipline and will be reflected in the Contractor's performance rating. In the event that a Contractor is determined to be responsible for an ES, all direct and indirect costs incurred by the Government for ES remediation will be charged to the Contractor. |
| 6.6.1 | NSWCDD Security will be responsible for the corrective action plan in accordance with the security guidance reflected on the DOD Contract Security Classification Specification - DD254. NSWCDD Security will identify the Contractor facility and contract number associated with all electronic spillages that involve the Contractor. NSWCDD Security will notify the Contracts Division with the Contractor facility name and contract number, incident specifics, and associated costs for cleanup. The Contracting Officer will be responsible for working with the Contractor Facility to capture the costs incurred during the spillage cleanup. The Contractor is also responsible for taking Information Security Awareness training annually, via their Facility Security Officer (FSO), as part of the mandatory training requirements. If a spillage occurs, additional training will be required to prevent recurrence. |
| 6.7 | Portable Electronic Devices (PEDS): Non-Government and/or personally owned portable electronic devices (PEDs) are prohibited with the exception of personally owned cell phones, which are authorized for use in General Office Spaces (GOS). All personnel need to be aware of the policy involving PEDs. Contractor/personnel visiting shall ensure the onsite personnel remains compliant with this PED policy. NSWCDD instruction defines PEDs as the following: any electronic device designed to be easily transported, with the capability to store, record, receive, or transmit text, images, video, or audio data in any format via any transmission medium. PED’s include, but are not limited to, cell phones, smart watches, laptops, radios, compact discs, and cassette players/recorders. In addition, this includes removable storage media such as flash memory, memory sticks, multimedia cards and secure digital cards, micro-drive modules, ZIP drives, ZIP disks, CD-RWs, DVD-RWs, MP3 players, iPADs, digital picture frames, electronic book readers, kindle, nook, cameras, external hard disk drives, and floppy diskettes. |
| 6.7.1 | Personal Wearable Fitness Devices (PWFDs) marketed primarily as fitness or sleep devices are allowed in all Navy spaces, if they are compliant with NAVADMIN 216/15, where collateral non-Sensitive Compartmented Information (SCI), classified information is processed, stored, or discussed up to and including secret. The User must ensure the PWFD is compliant with all requirements in NAVADMIN 216/15, Cyber Hygiene Authorization to use Personal Wearable Fitness Devices (e.g., FitBit, Jawbone UP, etc.) in Navy Spaces, dated 14 September 2015 and register PWFD in the NSWCDD Fitness Device Tracker. |
| 6.7.2 | Personnel requiring the use of Medical Portable Electronic Devices (MPEDS) must submit Form NSWCDD 5239/1 for authorization to the classified area. For Special Access Program Facility (SAPF), authorizations, follow the guidance provided by the Government Special Access Program Security Officer (GSSO). Authorizations for use in SAPFs that are co-utilized within NSWCDD SCIFS require coordination between both the GSSO and SSO. For authorizations to use MPED in Collateral Classified spaces, submit the form to the Special Programs Branch, Code 1053. |
| 6.7.3 | PED’s belonging to an external organization shall not be connected to NSWCDD networks or infrastructure without prior approval from the NSWCDD Information Assurance and Compliance Branch. This approval will be granted using the TARIS form and action tracker process. Personally owned hardware or software shall not be connected or introduced to any NSWCDD hardware, network or information system infrastructure. |
| 6.8 | Government-procured headsets with or without microphones must be wired, use either a 3.5 millimeter (mm) audio jack or universal serial bus (USB) port, cannot contain active-noise canceling functionality, and may be used on systems and may be used on systems of classification up to and including collateral SECRET. The headsets are considered unclassified when unplugged and must be unplugged when not in use within classified spaces or when classified discussions are taking place in unclassified spaces. |
| 6.8.1 | Government-procured Bluetooth earbuds and headsets that do not require a USB dongle or any other physical connection to enable wireless connectivity are allowed for use on Government-issued tablets, phones, and personal devices in telework environments or unclassified general office space where no classified discussions are occurring. |
| 6.8.2 | Web cameras may only be used on systems at the classification level of the space. For example, in a collateral SECRET open storage area an external web camera may be commented to the SECRET workstation only. No camera pass is required for these devices. |
| 6.8.3 | Government-provided printers and/or scanners are authorized in a telework environment. Users must ensure that any paper or media containing controlled unclassified information (CUI) or unclassified information not authorized for public release is safeguarded by locking it in a drawer, cabinet, or room. CUI and unclassified information not approved for public release must be returned to the worksite for destruction. |
| 6.8.4 | Government-issued peripherals may be used on personal devices. |
| 6.8.5 | While connected to any Navy network, whether on-site or while in a telework environment, the use of headsets with microphones and web cameras is restricted to official Government duties. |
| 6.9 | Contractor personnel shall follow OPSEC concepts and principles in the conduct of this requirement to protect critical information, personnel, facilities, equipment, and operations from compromise. All Contractors (including SubContractors) shall supplement their current security practices by requiring any personnel involved in executing this contract to complete Government-sponsored and administered Operations Security (OPSEC) training. In addition, all Contractors should be aware of the Critical Information and Indicators List (CIIL) for the organization they are supporting as well as the OPSEC plan for NSWCDD. These OPSEC requirements will be in effect throughout the life of the procurement from award through the conclusion of services at the end of the period of performance (PoP) or other procurement termination. The Contractor must immediately notify the Government upon the discovery of any nonconformance with the OPSEC Plan. |
| 6.10 | Privacy training is mandatory for all NSWCDD personnel (military, civilian, and Contractor) and must be completed annually. Total Workforce Management Services (Contractors) and Waypoints (Federal Employees) is the official database for workforce training and is the tool for taking and recording Privacy Act training. The Contractor is responsible for ensuring individual annual privacy training requirements are met. |
| 6.11 | The Contractor and NSWCDD key personnel should ensure that classified documents, recordings, audiovisual material, notes, and other materials created, distributed, or used during the conference are controlled, safeguarded, and transported as required. |
| 6.11.1 | The Contractor is responsible for providing access control to the conference area through visual recognition or identification. If appropriate, the conference proponent will request the conference facility to provide supplemental security personnel (e.g., military security forces, Contractor guard force). |
| 6.11.2 | Announcement of the classified conference should be unclassified and limited to a general description of topics expected to be presented, names of speakers, logistical information, and administrative and security instructions. |
| 6.11.3 | The Contractor and NSWCDD key personnel shall conduct an “End of day” security check to ensure no unsecured classified material remains in the conference area. All classified material will be stored in a GSA-approved security container. |
| 6.12 | The Contractor shall select a meeting space that limits the number of entrances to the area. Ensure the doors are locked or entry is prohibited. |
| 6.12.1 | The Contractor shall validate that the materials to be discussed cannot be heard by unauthorized persons in adjoining halls or rooms. |
| 6.12.2 | The Contractor shall ensure that visual aids cannot be observed in areas outside the meeting area. This includes shading of windows/doors, etc. |
| 6.12.3 | The Contractor shall ensure that a cleared employee monitors the entrance to the meeting area so only those individuals on the access list enter the meeting area. |
| 6.12.4 | The Contractor shall validate the attendee's identify by visually checking their CAC prior to them entering the classified meeting area. |
| 6.13 | The Contractor and NSWCDD key personnel will ensure that the highest level of classified information to be discussed, the classification authority, and other special security considerations are announced at the beginning of the meeting and after each break via an opening statement or use of a visual indicator. |
| 6.13.1 | The Contractor and NSWCDD key personnel will ensure that security announcements are made concerning the use of escorts, breaks, lunch, or other non-meeting occurrences, marking of classified notes, the taking of unclassified or classified notes, and disposal of classified waste. Also, caution attendees not to discuss classified materials in the hallways or other unauthorized areas. |
| 6.13.2 | The Contractor and NSWCDD key personnel will notify attendees that no audio, video, or photographic recording devices or cellular telephones are authorized at the meeting. |
| 6.13.3 | The Contractor and NSWCDD key personnel will ensure that during breaks or adjournment for meals, all classified materials are secured or that a cleared employee with a need-to-know remains in the meeting area to control entry and access. Safeguard all classified notes, minutes, summaries, recordings, and proceedings during scheduled breaks. |
| 6.13.4 | The Contractor and NSWCDD key personnel will identify all attendees upon reentry from breaks, etc. Ensure that all classified notes, minutes, summaries, or recordings are properly marked and safeguarded as required by the National Industrial Security Program Operation Manual (NISPOM). |
| 6.13.5 | The Contractor and NSWCDD key personnel will ensure all meeting participants understand reporting requirements if security incidents happen during the meeting. |
| 6.14 | The Contractor and NSWCDD key personnel shall ensure that all classified material; i.e. notes, minutes, summaries, recordings, and classified waste have been removed from the conference/meeting area and properly secured. |
| 6.14.1 | The Contractor and NSWCDD key personnel do not permit attendees to hand-carry classified notes outside the facility without proper authorization to courier classified material. |
| 6.14.2 | The Contractor and NSWCDD key personnel shall ensure that classified material is sent in accordance with the NISPOM and only to those cleared attendees whose facilities have an approved classified safeguard capability and have demonstrated the need to know to retain the materials. |
| 6.14.3 | The Contractor and NSWCDD key personnel will review the classified meeting process and report any lessons learned to the Facility Security Officer. |
| 6.15 | Foreign National Visit Expectations: Contract performance may require that the Contractor host, at an off-base location, foreign nationals and/or foreign representatives. A foreign national is a person who is a citizen of a foreign nation, and who is not a citizen of the United States. A foreign representative is a person who represents a foreign interest in dealings with the U.S. Government, either directly or through dealings with a U.S. Government Contractor. A foreign representative may be a United States citizen. |
| 6.15.1 | A Contractor-hosted visit of a foreign national or foreign representative may be either an “official” visit or an “unofficial” visit. An official visit is a visit where the foreign national or foreign representative is representing a foreign Government in an official capacity. An unofficial visit is a visit where the foreign national or foreign representative is not representing a foreign Government. |
| 6.15.2 | A visit by a foreign national or a foreign representative may be either “DoD Sponsored” or “Non-DoD Sponsored”. A DoD-sponsored visit is a visit that is coordinated by a DoD entity. A Non-DoD Sponsored visit is a visit that does not involve DoD coordination (A visit by either a foreign national or a foreign representative pursuant to performance by the Contractor under this contract is not considered to be, by itself, a sponsored visit). |
| 6.15.3 | The Contractor hosting a visit by either a foreign national or a foreign representative is responsible for adherence to DoD and DoN directives, instructions, regulations, and manuals that govern foreign disclosure. “Foreign Disclosure” is defined as the disclosure of Classified Military Information (CMI) and Controlled Unclassified Information (CUI) to foreign nationals and/or foreign representatives. Disclosure of such information may be accomplished orally, visually, in writing, or by any other medium. |
| 6.15.4 | Classified Military Information (CMI). This is information that is originated by or for the Department of Defense, or a Military Department, or an entity under its jurisdiction and control, and which requires protection in the interest of national security. Such information is designated up to SECRET. |
| 6.15.5 | Controlled Unclassified Information (CUI). This is information that although unclassified is subject to access or distribution limitations in accordance with statute or regulation. Included is information exempt from mandatory release to the public under the Freedom of Information Act, or information that is subject to export control. |
| 6.15.6 | NSWCDD Foreign National Visitor and Foreign Disclosure Application Process. NSWCDD has established a foreign national visitor approval and foreign disclosure process. Whenever, pursuant to the terms of this contract, a visit to a Contractor facility or Contractor workspace by a foreign national or foreign representative is anticipated, and one or more NSWCDD employees will be in attendance at this visit/meeting for the purpose of potential discussions, above the public release level, resulting in disclosure of either CMI or CUI, a completed “NSWCDD Foreign National Visitor and Foreign Disclosure Application” e-form must be supplied to the Contractor’s Facility Security Officer (FSO). The accountable NSWCDD personnel attending the meeting must ensure that the NSWCDD disclosure process has been complied with and an approved copy of the “NSWCDD Foreign National Visitor and Foreign Disclosure Application” generated e-form has been provided to the COR and the Contractor’s FSO. The Contractor’s FSO should ensure that approved copies of the e-form are maintained at their facility as a record of compliance with requirements outlined in the 32 CFR Part 117 as well as the requirements set forth above. |
| 6.15.7 | Attendance of foreign nationals must comply with the requirements of DoD Directive 5230.20 and DoD Directive 5230.11. Assurance is obtained, in writing, from the responsible U.S. Government foreign disclosure office(s) that the information to be presented has been cleared for foreign disclosure. Coordination efforts should be given 120 days’ lead time prior to the conference date to ensure completion. |
| 6.15.8 | The Contractor shall submit completed clearance packages within ten (10) calendar days or identification of any increased security requirements. |
| 6.15.9 | The Contractor shall be familiar with the 32 CFR Park 117, National Industry Security Program Manual (NISPOM). Specific to the protection of classified information. |
| 6.16 | Any meeting where classified and up to the secret level of information that is disseminated will inherently pose risks. Some of those risks can be foreseen and some cannot. It is critical for the Contractor and NSWCDD key personnel to be prepared to address those risks. |
| 6.16.1 | During a classified meeting or secret-level conference, focusing on executing the security plan in the areas of physical, personnel, and information security will help you be more prepared. It is recommended that the Contractor Security lead and NSWCDD key personnel shall ensure the following are accomplished: |
| 6.16.2 | Personnel Security: Verify clearance level and need-to-know access for all meeting participants. |
| 6.16.3 | Information Security: Ensure a General Services Administration (GSA) approved security container is in place for safeguarding classified information. |
| 6.16.4 | Classified information is protected from inadvertent disclosure by the use of cover sheets and media labels. |
| 6.16.5 | Contractor and NSWCDD key personnel staff are conducting security oversight and following end-of-the-day check procedures. |
| 6.16.6 | Contractor and NSWCDD key personnel provide continuous security education to presenters and attendees on handling classified information throughout the meeting or conference. |
| 6.16.7 | As a security official in charge of a classified meeting or conference, you must be mindful of attempts to gain information through unauthorized access or unauthorized disclosure. There could be potential elicitation of attendees in the form of outsiders trying to find out what is going on through casual conversation, or an unauthorized individual with a listening device, or someone milling about at the end of the meeting looking for notes or handouts that have been left behind. |
| 6.16.8 | Employing countermeasures, such as verifying clearance and need-to-know, patrolling internal and external perimeters, using secure information systems, and restricting note-taking/electronic recording reduces the risk of unauthorized access and unauthorized disclosure |
| 6.17 | Restricted Data is not a level of classification; rather a document can be classified as Confidential, Secret, or Top Secret, while also containing “restricted data.” In addition, a document containing Restricted Data could also contain Critical Nuclear Weapon Design Information. Therefore, the Contractor shall take security measures to protect data. |
| 6.17.1 | Controlled Unclassified Information (CUI) must be stored or handled in controlled environments that prevent or detect unauthorized access. |
| 6.17.2 | Computer Networks that the Contractor is required to ensure safety protocols are in place. The Secret Internet Protocol Router Network (SIPRNet) is a system of interconnected computer networks used by the U.S. Department of Defense and the U.S. Department of State to transmit classified information (up to and including information classified as Secret) by packet switching over a completely secure network. |
| 6.18 | The Contractor shall require access to Communications Security (COMSEC) information, which includes accountable or non-accountable information or CCI. The Contractor shall require a COMSEC account for usage of classified VTC equipment and associated keying material. |
| 6.19 | The Contractor shall require access to Restricted Data (RD) and Critical Nuclear Weapon Design Information (CNWDI) in association with classified meetings held at their facility. |
| 6.20 | Access is required to Controlled Unclassified Information (CUI) and Personally Identifiable Information (PII) generated and/or provided, which shall be safeguarded and marked as specified in DoDI 5200.48 and 5400.7-R Chapters 3 and 4. |
| 7.0 | TECHNICAL POINT OF CONTACT |