04_DD_254_3_Aug_16_as_posted.pdf
PDF 555 KB Posted
- Attached to
- EELV Phase 1A GPS III Launch Services (FA8811-16-R-0006) Federal contract opportunity
- Solicitation number
- 16-084
About this file
04 DD254
View the file
Other files for this federal contract opportunity
Show all 26
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
FA8811-16-R-0006 DD Form 254
Appendix A
(8) Actual Performance
CCAFS Department of the Air Force 45th Information Protection Office (45 SW/IP)
CCAFS
1201 Edward White II Street Patrick AFB, FL 32925-2221
CONTINUATION – DD FORM 254
Contract # FA8811-16-R-0006
(10a) Communications Security (COMSEC) Information The contractor shall forward COMSEC Information requests to the COMSEC officer through the EELV Program Security Manager (SMC/LEE). COMSEC Information shall not be released to DoD contractors without Air Force Cryptological Support Center (AFCSC) approval. The contractor is governed by DODM 5220.22, National Industrial Security Program Operating Manual. For accounts established by the National Security Agency (NSA) Committee on National Security Systems (CNSS) Policy No. 3, National Policy for Granting Access to U.S.
Classified Cryptographic Information applies. When accounts are established by the Air Force both CNSSP No. 3 and AFMAN 33-283, Communications Security (COMSEC) Operations apply. Access to COMSEC is outlined in AFMAN 33-283.
(10e(2)) Intelligence Information (non-SCI) The contractor shall be required to receive, generate, and store Intelligence Information (non- SCI) up to and including SECRET. Classified information shall be handled, marked, protected, reproduced, destroyed, and transmitted in accordance with the requirements stipulated in the NISPOM and applicable Air Force Instructions/Regulations required for on-base operations.
Flow-down requirements to subcontractor facilities are at the SECRET level.
(10j) Controlled Unclassified Information / For Official Use Only (FOUO) Controlled Unclassified Information (CUI) is now the term which collectively refers to FOUO and Unclassified Controlled Nuclear Information (UCNI). Guidance for CUI identification and protection is contained in DODM 5200.01, Volume 4, DoD Information Security Program:
Controlled Unclassified Information (CUI).
(11c) Receive and Generate Classified Material The contractor shall be required to receive, generate, and store classified information up to and including SECRET. Classified information shall be handled, marked, protected, reproduced, destroyed, and transmitted in accordance with the requirements stipulated in the NISPOM and applicable Air Force Instructions/Regulations required for on-base operations. Flow-down requirements to subcontractor facilities are at the SECRET level.
(11d) Fabricate, Modify or Store Classified Hardware The contractor shall provide adequate storage for classified hardware at the appropriate level of classification.
(11g) Use of the Defense Technical Information Center (DTIC) The contractor is authorized to use the services of the Defense Technical Information Center (DTIC) and shall process a DD Form 1540 and register with the Defense Logistics Service by processing a DD Form 2345 in accordance with the NISPOM, if required.
(11h) Require a COMSEC Account The contractor must have a COMSEC account. The contractor is governed by DoDI 8523.01, Communications Security (COMSEC), NSA and Air Force COMSEC requirements. When accounts are established by the National Security Agency (NSA) Committee on National Security Systems (CNSS) Policy No. 3, National Policy for Granting Access to U.S. Classified Cryptographic Information applies. When accounts are established by the Air Force both CNSSP No. 3 and AFMAN 33-283 apply. COMSEC Access requirements are outlined in
AFMAN 33-283. Personnel requiring COMSEC access shall be briefed IAW DODM 5220.22, CNSSP No. 3, and AFMAN 33-283 Section 6.3. DD FORM 254 (13 CON’T.), MAY 2010
(11j) Operation Security (OPSEC) The contractor shall comply with and implement the policy and processes outlined in the EELV OPSEC plan. The contractor shall protect sensitive unclassified information and activities, which could compromise classified information or operations or degrade the planning and execution of military operations performed by the contractor in support of the EELV mission. Disposition of Critical Information, FOUO, and Privacy Act (PA)/PII obtained or produced pursuant to this contract shall be shredded/degaussed to prevent reconstruction. Email transmission of Critical Information, FOUO, and PA/PII obtained or produced pursuant to this contract shall be encrypted or password protected. In addition, email containing FOUO and PA/PII shall be marked in the subject line (FOUO) or (PA). FOUO shall also be included at the beginning of the email with a non-disclosure statement.
(11k) Use of Defense Courier Service The contractor is authorized use of the Defense Courier Service for the transmission of classified information and/or materials.
(11l) Other Security of Unclassified DoD Information on Non-DoD Information Systems
The Contractor must implement security for DoD information as specified in DoDI 8582.01, Security of Unclassified DoD Information on Non-DoD Information Systems. CNSSP No. 18, National Policy on Classified Information Spillage, Chairman of The Joint Chiefs of Staff Instruction (CJCSI) 6510.01, Information Assurance and support to Computer Network Defense
(CND) .
The Contractor shall immediately (within 24 hours) notify the EELV Program Security Manager (SMC/LEE) of any instance of a network security breach involving the unauthorized access of DoD Information.
Definitions:
Non-Sensitive Information -- Information available in the public domain or DoD Information that has been approved for public release
Sensitive Information -- Information, the loss, misuse, or unauthorized access to or modification of, could adversely affect the national interest or the conduct of Federal programs, or the privacy to which individuals are entitled under Section 552a of title 5, United States Code, "The Privacy Act" but which has not been specifically authorized under criteria established by Executive order or an Act of Congress to be kept secret in the interest of national defense or foreign policy.
(Section 278g-3 of title 15, United States Code, “The Computer Security Act of 1987"). The Contractor must implement security for DoD information as specified in DoDI 8582.01, Security of Unclassified DoD Information on Non-DoD Information Systems. CNSSP No. 18, National Policy on Classified Information Spillage, Chairman of The Joint Chiefs of Staff Instruction (CJCSI) 6510.01, Information Assurance and support to Computer Network Defense (CND).
Visitor Group Security Agreement (VGSA) For activities at the Air Force installations identified in ITEM 8, the Contractor may be required by the host agency to enter into a VGSA in accordance with Air Force Instruction 31-601, Industrial Security. The VGSA is executed with the Contractor who requires or will have access to classified information or to sensitive unclassified information. The VGSA must address those security requirements and/or procedures that are unique to the installation for which the contractor shall be held contractually liable. VGSAs need only address those areas of security, safeguarding and/or protection that have not been covered elsewhere within the contract, DD Form 254, Statement of Work, Statement of Objectives, Performance-based Work Statement, etc.
Cybersecurity requirements:
The terms Cybersecurity, Information Systems, and Information Technology, as used in this clause, are defined in Committee on National Security Systems Instruction No. 4009.
Cybersecurity is explained in DODI 8500.01, Cybersecurity and is incorporated herein by reference.
Information systems (IS) shall be engineered and managed to protect and defend information and information systems from security risks, including the risks to timely authorization in accordance with current DoD policies, procedures, and statutes, to include:
The National Security Act The Clinger-Cohen Act Committee on National Security Systems Policy No. 11 National Institute on Standards and Technology Special Publications Federal Information Processing Standards DoD Instruction 8500.01, Cybersecurity
Cybersecurity requirements shall be established and maintained throughout the acquisition lifecycle in accordance with DODI 8580.1. All DoD information systems shall meet security requirements in accordance with DoDI 8500.01, and be authorized by the Authorization Official (AO) prior and during operation.
Prior to classified processing, the contractor will ensure the IS complies with the NISPOM, Chapter 8 and meets the confidentiality, integrity, authentication, non-repudiation and availability requirements as identified in the Defense Security Service (DSS) Industrial Security Field Operations (ISFO) Process Manual for Certification and Accreditation of Classified Systems under the NISPOM.
Security Incident Reporting:
In addition to the reporting requirements directed by the NISPOM, the contractor will provide a concurrent report of loss or compromise of classified information to the cognizant Government Contracting Activity (GCA) Information System Security Manager (ISSM) and Authorization Official (AO).
Export Control Requirements
Technology Transfer and Information Control and Arms Export Control: By law, the U.S.
Government and contractors must comply with the provisions of the International Traffic in Arms Regulations (ITAR) and the Arms Control Act before exporting defense articles, technical data, or defense services controlled by the ITAR. All such information intended for public release, or disclosure to any foreign person or U.S. person residing in a foreign country shall be submitted to SMC/ENP Foreign Disclosure Office (FDO), through the appropriate Foreign Disclosure Focal Point (FDFP), for potential technology transfer and suitability for the release of technical information. Visits by a Foreign Person and/or U.S. Person acting as a Representative of a Foreign Interest to facilities shall comply with applicable visit notifications, information access and escorting requirements. The exchange of classified Foreign Government Information is not permitted by this contract, ref. 10.h. of this specification.
(14) Additional Security Requirements Personnel Security All contractor personnel performing on this contract and permanently assigned to EELV launch site must be a U.S. Person, as defined by the International Traffic In Arms Regulations, and must be in process for or possess a favorable National Agency Check Inquiry (NAC-I), an equivalent determination approval as indicated in the Air Force Space Command Supplement to Air Force Instruction (AFI) 31-101, paragraph 7.2.1.1, or higher government security clearance, in accordance with AFI 31-501: Personnel Security Program Management or the NISPOM. This is also applicable to Subcontractor and Contractor personnel who are visiting or on a temporary duty assignment at the launch site. This requirement is for personnel who have or may need access to launch site restricted or controlled areas containing EELV Space Launch Systems and/or Information Systems which directly affect a launch system.
File details come from the government source that posted it. Updated .