Attachment J-4 Draft DD254.pdf

PDF 103 KB Posted

Attached to
Department of Homeland Security (DHS) Data Center and Cloud Optimization (DCCO) Support Services Federal contract opportunity
Solicitation number
70RTAC20R00000013
Issued by
Department of Homeland Security Office of Procurement Operations

About this file

This document contains a DD Form 254, which is a Department of Defense Contract Security Classification Specification. It specifies security requirements for a contract to provide contractor support for the operation, maintenance, automation, optimization, and modernization of the Department of Homeland Security's hybrid computing environment and other tasks. The contractor will require access to classified information up to the Secret level, including communications security information, intelligence information, and limited dissemination information. The contractor must have facilities cleared for Secret work and properly trained personnel with Secret clearances. The contract performance location is various government locations within the greater Washington D.C. metropolitan area. The DD Form 254 provides detailed classification guidance and requirements for marking, handling, and safeguarding all classified information associated with the contract.

The related federal contract opportunity notice announces the planned release of a solicitation for Data Center and Cloud Optimization Support Services under the DHS EAGLE Next Generation Program. The scope includes continuing and optimizing existing data center services, assisting with migration from other DHS data centers to cloud providers or colocation sites, and purchasing and managing both cloud and colocation services. An industry day is scheduled for March 2020, with a draft RFP planned for release in May 2020.

View the file

Other files for this federal contract opportunity

Other files attached to Department of Homeland Security (DHS) Data Center and Cloud Optimization (DCCO) Support Services, newest first.
File Type Posted
Attachment J-2 Draft PWS.pdf PDF
DCCO Draft Final Request for Proposal.pdf PDF
Attachment Draft J-1 Pricing Schedule.xlsx XLSX spreadsheet
FINAL DRAFT Request for Proposal Feedback Template.xlsx XLSX spreadsheet
Attachment J-3 Draft QASP.pdf PDF
DHS_DCCO_Industry_Day_II_Presentation_September 10 2020 FINAL .pdf PDF
DCCO Industry Day II Audio.mp4 MP4 file
Draft - Performance Work Statement .pdf PDF
DRAFT Section B - Supplies or Service and Price.pdf PDF
Draft CLIN Structure.pdf PDF
Attachment II - DRAFT Solicitation Feedback Template.xlsx XLSX spreadsheet
Draft Evaluation Factors .pdf PDF
DCCO Industry Day Recording.mp4 MP4 file
DCCO Industry Day Presentation - Question and Answers .pdf PDF
DHS DCCO Industry Day Presentation March 2020.pdf PDF
Attachment I - Questions and Topics of Discussion Template.xlsx XLSX spreadsheet
DHS DCCO Support Services - Executive Summary - Objectives and Scope.pdf PDF
Show all 17

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DEPARTMENT OF DEFENSE

CONTRACT SECURITY CLASSIFICATION SPECIFICATION

(The requirements of the DoD Industrial Security Manual apply to all security aspects of this effort.)

1. AND SAFEGUARDING

a. CLEARANCE REQUIRED

b. LEVEL OF SAFEGUARDING REQUIRED

2. IS FOR: (X and complete as applicable)

a. CONTRACT NUMBER

b. SUBCONTRACT NUMBER

c. DUE DATE (YYYYMMDD)

3. IS: (X and complete as applicable)

a. (Complete date in all cases)

REVISION NO.

c. (Complete Item 5 in all cases)

DATE (YYYYMMDD)

b. REVISED (Supersedes all previous specs)

DATE (YYYYMMDD)

DATE (YYYYMMDD)

4. THIS A FOLLOW-ON CONTRACT? YES NO. Yes, complete the following:

Classified material received or generated under (Preceding Contract Number) is transferred to this follow-on contract.

5. THIS A FINAL DD FORM 254? YES NO. Yes, complete the following:

In response to the contractor's request dated , retention of the classified material is authorized for the period of

6. (Include Commercial and Government Entity (CAGE) Code)

a. ADDRESS, AND ZIP CODE b. CAGE CODE c. SECURITY OFFICE (Name, Address, and Zip Code)

7.

a. ADDRESS, AND ZIP CODE b. CAGE CODE c. SECURITY OFFICE (Name, Address, and Zip Code)

8. PERFORMANCE

a. b. CAGE CODE c. SECURITY OFFICE (Name, Address, and Zip Code)

9. IDENTIFICATION OF THIS PROCUREMENT

10. CONTRACTOR WILL REQUIRE ACCESS TO: 11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL:YES NO YES NO

a. COMMUNICATIONS SECURITY (COMSEC) INFORMATION

b. RESTRICTED DATA

c. CRITICAL NUCLEAR WEAPON DESIGN INFORMATION

d. FORMERLY RESTRICTED DATA

e. INTELLIGENCE INFORMATION

(1) Sensitive Compartmented Information (SCI)

(2) Non-SCI f.

g. NATO INFORMATION

h. FOREIGN GOVERNMENT INFORMATION

i. LIMITED DISSEMINATION INFORMATION

j. FOR OFFICIAL USE ONLY INFORMATION

k. (Specify)

a. HAVE ACCESS TO CLASSIFIED INFORMATION ONLY AT ANOTHER

CONTRACTOR'S FACILITY OR A GOVERNMENT ACTIVITY

b. RECEIVE CLASSIFIED DOCUMENTS ONLY

c. RECEIVE AND GENERATE CLASSIFIED MATERIAL

d. FABRICATE, MODIFY, OR STORE CLASSIFIED HARDWARE

e. PERFORM SERVICES ONLY

f. ACCESS TO U.S. CLASSIFIED INFORMATION OUTSIDE THE U.S., PUERTO RICO, U.S. POSSESSIONS AND TRUST TERRITORIES

g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE TECHNICAL INFORMATION

CENTER (DTIC) OR OTHER SECONDARY DISTRIBUTION CENTER

h. REQUIRE A COMSEC ACCOUNT

i. HAVE TEMPEST REQUIREMENTS

j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS

k. BE AUTHORIZED TO USE THE DEFENSE COURIER SERVICE

l. (Specify)

CLEARANCE

FACILITY

THIS SPECIFICATION

PRIME

SOLICITATION OR OTHER NUMBER

THIS SPECIFICATION

ORIGINAL

FINAL

IS If

IS If

CONTRACTOR

NAME, COGNIZANT

SUBCONTRACTOR

NAME, COGNIZANT

ACTUAL

LOCATION COGNIZANT

GENERAL

SPECIAL ACCESS INFORMATION

OTHER

HAVE

OTHER

DD FORM 254, DEC 1999 PREVIOUS EDITION IS OBSOLETE.

Top Secret

Top Secret

✘ 70RTAC20R00000013 20201016

✘ 20201016

TBD

(U) PROVIDE CONTRACTOR SUPPORT FOR THE OPERATION, MANTENANCE, AUTOMATION, OPTIMIZATION, AND MODERNIZATION OF THE DEPARTMENT OF HOMELAND SECURITY HYBRID COMPUTING ENVIRONMENT

AND OTHER TASKS IN THE SOW.

Reset

TBD TBD

Patricia.Atkins Cross-Out

12. RELEASE. Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the Industrial Security Manual or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for approval prior to release a.

Direct Through (Specify)

d. ADDRESS (Include Zip Code)

Yes No to the Directorate for Freedom of Information and Security Review, Office of the Assistant Secretary of Defense (Public Affairs)* for review.

*In the case of non-DoD User Agencies, requests for disclosure shall be submitted to that agency.

13. The security classifiection guidance needed for this classified effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract;

and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended. (Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. Add additional pages as needed to provide complete guidance.)

14. Requirements, in addition to ISM requirements, are established for this contract.

(If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the cognizant security office. Use Item 13 if additional space is needed.)

Yes No15. Elements of this contract are outside the inspection responsibility of the cognizant security office.

(If Yes, explain and identify specific areas or elements carved out and the activity responsible for inspections. Use Item 13 if additional space is needed.)

16. CERTIFICATION AND SIGNATURE. Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. questions shall be referred to the official named below.

b. TITLE c. (Include Area Code) e.

17. DISTRIBUTION

a. CONTRACTOR

b. SUBCONTRACTOR

c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR

d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION

e. ADMINISTRATIVE CONTRACTING OFFICER f.

PUBLIC

TYPED NAME OF CERTIFYING OFFICIAL

SECURITY GUIDANCE.

ADDITIONAL SECURITY REQUIREMENTS.

INSPECTIONS.

All

TELEPHONE

SIGNATURE

REQUIRED

OTHERS AS NECESSARY

DD FORM 254 (BACK), DEC 1999

None Authorized UNLESS CONTRACTOR HAS OBTAINED AUTHORITY TO RELEASE FROM THE DEPARTMENT OF HOMELAND SECURITY: CONTRACTOR SHALL COORDINATE WITH THE COR AND THE OFFICE OF THE CHIEF

SECURITY OFFICER (OCSO) NATIONAL SECURITY DIVISION (NSSD) @

DHSHQ.INDUSTRIALSECURITY2@HQ.DHS.GOV ON ALL CHANGES TO THIS GUIDANCE

Reference Item 10a: “Contractor is authorized to use U.S. Government cryptographic equipment. Access to classified COMSEC information requires a final U.S. Government clearance at the appropriate level. Further disclosure of COMSEC information by a contractor, to include subcontracting, requires prior approval of the contracting activity. If the contractor must receive or take custody of accountable COMSEC material at its facility, it must have a COMSEC account. The NSA Central Office of Record has primary responsibility for the auditing of all COMSEC material governed by the DoD 5220.22-M. Contractor shall contact the DHS COMSEC Control Office of Record (COR), at Commercial (540) 542-3292 to receive current COMSEC guidance.”

Reference Item 10e (1)(2) Personnel: “All contractor personnel assigned to this contract shall possess security clearances issued by the Defense Security Service (DCSA) commensurate with the level of required access to classified information that is directly in support of this contract. Immigrant aliens, personnel cleared on an interim basis, or personnel holding contractor-generated Confidential clearances are not eligible for access to classified information released or generated under this contract. Contractor personnel who are specifically designated as requiring access to Sensitive Compartmented Information (SCI) must be eligible under the provisions of the Intelligence Community Directive (ICD) 704 without exception. Personnel will be submitted for access by their DHS manager and verified by their Contract Technical Representative. If approved for access, they will receive an indoctrination briefing by DHS security staff prior to being granted access to SCI. All personnel security reporting requirements of the ICD 704 will be made directly to the DHS SSO. Prior to leaving this contract, personnel will be scheduled for debriefing with the DHS SSO or by calling (202) 447-3033.”

See Addendum.

Item 14: (If Items 10e(1)(2) are selected use this language): “Access to intelligence information requires a special briefing and a final US Government clearance at the appropriate level for access. Foreign nationals are prohibited from access to any classified information. SCI requirement will be authorized by DHS upon contract award. All personnel assigned by the contractor for SCI access must meet Intelligence Community Directive (ICD) 704 eligibility requirements. Subcontracting requires prior approval of the GCA.”

“DHS has exclusive security responsibility for all SCI classified material released to or developed under this Contract/Task Order.

Defense Counterintelligence and Security Agency (DCSA) is relieved of security inspections responsibility for all such material.

DCSA retains oversight/inspection responsibilities for facility clearance requirements and collateral information outside of DHS facilities.”

Patricia M. Atkins Security Specialist

DHS HQ 301 7th St. SW Washington, District of Columbia 20528

202 447-5493

Reference Item 10e (1)(2) and 11c: “No SCI activities will occur at the contractor location until the facility has been accredited by DHS or a co-utilization agreement is made between DHS and the current facility Government accrediting authority, either must be in place at the time of award. DHS accreditation of an SCI Facility must be requested via the DHS Office of the Chief Security Officer, Physical Security Division, Security Projects Branch at HQSecurityProjects@HQ.DHS.GOV. The request for accreditation will include a concept of operations (CONOPS) which describes the operational requirement, facility description, and security oversight. Upon approval of the CONOPS, a fixed facility checklist, and Standard Operating Procedures will be submitted for review and approval. Co-utilization agreement will be requested by the contractor to the current accrediting authority and coordinated with DHS/OCSO. A copy of the approved co-utilization agreement will be provided to DHS/OCSO/SSPD prior to SCI activities occurring at the contractor location. DHS will inspect all SCI Facilities accredited by DHS, security policies and procedures, and all material generated or processed under the purview of this contract:

a. All SCI will be handled in accordance with special security requirements, which will be furnished by the designated responsible special security offices (SSO).

b. SCI will not be released to contractor employees without specific release approval of the originator of the material as outlined in governing directives; based on prior approval and certification of "need-to-know" by the designated contractor.

c. All Contractor personnel requiring access to SCI as part of this contract effort must be approved and indoctrinated by DHS. Requests for

Access will be submitted by the government project manager who can validate the justification for access.

d. Inquiries pertaining to classification guidance on SCI will be directed to the SSO.

e. SCI furnished in support of this contract remains the property of the Department of Homeland Security (DHS), agency, or component originator. Upon completion or cancellation of the contract, SCI furnished will be returned to the direct custody of the supporting SSO or destroyed IAW instructions outlined by the Contract Officer.

f. Visits by contractor employees will only be certified by DHS when such visits are conducted as part of the contract effort.

g. SCI will be stored and maintained only in properly accredited facilities at the contractor location (See note on 11c. above).

h. All contractor requests to process SCI electronically will be sent to the accrediting SSO for coordination through appropriate SCI channels.”

Reference Item 10j: “The Contractor is responsible for handling and marking FOUO information in accordance with DHS Directive (MD

11042.1) "Safeguarding Sensitive but Unclassified (For Official Use Only) Information," dated January 6, 2005; Furthermore, contractors must sign a special Non-Disclosure Agreement before receiving access to unclassified FOUO information. Contractors with questions on handling

DHS FOUO shall contact DHS OCSO NSSD at DHSHQ.INDUSTRIALSECURITY2@HQ.DHS.GOV.”

Reference Item 11c & 11d: “The contractor shall derivatively classify newly created information associated with this effort based on the classification guidance provided through existing classified sources. All classified information shall be marked in accordance with the

NISPOM. The ISOO Pamphlet on “Marking Classified National Security Information dated Revision 3, August 2016” may be used as a guide on the proper marking of classified information. Questions relating to Marking Classified National Security Information can be addressed to

DHS Office of the Chief Security Officer National Security Services Division, at DHSHQ.INDUSTRIALSECURITY2@HQ.DHS.GOV.”

Reference Item 11h: “All contractors receiving COMSEC material will have an established COMSEC account generated by the GCA. Security procedures and requirements of the COMSEC Annex to the NISPOM(CANISPOM) apply. The contractor shall verify that COMSEC clearance was approved and established by DHS, by contacting the DHS COMSEC Control Office of Records, at Commercial (540) 542-3292. The contractor shall request COMSEC guidance and verify that a copy of the CANISPOM was requested on their behalf form NSA. Accounts are not required when a contract involves only non-accountable information.”

CONTINUATION SHEET FOR BLOCK #13 Page: 1 DD Form 254, Classification Guidance to contract # issued to:-

COMPANY NAME/CAGE CODE: DHS HQ/

Reference Item 11i: TEMPEST. “The contractor will be required upon award of the contract to ensure compliance with amplifying DHS guidance and applicable ICDs. The contractor must have TEMPEST requirements I accordance to DHS-Certified TEMPEST Technical Authority (DHSCTTA) guidance and DHS 42300B, National Security Systems Handbook. For further interpretation and specifics for TEMPEST requirements, contact the DHS CTTA office at (202) 447-4464.”

Reference Item 11k: “The contracting activity Designated Security Officer (DSO) is responsible for requesting DCS services from the

Commander, Defense Courier Service, ATTN: Operations Division, Fort George G. Meade, Maryland, 207550-5370. In all cases of subcontracting the DSO approval is required before a contractor can authorize another contractor to use DCS services. ”

NOTE: Contract performance is restricted to the Department of Homeland Security (DHS) (TBD) various government locations within the greater Washington, DC metropolitan area and (add any other specific locations identified in the award/SOW). All contractor personnel must: be U.S. citizens, have been granted a final security clearance by the U.S. Government (Interim Secret clearances are accepted by

DHS), have been approved as meeting criteria by DHS OCSO, and have been indoctrinated by a Non Disclosure Agreement, Standard Form

312 for this specific program prior to being given any access to such information released or generated under this contract. Immigrant aliens, personnel cleared on an interim basis, or personnel holding contractor granted CONFIDENTIAL clearances, are not eligible for access to classified information released or generated under this contract. Classified material released or generated under this contract is not releasable to foreign nationals without the expressed written permission of the OCSO. Recipients of classified information under this contract may not be released to subcontractors without permission of the DHS OCSO. The contractor and COR will revalidate all billets under this contract with the OCSO annually or when a revised DD Form 254 is issued, whichever is sooner."

This contract and its related attachments may impose strict security requirements for need-to-know access, special handling procedures, physical security measures, and administrative controls beyond those prescribed for collateral Department of Homeland Security (DHS) information. The provisions delineated in DoD 5220.22M, Department of Homeland Security Directives, applicable Intelligence Community

Directives, and applicable Security Classification Guides are strictly enforced. This DD254 shall not be made accessible to persons without a valid need-to-know.

The contractor is responsible for returning all classified information (documents and other media) to the sponsoring DHS Component in accordance with the sponsoring DHS Component security directive. Furthermore, DHS contractors must end all work and performance associated with this effort based on the classification guidance provided through existing classified sources. Questions relating to handling, marking, and safeguarding Classified National Security Information can be addressed to the DHS Office of the Chief Security Officer, National Security Services Division, at DHSHQ.INDUSTRIALSECURITY2@HQ.DHS.GOV.

Insider Threat training for Contractors can be found at: https://securityawareness.usalearning.gov/itawareness/index.htm Certificate of training is required for all cleared contractors who are working with classified information. All certificates must be sent to the DHS Training

Office at: securitytraining@hq.dhs.gov and the DHS Contracting Officer Representative, before the Contractor or Subcontractor is granted access to classified information. All cleared contractor personnel are required to recertify Insider Threat training annually thereafter.

CONTINUATION SHEET FOR BLOCK #13 Page: 2 DD Form 254, Classification Guidance to contract # issued to:-

COMPANY NAME/CAGE CODE: DHS HQ/

File details come from the government source that posted it. Updated .