Appendix B - Industrial Contract Language_FSDS.pdf
PDF 157 KB Posted
- Attached to
- NTIA FSDS - Sources Sought Synopsis Notice Federal contract opportunity
- Solicitation number
- NTIA0000-23-00500-2
About this file
This document outlines security requirements and procedures for a classified federal contract requiring access to national security information. The contract involves providing cleared contractors with access to non-SCI collateral confidential and secret information as well as controlled unclassified information. Contractors must possess and maintain a final secret facility security clearance and meet secret safeguarding requirements. The contract stipulates personnel clearance levels, security training obligations, reporting procedures for adverse information and security incidents, and processes for discontinued employee access. The performance location includes Department of Commerce and other government facilities as well as cleared contractor sites.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| NTIA FSDS PM Q_A Vendor Attendance List.pdf | ||
| NTIA FSDS PM Q_A Questions and Answers.pdf | ||
| NTIA FSDS PM Q_A Session_Transcript_2023-11-06_FINAL.pdf | ||
| NTIA FSDS PM Q_A Brief-11062023.pdf | ||
| NTIA FSDS - Source Sought Synopsis Notice.pdf | ||
| Appendix A Statement of Need.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Appendix B
Standardized Security Language
For
Access to Classified Information
GENERAL:
Performance of this contract requires access Classified National Security Information (CNSI)
(includes documents and material) and Controlled Unclassified Information (CUI). Classified information is Government information which requires protection in accordance with Executive
Order 13526, Classified National Security Information as amended and supplemental directives.
CUI is sensitive unclassified information generally not authorized for release to the public governed by Executive Order 13556, Controlled Unclassified Information.
The Contractor shall abide by the requirements set forth in the DD Form 254, Contract Security
Classification Specification, an attachment to the contract, and the National Industrial Security
Program Operating Manual (NISPOM)/32 CFR Part 117 for the protection of CNSI and CUI at authorized contract and government facilities based upon the Facility Clearance Level (FCL) granted by the Defense Counterintelligence and Security Agency (DCSA). When the Contractor is required to have access to CNSI and CUI at a Department of Commerce (DOC) or other
Government Facility, it shall abide by the requirements set forth by the respective agency(s).
SECURITY REQUIREMENTS:
• Required FCL: The contract company supporting this contract/task order must possess and retain an active and Final FCL SECRET granted by DCSA from the time of proposal and throughout the performance period.
• Unclassified description summary of performance.
CLEARED CONTRACTORS WILL REQUIRE ACCESS TO
• Non-SCI (Collateral – CONFIDENTIAL, SECRET)
• Controlled Unclassified Information (CUI)
IN THE PERFORMANCE OF THIS CONTRACT, THE CONTRACTOR WILL
• Have access to classified information only at another cleared Contractor’s facility or other government activity
• Operation Security (OPSEC) Requirements (Always applicable)
• Receive, store, or generate CUI
Add the following to PLACE(S) OF PERFORMANECE SECTION:
• Department of Commerce and other Government activity location(s)
• Contractor facilities o When place of performance is at a contractor facility, the complete address is required to be identified in the DD-254.
• Identify the SCI level(s) of access (When Applicable)
• Non-SCI (Collateral – CONFIDENTIAL, SECRET)
• Identify Facility Clearance Level and when required the Safeguarding Level.
Note: Do not include the physical address, SCIF ID Number, Room Number and SCI Access
Levels, as the compilation of information will cause the security classification level to elevate from
CUI to the CNSI SECRET Level.
REQUIRED SECURITY CLAUSES FOR CLASSIFIED CONTRACTS:
The following sets forth basic policies and general information found in the Federal Acquisition
Regulations (FAR). The FAR prescribes administrative procedures for safeguarding information within industry and the specific, required clauses that must be written on classified contracts:
Part One: Subpart 4.4—Safeguarding Classified Information Within Industry and Part Two: FAR
52.204-2 Security Clause Requirements.
ADD APPLICABLE SECURITY CLAUSES:
FAR 52.204-2 Security Requirements
FAR 52.225-19 Contractor Personnel in a Designated Operational Area or
Supporting a Diplomatic or Consular Mission Outside the United
States
SAFEGUARDING CLASSIFIED INFORMATION:
Required Safeguarding Level: The contract company supporting this classified contract/task order must meet the requirements for safeguarding classified information against unauthorized disclosure commensurate with its level of classification. SECRET, when classified information is required to be accessed at the designated contractor facility (s).
PERSONNEL CLEARANCE LEVEL (PCL):
Identify the specific Personnel Clearance Level (s) required (i.e.: Number of contractor employees and clearance (final or interim)/access levels required, position description SECRET.
Number of contractors employees to be determined on award.
CONTINUED ELIGIBILITY:
DOC reserves the right to deny and/or restrict entrance to government facilities, prohibit employees from assigned work under the contract, deny and/or restrict handling of classified documents/material to any Contractor employee who DOC determines to present a risk of compromising classified and/or sensitive government information. The DOC Security Office may require drug screening at any time for probable cause and/or when the Contractor independently identifies circumstances where probable cause exists.
Initial and Annual Training for Clearance Holders
Classified contractors shall participate in initial and annual formal training sessions identifying the requirements associated with the proper safeguarding of classified information, which access is granted. This training includes Initial and Annual Derivative Classification and Marking and
Annual NSI Security Clearance Holder Training.
Adverse action reporting
The contract company must report any adverse information coming to their attention concerning contractors performing services on a DOC contract. All reporting criteria as listed in Security
Executive Agent Directive 3 shall be reported to osy_industrialsecurity@doc.gov.
ACCESS TO COMMERCE ENTERPRISE SECURE MISSION NETWORK OR
SECURE INTERNET PROTOCOL ROUTER NETWORK AT THE
CONTRACTOR’S LOCATION:
Contractors accessing the Commerce Enterprise Secure Mission Network (CESMN) or Secure
Internet Protocol Router Network (SIPRNet) at their location must have an approve certification of space and system by DOC prior to contract performance. DOC shall retain responsibilities for certification of the SIPRNet system and accreditation of designated space at contractor facility.
• Not required for this FSDS requirement
The contractor shall comply with all applicable security classification guidance. The contractor shall derivatively classify newly created information associated with this effort based on the classification guidance provided through existing classified sources.
SENSITIVE COMPARTMENTED INFORMATION FACILITY (SCIF):
A room (s), or building accredited to store, use, discuss, or electronically process SCI. The standards and procedures for a SCIF are stated in Intelligence Community Directive (ICD) 705.
WHEN A SCIF IS AT THE CONTRACTOR LOCATION:
Contract performance and access to classified information and/or equipment is restricted to
(Enter company name (s), addresses(s) CAGE Code (s) DCSA cognizant security office, DOC, other Government Controlled Facilities). The contractor (Enter Company Name) Facility
Security Officer (FSO) on file with DCSA is: (Enter name and phone number of cognizant contractors FSO). If this information is not correct, the contractor must contact the DCSA Field
Office identified in Block 6, and update contractor information as applicable.
CO-UTILIZATION/JOINT UTILIZATION AGREEMENT IS APPLICABLE
WHEN:
SCI will be accessed from a non-DOC accredited SCIF a Co-Use Agreement/Joint-Use
Agreement will be required to be initiated and approved prior to the start of contract performance. No SCI activities will occur at the contractor location until the facility has been accredited by DOC or a co-utilization agreement is made between DOC and the other government accrediting authority.
COMPLIANCE REVIEW
mailto:osy_industrialsecurity@doc.gov
A report shall be provided to OSY_IndustrialSecurity@doc.gov annually including a complete list of active contractors and/or consultants performing work on the contract. To include clearance levels, training completion dates and certificates of training.
SECURITY INCIDENTS REPORTING
Security Incidents involving contractors, grantees, licensees, and other personnel falling under the purview of the NISP are required to report the security incident to the FSO and
OSY_IndustrialSecurity@doc.gov. All DOC contract personnel provided access to classified information, facilities, and systems shall:
a. Protect classified information from unauthorized disclosure.
b. Report security incidents involving the unauthorized and or mishandling of classified information.
This includes while working onsite at a DOC/Bureau, Other Government Agency locations or contractor facility(s).
DISCONTINUED ACCESS (RESIGNATION/TERMINATION/DEATH)
The COR shall be notified of all resignations/terminations/deaths of contractors within two (2) business days of occurrence. The Contractor shall return to the COR all DOC issued identification cards, building passes and equipment when no longer providing contract support to DOC/Bureau.
The contract FSO will assist in the facilitation of the timely return and notification of contractors, who are no longer providing contract support to DOC/Bureau as soon as known. If an identification card or building pass is not available to be returned, an incident report shall be submitted to the
COR, referencing the pass or card number, name of individual to whom issued and the last known location and disposition of the ID Card or building pass.
mailto:OSY_IndustrialSecurity@doc.gov mailto:OSY_IndustrialSecurity@doc.gov
File details come from the government source that posted it. Updated .