Appendix B - Industrial Contract Language_FSDS.pdf

PDF 157 KB Posted

Attached to
NTIA FSDS - Sources Sought Synopsis Notice Federal contract opportunity
Solicitation number
NTIA0000-23-00500-2
Issued by
Department of Commerce Office of the Secretary

About this file

This document outlines security requirements and procedures for a classified federal contract requiring access to national security information. The contract involves providing cleared contractors with access to non-SCI collateral confidential and secret information as well as controlled unclassified information. Contractors must possess and maintain a final secret facility security clearance and meet secret safeguarding requirements. The contract stipulates personnel clearance levels, security training obligations, reporting procedures for adverse information and security incidents, and processes for discontinued employee access. The performance location includes Department of Commerce and other government facilities as well as cleared contractor sites.

View the file

Other files for this federal contract opportunity

Other files attached to NTIA FSDS - Sources Sought Synopsis Notice, newest first.
File Type Posted
NTIA FSDS PM Q_A Vendor Attendance List.pdf PDF
NTIA FSDS PM Q_A Questions and Answers.pdf PDF
NTIA FSDS PM Q_A Session_Transcript_2023-11-06_FINAL.pdf PDF
NTIA FSDS PM Q_A Brief-11062023.pdf PDF
NTIA FSDS - Source Sought Synopsis Notice.pdf PDF
Appendix A Statement of Need.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Appendix B

Standardized Security Language

For

Access to Classified Information

GENERAL:

Performance of this contract requires access Classified National Security Information (CNSI)

(includes documents and material) and Controlled Unclassified Information (CUI). Classified information is Government information which requires protection in accordance with Executive

Order 13526, Classified National Security Information as amended and supplemental directives.

CUI is sensitive unclassified information generally not authorized for release to the public governed by Executive Order 13556, Controlled Unclassified Information.

The Contractor shall abide by the requirements set forth in the DD Form 254, Contract Security

Classification Specification, an attachment to the contract, and the National Industrial Security

Program Operating Manual (NISPOM)/32 CFR Part 117 for the protection of CNSI and CUI at authorized contract and government facilities based upon the Facility Clearance Level (FCL) granted by the Defense Counterintelligence and Security Agency (DCSA). When the Contractor is required to have access to CNSI and CUI at a Department of Commerce (DOC) or other

Government Facility, it shall abide by the requirements set forth by the respective agency(s).

SECURITY REQUIREMENTS:

• Required FCL: The contract company supporting this contract/task order must possess and retain an active and Final FCL SECRET granted by DCSA from the time of proposal and throughout the performance period.

• Unclassified description summary of performance.

CLEARED CONTRACTORS WILL REQUIRE ACCESS TO

• Non-SCI (Collateral – CONFIDENTIAL, SECRET)

• Controlled Unclassified Information (CUI)

IN THE PERFORMANCE OF THIS CONTRACT, THE CONTRACTOR WILL

• Have access to classified information only at another cleared Contractor’s facility or other government activity

• Operation Security (OPSEC) Requirements (Always applicable)

• Receive, store, or generate CUI

Add the following to PLACE(S) OF PERFORMANECE SECTION:

• Department of Commerce and other Government activity location(s)

• Contractor facilities o When place of performance is at a contractor facility, the complete address is required to be identified in the DD-254.

• Identify the SCI level(s) of access (When Applicable)

• Non-SCI (Collateral – CONFIDENTIAL, SECRET)

• Identify Facility Clearance Level and when required the Safeguarding Level.

Note: Do not include the physical address, SCIF ID Number, Room Number and SCI Access

Levels, as the compilation of information will cause the security classification level to elevate from

CUI to the CNSI SECRET Level.

REQUIRED SECURITY CLAUSES FOR CLASSIFIED CONTRACTS:

The following sets forth basic policies and general information found in the Federal Acquisition

Regulations (FAR). The FAR prescribes administrative procedures for safeguarding information within industry and the specific, required clauses that must be written on classified contracts:

Part One: Subpart 4.4—Safeguarding Classified Information Within Industry and Part Two: FAR

52.204-2 Security Clause Requirements.

ADD APPLICABLE SECURITY CLAUSES:

FAR 52.204-2 Security Requirements

FAR 52.225-19 Contractor Personnel in a Designated Operational Area or

Supporting a Diplomatic or Consular Mission Outside the United

States

SAFEGUARDING CLASSIFIED INFORMATION:

Required Safeguarding Level: The contract company supporting this classified contract/task order must meet the requirements for safeguarding classified information against unauthorized disclosure commensurate with its level of classification. SECRET, when classified information is required to be accessed at the designated contractor facility (s).

PERSONNEL CLEARANCE LEVEL (PCL):

Identify the specific Personnel Clearance Level (s) required (i.e.: Number of contractor employees and clearance (final or interim)/access levels required, position description SECRET.

Number of contractors employees to be determined on award.

CONTINUED ELIGIBILITY:

DOC reserves the right to deny and/or restrict entrance to government facilities, prohibit employees from assigned work under the contract, deny and/or restrict handling of classified documents/material to any Contractor employee who DOC determines to present a risk of compromising classified and/or sensitive government information. The DOC Security Office may require drug screening at any time for probable cause and/or when the Contractor independently identifies circumstances where probable cause exists.

Initial and Annual Training for Clearance Holders

Classified contractors shall participate in initial and annual formal training sessions identifying the requirements associated with the proper safeguarding of classified information, which access is granted. This training includes Initial and Annual Derivative Classification and Marking and

Annual NSI Security Clearance Holder Training.

Adverse action reporting

The contract company must report any adverse information coming to their attention concerning contractors performing services on a DOC contract. All reporting criteria as listed in Security

Executive Agent Directive 3 shall be reported to osy_industrialsecurity@doc.gov.

ACCESS TO COMMERCE ENTERPRISE SECURE MISSION NETWORK OR

SECURE INTERNET PROTOCOL ROUTER NETWORK AT THE

CONTRACTOR’S LOCATION:

Contractors accessing the Commerce Enterprise Secure Mission Network (CESMN) or Secure

Internet Protocol Router Network (SIPRNet) at their location must have an approve certification of space and system by DOC prior to contract performance. DOC shall retain responsibilities for certification of the SIPRNet system and accreditation of designated space at contractor facility.

• Not required for this FSDS requirement

The contractor shall comply with all applicable security classification guidance. The contractor shall derivatively classify newly created information associated with this effort based on the classification guidance provided through existing classified sources.

SENSITIVE COMPARTMENTED INFORMATION FACILITY (SCIF):

A room (s), or building accredited to store, use, discuss, or electronically process SCI. The standards and procedures for a SCIF are stated in Intelligence Community Directive (ICD) 705.

WHEN A SCIF IS AT THE CONTRACTOR LOCATION:

Contract performance and access to classified information and/or equipment is restricted to

(Enter company name (s), addresses(s) CAGE Code (s) DCSA cognizant security office, DOC, other Government Controlled Facilities). The contractor (Enter Company Name) Facility

Security Officer (FSO) on file with DCSA is: (Enter name and phone number of cognizant contractors FSO). If this information is not correct, the contractor must contact the DCSA Field

Office identified in Block 6, and update contractor information as applicable.

CO-UTILIZATION/JOINT UTILIZATION AGREEMENT IS APPLICABLE

WHEN:

SCI will be accessed from a non-DOC accredited SCIF a Co-Use Agreement/Joint-Use

Agreement will be required to be initiated and approved prior to the start of contract performance. No SCI activities will occur at the contractor location until the facility has been accredited by DOC or a co-utilization agreement is made between DOC and the other government accrediting authority.

COMPLIANCE REVIEW

mailto:osy_industrialsecurity@doc.gov

A report shall be provided to OSY_IndustrialSecurity@doc.gov annually including a complete list of active contractors and/or consultants performing work on the contract. To include clearance levels, training completion dates and certificates of training.

SECURITY INCIDENTS REPORTING

Security Incidents involving contractors, grantees, licensees, and other personnel falling under the purview of the NISP are required to report the security incident to the FSO and

OSY_IndustrialSecurity@doc.gov. All DOC contract personnel provided access to classified information, facilities, and systems shall:

a. Protect classified information from unauthorized disclosure.

b. Report security incidents involving the unauthorized and or mishandling of classified information.

This includes while working onsite at a DOC/Bureau, Other Government Agency locations or contractor facility(s).

DISCONTINUED ACCESS (RESIGNATION/TERMINATION/DEATH)

The COR shall be notified of all resignations/terminations/deaths of contractors within two (2) business days of occurrence. The Contractor shall return to the COR all DOC issued identification cards, building passes and equipment when no longer providing contract support to DOC/Bureau.

The contract FSO will assist in the facilitation of the timely return and notification of contractors, who are no longer providing contract support to DOC/Bureau as soon as known. If an identification card or building pass is not available to be returned, an incident report shall be submitted to the

COR, referencing the pass or card number, name of individual to whom issued and the last known location and disposition of the ID Card or building pass.

mailto:OSY_IndustrialSecurity@doc.gov mailto:OSY_IndustrialSecurity@doc.gov

File details come from the government source that posted it. Updated .