Attach 5a PARCS DRAFT DD254 Continutation Sheet.docx
DOCX document 51 KB Posted
- Attached to
- Perimeter Acquisition Radar Attack Characterization System (PARCS) Operations, Maintenance, and Support (OM&S) Services Federal contract opportunity
- Solicitation number
- FA2518-21-R-0024
About this file
This document package includes a DD Form 254 and related attachments outlining security requirements for a federal contract opportunity to provide operations, maintenance, and support services for the Perimeter Acquisition Radar Attack Characterization System at Cavalier Air Force Station in North Dakota.
The contractor shall operate, maintain, and support the PARCS radar system and associated mission computer systems on a continuous 24/7 basis. Services include management of radar and computer maintenance, civil engineering support, security, logistics, and sensitive and non-sensitive communications support. The contractor must have personnel with appropriate security clearances to handle classified materials up to the Secret level and access to Sensitive Compartmented Information as defined in the document attachments. The physical security requirements, operations security protocols, and communications security controls that the contractor must follow are extensively delineated in the provided attachments.
This is a requirements document outlining the security parameters for a potential follow-on contract solicitation for PARCS support services currently performed by the incumbent contractor. The related opportunity posting provides additional context regarding the scope of operations, maintenance, and support services required under the forthcoming solicitation.
View the file
Other files for this federal contract opportunity
Show all 21
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
| PARCS DD254 | FA2518-21-R-0024 | |
| Rev NN |
Continuation of Block 10.
Ref 10.a. COMSEC material/information may not be released to DoD contractors without Air Force Cryptological Support Center (AFSCS) approval. Contractor must forward requests for COMSEC material/information to the COMSEC Officer through the program office. The contractor is governed by DoD 5220.22-5 COMSEC Supplement to the NISPOM in the control and protection of COMSEC material/information. Access to COMSEC material by personnel is restricted to US citizens holding final US Government clearances. Such information is not releasable to personnel holding only reciprocal clearances.
Ref. 10.j. Controlled Unclassified Information (CUI) information provided under this contract shall be safeguarded as specified in DoDM 5200.01, Vol 4, “DoD Information Security Program: Controlled Unclassified Information (CUI).”
Continuation of Block 11.
Ref. 11.a. Contract performance is restricted to Cavalier AFS, North Dakota. Using activity will provide security classification guidance for performance of this contract. The following Security Classification Guides (SCG) and subsequent revisions/changes apply to this contract:
a. SPACETRACK Surveillance and Warning Systems 496L, 1 Jan 90, OPR: HQ AFSPC/DOS, Peterson AFB, CO 80914-5000.
b. System Operational Protection Guide (SOPG) for the Ground-Based Radar Missile Warning System, 1 Sep 03, OPR: HQ AFSPC/DOS, Peterson AFB, CO 80914-5000.
c. Space Surveillance Network, 1 May 91, OPR: HQ AFSPC/J3S, Peterson AFB, CO 80914-5000
Ref 11.d. Contractors are expected to maintain TS COMSEC materials (at Cavalier SFS) and are charged with the maintenance and configuration of TS devices. Per PWS 1.5.14.1
Ref 11.e. From the DD254 Guide: "Contract is for equipment maintenance services on equipment which processes classified information. Actual knowledge of, generation, or production of classified information is not required for performance of the contract. Cleared personnel are required to perform this service because access to classified information cannot be precluded by escorting personnel." Contractors are expected to provide/maintain equipment from the JWICS Point of Presence to the Government owned equipment in the SCIF. Routine Facility maintenance of the SCIF is also required PWS 1.5.14
Ref. 11g. The Contractor must prepare and process a DD Form 1540 and 1541 for request to utilize the Defense Technical Information Center (DTIC). Reference the NIS11g. The Contractor must prepare and process a DD Form 1540 and 1541 for request to utilize the Defense Technical Information Center (DTIC). Reference the NISPOM for preparation and processing of these forms.
Ref. 11i. See Emission Security (EMSEC) requirements in Attachment 1, “EMISSION SECURITY ASSESSMENT REQUEST (ESAR) FOR ALL CLASSIFIED SYSTEMS”.
Ref. 11j. See Operations Security (OPSEC) requirements in Attachment 2.
Ref.11k.
COMSEC material shipped to the site comes through the Defense Courier Service (DCS).
Ref. 11.m. Provide the information required by FAR contract clauses 52.204-2, 52.204-9000 and 52.204-9001 to the Information Security Program Manager (ISPM). Computer security (COMPUSEC): Tasks outlined in Performance Work Statement (PWS), Chapter 5, paragraph 5.5.2. (inclusive).
Computer security (COMPUSEC): Tasks outlined in Performance Work Statement (PWS), Chapter 5, paragraph 5.5.2.2.
Continuation of Block 13.
· Ref. 10a: If the contractor is authorized to receive Government furnished cryptographic equipment, the guidance will state that fact. Access to classified COMSEC information requires a final U.S. Government clearance at the appropriate level. Further disclosure of COMSEC information by a contractor, to include subcontracting, requires approval of the GCA. Non-accountable COMSEC information, though not tracked in the COMSEC material control system, may still require a level of control within a document control system. Refer to NSA/CSS Manual 3-16, “Control of Communications Security Material,” and the Committee on National Security Systems Instruction (CNSSI) 4001, “Controlled Cryptographic Items,” for guidance. If access to COMSEC information is required at Government facilities, or the material is under Government control, contractor personnel will follow the security requirements of the host government activity.
· Ref 10j: DoD Components; refer to DoDM 5200.01, Volume 4, “DoD Information Security Program: Controlled Unclassified Information (CUI),” available at http://www.esd.whs.mil/DD/DoD-Issuances/ , when considering protection for CUI. Non-DoD Components must consult with their Component specific information security policy office to determine if they have any existing authority by law, government-wide policy or government- wide regulation to impose this requirement.
· DD MMM YY (TBD). This date reflects, among other things, when the SCI indoctrinated contractor personnel will be debriefed.
· The SCIF at Cavalier AFS will be used to perform SCI contractual requirements.
· The following documents with subsequent revisions or changes will be used for specific security classification guidance on this contract.
· DoD 5105.21M Volumes 1, 2, and 3.
· AFMAN 14-304, Signals Intelligence Security Regulation and Imagery Policy Series.
· Inquiries pertaining to classification guidance on SCI will be directed to the Contract Monitor.
· SCI data furnished to or generated by the contractor will require security handling and controls beyond those in the National Industrial Security Program Operating Manual (NISPOM). These supplemental instructions will be furnished and/or made available to the contractor thru the Contract Monitor by the User Agency Special Security Office, SSO USSF.
· Names of contractor personnel requiring access to SCI will be submitted to the SCI Contract Monitor. Forms requesting Special Background Investigations will be prepared in accordance with the NISPOM and submitted to Defense Security Service (DSS).
· The contractor will establish and maintain a current access list of those employees working on this contract. A copy of this list will be furnished to the SCI Contract Monitor.
· The contractor will advise the SCI Contract Monitor immediately upon reassignment of personnel to other duties not associated with this contract.
· Release of Information. SCI with restrictive caveats (e.g., ORCON, PROPIN, etc.) will be released to contractors only when originator approval has been obtained. The contractor will control SCI, which has been originated or obtained under this contract as follows: The contractor may release such material to any contractor employee working against a billet under this contract only when a need-to-know exists. The contractor will release such material to any Special Security Office personnel assigned to HQ USSF or DIA upon demand by such personnel. The contractor may release such material to any other personnel, including contractor and subcontractor employees, and employees of any Federal Government agency, only upon prior written approval from the SCI Contract Monitor. An access certification to an AFSPC contractor-occupied SCIF does not constitute approval to release USSF contractual material to these other personnel; Contract Monitor approval is nevertheless required. Contract Monitor approval of an USSF contractor visit certification or permanent certification to another facility will constitute approval to discuss contractual material at facility to be visited.
· Any SCI released to the contractor in support of this contract remains the property of DOD department, agency, or command that releases it. The contractor will maintain active accountability of all SCI released to his/her custody, regardless of whether the release is within a contractor or US Government SCIF. Upon completion/cancellation of the contract, the contractor must return all such material to SSO AFSPC unless a follow-on contract specifies that the material will be transferred to a subsequent contract. SCI inventories will be conducted IAW DoD 5105.21M Vol 1/2/3 and AFMAN 14-304.
· This contract requires use of the Defense Courier system. SSO USSF will validate Defense Courier Service requirements.
· Electronic processing of classified information is permitted only when the requirements of AFMAN 14-304 have been met as determined by an accredited TEMPEST authority. This contract requires electronic processing of SCI. TEMPEST accreditation of ADPS must be obtained IAW the above reference. Operational accreditation of ADPS using software must be obtained IAW DoD 5105.21M Vol 1/2/3 and AFMAN 14-304. Security provisions of DoD 5105.21M Vol 1/2/3 and AFMAN 14-304 also apply and are part of this contract. The CSSO will appoint an Information Systems Security Officer (ISSO) and advise SSO USSF of this appointment.
· Contractor Special Security Officers (CSSOs) must coordinate with the SCI Contract Monitor and obtain the concurrence of SSO USSF prior to subcontracting any portion of SCI efforts involved in this contract.
· No contractor personnel will be granted access to SCI material under this contract unless they are filling a DOD SCI billet. The contractor will coordinate with SCI Contract Monitor to ensure adequate billets are requested under this contract. Multiple contract employees sponsored by the organizations other than Space Command must be certified to SSO USSF for use on the contract.
· The contractor will designate a Special Security Point of Contact (POC) to SSO USSF. The POC will be responsible for all personnel and information security transactions between the contractor and SSO USSF.
· Contractor will not use references to SCI accesses, even by unclassified acronyms, in advertising, promotional efforts, or recruitment for employees.
· The following activity is designated as the User Agency SS for SCI requirements IAW DoD 5105.21M Vol 1/2/3; HQ USSF/A2S, Peterson AFB CO 80914-4311.
Continuation of Block 14.
1. This contract requires access to Sensitive Compartmented Information (SCI). Per (list applicable DoD publications, ICDs, DCIDs, DoDM 5105.21, Volumes 1,2 3 and AFMAN 14-401, Joint DoDISS Cryptologic SCI Information Systems Standards (JDCSISSS), NISPOM Supplement, etc.) provides the necessary guidance for physical, personnel, information and information systems security measures and is part of the SCI security specifications for the contract.
Executive Order 12333 -United States Intelligence Activities (AMMENDED by EO 13470, 2008)
Executive Order 13526 - Classified National Security Information (29 Dec 09) {replaced EO 12958}
ICD 503 - Information Systems
ICD and ICPGs 704 - Personnel Security
ICD and ICS/Tech Specs 705 - Physical Security
DCID 1/20P - Security Policy Concerning Travel and Assignment of Personnel with Access to SCI
DCID 6/1 - Security Policy for Sensitive Compartmented Information and Security Policy
DCID 6/9 - Physical Security (for facilities accredited under 6/9 standards)
DoDM 5105.21 V1, V2, V3 - SCI Administrative Security Manual(s)
DoDM 5200.01 V1, V2, V3, V4 -DoD Information Security
DoDM 5200.02 - Procedures for the DoD Personnel Security Program (PSP)
DoDM 5220.22 Volume 2 -National Industrial Security Program (NISP)
AFMAN 14-304 - Security, Use and Dissemination of SCI AFMAN 16-1405 -Air Force Personnel Security Program
AFI 16-1404 - Air Force Information Security Program
AFI 16-1406 -Air Force Industrial Security Program
DIAM 50-4 - Defense Intelligence Agency Manual
NISPOM Supplement
NIST 800-53 Rev 4
2. Name, organization, telephone number and address of the Contract Officer Representative (COR) for the SCI portion of this contract is:
TSgt James Estep, 10 SWS/SF, 701-993-3266
3. All DD Form 254s prepared for subcontracts involving access to SCI under this contract must be forwarded to the COR for approval and then to USSF SSO for review and concurrence prior to award of the contract. Inquiries pertaining to classification guidance on SCI will be directed to the COR listed in para. 2 above. SCI security management issues shall be directed to USSF SSO, 150 Vandenberg St., Ste 1105, Peterson SFB, CO. 80914, DSN: 692-2402, Comm: (719) 554-2402.
4. SCI access is subject to U.S. Government review and approval as outlined in the aforementioned SCI security guidance. Upon completion or cancellation of the contract, the SSO/CSSO will debrief all personnel not required for contract closeout and those positions will be disestablished.
5. Names of contractor personnel requiring access to SCI and justification for SCI access will be submitted for coordination and action to USSF SSO, Peterson AFB after the COR's approval/concurrence. Upon receipt of written approval from the COR, the Facility Security Officer (FSO) and/or Contractor Special Security Officer (CSSO) may submit the necessary forms to the Defense Security Service (DSS) for a Single Scope Background Investigation (SSBI) for those personnel nominated for SCI in accordance with the National Industrial Security Program Operating Manual (NISPOM).
6. The SSO/CSSO can grant access to only those who possess the necessary security clearance and who are actually providing services under the contract. Further dissemination to other contractors, sub-contractors, other government agencies, private individuals or organizations is prohibited unless authorized in writing by the releasing agency.
| 7. | SCI materials furnished in support of this contract remains the property of the DoD department or command that released it. Upon completion or cancellation of the contract, all SCI materials furnished will be returned to the direct custody of the originator of the materials. |
| 8. | Classified foreign intelligence materials must not be released to foreign nationals or immigrant aliens whether or not they are also consultants, U.S. contractors, or employees of the contractor |
regardless of the level of their security clearance, except with advance written permission from the originator.
9. Contractor personnel must maintain accountability for all intelligence (to include foreign intelligence) materials released to their custody.
10. Contractor personnel must not reproduce classified foreign intelligence without advance approval of the releasing agency. If permission is granted, each copy will be controlled in the same manner as the original. The CSSO must not destroy any classified foreign intelligence without advance approval of the releasing agency.
11. A SCIF meeting the physical security requirements in DCID 619 or ICD 705 is required for this contracting effort. All SCI used for this contract shall be stored, handled, and maintained in an accredited SCIF, be it the local contractor SCIF or similarly SCI accredited facilities used by the contractor. Address of the SCIF for contract execution:
• 10 SWS, 830 Patrol Road, Bldg. #830, Cavalier SFS, ND, and 58220.
• TSgt Quesenberry Jason, 10 SWS/SF, 701-993-3204, TSgt Bradley Wiegel, 10 SWS/SF, 701-993-3299, and Jacqueline Wilson 318-294-6484.
12. Visits. The contractor will submit the written request for SCI visit certifications through the COR for approval of the visit. The certification must arrive at USSF SSO at least three working days prior to the visit.
13. Information assurance and electronic processing; information security (computer) and network connectivity require accreditation of the equipment connectivity.
Specified by unit directives: the contractor shall execute a Visitor Group Security Agreement (VGSA) with the government.
Note 1. The use of automated information systems for processing and producing classified information at Cavalier Air Force Station, North Dakota, is required. Computer security requirements of AFSPC Policy for Accrediting Standalone Personal Computers and Workstations, 1 Jul 94; AFSPC Policy for Accrediting Critical Automated Information Systems, 1 Jul 93 and AFSPCR 56-3, Accreditation for Small or Non-Critical Systems, 22 May 92 apply.
Note 2. The contractor shall comply with security and law enforcement policies and procedures in effect on government installations where contractor performance occurs under this contract. The contract will be performed within USAF restricted areas on Cavalier AFS, ND. At Cavalier AFS, ND, contractor employees must be subject of a National Agency Check or already have been issued a final or interim secret clearance for the purpose of access to classified information before being permitted unescorted entry to these restricted areas. Contractor employees not meeting the prerequisite for unescorted entry shall be under the continuous escort by other cleared contractor employees while in restricted areas.
Note 3. The contractor shall provide a visit request in accordance with DoD 5220.22-R, Section III, Para 1, to the Commander, 10 SWS to permit unescorted entry to USAF restricted areas and/or access to classified information while on the installation (see AFI 31-101, para 9.2 and DoD 5220.22-M, National Industrial Security Program (NISPOM)), Feb 2006.
Note 4. When performance involves classified information on a military installation where the contractor does not possess a facility clearance for that location, the contractor operation is considered a “visitor group” on the installation. As such, the contractor’s security procedures shall be integrated with those of the installation. The contractor shall enter into a security agreement (or understanding) with the responsible military commander(s) to formalize:
1. Those security actions which will be performed for the contractor by the installation, such as providing storage and classified reproduction facilities; guard services; security forms; security inspection under DoD 5220.22-M, classified mail services; security badging; visitor control; and investigation security incidents and;
2. Those security actions for which joint action may be required, such as packaging and addressing classified transmittals, security checks, internal security controls and implanting emergency procedures to protect classified materials.
Note 5. To ensure National security interests are protected by confirmed security support and identifying security procedures unique to the installation, the visitor group contractor visitor security agreement is developed by the Security Service Agency (SSA) and signed by the installation commander.
Note 6. If after reviewing the security agreement and discussing it with the military commander or representative, the contractor believes there may be a cost impact, the contractor will notify the contracting officer in writing. The contracting officer will work closely with the FSO toward an appropriate solution.
Note 7. The VGSA, when signed by the contractor’s security manager and site commander, may suffice in lieu of a Standard Practice Procedure for group visitor contractor performance on a military installation.
Note 8. See DoDM 5200.01, Volume 1, for marking guidance regarding classified information.
Continuation of Block 15.
This contract requires access to SCI. If the contractor has established a SCIF, DIA and its designees are responsib1e for all inspections of the contractor SCIF and SCI security management program for ensuring compliance with all SCI security regulations and policies. If a new SCIF must be established in accordance with this contracting effort, permission to build/accredit a SCIF must be requested through the COR and forwarded to the USSF SSO. Special Security Officers reserve the right to conduct program reviews of AF SCI materials and SCI program management to ensure the protection of AF equities.
The prime contractor is responsible for preparing DD Form 254s for SCI access of their subcontractors. Completed subcontractor DD 254s are provided to the supporting SSO for review and validation. Validation consists of ensuring SCI security requirements mirror that of the Prime Contractor's DD 254. All attachments and addendums should be part of the subcontractor's DD 254 as well. Supporting SSO will submit the reviewed and validated DD 254 to the MAJCOM SSO (listed on the Prime Contract) for approval.
DSS is relieved of inspection responsibility for all classified material that is released to or developed by the contractor while on a military installation. DSS retains inspection responsibility for all non-SCI classified material released to or developed by the contractor and held in the contractors’ facility. The SSO maintains inspection responsibility for all SCI material related to this contract. Local Information Protection security program assessments while operating on an Air Force installation, shall be conducted by the IPO. HQ AFSPC/IN retains security cognizance of all Intelligence materials released to the contractor.
The contract effort will be performed on an Air Force installation. The host security force on the installation is responsible for Industrial security supervision and inspections of the contractor to ensure contractor compliance with DOD 5220.22-M, National Industrial Security Program (NISPOM), Feb 2006.
Continuation of Block 18.
Reference 18f. Required Distribution, Others as necessary: Coordination: Director, Defense Courier Service.
Signature:
| Name: |
| BRET A. DURYEE, GS-12 |
| Name: |
| SHAWN M. THOMPSON, TSgt, USAF |
| Title: |
| PARCS Program Manager |
| Title: |
| Information Security Program Manager |
| Office symbol: |
| 21SW/PMD, Peterson AFB, CO |
| Office symbol: |
| 10 SWS/SFS |
Cavalier AFS, North Dakota
| Name: |
| STEPHEN HEMINGTON, GS-12 |
| Name: |
| KEVIN D. HORNER, 2d Lt, USAF |
| Title: |
| Industrial Security Prgm Manager |
| Title: |
| COMSEC Responsible Officer |
| Office symbol: |
| 319 ABW/IP, Grand Forks AFB, ND |
| Office symbol: |
| 10 SWS/SFS |
Cavalier AFS, North Dakota
| Name: |
| DANYAL DRISCOLL, GS-12 |
| Title: |
| Chief, Information/Industrial Security |
| Office symbol: |
| AFSPC SSO, Peterson AFB, CO |
Attachment 1
EMISSIONS SECURITY (EMSEC) REQUIREMENTS
EMISSIONS SECURITY ASSESSMENT REQUEST (ESAR)
FOR ALL CLASSIFIED SYSTEMS
REF. TO ITEM 11i OF DD FORM 254
The contractor shall ensure that compromising emanations (EMSEC) conditions related to this contract are minimized.
The contractor shall provide countermeasures assessment data to the Contracting Officer (CO), in the form of an Emissions Security Assessment Request (ESAR). The ESAR shall provide only specific responses to the data required in paragraph c, below. The contractor’s standard security plan shall NOT be used as a “stand alone” ESAR response. The contractor shall NOT submit a detailed facility analysis/assessment. The ESAR information will be used to complete an EMSEC Countermeasures Assessment Review of the contractor’s facility to be performed by the government EMSEC authority using current Air Force EMSEC directives. EMSEC is applied on a case-by-case basis and further information may be required to complete the review; should this be the case the contractor shall provide this information to the contracting officer when requested. After the evaluation of the ESAR by the government EMSEC authority, additional EMSEC requirements may be necessary.
*ESAR contents shall include, as minimum, the following information (NISPOM), para 11 101c):
1. The specific classification and special categories of material to be processed/handled by electronic means.
2. The percentage of information being processed. Identify the approximate percentage for each level of information processed including unclassified.
3. The specific location where classified processing will be performed.
4. The name, address, title and telephone number of a point of contact at the facility where processing will occur.
NOTE: Once the above information has been provided to the CO, no further reporting is required for equipment reconfigurations. However, if the facility is physically relocated to another geographical location, the information requested in paragraph “c” above MUST be furnished to the CO.
The prime contractor shall ensure that all subcontractors and/or vendors comply with EMSEC requirements when performing classified processing related to this contract. They will provide the above documentation trough their prime to the contracting officer to complete the ESAR.
*NOTE: A copy of your Automated Information System Security Plan(s) (AISSP) will suffice.
Attachment 2
OPERATIONS SECURITY (OPSEC)
REF. TO ITEM 11j of DD FORM 254
1. PURPOSE: This section outlines the requirements and procedures necessary to protect Critical Information for Operations security (OPSEC).
2. MISSION: To maintain a continuing awareness of adversary interest in center actions and adversary intelligence collection capabilities. To understand the need to identify and protect classified and unclassified indicators, which occur, reveal sensitive information. To evaluate the effectiveness of OPSEC measures taken to preclude or reduce adversary acquisition and exploitation of sensitive information.
3. DEFINITION: OPSEC is the process of analyzing friendly actions attendant to military operations and other activities to:
a. Identify those actions that can be observed by adversary intelligence systems.
b. Determine indicators hostile intelligence systems might obtain that could be interpreted or pieced together to drive critical information in time to be useful to adversaries.
c. Select and execute measures that eliminate or reduce to an acceptable level the vulnerabilities of friendly actions to adversary exploitation.
4. OBJECTIVES:
a. To protect planned operational center activities by preventing the inadvertent disclosure of unclassified information relating to or revealing a possible classified operation.
b. To preserve secrecy concerning specific scenarios events and a NORAD response to these events.
c. To identify OPSEC vulnerabilities and recommend protective measures which will serve to enhance the security of future operations.
5. TASKS: Task requirements are outlined in the Performance /Work Statement for this effort.
ESSENTIAL SECRECY:
PURPOSE: Operations security is implemented to ensure the denial of intelligence collection including all unclassified sensitive information that can reveal a new capability, command intentions or sensitive activities.
MISSION: Maintain awareness of latest information protection and control trends in the protection of unclassified essential elements friendly of information and apply OPSEC to Controlled Unclassified Information and sensitive information during force protection FPCON B-18.
DEFINITION:
a. Identify critical information for protection on projects, contracts and task orders.
b. Determine (SPACE) indicators that can be aggregated by competitive and adversarial forces.
c. Select measure against vulnerability and quality assure operational and information security measures to deter release of intelligence information into open sources.
OBJECTIVES:
a. Detect, deter and deny (3D.) Deny adversary contractors and hostile militaries trade secrets, new capabilities and our future intentions.
b. Protect military and contractor critical information to include privacy and personal identifiable information in the prevention of theft of proprietary data as well as identities.
c. Preserve both secrecy and privacy here and overseas (Travel).
TASKS: Task requirements are outlined in the Performance Work Statement (PWS) for this effort.
Attachment 3
COMMUNICATIONS SECURITY (COMSEC) OPERATIONS
Access to Keying Material Designated for Encryption of Sensitive Compartmented Information (SCI). Access to keying material that has been used to encrypt SCI constitutes access to the SCI itself. Keying material designated for encryption of SCI is considered SCI and is unencrypted (i.e., in RED form) when it becomes effective or when it is removed from its protective packaging or the protective packaging is no longer intact, whichever occurs first. Restrict access to unencrypted keying material used to protect SCI as follows:
NOTE: The COMSEC Account Manager is not considered to have access to unencrypted key if, when loading a user's electronic fill device with key from a Key Processor or a KP, the user is present and immediately departs with the fill device after the key load is complete. For TOP SECRET key, this requires two individuals to accompany the fill device.
Keying material designated for encryption of SCI must be issued for use only to personnel who are indoctrinated for SCI. The ConAuth must approve exceptions.
Control of TOP SECRET Keying Material. TOP SECRET keying material protects the most sensitive national security information. Losing it to an adversary can endanger all the information the key protects. Single-person access to TOP SECRET keying material increases opportunities for unauthorized handling, use, production, dissemination, removal, and possession of the material. For this reason, TOP SECRET keying material, to include codes and authenticators, and TOP SECRET key generating equipment, must be provided special protection.
Exceptions. This section does not apply to:
· Positive Control material and devices. (Control this material according to CJSCI 3260.01, Joint Policy Governing Positive Control Material and Devices).
· Unopened NSA protectively packaged material.
· Unopened packages received from or in the custody of the Defense Courier Service or Diplomatic Courier Service.
· COMSEC material used in tactical situations and implementing TPI is not possible.
Two-Person Integrity of TOP SECRET Keying Material. TPI is a storage and handling system that prohibits individual access to TOP SECRET keying material. It requires the presence of at least two authorized persons who know two-person integrity (TPI) procedures and can each detect incorrect or unauthorized security procedures for the task being performed. All activities with TOP SECRET keying material must handle, store, issue, transport, and destroy it under TPI control. Each user of TOP SECRET keying material and TOP SECRET key generators develops and uses procedures and controls to make sure lone individuals do not have access to TOP SECRET keying material (hard copy, set on permuter trays, or contained in electronic fill devices, etc.). Lone access to TOP SECRET COMSEC material for any length of time, without an approved waiver, is a reportable incident according to Chapter 9, Reporting COMSEC Deviations. (T-0)
No-Lone Zone. A no-lone zone is an area, room, or space which, when attended, must be occupied by two or more appropriately cleared individuals who remain within sight of each other. TPI procedures differ from no-lone zone procedures in that, under TPI controls, two authorized persons must directly participate in the handling and safeguarding of the keying material (as in accessing storage containers, transportation, keying/rekeying operations, and destruction). No-lone zone controls are less restrictive in that the two authorized persons need only be physically present in the common area where the material is located. Establish a COMSEC no-lone zone:
NOTE: Two-person integrity procedures differ from no-lone zone procedures in that, under two-person integrity controls, two authorized persons must directly participate in the handling and safeguarding of the keying material (as in accessing storage containers, transportation, keying/rekeying operations, and destruction). No-lone zone controls are less restrictive in that the two authorized persons need only be physically present in the common area where the material is located. Establish a COMSEC no-lone zone:
Establish a COMSEC no-lone-zone (CNLZ):
· At COMSEC facilities that produce classified hard copy or unencrypted electronic key.
· At cryptologist facilities that store or distribute unencrypted classified keying material.
· COMSEC users establish CNLZ whenever:
· Permuter trays are set up with TOP SECRET key.
· Cryptographic equipment contains TOP SECRET key in hard-copy form.
· TOP SECRET key is set in a mechanical permuter plug installed in cryptographic equipment.
NOTE: No-lone zones are not required if the COMSEC equipment has been modified to preclude single person access by installing locking bars secured by an approved padlock, or if tamper indicating seals are used in accordance with instructions provided by NSA.
Transportation. Adhere to the following procedures when transporting TOP SECRET keying material.
Apply TPI controls when transporting TOP SECRET keying material not sealed in NSA-approved protective packaging. Both persons moving the material must be granted cryptographic access according to Chapter 6, CAP, and must sign a receipt for the material when they pick it up.
TPI controls are not required when transporting TOP SECRET keying material in NSA-approved protective packaging. However, lone individuals moving the material must have proper clearance and have been granted cryptographic access according to Chapter 6.
When users locally transport the material from the COMSEC account to their duty section, ensure local procedures require a second individual to inspect the package for tampering and record the inspection on the user's copy of the receipt.
Handling Packages Containing TOP SECRET Material. Packages received into the COMSEC account can have the outer wrapper removed by one person. If the inner wrap is stamped TOP SECRET CRYPTO, terminate further opening of the package until a second TOP SECRET-cleared individual is present. The presence of two appropriately cleared individuals is required only as long as it takes to determine that the TOP SECRET material is in protective packaging and that the packaging has not been damaged or opened.
Storing Material. Store TOP SECRET keying material, not in NSA protective packaging, under TPI controls. Use an X-09 (or equivalent) combination lock with no one person authorized access to both combinations. Make sure at least one combination lock is built-in, as in a vault door or in a security container drawer. Storage can be in a special access control container (SACC) within a security container, in a security container within a vault, in a security container equipped with an electronic lock using the dual access mode, or in a security container with two combination locks. Security containers used to store TOP SECRET keying material must be GSA-approved and have their Federal Specification approved FF-L-2740A lock set up in the TPI, two combination mode. When using two combination locks, identify each security container (that is, lock 1, lock 2, safe 1, safe 2) and name, in writing, each person with authorized access to each combination. Each lock must have a separate SF 700 and SF 702. Limit the SF 700 to the top 4 individuals who could be contacted if the safe is left unsecure. While the SF 700 is not an access list, the individuals listed will be individuals already on the access list for the vault or container.
NOTE: Keep common fill devices under TPI whenever they are used to store TOP SECRET key. Apply TPI controls to the SKL, RaSKL, etc., whenever they are used to store TOP SECRET key and the CIK is installed or not properly secured.
TPI storage procedures are not required for TOP SECRET key in tactical situations. In situations where units are unable to meet normal TPI storage requirements, users must either:
Store TOP SECRET keying material in a standard, approved field safe or similar container secured by a 3-position mechanical combination lock meeting federal specification FF-L-2937; or, If adequate storage facilities are not available or in unique travel circumstances, keep TOP SECRET keying material under personal custody.
Procedures in effect must require inspections of protective packaging in accordance with applicable Protective Technologies Pamphlets.
Recording Combinations. To provide ready access to secured material in emergencies, it is permissible to keep a central record of all lock combinations used to protect TOP SECRET keying material in a single secure container, approved for TOP SECRET storage. Protect the combinations by using part 2 of the SF 700. Seal this to prevent undetected, unauthorized access to the combination.
Loading TOP SECRET Keying Material. Except in tactical environments when TPI is not possible, always apply TPI handling procedures to keying operations.
Two-Person Integrity Incidents. In addition to COMSEC incidents identified in Chapter 9, report any violation of TPI or CNLZ requirements, including situations in which an individual not under the CAP program accesses TOP SECRET keying material alone without a valid waiver.
TPI Waivers. TPI waivers are approved by NSA only. (T-0) All TPI waivers must be submitted to AFSPC CYSS/CYS COMSEC Field Support with coordination from the requesting unit’s MAJCOM/A6s and all the controlling authorities of the affected material. Revised operational procedures or work schedules or other unit-level initiatives may make waivers unnecessary. A lone person must not access TOP SECRET keying material until entered into the CAP and an approved waiver has been granted.
Attachment 4
FOR OFFICIAL USE ONLY (FOUO)
REF. TO ITEM 11j OF DD FORM 254
1. GENERAL:
a. The "For Official Use Only" (FOUO) marking is assigned to information at the time of its creation in a DOD User Agency. It is not authorized as a substitute for a security classification marking but is used on official government information that may be withheld from the public under exemptions 2 through 9 of the Freedom of Information Act (FOIA).
b. Other non-security markings, such as "Limited Official Use" and "Official Use Only" are used by non-DoD User Agencies for the same type of information and should be safeguarded and handled in accordance with instruction received from such agencies.
c. Use of the above markings does not mean that the information cannot be released to the public under FOIA, only that the Government must review the information prior to its release to determine whether a significant and l legitimate government purpose is served by withholding the information or portions thereof.
2. MARKINGS:
a. An unclassified document containing FOUO information will be marked "For Official Use Only" at the bottom of the front cover (if any), on the first page, on each page containing FOUO information, on the back page, and on the outside of the back cover (if any).
b. Within a classified document, an individual page that contains both FOUO and classified information will be marked at the top and bottom with the highest security classification of information appearing on the page. If an individual portion contains FOUO information but no classified information, the portion will be marked, "FOUO."
c. Removal of the "For Official Use Only" marking can only be accomplished by the originator or other competent authority. When the "For Official Use Only" status is terminated, all known holders will be notified to the extent practical.
3. DISSEMINATION: Contractors may disseminate "For Official Use Only" information to their employees and subcontractors who have a need for the information in connection with a classified contract. Contractors must ensure employees and subcontractors are aware of the special handling instructions detailed below.
4. STORAGE: During working hours, "For Official Use Only" information shall be placed in an out-of-sight location if the work area is accessible to persons who do not have a need for the information. During nonworking hours, the information shall be stored to preclude unauthorized access. Filing such material with other unclassified records in unlocked files or desks, is adequate when internal building security is provided during nonworking hours. When such internal security control is not exercised, locked buildings or rooms will provide adequate after hours protection or the material can be stored in locked receptacles such as file cabinets, desks, or bookcases.
5. TRANSMISSION: "For Official Use Only" information may be sent via first-class mail or parcel post. Bulky shipments may be sent by fourth-class mail. DOD components, officials of DOD components, and authorized DOD contractors, consultants, and grantees send FOUO information to each other to conduct official. Tell recipients the status of such information, and send the material in a way that prevents unauthorized public disclosure. Make sure documents that transmit FOUO material call attention to any FOUO attachments. Normally, you may send FOUO records over facsimile equipment. To prevent unauthorized disclosure, consider attaching special cover sheets, the location of sending and receiving machines, and whether authorized personnel are around to receive FOUO information. FOUO information may be passed to officials in other departments and agencies of the executive and judicial branches to fulfill a government function. Mark the records "For Official Use Only" and tell the recipient the information is exempt from public disclosure under the FOIA and requires special handling.
6. DISPOSITION: When no longer needed, FOUO information must be shredded.
7. UNAUTHORIZED DISCLOSURE: Unauthorized disclosure of "For Official Use Only" information does not constitute a security violation but the releasing agency should be informed of any unauthorized disclosure. The unauthorized disclosure of FOUO information protected by the Privacy Act may result in criminal sanctions and disciplinary action may be taken against those responsible.
- 6 -
File details come from the government source that posted it. Updated .