Attachment 0003 DD254 Security Classification (Draft).pdf

PDF 105 KB Posted

Attached to
ACC-RSA Logistic Support Facility Services (LSFS-1) Federal contract opportunity
Solicitation number
W58RGZ-22-R-0090
Issued by
Department of the Army Materiel Command Contracting Command Redstone Arsenal

View the file

Other files for this federal contract opportunity

Other files attached to ACC-RSA Logistic Support Facility Services (LSFS-1), newest first.
File Type Posted
Consolidated Draft RFP Questions_Answers-Responses_01Sep2022_Clean.pdf PDF
W58RGZ-22-R-0090 DRAFT RFP Revised 25 Jul 2022.pdf PDF
Attachment 0007 Section M-Evaluation Factors for Award.pdf PDF
W58RGZ-22-R-0090 DRAFT RFP.pdf PDF
Attachment 0008 Section C - Description_Specification.pdf PDF
Atttachment 0016 Pre-Award Survey of Prospective Contractor Accounting System Checklist.pdf PDF
Attachment 0009 Past Performance Questionnaire.docx DOCX document
Attachment 0005 LSFS-1 Labor Category Requirement.xlsx XLSX spreadsheet
Attachment 0001 Document Summary List (DSL).pdf PDF
Exhibit A Contract Data Requirements List (CDRL).pdf PDF
Attachment 0015 Cage Code and Cognizant DCMA_DCAA Info.xlsx XLSX spreadsheet
Attachment 0014 Sample Order 2.pdf PDF
Attachment 0013 Sample Order 1.pdf PDF
Attachment 0012 LSFMA Performance Cost Report.pdf PDF
Attachment 0011 Draft RFP Questions_Answers Form.xlsx XLSX spreadsheet
Attachment 0010 Industry Questions.xlsx XLSX spreadsheet
Attachment 0006 Section L- Instructions_ Conditions and Notices to Offerors.pdf PDF
Attachment 0004 Performance Work Statement.pdf PDF
Attachment 0002 LSFS-1 Cost Price Template.xlsx XLSX spreadsheet
Show all 19

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Please wait...

If this message is not eventually replaced by the proper contents of the document, your PDF viewer may not be able to display this type of document.

You can upgrade to the latest version of Adobe Reader for Windows®, Mac, or Linux® by visiting http://www.adobe.com/go/reader_download.

For more assistance with Adobe Reader visit http://www.adobe.com/go/acrreader.

Windows is either a registered trademark or a trademark of Microsoft Corporation in the United States and/or other countries. Mac is a trademark of Apple Inc., registered in the United States and other countries. Linux is the registered trademark of Linus Torvalds in the U.S. and other countries.

W58RGZ-XX-X-XXXX Company Name Here

Contract Number: DD254 Continuation Sheet Block 13

ACTUAL PERFORMANCE (continued)

Item 10.a & 11.h: The contractor shall maintain a valid U.S. COMSEC account throughout the period of performance of this contract. COMSEC access shall be in accordance with National Industrial Security Program Operating Manual (NISPOM) (DoD 5220.22-M) and Policy for Safeguarding and Controlling Communications Security (COMSEC) Material (AR 380-40). When access is required at Government facilities, contractor personnel shall adhere to COMSEC rules and regulations as mandated by Command policy and procedures. National Security Agency (NSA) Central Security Service (CSS), NSA/CSS Policy Manual No. 3-16 “Control of Communications Security (COMSEC) Material” applies to this contract. The contractor shall train its Government Owned Contractor Operated (GOCO) Forward Support Representative (FSR) personnel in the use of COMSEC/CCI fill devices and training hardware furnished by the Government. All COMSEC/CCI equipment shall be controlled and chain of custody maintained through a Standard Form 153. The contractor shall be responsible for the protection of COMSEC equipment from the time of receipt of the equipment until transferred via the completion of an SF-153, inventory, confirmation of end item (COMSEC) and serial numbers on the SF-153 with signatures.

The management and distribution of keying (fill) material(s) is the responsibility of the Government. The Government is responsible for ensuring the correct COMSEC keys, appropriate to each mission, are provided to contractor personnel as needed. When the military unit does not have the personnel to procure COMSEC keying material, COMSEC briefed and trained contractor personnel are authorized to procure the COMSEC keying material from the local COMSEC Custodian, key the COMSEC equipment, and secure the keying device in support of the Logistics Support Facility Management Activity (LSFMA). The Government will provide the keying fill device(s) to the Contractor COMSEC by transfer to COMSEC account via an SF-153. The Government is responsible for providing GFE approved GSA security container(s) for the contractor teams to secure the COMSEC/CCI equipment.

Contractor must notify the NSA Central Office of Record before negotiating or awarding access to COMSEC to subcontractors. Written concurrence of the Contracting Officer is required prior to subcontracting access to COMSEC.

Item 10.h: Foreign Government Information (FGI) is not releasable to contractor employees who have not received a FINAL clearance at the appropriate security level. Written concurrence of the KO is required prior to subcontracting. Contractor as required may be provided FOREIGN GOVERNMENT INFORMATION on a Delivery/Task Order basis.

Item 10.j: Contractor will comply with the requirements of DoDM 5200.01,DoD Information Security Program, Controlled Unclassified Information (CUI), Volume 4, February 24, 2012, Identification and Protection of CUI, for the processing of FOUO information in this contract.

Item 10.k: Contractor is authorized access and e-mail account to SECRET Internet Protocol Router Network (SIPRNET) at Government facilities only. Contractor employees requiring access to the SIPRNET must complete the SIPRNET Access Request Form. The contractor shall not access, download or further disseminate any special access data (Intelligence, NATO, COMSEC, etc.) outside the execution of the defined contract requirements and without the guidance and written permission of the Contracting Officer. NATO awareness briefing is required for contractor employees who require access to the SIPRNET. Contractor access to SIPRNET is restricted to sites directly related to meeting the requirements of this contract as validated by the Contracting Officer Representative (COR) and/or the Scope of Work. The contractor shall not access INTELLINK-S, while on the SIPRNET without formal access authorization of the COR and AMCOM G-2 (Intelligence and Security). Contracting Officer written approval is required prior to subcontracting access to SIPRNET.

Item 11.c & 11.m: The contractor requires access to classified source data up to and including SECRET in support of the work effort. Any extracts or use of such data requires the contractor to apply derivative classifications and markings consistent with the source documents. Use of “Multiple Sources” on the “Derived From” line necessitates compliance with the NISPOM, paragraph 4-208a, and the use of a bibliography. All classified information, for the duration of the classification, received or generated under this contract is the property of the US Government, regardless of proprietary claims. At the termination or expiration of this contract, the US Government will be contacted for proper disposition instructions. Contractor shall follow Chapter 8 of the NISPOM for guidance on classified computer processing. Contractor is authorized to process classified information up to and including SECRET at their facility on accredited computer systems. Contractor shall account for all classified material on Classified Document Accountability Record (DA Form 3964) or contractor equivalent, throughout each phase of the contract. The Security Classification Guides will be provided to the Contractor via safe communications.

Access to Government IT Systems. Contractors requiring access to Government IT systems must adhere to the requirement of AR 25-2, Information Technology (IT), Rapid Revision (RAR), Issue Date: 23 March 2009, on Government installations. All contractor employees and associated sub-contractor employees shall complete the DoD IA awareness training before issuance of network access and annually thereafter.

Item 11.d: Fabricate, Modify, or Store Classified Information Hardware: During the performance of this contract it may be necessary for your company to store classified hardware. Due to the nature, size, or unique characteristics, it may not fit in an approved security container. Your company may have to establish approved restricted or closed area(s) IAW DoD 5220.22-M, National Security Program Operating Manual (NISPOM), 18 May 2016. The point at which proposed hardware becomes classified shall be provided by the contract monitor.

Item 11.h. NSA/CSS Policy Manual 3-16, “Control of Communications Security (COMSEC) Material”, Aug 05, and the National Industrial Security Program Operating Manual (NISPOM) apply to this contract.

Item 11.j: There is no required OPSEC deliverable associated with this contract. However, the contractor will need to adhere to all OPSEC requirements outlined in the National Security Decision Directive (NSDD) No. 298, "National Operations Security Program", dated January 22, 1988, Department of Defense Directive 5205.2, "DoD Operations Security (OPSEC) Program", dated November 29, 1999 and Army Regulation 530-1, "Operations Security (OPSEC)", dated 20 March 2007.

Item 11.m: Co-located/embedded contractor personnel will be required to take the following training annually: Security Refresher, Cyber Awareness Challenge (Information Assurance), Operation Security (OPSEC), Anti-Terrorism Level I Training and Threat Awareness and Reporting Program (TARP). All training is provided on site by the Government. No delivery is required. IAW AR 381-12, Threat Awareness and Reporting Program (TARP), 1 June 2016, Contractors will report threat-related incidents, behavioral indicators and other matters of Counter Intelligence (CI) interest specified in Chapter 3, to the Facility Security Officer (FSO), the nearest military CI office, the FBI, or the DSS.

Item 12. All submittals for request for public release of information, articles, videos, etc., shall be submitted to the Public Affairs Officer, (AMSAM-PA) AMCOM, Redstone Arsenal, AL 35898-5020. The submissions shall include a letter of transmittal certifying the review by the FSO that the material has been reviewed and it contains no classified information. The letter of transmittal shall include the contract number. A minimum of 15 working days is required to process and review the request. Information or material will not be released until approval is granted. Non-SCI information is NOT authorized and is prohibited from Public Release.

Continued:

a. Public Release: Within the DA, the public release of official U.S. Army information regarding LSFMA will be IAW the provisions of AR 360-1, The Army Public Affairs Program, and any local organizational implementation of the regulation. The fact that this guide shows certain details of information to be UNCLASSIFIED does not authorize or allow automatic public release. Proposed public disclosures of UNCLASSIFIED information regarding LSFMA information shall be processed through appropriate channels for approval for publication.

(1) Defense contractors and other organizations must screen all information they submit for determination of public release to ensure it is both unclassified and technically accurate. A letter of transmittal must certify the review and include a statement from the Defense Contractor Facility Security Officer that the material has been reviewed and it contains no classified information. Defense contractors will comply with the NISPOM, and other contractual requirements. Copies of the material may not be released outside official channels until the review process is complete. All requests will be submitted to the Public Affairs Officer, (AMSAM-PA) AMCOM, Redstone Arsenal, AL 35898, for adjudication. Allow at least 15 days to review the request. Information or material will not be released until approval is granted. Non-SCI information is NOT authorized and is prohibited from Public Release.

(2) Government organizations wishing to publicly release information covered by this guide should submit a request to the Public Affairs Officer, (AMSAM-PA) AMCOM, Redstone Arsenal, AL 35898 for adjudication. Allow at least 15 days to review the request. Information or material will not be released until approval is granted.

(3) Care must be taken to ensure that all official U.S Army information that is entered on public accessible or unprotected World Wide Websites has been processed, reviewed and approved IAW Army policies. In addition to AR 360-1, the provisions of AR 25-2, Information Assurance, apply.

b. Release of Classified Information at Symposiums, Seminars, Conferences, and Other Forums: All presentations containing information classified under this SCG that are intended to be released at classified symposiums, seminars, conferences, or similar forums will be submitted for approval IAW the provisions of AR 380-5 and all local organizational policies and procedures. The request will include the name of the individual making the presentation, date of the presentation, title of the forum, security point of contact for the event, and justification for the proposed release.

Visit Requests. Contractor shall submit Visit Request via Defense Security Service - Joint Personnel Adjudication System (JPAS). All Visit Request shall include the Technical POC and Technical POC telephone number. Visit Request shall not exceed a one year period or beyond the end of the contract if less than one year.

Concurrence of the Contracting Officer and PEO Aviation Foreign Disclosure Officer will be obtained prior to issue of a Limited Access Authorization to a non-US citizen in compliance with the NISPOM. Controlled Unclassified Information as defined in DOD 5200.01 V4, may be disclosed to US persons who are employed by the prime contractor or subcontractor, or to such employees who are foreign persons when requirements of export control and other laws are met. The contractor is responsible for compliance with all applicable laws and federally mandated regulations governing access to Classified Information or Covered Defense Information (CDI). (DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting).

Contractor shall prepare a Security Plan for Controlling access to US Government Information when Non-US Citizens or Representatives of Foreign Interests are resident in or visitors at the Contractor Facility.

Contractor personnel are not authorized to take pictures with any form of camera inside Government facilities or on military installations without prior coordination and approval of the Public Affairs office.

Contractor personnel shall abide all Government Regulations, Policies and Standard Operating Procedures when working or visiting Government facilities.

As of Aug 10, 2017, there is a new CAC SOP. (Department of the Army Trusted Associate Sponsorship System (TASS) Standard Operating Procedure and Army TASS Policy.

The LSFMA holds final determination on the approval for CACs. Consideration for a CAC will be addressed on a case-by-case basis.

A CAC is tied to an individual; not a contract number, contract company, or geographic location. Contractors leaving one TASS site ID for another within the same service (Army) must notify their current Trusted Agent (TA) of their pending move so that a transfer of the contractor’s CAC from the losing TA site (identified by 6-digit site ID) to the gaining TA site can be coordinated through the Service Point of Contact (SPOC). Only “issued” and “approved” CAC applications are eligible for transfer between site IDs. It is evident that many contractors often leave without notifying the TA that they are going to another contract position, however some sites/installations have made policy to revoke CACs even when the transfer is known. Sites/organizations should refrain from this practice due to the resulting unnecessary expenditure of time and resources in reissuing a new CAC, as well as the unnecessary downtime for the contractor. Follow the Department of the Army Trusted Associate Sponsorship System SOP, dated 10 Aug 2017, Section 12.

CACs will be considered for contractor employees that are deploying, that work full time on a military installation, and for contractor employees that require frequent access to multiple DoD installations in support of this contract for test. Justification, to include list of multiple DoD facilities, must be included with each request for a CAC. Contractor employees issued a CAC shall maintain possession of their CAC at all times. The CAC will not be used in temporary badge exchanges. Contractor employees issued a CAC shall not share their CAC PIN with anyone. CAC will not be left unattended in computer. CACs are the property of the US Government and will be surrendered to the LSFMA COR or Government Trusted Agent upon termination of employment with the company, expiration of the CAC, replacement of a CAC, or upon contract completion. The COR shall return the CAC to One Stop on Redstone Arsenal. The loss of a CAC shall be reported, on the first business day following the discovery of the lost CAC, to your chain of command, Facility Security Office, LSFMA COR (256-842-4245), and to the issuing agency. Visit the Realtime Automated Personnel Identification System (RAPIDS) site at: http://www/dmdc.osd.mil/rsl/owa/home for issuing agency’s telephone number. Unauthorized possession of a CAC can be prosecuted criminally under section 701, title 18, United States Code. FAR 52.204-9 - Personal Identity Verification of Contractor Personnel (January 2011) applies to this contract. FAR 52.204-9 - Personal Identity Verification of Contractor Personnel (January 2011) applies to this contract.

Photocopying of US Government Identification (CAC) is a violation of Title 18, US Code Part I, Chapter 33, Section 701 and punishable by both fine and imprisonment. Although the asking for military/government identification is totally permissible by commercial establishments, there is a prohibition on duplication of government identification. A state driver license or other form of photo identification should be provided to be photocopied if an establishment insists on a photocopy of the traveler’s identification. Please ensure all employees are aware of this law.

Contractor personnel requiring access to US Army Computer Networks must annually complete the Computer User Training and annually sign an Acceptable Use Policy (AUP) of the installation/facility where the access is required. Contractor personnel will be required to register at the Army Training and Certification Tracking System (https://afc.us.army.mil/iastar/index.php) and upload copies of their signed AUP and training.

Contractor personnel shall utilize DISA or company e-mail for transmitting official U.S. Government business. Official U.S. Government business shall not be transmitted via personal, private, and commercial e-mail accounts, i.e., YAHOO, HOTMAIL, GMAIL, JUNO, etc. US Army LSFMA information shall NOT be processed or stored on contractor employee’s personal computer or any other personally owned electronic devices.

A copy of all subcontract DD 254’s shall be provided to the LSFMA COR, via US Post Office, fax, or e-mail.

Any loss, compromise or suspected compromise of classified information, foreign or domestic, shall be reported to the Cybersecurity Task Lead, Alan Neuschwander, George.a.neuschwander.civ@mail.mil, 256-313-3585.

Questions concerning any aspect of security will be referred to the LSFMA Office, 256-842-4245.

FOLLOW THE ANTI-TERRIORISM/OPERATIONS SECURITY INFORMTION BELOW IF APPLICABLE

FOR CONTRACTORS THAT DO NOT REQUIRE CAC, BUT REQUIRE ACCESS TO A DOD FACILITY OR INSTALLATION.

Contractor and all associated subcontractors employees shall comply with adjudication standards and procedures using the National Crime Information Center Interstate Identification Index (NCIC-III) and Terrorist Screening Database (TSDB) (Army Directive 2014-05/AR 190-13), applicable installation, facility and area commander installation/facility access and local security policies and procedures (provided by government representative), or, at OCONUS locations, in accordance with status of forces agreements and other theater regulations.

AT AWARENESS TRAINING FOR CONTRACTOR PERSONNEL TRAVELING OVERSEAS.

This standard language text required US based contractor employees and associated sub-contractor employees to make available and to receive government provided area of responsibility (AOR) specific AT awareness training as directed by AR 525-13. Specific AOR training content is directed by the combatant commander with the unit ATO being the local point of contact.

iWATCH TRAINING.

The contractor and all associated subcontractors shall brief all employees on the local iWATCH program (training standards provided by the requiring activity ATO). This locally developed training will be used to inform employees of the types of behavior to watch for and instruct employees to report suspicious activity to the COR. This training shall be completed within 30 calendar days of contract award and within 30 calendar days of new employees commencing performance with the results reported to the COR NLT 30 calendar days after contract award.

ARMY TRAINING CERTIFICATION TRACKING SYSTEM (ATCTS) REGISTRATION FOR CONTRACTOR EMPLOYEES WHO REQUIRE ACCESS TO GOVERNMENT INFORMATION SYSTEMS.

All contractor employees with access to a government info system must be registered in the ATCTS (Army Training Certification Tracking System) at commencement of services, and must successfully complete the DOD Information Assurance Awareness prior to access to the IS and then annually.

FOR CONTRACTS THAT REQUIRE A FORMAL OPSEC PROGRAM.

The contractor shall develop an OPSEC Standing Operating Procedure (SOP)/Plan within 90 calendar days of contract award, to be reviewed and approved by the responsible Government OPSEC officer. This plan will include a process to identify critical information, where it is located, who is responsible for it, how to protect it and why it needs to be protected. The contractor shall implement OPSEC measures as ordered by the commander. In addition, the contractor shall have an identified certified Level II OPSEC coordinator per AR 530‐1. For information assurance (IA)/information technology (IT) training. All contractor employees and associated sub‐contractor employees must complete the DoD IA awareness training before issuance of network access and annually thereafter.

FOR CONTRACTS THAT REQUIRE OPSEC TRAINING.

Per AR 530‐1 Operations Security, the co-located contractor employees must complete Level I OPSEC Awareness training. New employees must be trained within 30 calendar days of their reporting for duty and annually thereafter.

FOR INFORMATION ASSURANCE (IA)/INFORMATION TECHNOLOGY (IT) TRAINING.

All co-located contractor employees and associated sub‐contractor employees must complete the DoD IA awareness training before issuance of network access and annually thereafter.

FOR INFORMATION ASSURANCE (IA) / INFORMATION TECHNOLOGY (IT) TRAINING AND/OR CERTIFICATION.

Per DoD 8570.01-M, DFARS 252.239.7001 and AR 25-2, the contractor employees supporting IA/IT functions shall be appropriately trained and/or certified, as required upon contract award. The baseline certification as stipulated in DoD 8570.01-M must be completed upon contract award. Additional training for IA workforce positions must be completed within six months.

FOR CONTRACTORS AUTHORIZED TO ACCOMPANY THE FORCE.

DFARS Clause 252.225‐7040, Contractor Personnel Authorized to Accompany U.S. Armed Forces Deployed Outside the United States. The clause shall be used in solicitations and contracts that authorize contractor personnel to accompany US Armed Forces deployed outside the US in contingency operations; humanitarian or peacekeeping operations; or other military operations or exercises, when designated by the combatant commander. The clause discusses the following AT/OPSEC related topics: required compliance with laws and regulations, pre‐deployment requirements, required training (per combatant command guidance), and personnel data required.

FOR CONTRACT REQUIRING PERFORMANCE OR DELIVERY IN A FOREIGN COUNTRY.

DFARS Clause 252.225‐7043, Antiterrorism/Force Protection for Defense Contractors Outside the US. The clause shall be used in solicitations and contracts that require performance or delivery in a foreign country. This clause applies to both contingencies and non‐contingency support. The key AT requirement is for non‐local national contractor personnel to comply with theater clearance requirements and allows the combatant commander to exercise oversight to ensure the contractor’s compliance with combatant commander and subordinate task force commander policies and directives.

FOR CONTRACTS THAT REQUIRE HANDLING OR ACCESS TO CLASSIFIED INFORMATION.

Contractor shall comply with FAR 52.204-2, Security Requirements. This clause involves access to information classified “Confidential,” “Secret,” or “Top Secret” and requires contractors to comply with— (1) The Security Agreement (DD Form 441), including the National Industrial Security Program Operating Manual (DoD 5220.22-M); any revisions to DOD 5220.22-M, notice of which has been furnished to the contractor.

DRAFT

SAMPLE

PREVIOUS EDITION IS OBSOLETE.

Page of AEM LiveCycle Designer

DD FORM 254, APR 2018

NEEDS DD67

DEPARTMENT OF DEFENSE

CONTRACT SECURITY CLASSIFICATION SPECIFICATION

(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)

OMB No. 0704-0567 OMB approval expires:

October 31, 2020 The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.

RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.

1. CLEARANCE AND SAFEGUARDING

2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)

3. THIS SPECIFICATION IS: (X and complete as applicable.)

a. ORIGINAL (Complete date in all cases.)

b. REVISED (Supersedes all previous specifications.)

4. IS THIS A FOLLOW-ON CONTRACT?

If yes, complete the following:

Classified material received or generated under

5. IS THIS A FINAL DD FORM 254?

If yes, complete the following:

6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)

7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor)

8. ACTUAL PERFORMANCE (Click button to add more locations.)

10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)

e. NATIONAL INTELLIGENCE INFORMATION:

11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)

12. PUBLIC RELEASE

Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)

13. SECURITY GUIDANCE

The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.

(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)

14. ADDITIONAL SECURITY REQUIREMENTS

Requirements, in addition to NISPOM requirements for classified information, are established for this contract.

If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)

15. INSPECTIONS

Elements of this contract are outside the inspection responsibility of the CSO.

If Yes, explain and identify specific areas and government activity responsible for inspections. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)

16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)

17. CERTIFICATION AND SIGNATURES

Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below. Upon digitally signing Item 17h, no changes can be made as the form will be locked.

18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL

9.0.0.2.20120627.2.874785 DD 254, DoD Contract Security Classification Specification List of Attachments [1] (All Files Must be Attached Prior to Signing, i.e., for any digital signature on the form) W58RGZ-XX-X-XXXX Item 13 Continuation Sheet DD254.docx

CurrentPage:
PageCount:
Classification: Unclassified
SerialNum: 2022-03
a. Facility clearance level. Select one.: 2
b. Level of safeguarding for classified information/material required at contractor facility. Select one.: 2
Choose Yes or No: 0
Choose Yes or No: 1
Prime: TBD
Choose Yes or No: 0
Choose Yes or No: 0
Sub:
Choose Yes or No: 1
Choose Yes or No: 0
Soli: W58RGZ-22-R-0090
DueDate:
dateA: 2023-03-31
RevisionNum:
dateB:
Final:
dateC:
No: 1
No: 1
No: 1
No: 1
Yes: 0
Yes: 0
Yes: 0
Yes: 0
Enter your name here.:
ReqDated:
Enter your name here.:
Name: Antionette McClinton
Cage:
CSO:
addrow:
Removerow:
Click to delete a row:
Location:
Block9: LSFMA provides a rapid response contractual vehicle for predominantly Aviation program management (PM) – driven requirement and sustainment support, to include: Modification Work Orders (MWOs), Non-Recurring Engineering (NRE) in support of MWOs, Production and Installation of kits, and Aircraft Augmentation.
a: 1
a: 0
a: 1
f: 0
f: 0
f: 0
b: 0
b: 0
b: 1
g: 0
g: 1
c: 0
c: 1
c: 1
h: 1
h: 1
d: 0
d: 1
d: 0
i: 0
i: 0
SCI: 0
NonSCI: 0
j: 1
j: 1
k: 1
k: 0
Enter your name here.: See Item 13 Continuation
Enter your name here.: See Item 13 Continuation
e: 0
e: 1
l: 1
m: 1
direct: 0
thru: 1
Enter your name here.: Commander, USAAMCOM, Office of Public and Congressional Affairs, AMAM-PC, Redstone Arsenal, AL 35898.
PublicAuthority: Commander, USAAMCOM, Office of Public and Congressional Affairs, AMAM-PC, Redstone Arsenal, AL 35898.
AddSig:
RemoveSig:
text:

REF Item 11.c and 11.d. Security Classification Guidance will be further delineated and provided in the subsequently issued Delivery/Task Order (DO/TO), and accompanying order-specific DD Form 254.

REF Item 11.c and 11.d.: Contractor shall comply with FAR 52.204‐2, Security Requirements. This clause involves access to information classified “Confidential,” “Secret,” or “Top Secret” and requires contractors to comply with— (1) The Security Agreement (DD Form 441), including the National Industrial Security Program Operating Manual (DoD 5220.22‐M); (2) any revisions to DOD 5220.22‐M, notice of which has been furnished to the contractor. The contractor shall utilize the most current Major End Item Security Classification Guide (SCG) for classification guidance. The SCG will be mailed under separate cover to the contractor Facility Security Officer (FSO). The contractor is authorized to release the SCG only to their subcontractors on this contract. The performance of this contract shall require access, receipt, generation, and storage of classified information or equipment at the SECRET level at contractor facilities in support of the work effort. Classified information is, and remains for the duration of the classification, the property of the U.S. Government, regardless of proprietary claims. Contractor is authorized to process classified information via accredited computer system in accordance with DOD 5220.22-M, National Industrial Security Program Operating Manual, Chapter 8. Any extracts or use of such data requires the contractor to apply derivative classifications and markings consistent with the source documents. Use of “Multiple Sources” on the “Derived From” line necessitates compliance with the NISPOM, paragraph 4-208a, and the use of a bibliography. The contractor shall utilize the current Marking Classified National Security Information guide to ensure classified information generated is properly marked. Contractor must provide adequate storage at their facility for classified material up to and including SECRET. All classified material must be accounted for on a DA Form 3964 or contract equivalent form throughout each phase of the contract. At the termination or expiration of this contract, the U.S. Government shall be contacted for proper disposition instructions. All classified information mailed to the Cargo Project Office should be mailed to the address in block 17 below.

Non-US Citizens or Representatives or Foreign Interests shall not have access to US Classified Military Information or Equipment, Network Computers that store or process US Government information, Any Source Codes, COMSEC Information or Equipment.

The contractor is not authorized to release any data to foreign nationals or foreign representatives without an approved export license.

Prior to sub-contracting with a foreign industry the U.S. contractor will consult with the Contracting Officer and Aviation and Missile Command (AMCOM) Security Manager. Foreign subcontractors must agree that only citizens of their country or the U.S. will be allowed to perform on the contract. The U.S. contractor is responsible for complying with the regulations outlined in the International Traffic In Arms Regulations (ITAR).

Ref Item 10.a./11.h. If the contractor is authorized to receive Government furnished cryptographic equipment, the guidance will state that fact. Access to classified COMSEC information requires a final U.S. government clearance at the appropriate level. Further disclosure of COMSEC information by a contractor, to include subcontracting, requires prior approval of the GCA. Non-accountable COMSEC information, though not tracked in the COMSEC material control system, may still require a level of control within a document control system. Refer to NSA/CSS Manual 3-16, “Control of Communications Security Material, ” and the Committee on National Security Systems Instruction (CNSSI) 4001, “Controlled Cryptographic Items” for guidance. If access to COMSEC information is required at Government facilities, contractor personnel will follow the security requirements of the host government activity.

REF Item 10.j and 11.l: ICUI information provided by DoD to contractors must be identified as such via the contracting vehicle, in whole or part, with all such documents, material, or media marked in accordance with DoDI 5200.48.

CUI, provided by DoD to, or generated by, non-DoD entities require protective measures and dissemination controls, including those directed by relevant law, regulation, or government-wide policy, and will be articulated in the contract, grant, or other legal agreement, as appropriate.

DoD contracts must require contractors to monitor CUI for aggregation and compilation based on the potential to generate classified information pursuant to security classification guidance addressing the accumulation of unclassified data or information. DoD contracts shall require contractors to report the potential classification of aggregated or compiled CUI to a DoD representative.

DoD personnel and contractors, pursuant to mandatory DoD contract provisions, will submit unclassified DoD information for review and approval for release in accordance with the standard DoD Component processes and DoDI 5230.09.

All CUI records must follow the approved mandatory disposition authorities whenever the DoD provides CUI to, or CUI is generated by, non-DoD entities in accordance with Section 1220-1236 of Title 36, CFR, Section 3301a of Title 44, U.S.C., and this issuance.

Electronically transmitted CUI shall be sent via: 1) encrypted email, 2) password protected/encrypted document, 3) Safe Access File Exchange at https://safe.apps.mil,or 4) an accredited information system with proper security controls.

The Contractor shall not release to anyone outside the Contractor's organization any unclassified information, regardless of medium (e.g., film, tape, document), pertaining to any part of this contract or any program related to this contract, unless—

• The Contracting Officer has given prior written approval; or

• The information is otherwise in the public domain before the date of release.

Requests for approval shall identify the specific information to be released, the medium to be used, and the purpose for the release. The Contractor shall submit its request to the Contracting Officer at least 45 days before the proposed date for release.

The Contractor agrees to include a similar requirement in each subcontract under this contract. Subcontractors shall submit requests for authorization to release through the prime contractor to the Contracting Officer.

Classified information processing at contractor facilities will be conducted in accordance with Chapter 8 of the NISPOM.

Contractors requiring access to government information systems at government or contractor facilities will comply with AR 25-2 guidance.

Contractor access to SIPRNet via government accounts is restricted to sites directly related to meeting the requirements of this contract as validated by the COR and/or the Performance Work Statement/Statement of Work (PWS/SOW).

The contractor will not access INTELINK-S while on the SIPRNET without formal access authorization of the COR and AMAM-IS.

Requests for SIPRNet access will be forwarded to the project COR to facilitate the local vetting and approval process.

SIPRNet access via government accounts may not be subcontracted without prior written authorization of the Contracting Officer, COR and AMAM-IS.

*Prior to SIPRNet access, personnel must receive a NATO awareness briefing and complete Derivative Classification training.

*If SIPRNet is required at contractor facility, contractor shall coordinate with appropriate DSCA representatives. Access via Defense Information Systems Network (DISN) Secret Internet Protocol Routing Network (SIPRNet) dated 01 June 2013, or most current.

NSA/CSS Policy Manual 3-16, Control of Communications Security (COMSEC) Material, Aug 05, DoD 5220.22-M NISPOM Incorporating Change 2, and AR 380-40 apply to this contract.

REF Item 11.j. Per AR 530‐1 Operations Security, the contractor employees must complete Level I OPSEC Awareness training. New employees must be trained within 30 calendar days of their reporting for duty and annually thereafter. OPSEC Level 1 Training is located at http://www.iad.gov/ioss/index.

Contractor personnel requiring access to U.S. Army Computer Networks must complete the Cyber Awareness Training and sign an Acceptable Use Policy (AUP) of the installation/facility where the access is required. A copy of the training certificate and AUP must be provided to the designated personnel at the Government facilities.

REF Item 11. j. Contractor is required to comply with the GCA OPSEC Plan which will be provided upon award of the contract, and the AT/OPSEC requirements stipulated in the Security Requirements Clause of the PWS, or equivalent, for this contract. Prime contractors may not impose OPSEC requirements on subcontractors without GCA approval.

REF Item 11.m. IAW AR 381-12, Threat Awareness and Reporting Program (TARP), 1 June 2016, Contractors will report threat-related incidents, behavioral indicators and other matters of Counter Intelligence (CI) interest specified in Chapter 3, to the Facility Security Officer (FSO), the nearest military CI office, the FBI, or the DCSA. Contractor employees working as an integral part of the Army organization ARE REQUIRED TO COMPLETE ANNUAL Threat Awareness training. Contractor FSOs will ensure that all applicable AR 381-12 requirements are implemented for personnel who work at contractor facilities.

Concurrence of the Contracting Officer and G-2 (Intelligence and Security), will be obtained prior to issue of a Limited Access Authorization to a non-U.S. citizen in compliance with the NISPOM. Controlled Unclassified information as defined in DoDI 5200.48, Controlled Unclassified Information (CUI), may be disclosed to U.S. persons who are employed by the prime contractor or subcontractors or to such employees who are foreign persons when requirements of export control and other laws are met. The contractor is responsible for compliance with all applicable laws and regulations governing access to Classified Information or Controlled Unclassified Information.

The contractor is not authorized to release any data to foreign nationals or foreign representatives without an approved export license.

HSPD-12 requires that contractor and all associated subcontractor employees shall provide all information required for background checks to meet installation access requirements of installation Provost Marshal Office, Director of Emergency Services or Security Office. Contractor workforce must comply with all personal identity verification requirements (FAR clause 52.204-9, Personal Identity Verification of Contractor Personnel) as directed by DOD, HQDA and/or local policy.

IAW with DOD 5200.01, Volume 3, at a minimum, all on-site support contractors with access to classified information shall receive annual refresher training that reinforces the policies, principles, and procedures covered in their initial and specialized training. A record of completion shall be provided to the CSA.

Questions concerning any aspect of security will be referred to G-2 (Intelligence and Security), USAAMCOM for resolution.

The technical point of contact is: William T Furgeson, Execution Lead Logistics Support Facility Management Activity

(LSFMA)

256-842-2646 (O) 931-801-1777 (C) william.t.ferguson.civ@army.mil

Prior to subcontracting with a foreign industry the U.S. contractor will consult with the Contracting Officer and G-2 (Intelligence and Security). Foreign sub-contractors must agree that only citizens of their country or the U.S. will be allowed to perform on the contract. The U.S. contractor is responsible for complying with the regulations outlined in the International Traffic in Arms Regulations (ITAR).

The contracting officer shall not consent to any subcontract with a firm, or a subsidiary of a firm, that is identified by the Secretary of Defense in SAM Exclusions as being owned or controlled by the government of a country that is a state sponsor of terrorism unless the agency head states in writing the compelling reasons for the subcontract. (Reference FAR 209.405-2)

Concurrence of the Contracting Officer and G-2 (Intelligence and Security), will be obtained prior to issue of a Limited Access Authorization to a non-US Citizen in compliance with the NISPOM. Controlled Unclassified Information, as defined in DoDI 5200.48, may be disclosed to U.S. persons who are employed by the prime contractor or subcontractor or to such employees who are foreign persons when requirements of export control and other laws are met. The contractor is responsible for compliance with all applicable laws and regulations governing access to classified information or Controlled Unclassified Information.

REF Item 11.m: Co-located/embedded contractor personnel will be required to take the following training annually: Security Refresher, Cyber Awareness Challenge (Information Assurance), Operation Security (OPSEC), Anti-Terrorism Level I Training and Threat Awareness and Reporting Program (TARP). All training is provided on site by the Government. No delivery is required. IAW AR 381-12, Threat Awareness and Reporting Program (TARP), 1 June 2016, Contractors will report threat-related incidents, behavioral indicators and other matters of Counter Intelligence (CI) interest specified in Chapter 3, to the Facility Security Officer (FSO), the nearest military CI office, the FBI, or the Defense Counterintelligence & Security Agency(DCSA). IAW AR 381-12, “Threat Awareness and Reporting Program (TARP)” dated 01 June 2016, contractors will report threat related incidents, behavioral indicators, and other matters of Counter Intelligence (CI) interest specified in chapter 3, to the Facility Security Office (FSO), the nearest military CI office, the FBI, or the DCSA. Contractor Employees working as an integral part of the Army organization are required to complete annual Threat Awareness training.

Contractor FSO’s will ensure that all applicable AR 381-12 requirements are implemented for personnel who work at contractor facilities.

AT Level I training. This standard language is for contractor employees with an area of performance within an Army controlled installation, facility or area. All contractor employees, to include subcontractor employees, requiring access to Army installations, facilities and controlled access areas shall complete AT Level I awareness training within 45 calendar days after contract start date or effective date of incorporation of this requirement into the contract, whichever is applicable. The contractor shall submit certificates of completion for each affected contractor employee and subcontractor employee, to the COR or to the contracting officer, if a COR is not assigned, within 45 calendar days after completion of training by all employees and subcontractor personnel. AT level I awareness training is available at the following website: http://jko.jten.mil.

The contracting officer shall not consent to any subcontract with a firm, or a subsidiary of a firm, that is identified by the Secretary of Defense in SAM Exclusions as being owned or controlled by the government of a country that is a state sponsor of terrorism unless the agency head states in writing the compelling reasons for the subcontract (Reference FAR 209.405-2).

Homeland Security Presidential Directive (HSPD)-12 requires that contractor and all associated subcontractor employees shall provide all information required for background checks to meet installation access requirements of installation Provost Marshal Office, Director of Emergency Services or Security Office. Contractor workforce must comply with all personal identity verification requirements (FAR clause 52.204-9, Personal Identity Verification of Contractor Personnel) as directed by DOD, HQDA and/or local policy.

Contractor personnel shall abide by all Government Regulations (ARs 380-5, 380-10, 380-40, 381-12, 25-2, 25-55, 190-13, and 530-1) and Standard Operating Procedures when working or visiting Government facilities. Contractor personnel are not authorized to take pictures with any form of camera inside Government facilities or on military installations without prior coordination with the Public and Congressional Affairs Office.

Contractor personnel requiring access to U.S. Army Computer Networks must complete the Army Cyber Awareness training, with exam, and sign an Acceptable Use Policy (AUP) of the installation/facility where the access is required. A copy of the Cyber Awareness Training certificate and AUP must be provided to the designated personnel at the Government facilities.

Contractor personnel, with a Government .mil computer account, shall include their company name on the line after their name, in the signature block. This requirement shall be subcontracted down with the subcontractor company name being inserted. Contractor shall ensure all employees are aware of this requirement. Contractor personnel shall utilize company e-mail for transmitting official U.S. Government business. Official U.S. Government business shall NOT be transmitted via personal, private, and commercial e-mail accounts, i.e. YAHOO, HOTMAIL, GMAIL, JUNO, AOL, etc. U.S. Army Cargo Helicopter information shall NOT be processed or stored on contractor employees’ personal computer or any other personally owned electronic devices.

As of 10 August 2017, there is a new CAC SOP. (Department of the Army Trusted Associate Sponsorship System (TASS) Standard Operating Procedure and Army TASS Policy. The Cargo PO holds final determination on the approval for Common Access Cards (CACs). Consideration for a CAC will be addressed on a case-by-case basis. CACs will be considered for contractor employees that are deploying, that work full time on a military installation, and for contractor employees that require frequent access to multiple DOD installations in support of this contract for test. Contractor employees issued a CAC shall maintain possession of their CAC at all times, and shall not share their CAC PIN with anyone. The CAC will not be used in temporary badge exchanges. CACs will not be left unattended in computer. Justification, to include list of multiple DOD facilities, must be included with each request for a CAC.

CACs are the property of the U.S. Government and shall be given to the Cargo PO Security Manager or Government Trusted Agent (TA) upon termination of employment with the company, or upon contract completion. The loss of a CAC shall be reported, on the first business day following the discovery of the lost CAC, to your chain of command, FSO, COR, and to the issuing agency.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .