Attachment 0034- Additional Guidelines for Controlled Unclassified Information.docx
DOCX document 114 KB Posted
- Attached to
- Water Storage Distribution System (Solicitation) Federal contract opportunity
- Solicitation number
- W56HZV21R0011
About this file
This document outlines requirements for a federal procurement of water storage and distribution systems. The U.S. Army Contracting Command-Detroit Arsenal intends to award multiple IDIQ contracts for the integration, assembly, and logistics of up to 123 water storage systems with capacities of 100k gallons or split capacities of 2 units of 50k gallons each. The contracts may also include options for up to 150 spare 350 GPM fluid distribution pumps. The water storage systems provide bulk water storage and distribution capabilities. The resulting contracts will be five-year firm fixed price IDIQ contracts with two additional option years. This procurement is set aside exclusively for small businesses. Interested parties should contact the listed buyer for additional details.
View the file
Other files for this federal contract opportunity
Show all 50
Water Storage Distribution System (Solicitation) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
2020 Nov 18
ADDITIONAL GUIDELINES FOR CONTROLLED UNCLASSIFIED INFORMATION
General: There are types of information that are not classified but that require application of access and distribution controls and protective measures for a variety of reasons. This information is known as “controlled unclassified information (CUI).” The types of information considered CUI for the program are information marked “For Official Use Only” by the U.S. Government and technical data. When handling CUI material, all personnel are to comply with these requirements and follow their company policy and/or applicable Proprietary Information Agreements (PIA) concerning the protection of proprietary information in situations not clearly stated herein.
Technical Data Description: Any recorded information related to experimental, developmental, or engineering works that can be used to define an engineering or manufacturing process, or can be used to design, procure, produce, support, maintain, operate, repair, or overhaul program material. The data may be graphic or pictorial delineations in media (e.g., computer software, drawings, or photographs), text in specifications, related performance or design documents, or computer printouts. Examples of technical data include research and engineering data, engineering drawings, and associated lists, specifications, standards, process sheets, manuals, technical reports, catalog-item identifications, and related information, and computer software documentation.
For Official Use Only (FOUO) Information Description: “For Official Use Only (FOUO)” is a Government designation applied to unclassified information that may be exempt from mandatory release to the public under the Freedom of Information Act (FOIA). FOUO information includes information identified as such in the Security Classification Guide or information from a government document marked FOUO.
CUI Markings Marking of FOUO documents will be in accordance with Army Regulation (AR) 25-55. Information extracted from an FOUO document will carry the FOUO marking until formally reviewed by the government.
AR 25-55 can be found at https://armypubs.army.mil/epubs/DR_pubs/DR_a/ARN30378-AR_25-55-000-WEB-1.pdf . Comment by Espino, Kelly A Ms CIV USA PEO CS&CSS: This link does not work.
| Suggest just using https://armypubs.army.mil/ | Comment by Donahoe, Gregory S CIV USARMY ACC (US): Changed. | |
| Marking of Technical Data will include the applicable Distribution Statement which the contractor shall obtain from the Assistant Program Manager prior to marking. If the contents of the technical document require more than one Distribution Statement, apply the most restrictive statement. This does not preclude additional mandated markings as may be required by the contract. | Comment by Espino, Kelly A Ms CIV USA PEO CS&CSS: Do we include the Security Classification Guide as an attachment to the contract? | Comment by Donahoe, Gregory S CIV USARMY ACC (US): Changed. |
Protection of CUI Information Access: CUI may be released only to an individual who has a valid need for such access in connection with the accomplishment of a lawful and authorized Government purpose. Information in any media format may only be disseminated on a need-to-know basis. The need-to-know restricts the use or dissemination of CUI data to those individuals or organizations with direct affiliation with the given program or project. Further dissemination of such information will be at the discretion of the Government Security Manager. Personnel no longer requiring access to CUI must dispose (see “Disposal” below) or surrender any in their possession and terminate future access to it.
Storing/Handling: During working hours, take reasonable steps to minimize risk of access to CUI by unauthorized personnel. After working hours, when not in physical possession of the owner, all CUI (whether hardcopy or media that contains CUI) must be afforded a reasonable degree of physical protection to prevent theft of program information (e.g., store CUI information in locked desks or file cabinets, locked rooms, cable lock laptops, storing in a trunk, storing out of site or similar means). Do not display CUI in public places (e.g., airports, airplanes, restaurants). Computers used to process CUI do not need to be accredited for classified use, but shall be in accordance with DFARS 252.204-7012 Safeguarding of Unclassified Controlled Technical Information. Do not process CUI on public computers (e.g., those available for use by the general public in kiosks, hotel business centers), public wireless networks or computers that do not have access control. Personally owned computers and personally owned devices are not authorized to process CUI. Mobile devices used to store CUI electronically (e.g., company-issued laptops, personal electronic devices [PED]) must be physically protected and use NIST/NIAP-approved cryptographic products/algorithms. These are available at http://iase.disa.mil/pki/eca or http://csrc.nist.gov/cryptval/. All media shall be marked in accordance with the marking guidance provided by the APM and protected as below: Comment by Espino, Kelly A Ms CIV USA PEO CS&CSS: Same as above. What Security Classification Guide? Are we providing? Comment by Donahoe, Gregory S CIV USARMY ACC (US): Changed.
· Portable electronic devices (e.g., smartphones, laptop computers, tablets) and removable media (e.g., external hard drives, flash drives, USB drives; not including optical media) must be physically and electronically protected as described in this instruction.
· Optical Media (e.g., DVDs, CDs) and non-portable computers (e.g., desktop or tower computers) are required to be physically protected; however, they are not required to be electronically protected as described in this instruction.
Dissemination: CUI printed documents and material may be transmitted through mail channels, commercial carrier or hand-carried without formal courier orders. FOUO information may be disseminated to DoD personnel and DoD contractors to conduct official business for the program. If dissemination is required outside of DoD personnel or DoD contractors, contact the Government Security Manager for approval. Technical data will follow the release instructions identified in the Distribution Statement. Use secure communications whenever possible; however, land-line telephones are more secure than cellular telephones and should be used whenever available for discussions involving CUI. Transmit voice and facsimile transmissions only when you have a reasonable assurance that only authorized recipients will have access to the transmission. Digital transmission shall comply with the below:
All transmission and/or dissemination of CUI (i.e., email and file transfers) must use NIST/NIAP-approved cryptographic products/algorithms, e.g., DoD Secure Access File Exchange (SAFE); https://safe.apps.mil/.
· Contractor-hosted collaborative suites may be used for digital transmission and/or dissemination of CUI by personnel not located on a government backbone (e.g., NIPRNET), provided the following conditions apply:
· Use only NIST/NIAP-approved cryptographic products/algorithms. The latest validation lists may be obtained at http://iase.disa.mil/pki/eca or http://csrc.nist.gov/cryptval/.
· Use an internally hosted service that does not use a third-party collaborative suite service provider.
· Do not post CUI to web pages that are publicly available or have access limited only by domain/IP restrictions. As permitted by other contract provisions, CUI may be posted to web pages that control access through the use of a DoD approved Public Key Infrastructure Certification and that provide protection via use of secure sockets, or other equivalent technologies. These are available at http://iase.disa.mil/pki/eca.
· As new technologies become available in the electronics arena, care should be given to providing a reasonable degree of protection from known vulnerabilities.
· The Internet is “Public Access.” CUI must be reviewed and officially approved by the PEO GCS Public Affairs Officer for public release before placing on the Internet. This is not applicable when the Internet is used for e-mail transmissions and encryption is used as noted above.
Disposal: Destroy CUI documents by any means approved for the destruction of classified information, i.e. cross-cut shredding or other means that would make it difficult to recognize or reconstruct the information. Clear, purge, or destroy CUI on removable media IAW BBP 03-PE-O-0003 Army Information Assurance Sanitization of Media to AR 25-2. This is available at https://informationassurance.us.army.mil.
Report of Loss of CUI: Report any loss of CUI or loss of CUI from a contractor information system that is known to the contractor within the period of performance of this contract to the Government Security Manager. Initial reports shall be made as expeditiously as possible in all cases within 72 hours of discovery. If additional information is required after submission and review of the initial report, guidance will be provided at that time. Mark any reports For Official Use Only, exemptions 2 and 5 apply. Initial report content shall include the following information as available.
· Applicable dates, including dates of compromise and dates of discovery
· Threat methodology, including all known resources used (e.g. IP addresses, domain names, software tools)
· Account of what actions the threat(s) may have taken on victim system/network
· What information may have been compromised, exfiltrated, or lost, and its potential impact on government programs Report of Cyber Intrusions: Report cyber intrusions or other compromises of CUI to your supporting counterintelligence office, which will inform the DoD-DIB Common Information Sharing Environment (DCISE). Notify the Government Security Manager of any incidents as well. Refer to Report of Loss of CUI for what needs to be reported, when, and how.
image1.emf
CUI Registry Common Categories.pdf
Organizational Index Grouping CUI Categories Category Marking Category Description
Emergency Management EMGT Related to information concerning the continuity of executive branch operations during all-hazards emergencies or other situations that may disrupt normal operations.
Physical Security (PHYSEC) PHYS Related to protection of federal buildings, grounds or property.
Defense Controlled Technical Information (CTI) CTI
Controlled Technical Information means technical information with military or space application that is subject to controls on the access, use, reproduction, modification, performance, display, release, disclosure, or dissemination. Controlled technical information is to be marked with one of the distribution statements B through F, in accordance with Department of Defense Instruction 5230.24, "Distribution Statements of Technical Documents." The term does not include information that is lawfully publicly available without restrictions. "Technical Information" means technical data or computer software, as those terms are defined in Defense Federal Acquisition Regulation Supplement clause 252.227-7013, "Rights in Technical Data - Noncommercial Items" (48 CFR 252.227-7013). Examples of technical information include research and engineering data, engineering drawings, and associated lists, specifications, standards, process sheets, manuals, technical reports, technical orders, catalog-item identifications, data sets, studies and analyses and related information, and computer software executable code and source code.
Export Control Export Controlled EXPT
Unclassified information concerning certain items, commodities, technology, software, or other information whose export could reasonably be expected to adversely affect the United States national security and nonproliferation objectives. To include dual use items; items identified in export administration regulations, international traffic in arms regulations and the munitions list; license applications; and sensitive nuclear technology information.
Budget BUDG Related to information concerning the federal budget, including authorizations and estimates of income and expenditures.
General Financial Information FNC Related to the duties, transactions, or otherwise falling under the purview of financial institutions or United States Government fiscal functions. Uses may include, but are not limited to, customer information held by a financial institution.
International Agreements International Agreement Information INTL
Information provided by, otherwise made available by, or produced in cooperation with, a foreign government or international organization that requires protection pursuant to an existing treaty, agreement, bilateral exchange or other obligation under the requirements stipulated in 10 USC 130c(b), when not subject to classification under Executive Order 13526. Title 10 USC 130c(b) may exempt this class of foreign government information from the safeguard provisions otherwise required by Executive Order 13526. Per Title 10 USC 130c(h) the following national security officials are the only ones defined by statute as able to determine such information requires control: (A) The Secretary of Defense, with respect to information of concern to the Department of Defense. (B) The Secretary of Homeland Security, with respect to information of concern to the Coast Guard, as determined by the Secretary, but only while the Coast Guard is not operating as a service in the Navy. (C) The Secretary of Energy, with respect to information concerning the national security programs of the Department of Energy, as determined by the Secretary.
Administrative Proceedings ADPO Adjudication of agency-related matters including, but not limited to, dispute resolution, settlements, and issuances of orders.
Collective Bargaining BARG Defining agencies' and representatives' duty to negotiate in good faith to include disclosure of certain labor relations training and guidance materials and limiting the issuance of certain subpoenas.
Contract Use CONTRACT Stipulations for a contractor to meet before material may be used in performance of certain contracts.
General Privacy PRVCY Refers to personal information, or, in some cases, "personally identifiable information," as defined in OMB M-17-12, or "means of identification" as defined in 18 USC 1028(d)(7).
Health Information HLTH
As per 42 USC 1320d(4), "health information" means any information, whether oral or recorded in any form or medium, that (A) is created or received by a health care provider, health plan, public health authority, employer, life insurer, school or university, or health care clearinghouse; and (B) relates to the past, present, or future physical or mental health or condition of an individual, the provision of health care to an individual, or the past, present, or future payment for the provision of health care to an individual.
Military Personnel Records MIL Any member or former member of the armed forces or affiliated organization of the Department of Defense.
Personnel Records PERS Related to the employees of federal agencies.
General Procurement and Acquisition PROCURE Material and information relating to, or associated with, the acquisition and procurement of goods and services, including but not limited to, cost or pricing data, contract information, indirect costs and direct labor rates.
Source Selection SSEL
Per FAR 2.101: any of the following information that is prepared for use by an agency for the purpose of evaluating a bid or proposal to enter into an agency procurement contract, if that information has not been previously made available to the public or disclosed publicly: (Items 1-10).
Provisional Operations Security (OPSEC) OPSEC Unclassified information that could constitute an indicator of U.S. Government intentions, capabilities, operations, or activities or otherwise threaten/compromise operations security.
Common CUI Registry Categories
Critical Infrastructure
Financial
Legal
Privacy
Procurement and Acquisition
Sheet1
File details come from the government source that posted it. Updated .