Attachment 03 DD Form 254 FMS Apache Transition Training Support 20241022.pdf
PDF 214 KB Posted
- Attached to
- Apache AH-64 Transition Training Support (ATTS)-Amd 01 Cancelation Federal contract opportunity
- Solicitation number
- W900KK-25-R-0002
About this file
This document is a DD Form 254, Department of Defense Contract Security Classification Specification, for a federal contract opportunity related to Apache AH-64 Transition Training Support (ATTS).
The key details are:
- The contract requires qualified proposals to provide ATTS to the U.S. Government and Foreign Military Sales customers, to ensure personnel are qualified and trained to effectively transition operations from previous Apache versions to the AH-64E V6 and subsequent versions.
- The contract is a 5-year, single-award, indefinite delivery/indefinite quantity (ID/IQ) contract.
- The contract requires compliance with security regulations, including the NISPOM Rule, DoDI 5200.48 on Controlled Unclassified Information (CUI), and other relevant Army security policies.
- The contractor must follow specific security requirements for handling classified information, COMSEC, NATO, and CUI, including training, storage, transmission, and reporting requirements.
- The government contracting activity is the Army Contracting Command Orlando (ACC-Orlando) on behalf of the Program Executive Office for Simulation, Training, and Instrumentation (PEO STRI).
View the file
Other files for this federal contract opportunity
Show all 16
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Please wait...
If this message is not eventually replaced by the proper contents of the document, your PDF viewer may not be able to display this type of document.
You can upgrade to the latest version of Adobe Reader for Windows®, Mac, or Linux® by visiting http://www.adobe.com/go/reader_download.
For more assistance with Adobe Reader visit http://www.adobe.com/go/acrreader.
Windows is either a registered trademark or a trademark of Microsoft Corporation in the United States and/or other countries. Mac is a trademark of Apple Inc., registered in the United States and other countries. Linux is the registered trademark of Linus Torvalds in the U.S. and other countries.
PREVIOUS EDITION IS OBSOLETE.
Page of
DD FORM 254, APR 2018
NEEDS DD67
DEPARTMENT OF DEFENSE
CONTRACT SECURITY CLASSIFICATION SPECIFICATION
(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)
OMB No. 0704-0567 OMB approval expires:
June 30, 2025 The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.
RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.
1. CLEARANCE AND SAFEGUARDING
2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)
3. THIS SPECIFICATION IS: (X and complete as applicable.)
a. ORIGINAL (Complete date in all cases.)
b. REVISED (Supersedes all previous specifications.)
4. IS THIS A FOLLOW-ON CONTRACT?
If yes, complete the following:
Classified material received or generated under
5. IS THIS A FINAL DD FORM 254?
If yes, complete the following:
6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)
7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor)
8. ACTUAL PERFORMANCE (Click button to add more locations.)
10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)
e. NATIONAL INTELLIGENCE INFORMATION:
11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)
12. PUBLIC RELEASE
Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)
13. SECURITY GUIDANCE
The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.
(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)
List of Attachments (All Files Must be attached Prior to Signing, i.e., for any digital signature on the form)
14. ADDITIONAL SECURITY REQUIREMENTS
Requirements, in addition to NISPOM requirements for classified information, are established for this contract.
If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)
15. INSPECTIONS
Elements of this contract are outside the inspection responsibility of the CSO.
If Yes, explain and identify specific areas and government activity responsible for inspections. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)
16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)
17. CERTIFICATION AND SIGNATURES
Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below. Upon digitally signing Item 17h, no changes can be made as the form will be locked.
18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL
9.0.0.2.20120627.2.874785 DD 254, "DoD Contract Security Classification Specification"
| CurrentPage: |
| PageCount: |
| Select classification from drop-down list.: Unclassified |
| SerialNum: |
| a. Facility clearance level. Select one.: 2 |
| b. Level of safeguarding for classified information/material required at contractor facility. Select one.: 4 |
| Select for "original.": 1 |
| Select for "original.": 1 |
| Enter prime contract number.: TBA |
| Select for "revised.": 0 |
| Select for "revised.": 0 |
| Enter subcontract number.: |
| Select for "final.": 0 |
| Select for "final.": 0 |
| Enter solicitation or other number.: |
| Enter due date in format YYYYMMDD.: |
| Enter date in format YYYYMMDD.: |
| Enter revision number.: |
| Enter date in format YYYYMMDD.: |
| Enter final specification.: |
| Enter date in format YYYYMMDD.: |
| Select for "no.": 1 |
| Select for "no.": 1 |
| Select for "no.": 1 |
| Select for "no.": 1 |
| Select for "yes.": 0 |
| Select for "yes.": 0 |
| Select for "yes.": 0 |
| Select for "yes.": 0 |
| Enter preceding contract number.: |
| Enter contractor's request date in format YYYYMMDD.: |
| Enter period.: |
| Enter typed name of certifying official (last, first, middle initial).: TBA |
| Enter typed name of certifying official (last, first, middle initial).: N/A |
| Enter typed name of certifying official (last, first, middle initial).: Nguyen, Tam |
| Enter CAGE code of the prime contractor.: TBA |
| Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: TBA |
| Select to add row to locations.: |
| Select to remove last row from locations.: |
| Select to delete all signatures.: |
| Enter location(s).: DoD Installations |
Foreign Partners' Installation
| Enter general unclassified description of this procurement.: Provide services to qualify/train operators, maintainers, MTPs and support personnel in the AH64E, transition from their current AH-64 configuration to the AH-64E V6 (and beyond) configuration, train new mission system, and provide training to support their current fleet. |
| Select for "a. CONTRACTOR.": 1 |
| Select for "a. CONTRACTOR.": 1 |
| Select for "a. CONTRACTOR.": 1 |
| Select for "f. OTHER AS NECESSARY.": 0 |
| Select for "f. OTHER AS NECESSARY.": 1 |
| Select for "f. OTHER AS NECESSARY.": 0 |
| Select for "b. SUBCONTRACTOR.": 0 |
| Select for "b. SUBCONTRACTOR.": 0 |
| Select for "b. SUBCONTRACTOR.": 0 |
| Select for "g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE TECHNICAL INFORMATION CENTER (DTIC) OR OTHER SECONDARY DISTRIBUTION CENTER.": 1 |
| Select for "g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE TECHNICAL INFORMATION CENTER (DTIC) OR OTHER SECONDARY DISTRIBUTION CENTER.": 1 |
| Select for "c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR.": 0 |
| Select for "c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR.": 0 |
| Select for "c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR.": 1 |
| Select for "h. REQUIRE A COMSEC ACCOUNT.": 1 |
| Select for "h. REQUIRE A COMSEC ACCOUNT.": 0 |
| Select for "d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION.": 0 |
| Select for "d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION.": 0 |
| Select for "d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION.": 0 |
| Select for "i. HAVE A TEMPEST REQUIREMENT.": 0 |
| Select for "i. HAVE A TEMPEST REQUIREMENT.": 0 |
| Select for "e. NATIONAL INTELLIGENCE INFORMATION: - (1) Sensitive Compartmented Information (SCI).": 0 |
| Select for "e. NATIONAL INTELLIGENCE INFORMATION: - (2) Non-SCI.": 0 |
| Select for "j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS.": 1 |
| Select for "j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS.": 1 |
| Select for "k. BE AUTHORIZED TO USE DEFENSE COURIER SERVICE.": 1 |
| Select for "k. BE AUTHORIZED TO USE DEFENSE COURIER SERVICE.": 0 |
| Enter infomration for "other.": SIPRNET |
| Enter infomration for "other.": Dual Citizens |
| Select for "e. ADMINISTRATIVE CONTRACTING OFFICER.": 0 |
| Select for "e. ADMINISTRATIVE CONTRACTING OFFICER.": 1 |
| Select for "l. RECEIVE, STORE, OR GENERATE CONTROLLED UNCLASSIFIED INFORMATION (CUI). .": 1 |
| Select for "m.OTHER.": 1 |
| Select for "direct.": 0 |
| Select for ": 1 |
| Enter specification for "through".: ACC-Orlando, KO |
| Enter public release authority.: PEO STRI: PAO |
12211 Science Dr., Orlando, FL 32826
| Select to add signature.: |
| Select to remove last signature.: |
| text: |
Item 13. Security Guidance and CUI information supporting this DD254 ***The contract expires on 30 April 2030***
GENERAL GUIDANCE:
1. The contractor and subcontractor(s) shall comply with the Security Agreement (DD Form 441) and following Security Regulations (DoDM 5200.01 Volumes 1 thru 3), 32 CFR part 117 NISPOM Rule, DoDI 5200.48 Controlled Unclassified Information (CUI), AR 25-2 Information Assurance, AR 380-5 Information Security, AR 380-49 Industrial Security, AR 380-10 current versions and affiliated regulations.
2. The contractor and subcontractor employees requiring access to DoD government or DoD contractor's facilities where proof of a security clearance is required, shall meet the security access requirements specified by the host and/or owner of those facilities per FAR 52.204-9, Personal identity verification of contractor personnel.
3. Any prime contractors to include subcontractors that are USA Foreign Owned, Controlled and Influenced (FOCI) company that have been granted a Facility Security Clearance (FCL) under a Special Security Agreement (SSA) by the Defense Counterintelligence Security Agency (DCSA) are authorized to work on this contract. Contractors/Private Industries who do not have their FOCI mitigated by DCSA and do not possess a FCL and SSA are not authorized to perform on this contract.
4. The contractor is not authorized to disclose collateral Classified Military Information (CMI) information to the public.
a. The contractor is not authorized to disclose or release Controlled Unclassified Information (CUI) pertaining to this contract to the public without prior review and approval from the Requiring Activity OPSEC Officer, Legal and Public Affairs Officer. Requests for disclosure or release shall be submitted 10 working days in advance to the address specified in block 12.
b. The contractor is not authorized to disclose or release any program Classified Military Information (CMI) Controlled Unclassified Information (CUI) Technical Data, Information pertaining to this contract to any Foreign Nationals or Foreign Representatives.
5. The contractor shall only issue security clearances to those employees who meet the personal security requirements stated in the 32 CFR part 117.10 NISPOM, DoDM 5105.21 V1-3 and who require access to classified information based on a Need-to-Know.
a. For collateral security clearances and access, the contractor shall follow the Security guidelines established in 32 CFR part 117.10 NISPOM and the Defense Counterintelligence Security Agency (DCSA) Facility Security Officer Toolkit located at https://www.cdse.edu/toolkits/fsos/index.php
b. For TS/SCI security clearances and access, the contractor shall follow the Security guidelines listed in the SCI addendum to this contract. (For SCI Only)
c. Contractors who do not require a security clearance but require a Government Common Access Card (CAC) must have a Tier 1 security investigation and follow the credentialing requirements of this contract!
6. The contractor and subcontractors shall ensure that all Classified information, Controlled Unclassified Information (CUI), Controlled Technical Information (CTI) documents, data and or export controlled information; is marked, handled and safeguarded with the appropriate security classification, distribution statement(s) and export control warning statement in accordance with DFARS 204.4 Safeguarding Classified Information within Industry, DoDD 5230.24, DoDI 5200.48, 32 CFR part 117.15 NISPOM, DoDM 5105.21 V1-3, and DoDM 5200.01 Vol 1-3.
a. The contractor and subcontractors shall NOT ACCEPT any documents, data or information from any source including the government requiring activity unless the documents, data or information is marked.
7. The prime contractor is responsible for vetting all subcontractors for eligibility, suitability prior to issuing a subcontractor DD Form 254, 32 CFR part 117.17 NISPOM Rule and AR 380-49. The prime contractor shall issue the PEO STRI vendor vetting process letter to all subcontractors to fill out and respond to.
a. The prime contractor is responsible for issuance of all subcontractor DD254 per 32 CFR Part 117.17 NISPOM Rule.
b. All contractors must be vetted for suitability and eligibility to receive Federal Contract Information and Controlled Unclassified Information prior to being allowed to do business with the Department of Defense or Department of the Army.
c. The prime contractor shall follow DCSA sponsorship procedures (if required) only to those not cleared Subcontractor companies for a FCL who require access to classified data/information for this contract. The government nor the prime contractor shall not incur any cost in this process.
d. The prime contractor FSO will provide the KO and/or COR with a copy of all subcontract DD Form 254s to be attached to the prime contract. The KO and/or COR will provide a copy of all subcontract DD Form 254’s to the ISS and DCSA.
8. Contractor shall comply with FAR 52.204-2 “Security Requirements”. This clause involves access to information classified “Confidential,” “Secret,” or “Top Secret”. The Contractor shall comply with (1) Security Agreement (DoD Form 441), including the 32 CFR part 117 NISPOM.
9. The contractor will use the following Security Classification Guides (SCG), and/or the latest changes, revisions, and amendments for the duration of this contract:
o AH-64 Apache Attack Helicopter (AAH) SCG, dated 2 April 2021, o Anti-Tamper, dated 17 March 2010.
o Anti-Tamper Security Classification Guide Change 1, dated 18 April 2011.
o Anti-Tamper Security Classification Guide Change 2, dated 19 May 2014.
10. Contractors who work in a DoD or Contractor cleared facility on DA installations and or government leased facilities and who are embedded or integrated within a DA program or activity, shall report all adverse information, suspicious contacts, and other reportable incidents to the KO, COR, ISS and local security office per AR 380-49 and DFARS 252.204-7012 Safeguarding covered defense information and cyber incident reporting.
11. The contractor and their subcontractors shall immediately report any loss, compromise, suspected compromise/incidents of classified information or any security violations, or incidents involving a contractor employee, which occurs on this contract per 32 CFR part 117.8(d) NISPOM Rule to their Facility Security Manager (FSO) and local DCSA office. The contractor shall also inform the KO, COR, and the ISS.
12. The contractor shall not allow foreign nationals or foreign persons to visits, participate in demonstrations, or have access to this project effort without first getting the requiring activity Foreign Disclosure Office (FDO) written approval, 5 days in advance of any visit/access request. The contractor shall adhere to DFARS 252.204-7000, Disclosure of Information, 32 CFR, part 117 and AR 380-10 as it relates to foreign visits, meetings, and disclosure etc. SCI is NOT authorized for foreign disclosure or release!
13. The contractor and their subcontractors will designate in writing a U.S. citizen (not a dual citizen) as the Insider Threat program official 32 CFR part 117.12(g). All contractors with security clearances shall comply with Insider Threat Training requirements per 32 CFR part 117.12(g). Additionally, the contractor shall report threat-related incidents, behavioral indicators to the Requiring Activity Cognizant Security Office. Insider Threat training information can be found at the following DCSA site https://www.cdse.edu/
14. The prime contractor and subcontractors shall ensure that all contract employees with security clearances meet the annual security training required by 32 CFR part 117.12, DoDI 5200.48, AR 380-5 and AR 381-12:
REQUIRED ANNUAL SECURITY TRAINING
The contractor shall read and execute the below listed annual security training requirements for only those employees who have security clearances and access to CUI on this contract;
Threat Awareness Reporting Program (TARP) All contractors and subcontractors with security clearances must receive annual Threat Awareness and Reporting Program (TARP) training per AR 381-12. The training should be provided by a CI agent or other trainer as specified in 2-4b and chapter 3 AR 381-12.
The Contractor shall ensure its employees report threat-related incidents, behavioral indicators, and other matters of CI interest specified in the AR 381-12, to their FSO and the PEO STRI G2 Office, the nearest military CI office, the Federal Bureau of Investigation, or the Defense Security Service.
OPSEC Awareness Training - Per AR 530-1 Operations Security, the contractor employees working on this contract must complete Level I OPSEC Awareness training. New employees must be trained within 30 calendar days of their start date on this contract and annually thereafter. OPSEC Awareness training information and materials are available at https://securityawareness.usalearning.gov/opsec/index.htm
Insider Threat Training - The contractor and their subcontractors will designate in writing a U.S. citizen as the Insider Threat program official per 32 CFR part 117.12(g) NISPOM Rule. All contractors shall comply with Insider Threat Training requirements per 32 CFR part 117.12(g) NISPOM Rule. Insider threat program information and materials are available at https://securityawareness.usalearning.gov/itawareness/index.htm
DoD Annual Security Awareness Refresher Training - All contractor employees working on this contract with a security clearance must complete the annual SCI security awareness refresher training. New employees must complete the initial security training and the security awareness refresher training annually thereafter. This training refreshes the employee’s basic understanding of initial security training requirements outlined in DoDM 5100.21 Volume 3 enclosure 6, and 32 CFR part 117.12 and other applicable policies and regulations. This training is available at https://securityawareness.usalearning.gov/awarenessrefresher/index.html
Controlled Unclassified Information Training - This contract contains CUI, all contractors shall have only those employees who handle CUI take annual CDSE CUI Training required for all DoD and Industrial personnel with access to controlled unclassified information. New employees must complete this training 30 day from start day of the contract. No CAC or password needed the training website also provides a resource tab which lists regulations, policies and more information on the subject. https://securityawareness.usalearning.gov/cui/index.html
Unauthorized Disclosure of Classified Information for DoD and Industry Contractor employees working on this contract with security clearances must complete the annual Unauthorized Disclosure of Classified Information for DoD and Industry training. New employees must complete this training 30 day from start day of the contract. This training provides an overview of what unauthorized disclosure is, including specific types of unauthorized disclosure and some common misconceptions about unauthorized disclosure, the types of damage caused by unauthorized disclosure and the various sanctions one could face if caught engaging in unauthorized disclosure. This training is available at https://securityawareness.usalearning.gov/disclosure/index.html
AT Awareness Training for Contractor Personnel Traveling to Military Installations and Overseas. The contractor FSOs and associated subcontractor FSOs will brief and make available government area of responsibility (AOR) specific AT awareness training and information to employees traveling to military installations and overseas as directed by AR 525-13. Specific AOR training content is directed by the combatant commander with the unit ATO being the local point of contact. AT level I awareness training meets this requirement and is available at the following website: https://atlevel1.dtic.mil/at/
DCSA provides the Facility Security Officer (FSO) Toolkit located at https://www.cdse.edu/toolkits/fsos/index.php
15. SELF EMPLOYED CONSULTANTS – The requiring activity security office shall be notified of all consultants who work for or support the contractor (prime and subs) for this effort! The contractor who employs or has consultants on their team shall provide a copy of all consultant certificate/agreements to the requiring activity COR and security office per 32 CFR part 117.9(l).
16. Work shall also be performed on a TDY status at Government installations and other CONUS and OCONUS locations as required to support the requirements of this contract as validated by the PEOSTRI International Aviation Office Technical Point of Contact (POC) and/or the Statement of Work/Performance Work Statement.
17. The PEOSTRI International Aviation Office Technical POC is Tanya Caceres, SFAE-STRI-IPO, 407-669-8177, tanya.e.caceres.civ@army.mil.
ITEM 10:
Ref 10a: Classified COMSEC material is not releasable to contractor employees who have not received a FINAL clearance at the appropriate security level. COMSEC access shall be IAW the 32 CFR 117 and AR 380-40. When access is required at Government facilities, contractor personnel will adhere to COMSEC rules and regulations as mandated by Command policy and procedures. Written concurrence of the KO is required prior to subcontracting. In addition, the prime contractor must notify the National Security Agency Central Office of Record before negotiating or awarding subcontracts.
Ref 10g: Personnel who require access to NATO classified information, NATO COSMIC, NATO Secret or access to the NATO accredited SIPRNET terminals, must possess a FINAL clearance based upon the appropriate personnel security investigation required. Personnel with access to NATO ATOMAL information must possess a FINAL clearance. The government program/project manager will ensure the contractor personnel are NATO briefed prior to access. Prior approval from the KO is required for subcontracting.
Ref 10h: Foreign Government Information is not releasable to contractor employees who have not received a FINAL clearance at the appropriate security level. Written concurrence of the KO is required prior to subcontracting.
Ref 10j: Controlled Unclassified Information generated and/or provided under this contract is identified as CUI 2b below and shall be marked, safeguarded and protected in accordance with DoDI 5200.48.
Ref 10K: The contractor shall not access, download or further disseminate any special access data (i.e. intelligence, NATO, COMSEC, etc.) outside the execution of the defined contract requirements and without the guidance and written permission of the KO. The contractor must complete the SIPRNET Access Request Form, and forward to the KO prior to receiving access. Additionally, a NATO briefing will also be required prior to access to the SIPRNET.
ITEM 11:
Ref Item 11.a: ACCESS TO CLASSIFIED INFORMATION ONLY AT ANOTHER CONTRACTORS FACILITY OR A GOVERNMENT ACTIVITY – Contractor performance is restricted to the names in block 8a. Government agency or activity will provide security classification guidance for performance of this contract. Submit visit request to the Facility Security Officer (FSO), Security Management Office via DISS for need-to-know verification and access.
Ref Item 11.f: ACCESS TO U.S. CLASSIFIED INFORMATION OUTSIDE THE U.S - This contract may require your company to have access to classified information in an overseas area. The specific overseas area(s) will be provided by the Contract Monitor or the Contracting Officer. Classified information or materials will remain under the direct control of the US government while in an overseas area unless prior approval is granted by this command. Release of classified information to a foreign entity will be accomplished in accordance with 32 CFR part 117.19 NISPOM Rule and AR 380-10.
Ref Item 11.g: AUTHORIZED TO USE DEFENSE TECHNICAL INFORMATION CENTER (DTIC) - The contractor is authorized to use the services of Defense Technical Information Center (DTIC) and is required to prepare and process a DD Forms 1540 and 2345 to registration for Scientific and Technical Information Services. The contracting activity must be involved in certifying need-to-know to DTIC.
Ref Item 11.j: OPERATIONS SECURITY (OPSEC) REQUIREMENTS - The contractor shall develop, implement, and maintain a facility level OPSEC program to protect classified and/or sensitive unclassified information used at the contractor, government and other contractor facilities during the performance of this contract. The OPSEC requirements may be included in the Vendor’s/Contractor’s Standard Practice Procedures (SPP) or Technology Control Plan (TCP), whichever is more applicable.
Ref Item 11.l: RECEIVE, STORE OR GENERATE CONTROLLED UNCLASSIFIED INFORMATION (CUI) – For Controlled Unclassified Information (CUI) provided under this contract shall be safeguarded and marked as specified in DoDI 5200.48. CUI information that is export controlled shall not be shared with any foreign nationals unless approved by the Requiring Activity security office along with the approved State Department license. (See the CUI below paragraph 8 Dissemination).
a. COMPILATION - The contractor shall be aware of certain information that would otherwise be unclassified or CUI when standing alone may require classification when combined or associated with other unclassified or CUI information. The determination that information requires classification by compilation will be based on specific guidance regarding compilation provided in a Security Classification Guide (SCG) or from the information/data owner. When classification is required to protect a compilation of such information, the overall classification assigned to the compilation shall be conspicuously affixed. The reason for classifying the compilation shall be stated at an appropriate location at or near the beginning of the compilation. Any unclassified or CUI portions will be portion marked (U) or (CUI), while the overall markings will reflect the classification of the compiled information.
Ref Item 11.M: Dual Citizens: The contractor FSO must maintain a list of all dual citizen employees and provide that list upon inspection from DCSA or the cognizant security authority ISS. Contractors’ employees who are dual citizens and have access to software and technical data must have the appropriate security clearance in accordance with the current version of 32 CFR part 117 NISPOM Rule.
“CONTROLLED UNCLASSIFIED INFORMATION (CUI) ” SECTION
1. GENERAL:
The contractor shall adhere to DoDI 5200.48 CUI and Army Controlled Unclassified Information (CUI) guidance as it relates to controlling, marking, safeguarding, storage and disposal of CUI materials on this contract /agreement.
2. IDENTIFYING CUI.
a. The official CUI Registry approved by the CUI Executive Agent identifies all approved CUI categories; provides general descriptions for each; identifies the basis for controls; establishes markings, and includes guidance on handling procedures. The Contractor shall refer to the CUI Registry’s category listing found at https://www.archives.gov/cui/registry/category-list to determine if information can be designated as CUI. The contractor shall also coordinate with the COR/AOR for support and advice.
b. The authorized holder (originator/owner of the information; the original classification authority or other official (government or contractor) that controls the information) is responsible for determining, at the time of creation, whether information in a document or material falls into a CUI category. If so, the authorized holder is responsible for applying CUI markings and dissemination instructions accordingly.
c. Only categories listed in the CUI Registry (includes DoD related categories) can be used to identify if the information meets CUI designation.
3. LEGACY MATERIAL.
a. Policy for legacy CUI created and marked under Department of Defense Manual (DoDM) 5200.01, Volume 4 is cancelled. For information on Army legacy material: (Ref: DoDI 5200.48, para 3.2)
(1) Will not be required to be re-marked or redacted while it remains under control or is accessed on line and downloaded for use on the contract. However, when legacy CUI is incorporated into, or cited in, another document or material, it must be reviewed for CUI and marked in accordance with DoDI 5200.48.
(2) Marked and stored on an access-controlled website or database does not need to be remarked as CUI, even if other agencies and contractors are granted access to the websites or databases.
(3) Does not automatically become CUI. It must be reviewed by the owner of the information to determine if it meets or falls under one of the new CUI categories. If it meets the new CUI requirements, it will be marked in accordance with DoDI 5200.48.
b. The original classification authorities (OCAs) are required to review all SCGs under their authority to determine if the information (previously marked as “For Official Use Only” or “FOUO” or other legacy markings) meets the CUI designation. The SCGs must be reissued to ensure clear protection guidance is provided. (Ref: DoDI 5200.48, para 3-7e and 3.8)
4. Marking. The contractor shall ensure that all documents containing CUI carry the CUI markings in accordance with DoDI 5200.48. Discontinue all use of legacy or other markings is not permitted or included in either the CUI Registry or DoDI 5200.48. Refer to the OUSD(I&S)/DDI(CL&S) Information Security CUI Marking Guidance dated April 2020.
5. Safeguarding and Storage. The contractor shall protect CUI from unauthorized disclosure or access by unauthorized personnel, by ensuring these measures are implemented: (Ref: DoDI 5200.48, para 4.1e)
a. During working hours. Contractor employees working with CUI will be careful not to expose CUI to unauthorized users or others who do not have a lawful government purpose to see the information. Cover sheets (Stand Form 901) can be placed on top of documents to conceal the contents from casual viewing.
b. The contractor shall keep CUI under control at all times or protect it with at least one physical barrier and reasonably ensure that the information is protected from unauthorized access and observation.
c. CUI will not be stored in personal residence, hotel room safes, and automobiles or viewed while on public transportation if allowed to transfer hard-copy (document form) CUI material outside the organization.
6. Transmission Requirements.
a. CUI information may be transmitted electronically (e.g., data, website, or e-mail), via approved secure communications systems or systems utilizing other protective measures such as Public Key Infrastructure or transport layer security (e.g., https). Avoid wireless telephone transmission of CUI when other options are available. (Ref: DoDI 5200.48, para 4.1e).
b. CUI transmission via facsimile machine is permitted; however, the sender is responsible for determining whether appropriate protection will be available at the receiving location before transmission (e.g., facsimile machine attended by a person authorized to receive CUI; facsimile machine located in a controlled government environment) or an authorized DoD contractor facility.
c. CUI information and material may be transmitted via first class mail, parcel post, FEDEX or, bulk shipments. Do not place CUI markings on the outer envelopes or packaging. Refer to the OUSD(I&S)/DDI(CL&S) Information Security CUI Marking Guidance dated April 2020.
d. The contractor shall not use unofficial or personal (e.g., .net; .com) e-mail accounts, messaging systems, or other non-DoD information systems, except approved or authorized government contractor systems, to conduct official business involving CUI.
7. CUI within Information Systems. (Ref: DoDI 5200.48, para 3-3, 3-10)
a. DoD information systems (IS) processing, storing, or transmitting CUI will be categorized at the moderate impact level, and follow the guidance in DoDI 8500.01 and 8510.01.
b. Non-DoD information systems processing, storing, or transmitting CUI will provide adequate security, and the appropriate requirements must be incorporated into all contracts, grants, and other legal agreements with non-DoD entities in accordance with DoDI 8582.01. The NIST-SP 800-171 identifies the baseline system requirements for processing CUI for industry.
c. For systems, networks, and programs operating on the various domains, a splash screen warning and notice of consent must be employed to alert users of the presence of CUI.
d. When made available by the DoD Chief Information Officer and OUSD(I&S), Army organizations will modify or install classification marking tools on unclassified, Secret and Top Secret network systems to account for CUI information and readily permit inclusion of CUI markings and designator indicators.
8. Dissemination. (Ref DoDI 5200.48, para 4-2)
a. The contractor shall follow CUI access to the extent the access or dissemination: complies with the Law, Regulation, and Government-wide policy (LRGWP) identifying the information as CUI; furthers a lawful government purpose; is not restricted by an authorized Limited Dissemination Controls (LDC); or is not prohibited by any LRGWP.
b. Authorized holders may place limits on disseminating CUI for a lawful government purpose using the approved LDCs and associated marking or methods authorized by a specific LRGWP.
c. The originator may use the LDCs to limit access to those on an accompanying dissemination list, as shown in Table 2 of DoDI 5200.48. LDCs or distribution statements cannot unnecessarily restrict CUI access.
d. When handling other Executive Branch CUI (non-DoD or Army), DA personnel will follow their regulatory guidance for when the application of dissemination controls and its markings are allowed, and by whom, while ensuring the policy is in accordance with Part 2002 of Title 32, CFR.
e. Government CUI designated information may be disseminated to a foreign or FOCI recipient in order to conduct official business for the Army provided.
(1) CUI is not controlled or marked as NOFORN.
(2) Access to such government contract data/information is within the scope of the foreign or FOCI State Department licenses and export control regulations.
(3) There are no contract restrictions prohibiting access to such data/information.
(4) Access to such data/information would help accomplish the contract and would not be detrimental to the interests of the DoD or the U.S. government.
(5) Access to such data/information is in accordance with this DD254.
9. Legacy Distribution Statements.
a. Legacy CUI technical documents and materials requiring export control have used distribution statements in accordance with DoDI 5230.24 in order to address the shared responsibility between the DoD and its contractors to safeguard this information. This was done for legacy CUI creation, transmission, receipt, storage, distribution, decontrol, and approved disposition authorities, including destruction. (Ref: DoDI 5200.48, para 4.3a)
b. CUI export controlled technical information or other scientific, technical, and engineering information will continue to use distribution statements and must be marked with an export control warning in accordance with DoDI 5230.24, DoDD 5230.25, and Part 250 of Title 32, CFR (Withholding of Unclassified Technical Data from Public Disclosure). However, where other markings are authorized and used in accordance with associated LRGWP (e.g., North Atlantic Treaty Organization markings, REL TO), those markings may be used to further inform distribution decisions. (Ref: DoDI 5200.48, para 4.3b)
c. “REL TO” is authorized for use with foreign nationals once the information distribution is properly coordinated with the requiring activity foreign disclosure office.
10. Destruction. (Ref: DoDI 5200.48, para 4.5)
a. The contractor shall take all CUI documents (Record and Non-record copies) and materials and formally review them in accordance with Chapter 33 of Title 44, United States Code (and AR 25-400-2 before approved disposition authorities are applied, including destruction. Media containing CUI must include decontrolling indicators. (Ref: DoDI 5200.48, para 4.5)
b. The contractor shall ensure that CUI will be destroyed in a manner that makes it unreadable, indecipherable, and irrecoverable. The CUI will be destroyed according to any specific directives regarding the information. If the authority does not specify a destruction method, the contractor shall use one of the following methods: (Ref: DoDI 5200.48, para 4.5a and b)
(1) Any method of destruction approved for classified information.
(2) Guidance for destruction outlined in the NIST SP 800-88, and further explained in NARA’s CUI Notice 2019-03.
11. Decontrol of CUI. Decontrol occurs when the information has been removed from the protection of the CUI designation and no longer requires safeguarding or dissemination controls.
a. Decontrolling and releasing CUI records will be executed by the originator of the Information or other authority (e.g., initial Freedom of Information Act (FOIA) denial and appellant authorities) and designated government program office for decontrolling CUI pursuant to the procedures for the review and release of information (see AR 360-1). There are no specific timelines to decontrol CUI unless specifically required in a LRGWP. Decontrol will occur when the CUI no longer requires safeguarding and will follow Army records management procedures (see AR 25-400-2). (Ref: DoDI 5200.48, para 4.4)
b. CUI documents and materials will be formally reviewed by the government program chief engineer, SME before being decontrolled or chief engineer, SME, OPSEC officer, legal and PAO prior to public release.
c. Decontrol will occur when the designating agency decides to release the CUI to the public by making an affirmative, proactive disclosure (for example, FOIA request). Disclosure under FOIA does not automatically constitute CUI decontrol for all purposes.
d. Disclosures under the Privacy Act constitute decontrol only with respect to the limited purpose of disclosure to the individual who requested access to their records maintained in a system of records.
e. When indicated by a decontrol marking specifying a decontrol date or event, CUI is decontrolled without further review by the originator.
f. A designating agency may also decontrol CUI:
(1) In response to a request from an authorized holder to decontrol CUI.
(2) Concurrently with any declassification action under E.O. 13526 or any predecessor or successor order, as long as the information also appropriately qualifies for decontrol as CUI.
(3) In PEO STRI, the government program office in charge of the contract is the local CUI personnel it authorizes to decontrol CUI, consistent with a LRGWP.
(4) Decontrolling CUI for purposes other than FOIA disclosure relieves the requirement to handle the information under the CUI Program but does not constitute authorization for public release.
(5) Personnel must clearly indicate that CUI is no longer controlled when restating, paraphrasing, re-using, releasing to the public, or donating the CUI to a private institution. Otherwise, personnel do not have to mark, review, or take other actions to indicate the CUI is no longer controlled.
g. Once decontrolled, any public release of information that was formerly CUI must be in accordance with AR 360-1.
h. Authorized holders may request that the designating agency decontrol CUI that they believe should be decontrolled. If an authorized holder publicly releases CUI in accordance with the designating agency’s (not Army or DoD) authorized procedures, the release constitutes decontrol of the information.
i. Unauthorized disclosure of CUI does not constitute decontrol.
j. Personnel must not decontrol CUI to conceal, or to otherwise circumvent accountability for, an unauthorized disclosure.
k. When a LRGWP require specific decontrol procedures, personnel must follow such requirements
l. CUI and the Freedom of Information Act (FOIA). FOIA may not be cited as a CUI safeguarding or disseminating control authority for CUI. When determining whether to disclose information in response to a FOIA request, the decision must be based on content of the information and applicability of any FOIA statutory exemptions, regardless of whether or not the information is designated or marked as CUI. (Ref: Title 32 CFR 2002.44(b), Part 2002)
m. CUI and the Privacy Act. Information contained in Privacy Act systems of records may be subject to controls under other CUI categories and may need to be marked as CUI for that reason. In addition, when determining whether certain information must be protected under the Privacy Act or whether the Privacy Act allows an individual the right to access their information maintained in a system of records, the decision to release must be based upon the content of the information as well as Privacy Act criteria, regardless of whether the information is designated or marked as CUI.
n. Decontrol of CUI for the limited purpose of making an individual’s information available to them under the Privacy Act does not result in decontrol. (Ref: CFR 2002.46, Title 32 Part 2002)
12. Challenges to Designation of Information as CUI.
a. The contractor who believes that a designation as CUI is improper or incorrect, or who believe they have received unmarked CUI, should notify the government agency that disseminated the information. When the disseminating agency is not the designating agency of the CUI, it is the responsibility of the disseminator agency to contact the designating agency of the challenge. Challenges may be made anonymously; and challengers cannot be subject to retribution for bringing such challenges. (Ref: CFR 2002.50 Title 32, Part 2002)
b. If a contractor or government command or organization receives a challenge, the government program office or other designated individual for handling challenges will take the following measures:
(1) Acknowledge receipt of the challenge in writing, providing an expected timeline for response to the challenger,
(2) Review the merits of the challenge with a subject matter expert, offer an opportunity to the challenger to define a rationale for belief that the CUI in question is inappropriately designated,
(3) Notify the challenger of the decision in writing and provide contact information of the official making the decision in this matter.
c. Until the challenge is resolved, the challenged CUI, including challenges to unmarked CUI, will continue to be safeguarded and disseminated at the appropriate control level indicated in the markings or presumed category. If a challenging party disagrees with the response to a challenge, contact the contract cognizant security office (Information Security Team) for assistance with resolution.
13. Misuse or Unauthorized Disclosure of CUI.
a. The contractor shall report promptly and shall take appropriate action in cases of misuse, mishandling, or unauthorized disclosure (UD) of CUI.
b. For UD of CUI, no formal security inquiry or investigation is required unless disciplinary action will be taken against the individual(s) responsible, in such case an inquiry would be appropriate. Incidents involving the UD of CUI will be reported to the COR/AOR and contracting officer.
14. CUI Training. All contractors handling CUI in support to this contract, will execute initial and refresher CUI training as stated in item 13 paragraph 14. CUI training can be taken at the following URL; https://securityhub.usalearning.gov/index.html
15. CUI Requirements in Army Contracts. (Ref: DoDI 5200.48, para 5.3)
a. CUI will be identified by the government program office in all Army contracts to include the applicable security clauses and security standards associated with the CUI in accordance with DoDI 5200.48.
b. Whenever the Army and government program office provides CUI to, or CUI is generated by, non-DoD entities, protective measures, and dissemination controls, including those directed by LRGWP, will be articulated in the contract, grant, or other legal agreement, as appropriate.
c. The contractor shall monitor CUI for aggregation and compilation based on the potential to generate classified information pursuant to security classification guidance addressing the accumulation of unclassified data or information.
d. The contractor shall report the potential classification of aggregated or compiled CUI to the Army requiring activity.
e. The contractor shall submit unclassified Army information for review and approval for release in accordance with the standard Army release requirements under AR 360-1.
f. All CUI records must follow the approved mandatory disposition authorities whenever the government requiring activity provides CUI to, or CUI is generated by, non-DoD entities.
| Click on this button to attach a file(s).: |
| rep: Rick Denny, Product Lead International Aviation |
| Enter signature.: |
| Explain and identify specific areas and government activity responsible for inspections.: |
| Enter GCA name.: ACC-ORL |
| Enter AAC of the contracting office.: 900KK |
| Enter AAC of the contracting office.: 900KK |
| Enter address (include zip code).: 12211 Science Dr., Orlando, FL 32826 |
| Enter address (include zip code).: 12211 Science Dr., Orlando, FL 32826 |
| Enter POC name.: Jason Holden |
| Enter telephone number (include area code).: 4072083312 |
| Enter telephone number (include area code).: 5206936108 |
| Enter email address.: jason.n.holden.civ@army.mil |
| Enter email address.: tam.v.nguyen13.civ@army.mil |
| Enter title.: Industrial Security Specialist |
| Enter the date signed in format YYYYMMDD.: |
File details come from the government source that posted it. Updated .