Attachment 1 - DD 254 BID.pdf

PDF 360 KB Posted

Attached to
Draft Rapid Operations Material Management (ROMM) RFP Federal contract opportunity
Solicitation number
N0042124R0041
Issued by
Department of the Navy Naval Air Systems Command Naval Air Warfare Center

About this file

This document is a Data Item Description (DID) for a Department of Defense Operations Security (OPSEC) Plan. The OPSEC Plan is used to identify and monitor a contractor's OPSEC activities during the performance of a contract. Key details include:

The OPSEC Plan must describe the OPSEC environment, document the OPSEC risk analysis, identify proposed OPSEC measures, define OPSEC responsibilities, and serve as a repository of the OPSEC history of the contract. The plan must reference relevant OPSEC regulations and guidelines. It must identify the OPSEC manager, contractor program manager, and responsibilities of all program personnel. The plan must address OPSEC communications, threat analysis, critical information identification, vulnerability assessment, OPSEC measures, and a program chronology. The OPSEC Plan is subject to joint audit and/or inspection by the Defense Security Service and the contracting activity.

View the file

Other files for this federal contract opportunity

Other files attached to Draft Rapid Operations Material Management (ROMM) RFP, newest first.
File Type Posted
N0042124R0041 ROMM DRAFT RFP QA Final.pdf PDF
Attachment 8 - Wage Determination 2015-4377.pdf PDF
Attachment 5 - Locator Form.pdf PDF
Attachment P1 - Cost Summary Sheet.xlsx XLSX spreadsheet
Attachment P2 - Annual Fully Burnened Rates.xlsx XLSX spreadsheet
Attachment 4 - OCI List.docx DOCX document
Attachment 6 - Wage Determination 2015-4279.pdf PDF
Attachment 2 - CSP.docx DOCX document
Attachment 3 -Data Item Transmittal Form.docx DOCX document
Attachment 9 - Wage Determination 2015-4341.pdf PDF
Exhibit A - CDRLS.docx DOCX document
Attachment 7 - Wage Determination 2015-5635.pdf PDF
N0042124R0041 Draft RFP 18 June 2024.docx DOCX document
Show all 13

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Please wait...

If this message is not eventually replaced by the proper contents of the document, your PDF viewer may not be able to display this type of document.

You can upgrade to the latest version of Adobe Reader for Windows®, Mac, or Linux® by visiting http://www.adobe.com/go/reader_download.

For more assistance with Adobe Reader visit http://www.adobe.com/go/acrreader.

Windows is either a registered trademark or a trademark of Microsoft Corporation in the United States and/or other countries. Mac is a trademark of Apple Inc., registered in the United States and other countries. Linux is the registered trademark of Linus Torvalds in the U.S. and other countries.

DATA ITEM DESCRIPTION

Title: NAVAIR OPERATIONS SECURITY (OPSEC) PLAN

Number: DI-MGMT-81999 Approval Date: 20151013

AMSC NUMBER: 9593 Limitation:

DTIC Applicable: GIDEP Applicable:

Preparing Activity: AS Project Number: MGMT-2015-019

Applicable Forms:

Use/Relationship: The OPSEC Plan is used to identify and monitor a contractor’s OPSEC activities during the performance of a contract. It is intended to be a living document that will require periodic updates throughout the life of the contract. The OPSEC plan; (1) Describes the

OPSEC environment to include identification of critical information, the OPSEC threat and vulnerabilities an adversary might exploit to acquire critical information, (2) Documents the

OPSEC risk analysis, (3) Identifies proposed and actual OPSEC measures, (4) Defines and assigns specific OPSEC responsibilities and ties the OPSEC Plan to the contractor’s corporate

OPSEC Program, and (5) Serves as a repository of the OPSEC history of the contract.

This Data Item Description (DID) contains the format and content preparation instructions for the data product generated by the specific and discrete task requirements delineated in the contract.

This DID is applicable only when the contracting activity determines that the sensitivity of the contracted effort warrants OPSEC protections.

The contractor’s implementation of the OPSEC Plan, approved by the contracting activity, is subject to joint audit and/or inspection by the Defense Security Service and the contracting activity.

Requirements:

1. Reference documents. The content of this DID shall identify changes as specified in the following:

a. Title 15, US Code, Section 278g-3(d)(4). Use the definition of sensitive information.

b. DOD Manual 5220.22.M. “National Industrial Security Program Operating Manual (NISPOM)”

c. OPNAVINST 3432.1 Department of the Navy Operations Security Program

d. OPNAVINST 3432.1A Operations Security dated 4 Aug 2011

e. National Security Decision Directive 298 of 22 January 1988. Use for concept of Operations

Security, and apply the framework for telecommunications security in DFARS clause 252.239-7016, as appropriate.

2. Format. The OPSEC Security Plans shall be submitted in contractor determined format.

3. Content. The content of this plan shall consist of the following:

Source: https://assist.dla.mil -- Downloaded: 2016-01-05T20:35Z Check the source to verify that this is the current version before use.

DI-MGMT-81999

3.1 COVER PAGE

The cover page for an OPSEC Plan shall clearly present the following information:

1. Title of the Acquisition Program

2. Title of the Document (i.e. “Operations Security Plan”)

3. Reference to the government contract number

4. Date of latest revision

5. Name, signature and title of the preparer of the OPSEC Plan

6. Name, signature and title of the approver of the OPSEC Plan.

7. Reference for whom the document was prepared (Contracting activity)

8. Reference by whom the document was prepared (Corporation)

9. All appropriate distribution or classification statements

3.2 TABLE OF CONTENTS PAGE

The Table of Contents for an OPSEC Plan shall outline each section contained in the OPSEC

Plan.

3.3 PREFACE PAGE

The purpose of the Preface is to provide a brief, unclassified, overview of the program and the need for OPSEC measures. The specific objectives of the contracted effort shall be introduced with reference to all strategic participants and partnerships required to make the program a success. The anticipated development of any innovative concepts or technologies shall also be introduced in the Preface.

The Preface shall reference all links between the OPSEC Plan and any corporate OPSEC

Program(s). The Preface may conclude by referencing requirement documents such as the contract number, Contract Security Classification Specification (DD254), Contract Data

Requirements List (DD1423) and any other pertinent guidance provided by the contracting activity. It shall also provide an OPSEC point of contact, with contact information, for additional guidance or assistance such as the OPSEC program manager or contractor program manager.

3.4 OPSEC PLAN INTRODUCTION

3.4.1 Purpose and Scope: The purpose of the OPSEC Plan shall be effectively communicated in this section and include a description of the scope of the OPSEC Plan (unique physical locations, subcontractors, suppliers, period of performance, etc.).

3.4.2 Authorities: The requirement to protect critical information shall be documented within this section. Documenting the requirement can be achieved by referencing the Corporate

OPSEC Program (Policy) and Plan, DODM 5205.-2M, specific contract documents including the

DD254 for contracts involving classified data, or other contracting activity specific guidance.

3.4.3 OPSEC Plan Major Activity Timeline: This section shall include a list of all major OPSEC Plan activities such as quarterly OPSEC Working Group Meetings, Annual

Assessments, scheduled OPSEC awareness training, Sub-contractor OPSEC Assessments and

Surveys, Threat and Vulnerability Reviews, etc. This section shall also include scheduled

OPSEC Plan reviews.

3.4.4 Responsibilities: The OPSEC Plan shall identify whom is responsible for the major activities described in the Plan. For example (not intended as an inclusive list):

The OPSEC Manager shall be identified by name and include a list of duties that may include:

1. Coordinate all OPSEC policy responsibilities/ procedures within the program.

2. Revise the Program OPSEC Plan as necessary.

3. Convene and coordinate the annual Program OPSEC Assessment.

4. Disseminate updated threat information to program personnel.

5. Assist in the review of contract requirements for OPSEC considerations.

6. Conduct OPSEC briefing(s) upon customer approval of the plan.

7. Principal advisor to the Contractor Program Manager on all OPSEC matters.

8. Develop/Disseminate Program Critical Information List (CIL).

9. Promote OPSEC awareness within the program.

The Contractor Program Manager shall be identified by name and include a list of duties that may include:

1. Responsible for the overall implementation of the program/contract.

2. Ensure proper OPSEC procedures are implemented by program personnel.

3. Ensure all subcontractors and suppliers supporting the program develop and implement procedures in compliance with the Program OPSEC Plan.

4. Remain cognizant of emerging OPSEC threats and vulnerabilities that may adversely impact upon the success of the program.

5. Actively participate in periodic Program OPSEC assessments.

6. Remain cognizant of any changes in critical information and communicate them to the

Program OPSEC Manager.

7. Promote OPSEC awareness within the program.

A short description of the expectations and responsibilities of all program personnel (including subcontractors and suppliers) shall be provided and may typically include:

1. Remain compliant with all applicable OPSEC Plans.

2. Maintain an awareness of all applicable CIL.

3. Attend all OPSEC program briefings.

4. Timely reporting of any OPSEC concerns to the Contractor Program Manager and/or the

Program OPSEC Manager.

5. Generation of OPSEC Plans (sub-contractors or suppliers only).

3.4.5 Organizational OPSEC Communications and Interfaces: A description as to how the

OPSEC Plan will be communicated to all personnel supporting the program (hardcopy, via a webpage, briefings, etc.).

3.4.5.1 Internal: In this section the OPSEC Plan shall identify all anticipated

OPSEC interfaces internal to the corporation such as the senior corporate leadership, corporate

OPSEC Working Group, OPSEC coordinators, program personnel, etc.

3.4.5.2 External: In this section the OPSEC Plan shall identify all anticipated external points of contact such as the contracting activity, Defense Contract Management

Agency (DCMA), The Defense Security Service (DSS), Federal Bureau of Investigation (FBI) and local law enforcement and their primary role within the OPSEC program (i.e. DCMA audits acquisition management practices, DSS provides security oversight, FBI and law enforcement may provide threat data). Subcontractor and supplier OPSEC points of contact shall be similarly identified.

3.4.6 Marking, Handling and Distribution of Documents: This section shall provide a description of marking, handling, storage, access and transmission authorizations and procedures for any critical information provided to, or generated by, the contractor.

Reference to the program classification guide, Freedom of Information Act and any additional guidance provided by the contracting activity may be cited as applicable.

3.5 THREAT

3.5.1 General Threat: This section shall identify and demonstrate an understanding of the overall threat to program critical information throughout the anticipated duration of the contract/program. For example, an information systems program might note the following:

DSS analysis of 2008 threat data shows, “Information systems, especially C4ISR related systems remained the primary sought-after technology for East Asia and Pacific Region countries. Direct requests (often via the Internet) and other suspicious Internet activity continued to be the preferred method of collection. Information systems are primary targets for Near East adversaries of the United States. Near East commercial entity activity indicates a growing collusion between commercial entities and government associated entities such as universities, public agencies and research and development centers. Adversaries using HUMINT and OSINT collection methods represent a significant threat to program critical information.

The section shall conclude with a brief description of all identified intelligence collection methods that may be expected to be used by an adversary to acquire critical information.

Note: A general description of intelligence collection methods may be found in “Applying

OPSEC to Government Acquisitions and Contracts” at www.ioss.gov.

3.5.2 Program Detailed Threat: This section shall be similar to section 3.5.1 above referencing any known direct threats to acquisition specific elements of critical information within the program/contract. As complete a description of each threat as possible shall be provided while maintaining the overall plan classification at the unclassified level. Since detailed threat information may derive from classified sources, reference to source documents as provided by the government contracting activity or other reputable source is permitted.

3.5.3 Threat Analysis: Each threat identified in sections 3.5.1 and 3.5.2 shall be analyzed to determine the level of threat to the corresponding critical information. The results of this analysis shall be presented in this section. A description of the specific threat analysis method used by the contractor to quantify each threat shall be included in this section.

Note: For additional guidance and a sample threat analysis methodology see, “Applying OPSEC to Government Acquisitions and Contracts” at www.ioss.gov and DODM 5205.02.

3.5.4 Changes Within Threat Environment: The Threat section shall conclude with a statement that addresses how new threat data is to be received and incorporated into the OPSEC Plan to ensure OPSEC risk remains in compliance with all applicable guidance.

3.6 CRITICAL INFORMATION

3.6.1 General: Critical information shall be identified within this section of the plan and a comprehensive program Critical Information List (CIL) shall be included.

3.6.2 Critical Information List: Guidance on the creation of a CIL is contained within

“Applying OPSEC to Government Acquisitions and Contracts,” available at www.ioss.gov, DODM 5205.02M, or may be provided by the contracting activity. Ideally the CIL shall remain unclassified to facilitate wide internal distribution, but may provide reference to classified information as applicable.

3.7 VULNERABILITY

3.7.1 General: The Vulnerability section of the OPSEC Plan shall describe the analysis of activities (indicators) that point to OPSEC vulnerabilities an adversary can exploit to acquire critical information. This section shall contain a list of all identified OPSEC vulnerabilities.

3.7.2 List of OPSEC Vulnerabilities: Each vulnerability shall be described in sufficient detail as to communicate to the contracting activity the extent of the vulnerability. The Vulnerability List shall remain unclassified, but may provide reference to classified information if applicable.

Reference to classified reports and other information shall include an unclassified description of the documentation (report title, number, etc.) and the source responsible for publication of the information.

Note: A list of typical OPSEC vulnerabilities which may require OPSEC measures may be found within “Applying OPSEC to Government Acquisitions and Contracts”, available at www.ioss.gov or may be provided by the contracting activity. These sample vulnerabilities are not all inclusive and the submitted vulnerability list shall be tailored to the specific acquisition or contract.

3.7.3 Vulnerability Analysis: Once potential program vulnerabilities have been identified, the magnitude of each vulnerability shall be determined using a consistent methodology identified and documented in this section of the OPSEC Plan. The results of this analysis shall also be described in this section.

Note: For additional guidance and a sample vulnerability methodology see, “Applying OPSEC to Government Acquisitions and Contracts” at www.ioss.gov and DODM 5205.0-2M.

3.8 RISK ASSESSMENT

3.8.1 General: The OPSEC risk of a program represents the probability of compromise of critical information and the impact to the program/contract taking into account the threat and vulnerabilities. The acceptable level of OPSEC risk (as determined by senior leadership, or the contracting activity) shall be described in this section in terms consistent with the selected

OPSEC methodology.

3.8.2 Risk Assessment: The specific OPSEC risk shall be described in terms consistent with the

OPSEC methodology selected for determining OPSEC threat and vulnerability. The method, and the results of the assessment, shall be presented in this section. The conclusion of the risk assessment shall result in an ordinal ranking of OPSEC risk (highest to lowest).

Note: Additional guidance and a sample risk methodology are available in “Applying OPSEC to

Government Acquisitions and Contracts” at www.ioss.gov and DODM 5205.0-2M.

3.9 OPSEC MEASURES

3.9.1 General: This section of the OPSEC Plan shall identify specific OPSEC Measures proposed for mitigating OPSEC risk to acceptable levels including the cost to implement each measure. A sampling of common OPSEC measures is available in “Applying OPSEC to Government

Acquisitions and Contracts” at www.ioss.gov. This list is not to be considered exhaustive and is provided as guidance for the development of the program/contract specific list of potential

OPSEC measures.

3.9.2 Residual Risk: This section shall contain an analysis of residual OPSEC risk, in terms consistent with the OPSEC methodology selected, as a result of implementation of each OPSEC measure presented in section 3.9.1. This section shall identify which OPSEC measures will be implemented and the rationale for those that will not.

3.10 OPSEC Program Chronology: This section shall document significant program OSPEC events throughout the lifecycle of the program. Significant events may include changes to the

CIL, changes in program leadership or results of program assessments and surveys (including subcontractors). At a minimum, this section shall include a brief description of the event, date of occurrence, actions taken by the contractor and final disposition. A known compromise of critical information need only be referenced in keeping with the intended classification of this document.

Note: The history contained herein may be used by the government as a part of an OPSEC or security audit conducted by the contracting activity, DSS or other authorized agency.

3.11 ACRONYMS: This section shall include a complete list of acronyms used in the Program

OPSEC Plan (i.e., CDRL – Contract Data Requirements List, DID – Data Item Description, etc.).

3.12 REFERENCES: This section shall include a complete list of all references cited in the

Program OPSEC Plan (i.e. DoD Manual 5205.02-M, dated November 3, 2008, Contract Number, Corporate OPSEC Plan(s)/Program(s), etc.).

The specific example provided derives from annual documentation produced by the Defense

Security Service, Counterintelligence Office in 2009. Current assessments may be found at https://www.dss.mil/isp/count_intell/count_intell.html.

End of: DI-MGMT-81999

PREVIOUS EDITION IS OBSOLETE.

Page of

DD FORM 254, APR 2018

NEEDS DD67

DEPARTMENT OF DEFENSE

CONTRACT SECURITY CLASSIFICATION SPECIFICATION

(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)

OMB No. 0704-0567 OMB approval expires:

June 30, 2025 The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.

RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.

1. CLEARANCE AND SAFEGUARDING

2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)

3. THIS SPECIFICATION IS: (X and complete as applicable.)

a. ORIGINAL (Complete date in all cases.)

b. REVISED (Supersedes all previous specifications.)

4. IS THIS A FOLLOW-ON CONTRACT?

If yes, complete the following:

Classified material received or generated under

5. IS THIS A FINAL DD FORM 254?

If yes, complete the following:

6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)

7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor)

8. ACTUAL PERFORMANCE (Click button to add more locations.)

10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)

e. NATIONAL INTELLIGENCE INFORMATION:

11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)

12. PUBLIC RELEASE

Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)

13. SECURITY GUIDANCE

The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.

(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)

List of Attachments (All Files Must be attached Prior to Signing, i.e., for any digital signature on the form)

14. ADDITIONAL SECURITY REQUIREMENTS

Requirements, in addition to NISPOM requirements for classified information, are established for this contract.

If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)

15. INSPECTIONS

Elements of this contract are outside the inspection responsibility of the CSO.

If Yes, explain and identify specific areas and government activity responsible for inspections. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)

16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)

17. CERTIFICATION AND SIGNATURES

Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below. Upon digitally signing Item 17h, no changes can be made as the form will be locked.

18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL

9.0.0.2.20120627.2.874785 DD 254, "DoD Contract Security Classification Specification" Hide Attachment Bar

CurrentPage:
PageCount:
Select classification from drop-down list.: Unclassified
SerialNum:
a. Facility clearance level. Select one.: 2
b. Level of safeguarding for classified information/material required at contractor facility. Select one.: 2
Select for "original.": 0
Select for "original.": 1
Enter prime contract number.: Request for Proposal, Not Valid for Performance
Select for "revised.": 0
Select for "revised.": 0
Enter subcontract number.:
Select for "final.": 1
Select for "final.": 0
Enter solicitation or other number.: N00421-24-R-0041
Enter due date in format YYYYMMDD.:
Enter date in format YYYYMMDD.: 20240208
Enter revision number.:
Enter date in format YYYYMMDD.:
Enter final specification.:
Enter date in format YYYYMMDD.:
Select for "no.": 1
Select for "no.": 1
Select for "no.": 0
Select for "no.": 1
Select for "yes.": 0
Select for "yes.": 0
Select for "yes.": 1
Select for "yes.": 0
Enter preceding contract number.:
Enter contractor's request date in format YYYYMMDD.:
Enter period.:
Enter typed name of certifying official (last, first, middle initial).: Request for Proposal, Not Valid for Performance
Enter typed name of certifying official (last, first, middle initial).: TBD
Enter typed name of certifying official (last, first, middle initial).: Cullison, Ashley
Enter CAGE code of the prime contractor.: TBD
Enter CAGE code of the prime contractor.: TBD
Enter CAGE code of the prime contractor.: N/A
Enter CAGE code of the prime contractor.: N/A
Enter CAGE code of the prime contractor.: N/A
Enter CAGE code of the prime contractor.: TBD
Enter CAGE code of the prime contractor.: TBD
Enter CAGE code of the prime contractor.: TBD
Enter CAGE code of the prime contractor.: TBD
Enter CAGE code of the prime contractor.: N/A
Enter CAGE code of the prime contractor.: N/A
Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: TBD
Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: TBD
Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: N/A
Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: N/A
Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: N/A
Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: TBD
Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: TBD
Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: TBD
Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: TBD
Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: N/A
Select to add row to locations.:
Select to remove last row from locations.:
Select to delete all signatures.:
Enter location(s).: Naval Air Warfare Center Aircraft Division (NAWCAD)

Webster Outlying Field (WOLF), Saint Inigoes, MD 20684 Enter location(s).: NAVAIR Material Management Facility North 46967 Bradley Blvd. Suite A Lexington Park, MD 20653 Enter location(s).: Naval Air Warfare Center Aircraft Division (NAWCAD) NAS Patuxent River Patuxent River, MD 20670

Enter location(s).: Contractor Site (TBD) within 50 drivable miles of WOLF, St. Inigoes, MD
Enter location(s).: Contractor Site (TBD) within 50 drivable miles of Norfolk Naval Air Station, Norfolk, VA
Enter location(s).: Contractor Site within 50 drivable miles of Naval Base San Diego, San Diego, CA
Enter location(s).: Contractor Site within 50 drivable miles of Fort Bragg, Fayetteville, NC
Enter location(s).: United States Naval Facilities Engineering Systems

Command Southwest Navy Building One 750 Pacific Highway San Diego, CA 92132

Enter general unclassified description of this procurement.: The Contractor shall provide the NAWCAD WOLF Command with life cycle management, material and equipment management, and recordkeeping and reporting. This includes material handling, delivery and issuance of equipment, shipping, storage, supply maintenance, administrative, logistics and other collateral support services, such as the disposal and handling of Hazardous Material (HAZMAT).
Select for "a. CONTRACTOR.": 1
Select for "a. CONTRACTOR.": 0
Select for "a. CONTRACTOR.": 1
Select for "f. OTHER AS NECESSARY.": 0
Select for "f. OTHER AS NECESSARY.": 0
Select for "f. OTHER AS NECESSARY.": 1
Select for "b. SUBCONTRACTOR.": 0
Select for "b. SUBCONTRACTOR.": 0
Select for "b. SUBCONTRACTOR.": 0
Select for "g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE TECHNICAL INFORMATION CENTER (DTIC) OR OTHER SECONDARY DISTRIBUTION CENTER.": 0
Select for "g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE TECHNICAL INFORMATION CENTER (DTIC) OR OTHER SECONDARY DISTRIBUTION CENTER.": 1
Select for "c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR.": 0
Select for "c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR.": 1
Select for "c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR.": 1
Select for "h. REQUIRE A COMSEC ACCOUNT.": 0
Select for "h. REQUIRE A COMSEC ACCOUNT.": 1
Select for "d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION.": 0
Select for "d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION.": 1
Select for "d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION.": 0
Select for "i. HAVE A TEMPEST REQUIREMENT.": 0
Select for "i. HAVE A TEMPEST REQUIREMENT.": 0
Select for "e. NATIONAL INTELLIGENCE INFORMATION: - (1) Sensitive Compartmented Information (SCI).": 0
Select for "e. NATIONAL INTELLIGENCE INFORMATION: - (2) Non-SCI.": 0
Select for "j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS.": 1
Select for "j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS.": 1
Select for "k. BE AUTHORIZED TO USE DEFENSE COURIER SERVICE.": 1
Select for "k. BE AUTHORIZED TO USE DEFENSE COURIER SERVICE.": 1
Enter infomration for "other.": Additional Controlled Unclassified COMSEC storage required in the contractor-provided warehouse location near Fort Bragg
Enter infomration for "other.": Contracting Officer's Representative: Lincoln A. Lawrence

(lincoln.a.lawrence.civ@us.navy.mil)

Select for "e. ADMINISTRATIVE CONTRACTING OFFICER.": 0
Select for "e. ADMINISTRATIVE CONTRACTING OFFICER.": 1
Select for "l. RECEIVE, STORE, OR GENERATE CONTROLLED UNCLASSIFIED INFORMATION (CUI). .": 1
Select for "m.OTHER.": 0
Select for "direct.": 0
Select for ": 1
Enter specification for "through".: Transmissions by non-secure facsimile or email is NOT authorized (by Prime or subcontractor(s))
Enter public release authority.: Submit ALL Public Releases to: NAWCAD WOLF COR

NAVAIR FORM 5720.10 must be completed and attached.

Select to add signature.:
Select to remove last signature.:
text: Technical papers, briefings, presentations, either classified or unclassified to be presented at classified symposia must be submitted to A0N0000 for approval prior to presentation. Unclassified material submitted for public release (that is not to be presented at classified symposia) shall be forwarded for review prior to release as stated in item 12 above. All controlled unclassified and classified technical information shall be appropriately marked with distribution statements as specified in DoDI 5230.24 (Distribution Statements on Technical Documents) http://www.dtic.mil/whs/directives/corres/pdf/523024p.pdf.

Determination of need-to-know in connection with a classified visit is the responsibility of the individual/host who will disclose the classified information.

All contracts with non-Sensitive Compartmented Information and Non-Compartmented work that may reveal mission-related information of a sensitive activity or sensitive operation should be routed to the NAVAIR STILO for approval.

The COR, TPOC, and Government Security Office, concerning instances of possible loss, compromise, and electronic spillage of classified or controlled unclassified information shall be notified immediately upon discovery and/or no later than 72 hours of discovery.

Block 10.a and 11.h: Classified COMSEC material is not releasable to contractor employees who have not received a final security clearance at the appropriate level. Cryptologic keying materials and Controlled Cryptographic Items (CCI) are controlled by Department of the Navy, NISPOM, and National Security Agency (NSA) guidelines. The contractor shall be guided by NSA/CSS Policy Manual 3-16 in the control and protection of COMSEC material/information at their facilities.

When access is required at Government facilities, contractor personnel will adhere to COMSEC rules and regulations as mandated by DoD National Industrial Security Program Operating Manual (NISPOM) codifying 32 Code of Federal Regulation Part 117, NISPOM Rule, 24 February 2021, Department of the Navy (DoN) COMSEC Policy and Procedures Manual (CMS-1A) and Command policy and procedures. Written concurrence of the Technical Point of Contact identified in Block 16, or Contracting Officer Representative/Contracting Officer Representative for Security (as applicable) is required prior to subcontracting.

Block 10.j and 11.l: Controlled Unclassified Information including Legacy FOUO and Covered Defense Information (meeting the definition of DFARS Clause 252.204–7012 Safeguarding covered defense information and cyber incident reporting) generated and/or provided under this contract shall be marked and safeguarded as specified in DoD Instruction 5200.48 (Controlled Unclassified Information) (CUI)) available at https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/520048p.PDF. Any product containing Covered Defense Information shall be assigned the appropriate distribution statement using the criteria set forth in DoDI 5230.24 (Distribution Statements on Technical Documents); and have this statement displayed per DoDI 5230.24, Enclosure 3-4.

All Covered Defense Information (CDI), Legacy FOUO, and program Controlled Unclassified Information (CUI) data transmitted and safeguarded via electronic means shall use approved encryption. The Contractor shall ensure that when transmitting CUI/Legacy FOUO/CDI over non-secure e-mail (e.g. not connected to the Navy Marine Corps Intranet through Broadband Unclassified Remote Access System / Virtual Private network), those transmissions are encrypted using Department of Defense Public Key Infrastructure (PKI), or an approved DoD External Certificate Authority, in accordance with Public Key Infrastructure & Public Key Enabling, DoDI 8520.02, 24 May 2011.

Block 10.k: Use of Secure Terminal Equipment (STE) for transmission of classified U. S. Government information is authorized. Secure Facsimile: Receipt and transmission of Classified Information authorized via Secure Facsimile. Written concurrence of the Contracting Officer Representative/Technical Point of Contact, identified in Block 16, or Contracting Officer Representative for Security (as applicable), is required prior to subcontracting.

Block 11.c: Information Systems (IS) shall be protected in accordance with DoDI 8510.01and/or per guidance in the DoD National Industrial Security Program Operating Manual (NISPOM) codifying 32 Code of Federal Regulation Part 117, NISPOM Rule, 24 February 2021.

Specific Security Classification Guidance (SCGs), to include subsequent upgrades/revision(s), applying to classified performance on this contract, shall be provided by the Contracting Officer Representative or Technical Point of Contact, identified in Blk 16, as Government Furnished Information (GFI); and shall be executed by the Contractor without obligation to modify this DD Form 254. If additional security classification is required, contact the COR identified in Blk 16d.

Block 11.d: Contractor shall provide adequate storage at their facility for classified hardware. Classified shipments are not to exceed two cubic feet. Larger size shipments require prior coordination with the Facility Security Officer (FSO) to confirm facility storage capacity. Preparation and transmission of material for shipment will be in accordance with the DoD National Industrial Security Program Operating Manual (NISPOM) codifying 32 Code of Federal Regulation Part 117, NISPOM Rule, 24 February 2021 and the DoD 5200.01 V3, DoD Information Security Program Manual.

Block 11.g: To use DTIC services, the contractor must register for an account at http://www.dtic.mil/dtic/registration/contractors/index.html.

Block 11.j: The contractor shall develop, implement, and maintain a facility level OPSEC Program to protect critical information to be used at the contractor facility during the performance of this contract. Contract data requirements list (CDRL) and data item description (DID-DI-MGMT-81999) are a component of the contract. A draft OPSEC Plan must be submitted to: Commander, Naval Air Systems Command, ATTN: NAWCAD WOLF COR, within 90 days of contract award. A final OPSEC Plan is due 45 days from the date that the draft OPSEC Plan is approved. The Contractor shall be responsible for subcontractor implementation of the OPSEC Program requirements for this contract.

Block 11.k: Contractor shall use approved courier methods per the NSA/CSS Policy Manual 3-16, and/or the Department of the Navy (DoN) COMSEC Policy and Procedures Manual (CMS-1A), Command policy and procedures, or the procedures of the Defense Courier Service for delivery of all COMSEC and/or Top Secret information. When utilizing the Defense Courier Service, the contractor shall forward their USTRANSCOM IMT10 Defense Courier Account Record form to the COR/TPOC to verify clearances and sign Part II.

*****************************END OF DD254 ADDITIONAL DATA SHEETS****************************************

text: DID-MGMT-81999 Template
Click on this button to attach a file(s).:
rep:
Enter signature.:
Explain and identify specific areas and government activity responsible for inspections.: OPSEC CDRL in contract.
Enter GCA name.: Naval Air Warfare Center Aircraft Division
Enter AAC of the contracting office.: N00421
Enter AAC of the contracting office.: N00019
Enter address (include zip code).: SCMS Division, Naval Air Warfare Center Aircraft Division, 17100 Webster Field Road, B8185

St. Inigoes, MD 20684-4009 Enter address (include zip code).: Commander, Naval Air Warfare Center Aircraft Division Bldg 1489, Rm 122, Attn: Industrial Security 22095 Fortin Circle, Patuxent River, MD 20670

Enter POC name.: Lincoln A. Lawrence
Enter telephone number (include area code).: 3019956527
Enter telephone number (include area code).: 3019951905
Enter email address.: lincoln.a.lawrence.civ@us.navy.mil
Enter email address.: ashley.s.cullison.civ@us.navy.mil
Enter title.: Industrial Security Representative
Enter the date signed in format YYYYMMDD.: 20240304

File details come from the government source that posted it. Updated .