Attachment_11_C-12_Contract_Security_Classification_Specification_(DD254).pdf

PDF 3 MB Posted

Attached to
Contractor Logistic Support (CLS) Services for USAF C-12 Aircraft Fleet Federal contract opportunity
Solicitation number
FA8134-25-R-B002
Issued by
Department of the Air Force Materiel Command Lifecycle Management Center Tinker Air Force Base

About this file

This is a Contract Security Classification Specification (DD Form 254) and Special Access Program (SAP) Addendum for solicitation FA8134-25-R-B002, which specifies security requirements for Contractor Logistics Support (CLS) Services for C-12 Aircraft operated by PACAF, DIA, DSCA, 586th FLTS Holloman AFB, NM, and 412th TW Edwards AFB, CA. The document requires a Secret facility clearance level and establishes security requirements for classified and controlled unclassified information (CUI).

The specification outlines detailed security protocols including COMSEC requirements, special access program controls, operations security (OPSEC) requirements, and classified hardware handling procedures. Performance locations span 21 sites worldwide including facilities in the US, Europe, Asia, Africa, and South America, with most locations requiring Collateral Secret level access. The contractor must comply with DoDM 5205.07 requirements for SAP security, implement an insider threat program, and follow specific procedures for handling classified materials. Key security oversight is provided by AFLCMC/WVV at Tinker AFB, with the Program Security Officer having responsibility for SAP oversight. The contract completion date is October 31, 2035.

View the file

Other files for this federal contract opportunity

Other files attached to Contractor Logistic Support (CLS) Services for USAF C-12 Aircraft Fleet, newest first.
File Type Posted
Attachment_7_C-12_Section L-Instruction to Offerors_Rev02_Corrected.pdf PDF
C-12_CLS_Questions and Answers_Rev02.pdf PDF
SF30_Amendment_of_Solicitation_FA813425RB0020002.pdf PDF
FA813425RB002_Amendment_02_Clause_Set_Updates.pdf PDF
Attachment_9_C-12_Pricing_Matrix_Rev01.xlsx XLSX spreadsheet
Attachment_7_C-12_Section L-Instruction to Offerors_Rev02.pdf PDF
Attachment_7_C-12_Section L-Instruction to Offerors_Rev02 (DRAFT).pdf PDF
C-12_CLS_Questions and Answers_Rev01.pdf PDF
FA813425RB002 Amendment 02 Clause Set Updates (DRAFT).pdf PDF
Attachment_10_C-12_Wage_Determinations_(CBA)_Rev01.pdf PDF
Attachment_1_C-12_CLINs_Descriptions_and_Specifications_Rev01.pdf PDF
Attachment_7_C-12_Section L-Instruction to Offerors_Rev01.pdf PDF
Exhibit A_C-12_CLS_Contract_Data_Requirements_List_(CDRLs)_Rev01.pdf PDF
SF30_Amendment_of_Solicitation_FA813425RB0020001.pdf PDF
Attachment_8_C-12_Section M -Evaluation Factors for Award_Rev01.pdf PDF
Attachment_5_C-12_Performance_Work_Statement_Rev01.pdf PDF
Attachment_10_C-12_Wage_Determinations_(CBA)_Rev01.pdf PDF
Attachment_12_C-12_Incentive_Plan_Rev01.pdf PDF
C-12_CLS_Questions and Answers.pdf PDF
Attachment_7_C-12_Section L-Instruction to Offerors_Rev01_DRAFT.pdf PDF
PPI_Tool_Download_Instruction.docx DOCX document
C-12 CLS Pre-proposal Registration Fillable Form.pdf PDF
C-12 CLS Pre-Proposal Conference Instructions.pdf PDF
Contractor Vendor Controlled Documents betaSAM.pdf PDF
JCP Portal Access Guide.pdf PDF
Exhibit A_C-12_CLS_Contract_Data_Requirements_List_(CDRLs).pdf PDF
Attachment_10_C-12_Wage_Determinations_(CBA).pdf PDF
Attachment_5_C-12_Performance_Work_Statement.pdf PDF
Attachment_8_C-12_Section M -Evaluation Factors for Award.pdf PDF
Attachment_12_C-12_Transition-QA_Incentive Plan.pdf PDF
C-12 CLS RFP Questions.xlsx XLSX spreadsheet
Attachment_6_C-12_Government_Furnished_Property_List.pdf PDF
Attachment_7_C-12_Section L-Instruction to Offerors.pdf PDF
Attachment_3_C-12_Inspection_and_Acceptance.pdf PDF
Attachment_13_C-12_ID_and_Assertion_of_Use_Release_or_Disclosure_Restrictions_Clause.pdf PDF
Attachment_9_C-12_ Pricing_Matrix.xlsx XLSX spreadsheet
Attachment_1_C-12_CLINs_Descriptions_and_Specifications.pdf PDF
Attachment_4_C-12_Deliveries or Performance.pdf PDF
Official RFP- FA813425RB002.pdf PDF
Attachment_2_C-12_Packaging_and_Transport.pdf PDF
Show all 40

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

FA8134-25-R-B002

Block 13 Cont’d

a. Ref Blk 10a: Base/AFMC Account(s): COMSEC/Cryptographic safeguarding requirements apply. See AFMAN 33-283, Communications Security (COMSEC) Operations for guidance. b. NSA COMSEC Account(s): COMSEC/Cryptographic safeguarding requirements apply. See NSA/CSS Policy Manual 3- 16, Control of COMSEC Material for guidance.

b. Ref Blk 10e(2): Contractor will require access to intelligence information and must comply with AFI 14- 303/AFMC Supplement 1. The Program Manager has determined that disclosure does not create an unfair competitive advantage for the contractor or a conflict of interest with the contractor's obligation to protect the information and will submit the AFMC Form 210 to the AFMC Senior Intelligence Officer (SIO) (HQ AFMC/A2S) for approval prior to granting access.

c. Ref Blk 10f: See SAP Continuation Sheet.

d. Ref Blk 10j: See DoDM 5200.01, Volume 4, DoD Information Security Program: Controlled Unclassified Information (CUI), Enclosures 3 & 4 and DoD 5400.7‑R/Air Force Manual 33‑302, DoD Freedom of Information Act (FOIA) Program, and AFI 16-1404, Air Force Information Security Program, for requirements.

e. Ref Blk 10k: The Program Protection Plan (PPP) will be provided by the Government activity.

f. Ref Blk 11d: The contractor must provide adequate storage for classified hardware and materials to the level of Secret which because of size and quantity it cannot be safeguarded in a General Service Administration (GSA) approved security container.

g. Ref Blk 11f: Overseas contractor performance will occur as a visitor group at (See Table 1). Partial performance will occur at (See Table 1). DSCA is relieved of all security oversight for performance on the installation and overseas performance. For performance on overseas location, security oversight will be under the cognizance of the security listed in Table 1 of the continuation sheet.

h. Ref Blk 11h: Base/AFMC Account(s): COMSEC/Cryptographic safeguarding requirements apply. See AFMAN 33-283, Communications Security (COMSEC) Operations for guidance. b. NSA COMSEC Account(s): COMSEC/Cryptographic safeguarding requirements apply. See NSA/CSS Policy Manual 3-16, Control of COMSEC Material for guidance.

i. Ref Blk 11j: Program and mission specific OPSEC requirements will be conducted in accordance with the

PWS.

j. Ref Blk 11l: Controlled Unclassified Information is applicable to this contract. The contractor shall refer to the PWS for requirements.

k. Ref Blk 11m: Provide the information requested by the Notification of Government Security Activity and Visitor Group Security Agreements clause, Air Force Federal Acquisition Regulation Supplement (AFFARS) 5352.204-9000, to the security activities listed in Table 1, Block 8a.

Ref Blk 18f (Distribution):

88 ABW/IPD, 1801 Tenth St, Wright-Patterson AFB OH 45433 7625 88ABW.IPD.Industrial.Security@us.af.mil

FA8134-25-R-B002

AFLCMC/WVV (Security Manager),3001 Staff Drive, Ste. 1AC4 106C, Tinker AFB OK 73145, Courtney Penn, courtney.penn@us.af.mil

AFLCMC/WV (Security Specialist) Chris Clark, Presidential & Executive Airpower, Program Execution Group AFLCMC/WV-CROWS, Wright Patterson AFB, OH Work: (937) 656-9647

HQ Defense Counterintelligence and Security Agency, 27130 Telegraph Rd, Quantico VA 22134.

CUI

Controlled by: Department of the Air Force Controlled by: AFLCMC/WVV CUI Category: OPSEC POC: Kalie Posey, 312-336-3803

CUI

DoD SAP ADDENDUM Mandatory for all SAP efforts

(U) ADDENDUM FOR CONTRACT #TBD at Revision - Solicitation FA8134-25-R-B002

(U) CONTRACT COMPLETION DATE: 31 OCT 2035

(U) NETWORK ACCESS REQUIRED: N/A

(U) PRIVILEGED USERS SUPPORT THIS CONTRACT: NO

1. (U) Item 1a: Level of Facility Clearance (FCL) Required: NISS database verification of appropriate FCL level will be completed prior to SAP nomination/access.

2. (U) Item 1b: Level of Safeguarding for Classified Information/Material at Contractor Facility: There will be no storage of SAP materials at contractor facility. All SAP materials will remain at the performance location listed below.

3. (U) Item 8a-c: Actual Performance: Actual performance location(s) listed in DD254 Block 8 does not constitute approved SAP location(s). SAP performance is authorized ONLY at the following location(s) if formal SAP facility (SAPF) accreditation by the OSI PJ SAO exists.

# Location (Physical Address) CAGE Code CSO (Physical Address)

1 704 TG/586 FLTS

961 Dezonia Road Building 1074 Holloman AFB, NM

4. (U) Item 10a: Communication Security (COMSEC) Information: Contractor must forward request for COMSEC material/information through Contracting Officer Representative (COR). The contractor is governed by 32 CFR Part 117.21. Access to COMSEC material is restricted to U.S. Citizens holding a final U.S. Government security clearance at the appropriate level. Prior approval from the Government Contracting Agency is required in order for a prime contractor to grant COMSEC access to a subcontractor. Non-accountable COMSEC information, though not tracked in the COMSEC material control system, may still require a level of control within a document control system. Refer to NSA/CSS Policy Manual 3- 16, "Control of Communications Security Material," and the Committee on National Security Systems Instruction (CNSSI) 4001 “Controlled Cryptographic Items," for guidance.

a. Unless “11.h.” is checked, all accountable COMSEC material provided to the contractor is on loan by a government COMSEC account under the terms of the contract and the contractor is established as a Local Element/Hand Receipt Holder of the Government account.

5. (U) Item 10e (2). Intelligence Information (Non-SCI): Contractor will require access to ICD 710 Classification Management and Control Markings System. For Non-SCI Requirements: All contractor personnel assigned under this contract must possess a current Top Secret security clearance. Personnel are required to sign a non-disclosure agreement. The GCA must provide prior approval before a subcontract involving access to non-intelligence information can be issued.

(U) ADDENDUM FOR CONTRACT #TBD at Revision - Solicitation FA8134-25-R-B002

(U) CONTRACT COMPLETION DATE: 31 OCT 2035

(U) NETWORK ACCESS REQUIRED: N/A

(U) PRIVILEGED USERS SUPPORT THIS CONTRACT: NO

6. (U) Item 10f. Special Access Program (SAP) Information: This contract is in support of a special access program (SAP) imposing strict requirements for Need-to-Know (NTK), access controls, special handling procedures, physical security measures, and administrative controls beyond those prescribed for collateral Department of Defense (DoD) classified Information. The portion of this contract conducted at the actual performance area listed paragraph 3 above is a total carve out established in accordance with 32 CFR Part 117 and requires special security requirements.

a. (U) Personnel may be required to be accessed to additional programs based on mission need.

Specific program security classification guides will be provided as needed under separate cover.

b. (U) The Defense Counterintelligence Security Agency (DCSA) Cognizant Security Office identified in Item 6c. of the DD Form 254 is relieved of responsibility and security oversight of the portion of this contract conducted at the actual performance area listed paragraph 3 above.

The PSO shall have overall security oversight and responsibility for that portion, to include oversight of all compartmented information and/or material received and/or generated under this contract.

c. (CUI) The contract document and its Contract Security Classification Specification (DD Form

254) shall not be released without prior written authorization from the PSO. If in direct support of a mission requirement and validated and approved by the PSO, the unclassified acknowledgement statement indicated in the Security Classification Guide (SCG) for the programs may be provided to un-cleared personnel; under no circumstance is CLASSIFIED, CONTROLLED UNCLASSIFIED, and/or HVSACO information to be divulged to individuals without formal access to the Special Access Program(s) and/or valid need-to-know. The PSO shall be notified immediately of attempts by unauthorized persons to seek information regarding this program.

Public release of program information, regardless of the classification, is not authorized without approval from the GPM, the COR and the PSO.

(U) The Department of Defense Manuals (DoDM) 5205.07 Vol 1-4 and successor guidance as updated shall be utilized in the execution of this contract. A series of Security Classification Guides, specific to the programs to include collateral classification guides if applicable, will be provided to the contractor under separate cover. Other non-contract related SAP information is not authorized for use in the performance of this contract without prior written authorization of the Government Program Manager (GPM) and the cognizant Program Security Officer.

d. (U) This contract imposes strict application of the need-to-know principle. Program access is strictly limited to an absolute minimum number of persons essential to the fulfillment of this contract. Prospective candidates for performance on this contract shall not be informed of their consideration for access to a SAP. They may however, be advised of their consideration to a position requiring access to classified information. Nominees for access to program information will require written approval by the cognizant access approval authority, or designated representative prior to gaining knowledge of or access to any codeword or program related information. Access approvals are valid for 30 days following official notification, unless the PSO has approved an extension in writing. Persons approved for access will execute a Special Access Program Indoctrination Agreement (SAPIA) prior to receiving indoctrination briefings

(U) CONTRACT COMPLETION DATE: 31 OCT 2035

into this SAP. Executed SAPIAs shall be forwarded to the PSO within three (3) working days or uploaded into the DoD system of record.

e. (CUI) Baseline clearance and investigation requirements for the program(s) are:

i. (U) SECRET Level Access: A US Government SECRET clearance based on a current (within 6 years) completed Access National Agency Check (ANACI) or National Agency Check with Local Agency and Credit Checks (NACLC)/Tier 3 and access eligibility in accordance with Special Access Program Nomination Process (SAPNP) criteria.

f. (U) Personnel nominated for access to Secret SAP information will be determined eligible/ineligible for access in accordance with the established DoDM 5205.07 Vol 2 Special Access Program Nomination Process (SAPNP) criteria.

g. (CUI) The Contract number FA8134-25-R-B002, regardless of the classification per the SCG, is not authorized for release in the public domain without prior approval from the PSO. This includes any contractor corporate payment/management systems, requests for Common Access Cards, COMSEC accounts, requests for access to government systems, etc.

h. (U) All classified discussions, Information Systems (IS) processing and/or storage of any SAP information and/or materials will be conducted at the SAP accredited/approved facility identified in Section 8 of the attached DD Form 254.

i. (U) Classified information/materials generated under this contract will reflect appropriate security classification markings (e.g., portion and banner markings), program codeword, PID, and required access level, as stipulated in DoD guidance and the applicable SCGs.

j. (U) The Contractor Program Manager (CPM) and Contractor Program Security Officer (CPSO) have security classification review responsibility for information generated/produced in connection with this contract. Questions regarding security classification, not governed by specific security classification guidance, will be addressed to the PSO for a classification determination.

k. (U) Collateral information/materials not directly re1ating to this contract shall not be introduced or authorized within an approved program facility without prior written authorization from the

PSO.

l. (U) Graphic arts, reproduction, publication, printing, binding, word processing, and clerical and administrative support services will not be subcontracted to commercial facilities nor will work on any program information relating to this contract by performed external to accredited program space/area(s) within the contractor's facility.

m. (U) Classified or unclassified program subcontracting must have prior approval of the Procurement Contracting Officer (PCO) and PSO. The CPSO will complete a subcontractor or supplier data sheet for submission to the PSO. Any classified program activity which requires the use of a subcontractor facility must meet DoDM 5205.07 Vol 3 criteria and be approved by the

(U) CONTRACT COMPLETION DATE: 31 OCT 2035

PSO. The Prime Contractor CPSO is responsible for the security administration at the subcontractor facility, under the security oversight of the PSO.

n. (U) The CPSO is required to ensure that all adverse and Continuous Evaluation (CE) information regarding any indoctrinated personnel under his or her cognizance is forwarded to the Consolidated Adjudication Services (CAS) by the site or facility Local Security Manager or entry in Defense Information System for Security (DISS) or successor system of record procedures for reporting information. The CPSO is to retain evidential record of submission of said information to the CAS; compliance of this requirement will be validated during the facility compliance inspection. Additionally, the CPSO is required to adhere to the DoDM 5205.07 Vol 2 by providing the cognizant PSO with the applicable SAP Format(s), or other submitted documentation for any reportable adverse event/occurrence of indoctrinated personnel.

(U) Within 24 hours, contractors will notify their Agency (or GCA) PSO in writing of any and all security incidents. Subcontractors will also notify their prime contractors if they make any notifications or submit reports to their CSA IAW 32 CFR Part 117: NISPOM Rule. The prime contractor will also provide notification to both subcontractor management and FSO of subcontractor security incidents courtesy copying the Agency (or GCA) PSO.

(U) The prime contractor must provide the PSO documentation from the owning facility security officer (FSO), including subcontractors, attesting that Defense Information System for Security (DISS) entries have been made for each security violation. Documentation of DISS entry must be furnished within 30 calendar days of final report submission and must include the DISS entry date, DISS case number, culpable individual name, and security incident date, and the incident description entered in DISS.

o. (U) All programmatic material relating to this contract and its administration shall be classified and marked and transmission shall be protected in accordance with the program specific security classification guide, this DD Form 254, the DoDM 5205.07 Vol l and 4, DoD guidance or as directed by the PSO.

i. (U) TOP SECRET//SAR material shall not under any circumstances, be mailed through the U.S. Postal System. Courier of TOP SECRET//SAR material will be only on U.S.

military or commercial aircraft with prior written PSO approval.

p. (U) The following mailing addresses will be utilized to send materials in support of this contract to the government:

(U) REQUESTS FOR PAYMENT - Follow the procurement and payment process specified in the contract document.

q. (U) The contractor's mailing procedures shall be sent to the PSO for review and approval. The contractor will immediately inform both the PCO and PSO of an1 change in the contractor’s mailing address or mailing procedures.

(U) CONTRACT COMPLETION DATE: 31 OCT 2035

r. (U) All invoices/vouchers submitted under this contract will be UNCLASSIFIED and devoid of any information which would require them to be classified. Follow the invoice/voucher submission instructions contained in the contract/order.

s. (U) When counsel is retained by the contractor to represent corporate interests in matters related to or associated with program sponsored activities, the PCO/PSO must be notified in writing. The counsel shall be treated as any subcontractor with a subcontract.

t. (U) The contractor shall comply with DoDI 5015.02 DoD Records Management Program for all records management procedures. Upon completion of this contract and when the final deliverable has been accepted by the Government, the contractor will conduct an inventory/audit of all accountable classified documents received or generated under this contract and forward a copy to the PSO. Documents necessary for contract close-out (i.e., notification of receipt and acceptance by sponsor, applicable financial documents, contracts, etc.) may be retained by the contractor after contract completion if determined, by the PCO and PSO, to be required for final audit and subsequent close-out.

u. (U) At the end of the contract Period of Performance, the contractor shall submit a written request to the PCO/PSO for authorization to retain specific materials or transfer materials to a new contract. Retention of any additional program classified documents beyond contract closeout will be considered only if there is a follow-on contract. Exceptions to this may be granted by the Government on a case by case basis. Written requests should be forwarded to the PSO/PCO for consideration.

v. (U) Program related verbal communications shall be conducted on approved secure telephone lines. Therefore, the contractor shall obtain, operate, and maintain secure telephonic communications compatible with STE/vIPer phones. The cost of obtaining and operating secure communications shall not be a direct charge to the contract.

w. (U) The following reports/deliverables are required in addition to the requirements of the DoDM

5205.07 Vol 1-4 and successor guidance as updated:

i. (U) A Corrective Action Plan (CAP) addressing deficiencies noted during the compliance inspection will be developed and forwarded to the PSO no later than 30 days from contractor receipt of the inspection report. The CAP shall be updated and sent to the PSO every 30 days thereafter until all open items have been certified closed by the PSO.

ii. (U) Security Plan for Test will be developed in accordance with the DoDI 5000.89 Department of Defense Instruction Test and Evaluation policy and forwarded to the PSO for review no later than 90 days prior to the activity to ensure that a final plan is signed prior to the commencement of the events(s).

iii. (U) An approved site specific Operations Security (OPSEC) Plan is required. Site specific OPSEC plans will be developed in consonance with the guidance outlined within the current 32 CFR Part 117, and DoDM 5205 .07, Vol 1-4.

(U) CONTRACT COMPLETION DATE: 31 OCT 2035

x. (U) Any conflict between instructions contained in 32 CFR Part 117, the DoDM 5205.07 Vol 1-4, the DoDM 5200.01 Vol 1-4, and this DD Form 254 must be reported to the PSO by the most expedient means for resolution.

y. (U) Non-compliance with any of the requirement and restrictions of this clause, 32 CFR Part 117, DoDM 5205.07 Vol 1-4, or other DoD security policy may result in debriefing and removal from access to this program, and may also be grounds for termination of the contract for default.

Furthermore, any unauthorized disclosure of classified information pertaining to this contract or program could seriously affect the National Defense of the United States, and such revelation would be subject to Federal Prosecution under the Espionage Laws, Title 18, United States Code, Sections 641, 793, 794, 798, 952, and 1001.

7. (U) Item 10j. Controlled Unclassified Information (CUI): The Contractor is authorized access to CUI and it must be classified, declassified, marked, protected, stored, destroyed, transmitted, and transported, as specified in DoDI 5200.48 Controlled Unclassified Information. The contractor is prohibited from disclosing or disseminating this information without the expressed written authorization of the COR. In addition, contractors or subcontractors must obtain approval from the GCA prior to posting any unclassified information on the Internet. The contractor shall provide all cleared employees with some form of security education and training at least annually. Refresher training shall reinforce the information provided during the initial security briefing and shall keep cleared employees informed of appropriate changes in security regulations. Contractors shall maintain records about the programs offered and employee participation in them. Contractors may obtain defensive security, threat awareness, and other education and training information and material from their CSA or other sources.

a. (U) With the implementation of DoDI 5200.48, DoDI 5200.01, Volume 4, “DoD Information

Security Program: Controlled Unclassified Information” (24 February 2012, as amended), has been cancelled and "For Official Use Only" (FOUO) and is no longer authorized.

b. (U) Unclassified Automated Information Systems (AIS) used to process CUI under this contract must meet the basic security requirements listed in the NIST SP 800-171 as amended, “Compliance for Federal Contract”. AIS accredited and approved for processing classified information under this contract are also approved to process DoD CUI.

c. (U) Transmission: CUI may be transmitted using the following:

o (U) Mail CUI may be sent via first class mail or parcel post. Bulk shipments may be sent by fourth class mail. Contents must be properly marked, but no markings will appear on the outer wrapper.

o (U) Facsimile - Normally CUI may be sent via Facsimile equipment. To prevent unauthorized disclosure, coversheets should be used, the locations of both fax machines should be considered, and availability of an authorized recipient at the receiving end should be confirmed. Secure classified fax machines may be used without the above verifications.

(U) CONTRACT COMPLETION DATE: 31 OCT 2035

o (U) E-Mail/Web Sites - E-mail may be used on approved secure communication systems or systems using other protective measures such as Public Key Infrastructure (PKI) or transport layer security (e.g., https). E-mail messages must be appropriately marked to identify CUI status. Personnel will not use unofficial or personal email accounts, messaging systems, or other non-DoD information systems, except approved government contractor systems to conduct official business involving CUI.

o (U) Video Teleconferencing - Only use Government Agency approved secure, encrypted video conferencing and collaborative platforms (i.e. SVTC, etc.). CUI may not be discussed over commercially available video conferencing applications.

d. (U) Unauthorized Disclosure: Report misuse, mishandling, or Unauthorized Disclosure of CUI to the Unauthorized Disclosure Program Management Office, the Controlling Agency, and the appropriate Military Department Counterintelligence Organization. While Unauthorized Disclosure of CUI does not constitute a security violation, a formal security inquiry/ investigation is required if disciplinary action will be taken against the individual(s) responsible. Unauthorized Disclosure of certain CUI, such as export controlled-technical data, may also result in civil and criminal sanctions against responsible persons based on procedures codified in relevant law, regulation, or government-wide policy.

8. (U) Item 10k. Other (Specify): The Program Protection Plan (PPP) will be provided by the Government activity.

9. (U) Item 11a. Have Access to Classified Information Only at Another Contractor's Facility or a Government Activity: The contractor will not have access to SAP information at its own contractor facility, but will have that access elsewhere: See paragraph 3 above. The contractor will be expected to adhere to the government security standards for work within that space as identified by the government activity.

10. (U) Item 11d. Fabricate, Modify, or Store Classified Hardware: (Note: As the Cognizance Security Office, the PSO, should verify the appropriate mailing or shipping address to transmit any classified hardware and to verify the approved classified storage capacity at the contractor facility and any other contractor actual performance locations. Describe the nature and extent of the storage that will be required. Will Restricted or Closed Areas be required? Is hardware involved? If so, how much hardware is involved? How large is the hardware? Will there be a separate requirement for open storage of classified documents?)

11. (U) Item 11f. Have Access to U.S. Classified Information Outside the U.S., Puerto Rico, U.S.

Possessions and Trust Territories: The Contractor will not be performing SAP duties outside the United States under this contract.

12. (U) Item 11h. Require a COMSEC Account: All program related classified verbal and electronic communications shall be conducted on approved secured instruments. Access to COMSEC material is restricted to US Citizens holding a final US Government security clearance. Such information is not releasable to personnel holding only reciprocal clearance. The contractor will not require a SAP COMSEC account. SAP COMSEC equipment will be provided by the Government.

(U) CONTRACT COMPLETION DATE: 31 OCT 2035

13. (U) Item 11j. Have Operations Security (OPSEC) Requirements: The contractor will apply Operations Security (OPSEC) to enhance protection for classified and unclassified critical information. While the documents identified in references below provide details on the development of OPSEC programs and implementation of OPSEC analyses, the requirements below provide the minimum standards for OPSEC application directed in this contract.

a. (U) The contractor manager or a delegated OPSEC coordinator will be familiar with operations security (OPSEC) as described in National Security Decision Directive Number 298, DoD Directive 5205.02, and DoD Manual 5205 .02-M.

b. (U) Military Service and COCOM OPSEC guidance (Joint Publication 3-13.3, CJCS Instructions, and appropriate Service or COCOM issuances) may also apply if the contracted activity is performed in a Service or COCOM operational environment. If performance is conducted in a tenant arrangement within a Service or COCOM environment and a conflict is identified in local guidance, forward concerns through the GPM, to the PSO for clarification.

c. (U) The PSO is the authority to resolve all OPSEC guidance conflict(s) for this contract and will coordinate with the Service or COCOM OPSEC Program Manager as needed.

d. (U) Personnel will comply with OPSEC measures and program requirements established at the government site/program.

e. (U) Personnel supporting the contract will protect details described on the Critical Information List (CIL) provided by the COR as proprietary to the government.

f. (U) All personnel supporting the contract will receive initial and recurring (at least annually) OPSEC awareness training that identifies relevant threat information including techniques used by adversaries to obtain classified and unclassified critical information, directed OPSEC measures, OPSEC coordinator contact information, and reporting requirements. The OPSEC coordinator will maintain training records that can be reviewed during assessments or compliance inspections.

14. (U) Item 11l. Receive Store or Generate Controlled Unclassified Information (CUI): Contractor will refer to DoDI 5200.48 when receiving, storing, or generating CUI. Contractors shall provide all cleared employees with security training and briefings commensurate with their involvement with classified information. The contractor shall provide all cleared employees with some form of security education and training at least annually. Refresher training shall reinforce the information provided during the initial security briefing and shall keep cleared employees informed of appropriate changes in security regulations. Contractors shall maintain records about the programs offered and employee participation in them. Contractors may obtain defensive security, threat awareness, and other education and training information and material from their CSA or other sources.

(U) CONTRACT COMPLETION DATE: 31 OCT 2035

15. (U) Item 11m. Other:

a. (U) All unclassified DoD information in the possession of non-DoD entities on non-DoD information systems shall be protected in accordance with DoDI 8582.01, “Security of Non-DoD Information Systems Processing Nonpublic DoD Information.”

b. (U) The contractor organization is required to establish and implement an Insider Threat program as required per 32 CFR Part 117.7(d). All Insider Threat concerns regarding SAP accessed personnel will be reported to the AFOSI PJ PSO or local PJ Office within 24 hours. AFOSI PJ will notify the contractor if further reporting is required.

c. (U) Consent to subcontract restriction : All security requirements levied upon the prime contractor and/or otherwise associated with this contract shall immediately be flowed down from the prime contractor to any subcontractor (or from a subcontractor to a lower tier subcontractor), regardless of the scope of any such participation should it require access to classified information or unescorted access to controlled space where classified information (regardless of media) and/or hardware is open-stored, generated or otherwise accessible. Escorted access is defined as being under the visual control of appropriately cleared personnel with the requisite need-to-know.

Subcontractors are expressly not authorized to participate in this contract unless and until such time that the COR has expressly consented in writing to the participation of any such participant.

d. (U) Contractors who have received a Common Access Card (CAC) to access to government installations and systems pursuant to the requirements of the contract are required to notify the Trusted Agent (TA) when an individual is no longer supporting the contract for which they obtained the CAC. All CACs must be returned to the TA at this time.

16. (U) Item 12. Public Release: No public release or disclosure is authorized of classified program information. A pre-release and/or pre-publication security review is required prior to the disclosure of information which is either categorically or directly related to the program, but not formally classified within SAP channels. In each case, approval must be obtained from the GPM. The request must be submitted from the person desiring to make the publication or presentation, via the Contractor Program Security Officer (CPSO) to the PSO with at least 30 days prior to its intended release.

17. (U) Item 13. Security Guidance: The contractor will adhere to all policy guidance listed in Item 13 of the DD 254.

a. (U) The contractor shall adhere to the following Security Classification Guides (SCGs) in accordance with Program Office (PO) guidance and all classification guidance signed by the DON SAPCO (or other agency as appropriate) and implemented by the PO. This includes:

i. (U) The current program SCGs. (Program SCGs will be provided at the Government work location.)

ii. (U) Program Office instructions.

File details come from the government source that posted it. Updated .