Attachment 2 Appendix 1.6.7 Security Requirements.pdf

PDF 361 KB Posted

Attached to
Test Engineering and Analysis Services (TEAS) Federal contract opportunity
Solicitation number
W9115124R0030
Issued by
Department of the Army

About this file

This document is an Appendix to a Request for Proposal (RFP) that contains security requirements for a federal contract opportunity. The key details are:

The security requirements cover topics such as classified information handling, physical access to installations and facilities, Common Access Card (CAC) issuance, security training, Operations Security (OPSEC), Antiterrorism/Force Protection (AT/FP), and handling of Controlled Unclassified Information (CUI) and Personally Identifiable Information (PII). Contractor personnel must comply with various Army and DoD regulations related to these security requirements. The Contractor is required to develop an OPSEC plan, maintain a Facility Security Officer, and ensure all personnel complete mandated security training. Requirements for personnel security clearances, drug testing, and protecting government assets are also specified. Technical and cybersecurity training and certification requirements are detailed for Contractor personnel with access to government information systems and networks.

View the file

Other files for this federal contract opportunity

Show all 22

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

APPENDIX 1.6.7

1.6.7. Security Requirements

1.6.7.1. Classified Information: Questions regarding CLASSIFIED information shall be handled through the WSMR Security Office. Specifically, any entity wanting to ask a question regarding CLASSIFIED information shall send an email to the WSMR Security Office, the Technical POC and the Business POC stating that the entity would like to ask a question regarding CLASSIFIED information. DO NOT EMAIL ANY QUESTIONS THAT MAY CONTAIN CLASSIFIED I NFORMATION. The Security POC will contact the entity and arrange for the question pertaining to CLASSIFIED information be asked through a secure method of communication. The WSMR G2 Security Office POC is Robert R. Easley, 575-678-5228, robert.r.easley.civ@army.mil.

1.6.7.1.1. Anti-Terrorism (AT) Level I Training general: All Contractor employees, to include sub-Contractor employees, requiring access Army installations, facilities and controlled access areas shall complete AT Level I awareness training within 30 calendar days after contract start date or effective date of incorporation of this requirement into the contract, whichever is applicable. The Contractor shall submit certificates of completion for each affected Contractor employee and sub-Contractor employee, to the COR or to the contracting officer (if a COR is not assigned), within 30 calendar days after completion of training by all employees and sub-Contractor personnel. AT level I awareness training is available at the following website: http://jko.jten.mil

1.6.7.2. Access and general protection/security policy and procedures: Contractor and all associated sub-Contractor employees shall provide complete and accurate information required for background checks to meet installation access requirements as defined by the Installation Provost Marshal Office, Director of Emergency Services, or Security Office. The Contractor workforce shall comply with all personal identity verification requirements (FAR clause 52.204-9, Personal Identity Verification of Contractor Personnel) as directed by DOD, DA and/or local policy. Should the Force Protection Condition (FPCON) at any individual facility or installation change, the Government may require changes in Contractor security matters or processes in accordance with DoDI 2000.16.

a. Installation Exercises and Scheduling: The Contractor shall work closely with the KO and/or the COR who has access to the Installation training schedule. The Contractor shall schedule work/deliveries accordingly. Contractors shall as part of the exercise and be required to provide an accountability of personnel to the COR of numbers of employees on hand and locations.

b. Unauthorized weapons/firearms: No Contractor, sub-Contractor, or affiliate shall bring Privately Owned Weapons/Firearms on the Installation.

c. Search and Seizure: Contractor personnel and property shall be subject to search and seizure in areas the Contractor is providing official support duties and upon entering, while on, or upon leaving the confines of WSMR.

d. Operational Delays Because of Threat, Disaster, Weather, or Operational Testing: The Senior Mission or Garrison Commander because of an increase in threat, disaster, inclement weather or operational testing may require the installation curtail operations, limiting access to essential Government employees only, http://jko.jten.mil/ block/restrict movement on major roads on or leading to WSMR, or close the installation. The Contractor cannot hold the United States (US) Government or the Command at the installation responsible for cost overruns because of these operational decisions.

1.6.7.3. Issuing New Common Access Card (CAC): Before CAC issuance, the Contractor employee requires, at a minimum, a favorably adjudicated Tier 1 (T1) (National Agency Check with Inquiries (NACI) equivalent) or higher investigation in accordance with Army Directive 2014-05. The Government will issue a Contractor a CAC only if duties involve one of the following:

a. Both physical access to a DoD facility and access, via logon, to DOD networks on-site or remotely

b. Remote access, via logon, to a DOD network using DOD-approved remote access procedures

c. Physical access to multiple DOD facilities or multiple non-DOD federally controlled facilities on behalf of the DOD on a recurring basis for a period of 6 months or more.

At the discretion of the sponsoring activity, an initial CAC may be issued based on a favorable review of the FBI fingerprint check and a successfully scheduled T1 investigation at the Office of Personnel Management.

1.6.7.3.1. CAC Issuance: The Contractor, through their human resources or personnel office, will send the Government COR a request for a CAC card if required. The application for the CAC card is normally obtained through the Trusted Associate Sponsorship System (TASS) website. The on-line application will be submitted in the TASS by the Contractor to the COR. Contractor CAC card and WSMR Network access require an NACI Investigation using the SF 85P form. The COR will approve the application and process for issuance. In order to acquire the CAC, the Contractor employee shall present a current Federal or State photo identification (such as a driver’s license) and proper identification with their social security number. The Contractor is responsible for accountability of the CAC card and shall return it to the COR upon request or when employment for an individual ends. Lost CAC cards shall be reported to the COR with an account of the circumstances and explanation of actions to prevent reoccurrence prior to issuance of a replacement card.

1.6.7.3.2. Access Without a CAC: For Contractors that do not require a CAC, but require access to a DOD facility or installation, the Contractor and all associated sub- Contractor employees shall comply with adjudication standards and procedures:

a. National Crime Information Center Interstate Identification Index (NCIC-III)

b. Terrorist Screening Database (TSDB) (Army Directive 2014-05/AR 190-13)

c. Applicable Installation, facility and area commander installation/facility access

d. WSMR security policies and procedures

e. Status of forces agreements and other theater regulations while in OCONUS locations

1.6.7.3.3. Alternate Credential Issuance: All Contractor employees that will not require CAC shall be required to possess an alternate form of installation access ID credential. The specific list of approved credentials and procedures for obtaining them are identified in Memorandum for See Distribution, Subject White Sands Missile Range Visitor Control Program and attached annexes, Dated 29 January 2015 or subsequent updates.

1.6.7.3.4. Departing Employees: The Contractor shall ensure all permanently (and temporarily when in excess of 30 days) departing Contractor or sub-Contractor employees return security photographic identification cards, permits, CAC’s, Government property, keys, photo passes, and range passes. The Contractor shall request cancellation of Local Area Network (LAN) email access for departing personnel at the completion of their employment. The Contractor shall utilize a company / Installation clearance (out-processing) form to include a signature block for the COR to certify that an employee has returned all required badges, CACs, keys, and other accountable items. The Contractor shall return keys to the issuing key custodian prior to the employee departing. Depending on the position, information access, and clearance level, a Contractor may require a security debriefing prior to departure.

1.6.7.3.5 Key Control (If applicable). The Contractor shall establish and implement methods of making sure all keys/key cards issued to the Contractor by the Government are not lost or misplaced and are not used by unauthorized persons. NOTE: All references to keys include key cards. No keys issued to the Contractor by the Government shall be duplicated. The Contractor shall develop procedures covering key control that shall be included in the Quality Control Plan (QCP). Such procedures shall include turn-in of any issued keys by personnel who no longer require access to locked areas. The Contractor shall immediately report any occurrences of lost or duplicate keys/key cards to the Contracting Officer.

1.6.7.3.6. In the event keys, other than master keys, are lost or duplicated, the Contractor shall, upon direction of the KO and/or COR, re-key or replace the affected lock or locks; however, the Government, at its option, may replace the affected lock or locks or perform re-keying. When the replacement of locks or re-keying is performed by the Government, the total cost of re-keying or the replacement of the lock or locks shall be deducted from the monthly payment due the Contractor. In the event a master key is lost or duplicated, all locks and keys for that system shall be replaced by the Government and the total cost deducted from the monthly payment due the Contractor.

1.6.7.3.7. The Contractor shall prohibit the use of Government issued keys/key cards by any persons other than the Contractor’s employees. The Contractor shall prohibit the opening of locked areas by Contractor employees to permit entrance of persons other than Contractor employees engaged in the performance of assigned work in those areas, or personnel authorized entrance by the Contracting Officer.

1.6.7.3.8. Lock Combinations (If applicable): The Contractor shall establish and implement methods of ensuring that all lock combinations are not revealed to unauthorized persons. The Contractor shall ensure that lock combinations are changed when personnel having access to the combinations no longer have a need to know such combinations. These procedures shall be included in the Contractor’s QCP.

1.6.7.4. Initial, Annual, and Program Specific Security Training: Government furnished and required security training includes Initial (New Hire) and Annual Cybersecurity (CS) Awareness Training, iWATCH, AT, Operations Security (OPSEC), Threat Awareness and Reporting Program (TARP) Training, and any other command mandated training.

Contractors shall complete the following Security training within 30 calendar days of contract award and within 15 calendar days of new employees commencing performance with the results reported to the COR NLT 45 calendar days after contract award.

iWATCH Program AT Level 1 annual training OPSEC Awareness annual training

These trainings shall be tracked or documented using either hard copy sign in sheets, online-automated tracking programs, or CAC verification. The method of tracking will be identified to the Contractor through the COR prior to start of the training activity.

There are program specific trainings in the area of Arms, Ammunition, and Explosives (AA&E), Information Security (INFOSEC), Communications Security (COMSEC) and other security disciplines that shall be identified and tracked by the Program/Project Manager.

a. Part and Full Time Permanent Employee Security Training Tracking: Part and full time permanent employees requiring either WSMR Network access, installation access in excess of six months or both shall be required to complete all security-mandated trainings assigned and tracked through the ATEC Training Tracker Module (ATTM). The COR and the Government Training Coordinator shall log Contractor personnel and training requirements.

b. Other Category Employees Security Training Tracking: Casual, temporary, and those employees that do not have WSMR Network access shall be required to complete all assigned security trainings assigned through the ATTM to those employees identified above. The Facility Security Officer (FSO) and the G-2 Industrial Security Officer (ISO) shall coordinate the delivery and tracking method.

Annually (last week of August) a report of all such employees, identifying the completion date of each training event by each employee shall be provided to the

WSMR ISO.

c. New Employee Orientation: New Contractor employees require security training within thirty (30) days of start date. For the purposes of security training events, a new hire shall be defined as an employee that is newly hired to the Contractor or is returning after a break in employment in excess of one year. If an employee was previously a service member, civil servant, or employed with another Contractor assigned to or contracted by the WSMR/ATEC Command and did not have a break in service in excess of one year they shall not be considered a new hire. The

Contractor, the Government Training Coordinator, the COR, the FSO, and the ISO track Contractor security requirements.

d. AT Awareness Training for Contractor Personnel Traveling Overseas: The Contractor and associated sub-Contractor employees shall receive Government provided area of responsibility (AOR) specific AT awareness training as directed by AR 525-13. When OCONUS, the Contractor shall participate in specific AOR training content as directed by the Combatant Commander with the unit ATO being the local point of contact.

1.6.7.5 iWATCH TRAINING: The Contractor and all associated sub-Contractors shall brief all employees on the local iWATCH program (training standards provided by the requiring activity ATO). This locally developed training will be used to inform employees of the types of behavior to watch for and instruct employees to report suspicious activity to the appropriate personnel. This training shall be completed within 30 calendar days of contract award and within 15 calendar days of new employees commencing performance with the results reported to the COR NLT 45 calendar days after contract award.

1.6.7.6. The Contractor shall develop an OPSEC Standing Operating Procedure (SOP)/Plan within 90 calendar days of contract award, to be reviewed and approved by the responsible Government OPSEC officer (see CDRL 0010). This plan will include a process to identify critical information, where it is located, who is responsible for it, how to protect it and why it needs to be protected. The Contractor shall implement OPSEC measures as ordered by the commander. In addition, the Contractor shall have an identified certified Level II OPSEC coordinator per AR 530-1.

1.6.7.7. OPSEC Requirements: The Contractor shall comply with the OPSEC requirements IAW:

a. AR 530-1, Operations Security

b. US ATEC Policy Bulletin 14-12

c. WSMR OPSEC Standard Operating Procedure

d. WSMR OPSEC Plan,

e. OPSEC review and approval of Government / Research, Development, Test and Evaluation (RDT&E) information prior to its public release.

1.6.7.7.1. OPSEC Training: Per AR 530-1 Operations Security, the Contractor employees shall complete Level I OPSEC Awareness training. New employees shall be trained within 30 calendar days of their reporting for duty and annually thereafter.

1.6.7.8. Performance or Delivery in a Foreign Country: DFARS Clause 252.225-7040, Contractor Personnel Authorized to Accompany U.S. Armed Forces Deployed Outside the United States. The clause shall be used in solicitations and contracts that authorize Contractor personnel to accompany US Armed Forces deployed outside the US in contingency operations; humanitarian or peacekeeping operations; or other military operations or exercises, when designated by the combatant commander. The clause discusses the following AT/OPSEC related topics: required compliance with laws and regulations, pre-deployment requirements, required training (per combatant command guidance), and personnel data required.

1.6.7.9. Facility Clearance: The approved Contract Security Classification Specification, DD Form 254 governs on-site activities performed under the organization's facility clearance. The DD Form 254 issued to the Contractor with this PWS provides instructions for the safeguarding of classified information. The Contractor shall comply with FAR 52.204‐2, Security Requirements. This clause involves access to information classified “Confidential”, “Secret”, or “Top Secret” and requires Contractors to comply with:

a. The Security Agreement (DD Form 441), including the National Industrial Security Program Operating Manual (DoD 5220.22‐M); any revisions to DoD 5220.22‐M, notice of which has been furnished to the Contractor.

b. The Contract Security Classification Specification (DD Form 254).

c. DoD 5200.1, Volumes 1-4. DoD Information Security Program

d. AR 380-5, Department of the Army Information Security Program

1.6.7.10. Personnel Security Clearance: The Contractor shall be able to acquire a Facility Clearance Level of at least SECRET. Offeror must provide a current and complete DD Form 441, Department of Defense (DOD) Security Agreement and meet all requirements. If a current and complete DD Form 441 cannot be submitted, then the Contractor will put a plan and process in place to obtain a Facility Clearance. The approved Contract Security Classification Specification, DD Form 254 governs on-site activities performed under the organization's facility clearance. The DD Form 254 issued to the Contractor with this PWS provides instructions for the safeguarding of classified information. The Contractor shall comply with FAR 52.204‐2, Security Requirements. This clause involves access to information classified “Confidential”, “Secret”, or “Top Secret” and requires Contractors to comply with:

a. Be granted access to classified information

b. Be allowed to perform classified work

c. Be granted access to restricted areas, unless escorted by a person having proper clearance and authorization

d. Handle AA&E material, keys, or data

1.6.7.11. OWNING/SERVICING RELATIONSHIPS The FSO shall provide the WSMR Personnel Security Manager (PSM) with a list of all personnel, "Owned" or "Serviced" through the Defense Information System for Security (DISS) and assigned to this contract within ten (10) workdays after contract award. The Contractor shall provide a monthly update to the COR and PSM by the first Wednesday of each month. The FSO will maintain an "Owning" relationship with all personnel employed by the prime Contractor and a "Servicing" relationship with all sub-Contractor personnel. The Government maintains these relationships for personnel in possession of a security clearance and those with a NACI T1 background check investigation for the purposes of CAC issuance.

1.6.7.11.1. Facility Security Officer: The resident Facility Security Officer (FSO) shall have at least 2 years industrial security experience, hold a minimum of a secret security clearance, and meet training qualifications in accordance with the Defense Security Service (DSS).

1.6.7.12. Threat Awareness Reporting Program: Per AR 381-12 Threat Awareness and Reporting Program (TARP), Contractor employees shall receive annual TARP training by a CI agent or other trainer as specified in 2-4b of AR 381-12.

1.6.7.13. Antiterrorism Requirements: The Contractor shall comply with Antiterrorism/Force Protection (AT/FP) requirements IAW:

a. AR 525-13, Anti-terrorism

b. WSMR Installation AT Plan,

c. OCONUS Travel Briefs

d. Preparation of the Contractor’s Organizational Consolidated Force Protection, Security, and Evacuation Plans

e. Conduct of the WSMR Random Antiterrorism Measure Program

1.6.7.14. Foreign Interaction and/or Disclosure: The Contractor shall comply with:

a. AR 380-10, Foreign Disclosure and Contacts with Foreign Representatives

b. DOD 5230.11, Disclosure of Classified Military Information to Foreign Governments and International Organizations

c. DOD 5230.20, Visits, Assignments, and Exchanges of Foreign Nationals

d. WSMR Standard Operating Procedures, Foreign National Personnel Visits/Foreign Disclosure

Under no circumstances shall the Contractor disclose data or information gathered in the execution of this contract without express written direction or permission from the Government.

1.6.7.15. Physical Protection of Government Assets: The Contractor shall comply with conventional key and lock requirements under AR 190-51, Security of Unclassified Army Property (Sensitive and Non-sensitive) and WSMR Reg. 190-6 for those facilities, areas, and equipment not governed by AA&E or NISPOM guidance (e.g., office space that does not process or store classified or AA&E material).

1.6.7.16. AA&E Material: When handling, processing, and/or storing AA&E the Contractor shall comply with:

a. AR 190-11, Physical Security of Arms, Ammunition, and Explosives

b. AR 190-13, The Army Physical Security Program

c. DA Pam 190-51, Risk Analysis for Army Property

d. DESR 6055.09 Defense Explosives Safety Regulation

e. DA PAM 385-64 Ammunition and Explosives Safety Standards

1.6.7.17. Requirements for Unclassified//Controlled Unclassified Information (CUI) Handling Instructions. (If not present on a DD Form 254) / Shall comply with CUI

IAW Directives and Categories Located at National Archives https://www.archives.gov/cui/registry/category-list.

1.6.7.18. The Contractor shall follow DOD Federal Acquisition Regulation Supplement (DFARS) clause 252.223-7004, Drug-free Work Force. The Contractor shall conduct drug tests, ensuring all top secret cleared Contractor employees are tested at least once per year, each year of the contract, as well as when there is a reasonable suspicion that an employee uses illegal drugs. The drug testing shall be at the Contractor’s expense. Positive drug test results shall be made available to both the KO and/or COR within 24 hours of known test results. Records of drug testing shall be made available to the COR.

1.6.7.19. CS Training / Certification:

1.6.7.19.1. CS Training (User Level Access):

a. All Contractor personnel with access to Government information systems and networks shall successfully complete all required CS awareness training as specified in AR 25-2 and as specified by the Government requiring activity. Training is available at https://cs.signal.army.mil.

b. Contractor employees and sub-Contractor employees performing work under this contract who have access to Government information systems and networks shall create a user account and profile in the Army Training and Certification Tracking System website (ATCTS) at https://atc.us.army.mil, in the unit container managed by the COR. Certificate of successful completion of CS training (DoD CS Awareness Challenge Training), Acceptable Use Policy (AUP), and DD Form 2875 – System Authorization Access Request (SAAR), shall be uploaded to the ATCTS and provided to the COR for continuous compliance monitoring and reporting.

c. All Contractor employees and associated sub-Contractor employees shall complete the DoD CS awareness training before issuance of network access and annually thereafter. The Contractor shall ensure that all Contractor employees and sub-Contractor employees requiring CS awareness training complete the training prior to the start of work performance on this contract and annually thereafter for the duration of this contract and require employees to maintain their information in a ‘current’ status at the ATCTS website.

d. The Contractor shall ensure that all Contractor employees and sub-Contractor employees performing work under this contract who have access to Government information systems and networks, upon having completed the above referenced requirements for User Level Access, have been issued common access cards (CAC) and / or Secret Internet Protocol Router (SIPR) tokens for user authentication.

Violations of the individual use of the issued and authorized means of authentication will be treated as a security violation and may terminate the contract.

1.6.7.19.2. CS Training / Certification (Technical Level Access):

a. All Contractor personnel with access to Government information systems and networks shall successfully complete all required CS awareness training as specified in AR 25-2, DODD 8140.01, DOD 8570.01m, and as specified by the Government requiring activity. Training is available at https://cs.signal.army.mil.

https://www.archives.gov/cui/registry/category-list

b. Contractor employees and sub-Contractor employees performing work under this contract who have access to Government information systems and networks shall create a user account and profile in the Army Training and Certification Tracking System (ATCTS) website at https://atc.us.army.mil, in the unit container managed by the COR. A certificate of successful completion of CS training (DoD CS Awareness Challenge Training), Acceptable Use Policy (AUP), DD Form 2875 – System Authorization Access Request (SAAR)s, Privileged Access Agreement (PAA), Appointment Orders, applicable baseline and computing environment certifications, and continuing professional education credits, as required by DoDD 8140.01/DoD 8570.01-M , shall be uploaded to the ATCTS and provided to the COR for continuous compliance monitoring and reporting.

c. The Contractor shall ensure that all Contractor employees and sub-Contractor employees requiring CS awareness training complete the training at the start of work performance on this contract and annually thereafter for the duration of this contract and require employees to maintain their information in a ‘current’ status at the ATCTS website.

d. The Contractor shall ensure that all Contractor employees and sub-Contractor employees performing work under this contract who have elevated/privileged access to Government information systems and networks, upon having completed the above referenced requirements for Technical Level Access, have been issued CACs and/or SIPR tokens for user authentication and secondary authentication tokens tied to their technical level permissions. Violations of the use of the issued and authorized means of authentication will be treated as a security violation and may terminate the contract.

e. DFARS clause 252.239-7001 (Information Assurance Contractor Training and Certification) applies to this contract. This contract is subject to the mandates of DoD 8570.01-M, which establishes baseline technical and management CS training and certification requirements for personnel performing CS functions within DoD.

Functions spanning multiple levels require certification of the highest-level functions.

Contractor personnel performing functions in multiple categories or specialties shall hold certifications appropriate to the functions performed in each category or specialty.

f. The Contractor shall ensure its IT (CS) workforce members have the baseline certifications corresponding to their IT (CS) functions, as defined by DODD 8140.01 and Chapters 3, 4, 5, 10, and 11, and Appendix 3 of DoD 8570.01-M at work performance start date. Information Assurance Technical (IAT) and Information Assurance Management (IAM) levels I, II, and III correspond to support provided to the Computing Environment, Network Environment, and Enclave Environments, respectively, and require corresponding levels of compliant baseline certifications.

Contractors will obtain all required Computing Environment (CE) certificates corresponding to the operating systems and/or security-related tools they support prior to being engaged. The IAT Level I baseline certification is the minimum requirement for unsupervised privileged access. The Contractor shall ensure that all employee certifications remain active and are renewed prior to expiration.

g. Reserved.

i. All personnel responsible for implementing the IAVM process will subscribe at https://iavm.csd.disa.mil current notification group to receive vulnerability and patching messages.

j. The interim assignment of Contractor personnel fulfilling IT positions will be restricted and implemented only upon documentation in the Risk Management Framework (RMF) Security Authorization Package (SAP) and acceptance of the Authorizing Official (AO) and the Contracting Officer evaluations on a case‐by‐case basis.

k. Contractor personnel occupying an IT position will be subject to a periodic reinvestigation according to existing contract, labor relations, or personnel security policy.

l. Contractors supporting CS functions will meet the background investigation requirements in accordance with their position sensitivity and criticality designation, as determined by the Government.

m. Contractor personnel supporting CS functions in accordance with DoD 8570.01‐ M shall provide verification to the Defense Eligibility Enrollment System (DEERS). In addition, all Contractor positions supporting CS functions will be assigned a CS workforce Category, Specialty and IT Level code in the contract. These codes shall be identified by the Contractor to Defense Manpower Data Center (DMDC).

Contractor personnel shall also have their CS certification and function level documented in DMDC supported applications. They will also register for an ATCTS account in accordance with current guidelines.

1.6.7.20. Non-Government-owned Computing Systems or Devices: The Contractor shall comply with AR 25-1 and AR 25-2. The Contractor shall not install, connect, non- Government-owned computing systems or devices to Government networks or store, process, transmit, or display Government information on Contractor owned IT without COR approval and adherence with DFARS clause 252.204-7012 (Safeguarding Covered Defense Information and Cyber Incident Reporting) and DoDI 8582.01 (Security of Unclassified DoD Information on Non-DoD Information Systems). The Contractor shall coordinate and obtain proper authorization from the appropriate Command or Local level Information Systems Security Manager (ISSM), ensuring that all software has been properly assessed and approved by the Configuration Control/Management Board and ISSM. The non-Government-owned computing systems or devices include, but are not limited to, personal or Contractor-owned information systems, thumb drives (e.g., memory sticks, flash drives, Universal Serial Bus (USB) drives, jump drives, pen drives), removable or external hard drives, Personal Digital Assistants (PDA), PC Cards / Express Cards, MP3 players, cell phones, digital media, floppy disks, compact disc (CD) / digital video disk (DVD) burners, optical recordings, photo flash cards, laptops, cameras or any devices that can store data.

1.6.7.21. Protection of Sensitive Unclassified Data / Personally Identifiable Information (PII): Protection of Sensitive Unclassified Data / Personally Identifiable Information (PII): The Contractor shall ensure any sensitive information, including, but not limited to, Personally Identifiable Information (PII) and CUI, proprietary, and Law Enforcement (LE) Sensitive information residing on Mobile Computing Devices (MCD) or other external media, is protected in accordance with current Data at Rest (DAR) guidelines and requirements. The Contractor shall use an authorized, approved, and prescribed DAR solution. The MCDs include, but are not limited to, laptop, netbook, notebook, or tablet computers, and Blackberry or equivalent devices. External media include optical disk media such as CDs, DVDs, USB drives (also referred to as flash or thumb drives) (when authorization to use them is restored), floppy disks, and other portable digital storage devices. Guidance for protecting DAR information appears in DoD Policy Memorandum, 3 Jul 07, subject: Encryption of Sensitive Unclassified Data-at-Rest on Mobile Computing Devices and Removable Media and in DoD Component implementing instructions.

1.6.7.22. Appropriate Appearance/Conduct: Contractor personnel shall conform to standards of conduct and code of ethics, which are consistent with those applicable to Government employees as provided in the Joint Ethics Regulation 5500.7.R.

Contractor personnel shall present a neat professional appearance and be easily identified. This shall be accomplished by wearing distinctive clothing bearing the company name or by wearing appropriate badges that contain the company name and employee’s name.

1.6.7.23. Conduct of Personnel: The Contractor and their employees, to include sub- Contractors, shall observe and support all policies, rules and regulations issued by the local installation commander pertaining to safety, fire prevention, sanitation, severe weather, use of tobacco, admission to the installation, and conduct of operations. The Government may require the Contractor to remove any employees from the work site based on misconduct, security violations, use of incapacitating agents, or any other reason determined to be in the Government’s best interest. The installation commander has the authority under 18 U.S.C. § 1382: US Code - Section 1382: Entering military, naval, or Coast Guard Property, to bar individuals from the installation.

1.6.7.24. Reserved

File details come from the government source that posted it. Updated .