Attachment 2 - DD-Form-254-Draft- SETA VI Dec 21.pdf
PDF 433 KB Posted
- Attached to
- Systems Engineering & Technical Assistance (SETA VI) Federal contract opportunity
- Solicitation number
- FA002122R0002
View the file
Other files for this federal contract opportunity
Show all 20
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Please wait...
If this message is not eventually replaced by the proper contents of the document, your PDF viewer may not be able to display this type of document.
You can upgrade to the latest version of Adobe Reader for Windows®, Mac, or Linux® by visiting http://www.adobe.com/go/reader_download.
For more assistance with Adobe Reader visit http://www.adobe.com/go/acrreader.
Windows is either a registered trademark or a trademark of Microsoft Corporation in the United States and/or other countries. Mac is a trademark of Apple Inc., registered in the United States and other countries. Linux is the registered trademark of Linus Torvalds in the U.S. and other countries.
LAST REVIEWED/UPDATED
June 2020
ADDENDUM TO DD FORM 254 (BLOCK 10I)
Alternate Compensatory Control Measures (ACCM)
1. For access to ACCM Program, contractors must be verified to have a “need to know” and a proper security clearance. After proper vetting, contractors may be briefed into Focal Point and will be entered into USSOCOM’s Need-to-Know database (NTKMM). Contractors are permit-ted access to ACCM they are cleared to in the performance of their contract. During out-pro-cessing, the contractor’s assigned unit will coordinate with ACCM Coordinator to schedule de-briefing along with ACCM badge turn-in. The ACCM Coordinator will remove the contractor from the Need-to-Know database (NTKMM) and collect ACCM badge. The assigned unit will then notify the COR of read out from ACCM Program.
2. ACCM requirements and assistance can be found at the following:
1 SOW: https://usaf.dps.mil/sites/AFSOC-1SOAOS/DOC o Contact: 1SOAOS.doxj.vmpfoutpro@us.af.mil or 884-8217
AFSOC: https://eis.afsoc.af.mil/sites/afsoc_sa/focalpoint/default.aspx o Contact: AFSOC.sa.fpco@us.af.mil https://usaf.dps.mil/sites/AFSOC-1SOAOS/DOC mailto:1SOAOS.doxj.vmpfoutpro@us.af.mil https://eis.afsoc.af.mil/sites/afsoc_sa/focalpoint/default.aspx mailto:AFSOC.sa.fpco@us.af.mil
Aug 2021
ADDENDUM TO DD FORM 254 (BLOCK 10j)
Controlled Unclassified Information (CUI) (Reference: DODM 5400.48 DOD CUI Program
1. GENERAL: Controlled Unclassified Information (CUI) requires safeguarding measures identified by the CUI EA in Part 2002.14 of Title 32, CFR and, as necessary, in the law, regula-tion, or government-wide policy with which it is associated. DoD CUI may be disseminated to DoD personnel to conduct official DoD and U.S. Government business in accordance with a law, regulation, or government-wide policy.
a. No individual may have access to CUI information unless it is determined he or she has an authorized, lawful government purpose.
b. The person with authorized possession, knowledge, or control of CUI will determine whether an individual has an authorized, lawful government purpose to access designated CUI.
c. CUI information may be disseminated within the DoD Components and between DoD Component officials and DoD contractors, consultants, and grantees to conduct official business for the DoD, provided dissemination is consistent with controls imposed by a distribu-tion statement or limited dissemination controls (LDC). 2.
2. MARKING: At minimum, CUI markings for unclassified DoD documents will include the acronym “CUI” in the banner and footer of the document. If portion markings are selected, then all document subjects and titles, as well as individual sections, parts, paragraphs, or similar por-tions of a CUI document known to contain CUI, will be portion marked with “(CUI).” Use of the unclassified marking “(U)” as a portion marking for unclassified information within CUI docu-ments or materials is required.
a. There is no requirement to add the “U,” signifying unclassified, to the banner and footer as was required with the old FOUO marking (i.e., U//FOUO).
b. Banners, footers, and portion marking will only be marked “Unclassified” or “(U)” for un-classified information in accordance with the June 4, 2019 ISOO letter. If the document also con-tains CUI, it will be marked in accordance with CUI in the banner and footer of the document.
(1) The first page or cover of any document or material containing CUI, including a docu-ment with commingled classified information, will include a CUI designation indicator. This CUI designation indicator is similar to the classification-marking block used for CNSI docu-ments and materials. Documents and materials containing CUI will require a generic “CUI” marking at the top and bottom of each page.
(2) In accordance with Part 2002 of Title 32, CFR, the CUI designation indicator must con-tain, at minimum, the name of the DoD Component determining that the information is CUI. If letterhead or another standard indicator of origination is used, this line may be omitted.
(3) The second line must identify the office making the determination.
(4) The third line must identify all types of CUI contained in the document.
(5) The fourth line must contain the distribution statement or the dissemination controls ap-plicable to the document.
(6) The fifth line must contain the phone number or office mailbox for the originating DoD Component or authorized CUI holder.
CUI Designation Indicator for All Documents and Material Controlled by: [Name of DoD Component] (Only if not on letterhead) Controlled by: [Name of Office] CUI Category: (List category or categories of CUI) Distribution/Dissemination Control:
POC: [Phone or email address]
c. CUI markings in classified documents will appear in paragraphs or subparagraphs known to contain only CUI and must be portion marked with “(CUI).” “CUI” will not appear in the banner or footer.
d. There will be an acknowledgement statement added to the warning box on the first page of multi-page documents to alert readers to the presence of CUI in a classified DoD document, as shown in Figure 1 of DODM 5200.48. See Volume 2 of DoDM 5200.01 for further marking re-quirements.
4. DISSEMINATION: In accordance with this issuance, CUI access should be encouraged and permitted to the extent the access or dissemination:
a. Complies with the law, regulation, or government-wide policy identifying the information as CUI.
b. Furthers a lawful government purpose.
c. Is not restricted by an authorized Limited Dissemination Controls (LDC) established by the
CUI EA.
d. Is not otherwise prohibited by any other law, regulation, or government-wide policy.
e. Agencies may place limits on disseminating CUI for a lawful government purpose only us-ing the dissemination controls listed in Table 2 of DODM 5200.48 or methods authorized by a specific law, regulation, or government-wide policy.
5. TRANSMISSION: CUI information and material may be transmitted via first class mail, parcel post, or, bulk shipments. When practical, CUI information may be transmitted electroni-cally (e.g., data, website, or e-mail), via approved secure communications systems or systems utilizing other protective measures such as Public Key Infrastructure or transport layer security (e.g., https). Avoid wireless telephone transmission of CUI when other options are available.
CUI transmission via facsimile machine is permitted; however, the sender is responsible for
6. STORAGE: During working hours, steps will be taken to minimize the risk of access by un-authorized personnel, such as not reading, discussing, or leaving CUI information unattended where unauthorized personnel are present. After working hours, CUI information will be stored in unlocked containers, desks, or cabinets if the government or government-contract building provides security for continuous monitoring of access. If building security is not provided, the information will be stored in locked desks, file cabinets, bookcases, locked rooms, or similarly secured areas. The concept of a controlled environment means there is sufficient internal security measures in place to prevent or detect unauthorized access to CUI. For DoD, an open storage en-vironment meets these requirements.
7. DESTRUCTION: Guidance for destroying CUI documents and materials is provided in the CUI Registry, and ISOO Notice 2019-03.
a. Record and non-record copies of CUI documents will be disposed of in accordance with Chapter 33 of Title 44, U.S.C. and the DoD Components’ records management directives. When destroying CUI, including in electronic form, agencies must do so in a manner making it unread-able, indecipherable, and irrecoverable. If the law, regulation, or government-wide policy speci-fies a method of destruction, agencies must use the method prescribed.
b. Record and non-record CUI documents may be destroyed by means approved for destroying classified information or by any other means making it unreadable, indecipherable, and unrecov-erable the original information such as those identified in NIST SP 800-88 and in accordance with Section 2002.14 of Title 32, CFR.
8. Direct questions concerning CUI to the 1 SOW/IPI Office at 884-4322.
ADDENDUM TO DD FORM 254 (BLOCK 10k)
AUTOMATED INFORMATION SYSTEMS
1. This section outlines the requirements, procedures and Air Force publications that must be ad-hered to by contractors as a condition of use of Hurlburt Field Automated Information Systems (AIS) and Local Area Networks (LAN).
2. Cybersecurity practices are the actions that protect information and information systems by ensuring their continued availability, integrity, confidentiality, and non-repudiation. This in-cludes providing for restoration of information systems by incorporating disaster recovery capa-bilities to ensure continuity of operations under all conditions.
3. Key publications governing the use and security of AF AIS are listed below. Many include additional publications by reference, which are equally applicable.
• AFSSI 7700, Emission Security
• AFI 33-200, Air Force Cybersecurity Program Management
• AFI 33-210, Air Force Certification and Accreditation (C&A) Program (AFCAP)
• AFMAN 33- 152, User Responsibilities and Guidance for Information Systems
• AFI 10-712, Cyberspace Defense Analysis (CDA) Operations and Notice and Consent
Process
4. All personnel are required to safeguard information and information systems against unau-thorized access, modification, destruction or disclosure.
5. Per the Hurlburt Field NIPRnet System Security Authorization Agreement (SSAA), contrac-tor owned hardware and software will not be connected to Hurlburt Field unclassified or classi-fied LAN.
6. Non-Air Force wireless network devices are forbidden on Hurlburt Field.
7. All portable electronic devices (PED) are prohibited from use or possession within Hurlburt Field buildings where classified information is processed, stored or discussed.
8. All information systems, software, and/or enclaves operating on Hurlburt Field must be certi-fied and accredited through the DoD Information Assurance Certification and Accreditation Pro-gram (DIACAP) prior to being implemented or connected to a network.
9. The 1 SOW Cybersecurity Office is the source for cybersecurity related information.
• Email: 1sow.cybersecurity@us.af.mil
• Contact: 1 SOCS/SCXS at (850) 884-6605 mailto:1sow.ia@hurlburt.af.mil
ADDENDUM TO DD FORM 254 (BLOCK 11j)
OPERATIONS SECURITY
1. This section outlines the requirements and procedures necessary for contractors to provide Operations Security (OPSEC) protection for AFSOC’s Critical Information (CI).
2. OPSEC is the process of analyzing friendly actions attendant to military operations and other activities to:
• Identify those actions that can be observed by adversary intelligence systems.
• Determine which actions are indicators to hostile intelligence systems.
• Identify the information that adversaries can obtain and interpret or piece together to derive relevant critical information.
• Develop, select, and execute countermeasures that eliminate or reduce vulnerabilities to an acceptable level.
3. OPSEC principles are used to help assigned personnel:
• Maintain a continuing awareness of adversary interest in SOF actions and adversary intelligence collection capabilities.
• Understand the need to identify and protect unclassified indicators that reveal sensitive information.
• Evaluate the effectiveness of OPSEC measures taken to preclude or reduce adversary acquisition and exploitation of sensitive information.
4. Our objectives are:
• Protect planned operational activities by preventing the inadvertent disclosure of unclassified information relating to or revealing a possible classified operation.
• To preserve secrecy concerning specific scenario events and a USSOCOM or AFSOC response to these events.
• To identify OPSEC vulnerabilities and recommend protective measures which will serve to enhance the security of future operations.
5. AFSOC employed contractors will be briefed on unit Critical Information and Indicators and how to apply OPSEC principles by assigned unit OPSEC program manager/coordinator within 30 days of assignment. Individual training will be developed and applied as required by the level of contact with AFSOC critical information.
6. Unit OPSEC requirements, Critical Information and Indicators Lists (CIILs) and assistance can be found by contacting the unit-specific OPSEC coordinator.
7. OPSEC requirements and assistance can be found at the following:
• AFI 10-701, Operations Security (OPSEC)
• Email: 1sow.io@us.af.mil
• Contact: 1 SOW/IO at 884-4565
DRAFT
SAMPLE
PREVIOUS EDITION IS OBSOLETE.
Page of AEM LiveCycle Designer
DD FORM 254, APR 2018
NEEDS DD67
DEPARTMENT OF DEFENSE
CONTRACT SECURITY CLASSIFICATION SPECIFICATION
(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)
OMB No. 0704-0567 OMB approval expires:
October 31, 2020 The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.
RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.
1. CLEARANCE AND SAFEGUARDING
2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)
3. THIS SPECIFICATION IS: (X and complete as applicable.)
a. ORIGINAL (Complete date in all cases.)
b. REVISED (Supersedes all previous specifications.)
4. IS THIS A FOLLOW-ON CONTRACT?
If yes, complete the following:
Classified material received or generated under
5. IS THIS A FINAL DD FORM 254?
If yes, complete the following:
6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)
7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor)
8. ACTUAL PERFORMANCE (Click button to add more locations.)
10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)
e. NATIONAL INTELLIGENCE INFORMATION:
11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)
12. PUBLIC RELEASE
Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)
13. SECURITY GUIDANCE
The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.
(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)
14. ADDITIONAL SECURITY REQUIREMENTS
Requirements, in addition to NISPOM requirements for classified information, are established for this contract.
If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)
15. INSPECTIONS
Elements of this contract are outside the inspection responsibility of the CSO.
If Yes, explain and identify specific areas and government activity responsible for inspections. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)
16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)
17. CERTIFICATION AND SIGNATURES
Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below. Upon digitally signing Item 17h, no changes can be made as the form will be locked.
18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL
9.0.0.2.20120627.2.874785 DD 254, DoD Contract Security Classification Specification List of Attachments (All Files Must be Attached Prior to Signing, i.e., for any digital signature on the form)
| CurrentPage: |
| PageCount: |
| Classification: Unclassified |
| SerialNum: |
| a. Facility clearance level. Select one.: 1 |
| b. Level of safeguarding for classified information/material required at contractor facility. Select one.: 4 |
| Choose Yes or No: 0 |
| Choose Yes or No: 1 |
| Prime: |
| Choose Yes or No: 0 |
| Choose Yes or No: 0 |
| Sub: |
| Choose Yes or No: 1 |
| Choose Yes or No: 0 |
| Soli: FA002122R0002 |
| DueDate: 2022-04-07 |
| dateA: 2021-12-13 |
| RevisionNum: |
| dateB: |
| Final: |
| dateC: |
| No: 1 |
| No: 1 |
| No: 1 |
| No: 1 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Enter your name here.: |
| ReqDated: |
| Enter your name here.: |
| Name: Edwards, Shawn D. |
| Cage: N/A |
| Cage: N/A |
| Cage: N/A |
| Cage: N/A |
| Cage: N/A |
| CSO: 1 SOW/IP |
212 Lukasik, Room 230, Hurlburt Field, FL. 32544 850-884-5143 1SOW.IPC.IndustrialSecurity@us.af.mil
CSO: 1 SOW/IP
212 Lukasik, Room 230, Hurlburt Field, FL. 32544 850-884-5143 1SOW.IPC.IndustrialSecurity@us.af.mil
CSO: 27 SOW/IP
102 North Chindit Blvd, Bldg 155 Cannon AFB, NM. 88103 575-784-2129 27SOW.IP@us.af.mil
CSO: 100 ARW/IP
Unit 4930, Box 420
APO, AE 09459
DSN: 314-238-3105
CSO:
18 WG/IP
Unit 5212
APO, AP 96368-5212
DSN: 315-634-1273
| addrow: |
| Removerow: |
| Click to delete a row: |
| Location: 1 SOW |
315 Lukasik Avenue Hurlburt Field, FL. 32544
Location: 492 SOW 229 Cody Avenue Hurlburt Field, FL. 32544 Location: 27 SOW 100 South Air Commando Way, Bldg 1 Cannon AFB, NM. 88103 Location: 352 SOW Unit 8805 Box 240, APO AE 09459 RAF Mildenhall, UK Location: 353 SOW 25 E Street, STE D-100, APO AP 96368 Kadena AB, Japan Block9: SETA VI Contract Support at various AFSOC locations. Specific security requirements will be made known at the task order level. The basic contract-level DD254 is provided for information only for the purpose of offerers under referenced solicitation.
| a: 0 |
| a: 1 |
| a: 1 |
| f: 0 |
| f: 1 |
| f: 1 |
| b: 0 |
| b: 0 |
| b: 0 |
| g: 1 |
| g: 1 |
| c: 0 |
| c: 0 |
| c: 1 |
| h: 0 |
| h: 0 |
| d: 0 |
| d: 0 |
| d: 0 |
| i: 1 |
| i: 0 |
| SCI: 0 |
| NonSCI: 0 |
| j: 1 |
| j: 1 |
| k: 1 |
| k: 0 |
| Enter your name here.: NIPRNET and SIPRNET |
| Enter your name here.: 1 SOW/IPC (Industrial Security Office) |
27 SOW/IP
100 ARW/IP
18 WG/IP
| e: 0 |
| e: 1 |
| l: 0 |
| m: 0 |
| direct: 0 |
| thru: 1 |
| Enter your name here.: See block 13 |
| PublicAuthority: See block 13 |
| AddSig: |
| RemoveSig: |
| text: 1. Supported USAF organizations will provide security classification guides and other classification guidance to the contractor as required for contract performance. Contractors will comply with all Hurlburt Field, supported unit and special program requirements. Supported units will provide security requirements and instructions, and will include contractors in the unit Information Security program. |
2. Classified markings on all working, draft, and final copies of deliverable material shall be in accordance with DODM 5200.01, Vol 2, and applicable instructions contained in the respective security classification guides.
3. All classified material provided will be safeguarded at all times and returned by the contractor at contract completion.
4. Use only AF certified AIS for performance on base and will comply with all AF AIS procedures.
Ref Item 10k: Secret Internet Protocol Network (SIPRNET) access authorization. The contractor shall not access, download, or further disseminate any information or data that falls outside the scope of execution of the defined contract requirements. In the event any additional access is required, the Program Manager, Contracting Officer Representative, or Security Manager must request modification/revision of the DD Form 254 and/or Statement of Work to the issuing Contracting Officer. Contractor shall prepare and submit all required documentation as required by command policy prior to receiving access.
Ref Item 12: Contractor is to submit requests through the Contracting Officer for OPSEC Program Manager review and public release authorization. The Contracting Officer will provide contractor with written approval/disapproval. Information requiring AF or DoD–level review will be reviewed by the unit’s OPSEC Program Manager or Coordinator who will in-turn forward to the entry-level public affairs office through the AFIMSC Public Affairs Office to the Secretary of the Air Force, Office of Public Affairs, Security and Review Division (SAF/PAX), 1690 Air Force Pentagon, Washington DC 20330-1690.
text: AFSOC/A3TS 850-884-5773 AFSOC.A3TS.DL@us.af.mil text: 1 SOW/IPC 850-884-5143 1SOW.IPC.IndustrialSecurity@us.af.mil
| attachmentsList: |
| AddAttachment: |
| ViewAttachment: |
| RemoveAttachment: |
| rep: JAMES R. MCNULTY, GS-13 |
Program Manager rep: PARRISH HOLLINGSWORTH, GS-11 Chief, Industrial Security
| Sig: |
| Enter your name here.: |
| GCAName: 765 ESF |
| AAC: FA0021 |
| AAC: FA0021 |
| Address: 427 Cody Ave, Bldg 90333 |
Hurlburt Field Fl 32544 Address: 427 Cody Ave, Bldg 90333 Hurlburt Field, FL 32544
| POCName: SHAWN EDWARDS |
| Phone: 8508847829 |
| Phone: 8508847829 |
| Email: shawn.edwards.14@us.af.mil |
| Email: shawn.edwards.14@us.af.mil |
| Title: Contracting Officer |
| Enter the date using the format DD-Mon-YYYY: 20211220 |
File details come from the government source that posted it. Updated .