Attachment 2 - DD254.pdf
PDF 159 KB Posted
- Attached to
- Orbital Services Program-4 (OSP-4) On Ramp #1 Request for Proposal (RFP) Federal contract opportunity
- Solicitation number
- FA8818-21-R-0003
About this file
This is a Request for Proposal (RFP) for the Orbital Services Program-4 (OSP-4) On-Ramp #1 multiple award Indefinite Delivery/Indefinite Quantity (IDIQ) contract issued by the Space and Missile Systems Center's (SMC) Launch Enterprise, Small Launch and Targets Division, Rocket Systems Launch Program (RSLP). The RFP seeks to expand the current vendor pool to provide flexible small launch capability for payloads ranging between 400 pounds to low Earth orbit (LEO) and approximately 8,000 pounds to geostationary transfer orbit (GTO). The Space Force is the contracting agency. The North American Industry Classification System code is 481212 and the small business size standard is 1,500 employees, though responses from small and small disadvantaged businesses are encouraged. The deadline to submit inquiries is January 29, 2021. All offerors awarded a basic contract will receive a Launch Service User Guide Study Task Order. Foreign firms are not eligible to participate as prime contractors.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| OSP-4OnRamp1CRM_updated 24 Feb.pdf | ||
| OSP-4OnRamp1CRM.pdf | ||
| OSP-4 E CDRL - On-Ramp.pdf | ||
| Attachment 3 - Instructions to Offerors.pdf | ||
| Minimum Award - LSUG Task Order 0001.pdf | ||
| OSP-4 A CDRL - On-Ramp.pdf | ||
| OSP-4 C CDRL - On-Ramp.pdf | ||
| OSP-4 D CDRL - On-Ramp.pdf | ||
| Attachment 5 - Ordering Guide with Appendices - Rev 1.pdf | ||
| OSP-4 Model Contract.pdf | ||
| OSP-4 B CDRL - On-Ramp.pdf | ||
| Attachment 4 - Evaluation Criteria.pdf | ||
| OSP-4 On Ramp Table of Contents.pdf | ||
| OSP-4 F CDRL - On-Ramp.pdf | ||
| Attachment 1 - Performance Work Statement (PWS) - Rev1.pdf |
Show all 15
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Please wait...
If this message is not eventually replaced by the proper contents of the document, your PDF viewer may not be able to display this type of document.
You can upgrade to the latest version of Adobe Reader for Windows®, Mac, or Linux® by visiting http://www.adobe.com/go/reader_download.
For more assistance with Adobe Reader visit http://www.adobe.com/go/acrreader.
Windows is either a registered trademark or a trademark of Microsoft Corporation in the United States and/or other countries. Mac is a trademark of Apple Inc., registered in the United States and other countries. Linux is the registered trademark of Linus Torvalds in the U.S. and other countries.
Local Office Location: Department of Defense Cognizant Security Office
SMC/ECLX 377 ABW/IPD
3548 Aberdeen Ave SE 4500 Biggs Ave SE Kirtland AFB, NM 87117 Kirtland AFB, NM 87117
FOR OFFICIAL USE ONLY (FOUO) ADDENDUM,
DoD CONTROLLED UNCLASSIFIED INFORMATION ADDENDUM
Ref DD Form 254 block/item 10j. In addition to classified information, certain types of unclassified information also require application of access and distribution controls and protective measures for a variety of reasons. Such information is referred to collectively as Controlled Unclassified Information (CUI). DoD CUI includes For Official Use Only (FOUO), Law Enforcement Sensitive (LES), DoD Unclassified Controlled Nuclear Information (DoD UCNI), and LIMITED DISTRIBUTION, as well as some of those developed by other Executive Branch agencies. Contractors shall comply with related CUI applicable provisions identified in DoDI 5200.48, dated March 6, 2020.
ALL DoD unclassified information MUST BE REVIEWED AND APPROVED FOR RELEASE through standard DoD Component processes before it is provided to the public. The contractor will notify the Government Contracting Officer of unauthorized disclosures of DoD CUI. The originator of a document is responsible for determining at origination whether the information may qualify for CUI status, and if so, for applying the appropriate CUI markings.
FOR OFFICIAL USE ONLY (FOUO)
FOUO is a dissemination control applied by the Department of Defense to unclassified information when disclosure to the public of that particular record, or portion thereof, would reasonably be expected to cause a foreseeable harm to an interest protected by one or more of FOIA Exemptions 2 through 9. The document’s originator will determine at origination whether the information may qualify for FOUO status and to ensure markings are applied as required.
Contractors will comply with DoDI 5200.48, dated March 6, 2020. In regards to DoD CUI and related FOUO. The following are select areas of emphasis:
1. ACCESS/DESIGNATION: Access to FOUO material shall be limited to those employees needing the material to do their jobs. No person may have access to information designated as FOUO unless that person has been determined to have a valid need for such access in connection with the accomplishment of a lawful and authorized Government purpose. FOUO is not a classification. When a classified document or portion thereof is declassified, FOUO markings may be applied, if applicable, to protect the information. Marking information FOUO does not automatically qualify it for exemption from public release pursuant to the FOIA. If a request for a record is received, the information shall be reviewed to determine if it truly qualifies for exemption.
2. MARKING: Mark FOUO documents in accordance with DoDI 5200.48, dated March 6, 2020, unless directed by the AF Activity to use approved variations. For example, for any e-mail containing FOUO, ensure the subject line alerts a reader the information includes FOUO (Subject Line Example: (FOUO) SUBJECT XYZ). Also, include the following warning Statement at the top of each email containing FOUO: This e-mail contains FOR OFFICIAL USE ONLY (FOUO) information which must be protected under the Freedom of Information Act (5 U.S.C 552) and/or the Privacy Act of 1974 (5 U.S.C. 552a). Unauthorized disclosure or misuse of this PERSONAL INFORMATION may result in disciplinary action, criminal and/or civil penalties. Further distribution is prohibited without the approval of the author of this message unless the recipient has a need to know in the performance of official duties. If you have received this message in error, please notify the sender and delete all copies of this message.
3. STORAGE: During working hours, reasonable steps shall be taken to minimize the risk of access by unauthorized personnel (e.g., not reading, discussing, or leaving FOUO information unattended where unauthorized personnel are present). After working hours, FOUO information may be stored in unlocked containers, desks, or cabinets if Government or Government-contract building security is provided. If such building security is not provided or is deemed inadequate, the information shall be stored in locked desks, file cabinets, bookcases, locked rooms, etc.
Expenditure of funds for security container or close areas solely for the protection of FOUO material is prohibited unless specifically authorized by the Government Contracting Officer.
4. TRANSMISSION: FOUO information and material may be transmitted via first class mail, parcel post, or, for bulk shipments, via fourth class mail. Whenever practical, electronic transmission of FOUO information (e.g., data, website, or e-mail) shall be by approved secure communications systems or systems utilizing other protective measures such as Public Key Infrastructure (PKI) or transport layer security (e.g., https). Use of wireless telephones should be avoided when other options are available. Transmission of FOUO by facsimile machine (fax) is permitted;
the sender is responsible for determining that appropriate protection will be available at the receiving location prior to transmission (e.g., machine attended by a person authorized to receive FOUO; fax located in a controlled government environment).
5. RELEASE: FOUO material shall not be released outside the contractor's facility except to representatives of the
DOD.
6. DESTRUCTION: When no longer needed, FOUO material shall be disposed of by a method that precludes its disclosure to unauthorized individuals.
Report of Loss of Personal Identifiable Information
Reporting of incidents is required when there is a loss, theft or compromise of PII (i.e. breach). All breaches shall be reported to the government Program Manager and the installation Privacy Act Officer immediately. Breaches subject to reporting and notification include electronic systems and paper documents.
Contractors shall:
• Take such actions, as considered appropriate, to ensure that any government personal information contained in a system of records, of which they have access to and are using to conduct official business, shall be protected so that the security and confidentiality of the information shall be preserved.
• Not disclose any government personal information contained in any system of records, except as authorized by applicable laws or regulations. Contractors willfully making such disclosure when knowing that disclosure is prohibited are subject to possible criminal penalties and/or administrative sanctions.
• Report any unauthorized disclosures of government personal information from a system of records or the maintenance of any system of records that are not authorized to the installation Privacy Act Officer.
• Initial written reports shall be made as expeditiously as possible in all cases within 72 hours of discovery. Additional information may be required after submission and review of the initial report, guidance will be provided at that time.
Mark any reports For Official Use Only, identifying exemptions 6 and 7 apply. Initial report content shall include the following information:
• Identify the organization involved.
• Specify the date of the breach and the number of individuals impacted, to include whether they are DoD civilian, military or contractor personnel; DoD civilian or military retirees; family members; other Federal personnel or members of the public, etc.
• Describe the facts and circumstances surrounding the loss, theft, or compromise.
• Describe actions taken in response to the breach, to include whether the incident was investigated and by whom;
the preliminary results of the inquiry if then known; actions taken to mitigate any harm that could result from the breach; whether the affected individuals are being notifies, and if this will not be accomplished within 10 working days; what remedial actions have been, or will be, taken to prevent a similar such incident in the future, e.g., refresher training conducted, new or revised guidance issued; and any other information considered pertinent as to actions to be taken to ensure that information is properly safeguarded.
DRAFT
SAMPLE
PREVIOUS EDITION IS OBSOLETE.
Page of
DD FORM 254, MAY 2019
NEEDS DD67
DEPARTMENT OF DEFENSE
CONTRACT SECURITY CLASSIFICATION SPECIFICATION
(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)
OMB No. 0704-0567 OMB approval expires:
20220531 The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.
RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.
1. CLEARANCE AND SAFEGUARDING
2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)
3. THIS SPECIFICATION IS: (X and complete as applicable.)
a. ORIGINAL (Complete date in all cases.)
b. REVISED (Supersedes all previous specifications.)
4. IS THIS A FOLLOW-ON CONTRACT?
If yes, complete the following:
Classified material received or generated under
5. IS THIS A FINAL DD FORM 254?
If yes, complete the following:
6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)
7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor)
8. ACTUAL PERFORMANCE (Click button to add more locations.)
10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)
e. NATIONAL INTELLIGENCE INFORMATION:
11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)
12. PUBLIC RELEASE
Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)
13. SECURITY GUIDANCE
The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.
(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)
14. ADDITIONAL SECURITY REQUIREMENTS
Requirements, in addition to NISPOM requirements for classified information, are established for this contract.
If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)
15. INSPECTIONS
Elements of this contract are outside the inspection responsibility of the CSO.
If Yes, explain and identify specific areas and government activity responsible for inspections. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)
16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)
17. CERTIFICATION AND SIGNATURES
Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below. Upon digitally signing Item 17h, no changes can be made as the form will be locked.
18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL
9.0.0.2.20120627.2.874785 DD 254, DoD Contract Security Classification Specification whs.mc-alex.esd.mbx.formswebmaster@mail.mil
WHS
List of Attachments [1] (All Files Must be Attached Prior to Signing, i.e., for any digital signature on the form) FOUO & CUI Addendum.pdf
| CurrentPage: |
| PageCount: |
| Classification: Unclassified |
| SerialNum: CUI |
| a. Facility clearance level. Select one.: 2 |
| b. Level of safeguarding for classified information/material required at contractor facility. Select one.: 2 |
| Choose Yes or No: 0 |
| Choose Yes or No: 0 |
| Prime: |
| Choose Yes or No: 0 |
| Choose Yes or No: 0 |
| Sub: |
| Choose Yes or No: 1 |
| Choose Yes or No: 0 |
| Soli: FA8818-21-R-0003 |
| DueDate: 2021-01-29 |
| dateA: |
| RevisionNum: |
| dateB: |
| Final: |
| dateC: |
| No: 1 |
| No: 1 |
| No: 0 |
| No: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 1 |
| Yes: 1 |
| Enter your name here.: |
| ReqDated: |
| Enter your name here.: |
| Name: LUCIA CORRAL |
| Cage: |
| CSO: |
| addrow: |
| Removerow: |
| Click to delete a row: |
| Location: |
| Block9: Orbital Services Program-4 (OSP-4) provides flexible small launch capability using Spacelift System (SS) designs based on commercial and/or Government Furnished Property (GFP) motors to meet the customer requirements. The contract supports payloads ranging between 400 lb to low earth orbit (LEO) to approx. 8,000 lb to geostationary transfer orbit (GTO). A key cornerstone of OSP-4's strategy is to utilize a low barrier to entry to establish a large vendor pool consisting of both large and small businesses. Each mission task order will be competitively competed and tailored to customer requirements. |
| a: 1 |
| a: 0 |
| a: 1 |
| f: 0 |
| f: 0 |
| f: 1 |
| b: 1 |
| b: 0 |
| b: 0 |
| g: 0 |
| g: 1 |
| c: 0 |
| c: 1 |
| c: 1 |
| h: 1 |
| h: 1 |
| d: 1 |
| d: 1 |
| d: 0 |
| i: 0 |
| i: 0 |
| SCI: 0 |
| NonSCI: 0 |
| j: 1 |
| j: 1 |
| k: 0 |
| k: 0 |
| Enter your name here.: SMC/ECL Security, SMC/INX, SMC/ECLX |
| e: 0 |
| e: 1 |
| l: 1 |
| m: 0 |
| direct: 0 |
| thru: 1 |
| Enter your name here.: SMC/EC (ATTN: Security), smc.ecl.security@us.af.mil |
483 N. AVIATION BLVD, EL SEGUNDO, CA 90245
PublicAuthority: SMC/PA, smcpa.media@us.af.mil, 310-652-1131
483 N. AVIATION BLVD, EL SEGUNDO, CA 90245
| AddSig: |
| RemoveSig: |
| text: The Orbital Services Program-4 (OSP-4) contract vehicle was awarded on 10 October 2019. The contract has a nine-year ordering period which extends from 10 October 2019 to 9 October 2028. Mission Task Orders' period of performance may extend two years beyond the ordering period. |
Program Protection Plans (PPP) and Security Classification Guides (SCG): The contractors shall protect critical program information (CPI) and critical components (CC) in compliance with the Program Protection Plan (PPP). Program Security Classification Guides (SCGs) will be provided by the Government program office. Classified national security information, and unclassified controlled information (CUI) shall be protected as outlined in the SCG, NISPOM and/or DODM 5200.01 V1-4.
Research and developmental contractors shall develop a Program Protection Implementation Plan (PPIP) to be approved by the program office. The PPIP shall describe the protection measures being implemented by the contractor and sub-contractors for CPI and CC. The prime contractor shall flow-down to any subcontractor protection requirements for implementation as described in the PPIP in compliance with PPP. The government program office shall conduct Program Protection Surveys at contractor locations to assess the effectiveness of the established PPIP.
Information requiring AF or DoD–level review will be forwarded by the entry-level public affairs office through the MAJCOM/DRU Public Affairs Office to the Secretary of the Air Force, Office of Public Affairs, Security and Review Division (SAF/PAX), 1690 Air Force Pentagon, Washington DC 20330-1690.
Ref 10a: Classified COMSEC material is not releasable to contractor employees who have not received a FINAL clearance at the appropriate security level. COMSEC access shall be IAW DoD 5220.22-M. Written concurrence of the GCA is required prior to subcontracting. : Prior approval from the Contracting Officer is required in order for a Prime Contractor to grant COMSEC access to a subcontractor. The Prime Contractor shall also notify the National Security Agency (NSA) Central Office of Record (COR) before negotiating or awarding subcontracts.
(For Visitor Groups) Contractor will require access to COMSEC information at the on-base locations listed in item 8a. On-base contractors will not require their own COMSEC account. Access will be controlled by 61st AirBase Group (ABG) or host installation. On-base contractors will protect COMSEC material IAW directives identified by the installation COMSEC Custodian to include Air Force Manual 17-1302-0, Communications Security (COMSEC) Operations. Access to COMSEC material by personnel is restricted to U.S. citizens holding final U.S. Government clearances.
Ref 10b: Restricted Data Information is not releasable to contractor employees who have not received a FINAL clearance at the appropriate security level. Written concurrence of the GCA is required prior to subcontracting. : Protection requirements for RD/FRD/CNWDI are contained in DoDM 5200.01, Volume 1, DoD Information Security Program, which states that: Classified information, including Critical Nuclear Weapon Design Information, in the custody of the Department of Defense marked as RD and FRD in accordance with the Atomic Energy Act of 1954, as amended, shall be stored, protected, and destroyed in the same manner as information of a comparable level of security classification Contractor IT systems and networks must be certified and accredited for RD, FRD, and/or CNWDI prior to transmission, processing, or storage of such data. RD and FRD must be marked IAW instructions in the NISPOM.
Ref 10d: The contractor is permitted access to Formerly Restricted Data (FRD) in the performance of this contract. Access to FRD requires a final U.S. Government clearance at the appropriate level. Written concurrence of the GCA is required prior to subcontracting. : Protection requirements for RD/FRD/CNWDI are contained in DoDM 5200.01, Volume 1, DoD Information Security Program, which states that: Classified information, including Critical Nuclear Weapon Design Information, in the custody of the Department of Defense marked as RD and FRD in accordance with the Atomic Energy Act of 1954, as amended, shall be stored, protected, and destroyed in the same manner as information of a comparable level of security classification Contractor IT systems and networks must be certified and accredited for RD, FRD, and/or CNWDI prior to transmission, processing, or storage of such data. RD and FRD must be marked IAW instructions in the NISPOM.
Ref 10h: Foreign Government Information (FGI) is not releasable to contractor employees who have not received a FINAL clearance at the appropriate security level. Written concurrence of the GCA is required prior to subcontracting. : The Program Manager will validate contractor requests for FGI on a case-by-case basis. Access to FGI requires a final government clearance at the appropriate level. Information supplied by or provided to a foreign government(s) shall be handled in accordance with the NISPOM, Chapter 10, Section 3 and DoDM 5200-01-V1-V4.
Ref 10j. Controlled Unclassified Information - For Official Use Only (FOUO) Information generated and/or provided under this contract shall be safeguarded and marked as specified in DoD Instruction 5200.48. Controlled Unclassified Information (CUI) is the term which includes For Official Use Only. CUI provided under this contract shall be managed and safeguarded IAW DoD Instruction 5200.48, Controlled Unclassified Information, available at http://www.esd.whs.mil/DD/DoD-Issuances/.
Ref 11c: The contractor requires access to classified information. Any extracts must apply derivative classifications and markings consistent with the source documents. Use of "Multiple Sources" on the "Derived From" line necessitates compliance with the NISPOM, paragraph 4-208b. : Classified material will be handled in accordance with DoDM 5200.01-V1-V3, and the NISPOM.
Ref 11d: Contractor must provide adequate storage at their facility for classified hardware to the level of required safeguarding (See Block 1b above). : The contractor may access information provided by DTIC by complying with all established safeguards and following the registration procedures as set forth in Chapter 11 Section 2 of the NISPOM.
Ref 11g : The contractor may access information provided by DTIC by complying with all established safeguards and following the registration procedures as set forth in Chapter 11 Section 2 of the NISPOM.
Ref 11h: A COMSEC account must be established when accountable COMSEC material is to be provided, acquired, or produced under a contract. The GCA will inform the contractor that a COMSEC account is required.
(On-base contractors) The contractor will be required to establish and maintain a COMSEC user account following the procedures and requirements contained in Committee on National Security Systems (CNSS) Policy No. 3, National Policy for Granting Access to U.S. Classified Cryptographic Information and AFMAN 17-1302-0, Communications Security (COMSEC) Operations, the NISPOM, and installation COMSEC account procedures.
(Off-base contractors) NSA account will be established for and maintained by contractor IAW Committee on National Security Systems (CNSS) Policy No. 3, National Policy for Granting Access to U.S. Classified Cryptographic Information. The Contractor will comply with the additional security requirements and the management of NSA information/ material as defined in the manual.
Ref 11j : The contractor shall accomplish the following minimum requirements in support of the government Operations Security (OPSEC) Program:
a. The contractor shall comply with the User Agency OPSEC Plan, and apply protective measures therein. Research and Development contractors (off-base) shall develop an OPSEC Plan in accordance with DoDM 5205.2 and include OPSEC as a part of their ongoing security awareness program.
b. The contractor shall protect all unclassified information and activities, which could compromise classified information or operations, or degrade the planning and execution of military operations performed by the contractor in support of the mission. Contractor shall protect controlled unclassified information (CUI) and information identified in the SMC and SMC program office critical information list (CIL)
c. Disposition of Critical Information and CUI obtained or produced pursuant to this contract shall be shredded/degaussed to prevent reconstruction.
Ref 11l. Receive, Store, or Generate Controlled Unclassified Information (CUI) - Protection of Unclassified DoD Information on Non-Government Information Systems: The Contractor must comply with the information safeguards as specified in DoDI 8582.01, Security of Unclassified DOD Information on Non-DOD Information Systems, CNSSP No. 18, National Policy on Classified Information Spillage, Chairman of The Joint Chiefs of Staff Instruction (CJCSI) 6510.01, Information Assurance and Support to Computer Network Defense (CND), and AF Manual 17-1301, Computer Security.
The Contractor shall comply with DFAR Clauses related to the Disclosure of Information (DFAR 252.204-7000), Safeguarding Covered Defense Information and Cyber Incident Report (DFARS 252.204-7012 and DFAR Subpart 204.73) for the protection of unclassified controlled technical information. In line with this clause, NIST SP 800-171 provides guidance for the protection of Controlled Unclassified Information (CUI) on non-federal information systems. Contractor shall apply security controls contained in NIST SP 800-171 for the protection of CUI on non-DoD information systems. CUI information will not be placed on publicly accessible web sites.
Definitions:
Adequate Security - Security commensurate with the risk and the magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of information (see 0MB Circular A-130). Current means of achieving adequate security for Information Technology is to use DoD, CNSS and NIST guidance (see CNSSI No. 4009).
Non-Sensitive Information - Information available in the public domain or DoD information that has been approved for public release.
Sensitive Information - Information, the loss, misuse, or unauthorized access to or modification of, could adversely affect the national interest or the conduct of Federal programs, or the privacy to which individuals are entitled under Section 552a of title 5, United States Code, "The Privacy Act" but which has not been specifically authorized under criteria established by Executive order or an Act of Congress to be kept secret in the interest of national defense or foreign policy.
The terms Cybersecurity, Information Systems, and Information Technology, as used in this clause, are defined in Committee on National Security Systems Instruction 4009. Cybersecurity is further defined in DODI 8500.01 and is incorporated herein by reference:
Information systems (IS) shall be engineered and managed to protect and defend information and information systems from cybersecurity risks, including the risks to confidentiality, integrity, non- repudiation, and authorization in accordance with current DoD policies, procedures, and statutes, to include: National Security Act, Clinger-Cohen Act, Committee on National Security Systems Policy No. 11, National Institute on Standards and Technology Special Publications Federal Information Processing Standards, DoD Instruction 8500.01, Cybersecurity, DoDI 8581.01, IA Policy for Space Systems Used by the DoD , NISPOM Defense Security Service, Industrial Security Field Operations (ISFO), Assessment and Authorization Manual.
Security Incident Reporting: In addition to the NISPOM requirements, the contractor shall provide a report of loss or compromise of CUI and/or classified information to the cognizant Government Contracting Activity (GCA), Government Information System Security Manager (ISSM), and Authorization Official (AO). Incidents involving contractor SCI information and/or programs, CSSO shall report through the Agreements Officer Representative (AOR) to the appropriate SCI Security Representative (SSR) official. Contractors shall go through the contracting officer to the organizations that issued the contract when emergency matters exists that affect plans or operations when there is a danger of compromise.
Max Subcontracting Level: NONE text:
SMC/ECLXA
text:
SMC/ECLXO
| text: SMC/ECL |
| text: SMC/INX |
| attachmentsList: |
| AddAttachment: |
| ViewAttachment: |
| RemoveAttachment: |
| rep: MAJ BRIAN RILEY |
PROGRAM MANAGER
rep: ROBERT DOUGLASS
COR
rep: BRIAN SMITH
SECURITY REPRESENTATIVE
rep: MARY JANE BRENCE
SMC/INX
| Sig: |
| Enter your name here.: Visitor Group Security Agreement (VGSA) is required for locations operating on a government installation. PROGRAM PROTECTION PLANNING: The prime contractor and its subcontractors shall protect Critical Program Information (CPI), Sensitive Compartmented Information (SCI), Critical Components (CC), technologies and systems when identified in appropriate Program Protection Plans (PPP). |
| Enter your name here.: The Defense Counterintelligence Security Agency is relieved of security inspection responsibility for contracts on government installations. The Commander retains cognizance over contracts on the installation. SMC/INX staff is designated as member of the Wing Inspection Team and has inspection authority when assigned under SMC/IG. |
| GCAName: SMC/ECLK-KT |
| AAC: FA8818 |
| AAC: FA8818 |
| Address: 3548 Aberdeen Ave. SE |
Kirtland, AFB, NM, 87117 Address: SMC/ECLK-KT 3548 Aberdeen Ave. SE Kirtland, AFB, NM, 87117
| POCName: LUCIA CORRAL |
| Phone: 5058535873 |
| Phone: 5058535873 |
| Email: lucia.corral@us.af.mil |
| Email: lucia.corral@us.af.mil |
| Title: CONTRACTING OFFICER |
| Enter the date using the format DD-Mon-YYYY: |
File details come from the government source that posted it. Updated .