Attachment 2 - DD254_MSOFS.pdf
PDF 183 KB Posted
- Attached to
- Maritime Special Operations Forces (MSOFS) 2. 0 Federal contract opportunity
- Solicitation number
- H9224025R0001
- Issued by
- United States Special Operations Command
About this file
This document is a DD Form 254, Department of Defense Contract Security Classification Specification, for a Maritime Special Operations Forces Support (MSOFS) 2.0 contract. The purpose of this contract is to obtain highly qualified services in support of Naval Special Warfare (NSW) day-to-day operations across all mission areas. The period of performance is August 1, 2024 to July 31, 2033, with a biennial review of the DD Form 254 required. The contract is a total small business set-aside with a NAICS code of 541990 and a $19.5M small business size standard. This DD Form 254 is tentatively approved, and the final version with all details will be submitted to the Naval Special Warfare Command Contracting Officer's Security Representative for final review and approval upon contract award. Key requirements include access to Sensitive Compartmented Information (SCI) and Controlled Unclassified Information (CUI), adherence to NSW Operations Security (OPSEC) and Information Technology (IT) security policies, and specific on-site security procedures for contractor personnel at NSW facilities.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| H9224025R0001 Amend 1.pdf | ||
| Attachment 1 - PWS MSOFS 2.0_r1.pdf | ||
| H9224025R0001 Conf thru Amend 1.pdf | ||
| Q_A Govt Answers_15Nov24.pdf | ||
| Attachment 6 - HTRO Self Score Matrix_rev1.xlsx | XLSX spreadsheet | |
| Exhibit A-1 CDRL A001 Submission Format.pdf | ||
| Attachment 4-QASP_MSOFS2.pdf | ||
| Attachment 6 - HTRO Self Score Matrix.xlsx | XLSX spreadsheet | |
| Exhibit A-2 CDRL A002 Submission Format.pdf | ||
| Attachment 1 - PWS MSOFS 2.0.pdf | ||
| Attachment 3 - Price Worksheet.xlsx | XLSX spreadsheet | |
| Attachment 7 - Work Sample Cover Sheet.docx | DOCX document | |
| H9224025R0001 Final.pdf | ||
| Attachment 5 - Q_A Template.docx | DOCX document | |
| Exhibit A CDRL A001.pdf | ||
| Exhibit A CDRL A002.pdf |
Show all 16
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
CLASSIFICATION (When filled in): Unclassified
CUI
PREVIOUS EDITION IS OBSOLETE. Page 1 of 16DD FORM 254, APR 2018
DEPARTMENT OF DEFENSE
CONTRACT SECURITY CLASSIFICATION SPECIFICATION
(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)
OMB No. 0704-0567 OMB approval expires:
June 30, 2025
The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.
RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.
1. CLEARANCE AND SAFEGUARDING
a. LEVEL OF FACILITY SECURITY CLEARANCE (FCL) REQUIRED
(See Instructions)
Top Secret
b. LEVEL OF SAFEGUARDING FOR CLASSIFIED INFORMATION/
MATERIAL REQUIRED AT CONTRACTOR FACILITY
Secret
2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)
a. PRIME CONTRACT NUMBER (See instructions.)
TBD
b. SUBCONTRACT NUMBER
c. SOLICITATION OR OTHER NUMBER DUE DATE (YYYYMMDD)
3. THIS SPECIFICATION IS: (X and complete as applicable.)
a. ORIGINAL (Complete date in all cases.)
DATE (YYYYMMDD)
20240730
b. REVISED (Supersedes all previous specifications.)
REVISION NO. DATE (YYYYMMDD)
c. FINAL (Complete Item 5 in all cases.) DATE (YYYYMMDD)
4. IS THIS A FOLLOW-ON CONTRACT? No Yes If yes, complete the following:
Classified material received or generated under (Preceding Contract Number) is transferred to this follow-on contract.
5. IS THIS A FINAL DD FORM 254? No Yes If yes, complete the following:
In response to the contractor's request dated , retention of the classified material is authorized for the period of:
6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)
a. NAME, ADDRESS, AND ZIP CODE ***This DD254 is for solicitation purposes only. An original DD254 will be provided upon contract award.***
b. CAGE CODE c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)
7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor) Add Row Remove Last Row Delete All Rows
a. NAME, ADDRESS, AND ZIP CODE
SEE ITEM 13
b. CAGE CODE c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)
8. ACTUAL PERFORMANCE (Click button to add more locations.) Add Row Remove Last Row Delete All Rows
a. LOCATION(S) (For actual performance, see instructions.)
Naval Special Warfare Command 2000 Trident Way San Diego, CA 92155
b. CAGE CODE (If applicable, see Instructions.)
N/A
c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional) Naval Special Warfare Command Attn: Activity Security Manager 2000 Trident Way San Diego, CA 92155
a. LOCATION(S) (For actual performance, see instructions.)
Naval Special Warfare Group ONE 208 Neptune Street, Building 208 San Diego, CA 92155
b. CAGE CODE (If applicable, see Instructions.)
N/A
c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional) Naval Special Warfare Group ONE Attn: Activity Security Manager 208 Neptune Street, Building 208 San Diego, CA 92155
CUI
PREVIOUS EDITION IS OBSOLETE. Page 2 of 16DD FORM 254, APR 2018
a. LOCATION(S) (For actual performance, see instructions.)
Naval Special Warfare Group TWO 1300 Helicopter Road BLDG 3854 Virginia Beach, VA 23459-2944
b. CAGE CODE (If applicable, see Instructions.)
N/A
c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional) Naval Special Warfare Group TWO Attn: Activity Security Manager 1300 Helicopter Road BLDG 3854 Virginia Beach, VA 23459-2944
a. LOCATION(S) (For actual performance, see instructions.)
Naval Special Warfare Group FOUR 2220 Schofield Road Virginia Beach, VA 23459-8838
b. CAGE CODE (If applicable, see Instructions.)
N/A
c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional) Naval Special Warfare Group FOUR Attn: Activity Security Manager 2220 Schofield Road Virginia Beach, VA 23459-8838
a. LOCATION(S) (For actual performance, see instructions.)
Naval Special Warfare Group EIGHT VA 1600 Seabee Drive Virginia Beach, VA 23459
b. CAGE CODE (If applicable, see Instructions.)
N/A
c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional) Naval Special Warfare Group EIGHT Attn: Activity Security Manager 1600 Seabee Drive Virginia Beach, VA 23459
a. LOCATION(S) (For actual performance, see instructions.)
Naval Special Warfare Group EIGHT CA 260 Anaconda Rd Bldg. 262 San Diego, CA 92118
b. CAGE CODE (If applicable, see Instructions.)
N/A
c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional) Naval Special Warfare Group EIGHT CA Attn: Activity Security Manager 260 Anaconda Rd Bldg. 262 San Diego, CA 92118
a. LOCATION(S) (For actual performance, see instructions.)
Naval Special Warfare Group ELEVEN 3322 Guadalcanal Rd, Bldg 309 San Diego, CA 92155
b. CAGE CODE (If applicable, see Instructions.)
N/A
c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional) Naval Special Warfare Group ELEVEN Attn: Activity Security Manager 3322 Guadalcanal Rd, Bldg 309 San Diego, CA 92155
a. LOCATION(S) (For actual performance, see instructions.)
Naval Special Warfare CENTER 2446 Trident Way San Diego, CA 92155-5494
b. CAGE CODE (If applicable, see Instructions.)
N/A
c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional) Naval Special Warfare CENTER Attn: Activity Security Manager 2446 Trident Way San Diego, CA 92155-5494
a. LOCATION(S) (For actual performance, see instructions.)
Naval Special Warfare Advanced Training Command 1 Hooper Blvd Imperial Beach, CA 91932-1050
b. CAGE CODE (If applicable, see Instructions.)
N/A
c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional) Naval Special Warfare Advanced Training Command Attn: Activity Security Manager 1 Hooper Blvd Imperial Beach, CA 91932-1050
a. LOCATION(S) (For actual performance, see instructions.)
Naval Special Warfare Basic Training Command 2446 Trident Way San Diego, CA 92155-5494
b. CAGE CODE (If applicable, see Instructions.)
N/A
c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional) Naval Special Warfare Basic Training Command Attn: Activity Security Manager 2446 Trident Way San Diego, CA 92155-5494
a. LOCATION(S) (For actual performance, see instructions.)
Naval Special Warfare Development Group 1636 Regulus Ave Virginia Beach, VA 23461
b. CAGE CODE (If applicable, see Instructions.)
N/A
c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional) Naval Special Warfare Development Group Attn: Activity Security Manager 1636 Regulus Ave Virginia Beach, VA 23461
CUI
PREVIOUS EDITION IS OBSOLETE. Page 3 of 16DD FORM 254, APR 2018
a. LOCATION(S) (For actual performance, see instructions.)
Naval Small Craft Instruction & Technical Training School 2606 Lower Gainesville Road Stennis Space Center, MS 39529
b. CAGE CODE (If applicable, see Instructions.)
N/A
c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional) Naval Small Craft Instruction & Technical Training School Attn: Activity Security Manager 2606 Lower Gainesville Road Stennis Space Center, MS 39529
a. LOCATION(S) (For actual performance, see instructions.)
Special Boat Team TWENTY TWO 2603 Lower Gainesville Road Stennis Space Center, MS 39529
b. CAGE CODE (If applicable, see Instructions.)
N/A
c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional) Special Boat Team TWENTY Attn: Activity Security Manager 2603 Lower Gainesville Road Stennis Space Center, MS 39529
a. LOCATION(S) (For actual performance, see instructions.)
Special Boat Team TWENTY 2220 Schofield Road Virginia Beach, VA 23459-8838
b. CAGE CODE (If applicable, see Instructions.)
N/A
c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional) Special Boat Team TWENTY Attn: Activity Security Manager 2220 Schofield Road Virginia Beach, VA 23459-8838
a. LOCATION(S) (For actual performance, see instructions.)
Special Boat Team TWELVE 3402 Tarawa Road San Diego CA 92155-5003
b. CAGE CODE (If applicable, see Instructions.)
N/A
c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional) Special Boat Team TWELVE Attn: Activity Security Manager 3402 Tarawa Road San Diego CA 92155-5003
a. LOCATION(S) (For actual performance, see instructions.)
Naval Special Warfare Group EIGHT HI 455 Hornet Ave Honolulu, HI 96860
b. CAGE CODE (If applicable, see Instructions.)
N/A
c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional) Naval Special Warfare Group EIGHT HI Attn: Activity Security Manager 455 Hornet Ave Honolulu, HI 96860
9. GENERAL UNCLASSIFIED DESCRIPTION OF THIS PROCUREMENT
THIS DD FORM 254 IS TENTATIVELY APPROVED. Upon (company selection, identification of a Contract Number/Task Order) but prior to award and any classified release, this DD Form 254 with all pertinent information inserted in appropriate sections will be submitted to Naval Special Warfare Command Contracting Officer’s Security Representative for final review and approval.
The purpose of the Maritime Special Operations Forces Support (MSOFS) 2.0 contract is to obtain highly qualified services in support of NSW day-to-day operations in all mission areas.
Period of Performance: 1 AUG 2024 - 31 JUL 2033 (BIENNIAL DD FORM 254 REVIEW REQUIRED - SEE ITEM 13)
10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)
a. COMMUNICATIONS SECURITY (COMSEC) INFORMATION f. SPECIAL ACCESS PROGRAM (SAP) INFORMATION
b. RESTRICTED DATA g. NORTH ATLANTIC TREATY ORGANIZATION
(NATO) INFORMATION
c. CRITICAL NUCLEAR WEAPON DESIGN INFORMATION (CNWDI) (If CNWDI applies, RESTRICTED DATA must also be marked.) h. FOREIGN GOVERMENT INFORMATION
d. FORMERLY RESTRICTED DATA i. ALTERNATIVE COMPENSATORY CONTROL MEASURES
(ACCM) INFORMATION
e. NATIONAL INTELLIGENCE INFORMATION:
(1) Sensitive Compartmented Information (SCI)
(2) Non-SCI
j. CONTROLLED UNCLASSIFIED INFORMATION (CUI) (See instructions.)
k. OTHER (Specify) (See instructions.)
SEE ITEM 13
CUI
PREVIOUS EDITION IS OBSOLETE. Page 4 of 16DD FORM 254, APR 2018
11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)
a. HAVE ACCESS TO CLASSIFIED INFORMATION ONLY AT
ANOTHER CONTRACTOR'S FACILITY OR A GOVERNMENT
ACTIVITY
(Applicable only if there is no access or storage required at contractor facility.
See instructions.)
b. RECEIVE AND STORE CLASSIFIED DOCUMENTS ONLY
c. RECEIVE, STORE, AND GENERATE CLASSIFIED
INFORMATION OR MATERIAL
d. FABRICATE, MODIFY, OR STORE CLASSIFIED HARDWARE
e. PERFORM SERVICES ONLY
f. HAVE ACCESS TO U.S. CLASSIFIED INFORMATION OUTSIDE
THE U.S.,PUERTO RICO, U.S. POSSESSIONS AND TRUST
TERRITORIES
g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE
TECHNICAL INFORMATION CENTER (DTIC) OR OTHER
SECONDARY DISTRIBUTION CENTER
h. REQUIRE A COMSEC ACCOUNT
i. HAVE A TEMPEST REQUIREMENT
j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS
k. BE AUTHORIZED TO USE DEFENSE COURIER SERVICE
l. RECEIVE, STORE, OR GENERATE CONTROLLED UNCLASSIFIED
INFORMATION (CUI).
(DoD Components: refer to DoDI 5200.48, only for specific CUI protection requirements. Non-DoD Components: see instructions.)
m. OTHER (Specify) (See instructions.)
SEE ITEM 13
12. PUBLIC RELEASE
Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority.
Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)
DIRECT THROUGH (Specify below)
CONTRACTING OFFICER'S REPRESENTATIVE (COR) IN
BLOCK 13
Public Release Authority:
WARCOM PUBLIC AFFAIRS OFFICE AND CONTRACTING
OFFICER
13. SECURITY GUIDANCE Add Signature Remove Last Signature Delete All Signatures
The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract;
and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.
(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)
The Contracting Officer’s Representative/Program Manager will provide a copy of all applicable security directives for this contract.
Appropriate applicable HQ USSOCOM, NAVSPECWARCOM (NSWC), or NSW subordinate command security directives, regulations, and standard operating procedures will be provided by the requiring agency (normally through the Performance Monitor or Component/ Theater Special Operations Command COR/PM). Upon completion or termination of the classified contract, or sooner when the purpose of the release has been served, the contractor will return all classified information (furnished or generated) to the source from which received unless retention or other disposition instructions are authorized in writing by the USSOCOM or NAVSPECWARCOM Government Contracting Agency/Activity. Furthermore, the contractor will account for and return all Common Access Cards (CACs) to Contracting Officer's Representative, Program Manager, or Trusted Agent upon completion or termination of the classified contract, termination of employment, or suspension of classified clearance or access of any contractor employee. Security badges, installation entry passes/vehicle decals issued to contractor personnel will be returned to the appropriate issuing office as required.
Ref 2b: Subcontracting of this effort must be approved by NAVSPECWARCOM prior to award. Forward requests and draft Subcontract DD FM 254s to the Contracting Officer’s Security Representative (COSR) (nsw.industrial.security.dl@socom.mil). (IAW NAVSPECWARCOMINST 5520.1, Industrial Security, please allow 10 duty days for review/approval).
Ref 7: See guidance in Ref 2b.
Ref 9: Unless DD FM 254 revision is required due to change in the security requirements of the effort or there is a change in the contractor’s Facility Clearance (FCL) status, the responsible Contracting Officer’s Representative/Program Manager (COR/PM) must conduct a review of the DD FM 254 and associated Individual Work Plan, Performance Work Statement/Statement of Objectives/ Statement of Work every 24 MONTHS (BIENNIALLY) in order to validate and/or update the requirements of the effort as required by DoDM 5220.22-V2, National Industrial Security Program: Industrial Security Procedures for Government Activities. Documentation of review (email is sufficient) should be forwarded to HQ USSOCOM Industrial Security via NIPRNet at IndustrialSecurity@socom.mil through the NAVSPECWARCOM COSR at nsw.industrial.security.dl@socom.mil.
Ref 12: Requests must be forwarded through the responsible Contracting Officer’s Representative, COSR, Program Manager, Contracting
CUI
PREVIOUS EDITION IS OBSOLETE. Page 5 of 16DD FORM 254, APR 2018
Official (Item 16) and NSW FOIA office prior to public release.
The use of personal electronic media (cameras, video recorders, computer laptops, flash (thumb), or other removable drives) is prohibited in all Naval Special Warfare spaces. All removable electronic media must be labeled (unclassified, etc.) To the highest classification of data stored, and/or for the classification of the system in which it is used. If classified, any removable electronic media must be tracked and stored appropriate to that level of classification.
Anti-terrorism/Force Protection (AT/FP) briefings are required for all personnel (military, DoD civilian, and contractor) per OPNAVINST F3300.53c. Contractor employees must receive the AT/FP briefing annually. The briefing is available at https://jkodirect.jten.mil/html/ COI.xhtml?course_prefix=JS&course_number=-US007. Forward a copy of training certificate to the COR.
The COR will specify which positions require any additional clearance and when the contractor is authorized to courier classified information and equipment in support of the naval special warfare.
The security requirements for personnel assigned under this task shall be in accordance with the requirements of SECNAVINST 5510.30/36 series. The highest-level security required for this task is TOP SECRET. The work performed by the contractor will include access to unclassified and up to TOP SECRET information, and spaces. The contractor may be required to attend meetings classified up to the TOP SECRET level.
Personnel performing classified work or requiring access to classified material or spaces under this delivery order/task order shall possess both a DoD security clearance at the appropriate level and need to know. Request for visit authorization shall be submitted in accordance with 32 CFR Part 117 (National Industrial Security Program Operating Manual (NISPOM)) not later than one (1) week prior to visit.
DD254 of the basic contract applies.
All development of databases, classified hardware, and graphics (if/when conducted at the contractor’s location) will be done upon Defense Counterintelligence and Security Agency (DCSA) approved Information Assurance (IA) equipment.
All classified information/hardware developed will be classified pursuant to derivative classification procedures or as any applicable classification guide so dictates (NISPOM Part 117.13) and executive order 13526. All applicable classification guides will be identified and made available by the COR.
Meetings or visits conducted by the contractor will be done IAW NISPOM Part 117.16.
SCI ADDENDUM
(14 SEPTEMBER 2020)
This supplement applies to:
Prime Contract Number: Hxxxxxxxxxxx Subcontract Number: N/A Delivery/Task Order Number: Hxxxxxxxxx Expiration Date: 31 JUL 2033
The following controls will apply to Sensitive Compartmented Information (SCI) provided under this contract.
1. Item 10e (1): Contractors with HCS-P eligibility may be read into KLM/KLM-R. Need to know must be established as a requirement in performance of their duties.
2. Item 10e (2): Security clearances for contractors working within SCIF spaces must be adjudicated meeting Intelligence Community Policy Guidance (ICPG) 704.1, 704.2, 704.3, 704.4, 704.5 eligibility requirements. Prior approval of the contracting activity is required for sub-contracting. Access to intelligence information requires special briefings and a final U.S. Government clearance at the appropriate level.
3. Item 13: Department of Defense (DoD) manual 5105.21, volumes 1-3, Intelligence Community Policy Guidance (ICPG) 704.1, 704.2, 704.3, 704.4, 704.5, Intelligence Community Standard (ICS) 705-1&2 including the technical specifications for construction and management of Sensitive Compartmented Information Facilities (IC Tech Spec-for ICD/ICS 705, Headquarters, United States Special Operations Command (HQ USSOCOM) 380-6, and COMNAVSPECWARCOMINST 5510.4 (series), provide the necessary guidance for physical and information security measures and are part of the SCI security specifications for the contract.
4. Item 13: inquiries pertaining to classification guidance will be directed to the responsible NAVSPECWAR Contracting Officer
CUI
PREVIOUS EDITION IS OBSOLETE. Page 6 of 16DD FORM 254, APR 2018
Representative/Program Manager/Contract Monitor.
5. Item 13: all SCI furnished to the contractor in support of this contract / delivery / task order remains the property of the DoD or the agency or command that releases the information. Upon termination of the contract, all furnished SCI will be returned to the NAVSPECWARCOM Special Security Office (SSO) or the prime contractor.
6. Item 14: this contract / delivery / task order requires that UNDETERMINED [X] contract billets be established in order to fulfill the contractual obligations incurred. Contract billets will be designated at the task order level. Access will be granted by the government agency. Upon completion or cancellation of the contract, the Contractor SSO (CSSO) will debrief or notify the NSWC SSO to debrief all personnel not required for contract closeout and those billets will be disestablished.
7. Item 14: names of contractor personnel requiring access to SCI and justification for SCI billets will be submitted to NSWC SSO after contract monitor coordination. Billet justifications will include the contract statement of work. If a T5 investigation has not been completed upon approval of billets by the NSWC SSO, the CSSO will submit necessary forms to the Vulnerability Risk Operations Center (VROC) for a T5. The T5 investigation and access to SCI will comply with the national industrial security program manual. Upon completion of the T5, a nomination for SCI access will be submitted to the NSWC SSO.
8. Item 14: The CSSO will advise the NSWC SSO, through the contract monitor, upon reassignment of personnel to other duties not associated with this contract. The contract monitor will also notify the SSO office at aaron.m.mata.civ@socom.mil (619) 537-1054 so the SSO can remove their ownership of the contractor in DISS.
9. Item 14: The CSSO must coordinate with the SCI contract monitor before subcontracting any portion of SCI efforts involved in the contract. A separate DD254 for the subcontractor will be processed and a copy provided to the NSWC SSO.
10. Item 14: The contractor will not use references to SCI access, even by unclassified acronyms, in advertisements, promotional efforts, or recruitment of employees.
11. Item 14: All SCI work will be performed at the locations specified below and in subsequent Task Orders.
a. designated at the task order level.
12. Item 15: The NSWC SSO has exclusive security responsibility for all SCI released to the contractor or developed under this contract.
SSO Navy and HQ NAVSPECWARCOM N23, retain authority for all inspections of the contractor to ensure compliance with SCI directives, regulations, and instructions.
13. In accordance with DODM 5105.21 volume 1-3, the following activity is designated User Agency Special Security Office for SCI requirement:
NSWC
ATTN: SSO navsoc_csm_sso@socom.mil 2000 Trident Way 619-537-1023/1054/1066/1059 San Diego, CA 92155
PROTECTING “CONTROLLED UNCLASSIFIED INFORMATION” (CUI)
CUI Addendum (Updated March 2021)
1. GENERAL:
a. Controlled Unclassified Information (CUI) is not a security classification, but designates unclassified information that requires any safeguarding or dissemination control per DoD Instruction 5200.48, “Controlled Unclassified Information” (6 March 2020).
b. With the implementation of DoDI 5200.48, DoDI 5200.01, Volume 4, “DoD Information Security Program: Controlled Unclassified Information” (24 February 2012, as amended), has been cancelled and “For Official Use Only” (FOUO) and is no longer authorized. All new documents shall be marked in accordance with the guidance below.
c. In order to balance the need to safeguard CUI with the public interest the CUI Registry, established by DoDI 5200.48, lists categories of CUI Basic/Specified and identifies basis for controls, and includes guidance on handling procedures.
CUI
PREVIOUS EDITION IS OBSOLETE. Page 7 of 16DD FORM 254, APR 2018
d. There are two subsets of CUI.
i. CUI Basic is the subset of CUI for which law, regulation, or government policy does not set out specific handling or dissemination controls. CUI Basic handling and dissemination controls are the same as previously used for FOUO.
ii. CUI Specified is the subset of CUI for which law, regulation, or government policy contains specific handling controls that differ from CUI Basic. The government will provide marking and handling guidance separately for CUI Specified.
e. Remarking legacy FOUO documents is not required as long as they remain under DoD control. When needed, FOUO information does not automatically become CUI, so the material must be reviewed by the information owner to determine if it meets the CUI requirements and marked appropriately.
f. When responding to FOIA requests, the responsible DoD agency must base its decision on the content of the information and applicability of any of the FOIA statutory exemptions regardless of whether an agency designates or marks the information as CUI.
2. DESIGNATION as CUI: Designating CUI occurs when an authorized holder, consistent with DoDI 5200.48 and the CUI Registry, determines that a specific item of information falls into a CUI category or subcategory. The information must be designated as either CUI Basic or CUI Specified and the authorized holder must ensure that appropriate markings are applied to documents to ensure recipients are aware of the CUI status. See the associated Security Classification Guide (SCG) or other guidance provided by the Government Contracting Agency (GCA) for specific categories of CUI related to this contract and guidance on storage, handling, and dissemination.
3. MARKING:
a. Unclassified documents containing CUI will be marked CUI at the top & bottom of each page. As a best practice each “portion” (i.e.
titles, subject lines, paragraphs, bullets, charts, etc.) containing CUI may be Portion Marked (CUI). If portion marks are used then Unclassified portions will be Portion Marked (U). Do not use (U//CUI).
b. The government will provide marking, handling, and dissemination guidance separately for any CUI Specified information. For classified contracts, this guidance will be contained in the associated SCG.
c. The following CUI Designation Indicator information will be included on the first/title page or cover of all unclassified documents containing CUI:
Controlled by: [Name of DoD Component and Office] CUI Category: [List of Category or Categories of CUI] Distribution/Dissemination Control: [Use “None” for CUI Basic/As required for CUI Specified) POC: [Phone Number and/or E-mail]
d. Classified documents containing CUI will NOT include CUI in the banner marking at the top and bottom of each page. Each paragraph that contains only CUI will be portion marked (CUI). All other paragraphs will be marked according to their classification. Do not “co-mingle” CUI with classified information. The above CUI Designation Indicator information must be included on the first page or cover (same as unclassified documents). Additionally, the following statement must be included on the first page of documents that contain both CUI and classified information:
This content is classified at the [insert highest classification level of the document] level and may contain elements of controlled unclassified information (CUI), unclassified, or information classified at a lower level than the overall classification displayed. This content shall not be used as a source of derivative classification; refer to [cite specific reference or applicable Security Classification Guide]. It must be reviewed for both Classified National Security Information (CNSI) and CUI in accordance with DoDI 5230.09 prior to public release.
4. PROCESSING: Unclassified Automated Information Systems (AIS) used to process CUI under this contract must meet the basic security requirements listed in the NIST SP 800-171 REV 2, “Protecting Controlled Unclassified Information in Non-Federal Systems and Organizations”, 21 February 2020. AIS accredited and approved for processing classified information under this contract are also approved to process DoD CUI.
5. DISSEMINATION: CUI may be disseminated between officials of DoD Agencies, DoD contractors, consultants and grantees to conduct official business for the DoD provided the dissemination is consistent with controls imposed by a Distribution Statement or Limited Dissemination Controls (LDC). Guidance on Distribution Statements and LDCs will be provided separately by the government for any prescribed CUI Specified information. For classified contracts, this information will be contained in the program SCG. CUI always requires Foreign Disclosure Decision before release outside of DoD Agencies, DoD contractors, consultants and grantees.
CUI
PREVIOUS EDITION IS OBSOLETE. Page 8 of 16DD FORM 254, APR 2018
6. STORAGE: During working hours, to prevent unauthorized access, do not leave CUI unattended, read or discuss around unauthorized personnel. CUI shall be placed in an out-of-sight location if the work area is accessible to persons who do not have a need for the information. During non-working hours, the information shall be stored to preclude unauthorized access. Filing such material with other unclassified records in unlocked files or desks, is adequate when internal building security is provided during non-working hours. When such internal security control is not exercised, locked buildings or rooms will provide adequate after-hours protection or the material can be stored in locked receptacles such as file cabinets, desks, or bookcases.
7. TRANSMISSION: CUI may be transmitted using the following:
a. Mail – CUI may be sent via first class mail or parcel post. Bulk shipments may be sent by fourth class mail. Contents must be properly marked, but no markings will appear on the outer wrapper.
b. Fax – Normally CUI may be sent via Facsimile equipment. To prevent unauthorized disclosure, coversheets should be used, the locations of both fax machines should be considered, and availability of an authorized recipient at the receiving end should be confirmed.
Secure classified fax machines may be used without the above verifications.
c. E-Mail/Web Sites – E-mail may be used on approved secure communication systems or systems using other protective measures such as Public Key Infrastructure (PKI) or transport layer security (e.g., https). E-mail messages must be appropriately marked to identify CUI status. Personnel will not use unofficial or personal email accounts, messaging systems, or other non-DoD information systems, except approved government contractor systems to conduct official business involving CUI.
d. Video Teleconferencing – Only use Government Agency approved secure, encrypted video conferencing and collaborative platforms (i.e. SVTC, etc.). CUI may not be discussed over commercially available video conferencing applications.
e. Avoid wireless transmission unless no other means are available.
8. DESTRUCTION: When no longer needed, CUI must be disposed of in a way that will make it unreadable, indecipherable, and irrecoverable. Use of approved sensitive/classified material destruction devices is recommended. (ISOO CUI Notice 2019-03, “Destroying Controlled Unclassified Information in Paper Form”, 15 July 2019)
9. UNAUTHORIZED DISCLOSURE: Report misuse, mishandling, or Unauthorized Disclosure of CUI to the Unauthorized Disclosure Program Management Office, the Controlling Agency and the appropriate Military Department Counterintelligence Organization. While Unauthorized Disclosure of CUI does not constitute a security violation, a formal security inquiry/investigation is required if disciplinary action will be taken against the individual(s) responsible. Unauthorized Disclosure of certain CUI, such as export controlled-technical data, may also result in civil and criminal sanctions against responsible persons based on procedures codified in relevant law, regulation, or government-wide policy.
NAVAL SPECIAL WARFARE COMMAND OPERATIONS SECURITY (OPSEC) REQUIREMENTS
(ADHERENCE TO ALL NSW COMPONENT COMMAND OPSEC REQUIREMENTS IS MANDATORY)
- All work is to be performed in accordance with DoD and Navy Operations Security (OPSEC) requirements, per the following applicable documents:
- National Security Decision Directive 298 -National Operations Security Program (NSDD) 298
- DoD 5205.02 - DoD Operations Security (OPSEC) program
- OPNAVINST 3432.1 - DoN Operations Security
- NSWCINST 3421 (series) - NSW Operations Security Policy
- The contractor will accomplish the following minimum requirements in support of naval special warfare command (WARCOM) operations security (OPSEC) program:
- the contractor will practice OPSEC and implement OPSEC countermeasures to protect DoD critical information. Items of critical information are those facts, which individually, or in the aggregate, reveal sensitive details about NSW or the contractor’s security or operations related to the support or performance of the PWS/SOO/SOW, and thus require a level of protection from adversarial collection or exploitation not normally afforded to unclassified information.
- contractor must protect critical information and other sensitive unclassified information and activities, especially those activities or
CUI
PREVIOUS EDITION IS OBSOLETE. Page 9 of 16DD FORM 254, APR 2018 information which could compromise classified information or operations, or degrade the planning and execution of military operations performed or supported by the contractor in support of the mission. Protection of critical information will include the adherence to and execution of countermeasures which the contractor is notified by or provided by WARCOM, for critical information on or related to the
PWS/SOO/SOW.
- sensitive unclassified information is that information marked for official use only (or fouo), privacy act of 1974, company proprietary, and also information as identified by WARCOM.
- WARCOM has identified the following items as critical information that may be related to this PWS/SOO/SOW:
• known or probable vulnerabilities to any U.S. system and their direct support systems.
• details of capabilities or limitations of any U.S. system that reveal or could reveal known or probable vulnerabilities of any U.S. system and their direct support systems.
• details of information about military operations, missions and exercises.
• details of U.S. systems supporting combat operations (numbers of systems deployed, deployment timelines, locations, effectiveness, unique capabilities, etc.).
• operational characteristics for new or modified weapon systems (probability of kill (pk), countermeasures, survivability, etc.).
• required performance characteristics of U.S. systems using leading edge or greater technology (new, modified or existing).
• telemetered or data-linked data or information from which operational characteristics can be inferred or derived.
• test or evaluation information pertaining to schedules of events during which critical information might be captured. (advance greater than 3 days).
• details of naval special warfare unique test or evaluation capabilities (disclosure of unique capabilities).
• existence and/or details of intrusions into or attacks against DoD networks or information systems, including, but not limited to, tactics, techniques and procedures used, network vulnerabilities exploited, and data targeted for exploitation.
• network user id’s and passwords.
• counter-ied capabilities and characteristics, including success or failure rates, damage assessments, advancements to existing or new capabilities.
• vulnerabilities in command processes, disclosure of which could allow someone to circumvent security, financial, personnel safety, or operations procedures.
• force protection specific capabilities or response protocols (timelines/equipment/numbers of personnel/training received/etc.).
• command leadership and vip agendas, reservations, plans/routes etc.
• detailed facility maps or installation overhead photography (photo with annotation of command areas or greater resolution than commercially available).
• details of coop, naval special warfare emergency evacuation procedures, or emergency recall procedures.
• government personnel information that would reveal force structure and readiness (such as recall rosters or deployment lists).
• compilations of information that directly disclose command critical information.
- the above critical information and any that the contractor develops, regardless if in electronic or hardcopy form, must be protected by a minimum of the following countermeasures:
• all emails containing critical information must be DoD public key infrastructure (pki) signed and pki encrypted when sent.
• critical information may not be sent via unclassified fax.
• critical information may not be discussed via non-secure phones.
• critical information may not be provided to individuals that do not have a need to know it in order to complete their assigned duties.
• critical information may not be disposed of in recycle bins or trash containers.
• critical information may not be left unattended in uncontrolled areas.
• critical information in general should be treated with the same care as cui, fouo or proprietary information.
• critical information must be destroyed in the same manner as cui.
• critical information must be destroyed at contract termination or returned to the government at the government’s discretion.
- the contractor shall document items of critical information that are applicable to contractor operations involving information on or related to the PWS/SOO/SOW. Such determinations of critical information will be completed using the DoD OPSEC 5 step process as described in National Security Decision Directive (NSDD) 298, “National Operations Security Program”.
- OPSEC training must be included as part of the contractors ongoing security awareness program conducted in accordance with chapter 3, section 1, of the NISPOM. NSDD 298, DoD 5205.02, “DoD Operations Security (OPSEC) Program”, and OPNAVINST 3432.1, “operations security” should be used to assist in creation or management of training curriculum.
- if the contractor cannot resolve an issue concerning OPSEC they will contact the program manager / cor (who will consult with the WARCOM security manager).
PREVIOUS EDITION IS OBSOLETE. Page 10 of 16DD FORM 254, APR 2018
- all above requirements must be passed to all sub-contractors.
(continued on next page)
NAVAL SPECIAL WARFARE COMMAND INFORMATION TECHNOLOGY (IT) SYSTEMS SECURITY REQUIREMENTS
(ADHERENCE TO ALL NSW COMPONENT COMMAND IT REQUIREMENTS IS MANDATORY)
The U.S. government conducts trustworthiness investigations of personnel who are assigned to positions that directly or indirectly affect the operation of unclassified it resources and systems that process Department of Defense (DoD) information, to include Controlled Unclassified Information (CUI).
The Defense Counterintelligence And Security Agency (DCSA) processes all requests for U.S. government trustworthiness investigations.
Requirements for these investigations are outlined in paragraph c3.6.15 and appendix 10 of DoD 5200.2-R, available at http:// www.dtic.mil/whs/directives/corres/dir.html. Personnel occupying an it position shall be designated as filling one of the it position categories listed below. The contractor shall include all of these requirements in any subcontracts involving it support. (note: terminology used in DoD 5200.2-r references “ADP” vice “it”. For purposes of this requirement, the terms ADP and it are synonymous.)
DoDD 8500.01E, subject: information assurance (IA), paragraph 4.8 states "access to all DoD information systems shall be based on a demonstrated need-to-know, and granted in accordance with applicable laws and DoD 5200.2-R for background investigations, special access and it position designations and requirements. An appropriate security clearance and non-disclosure agreement are also required for access to classified information” in accordance with DODM 5200.01 vol. 1. DoD 5200.2-R and DoDD 5200.2 require all persons assigned to sensitive positions or assigned to sensitive duties be U.S. citizens. All persons assigned to it-ii and it-iii positions, as well as all persons with access to controlled unclassified information (without regard to degree of it access) or performing other duties that are considered "sensitive" as defined in DoDD 5200.2 and DoD 5200.2-R must be U.S. citizens. Furthermore, access by non-U.S. citizens to unclassified export controlled data will only be granted to persons pursuant to the export control laws of the U.S. the categories of controlled unclassified information are specified in DoDI 5200.48 . These same restrictions apply to "representatives of a foreign interest" as defined by DoD 32 CFR Part 117 (National Industrial Security Program Operating Manual, NISPOM). DoD 8570.01-M further stipulates additional training and/or certification that is required by all persons assigned to information assurance functions.
Criteria for designated positions:
IT-II position (limited privileged)
Responsibility for systems design, operation, testing, maintenance, and/or monitoring that is carried out under technical review of higher authority in the IT-I category, includes but is not limited to:
• access to and/or processing of proprietary data, information requiring protection under the privacy act of 1974, and government-developed privileged information involving the award of contracts;
• accounting, disbursement, or authorization for disbursement from systems of dollar amounts less than $10 million per year. Other positions are designated by WARCOM that involve a degree of access to a system that creates a significant potential for damage or personal gain less than that in it-i positions. Personnel whose duties meet the criteria for an IT-II position require a favorably adjudicated national agency check with local agency check and credit check (NACLC) or T3/T3R investigation. The NACLC or T3R shall be updated every 10 years by using the electronic questionnaire for investigation processing (eQIP) web based program (SF86 format).
IT-III position (non-privileged)
• all other positions involving federal it activities. Incumbent in this position has non-privileged access to one or more DoD information systems, application, or database to which they are authorized access. Personnel whose duties meet the criteria for an IT-III position designation require a favorably adjudicated national agency check with inquiries (NACI).
Qualified cleared personnel do not require trustworthiness investigations:
When background investigations supporting clearance eligibility have been submitted and/or adjudicated to support assignment to sensitive national security positions, a separate investigation to support it access will normally not be required. A determination that an individual is not eligible for assignment to a position of trust will also result in the removal of eligibility for security clearance. Likewise, a determination that an individual is not eligible for a security clearance will result in the denial of eligibility for a position of trust.
Only the eQIP version of SF-85 and SF 86 are acceptable by Defense Counterintelligence and Security Agency (DCSA).
PREVIOUS EDITION IS OBSOLETE. Page 11 of 16DD FORM 254, APR 2018
The facility security officer (FSO) must verify employee's security clearance eligibility in the Defense Information System for Security (DISS) before contacting the COR to initiate request for trustworthiness investigations.
Contractor fitness determinations made by the DOD CAF are maintained in the DISS web applications. Favorable fitness determinations will support public trust positions only and not national security eligibility. If no issues are discovered, according to respective guidelines a “favorable determination” will be populated in DISS and will be reciprocal within DoD. If issues are discovered, the DOD CAF will place a “no determination made” in DISS and forward the investigation to the submitting office for the commander’s final determination.”
If an individual receives a negative trustworthiness determination, they will be immediately removed from their position of trust, the contractor will follow the same employee termination processing above, and they will replace the individual.
Visit Authorization Requests (VARS) for qualified employees:
Contractors that have been awarded a classified contract must submit visit requests using DISS. Contractors who work on classified contracts are required to have established an account through DISS for their facility. The DISS databases contains all U.S. citizens who have received a clearance of confidential, secret, and/or top secret. The visit request shall be submitted for the length of the contract but not longer than one year. Contact the COR for visit request SMO information on the NSW component to be visited.
Employment terminations:
The contractor shall:
• immediately notify the COR and NSW security manager of the employee’s termination.
• return any badge credentials, to include common access cards to Commander, Naval Special Warfare Command, 2000 Trident Way, BLDG 624, San Diego, CA 92155-5599 or NSW component command security office.
(continued on next page)
NAVAL SPECIAL WARFARE COMMAND SPECIFIC ON-SITE SECURITY REQUIREMENTS
(ADHERENCE TO ALL NSW COMPONENT COMMAND ONSITE REQUIREMENTS IS MANDATORY)
I. GENERAL.
A. Contractor performance. In performance of this contract the following security services and procedures are incorporated as an attachment to the DD254. The contractor will conform to the requirements of 32 CFR Part 117, National Industrial Security Program, Operating Manual (NISPOM), as revised. The contractor will follow all export laws and regulations in the performance of this contract.
When visiting Commander, Naval Special Warfare Command or any NSW component, the contractor will comply with the security directives used regarding the protection of classified and controlled unclassified information (CUI), SECNAVINST 5510.30/36 (series).
DoDM 5200.01 volumes 1 through 3, and COMNAVSPECWARCOMINST 5520.1 (series). A copy of COMNAVSPECWARCOMINST
5520.1 will be provided upon receipt of a written request from the contractor’s facility security officer (FSO) to the COR listed in the contract DD254. If the contractor establishes a cleared facility or defense counterintelligence and security agency (DCSA) approved off-site location aboard a U.S. government installation, the security provisions of the NISPOM will be followed within this cleared facility.
B. Security supervision. Us government personnel shall exercise security supervision over all contractors visiting WARCOM or any NSW component and shall provide security support to the contractor as noted below. The contractor will identify, in writing to the COR, an on-site point of contact to interface with the WARCOM’s security COR.
II. HANDLING CLASSIFIED MATERIAL OR INFORMATION.
A. Control and safeguarding. Contractor personnel located at the any NSW command are responsible for the control and safeguarding of all classified material in their possession. All contractor personnel will be briefed by their FSO on their individual responsibilities to safeguard classified material. In addition, all contractor personnel are invited to attend any NSW conducted security briefings. In the event of possible or actual loss or compromise of classified material, the on-site contractor shall immediately report the incident to COR and NSW security manager, as well as the contractor's FSO. A government representative will investigate the circumstances, determine culpability where possible, and report results of the inquiry to the FSO and the cognizant DCSA field office. On-site contractor personnel will promptly correct any deficient security conditions identified by a government representative.
PREVIOUS EDITION IS OBSOLETE. Page 12 of 16DD FORM 254, APR 2018
b. Storage.
1. Classified material may be stored in containers authorized by any NSW security manager for the storage of that level of classified material. Any areas located within cleared contractor facilities supporting NSW will be approved by DCSA.
2. The use of “open storage” areas must be pre-approved in writing by the COR and forwarded to the NSW security manager for the open storage or processing of any contract related classified material.
c. Transmission of classified material to WARCOM.
(for NSW component command, follow all command instructions)
1. All classified material transmitted by mail for use by long term visitors will be addressed as follows:
(a) Confidential and…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .