Attachment 2 - Draft DD 254 NW-D-OAA.pdf

PDF 78 KB Posted

Attached to
COMSEC Managerial Security Support Services Federal contract opportunity
Solicitation number
FA830724RB006
Issued by
Department of the Air Force Materiel Command Lifecycle Management Center Joint Base San Antonio

About this file

This document is a DD Form 254, which specifies security requirements and classification guidance for Solicitation Number FA830724RB006 to provide COMSEC Managerial Security Support Services. The contractor will require access to classified information up to the Secret level and will generate, receive, and store controlled unclassified information. The contractor must have facility and personnel security clearances and is authorized to use Defense Courier Service, Defense Technical Information Center, and receive a COMSEC account. Performance will occur in Poland and Ukraine, with oversight by HQ US EUCOM/CCJ2 SSO-USEUCOM. The government contracting activity is AFLCMC/HNCKA at Joint Base San Antonio, with a response due date not specified.

View the file

Other files for this federal contract opportunity

Other files attached to COMSEC Managerial Security Support Services, newest first.
File Type Posted
Solicitation - FA830724RB006_Updated.pdf PDF
Attachment 1 - PWS_Updated_11_29_23.docx DOCX document
Question and Answers Subbmited.pdf PDF
Amendment 1 Purpose.docx DOCX document
Attachment 3 - Facts Sheet.docx DOCX document
Exhibit A - DD Form 1423-1 CDRL.pdf PDF
Attachment 1 - PWS for COMSEC Custodian_.docx DOCX document
Attachment 6 - Transmittal Letter.docx DOCX document
Attachment 7 - Question and Answer.docx DOCX document
Solicitation - FA830724RB006.pdf PDF
Attachment 5 - Present_Past Performance Questionnaire.docx DOCX document
Attachment 8 - Cross Reference Matrix.docx DOCX document
Attachment 4 - Consent Form.docx DOCX document
Show all 13

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Please wait...

If this message is not eventually replaced by the proper contents of the document, your PDF viewer may not be able to display this type of document.

You can upgrade to the latest version of Adobe Reader for Windows®, Mac, or Linux® by visiting http://www.adobe.com/go/reader_download.

For more assistance with Adobe Reader visit http://www.adobe.com/go/acrreader.

Windows is either a registered trademark or a trademark of Microsoft Corporation in the United States and/or other countries. Mac is a trademark of Apple Inc., registered in the United States and other countries. Linux is the registered trademark of Linus Torvalds in the U.S. and other countries.

DRAFT

SAMPLE

PREVIOUS EDITION IS OBSOLETE.

Page of

DD FORM 254, APR 2018

NEEDS DD67

DEPARTMENT OF DEFENSE

CONTRACT SECURITY CLASSIFICATION SPECIFICATION

(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)

OMB No. 0704-0567 OMB approval expires:

June 30, 2025 The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.

RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.

1. CLEARANCE AND SAFEGUARDING

2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)

3. THIS SPECIFICATION IS: (X and complete as applicable.)

a. ORIGINAL (Complete date in all cases.)

b. REVISED (Supersedes all previous specifications.)

4. IS THIS A FOLLOW-ON CONTRACT?

If yes, complete the following:

Classified material received or generated under

5. IS THIS A FINAL DD FORM 254?

If yes, complete the following:

6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)

7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor)

8. ACTUAL PERFORMANCE (Click button to add more locations.)

10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)

e. NATIONAL INTELLIGENCE INFORMATION:

11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)

12. PUBLIC RELEASE

Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)

13. SECURITY GUIDANCE

The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.

(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)

List of Attachments (All Files Must be attached Prior to Signing, i.e., for any digital signature on the form)

14. ADDITIONAL SECURITY REQUIREMENTS

Requirements, in addition to NISPOM requirements for classified information, are established for this contract.

If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)

15. INSPECTIONS

Elements of this contract are outside the inspection responsibility of the CSO.

If Yes, explain and identify specific areas and government activity responsible for inspections. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)

16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)

17. CERTIFICATION AND SIGNATURES

Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below. Upon digitally signing Item 17h, no changes can be made as the form will be locked.

18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL

9.0.0.2.20120627.2.874785 DD 254, "DoD Contract Security Classification Specification"

CurrentPage:
PageCount:
Select classification from drop-down list.: Unclassified
Enter serial number.: FA8307-24-C
a. Facility clearance level. Select one.: 2
b. Level of safeguarding for classified information/material required at contractor facility. Select one.: 4
Select for "original.": 1
Select for "original.": 1
Enter prime contract number.: FA8307-24-C
Select for "revised.": 0
Select for "revised.": 0
Enter subcontract number.:
Select for "final.": 0
Select for "final.": 0
Enter solicitation or other number.:
Enter due date in format YYYYMMDD.:
Enter date in format YYYYMMDD.:
Enter revision number.:
Enter date in format YYYYMMDD.:
Enter final specification.:
Enter date in format YYYYMMDD.:
Select for "no.": 1
Select for "no.": 1
Select for "no.": 0
Select for "no.": 0
Select for "yes.": 0
Select for "yes.": 0
Select for "yes.": 1
Select for "yes.": 1
Enter preceding contract number.:
Enter contractor's request date in format YYYYMMDD.:
Enter period.:
Enter typed name of certifying official (last, first, middle initial).: NA
Enter typed name of certifying official (last, first, middle initial).: Villarreal, Jennifer
Enter CAGE code of the prime contractor.: NA
Enter CAGE code of the prime contractor.:
Enter CAGE code of the prime contractor.: 3F4Y3
Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: Defense Counter Intelligence & Security Agency

P.O. Box 644 Hanover, MD 21076 Phone: 410-689-2905 Email: dcsa.naesoc.generalmailbox@mail.mil

Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: NA
Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: NA
Select to add row to locations.:
Select to remove last row from locations.:
Select to delete all signatures.:
Enter location(s).: POLAND, Location to be determined by Office of Defense Cooperation
Enter general unclassified description of this procurement.: FMS Case NW-D-OAA Provide Primary and Alternate Communication Security (COMSEC) Manager support of various interoperability programs between the United States and Ukraine Ministry of Defense . In addition, the COMSEC managers will maintain current and future COMSEC equipment (C41 systems). The primary locations for CCI equipment: will be based in Poland.
Select for "a. CONTRACTOR.": 1
Select for "a. CONTRACTOR.": 1
Select for "a. CONTRACTOR.": 1
Select for "f. OTHER AS NECESSARY.": 0
Select for "f. OTHER AS NECESSARY.": 1
Select for "f. OTHER AS NECESSARY.": 0
Select for "b. SUBCONTRACTOR.": 0
Select for "b. SUBCONTRACTOR.": 0
Select for "b. SUBCONTRACTOR.": 0
Select for "g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE TECHNICAL INFORMATION CENTER (DTIC) OR OTHER SECONDARY DISTRIBUTION CENTER.": 0
Select for "g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE TECHNICAL INFORMATION CENTER (DTIC) OR OTHER SECONDARY DISTRIBUTION CENTER.": 0
Select for "c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR.": 0
Select for "c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR.": 0
Select for "c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR.": 1
Select for "h. REQUIRE A COMSEC ACCOUNT.": 1
Select for "h. REQUIRE A COMSEC ACCOUNT.": 1
Select for "d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION.": 0
Select for "d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION.": 0
Select for "d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION.": 1
Select for "i. HAVE A TEMPEST REQUIREMENT.": 0
Select for "i. HAVE A TEMPEST REQUIREMENT.": 0
Select for "e. NATIONAL INTELLIGENCE INFORMATION: - (1) Sensitive Compartmented Information (SCI).": 0
Select for "e. NATIONAL INTELLIGENCE INFORMATION: - (2) Non-SCI.": 0
Select for "j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS.": 1
Select for "j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS.": 1
Select for "k. BE AUTHORIZED TO USE DEFENSE COURIER SERVICE.": 1
Select for "k. BE AUTHORIZED TO USE DEFENSE COURIER SERVICE.": 1
Enter infomration for "other.": SIPRNET
Enter infomration for "other.": AFFARS 5352.204-9000 applies. see BLK 13.
Select for "e. ADMINISTRATIVE CONTRACTING OFFICER.": 0
Select for "e. ADMINISTRATIVE CONTRACTING OFFICER.": 1
Select for "l. RECEIVE, STORE, OR GENERATE CONTROLLED UNCLASSIFIED INFORMATION (CUI). .": 1
Select for "m.OTHER.": 1
Select for "direct.": 0
Select for ": 1
Enter specification for "through".: see block 13
Enter public release authority.: PUBLIC RELEASE MUST BE COORDINATED THROUGH GOVERNMENT PROGRAM OFFICE BEFORE RELEASE
Select to add signature.:
Select to remove last signature.:
text: 32 CFR Part 117, National Industrial Security Program Operating Manual (NISPOM) dated 24 February 2021 applies. Contractors will comply with Risk Management Framework (RMF).

The National Industrial Security Program Operating Manual, DoD 5220.22 (NISPOM), dated February 2006, incorporating Change 2, dated May 18, 2016, applies.

OPSEC GUIDANCE via AFI 10-701, dated 24 July 2019.

Ref Blk 1b: Contractor must obtain SECRET safeguarding capability prior to being provided SECRET information. *Facility will not store classified until facility is cleared to safeguard classified documents.

Ref Blk 8a. Actual Performance. All personnel shall comply with local DoD and National Security Policies as defined and enforced at the place of performance (see block 8). The local Commander has the delegated responsibility to assign “Need to Know” and authorize access to classified information, data, and/or products.

Ref Block 10a/11h: COMSEC information includes accountable or non-accountable COMSEC information and controlled cryptographic items (CCI). Access to COMSEC information is authorized to the prime contractor only. Further release requires prior approval from the owner of the COMSEC information. Lackland Line Managers will provide assistance to identify and obtain a source of COMSEC material support (whether from NSA or Air Force) for the contractor. COMSEC/Cryptologic safeguarding requirements apply. See AFMAN 17-1302-O, Communications Security (COMSEC) Operations for guidance.

Ref Blk 10h. Foreign Government Information (FGI): Access to Foreign Government Information (FGI) by cleared U.S. persons is based on the individuals having a valid need-to-know and a personnel security clearance (interim or final). Foreign Government Information: Any foreign government information (excluding NATO). Foreign Government Information (FGI) is classified information provided to the U.S. by a foreign government, an international organization, or any other element thereof which shall be protected, controlled and safeguarded in accordance with reference (e). (This does not include NATO.) The control and safeguarding requirements for FGI may be modified as required or permitted by a treaty or international agreement or, for other obligations that do not have the legal status of a treaty or international agreement such as a contract), by the responsible National security authority of the originating government.

Ref Blk 10j/11l: The contractor shall comply with DoDI 5200.48, Controlled Unclassified Information, AFI 16-1404 Air Force Information Security Program, Air Force Guidance Memorandum 2020-16-01, Air Force Guidance Memorandum for CUI, 23 July 2020, and DoDM 5400.07-Air Force Manual 33-302, DoD Freedom of Information Act (FOIA) Program. The contractor shall monitor CUI aggregation and compilation based on the potential to generate classified information pursuant to security classification guidance addressing the accumulation of unclassified data or information.

Ref Blk 10k: Program Protection Plan (PPP) will be provided by the Government activity. Network (SIPRNET) is authorized. SIPRNET users shall receive the Air Force North Atlantic Treaty Organization (NATO) Security Awareness Briefing and sign an acknowledgment prior to SIPRNET access. A formal NATO briefing is required when 1) the SIPRNET enclave, or other classified networks, is approved for NATO and no additional security measures are in place to preclude access or 2) Access to NATO information is authorized. Formal NATO briefings shall be accomplished IAW 32 CFR Part 117 section 117.19 (g) (7). Contractor employees who need access to government information technology (IT) assigned to national security positions or required to perform national security duties will be subject to investigation to determine whether they are and will remain reliable, trustworthy, of good conduct and character, and loyal to the United States and whether granting or continuing national security eligibility is clearly consistent with the national interest. IT level positions are defined in DoDM5200.02_AFMAN16-1405, Procedures for the DoD Personnel Security Program (PSP)/Air Force Personnel Security 16-1405, Section 3. Performance of these types of duties require a favorably completed Personnel Security Investigation also known as a trustworthiness determination; they do not result in clearance eligibility.

Ref Blk 11c: Any classified information generated in the performance of this contract shall require the contractor to apply derivative classification and markings consistent with the source material.

Ref Blk 11d. Fabricate, Modify, or Store Classified Hardware: The contractor is required to provide adequate and approved storage for classified hardware or material to the level of (SECRET OR CONFIDENTIAL) which because of size or quantity cannot be safeguarded in an approved storage container.

Ref Blk 11f. Have access to U.S. Classified Information outside the U.S, Puerto Rico, U.S Possessions and Trust Territories: Overseas contractor performance will occur as an intermittent visitor or a visitor group. DCSA is relieved of all security oversight for performance on the installation and overseas performance. Security oversight will be under the cognizance HQ USAFE/IP, HQ PACAF/IP or HQ US Central Command/CCJ2 SSO) for collateral classified performance.

Ref Blk 11j: Have Operations Security (OPSEC) Requirements: OPSEC requirements apply. See State of Work (SOW) for requirements.

Ref Blk 11k: Go to https://www.ustranscom.mil/cmd/associated/dcd/ for Defense Courier Service points of contacts and guidance.

Ref item 11l: The contractor shall comply with DoDI 5200.48, Controlled Unclassified Information, AFI 16-1404 Air Force Information Security Program, Air Force Guidance Memorandum 2020-16-01, Air Force Guidance Memorandum for CUI, 23 July 2020, and DoDM 5400.07-Air Force Manual 33-302, DoD Freedom of Information Act (FOIA) Program. The contractor shall monitor CUI aggregation and compilation based on the potential to generate classified information pursuant to security classification guidance addressing the accumulation of unclassified data or information.

Ref Blk 12: Public Release: Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the NISPOM (DoD 5220.22-M), unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority. The contractor is responsible for obtaining the approval of the GCA prior to release of any information received or generated under the contract, except for certain types of information authorized by the NISPOM. Subcontractors must submit requests for public release through the prime contractor. The prime contractor is responsible for submitting the subcontractor’s request for public release to the GCA public release authority. Contractor is to submit requests through the Contracting Officer for OPSEC Program Manager review and public release authorization. The Contracting Officer will provide contractor with written approval/disapproval. Information requiring AF or DoD-level review will be reviewed by the unit's OPSEC Program Manager or Coordinator who will in-turn forward to the entry-level public affairs office through the AFIMSC Public Affairs Office to the Secretary of the Air Force, Office of Public Affairs, Security and Review Division (SAF/PAX), 1690 Air Force Pentagon, Washington DC 20330-1690. Transmission of public release request via e-mail is not authorized.

Contractor will reference the appropriate security classification guidance when generating or deriving classified material or hardware. All classified information received or generated will be properly stored and handled according to the markings on the material. All classified information received or generated is the property of the U.S. Government. At the termination or expiration of the contract, the U.S. Government will be contacted for proper disposition instructions. Contractor will abide by and shall apply derivative classification and markings governed by the current version of the following security classification guidance: The National Industrial Security Program Operating Manual (NISPOM), February 2006, Incorporating Change 2 May 18, 2016 applies. Prior to declassifying or downgrading information marked with a date or event on the "declassify on" line: The Contractor will confirm the OCA has not extended the classification period by reference to the applicable Security Classification or Declassification Guide or by consulting with the Program Office with the OCA.

1. Responsibilities.

1. Air Force components that originate or are responsible for technical documents must determine their documents’ distribution availability and mark them appropriately before disseminating them. Components are responsible for the proper handling, securing, disseminating, and disposing of scientific and technical information.

1.1. The AFI 61-204 Instruction is based upon DODD 5230.24 and applies to all technical documents. “It also applies to engineering drawings, standards, specifications, technical manuals, blueprints, drawings, plans, instructions, computer software and documentation, photographs, technical orders, databases, and any information that can be used or adapted for use to design, engineer, produce, manufacture, operate, repair, overhaul, or reproduce any military or space equipment or technology concerning that equipment. It applies to any medium that transfers information, including paper, microform, electronic storage, and video recordings.” These technical documents can be defined as”…information that conveys scientific and technical information or information related to experimental, developmental, or engineering works that can be used to define an engineering or manufacturing process or to design, procure, produce, support, maintain, operate, repair or overhaul material. This data may be graphic or delineations in media, such as drawings or photographs, text in specifications or related performance or design type documents or computer printouts. Examples of technical data include research and engineering data, engineering drawings and associated lists, specifications, standards, process sheets, manuals, technical reports, catalog-item identifications, and related information and computer software documentation.

2. Marking Scientific and Technical Documents.

2.1. Mark all scientific and technical documents, whether produced in hard-copy or in digital format that may be disseminated.

2.1.1. Apply the single most appropriate distribution statements. Fill in the reason, the date of determination, and the controlling DoD office. Other changes to these distribution statements are prohibited. NOTE: Distribution statements apply to secondary distribution only; they do not apply to primary distribution from the controlling DoD office. Distribution control markings must be clearly discernable as documents and/or data are opened. Record media casings must also be clearly marked.

3. Dissemination of Scientific and Technical Information.

3.1. Do not disseminate any scientific or technical document, including one in draft or preliminary form that does not have a clearly marked distribution statement.

3.2. Primary dissemination of scientific or technical information must be in accordance with all regulations and instructions applicable to the scope of primary dissemination or the document’s distribution statement, whichever covers the broader audience.

Below is the marking that is to be used for all documents that require STINFO markings.

DISTRIBUTION F: Further dissemination only as directed by AFLCMC/HNCCPF/AFLCMC/HNC or DOD higher authority.

WARNING: This document contains technical data whose export is restricted by the Arms Export Control Act (Title 22, U.S.C Sec 2751 et seq.) or the Export Administration Act of 1979, as amended (Title 50 U.S.C. App. 2401 et seq.). Violators of these export laws are subject to severe criminal penalties. Disseminate in accordance with provisions of DOD Directive 5230.25.

HANDLING AND DESTRUCTION NOTICE: Comply with distribution statement and destroy by any method that will prevent disclosure of contents or reconstruction of the document. (STINFO markings should be located on the title page of the published or drafted document, briefing, drawing, etc. Markings require the following: (1) Distribution Statement, (2) Warning, and (3) Handling and Destruction Notice).

The contractor shall follow the Security Classification Guide (SCG) and all security classification guides of systems/information associated with the program for derivative classification, identification of the level and duration of classification for specific information elements, and public release requirements.

Prior to declassifying or downgrading information marked with a date or event on the "declassify on" line, the Contractor will confirm the Original Classification Authority (OCA) has not extended the classification period by reference to the applicable Security Classification or Declassification Guide, or by consulting with the OCAs Program Office. Contractor will reference the appropriate security classification guidance when generating or deriving classified material or hardware. All classified information received or generated will be properly stored and handled according to the markings on the material. All classified information received or generated is the property of the U.S. Government. At the termination or expiration of the contract, the U.S. Government will be contacted for proper disposition instructions. Contractor will abide by and shall apply derivative classification and markings governed by the current version of the following security classification guidance.

The Contractor shall distribute controlled unclassified information IAW DoD Instruction 3200.14, Principles and Operational Parameters of the DoD Scientific and Technical Information Program, and DoD Instruction 2040.02, International Transfer of Technology, Articles, and Services. The Contractor shall properly mark all such documents IAW DoD Instruction 5230.24, Distribution Statements on Technical Documents. Technical documents not subject to distribution are defined in DoD Instruction 5230.24, DoD Directive 5230.25, and DoD Manual 5010.12-M, Procedures for the Acquisition and Management of Technical Data.

The contractor shall identify CPI and Resident CPI (formerly called Critical Technology) which need to be protected. The CPI identified shall be approved by the USG Program Manager. The CPI identification shall include a review of the system, unique integration, support equipment and the Non-Resident design/process/material aspects of the program. All identified CPI shall be protected with appropriate countermeasures. In the case of Resident CPI the use of Anti-Tamper shall be considered and documented in an Anti-Tamper Recommendation Report in accordance with the DAG Chapter 13 and DoDI 5200.39. The contractor shall identify system security engineering requirements in the contractor’s Requirements Management Specification, write Test Plans and accomplish Verification Testing to mitigate protection risks to an appropriate level.

The Contractor will notify the Government Contracting Activity and the Government Security Manager within 24 hours of any incident involving the actual or suspected compromise/loss of classified information to enable the Government to conduct immediate assessment of potential impact pending formal inquiry/investigation. Actual or suspected compromise of Covered Defense Information will be reported IAW DFARS Clause 252.204-7012.

The Contractor shall immediately report a lost or stolen CAC/access control credentials (access badges) as directed by local Government policy. The Contractor shall notify the PCO/COR of any change to the list of contractor/subcontractor personnel who require a CAC and provide an updated list within three business days. The Contractor shall return a CAC/access control credentials (access badges) once determined the contractor/subcontractor personnel no longer require computer network/system access and/or facility access. The Contractor shall return an expired CAC to the government COR no-later-than close of business on the expiration date. The Contractor shall return an expired CAC to the government COR no-later-than close of business on the expiration date.

The contractor shall comply with DoDM 5400.07/Air Force Manual 33-302, DoD Freedom of Information Act (FOIA) Program requirements. Protection of unclassified DoD information not approved for public release on non-DoD Information Systems will be protected IAW DoDI 8582.01, Security of Unclassified DoD Information on non-DoD Information Systems.

- Program Manager/COR - BATTEN, ROGER

Applicable FARS and DFARS Clauses FARS and DFARS Clauses required to be put into the contract: FAR Clause 52.204-2 Security Requirements This clause applies to the extent that the contract involves access to information classified Confidential, Secret, or Top Secret. The clause is related to compliance with the National Industrial Security Program Operating Manual (NISPOM) and any revision to the manual for which notice has been furnished to a contractor FAR Clause 52.204-21 Basic Safeguarding of Covered Contractor Information This clause applies to information not intended for public release that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government, but not including information provided by the Government to the public (such as on public websites) or simple transactional information, such as necessary to process payments. DFARS Clause 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting –(This is required for all Solicitations and Contracts) This clause requires a company to safeguard CDI, as defined in the clause, and to report to the DoD the possible exfiltration, manipulation, or other loss or compromise of unclassified CDI: or other activities that allow unauthorized access to the contractor’s unclassified information system on which unclassified CDI is resident or transiting. The company must submit the malware to DoD if the company is able to isolate it and send it safely. DFARS Clause 252.204-7000 Disclosure of Information This cause prohibits the contractor from releasing any unclassified information pertaining to the contract or any program related to the contract, unless they have CO approval or the information is in the public domain before the date of release. DFARS Clause 252.204-7008 Compliance with Safeguarding Covered Defense Information Controls (Only required in all Solicitations) This clause requires contractors and subcontractors to safeguard covered defense information that resides in or transmits through covered contractor information systems by applying specified network security controls as identified in NISTSP 800-171 DFARS Clause 252.204.7009 Limitations on the Use or Disclosure of Third-Party Contractor Reported Cyber Incident Information (This is required in all Solicitations and Contracts) This clause is required for contractor services that include support for the Government’s activities related to safeguarding covered defense information and cyber incident reporting.

text: AFLCMC/HNCCPF

COR

text: AFLCMC/HNCCPF

CHIEF, FMS

text: AFLCMC/HNC-DOS

INDUSTRIAL/OPSEC

text: AFLCMC/EXSP

INFORMATION PROTECTIONS

text: AFLCMC/INHS

SSO

Click on this button to attach a file(s).:
rep: BATTEN, ROGER

AFLCMC/HNCCPF

rep: MOORE, TANESHA

AFLCMC/HNCCPF

rep: WALKER, KIMALA A

AFLCMC/HNC-DOS

rep: MCCASLIN, SEAN

AFLCMC/EZSP (IP)

rep: CEROVAC, DARLENE

AFLCMC/INHS

Enter signature.:
Explain and identify specific areas and government activity responsible for inspections.: REF BLCK 11J: OPSEC Requirements apply. see Performance Work Statement (PWS for requirements)
Explain and identify specific areas and government activity responsible for inspections.: Ref Blk 11f: Contractor performance will occur at. The overseas contractor performance will occur as a visitor group at Office Defense Partnership, Embassy of the United States, Kyiv, Ukraine. The DSCA is relieved of all security oversight for performance on the installation and overseas performance. HQ US EUCOM/CCJ2 SSO-USEUCOM will maintain security oversight.
Enter GCA name.: AFLCMC/HNCKA
Enter AAC of the contracting office.: FA8307
Enter AAC of the contracting office.: FA8307
Enter address (include zip code).: 410 N. Frank Luke Dr.

Bldg 1530 San Antonio, TX 78226-1810 Enter address (include zip code).: 410 N. Frank Luke Dr.

Bldg 1530 San Antonio, TX

Enter POC name.: Jennifer Villarreal
Enter telephone number (include area code).: 2109250743
Enter telephone number (include area code).: 2109250743
Enter email address.: jennifer.villarreal.4@us.af.mil
Enter email address.: jennifer.villarreal.4@us.af.mil
Enter title.: Contracting Officer
Enter the datesigned in format YYYYMMDD.:

File details come from the government source that posted it. Updated .