Attachment 2 OPSEC Plan.pdf
PDF 656 KB Posted
- Attached to
- OEM Tech Rep Services for Emergency Diesel Generator Federal contract opportunity
- Solicitation number
- N4215826QB506
About this file
This is a blank Operations Security (OPSEC) Plan template for contractors performing work at Norfolk Naval Shipyard (NNSY). The form serves as a required document that contractors must complete and submit to the assigned contracting official prior to contract award, signed by the Prime contractor through encrypted email, Department of Defense Secure Access File Exchange (SAFE), or United States Postal Service.
The plan establishes minimum OPSEC requirements applicable to all contractors and subcontractors conducting sensitive work—whether classified or unclassified—at NNSY. Contractors must identify and protect Critical Information (CI), which includes Naval Nuclear Propulsion Information (NNPI), unclassified naval nuclear information, Personal Identifiable Information (PII), production schedules, vessel modifications, and deployment frequencies. Key compliance requirements include: prohibiting removal of classified or unclassified NNPI materials without written approval from the Command Security Manager; restricting posting of sensitive information to websites or social media; safeguarding government-issued badges and identification; properly destroying classified documents using NSA-approved shredders; and refraining from removing badges, passes, and keys from NNSY premises. Contractors must complete Cyber Awareness and OPSEC training and provide certificates prior to arrival. The plan prohibits personal photography in Controlled Industrial Areas and restricts personal electronic devices (including cameras, recording devices, and cellular phones) unless prior authorized. Contractors must immediately report any compromise of CI or attempts by unauthorized parties to obtain sensitive information to the Command Security Manager or Naval Criminal Investigation Service. Non-disclosure requirements remain in effect indefinitely after contract completion. The Prime Contractor Point of Contact must sign the plan acknowledging that all contractors and subcontractors will review and comply with the guidance outlined.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachment 1 Statement of Work.pdf | ||
| Combined Synopsis and Solicitation.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Enclosure (3)
Norfolk Naval Shipyard Operations Security (OPSEC) Plan for Contractors
Tracking Number
Print Clearly
1. NAME OF CONTRACTOR COMPANY
2. CONTRACTOR COMPANY ADDRESS
3a. NAME OF NNSY REQUESTING ACTIVITY REPRESENTATIVE 3b. CODE 3c. IP NUMBER
4. TODAY’S DATE 5. PERFORMANCE START DATE 6. PERFORMANCE END DATE
OPSEC Statement
This OPSEC plan is used to record, identify and monitor the contractor’s OPSEC activities during the performance of this contract. After award but prior to availability start date, this OPSEC plan must be signed by the Prime contractor and forwarded to the assigned contracting official by encrypted email, through the approved Department of Defense Safe (DoD) Secure Access File Exchange (SAFE) at https://safe.apps.mil, or by United States Postal Service. THIS FORM
SHALL BE PROTECTED FROM PUBLIC RELEASE.
Distribution and Warning Statement
Federal Employees and Contractors Only: Distribution authorized to DoD and DoD US contractors only for Operations Security. Includes individuals or employees who enter into a contract with the U.S. Government to perform a specific job, supply labor and materials, or for the sale of products and services, so long as dissemination is in furtherance of the contractual purpose.
Warning: This document may contain technical data whose export is restricted by the Arms Export Control Act (Title 22, U.S.C., Sec 2751 et seq.) or Executive Order 12470. Violation of these export laws is subject to severe criminal penalties.
Controlled Unclassified Information (CUI) - The information contained in this document and any accompanying attachments may contain information which is protected from mandatory disclosure under the Freedom of Information Act (FOIA), 5 U.S.C. 552.1.
References
- DoDM 5205.02, Operations Security Program Manual, 3 November 2008
Controlled by:
Controlled by:
CUI Category: OPSEC Distribution/Dissemination: FEDCON/PRVCY
POC:
https://safe.apps.mil/
OPSEC Plan for Contractors (cont) Contract Number
OPSEC Requirements All contractors and subcontractors will accomplish the following minimum requirements in support of Norfolk Naval Shipyard (NNSY) OPSEC Program.
1. Applicability. This OPSEC Plan applies to contractors conducting sensitive work whether classified or unclassified onboard NNSY.
2. OPSEC Process. OPSEC is a process used to protect sensitive information from exploitation by an adversary.
Sensitive information, which is also referred to as Critical Information (CI) is defined as information that needs to be protected from unauthorized disclosure.
3. What is CI? CI is sensitive information whether classified or unclassified which must be protected from loss to keep an adversary from gaining a significant operational, economic, political or technological advantage and prevent adverse impact on the Shipyard’s mission accomplishments.
4. The OPSEC process is most effective when fully integrated into all planning and operational processes. The OPSEC process involves five steps:
(a) Identify CI – Determine what information must be protected? Why do you want to protect it?
(b) Analyze the Threat – Who wants it, who is your adversary?
(c) Analyze Vulnerabilities – How can an adversary obtain this information? How can we protect it?
(d) Assess the Risk – How will this impact your mission if exploited?
(e) Apply countermeasures – Reduce your weaknesses. Ensure to follow procedures that are in place.
5. Adherence to this OPSEC Plan is the responsibility of the Prime contractor.
a. The Prime contractor will coordinate the implementation of training, administration, and execution and ensure all procedures identified in this plan are followed.
b. All contractors and subcontractors are responsible for the successful implementation of this plan.
c. NNSY Security will aid the supporting contracting company in the development, implementation, and compliance with security procedures established in this OPSEC plan.
d. Contractor personnel assigned to this contract shall utilize this plan to protect all CI.
Job description
CONTRACT OBJECTIVE. Place a brief description of job procurement or job work below. This includes unclassified work.
- If the contract requires access to classified information or material, detailed security requirements shall be in accordance with DD Form 254. Refer to block 9 of the DD 254 for job work.
e.g. The specific objective of this contractual effort is to provide NNSY with _____________________________
Contract Number
Compliance on what sensitive information to protect (but not limited to)
During the period of this contract, contractor personnel may be exposed to, use, or produce, U.S. Government CI and observables indicators which may lead to disclosure of CI. Paragraphs in this section shall be controlled and will not be distributed to unauthorized third parties, including foreign governments, or Foreign Ownership, Control, or Influence (FOCI) companies.
a. No classified or unclassified Naval Nuclear Propulsion Information (NNPI) material will be removed from any shipyard space or ships in the performance of this contract unless approved in writing by the NNSY Command Security Manager (CSM). Description, drawings, technical papers, components, or equipment designed specifically for specialized production must be controlled and safeguarded at all times. This also includes names and personal information, including Personal Identifiable Information (PII) of company and government employees.
b. The Contractor shall not post classified information or CUI (to include Unclassified Naval Nuclear Information (U-NNPI)) to company websites, publications, newsletters or other media, any images, data or information that reveal sensitive government operations, personnel, or equipment details. In addition, tactics, techniques and procedures; production or work schedules; any visible or concealed modifications, upgrades, additions to vessels, weapons or equipment; increases, changes, or decreases in work or deployment frequency, and vessel movements.
c. The Contractor and its personnel shall not divulge any information about files, data processing activities or functions on public social media sites or to personnel who do not have a need to know.
d. Government issued badges, identification shall be removed and/or concealed from plain sight when off NNSY and shall not be left in vehicles or unprotected. Badges and passes may not be duplicated, copied or loaned to others. Lost or stolen identification badges, vehicle passes, etc., will be immediately reported to requiring representative, Industrial Security Office or the Base Police Department. (Upon completion of this contract, the Contractor and all assigned to this contract will return all access badges, passes, and keys before leaving NNSY premises).
Countermeasures on how to protect sensitive information (but not limited to)
The Contractor shall protect all CI as stated throughout this plan in a manner appropriate to the nature of the information.
a. Practice OPSEC and maintain Security Awareness at all times.
b. Restricting verbal discussion of CI to venues and circumstances that prevent the monitoring and interception of the discussion by unauthorized personnel.
c. The Contractor may work with internal production schedules, deliverables, and inventories. The Contractor shall safeguard this information from disclosure, inadvertent or otherwise, from unauthorized recipients.
d. Immediately and appropriately, destroy all CI no longer needed under this contract requirement. Documents will be destroyed via National Security Agency approved product listed crosscut shredders or disintegrators that are capable of rendering the documents unrecognizable and makes it difficult to reconstruct.
e. Do not throw any shipyard related documents in the trash.
Contract Number
NNSY Portable Electronic Device (PED) Policy
• Personal photography is prohibited at NNSY in the CIA and in designated spaces.
• When operationally required, a written request containing specific justification and details shall be submitted to the NNSY Command Security Manager via the Government Contracting Activity for consideration.
• Personal electronic devices (PEDs) include, but are not limited to: pagers, mobile/cellular telephones (with/without cameras), personal digital assistants/job performance aids, laptop/notebook/handheld computers, digital imagery (still/video) devices, analog/digital sound recorders (e.g. I-PODs), Fit-Bits, I-Watches, video game devices, USB devices, and devices of similar capability, functionality, or design. These devices are controlled and their use is dependent upon Shipyard guidance. Before use, coordinate with your sponsor, who can assist you by obtaining and sharing these requirements/controls with you. It is expected that if additional guidance is needed, the sponsor will coordinate with NNSY Computer Security division and determine what can be used and what is prohibited. Failure to do so risks security violations for the holder of the device.
• Contractor personnel shall not share written content, take photographs, or make any recordings (audio, visual digital) in the performance of this contract unless approved in writing by the NNSY ISSM and/or the NNSY Command Security Manager.
• Contractor personnel shall not enter NNSY spaces, Controlled Industrial Area (CIA), Controlled Nuclear Information Area (CNIA), or Nuclear Work Areas (NWA) or any other restricted area with personal electronic devices, laptops, tablet PCs, cellular phones, cameras, recording devices, and data recording/storage devices, unless prior authorized.
Computer Network Use
Contractor may request access to NNSY information systems based on the requirement of the contract. Contractor employees must successfully complete Cyber Awareness and OPSEC training, and submit with their information system access request. Ensure you provide training certificates to your shipyard sponsor.
Cyber Awareness – https://public.cyber.mil/training/cyber-awareness-challenge/ OPSEC – https://securityawareness.usalearning.gov/opsec/index.htm
CUI Requirements for Contractors
This paragraph highlights requirements for contractors.
a. Contractors involved with CUI in pursuant to contractual requirements must:
Complete CUI training prior to arrival. Certificates must be provided to the OPSEC PM prior to arrival. https://www.dodcui.mil/home/training.
Compromise – Unauthorized Disclosure
OPSEC compromise is the disclosure of CI or sensitive information that has been identified by the Command and any higher headquarters that jeopardizes the unit's ability to execute its mission or to adequately protect its personnel and equipment. The Contractor and all subcontractors under this contract will understand the following:
https://dl.dod.cyber.mil/wp-content/uploads/trn/online/cyber-awareness-challenge-2021/index.html https://securityawareness.usalearning.gov/opsec/index.htm https://www.dodcui.mil/home/training https://public.cyber.mil/training/cyber-awareness-challenge/
Contract Number ___________
a. The Contractor and its personnel shall realize that disclosure or compromise of CI to unauthorized persons, whether willfully or through gross negligence, carelessness, or indiscretion, may warrant action to remove the individual assigned or to terminate contract.
b. Contractor and its personnel can be used for the purpose of conducting any investigation of alleged misconduct, which may, in the opinion of the Contracting Officer, jeopardize the security of the project. Whenever there is probable cause to believe that such action is warranted in the interest of national security.
c. Any attempt by unauthorized third parties to solicit, obtain, photograph or record, or incidents of loss or compromise of government CI related to this contract shall be immediately reported to the CSM or the Naval Criminal Investigation Service (NCIS).
d. Non-Disclosure requirements remain in effect during the duration of this contract and indefinitely thereafter.
Prime Contractor Concurrence
A determination to request access and conduct work for NNSY is a matter of inherent command authority and is not at the discretion of the NNSY Contracting Officer or Requiring Activity Representative.
a. Contractors shall not have access to sensitive information unless it is required for them to accomplish the tasks required in the contract.
b. The Prime contractor must submit this signed OPSEC Security Plan prior to contract award.
c. The Contractor and subcontractors shall ensure that its personnel supporting NNSY and will comply with all measures outlined in this plan.
d. The Contractor shall institute and implement all effective OPSEC measures to prevent any violations by its employees and subcontractors.
e. The Prime Contractor will be responsible for the identification and protection of the identity of personnel working in support of this mission. This includes all contractors and subcontractors names, addresses and other contact information.
f. The Prime Contractor POC must sign the bottom of this plan stating, “Contractor and all subcontractors under this contract will review this document and will become familiar with the guidance detailed in this plan and the OPSEC process.”
PRIME CONTRACTOR POC
a. NAME b. SIGNATURE
c. EMAIL d. PHONE
e. TITLE
| Tracking Number: |
| 1 NAME OF CONTRACTOR COMPANY: |
| 2 CONTRACTOR COMPANY ADDRESS: |
| 3a NAME OF NNSY REQUESTING ACTIVITY REPRESENTATIVE: |
| 3b CODE: |
| 3c IP NUMBER: |
| 4 TODAYS DATE: |
| 5 PERFORMANCE START DATE: |
| 6 PERFORMANCE END DATE: |
| DoDM 520502 Operations Security Program Manual 3 November 2008Row1: |
| Controlled by Controlled by CUI Category OPSEC DistributionDissemination FEDCONPRVCY POC: |
| OPSEC Plan for Contractors cont Contract Number: |
| undefined: |
| undefined_2: |
| eg The specific objective of this contractual effort is to provide NNSY with 1: |
| eg The specific objective of this contractual effort is to provide NNSY with 2: |
| OPSEC Plan for Contractors cont Contract Number_2: |
| undefined_3: |
| OPSEC Plan for Contractors cont Contract Number_3: |
| undefined_4: |
| OPSEC Plan for Contractors cont Contract Number_4: |
| PRIME CONTRACTOR POC: |
| a NAME: |
| b SIGNATURE: |
| c EMAIL: |
| d PHONE: |
| e TITLE: |
| BLANK FORM: [BLANK FORM ] |
File details come from the government source that posted it. Updated .