Attachment 2 - OSP-4 RFP DD-254.pdf
PDF 526 KB Posted
- Attached to
- Orbital Services Program-4 (OSP-4) On-Ramp #2 Federal contract opportunity
- Solicitation number
- FA8818-24-R-B003
About this file
This document is a request for proposal for the Orbital Services Program-4 On-Ramp #2 multiple award indefinite delivery/indefinite quantity contract. The Space Systems Command Launch Enterprise seeks to expand the current vendor pool through this solicitation to provide flexible small launch capability using small launch vehicles and targets. Offerors will be awarded a basic contract and all qualifying offerors will receive a $50,000 task order to develop a Launch Service User Guide Study. There is no small business set-aside but responses from small and small disadvantaged businesses are encouraged. Interested parties can request access to the program's bidder's library which provides relevant guidance documents by contacting specified points of contact and including company information. Foreign firms will not be allowed to participate as prime contractors. The North American Industry Classification System code for this effort is 481212 and the small business size standard is 1,500 employees.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Minimum Award LSUG SOW- On-Ramp 2 05 Aug 2021.pdf | ||
| Attachment 3 - Instructions to Offerors (15Mar24).pdf | ||
| OSP-4 E CDRL - On-Ramp 2.pdf | ||
| OSP-4 B CDRL - On-Ramp 2.pdf | ||
| OSP-4 C CDRL - On-Ramp 2.pdf | ||
| OSP-4 F CDRL - On-Ramp 2.pdf | ||
| Attachment 4 - Evaluation Criteria (15Mar24).pdf | ||
| OSP-4 A CDRL - On-Ramp 2.pdf | ||
| Attachment 1 - Performance Work Statement (PWS) - Rev3.pdf | ||
| Attachment 5 Ordering Guide Rev3.pdf | ||
| OSP-4 D CDRL - On-Ramp 2.pdf | ||
| Min Award LSUG Model Contract_Solicitation - FA881824RB004.pdf | ||
| Minimum Award LSUG SOW.pdf | ||
| OSP-4 Model Contract_Solicitation - FA881824RB003.pdf |
Show all 14
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
CLASSIFICATION (When filled in): Unclassified
FA8818-24-R-B003
PREVIOUS EDITION IS OBSOLETE. Page 1 of 9DD FORM 254, APR 2018
DEPARTMENT OF DEFENSE
CONTRACT SECURITY CLASSIFICATION SPECIFICATION
(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)
OMB No. 0704-0567 OMB approval expires:
June 30, 2025
The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.
RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.
1. CLEARANCE AND SAFEGUARDING
a. LEVEL OF FACILITY SECURITY CLEARANCE (FCL) REQUIRED (See Instructions)
Secret
b. LEVEL OF SAFEGUARDING FOR CLASSIFIED INFORMATION/
MATERIAL REQUIRED AT CONTRACTOR FACILITY
Secret
2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)
a. PRIME CONTRACT NUMBER (See instructions.)
b. SUBCONTRACT NUMBER
c. SOLICITATION OR OTHER NUMBER
FA8818-24-R-B003
DUE DATE (YYYYMMDD)
3. THIS SPECIFICATION IS: (X and complete as applicable.)
a. ORIGINAL (Complete date in all cases.)
DATE (YYYYMMDD)
b. REVISED (Supersedes all previous specifications.)
REVISION NO. DATE (YYYYMMDD)
c. FINAL (Complete Item 5 in all cases.) DATE (YYYYMMDD)
4. IS THIS A FOLLOW-ON CONTRACT? No Yes If yes, complete the following:
Classified material received or generated under (Preceding Contract Number) is transferred to this follow-on contract.
5. IS THIS A FINAL DD FORM 254? No Yes If yes, complete the following:
In response to the contractor's request dated , retention of the classified material is authorized for the period of:
6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)
a. NAME, ADDRESS, AND ZIP CODE b. CAGE CODE c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)
7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor)
a. NAME, ADDRESS, AND ZIP CODE b. CAGE CODE c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)
8. ACTUAL PERFORMANCE (Click button to add more locations.)
a. LOCATION(S) (For actual performance, see instructions.) b. CAGE CODE (If applicable, see Instructions.)
c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)
9. GENERAL UNCLASSIFIED DESCRIPTION OF THIS PROCUREMENT
Orbital Services Program-4 (OSP-4) provides flexible small launch capability using Spacelift System (SS) designs based on commercial and/ or Government Furnished Property (GFP) motors to meet the customer requirements. The contract supports payloads ranging between 400 lb to low earth orbit (LEO) to approx. 8,000 lb to geostationary transfer orbit (GTO). A key cornerstone of OSP-4's strategy is to utilize a low barrier to entry to establish a large vendor pool consisting of both large and small businesses. Each mission task order will be competitively competed and tailored to customer requirements.
FA8818-24-R-B003
PREVIOUS EDITION IS OBSOLETE. Page 2 of 9DD FORM 254, APR 2018
10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)
a. COMMUNICATIONS SECURITY (COMSEC) INFORMATION f. SPECIAL ACCESS PROGRAM (SAP) INFORMATION
b. RESTRICTED DATA
g. NORTH ATLANTIC TREATY ORGANIZATION
(NATO) INFORMATION
c. CRITICAL NUCLEAR WEAPON DESIGN INFORMATION (CNWDI) (If CNWDI applies, RESTRICTED DATA must also be marked.)
h. FOREIGN GOVERMENT INFORMATION
d. FORMERLY RESTRICTED DATA
i. ALTERNATIVE COMPENSATORY CONTROL MEASURES
(ACCM) INFORMATION
e. NATIONAL INTELLIGENCE INFORMATION:
(1) Sensitive Compartmented Information (SCI)
(2) Non-SCI
j. CONTROLLED UNCLASSIFIED INFORMATION (CUI) (See instructions.)
k. OTHER (Specify) (See instructions.)
11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)
a. HAVE ACCESS TO CLASSIFIED INFORMATION ONLY AT
ANOTHER CONTRACTOR'S FACILITY OR A GOVERNMENT
ACTIVITY
(Applicable only if there is no access or storage required at contractor facility.
See instructions.)
b. RECEIVE AND STORE CLASSIFIED DOCUMENTS ONLY
c. RECEIVE, STORE, AND GENERATE CLASSIFIED
INFORMATION OR MATERIAL
d. FABRICATE, MODIFY, OR STORE CLASSIFIED HARDWARE
e. PERFORM SERVICES ONLY
f. HAVE ACCESS TO U.S. CLASSIFIED INFORMATION OUTSIDE
THE U.S.,PUERTO RICO, U.S. POSSESSIONS AND TRUST
TERRITORIES
g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE
TECHNICAL INFORMATION CENTER (DTIC) OR OTHER
SECONDARY DISTRIBUTION CENTER
h. REQUIRE A COMSEC ACCOUNT
i. HAVE A TEMPEST REQUIREMENT
j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS
k. BE AUTHORIZED TO USE DEFENSE COURIER SERVICE
l. RECEIVE, STORE, OR GENERATE CONTROLLED UNCLASSIFIED
INFORMATION (CUI).
(DoD Components: refer to DoDI 5200.48, only for specific CUI protection requirements. Non-DoD Components: see instructions.)
m. OTHER (Specify) (See instructions.)
12. PUBLIC RELEASE
Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority.
Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)
DIRECT THROUGH (Specify below)
SSC/AATS (Security) SSC.le.securityworkflow@spaceforce.mil 483 N. Aviation Blvd, El Segundo, CA 90245
Public Release Authority:
SSC/PA, (Public Affairs) SSC.PA@spaceforce.mil, 310-652-1131 483 N. Aviation Blvd, El Segundo, CA 90245
13. SECURITY GUIDANCE
The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract;
and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.
(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)
Contractor(s) will not be afforded access to classified information at any level (i.e. Confidential, Secret, or Top Secret) until the Defense Counterintelligence and Security Agency (DCSA) grants a interim Facility Security Clearance (FCL) at the appropriate level.
FAR 52.204-2 Security Requirements. Security Requirements Clause: (a) This clause applies to the extent that this contract involves access to information classified up to “Secret” (b) The Contractor shall comply with (1)The Security Agreement (DD Form 441/DD Form 254), including 32 Code of Federal Regulation (CFR) Part 117, National Industrial Security Program Operating Manual (NISPOM); and (2) Any revisions to that manual, notice of which has been furnished to the Contractor. (c) If, subsequent to the date of this contract, the security classification or security requirements under this contract are changed by the Government and if the changes cause an increase or decrease in security costs or otherwise affect any other term or condition of this contract, the contract shall be subject to an equitable adjustment as if the changes were directed under the Changes clause of this contract. (d) The Contractor agrees to insert terms that conform substantially to the language of this clause, including this paragraph (d) but excluding any reference to the Changes clause of this contract, in all subcontracts under this contract that involve access to classified information.
FA8818-24-R-B003
PREVIOUS EDITION IS OBSOLETE. Page 3 of 9DD FORM 254, APR 2018
By signing this form, the requesting Government program office and the servicing Contractor (or Subcontractor) verify that the stated access requests on this form are based on legitimate and bona fide need(s)/requirement(s) of the Government.
General Security - Space Systems Command, Assured Access To Space (SSC/AATS) has determined that performance of this contract requires that the contractor, subcontractor(s), vendor(s), etc. (herein known as contractor), requires access to classified National Security Information (herein known as classified information). Classified information is Government information which requires protection in accordance with Executive Order 13526, Classified National Security Information, and supplementing directives.
The Contractor shall abide by the requirements set forth in the DD Form 254, Contract Security Classification Specification, Included in the contract, and the 32 Code of Federal Regulation (CFR) Part 117, National Industrial Security Program Operating Manual (NISPOM) for the protection of classified information at its cleared facility if applicable, as directed by the Defense Counterintelligence and Security Agency (DCSA).
Any firm or business under contract with the Air Force (AF), which requires access to classified information, will require a facility security clearance commensurate with the level of access required. Firms that do not possess a facility clearance, or the requisite level of facility clearance, will be sponsored for a Department of Defense facility clearance.
For access to classified information contractor will ensure all required actions IAW 32 Code of Federal Regulation (CFR) Part 117, National Industrial Security Program Operating Manual (NISPOM) are completed for personnel working on this contract. Interim clearances are authorized except when the contractor will require NATO and COMSEC access, where a finalized security clearance is required. Security clearances are in accordance with the 32 Code of Federal Regulation (CFR) Part 117, National Industrial Security Program Operating Manual (NISPOM). Access to SCI will be in accordance with the current SCI addendum and DOD Manual 5105.21 Volumes 1-3 for SCI management.
This is also applicable to Contractor and Subcontractor personnel who are visiting or on a temporary duty assignment at the NSSL launch sites. This requirement is for personnel who have or may need access to launch site restricted or controlled areas containing (NSSL) National Security Space Launch and/or Information Systems, which directly affect a launch system. Alternate Personnel Security determinations (when applicable) must be appropriately authorized in the DAFI31-101_SSCSUP_DAFGM2021-1 supplement and validated/approved.
Security Management -The contractor shall appoint a senior official to act as the Facility Security Officer. The individual will interface with SSC/AA security on all security matters, to include physical, personnel, industrial, information, program protection and cybersecurity and will protect all Government information and data accessed by the Contractor.
Contractor employees who become eligible for access to classified National Security Information shall receive annual refresher training in accordance with the 32 Code of Federal Regulation (CFR) Part 117, National Industrial Security Program Operating Manual (NISPOM).
In the event classified information is inadvertently received by a contractor who does not hold an active security clearance at the appropriate level, a Government employee or Contractor with the appropriate security clearance equal to or higher than the classified information received, will take possession of the material and shall safeguard and store the information in accordance with standards set forth in the 32 Code of Federal Regulation (CFR) Part 117, National Industrial Security Program Operating Manual (NISPOM). The inadvertent disclosure will be immediately reported to their supervisor and then to SSC/AA's Security Manager for action as appropriate.
Period of Performance: 10 October 2019 to 9 October 2028
Ref 10a. COMSEC -Classified COMSEC material is not releasable to contractor employees who have not received a FINAL clearance at the appropriate security level. All personnel granted access to COMSEC are required to be familiar with applicable Air Force and specialized COMSEC publications, and Air Force Methods and Procedures Technical Orders (MPTOs), etc. When access is required at Government facilities, contractor personnel will adhere to COMSEC rules and regulations as mandated by Command policy and procedures. Written concurrence of the GCA is required prior to subcontracting. The Prime Contractor should also notify the National Security Agency (NSA) Central Office of Record (COR) before negotiating or awarding subcontracts.
(U) (For Visitor Groups) Contractor will require access to COMSEC information at the on-base locations listed in item 8a. On-base contractors will not require their own COMSEC account. Access will be controlled by 61st Air Base Group (ABG) or host installation.
On-base contractors will protect COMSEC material IAW directives identified by the installation COMSEC Custodian to include Air Force Manual 17-1302-0, Communications Security (COMSEC) Operations. Access to COMSEC material by personnel is restricted to U.S.
citizens holding final U.S. Government clearances.
Reference Block 10b, and 10d: Restricted Data and Formerly Restricted Data.
a. The contractor is permitted access to Restricted Data (RD) and Formerly Restricted Data (FRD) in performance of this contract. Access
FA8818-24-R-B003
PREVIOUS EDITION IS OBSOLETE. Page 4 of 9DD FORM 254, APR 2018 and handling of RD and FRD must comply with the 32 Code of Federal Regulation (CFR) Part 117, National Industrial Security Program Operating Manual (NISPOM) and DoDI 5210.02, Access to and Dissemination of Restricted and Formerly Restricted Data. The Government Program Manager will validate contractor requests for this information on a case-by-case basis. RD/FRD information is not releasable to employees who are not citizens, foreign nationals or those having limited access authorizations. A final government clearance at the appropriate level is required along with a valid Need-To-Know (including documented training) for access to government information/data. These records will be maintained per 32 Code of Federal Regulation (CFR) Part 117, National Industrial Security Program Operating Manual (NISPOM). The Department of Energy (DoE) requires that any contractor requiring access to RD/FRD for the purpose of reviewing, analyzing, and creating new RD/FRD products or material, must complete relevant training.
(1) Restricted Data means all data concerning (a) design, manufacture, or utilization of atomic weapons (b) the production of special nuclear material or (c) the use of special nuclear material in the production of energy, but shall not include data declassified or removed from the Restricted Data category pursuant to Section 142.
(2) Formerly Restricted Data is information which has been removed from the Restricted Data category after the DoE and the DoD have jointly determined that the information relates primarily to the military utilization of atomic weapons and can be adequately safeguarded as National Security Information in the US. Such data may not be given to any other nation except under the terms of an agreement for cooperation.
b. The Atomic Energy Act of 1954, as amended, provides for the development, use, and control of atomic energy. The Act establishes policy for handling atomic energy-related classified information designated as Restricted Data and Formerly Restricted Data. The Act provides responsibility to DoE to "control the dissemination and declassification of Restricted Data". This clause is intended to ensure reasonable conformity in policy and procedures is used by contractors for the control of RD and FRD.
c. In accordance with the Atomic Energy Act, all atomic energy information remains classified unless action is taken to declassify material only by the DoE. No other organization can declassify atomic energy information, and once it is declassified, it cannot be reclassified.
e. DoDI 5210.02, Access to and Dissemination of Restricted Data and Formerly Restricted Data, states that it is DoD policy that access to and dissemination of RD and FRD information within and between DoD components, including DoD contractors, will be governed by the same criteria that governs the access to other classified information, which is contained in DoDI 5210.02, DoDM 5200.01, and 32 Code of Federal Regulation (CFR) Part 117, National Industrial Security Program Operating Manual (NISPOM).
f. Protection requirements for RD/FRD are contained in DoDM 5200.01, Volume 1, DoD Information Security Program, which states that:
Classified information, in the custody of the Department of Defense marked as RD and FRD in accordance with the Atomic Energy Act of 1954, as amended, shall be stored, protected, and destroyed in the same manner as information of a comparable level of security classification Contractor IT systems and networks must be certified and accredited for RD and/or FRD prior to transmission, processing, or storage of such data. RD and FRD must be marked IAW instructions in the 32 Code of Federal Regulation (CFR) Part 117, National Industrial Security Program Operating Manual (NISPOM).
g. The disclosure by a contractor of RD and FRD to foreign governments shall not be permitted until an agreement is signed by the U.S.
and participating government(s) and disclosure guidance and security arrangements have been established.
Ref 10d: Formerly Restricted Data. Access to FRD requires a final U.S. Government clearance at the appropriate level. Written concurrence by the KO is required prior to subcontracting.
Ref 10h – Foreign Government Information. Access to foreign government information may be required in the performance of this contract. The Program Manager will validate contractor requests for FGI on a case-by-case basis. Access to FGI requires a final government clearance at the appropriate level. FGI shall be protected in the same manner as the equivalent U.S. government classified information. Information supplied by or provided to a foreign government(s) shall be handled in accordance with the 32 Code of Federal Regulation (CFR) Part 117, National Industrial Security Program Operating Manual (NISPOM), and DoDM 5200-01 Vol 1-3.
Ref 10j. Controlled Unclassified Information (CUI), Controlled Unclassified Information (CUI) is the term which collectively refers to For Official Use Only (FOUO), Unclassified Controlled Technical Information (UCTI), Unclassified Controlled Nuclear Information (UCNI) and many other designations. CUI information generated and/or provided under this contract shall be managed and safeguarded IAW DoDI 5200.48, Controlled Unclassified Information, which supersedes DoDM 5200.01, Volume 4, DoD Information Security Program: DoDI
5200.48 DAFI 16-1403 Controlled Unclassified Information Implementation Guidance applies to arrangements, agreements, contract, and other transaction authority actions requiring access to Controlled Unclassified Information according to terms and conditions of such documents, as defined in Clause 2.101 of the Federal Acquisition Regulation and Section 2002.4 of Title 32, CFR, including but not limited to, grants, licenses, certificates, memoranda of agreement’/arrangement or understanding, and information-sharing agreements or arrangements.
AFGM2021-16-01 supersedes sections of Air Force Instruction (AFI) 16-1404, Air Force Information Security Program, where the designation For Official Use Only (FOUO) is referenced. See Block 11l for Information Systems protection guidance.
FA8818-24-R-B003
PREVIOUS EDITION IS OBSOLETE. Page 5 of 9DD FORM 254, APR 2018
All CUI must be controlled until authorized for public release in accordance with DoDIs 5230.09, Clearance of DoD Information for Public Release, 5230.29, Security and Policy Review of DoD Information for Public Release, DoDM 5400.07, DoD Freedom of Information Act (FOIA) Program, and DoDM 5205.07-V1, DoD SAP Security Manual: General Procedures.
Support to Controlled Unclassified Information (CUI) portions of work on a lawful government contract may be accomplished by individuals without a security clearance needing to access CUI. No individual may have access to CUI unless it is determined that the individual has an authorized, lawful government purpose. The individual with authorized possession, knowledge, or control of CUI will determine whether an individual has an authorized, lawful government purpose to access designated CUI. CUI does not include information lawfully and publically available without restrictions. CUI requires safeguarding measures identified by the necessary law, regulation, or government wide policy with which it is associated.
Reference security requirements of NIST SP 800-171, they must use the NIST SP 800-171A procedures to evaluate the effectiveness of the tested controls. NIST SP 800-171A is the primary and authoritative guidance on assessing compliance with NIST SP 800-171.
Ref 11c. Receive, Store, and Generate Classified Information or material - The contractor requires access to classified source data up to and including Top Secret in support of the work effort. Any extracts or use of such data requires the contractor to apply derivative classifications and markings consistent with the source documents. Use of "Multiple Sources" on the "Derived From" line necessitates compliance with the 32 CFR 117.13(c)(3).
Ref 11d. Fabricate, modify, or store classified Hardware - The Contractor is required to provide adequate storage for classified hardware up to and including the level indicated in block lb. If the hardware is such a size and/or quantity that it cannot be safeguarded in an approved storage container, the use of an approved 'Closed Area' will be required. Contractors will provide the extent of protection to classified information sufficient to reasonably protect it from loss or compromise IAW 32 CFR Part 117 and DoDM5220.22v2_AFMAN16-1406v2
Ref 11g. Authorized to Use the Services of Defense Technical Information Center (DTIC) Access to DTIC can be requested through the DD Form 1540, Registration for Scientific and Technical Information Services or online at: http://www.dtic.mil/dtic/registration/ registration.html The contractor may access information provided by DTIC by complying with all established safeguards and following the registration procedures as set forth in the 32 Code of Federal Regulation (CFR) Part 117, National Industrial Security Program Operating Manual (NISPOM).
Ref 11h. Require a COMSEC Account - A COMSEC account must be established when accountable COMSEC material is to be provided, acquired, or produced under a contract. The GCA will inform the contractor that a COMSEC account is required.
(On-base contractors) The contractor will be required to establish and maintain a COMSEC user account following the procedures and requirements contained in Committee on National Security Systems (CNSS) Policy No. 3, National Policy for Granting Access to U.S.
Classified Cryptographic Information and AFMAN 17-1302-0, Communications Security (COMSEC) Operations, the 32 Code of Federal Regulation (CFR) Part 117, National Industrial Security Program Operating Manual (NISPOM), installation COMSEC account procedures and/or NSA Policy Manual No. 3-16.
(Off-base contractors) NSA account will be established for and maintained by contractor IAW Committee on National Security Systems (CNSS) Policy No. 3, National Policy for Granting Access to U.S. Classified Cryptographic Information. The Contractor will comply with the additional security requirements and the management of NSA information/ material as defined in the manual.
Ref 11j. Have OPSEC Requirements - The contractor shall accomplish the following minimum requirements in support of the SSC/AATS Operations Security (OPSEC) Program.
a. The contractor shall protect activities that warrant OPSEC to include but are not limited to research, development, analysis, test and evaluation; acquisitions; treaty verification; nonproliferation protocols; international agreements; force protection operations; special access programs; and activities that prepare, sustain, or employ Military Services over the range of military operations.
b. The contractor shall protect sensitive unclassified information and activities, which could compromise classified information or operations, or degrade the planning and execution of military operations performed by the contractor in support of the mission. Sensitive unclassified information is that information marked For Official Use Only (FOUO), Controlled Unclassified Information (CUI), Privacy Act (PA) Of 1974, Company Proprietary, and as identified by the government program office and program manager, and SSC/AATS OPSEC Program Manager. OPSEC is essential to defense activities that may be compromised whenever open sources and detectable activities provide information that when compiled or analyzed is a detriment to U.S. interests.
c. Compliance with security requirements imposed by documents generated in response to DoDI 5200.39, Critical Program Information
(f) Identification and Protection within Research, Development, Test and Evaluation (RDT&E).
d. The contractor shall comply with the NSSL OPSEC Plan, and apply protective measures therein. Research and Development
FA8818-24-R-B003
PREVIOUS EDITION IS OBSOLETE. Page 6 of 9DD FORM 254, APR 2018 contractors (off-base) shall develop an OPSEC Plan in accordance with NSSL OPSEC Plan, AFI 10-701, and DoDM 5205.2 as identified by the government program office, Program Manager, and the SSC/AA OPSEC Program Manager. OPSEC shall be a part of ongoing security awareness program conducted in accordance with the National Industrial Security Program Operating Manual.
e. The contractor shall participate in the host installation scheduled annual OPSEC program reviews.
f. The contractor shall protect all unclassified information and activities, which could compromise classified information or operations, or degrade the planning and execution of military operations performed by the contractor in support of the mission. Contractor shall protect Controlled Unclassified Information (CUI), IAW 32 CFR Part 2002 and information identified in the SSC and SSC program office Critical Information List (CIL), IAW AFI 10-701, OPSEC and DoD Operations Security (OPSEC) Program, DoDM 5205.02.
Email transmission of Sensitive Information, Critical Information, and Legacy Information (FOUO), and CUI obtained or produced pursuant to this contract will be encrypted or password protected. If the CUI is in the attachment(s), it must be identified and encrypted.
CUI marking must be included at the top and bottom of each email. Email must also have the CUI Designation Indicator after the sender’s signature block.
g. Destruction of Sensitive Information, Critical Information, Legacy Information (FOUO), and CUI obtained or produced pursuant to this contract shall be in a manner that makes it unreadable, indecipherable, and irrecoverable. Contractor must use any destruction method specifically required by law, regulation, or Government-wide policy for that CUI. If the authority does not specify a destruction method, Contractor must use one of the following methods: Guidance for destruction in NIST SP 800–53: Security and Privacy Controls for Federal Information Systems and Organizations, and NIST SP 800–88, Revision 1: Guidelines for Media Sanitization (incorporated by reference, 32 CFR 2002.2); or any method of destruction approved for Classified National Security Information, as delineated in 32 CFR 2001.47, unless the CUI category's authority mandates other destruction methods (CUI Specified categories). Also, ISOO CUI Notice 2019-03 – “Destroying Controlled Unclassified Information (CUI) in Paper Form, this notice clarifies certain aspects of the requirements for destroying paper CUI. NIST SP 800-88, Revision 1, describes authorized methods for destroying other media types that contain CUI.
Ref 11l. Receive, Store, or Generate Controlled Unclassified Information (CUI) -
Contractor shall apply security controls contained in NIST SP 800-171 for the protection of CUI on non-DoD information systems. CUI information will not be placed on publicly accessible web sites.
Definitions:
Adequate Security - Security commensurate with the risk and the magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of information (see 0MB Circular A-130). Current means of achieving adequate security for Information Technology is to use DoD, CNSS and NIST guidance (see CNSSI No. 4009).
Non-Sensitive Information - Information available in the public domain or DoD information that has been approved for public release.
Sensitive Information - Information, the loss, misuse, or unauthorized access to or modification of, could adversely affect the national interest or the conduct of Federal programs, or the privacy to which individuals are entitled under Section 552a of title 5, United States Code, "The Privacy Act" but which has not been specifically authorized under criteria established by Executive order or an Act of Congress to be kept secret in the interest of national defense or foreign policy.
Ref 13: Security Guidance
Program Protection Plans (PPP) and Security Classification Guides (SCG): The contractors shall protect critical program information (CPI) and critical components (CC), technologies and systems in compliance with the applicable LSP Annex to the NSSL Program Protection Plan (PPP) and the contractor developed Program Protection Implementation Plan (PPIP). Program Security Classification Guides (SCGs) will be provided by the Government program office. Classified national security information, and unclassified controlled information (CUI) shall be protected as outlined in the SCG, 32 Code of Federal Regulation (CFR) Part 117, National Industrial Security Program Operating Manual (NISPOM), DODM 5200.01 V1-3 and DoDI 5200.48.
Research and developmental contractors shall develop a Program Protection Implementation Plan (PPIP) to be approved by the program office. The PPIP shall describe the protection measures being implemented by the contractor and sub-contractors for CPI and CC. The prime contractor shall flow-down to any subcontractor protection requirements for implementation as described in the PPIP in compliance with PPP. The government program office shall conduct Program Protection Surveys at contractor locations to assess the effectiveness of the established PPIP.
**RSLP is an Investment Activity and not a Program (regardless of acquisition category), therefore, a PPP and PPIP are not applicable.
**SCG specific details vary depending on customer. SCGs will include generating classified material such as launch mission profiles and storing classified hardware such as re-entry vehicles.
Personnel Security - For access to classified information contractor will ensure all required actions IAW DoDM 5200.02, AFM 16-1405, FA8818-24-R-B003
PREVIOUS EDITION IS OBSOLETE. Page 7 of 9DD FORM 254, APR 2018
AFGM2022-03, and 32 CFR Part 117, are completed for personnel working on this contract. An interim SECRET or CONFIDENTIAL Personnel Security Clearance (PCL) is valid for access to classified information at the level of the eligibility granted. Interim SECRET or CONFIDENTIAL PCLs are authorized except when the contractor will require access COMSEC information, RD, or NATO information, where a finalized security clearance is required. Note, an interim TOP SECRET PCL is the equivalent of a final SECRET PCL. Security clearances are in accordance with the 32 Code of Federal Regulation (CFR) Part 117, National Industrial Security Program Operating Manual (NISPOM). Access to SCI will be in accordance with the current SCI addendum and DOD Manual 5105.21 Volumes 1-3 for SCI management. Contractor(s) will not be afforded access to classified information at any level (i.e. Confidential, Secret, or Top Secret) until the Defense Counterintelligence and Security Agency (DCSA) Consolidated Adjudication Services (CAS) grants a final PCL at the appropriate level. Interim PCLs are authorized only when granted by the adjudicative authority and have been entered into Defense Information System for Security (DISS). Contractor(s) must be employed in a position that requires a clearance in order to be submitted for the appropriate PCL. Contractor(s) Facility Security Officer (FSO) will submit all investigation requests through National Background Investigation Services (NBIS) and ensure individuals complete a clearance application in the Electronic Application (e-App). Contractor(s) FSO reviews, approves, and forwards the completed e-App to DCSA Vetting Risk Operations (VRO) for approval, issuance of an interim clearance, and release to Office of Personnel Management (OPM) for investigation.
Alternate methods of clearance submission are acceptable as long as the contractor security personnel ensures clearance levels are available in Defense Information System for Security (DISS) for review.
Contract performance on a Government installation and/or 1) access to classified information and/or 2) IT Level I/II/III access and/or 3) when cleared personnel are required to perform unclassified services in a facility requiring a security clearance for unescorted access, shall undergo a Personnel Security Investigation (PSI), as appropriate. This is also applicable to contractor and subcontractor personnel who are visiting or on a temporary and/or escort duties for a period of 90 days or more. This requirement is for personnel who have or may need access to restricted or controlled areas. Contractor employees who require access to government IT systems/networks are determined to be trustworthy by the completion of a favorable PCL investigation appropriate with assigned duties and by a designated government official prior to IT access being granted. This is accomplished through the system authorization access request, DD Form 2875, process.
Reference AFI 31-501, Personnel Security Program Management (or applicable revisions) for background investigation requirements.
Reference AFI 16-1406, Air Force Industrial Security Program and AFI 31-101, Integrated Defense, for administrative approaches to identify installation access for contractors as “Visitor Groups,” “Intermittent,” and “Cleared Facilities.” Both installation and network access as prescribed in AFI 16-1406 correlates to AFI 36-3026, Volume 2, Common Access Card (CAC), for contractor and volunteer populations, eligibility and enrollment to DEERS via the online TASS application.
Grant contractors (prime contractors and subcontractors) access to the installation IAW AFMAN 31-113, Installation Perimeter Access Control.
Any conflict and/or issue regarding classification level between this and any other application guide will be protected at the highest level until the conflict or issue is resolved by the Corps Security Manager, and Information Protection Office (IPO) and Special Security Office (SSO). Written resolution and/or direction will be provided by the Corps Security Manager, and IPO and SSO.
Security Incident Reporting: In addition to the reporting requirements directed by the NISPOM, the contractor shall provide a concurrent report of loss or compromise and/or unauthorized access of CUI, FOUO, and any classified information, materials, hardware, and/or systems to the cognizant Government Contracting Activity (GCA), Government Information System Security Manager (ISSM), Corps Security Manager (CSM), and SSC Information Protection Office (SSC/S2S), and supporting CSO (DCSA, etc.). Contractor shall report loss or compromise and/or unauthorized access of CUI, FOUO, and any classified information, materials, hardware, and/or systems to the contractor's cognizant security office identified in Block(s) 6c and 8c, within 24-hrs.
Upon expiration of this contract, the contractor shall request disposition instruction for all classified and unclassified project material. The contractor may be directed to properly destroy or return material. If the contractor desires to retain classified or unclassified program information, the contractor must provide a request six (6) months in advance of contract completion to transfer project information to follow-on contractor or similar effort, contractor must have written approval from the Government: Program Manager, Contracting Officer and Security Officer. The contractor shall return to the GCA all CACs, security badges, entry passes/vehicle decals issued to contractor personnel. This applies to termination, cancellation and/or expiration contract, and/or of employment and/or suspension of clearance.
Transfer of document to other Independent Research and Development (IRAD) is not permitted.
The undersigned has reviewed the Security Specification, understands the provisions and will ensure that it is complied with within the limits of his/her responsibility, and that any violations are brought to the attention of the GCA.
List of Attachments (All Files Must be attached Prior to Signing, i.e., for any digital signature on the form)
SSC/AAMXA
NAME & TITLE OF REVIEWING OFFICIAL
Capt Jeremiah C. Williams Program Manager
SIGNATURE
WILLIAMS.JEREM
IAH.C.1470776532
Digitally signed by
WILLIAMS.JEREMIAH.C.14707
76532 Date: 2024.02.21 14:07:49 -07'00'
FA8818-24-R-B003
PREVIOUS EDITION IS OBSOLETE. Page 8 of 9DD FORM 254, APR 2018
SSC/AAMXO
Robert Douglass Contracting Officer Representive
SIGNATURE
SSC/BZS-AATS
Kevin Morris Security Representative
SIGNATURE
SSC/BZS
Reginald King Industrial Security Specialist
SIGNATURE
14. ADDITIONAL SECURITY REQUIREMENTS
Requirements, in addition to NISPOM requirements for classified information, are established for this contract.
No Yes If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted.
(See instructions for additional guidance or use of the fillable PDF.)
1. PROGRAM PROTECTION PLANNING: The prime contractor and its subcontractors shall protect Critical Program Information (CPI), Sensitive Compartmented Information (SCI), Critical Components (CC), technologies and systems when identified in appropriate Program Protection Plans (PPP).
2. For OPSEC requirements (reference Block 13 for details). Contractor will comply with the policies and procedures outlined in the host organization OPSEC Plan in support of this effort. Host organization OPSEC plan will be furnished by the government upon contract award to ensure compliance with all OPSEC guidelines set forth.
15. INSPECTIONS
Elements of this contract are outside the inspection responsibility of the CSO.
No Yes If Yes, explain and identify specific areas and government activity responsible for inspections. The field will expand as text is added or you can also use item
13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted.
(See instructions for additional guidance or use of the fillable PDF.)
The DCSA is relieved of security inspection responsibility for contract performance on government installations. The Commander retains cognizance over contracts on the installation. SSC/BZS staff is designated as member of the Wing Inspection Team and has inspection authority when assigned under SSC/IG.
16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)
a. GCA NAME
SSC/AAK-KT
b. ACTIVITY ADDRESS CODE (AAC) OF THE CONTRACTING OFFICE (See Instructions)
FA8818
c. ADDRESS (Include ZIP Code)
3548 Aberdeen Drive SE Kirtland AFB, NM 87117
d. POC NAME
Lucia A. Corral
e. POC TELEPHONE (Include Area Code)
+1 (505) 853-5873
f. EMAIL ADDRESS (See Instructions) lucia.corral@spaceforce.mil
17. CERTIFICATION AND SIGNATURES
Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below. Upon digitally signing Item 17h, no changes can be made as the form will be locked.
a. TYPED NAME OF CERTIFYING OFFICIAL (Last, First, Middle Initial) (See Instructions)
Lucia A. Corral
b. TITLE
CONTRACTING OFFICER
c. ADDRESS (Include ZIP Code)
SSC/AAK-KT
3548 Aberdeen Drive SE Kirtland AFB, NM 87117
d. AAC OF THE CONTRACTING OFFICE (See Instructions)
FA8818
e. CAGE CODE OF THE PRIME CONTRACTOR (See Instructions.)
N/A
f. TELEPHONE (Include Area Code)
+1 (505) 853-5873
g. EMAIL ADDRESS (See Instructions) lucia.corral@spaceforce.mil
h. SIGNATURE
i. DATE SIGNED (See Instructions)
DOUGLASS.ROB
ERT.A.1164956420
Digitally signed by
DOUGLASS.ROBERT.A.116495
Date: 2024.02.21 14:37:59 -07'00'
MORRIS.KEVI
N.1230097450
Digitally signed by
MORRIS.KEVIN.1230097450
Date: 2024.02.23 07:46:12 -08'00'
FA8818-24-R-B003
PREVIOUS EDITION IS OBSOLETE. Page 9 of 9DD FORM 254, APR 2018
18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL
a. CONTRACTOR
b. SUBCONTRACTOR
c. COGNIZANT SECURITY OFFICE FOR PRIME AND
SUBCONTRACTOR
d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY
ADMINISTRATION
e. ADMINISTRATIVE CONTRACTING OFFICER
f. OTHER AS NECESSARY (If more room is needed, continue in Item 13 or on additional page if necessary.)
SSC/AATS, SSC/AAMX, SSC/AAMXA, SSC/AAMXO,
SSC/BZS
File details come from the government source that posted it. Updated .