Attachment 2 Solicitation DD 254 Cisco Network Optimization.pdf
PDF 365 KB Posted
- Attached to
- Cisco Business Critical Services for Network Optimization at PHNSY&IMF Federal contract opportunity
- Solicitation number
- HC101923R0010
- Issued by
- Defense Information Systems Agency
About this file
This document is a DD Form 254, which is a Department of Defense Contract Security Classification Specification. The form specifies security requirements for a contract between the Defense Information Systems Agency and Cisco to provide network optimization services to the Pearl Harbor Naval Shipyard & Intermediate Maintenance Facility. The contractor will require access to the SYLAN and SECNET systems and have operations security requirements. The period of performance is through September 18, 2023. The contractor facility clearance level must be at least Secret and safeguarding is required at the Secret level. The cognizant security office is the Commander of Pearl Harbor Naval Shipyard & IMF.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| HC1019-23-R-0010 7SEP2023.pdf | ||
| Attachment 3 QASP MSSD-5339.docx | DOCX document | |
| Attachment 4 PHNSYIMF OPSEC Contract Requirements 03-21-22.pdf | ||
| Attachment 5 Pricing Worksheet.xlsx | XLSX spreadsheet | |
| Attachment 6 QA Template.xlsx | XLSX spreadsheet | |
| Attachment 1 Addendums for Solicitation.docx | DOCX document | |
| JA23-087 JA Cisco Network Optimization Services Final_Redacted.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Please wait...
If this message is not eventually replaced by the proper contents of the document, your PDF viewer may not be able to display this type of document.
You can upgrade to the latest version of Adobe Reader for Windows®, Mac, or Linux® by visiting http://www.adobe.com/go/reader_download.
For more assistance with Adobe Reader visit http://www.adobe.com/go/acrreader.
Windows is either a registered trademark or a trademark of Microsoft Corporation in the United States and/or other countries. Mac is a trademark of Apple Inc., registered in the United States and other countries. Linux is the registered trademark of Linus Torvalds in the U.S. and other countries.
DRAFT
SAMPLE
PREVIOUS EDITION IS OBSOLETE.
Page of
DD FORM 254, APR 2018
NEEDS DD67
DEPARTMENT OF DEFENSE
CONTRACT SECURITY CLASSIFICATION SPECIFICATION
(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)
OMB No. 0704-0567 OMB approval expires:
June 30, 2025 The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.
RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.
1. CLEARANCE AND SAFEGUARDING
2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)
3. THIS SPECIFICATION IS: (X and complete as applicable.)
a. ORIGINAL (Complete date in all cases.)
b. REVISED (Supersedes all previous specifications.)
4. IS THIS A FOLLOW-ON CONTRACT?
If yes, complete the following:
Classified material received or generated under
5. IS THIS A FINAL DD FORM 254?
If yes, complete the following:
6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)
7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor)
8. ACTUAL PERFORMANCE (Click button to add more locations.)
10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)
e. NATIONAL INTELLIGENCE INFORMATION:
11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)
12. PUBLIC RELEASE
Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)
13. SECURITY GUIDANCE
The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.
(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)
List of Attachments (All Files Must be attached Prior to Signing, i.e., for any digital signature on the form)
14. ADDITIONAL SECURITY REQUIREMENTS
Requirements, in addition to NISPOM requirements for classified information, are established for this contract.
If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)
15. INSPECTIONS
Elements of this contract are outside the inspection responsibility of the CSO.
If Yes, explain and identify specific areas and government activity responsible for inspections. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)
16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)
17. CERTIFICATION AND SIGNATURES
Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below. Upon digitally signing Item 17h, no changes can be made as the form will be locked.
18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL
9.0.0.2.20120627.2.874785 DD 254, "DoD Contract Security Classification Specification"
| CurrentPage: |
| PageCount: |
| Select classification from drop-down list.: Unclassified |
| Enter serial number.: |
| a. Facility clearance level. Select one.: 2 |
| b. Level of safeguarding for classified information/material required at contractor facility. Select one.: 4 |
| Select for "original.": 0 |
| Select for "original.": 1 |
| Enter prime contract number.: |
| Select for "revised.": 0 |
| Select for "revised.": 0 |
| Enter subcontract number.: |
| Select for "final.": 1 |
| Select for "final.": 0 |
| Enter solicitation or other number.: HC1019-23-R-0010 |
| Enter due date in format YYYYMMDD.: 20230918 |
| Enter date in format YYYYMMDD.: 20230329 |
| Enter revision number.: |
| Enter date in format YYYYMMDD.: |
| Enter final specification.: |
| Enter date in format YYYYMMDD.: |
| Select for "no.": 1 |
| Select for "no.": 1 |
| Select for "no.": 0 |
| Select for "no.": 0 |
| Select for "yes.": 0 |
| Select for "yes.": 0 |
| Select for "yes.": 1 |
| Select for "yes.": 1 |
| Enter preceding contract number.: |
| Enter contractor's request date in format YYYYMMDD.: |
| Enter period.: |
| Enter typed name of certifying official (last, first, middle initial).: McMillan, Laura F. |
| Enter CAGE code of the prime contractor.: N/A |
| Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: Commander, |
Pearl Harbor Naval Shipyard & Intermediate Maintenance Facility (Code 1120) 667 Safeguard street, Suite 100 Phone: (808) 474-9119
| Select to add row to locations.: |
| Select to remove last row from locations.: |
| Select to delete all signatures.: |
| Enter location(s).: Commander, Pearl Harbor Naval Shipyard & IMF |
667 Safeguard street, Suite 100
JBPHH, HI 96860-5033
Enter general unclassified description of this procurement.: To provide Pearl Harbor Naval Shipyard & IMF (PHNSY&IMF) with services to optimize its networks to further the goal of assisting its mission of providing 24-hours-a-day, 7-days-a-week optimal network support for ship repair in the Pacific Basin. The service provider will require access to SYLAN (Shipyard Local Area Network) and SECNET (Secured Network) systems.
| Select for "a. CONTRACTOR.": 1 |
| Select for "a. CONTRACTOR.": 1 |
| Select for "a. CONTRACTOR.": 1 |
| Select for "f. OTHER AS NECESSARY.": 0 |
| Select for "f. OTHER AS NECESSARY.": 0 |
| Select for "f. OTHER AS NECESSARY.": 1 |
| Select for "b. SUBCONTRACTOR.": 1 |
| Select for "b. SUBCONTRACTOR.": 0 |
| Select for "b. SUBCONTRACTOR.": 0 |
| Select for "g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE TECHNICAL INFORMATION CENTER (DTIC) OR OTHER SECONDARY DISTRIBUTION CENTER.": 0 |
| Select for "g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE TECHNICAL INFORMATION CENTER (DTIC) OR OTHER SECONDARY DISTRIBUTION CENTER.": 0 |
| Select for "c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR.": 0 |
| Select for "c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR.": 0 |
| Select for "c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR.": 1 |
| Select for "h. REQUIRE A COMSEC ACCOUNT.": 0 |
| Select for "h. REQUIRE A COMSEC ACCOUNT.": 0 |
| Select for "d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION.": 0 |
| Select for "d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION.": 0 |
| Select for "d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION.": 0 |
| Select for "i. HAVE A TEMPEST REQUIREMENT.": 0 |
| Select for "i. HAVE A TEMPEST REQUIREMENT.": 0 |
| Select for "e. NATIONAL INTELLIGENCE INFORMATION: - (1) Sensitive Compartmented Information (SCI).": 0 |
| Select for "e. NATIONAL INTELLIGENCE INFORMATION: - (2) Non-SCI.": 0 |
| Select for "j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS.": 1 |
| Select for "j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS.": 1 |
| Select for "k. BE AUTHORIZED TO USE DEFENSE COURIER SERVICE.": 1 |
| Select for "k. BE AUTHORIZED TO USE DEFENSE COURIER SERVICE.": 0 |
| Enter infomration for "other.": NNPI - NUCLEAR WORK AREA |
UNNPI - UNCLASSIFIED NUCLEAR WORK AREA
| Enter infomration for "other.": Requires a Red Shipyard Access Control Badge |
| Enter infomration for "other.": SEA 08 |
PHNSY&IMF Code 1123
| Select for "e. ADMINISTRATIVE CONTRACTING OFFICER.": 0 |
| Select for "e. ADMINISTRATIVE CONTRACTING OFFICER.": 1 |
| Select for "l. RECEIVE, STORE, OR GENERATE CONTROLLED UNCLASSIFIED INFORMATION (CUI). .": 1 |
| Select for "m.OTHER.": 1 |
| Select for "direct.": 0 |
| Select for ": 1 |
| Enter specification for "through".: |
| Enter public release authority.: PHNSY&IMF Congressional and Public Affairs Officer (Code 1160), Ana Maring, ana.m.maring1@navy.mil |
| Select to add signature.: |
| Select to remove last signature.: |
| text: |
***This DD Form 254 is for Solicitation purposes only; therefore, it must be returned to the SCO identified in item 17 to be updated before the contract is awarded.***
-Item 10(a): COMSEC information/material will be processed IAW NISPOM 32 CFR Part 117 and OPNAVINST 2221.5D dtd 8/15/16, and any additional security guidelines. Contractor personnel requiring COMSEC access must be U.S. Citizens and possess a final clearance at the appropriate level. All contractors shall be briefed before access to COMSEC is granted. Written concurrence of the PHNSY&IMF Program Manager is required prior to subcontracting.
-Item 10(b) & 10(k)1: (U) Security Controls on the Dissemination of NNPI Received or Generated Under NAVSEA Contracts 12/1/2011 -Item 10(b) & 10(k)2: OPNAVINST, N9210.3 (U) Safeguarding of Naval Nuclear Propulsion Information (NNPI) 6/7/2010 -Item 10(b) & 10(k)3: (C-RD) CG-RN-1, REV.3, CHANGES 1-20, DOE-DOD SCG for the NNPP which includes Interpretive Guidance Bulletins 1-19 -Item: 10(b) 4. Access to NNPI RD for this contract requires a final U.S. Government National Security Clearance at the appropriate level and an NNPI RD security briefing from the Facility Security Officer (FSO).
-Item: 10(b) & (k) 5. Processing of NNPI on non-federal IT systems requires NAVSEA 08 authorization per OPNAVINST N9210.3, using the procedures identified in NAVSEA ltr 08B/19-03823, dated 2 August 2019.
-Item: 10(b) & (k) 6. The Contractor must maintain a current Certification of eligibility from the Defense Logistics Agency (DLA), Joint Certification Office for access to export-controlled CUI, which includes U-NNPI. DD Form 2345, Militarily Critical Technical Data Agreement, applies. Per DLA, the Certification is only specific to each facility's CAGE code.
-Item: 10(b) & (k) 7. The Contractor must submit a request for sharing of NNPI RD to sub-contractors in a writing to the PHNSY&IMF SCO (see item 17) and include a draft sub-contractor DD Form 254 for NAVSEA 08 to sign approval.
-Item: 10(k) 8. For sharing of U-NNPI the Contractor must prepare a sub-contractor DD 254 that includes the security guidance for U-NNPI from the prime contract; verify the sub-contractor has a current DD Form 2345 (see Item: 10(b) & (k) 6 of this DD 254). The Contractor must forward an info-copy of the sub-contractor DD 254 to NAVSEA 08 and the SCO. Also list in Item 18(f) distribution to "SEA 08, PHNSY&IMF Code 1123".
-Item: 10(j). All CUI associated with this contract must be protected per the guidance provided in Item 11(l) of this DD 254 and Attachment (3) of this DD Form 254, that contains basic safeguarding measures from DODI 5200.48 (CUI).
-Item 11(a) No classified and/or NNPI material will be removed from the ship in the performance of this contract unless approved in writing by the ship's Commanding Officer and PHNSY&IMF's Security Manager (Code 1122). Contractor shall utilize security guidance from SECNAVINST 5510.36B and the NISPOM 32 CFR Part 117.
-Item: 11(l). U-NNPI CUI must be protected in accordance with OPNAVINST N9210.3 and may not be stored or processed on Non-federal AIS without written authorization of NAVSEA 08, Naval Reactors.
-Item: 11(l): Legacy information from existing documents (e.g. Technical Manuals) marked For Official Use Only or FOUO, that is used to create a new document/correspondence, shall follow the minimum marking requirements of DODI 5200.48, Section 3, paragraph 3.4.a, and include the acronym "CUI" in the banner and footer of the document. Nonfederal information systems storing and processing CUI shall be protected per NIST SP-800-171, or subsequent revisions. All transmissions to personal email accounts (AOL, Yahoo, Hotmail, Comcast, etc.) and posting on social media websites (Facebook, Instagram, Twitter, LinkedIn, etc.) are prohibited. Destroy all CUI associated with this contract by any of the following approved methods: A cross-cut shredder; a certified commercial destruction vendor; a central destruction facility; incineration; chemical decomposition; pulverizing, disintegration; or methods approved for classified destruction.
-All security aspects of this contract fall under the cognizance of PHNSY&IMF. Contact the PHNSY&IMF SCO for any questions regarding the content of the DD 254.
-Classified or unclassified technical papers to be presented at a classified symposium must be approved by the PHNSY&IMF Contracting Officer's Representative (COR) in concert with Code 1122 and Code 1160 prior to the presentation.
-Security Classification Guides (SCGs) and CUI (e.g., formerly FOUO, distribution statement controlled) are not authorized for public release; therefore, they cannot be posted on a publicly accessible web-server or transmitted over the internet unless appropriately encrypted. Request for public release cannot be transmitted via the Internet until the contractor receives final approval from PHNSY&IMF (Code 1160).
-The subsequent revisions of SCGs apply to this contract. Subsequent revisions shall be provided by the Government Contracting Activity (GCA) as Government Furnished Information (GFI) and shall be executed by the Contractor at no additional cost to the government.
-Contractor must submit a request for sharing of classified and other sensitive information between prime contracts in writing to the SCO identified in Item 17 of this DD 254. Each request must reference the contract number to identify the specific information for which approval is being sought, a justification for needing to share the information, the name of the other contractor and its contract number under which the requested information will be shared.
-Personnel designated as derivative classifiers shall receive derivative classification training prior to access from the contractor's FSO. The FSO shall ensure personnel receive initial and annual refresher training during the life of this contract. Evidence of completion, training certificates or equivalent, shall be provided to the PHNSY&IMF Information Assurance Manager and COR no later than the individual's due date.
-All classified documents must be destroyed using a National Security Agency (NSA) approved high security crosscut shredder listed on the NSA/CSS evaluated products list (EPL) for high security crosscut paper shredders, or other PHNSY&IMF approved method for destroying classified information.
-Copies of preliminary inquiry or investigative reports of security incidents involving contractor personnel and classified information and/or U-NNPI shall be appropriately reported to the SCO identified in Item 17 of this DD 254. All classified information and U-NNPI involved in security incidents shall be retained and safeguarded for classification review or until advised by Code 1122 of the disposition. The contractor shall abide by other reporting requirements outlined in the NISPOM 32 CFR Part 117.
-Contractor must comply with Attachments (1) through (3) embedded in item 13 of this DD 254.
ATTACHMENT (1)
CONTRACTOR SECURITY REQUIREMENTS FOR PHNSY&IMF’S CONTROLLED INDUSTRIAL AREA, CONTROLLED NUCLEAR INFORMATION AREAS, NUCLEAR WORK AREAS AND/OR OTHER SENSITIVE AREAS (Rev. JUN 2021)
Ref: (a) NAVSHIPYD&IMFPEARLINST 5510.78 (series), Information and Personnel Security Program
(b) NAVSHIPYD&IMFPEARLINST 5530.1 (series), Physical Security Plan
(c) NAVSHIPYD&IMFPEARLINST 3070.1 (series), Operation Security (OPSEC) Program
(d) NAVSHIPYD&IMFPEARLINST 5239.1 (series), Activity Information Systems Security Plan (AISSP)
(e) NAVSHIPYD&IMFPEARLINST 2200.1 (series), Portable Electronic Devices Policy
Appendix: (1) Documents Acceptable for Proof of U.S. Citizenship
1. The provisions of these security requirements are in accordance with references (a) through (e) and applicable to contracts, subcontracts and Memorandums of Agreement (MOAs) for access to:
a. Controlled Industrial Area (CIA) – The large fenced-in area encompassing the waterfront and industrial shops, extending from 1274 Compound to include all of Bravo Pier 2.
b. CIA Restricted Waterways (between Landing "C" and Bravo Pier 2 or if the CIA is extended to include Bravo 4) - See paragraph 18 of this document for specific access requirements.
c. Areas designated other sensitive area (OSA), “Controlled Nuclear Information Area” (CNIA); and “Nuclear Work Area” (NWA).
2. Performance of all work under this Contract or MOA is restricted to U.S. citizens and U.S. nationals only . U.S. citizen employees of a foreign owned, controlled, and/or influenced company (including a parent company) for access purposes are considered foreign nationals and special authorization will be required for access to PHNSY&IMF spaces.
3. In accordance with reference (a) for issuance of Red or Yellow Shipyard Access Control Badges (SACBs), a “classified contract” is required with a Contract Security Classification Specification (DD 254) that includes:
a. Red SACB - Access to Restricted Data (RD) and Naval Nuclear Propulsion Information
(NNPI).
b. Yellow SACB - Access to Classified National Security Information (C-NSI) and unclassified NNPI.
c. In either case, the DD 254 must contain an approval signature from Naval Sea Systems Command (NAVSEA) SEA 08/Chief of Naval Operations (CNO) N00N and NNPI handling requirements in accordance with OPNAVINST N9210.3 (Safeguarding of NNPI).
4. These security requirements are applicable to the prime contractor as well as to all subcontractors and suppliers thereunder. The terms “contractor or contract” shall refer to all of the above whether this document is included in a contract, subcontract or MOA.
5. The period of proposed work in particular areas of the PHNSY&IMF is subject to further approval of the PHNSY&IMF Commander depending on the sensitivity of industrial operations in the affected areas.
6. At least three weeks prior to the visit, the PHNSY&IMF Sponsor will provide the contractor’s Facility Security Officer (FSO) or other Company Official the Contractor Visit Request (VR) form (PH-SYD 5512/28) and its completion instructions. The FSO or Company Official shall complete applicable items on Part 1 of the PH-SYD 5512/28 and submit it to the Government Contracting Activity (GCA) for completion of Part 2. The GCA will then forward the VR, DD 254 (i.e. for Yellow or Red SACBs), and prime contract documentation via encrypted means, to the PHNSY&IMF Sponsor for completion of Part 3 no later than two weeks prior to the visit. The PHNSY&IMF Sponsor will upload the VR and associated documents to the Code 320 Contractor Visit Request SharePoint no later than one week prior to the visit start date. The VR must specify the PHNSY&IMF areas to be accessed. Entry into the CIA, CNIA, NWA or OSA for those listed on the VR may be authorized under the following conditions.
a. For unescorted entry to the CIA: contractor personnel must show proof of U.S. citizenship before a Green badge can be issued.
b. For unescorted entry into an OSA, CNIA or NWA:
(1) All contractor companies must have DOD Facility Clearances (FCLs) granted by the Defense Counterintelligence and Security Agency (DCSA) and their personnel who need unescorted access to the OSA, CNIA and/or NWA must have DOD Personnel Clearances (PCLs) granted by the DOD Central Adjudication Facility (DODCAF). The FCLs, PCLs and security access (granted by the contractor) must be verifiable in the applicable DOD record system
(2) A Yellow or Red SACB will be issued depending on the areas needed to be accessed. For a Yellow (CNIA) SACB, the contractor must have at least an Interim PCL. For a Red (NWA) SACB, the contractor must have a final PCL/ RD access.
c. For situations other than the above, personnel requiring unclassified CIA access may be issued a White “Escort Required” (“ER”) SACB for escorted access by a briefed Yellow or Red badged PHNSY&IMF employee knowledgeable of the area. Escorted access to CNIAs and NWAs must be coordinated with the cognizant Department or Project Security Coordinator to ensure that the area is sanitized and the escort is properly briefed. In some cases, the Naval Nuclear Propulsion Information Control Officer (NNPICO) may determination that a Security Plan is required. Contractors are advised that processing of “ER” SACBs may take up to five working days to complete.
d. If the contract requires additional contractor personnel, new visit requests must be submitted and they shall be subject to the same pre-entry screening requirements as outlined above.
e. Under no circumstances shall contractor personnel sign, email or hand-carry their own VR. If the contractor or vendor is a one-person company, contact the Industrial Security Branch (Code 1123) for guidance.
f. Ensure that all contractor employees when reporting to the Pass and ID Office for PHNSY&IMF SACBs bring their valid Defense Biometric Identification Systems (DBIDS) identification cards. Also if they have no PCLs or interim PCLs, they must bring their proof of U.S. citizenship. See Appendix (1) for a list of acceptable documents.
g. Ensure any derogatory or questionable information concerning contractor employees possessing DOD PCLs and/or PHNSY&IMF SACBs is immediately reported to Code 1123) so that PHNSY&IMF access eligibility can be evaluated.
h. Ensure that contractor employees attend the 30-minute annual orientation on safety, security, OPSEC and radiological protection aspects of industrial operations within PHNSY&IMF.
NOTE: The annual orientation video will be shown at the Pass and ID Office in groups of 4, prior to issuance of PHNSY&IMF SACBs.
i. Ensure that embedded contractor personnel issued Red or Yellow SACBs complete mandatory PHNSY&IMF security training and briefings.
j. Ensure that contractor employees at all times while in PHNSY&IMF spaces wear and display their PHNSY&IMF SACB in plain view, vertically, on their outer clothing positioned above the waist and with the front/photograph facing outward. If an employee is issued a temporary (i.e. no picture) SACB, the employee must also carry his or her DBIDS identification card
k. Ensure that each SACB is used only by the specific individual named on the SACB.
l. Maintain strict accountability over SACBs and passes issued by the Pass and ID Office. Report immediately, to the Pass and ID Office, any that are missing, lost or stolen and the circumstances. Return SACBs/passes to the GCA or PHNSY&IMF Sponsor immediately upon termination of any employee, SACB expiration, completion of the work, or when no longer required, whichever occurs soonest. The GCA or PHNSY&IMF Sponsor will ensure that all SACBs/passes are forwarded to the PHNSY&IMF Pass and ID Office.
m. Restrict hours of work to first shift, i.e. 0630 to 1500 hours, Monday through Friday (except for federal holidays). In accordance with reference (b) when operational needs require the contractor to schedule work outside of first shift, on weekends and/or holidays, submit written notification at least two weeks in advance to PHNSY&IMF Sponsor who will obtain approval from the respective PHNSY&IMF Departments, Offices and Shop Heads. Such notifications will include the company name, type of work to be performed, location of work, specific dates, and hours of work. The PHNSY&IMF Sponsor will also submit a request in writing to the Operations & Physical Security Branch (Code 1121) by Wednesday of each week, to add the contractor to the “Non-Duty Hours Contractor Access List” that is issued weekly. Emergency access for contractors not on the list will be authorized by the Security Officer (Code 1120) or Code 1121, upon verification with the PHNSY&IMF Sponsor.
n. Restrict employees/representatives to the work site and control travel directly to and from the work site.
7. The Pass and ID Office is located in Building 207 at Safeguard Street and Russell Avenue. Hours of operation are Monday through Friday (except for federal holidays) 0600 to 1400 hours, except on Wednesday, 0600 to 1230 hours. Contractors must be signed in 45 minutes before closing to be serviced.
8. No vehicle will be permitted access to a work site in the CIA without a valid PHNSY&IMF CIA vehicle pass. The CIA vehicle passes are issued for limited purposes by the PHNSY&IMF Pass and ID Office and will not be issued without proof of vehicle registration. All vehicles are required to conform to PHNSY&IMF traffic regulations. The speed limit is 15 MPH in the CIA. Outside of the CIA, the speed limit is as posted or marked.
9. Only those contractor vehicles meeting all of the following criteria will be allowed to enter the CIA with the PHNSY&IMF CIA vehicle pass:
a. Vehicles must be registered to the company.
b. All contractor/commercial vehicles must be visually inspected prior to any entry into the CIA.
c. All vehicles must clearly display an authorized company sign or logo on both sides of the vehicles. The logo must be either painted on the vehicle; a decal or vinyl sticker; or a magnetic sign. Paper or cardboard signs are not authorized. Lettering of the logo must not be less than 2-1/2 inches in height and 1/4 inch wide.
d. Every vehicle entering the CIA will display the pass on the dashboard or visor (facing outward). The pass will be visible at all times while in the CIA.
e. Vehicle access to the CIA will only be allowed for transportation of contractors’ heavy tools, parts, and materials to and from the work site. Contractor vehicles found parked in the CIA, not meeting the above criteria, will lose their CIA access privilege.
NOTE: Contractor vehicles will not be used solely to transport employees to the job site. Privately owned vehicles will not be allowed in the CIA.
10. Vehicles may enter and exit from gates located on Paul Hamilton Avenue, Monday through Friday, 0600 to 1800 hours or on Chosin Street, 24 hours, 7 days a week, including federal holidays. In addition, for access before 0630 and after 1500 hours, weekends and holidays the contractors must comply with paragraph 6.m.
11. Parking is not permitted on any piers on any dry dock/waterfront areas. Contractors shall not park on or block the marked fire lanes at any time. Vehicles may stop on the piers of dry dock/waterfront areas for 15 minutes for loading or unloading. An exception may be made for vehicles that are part of the equipment needed to do the required work and are attached or connected to the pier or ship, i.e., a truck that uses a mounted generator, a vehicle with built-in equipment, etc. The exception request must be in writing and include justification. The contractor will send the request to Code 1120 via the GCA at least two weeks prior to the date parking space is required. Emergency notifications to the Regional Dispatch Center (RDC) may be necessary if pier access is blocked. The following information is also required:
a. The license number of the vehicle(s).
b. The type and size of the vehicle(s) (e.g. pickup truck, crane, forklift, etc.)
c. Parking location.
d. Purpose and duration.
12. Parking for privately-owned vehicles is available:
a. In the “N” parking lot on Central Avenue and “D” parking lot on Paul Hamilton Avenue, located between South Avenue and Safeguard Street or,
b. In the “C” parking lot on Lake Erie Street and Central Avenue.
13. All vehicles are subject to search while entering, remaining in, or leaving the PHNSY&IMF and/or Joint Base Pearl Harbor Hickam (JBPHH) areas. A Property Pass (OP-7) or Bill of Lading issued and signed by the GCA must cover all government material being transported out of the CIA by contractors. Material found without the above will be confiscated and a police offense report issued.
14. Entry into shop, office, or ship spaces covered by this contract will be subject to prior approval of the respective Department, Office or Shop Head or Ship’s Commanding Officer. Contractors will coordinate action with the PHNSY&IMF Sponsor for obtaining entry approval.
15. Code 1120 will coordinate guard services on a reimbursable basis for contractors requiring guard services. The contractor must notify and obtain approval from Code 1120 via the GCA at least two weeks prior to the time guard services will be required. Notification in writing shall (include the purpose and number of hours guard services will be required). Funding must be submitted by the GCA to JBPHH prior to the requested service date.
16. Contractor personnel will not be permitted to enter PHNSY&IMF buildings, spaces, and areas not covered by this contract except on prior approval of the PHNSY&IMF Department, Office or Shop Heads having jurisdiction of the areas. Contractors will coordinate in advance with the PHNSY&IMF Sponsor to obtain entry approval.
17. If access is needed to the restricted CIA waterways for divers and boats, the PHNSY&IMF Sponsor must coordinate access controls with Code 1121 in advance. Code 1121 will then coordinate with the CIA security force (JB2) and the RDC.
a. Access onto the CIA piers requires all personnel have SACBs that allow unescorted access to the CIA (i.e. Green, Yellow or Red). An armed JBPHH officer at the debarking point must validate SACBs of all personnel prior to their stepping onto a CIA pier.
b. EVERY TIME personnel leave the CIA perimeter and re-enter the CIA by waterway, they must meet with an armed JBPHH officer and their badges checked prior to accessing the CIA.
c. Once work is completed for the day, the PHNSY&IMF Sponsor must notify Code 1121 and the RDC.
d. If working only in the waterways, personnel must be instructed to stay in the water or boat (i.e. do not tie up to or step onto a CIA pier) and advise Code 1121 prior to starting the work.
e. All emergencies that require personnel to come onto the CIA pier without CIA SACBs and/or advance notification require notification to the RDC. Once the personnel are safe they must stand by in the area, call the RDC at 911 and explain that they have come ashore in the Pearl Harbor Naval Complex CIA, and do not have authorization to be there. The notification must include if personnel require urgent medical treatment. The RDC will dispatch a JBPHH officer and paramedics, if applicable, to the location to address the situation and notify key personnel for action or instructions. The PHNSY&IMF Sponsor must make other notifications to appropriate (non-security) personnel, i.e., PHNSY&IMF Docking Officer, Harbor Control, etc.
18. Access to unclassified and classified U.S. Navy shipbuilding, conversion, or repair technology and related technical information manuals, documents, drawings, plans, specifications, etc., by the contractor shall be restricted to an official need-to-know basis. This type of information shall be handled, controlled, and safeguarded to prevent oral, visual, and documentary disclosure to uncleared personnel, the public, to foreign sources, and to all personnel not having an official need-to-know. It shall be returned to the PHNSY&IMF upon completion of contracted work, except when the GCA grants specific retention authorization.
19. Photography is prohibited in PHNSY&IMF spaces and photographic equipment are prohibited in the CIA and sensitive areas. When operationally required, a written request containing specific justification and details will be submitted to the Security Manager (Code 1122) via the GCA for consideration. If a PHNSY&IMF photographer is unable to take the photographs, authorization will only to be granted to the contractor if the contractor has a PHNSY&IMF Sponsor and is under continuous escort of a designated PHNSY&IMF employee. The designated escort shall be briefed by Code 1122. The escort will take the film or photographic media in his or her custody and turn it over to the PHNSY&IMF Sponsor. The PHNSY&IMF Sponsor will mark and control the photographs as “Controlled Unclassified Information” (formerly For Official Use Only) and prior to release from PHNSY&IMF’s custody, route them in accordance with reference (a) for review and approval of a Distribution Statement..
20. Portable Electronic Devices (PEDs). PED is defined in reference (e) as a portable electric device having the capability to store, record, or transmit text, images, video, or audio data. Examples of PED include, but are not limited to: pagers, laptops, cellular telephones, radios, compact disc, cassette players, cassette recorders, portable digital assistants, audio devices, watches with input capability, reminder recorders and mobile devices.
a. Non-camera PED devices can have audio recording capability but this feature cannot be used in PHNSY&IMF spaces.
b. All personnel authorized to use PEDs in PHNSY&IMF workspaces, whether personal (includes contractor-owned) or government-owned, are required to comply with references (d) and (e).
c. Violations may result in the confiscation and sanitization of the PEDs. The only approved method of sanitizing most PEDs is physical destruction.
21. Ensure that yellow plastic material is not used for warning signs, covering material, etc.
22. Be responsible for control and security of all contractor-owned equipment and material at the work site. Report immediately, all missing/lost/stolen property to the JBPHH Security Detachment (phone 474-2222) as each case occurs.
23. Ensure that no material is stacked within ten (10) feet of the CIA perimeter. Remove from the work site, or secure, ladders or other such equipment, which could be used to climb the CIA perimeter fence. Ensure that no vehicles are parked within ten (10) feet of the CIA perimeter.
24. Provide written notification to Code 1120 via the GCA, two (2) weeks prior to actual start of work to allow for notification of the appropriate PHNSY&IMF departments, offices, and shops of the impact resulting from the contract work. Such notifications will include specific details such as work schedules (including actual start date for PHNSY&IMF entry), and impact statements concerning tasks to be done, e.g. specific parking spaces to be vacated, inclusive dates involved, traffic rerouting, changes to traffic and parking patterns, traffic/parking controls to be instituted by the contractor, barricades to be erected by the contractor, etc., along with sketches of the particular areas involved.
25. Two weeks prior to making any penetrations (i.e. tunneling under, cutting through a fence, or building, etc.) in a restricted area (e.g. CIA fence line, CNIA or NWA) the contractor shall contact Code 1120 via the GCA to arrange for a security guard or other measures required to meet all security requirements. The cost for the security guard will be charged to the GCA.
27. Any exceptions to these security requirements must be coordinated with the Security Office (Code 1120).
APPENDIX (1) OF ATTACHMENT (1)
DOCUMENTS ACCEPTABLE FOR PROOF OF U.S. CITIZENSHIP
(Original documents or certified copies)
1. U.S. BIRTH REGISTRATION CARD (with Registrar’s raised seal and signature)
2. U.S. BIRTH CERTIFICATE (original with raised seal from one of the 50 states or outlying U.S. territories or U.S. possessions)
3. U.S. IMMIGRATION AND NATURALIZATION SERVICE NATURALIZATION CERTIFICATE (INS N-550/570)
4. DD FORM 1966 (U.S. citizenship documents sighted are listed and attested to by a recruiting official)
5. DELAYED BIRTH CERTIFICATE (Original with Registrar’s seal and signature and cites secondary evidence)
6. HOSPITAL BIRTH CERTIFICATE (Original with authenticating raised seal or signature provided all vital information is given)
7. U.S. PASSPORT or U.S. PASSPORT CARD (Not expired)
8. U.S. IMMIGRATION AND NATURALIZATION SERVICE CERTIFICATE OF CITIZENSHIP (INS N-560/561)
9. FORM FS 240 – REPORT OF BIRTH ABROAD OF A CITIZEN OF THE UNITED STATES OF AMERICA/CONSULAR REPORT OF BIRTH
10. FORM FS 545 – CERTIFICATION OF BIRTH (Issued by U.S. Consulate)
11. FORM DS 1350 – DEPARTMENT OF STATE CERTIFICATION
NOTE: Refer to references (a) through (e) for additional guidance.
ATTACHMENT (2)
NARRATIVE: 9T-NNPI
REVISED: 1 DECEMBER 2011
SECURITY CONTROLS ON THE DISSEMINATION OF NAVAL NUCLEAR PROPULSION INFORMATION RECEIVED OR
GENERATED UNDER NAVSEA CONTRACTS
1. The provisions of the DOE-DOD Classification Guide for the Naval Nuclear Propulsion Program, CG-RN-1, Revision 3, and its Interpretive Guidance Bulletins and OPNAVINST N9210.3 are applicable to all Naval Nuclear Propulsion Information (NNPI) work done under this contract.
2. Disclosure of NNPI, classified or unclassified, to contractor employees who are granted Limited Clearances under the provisions of National Industrial Security Program Operating Manual (NISPOM) 32 CFR Part 117 (See Note) is not authorized without approval from the Naval Sea Systems Command (SEA 08).
3. Access to Navy ships, or Navy or commercial shipyards where Navy ships are located, is subject to the requirements of NAVSEAINST 5510.2D of 8 November 2018, Subj: Naval Sea Systems Command Access and Movement Control Instruction.
4. All Naval Nuclear Propulsion Information, classified or unclassified shall be marked in accordance with Chapter (2) of OPNAVINST N9210.3.
5. Critical Technology (also referred to as militarily critical technology) is defined as follows:
a. Arrays of design and manufacturing know-how (including technical data);
b. Keystone equipment (including manufacturing, inspecting and testing equipment) is the equipment specifically necessary for the effective application of a significant array of technical information and know-how;
c. Keystone materials are materials specifically necessary for the effective application of a significant array of technical information and know-how; and
d. Goods accompanied by sophisticated operation, application or maintenance know-how that would make a significant contribution to the military potential of any country or combination of countries and that may prove detrimental to the security of the United States.
6. Information other than NNPI that contains critical technology information as defined in paragraph 5 above shall be marked with the following warning notice, along with the designated distribution statement:
WARNING - This document contains technical data whose export is restricted by the Arms Export Control Act (Title 22, U.S.C. Sec. 2751 et seq.) or the Export Administration Act of 1979, as amended, Title 50, U.S.C., App 2401, et seq. Violations of these export laws are subject to severe criminal penalties. Disseminate in accordance with the provisions of DoD Directive 5230.25.
7. The contractor shall invoke the foregoing provisions, as appropriate, in all subcontracts hereunder which involve access to NNPI. The requirements of OPNAVINST N9210.3 and appropriate sections of the DOE-DOD Classification Guide for Naval Nuclear Propulsion Program, CG-RN-1, Revision 3 and its Interpretive Guidance Bulletins are applicable for all contracts and are also applicable to all subcontracts which involve access to Classified NNPI.
NOTE: Effective 24 February 2021, DOD 5220.22-M (NISPOM) was updated to NISPOM CFR 32 CFR Part 117. Refer to CG-RN-1, Revision 3, and its Interpretive Guidance Bulletins and OPNAVINST N9210.3 for additional guidance.
ATTACHMENT (3)
Excerpts from DoDI 5200.48 March 6, 2020
CONTROLLED UNCLASSIFIED INFORMATION (CUI)
SECTION 4: DISSEMINATION, DECONTROLLING, AND DESTRUCTION OF CUI
4.1. GENERAL
Part 2002 of Title 32, CFR requires dissemination statements to be placed on classified and unclassified documents or other materials when CUI necessitates access restrictions, including those required by law, regulation, or government-wide policy. These statements facilitate control, secondary sharing, decontrol, and release without the need to repeatedly obtain approval or authorization from the controlling DoD office.
a. Dissemination controls identify the audience deemed to have a lawful government purpose to use the CUI and specify the rationale for applying the controls by specific codes in accordance with DoDI 5230.24 and this issuance.
b. Agencies must promptly decontrol CUI properly determined by the CUI owner to no longer require safeguarding or dissemination controls, unless doing so conflicts with the related law, regulation, or government-wide policy in accordance with DoDI 5230.09.
c. Decontrolling CUI through the public release process relieves authorized holders from requirements for handling information in accordance with the CUI Program. A prepublication review must be conducted in accordance with DoDI 5230.09 before public release may be authorized.
d. In accordance with Part 2002.20 of Title 32, CFR, if the authorized holder of the CUI publicly releases the CUI in accordance with the designating agency’s authorized procedures, this constitutes the decontrol of the document.
e. To ensure CUI protection, the following measures will be implemented:
(1) During working hours, steps will be taken to minimize the risk of access by unauthorized personnel, such as not reading, discussing, or leaving CUI information unattended where unauthorized personnel are present. After working hours, CUI information will be stored in unlocked containers, desks, or cabinets if the government or government-contract building provides security for continuous monitoring of access. If building security is not provided, the information will be stored in locked desks, file cabinets, bookcases, locked rooms, or similarly secured areas. The concept of a controlled environment means there is sufficient internal security measures in place to prevent or detect unauthorized access to CUI. For DoD, an open storage environment meets these requirements.
(2) CUI information and material may be transmitted via first class mail, parcel post, or, bulk shipments. When practical, CUI information may be transmitted electronically (e.g., data, website, or e-mail), via approved secure communications systems or systems utilizing other protective measures such as Public Key Infrastructure or transport layer security (e.g., https). Avoid wireless telephone transmission of CUI when other options are available. CUI transmission via facsimile machine is permitted; however, the sender is responsible for determining whether appropriate protection will be available at the receiving location before transmission (e.g., facsimile machine attended by a person authorized to receive CUI; facsimile machine located in a controlled government environment.
4.5. DESTRUCTION.
Guidance for destroying CUI documents and materials is provided in this issuance, the CUI Registry, and ISOO Notice 2019-03. CUI documents and materials will be formally reviewed in accordance with Paragraphs 4.5.a. and 4.5.b. before approved disposition authorities are applied, including destruction. Media containing CUI must include decontrolling indicators.
a. Record and non-record copies of CUI documents will be disposed of in accordance with Chapter 33 of Title 44, U.S.C. and the DoD Components’ records management directives. When destroying CUI, including in electronic form, agencies must do so in a manner making it unreadable, indecipherable, and irrecoverable. If the law, regulation, or government-wide policy specifies a method of destruction, agencies must use the method prescribed.
b. Record and non-record CUI documents may be destroyed by means approved for destroying classified information or by any other means making it unreadable, indecipherable, and unrecoverable the original information such as those identified in NIST SP 800-88 and in accordance with Section 2002.14 of Title 32, CFR.
SECTION 5: APPLICATION OF DOD INDUSTRY
5.3. REQUIREMENTS FOR DOD CONTRACTORS.
This paragraph highlights requirements for DoD contractors.
a. Whenever DoD provides information to contractors, it must identify whether any of the information is CUI via the contracting vehicle, in whole or part, and mark such documents, material, or media in accordance with this issuance.
b. Whenever the DoD provides CUI to, or CUI is generated by, non-DoD entities, protective measures and dissemination controls, including those directed by relevant law, regulation, or government-wide policy, will be articulated in the contract, grant, or other legal agreement, as appropriate.
c. DoD contracts must require contractors to monitor CUI for aggregation and compilation based on the potential to generate classified information pursuant to security classification guidance addressing the accumulation of unclassified data or information. DoD contracts shall require contractors to report the potential classification of aggregated or compiled CUI to a DoD representative.
d. DoD personnel and contractors, pursuant to mandatory DoD contract provisions, will submit unclassified DoD information for review and approval for release in accordance with the standard DoD Component processes and DoDI 5230.09.
e. All CUI records must follow the approved mandatory disposition authorities whenever the DoD provides CUI to, or CUI is generated by, non-DoD entities in accordance with Section 1220-1236 of Title 36, CFR, Section 3301a of Title 44, U.S.C., and this issuance.
NOTE: Refer to DODI 5200.48 (March 6, 2020) for additional guidance.
text:
Item 10(k): Access to RD, U-NNPI and NNPI NSI are authorized for this contract text:
See item 14 for OPSEC guidance.
| Click on this button to attach a file(s).: |
| rep: Bonnie Hilton (SEA 08) |
Program Manager, Supplier Security rep: Angelo McDuffie (Code 1122) PHNSY&IMF OPSEC Program Manager
| Enter signature.: |
| Explain and identify specific areas and government activity responsible for inspections.: -Item: 10(b) RD &10(k) NNPI: Access to NNPI is required for this contract; (U) OPNAVINST, N9210.3 Safeguarding of Naval Nuclear Propulsion Information (NNPI) 6/7/2010 applies. |
-Item 11.j(1): Performance under this contract requires the contractor to adhere to OPSEC requirements.
-Item 11.j(2): The Operations Security (OPSEC) Plan will be completed prior to award to the potential awardee then forwarded to the OPSEC Program Manager (PM) by encrypted email, through DoD SAFE at https://safe.apps.mil/, or by U. S. Postal Service. All Contractor (including subcontractor) personnel assigned to this contract will accomplish the following requirements in support of Pearl Harbor Naval Shipyard & IMF (PHNSY&IMF) OPSEC Program.
-Item 11.j(3): During the period of this contract, the Contractor personnel may be exposed to, use, or produce, U.S. Government critical information (CI) and observable indicators which may lead to discovery of CI. PHNSY&IMF's CI will not be distributed to unauthorized third parties, including foreign government or companies under Foreign Ownership, Control or influence (FOCI). The Contractor shall protect CI associated with this contract to prevent unauthorized disclosure. The contractor shall protect all CI as stated throughout the plan in a manner appropriate to the nature of the information. Review the OPSEC plan for examples of indicators.
-Item 11.j(4): PHNSY&IMF CI shall not be publicized in corporate wide newsletter, trade magazines, displays, internet pagers or public facing websites. All transmission to personal email accounts (AOL, Yahoo, Gmail, Hotmail, Comcast, etc.,) and posting on social media websites (Facebook, Instagram, Twitter, LinkedIn, etc.,) are prohibited. Media requests related to this project shall be directed to PHNSY&IMF Public Release Authority listed in Item 12 of this DD Form 254.
-Item 11.j(5): The Lead Contractor…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .