Attachment 3 - DD Form 254.pdf
PDF 275 KB Posted
- Attached to
- AIR FORCE STRATEGIC TRANSFORMATION SUPPORT (AFSTS) SOLICITATION Federal contract opportunity
- Solicitation number
- FA701420R0015
About this file
This DD Form 254 is a Department of Defense Contract Security Classification Specification for an Air Force Strategic Transformation Support (AFSTS) solicitation. The solicitation seeks advisory and assistance services to support the Deputy Assistant Secretary of the Air Force Office of Business Transformation and Deputy Chief Management Officer in managing and improving strategic transformation initiatives at the enterprise level. Services shall not include inherently governmental functions. The performance period is five years with a ceiling of $990 million to be awarded across two tiers. Tier 1 will award to all technically acceptable vendors, while two of the Tier 2 awards are set aside for small businesses. If no small business offerors are deemed technically acceptable, the small business set aside portion will dissolve. Classified information up to the secret level may be required, and additional security requirements are identified in attachments. National intelligence and special access programs are excluded from the scope of work.
View the file
Other files for this federal contract opportunity
Show all 32
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Please wait...
If this message is not eventually replaced by the proper contents of the document, your PDF viewer may not be able to display this type of document.
You can upgrade to the latest version of Adobe Reader for Windows®, Mac, or Linux® by visiting http://www.adobe.com/go/reader_download.
For more assistance with Adobe Reader visit http://www.adobe.com/go/acrreader.
Windows is either a registered trademark or a trademark of Microsoft Corporation in the United States and/or other countries. Mac is a trademark of Apple Inc., registered in the United States and other countries. Linux is the registered trademark of Linus Torvalds in the U.S. and other countries.
DRAFT
SAMPLE
PREVIOUS EDITION IS OBSOLETE.
Page of AEM LiveCycle Designer
DD FORM 254, APR 2018
NEEDS DD67
DEPARTMENT OF DEFENSE
CONTRACT SECURITY CLASSIFICATION SPECIFICATION
(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)
OMB No. 0704-0567 OMB approval expires:
May 31, 2022 The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.
RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.
1. CLEARANCE AND SAFEGUARDING
2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)
3. THIS SPECIFICATION IS: (X and complete as applicable.)
a. ORIGINAL (Complete date in all cases.)
b. REVISED (Supersedes all previous specifications.)
4. IS THIS A FOLLOW-ON CONTRACT?
If yes, complete the following:
Classified material received or generated under
5. IS THIS A FINAL DD FORM 254?
If yes, complete the following:
6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)
7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor)
8. ACTUAL PERFORMANCE (Click button to add more locations.)
10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)
e. NATIONAL INTELLIGENCE INFORMATION:
11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)
12. PUBLIC RELEASE
Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)
13. SECURITY GUIDANCE
The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.
(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)
List of Attachments (All Files Must be attached Prior to Signing, i.e., for any digital signature on the form)
14. ADDITIONAL SECURITY REQUIREMENTS
Requirements, in addition to NISPOM requirements for classified information, are established for this contract.
If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)
15. INSPECTIONS
Elements of this contract are outside the inspection responsibility of the CSO.
If Yes, explain and identify specific areas and government activity responsible for inspections. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)
16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)
17. CERTIFICATION AND SIGNATURES
Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below. Upon digitally signing Item 17h, no changes can be made as the form will be locked.
18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL
9.0.0.2.20120627.2.874785 DD 254, DoD Contract Security Classification Specification
| CurrentPage: |
| PageCount: |
| Classification: |
| SerialNum: |
| a. Facility clearance level. Select one.: 1 |
| b. Level of safeguarding for classified information/material required at contractor facility. Select one.: 4 |
| Choose Yes or No: 1 |
| Choose Yes or No: 1 |
| Prime: TBD |
| Choose Yes or No: 0 |
| Choose Yes or No: 0 |
| Sub: |
| Choose Yes or No: 0 |
| Choose Yes or No: 0 |
| Soli: FA701420R0015 |
| DueDate: |
| dateA: 2020-02-21 |
| RevisionNum: |
| dateB: |
| Final: |
| dateC: |
| No: 1 |
| No: 1 |
| No: 0 |
| No: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 1 |
| Yes: 1 |
| Enter your name here.: |
| ReqDated: |
| Enter your name here.: |
| Name: TBD |
| Name: Griffin, Nimal B |
| Cage: FA701 |
| CSO: TBD |
| CSO: 11 WG/IP |
1330 AF Pentagon Washington, DC 20330
CSO: 11 WG/IP
1330 AF Pentagon Washington, DC 20330
| addrow: |
| Removerow: |
| Click to delete a row: |
| Location: SAF/MG |
1500 W Perimeter Rd Andrews AFB, MD 20762 Location: AF Pentagon 1790 Air Force Pentagon Washington DC, 20330-1660
| Block9: The purpose of this IDIQ is to obtain Contractor support to provide Advisory and Assistance Services (A&AS) to support the Deputy Assist Secretary of the AF Office of Business Transformation (SAF/MG) and Deputy Chief Mgmt Officer (DCMO) in managing and improving Strategic Transformation Initiatives at the enterprise level. Services shall not include inherently governmental functions as discussed in FAR Subpart 7.5, “Inherently Gov't Functions”.Services and deliverables include three (3) Advisory and Assistance (A&AS) categories: Mgmt and professional services; and studies, research, analyses, and evaluations expertise. The Contractor shall provide all services, materials, supplies, equipment, and project supervision, as required in connection with any task orders awarded using AFSTS IDIQ. The primary NAICS for this IDIQ is: 541611 Admin Mgmt and General Mgmt Consulting Services. This is NOT an Info Technology (IT) contract; however, IT services, tools, and prototypes may be used/developed as long as it is necessary to provide a total transformational solution to meet agency needs. For the purpose of this IDIQ, “Transformation” means the process of fundamentally changing the systems, processes, people and/or technology across a whole enterprise (entity), to achieve measurable improvements in efficiency, effectiveness and stakeholder satisfaction. |
| a: 1 |
| a: 1 |
| a: 1 |
| f: 1 |
| f: 1 |
| f: 1 |
| b: 1 |
| b: 0 |
| b: 0 |
| g: 1 |
| g: 0 |
| c: 0 |
| c: 0 |
| c: 1 |
| h: 0 |
| h: 0 |
| d: 0 |
| d: 0 |
| d: 0 |
| i: 0 |
| i: 0 |
| SCI: 1 |
| NonSCI: 1 |
| j: 1 |
| j: 1 |
| k: 1 |
| k: 0 |
| Enter your name here.: SIPRNet, JWICS |
| Enter your name here.: 1. SAF/MG |
1790 Air Force Pentagon, Washington DC, 20330-1790
2. 11 WG/IP
1330 Air Force Pentagon, Washington, DC 20330-1330
| e: 1 |
| e: 0 |
| l: 1 |
| m: 0 |
| direct: 0 |
| thru: 1 |
| Enter your name here.: See Attachment 1 |
| PublicAuthority: See Attachment 1 |
| AddSig: |
| RemoveSig: |
| text: All contractor personnel shall comply with the provisions of DoD 5220.22-M, National Industrial Security Program Operating Manual. February 2006 (NISPOM) Incorporating Change 2, May 2016; DoDI 5220.22, National Industrial Security Program, Incorporating Change 1, Effective May 2018; DoDM 5220.22, Vol. 2, National Industrial Security Program: Industrial Security Procedures for Government Activities and Program Security Classification Guide; AFI 16-1406, Air Force Industrial Security Program, Incorporating Change 1, 30 January 2017 and AFGM, AFI-1601406, Industrial Security Program 24 Oct 2019. |
Contract performance: Base period is one year plus 4 option periods. See DD Form 254, Attachment 1 Item 13 Continuation Addendum attached for reference statements pertaining to this block.
ATTACHMENT 1 DD FORM 254
Ref. 10.a.: Communications Security: COMSEC information includes accountable or non-accountable COMSEC information and controlled cryptographic items (CCI).
If accountable COMSEC material is involved, the Visitor Group must have a COMSEC account. NOTE: COMSEC custodians are DAF civilians or military members. Visitor Groups are considered hand receipt holders.
Ref. 10.a.: Classified COMSEC material is not releasable to Visitor Group employees who have not received a FINAL clearance at the appropriate security level. COMSEC access shall be IAW DoD 5220.22-M. When access is required at Government facilities, Visitor Group personnel will adhere to COMSEC rules and regulations as mandated by Command policy and procedures. Prior written approval from the CO is required in order for a prime Visitor Group to grant COMSEC access to a subcontracting Visitor Group. See “COMSEC ACCESS AND/OR ACCOUNT ADDENDUM”, attachment 10a.
Ref. 10.b.: Restricted Data Information is not releasable to Visitor Group employees who have not received a FINAL clearance at the appropriate security level. Written concurrence of the CO is required prior to subcontracting. Access to RESTRICTED DATA requires a FINAL U. S. Government clearance at the appropriate level. RESTRICTED DATA will be handled and controlled as indicated in the NISPOM. See “RESTRICTED DATA INFORMATION ADDENDUM”, Attachment 10b.
Ref 10.e.(1): SCI Access required. Contractor will require access to DCID's 1/7 (6/6) and 1/19 (6/1). Visitor Group will require access to AFPD 14-3, AFI 14-302 and DOD 5-5105.21-M-1 and DOD 5220.22-M. See “RELEASE OF SENSITIVE COMPARTMENTED INFORMATION (SCI) INTELLIGENCE INFORMATION TO US VISITOR GROUPS ADDENDUM”, attachment 10e1 Ref. 10.e.(2):. Access to Intelligence information required for performance. Visitor Group will require access to and comply with AFI 14-302 (DCID 1/7) and 14-303. Release of intelligence information does not create an unfair competitive advantage for the Visitor Group nor a conflict of interest with the Visitor Group’s obligation to protect the information. See “RELEASE OF NON-SENSITIVE COMPARTMENTED INFORMATION (NON-SCI) INTELLIGENCE INFORMATION TO US VISITOR GROUPS ADDENDUM”, attachment 10e2.
Ref. 10.f.: Access to SAP information requires a final U.S. Government clearance within the last five years at the appropriate access level and special briefings. AFOSI/PJ maintains cognizance over the SAP. The inspecting Industrial Security Representative must be briefed into the SAP (TBD) by the government program manager or designated representative prior to access to the SAP material. The cognizant SAP security office is responsible for providing the Visitor Group with the additional security requirements needed to ensure adequate protection of SAP information. If a SAP subcontract is awarded, the prime Visitor Group is responsible to incorporate the additional security requirements in the subcontract. The Program Manager must grant written authorization for release of SAP information to the subcontracting Visitor Group prior to issuance of any SAP subcontract.
Ref. 10.f.: To execute this contract, additional security requirements in addition to DoD 5220.22-M will be required. The Visitor Group shall comply with the security provisions of these programs. Marking and/or classification guidance for material originated or generated under this contract will be provided through the SAF/MG Security Manger under separate cover. Any material generated by the Visitor Group (including correspondence, drawings, models, mockups, photographs, schematics, progress, special and inspection reports, engineering notes, computations and training aids) shall be classified according to content. Guidance for classification shall be derived from the applicable Security Classification Guides, Government furnished equipment or data, or special instructions. Such material shall not contain Visitor Group logos or similar identifiers which identify the specific Visitor Group or team members. Reproduction and destruction of this material, regardless of the classification, is prohibited without written approval. Prior written approval from the AFOSI/PJ office is required for subcontracting. See “SPECIAL ACCESS INFORMATION ADDENDUM” attachment 10f.
Ref 10.g.: Special briefings are required for access to NATO IAW AFI 31-406, Applying NATO Protection Standards. Prior approval of the contracting activity is required for subcontracting. Personnel not assigned to a NATO staff position, but requiring access to NATO classified information, NATO COSMIC, NATO Secret or access to the NATO accredited SIPRNET terminals, must possess the equivalent FINAL or Interim U.S. Security Clearance based upon the appropriate personnel security investigation required. Personnel with access to NATO ATOMAL information must have the appropriate level FINAL U.S. Security Clearance at the appropriate level. The Visitor Group will maintain strict compliance in regards to NATO information IAW DoD 5220.22-M, February 28, 2006 National Industrial Security Program Operating Manual (NISPOM) Section 7. NATO Information Security Requirements.
Ref 10. k.: The GCA is responsible for providing the Visitor Group with the classification guidance necessary for the protection of the information. For Official Use Only (FOUO) information provided under this contract shall be safeguarded as specified in DoD 5400.7-R, DoD Freedom of Information Act Program, Chapter 4, dated Sep 1998. The Visitor Group is responsible for incorporating safeguards in the contract. See “FOR OFFICIAL USE ONLY (FOUO) ADDENDUM” attachment 10k.
Ref 11.a.: Contract performance is restricted to those locations specified in Item 8a or other approved locations as directed by the COR. Using activity will provide security classification guidance for performance of this contract.
Ref 11.a.: If the classified information is provided at the Visitor Group’s facility, ensure compliance with the provisions of DoD 5220.22-R, “Industrial Security Regulation,” December 4, 1985.
Ref. 11.e.: “YES” in this item will require a statement to explain the services and to provide appropriate guidance use the Preparation Guide for assistance.
Ref. 11.j.: Operations Security (OPSEC) protection for classified and sensitive unclassified information (as defined in Public Law 100-236, 9 January 1988) developed or used in performance of this contract. OPSEC requirements are contained in National Security Decision Directive 298 dated 23 January 1988. The project officer will forward these documents under separate cover. The prime Visitor Group may not impose OPSEC requirements on their subcontracting Visitor Group(s) unless the CO approves the OPSEC requirements.
Ref. 11.j.: See Contract Clause No.(TBD) for additional OPSEC requirements.
Item 13.: All classified visit requests by Visitor Groups shall be forwarded to the COR for approval and need-to-know certification before being sent to the facility to be visited. The COR must be notified and approve the receipt and/or generation of classified information under this contract. All classified information received and/or generated under this contract is the property of the U.S. Government regardless of proprietary claims. Upon completion or termination of this contract, the U.S. Government will be contacted for destruction or disposition instructions.
Item 13.: Some tasks being performed under this contract will require special security accesses and will only be granted as required for contract performance. Visitor Groups requiring special security accesses must be justified and approved by the government point of contact prior to security indoctrination. An inventory of regular classified information to include but on a separate list the material referenced in items 10a, 10f, and 10g as holdings. All classified information will be physically sighted by the local FSO agent and a formal listing will be forwarded to SAF/MG Security Manger by 30 April yearly and whenever there is a turnover of custodians.
Item 13.: In addition to the reporting requirements directed by the NISPOM, the Visitor Group will provide a concurrent report of loss or compromise of classified information to the SAF/MG Security Manger. Visit requests to activities other than those not listed in the statement of work on this DD 254 shall have "Need to Know" certified by the SAF/MG Security Manger Security Manager. All requests shall contain the information required by the NISPOM and shall not exceed a 12 month period.
Item 13.: All classified material received, generated, fabricated, or modified by this contract will be returned within 30 days after completion of contract or destroyed with destruction report being submitted to SAF/MG Security Manger Security Manager. Prior to any destruction of classified information a full listing of documents will be provided to the SAF/MG Security Manger Security Manager for review and approval. If additional contracting requirements exist where retention of classified information by the Visitor Group facility is required, a written request to retain material for a period but not to exceed 2 years is required.
Item 13.: Provide the information requested by the Notification of Government Security Activity Clause, AFFARS 5352.204-9000, and Visitor Group Security Agreements Clause, AFFARS5352.204.9001, to the Servicing Security Activity (SSA) address in block 17.f. of this form. Refer to the contract document for these clauses.
Item 13.: Non-Disclosure Agreement: The Visitor Group may be required to have access to highly sensitive and confidential plans and data for the performance of this delivery order. The Visitor Group will not divulge any information about activities or functions, or other knowledge gained, to anyone who is not authorized to have access to such information. It will be the Visitor Group’s responsibility to ensure that persons have the proper authority and “need to know” prior to any discussions. The Visitor Group will observe and comply with any security provisions.
Item 14, Ref 11.j.: OPSEC requirements - Prior approval of the GCA is required before a Prime Visitor Group can impose additional security requirements on a Subcontracting Visitor Group.
Item 15, Ref 10.e. (1). The 11W/IP has exclusive security responsibility for all SCI material released or developed under this contract and held within the Visitor Group’s SCIF. DSS is relieved of security inspection responsibility for all such material but retains responsibility for all non-SCI classified material released to or developed under the contract and held within the Visitor Group’s SCIF. DIA with trained DSS augmentees shall be responsible for reviewing the entire Visitor Group’s SCIF documentation to ensure compliance with SCI directives or regulations. SCI will be processed on an SCI accredited and approved system, located at (state location and name of facility (ies)). Reproduction and destruction of this material is prohibited without written approval from AF/SSO. In all cases, provide DSS a copy of the DD Form 254.
Item 15, Ref 10.f.: DSS has no responsibility for (TBD) SAP material. AFOSI/PJ has exclusive security responsibility for all SAP material released or developed under this contract.
Item 15, Ref. 11.a.: Industrial security reviews for long term visitor groups will be conducted by the SSA while operating on an Air Force Installation. The Visitor Group will comply with the visitor group security agreement provided by the USAF Program/Project Manager at the performance location.
Item 18.f.: REQUIRED DISTRIBUTION
1. 11 WG/IP, 1330 AF Pentagon, Washington DC 20330
2. Other CSO locations as prescribed by the contracting officer consistent with USAF requirements.
3. Other Headquarters Air Force, Major Commands, Deputy Combatant Commanders, Service Chief Mgmt Officers and Priciple Staff Assistants (TBD)
ATTACHMENT 2 ITEM 10A COMSEC
1. COMSEC material/information may not be released to DOD contractors without Air Force Cryptological Support Center (AFCSC) approval.
2. Contractor must forward requests for COMSEC material/information to the COMSEC officer through the program office.
3. The contractor is governed by the following DoD 5220.22-M, February 28, 2006 National Industrial Security Program Operating Manual (NISPOM) Section 4. Communications Security (COMSEC) in the control and protection of COMSEC material/information.
4. Access to COMSEC material by personnel is restricted to U.S. citizens holding final U.S. Government clearances. Such information is not releasable to personnel holding only reciprocal clearances.
5. The contractor will establish a COMSEC Account with : 844th CS, XXXX Air Force Pentagon, Washington DC 20330, xxx-xxx-xxxx
6. The contractor is governed by AFKAG-1, AFKAG-2, and appropriate Air Force Systems Security Instructions/Manuals (AFSSI/AFSSM) or Air Force Instructions (AFI). Access to COMSEC material or information is restricted to US citizens holding final U.S. Government clearances and is not releasable to personnel holding only a reciprocal clearance.
7. Personnel requiring COMSEC access shall be briefed in accordance with AFI 33-211(COMSEC User Requirements). NOTE: The COMSEC briefing applies only to the use and control of cryptographic equipment and specialized COMSEC publications. Additionally, cryptographic information/equipment shall be retained in a contractor facility user COMSEC account in accordance with current guidelines.
8. The Air Force program/project manager shall designate the number of personnel requiring COMSEC access. The number will be limited to the minimum necessary and will be on a strict need-to-know basis.
9. When COMSEC support, including STU III, is provided by an AF COMSEC Account, the contractor must comply with AFI 33-211 and AFI 33-209.
ATTCHMENT 3 ITEM 10B RD
Policy: DoD 5200.1-R, Information Security Program; DoD Directive 5210.2, Access To and Dissemination of Restricted Data; and Atomic Energy Act of 1954
1) Contractor is permitted access to Restricted Data (RD) in performance of this contract. CONFIDENTIAL security clearance eligibility is not valid for access to Restricted Data. Contractors must comply with all instructions and guidance provided by the servicing AF Activity security manager. Prior approval of the contracting activity is required for subcontracting.
2) Definitions:
a) Restricted Data (RD). Information which is classified and controlled under the Atomic Energy Act of 1954. It is all data (information) concerning design, manufacture, or utilization of atomic weapons; the production of special nuclear material; or the use of special nuclear material in production of energy. The term does not include data declassified or removed from the Restricted Data category pursuant to section 142 of the Atomic Energy Act of 1954, as amended (reference (b)). (Also see “Formerly Restricted Data.”)
b) Access. Within and between DoD Components, to include contractor activities, access to Restricted Data (RD) information will be governed by the same procedures and criteria required for access to other classified information:
i) Require access in performance of official duties.
ii) Have a final US Government security clearance at a level commensurate with the information concerned.
iii) Access requires in-brief by the servicing AF activity security manager, documentation of AF Form 2583, and indoctrination via the Joint Personnel Adjudication System (JPAS). Item 10b of the DD Form 254 will always be marked “YES” when Item 10c (CNWDI) is marked “YES.”
iv) Requests for access to Restricted Data in the possession of the DOE or other Federal Agencies designated by the Department of Energy (DOE), other than the Department of Defense and NASA, are submitted via DOE Form 277, Request for Visit or Access Approval. (Refer to DoDD 5210.2 for further information.)
c) Dissemination. Restricted Data dissemination will be governed by the same procedures and criteria as govern the dissemination of other classified information. DoD personnel may disseminate Restricted Data information only under the following guidelines:
i) Within and between the DoD Components, to include DoD contractors.
ii) To properly cleared Department of Energy (DOE) personnel and to DOE-cleared personnel of other Federal Agencies.
iii) Restricted Data information pertaining only to nuclear research reactors or nuclear electric power generating reactors may be made to Nuclear Regulatory Commission (NRC) personnel, i.e., DoD, State Department, NASA, etc. Restricted Data not related to these reactors may be released to NRC personnel only through the DOE.
iv) Restricted Data information other than that pertaining to aeronautical and space activities may be released to NASA personnel only through the DOE.v) In all above cases, dissemination of Restricted Data information will be made only after the holder of the information has verified:
(a) Identification of the prospective recipient
(b) The validity of the prospective recipient’s security clearance (via JPAS)
(c) The “need-to-know” of the prospective recipient in connection with official duties
3) Dissemination of Restricted Data (and Formerly Restricted Data) to any nation or regional defense organization, or to a representative thereof, is prohibited; except in accordance with agreements for cooperation, entered into pursuant to section 123 of the Atomic Energy Act of 1954, as amended (reference (b)).
4) Except as provided above, Formerly Restricted Data will be treated and disseminated in the manner prescribed for classified information in DoD 5200.1-R.
5) Marking. Classified information marking will be in accordance with Air Force-adopted Controlled Access Program Coordination Office (CAPCO) standardized marking guidelines. Additional classified marking guidance (including country trigraph codes) is located on the SIPRNet CAPCO page at http://capco.dssc.sgov.gov .
6) Contact your servicing AF activity security manager for additional assistance.
ATTACHMENT 4: 10e1 SENSITIVE COMPARTMENTED INFORMATION (SCI)
1. Requirements for access to SCI:
a) No public release of information authorized, public disclosure or confirmation of any subject related to the support contract is not authorized without first obtaining written approval from the CO.
b) Prior approval of contracting activity is required for subcontracting.
c) Access to Intelligence information requires SCI indoctrination and a final Top Secret U.S. Government clearance.
d) All SCI will be handled in accordance with special security requirements which will be furnished by the designated responsible special security office (SSO). Security Classification Guides or extracts are attached or will be provided under separate cover.
e) SCI will not be released to contractor employees without specific release approval of the originator of the material as outlined in governing directives; based on prior approval and certification of "need-to-know" by the designated contractor.
f) Contractors will not release this information to any activity or person not directly engaged in providing services under the contract or to another contractor (including subcontractors), government agency, private individual, or organization without written prior approval.
g) Intelligence material will not be released to foreign nationals or immigrant aliens who may be employed by the contractor, regardless of the level of their security clearance or access authorization, except with specific written permission.
2. The contractor will submit the request for SCI visit certifications .through the CM for approval of the visit. The certification request must arrive at the Contractor Support Element at least ten (10) working days prior to the visit. Visit certification requests will be processed through JCAVS.
a) Upon receipt of written approval from the CM, the company security officer will submit request(s) for special background investigations in accordance with the NISPOM, to the Intelligence Support Office. The entire personnel security questionnaire package should not be forwarded to the Intelligence Support Office. The Contractor Special Security Officer (CSSO) must follow the instructions provided by the Intelligence Support Office to the CSSO.
(1) Contractors will maintain records which will permit them to furnish, on demand, the names of individuals who have access to intelligence material in their custody.
(2) Names of contractor personnel requiring access to SCI will be submitted to the contract monitor (CM) for approval.
b) Inquiries pertaining to classification guidance on SCI will be directed through the CSSO to the responsible CM.
3. SCI furnished in support of this contract remains the property of the Department of Defense (DoD) department, agency, or command originator. Intelligence information does not become the property of the contractor and may be withdrawn at any time. Upon completion or cancellation of the contract, SCI furnished will be returned to the direct custody of the supporting SSO, or destroyed IAW instructions outlined by the CM.
a) SCI will be stored and maintained only in properly accredited facilities at the contractor location.
b) All intelligence material will bear a prohibition against reproduction while in the custody of the contractor.
c) Any reproduction and destruction of this material, regardless of the classification, is prohibited without written approval of the CM.
4. All DD Forms 254 prepared for subcontracts involving access to SCI under this contract must be forwarded to the CM for approval and then to HQ AF SSO, for review and concurrence prior to award of the subcontract.
5. The contract monitor (CM) will:
a) Review the SCI product for contract applicability and determine that the product is required by the contractor to complete contractual obligations. After the CM has reviewed the SCI product(s) for contract applicability and determined that the product is required by the contractor to complete obligations, the CM must request release from the originator through the Intelligence Division. Originator release authority is required on the product types below:
(1) Documents bearing the control markings of ORCON, PROPIN.
(2) GAMMA controlled documents.
(3) Any NSA/SPECIAL marked product.
(4) All categories as listed in USAF Intel 201-1.
b) Prepare or review contractor billet/access requests to insure satisfactory justification (need-to-know) and completeness of required information.
c) Approve and coordinate visits by contractor employees when such visits are conducted as part of the contract effort.
d) Maintain records of all SCI material provided to the contractor in support of the contract effort. By 15 January (annually), provide the contractor, for inventory purposes, with a complete list of all documents transferred by contract number, organizational control number, copy number, and document title.
e) Determine dissemination of SCI studies or materials originated or developed by the contractor.
f) Within 30 days after completion of the contract, provide written disposition instructions for all SCI material furnished to, or generated by, the contractor with an information copy to the supporting SSO.
g) Review and forward all contractor requests to process SCI electronically to the accrediting SSO for coordination through appropriate SCI channels.
6. Request for release of intelligence material to a contractor must be prepared by the contract monitor (CM) and submitted to the Intelligence Support Office. This should be accomplished as soon as possible after the contract has been awarded. The request will be prepared and accompanied with a letter explaining the requirement and copies of the DD Form 254 and Statement of Work.
ATTACHMENT 5: 10e2 NON-SENSITIVE COMPARTMENTED INFORMATION (NON-SCI) INTELLIGENCE INFORMATION TO US CONTRACTORS ADDEMDUM
1. Requirements for access to non-SCI Intelligence Information:
a. Non-SCI Intelligence Information is not releasable to contractor employees who have not received a FINAL clearance at the appropriate security level.
b. Contractors will maintain records which will permit them to furnish, on demand, the names of individuals who have access to intelligence material in their custody.
c. All intelligence material released to the contractor remains the property of the US Government and may be withdrawn at any time. The contractor must maintain accountability for all classified intelligence released in his/her custody.
d. Contractors will not release this information to any activity or person not directly engaged in providing services under the contract or to another contractor (including subcontractors), government agency, private individual, or organization without prior written approval of SAF/MG Security Managers and HQ USAF/SSO.
e. Upon expiration of the contract, all intelligence released and any material using data from the intelligence will be returned to the project officer or COR for final disposition.
f. Written concurrence of the CO is required prior to subcontracting.
g. All intelligence material will bear a prohibition against reproduction while in the custody of the contractor. The contractor must not reproduce intelligence material without the written permission of the originating agency through the HQ USAF/SSO. If permission is granted, each copy shall be controlled in the same manner as the original.
h. The contractor must not destroy any intelligence material without advance approval or as specified by the contract monitor (CM). EXCEPTION: Classified waste shall be destroyed as soon as practicable in accordance with the provisions of the Industrial Security Program).
i. The contractor must restrict access to only those individuals who possess the necessary security clearance and who are actually providing services under the contract with a valid need to know. Further DISSEMINATION to other contractors, subcontractors, other government agencies, private individuals or organizations is prohibited unless authorized in writing by the originating agency through the CM.
j. The contractor must ensure each employee having access to intelligence material is fully aware of the special security requirements for this material and shall maintain records in a manner that will permit the contractor to furnish, on demand, the names of individuals who have had access to this material in their custody.
k. Intelligence material must not be released to foreign nationals or immigrant aliens whether they are consultants, US contractors, or employees of the contractor and regardless of the level of their security clearance, except with advance written permission from SAF/MG. Requests for release to foreign nationals shall be initially forwarded to the contract monitor and shall include:
i. A copy of the proposed disclosure.
ii. Full justification reflecting the benefits to US interests.
iii. Name, nationality, particulars of clearance, and current access authorization of each proposed foreign national recipient.
l. Upon completion or termination of the classified contract, or sooner when the purpose of the release has been served, the contractor will return all classified intelligence (furnished or generated) to the source from which received unless retention or other disposition instructions are authorized in writing by the CM.
m. The contractor must designate an individual who is working on the contract as custodian. The designated custodian shall be responsible for receipting and accounting for all classified intelligence material received under this contract. This does not mean that the custodian must personally sign for all classified material. The inner wrapper of all classified material dispatched should be marked for the attention of a designated custodian and must not be opened by anyone not working directly on the contract.
n. Within 30 days after the final product is received and accepted by the procuring agency, classified intelligence materials released to or generated by the contractor, must be returned to the originating agency through the contract monitor unless written instructions authorizing destruction or retention are issued. Request to retain material shall be directed to the CM for this contract in writing and must clearly indicate the justification for retention and identity of the specific document to be retained.
o. Classification and declassification marking of documentation produced by the contractor shall be consistent with that applied to the information or documentation from which the new document was prepared. If a compilation of information or a complete analysis of a subject appears to require a security classification other than that of the source documentation, the contractor shall assign the tentative security classification and request instructions from the contract monitor. Pending final determination, the material shall be safeguarded as required for its assigned or proposed classification, whichever is higher, until the classification is changed or otherwise verified.
2. Intelligence material carries special markings. The following is a list of the authorized control markings of intelligence material:
a. "Dissemination and Extraction of Information Controlled by Originator (ORCON)." This marking is used, with a security classification to enable a continuing knowledge and supervision by the originator of the use made of the information involved. This marking may be used on intelligence which clearly identifies, or would reasonably permit ready identification of an intelligence source or method which is particularly susceptible to countermeasures that would nullify or measurably reduce its effectiveness. This marking may not be used when an item or information will reasonably be protected by use of other markings specified herein, or by the application of the “need-to-know” principle and the safeguarding procedures of the security classification system.
b. “Not Releasable to Foreign Nationals (NOFORN). ” This marking must be used with a security classification to identify intelligence that may not be released in any form to foreign governments, foreign nationals, or non-US government originator, and than only when released in compliance with the National Disclosure Policy.
c. "Authorized for Release to (Name of Country(ies) or International Organization." The above is abbreviated "REL _________." This marking must be used when it is necessary to identify classified intelligence material the US government originator has predetermined to be releasable or has been released through established foreign disclosure channels to the indicated country(ies) or organization.
3. The following procedures govern the use of control markings.
a. Any recipient desiring to use intelligence in a manner contrary to restriction established by the control marking set forth above shall obtain the advance permission of the originating agency through the CM. Such permission applies only to the specific purposes agreed to by the originator and does not automatically apply to all recipients. Originators shall ensure that prompt consideration is given to recipients' requests in these regards, with particular attention to reviewing and editing, if necessary, sanitized or paraphrased versions to derive a text suitable for release subject to lesser or no control markings.
b. The control marking authorized above shall be shown on the title page, front cover, and other applicable pages of documents, incorporated in the text of electrical communications, shown on graphics, and associated (in full or abbreviated form) with data stored or processed in automatic data processing systems. The control marking also shall be indicated by parenthetical use of the marking abbreviations at the beginning or end of the appropriate portions. If the control marking applies to several or all portions, the document must be marked with a statement to this effect rather than marking each portion individually.
c. The control markings shall be individually assigned at the time of preparation of intelligence products and used in conjunction with security classifications and other marking specified by E.O. 12958 and its implementing security directives. The marking shall be carried forward to any new format in which the same information is incorporated including oral and visual presentations.
4. Request for release of intelligence material to a contractor must be prepared by the contract monitor (CM) and submitted to the HQ USAF/SSO. This should be accomplished as soon as possible after the contract has been awarded. The request will be prepared, explaining the requirements and copies of the DD Form 254 and Statement of Work.
ATTACHMENT 6: 10F SPECIAL ACCESS INFORMATION (SAP)
Special Access Information: Special Access Programs (SAP) imposes security requirements on the contractor that exceed the NISPOM. When SAP information is involved, the cognizant SAP security office is responsible for providing the contractor with the additional security requirements needed to ensure adequate protection of SAP information which supports numerous Special Access Programs throughout the Air Force. These programs include space and weapons systems in all stages of the Acquisition life cycle. This is an Advisory and Assistance Services (A&AS) support contract to support the Deputy Assistant Secretary of the Air Force Office of Business Transformation (SAF/MG) and Deputy Chief Management Officer (DCMO) in managing and improving Strategic Transformation Initiatives at the enterprise level, that provides management and professional services, studies, research, analyses, and evaluations expertise and recommendations across the breadth of programs over which SAF/MG has purview. Thus, the SAP requirement is not tied to any one program, system or capability. The access requirements for a given contractor employee will vary according to the program needs and security requirements of the given program.
SECTION 1 – Core Security Guidance: (applies to ALL SAP-related DD Form 254s)
1. The following core security guidance must be followed on this contract:
a. DoD 5220.22-M, National Industrial Security Program Operating Manual (NISPOM), (latest version
b. DoD Directive (DoDD) 5205.07, Special Access Program (SAP) Policy, as supplemented
c. DoD Instruction (DoDI) 5205.11, Management, Administration, and Oversight of DoD Special Access Programs (SAPs)
d. DoD Manual (DoDM) 5205.07, Volume 1 - AFMAN 16-703 V1, DoD Special Access Program (SAP) Security Manual: General Procedures (*Note – AFMAN 16-703 V1 is cited in anticipation of publication in Sep/Oct 2016)
e. DoD Manual (DoDM) 5205.07, Volume 2 - AFMAN 16-703 V2, Special Access Program (SAP) Security Manual: Personnel Security (*Note – AFMAN 16-703 V2 is cited in anticipation of publication in Sep/Oct 2016)
f. DoD Manual (DoDM) 5200.01, Volume 1, DoD Information Security Program: Overview, Classification and Declassification
g. DoD Manual (DoDM) 5200.01, Volume 2, DoD Information Security Program: Marking of Classified Information
h. DoD Manual (DoDM) 5200.01, Volume 3, DoD Information Security Program: Protection of Classified Information
i. DoD Manual (DoDM) 5200.01, Volume 4, DoD Information Security Program: Controlled Unclassified Information (CUI)
j. AF Policy Directive (AFPD) 16-7, Special Access Programs
k. AF Instruction (AFI) 16-701, Management, Administration, and Oversight of Special Access Programs
l. SAF/AAZ Memorandum, “Implementing DoD Manual 5205.07, V4, SAP Manual: Marking, United States Air Force Security Marking Guide for Special Access Programs, (latest version)
m. SAF/AAZ Memorandum, “Implementation of DoDM 5205.07, DoD Special Access Program (SAP) Security Manual, Volumes 1-4” (dtd 4 April 2016)
n. Include the following website addresses for both DoD issuances and AF e-publishing websites:
i. DoD issuances website: http://www.dtic.mil/whs/directives/
ii. AF e-Publications website: http://www.e-publishing.af.mil/ SECTION 2 – Classified Storage & Safeguarding: (only if classified storage is required/ authorized)
1. The following security guidance must be followed on this contract:
a. DoD Manual (DoDM) 5205.07, Volume 3 - AFMAN 16-703 V3, DoD Special Access Program (SAP) Security Manual: Physical Security
b. DoDM 5205.07, Volume 4, SAP Security Manual: Marking, (latest version)
c. SAF/AAZ Memorandum, “Implementing DoD Manual 5205.07, V4, SAP Manual: Marking, United States Air Force Security Marking Guide for Special Access Programs, (latest version)
d. SAF/AAZ Memorandum, “Implementation of DoDM 5205.07, DoD Special Access Program (SAP) Security Manual, Volumes 1-4” (dtd 4 April 2016) SECTION 3 - Processing:
1. The following core security guidance must be followed on this contract:
a. Risk Management Framework (RMF) using the Joint Special Access Program Implementation Guide (JSIG), dated 9 October 2013, or latest version
b. NSA/CSS Policy Manual 3-16, Control of COMSEC Material, latest version.
2. Communications Security (COMSEC) User Requirements,
a. AFI 33-201V2, Change 2, dtd 22 Sep 2011
b. Operational Instructions for Secure Voice Devices, AFI 33-201V9, dtd 13Apr 2005
3. TEMPEST requirement add the following guidance:
a. CNSSAM TEMPEST/01-13, RED/BLACK Installation Guidance, 17 Jan 2014, or latest version NOTE: “Supersession of any of the above documents will not require an immediate revision to this DD Form 254. The updated document will be deemed to be on contract as of the date of supersession. Additional costs incurred due to updated guidance will be brought to the attention of the GCO immediately.
SECTION 4 – Security Classification Guides (SCGs): Since work will be performed at Gov facilities, personnel will abide by all SCG's for which the facility is cleared for.
ATTACHMENT 7: 10J CONTROLLED UNCLASSIFIED INFORMATION (CUI)
IDENTIFICATION AND PROTECTION OF CUI
1. GENERAL. In addition to classified information, certain types of unclassified information also require application of access and distribution controls and protective measures for a variety of reasons. In accordance with Reference (e), such information is referred to collectively as CUI. This enclosure identifies the controls and protective measures developed for DoD CUI (i.e., For Official Use Only (FOUO), Law Enforcement Sensitive (LES), DoD Unclassified Controlled Nuclear Information (DoD UCNI), and LIMITED DISTRIBUTION) as well as some of those developed by other Executive Branch agencies. This enclosure also addresses handling of certain foreign government information and the use of distribution statements on unclassified technical documents as a means to facilitate control, distribution, and release of such documents.
a. In accordance with Reference (b), information may not be designated CUI to:
(1) Conceal violations of law, inefficiency, or administrative error;
(2) Prevent embarrassment to a person, organization, or agency;
(3) Restrain competition; or
(4) Prevent or delay the release of information that does not require protection under statute or regulation.
b. Information shall not be designated CUI:
(1) To prevent or avoid its proper classification in accordance with the requirements of Reference (d) and Volume 1 of this Manual; or
(2) If there is significant doubt concerning the need for such designation in accordance with section 3.b of Reference (e)
c. Information that has been disclosed to the public under proper authority may not be subsequently designated or re-designated CUI.
d. The originator of a document is responsible for determining at origination whether the information may qualify for CUI status, and if so, for applying the appropriate CUI markings. However, this responsibility does not preclude competent authority (e.g., officials higher in chain of command; functional experts) from modifying the marking(s) applied or originally applying additional markings. In such cases, the originator shall be notified of the changes.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .