Attachment 3 - DD Form 254.pdf
PDF 318 KB Posted
- Attached to
- ATC Test Support Services Federal contract opportunity
- Solicitation number
- W91CRB-21-R-0016
About this file
This DD Form 254 is a contract security classification specification outlining classified information access requirements for a test support services contract with the US Army Aberdeen Test Center. The contractor will require access to classified COMSEC material up to the Secret level once obtaining a final clearance. The contractor must adhere to COMSEC rules and regulations when accessing such information at government facilities. Subcontracting is subject to written approval from the contracting officer. The contractor will provide test support services including ammunition operations, compliance and program support, engineering and scientific support, facilities design and maintenance, test instrumentation operation, marine operations and maintenance, vehicle and equipment operations and maintenance, technical test support, and test range and facility operations support to assist with the Aberdeen Test Center's test and evaluation mission.
View the file
Other files for this federal contract opportunity
Show all 27
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Please wait...
If this message is not eventually replaced by the proper contents of the document, your PDF viewer may not be able to display this type of document.
You can upgrade to the latest version of Adobe Reader for Windows®, Mac, or Linux® by visiting http://www.adobe.com/go/reader_download.
For more assistance with Adobe Reader visit http://www.adobe.com/go/acrreader.
Windows is either a registered trademark or a trademark of Microsoft Corporation in the United States and/or other countries. Mac is a trademark of Apple Inc., registered in the United States and other countries. Linux is the registered trademark of Linus Torvalds in the U.S. and other countries.
ATTACHMENT ONE (Continuation of Block 13 of the DD Form 254 for Contract To Be Determined)
13. Security Guidance.
Item 10f. Discussion, storage or processing of SAP information associated with this contract will be restricted to US Army Aberdeen Test Center (ATC), 6943 Colleran Road, Aberdeen Proving Ground, Maryland 21005-5059. The facilities will be specifically accredited by the Army SAPCO (or designee), or equivalent component-level SAPCO. SAP activities are governed by Revision 1 Department of Defense Overprint to the National Industrial Security Program Operating Manual Supplement, 1 April 2004 and applicable program security classification and procedures guides. Component-managed SAPFs and SAP Temporary Secure Working Areas (TSWA) are governed by the Intelligence Community Directive-705 (ICD-705). In addition, SAPFs and SAP TSWA are governed by Department of Defense Manual 5205, Volumes one through four.
Access to SAP information requires employees undergo additional personnel security screening and meet the policies. SAP inspections and security oversight while at ATC are under the cognizance of the SAPCO, as appropriate. ATC Security and Intelligence Division will conduct SAP briefings and debriefings as required for contractor personnel, refer to Army Regulation 380-381, Special Access Programs and Sensitive Activities.
Contractor personnel accesses to SAPs are subject to random selection for counterintelligence scope polygraph examinations IAW DOD Regulation 5210.48.
Failure of selected individual to submit to polygraph examination may result in their access to SAP information being suspended. No subcontracting efforts for SAPs will be initiated without written approval by the ATC Security Manager and the Contracting Officer (KO). SAP information generated in performance of this contract is strictly prohibited for release to foreign nationals. See Attachment Three of this DD Form 254 for the SAP Addendum.
Item 10j. This contract does require access to Controlled Unclassified Information (CUI). All CUI information that is generated, handled and stored will be in compliance with the Department of Defense Manual Number 5200.01, Volume 4, DoD Information Security Program: Controlled Unclassified Information (CUI). This manual provides guidance for the identification and protection of CUI.
Item 11a. Contractor performance does require travel beyond the boundaries of APG during the course of the contract for training or work to be accomplished at sites other than APG. The contractor shall have personnel available and ready to travel on the required date. ATC is engaged in remote testing and test support at sites all over the CONUS as well as OCONUS. The contractor shall have the capability to support the remote testing using the personnel that are already supporting ATC’s mission at APG.
There will be no access to classified information at the contractor’s facility. Therefore, the contractor will not be required to have any safeguarding capability at their facility.
All access to classified information will be at a Government Activity or another contractor’s facility should a contract employee need to accompany a government employee in support of a classified item away from ATC.
ATTACHMENT ONE (Continuation of Block 13 of the DD Form 254 for
Item 11j. The contract requires planning for and application of OPSEC in accordance with Army Regulation 530-1, Operations Security (OPSEC) and the contract clauses and statement of work. OPSEC guidance will also be provided as applicable for each project or program affected by this support. In addition, the ATC Security Manager shall advise the contractor of ATC’s Critical Information (CI), why it needs to be protected, where it is located, who is responsible for it and how to protect it. Individual security classification guides and test plans will be provided by ATC for performance of this contract as needed.
Item 11m. Secret Internet Protocol Network (SIPRNET) access required. The contractor shall not access, download or further disseminate any special access data (i.e.
intelligence, NATO, COMSEC, etc.) outside the execution of the defined contract requirements and without the guidance and written permission of the KO, ATC Information Assurance Manager (IAM) and ATC Security Manager.
ATTACHMENT TWO (Continuation of Block 14 of the DD Form 254 for
14. Additional Security Requirements.
Facility Clearance. The contractor shall possess a TOP SECRET Facility Clearance as prescribed by the DD Form 254, Contract Security Classification Specification.
Verification by the ATC Security and Intelligence Division shall be made to the Defense Security Service (DSS) using the National Industrial Security Program (NISP) Central Access Information Security System (NCAISS).
Preliminary Security Screening for Non-classified Internet Protocol Router Network (NIPRNET) Access. All contractor access control employees shall be capable of acquiring a final SECRET clearance in order to provide classified support on this contract. All contractor Special Access employees shall be capable of acquiring a final TOP SECRET in order to provide special access support to this contract. However, to initially provide unclassified support to this contract and to gain Non-classified Internet Protocol Router Network (NIPRNET) access, a new contract employee must have at a minimum an Interim SECRET clearance.
Personnel Security Clearances. All contractor employees shall possess at a minimum a final SECRET clearance. Once an interim and/or final SECRET clearance is granted, every new contract employee will receive a security indoctrination briefing. This briefing will be conducted within 30 days of issuance of a security clearance. This briefing will at a minimum include the following topics: general security education, OPSEC awareness, Information Systems Security, Force Protection, and training on the Threat Awareness Reporting Program (TARP). This training will also provide any additional security training that may be job specific to the duties performed by the contractor. The contractor will notify the government in writing when this initial security training has been completed. Contractor employees who support a SAP under this contract must possess a final TOP SECRET clearance in order to gain access to the Army Special Access Program (SAP) Enterprise Portal (ASEP). Contractor personnel shall not report to work until at a minimum, an interim SECRET clearance is granted. However, the performance of some tasks will require the contractor to have a final TOP SECRET clearance at the start date of this contract in order to gain access to the ASEP which is housed at the Government facility. The company is required to maintain a TOP SECRET facility clearance since they employ an employee that may require access to a TOP SECRET computer system. The contract employee will not be accessing TOP SECRET level information. They will only be accessing a TOP SECRET computer system. A visit request will be submitted annually via the Joint Personnel Adjudication System (JPAS) to the ATC SMO code of W4QUAA by the Facility Security Officer (FSO) or Alternate FSO. In addition, the contractor shall prepare a roster of current employees which includes each employee’s name, social security number, and level of security clearance. This roster shall be verified and signed by the FSO or Alternate FSO and submitted to the ATC Security Manager. This roster shall be updated as required to reflect any changes in employee’s status or information. At the conclusion of this contract, the FSO or Alternate FSO, will submit a termination letter to the ATC Visitor Desk and a copy sent to the ATC Security Manager. Contract personnel whose security clearances are suspended shall not be permitted to work under this contract until their security clearance is reinstated.
Information Systems (IS) Access. The contractor shall designate Information Technology (IT) positions for all personnel requiring access to IS in accordance with Army Regulation 25-2, Information Assurance, Army Regulation 25-1, Army Knowledge Management and Information Technology Management, Army Regulation 380-67, Department of the Army Personnel Security Program and Army Regulation 380-5, Department of the Army Information Security Program. ATC computer related positions will be designated as IT 1, 2, or 3. The contractor shall request the appropriate personnel security investigation based upon the IT position designation. The investigations must be favorably completed prior to employees being permitted access to IS and being placed in an IT position. All positons under this contract are designated as IT 3. The contractor shall prepare a list identifying this IT position designation and submit to the ATC Cyber Security Directorate and the ATC Security Manager. In accordance with Army Regulation 25-1, all employees requesting access to an IS shall be required to sign an Acceptable Use Policy (AUP) and adhere to the policies outlined in the document regarding acceptable use of Government-owned computer systems and networks. This document will be reviewed and signed annually thereafter. Also, prior to gaining access to a government computer system, all employees must take initial Information Assurance (IA) training and annually thereafter. This is mandatory on line training which will be completed by scheduling an appointment with the Cybersecurity Office. All Army IS will be used for OFFICIAL business only. Using Army IS to access pornographic, game, militia or similar sites is strictly prohibited. Access to chat rooms (except AKO chat), use of commercial email addresses to send or receive DoD information, and use of Army IS to download shareware is also strictly prohibited. The contractor shall ensure that all IS used by contractor personnel are protected and accredited in accordance with Army Regulation 25-2 and related supporting directives and AUP guidance published by ATC.
Any DoD information processed on either Government furnished or contractor furnished computers belongs to the Government. During the Phase-In period, the Contractor shall complete a Request for Access (DD Form 2875 System Authorization Access Request) and Non-Disclosure Statement to ATC Computer Systems for the designated employees.
This form shall be returned to the Government designee after completion. Where applicable, the contractor shall recommend through the COR to the ATC IAM the appointment of an Information Assurance Security Officer and alternate(s). Prior to any classified work being processed on an IS regardless of location, approval must be obtained by the ATC Information Assurance Manager and the ATC Security Manager.
Usage of Privately Owned Personal Electronic Devices (PEDs) Within the Restricted Area (RA). A privately owned personal electronic device (PED) is defined as a civilian multifunction cell phone, personal digital assistant, tablet, blackberry, personal wireless fitness devices (PWFD), digital inventory devices and electronic recording/storage devices. Contractor personnel shall not use the PED’s photographic/recording capability within the ATC Restricted Area (RA). The contractor shall not install or connect a privately owned PED to any government-owned computer or network system. Also, a PED that has the capability to store data cannot be connected to a government computer for purposes of charging the device’s battery. Contractor employees must use the appropriate wall adapter to charge a privately owned PED. All PEDs (government or personal) are prohibited in any area that contains a Secure Internet Protocol Router Network (SIPRNET) connection; in any area or briefing room where classified material is being discussed; and in any area designated as a Special Access Program (SAP) area.
PEDs are authorized for private, non-work related matters. Under no circumstances will a privately owned PED be used to transmit sensitive government information.
Reports of Adverse Information. The contractor shall report to the ATC Security Manager immediately all adverse information on contractor personnel such as security violations, arrests, bankruptcy, wage garnishments and denial, suspension, or revocation of security clearances. The ATC Security Manager may deny employees’ access into APG restricted areas based upon the adverse information.
Installation Access. All contractor personnel will comply with the requirements of APG Regulation 190-4, Movement Control Within the Installation, for entry, exit, and internal control of personnel, material and vehicles on APG. To gain access to APG, DA Form 1602, Civilian Identification Card, shall be issued to contractors who do not require computer access or do not travel on official Government business upon written approval from the COR. All vehicles and personnel are subject to search and seizure of contraband and/or unauthorized Government property in accordance with Army Regulation 190-13, The Army Physical Security Program.
Unescorted Access into Restricted Areas. Unescorted access will be permitted into the APG restricted area provided the contractor employee was issued an interim or final SECRET clearance by the Department of Defense (DOD) Central Adjudication Facility (CAF). Most areas of ATC are within the restricted areas of APG.
Restricted Area (RA) Security Identification Credential. Contractor personnel will be granted unescorted access provided the security clearance requirement stated above has been met. Once a written request from the COR has been received and the security clearance has been verified by the visit authorization letter or a visit request submitted via JPAS, the contractor employee will have their Department of Defense Common Access Card (CAC) programmed for unescorted access into the RA. At the same time the contract employee’s CAC is programmed, they will be issued an organizational credential to be used while in the RA. This credential identifies that the employee has an official need to be in the RA. If a contractor requires camera pass authority, their government point of contact must send an email to ATC Security justifying why the individual needs camera authorization in the RA. Once approved by ATC Security, a camera pass icon will be placed on the organizational credential. At no time will a contractor be permitted to take any type of photographs, video or recording with their personal cellular or Smartphone while in the Restricted Area (RA). Contractor personnel will wear their security credential above the waist at all times when in the restricted areas of APG with the following exceptions: (a) when photography is ongoing and the employee is likely to be in the photograph, and (b) when the employee is actually working with a piece of equipment that could catch the security credential and endanger the safety of the employee.
Photographic and Recording Permits. The Contractor shall obtain applicable permits to use government issued only photographic and recording equipment within APG restricted areas. Contractor employees who must take photographs in the course of their official duties shall ensure that they have the camera icon on their security area picture badge. At no time will a contractor be permitted to take any type of photographs, video or recording with their personal cellular or Smartphone. All images/video captured in the restricted area are for official purposes only and must be OPSEC reviewed/approved prior to distribution. In order to take recording devices (other than personal cellular or Smartphone) into the restricted areas, the contractor employee must get written permission from the ATC Security Manager.
Common Access Card. All contractor employees who require computer access or travel on official Government business shall be issued a Department of Defense Common Access Card (CAC) through the Defense Enrollment Eligibility Reporting System (DEERS). CACs are processed in accordance with the guidelines for the Trusted Associate Sponsorship System (TASS). The contractor organization security manager gets the upcoming applicant vetted per requirements and forwards that information to the COR who is the Trusted Agent (TA) identified in the TASS. Once the TA receives the required information, it is entered into the TASS. The system generates an ID and new applicant password. The ID and password is forwarded to the applicant who will enter this information into TASS. The system will receive this information and it will notify the applicant with an approval email. Once the TA approves issuance of a CAC to the applicant through the TASS, the applicant can go to the nearest RAPIDS center with the proper identification and will be processed for a CAC which will be issued to them on the spot.
Safeguarding Government Information and Property. The contractor shall be responsible for safeguarding all Government information and property provided for contractor use. The contractor shall safeguard information and material designated as classified, unclassified sensitive, Controlled Unclassified Information (CUI), Operations Security (OPSEC) sensitive, and Personally Identifiable Information (PII) in accordance with applicable directives stated in Item 13 (Security Guidance). The contractor will not release any work related information to the public without prior authorization. In addition, the contractor will not post any personal comments associating them with working for the federal government or any type of work related information on social media platforms. This includes discussion forums, blogging, etc. Contractor personnel who have access to the Army Test and Evaluation Command (ATEC) Decision Support System (ADSS) will not disclose ADSS information to any person or entity without explicit authority. Government-furnished property will be secured in accordance with AR 190-51, Security of Unclassified Army Property (Sensitive and Nonsensitive).
Foreign Nationals/Immigrant Aliens. Foreign nationals/immigrant aliens cannot be granted unescorted access to the restricted area, and shall not be scheduled to perform work under this contract. However, when foreign nationals/immigrant aliens visit ATC, the contractor shall comply with Army Regulation 380-10, Foreign Disclosure and Contacts with Foreign Representatives and local policies.
Loss or Possible Compromise of Classified Information. The contractor shall immediately report the loss or possible compromise of classified information or material to the ATC Security Manager or his designee in accordance with ATC Regulation 380-5, Information Security Program. In the event that there is a data spillage, the contractor will immediately notify their government supervisor, ATC Security Manager or his designee and the ATC Information Assurance Manager.
Courier Card. The contractor may be required to hand carry classified material from one location on the installation to another location. Also, the contractor may be required to hand carry classified to another cleared facility or military organization. In accordance with Army Regulation 380-5, Department of the Army Information Security Program, the contractor will be in possession of the DD Form 2501, Courier Authorization Card. The card authorizes the appropriately cleared government civilian and contractor to hand carry classified material. The contractor’s level of clearance will be the same level of classified material that is being hand carried. If a contractor needs a DD Form 2501, their government sponsor must submit a written request to the COR. The COR will forward request to ATC Security for approval and subsequent issuance of the card. A courier briefing will be given by ATC Security to all courier card holders prior to issuance of the card. If the contractor loses access or leaves employment with the contractor, the card will be returned to ATC Security.
Key Control. The contractor shall have access as needed to all Government-furnished facilities in accordance with Army Regulation 190-11, Physical Security of Arms, Ammunition and Explosives, Army Regulation 190-51, Security of Unclassified Army Property (Sensitive and Nonsensitive), Army Regulation 380-5, Department of the Army Information Security Program and ATC Regulation 380-8, Security Key and Lock Control. The contractor shall develop and implement procedures to account for, control and safeguard metal and electronic keys and proximity cards received from the Government in accordance with above regulations.
Security Training. The contractor shall develop and implement a security education program to ensure contractor personnel understand and are familiar with security requirements. The contractor shall conduct security indoctrination for all new employees within 30 days after their arrival and refresher sessions annually thereafter. Upon completion of the security indoctrination, the contractor will have each employee sign the Standard Form (SF) 312 Classified Information Nondisclosure Agreement prior to granting access to classified information. The contractor will maintain the SF 312 on each employee and this document should be available to the government upon request.
Contractor personnel may attend ATC’s annual refresher training; however, contractor personnel who are unable to attend the training shall receive the same training from contractor management. This training will include general security education, OPSEC awareness, Information Systems Security, Force Protection, and training on the Threat Awareness Reporting Program (TARP). Designated ATC Security personnel will conduct Anti-Terrorism/Force Protection training for contractor personnel traveling OCONUS. The senior management, training coordinator, or FSO will provide through the COR a record of all contractor employees who have attended annual mandatory training by name and date of attendance to the ATC Security Manager. ATC Security personnel will conduct indoctrination and termination briefings for contractor personnel supporting SAPs.
iWATCH Training. All contractors who perform their tasks within an Army controlled installation, facility or area must be briefed on iWATCH procedures. The contractor and all associate sub-contractors shall brief all employees on the local iWATCH program (training standards provided by the requiring activity Anti-Terrorism Officer (ATO)).
This locally developed training will be used to inform employees of the types of behavior to watch for and instruct employees to report suspicious activity to the COR. This training shall be completed within 30 days of new employees commencing performance with the results reported to the COR upon completion of this training.
Operations Security. All written (hard copy) and electronic material produced by the contractor which will be disseminated outside of ATC will be subject of an OPSEC and Security review to be performed by the ATC OPSEC Officer prior to release. This includes all written (hardcopy) and electronic materials produced such as organizational press releases and marketing material. All information associated with a program that is indicated as unclassified/sensitive by the COR shall be afforded protection sufficient to preclude disclosure to individuals who do not have a need to know of the material. As a minimum, the following requirements apply:
a. Distribution of information/reports of this contract shall be limited to personnel associated with this contract and applicable Government personnel.
b. Documents/material shall be kept under lock and key when not in use.
c. Documents/material indicated by the COR as unclassified/sensitive which are no longer required shall be destroyed by shredding or by placing information in a box for destruction during a trip to the incinerator.
Disclosure of Proprietary and Intellectual Information. The contractor may be required to access data and information that is proprietary to another government agency, government contractor or of such a nature that its dissemination or use other than as specified would be adverse or contradictory to the government’s interest. The contractor and their employees shall not divulge or release data or information developed or obtained under this contract except to authorized government personnel or upon written approval from the Contracting Officer. The Contractor shall not use, disclose or reproduce proprietary data that bears a restrictive legend. The Contractor shall obtain written permission of the originator prior to releasing any information. Under Title 18, Sections 793 and 798, the Contractor and the Contractor employees are liable for any improper release. The Contractor will direct all inquiries, comments, or complaints arising from matters observed, experienced, or learned as a result of, or in connection with the performance of this contract to the Contracting Officer. The resolution of which may require dissemination of official information. In this case, the Contracting Officer, upon a request from the contractor, will coordinate with the ATC Security Manager or designee for guidance. Inquiries the Contractor receives for information relative to the Freedom of Information Act (FOIA) shall be directed to the Contracting Officer, or COR for evaluation. The Government retains the authority to release or deny access to the information. The Contractor shall be responsible for search and submission of records under the Contractors control upon Government request. All work, including but not limited to intellectual property and data rights, produced under this contract is the sole property of the Government.
Departing Employees. The contractor shall ensure all contractor employees return photographic security identification badges and Common Access Cards/ Identification Cards and all permits issued by the Government at the completion of their employment.
All issued keys will be returned before departure. The turn in of these items will be completed no later than 24 hours after their departure. The contractor will ensure that all contract employees receive a security debriefing upon their departure. Following the debriefing, the employee will sign the bottom portion of the SF 312. The contractor will ensure that all employees who maintain a hand receipt do not leave the installation until all items have been accounted for and all equipment under their control has been transferred to the new hand receipt holder. An employment/installation clearance procedure and checklist will be developed and implemented by the contractor to ensure that an employee has turned in all badges, Government property, and keys before leaving employment on the installation and access to the Local Area Network (LAN)/email has been cancelled. This checklist will contain a signature block for the ATC Security and Intelligence Division to initial to ensure all contract employees have cleared all aspects of employment at ATC. Security badges will be returned to the ATC Security and Intelligence Division on the employee’s last day of employment with the government. If departure is after normal business hours, the FSO will collect the badge on the last day of employment and turn the badge in to ATC Security and Intelligence Division the next business day. Keys and proximity cards will be returned to the issuing key custodian prior to the employee departing ATC. In addition, contractor personnel briefed on SAPs shall contact ATC Security personnel to complete a termination briefing prior to termination of employment.
Force Protection. The contractor shall ensure that each contractor employee receives annual Level I Antiterrorism awareness training per Army Regulation 525-13 (Antiterrorism). Contractor personnel may attend ATC’s annual Force Protection training; however, contractor personnel who are unable to attend the training shall receive the same training from contractor management.
SPECIAL ACCESS PROGRAM (SAP) ADDENDUM FOR DD FORM 254
ATTACHMENT THREE
Contract To Be Determined
GENERAL: The policy documents identified below provide the necessary guidance for physical, personnel, and information security for safeguarding SAP information, and are part of the security classification specification for this contract.
a. Department of Defense Manual 5205 Volume 1: Special Access General Procedures
b. Department of Defense Manual 5205 Volume 2: Special Access Personnel Security Procedures
c. Department of Defense Manual 5205 Volume 3: Special Access Physical Security Procedures
d. Department of Defense Manual 5205 Volume 4: Special Access Marking Procedures
e. Joint Air Force Army Navy Manuals
f. Intelligence Community Directives
g. SAP-specific Program Security Guides(s) (PSG);
h. SAP-specific Security Classification Guide(s) (SCG);
i. Applicable Facility Specific Standard Operating Procedures
j. Applicable Facility Specific Treaty Plans; and
k. OPSEC Guides.
PROTECTION: All programmatic material relating to this contract and its administration shall be classified in accordance with the requirements outlined in the SAP-specific security classification guides, this DD Form 254, and protected in accordance with the Program Security Guide.
Access: Access to SAP information or material shall be at government facilities and other designated contractor locations only as identified and approved by the Government Program Security Officer (PSO). Access to SAP information will be in accordance with references stated above. Nomination packages will be sent to the PSO for a Tier Review.
Candidates may also be subject to counter-intelligence polygraph exams and random urinalysis testing. Failure of selected individual to submit to the polygraph exams and/or random urinalysis test may result in his or her access to SAP information being suspended. The individual being nominated for access to the SAP must have his company’s Facility Security Officer (FSO) or Contractor Program Security Officer (CPSO) sign the Program Access Request (PAR).
Storage and Handling: Any facility that stores, processes or discusses SAP information or data in regard to this contract will be designated as a SAPF. SAPF’s will be accredited using the standards identified in the references above and approved, in writing, by the PSO prior to any discussions or receipt and/or generation of any classified material. If the Proposed SAPF is already accredited by another sponsor and/or located within an
ATTACHMENT THREE (Continuation of SAP Addendum for DD Form 254 accredited Sensitive Compartmented Information Facility (SCIF), the facility will still have to be approved by the PSO. A Co-Utilization Agreement (CUA) is required between the PSO and the SCI CSA or the established SAP Cognizant Security Authority (CSA) prior to introduction of SAP data into an accredited SCIF or SAPF, respectively.
Collateral information/material not directly relating to this contract shall not be introduced or authorized within a SAPF without prior written authorization from the
PSO.
Processing: Information Systems (IS) processing SAP data must be certified and accredited in accordance with the DoD Special Access Program (SAP) Program Manager (PM) Handbook to the Joint Special Access Program (SAP) Implementation Guide (JSIG) and the Risk Management Framework (RMF) and approved to process SAP information by the PSO in writing. Any modifications that affect the security posture of the system will dictate new accreditation (and documentation) IAW the regulation stated above. Downloading of unclassified information to unclassified media from an IS approved to process SAP information is not permitted.
Communications and Transmissions: Any communications with outside activities not involved with the specific supported SAP are PROHIBITED, unless otherwise authorized by the PSO. It is PROHIBITED to use the following in encrypted emails: SAP nicknames or tri-graphs or di-graphs; SAP, SAR, black program. Information containing any of these terms shall be sent over approved secure communications, refer to the PSG.
Treaty Compliance: Army SAP facilities are subject to inspection and monitoring under select Arms Control Treaties. A notification process must be in place.
Release: Public release of SAP information is PROHIBITED. Finished documents or other materials pertaining to this effort will not be released to the Defense Technical Information Center (DTIC) or any other such information service under any circumstances. A pre-publication and/or presentation(s) review is required prior to the use of any classified or unclassified information which is either tangentially or directly related to any SAP. In each case, approval must be obtained from the PSO. The request must be submitted by the person who desires to make the publication or presentation via the Contract Program Security Officer (CPSO) to the PSO. The contractor shall not use references to SAP accesses or information, even by unclassified acronyms, in advertising, promotional efforts or recruitment of employees.
SUBCONTRACTING: All subcontracts with SAP authorization must have prior approval of the PSO. Contractors will include the provisions of this supplement in all subcontracts requiring SAP access in support of this effort. Any classified program activity that requires the use of a subcontractor facility must meet referenced criteria and be accredited by the PSO. The PSO’s office will provide the SAP-specific documents to the subcontractor once approved for storage.
ATTACHMENT THREE (Continuation of SAP Addendum for DD Form 254
LEGAL COUNSEL: Should the contractor require private counsel to represent corporate interests in matters related to or associated with SAP sponsored activities, the Procurement Contracting Officer (PCO), and PSO shall be notified in writing. The private counsel shall be treated as a subcontractor. In those incidents where the issues are not program specific, it is the responsibility of the appropriate indoctrinated contractor personnel to prevent inadvertent dissemination of SAP related information/data, operational procedures and/or administrative details to the private counsel.
RETENTION OF PROGRAM RELATED DOCUMENTION: Upon completion of this contract and acceptance by the Government of final deliverables, the contractor shall:
• Conduct an inventory/audit of all classified documents received and/or generated under this contract and forward it to the PSO.
• In accordance with PSO direction, the contractor shall destroy classified material utilizing approved destruction procedure/methods and maintain certificates of destruction for final close-out review. Retention of SAP information at the contractor facility is not generally authorized beyond contract close-out unless a follow on contract/task is anticipated. A written request for authorization for document retention must be forwarded through the PCO to the PSO for approval.
ISSUES/CONFLICT REPORTING:
• Any questions regarding classification, access, or any other security related issue in regard to this contract must be referred, in writing, to the PSO.
• Any suspected or confirmed security incident or violation involving SAP information will be immediately reported, in writing, to the PSO.
• Any conflict between instructions contained in any referenced policy and this DD Form 254 must be reported to the PSO by the most expedient means.
DRAFT
SAMPLE
PREVIOUS EDITION IS OBSOLETE.
Page of AEM LiveCycle Designer
DD FORM 254, APR 2018
NEEDS DD67
DEPARTMENT OF DEFENSE
CONTRACT SECURITY CLASSIFICATION SPECIFICATION
(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)
OMB No. 0704-0567 OMB approval expires:
October 31, 2020 The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.
RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.
1. CLEARANCE AND SAFEGUARDING
2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)
3. THIS SPECIFICATION IS: (X and complete as applicable.)
a. ORIGINAL (Complete date in all cases.)
b. REVISED (Supersedes all previous specifications.)
4. IS THIS A FOLLOW-ON CONTRACT?
If yes, complete the following:
Classified material received or generated under
5. IS THIS A FINAL DD FORM 254?
If yes, complete the following:
6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)
7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor)
8. ACTUAL PERFORMANCE (Click button to add more locations.)
10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)
e. NATIONAL INTELLIGENCE INFORMATION:
11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)
12. PUBLIC RELEASE
Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)
13. SECURITY GUIDANCE
The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.
(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)
14. ADDITIONAL SECURITY REQUIREMENTS
Requirements, in addition to NISPOM requirements for classified information, are established for this contract.
If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)
15. INSPECTIONS
Elements of this contract are outside the inspection responsibility of the CSO.
If Yes, explain and identify specific areas and government activity responsible for inspections. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)
16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)
17. CERTIFICATION AND SIGNATURES
Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below. Upon digitally signing Item 17h, no changes can be made as the form will be locked.
18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL
9.0.0.2.20120627.2.874785 DD 254, DoD Contract Security Classification Specification List of Attachments [1] (All Files Must be Attached Prior to Signing, i.e., for any digital signature on the form) Attachments 1-3.pdf
| CurrentPage: |
| PageCount: |
| Classification: |
| SerialNum: |
| a. Facility clearance level. Select one.: 1 |
| b. Level of safeguarding for classified information/material required at contractor facility. Select one.: 4 |
| Choose Yes or No: 0 |
| Choose Yes or No: 1 |
| Prime: |
| Choose Yes or No: 0 |
| Choose Yes or No: 0 |
| Sub: |
| Choose Yes or No: 1 |
| Choose Yes or No: 0 |
| Soli: W91CRB-20-R-0032 2020-11-13 |
| DueDate: |
| dateA: |
| RevisionNum: |
| dateB: |
| Final: |
| dateC: |
| No: 0 |
| No: 1 |
| No: 0 |
| No: 0 |
| Yes: 1 |
| Yes: 0 |
| Yes: 1 |
| Yes: 1 |
| Enter your name here.: W91CRB-15-D-0018 |
| ReqDated: |
| Enter your name here.: |
| Name: |
To Be Determined Name:
To Be Determined
| Name: JENELL BIGHAM |
| Cage: N/A |
| Cage: TBD |
| CSO: To Be Determined |
| CSO: N/A |
| addrow: |
| Removerow: |
| Click to delete a row: |
| Location: US Army Aberdeen Test Center |
6943 Colleran Road Aberdeen Proving Ground, MD 21005.5059
| Block9: Provide Test Support Services to the US Army Aberdeen Test Center, a subordinate activity of the US Army Test and Evaluation Command (ATEC).Support aligns with the major test mission areas of automotive, firepower, survivability/lethality, warfighter and other support areas. Support relates to the areas of Ammunition Operations; Compliance, Program, and Staff Support; Engineering and Scientific Support; Facilities Design and Maintenance; Electronic Instrumentation Operation; Marine Operations and Maintenance; Vehicle and Equipment Operations and Maintenance; Technical Test Support; and Test Range/Facility Operations Support. |
| a: 1 |
| a: 1 |
| a: 1 |
| f: 1 |
| f: 0 |
| f: 1 |
| b: 0 |
| b: 0 |
| b: 1 |
| g: 0 |
| g: 0 |
| c: 0 |
| c: 0 |
| c: 1 |
| h: 0 |
| h: 0 |
| d: 0 |
| d: 0 |
| d: 0 |
| i: 0 |
| i: 0 |
| SCI: 0 |
| NonSCI: 0 |
| j: 1 |
| j: 1 |
| k: 0 |
| k: 0 |
| Enter your name here.: SIPRNET Access (See Attachment One) |
| Enter your name here.: ATC Security and Intelligence Division |
Program Security Office (PSO)
| e: 0 |
| e: 1 |
| l: 0 |
| m: 1 |
| direct: 0 |
| thru: 1 |
| Enter your name here.: US Army Aberdeen Test Center, ATTN: TEDT-AT-CSI |
No information regarding Special Access Programs will be release
| PublicAuthority: Not Applicable |
| AddSig: |
| RemoveSig: |
| text: 10a. Classified COMSEC material is not releasable to contract employees who have not received a FINAL clearance at the appropriate security level. COMSEC access shall be in accordance with Chapter 9, Section 4 of the National Industrial Security Program Operating Manual (NISPOM) and Army Regulation 380-40, Policy for Safeguarding and Controlling Communications Security (COMSEC) Material. When access is required at Governmnet facilities, contractor personnel will adhere to COMSEC rules and regulations as mandated by Command policy and procedures. Written concurrence from the Contracting Officer (KO) is required prior to subcontracting. |
| attachmentsList: |
| AddAttachment: |
| ViewAttachment: |
| RemoveAttachment: |
| rep: KATHLEEN M. SMITH |
Contracting Officer Representative, ATC
(410) 278-3181 rep: JENELL BIGHAM ATC Industrial Security Specialist 4102782953
| Sig: |
| Enter your name here.: See Attachment One (Continuation of Block 13) |
See Attachment Two (Continuation of Block 14) See Attachment Three (SAP Addendum)
| Enter your name here.: ATC will be responsible for security oversight of contractor personnel supporting SAPs and collateral programs at ATC. |
| GCAName: Army Contracting Command - APG |
| AAC: W91CRB |
| AAC: W91CRB |
| Address: Building 4310 |
6515 Integrity Court
APG, MD 21005-3013
Address: Building 324 6867 Colleran Road Aberdeen Proving Ground, Maryland 21005-5059
| POCName: Erin K. Weber |
| Phone: 4103062790 |
| Phone: 4102782953 |
| Email: erin.k.weber.civ@mail.mil |
| Email: jenell.bigham.civ@mail.mil |
| Title: ATC Industrial Security Specialist |
| Enter the date using the format DD-Mon-YYYY: |
File details come from the government source that posted it. Updated .