Attachment 3 - DD254.pdf
PDF 204 KB Posted
- Attached to
- Naval Special Warfare Resilience Program Federal contract opportunity
- Solicitation number
- H92240-22-R-0003
- Issued by
- United States Special Operations Command
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| H92240-22-R-0003 AMD 3.pdf | ||
| Attachment 2 - Basic Contract Exhibit Line Item (ELIN) Spreadsheet 4.21.22.xlsx | XLSX spreadsheet | |
| H92240-22-R-0003 AMD 2.pdf | ||
| Questions and Government Responses.xlsx | XLSX spreadsheet | |
| Attachment 1 - Performance Work Statement (PWS)_ 4.21.22.pdf | ||
| H92240-22-R-0003 AMD 1.pdf | ||
| Attachment 1 - Performance Work Statement (PWS).pdf | ||
| H92240-22-R-0003 NSW Resilience Program.pdf | ||
| Attachment 2 - Basic Contract Exhibit Line Item (ELIN) Spreadsheet.xlsx | XLSX spreadsheet |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Please wait...
If this message is not eventually replaced by the proper contents of the document, your PDF viewer may not be able to display this type of document.
You can upgrade to the latest version of Adobe Reader for Windows®, Mac, or Linux® by visiting http://www.adobe.com/go/reader_download.
For more assistance with Adobe Reader visit http://www.adobe.com/go/acrreader.
Windows is either a registered trademark or a trademark of Microsoft Corporation in the United States and/or other countries. Mac is a trademark of Apple Inc., registered in the United States and other countries. Linux is the registered trademark of Linus Torvalds in the U.S. and other countries.
DRAFT
SAMPLE
PREVIOUS EDITION IS OBSOLETE.
Page of
DD FORM 254, MAY 2019
NEEDS DD67
DEPARTMENT OF DEFENSE
CONTRACT SECURITY CLASSIFICATION SPECIFICATION
(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)
OMB No. 0704-0567 OMB approval expires:
20220531 The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.
RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.
1. CLEARANCE AND SAFEGUARDING
2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)
3. THIS SPECIFICATION IS: (X and complete as applicable.)
a. ORIGINAL (Complete date in all cases.)
b. REVISED (Supersedes all previous specifications.)
4. IS THIS A FOLLOW-ON CONTRACT?
If yes, complete the following:
Classified material received or generated under
5. IS THIS A FINAL DD FORM 254?
If yes, complete the following:
6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)
7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor)
8. ACTUAL PERFORMANCE (Click button to add more locations.)
10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)
e. NATIONAL INTELLIGENCE INFORMATION:
11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)
12. PUBLIC RELEASE
Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)
13. SECURITY GUIDANCE
The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.
(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)
14. ADDITIONAL SECURITY REQUIREMENTS
Requirements, in addition to NISPOM requirements for classified information, are established for this contract.
If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)
15. INSPECTIONS
Elements of this contract are outside the inspection responsibility of the CSO.
If Yes, explain and identify specific areas and government activity responsible for inspections. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)
16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)
17. CERTIFICATION AND SIGNATURES
Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below. Upon digitally signing Item 17h, no changes can be made as the form will be locked.
18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL
9.0.0.2.20120627.2.874785 DD 254, DoD Contract Security Classification Specification whs.mc-alex.esd.mbx.formswebmaster@mail.mil
WHS
List of Attachments (All Files Must be Attached Prior to Signing, i.e., for any digital signature on the form)
| CurrentPage: |
| PageCount: |
| Classification: Unclassified |
| SerialNum: |
| a. Facility clearance level. Select one.: 2 |
| b. Level of safeguarding for classified information/material required at contractor facility. Select one.: 4 |
| Choose Yes or No: 1 |
| Choose Yes or No: 1 |
| Prime: TBD |
| Choose Yes or No: 0 |
| Choose Yes or No: 0 |
| Sub: |
| Choose Yes or No: 0 |
| Choose Yes or No: 0 |
| Soli: |
| DueDate: |
| dateA: 2022-02-09 |
| RevisionNum: |
| dateB: |
| Final: |
| dateC: |
| No: 1 |
| No: 1 |
| No: 0 |
| No: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 1 |
| Yes: 1 |
| Enter your name here.: |
| ReqDated: |
| Enter your name here.: |
| Name: ***This DD254 is for solicitation purposes only. An original DD254 will be provided upon contract award.*** |
| Name: SEE ITEM 13 |
| Name: Sanchez, Eileah M. |
| Cage: N/A |
| Cage: N/A |
| Cage: N/A |
| Cage: N/A |
| Cage: TBD |
| CSO: Naval Special Warfare Command |
Attn: Activity Security Manager 2000 Trident Way San Diego, CA 92155 CSO: Naval Special Warfare Command Attn: Activity Security Manager 2000 Trident Way San Diego, CA 92155 CSO: Naval Special Warfare Command Attn: Activity Security Manager 2000 Trident Way San Diego, CA 92155 CSO: Naval Special Warfare Command Attn: Activity Security Manager 2000 Trident Way San Diego, CA 92155
| addrow: |
| Removerow: |
| Click to delete a row: |
| Location: San Diego, CA and surrounding areas |
| Location: Virginia Beach, VA and surrounding areas |
| Location: Honolulu, HI and surrounding areas. |
| Location: Stennis, MS and surrounding areas. |
| Block9: ****************************************************************************************************************** |
THIS DD FORM 254 IS TENTATIVELY APPROVED. Upon (company selection, identification of a Contract Number/Task Order) but prior to award and any classified release, this DD Form 254 with all pertinent information inserted in appropriate sections will be submitted to Naval Special Warfare Command Contracting Officer’s Security Representative for final review and approval.
******************************************************************************************************************The contractor shall develop, implement, analyze, evaluate, and revise an evidence-based resilience program to mitigate stress and strengthen Warriors and their families across the NSW community.
Period of Performance: 31 JAN 2022 - 31 JAN 2027. (BIENNIAL DD FORM 254 REVIEW REQUIRED - SEE ITEM 13)
| a: 0 |
| a: 0 |
| a: 1 |
| f: 0 |
| f: 0 |
| f: 1 |
| b: 0 |
| b: 0 |
| b: 0 |
| g: 0 |
| g: 0 |
| c: 0 |
| c: 0 |
| c: 1 |
| h: 0 |
| h: 0 |
| d: 0 |
| d: 0 |
| d: 0 |
| i: 0 |
| i: 0 |
| SCI: 0 |
| NonSCI: 0 |
| j: 1 |
| j: 1 |
| k: 0 |
| k: 0 |
| Enter your name here.: NAVSPECWARCOM N23 ENTERPRISE SECURITY PROGRAMS DIVISION |
| e: 1 |
| e: 1 |
| l: 1 |
| m: 0 |
| direct: 0 |
| thru: 1 |
| Enter your name here.: CONTRACTING OFFICER'S REPRESENTATIVE (COR) IN BLOCK 13 |
| PublicAuthority: WARCOM PUBLIC AFFAIRS OFFICE AND CONTRACTING OFFICER |
| AddSig: |
| RemoveSig: |
| text: The Contracting Officer’s Representative/Program Manager will provide a copy of all applicable security directives for this contract. Appropriate applicable HQ USSOCOM, NAVSPECWARCOM (NSWC), or NSW subordinate command security directives, regulations, and standard operating procedures will be provided by the requiring agency (normally through the Performance Monitor or Component/Theater Special Operations Command COR/PM). Upon completion or termination of the classified contract, or sooner when the purpose of the release has been served, the contractor will return all classified information (furnished or generated) to the source from which received unless retention or other disposition instructions are authorized in writing by the USSOCOM or NAVSPECWARCOM Government Contracting Agency/Activity. Furthermore, the contractor will account for and return all Common Access Cards (CACs) to Contracting Officer's Representative, Program Manager, or Trusted Agent upon completion or termination of the classified contract, termination of employment, or suspension of classified clearance or access of any contractor employee. Security badges, installation entry passes/vehicle decals issued to contractor personnel will be returned to the appropriate issuing office as required. |
Ref 2b: Subcontracting of this effort must be approved by NAVSPECWARCOM prior to award. Forward requests and draft Subcontract DD FM 254s to the Contracting Officer’s Security Representative (COSR) (nsw.industrial.security.dl@socom.mil). (IAW NAVSPECWARCOMINST 5520.1, Industrial Security, please allow 10 duty days for review/approval).
Ref 7: See guidance in Ref 2b.
Ref 9. Unless DD FM 254 revision is required due to change in the security requirements of the effort or there is a change in the contractor’s Facility Clearance (FCL) status, the responsible Contracting Officer’s Representative/Program Manager (COR/PM) must conduct a review of the DD FM 254 and associated Individual Work Plan, Performance Work Statement/Statement of Objectives/Statement of Work every 24 MONTHS (BIENNIALLY) in order to validate and/or update the requirements of the effort as required by DoDM 5220.22-V2, National Industrial Security Program: Industrial Security Procedures for Government Activities. Documentation of review (email is sufficient) should be forwarded to HQ USSOCOM Industrial Security via NIPRNet at IndustrialSecurity@socom.mil through the NAVSPECWARCOM COSR at nsw.industrial.security.dl@socom.mil.
Ref 10j: Controlled Unclassified Information (CUI) provided under this contract shall be safeguarded as specified in the CUI Addendum included with this specification.
Ref 11e: Contract is for NSW support services. Classification markings on the material to be furnished will provide the guidance necessary for performance of the contract. Services will not be provided on military installations or at contractors facility. All services will be provided in areas not commonly covered directly under a cognizant security office. Should issues arise concerning security, please consult the NAVSPECWARCOM SSO.
Ref 11j: See Operations Security (OPSEC) addendum.
Ref 11l: Controlled Unclassified Information (CUI) provided under this contract shall be safeguarded as specified in the CUI Addendum included with this specification.
Ref 12: Requests must be forwarded through the responsible Contracting Officer’s Representative, COSR, Program Manager, Contracting Official (Item 16) and NSW FOIA office prior to public release.
The use of personal electronic media (cameras, video recorders, computer laptops, flash (thumb), or other removable drives) is prohibited in all Naval Special Warfare spaces. All removable electronic media must be labeled (unclassified, etc.) To the highest classification of data stored, and/or for the classification of the system in which it is used. If classified, any removable electronic media must be tracked and stored appropriate to that level of classification.
Anti-terrorism/Force Protection (AT/FP) briefings are required for all personnel (military, DoD civilian, and contractor) per OPNAVINST F3300.53c. Contractor employees must receive the AT/FP briefing annually. The briefing is available at http://jko.jten.mil/courses/atl1/launch.html. Forward a copy of training certificate to the COR.
The COR will specify which positions require any additional clearance and when the contractor is authorized to courier classified information and equipment in support of the naval special warfare.
The security requirements for personnel assigned under this task shall be in accordance with the requirements of SECNAVINST 5510.30/36 series. The highest-level security required for this task is SECRET. The work performed by the contractor will include access to unclassified and up to SECRET information, and spaces. The contractor may be required to attend meetings classified up to the SECRET level.
Personnel performing classified work or requiring access to classified material or spaces under this delivery order/task order shall possess both a DoD security clearance at the appropriate level and need to know. Request for visit authorization shall be submitted in accordance with DoD 5220.22m (National Industrial Security Program Operating Manual (NISPOM)) not later than one (1) week prior to visit. DD254 of the basic contract applies.
All development of databases, classified hardware, and graphics (if/when conducted at the contractor’s location) will be done upon Defense Counterintelligence and Security Agency (DCSA) approved Information Assurance (IA) equipment.
All classified information/hardware developed will be classified pursuant to derivative classification procedures or as any applicable classification guide so dictates (NISPOM chapter 4, section 2) and executive order 13526. All applicable classification guides will be identified and made available by the COR.
Meetings or visits conducted by the contractor will be done IAW NISPOM chapter 6.
PROTECTING “CONTROLLED UNCLASSIFIED INFORMATION” (CUI)
CUI Addendum (Updated March 2021)
1. GENERAL:
a. Controlled Unclassified Information (CUI) is not a security classification, but designates unclassified information that requires any safeguarding or dissemination control per DoD Instruction 5200.48, “Controlled Unclassified Information” (6 March 2020).
b. With the implementation of DoDI 5200.48, DoDI 5200.01, Volume 4, “DoD Information Security Program: Controlled Unclassified Information” (24 February 2012, as amended), has been cancelled and “For Official Use Only” (FOUO) and is no longer authorized. All new documents shall be marked in accordance with the guidance below.
c. In order to balance the need to safeguard CUI with the public interest the CUI Registry, established by DoDI 5200.48, lists categories of CUI Basic/Specified and identifies basis for controls, and includes guidance on handling procedures.
d. There are two subsets of CUI.
i. CUI Basic is the subset of CUI for which law, regulation, or government policy does not set out specific handling or dissemination controls. CUI Basic handling and dissemination controls are the same as previously used for FOUO.
ii. CUI Specified is the subset of CUI for which law, regulation, or government policy contains specific handling controls that differ from CUI Basic. The government will provide marking and handling guidance separately for CUI Specified.
e. Remarking legacy FOUO documents is not required as long as they remain under DoD control. When needed, FOUO information does not automatically become CUI, so the material must be reviewed by the information owner to determine if it meets the CUI requirements and marked appropriately.
f. When responding to FOIA requests, the responsible DoD agency must base its decision on the content of the information and applicability of any of the FOIA statutory exemptions regardless of whether an agency designates or marks the information as CUI.
2. DESIGNATION as CUI: Designating CUI occurs when an authorized holder, consistent with DoDI 5200.48 and the CUI Registry, determines that a specific item of information falls into a CUI category or subcategory. The information must be designated as either CUI Basic or CUI Specified and the authorized holder must ensure that appropriate markings are applied to documents to ensure recipients are aware of the CUI status. See the associated Security Classification Guide (SCG) or other guidance provided by the Government Contracting Agency (GCA) for specific categories of CUI related to this contract and guidance on storage, handling, and dissemination.
3. MARKING:
a. Unclassified documents containing CUI will be marked CUI at the top & bottom of each page. As a best practice each “portion” (i.e. titles, subject lines, paragraphs, bullets, charts, etc.) containing CUI may be Portion Marked (CUI). If portion marks are used then Unclassified portions will be Portion Marked (U). Do not use (U//CUI).
b. The government will provide marking, handling, and dissemination guidance separately for any CUI Specified information. For classified contracts, this guidance will be contained in the associated SCG.
c. The following CUI Designation Indicator information will be included on the first/title page or cover of all unclassified documents containing CUI:
Controlled by: [Name of DoD Component and Office] CUI Category: [List of Category or Categories of CUI] Distribution/Dissemination Control: [Use “None” for CUI Basic/As required for CUI Specified) POC: [Phone Number and/or E-mail]
d. Classified documents containing CUI will NOT include CUI in the banner marking at the top and bottom of each page. Each paragraph that contains only CUI will be portion marked (CUI). All other paragraphs will be marked according to their classification. Do not “co-mingle” CUI with classified information. The above CUI Designation Indicator information must be included on the first page or cover (same as unclassified documents). Additionally, the following statement must be included on the first page of documents that contain both CUI and classified information:
This content is classified at the [insert highest classification level of the document] level and may contain elements of controlled unclassified information (CUI), unclassified, or information classified at a lower level than the overall classification displayed. This content shall not be used as a source of derivative classification; refer to [cite specific reference or applicable Security Classification Guide]. It must be reviewed for both Classified National Security Information (CNSI) and CUI in accordance with DoDI 5230.09 prior to public release.
4. PROCESSING: Unclassified Automated Information Systems (AIS) used to process CUI under this contract must meet the basic security requirements listed in the NIST SP 800-171 REV 2, “Protecting Controlled Unclassified Information in Non-Federal Systems and Organizations”, 21 February 2020. AIS accredited and approved for processing classified information under this contract are also approved to process DoD CUI.
5. DISSEMINATION: CUI may be disseminated between officials of DoD Agencies, DoD contractors, consultants and grantees to conduct official business for the DoD provided the dissemination is consistent with controls imposed by a Distribution Statement or Limited Dissemination Controls (LDC). Guidance on Distribution Statements and LDCs will be provided separately by the government for any prescribed CUI Specified information. For classified contracts, this information will be contained in the program SCG. CUI always requires Foreign Disclosure Decision before release outside of DoD Agencies, DoD contractors, consultants and grantees.
6. STORAGE: During working hours, to prevent unauthorized access, do not leave CUI unattended, read or discuss around unauthorized personnel. CUI shall be placed in an out-of-sight location if the work area is accessible to persons who do not have a need for the information. During non-working hours, the information shall be stored to preclude unauthorized access. Filing such material with other unclassified records in unlocked files or desks, is adequate when internal building security is provided during non-working hours. When such internal security control is not exercised, locked buildings or rooms will provide adequate after-hours protection or the material can be stored in locked receptacles such as file cabinets, desks, or bookcases.
7. TRANSMISSION: CUI may be transmitted using the following:
a. Mail – CUI may be sent via first class mail or parcel post. Bulk shipments may be sent by fourth class mail. Contents must be properly marked, but no markings will appear on the outer wrapper.
b. Fax – Normally CUI may be sent via Facsimile equipment. To prevent unauthorized disclosure, coversheets should be used, the locations of both fax machines should be considered, and availability of an authorized recipient at the receiving end should be confirmed. Secure classified fax machines may be used without the above verifications.
c. E-Mail/Web Sites – E-mail may be used on approved secure communication systems or systems using other protective measures such as Public Key Infrastructure (PKI) or transport layer security (e.g., https). E-mail messages must be appropriately marked to identify CUI status. Personnel will not use unofficial or personal email accounts, messaging systems, or other non-DoD information systems, except approved government contractor systems to conduct official business involving CUI.
d. Video Teleconferencing – Only use Government Agency approved secure, encrypted video conferencing and collaborative platforms (i.e. SVTC, etc.). CUI may not be discussed over commercially available video conferencing applications.
e. Avoid wireless transmission unless no other means are available.
8. DESTRUCTION: When no longer needed, CUI must be disposed of in a way that will make it unreadable, indecipherable, and irrecoverable. Use of approved sensitive/classified material destruction devices is recommended. (ISOO CUI Notice 2019-03, “Destroying Controlled Unclassified Information in Paper Form”, 15 July 2019)
9. UNAUTHORIZED DISCLOSURE: Report misuse, mishandling, or Unauthorized Disclosure of CUI to the Unauthorized Disclosure Program Management Office, the Controlling Agency and the appropriate Military Department Counterintelligence Organization. While Unauthorized Disclosure of CUI does not constitute a security violation, a formal security inquiry/investigation is required if disciplinary action will be taken against the individual(s) responsible. Unauthorized Disclosure of certain CUI, such as export controlled-technical data, may also result in civil and criminal sanctions against responsible persons based on procedures codified in relevant law, regulation, or government-wide policy.
NAVAL SPECIAL WARFARE COMMAND OPERATIONS SECURITY (OPSEC) REQUIREMENTS
(ADHERENCE TO ALL NSW COMPONENT COMMAND OPSEC REQUIREMENTS IS MANDATORY)
- All work is to be performed in accordance with DoD and Navy Operations Security (OPSEC) requirements, per the following applicable documents:
- National Security Decision Directive 298 -National Operations Security Program (NSDD) 298
- DoD 5205.02 - DoD Operations Security (OPSEC) program
- OPNAVINST 3432.1 - DoN Operations Security
- NSWCINST 3421 (series) - NSW Operations Security Policy
- The contractor will accomplish the following minimum requirements in support of naval special warfare command (WARCOM) operations security (OPSEC) program:
- the contractor will practice OPSEC and implement OPSEC countermeasures to protect DoD critical information. Items of critical information are those facts, which individually, or in the aggregate, reveal sensitive details about NSW or the contractor’s security or operations related to the support or performance of the PWS/SOO/SOW, and thus require a level of protection from adversarial collection or exploitation not normally afforded to unclassified information.
- contractor must protect critical information and other sensitive unclassified information and activities, especially those activities or information which could compromise classified information or operations, or degrade the planning and execution of military operations performed or supported by the contractor in support of the mission. Protection of critical information will include the adherence to and execution of countermeasures which the contractor is notified by or provided by WARCOM, for critical information on or related to the PWS/SOO/SOW.
- sensitive unclassified information is that information marked for official use only (or fouo), privacy act of 1974, company proprietary, and also information as identified by WARCOM.
- WARCOM has identified the following items as critical information that may be related to this PWS/SOO/SOW:
• known or probable vulnerabilities to any U.S. system and their direct support systems.
• details of capabilities or limitations of any U.S. system that reveal or could reveal known or probable vulnerabilities of any U.S. system and their direct support systems.
• details of information about military operations, missions and exercises.
• details of U.S. systems supporting combat operations (numbers of systems deployed, deployment timelines, locations, effectiveness, unique capabilities, etc.).
• operational characteristics for new or modified weapon systems (probability of kill (pk), countermeasures, survivability, etc.).
• required performance characteristics of U.S. systems using leading edge or greater technology (new, modified or existing).
• telemetered or data-linked data or information from which operational characteristics can be inferred or derived.
• test or evaluation information pertaining to schedules of events during which critical information might be captured. (advance greater than 3 days).
• details of naval special warfare unique test or evaluation capabilities (disclosure of unique capabilities).
• existence and/or details of intrusions into or attacks against DoD networks or information systems, including, but not limited to, tactics, techniques and procedures used, network vulnerabilities exploited, and data targeted for exploitation.
• network user id’s and passwords.
• counter-ied capabilities and characteristics, including success or failure rates, damage assessments, advancements to existing or new capabilities.
• vulnerabilities in command processes, disclosure of which could allow someone to circumvent security, financial, personnel safety, or operations procedures.
• force protection specific capabilities or response protocols (timelines/equipment/numbers of personnel/training received/etc.).
• command leadership and vip agendas, reservations, plans/routes etc.
• detailed facility maps or installation overhead photography (photo with annotation of command areas or greater resolution than commercially available).
• details of coop, naval special warfare emergency evacuation procedures, or emergency recall procedures.
• government personnel information that would reveal force structure and readiness (such as recall rosters or deployment lists).
• compilations of information that directly disclose command critical information.
- the above critical information and any that the contractor develops, regardless if in electronic or hardcopy form, must be protected by a minimum of the following countermeasures:
• all emails containing critical information must be DoD public key infrastructure (pki) signed and pki encrypted when sent.
• critical information may not be sent via unclassified fax.
• critical information may not be discussed via non-secure phones.
• critical information may not be provided to individuals that do not have a need to know it in order to complete their assigned duties.
• critical information may not be disposed of in recycle bins or trash containers.
• critical information may not be left unattended in uncontrolled areas.
• critical information in general should be treated with the same care as cui, fouo or proprietary information.
• critical information must be destroyed in the same manner as cui.
• critical information must be destroyed at contract termination or returned to the government at the government’s discretion.
- the contractor shall document items of critical information that are applicable to contractor operations involving information on or related to the PWS/SOO/SOW. Such determinations of critical information will be completed using the DoD OPSEC 5 step process as described in National Security Decision Directive (NSDD) 298, “National Operations Security Program”.
- OPSEC training must be included as part of the contractors ongoing security awareness program conducted in accordance with chapter 3, section 1, of the NISPOM. NSDD 298, DoD 5205.02, “DoD Operations Security (OPSEC) Program”, and OPNAVINST 3432.1, “operations security” should be used to assist in creation or management of training curriculum.
- if the contractor cannot resolve an issue concerning OPSEC they will contact the program manager / cor (who will consult with the WARCOM security manager).
- all above requirements must be passed to all sub-contractors.
(continued on next page)
NAVAL SPECIAL WARFARE COMMAND INFORMATION TECHNOLOGY (IT) SYSTEMS SECURITY REQUIREMENTS
(ADHERENCE TO ALL NSW COMPONENT COMMAND IT REQUIREMENTS IS MANDATORY)
The U.S. government conducts trustworthiness investigations of personnel who are assigned to positions that directly or indirectly affect the operation of unclassified it resources and systems that process Department of Defense (DoD) information, to include Controlled Unclassified Information (CUI).
The Defense Counterintelligence And Security Agency (DCSA) processes all requests for U.S. government trustworthiness investigations. Requirements for these investigations are outlined in paragraph c3.6.15 and appendix 10 of DoD 5200.2-R, available at http://www.dtic.mil/whs/directives/corres/dir.html. Personnel occupying an it position shall be designated as filling one of the it position categories listed below. The contractor shall include all of these requirements in any subcontracts involving it support. (note: terminology used in DoD 5200.2-r references “ADP” vice “it”. For purposes of this requirement, the terms ADP and it are synonymous.)
DoDD 8500.01E, subject: information assurance (IA), paragraph 4.8 states "access to all DoD information systems shall be based on a demonstrated need-to-know, and granted in accordance with applicable laws and DoD 5200.2-R for background investigations, special access and it position designations and requirements. An appropriate security clearance and non-disclosure agreement are also required for access to classified information” in accordance with DODM 5200.01 vol. 1. DoD 5200.2-R and DoDD 5200.2 require all persons assigned to sensitive positions or assigned to sensitive duties be U.S. citizens. All persons assigned to it-ii and it-iii positions, as well as all persons with access to controlled unclassified information (without regard to degree of it access) or performing other duties that are considered "sensitive" as defined in DoDD 5200.2 and DoD 5200.2-R must be U.S. citizens. Furthermore, access by non-U.S. citizens to unclassified export controlled data will only be granted to persons pursuant to the export control laws of the U.S. the categories of controlled unclassified information are specified in DODM 5200.01 vol. 4. These same restrictions apply to "representatives of a foreign interest" as defined by DoD 5220.22-M (National Industrial Security Program Operating Manual, NISPOM). DoD 8570.01-M further stipulates additional training and/or certification that is required by all persons assigned to information assurance functions.
Criteria for designated positions:
IT-II position (limited privileged)
Responsibility for systems design, operation, testing, maintenance, and/or monitoring that is carried out under technical review of higher authority in the IT-I category, includes but is not limited to:
• access to and/or processing of proprietary data, information requiring protection under the privacy act of 1974, and government-developed privileged information involving the award of contracts;
• accounting, disbursement, or authorization for disbursement from systems of dollar amounts less than $10 million per year. Other positions are designated by WARCOM that involve a degree of access to a system that creates a significant potential for damage or personal gain less than that in it-i positions. Personnel whose duties meet the criteria for an IT-II position require a favorably adjudicated national agency check with local agency check and credit check (NACLC) or T3/T3R investigation. The NACLC or T3R shall be updated every 10 years by using the electronic questionnaire for investigation processing (eQIP) web based program (SF86 format).
IT-III position (non-privileged)
• all other positions involving federal it activities. Incumbent in this position has non-privileged access to one or more DoD information systems, application, or database to which they are authorized access. Personnel whose duties meet the criteria for an IT-III position designation require a favorably adjudicated national agency check with inquiries (NACI).
Qualified cleared personnel do not require trustworthiness investigations:
When background investigations supporting clearance eligibility have been submitted and/or adjudicated to support assignment to sensitive national security positions, a separate investigation to support it access will normally not be required. A determination that an individual is not eligible for assignment to a position of trust will also result in the removal of eligibility for security clearance. Likewise, a determination that an individual is not eligible for a security clearance will result in the denial of eligibility for a position of trust.
Only the eQIP version of SF-85 and SF 86 are acceptable by defense counterintelligence and security agency (DCSA).
The facility security officer (FSO) must verify employee's security clearance eligibility in the Defense Information System for Security (DISS) before contacting the COR to initiate request for trustworthiness investigations.
Contractor fitness determinations made by the DOD CAF are maintained in the DISS web applications. Favorable fitness determinations will support public trust positions only and not national security eligibility. If no issues are discovered, according to respective guidelines a “favorable determination” will be populated in DISS and will be reciprocal within DoD. If issues are discovered, the DOD CAF will place a “no determination made” in DISS and forward the investigation to the submitting office for the commander’s final determination.”
If an individual receives a negative trustworthiness determination, they will be immediately removed from their position of trust, the contractor will follow the same employee termination processing above, and they will replace the individual.
Visit authorization requests (CARS) for qualified employees:
Contractors that have been awarded a classified contract must submit visit requests using DISS. Contractors who work on classified contracts are required to have established an account through DISS for their facility. The DISS database contains all U.S. citizens who have received a clearance of confidential, secret, and/or top secret. The visit request shall be submitted for the length of the contract but not longer than one year. Contact the COR for visit request SMO information on the NSW component to be visited.
Employment terminations:
The contractor shall:
• immediately notify the COR and NSW security manager of the employee’s termination.
• return any badge credentials, to include common access cards to Commander, Naval Special Warfare Command, 2000 Trident Way, BLDG 624, San Diego, CA 92155-5599 or NSW component command security office.
(continued on next page)
NAVAL SPECIAL WARFARE COMMAND SPECIFIC ON-SITE SECURITY REQUIREMENTS
(ADHERENCE TO ALL NSW COMPONENT COMMAND ONSITE REQUIREMENTS IS MANDATORY)
I. GENERAL.
A. Contractor performance. In performance of this contract the following security services and procedures are incorporated as an attachment to the DD254. The contractor will conform to the requirements of DoD 5220.22-m, Department of Defense National Industrial Security Program, Operating Manual (NISPOM), as revised. The contractor will follow all export laws and regulations in the performance of this contract. When visiting Commander, Naval Special Warfare Command or any NSW component, the contractor will comply with the security directives used regarding the protection of classified and controlled unclassified information (CUI), SECNAVINST 5510.30/36 (series). DoDM 5200.01 volumes 1 through 3, and COMNAVSPECWARCOMINST 5520.1 (series). A copy of COMNAVSPECWARCOMINST 5520.1 will be provided upon receipt of a written request from the contractor’s facility security officer (FSO) to the COR listed in the contract DD254. If the contractor establishes a cleared facility or defense counterintelligence and security agency (DCSA) approved off-site location aboard a U.S. government installation, the security provisions of the NISPOM will be followed within this cleared facility.
B. Security supervision. Us government personnel shall exercise security supervision over all contractors visiting WARCOM or any NSW component and shall provide security support to the contractor as noted below. The contractor will identify, in writing to the COR, an on-site point of contact to interface with the WARCOM’s security COR.
II. HANDLING CLASSIFIED MATERIAL OR INFORMATION.
A. Control and safeguarding. Contractor personnel located at the any NSW command are responsible for the control and safeguarding of all classified material in their possession. All contractor personnel will be briefed by their FSO on their individual responsibilities to safeguard classified material. In addition, all contractor personnel are invited to attend any NSW conducted security briefings. In the event of possible or actual loss or compromise of classified material, the on-site contractor shall immediately report the incident to COR and NSW security manager, as well as the contractor's FSO. A government representative will investigate the circumstances, determine culpability where possible, and report results of the inquiry to the FSO and the cognizant DCSA field office. On-site contractor personnel will promptly correct any deficient security conditions identified by a government representative.
b. Storage.
1. Classified material may be stored in containers authorized by any NSW security manager for the storage of that level of classified material. Any areas located within cleared contractor facilities supporting NSW will be approved by DCSA.
2. The use of “open storage” areas must be pre-approved in writing by the COR and forwarded to the NSW security manager for the open storage or processing of any contract related classified material.
c. Transmission of classified material to WARCOM.
(for NSW component command, follow all command instructions)
1. All classified material transmitted by mail for use by long term visitors will be addressed as follows:
(a) Confidential and Secret material transmitted by FEDEX or USPS will be addressed to:
COMMANDER NAVAL SPECIAL WARFARE COMMAND
2000 TRIDENT WAY, BLDG 624
SAN DIEGO, CA 92155-5599
(b) the inner envelope will be addressed to the attention of the Contracting Officer's Representative (COR) or applicable Technical Representative (TR) for this contract.
(c) TS or Sensitive Compartmented Information will be coordinated/addressed IAW guidance provided by the respective government Special Security Officer or Activity Security Manager.
2. All Secret or Confidential material hand carried to any NSW command by contractor personnel with a contractor provided courier card must be accompanied with a delivery receipt and be to delivered immediately to a us government representative of the command.
3. All classified material couriered by contractor personnel from any NSW command shall be approved by the COR or U.S. government Technical Representative (TR) for this contract with NSW Activity Security Manager notification.
4. Contractors couriering classified information in support of NSW shall follow all NISPOM information security directives and instructions
III. INFORMATION SYSTEMS (IS) SECURITY. Contractors using us government is, networks, or computer resources to process classified or controlled unclassified information (cui) will comply with the provisions of SECNAVINST 5239.3 (series) and local policies and procedures. Contractor personnel must ensure that the systems they use at any NSW command have been granted and a us special operations command (USSOCOM) system authorization access request (SAAR) has been approved by the WARCOM information assurance office.
IV. VISITOR CONTROL PROCEDURES. (Adhere to all NSW component command instructions) Title 18 USC 701 provides for criminal sanctions including fine or imprisonment for anyone in possession of a badge who is not entitled to have possession. Sec. 701. Official badges, identification cards, other insignia. Whoever manufactures, sells, or possesses any badge, identification card, or other insignia, of the design prescribed by the head of any department or agency of the united states for use by any officer or employee thereof, or any colorable imitation thereof, or photographs, prints, or in any other manner makes or executes any engraving, photograph, print, or impression in the likeness of any such badge, identification card, or other insignia, or any colorable imitation thereof, except as authorized under regulations made pursuant to law, shall be fined under this title or imprisoned not more than six months, or both.
A. Contractor personnel assigned to a NSW command shall be considered long-term visitors for the purpose of this contract.
B. Contractors that have been awarded a classified contract must submit visit requests to other locations using the Defense Information System for Security (DISS) or official encrypted email visit request that includes official company letterhead. DISS visit requests are preferred. All U.S. government activities have been directed to use DISS when transmitting or receiving VARs. Visit requests can be submitted for one year for personnel not considered long-term visitors. When submitting visit requests, use the security management office (SMO) number for level of the visit and list a us government POC (not the security manager or SSO).
C. For long term visitors to receive a NSW access badge, their government POC must approve their visit request and the visitor must present government issued photo identification. NSW badges are required to be worn in NSW spaces at all times.
D. Visit requests for all visitors must be received at least one week prior to the expected arrival of the visitor to ensure necessary processing of the request.
E. NSW will issue temporary identification badges to contractor personnel following receipt of a valid VAR from the contractor's FSO. The responsible COR will request issuance of picture access badges to contractor personnel on a case-by-case basis. Access badges are the property of the U.S. government, will be worn in plain sight, above the waist and used for official business only at NSW affiliated locations. Access badges are not authorized to be displayed off us government facilities. Unauthorized use of a NSW access badge will be reported to DCSA.
F. Prior to the termination of a contractor employee with an access badge or active VAR on file the FSO must:
1. Notify in writing (email approved) to the COR which employee had been granted unescorted access and the effective termination date.
2. Immediately confiscate any us government credentials (to include common access card (CAC) and access badge), and return to the COR no later than five working days after the effective date of the termination.
G. Common access card (CAC).
1. Approved by the contractor’s COR and CVS POC within NSW.
V. INSPECTIONS. For all personnel aboard WARCOM or NSW component commands, U.S. government personnel may conduct periodic inspections of the security practices of the onsite contractor. All contractor personnel will cooperate with us government representatives during these inspections. Any adverse reports of the inspection will be forwarded to the COR, technical representatives, and the contractor’s employing facility. The contractor must be responsive to the representative's findings.
VI. REPORTS. As required by the NISPOM, chapter 1, section 3, contractors are required to report certain events that have an impact on the status of the facility clearance (FCL), the status of an employee's personnel clearance (PCL), the proper safeguarding of classified information, or an indication classified information has been lost or compromised.
A. The contractor shall ensure that certain information pertaining to assigned contractor personnel or operations is reported to the COR. This reporting will include the following:
1. The denial, suspension, or revocation of security clearance of any assigned personnel;
2. Any adverse information on an assigned employee's continued suitability for continued access to classified access;
3. Any instance of loss or compromise, or suspected loss or compromise, of classified information;
4. Actual, probable or possible espionage, sabotage, or subversive information; or
5. Any other circumstances of a security nature that would affect the contractor's operation at WARCOM.
B. In addition to the NISPOM reporting requirements, any conviction and/or violation of the foreign corrupt practices act, or any other violation of the international traffic in arms regulations (ITAR) shall immediately be reported to the WARCOM designated disclosure authority (DDA), security manager, COR/TR, and contracting officer.
VII. PHYSICAL SECURITY.
A. WARCOM and all NSW component commands will provide appropriate information to emergencies occurring onboard this facility. The contractor will comply with all emergency direction and procedures established by WARCOM.
B. A 24 hour roving security patrol is conducted by NSW military personnel. Such coverage will consist of, but not be limited to, physical checks of the window or door access points, classified containers, unauthorized personnel in the workspaces, and improperly secured documents or spaces. Specific questions or concerns should be addressed with the COR.
C. All personnel aboard naval installations are subject to random inspections of their vehicles and personal items. Consent to these inspections is given when personnel accept a CAC and/or a NSW access badge. Compliance with all direction of master at arms personnel aboard all NSW facilities is mandatory.
D. Information about parking restrictions shall be provided by the COR.
E. Contractor personnel are not authorized to be in any NSW workspaces after normal working hours without us government personnel present. The COR will provide the authorized working hours. Contractor personnel are not authorized to be in the workspaces on non-workdays (weekends) or federal holidays without COR notification and a U.S. government escort.
VIII. COR RESPONSIBILITIES.
A. Review requests by cleared contractors for retention of classified information beyond a two-year period and advise the contractor of disposition instructions and/or submit a final DD254 to security’s COR.
B. In conjunction with the appropriate transportation element, coordinates a suitable method of shipment for classified material when required.
C. Certify and approve any registration for scientific and technical information services requests (DD 1540) (DTIC).
D. Ensure timely notice of contract award is given to host commands when contractor performance is required at other locations.
E. Certify need-to-know on visit requests and conference registration forms.
IX. SPECIAL CONSIDERATIONS FOR ON-SITE CLEARED FACILITIES.
Any cleared contractor facility used for NSW efforts shall be used strictly for official business associated with this contract. No other work may be performed aboard this facility. Additional contract supported work may be performed in other cleared facilities, but only on a case-by-case basis. The COR, NSW security manager, and contracting officer must all be in agreement that this particular arrangement best suits the needs of the government. At the end of this contract the on-site facility must be vacated, with proper written notification being submitted to the DCSA.
X. PROHIBITED ITEMS
The following items are prohibited aboard naval installations and within any NSW spaces with the exception of personnel authorized by the us…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .