Attachment 4 DD254 FA880924RB001.pdf
PDF 517 KB Posted
- Attached to
- RFP - Space Test Experiments Platform (STEP) 2. 0 Federal contract opportunity
- Solicitation number
- FA880924RB001
- Issued by
- Department of the Air Force
About this file
This document is a DD Form 254, which is a Department of Defense Contract Security Classification Specification. It provides details on the security requirements for a classified federal contract opportunity, Solicitation #FA880924RB001 for the Space Test Experiment Platform (STEP) 2.0 program.
The key details are:
- This is a multiple-award Indefinite Delivery/Indefinite Quantity (IDIQ) contract to procure proven spacecraft and space access for science and technology experiments, with a base period of 5 years and 1 option period of 5 additional years.
- The contract requires access to classified information up to the Top Secret level, including COMSEC, RESTRICTED DATA, FORMERLY RESTRICTED DATA, Sensitive Compartmented Information (SCI), and NATO information.
- Specific security requirements are outlined, such as facility clearance, personnel clearances, COMSEC controls, TEMPEST requirements, and Operations Security (OPSEC) measures.
- The contract has public release restrictions and requires a Program Protection Plan and Security Classification Guides to be followed.
- The contracting activity is the Space Systems Command (SSC) at Kirtland AFB.
View the file
Other files for this federal contract opportunity
Show all 27
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
CLASSIFICATION (When filled in): Unclassified
FA880924R-B001
PREVIOUS EDITION IS OBSOLETE. Page 1 of 8DD FORM 254, APR 2018
DEPARTMENT OF DEFENSE
CONTRACT SECURITY CLASSIFICATION SPECIFICATION
(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)
OMB No. 0704-0567 OMB approval expires:
June 30, 2025
The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.
RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.
1. CLEARANCE AND SAFEGUARDING
a. LEVEL OF FACILITY SECURITY CLEARANCE (FCL) REQUIRED (See Instructions)
Top Secret
b. LEVEL OF SAFEGUARDING FOR CLASSIFIED INFORMATION/
MATERIAL REQUIRED AT CONTRACTOR FACILITY
Top Secret
2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)
a. PRIME CONTRACT NUMBER (See instructions.)
b. SUBCONTRACT NUMBER
c. SOLICITATION OR OTHER NUMBER
FA8809-24-R-B001
DUE DATE (YYYYMMDD)
3. THIS SPECIFICATION IS: (X and complete as applicable.)
a. ORIGINAL (Complete date in all cases.)
DATE (YYYYMMDD)
20240418
b. REVISED (Supersedes all previous specifications.)
REVISION NO. DATE (YYYYMMDD)
c. FINAL (Complete Item 5 in all cases.) DATE (YYYYMMDD)
4. IS THIS A FOLLOW-ON CONTRACT? No Yes If yes, complete the following:
Classified material received or generated under (Preceding Contract Number) is transferred to this follow-on contract.
5. IS THIS A FINAL DD FORM 254? No Yes If yes, complete the following:
In response to the contractor's request dated , retention of the classified material is authorized for the period of:
6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)
a. NAME, ADDRESS, AND ZIP CODE
TBD
b. CAGE CODE
TBD
c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)
TBD
7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor)
a. NAME, ADDRESS, AND ZIP CODE
N/A
b. CAGE CODE
N/A
c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)
N/A
8. ACTUAL PERFORMANCE (Click button to add more locations.)
a. LOCATION(S) (For actual performance, see instructions.)
SSC/SZI (RSC)
3548 Aberdeen Ave SE Kirtland AFB, NM, 87117
b. CAGE CODE (If applicable, see Instructions.)
N/A
c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)
377 ABW/IP
4500 Biggs Ave SE Kirtland AFB, NM 87117
(505) 846-9867 377abw.ip@us.af.mil
a. LOCATION(S) (For actual performance, see instructions.)
TBD
b. CAGE CODE
(If applicable, see Instructions.)
TBD
c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)
TBD
9. GENERAL UNCLASSIFIED DESCRIPTION OF THIS PROCUREMENT
The Space Test Experiments Platform 2.0 (STEP 2.0) initiative establishes a multiple award Indefinite Delivery/Indefinite Quantity contract to procure flight proven Space Vehicles and supporting Ground Control Systems in order to provide space access for Department of Defense
FA880924R-B001
PREVIOUS EDITION IS OBSOLETE. Page 2 of 8DD FORM 254, APR 2018
Science & Technology experiments. STEP 2.0 Space Vehicles will range in size from 6U CubeSat to Multi-Manifest Design Specification Rev 1.0A Class 2, and will be primarily operated in either Low Earth Orbit or Geosynchronous Equatorial Orbit.
10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)
a. COMMUNICATIONS SECURITY (COMSEC) INFORMATION f. SPECIAL ACCESS PROGRAM (SAP) INFORMATION
b. RESTRICTED DATA
g. NORTH ATLANTIC TREATY ORGANIZATION
(NATO) INFORMATION
c. CRITICAL NUCLEAR WEAPON DESIGN INFORMATION (CNWDI) (If CNWDI applies, RESTRICTED DATA must also be marked.)
h. FOREIGN GOVERMENT INFORMATION
d. FORMERLY RESTRICTED DATA
i. ALTERNATIVE COMPENSATORY CONTROL MEASURES
(ACCM) INFORMATION
e. NATIONAL INTELLIGENCE INFORMATION:
(1) Sensitive Compartmented Information (SCI)
(2) Non-SCI
j. CONTROLLED UNCLASSIFIED INFORMATION (CUI) (See instructions.)
k. OTHER (Specify) (See instructions.)
NIPRNET, SIPRNET and JWICS are authorized
11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)
a. HAVE ACCESS TO CLASSIFIED INFORMATION ONLY AT
ANOTHER CONTRACTOR'S FACILITY OR A GOVERNMENT
ACTIVITY
(Applicable only if there is no access or storage required at contractor facility.
See instructions.)
b. RECEIVE AND STORE CLASSIFIED DOCUMENTS ONLY
c. RECEIVE, STORE, AND GENERATE CLASSIFIED
INFORMATION OR MATERIAL
d. FABRICATE, MODIFY, OR STORE CLASSIFIED HARDWARE
e. PERFORM SERVICES ONLY
f. HAVE ACCESS TO U.S. CLASSIFIED INFORMATION OUTSIDE
THE U.S.,PUERTO RICO, U.S. POSSESSIONS AND TRUST
TERRITORIES
g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE
TECHNICAL INFORMATION CENTER (DTIC) OR OTHER
SECONDARY DISTRIBUTION CENTER
h. REQUIRE A COMSEC ACCOUNT
i. HAVE A TEMPEST REQUIREMENT
j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS
k. BE AUTHORIZED TO USE DEFENSE COURIER SERVICE
l. RECEIVE, STORE, OR GENERATE CONTROLLED UNCLASSIFIED
INFORMATION (CUI).
(DoD Components: refer to DoDI 5200.48, only for specific CUI protection requirements. Non-DoD Components: see instructions.)
m. OTHER (Specify) (See instructions.)
See Block 13
12. PUBLIC RELEASE
Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority.
Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)
DIRECT THROUGH (Specify below)
SSC/SZI, 3548 Aberdeen Ave SE., Kirtland AFB, NM 87117, 505-853-7811
Public Release Authority:
SSC/PA, 483 Aviation Blvd., El Segundo, CA 90245 310-653-1204, SSCPA@us.af.mil
13. SECURITY GUIDANCE
The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract;
and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.
(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)
FAR 52.204-2 Security Requirements. Security Requirements Clause: (a) This clause applies to the extent that this contract involves access to information classified up to “Top Secret” (b)The Contractor shall comply with (1) The Security Agreement ( DD Form 441/DD Form 254), including 32 Code of Federal Regulation (CFR) Part 117, National Industrial Security Program Operating Manual (NISPOM); and
(2) Any revisions to that manual, notice of which has been furnished to the Contractor. (c) If, subsequent to the date of this contract, the security classification or security requirements under this contract are changed by the Government and if the changes cause an increase or decrease in security costs or otherwise affect any other term or condition of this contract, the contract shall be subject to an equitable
FA880924R-B001
PREVIOUS EDITION IS OBSOLETE. Page 3 of 8DD FORM 254, APR 2018 adjustment as if the changes were directed under the Changes clause of this contract. (d) The Contractor agrees to insert terms that conform substantially to the language of this clause, including this paragraph but excluding any reference to the Changes Clause of this contract, in all subcontracts under this contract that involve access to classified information.
By signing this form, the requesting Government program office and the servicing Contractor (or Subcontractor) verify that the stated access requests on this form are based on legitimate and bona fide need(s)/requirement(s) of the Government.
Classified national security information, and controlled unclassified information (CUI) shall be protected as outlined in the SCG, NISPOM, DODI 5200.48/DAFI 16-1403, and/or DODM 5200.01 V1-3. For any conflicts, challenges and/or questions regarding this guidance, contact:
SSC/SZI Security at 3548 Aberdeen Avenue, SE; Kirtland AFB, New Mexico 87117
The Prime Contractor shall submit to SSC/INX and Program Office Government Contracting Authority (GCA) all DD-254s for subcontractor(s) for review and approval prior to subcontractors having access to classified information. If this is an update to the DD-254 to an existing contract, the Prime Contractor will provide to the GCA a copy of DD-254s issued to subcontractors supporting this effort.
Subcontractors are not authorized access to Classified information/COMSEC/NATO information/task on contract until approved by GCA.
Ref 7a. (Subcontractor): The prime contractor shall submit to SSC/IN Security and the Program Office Government Contracting Authority (GCA) all DD254s for subcontractor(s) for review and approval prior to subcontractors having access to classified information. If this is an update to the DD254 of an existing contract, the Prime contractor will provide to the GCA a copy of DD254s issued to subcontractors supporting this effort. Subcontractors are not authorized access to classified information, COMSEC or NATO information/task on this contract until approved by GCA.
Ref 10a COMSEC: Classified COMSEC material is not releasable to contractor employees who have not received a FINAL clearance at the appropriate security level. All personnel granted access to COMSEC are required to be familiar with applicable Air Force and specialized COMSEC publications, and Air Force Methods and Procedures Technical Orders (MPTOs), etc. When access is required at Government facilities, contractor personnel will adhere to COMSEC rules and regulations as mandated by Command policy and procedures. Written concurrence of the GCA is required prior to subcontracting. The Prime Contractor should also notify the National Security Agency (NSA) Central Office of Record (COR) before negotiating or awarding subcontracts. Further disclosure of COMSEC information by a contractor, to include subcontracting, requires approval of the GCA. Non-accountable COMSEC information, though not tracked in the COMSEC material control system, may still require a level of control within a document control system. Refer to NSA/CSS Manual 3-16, “Control of Communications Security Material,” and the Committee on National Security Systems Instruction (CNSSI) 4001, “Controlled Cryptographic blocks,” for guidance. If access to COMSEC information is required at Government facilities, or the material is under Government control, contractor personnel will follow the security requirements of the host government activity, AFMAN 17-1302-0, Communications Security (COMSEC) Operations, 2 Apr 20 and MPTO 00-33B-5001, AF Accounting COMSEC Procedures. Contractor will comply with AFMAN 17-1302-O, Communications Security (COMSEC) Operations, 9 Apr 20. Contractor personnel will follow the security requirements of the host government activity.
Ref 10b: The contractor is permitted access to RESTRICTED DATA (RD) in the performance of this contract. Access to RD requires a final U.S. Government clearance at the appropriate level.
Ref 10.d.: The contractor is permitted access to Formerly Restricted Data (FRD) in the performance of this contract. Access to FRD requires a final U.S. Government clearance at the appropriate level.”
Ref 10e (1): SCI. No public release of information authorized, public disclosure or confirmation of any subject related to the support contract is not authorized without first obtaining written approval from the SSC/INS SSO Security Office. Written concurrence of SSC/AC INS SSO Security Office is required prior to subcontracting. The SSC/INS SSO Security Office shall have security cognizance for SCI.
All activities involving SCI (including discussions) will be conducted in a SENSITIVE COMPARTMENT FACILITY(SCIF). Physical security standards for SCIFs are contained in the ICD 705, applicable IC specifications, or standards and implementing DoD Component policies. SCI ADDENDUM V 6.0 will be provided upon award.
Ref 10e (2): NON-SCI. The contractor shall handle non-SCI or “collateral” intelligence information IAW 32 CFR Part 117 National Industrial Security Program Operating Manual, (NISPOM), DoDM 5200.01 V1-V3, Information Security Program and AFM 16-1404 - V1-V3, Information Security Program. Particular emphasis is placed on the contractor(s) correctly understanding and heeding intelligence portion markings. As classified material, the contractor shall afford collateral intelligence information the same protections, safeguards, and precautions required by any classified material required by DoDM 5200.01 V1-V3, unless special intelligence related handling instructions are specifically imposed. The contractor shall neither disclose, nor release intelligence derived information, whether its status is collateral or SCI, without the prior consent of the Security Intelligence Officer (SIO).
Ref 10f: Special Access Program (SAP) Information: DD 254 SAP Addendum will be provided upon award.
FA880924R-B001
PREVIOUS EDITION IS OBSOLETE. Page 4 of 8DD FORM 254, APR 2018
Ref 10g: The contractor is permitted access to North Atlantic Treaty Organization (NATO) information in performance of this contract.
Personnel requiring access to NATO classified information, NATO COSMIC, NATO Secret or access to the NATO accredited terminals, must possess the equivalent FINAL or Interim U.S. Security Clearance based upon the appropriate personnel security investigation required. The government project manager is the designated representative that will ensure the contractor Facility Security Officer and concerned employees are NATO briefed prior to access being granted. Prior approval of the contracting activity is required for subcontracting. Access requires a final U.S. Government clearance at the appropriate level. Forward NATO classified materials needed by the contractor only from an Air Force Sub-registry directly to the contractor concerned. Prior written approval from the GCA is required for subcontracting.
Ref 10h: The contractor is permitted access to Foreign Government information. Access to Foreign Government information requires a final U.S. Government clearance at the appropriate level. FGI shall be protected in the same manner at the equivalent U.S. government classified information. Information supplied by or provided to a foreign government(s) shall be handled in accordance with the NISPOM and DoDM 5200.0l. Vl-V3.
Ref 10j: Access to Controlled Unclassified Information is required. Contractors will comply with DoDI 5200.48/AFI 16-1403, DFARS 252.204-7000, 252.204-7012, and 252.204-7020 with emphasis on identification, sharing, marking, safeguarding, storage, dissemination, destruction, and records management of CUI. In accordance with Part 2002 of Title 32, CFR, CUI requires safeguarding or dissemination controls identified in a law, regulation, or government-wide policy for information that does not meet the requirements for classification in accordance with E.O. 13526. DoDI 5200.48/AFI 16-1403 contains specific CUI requirements that the contractor must review and assess in entirety. The contractor will notify the government Contracting Officer if unable to meet or comply with any applicable CUI requirements.
CUI initial and annual refresher training will be required for all contractors. The contractor shall not access, download or further disseminate any CUI outside the execution of the defined contract requirements without the guidance and written permission of the government Contracting Officer. CUI must be controlled until authorized for public release in accordance with DoD Instructions (DoDIs).
In accordance with DoDIs 8500.01 and 8510.01, security controls for systems and networks are set to the level required by the safeguarding requirements for the data or information being processed, as identified in Federal Information Processing Standards 199 and
200. For DoD CUI, the minimum security level will be moderate confidentiality in accordance with Part 2002 of Title 32, CFR and NIST SP 800-171. Contractors will not use unofficial or personal (e.g., .net; .com) e-mail accounts, messaging systems, or other non-DoD information systems, except approved or authorized government contractor systems, to conduct official business involving CUI.
Contractors must monitor CUI for aggregation and compilation based on the potential to generate classified information pursuant to security classification guidance addressing the accumulation of unclassified data or information. DoD contracts shall require contractors to report the potential classification of aggregated or compiled CUI to Contracting Officer or designated government security representative.
Ref 10k: Access to SIPRNet and JWICS are required in performance of this contract. Secret Internet Protocol Network (SIPRNet) access is required. The contractor shall not access, download or further disseminate any special access data (i.e. intelligence, NATO, COMSEC, etc.) outside the execution of the defined contract requirements and without the guidance and written permission of the government Contracting Officer. NATO awareness briefing is required prior to having access to the SIPRNT and NATO/Secret access is required prior to having access to JWICS.
Ref 10k., IT/AIS/IS/LAN. Information Technology (IT)/Automated Information System/s (AIS)/Information Systems (IS)/Local Area Network (LAN): The contractor will require access to the government IT/AIS/IS/LAN to perform their contractual duties. Contractors requiring access to government IT/AIS/IS/LAN must meet authorized user access control, training, reporting and other requirements specified by the host installation and as contained in AFMAN 17-1301, which includes being determined to be trustworthy by a designated government official prior to LAN access being granted. At no time will individual personally owned computer systems be used to support government operations without prior DAA C&A approval. At no time will foreign nationals or foreign government personnel be granted access to any information systems with official government information associated with the contract (either processing or with data at rest) without specific prior approval from GCA and DAA C&A. Ensure all users are warned and provided with appropriate privacy and security notices that the systems they are entering are DoD systems, and thus subject to monitoring, recording and auditing by authorized personnel.
In addition, in accordance with HSPD-12 any new applicant for the Common Access Card (CAC) will require an appropriate background investigation prior to issuance of CAC. Contractor shall report as soon as possible upon learning of cyber intrusions and other compromises of Defense Program Information (DPI) to their supporting counterintelligence office, which will inform the DoD-DIB Common Information Sharing Environment (DCISE). The Contractor will also notify the government Security Manager of any incidents.
Ref 1lc: Contractor will reference the appropriate security classification guidance when generating or deriving classified material or hardware. SCGs will be provided upon award and provided under separate cover. All classified information received or generated will be properly stored and handled according to the markings on the material. All classified information received or generated is the property of the U.S. Government. At the termination or expiration of the contract, the U.S. Government will be contacted to proper disposition instructions. The contractor requires access to classified source data, up to and including: the level of classified information stated for performance at contractor locations listed in Item 8.a. in support of the work effort. Any extracts or use of such data requires the contractor to apply derivative classifications and markings consistent with the source documents. Use of “Multiple Sources” on the “Classified By” line necessitates compliance with the NISPOM, paragraph 4-208, and use of a bibliography. Classification, declassification, and markings
FA880924R-B001
PREVIOUS EDITION IS OBSOLETE. Page 5 of 8DD FORM 254, APR 2018 will be in accordance with EO 13526 and other applicable Executive Orders.
Ref 11d: The contractor must provide adequate storage for classified hardware to the level of TOP SECRET which exceeds two cubic feet and is of size or quantity that cannot be safeguarded in an approved storage container.
Ref 11g: The contractor may access information provided by DTIC by complying with all established safeguards and is required to register at https://discover.dtic.mil/dtic-registration-benefits/dtic-registration/. You may be asked to complete a DD Form 2345, Military Critical Technical Data Agreement. If you need help registering you can find information here https://reg.dtic.mil/help/index.html or call DTIC at 1-800-225-3842.
Ref 11h: Accountable COMSEC material includes COMSEC aids and equipment which have the purpose to secure telecommunications or to ensure authenticity of such communications to include COMSEC key, CCI, in-process items that describe cryptographic logic and other items which perform COMSC functions. This material must be controlled within the COMSEC material Control System (CMCS) or an in-process accounting system. The Contractor will seek clarification from the government Contracting Officer, Program Manager or 377 MSG/SCXS installation COMSEC Manager for any area dealing with COMSEC and/or CYRPTO they are unsure of in regards to procedures, access, handling, safeguarding, etc. All directions and guidance from the 377 MSG/SCXS installation COMSEC Manager concerning contractors having a COMSEC account will be followed.
Ref 11i: Emanations security (aka TEMPEST) requirements apply to the SCIF execution location. See Defense Federal Acquisition Regulation Supplement (DFARS) Clause 252.239-7000, "Protection Against Compromising Emanations," dated October 2019; Intelligence Community (IC) Tech Spec-for ICD/ICS 705, "Technical Specifications For Construction and Management of Sensitive Compartmented Information Facilities," version 1.5, dated 13 March 2020; Committee on National Security Systems Advisory Memorandum (CNSSAM) TEMPEST/01-13, "Red/Black Installation Guidance," dated 17 January 2014.
Ref 11j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS. OPSEC requirements apply. The contractor shall accomplish the following minimum requirements in support of the user agency’s Operations Security (OPSEC) Program. Compliance with security requirements imposed by documents generated in response to DoDI 5200.39, Critical Program Information (CPI) Identification and Protection within Research, Development, Test and Evaluation (RDT&E), 28 May 2015, is required. Compliance with OPSEC measures if imposed by programs supported or by documents generated by user agency programs may be necessary. OPSEC program shall be IAW DoDM 5205.2, dated 3 November 2008 and AFI 10-701, dated 9 June 2020. Program OPSEC plans shall be coordinated with and approved by the user agency and shall be imposed on subcontractors as appropriate. Program protection measures shall be approved by the user agency and shall be applied at ALL locations where Critical Information is developed, produced, analyzed, maintained, transported, stored, tested, or used in training.
The contractor shall protect all unclassified information and activities, which could compromise classified information or operations, or degrade the planning and execution of military operations performed by the contractor in support of the mission. Contractor shall protect controlled unclassified information (CUI) and information identified in the SSC and SSC program office critical information list (CIL).
Disposition of Critical Information and CUI obtained or produced pursuant to this agreement shall be shredded/degaussed to prevent reconstruction. The contractor shall develop an OPSEC Plan in accordance with DoDM 5205.2. Include OPSEC as a part of their ongoing security awareness program conducted in accordance the National Industrial Security Operating Manual. Be responsive to the user agency OPSEC Manager on a non-interference basis. Protect sensitive unclassified information and activities, which could compromise classified information or operations, or degrade the planning and execution of military operations performed by the contractor in support of the mission. The contractor shall comply with AFI 35-102, Security and Policy Review Process for guidance and /or direction.
Ref 11l: Access to Controlled Unclassified Information is required. Contractors will comply with DoDI 5200.48/AFI 16-1403, DFARS 252.204-7000, 252.204-7012, and 252.204-7020 with emphasis on identification, sharing, marking, safeguarding, storage, dissemination, destruction, and records management of CUI. In accordance with Part 2002 of Title 32, CFR, CUI requires safeguarding or dissemination controls identified in a law, regulation, or government-wide policy for information that does not meet the requirements for classification in accordance with E.O. 13526. DoDI 5200.48/AFI 16-1403 contains specific CUI requirements that the contractor must review and assess in entirety. The contractor will notify the government Contracting Officer if unable to meet or comply with any applicable CUI requirements.
CUI initial and annual refresher training will be required for all contractors. The contractor shall not access, download or further disseminate any CUI outside the execution of the defined contract requirements without the guidance and written permission of the government Contracting Officer. CUI must be controlled until authorized for public release in accordance with DoD Instructions (DoDIs).
In accordance with DoDIs 8500.01 and 8510.01, security controls for systems and networks are set to the level required by the safeguarding requirements for the data or information being processed, as identified in Federal Information Processing Standards 199 and
200. For DoD CUI, the minimum security level will be moderate confidentiality in accordance with Part 2002 of Title 32, CFR and NIST SP 800-171. Contractors will not use unofficial or personal (e.g., .net; .com) e-mail accounts, messaging systems, or other non-DoD information systems, except approved or authorized government contractor systems, to conduct official business involving CUI.
Contractors must monitor CUI for aggregation and compilation based on the potential to generate classified information pursuant to security classification guidance addressing the accumulation of unclassified data or information. The contractor shall not release to anyone
FA880924R-B001
PREVIOUS EDITION IS OBSOLETE. Page 6 of 8DD FORM 254, APR 2018 outside the Contractor's organization any unclassified information, regardless of medium (e.g., film, tape, document), pertaining to any part of this contract or any program related to this contract, unless the Contracting Officer has given prior written approval. DoD contracts shall require contractors to report the potential classification of aggregated or compiled CUI to Contracting Officer or designated government security representative.
Ref 11m. GOVERNMENT NOTIFICATIONS. The Contractor will notify the government when so directed and/or specified by provisions in this DD254, related contract FA8809-24-R-B001 and/or related clauses, attachments, addendums, etc. Provide the information requested by the Notification of Government Security Activity, Department of the Air Force Federal Acquisition Regulation Supplement (DAFFARS) 5352.204-9000. The Contractor will immediately notify the government Contracting Officer of any changes relating to foreign owned, controlled, or influence (FOCI) type concerns, events and/or changes which may affect their Facility Security Clearance (FCL). Security Education and Training: Contractor personnel will participate in and receive security education and training at direction of the government Security Manager to include initial, recurring and annual venues. Training may include what defines classified information and CUI: proper protection of classified and CUI: actions to take if classified information or and use of Security Classification Guides/s (SCG/s) will also be done. Contractor personnel not completing required training may be limited or prohibited from doing government work if deemed necessary by the government Program Manager. Related training records should be maintained on file for review by the
CSO.
Reference Block 12: PUBLIC RELEASE SECURITY: Contractor is to submit requests through the contracting officer for OPSEC program manager review and public release authorization. The contracting officer will provide contractor with written approval/ disapproval. Information requiring AF or DoD-level review will be reviewed by the unit’s OPSEC program manager or coordinator who will in-turn forward to the entry-level public affairs office through the AFIMSC Public Affairs Office to the Secretary of the Air Force, Office of Public Affairs, Security and Review Division (SAF/PAX), 1690 Air Force Pentagon, Washington DC 20330-1690.
Reference Block 13: SECURITY GUIDANCE:
The LSP (Local Security Policies) is a legally binding contractual agreement between the DoD contractor and AF, and must be executed prior to initiation of on-base operations, unless an extension is specifically authorized permitting immediate on-base operational access due to mission requirements. Prime contractors are responsible for ensuring their subcontractors are knowledgeable of and comply with the applicable requirements. Prime must include a provision in each sub-contract that requires subcontractors to contact the installation commander’s designee (377 ABW/IPD at (505) 846-9867), Kirtland AFB Industrial Security Office. Subcontractors must execute a separate and/or independent LSP with the installation when not collocated (i.e., not working at the same military reservation) with the prime contractor. If at the same location, a subcontractor signature indicating acknowledgement of the prime contractor LSP requirements is acceptable, prior to beginning on-base operations.
The Contractor will notify the Government Contracting Activity and the Government Security Manager within 48 hours of any incident involving the actual or suspected compromise/loss of classified information to enable the Government to conduct immediate assessment of potential impact pending formal inquiry/investigation. Actual or suspected compromise of Covered Defense Information will be reported IAW DFARS Clause 252.204-7012.
Program Protection Plans (PPP) and Security Classification Guides (SCG):
The contractors shall protect critical program information (CPI) and critical components (CC) in compliance with the Program Protection Plan (PPP). Program Security Classification Guides (SCGs) will be provided by the Government program office. Classified national security information, and unclassified controlled information (CUI) shall be protected as outlined in the SCG, NISPOM and/or DODM
5200.01 V1-3.
The contractors shall protect critical program information (CPI) in compliance with the Research and Development Space and Missile Operations Program Protection Plan (PPP) and mission critical components. The contractor shall develop a Program Protection Implementation Plan (PPIP), to be approved by the program office, that describes the protection measures being implemented by the contractor and sub-contractors for protecting CPI and mission critical components. The prime contractor will flow-down to any subcontractor protection requirements for implementation as described in the PPIP in compliance with the PPP.
List of Attachments (All Files Must be attached Prior to Signing, i.e., for any digital signature on the form)
377 ABW/IPD NAME & TITLE OF REVIEWING OFFICIAL
KEITH W. KOLB
377 ABW Information Protection
SIGNATURE
SSC/SZI
NAME & TITLE OF REVIEWING OFFICIAL
ROLAND CANTU
Security Manager
SIGNATURE
SSC/SZIS
KOLB.KEITH.
W.1029146060
Digitally signed by
KOLB.KEITH.W.1029146060
Date: 2024.04.19 09:32:39 -05'00'
CANTU.ROLA
ND.1125511380
Digitally signed by
CANTU.ROLAND.1125511380
Date: 2024.04.19 08:55:31 -06'00'
FA880924R-B001
PREVIOUS EDITION IS OBSOLETE. Page 7 of 8DD FORM 254, APR 2018
NAME & TITLE OF REVIEWING OFFICIAL
MAJ DAVID LORE
Government Program Manager
SIGNATURE
14. ADDITIONAL SECURITY REQUIREMENTS
Requirements, in addition to NISPOM requirements for classified information, are established for this contract.
No Yes If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted.
(See instructions for additional guidance or use of the fillable PDF.)
SCI Addendum 6.0. and SAP Addendum will be provided upon award.
15. INSPECTIONS
Elements of this contract are outside the inspection responsibility of the CSO.
No Yes If Yes, explain and identify specific areas and government activity responsible for inspections. The field will expand as text is added or you can also use item
13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted.
(See instructions for additional guidance or use of the fillable PDF.)
SSC/INS SSO has exclusive security responsibility for SCI classified material released or developed under this contract and held within the contractor’s SCIF. The Defense Counterintelligence and Security Agency (DCSA) has been relieved of inspection oversight responsibilities for SAP programs associated with this contract. The Air Force is identified as the Servicing Security Activity (SSA) with the Office of Special Investigations (OSI), Office of Special Projects (PJ) fulfilling the execution role for all contractor inspections under the purview of
SAF/AAZ.
16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)
a. GCA NAME
SSC/SZK
b. ACTIVITY ADDRESS CODE (AAC) OF THE CONTRACTING OFFICE (See Instructions)
FA8809
c. ADDRESS (Include ZIP Code)
3548 Aberdeen Ave SE Kirtland AFB, NM 87117
d. POC NAME
Larry D. Asberry Jr.
e. POC TELEPHONE (Include Area Code)
+1 (405) 633-3487
f. EMAIL ADDRESS (See Instructions) larry.asberry@spaceforce.mil
17. CERTIFICATION AND SIGNATURES
Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below. Upon digitally signing Item 17h, no changes can be made as the form will be locked.
a. TYPED NAME OF CERTIFYING OFFICIAL (Last, First, Middle Initial) (See Instructions)
Asberry, Larry D. Jr.
b. TITLE
Contracting Officer
c. ADDRESS (Include ZIP Code)
SSC/SZK
3548 Aberdeen Ave SE Kirtland AFB, NM 87117
d. AAC OF THE CONTRACTING OFFICE (See Instructions)
FA8809
e. CAGE CODE OF THE PRIME CONTRACTOR (See Instructions.)
N/A
f. TELEPHONE (Include Area Code)
+1 (405) 633-3487
g. EMAIL ADDRESS (See Instructions) larry.asberry@spaceforce.mil
h. SIGNATURE
i. DATE SIGNED (See Instructions)
20240419
LORE.DAVID.JA
MES.1395819158
Digitally signed by
LORE.DAVID.JAMES.13958191
Date: 2024.04.19 09:01:09 -06'00'
ASBERR
Y.LARRY
.D.JR.152
3615390
Digitally signed by
ASBERRY.LAR
RY.D.JR.152361
Date: 2024.04.19 13:46:06 -05'00'
FA880924R-B001
PREVIOUS EDITION IS OBSOLETE. Page 8 of 8DD FORM 254, APR 2018
18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL
a. CONTRACTOR
b. SUBCONTRACTOR
c. COGNIZANT SECURITY OFFICE FOR PRIME AND
SUBCONTRACTOR
d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY
ADMINISTRATION
e. ADMINISTRATIVE CONTRACTING OFFICER
f. OTHER AS NECESSARY (If more room is needed, continue in Item 13 or on additional page if necessary.)
SSC/SZI Program Manager
377 ABW/IPD
File details come from the government source that posted it. Updated .