Attachment 6 - Applicable Provisions and Clauses Addendum.pdf

PDF 3 MB Posted

Attached to
Science and Technology Applied RF Systems (STARS) Federal contract opportunity
Solicitation number
FA8650-19-S-1110-Call-07
Issued by
Department of the Air Force Materiel Command Research Laboratory

About this file

This document is Attachment 6 - Applicable Provisions and Clauses Addendum to the federal contract opportunity for the Science and Technology Applied RF Systems (STARS) requirement under solicitation FA8650-19-S-1110-Call-07.

The key details are: The solicitation requires offerors to have a current NIST SP 800-171 DoD Assessment (no more than 3 years old) posted in the Supplier Performance Risk System (SPRS) for all relevant covered contractor information systems. Offerors can conduct and submit a Basic Assessment for posting to SPRS if they do not have the required assessment scores already posted. The solicitation also includes provisions prohibiting the use of ByteDance covered applications like TikTok on government information technology and addressing potential organizational conflicts of interest. Additionally, it includes a clause detailing security requirements for work performed at Air Force Research Laboratory (AFRL)-managed facilities.

View the file

Other files for this federal contract opportunity

Show all 14

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Attachment 6

PROVISIONS APPLICABLE TO

ARDIS FA8650-19-S-1110, CALL 07:

DFARS 252.204-7020 NIST SP 800-171 DoD Assessment Requirements

As prescribed in 204.7304(e), use the following provision:

NOTICE OF NIST SP 800–171 DOD ASSESSMENT REQUIREMENTS (NOV 2023)

(a) Definitions.

“Basic Assessment”, “Medium Assessment”, and “High Assessment” have the meaning given in the clause 252.204-7020, NIST SP 800-171 DoD Assessments.

“Covered contractor information system” has the meaning given in the clause 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, of this solicitation.

(b) Requirement. In order to be considered for award, if the Offeror is required to implement

NIST SP 800–171, the Offeror shall have a current assessment ( i.e., not more than 3 years old unless a lesser time is specified in the solicitation) (see 252.204–7020) for each covered contractor information system that is relevant to the offer, contract, task order, or delivery order. The Basic, Medium, and High NIST SP 800–171 DoD Assessments are described in the NIST SP 800–171

DoD Assessment Methodology located at https://www.acq.osd.mil/asda/dpc/cp/cyber/docs/safeguarding/NIST-SP-800-171-Assessment-

Methodology-Version-1.2.1-6.24.2020.pdf .

(c) Procedures.

(1) The Offeror shall verify that summary level scores of a current NIST SP 800-171 DoD

Assessment (i.e., not more than 3 years old unless a lesser time is specified in the solicitation) are posted in the Supplier Performance Risk System (SPRS) () for all covered contractor information systems relevant to the offer.

(2) If the Offeror does not have summary level scores of a current NIST SP 800-171 DoD

Assessment (i.e., not more than 3 years old unless a lesser time is specified in the solicitation) posted in SPRS, the Offeror may conduct and submit a Basic Assessment to for posting to SPRS in the format identified in paragraph (d) of this provision.

(d) Summary level scores. Summary level scores for all assessments will be posted 30 days post-assessment in SPRS to provide DoD Components visibility into the summary level scores of strategic assessments.

(1) Basic Assessments. An Offeror may follow the procedures in paragraph (c)(2) of this provision for posting Basic Assessments to SPRS.

(i) The email shall include the following information:

(A) Cybersecurity standard assessed (e.g., NIST SP 800-171 Rev 1).

Attachment 2

(B) Organization conducting the assessment (e.g., Contractor self-assessment).

(C) For each system security plan (security requirement 3.12.4) supporting the performance of a DoD contract—

(1) All industry Commercial and Government Entity (CAGE) code(s) associated with the information system(s) addressed by the system security plan; and

(2) A brief description of the system security plan architecture, if more than one plan exists.

(D) Date the assessment was completed.

(E) Summary level score (e.g., 95 out of 110, NOT the individual value for each requirement).

(F) Date that all requirements are expected to be implemented (i.e., a score of 110 is expected to be achieved) based on information gathered from associated plan(s) of action developed in accordance with NIST SP 800-171.

(ii) If multiple system security plans are addressed in the email described at paragraph

(d)(1)(i) of this section, the Offeror shall use the following format for the report:

System

Security Plan

CAGE Codes

Supported by this plan

Brief description of the plan architecture

Date of assessment

Total Score Date score of

110 will be achieved

(2) Medium and High Assessments. DoD will post the following Medium and/or High

Assessment summary level scores to SPRS for each system assessed:

(i) The standard assessed (e.g., NIST SP 800-171 Rev 1).

(ii) Organization conducting the assessment, e.g., DCMA, or a specific organization

(identified by Department of Defense Activity Address Code (DoDAAC)).

(iii) All industry CAGE code(s) associated with the information system(s) addressed by the system security plan.

(iv) A brief description of the system security plan architecture, if more than one system security plan exists.

(v) Date and level of the assessment, i.e., medium or high.

(vi) Summary level score (e.g., 105 out of 110, not the individual value assigned for each requirement).

(vii) Date that all requirements are expected to be implemented (i.e., a score of 110 is expected to be achieved) based on information gathered from associated plan(s) of action developed in accordance with NIST SP 800-171.

(3) Accessibility.

(i) Assessment summary level scores posted in SPRS are available to DoD personnel, and are protected, in accordance with the standards set forth in DoD Instruction 5000.79, Defense-wide Sharing and Use of Supplier and Product Performance Information (PI).

(ii) Authorized representatives of the Offeror for which the assessment was conducted may access SPRS to view their own summary level scores, in accordance with the SPRS Software

User’s Guide for Awardees/Contractors available at https://www.sprs.csd.disa.mil/pdf/SPRS_Awardee.pdf.

(iii) A High NIST SP 800-171 DoD Assessment may result in documentation in addition to that listed in this section. DoD will retain and protect any such documentation as

“Controlled Unclassified Information (CUI)” and intended for internal DoD use only. The information will be protected against unauthorized use and release, including through the exercise of applicable exemptions under the Freedom of Information Act (e.g., Exemption 4 covers trade secrets and commercial or financial information obtained from a contractor that is privileged or confidential).

(End of provision)

DAFFARS 5352.209-90001 Potential Organizational Conflict of Interest

As prescribed in DAFFARS 5309.507-2(b), insert the following provision:

POTENTIAL ORGANIZATIONAL CONFLICT OF INTEREST (JUL 2023)

(a) There is potential organizational conflict of interest (see FAR Subpart 9.5, Organizational and Consultant Conflicts of Interest) due to (state the nature of the proposed conflict). Accordingly:

(1) Restrictions are needed to ensure that upon award of this contract, the contractor, in order to gain access to another Government contractor’s proprietary information, enter into Non-

Disclosure Agreements, with the other Government contractors whose data is required for performance for the life of the applicable task order.

(2) As a part of the proposal, the offeror shall provide the contracting officer with complete information of previous or ongoing work that is in any way associated with the contemplated acquisition.

(b) The organizational conflict of interest clause included in this solicitation may not be modified or deleted.

(End of provision) https://www.sprs.csd.disa.mil/pdf/SPRS_Awardee.pdf https://www.acquisition.gov/daffars/part-5309-contractor-qualifications#DAFFARS_5309_507_2

CLAUSES APPLICABLE TO

ARDIS FA8650-19-S-1110, CALL 07

FAR 52.204-27 Prohibition on a ByteDance Covered Application.

As prescribed in 4.2203 , insert the following clause:

PROHIBITION ON A BYTEDANCE COVERED APPLICATION (JUN 2023)

(a) Definitions. As used in this clause—

Covered application means the social networking service TikTok or any successor application or service developed or provided by ByteDance Limited or an entity owned by ByteDance Limited.

Information technology, as defined in 40 U.S.C. 11101(6)—

(1) Means any equipment or interconnected system or subsystem of equipment, used in the automatic acquisition, storage, analysis, evaluation, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information by the executive agency, if the equipment is used by the executive agency directly or is used by a contractor under a contract with the executive agency that requires the use—

(i) Of that equipment; or

(ii) Of that equipment to a significant extent in the performance of a service or the furnishing of a product;

(2) Includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources; but

(3) Does not include any equipment acquired by a Federal contractor incidental to a Federal contract.

(b) Prohibition. Section 102 of Division R of the Consolidated Appropriations Act, 2023 (Pub.

L. 117-328), the No TikTok on Government Devices Act, and its implementing guidance under

Office of Management and Budget (OMB) Memorandum M-23-13, dated February 27, 2023, “No

TikTok on Government Devices” Implementation Guidance, collectively prohibit the presence or use of a covered application on executive agency information technology, including certain equipment used by Federal contractors. The Contractor is prohibited from having or using a covered application on any information technology owned or managed by the Government, or on any information technology used or provided by the Contractor under this contract, including equipment provided by the Contractor’s employees; however, this prohibition does not apply if the Contracting Officer provides written notification to the Contractor that an exception has been granted in accordance with OMB Memorandum M-23-13.

https://www.acquisition.gov/far/4.2203#FAR_4_2203

(c) Subcontracts. The Contractor shall insert the substance of this clause, including this paragraph (c), in all subcontracts, including subcontracts for the acquisition of commercial products or commercial services.

(End of clause)

DAFFARS 5352.209-9000 Organizational Conflict of Interest

As prescribed in DAFFARS 5309.507-2(a), insert the following clause, substantially as written, in

Section I:

ORGANIZATIONAL CONFLICT OF INTEREST (JUL 2023) (ALT III, ALT IV, AND ALT VI)

(a) The following restrictions and definitions apply to prevent conflicting roles which may bias the Contractor's judgment or objectivity, or to preclude the Contractor from obtaining an unfair competitive advantage in concurrent or future acquisitions.

(1) Descriptions or definitions: "Contractor" means the business entity receiving the award of this contract, its parents, affiliates, divisions and subsidiaries. "Development" means all efforts towards solution of broadly-defined problems. This may encompass research, evaluating technical feasibility, proof of design and test, or engineering of programs not yet approved for acquisition or operation. "Proprietary Information" means all information designated as proprietary in accordance with law and regulation, and held in confidence or disclosed under restriction to prevent uncontrolled distribution. Examples include limited or restricted data, trade secrets, sensitive financial information, and computer software; and may appear in cost and pricing data or involve classified information.

(b) The Contractor may gain access to proprietary information of other companies during contract performance. The Contractor agrees to enter into company-to-company agreements to: (1) protect another company's information from unauthorized use or disclosure for as long as it is considered proprietary by the other company; and, (2) to refrain from using the information for any purpose other than that for which it was furnished. For information purposes, the Contractor shall furnish copies of these agreements to the contracting officer. These agreements are not intended to protect information which is available to the Government or to the Contractor from other sources and furnished voluntarily without restriction.

(c) The Contractor agrees to accept and to complete all issued task orders, and not to contract with Government prime Contractors or first-tier subcontractors in such a way as to create an organizational conflict of interest.

(d) The above restrictions shall be included in all subcontracts, teaming arrangements, and other agreements calling for performance of work which is subject to the organizational conflict of interest restrictions identified in this clause, unless excused in writing by the contracting officer.

(End of clause) https://www.acquisition.gov/daffars/part-5309-contractor-qualifications#DAFFARS_5309_507_2

H0023 Air Force Research Laboratory

Wright Research Site Security Requirements (JUN 2023)

(a) Definitions. As used in this clause –

Air Force Research Laboratory (AFRL)-managed facilities means -

(1) AFRL buildings, areas, test facilities, and laboratories located at the AFRL Wright Research Site, Wright-Patterson Air Force Base (WPAFB), Ohio;

(2) Buildings owned or facility space leased by the AFRL Wright Research Site, whether for single or multi-tenant occupancy, and its grounds and approaches, all or any portion of which is under the jurisdiction, custody, or control of the AFRL Wright Research Site;

(3) Commercial space managed by the AFRL Wright Research Site that is shared with non-government tenants. For example, if the AFRL Wright Research Site leased the 10th floor of a commercial building, the directive applies to the 10th floor only;

(4) Contractor-operated facilities owned by the AFRL Wright Research Site, including laboratories engaged in national defense research and production activities.

Augmented reality (AR) device means a device that is capable of, or assists in, augmented reality by enhancing or creating digital overlays. AR is used to enhance natural environments or situations and offers perceptually enriched and interactive experiences achieved through digital visual elements, sounds, and other sensory stimuli via holographic technology. Examples include, but are not limited to, hardware components such as display sensors, computers, projectors, input devices, mobile devices, eyewear, wireless communication devices, and cameras.

Data storage device means computer hardware used to remember/store data. Examples include, but are not limited to, remote or autonomous drones, CDs, DVDs, Blue-Rays, USB flash drives, jump/stick/pen drives, external hard drives, solid state drives, cloud storage, mainframes, laptops, desktops, and flop disks.

Formal investigation means the process of investigation ordered by a competent U.S. Government authority that involves the questioning of involved parties and gathering of data with the intent to determine if classified or controlled unclassified information (CUI) was lost, compromised, suspected to be compromised, or not compromised at all.

Personal means items that are owned by an individual, person, or private entity and not provided for use under this contract by the U.S. Government.

Physical computer network means interconnected computing devices of any kind that can exchange data and share resources or communicate with other types of devices to execute operations or store information of any kind.

Security Incident Investigation (SII) means a formal investigation that occurs when there is a known or suspected loss of national security information (NSI) or CUI. U.S. Government security personnel conduct

SIIs to (1) determine the circumstances surrounding an actual or potential compromise of NSI or CUI; (2) ascertain individual responsibility; (3) notify outside stakeholders, when necessary; and (4) make recommendations to prevent similar occurrences in the future.

Virtual device means a device with no associated hardware. A virtual device mimics a physical hardware device when, in fact, it exists only in software form. Therefore, the device makes the system believe that a particular hardware exists when in reality it does not. Examples include, but are not limited to, a computer, tablet, or smartphone that is simulated in a computer.

(b) Prohibition. The following is prohibited within AFRL-managed facilities, except when explicitly authorized by a U.S. Government contract:

(1) Prohibited activities -

a. Photography

b. Videography

c. Live Streaming

d. Recordings of any kind (e.g., audio)

(2) Prohibited personal networks and devices -

a. AR devices

b. Virtual devices

c. Wi-Fi networks

d. Physical computer networks

e. Data storage devices

(c) Waivers. A request for a waiver to the prohibitions outlined in paragraph (b) shall be submitted in writing to the Government Program Manager/Contracting Officer’s Representative (COR) for internal Government coordination and approval. If a waiver request is granted, written approval shall be provided by the cognizant AFRL Operations Security (OPSEC) coordinator and Security Chief. The specific format for a waiver request will be provided upon request to the Government Program Manager/COR.

(d) Incident Reporting Requirement. If the contractor discovers a prohibited activity identified in paragraph

(b)(1) has occurred within an AFRL-managed facility and/or a prohibited personal network or device identified in paragraph (b)(2) has been brought into an AFRL-managed facility without a valid waiver, as specified in paragraph (c), the incident shall be immediately reported in writing to the Government Program

Manager/COR with a courtesy copy to the Contracting Officer.

(e) Violations. If a violation of this clause occurs or is suspected to have occurred, the cognizant AFRL security organization will lead and conduct a formal investigation. If a violation or suspected violation may involve classified material, the cognizant AFRL security organization will lead and conduct a Security Incident

Investigation (SII). Depending on the outcome of the investigation and the information involved, penalties for violations can range from a written warning to removal from the AFRL-managed facility and/or installation. Violations and potential penalties will be governed by the applicable contract clause(s), law(s), or regulation(s).

(f) Subcontracts. The contractor shall include this clause in all subcontracts or similar contractual instruments/agreements relating to work performed under this contract.

(End of clause)

Attachment 8 - Applicable Provisions and Clauses Addendum
Attachment 8 -
AFRL Wright Research Site Security Requirements H-Clause_05 Jun 23_FINAL

DPC

File details come from the government source that posted it. Updated .