Attachment_G_CUI_Guide.pdf
PDF 217 KB Posted
- Attached to
- Structures Uniquely Resolved to Guarantee Endurance (SURGE) Federal contract opportunity
- Solicitation number
- HR001124S0018
About this file
This document is a Controlled Unclassified Information (CUI) guide for the Structures Uniquely Resolved to Guarantee Endurance (SURGE) program, which is managed by the Defense Advanced Research Projects Agency (DARPA). The guide outlines the authority, applicability, and protection requirements for sensitive information associated with the SURGE program. It identifies specific CUI categories, including Controlled Technical Information, Proprietary Business Information, Budget Information, and Operations Security Information. The guide provides instructions for public disclosure, Freedom of Information Act requests, and reporting unauthorized disclosures related to SURGE CUI. In addition, it includes information protection guidance charts that specify the level of dissemination control for various types of SURGE-related information.
The related federal contract opportunity is a pre-solicitation for the SURGE program, which aims to develop methods to predict the useful life of critical structural parts produced through additive manufacturing. The research will focus on merging in-situ sensing, process modeling, and microstructure-based fatigue life methods to enable efficient part qualification and distributed additive manufacturing capabilities. Proposals are being solicited for innovative approaches that enable revolutionary advances in this area.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachment_E_Proposal_Instructions_and_Volume_II_Template__Cost.docx | DOCX document | |
| Attachment_B_Abstract_Instructions_and_Template.docx | DOCX document | |
| Attachment_C_Proposal_Summary_Slide_Template.pptx | PPTX presentation | |
| Attachment_A_Abstract_Summary_Side_Template.pptx | PPTX presentation | |
| HR001124S0018.pdf | ||
| Attachment_D_Proposal_Instructions_and_Volume_I_Template__Technical_and_Management_.docx | DOCX document | |
| Attachment_F_MS_ExcelTM_DARPA_Standard_Cost_Proposal_Spreadsheet.xlsx | XLSX spreadsheet |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DISTRIBUTION A: Approved for public release - distribution unlimited.
Controlled Unclassified Information Guide
Program: Structures Uniquely Resolved to Guarantee Endurance (SURGE) Program Manager: Andrew Detor, Ph.D.
Program Security Officer: Darrell Shelton
Date: March 6, 2024 Version: 1.0
Andrew Detor Darrell Shelton DSO Program Manager DSO Program Security Officer ii
FOREWORD
1. DESCRIPTION
2. AUTHORITY
3. DISTRIBUTION
GENERAL
1. PURPOSE
2. APPLICABILITY AND SCOPE
3. OFFICE OF PRIMARY RESPONSIBILITY
4. CONTROLLED UNCLASSIFIED INFORMATION (CUI) CHALLENGES
5. OPERATION SECURITY (OPSEC)
6. CUI CATEGORIES
7. EXPORT CONTROL RESTRICTED INFORMATION
8. FREEDOM OF INFORMATION ACT (FOIA) EXEMPT INFORMATION
9. DISCLOSURE OF CUI
10. CUI PROTECTION REQUIREMENTS
11. NOTIFICATION OF UNAUTHORIZED DISCLOSURE
12. INFORMATION PROTECTION GUIDANCE CHARTS
iii
FOREWORD
1. DESCRIPTION
The Defense Sciences Office (DSO) Structures Uniquely Resolved to Guarantee Endurance (SURGE) program aims to unlock the full potential of additive manufacturing (AM) for distributed production of mission-critical hardware anywhere in the world, on any machine, at any time. The program will develop and test transferable model-based part life prediction methods derived from data captured during manufacturing. If successful, SURGE will disrupt today’s legacy approach to part qualification that relies on extensive prior testing for every new part, machine, and material combination.
2. AUTHORITY
CUI elements referenced in this guide are under the authority of DoDI 5200.48, “Controlled Unclassified Information,” March 6, 2020.
3. DISTRIBUTION
Unlimited.
1. PURPOSE
a. The purpose of this CUI guide is to ensure the protection of SURGE information IAW DoDI 5200.48. SURGE information should be controlled and stored consistent with federal requirements and guidance from the National Institute for Standards and Technology (NIST).
Sensitive information does not include information in the public domain.
b. This guide is not for classified national security information as defined in Executive
Order 13526, but identifies specific elements of sensitive information that are unclassified in nature requiring protection. This information is not classified national security information, but it is covered by the legislation at large for the Freedom of Information Act (FOIA) and the exemptions therein.
2. APPLICABILITY AND SCOPE
This guide applies to all DARPA personnel, support contractors, mission partners, and industrial performers who support SURGE. This guide should be cited as the basis for identifying, protecting and marking of information and material designated as a type of controlled unclassified information (CUI) associated with SURGE. As defined at 32 CFR Section 2002.4(h), CUI is information that the government creates or possesses – or that an entity creates or possesses on behalf of the government that law, regulation or government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls. It is to be used in conjunction with related security classification guides and guidance documents associated with the overall effort of SURGE, in compliance with Executive Orders and related DoD guidance. The scope of this guide is based on SURGE as planned at the date of this guide, and may expand or change as strategic decisions are made over the course of SURGE.
3. OFFICE OF PRIMARY RESPONSIBILITY (OPR)
This CUI guide is issued by DARPA. All inquiries concerning content, interpretations, and clarification of this document should be addressed to DARPA at DSO_Security@darpa.mil with any questions.
4. CONTROLLED UNCLASSIFIED INFORMATION (CUI) CHALLENGES
CUI Challenges: Authorized holders of CUI who, in good faith, believe that a designation of information as CUI within this guide is improper or incorrect, or who believe they have received unmarked CUI, should notify DARPA at DSO_Security@darpa.mil. Until the challenge is resolved, the challenged CUI, including challenges to unmarked CUI, will continue to be safeguarded and disseminated at the appropriate control level indicated in the markings or presumed category.
5. OPERATIONS SECURITY (OPSEC)
a. OPSEC is a process that identifies and mitigates adversarial risk to our operations by looking at our operations through the eyes of our adversaries. The application of the OPSEC methodology includes identifying critical information, analyzing threats and vulnerabilities, analyzing, and assessing adversarial risk, and implementing OPSEC measures that reduce this risk.
b. SURGE critical information falls under the following index of CUI :
1) Defense
2) Proprietary Business Information
3) Financial
4) Provisional
6. CUI Categories
a. Defense: Controlled Technical Information (CTI). This category relates to technical information with military or space application that is subject to controls on the access, use, reproduction, modification, performance, display, release, disclosure, or dissemination.
Controlled technical information would meet that criterion, if disseminated, for distribution statements B through F using the criteria set forth in DoD Instruction 5230.24, Distribution Statements on Technical Documents.
b. Proprietary Business Information/General Proprietary Business Information
(PROPIN). Material and information relating to, or associated with, a company's products, business, or activities, including but not limited to financial information; data or statements;
trade secrets; product research and development; existing and future product designs and performance specifications.
c. Financial: Budget (BUDG). Related to information concerning the federal budget, including authorizations and estimates of income and expenditures.
d. Provisional: Operations Security Information. This category relates to unclassified information that could constitute an indicator of U.S. Government intentions, capabilities, operations, activities, or otherwise threaten/compromise operations security.
7. EXPORT CONTROL RESTRICTED INFORMATION
Not Applicable.
8. FREEDOM OF INFORMATION ACT (FOIA) EXEMPT INFORMATION
The Freedom of Information Act (FOIA), 5 U.S.C. § 552, is a federal law that defines agency records subject to public disclosure, outlines mandatory disclosure procedures, and defines nine exemptions that prohibit certain types of information from being released to the public. In addition to the FOIA, the Code of Federal Regulations (October 2016), 45 CFR § 5.31 specifies the type of information that falls under each of the nine exemptions that preclude release of information to the public under the FOIA. In accordance with 5 U.S.C. § 552(a)(8), DARPA will withhold records or information exempt from disclosure under the FOIA whenever disclosure would harm an interest protected by a FOIA exemption or disclosure is prohibited by law. The most relevant exemptions for SURGE are listed below; however other exemptions could apply:
a. Exemption 3 – Protects information exempted from release by statute.
b. Exemption 4 – Protects trade secrets and commercial or financial information which could harm the competitive posture or business interests of a company.
c. Exemption 5 – Protects the integrity of the deliberative or policy-making processes within the agency by exempting from mandatory disclosure opinion, conclusions, and recommendations included within inter-agency or intra-agency memoranda or letters.
9. DISCLOSURE OF CUI
a. Public Disclosure. Information from this CUI guide does not allow automatic public release of this information. DoD information requested by the media or members of the public or proposed for release to the public by DoD civilians or military personnel or their contractors will be processed in accordance with DARPA Instruction 65 and DoD Instructions 5230.09, 5230.29; Volume 3 of DoD Manual 5200.01; and DoD Manual 5400.07, as applicable. Proposed public disclosures of unclassified information shall be submitted using the public release form located at https://www.darpa.mil/work-with-us/contract-management/public-release.
b. Freedom of Information Act (FOIA) Requests. All personnel with knowledge of this Project must coordinate with the DARPA PSO prior to providing a response to requests for information under the provisions of the FOIA.
c. Proprietary Information (PROPIN). Additional safeguards may become necessary if a contract requires the transfer of PROPIN. The holder of the information must clearly identify any and all PROPIN prior to its disclosure and release, the release will be coordinated with the PROPIN owner.
d. Foreign Disclosure. Disclosure of DARPA CUI to foreign nationals will be coordinated with the PSO, International Security, and International Cooperation. Disclosure approval must be granted by the Director, SID, who is the Foreign Disclosure Officer for
DARPA.
10. CUI PROTECTION REQUIREMENTS
a. SURGE CUI (e.g., confidential business information, personally identifiable information, proprietary business information, unclassified controlled technical information) regardless of media or format, will be protected from disclosure to unauthorized persons or groups, by properly storing in locked offices, cabinets, and drawers in accordance with DoDI 5200.48.
b. CUI may only be processed on DIB systems that are compliant with DFARS 252.204- 7012 requirements as detailed in NIST 800-171.
11. NOTIFICATION OF UNAUTHORIZED DISCLOSURE
a. Personnel must immediately report all unauthorized disclosures or suspected and known security incidents, privacy breaches, and suspicious activities involving CUI to the SURGE PSO and PSR at DSO_Security@darpa.mil.
b. Data breaches of DIB networks and systems involving SURGE CUI material must be reported IAW DFARS 252.204-7012 requirements. In addition, all breaches must be reported to the DARPA Project contracting officer and program security officer (PSO) upon discovery.
12. INFORMATION PROTECTION GUIDANCE CHARTS
These charts are provided to assist in identifying what types of information associated with the SURGE effort may be sensitive, provide guidance on the relevant markings for this information to control dissemination, and provide guidance on when these dissemination controls no longer apply. If at any time there are questions regarding which category of information something falls under, or what dissemination controls apply, individuals should request guidance from DARPA at DSO_Security@darpa.mil.
Element of Information Index Category Reason LDC or Distribution Statement
Remarks
Budget (overall DARPA program budget)
Financial Budget FAR 2.101 and 3.104
Federal employees Only
(FED ONLY)
FOIA Exemption 5 may be applicable.
In-situ manufacturing sensing architectures, process models, and part life prediction methods developed on SURGE when applied to generic test coupons or components
N/A Unclassified N/A NONE Components will have no direct military, mission specific development nor prototypes which will have fielded or simulated environmental test and/or demonstrations.
Any model prediction or calculation predicting part life/failure and microstructure defects when applied to generic test coupons or components
N/A Unclassified N/A NONE Components will have no direct military, mission specific development nor prototypes which will have fielded or simulated environmental test and/or demonstrations.
Quantitative SURGE metrics when applied to a specific military application
Defense Controlled Technical Information (CTI)
DFARS
252.204.7012
DISTRO C FOIA Exemption 3 may be applicable.
and DoDI 5230.24
In-situ manufacturing sensing architectures, process models, and part life prediction methods developed on SURGE when applied to a specific military application
Defense Controlled Technical Information (CTI)
DFARS
252.204.7012 and DoDI 5230.24
DISTRO C FOIA Exemption 3 may be applicable.
Any computer model which utilizes data deemed CUI by SURGE or another organization
Defense Controlled Technical Information
DFARS
252.204.7012 and DoDI 5230.24
DISTRO C FOIA Exemption 3 may be applicable.
Any model prediction or calculation predicting part life/failure and microstructure defects when applied to a specific military application.
Defense Controlled Technical Information
DFARS
252.204.7012 and DoDI 5230.24
DISTRO C FOIA Exemption 3 may be applicable.
SURGE methods and/or manufacturing techniques protected by the company as proprietary
Proprietary Business Information
General Proprietary Business Information
(PROPIN)
18 USC 1905
29 USC 664
Dissemination List Controlled
(DL ONLY)
FOIA Exemption 4 may be applicable.
| 2024-03-07T07:00:14-0500 | |
| DETOR.ANDREW.JOSEPH.1016980354 |
| 2024-03-07T08:20:31-0500 | |
| SHELTON.DARRELL.E.1060572352 |
File details come from the government source that posted it. Updated .