B08 ATTACHMENT 0002 OPSEC SOW.pdf
PDF 67 KB Posted
- Attached to
- Ignition Cartridges - M702/M299/M752A1/M1020 Federal contract opportunity
- Solicitation number
- W519TC-23-R-0077
About this file
This document is a Statement of Work (SOW) that outlines the Operations Security (OPSEC) requirements for a federal contract.
The SOW states that the contractor shall not release sensitive information to the public without prior written approval from the Contracting Officer. Contractor employees who are U.S. citizens will be provided access to sensitive information on a "need to know" basis, while foreign national employees' access will be limited to non-sensitive information. The contractor shall be responsible for establishing and maintaining an OPSEC program to manage, protect, and control sensitive information. The contractor shall prepare and submit an OPSEC Plan within 30 days of receiving critical information, which will be reviewed and approved by the Government OPSEC officer. The contractor shall conduct annual self-assessments of their OPSEC program and provide OPSEC training to all employees. All sensitive program material shall be destroyed upon contract completion, and these requirements will flow down to all subcontractors.
View the file
Other files for this federal contract opportunity
Show all 22
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
STATEMENT OF WORK: OPERATIONS SECURITY (OPSEC) REQUIREMENTS
(a) As defined in Army Regulation (AR) 530-1, Operations Security (OPSEC), sensitive information is information requiring special protection from disclosure that could cause compromise or threat to our national security, an Army organization, activity, family member, DA civilian or DoD contractor.
Critical Information is defined as information important to the successful achievement of U.S. objectives and missions, or which may be of use to an adversary of the United States. It consists of specific facts about friendly capabilities, activities, limitations (includes vulnerabilities), and intentions needed by adversaries for them to plan and act effectively so as to degrade friendly mission accomplishment. All critical information is sensitive, but not all sensitive information is critical.
(b) The Contractor shall not release sensitive information to the general public without prior written approval from the Contracting Officer. All contractor requests to release sensitive information shall be in writing and clearly explain the necessity for release of the information and consequences if approval is not granted. Contractor employees who are U.S.
citizens shall be provided access to sensitive information on a "need to know" basis required to fulfill the terms and conditions of the contract. Foreign National (FN) employees’ access to information will be limited to non-sensitive information. FN access to sensitive information will be approved in writing by the Contracting Officer on a case-by-case basis, and will be strictly limited to the information that the employee must know in order to fulfill the terms and conditions of the contract.
(c) The Contracting Officer will provide the Contractor with a list of known Critical Information (CI) pertinent to contract requirements as soon as possible after contract award. Critical Information shall be used by the Contractor’s appointed OPSEC Manager to prepare an OPSEC Plan.
(d) The Contractor shall be responsible for establishing and maintaining an OPSEC program to adequately manage, protect and control sensitive information that has been provided or generated under the contract. The Contractor shall prepare and submit a written OPSEC Plan to the Contracting Officer for approval IAW DD 1423/DI-MGMT-80934C within 30 calendar days after receipt of the CI information addressed in Paragraph 3 above., to be reviewed and approved by the responsible
Government OPSEC officer. The contractor shall implement OPSEC measures as ordered by the Government. In addition, the contractor shall have an identified certified Level II OPSEC coordinator per AR 530-1. This plan will include a process to identify critical information, where it is located, who is responsible for it, how to protect it and why it needs to be protected. The contractor shall implement OPSEC measures as ordered by the commander. In addition, the contractor shall have an identified certified Level II OPSEC officer / coordinator per AR 530-1. The Contracting Officer will coordinate with the Government OPSEC Officer and advise the Contractor in writing of the approval, conditional approval or disapproval of the plan within 20 days of receipt.
(e) The Contractor shall conduct annual self-assessments of their OPSEC program and submit annual written assessments to the Contracting Officer in the anniversary month of contract award.
OPSEC Assessment checklists and sample assessment responses will be provided in advance by the Government as tools to aid the Contractor in assessing their OPSEC program.
(f) The Contractor’s Level II certified OPSEC Officer / coordinator shall provide OPSEC training to all employees regarding the safeguarding of sensitive information prior to employees being allowed access to such information, and annually thereafter.
(g) The Contractor shall destroy all sensitive program material at the completion of the contract so as to ensure the information cannot be accessed or utilized for any purpose and notify the Contracting Officer in writing of its destruction.
(h) These same requirements will flow down to all subcontractors working on or provided any sensitive information related to the contract.
File details come from the government source that posted it. Updated .