Continuation Sheet DD254.pdf

PDF 205 KB Posted

Attached to
HARM Engineering Services Federal contract opportunity
Solicitation number
FA8520-23-R0004
Issued by
Department of the Air Force Materiel Command Lifecycle Management Center Robins Air Force Base

View the file

Other files for this federal contract opportunity

Other files attached to HARM Engineering Services, newest first.
File Type Posted
Question-Answer.pdf PDF
HARM Evaluation Spreadsheet - 13 Jun 2023.xlsx XLSX spreadsheet
FA8520-23-R-0004-0001.pdf PDF
Solicitation - FA852023R0004 - Questions with Answers.pdf PDF
DD-Form-254.pdf PDF
FA8520-23-R-0004.pdf PDF
FD2060-23-30022 CDRL_A001.pdf PDF
FD2060-23-30022 CDRL_A004.pdf PDF
FD2060-23-30022 CDRL_A003.pdf PDF
FD2060-23-30022 CDRL_A002.pdf PDF
PWS.pdf PDF
Show all 11

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

CUI

CUI 1

PR/Solicitation #: FD2060-23-30022

INTELLIGENCE SECURITY ADDENDUM (SCI)

RETURN THIS DOCUMENT TO SSO ROBINS PRIOR TO AWARD SO THAT WE MAY UPDATE FINALIZED

DATA

Ref ltem 10c(1)/(2):

1. Contractor will require access to Special Compartmented Information (SCI). The following provide the necessary guidance for physical, personnel, industrial, information and Information system security measures and is part of the Sensitive Compartmented Information (SCJ) security specification for the contract AFPD 14-3, AFI 14-302, AFMAN 14-304, DoDM 5105.21 Vl-3, DoD 5220.22-M, AFMAN 14-304, lCDs 503, 701, 704, 705, JDCSISSS, and DIAM 50- 4. See Item 13 Release of Intelligence Information to US Contractors for additional security requirements. Prior approval of the contracting activity is required for subcontracting. Access to intelligence information requires special briefings and a US Government clearance at the appropriate level.

2. The contractor must have SCI indoctrinated personnel available to work the contract, and the designated government contract monitor (CM) or Contracting Officer Representative (COR) must also be assigned an SCI position. Names of contractor personal requiring access to SCI and justification for SCI positions will be submitted for coordination and action to SSO Robins -AFLCMC/INGS after the final contract monitor approval/concurrence. All DD Forms 254 prepared for subcontracts involving access 10 SCI under this contract must be submitted to CM and Robins SSO for review, approval, and concurrence, prior to granting SCI access. The Contractor Special Security Officer (CSSO) may submit the necessary forms to Defense Security Service (DSS) for a Single Scope Background Investigation (SSBI) for those personnel nominated for SCI access in accordance with the National Industrial Security Program Operating Manual (NlSPOM).

3. A SCI Facility (SCIF) meeting the physical security requirements outlined in ICD 705 must be used for contract work or established and maintained at the contractor location. All SCI used for this contract shall be stored, handled, and maintained in a SCIF, be it the local contractor SCIF or similarly SCI-accredited facilities used by the contractor. Unescorted access to SCIFs and local transmission/handling (courier) authorizations will be approved at the discretion of the local SSO/SIO. The SCIFs used for contract execution are listed in a separate memorandum and/or database maintained by the FSO/CSSO and will be furnished to the SSO upon request.

4. For contract work within a contractor established SCIF, information systems (computers), electronic connectivity, and similar electronic methods or storing and communicating within and outside the SCIF must be in compliance with ICD 703, DIAM 50-4, the JDCSISSS, and any additional instructions issued by DIA/DAC-2A, HQ AFMC/A2S and AFLCMC/INGS.

Ref item 10k: SCl positions requested under this contract will be processed upon SSO Robins receipt of the signed DD Form 254 and submittal of the initial personnel access request letters.

Ref Item 12: Public release of intelligence information is not authorized.

CUI 2

PR/Solicitation #: FD2060-23-30022

Contract Monitor (CM) POC Information

Name Erik Lomas Org/Office Symbol AFLCMC/EBWEM Address 320 Richard Ray Blvd

Robins AFB, GA 31098-1820 Comm/DSN Phone # 478-222-8258 E-mail address Erik.lomas@us.af.mil

1. Authority: SSO Robins - AFLCMC/INGS is the Senior Intelligence Officer (SIO) designated representative for all contracts issued by Robins AFB, GA, requiring access to intelligence information.

The SSO, or originator of the material, is authorized to approve the release of intelligence information to US contractors. No Government official shall authorize contractor use of intelligence materials or release to subcontractors without expressed authority from the SSO or the originator. Intelligence Information will not be released to contractor employees without the specific release approval by the SSO or originator of the material as outlined in the governing directives and based on prior approval and certification of "need-to-know" by the Contracting Officer's Representative (COR). A listing of all CORs is listed in a separate memorandum and/or database maintained at by the FSO/CSSO or Program Office and will be furnished to the SSO upon request.

2. Release of Intelligence Information to US Contractors: Specific procedures for release of intelligence information are outlined in AFMAN 14-304 (as supplemented by AFMC). All intelligence released must be under the US Government representative's control and supervision. The US Government representative must access each document prior to contractor review lo confirm the classification of each document. All information, to include access of Electronic Intelligence Databases/Networks, released to the contractor must be used, solely, to fulfill or be in accordance with contractual obligations and DD Form 254 requirements.

3. Estimated Contract Completion/Expiration: 3 Aug 2028: Upon completion, expiration, or cancellation of the contract, the individuals briefed for SCI on this contract will be debriefed or transferred and the SCI contract positions will be disestablished. Any contract modifications extending the completion/expiration date will be submitted to the SSO, to ensure continuation of SCI access positions.

4. Training: At locations where the contractor is deemed a "long term" or "integrated" visitor group, the contractor shall participate in that location's security awareness and education program as administered by the Servicing Security Activity (SSA) and/or location's Special Security Office (SSO) IAW AFI 16-1404, and AFI 16-1406. At all other locations. the CSSO/FSO will administer and document completion of this training. Documentation must include the date of training, subjects covered, and names of attendees and non-attendees. This documentation must be furnished to the SSO upon request. IAW AFMAN 14- 304, para 12.3., SCI Security Awareness training must be accomplished on a quarterly basis.

Ref Item 15:

1. SSO Robins has exclusive security responsibility for all SCI material released to or developed under this contract and held within the contractor's SCIF. DSS is relieved of security inspection responsibility

CUI 3

for all such material but retains responsibility for all non-SCI classified material released to or developed under this contract and held within the contractor's SCIF.

2. The accrediting activity, or their representatives, shall be responsible for reviewing all of the contractor's SCIF documentation to ensure compliance with SCI directives or regulations. In addition, if the contractor has established a SCIF, the accrediting activity and its designees are responsible for all inspections of the contractor SCIF and SCI security management program for ensuring compliance with all SCI security regulations and policies.

Ref Item 17f: See Ref item 10k.

SSO ROBINS-AFLCMC/INGS, 235 Byron St, Suite 19A, Robins AFB, GA 31098-1670; robins.sso@us.af.mil mailto:robins.sso@us.af.mil

CUI 4

Special Access Program Continuation Sheet to DD Form 254

Contract #_____________

PR/Solicitation #: FD2060-23-30022

BLOCK 8a:

(CUI) Contractor performance location is identified under separate cover

BLOCK 10a:

(CUI) The contractor is governed by NSA/CSS Policy Manual 3-16, dated August 2005, in the control and protection of COMSEC Material/Information. Access to COMSEC material by personnel is restricted to U.S. citizens holding a final U.S. Government clearance. Such information is not releasable to personnel holding only reciprocal clearances.

BLOCK 10.e.1/10.e.2:

Contractor will require access to and comply with AFI 14-303 and AFMC Supplement 1. Release of intelligence information does not create and unfair competitive advantage for the contractor nor a conflict of interest with the contractor's obligation to protect the information.

BLOCK 10f:

(CUI) AFOSI PJ OL is the cognizant security office for all SAPs related to this contract (AFOSI PJ Detachment 3 OL-A, Marietta, GA, (frank.jolly@us.af.mil).

BLOCK 10g:

(CUI) NATO briefing required prior to granting access. See NISPOM Chapter 10 for details.

BLOCK 10h:

The contractor is permitted access to Foreign Government information, except North Atlantic Treaty Organization (NATO) information, in the performance of this contract. Access to Foreign Government information requires a final U.S. Government clearance at the appropriate level. Prior approval of the contracting activity is required for subcontracting.

BLOCK 10j:

(CUI) FOR OFFICIAL USE ONLY information provided under this contract shall be safeguarded as specified in DoDM 5200.01-V4, DoD Information Security Program: Controlled Unclassified Information (CUI), Enclosures 3 & 4 and DoD 5400.7-R; Air Force manual 33-302, DoD Freedom of information Act (FOIA) Program for requirements.

BLOCK 10k:

(CUI) The Contractor must have SAP indoctrinated personnel available to work the contract, and the designated Government contract monitor (CM) or Contacting Officer Representative (COR) must also be assigned a SAP position. Names of contractor personal requiring access to SAP and justification for SAP positions will be submitted for coordination and action to AFLCMC/EBGS after the final contract monitor mailto:frank.jolly@us.af.mil

CUI 5

approval/concurrence. All DD Forms 254 prepared for subcontracts involving access to SAP under this contract must be submitted to CM and Program Security (AFOSI PJ Detachment 3 OL-A, Marietta, GA, frank.jolly@us.af.mil for review, approval, and concurrence, prior to granting SAP access.

BLOCK 11.a:

(CUI) Contractor performance is restricted to locations identified on SAP addendum.

BLOCK 11.f:

(CUI) Overseas contractor performance will occur as an intermittent visitor at locations identified on classified addendum.

BLOCK 11.j:

(CUI) Operations Security (OPSEC) Requirements and Outside Work Requests (OWR).

1. (CUI) To protect SAP Critical Program Information (CPI), the OPSEC process will be applied to all program activities. To ensure the dedicated application of the OPSEC process enumerated in the NISPOM and Security Classification Guides. The Contractor must obtain PSO approval prior to any work performed (classified or unclassified) by contractors, subcontractors, vendors, and/or suppliers.

Furthermore, program activity (ies) involving major/critical activities, (as determined by the SPO and PSO), such as subcontracting, sub-clement or component acquisition or fabrication/manufacture, major sub-element or component testing, system testing, demonstrations, etc., which are to occur outside of Special Access Program Facilities (SAPFs), must be approved by the PSO and coordinated with (Government) Program Manager prior to commencement. The OPSEC process will be applied to them through the use of an Outside Work Request (OWR).

2. (CUI) Prior to preforming major/critical work or minor/critical activities outside of SAPFs, an OWR must be submitted for PSO approval, no less than 30 days prior to the activity. An OWR must be submitted even if the work is considered unclassified or SECRET/ /COLLATERAL. At a minimum the request must contain the following:

(U) Subcontractor/Supplier/Vendor Information (SAP Form 13)

(U) A task summary stating the objective of the effort... what will the vender supply or test?

(U) The OPSEC strategy/enhanced OPSEC approach to be utilized, if required

(U) Justification for the non-SAR activity

(U) State how the subcontract will be established to prevent a link to the SAP, the SAR Prime

Contract Number, and/or Government relationship

(U) Identity of any program-briefed individuals (at the vendor) in the request activity

(U) Attachment of any information to be provided to the Vendor/Supplier and the form in which it will be provided, ie., hardcopy drawing(s), CD(s), etc.

BLOCK 12:

CUI 6

(CUI) PUBLIC RELEASE IS NOT AUTHORIZED. Release of any Special Access Required

(SAR) program information, material, or data outside of approved program channels or pass to persons not accessed and briefed to the Special Access Programs (SAPs) is prohibited. The designation UNCLASSIFIED does not permit automatic public release. This prohibition also applies to any unclassified material marked HVSACO. Proposed public disclosures of unclassified information regarding the SAP will be submitted to the Government Program Manager (PM) and Air Force Office of Special Investigations (AFOSl) Office of Special Projects (PJ) Program Security Officer (PSO) for review a minimum of 60 days before date needed.

BLOCK 13:

1. (CUI) Contractor will be provided security classification guides under separate cover as necessary.

2. (CUI) This effort also requires access to Air Forces SAPs under the cognizance of SAF/AQ and the AFOSI Office of Special Projects (PJ) Security Directorate. Classification management decisions will be made based on the respective SCGs (see SAP addendum). All classified SCGs will be provided under separate cover. The "United States Air Force Security Markings Guide for Special Access Programs”, dated 1 July 2011, Revision 1, dated 16 October 2013 will serve as the guide for the use by SAP accessed individuals under this contract in implementing security marking requirements contained in applicable U.S. Codes, Executive Orders (EOs), Department of Defense Directives and SAP Security Classification Guides (SCGs).

3. (CUI) The National Industrial Security Program Operating Manual (NISPOM) is the authoritative manual concerning baseline standards for the protection of classified information in connection with classified contract and activities under the Nation Industrial Security Program. Air Force Instruction 16- 701, Management, Administration and Oversight of Special Access Programs, dated 18 February 2014, (and subsequent revisions), establishes responsibilities for the management, administration, and oversight of SAPs for which the Air Force has cognizant authority (CA) and applies to the contract as stated in the SAF/AA Implementing Memorandum, dated 24 July 2008. DoDM 5205.07Vl dated 18 Jun 2015, DoD Special Access Program (SAP) Security Manual: General Procedures, is the authoritative SAP security manual. DoDM 5205.07V3, Special Access Program Security Manual: Physical Security, dated 31 Dec 2015 will serve as the baseline foe physical security of SAP facilities. The SAF/AA Memorandum, "Special Access Programs Nomination Process”, dated 30 September, 2013 and USD (l) Memorandum, "Special Access Programs Nomination Process”, dated 20 May 2013, will be utilized for all Program Access Request (PARs). The DoD manual 5205.07 Volume 4 dated 10 October 2013, "Special Access Programs (SAP) Security Manual: Marking”, SAF/AAZ Implementation Memorandum date 7 November 2013, and "United States Air Force Security Markings Guide for Special Access Programs”, dated 1 July 2011, Revision 1, dated 16 October 2013, will serve as the marking guide(s) for all SAP Material generated under this contract, as well as any subsequent revisions to the above publications.

4. (CUI) In accordance with DoD SAPCO Memorandum, Transition to the Risk Management Framework, dated December 8, 2013, certification and authorization of any information systems after January 1, 2014, must be accomplished utilizing the Risk Management Framework (RMF) and the Joint Special Access Program Implementation Guide (JSIG) Rev 4, dated 11 Apr 2016. Currently accredited systems will operate in accordance with JAFN 6/3, "Protecting Special Access Program Information within Information Systems”, dated 15 October 2004, and the JAFAN 6/3 Implementation Guide Version 1, CUI 7

September 2006. All existing information systems certified under JAFAN 6/3 will be reassessed for re-authorization utilizing the JSIG when possible, but not later than three years from the date of the memorandum. In order to be compliant with the 9 Oct 2013 JSIG memo, procedures outlined in the 24 Oct 2014 SAF/AAZ policy memorandum, media Control and Assured File Transfer (AFT) within Special Access Program Facilities (SAPF) with attachments, is mandatory. Contact the Information System Security Manager (ISSM)/Information System Security Officer (ISSO) to obtain a copy of the JSIG and related documentation/templates. as well as the Media control and AFT within SAPFs.

5. (CUI) The Contractor will keep a current list showing the location of containers, rooms, and completely dedicated buildings mat contain "Special Access Required" material carved out from DSS cognizance. This listing shall also include all subcontractors (for services and supplies) that require DD Forms 254. The Contractor will provide a copy of the list to AFOSI PJ.

6. (CUI) Program Access Request (PARs) will be submitted to the Air Force Life Cycle Management Center AFLCMC/EBGS, Robins AFB GA, via secure fax: (478) 926-5510. Notify AFOSI PJ PSO of a briefing/ debriefing within 24 hours. The Contractor will provide AFLCMC/EBGS a program access roster semiannually containing the following information: name of individual, biller (if applicable), level of access, social security number, and security clearance information.

7. (CUI) Specific TEMPEST (EMSEC) countermeasures will be implemented when a specific threat is identified in an area where classified processing is being conducted. At a minimum, all computer equipment and peripherals must be installed in accordance with National Security Telecommunications Information Systems Security Advisory Memorandum (NSTISSAM) TEMPEST/2-95 RED/BLACK separation criteria.

8. (CUI) All SAP work will be performed within approved SAP facilities (SAPF) designated by the local Government SAP Security Officer (GSSO).

9. (CUI) Request for SAP access will be made through the local GSSO or Program Manager (PM).

10. (CUI) Continued Contractor access to SAPs requires initial and recurring (annual) SAP security education training. The training will be conducted at the location where the Contractor's program access records are kept.

11. (CUI) Inquiries regarding SAP classification guidance will be directed to the PSO, GSSO or PM. Any SAP-derived material generated under this contract will be reviewed by the PSO, GSSO or PM for proper classification prior to final publication, distribution, or transmission.

12. (CUI) SAP i11formntion furnished or generated in support of this contract remains the property of Government and will be returned to the servicing program office upon completion of this contract.

13. (CUI) All procedures, equipment, and devices used for data processing or data transfer of SAP information must be accredited (approved) by the respective Authorizing Official (AO) before any processing is permitted. Any subsequent configuration or procedural changes must also be approved prior to use.

CUI 8

14. (CUI) The Contractor will produce classified material and have access to classified data/areas listed in block 13 only. The GSSO will provide daily security oversight of this contact unless delegated in writing by the PSO to another activity.

15. (CUI) Security requirement for SAP access is a final TOP SECRET clearance based on a T5 investigation within the last five (5) years.

16. (CUI) The government will provide adequate classified storage capability. Only proper accessed (program briefed) personnel will have access to security containers and classified media containing SAP information.

BLOCK 14:

(CUI) The following guidance, as well as any subsequent revision to them must be followed:

Air Force SAP Governing Documents

• AFI 16-701, “Management, Administration, and Oversight of Special Access Programs”, 18 February 2014

DoD SAP Governing Documents

• DoDM 5205.07Vl, DoD Special Access Program Security Manual: General Procedures, dated 18 June 2015

• DoDM 5205.07V2, DoD Special Access Program Security Manual: Personal Security, dated 24 November 2015

• DoDM O-5205.07V3-AFMAN 16-703V3 Special Access Program Security Manual:

Physical Security, dated 31 December 2015

• DoD 5205.07 v4, "Special Access Program Security Manual; Marking”, 10 October 2013 w/ attached “United States Air Force Security Marking Guide for Special Access Program”, dated 1 July 2011, Revision 1, dated 16 October 2013

• DoD 5200.01 v4, "DoD Information Security Program Controlled Unclassified Information (CUI)”, dated 24 February 2012

Miscellaneous Governing Document/Memos

• SAF/AA Memorandum, “Special Access Programs Notification Process”, dated 30 September

• USD (I) Memorandum, "Special Access Programs Nomination Process”, dated May 2013

• DoD SAPCO Memorandum, "Transition to Risk Management Framework”, dated December 18,

• DoD, Chief Information Officer Memorandum, dated 12 July 2013, and "Insider Treat Mitigation” with attachments

Governing Documents for Information System Authorization if Applicable

• DoD 8510.01, "Risk Management Framework (RMF) for DoD information Technology (IT)”, dated 12 Mar 2014

• JSIG, Joint Special Access Program Implementation Guide, Rev 4, dated 11 Apr 2016

CUI 9

o Provides policy and guidance of the transition to and application of the RMF

• CNSSI 1253 Rev 3, Security Categorization and Control Selection for Nation Security Systems, 27 Mar 14 o Instructions for applying RMF to National Security Systems

• NIST Special Publication (SP) Joint Task Force (JTF) Initiative o NIST SP 800-53, Rev 3, Recommended Security Controls for Federal Information

Systems and Organizations, dated April 2013 o NIST SP 800-53A, Guide for Assessing the security Controls in Federal Information

Systems and Organizations, Building Effective Security Assessment Plans, dated June o NIST SP 800-37, Guide for Applying the Risk Management Framework to Federal Information Systems, dated February 2010 o NIST SP 800-39, Managing Information Security Risk: Organizations, Mission, and Information System Views, March 2011 o NIST SP 800.30, Guide for Conduction Risk Assessments, September 2012

BLOCK 15:

1. (CUI) The AFOSI PJ Director has been designated as the Cognizant Security Agent for this contract. The Defense Security Service (DSS) has been carved out from security cognizance, to include program inspections, reporting and administrative requirements. AFOSI PJ Det 3 OL-A, or designated representative, will conduct security reviews of all SAP facilities, material and operation related to this contract.

2. (CUI) AFLCMC/EBG has exclusive security responsibility for all SAP material released to or developed under this contract and held within the SAPF. DSS is relieved of security inspection responsibility for all such material but retains responsibility for all non-SAP classified material released to or developed under this contract and held within the Contractor's SAPF.

3. (CUI) SAP security compliance inspections and annual self-inspections will be conducted in accordance with DoDM 5205.07-V-1, dated 18 Jun 2015, Enclosure 9. Annual self-inspections will be submitted to the PSO within 30 days following completion of the inspection. The PSO will be notified immediately if the self-inspection discloses the loss, compromise, or suspected compromise of classified material. Self-inspection reports will be retained for two (2) years following the formal Government CSA inspection. All outstanding items must be completed prior to the destruction of the self-inspection.

4. (CUI) The accrediting activity, or their representatives, shall be responsible for reviewing all of the Contractor’s SAPF documentation to ensure compliance with SAP directness or regulations.

5. (CUI) Authority. AFOSI PJ Detachment 3 OL-A is the Program Security Officer (PSO) designated representatives for all contracts issued by Robins AFB, GA, requiring access to SAP information. The PSO, or originator of the material, is authorized to approve the release of SAP information to US contractors.

AFLCMC/EBG has exclusive security responsibility for all SAP material released to or developed under this contract and held within a SAPF. No other Government official shall authorize contractor use of SAP materials or release to subcontractors without expressed authority from the PSO or the originator. SAP information will not be released to contractor employees without the specific release approval of the PSO or originator of the material as outlined in the governing directives and based on prior approval and

CUI 10

certification of "need-to-know" by the Contacting Officer's Representative (COR). A listing of all CORs is listed in separate memorandum and/or database maintained at by the FSC/CSSO or Program Office and will be furnished to the PSO upon request.

6. (CUI) Release of SAP Information to US Contractors: Specific procedures for release of SAP information are outlined in DoD 5205.07 V1.. All SAP released must be under the US Government representative's control and supervision. The US Government representative must access each document prior to the Contactor review to confirm the classification of each document. All information released to the Contactor must be used, solely, to fulfill or be in accordance with contractual obligations and DD Form 254.

7. (CUI) Estimated Contract Completion/Expiration: 3 August 2028 (this includes all outyear options):

Upon completion, expiration, or cancellation of the contract, the individuals briefed for SAP on this contract will be debriefed or transferred and the SAP contract positions will be disestablished. Any contract modifications extending the completion/expiration date will be submitted to the PSO, to ensure continuation of SAP access positions.

8. (CUI) Training; At locations where the Contractor is deemed a "long term" or "integrated" visitor group, the Contractor shall participate in the location's security awareness and education program as administered by the Government SAP Security Officer (GSSO) DoDM 5205.07V1 encl 7. At all other locations, the CPSO/FSO will administer and document completion of this training. Documentation must be accomplished via a SAP Form 17 and include subjects covered and the date of training. This documentation must be furnished to the PSO upon request IAW DoDM 5205.07V1 encl 5. SAP Security Awareness Refresher training must be accomplished on an annual basis.

Contract Monitor (CM) POC Information

Name: Erik Lomas Org/Office Symbol: AFLCMC/EBW Address: 320 Richard Ray Blvd Robins AFB, GA 31098-1640 Comm./DSN Phone #: 478-222-8258 Email Address: Erik.Lomas@us.af.mil

Block 17f:

AFLCMC/EBGS

425 Eastman Street

Robins AFB, GA 31098

Attn: Michael Gaskins/Samuel Dixon

See Ref Item 10k - AFOSI PJ Detachment 3 OL-A, Marietta, GA, frank.jolly@us.af.mil

File details come from the government source that posted it. Updated .