DD 254.pdf

PDF 1 MB Posted

Attached to
WCMD Engineering Services and Flight Support Federal contract opportunity
Solicitation number
FA821324RB007
Issued by
Department of the Air Force Materiel Command Lifecycle Management Center Hill Air Force Base

About this file

This document is a Performance Work Statement (PWS) for an Indefinite Delivery Indefinite Quantity (IDIQ) contract to provide engineering services support for the Wind Corrected Munitions Dispenser (WCMD) system. The contractor will be required to support WCMD flight testing, software and engineering services, aging and surveillance activities, and provide various technical reports. Key requirements include WCMD telemetry kit procurement and installation, flight test data analysis, aircraft integration maintenance, mission planning support, simulator maintenance, and surveillance teardown and testing of CBU-87 and CBU-89 munitions. The contract has a 5-year ordering period beginning in September 2022 and is a sole source award to Smart Munitions Expert Solutions. The contracting agency is the Air Force Life Cycle Management Center at Hill Air Force Base.

View the file

Other files for this federal contract opportunity

Other files attached to WCMD Engineering Services and Flight Support, newest first.
File Type Posted
Solicitation - FA821324RB007.pdf PDF
FY24 CDRLs WCMD Engineering Service.pdf PDF
FY24 PWS WCMD Engineering Service Rev3.docx DOCX document
FY24 QASP WCMD Engineering Service.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Please wait...

If this message is not eventually replaced by the proper contents of the document, your PDF viewer may not be able to display this type of document.

You can upgrade to the latest version of Adobe Reader for Windows®, Mac, or Linux® by visiting http://www.adobe.com/go/reader_download.

For more assistance with Adobe Reader visit http://www.adobe.com/go/acrreader.

Windows is either a registered trademark or a trademark of Microsoft Corporation in the United States and/or other countries. Mac is a trademark of Apple Inc., registered in the United States and other countries. Linux is the registered trademark of Linus Torvalds in the U.S. and other countries.

WCMD ENGINEERING SUPPORT

Performance Work Statement

For

Cluster Bomb Unit (CBU) Wind Corrected Munition Dispenser (WCMD) Engineering Support

IDIQ

FD2020-24-50079

20 Feb 2024

Prepared By: Dewey Hayes Area Attack Program Manager AFLCMC/EBHCA

Table of Contents

1.0DESCRIPTION OF SERVICES3
2.0WCMD FLIGHT TESTING SUPPORT3
3.0SOFTWARE & ENGINEERING SERVICES SUPPORT4
4.0AGING AND SURVEILLANCE SUPPORT5
5.0REPORTS6
6.0GOVERNMENT-FURNISHED PROPERTY (GFP)6
7.0GENERAL INFORMATION6
8.0SECURITY REQUIREMENTS7
10.0GOVERNMENT OBSERVATIONS AND PARTICIPATION9
11.0CONTRACT DATA REQUIREMENTS LIST – (CDRL’s)10
12.0CONTRACTOR MANPOWER REPORTING10

1.0 DESCRIPTION OF SERVICES

1.1 Scope: The purpose of this contract is for engineering services support on Wind Correction Munitions Dispenser (WCMD) systems and associated munition systems components necessary to support Weapon System Evaluation Program (WSEP), Aging & Surveillance flight testing, and munition component testing/analysis that are key to determine inventory health and warfighter readiness. The software and engineering services supports WCMD systems test and overall aircraft WCMD interface, including mission planning, Operational Flight Program (OFP) and System Integration Lab (SIL) requirements. The contractor shall provide technical and engineering support for aircraft integration, maintain WCMD ICD's, support ground/flight testing, system component testing, and software/hardware support for platforms that fly WCMD systems.

2.0 WCMD FLIGHT TESTING SUPPORT

2.1 The contractor shall support WCMD flight testing at different test locations to include but not limited to Hill AFB Utah Test and Training Range (UTTR), Eglin AFB, FL Test and Training Range, and Tyndall AFB, FL.

2.2 The contractor shall be required to install the telemetry kits and validate functionality with Government owned Lumistar and CMBRE equipment for the flight tests. Telemetry installations are accomplished the week prior to flights. Telemetry installations and functional validation may be accomplished at an alternative aircraft location other than Hill AFB, Eglin AFB, or Tyndall AFB for each flight test based on airframe departure location.

2.3 The contractor shall procure WCMD Telemetry Kits to support WSEP, aircraft integration and surveillance flight testing requirements - including facilitation and logistics for inventory control, storage, shipping and handling. The contractor shall analyze WCMD telemetry parts obsolesce or design concerns for continuous production capability.

2.4 The contractor shall provide on-site technical support in the Mission Control Center (MCC) for telemetry data collection in support of captive integration, and free flight missions.

2.5 The contractor shall provide engineering analysis of flight test data and anomalies utilizing engineers with specific experience in accordance with systems as defined in section 1.0 analyzing WCMD tail performance and WCMD telemetry data and Lumistar equipment. The contractor shall provide analysis of BLU-108 performance for WSEP and Surveillance testing. The Contractor shall provide a flight test report. (CDRL A001: DI-MISC- 80508B, Technical Report Services)

3.0 SOFTWARE & ENGINEERING SERVICES SUPPORT

3.1.1 Aircraft Integration: The contractor shall provide technical support for integration maintenance efforts on the following aircraft: A-10, B-1, B-2, B-52, F-15, F-16 and F-35. The support shall include the following activities:

3.1.2 The contractor shall provide support for aircraft integration maintenance activities. Efforts shall include software interface updates between aircraft and weapon system that occur due to aircraft upgrades, weapon system improvements, Common Munitions Built in Test Reprogramming Equipment (CMBRE), Munitions Application Program (MAP), Mission Planning updates or deficiencies, or additional compatibility requirements.

3.1.3 The contractor shall provide SIL maintenance support and training for WCMD SSS and WCMD tail simulators. Such as replacement of simulator circuit cards, software upgrades and anomaly resolution, troubleshooting, cable repair, and alterations necessary from aircraft hardware or software upgrades or technical changes.

3.1.4 The contractor shall provide maintenance support of 6DOF/3DOF support equipment for software/hardware obsolescence and cyber security requirements as limited by the existing software/hardware tooling baseline.

3.2 Interface Management & Additional Aircraft Integration Support: The contractor shall support the continual WCMD interface control process: to include updating the Interface Control Document (ICD), accept and evaluate interface change notices, distribute change pages and support Joint Interface Control Working Group (JICWG) meetings as required. JICWG’s shall not exceed 150 hours annually. The contractor shall provide technical support for aircraft listed in paragraph 3.1.1 of this PWS and other Air Force aircraft as directed. (CDRL A002: DI-SESS-81248B, Interface Control Document (ICD))

3.3 Mission Planning: The contractor shall provide mission planning to include the support required to maintain existing WCMD PC weapon planning module (WPM), integrated with the Joint Mission Planning System (JMPS), WCMD Fly-Out- Models (FOM’s), and Windows OS (Operating System) future upgrades.

3.4 Software Integration Lab (SIL) Support: The contractor shall maintain existing WSU’s, SSS’s, DSSS’s and WCMD tail kit simulators at government locations. Note: WCMD software is utilized on SSS hardware. The contractor shall provide aircraft support for upgrading or new manufacture of SSS’s with the current SSS supplier in support of aircraft SIL’s

3.5 The contractor shall have the expertise to update existing WSU, SSS and DSSS operating systems, host PC, Avionics Components, as required and update simulator unit at government locations. The contractor shall inform the Government if updates exceeding the scope of this contract are necessary.

3.6 Weapon Simulator Support: The contractor shall have the expertise to provide technical, engineering and production support to update, redesign or upgrade WCMD weapon simulators to include producing simulators of current or upgraded designs. Expertise shall include maintenance or refurbishment of existing simulators, modification, redesign or improvements to the simulator and address parts obsolescence, simulator requirement changes and other problems preventing effective support of weapon simulators. The contractor shall inform the Government when Weapon Simulator Support is necessary and provide a ROM as required.

3.7 WCMD Tail Fin Release Lanyard Repair: The contractor shall repair fin release lanyards at government location utilizing existing tooling to accomplish repair.

3.8 Hardware In The Loop (HWIL) Support and Update: The contractor shall have the expertise to support the HWIL and ensure that it maintains the ability to update WCMD software and hardware or provide flight path reconstructions for detailed analysis of test flights (i.e. WSEP analysis). The contractor shall inform the Government of necessary updates and provide a ROM as required.

4.0 AGING AND SURVEILLANCE SUPPORT

4.1 The contractor shall provide surveillance teardown support and component testing support for Area Attack Munitions. This effort shall be performed on Government selected munitions systems with system teardowns at McAlester AAP and China Lake Naval Air Weapons Station. The government requires 20 teardowns within a 12-month period of performance (PoP). An overall technical assessment report shall be provided following completion of all testing.

4.2 The contractor shall conduct work efforts consisting of supporting teardown and component testing of 10 each CBU-87 CEM, and 10 each CBU-89 Gator munition systems and system components. Test assets will be selected by the government for teardown/test to be accomplished at designated government facilities. The contractor shall provide lot number suggestions for CEM, and Gator systems for annual teardown and flight testing based on historical test results. The contractor shall track and update the SFW, CEM, and Gator test activities by lot numbers for aging and surveillance testing utilizing spreadsheets or databases to track test results with historical test information.

4.3 The contractor shall perform wind tunnel testing on sub munition decelerators for Ram Air Decelerators (RADs) and/or Air Inflatable Device (AIDs).

4.4 The contractor shall have the expertise to assist the government with tasks associated with teardown test equipment located at McAlester Army Ammunition Plant (CEM) and China Lake Naval Air Weapons Station (Gator). The contractor shall inform the Government of necessary efforts and provide a ROM for the effort as required.

4.5 The contractor shall provide a surveillance test report of surveillance activities and include China Lake, McAlester, and other pertinent test data in the report. This report shall include test data analysis and overall system functionality assessments. Separate test reports shall be provided for CEM and Gator. (CDRL A001: DI-MISC-80508B, Technical Report Services)

5.0 REPORTS

All reports must meet industry standards and the requirements of the contract data requirements list.

6.0 GOVERNMENT-FURNISHED PROPERTY (GFP)

6.1 GFP Provided: All required GFP/GFE for this contract will be provided by the USAF.

6.2 Inventory and Reporting: All GFP/GFE for this contract will be managed and inventoried by the contractor. (CDRL A003: DI-MGMT-80441D, Government Property Inventory Report)

7.0 GENERAL INFORMATION

7.1 Delivery Schedule: Products and services shall be delivered on a schedule jointly defined by the AFLCMC/EBHCA Program representative and the contractor.

7.2 Period of Performance: This is an IDIQ contract with a five-year ordering period beginning in Sept 2022.

7.3 Government Inspection and Acceptance of Deliverables: The government program representative will have the right to reject or require correction of any deficiencies found in deliverables. In the event of rejection of any deliverable, the contractor will be notified in writing by the government of the specific reasons why the deliverable was rejected. The contractor shall have 30 calendar days to correct the rejected deliverable and resubmit to the government for re-inspection. If no comments are provided within 30 calendar days of deliverable receipt, the deliverable will be deemed to have been accepted by the government.

7.4 The contractor shall host Program Management Reviews (PMR) on an Annual basis and Technical Interchange Meetings (TIM) Bi-annually. (CDRL A004: DI-MGMT- 80368A, Status Report)

7.5 Travel Requirements: Travel conducted by the contractor shall be included in the contract effort. The contractor shall request travel approval from the program office.

8.0 SECURITY REQUIREMENTS

8.1 Security Management: The Contractor shall comply with the security requirements specified in the DD Form 254, Contract Security Classification Specification. The Contractor shall flow down the security requirements to subcontractors as applicable. For further information on how to obtain a facility security classification please refer to this link to DCSA: https://www.dcsa.mil/mc/ctp/fc/

8.2 Operations Security (OPSEC): The contractor shall ensure OPSEC is incorporated into the performance of the contract IAW DoD Directive 5205.02E, DoD Operations Security (OPSEC) Program and AFI 10-701 Air Force OPSEC Program. The Contractor shall flow down all OPSEC requirements to subcontractors that handle Critical Information (CI). CI is defined as specific facts about friendly intentions, capabilities, or activities needed by adversaries to plan and act effectively against friendly mission accomplishment.

8.3 Controlled Unclassified Information (CUI): The Contractor shall comply with DoDM 5200.01, Volume 4, DoD Information Security Program: CUI, Enclosures 3 & 4, for identification, protection and training requirements of CUI. The contractor shall be responsible for training their personnel and accomplishment of the out-processing procedures identified in DoDM 5200.01, Volume 4, Enclosure 4. The contractor shall comply with DoDM 5400.07/Air Force Manual 33-302, DoD Freedom of Information Act (FOIA) Program requirements. Protection of unclassified DoD information not approved for public release on non-DoD Information Systems will be protected IAW DoDI 8582.01, Security of Unclassified DoD Information on non-DoD Information Systems, Enclosure 3. The Contractor shall distribute controlled unclassified information IAW DoD Instruction 3200.14, Principles and Operational Parameters of the DoD Scientific and Technical Information Program, and DoD Instruction 2040.02, International Transfer of Technology, Articles, and Services. The Contractor shall properly mark all such documents IAW DoD Instruction 5230.24, Distribution Statements on Technical Documents. Technical documents not subject to distribution are defined in DoD Instruction 5230.24, DoD Directive 5230.25, and DoD Manual 5010.12-M, Procedures for the Acquisition and Management of Technical Data.

8.4 Security Classification Guide (SCG): The contractor shall follow the appropriate SCG and all security classification guides of systems/information associated with the program for derivative classification, identification of the level and duration of classification for specific information elements, and public release requirements.

8.5 Personnel Security: The Contractor shall ensure applicable Contractor personnel have security clearances at the appropriate level for proper accomplishment of contract/order requirements. The security clearance shall be obtained in accordance with the DD Form 254, Department of Defense Contract Security Classification Specification. Contractor personnel whose clearances have been suspended or revoked shall immediately be denied access to classified information and/or CUI and classified items.

8.6 Security Incidents and Violations: The Contractor shall notify the Government Contracting Activity and the Government Security Manager within 48 hours of any incident involving the actual or suspected compromise/loss of classified information to enable the Government to conduct immediate assessments of potential impact pending formal inquiry/investigation. Actual or suspected compromise of Covered Defense Information will be reported IAW DFARS Clause 252.204-7012.

8.7 Common Access Card (CAC): The Contractor shall ensure a CAC is obtained by all contractor/subcontractor personnel who require access to DoD computer networks/systems, for DoD facility entry control and/or for physical access to facilities and buildings to perform tasks under the contract/order. The Contractor shall provide a list of contractor/subcontractor personnel who require a CAC to the PCO. The Government will provide the Contractor instruction on how to complete a Contractor Verification System (CVS) application and notify the Contractor of approval/disapproval of contractor/subcontractor personnel application. Contractor/subcontractor personnel shall obtain the CAC from the local Real Time Automated Personnel Identification Documentation System (RAPIDS) issuing facility [usually the Military Personnel Flight (MPF)] The Contractor shall immediately report a lost or stolen CAC as directed by local Government policy. The Contractor shall notify the PCO of any change to the list of contractor/subcontractor personnel who require a CAC and provide an updated list within five business days. The Contractor shall return a CAC within five business days once contractor/subcontractor personnel no longer require computer network/system access and/or facility access. The Contractor shall return an expired CAC within five business days after the expiration date. The Contractor shall return any and all CACs within five business days after completion/termination of the contract as directed by local Government policy.

9.0 QUALITY CONTROL

9.1 Quality Control Program: The contractor shall establish a Quality Control Program to ensure the requirements of this contract are provided as specified.

9.2 Quality Assurance: The government’s Contracting Officer’s Representative (COR) and technical representative for this contract will be identified with the contract award. The government will periodically evaluate the contractor’s performance by appointing a representative(s) to monitor performance to ensure services are received. The government representative will evaluate the contractor’s performance. The government may evaluate each test task as it is completed.

9.2.1 The COR is a representative of the contracting officer and will participate in the administration of this contract. Subsequent to contract award, the identity of the COR will be furnished to the contractor.

9.2.2 The COR or alternate(s) will inform the contract manager in person when discrepancies occur and will request corrective action. The COR or alternate(s) will make a notation of the discrepancy with the date and time the discrepancy was noted and will request the contract manager (or authorized representative) initial the entry.

9.2.3 Any matter concerning a change to the scope, prices, terms or conditions of this contract shall be referred to the Contracting Officer and not to the COR(s).

9.2.4 The services performed by the contractor shall be subject to review by the Contracting Officer or authorized representative(s) during the period of this contract at all times and places.

10.0 GOVERNMENT OBSERVATIONS AND PARTICIPATION

10.1 Government Observations: Government personnel, other than contracting officers (COs) and COR(s), may from timetotime, with CO coordination, observe contractor operations.

10.2 Government Participation: The government shall be allowed to participate in all aspects of testing at contractor or government facilities. The contractor shall conduct a Test Readiness Review (TRR) prior to each test event to ensure all pre-test activities are complete and coordinated with all participants.

11.0 CONTRACT DATA REQUIREMENTS LIST – (CDRL’s)

A001

DI-MISC-80508B, Technical Report Services

2.5, 4.5, 11.0

A002

DI-SESS-81248B, Interface Control Document (ICD)

3.2, 11.0

A003

DI-MGMT-80441D, Government Property Inventory Report

6.2, 11.0

A004

DI-MGMT-80368A, Status Report

7.4, 11.0

12.0 CONTRACTOR MANPOWER REPORTING

12.1 Labor Hours: The contractor shall report ALL contractor labor hours (including subcontractor labor hours) required for performance of services provided under this agreement via a secure data collection site. The contractor is required to completely fill in all required data fields at https://www.sam.gov.

12.2 Reporting Inputs: Reporting inputs will be for the labor executed during the period of performance for each Government fiscal year (FY), which runs 1 October through 30 September. While inputs may be reported any time during the FY, all data shall be reported no later than 31 October of each calendar year. Contractors may direct questions to the CMRA help desk.

12.2.1 Reporting Period: Contractors are required to input data by 31 October of each year.

12.2.2 Uses and Safeguarding of Information: Information from the secure web site is considered to be proprietary in nature when the contract number and contractor identity are associated with the direct labor hours and direct labor dollars. At no time will any data be released to the public with the contractor’s name and contract number associated with the data.

12.2.3 User Manuals: User manuals for government personnel and contractors are available in the System for Award Management located at https://www.sam.gov.

i

CUI

1 Feb 2021

ARMAMENT DIRECTORATE OPERATIONS

SECURITY (OPSEC) PLAN 10-701

EGLIN AFB, FL

1 Feb 2021

Controlled by: AFLCMC/EB Controlled by: Information Protection CUI Categories: OPSEC Distribution/Dissemination Controls: FEDCON POC: Anthony Linthicome, (850) 883-3971

ARMAMENT DIRECTORATE OPERATIONS SECURITY PLAN 1 Feb 2021 ii

TABLE OF CONTENTS

CHIEF OF SECURITY OPSEC Memo ........................................................................................ iii

FOREWORD ................................................................................................................................. iv

SUMMARY OF CHANGES .......................................................................................................... v

SECTION I OVERVIEW

REFERENCES

ELEMENTS OF THE FIVE-STEP OPSEC PROCESS ………………………………………….2

SECTION II RESPONSIBLITIES

SECTION III CRITICAL INFORMATION

SECTION IV INDICATORS

SECTION V THE THREAT

SECTION VI VULNERABILITIES

SECTION VII RISK ……………………………………………………………………………11

SECTION VIII COUNTERMEASURES

SECTION IX PUBLIC AFFAIRS RELEASE

SECTION X EDUCATION AND TRAINING

SECTION XI FOREIGN NATIONALS

SECTION XII OPSEC IN CONTRACTS

ATTACHMENT 1 ARMAMENT DIRECTORATE CIIL

ARMAMENT DIRECTORATE OPRATIONS SECURITY PLAN 1 Feb 2021 iii

DEPARTMENT OF THE AIR FORCE

AIR FORCE LIFE CYCLE MANAGEMENT CENTER

EGLIN AIR FORCE BASE FLORIDA

MEMORANDUM FOR AFLCMC/EB

FROM: AFLCMC/EBOS

SUBJECT: Armament Directorate Operations Security (OPSEC) Plan 10-701

1. This plan has been reviewed and coordinated by Armament Directorate leadership. It is deemed accurate, complete and necessary to the execution of unit missions.

2. This revision supersedes the previous Armament Directorate Operations Security (OPSEC) Plan, dated Feb 18. This is an overarching plan that affects all divisions within AFLCMC/EB.

3. This plan is effective upon receipt for planning purposes and for implementation as directed by the Program Executive Officer (PEO), Armament Directorate.

4. The office of primary responsibility for this document is AFLCMC/EBOS at 883-3965.

RODNEY PERRY, NH-IV, DAF

Chief of Security IP/Security Organizational Senior Functional (OSF)

1st Ind, AFLCMC/EB

MEMORANDUM FOR AFLCMC/EBOS

Concur. Subject plan will be posted on the AFLCMC/EB Security SharePoint site.

HEATH A. COLLINS, Brig Gen, USAF Air Force Program Executive Officer for Weapons and Director, Armament Directorate iv

FOREWORD

The Eglin Air Force Base Operations Security (OPSEC) Plan 10-701 identifies specific OPSEC threats, vulnerabilities and various countermeasures available during day-to-day operations.

Implementing this plan ensures mission effectiveness by maintaining an essential level of

OPSEC.

OPSEC is an Information-Related Capability (IRC) that preserves friendly essential secrecy by applying a process to identify, control, and protect critical information and indicators (CII) that, if compromised, would allow adversaries or potential adversaries to identify and exploit friendly vulnerabilities leading to increased risk of potential mission, function, program, or activity failure or the loss of life. OPSEC’s desired effect is to influence the adversary’s behavior and actions by reducing the adversary’s ability to collect and exploit critical information and indicators about friendly activities.

This plan establishes a baseline for the Armament Directorate, its associated divisions and Operating Locations (OLs) on Eglin AFB participating in the Eglin OPSEC program. OLs on installations other than Eglin AFB will utilize their host Installation OPSEC Plan in concert with the Armament Directorate’s Critical Information and Indicators List (CIIL) located at Attachment 1 of this OPSEC plan. A copy of this OPSEC Plan will be provided to all Armament Directorate OLs. The AFLCMC and Eglin AFB CIIL’s can be located on the AFLCMC/EB Security SharePoint.

v

SUMMARY OF CHANGES: This revision supersedes the previous Armament Directorate (AFLCMC/EB) OPSEC Plan, dated February 2018. This is an overarching plan and affects all Air Force Life Cycle Management Center, Armament Directorate (AFLCMC/EB) assigned divisions and Operating Locations regardless of their location. It implements Air Force Policy Directive (AFPD) 10-7, Air Force Information Operations, and DoDI 5200.48, Controlled Unclassified Information (CUI), and AFI 10-701, Operations Security, dated 24 July 2019.

This plan changes the five-step OPSEC process, and adds a measure of awareness and understanding of both adversary threats and of techniques employed by adversaries to collect classified and sensitive information. This plan also changes the Armament Directorate Critical Information and Indicator List (CIIL), and adds the requirement of an OPSEC Foreign National (FN) assessment checklist to be completed by the sponsor of FN visitors prior to their arrival.

SECTION I

OVERVIEW

1. REFERENCES:

1.1 . AFPD 10-7, Information Operations

1.2 . AFI 10-701, Operations Security (OPSEC)

1.3 . AFI 33-360, Publications and Forms Management

1.4 . DoDM 5200.01, Vol. 1-3, Information Security Program

1.5 . DoD 5205.02-M, Operations Security (OPSEC) Program Manual

1.6 . DoDM 5400.7/AFMAN 33-302, Freedom of Information Act Program

1.7 . DoDI 5200.48, Controlled Unclassified Information (CUI).

2. PURPOSE: The purpose of this plan is to deny our adversaries opportunities to collect critical information (CI), which includes Controlled Unclassified Information (CUI) and classified information concerning Eglin Air Force Base and Armament Directorate activities. This plan identifies sensitive aspects of interest to Foreign Intelligence Services and the procedures designed to reduce or eliminate our exploitable OPSEC vulnerabilities.

3. DEFINITION OF OPSEC: OPSEC is the process of identifying, analyzing and controlling critical information and indicators of friendly actions associated with military operations; and other activities to identify those actions that can be observed by adversary intelligence systems.

Determine what specific indicators could be collected, analyzed, and interpreted to derive critical information in time to be useful to adversaries and select and execute measures that eliminate or reduce to an acceptable level the vulnerabilities of friendly actions to adversary exploitation.

OPSEC is accomplished through the use of a five-step process:

3.1 . Identify Critical Information

3.2 . Analyze Threats

3.3 . Analyze Vulnerabilities

3.4 . Assess Risk

3.5 . Apply Countermeasures

4. ELEMENTS OF THE FIVE STEP OPSEC PROCESS:

4.1. Identify potential CI items and continuously update CI and indicators that directly point to CI.

4.2. Analyze with intelligence and counterintelligence analysts the threat to CI.

4.3. Determine vulnerabilities to CI (or indicators) that can be exploited or countered.

4.4. Determine what level of risk can be accepted should CI be exploited or countered.

4.5. Prepare and implement appropriate countermeasures that will eliminate or reduce the risk to an acceptable level.

SECTION II

RESPONSIBILITIES

1. GENERAL: All government employees, DoD contractors, and military personnel assigned to, or working in support of the Armament Directorate, shall comply with this plan unless their OPSEC is covered under another recognized oversight agency. In accordance with AFI 10-701, 24 Jul 2019, tenant organization OPSEC Coordinators will closely coordinate and integrate with the host wing OPSEC Program Manager (PM) or Signature Management (SM) initiatives, and comply with host MAJCOM and wing guidance.

However, administrative oversight of tenant organization’s program still resides with its OPSEC Program Manager.

2. DIRECTOR, ARMAMENT DIRECTORATE: The Director is responsible for the overall management of the Armament Directorate OPSEC program.

The Director will:

2.1. Provide OPSEC policy and guidance to effectively support host base and organization mission in accordance with OPSEC regulations and instructions.

2.2. Approve the Armament Directorate OPSEC Plan.

2.3. Ensure Critical Information and Indicator Lists (CIIL) are developed and procedures are in place to control CI and associated indicators.

2.4. Based on the risk assessment, decide on implementation of OPSEC countermeasures as documented in this plan.

2.5. Ensure OPSEC is integrated into planning efforts to increase mission effectiveness.

2.6. Appoint in writing a primary and alternate Armament Directorate OPSEC Coordinator for a minimum of two (2) years. This can be delegated to the Deputy Director, Armament Directorate or the Chief of Security, Armament Directorate.

3. DIVISION SENIOR MATERIEL LEADERS (SML’s)/DIRECTORS: Have responsibility to:

3.1. Approve division specific CIILs not covered by the current Armament Directorate CIIL. Coordinate them through the primary/alternate OPSEC Coordinator located in the Collateral Security Office (CSO) to be added to the CIIL. Ensure procedures are in place to control CI and associated indicators.

3.2. Ensure OPSEC training is completed by personnel within their division.

SMLs/Directors will enforce appropriate disciplinary action for failure to follow directed OPSEC measures and/or unauthorized disclosure of CI.

3.3. Apply appropriate countermeasures within their division consistent with OPSEC guidance.

3.4. Ensure OPSEC is integrated into planning efforts to increase mission effectiveness.

Ensure division planners are trained to incorporate OPSEC into all functional areas of plans.

4. OPSEC Coordinators: OPSEC Coordinators are functional experts trained to integrate OPSEC as an IRC, into the organization’s planning process using AF standards, policies, procedures and this instruction as guidance. The OPSEC Coordinator supports the OPSEC PM in ensuring OPSEC is incorporated into the planning process to protect the overall planning and execution of operational activities. OPSEC Coordinators serve an important function within the OPSEC Program structure regarding OPSEC related matters within the Armament Directorate. This include developing and recommending guidance and implementing countermeasures to mitigate the risk of potential adversary exploitation of critical information and indicators. OPSEC Coordinator’s will:

4.1. Implement and distribute the commander’s OPSEC guidance such as CIILs (See Attachment 1 for the Armament Directorate CIIL), memorandums, SOPs, OPSEC plans as required. Ensure all personnel have a hard or soft copy of CIILs at workstations.

4.2. Implement procedures per guidance from the host Installation OPSEC PM to control associated indicators to deny adversaries the opportunity to take advantage of publicly available information especially when aggregated.

4.3. Ensure critical information and indicators are protected from disclosure.

4.4. Ensure all personnel assigned to the Armament Directorate (military, civilians, and contractors) complete initial and annual refresher OPSEC training IAW Chapter 4, AFI 10- 701.

4.5. When necessary, conduct OPSEC reviews of organizational documents and photographs prior to being submitted to Public Affairs and/or release to the public.

4.6. When necessary, assist AFLCMC and Eglin AFB OPSEC PM’s in ensuring OPSEC is considered for all division contracts. (See Chapter 8, AFI 10-701 for additional information regarding OPSEC and contracts).

4.7. Coordinate with intelligence and counterintelligence providers to identify the intelligence needs for the OPSEC plan.

5. INDIVIDUAL: Shall apply OPSEC to the fullest extent possible in their daily duty performance. This includes, but is not limited to:

5.1. Being familiar with this OPSEC Plan and CIILs.

5.2. Protect critical and/or sensitive information from disclosure by securing all CI when leaving work areas and removing CACs from computer systems. Use protection measures, i.e., locked desks or cabinets, when not physically present. This includes behind cypher locked areas.

5.3. Do not transmit CI by unencrypted means, such as cell phones, emails, or radios. All government email accounts, to include Workflow/Org-Boxes, will have encryption capability for transmitting CI.

5.4. If posting or publishing official information in the public domain, personnel must first check with the unit OPSEC Coordinator, to ensure Critical Information is not compromised. This includes, but is not limited to, social media sites, letters, resumes, articles, email, website postings, blogs, internet message boards, etc.

5.5. Do not publicly disseminate or publish photographs displaying critical and/or sensitive information. Examples include, but are not limited to, improvised explosive device strikes, battle scenes, casualties, destroyed or damaged equipment, personnel killed in action (both friendly and adversary), and the protective measures of military facilities.

5.6. Do not publicly reference, disseminate, correct, or publish critical and/or sensitive information that has been compromised. This provides further unnecessary exposure of the compromised information and may serve as validation.

5.7. Actively encourage others, including family members and friends, to protect critical and/or sensitive information.

5.8. Destroy, shred, and etc., critical and/or CUI when no longer needed.

5.9. Know the unit appointed OPSEC Coordinator. Direct questions, concerns, or recommendations for OPSEC related topics to these individuals.

5.10. Report to the OPSEC Coordinator, any attempts by unauthorized personnel to solicit critical and/or sensitive information from EB personnel.

SECTION III

CRITICAL INFORMATION (CI)

1. DEFINITION: CI is specific facts (or evidence) about friendly intentions, capabilities, and activities vitally important to adversaries for them to plan and act effectively and to guarantee failure or unacceptable intelligence indicators that could impact friendly missions, and:

1.1. Reduce mission effectiveness

1.2. Compromise CI

1.3. Provide adversaries a technological, tactical and/or strategic advantage

1.4. Diminish security program effectiveness

2. PROTECTING CI: All Armament Directorate and OL personnel will apply the following when working with CI:

2.1. Ensure all CI remains within official channels (Active Duty, DoD Civilians, Contractors, Reserve and ANG).

2.2. Always apply “Need-to-Know” when disseminating CI.

2.3. Encrypt CI when transmitting over unsecure channels.

2.4. Implement protection measures to ensure data processing equipment, such as computers, copiers, printers, fax machines, smart phones, tablets, and other electronic devices, are protecting critical and/ or sensitive information.

2.5. Social Media. Social media includes, but is not limited to, weblogs, message boards, video sharing, and other media sharing websites. Do not post any CUI on social media site.

When in doubt, talk to your OPSEC Coordinator. Media sites created by spouses or family members of active duty or reserve component members, which contain specific unit information, must be approved by the Commander and reviewed periodically by the OPSEC Coordinator as they may contain information critical to the unit mission.

3. DESTROYING CII: All CII and/or sensitive information must be destroyed (i.e., burn or shred) when no longer needed to prevent inadvertent disclosure or reconstruction.

SECTION IV

INDICATORS

1. OPSEC INDICATORS: Friendly actions and information adversaries can potentially detect or obtain and then interpret to derive friendly Critical Information (CI).

2. TYPICAL OPSEC INDICATORS: The following items are examples of OPSEC indicators, not all-inclusive:

- Parking lots full of vehicles during non-duty hours

- Numbers and/or types of aircraft on the flight line suddenly change

- Security Forces blocking off areas of the Eglin Reservation

- An increase number of military personnel moving through airports

- Change in security posture at installation entry points

- Sudden changes in phone and/or email traffic

- Dramatic changes in traffic at base entry points

2.1. Security Classification Guides (SCG): Identify classified and CUI associated with the program or project that must be protected through SCGs. The user of the SCG must comply with identified program specific OPSEC requirements to protect the information.

2.2. Communications: Sensitive conversations can be monitored. OPSEC External Assessments (OEA) show significant amounts of sensitive information is discussed over unsecure lines. Whenever possible, utilize secure communications and do not discuss “shop talk” in public areas.

2.3. Computers: Unsecured systems can contain CUI and are extremely susceptible to exploitation and casual observation. Whenever possible, operate computers in a controlled environment. Ensure encryption is utilized for all emails containing Controlled Unclassified Information (CUI), OPSEC CII, Privacy Act (PA) and Personally Identifiable Information (PII).

2.4. Documentation: Proper control and disposal of documentation is crucial to protection. Do not leave CUI unattended while away from your desk or office. When no longer needed, CUI must be destroyed by shredding, the preferred method, or by burning.

2.5. Travel Schedules: Frequent travel to specific areas could indicate sensitive projects or activities. Whenever possible, randomly change travel schedules, flight times, alternate airports, alternate hotels, and etc., for recurring visits.

SECTION V

THE THREAT

1. DEFINITION OF THE OPSEC THREAT: Threat is an adversary with the capability and intent to undertake action detrimental to mission success, to include associated program activities and/or operations. An adversary is any entity with goals counter to your own.

2. LOCAL CRIMINAL THREAT: AFOSI assesses the overall criminal threat at each installation.

3. TYPES OF THREATS: Threats below can potentially threaten the Armament Directorate’s Critical information.

3.1. Human Intelligence (HUMINT):

3.1.1. Intelligence information gathered through human resources is normally gathered covertly through espionage or overtly through information readily available to the general public. The most common approach is targeting and developing contacts with DoD government and DoD contractor personnel.

3.2. Signal Intelligence (SIGINT):

3.2.1. SIGINT includes both Communications Intelligence (COMINT) and Electronic Intelligence (ELINT). SIGINT collection encompasses all forms of radiating systems such as communications, electronic signals, telemetry, radars and microwave. Most telephone conversations and fax transmissions are carried by microwave and are vulnerable to interception and exploitation. The use of a secure phone may prevent the accessibility of specific information, but it does not prevent profiling other information of value, where the call comes from and goes to, when the call was made, how long the call took, and other subsequent calls possibly associated with the initial call. Many times, sensitive information is exchanged by users on secure phones prior to going into a secure mode.

3.3. Imagery Intelligence (IMINT):

3.3.1. Imagery intelligence can be collected through the use of cameras and sensors on the ground, in passing vehicles, aircraft, drones, boat or satellite. This could be from within or outside the installation. Other types of imagery collection are possible.

3.4. Measurement and Signature Intelligence (MASINT):

3.4.1. MASINT is technically derived intelligence that when collected, processed, and analyzed by dedicated MASINT systems, results in intelligence that detects and classifies targets, and identifies or describes signature of fixed or dynamic target sources. In the context of MASINT, “measurement” relates to the finite metric parameters of targets. “Signature” covers the distinctive features of phenomena, equipment, or objects as they are sensed by the collection instruments. In addition to MASINT, IMINT and HUMINT can subsequently be used to track or more precisely, classify targets identified through the intelligence process. While traditional IMINT and SIGINT are not considered to be MASINT efforts, images and signals from other intelligence gathering processes can be further examined through the MASINT discipline, such as determining the depth of buried assets in imagery gathered through the IMINT process. The signature is used to recognize the phenomenon (the equipment or object) once its distinctive features are detected. MASINT measurement searches for differences from known norms and characterizes the signature of new phenomena.

3.5. Open Sources Intelligence (OSINT):

3.5.1. Open source literature is readily available and is the preferred method for acquiring information. Open source information is accessible through computers, newspapers, meeting and seminar pamphlets, bulletin boards, contractor advertisements, recycle bins, garbage bins, etc. Conferences attended by foreign nationals provide a common ground to solicit and exploit participating individuals.

Collection efforts may range from harmless questions and exchange of personal information for business correspondence to various forms of entrapment.

Information obtained from these sources provides the foreign intelligence collector with highly valuable information regarding capabilities, limitations, and performance.

3.6. Open Skies Overflight:

3.6.1. The Open Skies treaty is an international agreement that permits treaty members to fly observation missions over the territory of other members. Regardless of the intended purpose for such openness, the use of such resources for collecting military information cannot be overlooked.

SECTION VI

VULNERABILITIES

1. A VULNERABILITY EXISTS when the adversary is capable of collecting critical information and/or indicators, correctly analyzing them and acting quickly enough to impact friendly objectives. Vulnerabilities and indicators go hand-in-hand. They are extremely sensitive and maybe targeted by an adversary.

2. VULNERABILITY ANALYSIS: The examination of your processes, projects or missions to determine if you have inherent, naturally occurring or self-induced vulnerabilities or indicators that put your critical information and thus your mission at risk.

3. VULNERABILITIES CAN BE:

3.1. Foreign Intelligence Threats.

3.2. Documentation (i.e., technical manuals, contract proposals, test reports, mission statements, program introduction documents, test directives, and a test engineer’s handbook).

3.3. Poor security practices for meetings, symposiums, and conferences.

3.4. Improper release of sensitive information material from unauthorized disclosure.

3.5. Failure to mark documents containing Control Unclassified Information (CUI).

3.6. Failure to destroy critical and/or sensitive information correctly.

3.7. Discussing “shop talk” outside the work area.

3.8. Failure to transfer and/or discuss information securely in order to expedite a work effort.

3.9. Failure to challenge or question strangers in work areas.

3.10. Failure to acknowledge/report a security incident.

3.11. Failure to obtain the capability to encrypt and decrypt email.

3.12. Discussing CII over unencrypted cell phones and radios.

SECTION VII

RISK

1. DESCRIPTION: Risk is a measure of the potential degree to which critical information is subject to loss through adversary exploitation. The assessment of risk evaluates the degree of probable harm or adverse impact that a vulnerability or combination of vulnerabilities may cause if exploited by an adversary. It involves assessing the adversary’s ability to exploit vulnerabilities that would lead to the exposure of critical information and the potential impact it would have on the mission. Determining the level of risk is a key element of the OPSEC process and provides justification for the use of countermeasures.

Conduct risk assessments and develop recommended countermeasures based on operational planning and the current operating environment. AFLCMC and Eglin Air Force Base use countermeasures (CM) to eliminate potential vulnerabilities.

2. RISK ASSESSMENT:

2.1. Determine the level of risk by comparing the vulnerabilities identified with the probability of an adversary being able to exploit those vulnerabilities, and the impact, if exploited.

2.2. Once the amount of risk is determined, identify potential countermeasures to reduce the vulnerabilities with the highest risk. The most desirable countermeasures are those combining the highest possible protection with the lease amount of resource requirements and/or adverse effects on mission goals.

2.3. Consider the cost, time, and effort of implementing measures and countermeasures to mitigate risk. Factors to consider include:

2.3.1. What are the benefits of the proposed countermeasures to reduce risks compared to the negative effects on the mission?

2.3.2. What is the cost of the proposed countermeasure compared with the cost associated with the impact if the adversary exploits the vulnerability?

2.3.3. Will implementing the countermeasure create a new OPSEC indicator?

SECTION VIII

COUNTERMEASURES

1. DESCRIPTION: Countermeasures are anything which negates or reduces an adversary’s ability to exploit Air Force vulnerabilities. Countermeasures are designed to prevent an adversary from detecting critical information, provide an alternative interpretation of critical information or indicators (deception), or deny the adversary the ability to utilize their collection system to exploit Air Force operations. Countermeasures may be offensive or defensive in nature (e.g., camouflage, concealment, deception, intentional deviations from normal patterns, direct strikes against adversary collection capabilities).

The Armament Directorate will consider and implement Eglin AFB CMs, as well as implement other CMs, if required. These CMs consists of in-place security practices, policies and procedures. CMs should be no/low-cost to be effective.

2. CM TO CONCEAL:

2.1. Training: Armament Directorate OPSEC Coordinator’s will provide initial newcomers and refresher OPSEC training to assigned personnel to include Integrated Contractors.

2.2. Secure Communications: Utilize secure communications when operationally feasible.

2.3. Information Security: Established security practices and procedures, such as using only approved storage containers, end-of-day security checks, and ensuring the “need-to-know” principle before granting access to CUI or Classified, are measures taken to protect CII.

2.4. Physical Security: The most overlooked and easiest HUMINT vulnerability to exploit is poor visitor control.

2.5. Meeting: The meeting OPR is responsible for including security practices in the planning and execution of the meeting. The Armament Directorate OPSEC Coordinator assists and supports the OPR.

2.6. Destruction/Disposal: Each Division and Operating Location (OL) should analyze their shred policy and procedure. Implementing a 100% shred policy is the best policy, but may not always be feasible, due to mission requirements.

2.7. Clean Desk Policy: During duty hours, reasonable steps shall be taken to minimize risk of unauthorized personnel accessing sensitive information. After duty hours, CUI, Privacy Act Data and CII shall be stored in locked desks, file cabinets, bookcases, locked rooms, and etc.

3. CM TO CONFUSE:

3.1. Vary activities including travel, work, and leave schedules.

3.2. Without disrupting normal profiles, schedule activities to occur during periods of the least vulnerability.

SECTION IX

PUBLIC AFFAIRS RELEASE

1. Armament Directorate personnel must route information intended for public release or presentation to outside agencies, i.e., news media or other public media outlets and/or speeches, presentations, and photographs provided at symposium, through the OPSEC Coordinator. In turn, the OPSEC Coordinator will then forward the request to the 96 TW/Public Affairs (PA) Office, receiving a Security & Policy Review (SPR) prior to release. Operating Locations on installations other than Eglin AFB must route PA releases in accordance with (IAW) host installation requirements.

2. The author prepares the material and routes it through their respective Division coordination chain for initial review using AF Form 1768, Electronic Staff Summary Sheet, E-SSS (see sample E-SSS templates on the Security SharePoint). Armament Directorate does not utilize the AF Form 1420 to secure approval of the 96 TW/ PA Office.

SECTION X

EDUCATION AND TRAINING

1. GENERAL: Personnel (military, Department of the Air Force Civilians and DoD Contractors) require a general knowledge of threats, vulnerabilities, countermeasures and their responsibilities associated with protecting critical information. OPSEC education is a continuous requirement. Personnel require OPSEC awareness education during their initial in-processing and annually thereafter.

2. ANNUAL OPSEC BRIEFING: Personnel shall receive annual and refresher OPSEC training IAW DoDM 5205.02, DoD OPSEC Program Manual and AFI 10-701, Operations Security (OPSEC) that reinforces understanding of OPSEC policies and procedures, critical information, and procedures covered in initial and specialized training. Refresher training should also address the threat and techniques employed by adversaries attempting to obtain classified and sensitive information.

SECTION XI

FOREIGN NATIONALS

1. Foreign National Visits:

1.1. Foreign National (FN) visitors on the installation and in Armament Directorate areas, regardless of their business, have the capability to make contact with DoD personnel and collect open source literature and information on current events and future activities. An OPSEC FN Visit assessment checklist (Contact OPSEC Coordinator for the checklist) must be completed two duty-days prior to the foreign national’s arrival by the division sponsor of the FN visit.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .