DD 254 OCS Tutors.pdf
PDF 542 KB Posted
- Attached to
- SAF OPERATIONAL CONTRACT SUPPORT (OCS) Tutoring (Amended) Federal contract opportunity
- Solicitation number
- FA7014-24-R-0063
About this file
This document is a DD Form 254 - Department of Defense Contract Security Classification Specification for a federal contract opportunity. The requirements are for non-personal services for OCS tutor/trainers to provide technical expertise and deliver tailored instruction and tutoring to various military commands and personnel. The contractor must have a Top Secret Facility Clearance and ability to hire personnel with valid Top Secret Clearances with SCI eligibility. The contract performance period is 25 Sept 2024 through 24 Sept 2029. The contractor will be required to handle and protect various types of classified information including COMSEC, Restricted Data, SCI, and non-SCI intelligence. The contractor must also comply with Operations Security (OPSEC) requirements and public release procedures. This DD Form 254 provides detailed security guidance and requirements for the contractor.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Questions and Answers_3 for OCS Tutors FA7014-24-R-0063.pdf | ||
| Questions and Answers_2 for OCS Tutors FA7014-24-R-0063.pdf | ||
| Instructions to Offerors- OCS Tutors Revised 1.pdf | ||
| FA7014-24-R-0063 Combined Solitication_Synopis_Revised 1.pdf | ||
| Solicitation Amendment FA701424R00630001 SF 30.pdf | ||
| FA701424R0063 Questions and Answers.pdf | ||
| Solicitation - FA701424R0063.pdf | ||
| Evaluation Criteria - OCS Tutors Revised.pdf | ||
| OCS Tutors PWS Revised.pdf | ||
| OCS Tutors Ordering Form.xlsx | XLSX spreadsheet | |
| Instructions to Offerors- OCS Tutors Revised.pdf | ||
| FA7014-24-R-0063 Combined Solitication_Synopis_Revised.pdf |
Show all 12
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
CLASSIFICATION (When filled in):
PREVIOUS EDITION IS OBSOLETE. Page 1 of 12DD FORM 254, APR 2018
DEPARTMENT OF DEFENSE
CONTRACT SECURITY CLASSIFICATION SPECIFICATION
(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)
OMB No. 0704-0567 OMB approval expires:
June 30, 2025
The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.
RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.
1. CLEARANCE AND SAFEGUARDING
a. LEVEL OF FACILITY SECURITY CLEARANCE (FCL) REQUIRED (See Instructions)
Top Secret
b. LEVEL OF SAFEGUARDING FOR CLASSIFIED INFORMATION/
MATERIAL REQUIRED AT CONTRACTOR FACILITY
None (See instructions)
2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)
a. PRIME CONTRACT NUMBER (See instructions.)
FA7014-24-D-XXXX
b. SUBCONTRACT NUMBER
c. SOLICITATION OR OTHER NUMBER
FA7014-24-R-XXXX
DUE DATE (YYYYMMDD)
3. THIS SPECIFICATION IS: (X and complete as applicable.)
a. ORIGINAL (Complete date in all cases.)
DATE (YYYYMMDD)
b. REVISED (Supersedes all previous specifications.)
REVISION NO. DATE (YYYYMMDD)
c. FINAL (Complete Item 5 in all cases.) DATE (YYYYMMDD)
4. IS THIS A FOLLOW-ON CONTRACT? No Yes If yes, complete the following:
Classified material received or generated under (Preceding Contract Number) is transferred to this follow-on contract.FA7014-20-D-0013
5. IS THIS A FINAL DD FORM 254? No Yes If yes, complete the following:
In response to the contractor's request dated , retention of the classified material is authorized for the period of:
6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)
a. NAME, ADDRESS, AND ZIP CODE b. CAGE CODE c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)
Alexandria1 Field Office 571-551-7920
7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor)
a. NAME, ADDRESS, AND ZIP CODE b. CAGE CODE c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)
8. ACTUAL PERFORMANCE (Click button to add more locations.)
a. LOCATION(S) (For actual performance, see instructions.)
SAF/AQC
1060 Air Force Pentagon Washington, DC 20330-1060
b. CAGE CODE (If applicable, see Instructions.)
c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)
11th Wing Information Protection Office 1330 Air Force Pentagon, Room 1E871 Washington, D.C. 20330 703614-2932
a. LOCATION(S) (For actual performance, see instructions.) b. CAGE CODE (If applicable, see Instructions.)
c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)
PREVIOUS EDITION IS OBSOLETE. Page 2 of 12DD FORM 254, APR 2018
a. LOCATION(S) (For actual performance, see instructions.) b. CAGE CODE (If applicable, see Instructions.)
c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)
9. GENERAL UNCLASSIFIED DESCRIPTION OF THIS PROCUREMENT
The requirement is for non-personal services for OCS tutor/trainers that will provide technical expertise and deliver tailored instruction and tutoring to Geographic Combatant Commands (GCC), Functional Combatant Commands (FCC), and Service Headquarters and component members to implement OCS capability. This requirement will provide the training and curriculum materials to integrate OCS in the present force and propose a full spectrum doctrine, organization, training, material, leadership and education, personnel, and facilities (DOTMLPF) and capability solution framework to deliver more responsive and accountable OCS for the warfighter. The government requires tutoring/ instruction services to guide, mentor, and train-the-trainer GCC/FCC and Service staff as applicable to address capability gaps related to the planning and integration of OCS into current and future operations.
10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)
a. COMMUNICATIONS SECURITY (COMSEC) INFORMATION f. SPECIAL ACCESS PROGRAM (SAP) INFORMATION
b. RESTRICTED DATA
g. NORTH ATLANTIC TREATY ORGANIZATION
(NATO) INFORMATION
c. CRITICAL NUCLEAR WEAPON DESIGN INFORMATION (CNWDI) (If CNWDI applies, RESTRICTED DATA must also be marked.)
h. FOREIGN GOVERMENT INFORMATION
d. FORMERLY RESTRICTED DATA
i. ALTERNATIVE COMPENSATORY CONTROL MEASURES
(ACCM) INFORMATION
e. NATIONAL INTELLIGENCE INFORMATION:
(1) Sensitive Compartmented Information (SCI)
(2) Non-SCI
j. CONTROLLED UNCLASSIFIED INFORMATION (CUI) (See instructions.)
k. OTHER (Specify) (See instructions.)
See Item 13
11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)
a. HAVE ACCESS TO CLASSIFIED INFORMATION ONLY AT
ANOTHER CONTRACTOR'S FACILITY OR A GOVERNMENT
ACTIVITY
(Applicable only if there is no access or storage required at contractor facility.
See instructions.)
b. RECEIVE AND STORE CLASSIFIED DOCUMENTS ONLY
c. RECEIVE, STORE, AND GENERATE CLASSIFIED
INFORMATION OR MATERIAL
d. FABRICATE, MODIFY, OR STORE CLASSIFIED HARDWARE
e. PERFORM SERVICES ONLY
f. HAVE ACCESS TO U.S. CLASSIFIED INFORMATION OUTSIDE
THE U.S.,PUERTO RICO, U.S. POSSESSIONS AND TRUST
TERRITORIES
g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE
TECHNICAL INFORMATION CENTER (DTIC) OR OTHER
SECONDARY DISTRIBUTION CENTER
h. REQUIRE A COMSEC ACCOUNT
i. HAVE A TEMPEST REQUIREMENT
j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS
k. BE AUTHORIZED TO USE DEFENSE COURIER SERVICE
l. RECEIVE, STORE, OR GENERATE CONTROLLED UNCLASSIFIED
INFORMATION (CUI).
(DoD Components: refer to DoDI 5200.48, only for specific CUI protection requirements. Non-DoD Components: see instructions.)
m. OTHER (Specify) (See instructions.)
12. PUBLIC RELEASE
Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority.
Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)
DIRECT THROUGH (Specify below)
See Section 13
Public Release Authority:
See Section 13
13. SECURITY GUIDANCE
PREVIOUS EDITION IS OBSOLETE. Page 3 of 12DD FORM 254, APR 2018
The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract;
and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.
(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)
All contractor personnel shall comply with the provisions of Part 117, Title 32 CFR also known as the National Industrial Security Program Operating Manual (NISPOM) Incorporating Change 2, May 2016; DoDM 5220.32 Vol 1, National Industrial Security Program, Industrial Security Procedures for Government Activities, Change 2, 10 DEC 2021; DoDM 5220.22, Vol. 2_AFMAN 16-1406 Vol. 2, National Industrial Security Program: Industrial Security Procedures for Government Activities, May 2020.
Contract performance: 25 Sept 2024 through 24 Sept 2029
Security classification guidance on information, hardware, and equipment will be furnished to the contractor at the time access to classified is granted or when classification changes occur. This will include any special projects.
All classified visit requests by Visitor Groups shall be forwarded to the COR for approval and need-to-know certification before being sent to the facility to be visited. The COR must be notified and approve the receipt and/or generation of classified information under this contract. All classified information received and/or generated under this contract is the property of the U.S. Government regardless of proprietary claims. Upon completion or termination of this contract, the U.S. Government will be contacted for destruction or disposition instructions.
In addition to the reporting requirements directed by the NISPOM, the Visitor Group will provide a concurrent report of loss or compromise of classified information to the HAF/A4 Security Assistant. Visit requests to activities other than those not listed in the statement of work on this DD254 shall have a “Need to Know” certified by the HAF/A4 Security Assistant. All requests shall contain the information required by the NISPOM and shall not exceed a 12-month period.
All classified material received, generated, fabricated or modified by this contract will be returned within 30 days after completion of contract or destroyed with destruction report being submitted to HAF/A4 Security Assistant. Prior to any destruction of classified information a full listing of documents will be provided to the HAF/A4 Security Assistant for review and approval. If additional contracting requirements exist where retention of classified information by the Visitor Group facility is required, a written request to retain material for a period but not to exceed 2 years is required.
Provide the information requested by the Notification of Government Security Activity Clause, AFFARS 5352.204-9000 and Visitor Group Security Agreement Clause, AFFARS5352.204.90001, to the Cognizant Security Office (CSO) address in Block 18.f of this form. Refer to the contract document for these clauses.
Non-Disclosure Agreement: The Visitor Group may be required to have access to highly sensitive and confidential plans and data for the performance of this delivery order. The Visitor Group will not divulge any information about activities or functions, or other knowledge gained, to anyone who is not authorized to have access to such information. It will be the Visitor Group’s responsibility to ensure that persons have the proper authority and “need to know” prior to any discussions. The Visitor Group will observe and comply with any security provisions.
The use of cellular phones, hand-held radios, beepers/pagers, cordless telephones, cordless microphones, and all wireless electronic devices shall be addressed in the Standard Operating Procedures (SOP) of the Information Security (IS) procedures for each computer facility where classified processing is accomplished
Ref 10. CONTRACTOR WILL REQUIRE ACCESS TO:
Ref. 10.a.: Communications Security (COMSEC) Information:
1. COMSEC material/information may not be released to DOD contractors without Air Force Cryptological Support Center (AFCSC) approval.
2. Contractor must forward requests for COMSEC material/information to the COMSEC officer through the program office.
3. The contractor is governed by the following 32 CFR Part 117, December 21, 2020 National Industrial Security Program Operating Manual (NISPOM), Section 21, Communications Security (COMSEC) in the control and protection of COMSEC material/information.
4. Access to COMSEC material by personnel is restricted to U.S. citizens holding final U.S. Government clearances. Such information is not releasable to personnel holding only reciprocal clearances.
5. The contractor will establish a COMSEC Account with the 844th CS.
6. The contractor is governed by AFKAG-1, AFKAG-2, and appropriate Air Force Systems Security Instructions/Manuals (AFSSI/ AFSSM) or Air Force Instructions (AFI). Access to COMSEC material or information is restricted to US citizens holding final U.S.
PREVIOUS EDITION IS OBSOLETE. Page 4 of 12DD FORM 254, APR 2018
Government clearances and is not releasable to personnel holding only a reciprocal clearance.
7. Personnel requiring COMSEC access shall be briefed in accordance with AFI 33-211(COMSEC User Requirements). NOTE: The COMSEC briefing applies only to the use and control of cryptographic equipment and specialized COMSEC publications. Additionally, cryptographic information/equipment shall be retained in a contractor facility user COMSEC account in accordance with current guidelines.
8. The Air Force program/project manager shall designate the number of personnel requiring COMSEC access. The number will be limited to the minimum necessary and will be on a strict need-to-know basis.
9. When COMSEC support, including STU III, is provided by an AF COMSEC Account, the contractor must comply with AFI 33-211 and
AFI 33-209.
10. COMSEC information includes accountable or non-accountable COMSEC information and controlled cryptographic items (CCI). If accountable COMSEC material is involved, the Visitor Group must have a COMSEC account. NOTE: COMSEC custodians are DAF civilians or military members. Visitor Groups are considered hand receipt holders.
11. Classified COMSEC material is not releasable to Visitor Group employees who have not received a FINAL clearance at the appropriate security level. COMSEC access shall be IAW DoD 5220.22-M. When access is required at Government facilities, Visitor Group personnel will adhere to COMSEC rules and regulations as mandated by Command policy and procedures. Prior written approval from the CO is required in order for a prime Visitor Group to grant COMSEC access to a subcontracting Visitor Group.
Ref. 10.b.: Restricted Data (RD) Information:
Policy: DoDM 5200.01, Vol 1-3 Information Security Program; DoDI 5210.02, Access To and Dissemination of Restricted Data and Formerly Restricted Data
1) Contractor is permitted access to Restricted Data (RD) in performance of this contract. CONFIDENTIAL security clearance eligibility is not valid for access to Restricted Data. Contractors must comply with all instructions and guidance provided by the servicing AF Activity Security Manager. Prior approval of the contracting activity is required for subcontracting.
2) Definitions:
a) Restricted Data (RD). Information which is classified and controlled under the Atomic Energy Act of 1954. It is all data (information) concerning design, manufacture, or utilization of atomic weapons; the production of special nuclear material; or the use of special nuclear material in production of energy. The term does not include data declassified or removed from the Restricted Data category pursuant to section 142 of the Atomic Energy Act of 1954, as amended (reference (b)). (Also see “Formerly Restricted Data.”)
b) Access. Within and between DoD Components, to include contractor activities, access to Restricted Data (RD) information will be governed by the same procedures and criteria required for access to other classified information:
i) Require access in performance of official duties.
ii) Have a final US Government security clearance at a level commensurate with the information concerned.
iii) Access requires in-brief by the servicing AF Activity Security Assistant, documentation of AF Form 2583, and indoctrination via the Defense Information System for Security (DISS).
iv) Requests for access to Restricted Data in the possession of the DOE or other Federal Agencies designated by the Department of Energy (DOE), other than the Department of Defense and NASA, are submitted via DOE Form 277, Request for Visit or Access Approval. (Refer to DoDD 5210.2 for further information.)
c) Dissemination. Restricted Data dissemination will be governed by the same procedures and criteria as govern the dissemination of other classified information. DoD personnel may disseminate Restricted Data information only under the following guidelines:
i) Within and between the DoD Components, to include DoD contractors.
ii) To properly cleared Department of Energy (DOE) personnel and to DOE-cleared personnel of other Federal Agencies.
iii) Restricted Data information pertaining only to nuclear research reactors or nuclear electric power generating reactors may be made to Nuclear Regulatory Commission (NRC) personnel, i.e., DoD, State Department, NASA, etc. Restricted Data not related to these reactors may be released to NRC personnel only through the DOE.
iv) Restricted Data information other than that pertaining to aeronautical and space activities may be released to NASA personnel only through the DOE.
v) In all above cases, dissemination of Restricted Data information will be made only after the holder of the information has verified:
(a) Identification of the prospective recipient
(b) The validity of the prospective recipient’s security clearance (via DISS)
(c) The “need-to-know” of the prospective recipient in connection with official duties
3) Dissemination of Restricted Data (and Formerly Restricted Data) to any nation or regional defense organization, or to a representative
PREVIOUS EDITION IS OBSOLETE. Page 5 of 12DD FORM 254, APR 2018 thereof, is prohibited; except in accordance with agreements for cooperation, entered into pursuant to section 123 of the Atomic Energy Act of 1954, as amended (reference (b)).
4) Except as provided above, Formerly Restricted Data will be treated and disseminated in the manner prescribed for classified information in DoDM 5200.01, Volume 1-4.
5) Marking. Classified information marking will be in accordance with Air Force-adopted Controlled Access Program Coordination Office (CAPCO) standardized marking guidelines. Additional classified marking guidance (including country trigraph codes) is located on the SIPRNet CAPCO page at http://capco.dssc.sgov.gov.
6) Contact your servicing AF Activity Security Assistant for additional assistance.
7) Restricted Data Information is not releasable to Visitor Group employees who have not received a FINAL clearance at the appropriate security level. Written concurrence of the CO is required prior to subcontracting. RESTRICTED DATA will be handled and controlled as indicated in the NISPOM.
Ref 10.e.(1): RELEASE OF SENSITIVE COMPARTMENTED INFORMATION (SCI) INTELLIGENCE INFORMATION TO US
CONTRACTORS
1. Requirements for access to SCI:
a) No public release of information authorized, public disclosure or confirmation of any subject related to the support contract is not authorized without first obtaining written approval from the CO.
b) Prior approval of contracting activity is required for subcontracting.
c) Access to Intelligence information requires SCI indoctrination and a final Top Secret U.S. Government clearance.
d) All SCI will be handled in accordance with special security requirements which will be furnished by the designated responsible special security office (SSO). Security Classification Guides or extracts are attached or will be provided under separate cover.
e) SCI will not be released to contractor employees without specific release approval of the originator of the material as outlined in governing directives; based on prior approval and certification of "need-to-know" by the designated contractor.
f) Contractors will not release this information to any activity or person not directly engaged in providing services under the contract or to another contractor (including subcontractors), government agency, private individual, or organization without written prior approval.
g) Intelligence material will not be released to foreign nationals or immigrant aliens who may be employed by the contractor, regardless of the level of their security clearance or access authorization, except with specific written permission.
2. The contractor will submit the request for SCI visit certifications through the CM for approval of the visit. The certification request must arrive at the Contractor Support Element at least ten (10) working days prior to the visit. Visit certification requests will be processed through Defense Information Security System (DISS).
a) Upon receipt of written approval from the CM, the company security officer will submit request(s) for special background investigations in accordance with the NISPOM, to the Intelligence Support Office. The entire personnel security questionnaire package should not be forwarded to the Intelligence Support Office. The Contractor Special Security Officer (CSSO) must follow the instructions provided by the Intelligence Support Office to the CSSO.
(1) Contractors will maintain records which will permit them to furnish, on demand, the names of individuals who have access to intelligence material in their custody.
(2) Names of contractor personnel requiring access to SCI will be submitted to the contract monitor (CM) for approval.
b) Inquiries pertaining to classification guidance on SCI will be directed through the CSSO to the responsible CM.
3. SCI furnished in support of this contract remains the property of the Department of Defense (DoD) department, agency, or command originator. Intelligence information does not become the property of the contractor and may be withdrawn at any time. Upon completion or cancellation of the contract, SCI furnished will be returned to the direct custody of the supporting SSO, or destroyed IAW instructions outlined by the CM.
a) SCI will be stored and maintained only in properly accredited facilities at the contractor location.
b) All intelligence material will bear a prohibition against reproduction while in the custody of the contractor.
c) Any reproduction and destruction of this material, regardless of the classification, is prohibited without written approval of the CM.
4. All DD Forms 254 prepared for subcontracts involving access to SCI under this contract must be forwarded to the CM for approval and then to HQ AF SSO, for review and concurrence prior to award of the subcontract.
5. The contract monitor (CM) will:
a) Review the SCI product for contract applicability and determine that the product is required by the contractor to complete contractual obligations. After the CM has reviewed the SCI product(s) for contract applicability and determined that the product is required by the contractor to complete obligations, the CM must request release from the originator through the Intelligence Division. Originator release
PREVIOUS EDITION IS OBSOLETE. Page 6 of 12DD FORM 254, APR 2018 authority is required on the product types below:
(1) Documents bearing the control markings of ORCON, PROPIN.
(2) GAMMA controlled documents.
(3) Any NSA/SPECIAL marked product.
(4) All categories as listed in USAF Intel 201-1.
b) Prepare or review contractor billet/access requests to insure satisfactory justification (need-to-know) and completeness of required information.
c) Approve and coordinate visits by contractor employees when such visits are conducted as part of the contract effort.
d) Maintain records of all SCI material provided to the contractor in support of the contract effort. By 15 January (annually), provide the contractor, for inventory purposes, with a complete list of all documents transferred by contract number, organizational control number, copy number, and document title.
e) Determine dissemination of SCI studies or materials originated or developed by the contractor.
f) Within 30 days after completion of the contract, provide written disposition instructions for all SCI material furnished to, or generated by, the contractor with an information copy to the supporting SSO.
g) Review and forward all contractor requests to process SCI electronically to the accrediting SSO for coordination through appropriate SCI channels.
6. Request for release of intelligence material to a contractor must be prepared by the contract monitor (CM) and submitted to the Intelligence Support Office. This should be accomplished as soon as possible after the contract has been awarded. The request will be prepared and accompanied with a letter explaining the requirement and copies of the DD Form 254 and Statement of Work.
Ref. 10.e.(2): RELEASE OF NON-SENSITIVE COMPARTMENTED INFORMATION (NON-SCI) INTELLIGENCE INFORMATION
TO US CONTRACTORS
1. Requirements for access to non-SCI Intelligence Information:
a. Non-SCI Intelligence Information is not releasable to contractor employees who have not received a FINAL clearance at the appropriate security level.
b. Contractors will maintain records which will permit them to furnish, on demand, the names of individuals who have access to intelligence material in their custody.
c. All intelligence material released to the contractor remains the property of the US Government and may be withdrawn at any time. The contractor must maintain accountability for all classified intelligence released in his/her custody.
d. Contractors will not release this information to any activity or person not directly engaged in providing services under the contract or to another contractor (including subcontractors), government agency, private individual, or organization without prior written approval of HAF/A4L Security Assistant and HQ USAF/SSO.
e. Upon expiration of the contract, all intelligence released and any material using data from the intelligence will be returned to the project officer or COR for final disposition.
f. Written concurrence of the CO is required prior to subcontracting.
g. All intelligence material will bear a prohibition against reproduction while in the custody of the contractor. The contractor must not reproduce intelligence material without the written permission of the originating agency through the HQ USAF/SSO. If permission is granted, each copy shall be controlled in the same manner as the original.
h. The contractor must not destroy any intelligence material without advance approval or as specified by the contract monitor (CM).
EXCEPTION: Classified waste shall be destroyed as soon as practicable in accordance with the provisions of the Industrial Security Program).
i. The contractor must restrict access to only those individuals who possess the necessary security clearance and who are actually providing services under the contract with a valid need to know. Further DISSEMINATION to other contractors, subcontractors, other government agencies, private individuals or organizations is prohibited unless authorized in writing by the originating agency through the CM.
j. The contractor must ensure each employee having access to intelligence material is fully aware of the special security requirements for this material and shall maintain records in a manner that will permit the contractor to furnish, on demand, the names of individuals who have had access to this material in their custody.
k. Intelligence material must not be released to foreign nationals or immigrant aliens whether they are consultants, US contractors, or employees of the contractor and regardless of the level of their security clearance, except with advance written permission from the originator. Requests for release to foreign nationals shall be initially forwarded to the contract monitor and shall include:
i. A copy of the proposed disclosure.
ii. Full justification reflecting the benefits to US interests.
iii. Name, nationality, particulars of clearance, and current access authorization of each proposed foreign national recipient.
l. Upon completion or termination of the classified contract, or sooner when the purpose of the release has been served, the contractor will return all classified intelligence (furnished or generated) to the source from which received unless retention or other disposition instructions are authorized in writing by the CM.
m. The contractor must designate an individual who is working on the contract as custodian. The designated custodian shall be responsible for receipting and accounting for all classified intelligence material received under this contract. This does not mean that the custodian
PREVIOUS EDITION IS OBSOLETE. Page 7 of 12DD FORM 254, APR 2018 must personally sign for all classified material. The inner wrapper of all classified material dispatched should be marked for the attention of a designated custodian and must not be opened by anyone not working directly on the contract.
n. Within 30 days after the final product is received and accepted by the procuring agency, classified intelligence materials released to or generated by the contractor, must be returned to the originating agency through the contract monitor unless written instructions authorizing destruction or retention are issued. Request to retain material shall be directed to the CM for this contract in writing and must clearly indicate the justification for retention and identity of the specific document to be retained.
o. Classification and declassification marking of documentation produced by the contractor shall be consistent with that applied to the information or documentation from which the new document was prepared. If a compilation of information or a complete analysis of a subject appears to require a security classification other than that of the source documentation, the contractor shall assign the tentative security classification and request instructions from the contract monitor. Pending final determination, the material shall be safeguarded as required for its assigned or proposed classification, whichever is higher, until the classification is changed or otherwise verified.
2. Intelligence material carries special markings. The following is a list of the authorized control markings of intelligence material:
a. "Dissemination and Extraction of Information Controlled by Originator (ORCON)." This marking is used, with a security classification to enable a continuing knowledge and supervision by the originator of the use made of the information involved. This marking may be used on intelligence which clearly identifies, or would reasonably permit ready identification of an intelligence source or method which is particularly susceptible to countermeasures that would nullify or measurably reduce its effectiveness. This marking may not be used when an item or information will reasonably be protected by use of other markings specified herein, or by the application of the “need-to-know” principle and the safeguarding procedures of the security classification system.
b. “Not Releasable to Foreign Nationals (NOFORN). ” This marking must be used with a security classification to identify intelligence that may not be released in any form to foreign governments, foreign nationals, or non-US government originator, and than only when released in compliance with the National Disclosure Policy.
c. "Authorized for Release to (Name of Country(ies) or International Organization." The above is abbreviated "REL _________." This marking must be used when it is necessary to identify classified intelligence material the US government originator has predetermined to be releasable or has been released through established foreign disclosure channels to the indicated country(ies) or organization.
3. The following procedures govern the use of control markings.
a. Any recipient desiring to use intelligence in a manner contrary to restriction established by the control marking set forth above shall obtain the advance permission of the originating agency through the CM. Such permission applies only to the specific purposes agreed to by the originator and does not automatically apply to all recipients. Originators shall ensure that prompt consideration is given to recipients' requests in these regards, with particular attention to reviewing and editing, if necessary, sanitized or paraphrased versions to derive a text suitable for release subject to lesser or no control markings.
b. The control marking authorized above shall be shown on the title page, front cover, and other applicable pages of documents, incorporated in the text of electrical communications, shown on graphics, and associated (in full or abbreviated form) with data stored or processed in automatic data processing systems. The control marking also shall be indicated by parenthetical use of the marking abbreviations at the beginning or end of the appropriate portions. If the control marking applies to several or all portions, the document must be marked with a statement to this effect rather than marking each portion individually.
c. The control markings shall be individually assigned at the time of preparation of intelligence products and used in conjunction with security classifications and other marking specified by E.O. 12958 and its implementing security directives. The marking shall be carried forward to any new format in which the same information is incorporated including oral and visual presentations.
4. Request for release of intelligence material to a contractor must be prepared by the contract monitor (CM) and submitted to the HAF/A4.
This should be accomplished as soon as possible after the contract has been awarded. The request will be prepared, explaining the requirements and copies of the DD Form 254 and Statement of Work.
Ref. 10.j: Identificaton and Protection of CUI: CONTROLLED UNCLASSIFIED INFORMATION (CUI) ADDENDUM1.
General: There are types of information that are not classified but require application of access and distribution controls and protective measures developed for DoD Controlled Unclassified Information for a variety of reasons. The types of CUI identified for the program are For Official Use Only (FOUO), Law Enforcement Sensitive (LES), DoD Unclassified Controlled Nuclear Information (DoD UCNI), and LIMITED DISTRIBUTION as well as some of those developed by other Executive Branch agencies of the U.S. Government and technical data described below as well as protective measures for CUI material.
For Official Use Only (FOUO) Information Description: Is a Government protective marking/caveat designation applied to unclassified information that may be exempt from mandatory release to the public because of foreseeable harm to an interest protected by the Freedom of Information Act (FOIA), as implemented by DoD 5400.7-R and/or the Privacy Act of 1974, as amended.
Law Enforcement Sensitive (LES): A marking sometimes applied, in addition to the marking “FOR OFFICIAL USE ONLY,” by the Department of Justice and other activities in the law enforcement community, including those within the Department of Defense to denote
PREVIOUS EDITION IS OBSOLETE. Page 8 of 12DD FORM 254, APR 2018 that the information was compiled for law enforcement purposes and should be afforded security in order to protect certain legitimate government interests. Procedures can be found in DoDI 5200.48, CUI 06 March 2020.
DoD Unclassified Controlled Nuclear Information (DoD UCNI): Unclassified information on security measures (including security plans, procedures, and equipment) for the physical protection of DoD Special Nuclear Material (SNM), SNM equipment, SNM facilities, or nuclear weapons in DoD custody. Information is designated DoD UCNI in accordance with DoDD 5210.83.
LIMITED DISTRIBUTION: Caveat used by the National Geospatial-Intelligence Agency (NGA) to identify a select group of sensitive, unclassified imagery or geospatial information and data created or distributed by NGA or information, data, and products derived from such information. DoDI 5030.59 contains details of policies and procedures.
Technical Data Description: Any recorded information related to experimental, developmental, or engineering works that can be used to define an engineering or manufacturing process, or can be used to design, procure, produce, support, maintain, operate, repair, or overhaul program material. The data may be graphic or pictorial delineations in media (e.g., computer software, drawings, photographs, etc.), text in specifications, related performance or design documents, or computer printouts. Examples of technical data include research and engineering data, engineering drawings, and associated lists, specifications, standards, process sheets, manuals, technical reports, catalog-item identifications, related information, and computer software documentation. The DoD Scientific and Technical Information Program (see DoDI 3200.12.).
CUI Markings: Prescribed marking of CUI documents will be in accordance with DoDI 5200.48, CUI 06 March 2020. CUI may also be identified in security classification guides to ensure the information receives appropriate protection.
Access: CUI may be released to an individual who has a valid need for such access within the scope of their assigned duties, furthering the accomplishment of a lawful and authorized government purpose and would not be detrimental to the interests of the DoD or U.S.
Government. Information in any media format will be disseminated on a need-to-know basis. This restricts the use or dissemination of CUI data to those with direct affiliation with the given program/project to conduct official business for the DoD, provided that dissemination is consistent with any further controls imposed by a distribution statement. Personnel no longer requiring access to CUI must surrender any information in their possession to the program lead, who will take action to terminate further access.
Storing and Handling: During working hours, take reasonable steps to minimize the risk of access to CUI by unauthorized personnel (e.g., not reading, discussing, leaving FOUO information unattended where unauthorized personnel are present or display CUI in public places to include the internet). After working hours, store CUI information in locked desks, file cabinets, bookcases, locked rooms, locked/controlled e-files or similar means to prevent theft of program information. Computers used to process CUI do not need to be accredited for classified use. Do not process CUI on public computers (e.g., those available to the public in kiosks, hotels, café’s, etc.) or computers that do not have Public Key Infrastructure (PKI) access controls. Personally owned computers are not authorized to process CUI. Authorized electronic devices provided by the government agency (e.g., laptops, cell phone) used to store CUI must be physically protected and use NIST/NIAP-approved cryptographic products, e.g., DoD approved PKI Certification available at http://iase.disa.mil/pki/eca or http://csrc.nist.gov/ cryptval/, which require encryption passcodes to teleconferences/web conferences where CUI may be discussed.
Dissemination: CUI printed documents and material may be transmitted through mail channels or hand-carried without formal courier orders. CUI information may be disseminated to DoD personnel and DoD contractors to conduct official business for the program. If dissemination is required outside of DoD channels contact the program lead, contracting officer, and security manager for approval.
Release of technical data will follow the release instructions identified in the distribution statement. Use secure communications whenever available for discussions involving CUI. Send voice and facsimile transmissions only when authorized recipients have acknowledged positive control measures are in place to receive the information.
Destruction: CUI documents shall be disposed of according to provisions of EO 13556, CUI; DoDI 5200.48, CUI 06 March 2020; AFI 33-332. Component records management directives. Non-record FOUO documents may be destroyed by any methods that prevents compromise, e.g., tearing, burning, or shredding of the means approved for the destruction of classified information or by any other means that would make it difficult to recognize or reconstruct the information.
Reporting: Report any loss or unauthorized attempt to gain access to CUI information to the organization’s security manager immediately, but no later than the end of the first duty day. If additional information is required after initial notification, guidance will be provided at that time.
Ref 10. k.: Any transfer or processing of classified or sensitive information via electronic methods (e.g. facsimile, telemetry, voice, computer) must be protected by implementing an appropriate combination of countermeasures such as encryption devices and sound practices and procedures. Specific countermeasures used must be coordinated by the project manager for approval through the appropriate communications activity.
The contract can require access to sensitive unclassified Government AIS in Categories IT-I, II, and III. At a minimum, contractor
PREVIOUS EDITION IS OBSOLETE. Page 9 of 12DD FORM 254, APR 2018 employees must be the subject of a favorable T5/Single Scope Background Investigation if granted access and performing in Category IT-I positions. For Category IT-II positions, at a minimum, contractor employees must be the subject of a favorable T3/National Agency Check and Local Agency Check. For Category III positions, contractor employees must be the subject of a favorable T1/National Agency Check with Inquiries. In the event the investigation is not adjudicated favorably, unit commanders are responsible for suitability determinations.
Reference DoDM 5200.02_AFMAN 16-1405 AF PERSEC Program. Publications can be found at http://www.e-publishing.af.mil.
SIPRNET access is required for contractors working on a government installation. A NATO awareness briefing is also required. Actual knowledge of, generation, or production of NATO information might not be required for every contractor performancing on the contract.
JWICS access is required for contractors working on a government installation.
Ref 11. IN PEFORMING THIS CONTRACT, THE CONTRACTOR WILL:
Ref 11.a.: HAVE ACCESS TO CLASSIFIED INFORMATION ONLY AT ANOTHER CONTRACTOR’S FACILITY OR A GOVERNMENT ACTIVITY. Contract performance is restricted to those locations specified in Item 8a or other approved locations as directed by the COR through tasking order. Using activity will provide security classification guidance for performance of this contract.
Ref 11.f.: The city and country of overseas performance will be provided at the time of tasking. A copy of the DD 254 must be provided to the United States Air Force Chief Information Protection (CIP) responsible for overseas inspections and security oversight. HQ USAFE/IP or HQ PACAF/IP will be provided copies of the DD 254 as applicable.
Security Clauses for International Contracts Addendum
1.All classified information and material furnished or generated pursuant to this contract shall be protected as follows:
a. The recipient will not release the information or material to a third-country government, person, or firm without the prior approval of the releasing government.
b. The recipient will afford the information and material a degree of protection equivalent to that afforded it by the releasing government;
and
c. The recipient will not use the information and material for other than the purpose for which it was furnished without the prior approval of the releasing government.
2.Classified information and material furnished or generated pursuant to this contract shall be transferred through government channels or other specified in writing by the Governments of the United States and Canada and only to persons who have an appropriate security clearance and an official need for access to the information in order to perform on the contract.
3.Classified information and material furnished under this contract will be remarked by the recipient with its government’s equivalent security classification markings.
4.Classified information and material generated under this contract must be assigned a security classification as specified by the contract security classification specifications provided with this contract.
5.All cases in which it is known or there is reason to believe that classified information or material furnished or generated pursuant to this contract has been lost or disclosed to unauthorized persons shall be reported promptly and fully by the contract to itsgovernment’s security authorities.
6.Classified information and material furnished or generated pursuant to this contract shall not be further provided to another potential contractor or subcontractor unless:
a. A potential contractor or subcontractor which is located in the United States or Canada has been approved for access to classified information and material by U.S. or Canadian security authorities; or
b. If located in a third country, prior written consent is obtained from the United States Government.
7.Upon completion of the contract, all classified material furnished or generated pursuant to the contract will be returned to the U.S.
contractor or be destroyed.
8.The recipient contractor shall insert terms that substantially conform to the language of these clauses, including this clause, in all subcontracts under this contract that involves access to classified information furnished or generated under this contract.
Ref. 11j: The contractor must comply with any OPSEC requirement/clauses indicated in the contract. On military installations the contractor will follow the installation OPSEC plan and guidance set forth in AFI 10-701, Operations Security, as supplemented. Protect Critical Information (CI) and other sensitive unclassified information and activities, which could compromise the mission or operations or degrade the planning and execution of military operations performed by the contractor in support of the mission. These OPSEC requirements pertain to performance on government installations only.
OPERATION SECURITY (OPSEC) ADDENDUM
1. This section outlines the requirements and procedures necessary for contractors to provide Operations Security (OPSEC) protection for critical information.
2. OPSEC is the process of identifying, analyzing and controlling critical information indicating friendly actions attendant to military operations and other activities to:
a. Identify those actions that can be observed by adversary intelligence systems.
b. Determine what indicators adversary intelligence systems might obtain that could be interpret or pieced together to derive critical
PREVIOUS EDITION IS OBSOLETE. Page 10 of 12DD FORM 254, APR 2018 information in time to be useful to adversaries.
c. Select and execute countermeasures that eliminate or reduce to an acceptable level the vulnerabilities of friendly actions to adversary exploitation.
3. OPSEC principles are used to help assigned personnel:
a. Maintain a continuing awareness of adversary interest in SOF actions and adversary intelligence collection capabilities.
b. To understand the need to identify and protect classified and unclassified indicators that reveal sensitive information.
c. To evaluate the effectiveness of OPSEC measures taken to preclude or reduce adversary acquisition and exploitation of sensitive information.
4. Objectives are to:
a. Protect planned operational activities by preventing the inadvertent disclosure of unclassified information relating to or revealing a possible classified operation.
b. To preserve secrecy concerning specific scenario events and aresponse to these events.
c. To identify OPSEC vulnerabilities and recommend protective measures which will serve to enhance the security of future operations.
5. Employed contractors will be provided unit-specific OPSEC education training by the assigned unit/ directorate's OPSEC program manager/coordinator on the unit/directorate's OPSEC requirements before being given full access to or around an installation, organization, facility or information, but not more than 30 days prior to initial access. Individual training will be developed and applied as required by the level of contact with critical information.
6. The contractor shall provide operation security (OPSEC) protection for all sensitive and/or critical information as defined by DoD
5205.2 and the Air Force Instruction (AFI) 10-701 and all applicable supplements.
7. The contractor shall describe the steps necessary to protect sensitive and/or critical information. The OPSEC Program Manager will evaluate the OPSEC posture of the contract activities and operations.
8. The contractor is required to follow the provisions of the organizations pre-existing OPSEC Plan. A copy of the plan (or relevant portions thereof) and the approved Critical Information List (CIL) will be provided to assigned contractors upon inprocessing so that the contractor is aware of the critical information to be protected and the OPSEC measures expected during contract performance.
9. In the event the Government agency does not require compliance with a tailored written OPSEC plan, these OPSEC measures have been prescribed:
a. Annual contractor employee OPSEC awareness briefings
b. Approval of all press releases via proper government channel prior…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .