DD254 21Q0010.pdf

PDF 323 KB Posted

Attached to
Cyber Security Services Federal contract opportunity
Solicitation number
N0025321Q0010
Issued by
Department of the Navy Naval Sea Systems Command

View the file

Other files for this federal contract opportunity

Other files attached to Cyber Security Services, newest first.
File Type Posted
N0025321Q0010 Amend3.pdf PDF
N0025321Q0010 Amend2.pdf PDF
N0025321Q0010 Amend1.pdf PDF
N0025321Q0010 RFQ.pdf PDF
21Q0010 CDRL A001 redacted.pdf PDF
21Q0010 CDRL A002 redacted.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

CLASSIFICATION (When filled in): Unclassified

PREVIOUS EDITION IS OBSOLETE. Page # of ##

AEM LiveCycle Designer

DD FORM 254, APR 2018

DEPARTMENT OF DEFENSE

CONTRACT SECURITY CLASSIFICATION SPECIFICATION

(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)

OMB No. 0704-0567 OMB approval expires:

May 31, 2022

The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.

RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.

1. CLEARANCE AND SAFEGUARDING

a. LEVEL OF FACILITY SECURITY CLEARANCE (FCL) REQUIRED

(See Instructions)

Secret

b. LEVEL OF SAFEGUARDING FOR CLASSIFIED INFORMATION/

MATERIAL REQUIRED AT CONTRACTOR FACILITY

Secret

2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)

a. PRIME CONTRACT NUMBER (See instructions.)

TBD

b. SUBCONTRACT NUMBER

c. SOLICITATION OR OTHER NUMBER DUE DATE (YYYYMMDD)

3. THIS SPECIFICATION IS: (X and complete as applicable.)

a. ORIGINAL (Complete date in all cases.)

DATE (YYYYMMDD)

20200908

b. REVISED (Supersedes all previous specifications.)

REVISION NO. DATE (YYYYMMDD)

c. FINAL (Complete Item 5 in all cases.) DATE (YYYYMMDD)

4. IS THIS A FOLLOW-ON CONTRACT? No Yes If yes, complete the following:

Classified material received or generated under (Preceding Contract Number) is transferred to this follow-on contract.

5. IS THIS A FINAL DD FORM 254? No Yes If yes, complete the following:

In response to the contractor's request dated , retention of the classified material is authorized for the period of:

6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)

a. NAME, ADDRESS, AND ZIP CODE This DD254 is for Solicitation Purposes Only. It must be returned to NUWCDIVKPT Security with a contract number and contractor's name when the contract is awarded for updating and an approval signature.

b. CAGE CODE

TBD

c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)

TBD

7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor) Add Row Remove last Row Delete All Rows

a. NAME, ADDRESS, AND ZIP CODE b. CAGE CODE c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)

8. ACTUAL PERFORMANCE (Click button to add more locations.) Add Row Remove last Row Delete All Rows

a. LOCATION(S) (For actual performance, see instructions.)

Naval Undersea Warfare Center Division Keyport Keyport, WA, United States, 98345

b. CAGE CODE (If applicable, see Instructions.)

c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)

a. LOCATION(S) (For actual performance, see instructions.)

Naval Base Kitsap Bremerton, WA, United States 98314

b. CAGE CODE (If applicable, see Instructions.)

c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)

PREVIOUS EDITION IS OBSOLETE. Page # of ##

AEM LiveCycle Designer

DD FORM 254, APR 2018

a. LOCATION(S) (For actual performance, see instructions.)

Naval Station Pearl Harbor Pearl Harbor, HI, United States 96860

b. CAGE CODE (If applicable, see Instructions.)

c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)

9. GENERAL UNCLASSIFIED DESCRIPTION OF THIS PROCUREMENT

Naval Undersea Warfare Center (NUWC) Division Keyport requires contractor support in processing the Risk Management Framework RMF system accreditation package for the NUWC Keyport Secret Defense Research Engineering Network (KPT SDREN) system. KPT SDREN is a secure information network that provides connectivity to other nodes on High Performance Computing Modernization Program's (HPCMP) SDREN. System environments consist of a collection of like or similar computers, which main network connections are comprised of Ethernet switches and routers connected together over fiber optic, twisted pair cable utilizing authorized National Security Agency (NSA) Type 1 approved encryption devices. The majority of servers are virtualized using VMware products and virtual desktops are accessed through thin clients. The network and associated system environments operates at the System High Security mode of operation and at the Secret Classification.

10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)

a. COMMUNICATIONS SECURITY (COMSEC) INFORMATION f. SPECIAL ACCESS PROGRAM (SAP) INFORMATION

b. RESTRICTED DATA g. NORTH ATLANTIC TREATY ORGANIZATION

(NATO) INFORMATION

c. CRITICAL NUCLEAR WEAPON DESIGN INFORMATION (CNWDI) (If CNWDI applies, RESTRICTED DATA must also be marked.) h. FOREIGN GOVERMENT INFORMATION

d. FORMERLY RESTRICTED DATA i. ALTERNATIVE COMPENSATORY CONTROL MEASURES

(ACCM) INFORMATION

e. NATIONAL INTELLIGENCE INFORMATION:

(1) Sensitive Compartmented Information (SCI)

(2) Non-SCI

j. CONTROLLED UNCLASSIFIED INFORMATION (CUI) (See instructions.)

k. OTHER (Specify) (See instructions.)

Have access to SIPRNET & SDREN

11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)

a. HAVE ACCESS TO CLASSIFIED INFORMATION ONLY AT

ANOTHER CONTRACTOR'S FACILITY OR A GOVERNMENT

ACTIVITY

(Applicable only if there is no access or storage required at contractor facility.

See instructions.)

b. RECEIVE AND STORE CLASSIFIED DOCUMENTS ONLY

c. RECEIVE, STORE, AND GENERATE CLASSIFIED

INFORMATION OR MATERIAL

d. FABRICATE, MODIFY, OR STORE CLASSIFIED HARDWARE

e. PERFORM SERVICES ONLY

f. HAVE ACCESS TO U.S. CLASSIFIED INFORMATION OUTSIDE

THE U.S.,PUERTO RICO, U.S. POSSESSIONS AND TRUST

TERRITORIES

g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE

TECHNICAL INFORMATION CENTER (DTIC) OR OTHER

SECONDARY DISTRIBUTION CENTER

h. REQUIRE A COMSEC ACCOUNT

i. HAVE A TEMPEST REQUIREMENT

j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS

k. BE AUTHORIZED TO USE DEFENSE COURIER SERVICE

l. RECEIVE, STORE, OR GENERATE CONTROLLED UNCLASSIFIED

INFORMATION (CUI).

(DoD Components: refer to DoDM 5200.01, Volume 4 only for specific CUI protection requirements. Non-DoD Components: see instructions.)

m. OTHER (Specify) (See instructions.)

Access to Government Information Systems.

12. PUBLIC RELEASE

Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority.

Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)

DIRECT THROUGH (Specify below)

Commander, Naval Undersea Warfare Center Division, Keyport, (Attn: PAO), 610 Dowell Street, Keyport WA 98345-7610

Public Release Authority:

Phone: (360) 396-2699 Email: KYPT_PAO@navy.mil

13. SECURITY GUIDANCE Add Signature Remove last Signature Delete All Signatures

PREVIOUS EDITION IS OBSOLETE. Page # of ##

AEM LiveCycle Designer

DD FORM 254, APR 2018

The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract;

and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.

(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)

•Item 10.g: Access to NATO information is not required for performance of this contract. However, access to the SIPRNET is required and current regulations require a NATO briefing prior to SIPRNET access and requires a final U.S. Government clearance, at the appropriate level prior to access. A representative of the U.S. Government will brief the Facility Security Officer, who will in turn brief the contractor's personnel requiring access under this contract per DoD 5220.22-M (NISPOM) (10-0706). Written approval of government Contracting Officer is required prior to subcontracting, for each subcontractor. Additional guidance for the protection of NATO information is included in Item 14.

•Item 10.j: Controlled Unclassified Information (CUI) must be protected per DoDI 5200.48 Controlled Unclassified Information as specified in the CUI protection clause in the contract. It is emphasized that unencrypted transmission of CUI via the Internet is strictly prohibited. Amplifying guidance is provided in Block 14.

•Item 10.k: SIPRNET: Access to NATO information is NOT required for performance of this contract. Access to the SIPRNET is required and current regulations require a NATO briefing and annual derivative classifier training prior to SIPRNET access. Access to SIPIRNET requires a final U.S. Government clearance, at the appropriate level, prior to access.

•Item 11.c: Classified information will be safeguarded in accordance with the classification guidance identified in the source material, including DoD 5220.22-M, National Industrial Security Program Operating Manual. The contractor requires access to classified source data up to and including the level of Secret. Classified material generated in support of this contract shall be classified in per its source material or SCG. SDREN information systems is accredited by the Cognizant Security Agency (CSA) prior to processing classified information associated with this contract. Additionally, any classified information generated in performance of this contract shall be classified according to the markings shown on the source material and marked accordingly, to include Distribution Statements, Warning Notices, and Destruction Notices. All classified information received is the property of the US Government. Classified information shall be processed for appropriate disposition per DoD 5220.22-M (NISPOM), paragraph 5-700, upon contract closure. Artifacts supporting SDREN accreditation will be created and or modified. No material related to this effort will be stored outside NUWC Division, Keyport (B1003, RM130) and/or classified eMASS system.

• Item 11.j: Operations Security (OPSEC) requirements: Contractor personnel are subject to applicable provisions of NUWCDIVKPT

3432.1 OPSEC Program. Operations Security (OPSEC) requirements. CUI correspondence transmitted internally on the contractor's unclassified networks or information systems, and externally, shall be protected per NIST SP-800-171, Protecting Controlled Unclassified Information in Non-federal Systems and Organizations. Contractor personnel supporting this task order must complete annual government-provided OPSEC awareness training. Contractor personnel will have access to government Critical Information (CI) and Indicators and Observables that may indirectly disclose CI. CI includes, but is not limited to: Ship movements and schedules, weapons and sensor system installations, capabilities, and configurations; specific platform installations and characteristics, test schedules, deficiencies and vulnerabilities. Indicators and Observables may include, but are not limited to: Outdoors system testing; ship's external hull or superstructure modifications; shipboard equipment, ordnance, weapons, fuels, and/or stores loading/unloading operations, and/or personnel or aircraft embarkation. No CI, Indicators, or Observables may be divulged to third parties (including other company employees who are not subject to this contract) without approval of the local command Security Officer, OPSEC Officer, or the NUWC Keyport OPSEC Program Manager.

• Item 11.l and 11.m: Personnel accessing Government IT systems in the performance of contract work must meet the requirements of SECNAVINST 5510.30C, "DON Personnel Security Program." In performance of this contract personnel require a sensitivity level of Non Critical Sensitive and possibly up to Critical Sensitive, the type of background investigation (BI) requirement will be a favorably adjudicated T3/T5 or reinvestigation equivalent T3R/T5R. Additionally, per DOD Manual 8570-1 M (Change 3): C2.3.8 Contractor personnel supporting IA functions shall obtain the appropriate DOD-approved IA baseline certification prior to being engaged. Additional training on local or system operating systems or procedures must be met within 6 months of engagement. C3.2.3.3 Contract personnel must comply with the DOD and Vendor CEU requirements to maintain their IA baseline certification. Tables C3.T4, C3.T5, Paragraphs C7 .3.4 and AP3.1.5, performance requirements will be set at the Information Assurance Technical (IAT) level II and all training and certification specification are required to be met for any contracted employee. Secretary of Navy Manual (SECNAVMAN) SECNAVMAN 5239.21A Workforce Management Manual provides additional amplifying policy and requirements.

List of Attachments (All Files Must be attached Prior to Signing, i.e., for any digital signature on the form) Show Attachment Bar

PREVIOUS EDITION IS OBSOLETE. Page # of ##

AEM LiveCycle Designer

DD FORM 254, APR 2018

Naval Undersea Warfare Center Division Keyport 610 Dowell St. Code 104 Keyport, WA 98345-7610

NAME & TITLE OF REVIEWING OFFICIAL

Bryan Wilkins Information Technology

SIGNATURE

Naval Undersea Warfare Center Division Keyport 610 Dowell St. Code 105 Keyport, WA 98345-7610

NAME & TITLE OF REVIEWING OFFICIAL

Amy Abbott Security Specialist - OPSEC Program

SIGNATURE

14. ADDITIONAL SECURITY REQUIREMENTS

Requirements, in addition to NISPOM requirements for classified information, are established for this contract.

No Yes If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted.

(See instructions for additional guidance or use of the fillable PDF.)

14. ADDITIONAL SECURITY REQUIREMENTS: Contractor employees embedded in government work spaces will be included in the command security education program per SECNAV M-5510.36B (11-4.2.a) and must complete prescribed DoD/DoN training requirements.

Contractor employees shall review each NUWCDIVKPT Security Training Bulletin online at the training website. Embedded employees with a Secret or above security clearance must annually attend a locally provided NCIS counterintelligence briefing. Derivative classifiers (i.e., those who create new documents, including e-mails, based on existing classification guidance) shall receive training in derivative classification as required by DoDM 5200.01 V-1 with an emphasis on avoiding over-classification, at least once every 2 years. Training is available on the Total Workforce Development System or Defense Counterintelligence Security Agency website.

• All classified documents must be destroyed using a national security agency (NSA) approved high Security crosscut shredder listed on the NSA/CSS evaluated products list for high security crosscut paper shredders, or other APPROVED method by the Command Security Officer for destroying classified information.

CONTROLLED UNCLASSIFIED INFORMATION (INCLUDES FOR OFFICIAL USE ONLY INFORMATION)

Ref: (a) DoD Instruction 5200.48 Controlled Unclassified Information

(b) SECNAV M-5510.36B, DON Information Security Program Manual

1. Handling/Storage: Access to FOUO is limited to those needing it to conduct official business for the Department of Defense (DoD).

FOUO information is not classified information, but requires extra precautions to ensure it is not released to the public. During business hours, reasonable steps shall be taken to minimize risk of access by unauthorized personnel. After business hours, FOUO information shall be stored in unlocked containers, desks, or cabinets if Government or Government-contracted building security is provided. If it is not, store in locked desks, file cabinets, bookcases, locked rooms, or similar items.

2. Transporting/Transmitting/Release/Destruction: FOUO information shall be transported in a manner that prevents disclosure of the contents. FOUO information may be sent via USPS first-class mail, parcel post, or – for bulk shipments – 4th class mail. Electronic transmission of FOUO information (voice, data, or facsimile) shall be by approved secure communications systems. Transmission via unsecure fax is acceptable if an authorized person is standing by on the receiving end to take custody. All emails containing FOUO or attachments with FOUO must be digitally signed and encrypted when transmitted within a Navy network or to an approved contractor email address. Transmission of FOUO (i.e. any CUI) to personal email accounts (e.g. AOL, Yahoo, Hotmail, Comcast, etc.) is strictly prohibited.

FOUO sent out of the contractor’s facility electronically must be encrypted (DoD FIPS 140-2 standard). FOUO material shall not be released outside the contractor’s facility except to representatives of DoD. When no longer needed, destroy FOUO by a method that precludes its disclosure to unauthorized individuals.

3. Markings: Unclassified documents (paper or electronic) generated in support of this contract which contain FOUO are to be marked “For Official Use Only” at the bottom on the outside of the front cover (if any), on each page containing FOUO information, and on the outside of the back cover (if any). Each paragraph containing FOUO information shall be marked as such. Within a classified document, an individual page with both FOUO and classified information shall be marked at the top and bottom with the highest security classification of information appearing on the page. Individual paragraphs shall be marked at the appropriate classification level, as well as unclassified or FOUO, as appropriate. Within a classified document, an individual page that contains FOUO information but no classified information shall be marked “For Official Use Only” at the top and bottom of the page, as well as each paragraph that contains FOUO information. Other records, such as photographs, films, tapes, or slides, shall be marked “For Official Use Only” or “FOUO” in a manner that ensures that a recipient or viewer is aware of the status of the information therein. DS on technical documents identify access restrictions. DS “B” through “D” preclude public release and while not marked as FOUO, are subject to all FOUO protection requirements, including the prohibition on unencrypted transmission over the public Internet.

PRIVACY ACT INFORMATION

Contractor will adhere to FARS Clauses: 52.224-1 & 52.224-2. Specifically as Follows: Privacy Act Notification (Apr 1984) - The Contractor will be required to design, develop, or operate a system of records on individuals, to accomplish an agency function subject to the Privacy Act of 197 4, Public Law 93-579, December 31, 1974 (5 U.S.C.552a) and applicable agency regulations. Violation of the Act may

PREVIOUS EDITION IS OBSOLETE. Page # of ##

AEM LiveCycle Designer

DD FORM 254, APR 2018

involve the imposition of criminal penalties. The Contractor agrees to --(1) Comply with the Privacy Act of 1974 (the Act) and the agency rules and regulations issued under the Act in the design, development, or operation of any system of records on individuals to accomplish an agency function when the contract specifically identifies - (i) The systems of records; and (ii) The design, development, or operation work that the contractor is to perform; (2) Include the Privacy Act notification contained in this contract in every solicitation and resulting subcontract and in every subcontract awarded without a solicitation, when the work statement in the proposed subcontract requires the redesign, development, or operation of a system of records on individuals that is subject to the Act; and (3) Include this clause, including this subparagraph (3), in all subcontracts awarded under this contract which requires the design, development, or operation of such a system of records. (b) In the event of violations of the Act, a civil action may be brought against the agency involved when the violation concerns the design, development, or operation of a system of records on individuals to accomplish an agency function, and criminal penalties may be Imposed upon the officers or employees of the agency when the violation concerns the operation of a system of records on individuals to accomplish an agency function. For purposes of the Act, when the contract is for the operation of a system of records on individuals to accomplish an agency function, the Contractor is considered to be an employee of the agency. (c) (1) "Operation of a system of records," as used in this clause, means performance of any of the activities associated with maintaining the system of records, including the collection, use, and dissemination of records. (2) "Record," as used in this clause, means any item, collection, or grouping of information about an individual that is maintained by an agency, including, but not limited to, education, financial transactions, medical history, and criminal or employment history and that contains the person's name, or the identifying number, symbol, or other identifying particular assigned to the individual, such as a fingerprint or voice-print or a photograph. (3) "System of records on individuals," as used in this clause, means a group of any records under the control of any agency from which information is retrieved by the name of the individual or by some identifying number, symbol, or other identifying particular assigned to the individual.

• All reports of contractor security violations associated with this contract shall be mailed by the Cognizant DSS field office directly to the certifying official in block 16 of this DD254.

• All classified information involved in security incidents shall be retained and provided to the certifying official in block 16 (a) of this DD 254 for classification review.

• All security aspects of this contract fall under the cognizance of NUWC Keyport WA Command. Contact the NUWC Keyport Security Contracting Officer for any questions regarding the content of the DD form 254.

• Policy - All Personal Electronic Devices or equipment capable of recording, storing, transmitting, or exporting data such as photographic images or audible information of any kind are strictly prohibited in any NUWC Division, Keyport areas where classified, U-NNPI, or other CUI is exposed, processed, Or discussed. Electronic devices with these capabilities, are NOT authorized at any time in secure rooms, controlled access areas, classified conference rooms, or where classified information is processed, stored, or discussed.

• Classified or unclassified technical papers to be presented at classified symposiums must be approved by the Contracting Officer’s Representative PRIOR TO presentation.

• All contractor requests for sharing of classified and other sensitive information between prime contractors must be forwarded in writing to the government security office identified in Item 16.d of this DD254 for approval.

• Copies of all subcontract DD254s must be provided to the government security office identified in Item 16.d of this DD254.

• Security Classification Guides (OPNAVINST 5513 Series) and unclassified limited distribution documents (e.g. FOUO, Distribution Statement Controlled) are not authorized for public release; therefore, they cannot be posted on a publicly accessible web server or transmitted over the Internet unless appropriately encrypted to current DoD standards. Requests for public release cannot be transmitted via the Internet until the contractor receives final approval from the government.

• Per the requirements stated in the National Industrial Security Program Operation Manual (NISPOM) Dated February 2006, Chapter 5, Section 5, Paragraph 5-502, the Facility Security Officer (FSO) on the prime contract is authorized to flow down access to each subcontractor. It is the prime contractor FSO’s responsibility to ensure that all subcontractors have the appropriate access levels. It is also the prime contractor FSO’s responsibility to ensure that they have documented paperwork for each subcontract. If the current prime contractor FSO is replaced, it is the responsibility of the new FSO to inform NUWC Division Keyport in writing to security and the COR.

SECURITY INSTRUCTIONS AND DIRECTIVES: The following security instructions and directives are provided for informational purposes:

A. Cybersecurity Directives.

(1) DoDI 8500.01, Cybersecurity

b. Physical Security Directives.

PREVIOUS EDITION IS OBSOLETE. Page # of ##

AEM LiveCycle Designer

DD FORM 254, APR 2018

(1) DoD 5200.08-R, Physical Security Program

c. Industrial Security Directives.

(1) DoD 5220.22-M, National Industrial Security Program (NISPOM) Operating Manual

(2) DoDM 5220.22, National Industrial Security Program: Industrial Security Procedures for Government Activities

(3) DoDI 5220.22, National Industrial Security Program (NISP)

d. Information Security Directives.

(1) DoDM 5200.01 Vol. 1, DoD Information Security Program: Overview, Classification, and Declassification

(2) DoDM 5200.01 Vol. 2, DoD Information Security Program: Marking of Information

(3) DoDM 5200.01 Vol. 3, DoD Information Security Program: Protection of Classified Information

(4) DoDI 5200.48 Controlled Unclassified Information (CUI)

(5) SECNAV M-5510.36B, Department of the Navy Information Security Program

(6) NAVSEAINST 5510.1C, Naval Sea Systems Command Security Program Instruction

e. Personnel Security Directives.

(1) DoDI 5200.02, DoD Personnel Security Program (PSP)

(2) SECNAVINST 5510.30C, Department of the Navy Personnel Security Program

f. Privacy Act/PII Directives.

(1) OMB M-17-12, Preparing for and Responding to a Breach of Personally Identifiable Information

(2) DoDI 5400.11, DOD Privacy and Civil Liberties Programs

(3) SECNAVINST 5211.5F, Department of the Navy Privacy Program

(4) NAVSEAINST 5211.2B, Naval Sea Systems Command Privacy Program

g. Communications Security Directives.

(1) DOD Instruction 8523.01, Communications Security (COMSEC)

(2) CNSSI 4005, Safeguarding Communication Security (COMSEC) Facilities and Materials

h. Operations Security Directives.

(1) DoDDIR 5205.02E, DoD Operations Security (OPSEC) Program

(2) SECNAVINST 3070.2A, Operations Security

(3) OPNAVINST 3432.1A, Operations Security

(4) NAVSEAINST 3432.1A, Naval Sea Systems Command Operations Security Policy Instruction

(5) NAVSEAINST 2200.1A, Portable Electronic Devices Policy

i. Common Access Card (CAC) Directives.

(1) DoD Manual 1000.13, Vol. 1, DoD Identification (ID) Cards: ID Card Life-Cycle

(2) DoD Manual 1000.13, Vol. 2, DoD Identification (ID) Cards: Benefits for Members of the Uniformed Services, Their Dependents, and Other Eligible Individuals

(3) DoDI 5200.46, DoD Investigative and Adjudicative Guidance for Issuing the Common Access Card (CAC)

(4) FIPS Publication 201-2, Personal Identity Verification (PIV) of Federal Employees and Contractors

(5) CNO Ltr Ser N09N2/11U213200, DON Implementation of Homeland Security Presidential Directive

Contract Expiration Date: 29 Jul 2021

● The Contracting Officer is: Sally Buenaventura, NUWC Division, Keyport Code 023, (360) 315-3339, sally.buenaventura@navy.mil

● The Contract Specialist is: Edwin G. Donor, NUWC Division Keyport Code 023, (360) 315-5706, edwin.donor@navy.mil

● The ISSM POC is: Bryan Wilkins, NUWC Division Keyport Code 104, (360) 315-4901, bryan.l.wilkins@navy.mil

PREVIOUS EDITION IS OBSOLETE. Page # of ##

AEM LiveCycle Designer

DD FORM 254, APR 2018

● The Security Office Representative is: Ms. Daphne JC Perez, NUWC Keyport, Code 105, (360) 396-2015, daphne.perez@navy.mil

(END)

15. INSPECTIONS

Elements of this contract are outside the inspection responsibility of the CSO.

No Yes If Yes, explain and identify specific areas and government activity responsible for inspections. The field will expand as text is added or you can also use item

13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted.

(See instructions for additional guidance or use of the fillable PDF.)

16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)

a. GCA NAME

NUWC KEYPORT CONTRACTING DEPT

b. ACTIVITY ADDRESS CODE (AAC) OF THE CONTRACTING OFFICE (See Instructions)

N00253

c. ADDRESS (Include ZIP Code) Commanding Officer, Naval Undersea Warfare Center Division, Keyport - Code 023 610 Dowell St. Keyport, WA 98345

d. POC NAME

Sally Buenaventura

e. POC TELEPHONE (Include Area Code)

+1 (360) 315-3339

f. EMAIL ADDRESS (See Instructions) sally.buenaventura@navy.mil

17. CERTIFICATION AND SIGNATURES

Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below. Upon digitally signing Item 17h, no changes can be made as the form will be locked.

a. TYPED NAME OF CERTIFYING OFFICIAL (Last, First, Middle Initial) (See Instructions)

PEREZ, DAPHNE JC

b. TITLE

Security Contracting Officer

c. ADDRESS (Include ZIP Code) Commanding Officer, Naval Undersea Warfare Center Division, Keyport - Code 105 610 Dowell St. Keyport, WA 98345

d. AAC OF THE CONTRACTING OFFICE (See Instructions)

N00253

e. CAGE CODE OF THE PRIME CONTRACTOR

(See Instructions.)

f. TELEPHONE (Include Area Code)

+1 (360) 396-2015

g. EMAIL ADDRESS (See Instructions) daphne.perez@navy.mil

h. SIGNATURE

i. DATE SIGNED (See Instructions)

18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL

a. CONTRACTOR

b. SUBCONTRACTOR

c. COGNIZANT SECURITY OFFICE FOR PRIME AND

SUBCONTRACTOR

d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY

ADMINISTRATION

e. ADMINISTRATIVE CONTRACTING OFFICER

f. OTHER AS NECESSARY (If more room is needed, continue in Item 13 or on additional page if necessary.)

DRAFT

SAMPLE

PREVIOUS EDITION IS OBSOLETE.

Page of AEM LiveCycle Designer

DD FORM 254, APR 2018

NEEDS DD67

DEPARTMENT OF DEFENSE

CONTRACT SECURITY CLASSIFICATION SPECIFICATION

(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)

OMB No. 0704-0567 OMB approval expires:

May 31, 2022 The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.

RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.

1. CLEARANCE AND SAFEGUARDING

2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)

3. THIS SPECIFICATION IS: (X and complete as applicable.)

a. ORIGINAL (Complete date in all cases.)

b. REVISED (Supersedes all previous specifications.)

4. IS THIS A FOLLOW-ON CONTRACT?

If yes, complete the following:

Classified material received or generated under

5. IS THIS A FINAL DD FORM 254?

If yes, complete the following:

6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)

7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor)

8. ACTUAL PERFORMANCE (Click button to add more locations.)

10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)

e. NATIONAL INTELLIGENCE INFORMATION:

11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)

12. PUBLIC RELEASE

Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)

13. SECURITY GUIDANCE

The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.

(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)

List of Attachments (All Files Must be attached Prior to Signing, i.e., for any digital signature on the form)

14. ADDITIONAL SECURITY REQUIREMENTS

Requirements, in addition to NISPOM requirements for classified information, are established for this contract.

If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)

15. INSPECTIONS

Elements of this contract are outside the inspection responsibility of the CSO.

If Yes, explain and identify specific areas and government activity responsible for inspections. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)

16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)

17. CERTIFICATION AND SIGNATURES

Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below. Upon digitally signing Item 17h, no changes can be made as the form will be locked.

18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL

9.0.0.2.20120627.2.874785 DD 254, DoD Contract Security Classification Specification

CurrentPage:
PageCount:
Classification: Unclassified
SerialNum:
a. Facility clearance level. Select one.: 2
b. Level of safeguarding for classified information/material required at contractor facility. Select one.: 2
Choose Yes or No: 1
Choose Yes or No: 1
Prime: TBD
Choose Yes or No: 0
Choose Yes or No: 0
Sub:
Choose Yes or No: 0
Choose Yes or No: 0
Soli:
DueDate:
dateA: 20200908
RevisionNum:
dateB:
Final:
dateC:
No: 1
No: 1
No: 0
No: 1
Yes: 0
Yes: 0
Yes: 1
Yes: 0
Enter your name here.:
ReqDated:
Enter your name here.:
Name: This DD254 is for Solicitation Purposes Only. It must be returned to NUWCDIVKPT Security with a contract number and contractor's name when the contract is awarded for updating and an approval signature.
Name: PEREZ, DAPHNE JC
Cage: TBD
CSO: TBD
addrow:
Removerow:
Click to delete a row:
Location: Naval Undersea Warfare Center Division Keyport

Keyport, WA, United States, 98345 Location: Naval Base Kitsap Bremerton, WA, United States 98314 Location: Naval Station Pearl Harbor Pearl Harbor, HI, United States 96860

Block9: Naval Undersea Warfare Center (NUWC) Division Keyport requires contractor support in processing the Risk Management Framework RMF system accreditation package for the NUWC Keyport Secret Defense Research Engineering Network (KPT SDREN) system. KPT SDREN is a secure information network that provides connectivity to other nodes on High Performance Computing Modernization Program's (HPCMP) SDREN. System environments consist of a collection of like or similar computers, which main network connections are comprised of Ethernet switches and routers connected together over fiber optic, twisted pair cable utilizing authorized National Security Agency (NSA) Type 1 approved encryption devices. The majority of servers are virtualized using VMware products and virtual desktops are accessed through thin clients. The network and associated system environments operates at the System High Security mode of operation and at the Secret Classification.
a: 0
a: 0
a: 0
f: 0
f: 0
f: 0
b: 0
b: 0
b: 0
g: 1
g: 0
c: 0
c: 1
c: 0
h: 0
h: 0
d: 0
d: 0
d: 0
i: 0
i: 0
SCI: 0
NonSCI: 0
j: 1
j: 1
k: 1
k: 0
Enter your name here.: Have access to SIPRNET & SDREN
Enter your name here.: Access to Government Information Systems.
e: 0
e: 0
l: 1
m: 1
direct: 0
thru: 1
Enter your name here.: Commander, Naval Undersea Warfare Center Division, Keyport, (Attn: PAO), 610 Dowell Street, Keyport WA 98345-7610
PublicAuthority: Phone: (360) 396-2699

Email: KYPT_PAO@navy.mil

AddSig:
RemoveSig:
text:

•Item 10.g: Access to NATO information is not required for performance of this contract. However, access to the SIPRNET is required and current regulations require a NATO briefing prior to SIPRNET access and requires a final U.S. Government clearance, at the appropriate level prior to access. A representative of the U.S. Government will brief the Facility Security Officer, who will in turn brief the contractor's personnel requiring access under this contract per DoD 5220.22-M (NISPOM) (10-0706). Written approval of government Contracting Officer is required prior to subcontracting, for each subcontractor. Additional guidance for the protection of NATO information is included in Item 14.

•Item 10.j: Controlled Unclassified Information (CUI) must be protected per DoDI 5200.48 Controlled Unclassified Information as specified in the CUI protection clause in the contract. It is emphasized that unencrypted transmission of CUI via the Internet is strictly prohibited. Amplifying guidance is provided in Block 14.

•Item 10.k: SIPRNET: Access to NATO information is NOT required for performance of this contract. Access to the SIPRNET is required and current regulations require a NATO briefing and annual derivative classifier training prior to SIPRNET access. Access to SIPIRNET requires a final U.S. Government clearance, at the appropriate level, prior to access.

•Item 11.c: Classified information will be safeguarded in accordance with the classification guidance identified in the source material, including DoD 5220.22-M, National Industrial Security Program Operating Manual. The contractor requires access to classified source data up to and including the level of Secret. Classified material generated in support of this contract shall be classified in per its source material or SCG. SDREN information systems is accredited by the Cognizant Security Agency (CSA) prior to processing classified information associated with this contract. Additionally, any classified information generated in performance of this contract shall be classified according to the markings shown on the source material and marked accordingly, to include Distribution Statements, Warning Notices, and Destruction Notices. All classified information received is the property of the US Government. Classified information shall be processed for appropriate disposition per DoD 5220.22-M (NISPOM), paragraph 5-700, upon contract closure. Artifacts supporting SDREN accreditation will be created and or modified. No material related to this effort will be stored outside NUWC Division, Keyport (B1003, RM130) and/or classified eMASS system.

• Item 11.j: Operations Security (OPSEC) requirements: Contractor personnel are subject to applicable provisions of NUWCDIVKPT 3432.1 OPSEC Program. Operations Security (OPSEC) requirements. CUI correspondence transmitted internally on the contractor's unclassified networks or information systems, and externally, shall be protected per NIST SP-800-171, Protecting Controlled Unclassified Information in Non-federal Systems and Organizations. Contractor personnel supporting this task order must complete annual government- provided OPSEC awareness training. Contractor personnel will have access to government Critical Information (CI) and Indicators and Observables that may indirectly disclose CI. CI includes, but is not limited to: Ship movements and schedules, weapons and sensor system installations, capabilities, and configurations; specific platform installations and characteristics, test schedules, deficiencies and vulnerabilities. Indicators and Observables may include, but are not limited to: Outdoors system testing; ship's external hull or superstructure modifications; shipboard equipment, ordnance, weapons, fuels, and/or stores loading/unloading operations, and/or personnel or aircraft embarkation. No CI, Indicators, or Observables may be divulged to third parties (including other company employees who are not subject to this contract) without approval of the local command Security Officer, OPSEC Officer, or the NUWC Keyport OPSEC Program Manager.

• Item 11.l and 11.m: Personnel accessing Government IT systems in the performance of contract work must meet the requirements of SECNAVINST 5510.30C, "DON Personnel Security Program." In performance of this contract personnel require a sensitivity level of Non Critical Sensitive and possibly up to Critical Sensitive, the type of background investigation (BI) requirement will be a favorably adjudicated T3/T5 or reinvestigation equivalent T3R/T5R. Additionally, per DOD Manual 8570-1 M (Change 3): C2.3.8 Contractor personnel supporting IA functions shall obtain the appropriate DOD-approved IA baseline certification prior to being engaged. Additional training on local or system operating systems or procedures must be met within 6 months of engagement. C3.2.3.3 Contract personnel must comply with the DOD and Vendor CEU requirements to maintain their IA baseline certification. Tables C3.T4, C3.T5, Paragraphs C7 .3.4 and AP3.1.5, performance requirements will be set at the Information Assurance Technical (IAT) level II and all training and certification specification are required to be met for any contracted employee. Secretary of Navy Manual (SECNAVMAN) SECNAVMAN 5239.21A Workforce Management Manual provides additional amplifying policy and requirements.

text: Naval Undersea Warfare Center Division Keyport 610 Dowell St. Code 104 Keyport, WA 98345-7610 text: Naval Undersea Warfare Center Division Keyport 610 Dowell St. Code 105 Keyport, WA 98345-7610

Click on this button to attach a file(s).:
rep: Bryan Wilkins

Information Technology rep: Amy Abbott Security Specialist - OPSEC Program

Sig:
Enter your name here.: 14. ADDITIONAL SECURITY REQUIREMENTS: Contractor employees embedded in government work spaces will be included in the command security education program per SECNAV M-5510.36B (11-4.2.a) and must complete prescribed DoD/DoN training requirements. Contractor employees shall review each NUWCDIVKPT Security Training Bulletin online at the training website. Embedded employees with a Secret or above security clearance must annually attend a locally provided NCIS counterintelligence briefing. Derivative classifiers (i.e., those who create new documents, including e-mails, based on existing classification guidance) shall receive training in derivative classification as required by DoDM 5200.01 V-1 with an emphasis on avoiding over-classification, at least once every 2 years. Training is available on the Total Workforce Development System or Defense Counterintelligence Security Agency website.

• All classified documents must be destroyed using a national security agency (NSA) approved high Security crosscut shredder listed on the NSA/CSS evaluated products list for high security crosscut paper shredders, or other APPROVED method by the Command Security Officer for destroying classified information.

CONTROLLED UNCLASSIFIED INFORMATION (INCLUDES FOR OFFICIAL USE ONLY INFORMATION)

Ref: (a) DoD Instruction 5200.48 Controlled Unclassified Information

(b) SECNAV M-5510.36B, DON Information Security Program Manual

1. Handling/Storage: Access to FOUO is limited to those needing it to conduct official business for the Department of Defense (DoD). FOUO information is not classified information, but requires extra precautions to ensure it is not released to the public. During business hours, reasonable steps shall be taken to minimize risk of access by unauthorized personnel. After business hours, FOUO information shall be stored in unlocked containers, desks, or cabinets if Government or Government-contracted building security is provided. If it is not, store in locked desks, file cabinets, bookcases, locked rooms, or similar items.

2. Transporting/Transmitting/Release/Destruction: FOUO information shall be transported in a manner that prevents disclosure of the contents. FOUO information may be sent via USPS first-class mail, parcel post, or – for bulk shipments – 4th class mail. Electronic transmission of FOUO information (voice, data, or facsimile) shall be by approved secure communications systems. Transmission via unsecure fax is acceptable if an authorized person is standing by on the receiving end to take custody. All emails containing FOUO or attachments with FOUO must be digitally signed and encrypted when transmitted within a Navy network or to an approved contractor email address. Transmission of FOUO (i.e. any CUI) to personal email accounts (e.g. AOL, Yahoo, Hotmail, Comcast, etc.) is strictly prohibited. FOUO sent out of the contractor’s facility electronically must be encrypted (DoD FIPS 140-2 standard). FOUO material shall not be released outside the contractor’s facility except to representatives of DoD. When no longer needed, destroy FOUO by a method that precludes its disclosure to unauthorized individuals.

3. Markings: Unclassified documents (paper or electronic) generated in support of this contract which contain FOUO are to be marked “For Official Use Only” at the bottom on the outside of the front cover (if any), on each page containing FOUO information, and on the outside of the back cover (if any). Each paragraph containing FOUO information shall be marked as such. Within a classified document, an individual page with both FOUO and classified information shall be marked at the top and bottom with the highest security classification of information appearing on the page. Individual paragraphs shall be marked at the appropriate classification level, as well as unclassified or FOUO, as appropriate. Within a classified document, an individual page that contains FOUO information but no classified information shall be marked “For Official Use Only” at the top and bottom of the page, as well as each paragraph that contains FOUO information.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .