DD254_MTIO Special Projects.pdf
PDF 208 KB Posted
- Attached to
- Market Technology Integration Office (MTIO) Special Projects Federal contract opportunity
- Solicitation number
- HT001124R0069
- Issued by
- Defense Health Agency
About this file
This document is a DD Form 254, "Department of Defense Contract Security Classification Specification", which provides security requirements and guidance for a classified government contract. The contract is for Market Technology Integration Office (MTIO) Special Projects, and requires access to classified data up to Top Secret/SCI level. The contractor must obtain and maintain appropriate security clearances, comply with NISPOM requirements, and follow specified safeguarding procedures for protecting Controlled Unclassified Information (CUI). Access to government computer systems like NIPRNET, SIPRNET, and JWICS is also required. This is an 8(a) set-aside contract with a solicitation number of HT001124R0069. The Defense Health Agency is the contracting activity.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Questions and Answers_12Jul 2024.pdf | ||
| Questions_2 Jul 2024.xlsx | XLSX spreadsheet | |
| Amendment HT001124R0069-0001.pdf | ||
| MTIO Combined Synopsis-Solicitation HT001124R0069.pdf | ||
| DD1423-1 Consolidated MTIO Special Projects.pdf | ||
| Atch 5 Addendum to 52.212-1 and 52.212-2.pdf | ||
| MTIO Combined Synopsis-Solicitation HT001124R0069.pdf | ||
| PWS - FY24 MTIO Special Projects Final_21May2024.docx | DOCX document | |
| 09 - QASP MTIO Special Projects.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
CLASSIFICATION (When filled in): Unclassified
PREVIOUS EDITION IS OBSOLETE. Page 1 of 8DD FORM 254, APR 2018
DEPARTMENT OF DEFENSE
CONTRACT SECURITY CLASSIFICATION SPECIFICATION
(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)
OMB No. 0704-0567 OMB approval expires:
June 30, 2025
The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.
RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.
1. CLEARANCE AND SAFEGUARDING
a. LEVEL OF FACILITY SECURITY CLEARANCE (FCL) REQUIRED
(See Instructions)
Top Secret
b. LEVEL OF SAFEGUARDING FOR CLASSIFIED INFORMATION/
MATERIAL REQUIRED AT CONTRACTOR FACILITY
None (See instructions)
2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)
a. PRIME CONTRACT NUMBER (See instructions.)
b. SUBCONTRACT NUMBER
c. SOLICITATION OR OTHER NUMBER
HT001124R0069
DUE DATE (YYYYMMDD)
3. THIS SPECIFICATION IS: (X and complete as applicable.)
a. ORIGINAL (Complete date in all cases.)
DATE (YYYYMMDD)
20240417
b. REVISED (Supersedes all previous specifications.)
REVISION NO. DATE (YYYYMMDD)
c. FINAL (Complete Item 5 in all cases.) DATE (YYYYMMDD)
4. IS THIS A FOLLOW-ON CONTRACT? No Yes If yes, complete the following:
Classified material received or generated under (Preceding Contract Number) is transferred to this follow-on contract.
5. IS THIS A FINAL DD FORM 254? No Yes If yes, complete the following:
In response to the contractor's request dated , retention of the classified material is authorized for the period of:
6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)
a. NAME, ADDRESS, AND ZIP CODE b. CAGE CODE c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)
7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor) Add Row Remove Last Row Delete All Rows
a. NAME, ADDRESS, AND ZIP CODE b. CAGE CODE c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)
8. ACTUAL PERFORMANCE (Click button to add more locations.) Add Row Remove Last Row Delete All Rows
a. LOCATION(S) (For actual performance, see instructions.)
Defense Health Agency 7700 Arlington Blvd Falls Church, VA 22042
b. CAGE CODE (If applicable, see Instructions.)
HT0011
c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)
9. GENERAL UNCLASSIFIED DESCRIPTION OF THIS PROCUREMENT
Market Technology Integration Office (MTIO) Special Projects
PREVIOUS EDITION IS OBSOLETE. Page 2 of 8DD FORM 254, APR 2018
10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)
a. COMMUNICATIONS SECURITY (COMSEC) INFORMATION f. SPECIAL ACCESS PROGRAM (SAP) INFORMATION
b. RESTRICTED DATA g. NORTH ATLANTIC TREATY ORGANIZATION
(NATO) INFORMATION
c. CRITICAL NUCLEAR WEAPON DESIGN INFORMATION (CNWDI) (If CNWDI applies, RESTRICTED DATA must also be marked.) h. FOREIGN GOVERMENT INFORMATION
d. FORMERLY RESTRICTED DATA i. ALTERNATIVE COMPENSATORY CONTROL MEASURES
(ACCM) INFORMATION
e. NATIONAL INTELLIGENCE INFORMATION:
(1) Sensitive Compartmented Information (SCI)
(2) Non-SCI
j. CONTROLLED UNCLASSIFIED INFORMATION (CUI) (See instructions.)
k. OTHER (Specify) (See instructions.)
CAC, NIPRNet Access, SIPRNet Access, JWICS, GFE
11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)
a. HAVE ACCESS TO CLASSIFIED INFORMATION ONLY AT
ANOTHER CONTRACTOR'S FACILITY OR A GOVERNMENT
ACTIVITY
(Applicable only if there is no access or storage required at contractor facility.
See instructions.)
b. RECEIVE AND STORE CLASSIFIED DOCUMENTS ONLY
c. RECEIVE, STORE, AND GENERATE CLASSIFIED
INFORMATION OR MATERIAL
d. FABRICATE, MODIFY, OR STORE CLASSIFIED HARDWARE
e. PERFORM SERVICES ONLY
f. HAVE ACCESS TO U.S. CLASSIFIED INFORMATION OUTSIDE
THE U.S.,PUERTO RICO, U.S. POSSESSIONS AND TRUST
TERRITORIES
g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE
TECHNICAL INFORMATION CENTER (DTIC) OR OTHER
SECONDARY DISTRIBUTION CENTER
h. REQUIRE A COMSEC ACCOUNT
i. HAVE A TEMPEST REQUIREMENT
j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS
k. BE AUTHORIZED TO USE DEFENSE COURIER SERVICE
l. RECEIVE, STORE, OR GENERATE CONTROLLED UNCLASSIFIED
INFORMATION (CUI).
(DoD Components: refer to DoDI 5200.48, only for specific CUI protection requirements. Non-DoD Components: see instructions.)
m. OTHER (Specify) (See instructions.)
Authorized Government Travel; SEE Block 13
12. PUBLIC RELEASE
Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority.
Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)
DIRECT THROUGH (Specify below)
Defense Office of Prepublication and Security Review Rm. 2A534 Pentagon, Washington, DC 20301-1155
Public Release Authority:
FOIA PRENTAGON| NO PUBLIC RELEASE OF CLASSIFIED
INFROMATION AUTHORIZED
13. SECURITY GUIDANCE Add Signature Remove Last Signature Delete All Signatures
The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract;
and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.
(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)
For initial Industrial Security support, assistance, issues or contact information; the contractor should contact the DHA Industrial Security Help Desk at dha.ncr.admin-mgmt-j-1.mbx.industrialsecurity@health.mil (Unclassified Messages)
For Initial and Renewal CAC Application request(s); the contractor should contact the DHA Industrial Security Mailbox at dha.ncr.security.mbx.personnel-security-tass@health.mil (Please ensure that PII is Encrypted, Password Protected or sent via DoD Safe)
DD 254 review date: 27 February 2028 At the time of DD 254 generation:
COR: Christopher A. Combs 210-617-3238 christopher.a.combs2.civ@health.mil CO: Jeanna M. Butler 703-681-5995 jeanna.m.butler.civ@health.mil
*** Authorized CONUS Travel Locations ***
PREVIOUS EDITION IS OBSOLETE. Page 3 of 8DD FORM 254, APR 2018
REQUIRED CLEARANCE LEVEL: This contract involves access to classified data/information up to and including TOP SECRET/SCI with Yankee White clearance level. All contractor personnel performing under this contract shall possess the appropriate interim or final clearances necessary to review documents and data at the top secret level. Those who do not possess such clearance shall not receive or review any classified materials.
Other Personnel: REQUIRED CLEARANCE LEVEL (SECRET): This contract involves access to classified data/information up to and including SECRET clearance level. All contractor personnel performing under this contract shall possess the appropriate interim or final clearances necessary to review documents and data at the secret level. Those who do not possess such clearance shall not receive or review any classified materials.
SCI ACCESS
Access to intelligence information requires special briefings and a U.S. Government clearance at appropriate level TS/SCI as designated by government program manager. Cleared personnel are required to perform this service because access to classified information cannot be precluded. The contractor is not authorized to release classified information to any activity or person, including sub-contractors, without the government contract monitors written approval. Only with the expressed permission of the government contract monitor may the contractor reproduce any classified information or material classified Secret or above. TS/SCI contract performance is restricted to the OASD(HA) and DHA cleared facilities, other DoD facilities and military medical treatment facilities (MTF) as directed by the contracting officer in coordination with the COR.
Additional guidance for contractor personnel:
a. All intelligence material released to the contractor remains the property of the US Government and may be withdrawn at any time.
Contractors must maintain accountability for all classified intelligence released into their custody.
b. The contractor must not reproduce intelligence material without the written permission of the originating agency through the DWSSO. If permission is granted, each copy shall be controlled in the same manner as the original.
c. The contractor must not destroy any intelligence material without advance approval or as specified by the contract monitor (CM).
(EXCEPTION: Classified material shall be destroyed as soon as practicable in accordance with the provisions of the Industrial Security Program).
d. The contractor must restrict access to only those individuals who possess the necessary security clearance and who are providing services under the contract with a valid need to know. Further dissemination to other contractors, subcontractors, other government agencies, private individuals or organizations is prohibited unless authorized in writing by the originating agency through the CM authorized in writing by the originating agency through the CM.
GENERAL NOTES:
All provisions of 32 CFR Part 117, National Industrial Security Program Operating Manual (NISPOM) apply. Effective date is 24 Feb 2021.
NON-DISCLOSURE AGREEMENT (CNSI & CUI) All contractor personnel performing under this contract shall be required to sign and execute proprietary information non-disclosure statements for Classified National Security Information (CNSI) and Controlled Unclassified Information (CUI) {when required}. The proprietary information non-disclosure statements shall be required as part of the initial in-processing and must be executed prior to performing any work under this contract. The proprietary information non-disclosure statements will be maintained on file within the (DHA) Security Office. Contractor personnel who refuse to sign proprietary information non-disclosure statements will not be permitted to work on government contracts.
SECURITY EXECUTIVE AGENT DIRECTIVE 3 The contractor must comply with “Reporting Requirements for Personnel with Access to Classified Information or Who Hold a Sensitive Position,” along with DoD Manual 5200.02 and NISPOM. See INDUSTRIAL SECURITY LETTER (ISL) 2021-02 dated 12 August 2021 for additional information.
SECURITY EXECUTIVE AGENT DIRECTIVE 4 The contractor will comply with “National Security Adjudicative Guidelines,” which became effective on June 08, 2017. See INDUSTRIAL SECURITY LETTER (ISL) 2019-01 for additional information.
ORIGINAL CLASSIFICATION AUTHORITY Original Classification is not authorized. If the contractor believes information not currently classified, requires classification, the contractor will immediately notify the GCA.
SECURITY CLASSIFICATION GUIDANCE (SCGs) Specific SCGs, to include subsequent upgrades/revision(s), applying to classified performance on this contract, shall be provided by the Contracting Officer Representative or Technical Point of Contact, identified in Block 16, as Government Furnished Information (GFI); and shall be executed by the Contractor without obligation to modify this DD Form 254.
If additional security classification is required, contact the COR identified in Block 16.
PREVIOUS EDITION IS OBSOLETE. Page 4 of 8DD FORM 254, APR 2018
DESTRUCTION OF DoD INFORMATION The contractor must comply with on-site security procedures to dispose of DoD Information.
Destruction in the NCR is by use of approved burn bags.
AUDIO/VISUAL RECORDINGS The recording of DoD information, equipment, personnel, or facilities by any means is prohibited.
HAZARDOUS MATERIALS & WEAPONS Hazardous materials and weapons are prohibited from entry on/into government facilities to include any weapon, the possession of which, is prohibited under the laws of the state in which the facility is located (specifically Virginia, District of Columbia & Maryland). Knives with a blade length over 2.5 inches are prohibited. References:
18 U.S. Code §�930. Possession of firearms and dangerous weapons in Federal facilities https://www.law.cornell.edu/uscode/text/18/930 Title 32 - National Defense, Part 234 - CONDUCT ON THE PENTAGON RESERVATION https://www.govinfo.gov/app/details/CFR-2011-title32-vol2/CFR-2011-title32-vol2-part234/summary
SECURITY INCIDENTS The contractor will immediately report to the GCA any known or suspected incident in which government information/equipment is not properly safeguarded or has been disclosed to unauthorized persons; electronic data spills on information systems; or concerns of workplace violence.
- Notify the Facility Security Officer (FSO)
- Notify the GCA security office as appropriate (Government Security Manager).
- For Electronic Spillage, Notify the FSO, Security Manager and PENTCIRT immediately: Hotline (703) 695-CIRT(2478) to report data spills. Initial report should be UNCLASSIFIED.
- Law Enforcement needed: Notify the Pentagon Force Protection Agency: Emergency: 703.697.5555 or 911 from Office Landline; Non- Emergency Phone: 703.697.1001
ADDITIONAL SECURITY REQUIREMENTS FOR PERFORMANCE IN GOVERNMENT FACILITIES The contractor will comply with site specific security procedures and complete required security training. Additional security requirements may be imposed by the Department Of Defense imposed during the contract.
MOBILE DEVICES (Prohibited Electronic Devices (PEDs)) The introduction of mobile devices (personal or government issued) into facilities where classified information is processed, handled, stored, or discussed, is prohibited. Prohibited devices normally feature the ability to receive or transmit data, record audio/video, make cellular phone calls, and have Wi-Fi technology. Examples of prohibited devices include but are not limited to: cell phones; laptops; smart watch; camera; MP3 player. Key fobs for medical alert, motor vehicle, or home security are generally acceptable provided they have no features similar to prohibited devices. Medical devices may be acceptable but require individual assessment.
10.e.(1) SCI Requirement. Performance requiring access to or at the SCI level shall be governed by the SCI addendum titled “Release Of Sensitive Compartmented Information (SCI) Intelligence Information To Us Contractors”. Prior approval of contracting activity is required for subcontracting. Access to Intelligence information requires SCI indoctrination and a final Top Secret U.S. Government clearance.
Contractor will require access to DCID 6/1, DCID 6/6, and ICD 710. The names of contractor personnel requiring access to SCI shall be submitted to the contracting officer's representative (COR) for approval. The COR will approve and coordinate visits by contractor personnel to insure satisfactory justification.
10.e.(2) Non-SCI Intelligence. Performance requiring access to Non-SCI intelligence information shall be governed by the addendum titled “Release of Non-SCI Intelligence Information to DoD Contractors” Contractor will require access to ICD 503.
10.g. NATO Information. NATO information is the property of NATO and access is limited to representatives of NATO and its member nations unless proper NATO authority has been obtained to release outside of NATO. NATO classified information shall be safeguarded in compliance with United States Security Authority for NATO Affairs Instruction 1-07, “Implementation of North Atlantic Treaty Organization (NATO) Security Requirements,” April 5, 2007. When there is NOT a valid requirement for actual access to NATO in the SOW but potential for access exists (such as SIPRNet access) use this statement: To facilitate potential access to NATO classified information, to include NATO accredited SIPRNet terminals, all DoD military, civilian, and contractor personnel who are briefed on their responsibilities for protecting U.S. classified military information, shall also be briefed on the requirements for protecting NATO information, per Deputy Under Secretary of Defense Policy Security Memo of 5 Dec 01. Written concurrence of the Contracting Officer/ Technical Point of Contact, identified in Block 16, is required prior to subcontracting IAW 32 CFR Part 117 NISPOM 117.19(g(9). The briefing form is located here: https://www.cdse.edu/documents/toolkits-fsos/NATO_Brief.pdf.
10.j. CUI Information. Controlled Unclassified Information including Covered Defense Information (meeting the definition of 48 CFR 252.204–7012(a)) generated and/or provided under this contract shall be marked and safeguarded as specified in DoD Instruction 5200.48 Controlled Unclassified Information (CUI). Any product containing Covered Defense Information shall be assigned the appropriate distribution statement using the criteria set forth in DoDI 5230.24 Distribution Statements on Technical Documents. All Covered Defense Information (CDI), and program Controlled Unclassified Information (CUI) data transmitted and safeguarded via electronic means shall
PREVIOUS EDITION IS OBSOLETE. Page 5 of 8DD FORM 254, APR 2018 use approved encryption. The Freedom of Information Act applies.
10.k. Other: Performance in Government Facilities. This contract requires personnel to perform work in direct support of the DHA staff and will require individuals to work within Government controlled facilities. All contractor personnel under this contract who have access to classified information must possess a U.S. clearance. The Contract Monitor will provide security classification guidance for the performance of this contract.
In and Out Processing: This contract requires personnel to perform work in direct support of, the DHA staff and will require individuals to obtain and maintain government issued building access cards to enable performance within Government controlled facilities. As such, all contractor personnel are required to in-process with the Administration Directorate prior to reporting for work. As a condition of this contract, all personnel issued government access cards are required to ensure the card is returned to the DHA Security Office upon removal from the contract or termination of employment under this contract.
10.k. Other: Common Access Cards. This contract requires personnel to obtain the Government issued Common Access Card (CAC) in order to provide identification for access government computer systems and physical access to facilities. Personnel must meet and maintain investigative and adjudicative requirements specified in DoDI 5200.46, and immediately report to the GCA any issues affecting CAC eligibility. Government issued credentials are the property of the United States Government and must be returned when no longer required for performance on this contract. Return CACs to: DHA Security Office. CACs will not be used to access information systems, facilities, or installations that are outside the performance requirements of this contract. CACs will be used only by the individual to whom it was issued and will not be used for or by any other person. The contractor will immediately notify the GCA if a CAC is lost, stolen, or otherwise missing. Replacement CACs will require the contractor employee to obtain a signed memo from the DHA Security Office, requesting a new CAC be issued.
10.k. Other: NIPRNET access required. This contract requires the contractor to access and use the Unclassified government computer system known as the NIPRNET at locations identified by the government customer. All provisions of DoD Risk Management Framework (RMF) apply. This system is Unclassified only, and inappropriate or improper use of the system will result in a reportable incident to the DCSA. NIPRNET as well as other unclassified systems or equipment (e.g. printers, facsimile) will not be used to process classified information. NIPRNET systems will be used only for an official Government purpose. Inappropriate or improper use of the NIPRNET system will result in a reportable incident to the Defense Counterintelligence and Security Agency (DCSA).
10.k. Other: SIPRNET access required. This contract requires the contractor to access and use the Classified government computer system known as the SIPRNET at locations identified by the government customer. All provisions of DoD Risk Management Framework (RMF) apply. This system is authorized for use to but not exceeding the Secret-level only, and inappropriate or improper use of the system will result in a reportable incident to the Defense Intelligence Agency (DIA).
10.k. Other: JWICS access required. This contract requires the contractor to access and use the classified government computer system known as JWICS at locations identified by the government customer. All provisions of DoD Information Technology Security Certification and Accreditation Process (DITSCAP) apply. This system is authorized for use to but not exceeding the Top Secret level only and inappropriate or improper use of the system will result in a reportable incident to DCSA.
DERIVATIVE CLASSIFICATION training is required as a condition of access to SIPRNET. The contractor will maintain training certificates and provide copies to the GCA when requested. Annual training is required.
11.a. Have access to classified information ONLY at another contractor’s facility OR at a government activity. All classified information/ material shall be provided by the contractor facility or Government Contracting Activity (GCA) and safeguarded at the approved actual performance site.
11j. The contractor shall comply with OPSEC requirements specified in DoD 5220-22-M, National Industrial Security Program Operating Manual (NISPOM). OPSEC requirements are applicable to the contractor’s SAP procedures but only if specified by the SAP Program Office.
11.l. Receive, Store or Generate CUI Information. Controlled Unclassified Information under this contract shall be safeguarded as specified in DoDI 5200.48, "DoD Controlled Unclassified Information (CUI)". Contractor will have access to unclassified information requiring safeguarding and dissemination control in alignment with specific laws, regulations, or government-wide policies (Formerly identified as For Official Use Only (FOUO), Privacy Act information, Sensitive but Unclassified, or Law Enforcement Sensitive). Contractor shall follow the safeguarding requirements in DoDI 5200.48. DoDM 5400.07, DoD Freedom of Information Act Program applies. Legacy marked U//FOUO must be protected in the same manner as CUI until it is decontrolled.
11m. SEE BLOCK 13
PREVIOUS EDITION IS OBSOLETE. Page 6 of 8DD FORM 254, APR 2018
Government Travel. As required by the Government Program Manager, contractors will be authorized travel/Temporary Duty (TDY) outside the NCR region for official government business. Note that if 11c is marked yes then 1b must have level of storage at contract facility. The government program manager will provide travel orders and direction prior to departure; contractors will require anti-terrorism and force protection briefings as well.
CUI REQUIREMENTS FOR DOD CONTRACTORS
The following procedures will be used to protect Controlled Unclassified Information (CUI) documents and materials:
1) HANDLING: Access to CUI material shall be limited to those employees needing the material to perform their duties. The CUI marking is assigned to documents and material created by a DoD User Agency. CUI is not a classification, but requires extra precautions to ensure it’s properly safeguarded and disseminated and is not released to the public without government authorization.
2) MARKING: Mark unclassified documents containing CUI: “CUI" at the top and bottom of each page, include the CUI warning box, and the CUI Designation Indicator Block as required in DoDI 5200.48. In a classified document:
a) Mark individual paragraph containing only CUI, but not classified material by placing “(CUI)" at the beginning of the portion.
b) Mark top and bottom of each page with classified material with the highest security classification of the material on the page.
c) If the document or material contains CUI under the category of Controlled Technical Information (CTI), use of distribution statements is required. See DoDI 5200.48.
d) If a classified document contains CUI material or if the classified material becomes CUI when declassified, place the following statement on the bottom of the cover or the first page under the classification marking: “NOTE: If declassified, review the document to make sure the material is not still CUI. If it does, then it must have the appropriate safeguarding, dissemination controls, and CUI markings applied.
e) Mark other records such as computer print outs, photographs, films, tapes, or slides in accordance with DoDI 5200.48 so the receiver or viewer knows the it contains CUI material.
f) Mark a message containing material in accordance with DoDI 5200.48. Unclassified messages containing CUI material must show the abbreviation (CUI) before the text begins.
g) Ensure documents transmitting CUI material call attention to any attachments containing CUI.
h) CUI material released to a contractor by a DoD user agency must have the following statement on the front page or cover:
THIS DOCUMENT CONTAINS CUI MATERIAL AND MUST BE REVIEWED BY A GOVERNMENT REPRESENTATIVE UNDER THE REQUIREMENTS OF DODI 5200.48, DODI 5230.09, and DODI 5230.29.
3) STORAGE: During normal duty hours, place CUI material in an out-of-sight location if your work area is accessible to persons who do not have an authorized government purpose for access to the material. After normal duty hours, store CUI material to prevent unauthorized access. File with other unclassified records in unlocked files or desks when internal building security is provided and the file is marked as CUI. When there is no internal security, locked buildings or rooms usually provide adequate after hours protection. For additional protection, store CUI material in locked containers such as file cabinets, desks, or bookcases. Expenditure of funds for security containers or closed areas solely for the protection of CUI material is prohibited.
4) TRANSMISSION: CUI documents and materials may be transmitted via first class mail, parcel post or for bulky shipments-fourth class mail. Within the CONUS discussion of CUI material on the telephone is authorized if necessary for the performance of the contract and no alternative is available. Electronic transmission of CUI (voice, data, or facsimile) should be by approved secure communications systems whenever practical. If there is a fax transmission, the sender must ensure the intended receiver is available to receive it or a cover sheet will be used to allow carrying it to the final recipient to avoid unauthorized disclosure of the CUI.
5) RELEASE: CUI material shall not be released outside of the contractor’s facility except to the representative of DoD.
6) DESTRUCTION: When the CUI material no longer meets the threshold for safeguarding and dissemination, it shall be immediately decontrolled, be processed through the records management process, and destroyed by the approved methods identified in DoDI 5200.48 precluding its disclosure to unauthorized individuals by rendering it unreadable, indecipherable, and irrecoverable.
PREVIOUS EDITION IS OBSOLETE. Page 7 of 8DD FORM 254, APR 2018
7) UNAUTHORIZED DISCLOSURE: Report misuse, mishandling, or Unauthorized Disclosure of CUI to the Unauthorized Disclosure Program Management Office, the Controlling Agency and the appropriate Military Department Counterintelligence Organization. While Unauthorized Disclosure of CUI does not constitute a security violation, a formal security inquiry/investigation is required if disciplinary action will be taken against the individual(s) responsible. Unauthorized Disclosure of certain CUI, such as export controlled-technical data, may also result in civil and criminal sanctions against responsible persons based on procedures codified in relevant law, regulation, or government-wide policy.
List of Attachments (All Files Must be attached Prior to Signing, i.e., for any digital signature on the form) Show Attachment Bar
NAME & TITLE OF REVIEWING OFFICIAL
Brittany Reid, Lead Industrial Security Specialist
SIGNATURE
14. ADDITIONAL SECURITY REQUIREMENTS
Requirements, in addition to NISPOM requirements for classified information, are established for this contract.
No Yes If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted.
(See instructions for additional guidance or use of the fillable PDF.)
15. INSPECTIONS
Elements of this contract are outside the inspection responsibility of the CSO.
No Yes If Yes, explain and identify specific areas and government activity responsible for inspections. The field will expand as text is added or you can also use item
13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted.
(See instructions for additional guidance or use of the fillable PDF.)
DCSA is relieved of all inspection responsibility for SCI portions of this contract and other U.S. Government owned and operated facilities but retains responsibility for all non-SCI classified material released to or developed under the contract and held within the contractor's facility. DIA/DHA SSO has overall security cognizance for SCI information under this contract.
16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)
a. GCA NAME
Defense Health Agency (DHA)
b. ACTIVITY ADDRESS CODE (AAC) OF THE CONTRACTING OFFICE (See Instructions)
HT0011
c. ADDRESS (Include ZIP Code) 7700 Arlington Blvd.
Falls Church, VA 22042
d. POC NAME
Jeanna M. Butler
e. POC TELEPHONE (Include Area Code)
+1 (703) 681-5995
f. EMAIL ADDRESS (See Instructions)
Jeanna.m.butler.civ@health.mil
17. CERTIFICATION AND SIGNATURES
Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below. Upon digitally signing Item 17h, no changes can be made as the form will be locked.
a. TYPED NAME OF CERTIFYING OFFICIAL (Last, First, Middle Initial) (See Instructions)
Reid, Brittany
b. TITLE
Lead Industrial Security Specialist
c. ADDRESS (Include ZIP Code) 7700 Arlington Blvd Falls Church, VA 22042
d. AAC OF THE CONTRACTING OFFICE (See Instructions)
HT0011
e. CAGE CODE OF THE PRIME CONTRACTOR
(See Instructions.)
N/A
f. TELEPHONE (Include Area Code)
+1 (703) 300-0642
g. EMAIL ADDRESS (See Instructions) brittany.reid2.civ@health.mil
h. SIGNATURE
i. DATE SIGNED (See Instructions)
PREVIOUS EDITION IS OBSOLETE. Page 8 of 8DD FORM 254, APR 2018
18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL
a. CONTRACTOR
b. SUBCONTRACTOR
c. COGNIZANT SECURITY OFFICE FOR PRIME AND
SUBCONTRACTOR
d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY
ADMINISTRATION
e. ADMINISTRATIVE CONTRACTING OFFICER
f. OTHER AS NECESSARY (If more room is needed, continue in Item 13 or on additional page if necessary.)
DHA Industrial Security dha.ncr.admin-mgmt-j-1.mbx.industrialsecurity@health.mil
PREVIOUS EDITION IS OBSOLETE.
Page of
DD FORM 254, APR 2018
NEEDS DD67
DEPARTMENT OF DEFENSE
CONTRACT SECURITY CLASSIFICATION SPECIFICATION
(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)
OMB No. 0704-0567 OMB approval expires:
June 30, 2025 The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.
RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.
1. CLEARANCE AND SAFEGUARDING
2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)
3. THIS SPECIFICATION IS: (X and complete as applicable.)
a. ORIGINAL (Complete date in all cases.)
b. REVISED (Supersedes all previous specifications.)
4. IS THIS A FOLLOW-ON CONTRACT?
If yes, complete the following:
Classified material received or generated under
5. IS THIS A FINAL DD FORM 254?
If yes, complete the following:
6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)
7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor)
8. ACTUAL PERFORMANCE (Click button to add more locations.)
10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)
e. NATIONAL INTELLIGENCE INFORMATION:
11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)
12. PUBLIC RELEASE
Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)
13. SECURITY GUIDANCE
The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.
(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)
List of Attachments (All Files Must be attached Prior to Signing, i.e., for any digital signature on the form)
14. ADDITIONAL SECURITY REQUIREMENTS
Requirements, in addition to NISPOM requirements for classified information, are established for this contract.
If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)
15. INSPECTIONS
Elements of this contract are outside the inspection responsibility of the CSO.
If Yes, explain and identify specific areas and government activity responsible for inspections. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)
16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)
17. CERTIFICATION AND SIGNATURES
Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below. Upon digitally signing Item 17h, no changes can be made as the form will be locked.
18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL
9.0.0.2.20120627.2.874785 DD 254, "DoD Contract Security Classification Specification"
| CurrentPage: |
| PageCount: |
| Select classification from drop-down list.: Unclassified |
| SerialNum: |
| a. Facility clearance level. Select one.: 1 |
| b. Level of safeguarding for classified information/material required at contractor facility. Select one.: 4 |
| Select for "original.": 0 |
| Select for "original.": 1 |
| Enter prime contract number.: |
| Select for "revised.": 0 |
| Select for "revised.": 0 |
| Enter subcontract number.: |
| Select for "final.": 1 |
| Select for "final.": 0 |
| Enter solicitation or other number.: HT001124R0069 |
| Enter due date in format YYYYMMDD.: |
| Enter date in format YYYYMMDD.: 20240417 |
| Enter revision number.: |
| Enter date in format YYYYMMDD.: |
| Enter final specification.: |
| Enter date in format YYYYMMDD.: |
| Select for "no.": 1 |
| Select for "no.": 1 |
| Select for "no.": 1 |
| Select for "no.": 0 |
| Select for "yes.": 0 |
| Select for "yes.": 0 |
| Select for "yes.": 0 |
| Select for "yes.": 1 |
| Enter preceding contract number.: |
| Enter contractor's request date in format YYYYMMDD.: |
| Enter period.: |
| Enter typed name of certifying official (last, first, middle initial).: Reid, Brittany |
| Enter CAGE code of the prime contractor.: HT0011 |
| Enter CAGE code of the prime contractor.: N/A |
| Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: |
| Select to add row to locations.: |
| Select to remove last row from locations.: |
| Select to delete all signatures.: |
| Enter location(s).: Defense Health Agency |
7700 Arlington Blvd Falls Church, VA 22042
| Enter general unclassified description of this procurement.: Market Technology Integration Office (MTIO) Special Projects |
| Select for "a. CONTRACTOR.": 0 |
| Select for "a. CONTRACTOR.": 1 |
| Select for "a. CONTRACTOR.": 1 |
| Select for "f. OTHER AS NECESSARY.": 0 |
| Select for "f. OTHER AS NECESSARY.": 0 |
| Select for "f. OTHER AS NECESSARY.": 1 |
| Select for "b. SUBCONTRACTOR.": 0 |
| Select for "b. SUBCONTRACTOR.": 0 |
| Select for "b. SUBCONTRACTOR.": 0 |
| Select for "g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE TECHNICAL INFORMATION CENTER (DTIC) OR OTHER SECONDARY DISTRIBUTION CENTER.": 1 |
| Select for "g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE TECHNICAL INFORMATION CENTER (DTIC) OR OTHER SECONDARY DISTRIBUTION CENTER.": 0 |
| Select for "c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR.": 0 |
| Select for "c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR.": 0 |
| Select for "c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR.": 1 |
| Select for "h. REQUIRE A COMSEC ACCOUNT.": 0 |
| Select for "h. REQUIRE A COMSEC ACCOUNT.": 0 |
| Select for "d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION.": 0 |
| Select for "d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION.": 0 |
| Select for "d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION.": 0 |
| Select for "i. HAVE A TEMPEST REQUIREMENT.": 0 |
| Select for "i. HAVE A TEMPEST REQUIREMENT.": 0 |
| Select for "e. NATIONAL INTELLIGENCE INFORMATION: - (1) Sensitive Compartmented Information (SCI).": 1 |
| Select for "e. NATIONAL INTELLIGENCE INFORMATION: - (2) Non-SCI.": 1 |
| Select for "j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS.": 1 |
| Select for "j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS.": 1 |
| Select for "k. BE AUTHORIZED TO USE DEFENSE COURIER SERVICE.": 1 |
| Select for "k. BE AUTHORIZED TO USE DEFENSE COURIER SERVICE.": 0 |
| Enter infomration for "other.": CAC, NIPRNet Access, SIPRNet Access, JWICS, GFE |
| Enter infomration for "other.": Authorized Government Travel; SEE Block 13 |
| Enter infomration for "other.": DHA Industrial Security |
dha.ncr.admin-mgmt-j-1.mbx.industrialsecurity@health.mil
| Select for "e. ADMINISTRATIVE CONTRACTING OFFICER.": 0 |
| Select for "e. ADMINISTRATIVE CONTRACTING OFFICER.": 1 |
| Select for "l. RECEIVE, STORE, OR GENERATE CONTROLLED UNCLASSIFIED INFORMATION (CUI). .": 1 |
| Select for "m.OTHER.": 1 |
| Select for "direct.": 0 |
| Select for ": 1 |
| Enter specification for "through".: Defense Office of Prepublication and Security Review |
Rm. 2A534 Pentagon, Washington, DC 20301-1155
| Enter public release authority.: FOIA PRENTAGON| NO PUBLIC RELEASE OF CLASSIFIED INFROMATION AUTHORIZED |
| Select to add signature.: |
| Select to remove last signature.: |
| text: For initial Industrial Security support, assistance, issues or contact information; the contractor should contact the DHA Industrial Security Help Desk at dha.ncr.admin-mgmt-j-1.mbx.industrialsecurity@health.mil (Unclassified Messages) |
For Initial and Renewal CAC Application request(s); the contractor should contact the DHA Industrial Security Mailbox at dha.ncr.security.mbx.personnel-security-tass@health.mil (Please ensure that PII is Encrypted, Password Protected or sent via DoD Safe)
DD 254 review date: 27 February 2028 At the time of DD 254 generation:
COR: Christopher A. Combs 210-617-3238 christopher.a.combs2.civ@health.mil CO: Jeanna M. Butler 703-681-5995 jeanna.m.butler.civ@health.mil
*** Authorized CONUS Travel Locations ***
REQUIRED CLEARANCE LEVEL: This contract involves access to classified data/information up to and including TOP SECRET/SCI with Yankee White clearance level. All contractor personnel performing under this contract shall possess the appropriate interim or final clearances necessary to review documents and data at the top secret level. Those who do not possess such clearance shall not receive or review any classified materials.
Other Personnel: REQUIRED CLEARANCE LEVEL (SECRET): This contract involves access to classified data/information up to and including SECRET clearance level. All contractor personnel performing under this contract shall possess the appropriate interim or final clearances necessary to review documents and data at the secret level. Those who do not possess such clearance shall not receive or review any classified materials.
SCI ACCESS
Access to intelligence information requires special briefings and a U.S. Government clearance at appropriate level TS/SCI as designated by government program manager. Cleared personnel are required to perform this service because access to classified information cannot be precluded. The contractor is not authorized to release classified information to any activity or person, including sub-contractors, without the government contract monitors written approval. Only with the expressed permission of the government contract monitor may the contractor reproduce any classified information or material classified Secret or above. TS/SCI contract performance is restricted to the OASD(HA) and DHA cleared facilities, other DoD facilities and military medical treatment facilities (MTF) as directed by the contracting officer in coordination with the COR.
Additional guidance for contractor personnel:
a. All intelligence material released to the contractor remains the property of the US Government and may be withdrawn at any time. Contractors must maintain accountability for all classified intelligence released into their custody.
b. The contractor must not reproduce intelligence material without the written permission of the originating agency through the DWSSO. If permission is granted, each copy shall be controlled in the same manner as the original.
c. The contractor must not destroy any intelligence material without advance approval or as specified by the contract monitor (CM). (EXCEPTION: Classified material shall be destroyed as soon as practicable in accordance with the provisions of the Industrial Security Program).
d. The contractor must restrict access to only those individuals who possess the necessary security clearance and who are providing services under the contract with a valid need to know. Further dissemination to other contractors, subcontractors, other government agencies, private individuals or organizations is prohibited unless authorized in writing by the originating agency through the CM authorized in writing by the originating agency through the CM.
GENERAL NOTES:
All provisions of 32 CFR Part 117, National Industrial Security Program Operating Manual (NISPOM) apply. Effective date is 24 Feb 2021.
NON-DISCLOSURE AGREEMENT (CNSI & CUI) All contractor personnel performing under this contract shall be required to sign and execute proprietary information non-disclosure statements for Classified National Security Information (CNSI) and Controlled Unclassified Information (CUI) {when required}. The proprietary information non-disclosure statements shall be required as part of the initial in-processing and must be executed prior to performing any work under this contract. The proprietary information non-disclosure statements will be maintained on file within the (DHA) Security Office. Contractor personnel who refuse to sign proprietary information non-disclosure statements will not be permitted to work on government contracts.
SECURITY EXECUTIVE AGENT DIRECTIVE 3 The contractor must comply with “Reporting Requirements for Personnel with Access to Classified Information or Who Hold a Sensitive Position,” along with DoD Manual 5200.02 and NISPOM. See INDUSTRIAL SECURITY LETTER (ISL) 2021-02 dated 12 August 2021 for additional information.
SECURITY EXECUTIVE AGENT DIRECTIVE 4 The contractor will comply with “National Security Adjudicative Guidelines,” which became effective on June 08, 2017. See INDUSTRIAL SECURITY LETTER (ISL) 2019-01 for additional information.
ORIGINAL CLASSIFICATION AUTHORITY Original Classification is not authorized. If the contractor believes information not currently classified, requires classification, the contractor will immediately notify the GCA.
SECURITY CLASSIFICATION GUIDANCE (SCGs) Specific SCGs, to include subsequent upgrades/revision(s), applying to classified performance on this contract, shall be provided by the Contracting Officer Representative or Technical Point of Contact, identified in Block 16, as Government Furnished Information (GFI); and shall be executed by the Contractor without obligation to modify this DD Form 254. If additional security classification is required, contact the COR identified in Block 16.
DESTRUCTION OF DoD INFORMATION The contractor must comply with on-site security procedures to dispose of DoD Information. Destruction in the NCR is by use of approved burn bags.
AUDIO/VISUAL RECORDINGS The recording of DoD information, equipment, personnel, or facilities by any means is prohibited.
HAZARDOUS MATERIALS & WEAPONS Hazardous materials and weapons are prohibited from entry on/into government facilities to include any weapon, the possession of which, is prohibited under the laws of the state in which the facility is located (specifically Virginia, District of Columbia & Maryland). Knives with a blade length over 2.5 inches are prohibited. References:
18 U.S. Code § 930. Possession of firearms and dangerous weapons in Federal facilities https://www.law.cornell.edu/uscode/text/18/930 Title 32 - National Defense, Part 234 - CONDUCT ON THE…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .