Attachment 11 Draft DD254 412TW.pdf
PDF 1 MB Posted
- Attached to
- Technical Management Advisory Services (TMAS) 2 412 Test Wing (TW) Draft FOPR Federal contract opportunity
- Solicitation number
- FA2486-20-F-1003
View the file
Other files for this federal contract opportunity
Show all 19
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
For the best experience, open this PDF portfolio in
Acrobat X or Adobe Reader X, or later.
Get Adobe Reader Now!
http://www.adobe.com/go/reader
CONTROLLED UNCLASSIFIED INFORMATION (CUI) ADDENDUM ATTACHMENT
CONTROLLED UNCLASSIFIED INFORMATION (CUI) ADDENDUM
1. The definition of CUI is information that requires safeguarding or dissemination controls pursuant to and consistent with law, regulations, and Government-wide policies, excluding information that is classified pursuant to Executive Order 13526 of 29 December 2009 or the Atomic Energy Act, as amended. In accordance with DoD Instruction 5230.24, Distribution statements on Technical Documents, such information is referred to collectively as CUI. DoD 5200.1, Volume 4, DoD Information Security Program: Controlled Unclassified Information (CUI) identifies the controls and protective measures developed for DoD CUI (i.e., For Official Use Only (FOUO), Law Enforcement Sensitive (LES), DoD Unclassified Controlled Nuclear Information (DoD UCNI), and LIMITED DISTRIBUTION) as well as some of those developed by other Executive Branch agencies.
2. When CUI is to be provided to or generated by DoD contractors, the controls and protective measures to be applied shall be described in the pertinent contract documents (e.g., contact clause; statement of work; or DD Form 254, “Department of Defense Contract Security Classification Specification”). Solicitations and contracts shall use a non-disclosure of information clause that prohibits release of unclassified information to the public without approval of the contracting activity. The clause shall also be made applicable to subcontractors.
3. The Contractor shall not release to anyone outside the Contractor’s organization any unclassified information, regardless of medium (e.g., film, tape, document), pertaining to any part of this contract or any program related to this contract without prior approval from the government.
4. Technical Data is any recorded information related to experimental, developmental, or engineering works that can be used to define an engineering or manufacturing process or to design, procure, produce, support, maintain, operate, repair, or overhaul program material. The data may be graphic or pictoral delineations in media, such as computer software, drawings, or photographs, text in specifications, or related performance or design documents, or computer printouts. Examples of technical data include research and engineering data, engineering drawings, and associated lists, specifications, standards, process sheets, manuals, technical reports, catalog-item identifications, and computer software documentation.
5. GOVERNMENT DISTRIBUTIONS STATEMENTS: Will be added to all technical data generated during the execution of this contract, in accordance with DoD Instruction 5230.24.
6. The contractor shall protect CUI from unauthorized disclosure by appropriately marking, safeguarding, disseminating, and destroying such information. CUI will be checked in accordance with DoD 5200,01, Volume 4.
7. CUI may be identified in security classification guides to ensure the information receives appropriate protection.
8. For unauthorized disclosures of CUI, no formal security inquiry or investigation is required. However, appropriate management action shall be taken to fix responsibility for unauthorized disclosure of CUI whenever feasible or required by other guidance, and appropriate disciplinary action shall be taken against those responsible. The DoD Component that originated the CUI shall be informed of its unauthorized disclosure.
ADDENDUM TO DD FORM 254
Contract Number: FA2486-20-F-1003
Special Access Information Effective: 20200114
In performing this contract, the contractor will have access to Special Access Program Information or material only at another contractor’s facility or government activity as stated in Item 8.a. of this DD Form 254.
• DoD 5220.22-M, National Industrial Security Program Operating Manual (NISPOM), latest version
• DoD Directive (DoDD) 5205.07, Special Access Program Policy, as supplemented (latest version)
• DoD Instruction (DoDI) 5205.11, Management, Administration, and Oversight of DoD Special Access
Programs (SAPs), (latest version)
• DoDM 5205.07, Volume 1 – AFMAN 16-703 V1, DoD Special Access Program (SAP) Security Manual:
General Procedures (latest version)
• DoDM 5205.07, Volume 2 – AFMAN 16-703 V2, DoD Special Access Program (SAP) Security Manual:
Personnel Security (latest version)
• DoDM 5205.07, Volume 3 – AFMAN 16-703 V3, DoD Special Access Program (SAP) Security Manual:
Physical Security (latest version)
• DoDM 5205.07, Volume 4, SAP Security marking Manual: Marking (latest version)
• DoDM 5200.01, Volume 1, DoD Information Security Program: Overview, Classification and
Declassification (latest version)
• DoDM 5200.01, Volume 2, DoD Information Security Program: Marking of Classified (latest version)
• DoDM 5200.01, Volume 3, DoD Information Security Program: Protection of Classified Information
(latest version)
• DoDM 5200.01, Volume 4, DoD Information Security Program: Controlled Unclassified Information
• DoD Instruction (DoDI) 5000.02, Operation of the Defense Acquisition System (latest version)
• Air Force Policy Directive (AFPD) 16-7, Special Access Programs (latest version)
• Air Force Instruction (AFI) 16-701, Management, Administration, and Oversight of Special Access
Programs (latest version)
• Risk Management Framework (RMF) using the Joint Special Access Program Implementation Guide
(JSIG) (latest version)
• DoD Instruction (DoDI) 8510.01, Risk Management Framework (RMF) for DoD Information
Technology (IT) (latest version)
• SAF/AAZ Memorandum, Implementing DoD Manual 5205.07, V4, SAP Manual: Marking, United
States Air Force Security Marking Guide for Special Access Programs (latest version)
• SAF/AAZ Memorandum, Implementation of DoDM 5205.07, DoD Special Access Program (SAP)
Security Manual, Volumes 1-4 (latest version)
• DoD Issuances website: http://www.dtic.mil/whs/directives/
• AF e-Publications website: http://www.e-publishing.af.mil/
• NSA/CSS Policy Manual 3-16, Control of COMSEC Material (latest version)
• Or if COMSEC material is under the AF cog add:
• AFMAN 17-1302-O, dated 3 Feb 17, Communications Security (COMSEC) Operations
• Air Force Instruction (AFI) 33-201v2, Change 2, Communications Security (COMSEC) User
Requirements (latest version)
• Air Force Instruction (AFI) 33-201v9, Operational Instructions for Secure Voice Devices (latest version)
• CNSSAM TEMPEST/01-13, RED/BLACK Installation Guidance (latest version)
• Security Classification Guidance, there will be multiple Security Classification guides at the program level as this Contract applies to several programs. Contact the Contracting Officer’s Representative (COR) of the Performance Work Statement (PWS) requirement for guidance. Security Classification Guides will be provided at the performance location under separate cover.
• OPSEC Plan or Legend, the designated COR will provide appropriate information when required.
Supersession of any of the above documents will not require an immediate revision to this DD Form 254.
The updated document will be deemed to be on contract as of the date of the supersession. Additional costs incurred due to updated guidance will be brought to the attention of the Government Contract Officer immediately.
SCI ATTACHMENT
COMPANY NAME: TBD
CONTRACT #: FA2486-20-F-1003
CONTRACT EXPIRATION DATE: 30 SEP 25
NOTE: The Contract Office Representative (Program Manager if delegated duties) is required to send Statement Of Works (SOW) or Performance Work Statement (PWS) for verification of SCI requirements to the following workflow box: AFLCMC/INMS Workflow (Eglin) Special Security Office aflcmc.inms@eglin.af.mil.
Item 13.a: This contract requires access to Sensitive Compartmented Information (SCI). Per (list applicable DoD publications, ICDs, DCIDs, DoDM 5105.21, Volumes 1,2 3 and AFMAN 14-401, Joint DoDISS Cryptologic SCI Information Systems Standards (JDCSISSS), NISPOM Supplement, etc.)
provides the necessary guidance for physical, personnel, information and information systems security measures and is part of the SCI security specifications for the contract (See Item 13B).
Item 13.b: The following documents, with subsequent versions or changes, will be used for specific security classification guidance on this contract (if newer editions are published after award of the contract, the contractor will utilize the most recent edition of these documents):
1. Executive Order 13526, Classified National Security Information, (29 December 2009)
2. Director of Central Intelligence Directive 6/1 Security Policy for Sensitive Compartmented Information and Security Policy Manual (1 March 1995/ 4 November 2003)
3. ICD 503 - Intelligence Community Information Technology Systems Security: Risk Management, Certification and Accreditation, 15 September 2008
4. ICD 704 - Personnel Security Standards and Procedures Governing Eligibility for Access to Sensitive Compartmented Information and Other Controlled Access Program Information, 1 October 2008 (Including ICPG 704.1 – 704.5)
5. ICD 705 - Sensitive Compartmented Information Facilities (26 May 2010)
6. ICD 710 – Classification and Control Markings System (11 September 2009)
7. The Intelligence Community Classification and Control Markings Implementation Manual, (U/FOUO), with its classified Appendix-A
8. The Authorized Classification and Control Markings Register, (U/FOUO), with its classified Annex A and Annex B
9. Department of Defense Manual 5105.21-Vol 3, Sensitive Compartmented Information Administrative Security Manual (19 October 2012) (DoD 5105.21-Vol 3) mailto:aflcmc.inms@eglin.af.mil
10. Department of Defense Manual 5220.22-M, National Industrial Security Program Operating Manual, February 2006, C1 28 March 2013
11. Joint DoDIIS Cryptologic SCI Information Systems Security Standards (JDCSISSS) (For Official Use Only), 20 September 2012
12. Air Force Instruction 14-302, Control, Protection, and Dissemination of Sensitive Compartmented Information (18 January 1994)
13. Air Force Manual14-304, The Security Use and Dissemination of Sensitive Compartmented Information,, 23 December 2016
(14) There will be multiple Security Classification Guides at the organizational level as this Contract applies to several organizations. Contact the Contracting Officer’s Representative (COR) of each Performance Work Statement (PWS) requirement for guidance.
Item 13.c: Inquiries pertaining to classification guidance on SCI will be directed to the responsible 96 TW COR, indicated in Item 13.aa. Any SCI-derived material generated under this contract will be reviewed by the contract monitor for proper classification prior to final publication and distribution. The responsible special security office (shown in item 13.w) will provide assistance as required.
Item 13.d: SCI data furnished to or generated by the contractor will require special security handling and controls beyond those in the National Industrial Security Program Operating Manual (NISPOM).
Supplemental instructions will be furnished and/or made available to the contractor through the COR by
AFLCMC/INMS (SSO EGLIN).
Item 13.e: Names of contractor personnel requiring access to SCI will be submitted to the contract monitor for approval. If required, submit an Electronic Questionnaires for Investigations Processing (e- QIP) requesting a Single Scope Background Investigation (SSBI), prepared in accordance with the NISPOM and submitted to OPM. Upon approval by the contract monitor, a letter justifying need for access will be prepared and submitted to AFLCMC/INMS.
Item 13.f: The contractor will notify AFLCMC/INMS immediately upon receiving “reportable information” or knowledge of a change in the personal status involving employees assigned to work on this contract who have SCI access or access to any other intelligence information. “Reportable information” is defined in ICPG 704.1 – 704.5 of ICD 704 - Personnel Security Standards and Procedures Governing Eligibility for Access to Sensitive Compartmented Information and Other Controlled Access Program Information.
“Changes in status” is defined in Chapter 2 of Department of Defense Manual 5105.21-Vol 3, Sensitive Compartmented Information Administrative Security Manual (19 October 2012) (DoD 5105.21-Vol 3) Department . These two categories will be interpreted to mean information or changes in personal status which could potentially affect the employee’s continuing eligibility for access to SCI.
Item 13.g: The contractor will establish and maintain an access list of those employees working on the contract. A copy of this list will be furnished to the contract monitor when requested.
Item 13.h: The contractor will submit a Visit Cert request to AFLCMC/INMS for transmitting SCI certifications to their travel location.
Item 13.i: The contractor will advise AFLCMC/INMS through the SCI contract monitor immediately upon reassignment of personnel to other duties not associated with this contract.
Item 13.j: Release of Information: SCI will not be released to contractor employees without specific release approval of the Eglin Senior Intelligence Officer (SIO) or the originator of the material when applicable. SCI with restrictive caveats (ORCON, PROPIN, etc.) will be released to contractors only when originator approval has been obtained. This approval will be obtained through AFLCMC/INMS based on approval and certification of "need-to-know" by the COR. SCI documentation, or other material concerning this contract, will not be discussed with or released to any individual, subcontractor, agency (including Federal Government agencies and employees), and contractor employees not working on the contract without prior written approval from the contract monitor.
Item 13.k: SCI materials furnished in support of this contract remains the property of the DoD department or command that released it. Upon completion or cancellation of the contract, all SCI materials furnished will be returned to the direct custody of the originator of the materials.
Item 13.l: When required, the contractor will derivatively classify documents created in the course of this contract using the procedures and criteria defined in Executive Order 13526, Classified National Security Information, (EO 13526) as amended and Information Security Oversight Office Implementing Directive No. 1. Requests for original classification of intelligence information at any classification level or within any compartment will be referred to AFLCMC/INM. Requests for classification not involving SCI or intelligence will be referred to the 96 TW Information Protection Office via the Contracting Office Representative (COR).
Item 13.m: The contractor is prohibited from using references to SCI accesses, even by unclassified acronyms, in advertising, promotional efforts, recruitment media or on the company website.
Item 13.n: Contractor personnel must not reproduce classified foreign intelligence without advance approval of the releasing agency. If permission is granted, each copy will be controlled in the same manner as the original. The CSSO must not destroy any classified foreign intelligence without advance approval of the releasing agency.
Item 13.o: The contractor will not sanitize or decompartment any SCI or intelligence. If the contractor believes fulfillment of this contract requires sanitization of SCI or decompartmentation of intelligence, the information will be forwarded to AFLCMC/INMS.
Item 13.q: (Other SCIF) Access to SCI is limited to a US Government or other contractor SCIF; see notification of Government Security Activity clause contained in the contract.
Note 1: If the SCIF belongs to another government agency (someone else is cognizant authority for the security over the facility) a co-utilization agreement must be executed. You, as the COR, are responsible to ensure that information is provided to AFLCMC/INMS for approval prior to the contractor starting work in another agency’s SCIF. A sample format can be obtained from
AFLCMC/INMS.
Note 2: For any of the items above, it is required that you list specific locations, addresses, and for contractor(s) locations; also show CAGE Codes and appropriate DSS office addresses.
Item 13.r: This contract does/does not require the use of Defense Courier Service.
Item 13.s: Information assurance and electronic processing; information security (computer) and network connectivity require accreditation of the equipment connectivity.
Item 13.u: AFLCMC/INMS prohibits the possession or use of all cameras, video recorders, audio recorders, cellular phones, hand-held radios, two-way pagers, FitBits and all devices containing a Radio Frequency transmitter in any AFLCMC/INM SCIF. The contractors will comply with AFLCMC/INM policies which prohibit the possession or use of memory/storage devices variously described as Flash Memory, Memory Sticks, Smart Media, Thumb Drives and/or Jump Drives in SCIFs.
Item 13.v: All DD Form 254s prepared for subcontracts involving access to SCI under this contract must be forwarded to the COR for approval and then to (SSO, location) for review and concurrence prior to award of the subcontract. Inquiries pertaining to classification guidance on SCI will be directed to the COR listed on the DD Form 254 or SCI attachment. SCI security management issues shall be directed to AFLCMC/INM Senior Intelligence Officer (through the Special Security Office).
Item 13.w: The contractors will require access to intelligence information and must comply with AFI14-304. The Contract Office Representative (COR) has determined that disclosure does not create an unfair advantage for the contractor or a conflict of interest with the contractor’s obligation to protect the information.
SPECIAL SECURITY OFFICE (SSO)
AFLCMC/INMS
101 West D. Avenue, Suite 102 Eglin AFB, FL 32542
PHONE: DSN 872-3908, COM (850)-882-3908
Item 13.y: The contract monitor for SCI is:
AFTC/AZL
TBD
102 West D Avenue, Suite 201
PHONE: DSN 875-3716, COM (850)-882-0741
Item 13.aa: RELEASE OF NON-SENSITIVE COMPARTMENTED INFORMATION (NON-
SCI) INTELLIGENCE INFORMATION TO US CONTRACTORS
3. Requirements for access to intelligence information:
a. All intelligence material released to the contractor remains the property of the US Government and may be withdrawn at any time. Contractors must maintain accountability for all classified intelligence released into their custody.
b. Contractor personnel must not reproduce classified foreign intelligence without advance approval of the releasing agency. If permission is granted, each copy will be controlled in the same manner as the original.
The CSSO must not destroy any classified foreign intelligence without advance approval of the releasing agency.
c. The contractor must not destroy any intelligence material without advance approval or as specified by the contract monitor (COR). (EXCEPTION: Classified waste shall be destroyed as soon as practical in accordance with the provisions of the Industrial Security Program.)
d. The contractor must restrict access to only those individuals who possess the necessary security clearance and who are actually providing services under the contract with a valid need to know. Further dissemination to other contractors, sub-contractors, other government agencies, private individuals or organizations is prohibited unless authorized in writing by the originating agency through the COR.
e. The contractor must ensure each employee having access to intelligence material is fully aware of the special security requirements for this material and shall maintain records in a manner that will permit the contractor to furnish, on demand, the names of individuals who have had access to this material in their custody.
f. Classified foreign intelligence materials must not be released to foreign nationals or immigrant aliens whether or not they are also consultants, U.S. contractors, or employees of the contractor regardless of the level of their security clearance, except with advance written permission from the originator.
g. Upon completion or termination of the classified contract, or sooner when the purpose of the release has been served, the contractor will return all classified intelligence (furnished or generated) to the source from which received unless retention or other disposition instructions (see AFMAN 37-139) are authorized in writing by the COR.
h. The contractor must designate an individual who is working on the contract as custodian. The designated custodian shall be responsible for receipting and accounting for all classified material. The inner wrapper of all classified material dispatched should be checked for the attention of a designated custodian and must not be opened by anyone not working directly on the contract.
i. Within 30 days after the final product is received and accepted by the procuring agency, classified intelligence materials released to or generated by the contractor must be returned to the originating agency, through the contract monitor, unless written instructions authorizing destruction or retention are issued. Requests to retain material shall be directed to the COR for this contract in writing and clearly indicate the justification for retention and identity of the specific document to be retained.
j. Classification, reclassification, or declassification markings of documentation produced by the contractor shall be consistent with that applied to the information or documentation from which the new document was prepared. If a compilation of information or a complete analysis of subject appears to require a security classification other than that of the source documentation, the contractor shall assign the tentative security classification and request instructions from the contract monitor. Pending final determination, the material shall be safeguarded as required for its assigned or proposed classification, whichever is higher, until the classification is changed or otherwise verified.
4. Intelligence material carries special markings. The following is a list of the authorized control markings of intelligence material:
a. Intelligence that carries the ORCON marking requires written permission of the originating agency before release to a contractor outside of government owned or controlled facilities. Sponsoring agencies delete any reference to the Central Intelligence Agency (CIA) phrase “Directorate of
Operations” and any of its components, place acquired, field number, source description, and field dissemination from all CIA Directorate of Operations reports passed to contractors, unless prior approval to do otherwise is obtained from CIA.
b. Intelligence that carries the PROPIN markings requires written permission of the originating agency before release to contractors within or outside of government owned or controlled facilities.
c. Permit ready identification of an intelligence source or method which is particularly susceptible to countermeasures that would nullify or measurably reduce its effectiveness. This marking may not be used when an item or information will reasonably be protected by the use of other markings specified herein, or by the application of the “need-to-know” principle and the safeguarding procedures of the security classification system.
d. Authorized for Release to (Name of the Country(ies)/International Organization.) The above is abbreviated “REL _______________________.” This marking must be used when it is necessary to identify classified intelligence material the US government originator has predetermined to be releasable or has been released through established foreign disclosure channels to the indicated country(ies) or organization.
5. The following procedures govern the use of control markings.
a. Any recipient desiring to use intelligence in a manner contrary to restrictions established by the control markings set forth above shall obtain the advance permission of the originating agency through the COR. Such permission applies only to the specific purposes agreed to by the originator and does not automatically apply to all recipients. Originators shall ensure that prompt consideration is given to recipients’ requests in these regards, with particular attention to reviewing and editing, if necessary, sanitized or paraphrased versions to derive a text suitable for release subject to lesser or no control markings.
b. The control marking authorized above shall be shown on the title page, front cover, and other applicable pages of documents, incorporated in the text of electrical communications, shown on graphics, and associated (in full or abbreviated form) with data stored or processed in automatic data processing systems. The control marking also shall be indicated by parenthetical use of the marking abbreviations at the beginning or end of the appropriate portions. If the control marking applies to several or all portions, the document must be checked with a statement to this effect rather than marking each portion individually.
c. The control markings shall be individually assigned at the time of preparation of intelligence products and used in conjunction with security classifications and other marking specified by E.O. 13526 and its implementing security directives. The marking shall be carried forward to any new format in which the same information is incorporated including oral and visual presentations.
6. Request for release of intelligence material to a contractor must be validated by the contract monitor (COR) and coordinated through the Senior Intelligence Officer if needed. The COR accounts for all intelligence information released to the contractor and ensures electronic access to classified information is documented in Block 11 on DD Form 254 (e.g.
access to Secure Internet Protocol Network [SIPRNET], and/or any other classified network). Contractor personnel must maintain accountability for all intelligence (to include foreign intelligence materials released to their custody.
CONTRACTOR PERFORMANCE ON A GOVERNMENT INSTALLATION ATTACHMENT
TEMPEST REQUIREMENTS
1. The contractor shall ensure that TEMPEST conditions related to this contract are minimized.
2. When government furnished or contractor owned Information Systems (IS) are used on government installations TEMPEST countermeasures will be applied by the government supporting activity. Classified processing shall not begin until accreditation is completed by appropriate government personnel.
3. The contractor is required to provide copies of the written approval/authorization to appropriate government personnel upon request.
4. Problems encountered in obtaining the written approval/authorization for classified processing should be brought to the attention of the Government Contracting Activity (GCA) and Government Program Manager.
5. The TEMPEST authority on military installations is the local Communications Squadron.
6. Use of any telecommunications systems or devices on military installations to include, but not limited to, government issued cellular phones, hand-held radios, beepers/pagers, cordless telephones, cordless microphones, facsimile machines, and computers constitutes consent to monitoring in accordance with AFI 10-712.
COMSEC ACCESS AND /OR ACCOUNT ATTACHMENT
1. The contractor is governed by AFMAN 17-1302-O, AFKAG-2 and appropriate Air Force Systems Security Instructions/Manuals (AFSSI/AFSSM) or Air Force Instructions (AFI). Access to COMSEC material or information is restricted to U.S. citizens holding final United States Government clearances and is not releasable to personnel holding only a reciprocal clearance. Personnel requiring COMSEC access shall be briefed in accordance with AFMAN 17-1302-O (COMSEC Operations). NOTE: The COMSEC briefing applies only to the use and control of cryptographic equipment and specialized COMSEC publications. NACSIM/NACSEM documents are not considered COMSEC controlled material.
Additionally, cryptographic information/equipment shall be retained in a contractor facility user COMSEC account in accordance with current guidelines. The Air Force program/project manager shall designate the number of personnel requiring COMSEC access. The number will be limited to the minimum necessary and will be on a strict need-to-know basis.
2. When COMSEC support, including secure phone or other secure voice capabilities, is provided by an AF COMSEC Account, the contractor must comply with AFMAN 17-1302-O.
Please wait...
If this message is not eventually replaced by the proper contents of the document, your PDF viewer may not be able to display this type of document.
You can upgrade to the latest version of Adobe Reader for Windows®, Mac, or Linux® by visiting http://www.adobe.com/go/reader_download.
For more assistance with Adobe Reader visit http://www.adobe.com/go/acrreader.
Windows is either a registered trademark or a trademark of Microsoft Corporation in the United States and/or other countries. Mac is a trademark of Apple Inc., registered in the United States and other countries. Linux is the registered trademark of Linus Torvalds in the U.S. and other countries.
CONTRACTOR PERFORMANCE ON A GOVERNMENT INSTALLATION ATTACHMENT
TEMPEST REQUIREMENTS
1. The contractor shall ensure that TEMPEST conditions related to this contract are minimized.
2. When government furnished or contractor owned Information Systems (IS) are used on government installations TEMPEST countermeasures will be applied by the government supporting activity. Classified processing shall not begin until accreditation is completed by appropriate government personnel.
3. The contractor is required to provide copies of the written approval/authorization to appropriate government personnel upon request.
4. Problems encountered in obtaining the written approval/authorization for classified processing should be brought to the attention of the Government Contracting Activity (GCA) and Government Program Manager.
5. The TEMPEST authority on military installations is the local Communications Squadron.
6. Use of any telecommunications systems or devices on military installations to include, but not limited to, government issued cellular phones, hand-held radios, beepers/pagers, cordless telephones, cordless microphones, facsimile machines, and computers constitutes consent to monitoring in accordance with AFI 10-712.
COMSEC ACCESS AND /OR ACCOUNT ATTACHMENT
1. The contractor is governed by AFMAN 17-1302-O, AFKAG-2 and appropriate Air Force Systems Security Instructions/Manuals (AFSSI/AFSSM) or Air Force Instructions (AFI). Access to COMSEC material or information is restricted to U.S. citizens holding final United States Government clearances and is not releasable to personnel holding only a reciprocal clearance. Personnel requiring COMSEC access shall be briefed in accordance with AFMAN 17-1302-O (COMSEC Operations). NOTE: The COMSEC briefing applies only to the use and control of cryptographic equipment and specialized COMSEC publications. NACSIM/NACSEM documents are not considered COMSEC controlled material.
Additionally, cryptographic information/equipment shall be retained in a contractor facility user COMSEC account in accordance with current guidelines. The Air Force program/project manager shall designate the number of personnel requiring COMSEC access. The number will be limited to the minimum necessary and will be on a strict need-to-know basis.
2. When COMSEC support, including secure phone or other secure voice capabilities, is provided by an AF COMSEC Account, the contractor must comply with AFMAN 17-1302-O.
ADDENDUM TO DD FORM 254
Contract Number: FA2486-20-F-1004
Special Access Information Effective: 20200114
In performing this contract, the contractor will have access to Special Access Program Information or material only at another contractor’s facility or government activity as stated in Item 8.a. of this DD Form 254.
• DoD 5220.22-M, National Industrial Security Program Operating Manual (NISPOM), latest version
• DoD Directive (DoDD) 5205.07, Special Access Program Policy, as supplemented (latest version)
• DoD Instruction (DoDI) 5205.11, Management, Administration, and Oversight of DoD Special Access
Programs (SAPs), (latest version)
• DoDM 5205.07, Volume 1 – AFMAN 16-703 V1, DoD Special Access Program (SAP) Security Manual:
General Procedures (latest version)
• DoDM 5205.07, Volume 2 – AFMAN 16-703 V2, DoD Special Access Program (SAP) Security Manual:
Personnel Security (latest version)
• DoDM 5205.07, Volume 3 – AFMAN 16-703 V3, DoD Special Access Program (SAP) Security Manual:
Physical Security (latest version)
• DoDM 5205.07, Volume 4, SAP Security marking Manual: Marking (latest version)
• DoDM 5200.01, Volume 1, DoD Information Security Program: Overview, Classification and
Declassification (latest version)
• DoDM 5200.01, Volume 2, DoD Information Security Program: Marking of Classified (latest version)
• DoDM 5200.01, Volume 3, DoD Information Security Program: Protection of Classified Information
• DoDM 5200.01, Volume 4, DoD Information Security Program: Controlled Unclassified Information
• DoD Instruction (DoDI) 5000.02, Operation of the Defense Acquisition System (latest version)
• Air Force Policy Directive (AFPD) 16-7, Special Access Programs (latest version)
• Air Force Instruction (AFI) 16-701, Management, Administration, and Oversight of Special Access
Programs (latest version)
• Risk Management Framework (RMF) using the Joint Special Access Program Implementation Guide
(JSIG) (latest version)
• DoD Instruction (DoDI) 8510.01, Risk Management Framework (RMF) for DoD Information
Technology (IT) (latest version)
• SAF/AAZ Memorandum, Implementing DoD Manual 5205.07, V4, SAP Manual: Marking, United
States Air Force Security Marking Guide for Special Access Programs (latest version)
• DoD Issuances website: http://www.dtic.mil/whs/directives/
• AF e-Publications website: http://www.e-publishing.af.mil/
• NSA/CSS Policy Manual 3-16, Control of COMSEC Material (latest version)
• Or if COMSEC material is under the AF cog add:
• AFMAN 17-1302-O, dated 3 Feb 17, Communications Security (COMSEC) Operations
• Air Force Instruction (AFI) 33-201v2, Change 2, Communications Security (COMSEC) User
Requirements (latest version)
• Air Force Instruction (AFI) 33-201v9, Operational Instructions for Secure Voice Devices (latest version)
• CNSSAM TEMPEST/01-13, RED/BLACK Installation Guidance (latest version)
• Security Classification Guidance, there will be multiple Security Classification guides at the program level as this Contract applies to several programs. Contact the Contracting Officer’s Representative (COR) of the Performance Work Statement (PWS) requirement for guidance. Security Classification Guides will be provided at the performance location under separate cover.
• OPSEC Plan or Legend, the designated COR will provide appropriate information when required.
Supersession of any of the above documents will not require an immediate revision to this DD Form 254.
The updated document will be deemed to be on contract as of the date of the supersession. Additional costs incurred due to updated guidance will be brought to the attention of the Government Contract Officer immediately.
CONTROLLED UNCLASSIFIED INFORMATION (CUI) ADDENDUM ATTACHMENT
CONTROLLED UNCLASSIFIED INFORMATION (CUI) ADDENDUM
1. The definition of CUI is information that requires safeguarding or dissemination controls pursuant to and consistent with law, regulations, and Government-wide policies, excluding information that is classified pursuant to Executive Order 13526 of 29 December 2009 or the Atomic Energy Act, as amended. In accordance with DoD Instruction 5230.24, Distribution statements on Technical Documents, such information is referred to collectively as CUI. DoD 5200.1, Volume 4, DoD Information Security Program: Controlled Unclassified Information (CUI) identifies the controls and protective measures developed for DoD CUI (i.e., For Official Use Only (FOUO), Law Enforcement Sensitive (LES), DoD Unclassified Controlled Nuclear Information (DoD UCNI), and LIMITED DISTRIBUTION) as well as some of those developed by other Executive Branch agencies.
2. When CUI is to be provided to or generated by DoD contractors, the controls and protective measures to be applied shall be described in the pertinent contract documents (e.g., contact clause; statement of work; or DD Form 254, “Department of Defense Contract Security Classification Specification”). Solicitations and contracts shall use a non-disclosure of information clause that prohibits release of unclassified information to the public without approval of the contracting activity. The clause shall also be made applicable to subcontractors.
3. The Contractor shall not release to anyone outside the Contractor’s organization any unclassified information, regardless of medium (e.g., film, tape, document), pertaining to any part of this contract or any program related to this contract without prior approval from the government.
4. Technical Data is any recorded information related to experimental, developmental, or engineering works that can be used to define an engineering or manufacturing process or to design, procure, produce, support, maintain, operate, repair, or overhaul program material. The data may be graphic or pictoral delineations in media, such as computer software, drawings, or photographs, text in specifications, or related performance or design documents, or computer printouts. Examples of technical data include research and engineering data, engineering drawings, and associated lists, specifications, standards, process sheets, manuals, technical reports, catalog-item identifications, and computer software documentation.
5. GOVERNMENT DISTRIBUTIONS STATEMENTS: Will be added to all technical data generated during the execution of this contract, in accordance with DoD Instruction 5230.24.
6. The contractor shall protect CUI from unauthorized disclosure by appropriately marking, safeguarding, disseminating, and destroying such information. CUI will be checked in accordance with DoD 5200,01, Volume 4.
7. CUI may be identified in security classification guides to ensure the information receives appropriate protection.
8. For unauthorized disclosures of CUI, no formal security inquiry or investigation is required. However, appropriate management action shall be taken to fix responsibility for unauthorized disclosure of CUI whenever feasible or required by other guidance, and appropriate disciplinary action shall be taken against those responsible. The DoD Component that originated the CUI shall be informed of its unauthorized disclosure.
SCI ATTACHMENT
COMPANY NAME: TBD
CONTRACT #: FA2486-20-F-1005
CONTRACT EXPIRATION DATE: 30 SEP 25
NOTE: The Contract Office Representative (Program Manager if delegated duties) is required to send Statement Of Works (SOW) or Performance Work Statement (PWS) for verification of SCI requirements to the following workflow box: AFLCMC/INMS Workflow (Eglin) Special Security Office aflcmc.inms@eglin.af.mil.
Item 13.a: This contract requires access to Sensitive Compartmented Information (SCI). Per (list applicable DoD publications, ICDs, DCIDs, DoDM 5105.21, Volumes 1,2 3 and AFMAN 14-401, Joint DoDISS Cryptologic SCI Information Systems Standards (JDCSISSS), NISPOM Supplement, etc.) provides the necessary guidance for physical, personnel, information and information systems security measures and is part of the SCI security specifications for the contract (See Item 13B).
Item 13.b: The following documents, with subsequent versions or changes, will be used for specific security classification guidance on this contract (if newer editions are published after award of the contract, the contractor will utilize the most recent edition of these documents):
1. Executive Order 13526, Classified National Security Information, (29 December 2009)
2. Director of Central Intelligence Directive 6/1 Security Policy for Sensitive Compartmented Information and Security Policy Manual (1 March 1995/ 4 November 2003)
3. ICD 503 - Intelligence Community Information Technology Systems Security: Risk Management, Certification and Accreditation, 15 September 2008
4. ICD 704 - Personnel Security Standards and Procedures Governing Eligibility for Access to Sensitive Compartmented Information and Other Controlled Access Program Information, 1 October 2008 (Including ICPG 704.1 – 704.5)
5. ICD 705 - Sensitive Compartmented Information Facilities (26 May 2010)
6. ICD 710 – Classification and Control Markings System (11 September 2009)
7. The Intelligence Community Classification and Control Markings Implementation Manual, (U/FOUO), with its classified Appendix-A
8. The Authorized Classification and Control Markings Register, (U/FOUO), with its classified Annex A and Annex B
9. Department of Defense Manual 5105.21-Vol 3, Sensitive Compartmented Information Administrative Security Manual (19 October 2012) (DoD 5105.21-Vol 3) mailto:aflcmc.inms@eglin.af.mil
10. Department of Defense Manual 5220.22-M, National Industrial Security Program Operating Manual, February 2006, C1 28 March 2013
11. Joint DoDIIS Cryptologic SCI Information Systems Security Standards (JDCSISSS) (For Official Use Only), 20 September 2012
12. Air Force Instruction 14-302, Control, Protection, and Dissemination of Sensitive Compartmented Information (18 January 1994)
13. Air Force Manual14-304, The Security Use and Dissemination of Sensitive Compartmented Information,, 23 December 2016
(14) There will be multiple Security Classification Guides at the organizational level as this Contract applies to several organizations. Contact the Contracting Officer’s Representative (COR) of each Performance Work Statement (PWS) requirement for guidance.
Item 13.c: Inquiries pertaining to classification guidance on SCI will be directed to the responsible 96 TW COR, indicated in Item 13.aa. Any SCI-derived material generated under this contract will be reviewed by the contract monitor for proper classification prior to final publication and distribution. The responsible special security office (shown in item 13.w) will provide assistance as required.
Item 13.d: SCI data furnished to or generated by the contractor will require special security handling and controls beyond those in the National Industrial Security Program Operating Manual (NISPOM).
Supplemental instructions will be furnished and/or made available to the contractor through the COR by
AFLCMC/INMS (SSO EGLIN).
Item 13.e: Names of contractor personnel requiring access to SCI will be submitted to the contract monitor for approval. If required, submit an Electronic Questionnaires for Investigations Processing (e- QIP) requesting a Single Scope Background Investigation (SSBI), prepared in accordance with the NISPOM and submitted to OPM. Upon approval by the contract monitor, a letter justifying need for access will be prepared and submitted to AFLCMC/INMS.
Item 13.f: The contractor will notify AFLCMC/INMS immediately upon receiving “reportable information” or knowledge of a change in the personal status involving employees assigned to work on this contract who have SCI access or access to any other intelligence information. “Reportable information” is defined in ICPG 704.1 – 704.5 of ICD 704 - Personnel Security Standards and Procedures Governing Eligibility for Access to Sensitive Compartmented Information and Other Controlled Access Program Information.
“Changes in status” is defined in Chapter 2 of Department of Defense Manual 5105.21-Vol 3, Sensitive Compartmented Information Administrative Security Manual (19 October 2012) (DoD 5105.21-Vol 3) Department . These two categories will be interpreted to mean information or changes in personal status which could potentially affect the employee’s continuing eligibility for access to SCI.
Item 13.g: The contractor will establish and maintain an access list of those employees working on the contract. A copy of this list will be furnished to the contract monitor when requested.
Item 13.h: The contractor will submit a Visit Cert request to AFLCMC/INMS for transmitting SCI certifications to their travel location.
Item 13.i: The contractor will advise AFLCMC/INMS through the SCI contract monitor immediately upon reassignment of personnel to other duties not associated with this contract.
Item 13.j: Release of Information: SCI will not be released to contractor employees without specific release approval of the Eglin Senior Intelligence Officer (SIO) or the originator of the material when applicable. SCI with restrictive caveats (ORCON, PROPIN, etc.) will be released to contractors only when originator approval has been obtained. This approval will be obtained through AFLCMC/INMS based on approval and certification of "need-to-know" by the COR. SCI documentation, or other material concerning this contract, will not be discussed with or released to any individual, subcontractor, agency (including Federal Government agencies and employees), and contractor employees not working on the contract without prior written approval from the contract monitor.
Item 13.k: SCI materials furnished in support of this contract remains the property of the DoD department or command that released it. Upon completion or cancellation of the contract, all SCI materials furnished will be returned to the direct custody of the originator of the materials.
Item 13.l: When required, the contractor will derivatively classify documents created in the course of this contract using the procedures and criteria defined in Executive Order 13526, Classified National Security Information, (EO 13526) as amended and Information Security Oversight Office Implementing Directive No. 1. Requests for original classification of intelligence information at any classification level or within any compartment will be referred to AFLCMC/INM. Requests for classification not involving SCI or intelligence will be referred to the 96 TW Information Protection Office via the Contracting Office Representative (COR).
Item 13.m: The contractor is prohibited from using references to SCI accesses, even by unclassified acronyms, in advertising, promotional efforts, recruitment media or on the company website.
Item 13.n: Contractor personnel must not reproduce classified foreign intelligence without advance approval of the releasing agency. If permission is granted, each copy will be controlled in the same manner as the original. The CSSO must not destroy any classified foreign intelligence without advance approval of the releasing agency.
Item 13.o: The contractor will not sanitize or decompartment any SCI or intelligence. If the contractor believes fulfillment of this contract requires sanitization of SCI or decompartmentation of intelligence, the information will be forwarded to AFLCMC/INMS.
Item 13.q: (Other SCIF) Access to SCI is limited to a US Government or other contractor SCIF; see notification of Government Security Activity clause contained in the contract.
Note 1: If the SCIF belongs to another government agency (someone else is cognizant authority for the security over the facility) a co-utilization agreement must be executed. You, as the COR, are responsible to ensure that information is provided to AFLCMC/INMS for approval prior to the contractor starting work in another agency’s SCIF. A sample format can be obtained from
AFLCMC/INMS.
Note 2: For any of the items above, it is required that you list specific locations, addresses, and for contractor(s) locations; also show CAGE Codes and appropriate DSS office addresses.
Item 13.r: This contract does/does not require the use of Defense Courier Service.
Item 13.s: Information assurance and electronic processing; information security (computer) and network connectivity require accreditation of the equipment connectivity.
Item 13.u: AFLCMC/INMS prohibits the possession or use of all cameras, video recorders, audio recorders, cellular phones, hand-held radios, two-way pagers, FitBits and all devices containing a Radio Frequency transmitter in any AFLCMC/INM SCIF. The contractors will comply with AFLCMC/INM policies which prohibit the possession or use of memory/storage devices variously described as Flash Memory, Memory Sticks, Smart Media, Thumb Drives and/or Jump Drives in SCIFs.
Item 13.v: All DD Form 254s prepared for subcontracts involving access to SCI under this contract must be forwarded to the COR for approval and then to (SSO, location) for review and concurrence prior to award of the subcontract. Inquiries pertaining to classification guidance on SCI will be directed to the COR listed on the DD Form 254 or SCI attachment. SCI security management issues shall be directed to AFLCMC/INM Senior Intelligence Officer (through the Special Security Office).
Item 13.w: The contractors will require access to intelligence information and must comply with AFI14-304. The Contract Office Representative (COR) has determined that disclosure does not create an unfair advantage for the contractor or a conflict of interest with the contractor’s obligation to protect the information.
SPECIAL SECURITY OFFICE (SSO)
AFLCMC/INMS
101 West D. Avenue, Suite 102
PHONE: DSN 872-3908, COM (850)-882-3908
Item 13.y: The contract monitor for SCI is:
AFTC/AZL
Dava Oliver 102 West D Avenue, Suite 201
PHONE: DSN 875-3716, COM (850)-882-0741
Item 13.aa: RELEASE OF NON-SENSITIVE COMPARTMENTED INFORMATION (NON-
SCI) INTELLIGENCE INFORMATION TO US CONTRACTORS
3. Requirements for access to intelligence information:
a. All intelligence material released to the contractor remains the property of the US Government and may be withdrawn at any time. Contractors must maintain accountability for all classified intelligence released into their custody.
b. Contractor personnel must not reproduce classified foreign intelligence without advance approval of the releasing agency. If permission is granted, each copy will be controlled in the same manner as the original.
The CSSO must not destroy any classified foreign…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .