Attachment 11 Draft 96 CTG DD254.pdf

PDF 589 KB Posted

Attached to
96 CTG DRAFT FOPR Federal contract opportunity
Solicitation number
FA2486-20-F-DRAFT
Issued by
Department of the Air Force Materiel Command Test Center

About this file

Draft DD254

View the file

Other files for this federal contract opportunity

Show all 19

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Please wait...

If this message is not eventually replaced by the proper contents of the document, your PDF viewer may not be able to display this type of document.

You can upgrade to the latest version of Adobe Reader for Windows®, Mac, or Linux® by visiting http://www.adobe.com/go/reader_download.

For more assistance with Adobe Reader visit http://www.adobe.com/go/acrreader.

Windows is either a registered trademark or a trademark of Microsoft Corporation in the United States and/or other countries. Mac is a trademark of Apple Inc., registered in the United States and other countries. Linux is the registered trademark of Linus Torvalds in the U.S. and other countries.

CONTRACTOR PERFORMANCE ON A GOVERNMENT INSTALLATION ATTACHMENT

TEMPEST REQUIREMENTS

1. The contractor shall ensure that TEMPEST conditions related to this contract are minimized.

2. When government furnished or contractor owned Information Systems (IS) are used on government installations TEMPEST countermeasures will be applied by the government supporting activity. Classified processing shall not begin until accreditation is completed by appropriate government personnel.

3. The contractor is required to provide copies of the written approval/authorization to appropriate government personnel upon request.

4. Problems encountered in obtaining the written approval/authorization for classified processing should be brought to the attention of the Government Contracting Activity (GCA) and Government Program Manager.

5. The TEMPEST authority on military installations is the local Communications Squadron.

6. Use of any telecommunications systems or devices on military installations to include, but not limited to, government issued cellular phones, hand-held radios, beepers/pagers, cordless telephones, cordless microphones, facsimile machines, and computers constitutes consent to monitoring in accordance with AFI 10-712.

COMSEC ACCESS AND /OR ACCOUNT ATTACHMENT

1. The contractor is governed by AFMAN 17-1302-O, AFKAG-2 and appropriate Air Force Systems Security Instructions/Manuals (AFSSI/AFSSM) or Air Force Instructions (AFI). Access to COMSEC material or information is restricted to U.S. citizens holding final United States Government clearances and is not releasable to personnel holding only a reciprocal clearance. Personnel requiring COMSEC access shall be briefed in accordance with AFMAN 17-1302-O (COMSEC Operations). NOTE: The COMSEC briefing applies only to the use and control of cryptographic equipment and specialized COMSEC publications. NACSIM/NACSEM documents are not considered COMSEC controlled material.

Additionally, cryptographic information/equipment shall be retained in a contractor facility user COMSEC account in accordance with current guidelines. The Air Force program/project manager shall designate the number of personnel requiring COMSEC access. The number will be limited to the minimum necessary and will be on a strict need-to-know basis.

2. When COMSEC support, including secure phone or other secure voice capabilities, is provided by an AF COMSEC Account, the contractor must comply with AFMAN 17-1302-O.

CONTROLLED UNCLASSIFIED INFORMATION (CUI) ADDENDUM ATTACHMENT

CONTROLLED UNCLASSIFIED INFORMATION (CUI) ADDENDUM

1. The definition of CUI is information that requires safeguarding or dissemination controls pursuant to and consistent with law, regulations, and Government-wide policies, excluding information that is classified pursuant to Executive Order 13526 of 29 December 2009 or the Atomic Energy Act, as amended. In accordance with DoD Instruction 5230.24, Distribution statements on Technical Documents, such information is referred to collectively as CUI. DoD 5200.1, Volume 4, DoD Information Security Program: Controlled Unclassified Information (CUI) identifies the controls and protective measures developed for DoD CUI (i.e., For Official Use Only (FOUO), Law Enforcement Sensitive (LES), DoD Unclassified Controlled Nuclear Information (DoD UCNI), and LIMITED DISTRIBUTION) as well as some of those developed by other Executive Branch agencies.

2. When CUI is to be provided to or generated by DoD contractors, the controls and protective measures to be applied shall be described in the pertinent contract documents (e.g., contact clause; statement of work; or DD Form 254, “Department of Defense Contract Security Classification Specification”). Solicitations and contracts shall use a non-disclosure of information clause that prohibits release of unclassified information to the public without approval of the contracting activity. The clause shall also be made applicable to subcontractors.

3. The Contractor shall not release to anyone outside the Contractor’s organization any unclassified information, regardless of medium (e.g., film, tape, document), pertaining to any part of this contract or any program related to this contract without prior approval from the government.

4. Technical Data is any recorded information related to experimental, developmental, or engineering works that can be used to define an engineering or manufacturing process or to design, procure, produce, support, maintain, operate, repair, or overhaul program material. The data may be graphic or pictoral delineations in media, such as computer software, drawings, or photographs, text in specifications, or related performance or design documents, or computer printouts. Examples of technical data include research and engineering data, engineering drawings, and associated lists, specifications, standards, process sheets, manuals, technical reports, catalog-item identifications, and computer software documentation.

5. GOVERNMENT DISTRIBUTIONS STATEMENTS: Will be added to all technical data generated during the execution of this contract, in accordance with DoD Instruction 5230.24.

6. The contractor shall protect CUI from unauthorized disclosure by appropriately marking, safeguarding, disseminating, and destroying such information. CUI will be checked in accordance with DoD 5200,01, Volume 4.

7. CUI may be identified in security classification guides to ensure the information receives appropriate protection.

8. For unauthorized disclosures of CUI, no formal security inquiry or investigation is required. However, appropriate management action shall be taken to fix responsibility for unauthorized disclosure of CUI whenever feasible or required by other guidance, and appropriate disciplinary action shall be taken against those responsible. The DoD Component that originated the CUI shall be informed of its unauthorized disclosure.

SCI ATTACHMENT

COMPANY NAME: TBD

CONTRACT #: FA2486-20-F-1001

CONTRACT EXPIRATION DATE: 30 SEP 25

NOTE: The Contract Office Representative (Program Manager if delegated duties) is required to send Statement Of Works (SOW) or Performance Work Statement (PWS) for verification of SCI requirements to the following workflow box: AFLCMC/INMS Workflow (Eglin) Special Security Office aflcmc.inms@eglin.af.mil.

Item 13.a: This contract requires access to Sensitive Compartmented Information (SCI). Per (list applicable DoD publications, ICDs, DCIDs, DoDM 5105.21, Volumes 1,2 3 and AFMAN 14-401, Joint DoDISS Cryptologic SCI Information Systems Standards (JDCSISSS), NISPOM Supplement, etc.)

provides the necessary guidance for physical, personnel, information and information systems security measures and is part of the SCI security specifications for the contract (See Item 13B).

Item 13.b: The following documents, with subsequent versions or changes, will be used for specific security classification guidance on this contract (if newer editions are published after award of the contract, the contractor will utilize the most recent edition of these documents):

1. Executive Order 13526, Classified National Security Information, (29 December 2009)

2. Director of Central Intelligence Directive 6/1 Security Policy for Sensitive Compartmented Information and Security Policy Manual (1 March 1995/ 4 November 2003)

3. ICD 503 - Intelligence Community Information Technology Systems Security: Risk Management, Certification and Accreditation, 15 September 2008

4. ICD 704 - Personnel Security Standards and Procedures Governing Eligibility for Access to Sensitive Compartmented Information and Other Controlled Access Program Information, 1 October 2008 (Including ICPG 704.1 – 704.5)

5. ICD 705 - Sensitive Compartmented Information Facilities (26 May 2010)

6. ICD 710 – Classification and Control Markings System (11 September 2009)

7. The Intelligence Community Classification and Control Markings Implementation Manual, (U/FOUO), with its classified Appendix-A

8. The Authorized Classification and Control Markings Register, (U/FOUO), with its classified Annex A and Annex B

9. Department of Defense Manual 5105.21-Vol 3, Sensitive Compartmented Information Administrative Security Manual (19 October 2012) (DoD 5105.21-Vol 3) mailto:aflcmc.inms@eglin.af.mil

10. Department of Defense Manual 5220.22-M, National Industrial Security Program Operating Manual, February 2006, C1 28 March 2013

11. Joint DoDIIS Cryptologic SCI Information Systems Security Standards (JDCSISSS) (For Official Use Only), 20 September 2012

12. Air Force Instruction 14-302, Control, Protection, and Dissemination of Sensitive Compartmented Information (18 January 1994)

13. Air Force Manual14-304, The Security Use and Dissemination of Sensitive Compartmented Information,, 23 December 2016

(14) There will be multiple Security Classification Guides at the organizational level as this Contract applies to several organizations. Contact the Contracting Officer’s Representative (COR) of each Performance Work Statement (PWS) requirement for guidance.

Item 13.c: Inquiries pertaining to classification guidance on SCI will be directed to the responsible 96 TW COR, indicated in Item 13.aa. Any SCI-derived material generated under this contract will be reviewed by the contract monitor for proper classification prior to final publication and distribution. The responsible special security office (shown in item 13.w) will provide assistance as required.

Item 13.d: SCI data furnished to or generated by the contractor will require special security handling and controls beyond those in the National Industrial Security Program Operating Manual (NISPOM).

Supplemental instructions will be furnished and/or made available to the contractor through the COR by

AFLCMC/INMS (SSO EGLIN).

Item 13.e: Names of contractor personnel requiring access to SCI will be submitted to the contract monitor for approval. If required, submit an Electronic Questionnaires for Investigations Processing (e- QIP) requesting a Single Scope Background Investigation (SSBI), prepared in accordance with the NISPOM and submitted to OPM. Upon approval by the contract monitor, a letter justifying need for access will be prepared and submitted to AFLCMC/INMS.

Item 13.f: The contractor will notify AFLCMC/INMS immediately upon receiving “reportable information” or knowledge of a change in the personal status involving employees assigned to work on this contract who have SCI access or access to any other intelligence information. “Reportable information” is defined in ICPG 704.1 – 704.5 of ICD 704 - Personnel Security Standards and Procedures Governing Eligibility for Access to Sensitive Compartmented Information and Other Controlled Access Program Information.

“Changes in status” is defined in Chapter 2 of Department of Defense Manual 5105.21-Vol 3, Sensitive Compartmented Information Administrative Security Manual (19 October 2012) (DoD 5105.21-Vol 3) Department . These two categories will be interpreted to mean information or changes in personal status which could potentially affect the employee’s continuing eligibility for access to SCI.

Item 13.g: The contractor will establish and maintain an access list of those employees working on the contract. A copy of this list will be furnished to the contract monitor when requested.

Item 13.h: The contractor will submit a Visit Cert request to AFLCMC/INMS for transmitting SCI certifications to their travel location.

Item 13.i: The contractor will advise AFLCMC/INMS through the SCI contract monitor immediately upon reassignment of personnel to other duties not associated with this contract.

Item 13.j: Release of Information: SCI will not be released to contractor employees without specific release approval of the Eglin Senior Intelligence Officer (SIO) or the originator of the material when applicable. SCI with restrictive caveats (ORCON, PROPIN, etc.) will be released to contractors only when originator approval has been obtained. This approval will be obtained through AFLCMC/INMS based on approval and certification of "need-to-know" by the COR. SCI documentation, or other material concerning this contract, will not be discussed with or released to any individual, subcontractor, agency (including Federal Government agencies and employees), and contractor employees not working on the contract without prior written approval from the contract monitor.

Item 13.k: SCI materials furnished in support of this contract remains the property of the DoD department or command that released it. Upon completion or cancellation of the contract, all SCI materials furnished will be returned to the direct custody of the originator of the materials.

Item 13.l: When required, the contractor will derivatively classify documents created in the course of this contract using the procedures and criteria defined in Executive Order 13526, Classified National Security Information, (EO 13526) as amended and Information Security Oversight Office Implementing Directive No. 1. Requests for original classification of intelligence information at any classification level or within any compartment will be referred to AFLCMC/INM. Requests for classification not involving SCI or intelligence will be referred to the 96 TW Information Protection Office via the Contracting Office Representative (COR).

Item 13.m: The contractor is prohibited from using references to SCI accesses, even by unclassified acronyms, in advertising, promotional efforts, recruitment media or on the company website.

Item 13.n: Contractor personnel must not reproduce classified foreign intelligence without advance approval of the releasing agency. If permission is granted, each copy will be controlled in the same manner as the original. The CSSO must not destroy any classified foreign intelligence without advance approval of the releasing agency.

Item 13.o: The contractor will not sanitize or decompartment any SCI or intelligence. If the contractor believes fulfillment of this contract requires sanitization of SCI or decompartmentation of intelligence, the information will be forwarded to AFLCMC/INMS.

Item 13.q: (Other SCIF) Access to SCI is limited to a US Government or other contractor SCIF; see notification of Government Security Activity clause contained in the contract.

Note 1: If the SCIF belongs to another government agency (someone else is cognizant authority for the security over the facility) a co-utilization agreement must be executed. You, as the COR, are responsible to ensure that information is provided to AFLCMC/INMS for approval prior to the contractor starting work in another agency’s SCIF. A sample format can be obtained from

AFLCMC/INMS.

Note 2: For any of the items above, it is required that you list specific locations, addresses, and for contractor(s) locations; also show CAGE Codes and appropriate DSS office addresses.

Item 13.r: This contract does/does not require the use of Defense Courier Service.

Item 13.s: Information assurance and electronic processing; information security (computer) and network connectivity require accreditation of the equipment connectivity.

Item 13.u: AFLCMC/INMS prohibits the possession or use of all cameras, video recorders, audio recorders, cellular phones, hand-held radios, two-way pagers, FitBits and all devices containing a Radio Frequency transmitter in any AFLCMC/INM SCIF. The contractors will comply with AFLCMC/INM policies which prohibit the possession or use of memory/storage devices variously described as Flash Memory, Memory Sticks, Smart Media, Thumb Drives and/or Jump Drives in SCIFs.

Item 13.v: All DD Form 254s prepared for subcontracts involving access to SCI under this contract must be forwarded to the COR for approval and then to (SSO, location) for review and concurrence prior to award of the subcontract. Inquiries pertaining to classification guidance on SCI will be directed to the COR listed on the DD Form 254 or SCI attachment. SCI security management issues shall be directed to AFLCMC/INM Senior Intelligence Officer (through the Special Security Office).

Item 13.w: The contractors will require access to intelligence information and must comply with AFI14-304. The Contract Office Representative (COR) has determined that disclosure does not create an unfair advantage for the contractor or a conflict of interest with the contractor’s obligation to protect the information.

SPECIAL SECURITY OFFICE (SSO)

AFLCMC/INMS

101 West D. Avenue, Suite 102 Eglin AFB, FL 32542

PHONE: DSN 872-3908, COM (850)-882-3908

Item 13.y: The contract monitor for SCI is:

AFTC/AZL

Dava Oliver 102 West D Avenue, Suite 201 Eglin AFB, FL 32542

PHONE: DSN 875-3716, COM (850)-882-0741

Item 13.aa: RELEASE OF NON-SENSITIVE COMPARTMENTED INFORMATION (NON-

SCI) INTELLIGENCE INFORMATION TO US CONTRACTORS

3. Requirements for access to intelligence information:

a. All intelligence material released to the contractor remains the property of the US Government and may be withdrawn at any time. Contractors must maintain accountability for all classified intelligence released into their custody.

b. Contractor personnel must not reproduce classified foreign intelligence without advance approval of the releasing agency. If permission is granted, each copy will be controlled in the same manner as the original.

The CSSO must not destroy any classified foreign intelligence without advance approval of the releasing agency.

c. The contractor must not destroy any intelligence material without advance approval or as specified by the contract monitor (COR). (EXCEPTION: Classified waste shall be destroyed as soon as practical in accordance with the provisions of the Industrial Security Program.)

d. The contractor must restrict access to only those individuals who possess the necessary security clearance and who are actually providing services under the contract with a valid need to know. Further dissemination to other contractors, sub-contractors, other government agencies, private individuals or organizations is prohibited unless authorized in writing by the originating agency through the COR.

e. The contractor must ensure each employee having access to intelligence material is fully aware of the special security requirements for this material and shall maintain records in a manner that will permit the contractor to furnish, on demand, the names of individuals who have had access to this material in their custody.

f. Classified foreign intelligence materials must not be released to foreign nationals or immigrant aliens whether or not they are also consultants, U.S. contractors, or employees of the contractor regardless of the level of their security clearance, except with advance written permission from the originator.

g. Upon completion or termination of the classified contract, or sooner when the purpose of the release has been served, the contractor will return all classified intelligence (furnished or generated) to the source from which received unless retention or other disposition instructions (see AFMAN 37-139) are authorized in writing by the COR.

h. The contractor must designate an individual who is working on the contract as custodian. The designated custodian shall be responsible for receipting and accounting for all classified material. The inner wrapper of all classified material dispatched should be checked for the attention of a designated custodian and must not be opened by anyone not working directly on the contract.

i. Within 30 days after the final product is received and accepted by the procuring agency, classified intelligence materials released to or generated by the contractor must be returned to the originating agency, through the contract monitor, unless written instructions authorizing destruction or retention are issued. Requests to retain material shall be directed to the COR for this contract in writing and clearly indicate the justification for retention and identity of the specific document to be retained.

j. Classification, reclassification, or declassification markings of documentation produced by the contractor shall be consistent with that applied to the information or documentation from which the new document was prepared. If a compilation of information or a complete analysis of subject appears to require a security classification other than that of the source documentation, the contractor shall assign the tentative security classification and request instructions from the contract monitor. Pending final determination, the material shall be safeguarded as required for its assigned or proposed classification, whichever is higher, until the classification is changed or otherwise verified.

4. Intelligence material carries special markings. The following is a list of the authorized control markings of intelligence material:

a. Intelligence that carries the ORCON marking requires written permission of the originating agency before release to a contractor outside of government owned or controlled facilities. Sponsoring agencies delete any reference to the Central Intelligence Agency (CIA) phrase “Directorate of

Operations” and any of its components, place acquired, field number, source description, and field dissemination from all CIA Directorate of Operations reports passed to contractors, unless prior approval to do otherwise is obtained from CIA.

b. Intelligence that carries the PROPIN markings requires written permission of the originating agency before release to contractors within or outside of government owned or controlled facilities.

c. Permit ready identification of an intelligence source or method which is particularly susceptible to countermeasures that would nullify or measurably reduce its effectiveness. This marking may not be used when an item or information will reasonably be protected by the use of other markings specified herein, or by the application of the “need-to-know” principle and the safeguarding procedures of the security classification system.

d. Authorized for Release to (Name of the Country(ies)/International Organization.) The above is abbreviated “REL _______________________.” This marking must be used when it is necessary to identify classified intelligence material the US government originator has predetermined to be releasable or has been released through established foreign disclosure channels to the indicated country(ies) or organization.

5. The following procedures govern the use of control markings.

a. Any recipient desiring to use intelligence in a manner contrary to restrictions established by the control markings set forth above shall obtain the advance permission of the originating agency through the COR. Such permission applies only to the specific purposes agreed to by the originator and does not automatically apply to all recipients. Originators shall ensure that prompt consideration is given to recipients’ requests in these regards, with particular attention to reviewing and editing, if necessary, sanitized or paraphrased versions to derive a text suitable for release subject to lesser or no control markings.

b. The control marking authorized above shall be shown on the title page, front cover, and other applicable pages of documents, incorporated in the text of electrical communications, shown on graphics, and associated (in full or abbreviated form) with data stored or processed in automatic data processing systems. The control marking also shall be indicated by parenthetical use of the marking abbreviations at the beginning or end of the appropriate portions. If the control marking applies to several or all portions, the document must be checked with a statement to this effect rather than marking each portion individually.

c. The control markings shall be individually assigned at the time of preparation of intelligence products and used in conjunction with security classifications and other marking specified by E.O. 13526 and its implementing security directives. The marking shall be carried forward to any new format in which the same information is incorporated including oral and visual presentations.

6. Request for release of intelligence material to a contractor must be validated by the contract monitor (COR) and coordinated through the Senior Intelligence Officer if needed. The COR accounts for all intelligence information released to the contractor and ensures electronic access to classified information is documented in Block 11 on DD Form 254 (e.g.

access to Secure Internet Protocol Network [SIPRNET], and/or any other classified network). Contractor personnel must maintain accountability for all intelligence (to include foreign intelligence materials released to their custody.

ADDENDUM TO DD FORM 254

Contract Number: FA2486-20-F-1001

Special Access Information Effective: 20200701

In performing this contract, the contractor will have access to Special Access Program Information or material only at another contractor’s facility or government activity as stated in Item 8.a. of this DD Form 254.

• DoD 5220.22-M, National Industrial Security Program Operating Manual (NISPOM), latest version

• DoD Directive (DoDD) 5205.07, Special Access Program Policy, as supplemented (latest version)

• DoD Instruction (DoDI) 5205.11, Management, Administration, and Oversight of DoD Special Access

Programs (SAPs), (latest version)

• DoDM 5205.07, Volume 1 – AFMAN 16-703 V1, DoD Special Access Program (SAP) Security Manual:

General Procedures (latest version)

• DoDM 5205.07, Volume 2 – AFMAN 16-703 V2, DoD Special Access Program (SAP) Security Manual:

Personnel Security (latest version)

• DoDM 5205.07, Volume 3 – AFMAN 16-703 V3, DoD Special Access Program (SAP) Security Manual:

Physical Security (latest version)

• DoDM 5205.07, Volume 4, SAP Security marking Manual: Marking (latest version)

• DoDM 5200.01, Volume 1, DoD Information Security Program: Overview, Classification and

Declassification (latest version)

• DoDM 5200.01, Volume 2, DoD Information Security Program: Marking of Classified (latest version)

• DoDM 5200.01, Volume 3, DoD Information Security Program: Protection of Classified Information

(latest version)

• DoDM 5200.01, Volume 4, DoD Information Security Program: Controlled Unclassified Information

(latest version)

• DoD Instruction (DoDI) 5000.02, Operation of the Defense Acquisition System (latest version)

• Air Force Policy Directive (AFPD) 16-7, Special Access Programs (latest version)

• Air Force Instruction (AFI) 16-701, Management, Administration, and Oversight of Special Access

Programs (latest version)

• Risk Management Framework (RMF) using the Joint Special Access Program Implementation Guide

(JSIG) (latest version)

• DoD Instruction (DoDI) 8510.01, Risk Management Framework (RMF) for DoD Information

Technology (IT) (latest version)

• SAF/AAZ Memorandum, Implementing DoD Manual 5205.07, V4, SAP Manual: Marking, United

States Air Force Security Marking Guide for Special Access Programs (latest version)

• SAF/AAZ Memorandum, Implementation of DoDM 5205.07, DoD Special Access Program (SAP)

Security Manual, Volumes 1-4 (latest version)

• SAF/AAZ Memorandum, Implementation of DoDM 5205.07, DoD Special Access Program (SAP) Security Manual, Volumes 1-4 (latest version)

• DoD Issuances website: http://www.dtic.mil/whs/directives/

• AF e-Publications website: http://www.e-publishing.af.mil/

• NSA/CSS Policy Manual 3-16, Control of COMSEC Material (latest version)

• Or if COMSEC material is under the AF cog add:

• AFMAN 17-1302-O, dated 3 Feb 17, Communications Security (COMSEC) Operations

• Air Force Instruction (AFI) 33-201v2, Change 2, Communications Security (COMSEC) User

Requirements (latest version)

• Air Force Instruction (AFI) 33-201v9, Operational Instructions for Secure Voice Devices (latest version)

• CNSSAM TEMPEST/01-13, RED/BLACK Installation Guidance (latest version)

• Security Classification Guidance, there will be multiple Security Classification guides at the program level as this Contract applies to several programs. Contact the Contracting Officer’s Representative (COR) of the Performance Work Statement (PWS) requirement for guidance. Security Classification Guides will be provided at the performance location under separate cover.

• OPSEC Plan or Legend, the designated COR will provide appropriate information when required.

Supersession of any of the above documents will not require an immediate revision to this DD Form 254.

The updated document will be deemed to be on contract as of the date of the supersession. Additional costs incurred due to updated guidance will be brought to the attention of the Government Contract Officer immediately.

CONTRACT NUMBER:__________________________________________

COMPANY NAME:______________________________________________

96 TW Cybersecurity

GSSO

AFOSI Det 3

Other

AFLCMC/EB

PPP (AFLCMC EB Contracts Only

96 TW/IPIP

Industrial Security

96 TW/IPIP

OPSEC

AFLCMC/INMA

AFLCMC/INMS

Program Manager

N/A

N/A

CONTRACT NUMBER: FA2486-20-F-1001

COMPANY NAME: TBD

DRAFT

SAMPLE

PREVIOUS EDITION IS OBSOLETE.

Page of AEM LiveCycle Designer

DD FORM 254, APR 2018

NEEDS DD67

DEPARTMENT OF DEFENSE

CONTRACT SECURITY CLASSIFICATION SPECIFICATION

(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)

OMB No. 0704-0567 OMB approval expires:

October 31, 2020 The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.

RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.

1. CLEARANCE AND SAFEGUARDING

2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)

3. THIS SPECIFICATION IS: (X and complete as applicable.)

a. ORIGINAL (Complete date in all cases.)

b. REVISED (Supersedes all previous specifications.)

4. IS THIS A FOLLOW-ON CONTRACT?

If yes, complete the following:

Classified material received or generated under

5. IS THIS A FINAL DD FORM 254?

If yes, complete the following:

6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)

7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor)

8. ACTUAL PERFORMANCE (Click button to add more locations.)

10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)

e. NATIONAL INTELLIGENCE INFORMATION:

11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)

12. PUBLIC RELEASE

Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)

13. SECURITY GUIDANCE

The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.

(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)

14. ADDITIONAL SECURITY REQUIREMENTS

Requirements, in addition to NISPOM requirements for classified information, are established for this contract.

If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)

15. INSPECTIONS

Elements of this contract are outside the inspection responsibility of the CSO.

If Yes, explain and identify specific areas and government activity responsible for inspections. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)

16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)

17. CERTIFICATION AND SIGNATURES

Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below. Upon digitally signing Item 17h, no changes can be made as the form will be locked.

18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL

9.0.0.2.20120627.2.874785 DD 254, DoD Contract Security Classification Specification List of Attachments [5] (All Files Must be Attached Prior to Signing, i.e., for any digital signature on the form) TEMPEST & COMSEC on-base.pdf CONTROLLED UNCLASSIFIED INFORMATION (CUI).pdf FA2486-20-F-1001 SCI ATTACHMENT.pdf FA2486-20-F-1001 SAP ADDENDUM TO DD FORM 254 (new).pdf FA2486-20-F-1001 Coordination Block Attachment for DD254.pdf

CurrentPage:
PageCount:
Classification: Unclassified
SerialNum:
a. Facility clearance level. Select one.: 1
b. Level of safeguarding for classified information/material required at contractor facility. Select one.: 4
Choose Yes or No: 1
Choose Yes or No: 1
Prime: FA2486-20-F-1001
Choose Yes or No: 0
Choose Yes or No: 0
Sub:
Choose Yes or No: 0
Choose Yes or No: 0
Soli:
DueDate:
dateA: 20200701
RevisionNum:
dateB:
Final:
dateC:
No: 0
No: 1
No: 0
No: 0
Yes: 1
Yes: 0
Yes: 1
Yes: 1
Enter your name here.: FA2486-16-F-0031
ReqDated:
Enter your name here.:
Name: TBD
Name: N/A
Name: Vance, Maj Adam C.
Cage: TBD
Cage: N/A
Cage: N/A
Cage: N/A
Cage: N/A
Cage: N/A
Cage: N/A
Cage: N/A
CSO: TBD
CSO: N/A
CSO: 96 TW/IPIP

101 West D Avenue, STE 14 Eglin AFB, FL 32542 CSO: 45th Test Squadron, OL-A 201 E. Moore Drive Building 856, Room 207 Maxwell AFB Gunter Annex, AL 36114

(334) 416-4169 CSO: 46th Test Squadron, OL-A 440 Spacelift Avenue, Building 335 Patrick AFB, FL 32925

(321) 494-3704 CSO: 47th Cyberspace Test Squadron 3133 General Hudnell Drive, Suite 200 San Antonio, TX 78226

(210) 925-6227 CSO: 47th Cyberspace Test Squadron, OL-B 307 E. Popson Avenue Building 1400, Room 401 Edwards AFB, CA 93524

(661) 525-2170 CSO: 96th Cyberspace Test Group, Detachment 1 102 Barksdale Street, Building 1521 Hanscom AFB, MA 01731

(781) 225-6852

addrow:
Removerow:
Click to delete a row:
Location: 96 CTG (majority of support)

Eglin AFB, FL 32542 Work will also be performed at other locations on Eglin

Location: 45th Test Squadron, OL-A Maxwell AFB Gunter Annex, AL 36114
Location: 46th Test Squadron, OL-A Patrick AFB, FL 32925
Location: 47th Cyberspace Test Squadron San Antonio, TX 78226
Location: 47th Cyberspace Test Squadron, OL-B Edwards AFB, CA 93524
Location: 96th Cyberspace Test Group, Detachment 1 Hanscom AFB, MA 01731
Block9: Technical and Management Advisory Services (TMAS) 2 assistance to support Research, Development, Test and Evaluation (RDT&E) across various geographical locations, defined mission areas.
a: 1
a: 1
a: 1
f: 1
f: 1
f: 0
b: 1
b: 0
b: 0
g: 1
g: 1
c: 1
c: 0
c: 1
h: 1
h: 0
d: 1
d: 0
d: 1
i: 0
i: 1
SCI: 1
NonSCI: 1
j: 1
j: 1
k: 1
k: 0
Enter your name here.: SIPRNET, JWICS, NC2-ESI Access required
Enter your name here.: AIS (Computer Security), Sensitive Information
e: 0
e: 1
l: 1
m: 1
direct: 0
thru: 1
Enter your name here.: See statement in Item 13
PublicAuthority:
AddSig:
RemoveSig:
text: (1) The requirements, restrictions, and other safeguards prescribed by the National Industrial Security Program Operating Manual, DoD 5220.22-M, 28 Feb 2006, Change 2, May 18, 2016 applies to all classified contract performance after 28 Feb 2006.

(2) Task ordering could require additional security classification guidance. Additional security classification guidance will be provided, maintained, and used by the contractor as required. Security classification guidance on information, hardware, and equipment not included in the security classification guides will be furnished to the contractor through the authorized contracting officer or authorized representative at the time the contractor is tasked with a classified project, furnished information, hardware, equipment or when classification changes occur. Task ordering requiring additional security classification guidance as indicated above, independent of other changes, will not require updating or revising the DD 254.

SENSITIVE INFORMATION. Sensitive information is information that if lost, misused, compromised, or accessed by unauthorized persons could adversely affect the United States’ national interest, the conduct of DoD programs, or the privacy of DoD personnel. It comes in many forms such as personal data under the Privacy Act, personnel records, privileged data (chaplain and judge advocate records), investigative data, scientific and technical information, export controlled data (critical technologies), proprietary data, or FOUO data. Sensitive information meets the criteria for exemption from mandatory public disclosure under the Freedom of Information Act (FOIA).

Sensitive information must be protected. During working hours, reasonable steps must be taken to minimize risk of access by unauthorized personnel. After working hours, sensitive information can be stored in unlocked containers, desks, or cabinets if Government or Government-contract building security is provided. If Government or Government-contract building security is not provided after working hours, sensitive information shall be stored in locked desks, file cabinets, book cases, locked rooms, or similar items. Storage in a safe designed to secure classified information is not required. Sensitive records may be destroyed by any method that will prevent disclosure of contents or reconstruction of the document. For paper items, strip shredding is recommended with 3/16” being the maximum strip width.

Provide the information requested by the Notification of Government Security Activity and Visitor Group Security Agreements clause, Air Force Federal Acquisition Regulation Supplement (AFFARS) 5352.204-9000 to the Government installation servicing Information Protection Office.

The use of cellular phones, hand-held radios, beepers/pagers, cordless telephones, cordless microphones, and all wireless electronic devices shall be addressed in the Standard Operating Procedures (SOP) of the Information Security (IS) procedures for each computer facility where classified processing is accomplished.

International Security Requirements: Contract performance/tasking could require contact and involvement with foreign nationals and/or their representatives. Contractors must comply with export control laws, the NISPOM, and any clauses in the contract along with the Statement of Work (SOW)/Performance Work Statement (PWS).

Security classification guidance on information, hardware, and equipment will be furnished to the contractor at the time access to classified is granted or when classification changes occur. This will include any special projects.

Item 10.a: The contractor requires administrative access to classified COMSEC material. The contractor will not receipt, copy, or generate classified COMSEC material. Access will be at a Government installation and will be granted by the user agency. Access to classified COMSEC information requires a final United States Government clearance at the appropriate level.

Item 10.b: The contractor is permitted access to RESTRICTED DATA (RD) in the performance of this contract. Access to RD requires a final United States Government clearance at the appropriate level.

Item 10.c: The contractor is permitted access to Critical Nuclear Weapons Design Information (CNWDI) in performance of this contract. The Government project manager or designated representative will ensure the contractor security supervisor is briefed for CNWDI prior to access being granted. DSS briefs the contractor for access to CNWDI upon request. The Air Force program official must request this action from the appropriate DSS office if desired. If the program official retains this responsibility, advise the appropriate DSS office in writing.

Item 10.d: The contractor is permitted access to Formerly Restricted Data (FRD) in the performance of this contract. Access to FRD requires a final United States Government clearance at the appropriate level.

Item 10.e.(1): All intelligence information required for this contract will be handled in accordance with special security requirements provided in the SCI Attachment and regulations listed in 13b. Prior approval of the contracting activity is required for subcontracting. Access to intelligence information requires special briefings and a United States Government clearance at the appropriate level.

Item 10.e (2): Contractor requires access and storage of Non-SCI intelligence materials and must comply with AFI 14-304 and AFMC Supplement 1. Both instructions can be found at http://www.e-publishing.af.mil. For additional guidance contact the local Senior Intelligence Officer (SIO).

Item 10.f.: See Special Access Program (SAP) Addendum.

Item 10.g: The contractor is permitted access to North Atlantic Treaty Organization (NATO) information in performance of this contract. The Government project manager is the designated representative that will ensure the contractor Facility Security Officer and concerned employees are NATO briefed prior to access being granted. Prior approval of the contracting activity is required for subcontracting. Access requires a final United States Government clearance at the appropriate level. Forward NATO classified materials needed by the contractor only from an Air Force Sub-registry directly to the contractor concerned.

Item 10.h: The contractor is permitted access to foreign government information in the performance of this contract. Access to foreign government information requires a valid need to know and a United States Government clearance at the appropriate level (interim or final). Comply with the foreign government information requirements in the NISPOM, Chapter 10, Section 3.

Item 10.j: Controlled Unclassified Information (CUI) will be checked in accordance with DoDM 5200.01, Volume 4. Also, see Controlled Unclassified Information Addendum for additional guidance

Item 10.k.: SIPRNET access is required for contract performance on government installations. A NATO awareness briefing is also required. JWICS access is required for contractors working on a government installation. NC2-ESI access required.

Item 11.a: Access to classified information is limited to the performance locations identified in 8a unless specifically approved by the CO or PM through tasking order. The using contractor or government activity will provide security classification guidance for performance of this contract.

Item 11.f: The city and country of overseas performance will be provided at the time of tasking. A copy of the DD 254 must be provided to the United States Air Force CIP responsible for overseas inspections and security oversight. HQ USAFE/IP or HQ PACAF/IP will be provided copies of the DD 254 as applicable.

IItem 11.g: The contractor is authorized to use the services of Defense Technical Information Center (DTIC) and is required to prepare and process a DD 1540, Registration for Scientific and Technical Information Services, in accordance with the NISPOM. The contracting activity must be involved in certifying need-to-know to DTIC. DTIC not authorized for SAP information.

Item 11.i: For TEMPEST requirements and guidance see the attachment entitled TEMPEST Requirements. When Government Furnished Equipment (GFE) or contractor owned Automated Information Systems (AIS) are used on Government installations, TEMPEST countermeasures will be applied by the Government supporting activity.

Item 11.j: The contractor must comply with any OPSEC requirement/clauses indicated in the contract. On military installations the contractor will follow the installation OPSEC plan and guidance set forth in AFI 10-701, Operations Security, as supplemented. Protect Critical Information (CI) and other sensitive unclassified information and activities, which could compromise the mission or operations or degrade the planning and execution of military operations performed by the contractor in support of the mission. These OPSEC requirements pertain to performance on government installations only.

Item 11.l: For CUI requirements and guidance, see the CUI Attachment.

Item 11.m: Any transfer or processing of classified or sensitive information via electronic methods (e.g. facsimile, telemetry, voice, computer) must be protected by implementing an appropriate combination of countermeasures such as encryption devices and sound practices and procedures. Specific countermeasures used must be coordinated by the project manager for approval through the appropriate communications activity.

The contract can require access to sensitive unclassified Government AIS in Categories IT-I, II, and III. At a minimum, contractor employees must be the subject of a favorable Single Scope Background Investigation if granted access and performing in Category IT-I positions. For Category IT-II positions, at a minimum, contractor employees must be the subject of a favorable National Agency Check and Local Agency Check. For Category III positions, contractor employees must be the subject of a favorable National Agency Check with Inquiries. In the event the investigation is not adjudicated favorably, unit commanders are responsible for suitability determinations. Reference AFI 31-501 and Air Force Material Command, Supplement 1 to AFI 31-501. Both publications can be found at http://www.e-publishing.af.mil.

Item 12: Public release of Special Access Program (SAP) related data is NOT authorized without prior coordination through the Air Force Office of Special Investigations (AFOSI), Office of Special Projects (PJ) Security Director and subsequent approval of the Original Classification Authority (OCA) and Air Force Special Access Program Control Office (SAPCO). Submit all proposed public disclosures related to SAP data to the Government Program Manager (GPM) and the Air Force Office of Special Investigations (AFOSI), Office of Special Projects (PJ) Program Security Officer (PSO).

96 TW/PA, 101 West D Avenue, Suite 238, Eglin AFB, Florida, 32542-5498. Contractor is to submit requests through the Contracting Officer for OPSEC Program Manager’s review and public release authorization. The Contracting Officer will provide contractor with written approval/disapproval. Information requiring AF or DoD–level review will be reviewed by the unit’s OPSEC Program Manager or Coordinator who will in-turn forward to the entry-level public affairs office through the AFIMSC Public Affairs Office to the Secretary of the Air Force, Office of Public Affairs, Security and Review Division (SAF/PAX), 1690 Air Force Pentagon, Washington DC 20330-1690. For Non-SCI Intelligence Information, contact the AFLCMC/INM, 101 West D Avenue, Suite 102, Eglin AFB, Florida, 32542-6830. PUBLIC RELEASE OF SCI IS NOT AUTHORIZED. Contact the HQ AFMC/A2S, 4225 Logistics Dr., Wright-Patterson AFB, Ohio, 45433-5750 or the HQ USAF/AFIAA/IAS, the Pentagon Room MC845, Washington DC, 20330-1480.

attachmentsList:
AddAttachment:
ViewAttachment:
RemoveAttachment:
rep:
Sig:
Enter your name here.: Requirements for SCI, Non-SCI, SAP, COMSEC, TEMPEST, and OPSEC are referenced in Item 13.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it.