Block 13 Continuation Sheet 2 Sep 09.docx
DOCX document 23 KB Posted
- Attached to
- Advisory & Assistance Services & Systems Engineering & Technical Assistance Services for Headquarters, Air Force Space Command Federal contract opportunity
- Solicitation number
- FA2517-08-R-9000
About this file
DD 254 continuation page.
View the file
Other files for this federal contract opportunity
Show all 50
Advisory & Assistance Services & Systems Engineering & Technical Assistance Services for Headquarters, Air Force Space Command has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
BLOCK 13, CONTINUATION SHEET
AFPD 33-2, Information Assurance. This Air Force Policy Directive implements DoDD 8500.1, Information Assurance, and DoDD 8581.1E, Information Assurance Policy for Space Systems used by the Department of Defense. AFPD 33-2 is the primary guide which all 33-2XX series and AFSSIs/AFSSMs publications fall under. This publication shall be applied to contractors or other persons through the contract or other legally binding agreement with the Department of the Air Force. Information Assurance consists of Communications Security (COMSEC), Network and Computer Security, and Emission Security.
SIPRNET ACCESS: The contractor shall conduct all routine day-to-day business on SIPRNet consistent with HQ AFSPC/DS letter, 27 Aug 09, Headquarters Air Force Space Command Secure Space Collaborative Environment Business Practices COMSEC: At a minimum, the contractor must comply with 33-201, Vol 2 (FOUO) Communications Security (COMSEC); Vol 4, (FOUO) Cryptographic Access Program, and Vol 9 (FOUO), Management of Crypto Systems.
PERSONNEL SECURITY CLEARANCES: All contractor personnel shall have a minimum of a “SECRET” security clearance.
Ref. 10.a: Access to COMSEC material is restricted to U.S. citizens holding final U.S. Government clearances. Such information is not releasable to personnel holding only reciprocal clearances.
Ref 10.b.: Access to RESTRICTED DATA requires a final U.S. Government clearance at the appropriate level.
Ref. 10.c. This contractor is permitted access to CNWDI in performance of this contract. The government program manager or designated representative will ensure the contractor security supervisor is briefed for CNWDI.
Ref. 10.d.: Access to FORMERLY RESTRICTED DATA requires a final U.S. Government clearance at the appropriate level.
Item 10e(2): Contractor material marked as ORCON, PROPIN, NOFORN, or REL may be released to the contractor by the contract monitor only under the provisions of DCID 6/1. The controls and definitions specified in DCID 6/1 are applicable to the contract. The CSSO must ensure all contractor employees who have access to this material are fully trained in the DCID 6/1 requirements. The CSSO must provide a list of contractor personnel who have need-to-know for this information and the contract monitor must validate need-to-know by signature before the contractor employee has access to this information.
Ref. 10.f.: The OPR for the SAP is not the office shown in Item 13 of this form. The contractor must adhere to the special access requirements/procedures developed by the OPR.
Ref 10.g.: Access to classified NATO information requires a final U.S. Government clearance at the appropriate level.
Ref 10.g.: NATO in-briefs are required prior to accessing the SIPRNET. Actual knowledge of, generation, or production of NATO information is required for performance of the contract.
Ref. 10.h.: Access requires a final U.S. Government clearance at the appropriate level.
Ref. 10.j.: FOUO information provided under this contract shall be safeguarded as specified in the attachment “Protecting For Official Use Only (FOUO) Information.”
Ref. 10k: AIS access is identified at the task order level.
Ref 11.c.: The contractor requires access to classified source data up to and including Top Secret in support of the work effort. Any extracts or use of such data requires the contractor to apply derivative classifications and markings consistent with the source documents. Use of Multiple sources on the classified by line necessitates compliance with the NISPOM (or DoD 5200.1-R and AFI 31-401 if operating on an Air Force installation), and use of bibliography. Security Classification Guides (SCGs) will be identified upon task order award.
Ref. 11.d: Contractor must provide adequate storage for classified hardware to the level of Top Secret as required in the task order.
Ref 11.f: List city and country of oversees performance locations will be addressed within each task order.
Ref 11.g.: The contractor must prepare and process a DD Form 1540 and 1541 for request to utilize the Defense Technical Information Center (DTIC). Reference the NISPOM for preparation and processing of these forms.
Ref 11.h.: A COMSEC account will be established and COMSEC will be protected per DoD 5220.22-S.
Ref 11.i: Provide the information required by AFFARS 5352.204-9000, Notification of Government Security Activity Clause and AFFARS 5352-204-9001, Visitor Group Security Agreement Clause, to the Information Security Program Manager (ISPM). Refer to the contract document for these clauses.
Block 13a: Projected Contract expiration date is 1 April 2015. This date reflects, among other things, when the SCI indoctrinated contractor personnel will be debriefed.
Block 13b: SCIFs located within HQ AFSPC, Bldg 1, and at the contractor’s facility will be used to perform SCI contractual requirements. The contractor is required to have access to an existing contractor SCIF upon contract award. SCI material released to the contractor under this contract will be separately stored and maintained only in such properly accredited facilities. SCIFs owned by an organization other than AFSPC will be used only when covered by a co-utilization Memorandum of Agreement (MOA) between AFSPC and the sponsor of the facility. The supporting SSO is HQ AFSPC/A2S.
Block 13c: The following documents with subsequent revisions or changes will be used for specific SCI security classification guidance on this contract:
AFMAN 14-304
DoD 5105.21-M-1 Signals Intelligence Security Regulation and Imagery Policy Series
JDCSISSS
Block 13d: Inquiries pertaining to classification guidance on SCI will be directed to the Contract Monitor.
Block 14: Provide the information requested by AFFARS 5352.204-9000, Notification of Government Security Activity Clause and AFFARS 5353.204-9001, Visitor Group Security Agreement Clause, to the Information Security Program Manager (ISPM). Refer to the contract document for these clauses. Shipments of classified or sensitive equipment shall be handled, transported, transmitted and protected IAW NISPOM, DoD 5220.22M and as specified by “unit directives”. The contractor shall execute a VGSA with the government.
Block 15: DSS is relieved of inspection responsibility for all classified material that is released to or developed by the contractor while on a military installation. DSS retains inspection responsibility for all non-SCI classified material released to or developed by the contractor and held in the contractors’ facility. The SSO maintains inspection responsibility for all SCI material related to this contract. Industrial security reviews while operating on an Air Force installation, shall be conducted by the ISPM. HQ AFSPC/IN retains security cognizance of all Intelligence materials released to the contractor.
EMSEC Requirements (Addendum to DD Form 254, Block 11i)
EMMISSIONS SECURITY ASSESSMENT REQUEST (ESAR)
FOR ALL CLASSIFIED SYSTEMS
The contractor shall ensure that compromising emanations (EMSEC) conditions related to this contract are minimized.
The contractor shall provide countermeasures assessment data to the Contracting Officer (CO), in the form of a EMSEC Security Assessment Request (ESAR), the ESAR shall provide only specific responses to the data required in paragraph c, below. The contractor’s standard security plan shall NOT be used as a “stand-alone” ESAR response. The contractor shall NOT submit a detailed facility analysis/assessment. The ESAR information will be used to complete an EMSEC Countermeasures Assessment Review of the contractor’s facility to be performed by the government EMSEC authority using current Air Force EMSEC directives. EMSEC is applied on a case-by-case basis and further information may be required to complete the review; should this be the case the contractor shall provide this information to the contracting officer when requested. After the evaluation of the ESAR by the government EMSEC authority, additional EMSEC requirements may be necessary.
*ESAR contents shall include, as a minimum, the following information (NISPOM, para 11-101c):
| - The specific classification and special categories of material to be processed/handled by electronic means. |
| - The percentage of information being processed. Identify the approximate percentage for each level of information processed including unclassified. |
| - The specific location where classified processing will be performed. |
| - The name, address, title and telephone number of a point-of-contact at the facility where processing will occur. |
NOTE: Once the above information has been provided to the CO, no further reporting is required for equipment reconfigurations. However, if the facility is physically relocated to another geographical location, the information requested in paragraph “c” above MUST be furnished to the CO.
The prime contractor shall ensure that all subcontractors and/or vendors comply with EMSEC requirements when performing classified processing related to this contract. They will provide the above documentation through their prime to the contracting officer to complete the ESAR.
*NOTE: A copy of your Automated Information System Security Plan(s) (AISSP) will suffice.
FOR OFFICIAL USE ONLY (FOUO)
CONTROLLED UNCLASSIFIED INFORMATION
DoD 5200.1-R, January 1997
APPENDIX 3
Description: "For Official Use Only (FOUO)" is a designation that is applied to unclassified information that may be exempt from mandatory release to the public under the Freedom of Information Act (FOIA). The FOIA specifies nine exemptions that may qualify certain information to be withheld from release to the public if, by its disclosure, a foreseeable harm would occur. They are:
1) Information that is currently and properly classified.
2) Information that pertains solely to the internal rules and practices of the Agency. (This exemption has two profiles, "high" and "low." The "high" profile permits withholding of a document that, if released, would allow circumvention of an Agency rule, policy, or statute, thereby impeding the agency in the conduct of its mission. The "low" profile permits withholding if there is no public interest in the document, and it would be an administrative burden to process the request.)
3) Information specifically exempted by a statute establishing particular criteria for withholding. The language of the statute must clearly state that the information will not be disclosed.
4) Information such as trade secrets and commercial or financial information obtained from a company on a privileged or confidential basis that, if released, would result in competitive harm to the company, impair the Government's ability to obtain like information in the future, or protect the Government's interest in compliance with program effectiveness.
5) Inter-Agency memoranda that are deliberative in nature; this exemption is appropriate for internal documents that are part of the decision making process and contain subjective evaluations, opinions and recommendations.
6) Information, the release of which could reasonably be expected to constitute a clearly unwarranted invasion of the personal privacy of individuals.
7) Records or information compiled for law enforcement purposes that: Could reasonably be expected to interfere with law enforcement proceedings; Would deprive a person of a right to a fair trial or impartial adjudication; Could reasonably be expected to constitute an unwarranted invasion of the personal privacy of others; Disclose the identity of a confidential source; Disclose investigative techniques and procedures; or Could reasonably be expected to endanger the life or physical safety of any individual.
8) Certain records of Agencies responsible for supervision of financial institutions.
9) Geological and geophysical information concerning wells.
- Information that is currently and properly classified can be withheld from mandatory release under the first exemption category. "For Official Use Only" is applied to information that is exempt under one of the other eight categories. So, by definition, information must be unclassified in order to be designated FOUO. If an item of information is declassified, it can be designated FOUO if it qualifies under one of those other categories. This means that: Information cannot be classified and FOUO at the same time; and Information that is declassified may be designated FOUO, but only if it fits into one of the last eight exemption categories (categories 2 through 9).
- The FOIA provides that, for information to be exempt from mandatory release, it must fit into one of the qualifying categories and there must be a legitimate Government purpose served by withholding it. Simply because information is marked FOUO does not mean it automatically qualifies for exemption. If a request for a record is received, the information must be reviewed to see if it meets this dual test. On the other hand, the absence of the FOUO marking does not automatically mean the information must be released. Some types of records (for example, personnel records) are not normally marked FOUO, but may still qualify for withholding under reference (g).
- Markings:
AP3.2.2.1. Information that has been determined to qualify for FOUO status should be indicated by markings when included in documents and similar material. Markings should be applied at the time documents are drafted, whenever possible, to promote proper protection of the information.
AP3.2.2.2. Unclassified documents and material containing FOUO information shall be marked as follows:
AP3.2.2.2.1. Documents will be marked "FOR OFFICIAL USE ONLY" at the bottom of the front cover (if there is one), the title page (if there is one), the first page, and the outside of the back cover (if there is one).
AP3.2.2.2.2. Pages of the document that contain FOUO information shall be marked "FOR OFFICIAL USE ONLY" at the bottom.
AP3.2.2.2.3. Material other than paper documents (for example, slides, computer media, films, etc.) shall bear markings that alert the holder or viewer that the material contains FOUO information.
AP3.2.2.2.4. FOUO documents and material transmitted outside the Department of Defense must bear an expanded marking on the face of the document so that non-DoD holders understand the status of the information. A statement similar to this one should be used:
"This document contains information exempt from mandatory disclosure under the F0IA. Exemption(s) ______ apply."
AP3.2.2.3. Classified documents and material containing FOUO information shall be marked as required by Chapter 5 of this Regulation, with FOUO information identified as follows:
AP3.2.2.3.1. Overall markings on the document shall follow the rules in Chapter 5. No special markings are required on the face of the document because it contains FOUO information.
AP3.2.2.3.2. Portions of the document shall be marked with their classification as required by Chapter 5. If there are unclassified portions that contain FOUO information, they shall be marked with "FOUO" in parentheses at the beginning of the portion. Since FOUO information is, by definition, unclassified, the "FOUO" is an acceptable substitute for the normal "U."
AP3.2.2.3.3. Pages of the document that contain classified information shall be marked as required by Chapter 5. Pages that contain FOUO information but no classified information will be marked "FOR OFFICIAL USE ONLY" at the top and bottom.
AP3.2.2.4. Transmittal documents that have no classified material attached, but do have FOUO attachments shall be marked with a statement similar to this one: "FOR OFFICIAL USE ONLY ATTACHMENT."
AP3.2.2.5. Each part of electrically transmitted messages containing FOUO information shall be marked appropriately. Unclassified messages containing FOUO information shall contain the abbreviation "FOUO" before the beginning of the text.
AP3.2.3. Access to FOUO Information. FOUO information may be disseminated within the DoD Components and between officials of the DoD Components and DoD contractors, consultants, and grantees as necessary in the conduct of official business. FOUO information may also be released to officials in other Departments and Agencies of the Executive and Judicial Branches in performance of a valid Government function. (Special restrictions may apply to information covered by the Privacy Act, reference (h).) Release of FOUO information to Members of Congress is covered by DoD Directive 5400.4 (reference (gg)) and to the General Accounting Office by DoD Directive 7650.1 (reference (ll)).
AP3.2.4. Protection of FOUO Information AP3.2.4.1. During working hours, reasonable steps should be taken to minimize risk of access by unauthorized personnel. After working hours, FOUO information shall be stored in unlocked containers, desks or cabinets if Government or Government-contract building security is provided, or in locked desks, file cabinets, bookcases, locked rooms, or similar items.
AP3.2.4.2. FOUO documents and material may be transmitted via first-class mail, parcel post or -- for bulk shipments -- fourth-class mail. Electronic transmission of FOUO information (voice, data or facsimile) should be by approved secure communications systems whenever practical.
AP3.2.4.3. Record copies of FOUO documents shall be disposed of in accordance with the Federal Records Act (44 U.S.C. 33 (reference (p))) and Component records management directives. Non-record FOUO documents may be destroyed by shredding or tearing into pieces and discarding the pieces in regular trash containers.
AP3.2.5. Further Guidance. Further guidance on one type of FOUO information is contained in DoD 5400.11-R (reference (ww)), "Department of Defense Privacy Program."
OPERATIONS SECURITY (OPSEC)
Addendum to DD Form 254, Item 11.j.
GENERAL:
1. PURPOSE: This section outlines the requirements and procedures necessary to protect Critical Information for Operations Security (OPSEC).
2. MISSION: To maintain a continuing awareness of adversary interest in center actions and adversary intelligence collection capabilities. To understand the need to identify and protect classified and unclassified indicators, which occur, reveal sensitive information. To evaluate the effectiveness of OPSEC measures taken to preclude or reduce adversary acquisition and exploitation of sensitive information.
3. DEFINITION: OPSEC is the process of analyzing friendly actions attendant to military operations and other activities to:
a. Identify those actions that can be observed by adversary intelligence systems.
b. Determine indicators hostile intelligence systems might obtain that could be interpreted or pieced together to derive critical information in time to be useful to adversaries.
c. Select and execute measures that eliminate or reduce to an acceptable level the vulnerabilities of friendly actions to adversary exploitation.
4. OBJECTIVES:
a. To protect planned operational center activities by preventing the inadvertent disclosure of unclassified information relating to or revealing a possible classified operation.
b. To preserve secrecy concerning specific scenario events and a NORAD response to these events.
c. To identify OPSEC vulnerabilities and recommend protective measures which will serve to enhance the security of future operations.
5. TASKS: Task requirements are outlined in the Statement of Work for this effort.
File details come from the government source that posted it. Updated .