Atch 3 DD254 Amendment 1.docx

DOCX document 60 KB Posted

Attached to
Technical & Advisory Support Services (TA2S) Federal contract opportunity
Solicitation number
FA2517-09-R-6032
Issued by
Department of the Air Force Space Command

About this file

Revisions to DD 254

View the file

Other files for this federal contract opportunity

Other files attached to Technical & Advisory Support Services (TA2S), newest first.
File Type Posted
SF30_ _Summary_of_Changes_-_Amendment_3.doc DOC document
Atch 3 DD254 Amendment 3.docx DOCX document
Atch 5 Section L Attachment for Amendment 2 ITWAA TO Only.docx DOCX document
SF30_ _Summary_of_Changes_-_Amendment_1.doc DOC document
Atch 5 Section L Attachment for Amendment.docx DOCX document
Q A2.docx DOCX document
J7 Exercise Support CDRLs_Rev 1.pdf PDF
TA2S 0008 Training Materials.pdf PDF
TA2S 0004 Conference Report.pdf PDF
TA2S 0009 Monthly Status Report.pdf PDF
Atch 2 Acronym List 2 July 2010.xlsx XLSX spreadsheet
TA2S 0010 Technical Report- Study Services —
TA2S 0002 Limitations on Subcontracting.pdf PDF
TA2S 0005 Presentation Material.pdf PDF
TA2S 0011 Scientific and Technical Reports —
TA2S 0014 Syllabus.pdf PDF
TA2S 0006 Report Record of Meeting Minutes —
Atch 1 TA2S PWS 5 Nov 10.docx DOCX document
Atch 7 OCI Disclosure and Analysis Form.xlsx XLSX spreadsheet
Atch 5 Section L Attachment 19 Jan 11 following PEO review.docx DOCX document
TA2S 0017 Contractor Quality Program Plan.pdf PDF
TA2S RFP 28 Mar 11.docx DOCX document
TA2S RFP 4 Oct 10.docx DOCX document
Atch 5 Section L Attachment 6 Jul 10.docx DOCX document
Atch 8 Proposal Delivery Instructions.docx DOCX document
Atch 7 OCI Disclosure and Analysis Form.xlsx XLSX spreadsheet
Atch 6 OCI Mitigation Plan Checklist.docx DOCX document
Atch 1 TA2S PWS.docx DOCX document
DRAFT Section L M.docx DOCX document
Relevancy_TA2S.pdf PDF
N-NC Organizations and Components_Mission Statements.doc DOC document
TA2S NAICS Determination.pdf PDF
TA2S NAICS Determination.pdf PDF
Draft TA2S PWS_16 Dec 09.docx DOCX document
r_Lockheed Martin.pdf PDF
r_Intecon.pdf PDF
r_Delta.pdf PDF
r_SAIC2.pdf PDF
r_Willcor.pdf PDF
One-On-One Meeting Directions.pptx PPTX presentation
9005 INFO SHEET.docx DOCX document
9004 INFO SHEET.docx DOCX document
FA2517-06-D-9001.docx DOCX document
FA2517-06-D-9004.docx DOCX document
9000 INFO SHEET.docx DOCX document
9006 INFO SHEET.docx DOCX document
FA2517-06-D-9000.docx DOCX document
FA2517-06-D-9005.docx DOCX document
FA2517-06-D-9006.docx DOCX document
9001 INFO SHEET.docx DOCX document
Show all 50

Technical & Advisory Support Services (TA2S) has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DD Form 254 Continuation Sheet CONTRACT NO. FA2517-06-D-9000

DEPARTMENT OF DEFENSE
1. CLEARANCE AND SAFEGUARDING
CONTRACT SECURITY CLASSIFICATION SPECIFICATION
a. FACILITY CLEARANCE REQUIRED

TOP SECRET

(The requirements of the DoD Industrial Security Manual apply to all aspects of this effort)

b. LEVEL OF SAFEGUARDING REQUIRED

TOP SECRET

2. THIS SPECIFICATION IS FOR: (X and complete as applicable)
3. THIS SPECIFICATION IS: (X and complete as applicable)

a. PRIME CONTRACT NUMBER

a. ORIGINAL (Complete date in all cases)
Date (YYMMDD)
X
FA2517-09-R-6032
X
040511

b. SUBCONTRACT NUMBER

b. REVISED (Supersedes all previous specs)

Revision No.
Date (YYMMDD)
c. SOLICITATION OR OTHER NUMBER
Due Date (YYMMDD)
c. FINAL (Complete Item 5 in all cases)
Date (YYMMDD)

4. IS THIS A FOLLOW-ON CONTRACT?

YES
X
NO. If Yes complete the following

Classified material received or generated under_____________________________________________ (Preceding Contract Number) is transferred to this follow-on contract

5. IS THIS A FINAL DD FORM 254?

YES
X
NO. If Yes complete the following

In response to the contractor's request dated, _______ retention of the identified classified material is authorized for the period of______.

6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)

a. NAME, ADDRESS, AND ZIP CODE
b. CAGE CODE
c. COGNIZANT SECURITY OFFICE (Name, Address, and Zip Code)

7. SUBCONTRACTOR

a. NAME, ADDRESS, AND ZIP CODE
b. CAGE CODE
c. COGNIZANT SECURITY OFFICES (Name, Address, and Zip Code)

8. ACTUAL PERFORMANCE

a. LOCATION
b. CAGE CODE
c. COGNIZANT SECURITY OFFICE (Name, Address, and Zip Code)

See DD Form 254 Continuation Sheet, Attachment 4

9. GENERAL IDENTIFICATION OF THIS PROCUREMENT

Provides non-personal Advisory and Assistance Services (A&AS) and Non-Advisory and Assistance Services(Non-A&AS) to Headquarters North American Aerospace Defense Command (HQ NORAD) and Headquarters US Northern Command (HQ NORTHCOM) directorates, special staff offices, and other activities, in support of various missions, and command, control, communications, and intelligence activities.

10. THIS CONTRACT WILL REQUIRE ACCESS TO:
YES
NO
11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL:
YES
NO

a. COMMUNICATIONS SECURITY (COMSEC)

INFORMATION

X
a. HAVE ACCESS TO CLASSIFIED INFORMATION ONLY AT ANOTHER CONTRACTOR’S FACILITY OR A GOVERNMENT ACTIVITY

X

b. RESTRICTED DATA
X

b. RECEIVE CLASSIFIED DOCUMENTS ONLY

X

c. CRITICAL NUCLEAR WEAPON DESIGN INFORMATION
X
c. RECEIVE AND GENERATE CLASSIFIED MATERIAL
X
d. FORMERLY RESTRICTED DATA:
X
d. FABRICATE, MODIFY, OR STORE CLASSIFIED HARDWARE
X

e. INTELLIGENCE INFORMATION:

e. PERFORM SERVICES ONLY

X

(1) Sensitive Compartmented Information (SCI)
X
f. HAVE ACCESS TO U.S. CLASSIFIED INFORMATION OUTSIDE THE U.S., PUERTO RICO, U.S. POSSESSIONS AND TRUST TERRITORIES
X

(2) Non-SCI

X

g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE TECHNICAL INFORMATION CENTER (DTIC) OR OTHER SECONDARY DISTRIBUTION CENTER
X
f. SPECIAL ACCESS INFORMATION
X

h. REQUIRE A COMSEC ACCOUNT

X

g. NATO INFORMATION
X

i. HAVE A TEMPEST REQUIREMENT

X

h. FOREIGN GOVERNMENT INFORMATION
X
j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS
X

i. LIMITED DISSEMINATION INFORMATION

X
k. BE AUTHORIZED TO USE THE DEFENSE COURIER SERVICE

X

j. FOR OFFICIAL USE ONLY INFORMATION
X

l. OTHER (Specify):

k. OTHER SCI and NC2-ESI positions - See Block 13f

X

See Item 13 and other attachments for security guidance.
X

DD Form 254, DEC 1999 Previous editions are obsolete

12. PUBLIC RELEASE. Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the industrial Security Manual or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public release shall be submitted for approval prior to release

Direct X

Through (Specify):

HQ NORAD-USNORTHCOM/PA

250 VANDENBERG ST, STE Bldg 2

PETERSON AFB, CO 80914-3808

to the Directorate for Freedom of Information and Security Review, Office of the Assistant Secretary of Defense (Public Affairs)* for review.

*In the case of non-DoD User Agencies, requests for disclosure shall be submitted to that agency.

PUBLIC RELEASE OF FOUO, Collateral, and SCI Material IS NOT AUTHORIZED.

13. SECURITY GUIDANCE. The security classification guidance needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes: to challenge the guidance or classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended. (Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any document/guides/extracts referenced herein. Add additional pages as needed to provide complete guidance.

See DD Form 254 - Continuation Sheet and Attachments 1-3 for additional security guidance Signature blocks:

Program Manager: __________________________ Security Manager: _____________________

CHARLES ROTH, DAFC SALVATORE INGRALDI

Program Manager Command Security Manager

NORAD-USNORTHCOM/J44 NORAD-USNORTHCOM

ISPM: _____________________ SSO: __________________________

RICHARD K. ELLIN MICHAEL C. DERVISHIAN

Industrial Security Specialist Special Security Officer

21 SW/IPC NORAD-USNORTHCOM

14. ADDITIONAL SECURITY REQUIREMENTS. Requirements, in addition to ISM requirements, are established for this contract. (If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement, which identifies the additional requirements. Provide a copy of the requirements to the cognizant security office. Use Item 13 if additional space is needed.)
X
Yes

No

Prior approval of the contracting activity is required for subcontracting. Access to intelligence information requires special briefings and an U.S. Government clearance at the appropriate level. Provide the information requested by the Notification of Government Security Activity Clause, AAFARS 5352.204-9000, and Visitor Group Agreements Clause, AAFARS 5352.204-9001, to the Information Security Program Manager (ISPM) addressed in Attachment 4 of this form. Shipments of classified or sensitive equipment shall be handled, transported, transmitted and protected IAW NISPOM, DoD 5220.22M and as specified by “unit directives”. The contractor shall execute a VGSA with the government.

15. INSPECTIONS. Elements of this contract are outside the inspection responsibility of the cognizant security office. (If Yes, explain and identify specific areas or elements carved out and the activity responsible for inspections. Use Item 13 if additional space is needed.

X
Yes

No

This contract requires access to SCI, contractors retain inspection responsibility for all non-SCI classified material. No SCI material will be held in the contractor’s facility. Contractors are relieved of inspection responsibility for all classified material that is released to or developed by the contractor while on a military installation. The SSO maintains inspection responsibility for all SCI material related to this contract. Industrial security reviews while operating on an Air Force installation, shall be conducted by the ISPM. HQ N-NC SSO retains security cognizance of all Intelligence materials released to the contractor. DIA Manual 50-5 and DoD 5105 series provide the necessary guidance for physical, personnel, and information security measures and are part of the security specifications of this contract. Contractor compliance with these directives is mandatory unless specific provisions are specifically waived.

16. CERTIFICATION AND SIGNATURE. Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below.

a. TYPED NAME OF CERTIFYING OFFICIAL

b. TITLE Contracting Officer

c. TELEPHONE (Include Area Code) 719-556-

d. ADDRESS (Include ZIP Code)
17. REQUIRED DISTRIBUTION
21 CONS/LGCCB
X

a. CONTRACTOR

135 Dover St, Ste 1055

b. SUBCONTRACTOR

Peterson AFB, CO 80914-1117
X

c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR

e. SIGNATURE
X

d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION

X

e. ADMINISTRATIVE CONTRACTING OFFICER

X
f. OTHERS AS NECESSARY 21 SW/IPC and N-NC/J44

DD Form 254 Reverse, DEC 1999 Amendment 1

ITEM 10: Remarks:

Ref 10b.: Access to RESTRICTED DATA requires a final U.S. Government clearance at the appropriate level.

Ref. 10c.: This contractor is permitted access to CNWDI in performance of this contract. The government program manager or designated representative will ensure the contractor security supervisor is briefed for CNWDI.

Ref. 10d.: Access to FORMERLY RESTRICTED DATA requires a final U.S. Government clearance at the appropriate level.

Ref. 10e (1).: SCI requirements apply. Contractor takes its SCI guidance from HQ NORAD-USNORTHCOM J25S, SSO. Contractor will advise SSO of any security issues. Contractor will require access to DCID’s 6/9, 6/3, 6/4 and JDCSISSS. Secure equipment (fax, telephone, shredders) will be provided by the Government customer.

Ref. 10f : The OPR for the SAP is not the office shown in Item 13 of this form. However, the contractor requires access to NC2-ESI material. The contractor must adhere to the special access requirements/procedures developed by the OPR.

Ref 10g.: Access to classified NATO information requires a final U.S. Government clearance at the appropriate level.

Ref. 10h.: Access requires a final U.S. Government clearance at the appropriate level.

Ref. 10j.: FOUO information provided under this contract shall be safeguarded as specified in the Attachment 1. “Protecting For Official Use Only (FOUO) Information.”

Ref. 10k.: As SCI billets are required, sponsoring organizations will coordinate with

HQ NORAD-USNORTHCOM SSO.

ITEM 11: Remarks:

Ref 11.c.: The contractor requires access to classified source data up to and including (TOP SECRET) in support of the work effort. Any extracts or use of such data requires the contractor to apply derivative classifications and markings consistent with the source documents. Use of Multiple sources on the classified by line necessitates compliance with the NISPOM (or DoD 5200.1-R and AFI 31-401 if operating on an Air Force installation), and use of bibliography. Applicable Security Classification Guides include the following (as amended):

· DoD 5220.22-M, National Industrial Security Program Operating Manual

· DoDD 5220.22-R, Industrial Security Regulation

· DoD 5220.22-S, COMSEC supplement to the Industrial Security Manual

· DoDD 5230.9 Clearance of DOD Information for Public Release

· DODI S-3600.2 Information Operation Security Classification Guidance

· DoD Manual C-5105.21-M-1, "Sensitive Compartmented Information (SCI) Administrative Security Manual" August 1998 with subsequent revisions or changes

· DoDD 5200.1, "Information Security Program," Jan 1997 with subsequent revisions or changes

· DoDD 5200.2, "Personnel Security Program," Jan 1987 with subsequent revisions or changes

· DoDD 5240.1, "DoD Intelligence Activities," 25 April 1988 with subsequent revisions or changes

· DoDD 5240.2, "DoD Counter Intelligence (CI)," 22 May 1997 with subsequent revisions or changes

· DoDI 5240.6, "Counterintelligence (CI) Awareness and Briefing Program," 16 Jul 1996 with subsequent revisions or changes

· DoDI S-5240.9, "Support to DoD Offensive Counterintelligence Operations (OFCO)," 28 Nov 89 with subsequent revisions or changes

· DoDI 5240.10, "DoD Counterintelligence Support to Unified and Specified Commands," 18 May 1990 (Chg 1, 8 Apr 1992) with subsequent revisions or changes

· DoDD 5105.67, "DoD Counterintelligence Field Activity," 19 Feb 2002 with subsequent revisions or changes

· DoDD O-8530.1, "Computer Network Defense (CND)," 8 Jan 2001 with subsequent revisions or changes

· DoDI O-8530.2, "Support to Computer Network Defense (CND)," 9 Mar 2001 with subsequent revisions or changes

· DODD 5230.9 Clearance of DOD Information for Public Release

· CJCS Notice 5114 Implementation of E.O. 12958 -- Classified National Security Information

· CJCS Notice 5121 Implementation of E.O. 13142 – Amendment to E.O. 12958 -- Classified National Security Information

· CJCSI 3170.01B, "Requirements Generation System," 15 Apr 2001 with subsequent revisions or changes

· CJCSM 3213.02A,"Jointstaff Focal Point Communications Procedures Manual(U)", 31 Jan 97, CH 1 08 Aug 2003 with subsequent revisions or changes

· EAP CJCS Volume I, Appendix (Security Classification Guide), 1 Sep 04 with subsequent revisions or changes

· CCJCSM 5222.01B, 28 Feb 2005, National Military Command System (NMCS) Security Classification Manual, OPR is JS-J3;

· CJCSI 3231.01A, 7 Jan 00, Safeguarding the Single Integrated Operational Plan (SIOP), OPR JS-J3

· Air Force Instruction 14-303

· Air Force Instruction (AFI) 10-1101 OPSEC

· AFPD 31-6 (Industrial Security), 1 Apr 00 with subsequent revisions or changes

· AFH 31-602 (Industrial Security Program), 1 Feb 97 with subsequent revisions or changes

· AFI 31-601 (Industrial Security Program Management, AFSPC Sup1), 22 Nov 00 with subsequent revisions or changes

· DCID 1/19 = DCID 2/6P, DCID 1/21 – DCID 6/9, DCID 1/9

· DCID 1/7, "Security Controls on the Dissemination of Intelligence Information," 30 Jun 1998 with subsequent revisions or changes

· DCID 6/4, "Personnel Security Standards and Procedures for Governing Eligibility for Access to Sensitive Compartmented Information (SCI)," 13 Oct 1999, including annexes A-F with subsequent revisions or changes

· DCID 6/3, "Protecting Sensitive Compartmented Information within Information Systems," 5 Jun 1999 with subsequent revisions or changes

· DCID 6/5, Policy for protection of certain non-SCI Sources And Methods Information (SAMI), 12 Feb 2001 with subsequent revisions or changes

· Executive Order 12333, "United States Intelligence Activities," 4 Dec 1981, as amended 24 Jan 2003 with subsequent revisions or changes

· Executive Order 12958, "Classified National Security Information," 17 Apr 1995, as amended 25 Mar 2003 with subsequent revisions or changes

· Executive Order 12968, "Access to Classified Information," 4 Aug 1995 with subsequent revisions or changes

· Executive Order 12972, "Amendment to EO 12958," 19 Sep 1995 with subsequent revisions or changes

· Executive Order 13231, "Critical Infrastructure Protection in the Information Age," 16 Oct 2001 with subsequent revisions or changes

· PDD-62, "Combating Terrorism," 22 May 1998 with subsequent revisions or changes

· PDD-63, "Protecting America's Critical Infrastructure," 22 May 1998 with subsequent revisions or changes

· National Security Strategy

· National Military Strategy

· National Response Plan

· Defense Planning Guidance

· Unified Command Plan, 1 Oct 2002 with subsequent revisions or changes

· Joint Planning Document

· Homeland Security Presidential Directive/HSPD-5, "Management of Domestic Incidents," 28 Feb 2003 with subsequent revisions or changes

· USA Patriot Act, 24 Oct 2001 with subsequent revisions or changes

· National Strategy for the Physical Protection of Critical Infrastructure and Key Assets, Feb 2003 with subsequent revisions or changes

· SECDEF message, dtd 4 Apr 2003, "DoD Intelligence and Law Enforcement Policy to Support the War on Terrorism and Enhanced Domestic Force Protection." with subsequent revisions or changes

· DEPSECDEF Memorandum dtd 2 May 2003, "Collection, Reporting and Analysis of Terrorist Threats to DoD within the U.S." with subsequent revisions or changes

· DEPSECDEF Memorandum dtd 8 May 2003, "Implementation with subsequent revisions or changes Guidance on Restructuring Defense Intelligence-and Related Matters."

· DCI Memorandum, "Homeland Security Information Sharing Memorandum of Understanding," 4 Mar 03 with subsequent revisions or changes

· JP 1, "Joint Warfare of the Armed Forces of the United States, " 14 Nov 2000 with subsequent revisions or changes

· JP 2-0, "Doctrine for Intelligence Support to Joint Operations," 9 Mar 2000 with subsequent revisions or changes

· JP 2-01.2, "Joint Doctrine and Tactics, Techniques and Procedures for Counterintelligence Support to Operations," 7 May 2002 with subsequent revisions or changes

· JP 3-0, "Doctrine for Joint Operations," 10 Sep 2001 with subsequent revisions or changes

· JP 5-0, "Doctrine for Planning Joint Operations," 13 Apr 1995 with subsequent revisions or changes

· Joint DoDIIS/Cryptologic SCI Information Systems Security Standards, 11 Apr 2003 with subsequent revisions or changes

· DIAM 50-4, “Department of Defense (DoD), Intelligence Information System (DoDIIS), Information Systems Security (INFOSEC) Program, 30 April 1997 with subsequent revisions or changes

· DIAM 50-24, "Security for Using Communications Equipment in a SCIF," 31 Aug 1990 with subsequent revisions or changes

· USNORTHCOM Ballistic Missile Defense (BMD) Operations Security Classification Guide (SCG), dated 1 Jan 05 with subsequent revisions or changes

· Missile Defense Agency (MDA) Ground-based Missile Defense (GMD) Security Classification Guide (SCG), dated 6 Sep 02 with subsequent revisions or changes

· Missile Defense Agency (MDA) Ballistic Missile Defense System (BMDS) Security Classification Guide (SCG), dated 26 Apr 04 with subsequent revisions or changes

· USSTRATCOM Global Ballistic Missile Defense (GBMD)Security Classification Guide (SCG), dated 18 Oct 04 with subsequent revisions or changes

· NC HOI 10-220,"USNORTHCOM Focal Point Program"

· USNORTHCOM Mobile Consolidated Command Center (MCCC) SCG, 14 Apr 03; Originating Office and OPR is NC-J38 with subsequent revisions or changes

· Integrated Tactical Warning System and Attack Assessment (ITW/AA) System SCG, 22 Sep 00. OPR is NORAD J33 with subsequent revisions or changes

· NNCI 31-128 “NORAD-USNORTHCOM Security Program” latest version

Ref. 11.d.: Contractor must provide adequate storage for classified hardware to the level of Top Secret, which exceeds two cubic feet but not more than 150 cubic feet.

Ref 11.f.: Included, but not limited to Ottawa, Winnipeg and North Bay Canada, and other locations IAW requirements of awarded Delivery Orders.

Ref 11g.: The contractor must prepare and process a DD Form 1540 and 1541 for request to utilize the Defense Technical Information Center (DTIC). Reference the NISPOM for preparation and processing of these forms.

Ref. 11.i.: The contractor will follow EMSEC procedures as specified in Attachment 2.

Ref . 11j.: The contractor will follow OPSEC procedures as specified in Attachment 3.

Ref .11k.: Contractor is not authorized to use the services of DCS.

Ref 11l.: Additional SCG guidance will be provided as required. See Item 13

ITEM 13: Remarks:

13a.: The contract expiration date is 6 August 2011. This date reflects, among other things, when the SCI indoctrinated contractor personnel will be debriefed. Ensure revisions are issued if the date will be exceeded, or ensure the date is an accurate estimate of the contract completion date. Contract extension letters must be received NLT 3 duty days before expiration date.

13b.: The SCIF at HQ NORAD-USNORTHCOM will be used to perform SCI contractual requirements. SCI material released to the contractor under this contract will be separately stored and maintained only in such properly accredited facilities. Non HQ NORAD-USNORTHCOM SCIFs will be used only when covered by a co-utilization Memorandum of Agreement (MOA) between HQ NORAD-USNORTHCOM and the sponsor of the facility. The supporting SSO for this contract is HQ NORAD-USNORTHCOM SSO.

13c.: The following documents with subsequent revisions or changes will be used for specific security classification guidance on this contract: DCID 6/9, DCID 6/3, DCID 6/4, and JDCSISSS.

13d.: Inquiries pertaining to classification guidance on SCI will be directed to the Contract Monitor.

13e.: SCI data furnished to or generated by the contractor will require security handling and controls beyond those in the National Industrial Security Program Operating Manual (NISPOM). These supplemental instructions will be furnished and/or made available to the contractor through the Contract Monitor by the User Agency Special Security Office, HQ NORAD-USNORTHCOM SSO.

13f.: Names of each contractor personnel requiring access to SCI will be submitted to the SCI Contract Monitor (QAE). The contractor will provide HQ NORAD-USNORTHCOM SSO an SCI manpower list showing job description of each SCI position, levels of access required per position, and the statement of work justifying SCI-level clearances through the QAE.

13g.: The contractor will establish and maintain a current access list of those employees (by position) working on this contract. A copy of this list will be furnished to the SCI Contract Monitor (QAE).

13h.: The contractor will advise the SCI Contract Monitor (QAE) immediately upon reassignment of personnel to other duties not associated with this contract.” The QAE and unit Security Manager will ensure that HQ NORAD-USNORTHCOM SSO notified and that the individual is debriefed from SCI access by HQ NORAD-USNORTHCOM SSO.

13i.: Release of Information. SCI with restrictive caveats (e.g. ORCON, PROPIN, etc) will be released to contractors only when originator approval has been obtained. The contractor will control SCI which has been originated or obtained under this contract as follows: The contractor may release such material to any contractor employee working against a position under this contract only when need-to-know exists. The contractor will release such material to any Special Security Office personnel assigned to HQ NORAD-USNORTHCOM or DIA upon demand by such personnel. The contractor may release such material to any other personnel, including contractor and subcontractor employees, and employees of any Federal Government agency, only upon prior written approval from the SCI Contract Monitor. An access certification to a NORAD-USNORTHCOM SCIF does not constitute approval to release NORAD-USNORTHCOM contractual material to these other personnel; Contract Monitor approval is nevertheless required. Contract Monitor approval of a NORAD-USNORTHCOM contractor visit certification or permanent certification to another facility will constitute approval to discuss contractual material at the facility to be visited.

13j.: Any SCI release to the contractor in support of this contract remains the property of the DoD department, agency, or command that releases it. The contractor will maintain active accountability of all SCI released to his custody, regardless of whether the release is within a contractor or US Government SCIF. Upon completion/cancellation of the contract, the contractor must return all such material to HQ NORAD-USNORTHCOM SSO unless a follow-on contract specifies that material will be transferred to a subsequent contract. SCI inventories will be conducted IAW DIA Manual 50-14.

13k.: A SCIF at the contractor facility is not required for the NORAD-USNORTHCOM Advisory and Assistance Services contract. NORAD-USNORTHCOM sponsored SCIFs will not be co-utilized for other Government agency contracts unless properly covered by a MOA. The supporting SSO for this contract is HQ NORAD-USNORTHCOM SSO.

13l.: This contract does not require use of the Defense Courier systems.

13m.: Electronic processing of classified information is permitted only when the requirements have been met as determined by an accredited TEMPEST authority.” TEMPEST accreditation of ADPS must be obtained IAW the above reference. Operational accreditation of ADPS using software must be obtained IAW DIA Manual 50-14. Security provisions of DCID 6/9 and DIA Manual 50-14 also apply and are part of this contract. The CSSO will appoint an Information Systems Security Office (ISSO) and advise HQ NORAD-USNORTHCOM SSO of this appointment.

13n.: Contractor Special Security Officers (CSSOs) must coordinate with the SCI Contract Monitor, and obtain the concurrence of HQ NORAD-USNORTHCOM SSO prior to subcontracting any portion of SCI efforts involved in this contract.

13o.: No contractor personnel will be granted access to SCI material under this contract unless they are filling a DoD SCI position. The contractor will coordinate with the SCI Contract Monitor to ensure adequate positions are requested under this contract. Multiple contract employees sponsored by organizations other than NORAD-USNORTHCOM must be certified to HQ NORAD-USNORTHCOM for use on this contract.

13p.: The contractor will designate a Special Security Point of Contact (POC) to HQ NORAD-USNORTHCOM SSO. The POC will be responsible for all personnel and information security transactions between the contractor and HQ NORAD-USNORTHCOM SSO.

13q.: Contractor will not use references to SCI accesses, even by unclassified acronyms, in advertising, promotional efforts, or recruitment for employees.

13r.: The following activity is designated as the User Agency SSO for SCI requirements IAW DIA Manual 50-14; HQ NORAD-USNORTHCOM, Special Security Office, PETERSON AFB, CO 80914.

ATTACHMENT 1

FOR OFFICIAL USE ONLY (FOUO)

Ref. to Item 10J of DD Form 254

Extracted from DoD 5200.1-R, January 1997, Appendix 3, and Interim Information Security Guidance, 16 Apr 2004

1. Description. “For Official Use Only (FOUO)” is a designation that is applied to unclassified information that may be exempt from mandatory release to the public under the Freedom of Information Act (FOIA). The FOIA specifies nine exemptions that may qualify certain information to be withheld from release to the public, if, by its disclosure, a foreseeable harm would occur. They are:

a. Information that is currently and properly classified.

b. Information that pertains solely to the internal rules and practices of the Agency. (This exemption has two profiles, "high" and "low." The "high" profile permits withholding of a document that, if released, would allow circumvention of an Agency rule, policy, or statute, thereby impeding the agency in the conduct of its mission. The "low" profile permits withholding if there is no public interest in the document, and it would be an administrative burden to process the request.)

c. Information specifically exempted by a statute establishing particular criteria for withholding. The language of the statute must clearly state that the information will not be disclosed.

d. Information such as trade secrets and commercial or financial information obtained from a company on a privileged or confidential basis that, if released, would result in competitive harm to the company, impair the Government's ability to obtain like information in the future, or protect the Government's interest in compliance with program effectiveness.

e. Inter-Agency memoranda that are deliberative in nature; this exemption is appropriate for internal documents that are part of the decision making process and contain subjective evaluations, opinions and recommendations.

f. Information, the release of which could reasonably be expected to constitute a clearly unwarranted invasion of the personal privacy of individuals.

g. Records or information compiled for law enforcement purposes that:

(1) Could reasonably be expected to interfere with law enforcement proceedings;

(2) Would deprive a person of a right to a fair trial or impartial adjudication;

(3) Could reasonably be expected to constitute an unwarranted invasion of the personal privacy of others;

(4) Disclose the identity of a confidential source;

(5) Disclose investigative techniques and procedures; or

(6) Could reasonably be expected to endanger the life or physical safety of any individual.

h. Certain records of agencies responsible for supervision of financial institutions.

i. Geological and geophysical information concerning wells.

2. General.

a. Information that is currently and properly classified shall be withheld from mandatory release under the first exemption of the Freedom of Information Act FOIA. “FOR OFFICIAL USE ONLY” (FOUO) is applied to information that may be exempt under one or more of the other eight exemptions. So, by definition, information shall be unclassified in order to be designated FOUO. If an item of classified information is declassified, it may be designated FOUO if it qualifies under one of the other exemptions of the FOIA. This means that:

(1) Information cannot be classified and FOUO at the same time. Therefore, classified documents containing FOUO information cannot bear an overall document marking of FOUO. However, portions or pages of a classified document, that contain only FOUO information will be marked as FOUO.

(2) Information that is declassified may be designated FOUO, only if it is believed to fit into one or more of the last eight exemptions (exemptions 2 through 9).

b. The FOIA provides that, for information to be exempt from mandatory release, it must fit into one of the qualifying categories and there must be a legitimate Government purpose served by withholding it. Simply because information is marked FOUO does not mean it automatically qualifies for exemption. If a request for a record is received, the information must be reviewed to see if it meets this dual test. On the other hand, the absence of the FOUO marking does not automatically meant the information must be released. Some types of records (for example, personnel records) are not normally marked FOUO, but may still qualify for withholding under FOIA.

3. Marking.

a. Marking information FOUO does not automatically qualify it for exemption. If a request for a record is received, the information shall be reviewed to determine if it actually qualifies for exemption. Similarly, the absence of the FOUO marking does not automatically mean the information shall be released. Some types of records (for example, personnel records) are not normally marked FOUO, but may still be withheld under the FOIA. All DoD unclassified information must be reviewed before it is released to the public or to foreign governments and international organizations.

b. Information that has been determined to qualify for FOUO status should be indicated by markings when included in documents and similar material. Markings should be applied at the time documents are drafted, whenever possible, to promote proper protection of the information.

(1) Unclassified documents and material containing FOUO information shall be marked as follows:

a Documents will be marked "FOR OFFICIAL USE ONLY" at the bottom of the front cover (if there is one), the title page (if there is one), the first page, and the outside of the back cover (if there is one).

b Pages of the document that contain FOUO information shall be marked "FOR OFFICIAL USE ONLY" at the bottom.

c Portion Marking FOUO Information. Subjects, titles and each section, part, paragraph, and similar portion of an FOUO document shall be marked to show that they contain information requiring protection. Use the parenthetical notation “(FOUO)” to identify information as For Official Use Only for this purpose. Place this notation immediately before the text.

d Material other than paper documents (for example, slides, computer media, films, etc.) shall bear markings that alert the holder or viewer that the material contains FOUO information.

e FOUO documents and material transmitted outside the Department of Defense must bear an expanded marking on the face of the document so that non-DoD holders understand the status of the information. A statement similar to this one should be used:

"This document contains information exempt from mandatory disclosure under the F0IA. Exemption(s) ______ apply."

(2) Classified documents and material containing FOUO information shall be marked as required by Chapter 4 of the NISPOM (or DoD 5200.1-R, Chapter 5, as applicable), with FOUO information identified as follows:

a Overall markings on the document shall follow the rules in NSPOM Chapter 4 (or DoD 5200.1-R, Chapter 5). No special markings are required on the face of the document because it contains FOUO information.

b Portions of the document shall be marked with their classification as required by NISPOM Chapter 4 (or DoD 5200.1-R, Chapter 5). If there are unclassified portions that contain FOUO information, they shall be marked with "FOUO" in parentheses at the beginning of the portion. Since FOUO information is, by definition, unclassified, the "FOUO" is an acceptable substitute for the normal "U."

c Pages of the document that contain classified information shall be marked as required by NISPOM Chapter 4 (or DoD 5200.1-R, Chapter 5). Pages that contain FOUO information but no classified information will be marked "FOR OFFICIAL USE ONLY" at the top and bottom.

(3) Transmittal documents that have no classified material attached, but do have FOUO attachments shall be marked with a statement similar to this one:
"FOR OFFICIAL USE ONLY ATTACHMENT."

(4) Each part of electrically transmitted messages containing FOUO information shall be marked appropriately. Unclassified messages containing FOUO information shall contain the abbreviation "FOUO" before the beginning of the text.

4. Access to FOUO Information.

a. No person may have access to information designated as FOUO unless that person has been determined to have a valid need for such access in connection with the accomplishment of a lawful and authorized Government purpose.

b. The final responsibility for determining whether an individual has a valid need for access to information designated as FOUO rests with the individual who has authorized possession, knowledge or control of the information and not on the prospective recipient.

c. Information designated as FOUO may be disseminated within the DoD Components and between officials of DoD Components and DoD contractors, consultants, and grantees to conduct official business for the Department of Defense, provided that dissemination is not further controlled by a Distribution Statement.

d. DoD holders of information designated as FOUO are authorized to convey such information to officials in other Departments and Agencies of the Executive and Judicial Branches to fulfill a government function. If the information is covered by the Privacy Act, disclosure is only authorized if the requirements of DoD 5400.11-R are satisfied.

e. Release of FOUO information to Congress is governed by DoD Directive 5400.4. If the information is covered by the Privacy Act, disclosure is authorized if the requirements of DoD 5400.11-R are also satisfied.

f. DoD Directive 7650.1 governs release of FOUO information to the General Accounting Office (GAO). If the information is covered by the Privacy Act, disclosure is authorized if the requirements of DoD 5400.11-R are also satisfied.

5. Protection of FOUO Information

a. During working hours, reasonable steps shall be taken to minimize risk of access by unauthorized personnel. After working hours, store FOUO information in unlocked containers, desks or cabinets if Government or Government-contract building security is provided. If such building security is not provided, store the information in locked desks, file cabinets, bookcases, locked rooms, etc.

b. FOUO information and material may be transmitted via first class mail, parcel post or, for bulk shipments, via fourth class mail. Electronic transmission of FOUO information, e.g., voice, data or facsimile, e-mail, shall be by approved secure communications systems or systems utilizing other protective measures such as Public Key Infrastructure (PKI), whenever practical.

c. FOUO information may only be posted to DoD Web sites consistent with security and access requirements specified in Deputy Secretary of Defense Memorandum dated December 1998, Subject: “Web Site Administration”.

d. Record copies of FOUO documents shall be disposed of according to the Federal Records Act and the DoD Component records management directives. Non-record FOUO documents may be destroyed by any of the means approved for the destruction of classified information, or by any other means that would make it difficult to recognize or reconstruct the information.

6. Unauthorized Disclosure. The unauthorized disclosure of FOUO does not constitute an unauthorized disclosure of DoD information classified for security purposes. However, appropriate administrative action shall be taken to fix responsibility for unauthorized disclosure of FOUO whenever feasible, and appropriate disciplinary action shall be taken against those responsible. Unauthorized disclosure of FOUO information that is protected by the Privacy Act may also result in civil and criminal sanctions against responsible persons. The Military Department or other DoD Component that originated the FOUO information shall be informed of its unauthorized disclosure.

ATTACHMENT 2

EMSEC Requirements (Addendum to DD Form 254, Block 11i)

EMISSIONS SECURITY ASSESSMENT REQUEST (ESAR)

FOR ALL CLASSIFIED SYSTEMS

a. The contractor shall ensure that compromising emanations (EMSEC) conditions related to this contract are minimized.

b. The contractor shall provide countermeasures assessment data to the Contracting Officer (CO), in the form of a EMSEC Security Assessment Request (ESAR), the ESAR shall provide only specific responses to the data required in paragraph c, below. The contractor’s standard security plan shall NOT be used as a “stand-alone” ESAR response. The contractor shall NOT submit a detailed facility analysis/assessment. The ESAR information will be used to complete an EMSEC Countermeasures Assessment Review of the contractor’s facility to be performed by the government EMSEC authority using current Air Force EMSEC directives. EMSEC is applied on a case-by-case basis and further information may be required to complete the review; should this be the case the contractor shall provide this information to the contracting officer when requested. After the evaluation of the ESAR by the government EMSEC authority, additional EMSEC requirements may be necessary.

c. *ESAR contents shall include, as a minimum, the following information (NISPOM, para 11-101c):

(1) The specific classification and special categories of material to be processed/handled by electronic means.

(2) The percentage of information being processed. Identify the approximate percentage for each level of information processed including unclassified.

(3) The specific location where classified processing will be performed.

(4) The name, address, title and telephone number of a point-of-contact at the facility where processing will occur.

NOTE: Once the above information has been provided to the CO, no further reporting is required for equipment reconfigurations. However, if the facility is physically relocated to another geographical location, the information requested in paragraph “c” above MUST be furnished to the CO.

DD Form 254 Continuation Sheet CONTRACT NO. FA2517-09-D-6032

d. The prime contractor shall ensure that all subcontractors and/or vendors comply with EMSEC requirements when performing classified processing related to this contract. They will provide the above documentation through their prime to the contracting officer to complete the ESAR.

ATTACHMENT 3

OPSEC Requirements (Addendum to DD Form 254, Block 11k)

OPERATIONS SECURITY (OPSEC)

GENERAL:

1. PURPOSE: This section outlines the requirements and procedures necessary to protect Critical Information for Operations Security (OPSEC).

2. MISSION: To maintain a continuing awareness of adversary interest in center actions and adversary intelligence collection capabilities. To understand the need to identify and protect classified and unclassified indicators, which occur, reveal sensitive information. To evaluate the effectiveness of OPSEC measures taken to preclude or reduce adversary acquisition and exploitation of sensitive information.

3. DEFINITION: OPSEC is the process of analyzing friendly actions attendant to military operations and other activities to:

a. Identify those actions that can be observed by adversary intelligence systems.

b. Determine indicators hostile intelligence systems might obtain that could be interpreted or pieced together to derive critical information in time to be useful to adversaries.

c. Select and execute measures that eliminate or reduce to an acceptable level the vulnerabilities of friendly actions to adversary exploitation.

4. OBJECTIVES:

a. To protect planned operational center activities by preventing the inadvertent disclosure of unclassified information relating to or revealing a possible classified operation.

b. To preserve secrecy concerning specific scenario events and a NORAD response to these events.

c. To identify OPSEC vulnerabilities and recommend protective measures which will serve to enhance the security of future operations.

5. TASKS: Task requirements are outlined in the Statement of Work for this effort.

ATTACHMENT 4

Actual Performance (Addendum to DD Form 254, Block 8)

Location
Cage Code
Cognizant Security Office

HQ NORAD-NORTHCOM

250 Vandenberg, St.

Peterson AFB, CO 80914

N/A
For SCI level tasks: For collateral classified tasks:

HQ NORAD-NORTHCOM 21SW/ISPM

250 Vandenberg, St., Bldg 2 135 Dover St., Ste 1055 Peterson AFB, CO 80914 Peterson AFB, CO 80914-1159

File details come from the government source that posted it. Updated .