3._Attch_3,_DD_Form_254.pdf

PDF 170 KB Posted

Attached to
Solid State Phased Array Radar System (SSPARS) Federal contract opportunity
Solicitation number
FA2517-15-R-8001
Issued by
Department of the Air Force Space Command

About this file

This document package includes a DD Form 254, security classification specification, and related appendices for contract FA2517-15-R-8001. The contract is for operations and maintenance support of the Solid State Phased Array Radar System at sites in Clear, Alaska; Beale Air Force Base, California; Cape Cod Air Force Station, Massachusetts; Thule Air Base, Greenland; and Royal Air Force Fylingdales, United Kingdom. The work includes 24/7 support for missile warning, missile defense, space surveillance, and secure communications systems. The security classification is up to the Top Secret level with special access required. The document outlines security requirements for emissions, operations security, communications security, and other classified handling procedures.

Updated DD Form 254

View the file

Other files for this federal contract opportunity

Other files attached to Solid State Phased Array Radar System (SSPARS), newest first.
File Type Posted
2._Attch_2,_Contractor_Assessment_and_Performance_Reporting_(CAsPR)_Matrix.xlsx XLSX spreadsheet
12._Attch_12,_Questions_and_Answers.pdf PDF
11._Attch_11,_CLIN_Schedule_Worksheet.xlsx XLSX spreadsheet
5._Attch_5,_Cape_Cod_CBA_1_Oct_2016_-_30_Sep_2019.pdf PDF
1._Attch_1,_Performance_Work_Statement.docx DOCX document
6._Attch_6,_Clear_CBA_(FJCC)_1_Oct_2015_-_30_Sep_2019.pdf PDF
9._Attch_9,_Scheduled_Government_Furnished_Property.pdf PDF
1._Attch_1,_Performance_Work_Statement.docx DOCX document
5._Attch_5,_Cape_Cod_CBA_1_Oct_2016_-_30_Sep_2019.pdf PDF
8._Attch_8,_Quality_Assurance_Surveillance_Plan.docx DOCX document
7._Attch_7,_Clear_CBA_(IBT)_1_Oct_2016_-_30_Sep_2019.pdf PDF
6._Attch_6,_Clear_CBA_(FJCC)_1_Oct_2015_-_30_Sep_2019_(2).pdf PDF
3._Attch_3,_DD_Form_254.pdf PDF
10._Attch_10,_Staffing_Matrix.xlsx XLSX spreadsheet
1._Attch,_Performance_Work_Statement.docx DOCX document
11._Attch_11,_CLIN_Schedule_Worksheet.xlsx XLSX spreadsheet
4._Attch_4,_Beale_CBA_1_Oct_2015_-_30_Sep_2019.pdf PDF
10._Attch_10,_Staffing_Matrix.xlsx XLSX spreadsheet
9._Attch_9,_Schedule_Government_Furnished_Property.pdf PDF
7._Attch_7,Clear_CBA_(IBT)_1_Oct_2016_-_30_Sep_2019.pdf PDF
15._Attch_15,_Site_Visit_7_SWS_VAR_Form.doc DOC document
17._Attch_17,_Site_Visit_REAL_ID_Act_Primer.pdf PDF
OCI_Mitigation_Plan_REMINDER.pdf PDF
12._Attch_12_Site_Visit_Schedule.doc DOC document
9._Attch_9,_Schedule_Government_Furnished_Property.pdf PDF
0._DRAFT_Request_For_Proposal_FA2517-15-R-8001.pdf PDF
2._Attch_2,_Contractor_Assessment_and_Performance_Reporting_(CAsPR)_Matrix.xlsx XLSX spreadsheet
6._Attch_6,_Clear_CBA_(FJCC)_1_Oct_2015_-_Sep_2019.pdf PDF
17._Attch_17,_Site_Visit_REAL_ID_Act_Primer.pdf PDF
3._Attch_3,_DD_Form_254.pdf PDF
13._Attch_13,_Site_Visit_Base_Maps.pdf PDF
7._Attch_7,_Clear_CBA_(IBT)_1_Oct_2016_-_30_Sep_2019.pdf PDF
5._Attch_5,_Cape_Cod_CBA_1_Oct_2016_-_30_Sep_2019.pdf PDF
15._Attch_15,_Site_Visit_7_SWS_VAR_Form.doc DOC document
Updated_Draft_PWS_SSPARS_1_Dec_16.docx DOCX document
SSPARS_Draft_RFP_and_Industry_Day_Comments-_ROUND_3.pdf PDF
SSPARS_Draft_RFP_and_Industry_Day_Comments_-_ROUND_2.pdf PDF
SSPARS_Industry_Day_Attendees.pdf PDF
SSPARS_Draft_RFP_and_Industry_Day_Comments_-_ROUND_1.pdf PDF
Attch_2_DRAFT_Contractor_Assessment_and_Performance_Reporting_(CAsPR)_Matrix.xlsx XLSX spreadsheet
CORRECTED_Notice_of_Industry_Day.pdf PDF
DD2345.pdf PDF
DD2345_Requirements_and_Instructions.pdf PDF
FAQ_and_Answers_for_Form_DD2345.pdf PDF
Notice_of_Industry_Day.pdf PDF
Attch_1_-_Agenda.pdf PDF
FA2517-15-R-8001_Synopsis.docx DOCX document
RFI_3_Attch_1_LoS_Rule_2014-29753.pdf PDF
RFI_3_LoS _Prof_Emp.pdf PDF
RFI__1_General_Questions.docx DOCX document
Show all 50

Solid State Phased Array Radar System (SSPARS) has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Reset

DEPARTMENT OF DEFENSE

CONTRACT SECURITY CLASSIFICATION SPECIFICATION

(The requirements of the DoD Industrial Security Manual apply to all security aspects of this effort.)

1. CLEARANCE AND SAFEGUARDING

a. FACILITY CLEARANCE REQUIRED

TOP SECRET

b. LEVEL OF SAFEGUARDING REQUIRED

NONE

2. THIS SPECIFICATION IS FOR: (X and complete as applicable) 3. THIS SPECIFICATION IS: (X and complete as applicable)

a. PRIME CONTRACT NUMBER FA2517-15-R-8001 a. ORIGINAL (Complete date in all cases)

DATE (YYYYMMDD)

b. SUBCONTRACT NUMBER b. REVISED (Supersedes all previous specs)

REVISION NO. DATE (YYYYMMDD)

c. SOLICITATION OR OTHER NUMBER DUE DATE (YYYYMMDD)

c. FINAL (Complete Item 5 in all cases)

DATE (YYYYMMDD)

4. IS THIS A FOLLOW-ON CONTRACT? YES NO. If Yes, complete the following:

Classified material received or generated under FA2517-06-C-8001 (Preceding Contract Number) is transferred to this follow-on contract.

5. IS THIS A FINAL DD FORM 254? YES NO. If Yes, complete the following:

In response to the contractor's request dated , retention of the classified material is authorized for the period of

6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)

a. NAME, ADDRESS, AND ZIP CODE b. CAGE CODE c. COGNIZANT SECURITY OFFICE (Name, Address, and Zip Code)

Defense Security Service (1OFCL2) 7756 Teague Road, Ste. 580 Hanover, MD 21076

7. SUBCONTRACTOR

a. NAME, ADDRESS, AND ZIP CODE

N/A

b. CAGE CODE

N/A

c. COGNIZANT SECURITY OFFICE (Name, Address, and Zip Code)

N/A

8. ACTUAL PERFORMANCE

a. LOCATION

6th Space Warning Squadron (SWS) at Cape Cod Air Force Station (AFS), MA; 7 SWS at Beale Air Force Base (AFB), CA;

12 SWS at Thule Air Base (AB), GL; 13 SWS at Clear AFS, AK; and Royal Air Force (RAF) Fylingdales, UK

b. CAGE CODE N/A

c. COGNIZANT SECURITY OFFICE (Name, Address, and Zip Code)

21 SW/IPO

135 Dover Street, Ste 1055 Peterson AFB CO 80914-1159 See continuation sheet for Cognizant Security Offices and addresses for Beale AFB and RAF Fylingdales

9. GENERAL IDENTIFICATION OF THIS PROCUREMENT

Contract is for operations and maintenance on a continuous 24-hours-a-day, 7-days-a-week (24/7) in support of Missile Warning, Missile Defense and Space Surveillance missions under the 21st Operations Group (21 OG) at five installations/sites: Beale AFB, CA; Cape Cod AFS, MA; Clear AFS, AK; Thule AB, GL and Secure Communications at RAF Fylingdales, UK.

10. CONTRACTOR WILL REQUIRE ACCESS TO: YES NO 11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: YES NO

a. COMMUNICATIONS SECURITY (COMSEC) INFORMATION a. HAVE ACCESS TO CLASSIFIED INFORMATION ONLY AT ANOTHER

CONTRACTOR'S FACILITY OR A GOVERNMENT ACTIVITY

b. RESTRICTED DATA b. RECEIVE CLASSIFIED DOCUMENTS ONLY

c. CRITICAL NUCLEAR WEAPON DESIGN INFORMATION c. RECEIVE AND GENERATE CLASSIFIED MATERIAL

d. FORMERLY RESTRICTED DATA d. FABRICATE, MODIFY, OR STORE CLASSIFIED HARDWARE

e. INTELLIGENCE INFORMATION e. PERFORM SERVICES ONLY

(1) Sensitive Compartmented Information (SCI) f. HAVE ACCESS TO U.S. CLASSIFIED INFORMATION OUTSIDE THE U.S., PUERTO RICO, U.S. POSSESSIONS AND TRUST TERRITORIES

(2) Non-SCI g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE TECHNICAL INFORMATION

CENTER (DTIC) OR OTHER SECONDARY DISTRIBUTION CENTER

f. SPECIAL ACCESS INFORMATION h. REQUIRE A COMSEC ACCOUNT

g. NATO INFORMATION i. HAVE TEMPEST REQUIREMENTS

h. FOREIGN GOVERNMENT INFORMATION j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS

i. LIMITED DISSEMINATION INFORMATION k. BE AUTHORIZED TO USE THE DEFENSE COURIER SERVICE

j. FOR OFFICIAL USE ONLY INFORMATION l. OTHER (Specify)

Provide the information required by Contract clauses 52.204-2, 52.204-9000 and 52.204-9001 to the Information Security Program Manager (ISPM).

k. OTHER (Specify)

Will require 20 SCI billets; 5 per site (6 SWS, 7 SWS, 12 SWS and 13 SWS) DD FORM 254, DEC 1999 PREVIOUS EDITION IS OBSOLETE. Adobe Professional 7.0

Reset

12. PUBLIC RELEASE. Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the Industrial Security Manual or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for approval prior to release Direct Through (Specify)

"NO PUBLIC RELEASE OF SCI IS AUTHORIZED"

21 SW/PA, 755 Loring Ave, Suite 241, Peterson AFB, CO 80914 to the Directorate for Freedom of Information and Security Review, Office of the Assistant Secretary of Defense (Public Affairs)* for review.

*In the case of non-DoD User Agencies, requests for disclosure shall be submitted to that agency.

13. SECURITY GUIDANCE. The security classification guidance needed for this classified effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended. (Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. Add additional pages as needed to provide complete guidance.)

See continuation sheet for applicable guidance.

14. ADDITIONAL SECURITY REQUIREMENTS. Requirements, in addition to ISM requirements, are established for this contract. Yes No (If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the cognizant security office. Use Item 13 if additional space is needed.)

Provide the information requested by AFFARS 5352.204-9000, Notification to Government Security Activity Clause, and AFI 31-501, Industrial Security Program Management, to the Information Protection Office (IPO). Refer to the contract document for clauses. Contractor shall execute a Visitor Group Security Agreement (VGSA) with the Government at each operating location.

15. INSPECTIONS. Elements of this contract are outside the inspection responsibility of the cognizant security office. Yes No (If Yes, explain and identify specific areas or elements carved out and the activity responsible for inspections. Use Item 13 if additional space is needed.)

Industrial Security Reviews, while operating on an Air Force Installation, will be conducted by the Information Protection Office. See Continuation sheet comment.

16. CERTIFICATION AND SIGNATURE. Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below.

a. TYPED NAME OF CERTIFYING OFFICIAL

AUSTIN FRINDT

b. TITLE

Contracting Officer

c. TELEPHONE (Include Area Code)

(719) 554-2940

d. ADDRESS (Include Zip Code)

21 CONS\LGCZ

135 Dover Street, Suite 1240 Peterson AFB, CO 80914-1285

17. REQUIRED DISTRIBUTION

a. CONTRACTOR

b. SUBCONTRACTOR

c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR

d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION

e. ADMINISTRATIVE CONTRACTING OFFICER

f. OTHERS AS NECESSARY 21 SW/PMD, Program Manager

e. SIGNATURE

DD FORM 254 (BACK), DEC 1999

SSPARS DD Form 254 FA2517-15-R-8001

Continuation of Block 10:

Ref 10.a. COMSEC material/information may not be released to DoD contractors without Air Force Cryptological Support Center (AFSCS) approval. Contractor must forward requests for COMSEC material/information to the COMSEC Officer through the program office. The contractor is governed by the DoD 5220.22-5 COMSEC Supplement to the NISPOM in the control and protection of COMSEC material/information. Access to COMSEC material by personnel is restricted to US citizens holding final US Government clearances. Such information is not releasable to personnel holding only interim clearances.

Ref 10g. Applies to RAF Fylingdales only. NATO Information: Special briefing required for access to NATO. Prior approval of the contracting activity is required for subcontracting. Access to classified NATO information requires a final U.S. Government clearance at the appropriate level.

Ref 10h. Applies to RAF Fylingdales only. Foreign Government Information: Prior approval of the contracting activity is required for subcontracting. Access requires a final U.S. clearance at the appropriate level.

Ref 10.j. For Official Use Only (FOUO) information provided under this contract shall be safeguarded as specified in DoDM 5200.01 Vol IV, Enclosure 3.

Continuation of Block 11:

Ref 11.a. Contract performance is restricted to Clear AFS, AK, Cape Cod AFS, MA, Beale AFB, CA, Thule AB, GL, and RAF Fylingdales, UK.

The contractor requires access to classified source data and SCIFs up to and including TOP SECRET in support of the work effort. Any extracts or use of such data requires the contractor to apply derivative classifications and markings consistent with the source documents. Use of multiple sources on the classified by line necessitates compliance DoD 5200.01 Vol 2 and AFI 31-401, and use of the following Security Classification Guides (SCGs): (Subsequent revisions/changes apply to this contract)

a. Ground-Based Radar Missile Warning System, 1 Sep 03, OPR: HQ AFSPC/DOS, Peterson

AFB, CO 80914-5000

b. Dedicated Space Surveillance Network Sensors, 30 Sep 05, OPR: HQ AFSPC/XOC, Peterson AFB, CO 80914-5000

c. Milstar/Advanced Extremely High Frequency (AEHF) System Operations Protection Guide, 31 Dec 07, OPR: HQ AFSPC/A3, Peterson AFB, 80914-5000

Ref 11f. RAF Fylingdales, UK

Ref 11g. The Contractor must prepare and process a DD Form 1540 and 1541 for request to utilize the Defense Technical Information Center (DTIC). Reference the NISPOM for preparation and processing of these forms.

Ref 11i. See Emission Security (EMSEC) requirements in Attachment 1, “EMISSION SECURITY

ASSESSMENT REQUEST (ESAR) FOR ALL CLASSIFIED SYSTEMS”.

Ref 11j. See Operations Security (OPSEC) requirements in Attachment 2.

Ref 11k. See Communications Security (COMSEC) requirements in attachment 3. COMSEC material shipped to the site comes through the Defense Courier Service (DCS). Requires the contracting activity to request DCS services from the Commander, Defense Courier Service, ATTN: Operations Division, Fort George G. Meade, MD 20755-3570. Only certain classified information qualifies for shipment by DCS. It is the responsibility of the contracting activity to comply with DCS policy and procedures.

Ref 11l. Provide the information required by Contract clauses FAR 52.204-2, DFARS 252.204-7000 and AFFARS 5352.204-9000 to the Information Protection Office (IPO) or host Cognizant Security Office as identified in the Support Agreement.

Computer security (COMPUSEC): Tasks outlined in Performance Work Statement (PWS).

Continuation of block 13:

Item 13a: Contract Expiration Date: 30 April 2026

Item 13b: The Contractor will perform facility maintenance and maintain JWICS computers and peripheral equipment in the Sensitive Compartmental Information Facility (SCIF) at each site. The supporting SSO is AFSPC/A2.

Item 13c: SCIFs must be maintained by the contractor in accordance with PWS requirements.

Item 13d: Inquiries pertaining to classification guidance on SCI will be directed to the Contract Monitor.

Item 13e: SCI data furnished to or generated by the contractor will require security handling and controls beyond those in the National Industrial Security Program Operating Manual (NISPOM). These supplemental instructions will be furnished and/or made available to the contractor thru the Contract Monitor by the User Agency Special Security Office, SSO AFSPC.

Item 13f: Names of contractor personnel requiring access to SCI will be submitted to the SCI Contract Monitor. Forms requesting Special Background Investigations will be prepared in accordance with the NISPOM and submitted to Defense Security Service (DSS).

Item 13g: The contractor will establish and maintain a current access list of those employees working on this contract. A copy of this list will be furnished to the SCI Contract Monitor.

Item 13h: The contractor will advise the SCI Contract Monitor immediately upon reassignment of personnel to other duties not associated with this contract.

Item 13i: Release of Information. SCI with restrictive caveats (e.g., ORCON, PROPIN, etc.) will be released to contractors only when originator approval has been obtained. The contractor will control SCI, which has been originated or obtained under this contract as follows: The contractor may release such material to any contractor employee working against a billet under this contract only when a need-to-know exists. The contractor will release such material to any Special Security Office personnel assigned to HQ AFSPC or DIA upon demand by such personnel. The contractor may release such material to any other personnel, including contractor and subcontractor employees, and employees of any Federal Government agency, only upon prior written approval from the SCI Contract Monitor. An access certification to an AFSPC contractor-occupied SCIF does not constitute approval to release

AFSPC contractual material to these other personnel; Contract Monitor approval is nevertheless required. Contract Monitor approval of an AFSPC contractor visit certification or permanent certification to another facility will constitute approval to discuss contractual material at facility to be visited.

Item 13J: Any SCI released to the contractor in support of this contract remains the property of DOD department, agency, or command that releases it. The contractor will maintain active accountability of all SCI released to his/her custody, regardless of whether the release is within a contractor or US Government SCIF. Upon completion/cancellation of the contract, the contractor must return all such material to SSO AFSPC unless a follow-on contract specifies that the material will be transferred to a subsequent contract. SCI inventories will be conducted IAW DoD 5105.21m_vol1/2/3 and AFMAN 14- 304.

Item 13l: This contract requires use of the Defense Courier system. SSO AFSPC will validate Defense Courier Service requirements.

Item 13m: Electronic processing of classified information is permitted only when the requirements of AFMAN 14-304 have been met as determined by an accredited TEMPEST authority. This contract requires electronic processing of SCI. TEMPEST accreditation of ADPS must be obtained IAW the above reference. Operational accreditation of ADPS using software must be obtained IAW DoD 5105.21m_vol1/2/3 and AFMAN 14-304. Security provisions of DoD 5105.21m_vol1/2/3 and AFMAN 14-304 also apply and are part of this contract. The CSSO will appoint an Information Systems Security Officer (ISSO) and advise SSO AFSPC of this appointment.

Item 13n: Contractor Special Security Officers (CSSOs) must coordinate with the SCI Contract Monitor and obtain the concurrence of SSO AFSPC prior to subcontracting any portion of SCI efforts involved in this contract.

Item 13o: No contractor personnel will be granted access to SCI material under this contract unless they are filling a DOD SCI billet. The contractor will coordinate with SCI Contract Monitor to ensure adequate billets are requested under this contract. Multiple contract employees sponsored by the organizations other than Space Command must be certified to SSO AFSPC for use on the contract.

Item 13p: The contractor will designate a Special Security Point of Contact (POC) to SSO AFSPC.

The POC will be responsible for all personnel and information security transactions between the contractor and SSO AFSPC.

Item 13q: Contractor will not use references to SCI accesses, even by unclassified acronyms, in advertising, promotional efforts, or recruitment for employees.

Item 13r: The following activity is designated as the User Agency SS for SCI requirements IAW DoD 5105.21m_vol1/2/3; HQ AFSPC/A2S, Peterson AFB CO 80914-4311.

Continuation of Block 14:

Shipments of classified or sensitive equipment shall be handled, transported, transmitted, and protected IAW NISPOM, DoD 5220.22M and as specified by unit directives.

Note 1. The use of automated information systems for processing and producing classified information at 6 SWS at Cape Cod AFS, MA, 7 SWS at Beale AFB, CA, 12 SWS at Thule AB, GL, 13 SWS at Clear AFS, AK, and RAF Fylingdales, UK is required. Contractor shall assist with information systems accreditation as stated in the performance work statement.

Note 2. The contractor shall comply with security and law enforcement policies and procedures in effect on Government installations. The contract will be performed within USAF restricted areas on Clear AFS, AK, Cape Cod AFS, MA, Beale AFB, CA, Thule AB, GL, and RAF Fylingdales, UK. At each Solid State Array Phased Array Radar System (SSPARS) site, the contractor employees must be subject of a National Agency Check or already have been issued a final or interim secret clearance for the purpose of access to classified information before being permitted unescorted entry to these restricted areas. Contractor employees not meeting the prerequisite for unescorted entry shall be under the continuous escort by other cleared contractor employees while in restricted areas.

Note 3. The contractor shall provide a visit request to the respective Commander, 6 SWS, Commander, 7 SWS, Commander, 12 SWS, Commander, 13 SWS, or USAF Liaison Officer for RAF Fylingdales to permit unescorted entry to USAF restricted areas and/or access to classified information while on the installation (see AFI 31-101 (FOUO) - Restricted Areas and Controlled Areas).

Note 4. When performance involves classified information on a military installation where the contractor does not possess a facility clearance for that location, the contractor operation is considered a “visitor group” on the installation. As such, the contractor’s security procedures shall be integrated with those of the installation. The contractor shall enter into a Visitor Group Security Agreement (VGSA) with each Installation/Site Commander for the 6 SWS, 7 SWS, 12 SWS, 13 SWS, and USAF Liaison Officer for RAF Fylingdales to formalize:

1. Those security actions which will be performed for the contractor by the installation, such as providing storage and classified reproduction facilities; guard services; security forms; security inspection under DoD 5220.22-M, classified mail services; security badging; visitor control; and investigation security incidents and;

2. Those security actions for which joint action may be required, such as packaging and addressing classified transmittals, security checks, internal security controls and implanting emergency procedures to protect classified materials.

Note 5. The VGSA is developed by the Security Service Agency (SSA) and signed by the installation commander to ensure National security interests are protected by confirmed security support and identifying security procedures unique to the installation.

Note 6. If after reviewing the VGSA and discussing it with the military commander or representative, the contractor believes there may be a cost impact, the contractor will notify the contracting officer in writing. In such cases, do not sign or implement the security agreement unless directed by the Contracting Officer. The contracting officer will work closely with the FSO toward an appropriate solution.

Note 7. See DoDM 5200.01, Volume 1, for marking guidance regarding classified information.

Continuation of Block 15:

The Contractor will perform facility maintenance and maintain JWICS computers and peripheral equipment in the Sensitive Compartmental Information Facility (SCIF) at each site with the exception of RAF Fylingdales. DoD 5105.21M_vols 1/2/3 and AFMAN 14-304 provide the necessary guidance for physical, personnel, and information security measures and are part of the security specifications for this contract. Contractor compliance with these directives is mandatory unless specific provisions are specifically waived.

DSS is relieved of inspection responsibility for all classified material that is released to or developed by the contractor while on a military installation. DSS retains inspection responsibility for all non-SCI classified material released to or developed by the contractor and held in the contractors’ facility. The SSO maintains inspection responsibility for all SCI material related to this contract. Local Information Protection security program assessments while operating on an Air Force installation, shall be conducted by the IPO. HQ AFSPC/IN retains security cognizance of all Intelligence materials released to the contractor.

a. RAF Fylingdales, United Kingdom. Industrial security supervision is the responsibility of the 100th Air Refueling Wing, RAF Mildenhall, APO 09459 under support agreement 2500-181.

The majority of the contract effort will be performed on an Air Force installation. The host security force on the installation is responsible for Industrial security supervision and inspections of the contractor to ensure contractor compliance. Part of the contract effort will be performed on a USAF installation at Thule AB, Greenland and a British RAF installation at RAF Fylingdales, United Kingdom.

a. For Thule AB, Greenland, 21 SW/IP is responsible for industrial security supervision and inspections of the contractor to ensure contractor compliance for safeguarding classified information and the VGSA. Local Security Forces provide local security and law enforcement policies and procedures.

b. For Fylingdales, United Kingdom, 100 ARW/IP provides guidance, oversight, and inspection of the industrial security program; and the RAF Security and Ministry of Defense Police provide local security and law enforcement policies and procedures.

Continuation of Block 17:

Reference 17f. Required Distribution, 21 SW/PMD, SSPARS Program Manager, Peterson AFB CO 80914 21 SW/IP, Peterson AFB CO 80914-1560 6 SWS/SF, Cape Cod AFS, MA 02561-0428 7 SWS/SF, Beale AFB, CA 95903 Thule AB, GL (BMEWS I), 12 SWS/DOO, APO AE 09704 Clear AFS, AK (BMEWS II), 213 SWS/SFOP and 13 SWS/DOO RAF Fylingdales, UK (BMEWS III), 100 ARW/IP, RAF Mildenhall, UK APO AE 09459

Signature: ___________________________ Signature: ___________________________ Name: LAURA C. MCDONOUGH, GS-13 Name: ADAM M. ESTABROOK, TSGT Title: SSPARS Program Manager Title: 6 SWS Security Manager Office symbol: 21 SW/PMD, Peterson AFB, CO Office symbol: 6 SWS/MAS3A, Cape Cod AFS, MA

Signature: ___________________________ Signature: ___________________________ Name: MARK W. EVANGER, GG-14 Name: ROBERT P. BYROM, CIV Title: Chief, Special Security Office Title: 7 SWS Security Manager Office symbol: HQ AFSPC, Peterson AFB, CO Office symbol: 7 SWS/SO, Beale AFB, CA

Signature: ___________________________ Signature: ___________________________ Name: Name: TINA M. MILLER, TSGT Title: Title: 12 SWS Security Manager Office symbol:

JULIE K. BOYATT, GS-11

Industrial Security Prgm Manager 21 SW/IP, Peterson AFB, CO Office symbol: 12 SWS/DOU, Thule AB, GL

Signature: ___________________________ Signature: ___________________________ Name: BRIAN A. LADD, MAJOR Name: ROBERT J. ROSA, TSGT Title: AFSPC 21 OG OLA/USAFLO Title: 13 SWS Security Manager Office symbol: RAF Fylingdales, UK Office symbol: 213 SWS/S3OA, Clear AFS, AK

Signature: ___________________________ Signature: ___________________________ Name: DAVID CALLAHAN, GS-12 Name:

Title: COMSEC Manager Title:

Office symbol: 21 CS/SCXS, Peterson AFB, CO Office symbol:

Attachment 1

EMISSIONS SECURITY (EMSEC) REQUIREMENTS

EMISSIONS SECURITY ASSESSMENT REQUEST (ESAR)

FOR ALL CLASSIFIED SYSTEMS

REF. TO ITEM 11i OF DD FORM 254

General:

1. The Contractor shall ensure that compromising emanations (EMSEC) conditions related to this contract are minimized.

2. The Contractor shall provide countermeasures assessment data to the COR in the form of an EMSEC Security Assessment Request (ESAR). The ESAR shall provide only specific responses to the data required in paragraph 3 below. The Contractor’s standard security plan shall not be used as a “stand alone” ESAR response. The Contractor shall not submit a detailed facility analysis/assessment. The ESAR information will be used to complete an EMSEC Counter measures Assessment Review of the contractor’s facility to be performed by the Government EMSEC authority using current Air Force EMSEC directives. EMSEC is applied on a case-by-case basis and further information may be required to complete the review. Should this be the case, the Contractor shall provide this information to the COR and PSO when requested. After the evaluation of the ESAR by the Government EMSEC authority, additional EMSEC requirements may be necessary.

3. ESAR contents shall include, as a minimum, the following information (NISPOM, Para. 11-101c, ICD 705, JAFAN 6/9):

a. The specific classification and special categories of material to be processed/handled by electronic means.

b. The percentage of information being processed. Identify the approximate percentage for level of information processed including unclassified.

c. The specific location where classified processing will be performed.

d. The name, address, title and telephone number of a point-of-contact at the facility where processing will occur.

NOTE: Once the above information has been provided to the COR, no further reporting is required for equipment reconfigurations. However, if the facility is physically relocated to another geographical location, the information requested in paragraph 3 above must be furnished to the COR and PSO.

4. The prime Contractor shall ensure that all subcontractors and/or vendors comply with EMSEC requirements when performing classified processing related to this contract. They will provide the above documentation through their prime to the contracting officer to complete the ESR.

*NOTE: A copy of your System Security Plan(s) (SSP) will suffice.

Attachment 2

OPERATIONS SECURITY (OPSEC)

REF. TO ITEM 11j OF DD FORM 254

GENERAL:

1. PURPOSE: This section outlines the requirements and procedures necessary to protect Critical Information for Operations Security (OPSEC).

2. MISSION: To maintain a continuing awareness of adversary interest in center actions and adversary intelligence collection capabilities. To understand the need to identify and protect classified and unclassified indicators, which occur, reveal sensitive information. To evaluate the effectiveness of OPSEC measures taken to preclude or reduce adversary acquisition and exploitation of sensitive information.

3. DEFINITION: OPSEC is the process of analyzing friendly actions attendant to military operations and other activities to:

a. Identify those actions that can be observed by adversary intelligence systems.

b. Determine indicators hostile intelligence systems might obtain that could be interpreted or pieced together to derive critical information in time to be useful to adversaries.

c. Select and execute measures that eliminate or reduce to an acceptable level the vulnerabilities of friendly actions to adversary exploitation.

4. OBJECTIVES:

a. To protect planned operational center activities by preventing the inadvertent disclosure of unclassified information relating to or revealing a possible classified operation.

b. To preserve secrecy concerning specific scenario events and a NORAD response to these events.

c. To identify OPSEC vulnerabilities and recommend protective measures which will serve to enhance the security of future operations.

5. TASKS: Task requirements are outlined in the Statement of Work for this effort and at a minimum must include:

a. Release of the organizations Critical Information List to the contractor.

b. Threat information available (Threat Working Group Minutes).

c. Contractor receiving OPSEC training from the sponsoring organization.

d. Specific OPSEC countermeasures as needed.

Attachment 3

COMMUNICATIONS SECURITY (COMSEC) OPERATIONS

Access to Keying Material Designated for Encryption of Sensitive Compartmented Information (SCI).

Access to keying material that has been used to encrypt SCI constitutes access to the SCI itself. Keying material designated for encryption of SCI is considered SCI and is unencrypted (i.e., in RED form) when it becomes effective or when it is removed from its protective packaging or the protective packaging is no longer intact, whichever occurs first. Restrict access to unencrypted keying material used to protect SCI as follows:

NOTE: The COMSEC Account Manager is not considered to have access to unencrypted key if, when loading a user's electronic fill device with key from a Key Processor or a KP, the user is present and immediately departs with the fill device after the key load is complete. For TOP SECRET key, this requires two individuals to accompany the fill device.

Keying material designated for encryption of SCI must be issued for use only to personnel who are indoctrinated for SCI. The ConAuth must approve exceptions.

Control of TOP SECRET Keying Material. TOP SECRET keying material protects the most sensitive national security information. Losing it to an adversary can endanger all the information the key protects. S ingle-person access to TOP SECRET keying material increases opportunities for unauthorized handling, use, production, dissemination, removal, and possession of the material. For this reason, TOP SECRET keying material, to include codes and authenticators, and TOP SECRET key generating equipment, must be provided special protection.

Exceptions. This section does not apply to:

Positive Control material and devices. (Control this material according to CJSCI 3260.01, Joint Policy Governing Positive Control Material and Devices).

Unopened NSA protectively packaged material.

Unopened packages received from or in the custody of the Defense Courier Service or Diplomatic Courier Service.

COMSEC material used in tactical situations and implementing TPI is not possible.

Two-Person Integrity of TOP SECRET Keying Material. TPI is a storage and handling system that prohibits individual access to TOP SECRET keying material. It requires the presence of at least two authorized persons who know two-person integrity (TPI) procedures and can each detect incorrect or unauthorized security procedures for the task being performed. All activities with TOP SECRET keying material must handle, store, issue, transport, and destroy it under TPI control. Each user of TOP SECRET keying material and TOP SECRET key generators develops and uses procedures and controls to make sure lone individuals do not have access to TOP SECRET keying material (hard copy, set on permuter trays, or contained in electronic fill devices, etc.). Lone access to TOP SECRET COMSEC material for any length of time, without an approved waiver, is a reportable incident according to Chapter 9, Reporting COMSEC Deviations. (T-0)

No-Lone Zone. A no-lone zone is an area, room, or space which, when attended, must be occupied by two or more appropriately cleared individuals who remain within sight of each other. TPI procedures differ from no-lone zone procedures in that, under TPI controls, two authorized persons must directly participate in the handling and safeguarding of the keying material (as in accessing storage containers, transportation, keying/rekeying operations, and destruction). No-lone zone controls are less restrictive in that the two authorized persons need only be physically present in the common area where the material is located. Establish a COMSEC no-lone zone:

NOTE: Two-person integrity procedures differ from no-lone zone procedures in that, under two-person integrity controls, two authorized persons must directly participate in the handling and safeguarding of the keying material (as in accessing storage containers, transportation, keying/rekeying operations, and destruction). No-lone zone controls are less restrictive in that the two authorized persons need only be physically present in the common area where the material is located. Establish a COMSEC no-lone zone:

Establish a COMSEC no-lone-zone (CNLZ):

At COMSEC facilities that produce classified hard copy or unencrypted electronic key.

At cryptologist facilities that store or distribute unencrypted classified keying material.

COMSEC users establish CNLZ whenever:

Permuter trays are set up with TOP SECRET key.

Cryptographic equipment contains TOP SECRET key in hard-copy form.

TOP SECRET key is set in a mechanical permuter plug installed in cryptographic equipment.

NOTE: No-lone zones are not required if the COMSEC equipment has been modified to preclude single person access by installing locking bars secured by an approved padlock, or if tamper indicating seals are used in accordance with instructions provided by NSA.

Transportation. Adhere to the following procedures when transporting TOP SECRET keying material.

Apply TPI controls when transporting TOP SECRET keying material not sealed in NSA-approved protective packaging. Both persons moving the material must be granted cryptographic access according to Chapter 6, CAP, and must sign a receipt for the material when they pick it up.

TPI controls are not required when transporting TOP SECRET keying material in NSA-approved protective packaging. However, lone individuals moving the material must have proper clearance and have been granted cryptographic access according to Chapter 6.

When users locally transport the material from the COMSEC account to their duty section, ensure local procedures require a second individual to inspect the package for tampering and record the inspection on the user's copy of the receipt.

Handling Packages Containing TOP SECRET Material. Packages received into the COMSEC account can have the outer wrapper removed by one person. If the inner wrap is stamped TOP SECRET CRYPTO, terminate further opening of the package until a second TOP SECRET-cleared individual is present. The presence of two appropriately cleared individuals is required only as long as it takes to determine that the TOP SECRET material is in protective packaging and that the packaging has not been damaged or opened.

Storing Material. Store TOP SECRET keying material, not in NSA protective packaging, under TPI controls. Use an X-09 (or equivalent) combination lock with no one person authorized access to both combinations. Make sure at least one combination lock is built-in, as in a vault door or in a security container drawer. Storage can be in a special access control container (SACC) within a security container, in a security container within a vault, in a security container equipped with an electronic lock using the dual access mode, or in a security container with two combination locks. Security containers used to store TOP SECRET keying material must be GSA-approved and have their Federal Specification approved FF-L-2740A lock set up in the TPI, two combination mode. When using two combination locks, identify each security container (that is, lock 1, lock 2, safe 1, safe 2) and name, in writing, each person with authorized access to each combination. Each lock must have a separate SF 700 and SF 702. Limit the SF 700 to the top 4 individuals who could be contacted if the safe is left unsecure. While the SF 700 is not an access list, the individuals listed will be individuals already on the access list for the vault or container.

NOTE: Keep common fill devices under TPI whenever they are used to store TOP SECRET key. Apply TPI controls to the SKL, RaSKL, etc., whenever they are used to store TOP SECRET key and the CIK is installed or not properly secured.

TPI storage procedures are not required for TOP SECRET key in tactical situations. In situations where units are unable to meet normal TPI storage requirements, users must either:

Store TOP SECRET keying material in a standard, approved field safe or similar container secured by a 3-position mechanical combination lock meeting federal specification FF-L-2937; or, If adequate storage facilities are not available or in unique travel circumstances, keep TOP SECRET keying material under personal custody.

Procedures in effect must require inspections of protective packaging in accordance with applicable Protective Technologies Pamphlets.

Recording Combinations. To provide ready access to secured material in emergencies, it is permissible to keep a central record of all lock combinations used to protect TOP SECRET keying material in a single secure container, approved for TOP SECRET storage. Protect the combinations by using part 2 of the SF 700. Seal this to prevent undetected, unauthorized access to the combination.

Loading TOP SECRET Keying Material. Except in tactical environments when TPI is not possible, always apply TPI handling procedures to keying operations.

Two-Person Integrity Incidents. In addition to COMSEC incidents identified in Chapter 9, report any violation of TPI or CNLZ requirements, including situations in which an individual not under the CAP program accesses TOP SECRET keying material alone without a valid waiver.

TPI Waivers. TPI waivers are approved by NSA only. (T-0) All TPI waivers must be submitted to AFSPC CYSS/CYS COMSEC Field Support with coordination from the requesting unit’s MAJCOM/A6s and all the controlling authorities of the affected material. Revised operational procedures or work schedules or other unit-level initiatives may make waivers unnecessary. A lone person must not access TOP SECRET keying material until entered into the CAP and an approved waiver has been granted.

File details come from the government source that posted it. Updated .