Attch_3_DRAFT_DD_Form_254_SSPARS.pdf

PDF 177 KB Posted

Attached to
Solid State Phased Array Radar System (SSPARS) Federal contract opportunity
Solicitation number
FA2517-15-R-8001
Issued by
Department of the Air Force Space Command

About this file

This document contains a DD Form 254 detailing security classification specifications for a federal contract to provide operations and maintenance support for the Solid State Phased Array Radar System at various worldwide locations.

The contract requires top secret facility and personnel clearances. Work will involve classified materials up to the top secret level, including special access programs, intelligence information, and communications security materials. Performance will take place at radar sites in Alaska, California, Massachusetts, Greenland, and the United Kingdom. The contractor must abide by security regulations and requirements for special access programs when working onsite at government facilities. Two-person integrity controls and no-lone zone procedures are required for top secret materials. The contract expires in April 2026.

Draft DD Form 254 Security Classification

View the file

Other files for this federal contract opportunity

Other files attached to Solid State Phased Array Radar System (SSPARS), newest first.
File Type Posted
2._Attch_2,_Contractor_Assessment_and_Performance_Reporting_(CAsPR)_Matrix.xlsx XLSX spreadsheet
12._Attch_12,_Questions_and_Answers.pdf PDF
0._FA2517-15-R-8001-0001_(Conformed).pdf PDF
4._Attch_4,_Beale_CBA_1_Oct_2015_-_30_Sep_2019.pdf PDF
7._Attch_7,_Clear_CBA_(IBT)_1_Oct_2016_-_30_Sep_2019.pdf PDF
8._Attch_8,_Quality_Assurance_Surveillance_Plan.docx DOCX document
11._Attch_11,_CLIN_Schedule_Worksheet.xlsx XLSX spreadsheet
5._Attch_5,_Cape_Cod_CBA_1_Oct_2016_-_30_Sep_2019.pdf PDF
1._Attch_1,_Performance_Work_Statement.docx DOCX document
5._Attch_5,_Cape_Cod_CBA_1_Oct_2016_-_30_Sep_2019.pdf PDF
8._Attch_8,_Quality_Assurance_Surveillance_Plan.docx DOCX document
12._Attch_12,_Draft_RFP_and_Industry_Day_Questions_and_Answers.pdf PDF
9._Attch_9,_Scheduled_Government_Furnished_Property.pdf PDF
7._Attch_7,_Clear_CBA_(IBT)_1_Oct_2016_-_30_Sep_2019.pdf PDF
1._Attch,_Performance_Work_Statement.docx DOCX document
11._Attch_11,_CLIN_Schedule_Worksheet.xlsx XLSX spreadsheet
5._Attch_5,_Cape_Cod_CBA_1_Oct_2016_-_30_Sep_2019.pdf PDF
12._Attch_12,_Draft_RFP_and_Industry_Day_Questions_and_Answers.pdf PDF
0._DRAFT_Request_For_Proposal_FA2517-15-R-8001.pdf PDF
8._Attch_8,_Quality_Assurance_Surveillance_Plan.docx DOCX document
4._Attch_4,_Beale_CBA_1_Oct_2015_-_30_Sep_2019.pdf PDF
Site_Visit_-_Beale_AFB_Weather_Update.pdf PDF
16._Attch_16,_Site_Visit_Clear_Visit_Request_Worksheet.xlsx XLSX spreadsheet
12._Attch_12_Site_Visit_Schedule.doc DOC document
0._FA2517-15-R-8001_SSPARS_Notice_of_Site_Visit.pdf PDF
OCI_Mitigation_Plan_REMINDER.pdf PDF
12._Attch_12_Site_Visit_Schedule.doc DOC document
9._Attch_9,_Schedule_Government_Furnished_Property.pdf PDF
0._DRAFT_Request_For_Proposal_FA2517-15-R-8001.pdf PDF
2._Attch_2,_Contractor_Assessment_and_Performance_Reporting_(CAsPR)_Matrix.xlsx XLSX spreadsheet
16._Attch_16,_Site_Visit_Clear_Visit_Request_Worksheet.xlsx XLSX spreadsheet
14._Attch_14,_Site_Visit_Beale_AFB_EAL_Form.xls XLS spreadsheet
8._Attch_8,_Quality_Assurance_Surveillance_Plan.docx DOCX document
6._Attch_6,_Clear_CBA_(FJCC)_1_Oct_2015_-_Sep_2019.pdf PDF
17._Attch_17,_Site_Visit_REAL_ID_Act_Primer.pdf PDF
3._Attch_3,_DD_Form_254.pdf PDF
SSPARS_Draft_RFP_and_Industry_Day_Comments-_ROUND_3.pdf PDF
SSPARS_Industry_Day_Attendees.pdf PDF
SSPARS_Industry_Day_Briefing_4_Oct__16.pptx PPTX presentation
1._DRAFT_RFP_FA2517-15-R-8001_SSPARS.pdf PDF
Attch_1_DRAFT_PWS_SSPARS_23_Aug_16.docx DOCX document
DD2345.pdf PDF
DD2345_Checklist.pdf PDF
FOUO_Guidance.pdf PDF
Notice_of_Industry_Day.pdf PDF
Attch_3_-_Ground_Rules.pdf PDF
Attch_1_-_Agenda.pdf PDF
FA2517-15-R-8001_Synopsis.docx DOCX document
RFI_2_Attch_1 _CPARS_Matrix_with_Instructions.pdf PDF
SSPARS_PWS.pdf PDF
Show all 50

Solid State Phased Array Radar System (SSPARS) has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DD FORM 254, DEC 1999 PREVIOUS EDITION IS OBSOLETE. Adobe Professional 7.0 Reset

DEPARTMENT OF DEFENSE

CONTRACT SECURITY CLASSIFICATION SPECIFICATION

(The requirements of the DoD Industrial Security Manual apply to all security aspects of this effort.)

1. CLEARANCE AND SAFEGUARDING

a. FACILITY CLEARANCE REQUIRED

TOP SECRET

b. LEVEL OF SAFEGUARDING REQUIRED

TOP SECRET

2. THIS SPECIFICATION IS FOR: (X and complete as applicable) 3. THIS SPECIFICATION IS: (X and complete as applicable)

a. PRIME CONTRACT NUMBER

FA2517-18-C-8000

a. ORIGINAL (Complete date in all cases)

DATE (YYYYMMDD)

b. SUBCONTRACT NUMBER

b. REVISED (Supersedes all previous specs)

REVISION NO.

c. SOLICITATION OR OTHER NUMBER

DUE DATE (YYYYMMDD)

c. FINAL (Complete Item 5 in all cases)

4. IS THIS A FOLLOW-ON CONTRACT? YES NO. If Yes, complete the following:

Classified material received or generated under FA2517-06-C-8001 (Preceding Contract Number) is transferred to this follow-on contract.

5. IS THIS A FINAL DD FORM 254? YES NO. If Yes, complete the following:

In response to the contractor's request dated , retention of the classified material is authorized for the period of

6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)

a. NAME, ADDRESS, AND ZIP CODE

b. CAGE CODE

c. COGNIZANT SECURITY OFFICE (Name, Address, and Zip Code)

Defense Security Service (1OFCL2) 7556 Teague Road, Ste. 580 Hanover, MD 21076

7. SUBCONTRACTOR

a. NAME, ADDRESS, AND ZIP CODE

N/A

8. ACTUAL PERFORMANCE

a. LOCATION

6th Space Warning Squadron (SWS) at Cape Cod Air Force Station (AFS), MA; 7 SWS at Beale Air Force Base (AFB), CA;

12 SWS at Thule Air Base (AB), GL; 13 SWS at Clear AFS, AK; and Royal Air Force (RAF) Fylingdales, UK

21 SW/IPO

135 Dover Street, Ste 1055 Peterson AFB CO 80914-1159 Or as identified in a Support Agreement

9. GENERAL IDENTIFICATION OF THIS PROCUREMENT

Contract is for operations and maintenance on a continuous 24-hours-a-day, 7-days-a-week (24/7) in support of Missile Warning, Missile Defense and Space Surveillance missions under the 21st Operations Group (21 OG) at five installations/sites: Beale AFB, CA; Cape Cod AFS, MA; Clear AFS, AK; Thule AB, GL and Sensitive Communications at RAF Fylingdales, UK.

10. CONTRACTOR WILL REQUIRE ACCESS TO: YES NO 11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: YES NO

a. COMMUNICATIONS SECURITY (COMSEC) INFORMATION a. HAVE ACCESS TO CLASSIFIED INFORMATION ONLY AT ANOTHER

CONTRACTOR'S FACILITY OR A GOVERNMENT ACTIVITY

b. RESTRICTED DATA b. RECEIVE CLASSIFIED DOCUMENTS ONLY

c. CRITICAL NUCLEAR WEAPON DESIGN INFORMATION c. RECEIVE AND GENERATE CLASSIFIED MATERIAL

d. FORMERLY RESTRICTED DATA d. FABRICATE, MODIFY, OR STORE CLASSIFIED HARDWARE

e. INTELLIGENCE INFORMATION e. PERFORM SERVICES ONLY

(1) Sensitive Compartmented Information (SCI) f. HAVE ACCESS TO U.S. CLASSIFIED INFORMATION OUTSIDE THE U.S., PUERTO RICO, U.S. POSSESSIONS AND TRUST TERRITORIES

(2) Non-SCI g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE TECHNICAL INFORMATION

CENTER (DTIC) OR OTHER SECONDARY DISTRIBUTION CENTER

f. SPECIAL ACCESS INFORMATION h. REQUIRE A COMSEC ACCOUNT

g. NATO INFORMATION i. HAVE TEMPEST REQUIREMENTS

h. FOREIGN GOVERNMENT INFORMATION j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS

i. LIMITED DISSEMINATION INFORMATION k. BE AUTHORIZED TO USE THE DEFENSE COURIER SERVICE

j. FOR OFFICIAL USE ONLY INFORMATION l. OTHER (Specify)

Provide the information required by Contract clauses 52.204-2, 52.204-9000 and 52.204-9001 to the Information Security Program Manager (ISPM).

k. OTHER (Specify)

Will require 20 SCI billets; 5 per site for Cape Cod AFS, Clear AFS, Beale AFB and Thule AB.

DD FORM 254 (BACK), DEC 1999 Reset

12. PUBLIC RELEASE. Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the Industrial Security Manual or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for approval prior to release Direct Through (Specify)

"NO PUBLIC RELEASE OF SCI IS AUTHORIZED"

to the Directorate for Freedom of Information and Security Review, Office of the Assistant Secretary of Defense (Public Affairs)* for review.

*In the case of non-DoD User Agencies, requests for disclosure shall be submitted to that agency.

13. SECURITY GUIDANCE. The security classification guidance needed for this classified effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended. (Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. Add additional pages as needed to provide complete guidance.)

13a. Contract Expiration Date: 30 April 2026 13b. The Sensitive Compartmental Information Facility (SCIF) will be used to perform SCI contractual requirements. SCI material released to the contractor under this contract will be separately stored and maintained only in such properly accredited facilities.

13d. Inquiries pertaining to classification guidance on SCI will be directed to the Contract Monitor.

13e. SCI data furnished to or generated by the contractor will require security handling and controls beyond those in the National Industrial Security Program Operating Manual (NISPOM). These supplemental instructions will be furnished and/or made available to the contractor thru the Contract Monitor by the User Agency Special Security Office, SSO AFSPC.

13f. Names of contractor personnel requiring access to SCI will be submitted to the SCI Contract Monitor. Forms requesting Special Background Investigations will be prepared in accordance with the NISPOM and submitted to Defense Security Service

(DSS).

13g. The contractor will establish and maintain a current access list of those employees working on this contract. A copy of this list will be furnished to the SCI Contract Monitor.

13h. The contractor will advise the SCI Contract Monitor immediately upon reassignment of personnel to other duties not associated with this contract.

13i. Release of Information. SCI with restrictive caveats (e.g., ORCON, PROPIN, etc.) will be released to contractors only when originator approval has been obtained. The contractor will control SCI, which has been originated or obtained under this contract as follows: The contractor may release such material to any contractor employee working against a billet under this contract only when a need-to-know exists. The contractor will release such material to any Special Security Office personnel assigned to (see continuation)

14. ADDITIONAL SECURITY REQUIREMENTS. Requirements, in addition to ISM requirements, are established for this contract. Yes No (If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the cognizant security office. Use Item 13 if additional space is needed.)

Provide the information requested by AFFARS 5352.204-9000, Notification to Government Security Activity Clause, and AFI 16-1406, Industrial Security Program Management, to the Information Protection Office (IPO). Refer to the contract document for these clauses.

15. INSPECTIONS. Elements of this contract are outside the inspection responsibility of the cognizant security office. Yes No (If Yes, explain and identify specific areas or elements carved out and the activity responsible for inspections. Use Item 13 if additional space is needed.)

Industrial Security Reviews, while operating on an Air Force Installation, will be conducted by the Information Protection Office. See Continuation sheet comment.

16. CERTIFICATION AND SIGNATURE. Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below.

a. TYPED NAME OF CERTIFYING OFFICIAL

AUSTIN FRINDT

b. TITLE

Contracting Officer

c. TELEPHONE (Include Area Code)

(719) 554-2940

d. ADDRESS (Include Zip Code)

21 CONS\LGCZ

135 Dover Street, Suite 1240 Peterson AFB, CO 80914-1285

17. REQUIRED DISTRIBUTION

a. CONTRACTOR

b. SUBCONTRACTOR

c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR

d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION

e. ADMINISTRATIVE CONTRACTING OFFICER

f. OTHERS AS NECESSARY 21 SW/PMD, Program Manager

e. SIGNATURE

SSPARS DD Form 254 - Continuation FA2517-15-R-8001

Continuation of Block 8c:

AFSPC/SSO

150 Vandenberg Street, Suite 1105 Peterson AFB CO 80914

Continuation of Block 10:

Ref 10.a. COMSEC material/information may not be released to DoD contractors without Air Force Cryptological Support Center (AFSCS) approval. Contractor must forward requests for COMSEC material/information to the COMSEC Officer through the program office. The contractor is governed by the DoD 5220.22-5 COMSEC Supplement to the NISPOM in the control and protection of COMSEC material/information. Access to COMSEC material by personnel is restricted to US citizens holding final US Government clearances. Such information is not releasable to personnel holding only reciprocal clearances.

Ref 10g. Applies to RAF Fylingdales only. NATO Information: Special briefing required for access to NATO.

Prior approval of the contracting activity is required for subcontracting. Access to classified NATO information requires a final U.S. Government clearance at the appropriate level.

Ref 10h. Applies to RAF Fylingdales only. Foreign Government Information: Prior approval of the contracting activity is required for subcontracting. Access requires a final U.S. clearance at the appropriate level.

Ref 10.j. For Official Use Only (FOUO) information provided under this contract shall be safeguarded as specified in DoDM 5200.01 Vol IV, Enclosure 3.

Continuation of Block 11:

Ref 11.a. Contract performance is restricted to Clear AFS, AK, Cape Cod AFS, MA, Beale AFB, CA, Thule AB, GL, and RAF Fylingdales, UK.

The contractor requires access to classified source data up to and including TOP SECRET in support of the work effort. Any extracts or use of such data requires the contractor to apply derivative classifications and markings consistent with the source documents. Use of multiple sources on the classified by line necessitates compliance with the NISPOM (or DoD 5200.01 Vol 2 and AFI 16-1404 if operating on an Air Force Installation), and use of the following Security Classification Guides (SCGs): (Subsequent revisions/changes apply to this contract)

a. Ground-Based Radar Missile Warning System, 1 Sep 03, OPR: HQ AFSPC/DOS, Peterson AFB, CO 80914-5000.

b. Dedicated Space Surveillance Network Sensors, 30 Sep 05, OPR: HQ AFSPC/XOC, Peterson AFB, CO 80914-5000.

c. Milstar/Advanced Extremely High Frequency (AEHF) System Operations Protection Guide, 31 Dec 07, OPR: HQ AFSPC/A3, Peterson AFB, 80914-5000

Ref 11f. RAF Fylingdales, UK

Ref 11g. The Contractor must prepare and process a DD Form 1540 and 1541 for request to utilize the Defense Technical Information Center (DTIC). Reference the NIS11g. The Contractor must prepare and process a DD Form 1540 and 1541 for request to utilize the Defense Technical Information Center (DTIC). Reference the NISPOM for preparation and processing of these forms.

Ref 11i. See Emission Security (EMSEC) requirements in Attachment 1, “EMISSION SECURITY ASSESSMENT

REQUEST (ESAR) FOR ALL CLASSIFIED SYSTEMS”.

Ref 11j. See Operations Security (OPSEC) requirements in Attachment 2.

SSPARS DD Form 254 - Continuation FA2517-15-R-8001

Ref 11k. See Communications Security (COMSEC) requirements in attachment 3. COMSEC material shipped to the site comes through the Defense Courier Service (DCS). Requires the contracting activity to request DCS services from the Commander, Defense Courier Service, ATTN: Operations Division, Fort George G. Meade, MD 20755-3570. Only certain classified information qualifies for shipment by DCS. It is the responsibility of the contracting activity to comply with DCS policy and procedures.

Ref 11l. Provide the information required by Contract clauses FAR 52.204-2, DFARS 252.204-7000 and AFFARS 5352.204-9000 to the Information Protection Office (IPO) or host Cognizant Security Office as identified in the Support Agreement.

Computer security (COMPUSEC): Tasks outlined in Performance Work Statement (PWS).

Continuation of Block 13.

Ref 13i continued. HQ AFSPC or DIA upon demand by such personnel. The contractor may release such material to any other personnel, including contractor and subcontractor employees, and employees of any Federal Government agency, only upon prior written approval from the SCI Contract Monitor. An access certification to an AFSPC contractor-occupied SCIF does not constitute approval to release AFSPC contractual material to these other personnel; Contract Monitor approval is nevertheless required. Contract Monitor approval of an AFSPC contractor visit certification or permanent certification to another facility will constitute approval to discuss contractual material at facility to be visited.

Ref 13j. Any SCI released to the contractor in support of this contract remains the property of DOD department, agency, or command that releases it. The contractor will maintain active accountability of all SCI released to his/her custody, regardless of whether the release is within a contractor or US Government SCIF. Upon completion/cancellation of the contract, the contractor must return all such material to SSO AFSPC unless a follow-on contract specifies that the material will be transferred to a subsequent contract. SCI inventories will be conducted IAW DoD 5105.21m_vol1/2/3 and AFMAN 14-304.

Ref 13k. A SCIF must be established and maintained by the contractor. SCI material released to the contractor under this contract will be separately stored and worked on only in facilities either accredited through AFSPC, or another accredited agency, and properly covered by a co-utilization Memorandum of Agreement (MOA) between AFSPC and the sponsor of the facility. AFSPC sponsored SCIFs will not be co-utilized for other Government agency contracts unless properly covered by an MOA. The supporting SSO is (See SSO AFSPC for information).

Ref 13m. Electronic processing of classified information is permitted only when the requirements of AFMAN 14- 304 have been met as determined by an accredited TEMPEST authority. This contract requires electronic processing of SCI. TEMPEST accreditation of ADPS must be obtained IAW the above reference. Operational accreditation of ADPS using software must be obtained IAW DoD 5105.21m_vol1/2/3 and AFMAN 14-304.

Security provisions of DoD 5105.21m_vol1/2/3 and AFMAN 14-304 also apply and are part of this contract. The CSSO will appoint an Information Systems Security Officer (ISSO) and advise SSO AFSPC of this appointment.

Ref 13n. Contractor Special Security Officers (CSSOs) must coordinate with the SCI Contract Monitor and obtain the concurrence of SSO AFSPC prior to subcontracting any portion of SCI efforts involved in this contract.

Ref 13o. No contractor personnel will be granted access to SCI material under this contract unless they are filling a DOD SCI billet. The contractor will coordinate with SCI Contract Monitor to ensure adequate billets are requested under this contract. Multiple contract employees sponsored by the organizations other than Space Command must be certified to SSO AFSPC for use on the contract.

Ref 13p. The contractor will designate a Special Security Point of Contact (POC) to SSO AFSPC. The POC will be responsible for all personnel and information security transactions between the contractor and SSO AFSPC.

SSPARS DD Form 254 - Continuation FA2517-15-R-8001

Ref 13q. Contractor will not use references to SCI accesses, even by unclassified acronyms, in advertising, promotional efforts, or recruitment for employees.

Ref 13r. The following activity is designated as the User Agency SS for SCI requirements IAW DoD 5105.21m_vol1/2/3; HQ AFSPC/A2S, Peterson AFB CO 80914-4311.

Continuation of Block 14.

Shipments of classified or sensitive equipment shall be handled, transported, transmitted, and protected IAW NISPOM, DoD 5220.22M and as specified by unit directives. The contractor shall execute a VGSA with the Government.

Note 1. The use of automated information systems for processing and producing classified information at 6 SWS at Cape Cod AFS, MA, 7 SWS at Beale AFB, CA, 12 SWS at Clear AFS, AK, 13 SWS at Clear AFS, AK, and RAF Fylingdales, UK is required. Contractor shall assist with information systems accreditation as stated in the performance work statement.

Note 2. The contractor shall comply with security and law enforcement policies and procedures in effect on Government installations where contractor performance occurs under this contract. The contract will be performed within USAF restricted areas on Clear AFS, AK, Cape Cod AFS, MA, Beale AFB, CA, Thule AB, GL, and RAF Fylingdales, UK. At each Solid State Array Phased Array Radar System (SSPARS) site, the contractor employees must be subject of a National Agency Check or already have been issued a final or interim secret clearance for the purpose of access to classified information before being permitted unescorted entry to these restricted areas. Contractor employees not meeting the prerequisite for unescorted entry shall be under the continuous escort by other cleared contractor employees while in restricted areas.

Note 3. The contractor shall provide a visit request to the respective Commander, 6 SWS, Commander, 7 SWS, Commander, 12 SWS, Commander, 13 SWS, or USAF Liaison Officer for RAF Fylingdales to permit unescorted entry to USAF restricted areas and/or access to classified information while on the installation (see AFI 31-101, para 9.2 and DoD 5220.22-M, National Industrial Security Program) (NISPOM), Feb 2006).

Note 4. When performance involves classified information on a military installation where the contractor does not possess a facility clearance for that location, the contractor operation is considered a “visitor group” on the installation. As such, the contractor’s security procedures shall be integrated with those of the installation. The contractor shall enter into a security agreement (or understanding) with the responsible military commander(s) to formalize:

1. Those security actions which will be performed for the contractor by the installation, such as providing storage and classified reproduction facilities; guard services; security forms; security inspection under DoD 5220.22-M, classified mail services; security badging; visitor control; and investigation security incidents and;

2. Those security actions for which joint action may be required, such as packaging and addressing classified transmittals, security checks, internal security controls and implanting emergency procedures to protect classified materials.

Note 5. The visitor group contractor visitor security agreement is developed by the Security Service Agency (SSA) and signed by the installation commander to ensure National security interests are protected by confirmed security support and identifying security procedures unique to the installation.

Note 6. If after reviewing the security agreement and discussing it with the military commander or representative, the contractor believes there may be a cost impact, the contractor will notify the contracting officer in writing. In such cases, do not sign or implement the security agreement unless directed by the Contracting Officer. The contracting officer will work closely with the FSO toward an appropriate solution.

SSPARS DD Form 254 - Continuation FA2517-15-R-8001

Note 7. The visitor group contractor visitor security agreement, when signed by the contractor’s security manager and site commander, may suffice in lieu of a Standard Practice Procedure for group visitor contractor performance on a military installation.

Note 8. See DoDM 5200.01, Volume 2, for marking guidance regarding classified information.

Continuation of Block 15.

This contract requires access to SCI. The Senior Intelligence Officer, AFSPC/A2, has exclusive security oversight over all classified material produced under this contract within the contractors SCIF. DSS (see note), retains security inspection responsibility for all SCI and non-SCI material released to or developed under the contract and held within the contractor’s SCIF. DoD 5105.21M_vols 1/2/3 and AFMAN 14-304 provide the necessary guidance for physical, personnel, and information security measures and are part of the security specifications for this contract. Contractor compliance with these directives is mandatory unless specific provisions are specifically waived. DIA is relieved of responsibility for all SCI material released to the contractor under this contract.

DSS is relieved of inspection responsibility for all classified material that is released to or developed by the contractor while on a military installation. DSS retains inspection responsibility for all non-SCI classified material released to or developed by the contractor and held in the contractors’ facility. The SSO maintains inspection responsibility for all SCI material related to this contract. Local Information Protection security program assessments while operating on an Air Force installation, shall be conducted by the IPO. HQ AFSPC/IN retains security cognizance of all Intelligence materials released to the contractor.

a. RAF Fylingdales, United Kingdom. Industrial security supervision is the responsibility of the 100th Air Refueling Wing, RAF Mildenhall, APO 09459 under support agreement 2500-181.

The majority of the contract effort will be performed on an Air Force installation. The host security force on the installation is responsible for Industrial security supervision and inspections of the contractor to ensure contractor compliance with DOD 5220.22-M, National Industrial Security Program (NISPOM), Feb 2006. Part of the contract effort will be performed on a USAF installation at Thule AB, Greenland and a British RAF installation at RAF Fylingdales, United Kingdom.

a. For Thule AB, Greenland, 21 SW/IP is responsible for industrial security supervision and inspections of the contractor to ensure contractor compliance with DoD 5220-22-M, National Industrial Security Program Operators Manual for safeguarding classified information and the visitor group security agreement. Local Security Forces provide local security and law enforcement policies and procedures.

b. For Fylindales, United Kingdom, 100 ARW/IP provides guidance, oversight, and inspection of the industrial security program; and the RAF Security and Ministry of Defense Police provide local security and law enforcement policies and procedures.

SSPARS DD Form 254 - Continuation FA2517-15-R-8001

Continuation of Block 17.

Reference 17f. Required Distribution, 21 SW/IP, Peterson AFB CO 80914-1560 6 SWS/SF, Cape Cod AFS, MA 02561-0428 7 SWS/SF, Beale AFB, CA 95903 Thule AB GN (BMEWS I), 12 SWS/DOO, APO AE 09704 Clear AFS, AK (BMEWS II), 213 SWS/SFOP RAF Fylingdales, UK (BMEWS III), 100 ARW/IP, RAF Mildenhall, UK APO AE 09459

Signature:

Name: LAURA C. MCDONOUGH, GS-13 Name: TRAVIS CRIPPS, MSgt Title: SSPARS Program Manager Title: 21 OG Security Manager Office symbol: 21 SW/PMD, Peterson AFB, CO Office symbol: 21 OSS/OSO, Peterson AFB, CO

Name: MARK W. EVANGER, GG-14 Name: DAVID CALLAHAN, GS-11 Title: Chief, Special Security Office Title: COMSEC Responsible Officer Office symbol: HQ AFSPC, Peterson AFB, CO Office symbol: 21 CS/SCXS, Peterson AFB, CO

Name: ROBERT C. LARSEN, GS-13 Title: Chief, Information Protection Office symbol: 21 SW/IP, Peterson AFB, CO

SSPARS DD Form 254 - Continuation FA2517-15-R-8001

Attachment 1

EMISSIONS SECURITY (EMSEC) REQUIREMENTS

EMISSIONS SECURITY ASSESSMENT REQUEST (ESAR)

FOR ALL CLASSIFIED SYSTEMS

REF. TO ITEM 11i OF DD FORM 254

General:

1. The Contractor shall ensure that compromising emanations (EMSEC) conditions related to this contract are minimized.

2. The Contractor shall provide countermeasures assessment data to the COR in the form of an EMSEC Security Assessment Request (ESAR). The ESAR shall provide only specific responses to the data required in paragraph 3 below. The Contractor’s standard security plan shall not be used as a “stand alone” ESAR response. The Contractor shall not submit a detailed facility analysis/assessment. The ESAR information will be used to complete an EMSEC Counter measures Assessment Review of the contractor’s facility to be performed by the Government EMSEC authority using current Air Force EMSEC directives. EMSEC is applied on a case-by-case basis and further information may be required to complete the review. Should this be the case, the Contractor shall provide this information to the COR and PSO when requested. After the evaluation of the ESAR by the Government EMSEC authority, additional EMSEC requirements may be necessary.

3. ESAR contents shall include, as a minimum, the following information (NISPOM, Para. 11-101c, ICD 705, JAFAN 6/9):

a. The specific classification and special categories of material to be processed/handled by electronic means.

b. The percentage of information being processed. Identify the approximate percentage for level of information processed including unclassified.

c. The specific location where classified processing will be performed.

d. The name, address, title and telephone number of a point-of-contact at the facility where processing will occur.

NOTE: Once the above information has been provided to the COR, no further reporting is required for equipment reconfigurations. However, if the facility is physically relocated to another geographical location, the information requested in paragraph 3 above must be furnished to the COR and PSO.

4. The prime Contractor shall ensure that all subcontractors and/or vendors comply with EMSEC requirements when performing classified processing related to this contract. They will provide the above documentation through their prime to the contracting officer to complete the ESR.

*NOTE: A copy of your System Security Plan(s) (SSP) will suffice.

SSPARS DD Form 254 - Continuation FA2517-15-R-8001

Attachment 2

OPERATIONS SECURITY (OPSEC)

REF. TO ITEM 11j OF DD FORM 254

GENERAL:

1. PURPOSE: This section outlines the requirements and procedures necessary to protect Critical

Information for Operations Security (OPSEC).

2. MISSION: To maintain a continuing awareness of adversary interest in center actions and adversary intelligence collection capabilities. To understand the need to identify and protect classified and unclassified indicators, which occur, reveal sensitive information. To evaluate the effectiveness of OPSEC measures taken to preclude or reduce adversary acquisition and exploitation of sensitive information.

3. DEFINITION: OPSEC is the process of analyzing friendly actions attendant to military operations and other activities to:

a. Identify those actions that can be observed by adversary intelligence systems.

b. Determine indicators hostile intelligence systems might obtain that could be interpreted or pieced together to derive critical information in time to be useful to adversaries.

c. Select and execute measures that eliminate or reduce to an acceptable level the vulnerabilities of friendly actions to adversary exploitation.

4. OBJECTIVES:

a. To protect planned operational center activities by preventing the inadvertent disclosure of unclassified information relating to or revealing a possible classified operation.

b. To preserve secrecy concerning specific scenario events and a NORAD response to these events.

c. To identify OPSEC vulnerabilities and recommend protective measures which will serve to enhance the security of future operations.

5. TASKS: Task requirements are outlined in the Statement of Work for this effort and at a minimum must include:

a. Release of the organizations Critical Information List to the contractor.

b. Threat information available (Threat Working Group Minutes).

c. Contractor receiving OPSEC training from the sponsoring organization.

d. Specific OPSEC countermeasures as needed.

SSPARS DD Form 254 - Continuation FA2517-15-R-8001

Attachment 3

COMMUNICATIONS SECURITY (COMSEC) OPERATIONS

Access to Keying Material Designated for Encryption of Sensitive Compartmented Information (SCI). Access to keying material that has been used to encrypt SCI constitutes access to the SCI itself. Keying material designated for encryption of SCI is considered SCI and is unencrypted (i.e., in RED form) when it becomes effective or when it is removed from its protective packaging or the protective packaging is no longer intact, whichever occurs first. Restrict access to unencrypted keying material used to protect SCI as follows:

NOTE: The COMSEC Account Manager is not considered to have access to unencrypted key if, when loading a user's electronic fill device with key from a Key Processor or a KP, the user is present and immediately departs with the fill device after the key load is complete. For TOP SECRET key, this requires two individuals to accompany the fill device.

Keying material designated for encryption of SCI must be issued for use only to personnel who are indoctrinated for SCI. The ConAuth must approve exceptions.

Control of TOP SECRET Keying Material. TOP SECRET keying material protects the most sensitive national security information. Losing it to an adversary can endanger all the information the key protects. S ingle-person access to TOP SECRET keying material increases opportunities for unauthorized handling, use, production, dissemination, removal, and possession of the material. For this reason, TOP SECRET keying material, to include codes and authenticators, and TOP SECRET key generating equipment, must be provided special protection.

Exceptions. This section does not apply to:

Positive Control material and devices. (Control this material according to CJSCI 3260.01, Joint Policy Governing Positive Control Material and Devices).

Unopened NSA protectively packaged material.

Unopened packages received from or in the custody of the Defense Courier Service or Diplomatic Courier Service.

COMSEC material used in tactical situations and implementing TPI is not possible.

Two-Person Integrity of TOP SECRET Keying Material. TPI is a storage and handling system that prohibits individual access to TOP SECRET keying material. It requires the presence of at least two authorized persons who know two-person integrity (TPI) procedures and can each detect incorrect or unauthorized security procedures for the task being performed. All activities with TOP SECRET keying material must handle, store, issue, transport, and destroy it under TPI control. Each user of TOP SECRET keying material and TOP SECRET key generators develops and uses procedures and controls to make sure lone individuals do not have access to TOP SECRET keying material (hard copy, set on permuter trays, or contained in electronic fill devices, etc.).

Lone access to TOP SECRET COMSEC material for any length of time, without an approved waiver, is a reportable incident according to Chapter 9, Reporting COMSEC Deviations. (T-0)

No-Lone Zone. A no-lone zone is an area, room, or space which, when attended, must be occupied by two or more appropriately cleared individuals who remain within sight of each other. TPI procedures differ from no-lone zone procedures in that, under TPI controls, two authorized persons must directly participate in the handling and safeguarding of the keying material (as in accessing storage containers, transportation, keying/rekeying operations, and destruction). No-lone zone controls are less restrictive in that the two authorized persons need only be physically present in the common area where the material is located. Establish a COMSEC no-lone zone:

SSPARS DD Form 254 - Continuation FA2517-15-R-8001

NOTE: Two-person integrity procedures differ from no-lone zone procedures in that, under two-person integrity controls, two authorized persons must directly participate in the handling and safeguarding of the keying material (as in accessing storage containers, transportation, keying/rekeying operations, and destruction). No-lone zone controls are less restrictive in that the two authorized persons need only be physically present in the common area where the material is located. Establish a COMSEC no-lone zone:

Establish a COMSEC no-lone-zone (CNLZ):

At COMSEC facilities that produce classified hard copy or unencrypted electronic key.

At cryptologist facilities that store or distribute unencrypted classified keying material.

COMSEC users establish CNLZ whenever:

Permuter trays are set up with TOP SECRET key.

Cryptographic equipment contains TOP SECRET key in hard-copy form.

TOP SECRET key is set in a mechanical permuter plug installed in cryptographic equipment.

NOTE: No-lone zones are not required if the COMSEC equipment has been modified to preclude single person access by installing locking bars secured by an approved padlock, or if tamper indicating seals are used in accordance with instructions provided by NSA.

Transportation. Adhere to the following procedures when transporting TOP SECRET keying material.

Apply TPI controls when transporting TOP SECRET keying material not sealed in NSA-approved protective packaging. Both persons moving the material must be granted cryptographic access according to Chapter 6, CAP, and must sign a receipt for the material when they pick it up.

TPI controls are not required when transporting TOP SECRET keying material in NSA-approved protective packaging. However, lone individuals moving the material must have proper clearance and have been granted cryptographic access according to Chapter 6.

When users locally transport the material from the COMSEC account to their duty section, ensure local procedures require a second individual to inspect the package for tampering and record the inspection on the user's copy of the receipt.

Handling Packages Containing TOP SECRET Material. Packages received into the COMSEC account can have the outer wrapper removed by one person. If the inner wrap is stamped TOP SECRET CRYPTO, terminate further opening of the package until a second TOP SECRET-cleared individual is present. The presence of two appropriately cleared individuals is required only as long as it takes to determine that the TOP SECRET material is in protective packaging and that the packaging has not been damaged or opened.

Storing Material. Store TOP SECRET keying material, not in NSA protective packaging, under TPI controls. Use an X-09 (or equivalent) combination lock with no one person authorized access to both combinations. Make sure at least one combination lock is built-in, as in a vault door or in a security container drawer. Storage can be in a special access control container (SACC) within a security container, in a security container within a vault, in a security container equipped with an electronic lock using the dual access mode, or in a security container with two combination locks. Security containers used to store TOP SECRET keying material must be GSA-approved and have their Federal Specification approved FF-L-2740A lock set up in the TPI, two combination mode. When using two combination locks, identify each security container (that is, lock 1, lock 2, safe 1, safe 2) and name, in writing, each person with authorized access to each combination. Each lock must have a separate SF 700 and SF 702. Limit the SF 700 to the top 4 individuals who could be contacted if the safe is left unsecure. While the SF 700 is not an access list, the individuals listed will be individuals already on the access list for the vault or container.

NOTE: Keep common fill devices under TPI whenever they are used to store TOP SECRET key. Apply TPI controls to the SKL, RaSKL, etc., whenever they are used to store TOP SECRET key and the CIK is installed or not properly secured.

SSPARS DD Form 254 - Continuation FA2517-15-R-8001

TPI storage procedures are not required for TOP SECRET key in tactical situations. In situations where units are unable to meet normal TPI storage requirements, users must either:

Store TOP SECRET keying material in a standard, approved field safe or similar container secured by a 3-position mechanical combination lock meeting federal specification FF-L-2937; or, If adequate storage facilities are not available or in unique travel circumstances, keep TOP SECRET keying material under personal custody.

Procedures in effect must require inspections of protective packaging in accordance with applicable Protective Technologies Pamphlets.

Recording Combinations. To provide ready access to secured material in emergencies, it is permissible to keep a central record of all lock combinations used to protect TOP SECRET keying material in a single secure container, approved for TOP SECRET storage. Protect the combinations by using part 2 of the SF 700. Seal this to prevent undetected, unauthorized access to the combination.

Loading TOP SECRET Keying Material. Except in tactical environments when TPI is not possible, always apply TPI handling procedures to keying operations.

Two-Person Integrity Incidents. In addition to COMSEC incidents identified in Chapter 9, report any violation of TPI or CNLZ requirements, including situations in which an individual not under the CAP program accesses TOP SECRET keying material alone without a valid waiver.

TPI Waivers. TPI waivers are approved by NSA only. (T-0) All TPI waivers must be submitted to AFSPC CYSS/CYS COMSEC Field Support with coordination from the requesting unit’s MAJCOM/A6s and all the controlling authorities of the affected material. Revised operational procedures or work schedules or other unit-level initiatives may make waivers unnecessary. A lone person must not access TOP SECRET keying material until entered into the CAP and an approved waiver has been granted.

SSPARS DD Form 254 - Continuation FA2517-15-R-8001

Attachment 4

SPECIAL ACCESS PROGRAM ADDENDUM

Items 8a-c: SAP performance is authorized ONLY at the following locations:

Location (Physical Address) CAGE Code Cog. Security Office (Physical

HQ AFSPC N/A 21 SW/IPO

150 Vandenberg Street, Bldg 1 135 Dover Street, Suite 1055 Peterson AFB, CO 80914 Peterson AFB CO 80914-1159

Item 12: Public release of Special Access Program (SAP) data is NOT authorized without prior coordination through the AFOSI PJ Security Director and the subsequent approval of the Original Classification Authority and the Air Force Special Access Program Central Office (SAPCO). Submit all proposed public disclosures related to SAP data to the Government Program Manager HQ AFSPC/A2/3/6 and the AFOSI PJ PSO.

Item 13: Contractor will abide by all applicable security regulations, procedures and requirements while performing in the host facility.

Item 14: The following documents provide guidance for SAP contracts without performance at the contractor’s location:

• DoD Directive 5205.07, Special Access Program Policy, latest version

• DoDM 5200.01, DoD Information Security Program, Vol 1-4, latest version

• AFI 16-701, Management, Administration and Oversight of Special Access Programs, latest version

• DoDM 5205.07, Volume 2, SAP Security Manual: Personnel Security

Supersession of any of the above documents will not require an immediate revision to this DD Form 254. The updated document will be deemed to be on contract as of the date of supersession. Additional costs incurred due to updated guidance will be brought to the attention of the GCO immediately.

Item 15: DSS is carved out of inspection responsibility for the SAP portions of this contract by the DepSecDef.

Inspection responsibility is retained by SAF/AAZ and is executed per policy by AFOSI PJ.

SPECIAL ACCESS PROGRAM ADDENDUM

File details come from the government source that posted it. Updated .