Attch_4_Insider_threat_DD_254_(v2-C).pdf
PDF 941 KB Posted
- Attached to
- Insider Threat Program Federal contract opportunity
- Solicitation number
- FA7014-15-R-5015
About this file
DD254
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Amendment_02_-_Signed.pdf | ||
| Questions_submitted_to_insider_threat.pdf | ||
| Insider_Threat_Combo_amendment_2.pdf | ||
| INSIDER_THREAT_PWS_Amendment_2.pdf | ||
| interested_parties_list.pdf | ||
| signed_memo.pdf | ||
| Insider_Threat_Combo_amendment_1.pdf | ||
| ITO_Insider_Threat.pdf | ||
| Atch_3_-_Pricing_Breakdown_Insider_Threat.pdf | ||
| Attch_2_Eval_Criteria_Insider_threat.pdf | ||
| Attch_1_Insider_Threat_PWS.pdf | ||
| Insider_Threat_FBO_COMBO.pdf |
Show all 12
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Attachment 1 DD FORM 254, DEC 1999, Item 13. CONTINUATION
PRIME CONTRACT SOLICITATION PURCHASE REQUEST NUMBER:
FA7014-15-R-5015
TASK ORDER NUMBER: TBD
PRECEDING CONTRACT NUMBER: TBD
While performing at Military Service owned and/or operated locations/facilities the contractor will adhere to the respective Military Service: Information Security Program, ADP Programs, Physical Security Program and Industrial Security Program.
Appropriate local service/component command security directives, regulations, and standard operating procedures will be provided by the requiring agency (as needed) at the location in section 8.
Item 13.: All classified visit requests by Visitor Groups shall be forwarded to the COR for approval and need-to-know certification before being sent to the facility to be visited.
The COR must be notified and approve the receipt and/or generation of classified information under this contract. All classified information received and/or generated under this contract is the property of the U.S. Government regardless of proprietary claims. Upon completion or termination of this contract, the U.S. Government will be contacted for destruction or disposition instructions.
Item 13.: In addition to the reporting requirements directed by the NISPOM, the Visitor Group will provide a concurrent report of loss or compromise of classified information to the SAF/AAZ Security Manager. Visit requests to activities other than those not listed in the statement of work on this DD 254 shall have "Need to Know" certified by the SAF/AAZ Security Manager. All requests shall contain the information required by the NISPOM and shall not exceed a 12 month period.
Item 13.: All classified material received, generated, fabricated, or modified by this contract will be returned within 30 days after completion of contract or destroyed with destruction report being submitted to SAF/AAZ Security Manager. Prior to any destruction of classified information a full listing of documents will be provided to the SAF/AAZ Security Manager for review and approval. If additional contracting requirements exist where retention of classified information by the Visitor Group facility is required, a written request to retain material for a period but not to exceed 2 years is required.
Item 13.: Provide the information requested by the Notification of Government Security Activity Clause, AFFARS 5352.204-9000, and Visitor Group Security Agreements Clause, AFFARS5352.204.9001, to the Servicing Security Activity (SSA) address in block 17.f. of this form. Refer to the contract document for these clauses.
Item 13.: Non-Disclosure Agreement: The Visitor Group may be required to have access to highly sensitive and confidential plans and data for the performance of this delivery order. The Visitor Group will not divulge any information about activities or functions, or other knowledge gained, to anyone who is not authorized to have access
FA7014-15-R-5015
TASK ORDER NUMBER: TBD
PRECEDING CONTRACT NUMBER: TBD
to such information. It will be the Visitor Group’s responsibility to ensure that persons have the proper authority and “need to know” prior to any discussions. The Visitor Group will observe and comply with any security provisions.
Ref 8.a.: ACTUAL LOCATION: SAF/AAZ 1720, Air Force Pentagon, MC831 or MC830A, Washington, DC 20330-1720.
Ref 8.c.: COGNIZANT SECURITY OFFICE: 11 WG/IP, 1330 AF Pentagon, Washington DC 20330
Ref. 10.b.: Restricted Data Information is not releasable to Visitor Group employees who have not received a FINAL clearance at the appropriate security level. Written concurrence of the CO is required prior to subcontracting. Access to RESTRICTED DATA requires a FINAL U. S. Government clearance at the appropriate level.
RESTRICTED DATA will be handled and controlled as indicated in the NISPOM. See “RESTRICTED DATA INFORMATION ADDENDUM”, Attachment 3.
Ref 10.c.: CNWDI information will be handled and controlled as indicated in the NISPOM. This Visitor Group is permitted access to CNWDI in performance of the contract. The Government program manager or designated representative ensures the Visitor Group security supervisor is briefed for access to CNWDI by a Government representative prior to granting access. Access requires a FINAL U.S. Government clearance and special briefings at the appropriate level. Subcontracting CNWDI information by a Visitor Group requires prior written approval from the UNIT Security Manager and CO.
Ref. 10.d.: FORMERLY RESTRICTED DATA (FRD) will be handled and controlled as indicated in the NISPOM. This Visitor Group is permitted access to CNWDI in performance of the contract. The Government program manager or designated representative ensures the Visitor Group security supervisor is briefed for access to CNWDI by a Government representative prior to granting access. Subcontracting FRD information by a Visitor Group requires prior written approval from the Contracting Officer. Access to FORMERLY RESTRICTED DATA requires a FINAL U. S.
Government clearance at the appropriate level. See “FORMERLY RESTRICTED DATA INFORMATION ADDENDUM”, Attachment 4.
Ref 10.g.: Special briefings are required for access to NATO IAW AFI 31-406, Applying NATO Protection Standards. Prior approval of the contracting activity is required for
FA7014-15-R-5015
TASK ORDER NUMBER: TBD
PRECEDING CONTRACT NUMBER: TBD
subcontracting. Personnel not assigned to a NATO staff position, but requiring access to NATO classified information, NATO COSMIC, NATO Secret or access to the NATO accredited SIPRNET terminals, must possess the equivalent FINAL or Interim U.S.
Security Clearance based upon the appropriate personnel security investigation required. Personnel with access to NATO ATOMAL information must have the appropriate level FINAL U.S. Security Clearance at the appropriate level. The Visitor Group will maintain strict compliance in regards to NATO information IAW DoD 5220.22-M, February 28, 2006 National Industrial Security Program Operating Manual (NISPOM) Section 7. NATO Information Security Requirements.
Ref 10. j.: The GCA is responsible for providing the Visitor Group with the classification guidance necessary for the protection of the information. For Official Use Only (FOUO) information provided under this contract shall be safeguarded as specified in DoD 5400.7-R, DoD Freedom of Information Act Program, Chapter 4, dated Sep 1998. The Visitor Group is responsible for incorporating safeguards in the contract. See “FOR OFFICIAL USE ONLY (FOUO) ADDENDUM” attachment 5.
Ref. 10.k.: Privacy Act: Work on this project may require that personnel have access to Privacy Act Information. Personnel shall adhere to the Privacy Act, Title 5 of the US Code, Section 552a and applicable agency rules and regulations.
Ref 11.a.: Contract performance is restricted to those locations specified in Item 8a or other approved locations as directed by the COR. Using activity will provide security classification guidance for performance of this contract.
Ref 11.a.: If the classified information is provided at the Visitor Group’s facility, ensure compliance with the provisions of DoD 5220.22-R, “Industrial Security Regulation,” December 4, 1985.
Ref. 11.b.: Visitor Group will receive classified documents for reference only; however, if any classified information is generated in performance of this contract, it shall be derivatively classified and marked consistent with the source material.
Ref. 11.c.: The Visitor Group requires access to classified source data up to and including the classification levels identified in item 1a of this DD 254 in support of this work effort at their facility. The Visitor Group will be required to have safeguarding capability at its facility at the level identified in item 1b. Contractor personnel performing on this contract that require access to classified information/material, must have a final U.S. Government clearance at the appropriate level. Contractor personnel will contact
FA7014-15-R-5015
TASK ORDER NUMBER: TBD
PRECEDING CONTRACT NUMBER: TBD
SAF/AAZ for any and all reference material needed to comply with the security requirements.
Ref. 11.c.: Trained Derivative Classifiers will certify all classified documentation and attach an appropriate derivative classifier declaration to all finished documents in accordance with Executive Order 13526. Classifiers shall be trained and recertified every two years. Documentation generated as a result of this contract will be classified in accordance with source material provided by the user and will carry the most restrictive downgrading and/or declassification instructions, warning notices and control markings applicable. A listing of source material is to be included as a part of the document prepared by the Visitor Group. Any extracts or use of such data requires the Visitor Group to apply derivative classifications and markings consistent with the source documents. Use of “Multiple Sources” on the “Derived From” line necessitates compliance with the NISPOM, paragraph 4-208a, and the use of a bibliography.
Ref. 11.c.: The contractor is authorized the use of an Automated Information System (AIS) for processing classified information. The GCA or Prime contractor authorizes the contractor or subcontractor to receive and generate classified material in the performance of this contract. It is understood that AIS are a primary means for receiving and generating information; therefore, when 11.c. is marked “YES”, it justifies the contractor or subcontractor submitting a system security plan(s) for approval by DSS/ODAA to fulfill contractual obligations.
Ref. 11.d.: The Visitor Group is required to provide adequate storage for classified hardware to the level identified in item 1b of this DD 254.
Ref. 11.g.: The Visitor Group is authorized to obtain classified documents from DTIC.
The DD Form 1540, Registration For Scientific and Technical Information Services, will be accomplished by the Visitor Group. The sponsoring GCA must submit the DD Form 1540 “Registration for Scientific and Technical Information Services” to DTIC on behalf of the Visitor Group for processing. For subcontracting Visitor Groups, the prime Visitor Group submits the DD 1540 with the GCA certifying need-to-know to DTIC. The Visitor Group may also submit DD Form 2345 “Militarily Critical Technical Data Agreement” (after registration with DTIC) to the Defense Logistics Services Center for access to unclassified, militarily critical technical data from other DoD sources. The GCA must certify the need-to-know to DTIC. Information extracted from classified reference material shall be classified according to the markings on such material.
Item 15, Ref. 11.a.: Industrial security reviews for long term visitor groups will be conducted by the SSA while operating on an Air Force Installation. The Visitor Group
FA7014-15-R-5015
TASK ORDER NUMBER: TBD
PRECEDING CONTRACT NUMBER: TBD
will comply with the visitor group security agreement provided by the USAF Program/Project Manager at the performance location.
Item 17.f.: 11 WG/IP, 1330 AF Pentagon, Washington DC 20330 and other CSO locations as prescribed by the contracting officer consistent with USAF requirements.
Attachment 2 Automated Information Systems (AIS) Personnel Security Program Requirements Addendum
TASK ORDER NUMBER: TBD
PRECEDING CONTRACT NUMBER: TBD
1. The U.S. Government conducts trustworthiness investigations of personnel who require access to unclassified information and who perform AIS duties. Requirements for these investigations are outlined in DoD 5200.2-R, C3.6., Certain Positions Not Necessarily Requiring Access To Classified Information and Appendix 10, ADP Position Categories And Criteria For Designating Positions available at http://www.dtic.mil/whs/directives/corres/pdf/520002r.pdf. Falsification of information submitted for any government conducted investigation may result in contract default.
The contractor shall include all of these requirements in any subcontracts involving AIS support. Personnel performing work on AIS may be either a U.S. citizen or an Immigrant Alien (except as noted below).
2. An Immigrant Alien is defined as a foreign national lawfully admitted to the United States for permanent residence. These personnel shall be designated as filling one of the three AIS Categories listed below. The Contracting Officer’s Representative (COR) or Technical Representative (TR) shall determine if they or the contractor shall assign the AIS category to contractor personnel and inform the contractor of their determination. If it is decided the contractor shall make the assignment, the COR or TR must concur with the designation.
3. AIS Category I (High Risk) – may be filled by U.S. citizens only. Positions in which the incumbent is responsible for the planning, direction, and implementation of a computer security program; has a major responsibility for direction, planning, and design of a computer system, including the hardware and software; or can access a system during the operation or maintenance in such a way, and with relatively high risk for causing grave damage or realizing significant personal gain. Personnel whose duties meet the criteria for AIS Category I designation require a favorably adjudicated Single Scope Background Investigation (SSBI) or SSBI Periodic Reinvestigation (SSBI-PR), the updated standard for the BI listed in DoD 5200.2-R. The SSBI or SSBI-PR shall be updated every 5 years.
4. AIS Category II (Moderate Risk) – positions in which the incumbent is responsible for the direction, planning, design, operation or maintenance or a computer system, and whose work is technically reviewed by a higher authority at the AIS Category I level to insure the integrity or the system. Personnel whose duties meet the criteria for an AIS Category II designation require a favorably adjudicated National Agency Check with Local Agency and Credit Checks (NACLC), or National Agency Check with Written Inquiries (ANACI).
Attachment 2 Automated Information Systems (AIS) Personnel Security Program Requirements Addendum
TASK ORDER NUMBER: TBD
PRECEDING CONTRACT NUMBER: TBD
5. AIS Category III – all other positions. Personnel whose duties meet the criteria for an AIS Category III designation require a favorably adjudicated National Agency Check with Inquiries (NACI).
6. If an employee has a personnel security investigation at the appropriate level without a break in service for more than 24 months, with favorable adjudication, and in the case of AIS Category I is less than 5 years old, you do not need to submit an additional Electronic Personnel Security Questionnaire (EPSQ) for the trustworthiness determination. If required, the contractor will ensure personnel designated AIS category I, II, or III complete the EPSQ Standard Form (SF) 85 and provide it to their company’s designated reviewer for an initial suitability determination.
7. The reviewer will use the criteria outlined in the Adjudicative Desk Reference http://www.dhra.mil/perserec/adr/index.htm to make this initial determination. If, based on this initial review, the contractor gives the employee a negative trustworthiness determination the contractor will identify a replacement to the COR and the reviewer will submit their EPSQs to Defense Security Service (DSS). Investigative packages shall be submitted for all personnel in AIS Category I, II, or III prior to the employee being granted access to the AIS. Specific guidelines for obtaining software and submission of EPSQs are available at the DSS Web Site (www.dss.mil). If you are unfamiliar with the EPSQ SF85, you may contact your local DSS office for further information.
8. Investigation results shall be returned to the Security Manager for a trustworthiness determination to be made when a no determination is made by the USAF CAF. The Security Manager will notify the contractor of the decision. The contractor will promptly replace any individual where a negative trustworthiness determination is received.
9. The contractor will provide an AIS Category list that includes each person designated.
Attachment 3 RESTRICTED DATA INFORMATION ADDENDUM
Block 13, CONTINUATION: Ref Block 10, Item b., Restricted Data
PRIME CONTRACT SOLICITATION PURCHASE REQUEST NUMBER:
FA7014-15-R-5015
PRIME CONTRACT NUMBER: TBD
FOLLOW-ON CONTRACT NUMBER: TBD
Policy: DoD 5200.1-R, Information Security Program; DoD Directive 5210.2, Access To and Dissemination of Restricted Data; and Atomic Energy Act of 1954
1) Contractor is permitted access to Restricted Data (RD) in performance of this contract. CONFIDENTIAL security clearance eligibility is not valid for access to Restricted Data. Contractors must comply with all instructions and guidance provided by the servicing AF Activity security manager. Prior approval of the contracting activity is required for subcontracting.
2) Definitions:
a) Restricted Data (RD). Information which is classified and controlled under the Atomic Energy Act of 1954. It is all data (information) concerning design, manufacture, or utilization of atomic weapons; the production of special nuclear material; or the use of special nuclear material in production of energy. The term does not include data declassified or removed from the Restricted Data category pursuant to section 142 of the Atomic Energy Act of 1954, as amended (reference (b)). (Also see “Formerly Restricted Data.”)
b) Access. Within and between DoD Components, to include contractor activities, access to Restricted Data (RD) information will be governed by the same procedures and criteria required for access to other classified information:
i) Require access in performance of official duties.
ii) Have a final US Government security clearance at a level commensurate with the information concerned.
iii) Access requires in-brief by the servicing AF activity security manager, documentation of AF Form 2583, and indoctrination via the Joint Personnel Adjudication System
(JPAS).
iv) Requests for access to Restricted Data in the possession of the DOE or other Federal Agencies designated by the Department of Energy (DOE), other than the Department of Defense and NASA, are submitted via DOE Form 277, Request for Visit or Access Approval. (Refer to DoDD 5210.2 for further information.)
c) Dissemination. Restricted Data dissemination will be governed by the same procedures and criteria as govern the dissemination of other classified information.
PRIME CONTRACT SOLICITATION PURCHASE REQUEST NUMBER:
FA7014-15-R-5015
PRIME CONTRACT NUMBER: TBD
FOLLOW-ON CONTRACT NUMBER: TBD
DoD personnel may disseminate Restricted Data information only under the following guidelines:
i) Within and between the DoD Components, to include DoD contractors.
ii) To properly cleared Department of Energy (DOE) personnel and to DOE-cleared personnel of other Federal Agencies.
iii) Restricted Data information pertaining only to nuclear research reactors or nuclear electric power generating reactors may be made to Nuclear Regulatory Commission (NRC) personnel, i.e., DoD, State Department, NASA, etc. Restricted Data not related to these reactors may be released to NRC personnel only through the DOE.
iv) Restricted Data information other than that pertaining to aeronautical and space activities may be released to NASA personnel only through the DOE.
v) In all above cases, dissemination of Restricted Data information will be made only after the holder of the information has verified:
(a) Identification of the prospective recipient
(b) The validity of the prospective recipient’s security clearance (via JPAS)
(c) The “need-to-know” of the prospective recipient in connection with official duties
3) Dissemination of Restricted Data (and Formerly Restricted Data) to any nation or regional defense organization, or to a representative thereof, is prohibited; except in accordance with agreements for cooperation, entered into pursuant to section 123 of the Atomic Energy Act of 1954, as amended (reference (b)).
4) Except as provided above, Formerly Restricted Data will be treated and disseminated in the manner prescribed for classified information in DoD 5200.1-R.
5) Marking. Classified information marking will be in accordance with Air Force-adopted Controlled Access Program Coordination Office (CAPCO) standardized marking guidelines. Additional classified marking guidance (including country trigraph codes) is located on the SIPRNet CAPCO page at http://capco.dssc.sgov.gov .
PRIME CONTRACT SOLICITATION PURCHASE REQUEST NUMBER:
FA7014-15-R-5015
6) The below figure for provides an overall marking example for a document containing Secret information, Restricted Data information, and Formerly Restricted Data information:
7) Contact your servicing AF activity security manager for additional assistance.
Attachment 4 FORMERLY RESTRICTED DATA (FRD) INFORMATION
ADDENDUM
Block 13, CONTINUATION: Ref Block 10, Item d. Formerly Restricted Data
FA7014-15-R-5015
Policy: DOD 5200.1-R, Information Security Program; DODD 5210.2, Access To and Dissemination of Restricted Data; and Atomic Energy Act of 1954
1. This contractor requires access to Formerly Restricted Data in performance of this contract. Access to FORMERLY RESTRICTED DATA requires a final U.S.
Government Clearance at the appropriate level. Contractors must comply with all instructions and guidance provided by the servicing AF Activity security manager. Prior approval of the contracting activity is required for subcontracting
2. Definitions:
a. Formerly Restricted Data (FRD). Information which is controlled under the Atomic Energy Act of 1954. It is data removed from the Restricted Data category upon joint determination by the Department of Energy (DOE) and the Department of Defense (DOD) that such data relates primarily to the military utilization of atomic weapons and that such data can be adequately safeguarded as classified information. Such information is, however, treated the same as Restricted Data (RD) for purposes of foreign dissemination.
b. Access. Within and between DoD Components, to include contractor activities, access to Formerly Restricted Data (FRD) information will be governed by the same procedures and criteria required for access to other classified information:
i. Require access in performance of official duties.
ii. Have a final US Government security clearance at a level commensurate with the information concerned.
iii. Access requires in-brief by the servicing AF activity security manager, documentation of AF Form 2583, and indoctrination via the Joint Personnel Adjudication System
(JPAS).
iv. Requests for access to Restricted Data in the possession of the DOE or other Federal Agencies designated by the Department of Energy (DOE), other than the Department of Defense and NASA, are submitted via DOE Form 277, Request for Visit or Access Approval. (Refer to DoDD 5210.2 for further information.)
Attachment 5 FORMERLY RESTRICTED DATA (FRD) INFORMATION
FA7014-15-R-5015
3. Dissemination. Dissemination of Restricted Data and Formerly Restricted Data to any nation or regional defense organization, or to a representative thereof, is prohibited;
except in accordance with agreements for cooperation, entered into pursuant to section 123 of the Atomic Energy Act of 1954, as amended (reference (b)).
4. Except as provided above, Formerly Restricted Data will be treated and disseminated in the manner prescribed for classified information in DoD 5200.1-R (reference (f)).
5. Marking. Classified information marking will be in accordance with Air Force-adopted Controlled Access Program Coordination Office (CAPCO) standardized marking guidelines. Additional classified marking guidance (including country trigraph codes) is located on the SIPRNet CAPCO page at http://capco.dssc.sgov.gov .
6. The below figure for provides an overall marking example for a document containing Secret information, Restricted Data information, and Formerly Restricted Data information:
Proper portion marking examples are (S//FRD), (TS//RD), (S//RD/FRD), etc.
FA7014-15-R-5015
7. Contact your servicing AF activity security manager for additional assistance.
Attachment 5 FOR OFFICIAL USE ONLY (FOUO) ADDENDUM
Block 13, CONTINUATION: Ref Block 10, Item j., For Official Use Only Information
PRIME CONTRACT SOLICITATION PURCHASE REQUEST NUMBER:
FA7014-15-R-5015
PRIME CONTRACT NUMBER: TBD
FOLLOW-ON CONTRACT NUMBER: TBD
1. The following procedures will be used to protect FOR OFFICIAL USE ONLY (FOUO) material:
2. GENERAL:
a. The "For Official Use Only" (FOUO) marking is assigned to information at the time of its creation in a DoD User Agency. It is not authorized as a substitute for a security classification marking but is used on official government information that may be withheld from the public under exemptions 2 through 9 of the Freedom of Information Act (FOIA).
b. Other non-security markings, such as "Limited Official Use" and "Official Use Only" are used by non-DoD User Agencies for the same type of information and should be safeguarded and handled in accordance with instruction received from such agencies.
c. Use of the above markings does not mean that the information cannot be released to the public under FOIA, only that the Government must review the information prior to its release to determine whether a significant and legitimate government purpose is served by withholding the information or portions thereof.
3. HANDLING: Access to FOUO material shall be limited to those employees needing the material to do their jobs. The FOUO marking is assigned to material created by a DoD user agency. FOUO is not a classification, but requires extra precaution to ensure it is not released to the public.
4. MARKING:
a. An unclassified document containing FOUO information will be marked "For Official Use Only" at the bottom of the front cover (if any), on the first page, on each page containing FOUO information, on the back page, and on the outside of the back cover (if any).
b. Within a classified document, an individual page that contains both FOUO and classified information will be marked at the top and bottom with the highest security classification of information appearing on the page. If an individual portion contains FOUO information but no classified information, the portion will be marked, "FOUO."
c. Mark “FOUO” at the bottom of each page that has FOUO but not classified material.
FA7014-15-R-5015
d. If a classified document also contains FOUO material or if the classified material becomes FOUO when declassified, place the following statement on the bottom of the cover or the first page under the classification marking: “NOTE: If declassified, review the document to make sure material is not FOUO and not exempt under AFI 37-131 before public release.”
e. Mark other records such as computer print outs, photographs, films, tapes, or slides “FOR OFFICIAL USE ONLY”so the receiver or viewer knows the record contains FOUO material.
f. Mark each part of a message that contains FOUO material. Unclassified messages containing FOUO material must show the abbreviation “FOUO” before the text begins.
g. Ensure documents that transmit FOUO material call attention to any FOUO attachments.
h. FOUO material released to a contractor by a DoD user agency must have the following statement on the front page or cover: “THIS DOCUMENT CONTAINS
MATERIAL EXEMPT FROM MANDATORY DISCLOSURE UNDER THE FREEDOM
OF INFORMATION ACT. EXEMPTION(S) _________APPLY.”
i. Removal of the "For Official Use Only" marking can only be accomplished by the originator or other competent authority. When the "For Official Use Only" status is terminated, all known holders will be notified to the extent practical.
5. DISSEMINATION: Contractors may disseminate "For Official Use Only" information to their employees and subcontractors who have a need for the information in connection with a classified contract. Contractors must ensure employees and subcontractors are aware of the special handling instructions detailed below.
6. STORAGE: During normal duty hours/working hours, "For Official Use Only" information shall be placed in an out-of-sight location if the work area is accessible to persons who do not have a need for the information. During nonworking hours, the information shall be stored to preclude unauthorized access. Filing such material with other unclassified records in unlocked files or desks, is adequate when internal building security is provided during nonworking hours. When such internal security control is not exercised, locked buildings or rooms will provide adequate after- hours protection or the material can be stored in locked receptacles such as file cabinets, desks, or bookcases.
FA7014-15-R-5015
Expenditure of funds for security container(s) or closed areas solely for the protection of FOUO material is prohibited.
7. TRANSMISSION: "For Official Use Only" information may be sent via first-class mail or parcel post. Bulky shipments may be sent by fourth-class mail. DoD components, officials of DoD components, and authorized DoD contractors, consultants, and grantees send FOUO information to each other to conduct official DoD business. Tell recipients the status of such information, and send the material in a way that prevents unauthorized public disclosure. Make sure documents that transmit FOUO material call attention to any FOUO attachments. Normally, you may send FOUO records over facsimile equipment. To prevent unauthorized disclosure, consider attaching special cover sheets, the location of sending and receiving machines, and whether authorized personnel are around to receive FOUO information. FOUO information may be passed to officials in other departments and agencies of the executive and judicial branches to fulfill a government function. Mark the records "For Official Use Only" and tell the recipient the information is exempt from public disclosure under the FOIA and requires special handling.
8. RELEASE: FOUO material shall not be released outside the contractor’s facility except to representatives of the Department of Defense.
9. UNAUTHORIZED DISCLOSURE: Unauthorized disclosure of "For Official Use Only" information does not constitute a security violation but the releasing agency should be informed of any unauthorized disclosure. The unauthorized disclosure of FOUO information protected by the Privacy Act may result in criminal sanctions and disciplinary action may be taken against those responsible.
10. DESTRUCTION: When no longer needed, FOUO material shall be disposed of appropriately to prevent reconstruction in accordance with regulations, instructions, guidance etc.
| Big Sky Contract DD 254 (C).pdf |
| Big Sky Continuation Sheets |
File details come from the government source that posted it. Updated .