Attachment_E_-_Sample_DD254.pdf
PDF 267 KB Posted
- Attached to
- Software DevSecOps Services Blanket Purchase Agreement Federal contract opportunity
- Solicitation number
- fa8307-19-R-0133
View the file
Other files for this federal contract opportunity
Show all 28
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Please wait...
If this message is not eventually replaced by the proper contents of the document, your PDF viewer may not be able to display this type of document.
You can upgrade to the latest version of Adobe Reader for Windows®, Mac, or Linux® by visiting http://www.adobe.com/go/reader_download.
For more assistance with Adobe Reader visit http://www.adobe.com/go/acrreader.
Windows is either a registered trademark or a trademark of Microsoft Corporation in the United States and/or other countries. Mac is a trademark of Apple Inc., registered in the United States and other countries. Linux is the registered trademark of Linus Torvalds in the U.S. and other countries.
Supplement to Defense Department (DD) Form 254 “Contract Security Classification Specification”
ITEM 13 SECURITY GUIDANCE:
1. The following items apply to this contract #: FA8307-19-R-0006
GENERAL GUIDANCE:
The Contractor must:
• Maintain safeguarding for all classified material released to their custody and under their control. Individuals are responsible for safeguarding classified information entrusted to them.
• Reproduce classified material(s) to the minimum consistent with contractual and operational requirements. Each copy will be controlled in the same manner as the original.
• Destroy all classified information IAW DoD 5220-22M, National Industrial Security Program Operating Manual (NISPOM).
• Restrict access to only those individuals who possess the required security clearance and who are actually providing services under the contract.
• Not disclose classified information received or generated under a contract from one agency to any other Federal agency unless specifically authorized by the agency that has classification jurisdiction over the information.
• Not disclose classified information to foreign persons unless release of the information is authorized in writing by the Government Agency having classification jurisdiction over the information involved, e.g. the DOE for RD and FRD, the NSA for COMSEC, the DNI for SCI. The disclosure must also be consistent with applicable U.S. laws and regulations.
• Establish an information management system to protect and control the classified information in their possession. Contractors shall ensure that classified information in their custody is used or retained only for a lawful and authorized U.S.
Government purpose.
• (SCI only) For computer security direction, the contractor shall comply with Department of Defense Intelligence Information System (DoDIIS) – Joint Security Implementation Guide (DJSIG) for SCI Automated Information Systems.
DD Form 254 Supplement Attachment 1
• (Collateral AIS Government Furnished Equipment) For computer security direction, the contractor shall comply with AFMAN 17-1301, Computer Security, dated 10 February 2017. This guidance will be used in its entirety or waivers must be obtained in writing from AFLCMC/HNCOI.
• The Government Contracting Officer must review the DD Form 254 developed by the prime contractor for each subcontract to ensure that it correctly reflects the instructions furnished by the Government Program Manager and is specifically designed for the particular task(s) to be performed by the subcontractor.
• All security guidance contained in the DD Form 254, and attachments, must be flowed down by the Prime contractor to any sub-contractors on this effort.
• If work under the terms of this contract requires access to NSA systems, the contractor may be required to take a Counter Intelligence (CI) polygraph test.
• All contractor personnel will be indoctrinated into the appropriate SCI caveats.
ITEM 10:
Block 10a: COMSEC information includes accountable or non-accountable COMSEC information and controlled cryptographic items (CCI).
Ref item 10a: Access to COMSEC information is authorized to the prime contractor only.
Further release requires prior approval from the owner of the COMSEC information.
Block 10e (1). Contractor requires access to SCI materials; SCI security requirements apply.
(see AFLCMC/INHS, SCI addendum, for details).
Block 10e (2). Contractor will require access to intelligence information and must comply with directions provided by the Contracting Officer’s Representative (COR). The Program Manager has determined that disclosure does not create an unfair competitive advantage for the contractor or a conflict of interest with the contractor's obligation to protect the information. In accordance with para 8.9.2.2 of AFMAN 14-304, the COR will identify what intelligence information is required for the contractor to satisfy the contract and will submit that information to the Servicing Senior Intelligence Officer (SIO) for approval prior to granting access.
Block 10g. To facilitate potential access to NATO classified information, all DoD military, civilian, and contractor personnel who are briefed on their responsibilities for protecting U. S.
classified military information, shall also be briefed on the requirements for protecting NATO information. NATO briefing required prior to granting access. See NISPOM Chapter 10, Section 7, for details.
Ref item 10g: Access to SIPRNet and JWICS is authorized. (Identify system) users shall be briefed to NATO Secret IAW the NISPOM, Para 10-706, prior to access.
Block 10h. Foreign Government Information (FGI) is not releasable to contractor employees who have not received a final U.S Government security clearance at the appropriate level.
Block 10j/11k. See DoDM 5200.01, Volume 4, DoD Information Security Program: Controlled Unclassified Information (CUI), Enclosures 3 & 4 and DoDM 5400.07/Air Force Manual 33-302, DoD Freedom of Information Act (FOIA) Program, and AFI 16-1404, Air Force Information Security Program, for requirements.
Block 10k. Access to Secret Internet Protocol Router Network (SIPRNET) is authorized.
SIPRNET users shall receive the Air Force North Atlantic Treaty Organization (NATO) Security Awareness Briefing and sign an acknowledgement prior to SIPRNET access. A formal NATO briefing is required when 1) the SIPRNET enclave, or other classified networks, is approved for NATO and no additional security measures are in place to preclude access or 2) Access to NATO information is authorized. Formal NATO briefings shall be accomplished IAW the NISPOM, Para 10-706. Contractor requires Common Access Card (CAC)
ITEM 11:
Block 11c. Any classified information generated in the performance of this contract shall require the contractor to apply derivative classification and markings consistent with the source material.
Block 11d. The contractor is required to provide adequate and approved storage for classified hardware or material to the level of Top Secret which because of size or quantity cannot be safeguarded in an approved storage container.
Block 11j. On base contractor employees will comply with AFI 10-701, Operations Security, available on the Air Force's e-publishing web site at URL: http://www.e-publishing.af.mil/.
They will also participate in the assigned unit's OPSEC program, complete the Information Protection (ZZ133078) computer based training (CBT) module located on the Advanced Distributed Learning Service (ADLS) Website upon assignment and annually thereafter.
Block 11k. Go to https://www.ustranscom.mil/cmd/associated/dcd/ for Defense Courier Service points of contacts and guidance.
Block 11m: Couriers are authorized in the performance of this contract. Couriers shall be specifically designated as a courier and have authorized access to the SCI material they are transporting. They must be familiar with all rules and regulations governing couriers and transporting information, including hand-carrying aboard military, U.S. Government chartered, or commercial aircraft. Training and designation must be coordinated with the assigned Government Security Manager.
ITEM 12:
Contractor is to submit requests through the Contracting Officer for OPSEC Program Manager review and public release authorization. The Contracting Officer will provide contractor with written approval/disapproval. Information requiring AF or DoD–level review will be reviewed by the unit’s OPSEC Program Manager or Coordinator who will in-turn forward to the entry-level public affairs office through the AFIMSC Public Affairs Office to the Secretary of the Air
Force, Office of Public Affairs, Security and Review Division (SAF/PAX), 1690 Air Force Pentagon, Washington DC 20330-1690.
ITEM 14:
1. Provide the information requested by AFFARS 5352.204-9000, Notification of Government Security Activity Clause, and AFI 16-1406, Air Force Industrial Security Program, to the Information Protection Office (IPO). Refer to the contract document for these clauses.
Shipments of classified or sensitive equipment shall be handled, transported, transmitted and protected IAW NISPOM, DoD 5220.22M and as specified by unit directives. The contractor shall execute a VGSA with the government.
2. All Sensitive Compartmented Information (SCI) and material will be handled according to special security requirements furnished by the responsible Special Security Office (SSO) designated in item 13.
3. Upon completion of this contract, all Sensitive Compartmented Information (SCI) material provided to or generated by the contractor will be returned to the Air Force activity. If the material has been superseded or is no longer applicable, the Air Force activity will provide disposition instructions to the SSO.
4. The contractor will follow all applicable security guidance related to the protection of classified information. Baseline guidance includes the National Industrial Security Program Operating Manual (NISPOM), applicable Program Security Directives (PSDs) and Security Classification Guides (SCGs) and Standard Operating Procedures.
The following statements will be inserted if there are requirements for SCI.
CONTINUATION OF DD FORM 254
CONTRACTOR:
CONTRACT NUMBER: FA8307-19-R-0006
SENSITIVE COMPARTMENTED INFORMATION (SCI)
Item 13A. This contract requires additional security requirements established for Sensitive Compartmented Information (SCI) in accordance with (IAW) DoDM 5105.21-V1, V2, V3, and AFMAN 14-304. AFMAN 14-304 and DoDM 5105.21-V1, V2, V3 provides the necessary guidance for physical, personnel, and information security measures and is part of the security specifications for this contract.
Item 13B. This contract will be administered under the following documents, with subsequent versions or changes.
(1) AFMAN 14-304
(2) DoDM 5105.21-V1, V2, V3
(3) Intelligence Community Directive (ICD) 705 standards
(4) Applicable Security Classification Guide, as dated.
Item 13C. Inquiries pertaining to classification guidance on SCI will be directed to the responsible Contracting Officer’s Representative (COR), indicated in the applicable Project Work Statements (PWS).
Any SCI or SCI-derived material generated under this contract will be reviewed by the contract monitor for proper classification prior to final publication and distribution. The responsible Special Security Office as designated in Item 14H will provide assistance as required.
Item 14A. SCI data furnished to or generated by the contractor will require special security handling and controls beyond those in the National Industrial Security Program Operating Manual (NISPOM). These supplemental instructions will be furnished and/or made available to the contractor through the Sponsoring COR by the User Agency Special Security Office (AFLCMC/INHS). CORs and Contractor Special Security Officers (CSSOs) will comply with all requirements outlined in AFMAN 14-304 and DoDM 5105.21-V1, V2, V3. The CSSO will complete an annual self-inspection of all SCI related contract activity using the self-inspection checklist located in the DoDM 5105.21-V2. The self-inspection should take place in April of each year and a report of the self-inspection and all discrepancies noted will be forwarded to AFLCMC/INHS before the end of that month.
Item 14B. Contractor SCI billets are required to perform on this contract.
The contract Period of Performance and the expiration date are required / stated in item 13, in accordance with the contract identified in block 2 of the DD Form 254.
Item 14C. Names of contractor personnel requiring access to SCI will be submitted to the responsible COR for proper approval. Upon written approval by the contract monitor, forms requesting Single Scope Background Investigation (SSBI) will be prepared in accordance with the NISPOM and submitted to DSS.
Item 14D. The contractor will establish and maintain an access list of those employees working on this contract. A copy of this list will be furnished to the contract monitor and User Agency Special Security Office (AFLCMC/INHS).
Item 14E. The contractor will advise the User Agency Special Security Office (AFLCMC/INHS), through the SCI COR, immediately upon reassignment of personnel to other duties associated with this contract.
Item 14F. Release of Information: SCI shall not be released to contractor employees without specific release approval of the COR or the originator of the material when applicable. SCI with restrictive caveats (ORCON, PROPIN, etc.) will be released to contractors only when originator approval has been obtained.
This approval shall be coordinated through the appropriate SSO based on approval and certification of “need-to-know” by the COR. SCI documentation, or other material concerning this contract will not be discussed with or released to any individual , subcontractor, agency (including Federal government agencies and employees), and contractor employees not working on the contract without prior approval from the
COR.
Item 14G. Any SCI data released to or generated by the contractor in support of the contract remains the property of the DoD Department, agency, or command that released it. The contractor will maintain a record of all SCI released to their custody under this contract and upon completion/cancellation of the contract, must return all such materials to the supporting SSO identified in 14H or User Agency Special Security Office AFLCMC/INHS. This applies to all data and materials, including working papers and notes. The contractor will not reproduce any SCI related to this contract without the written permission of the COR. When such permission has been granted, the contractor will control and account for such reproductions in the same manner as pertains to originals. Reproduction of hard copy SCI documents in entirety is not permitted.
Item 14H. SCIF IDENTIFICATION AND SUPPORTING SSO IDENTIFICATION:
14H.a. IF A SCIF EXISTS: An accredited SCIF has been established by the contractor. The SCIF has been built IAW Intelligence Community Directive (ICD) 705 standards and an SCI accreditation message is on file within the SCIF. If the SCIF is accredited through other than HQ AFMC, a Co- Utilization Agreement (CUA) will be generated by COR. SCI material associated with this contract shall be separately stored and maintained only in such properly accredited facilities and in approved safes at the contract location. The supporting SSO for each facility is determined by the Government sponsor(s) of the contracted activity and not necessarily by the location of the facility. Once the supporting SSO is determined by the contractor or government sponsor they must coordinate with the User Agency Special Security Office (AFLCMC/INHS) for SCI requirements.
14H.b. IF A SCIF IS TO BE BUILT: A SCIF shall be built/accredited and maintained by the contractor IAW ICD 705 specifications and will not be operated as a SCIF until a SCI accreditation message from SSO DIA is on file within the facility. The contractor will nominate a CSSO and the supporting/responsible SSO will be determined based on the COR submittal of the mission requirements and outlined in the PWS(s). The responsible SSO determination will be coordinated with and approved by the User Agency Special Security Office (AFLCMC/INHS).
Item 14I. This contract does require the use of Defense Courier Service (DCS); the supporting SSO will validate all DCS Form 10.
Item 14J. A COMSEC account is not required.
If a COMSEC account is required, the National Security Agency/Central Security Service (NSA/CSS) Policy Manual No. 3-16 for the handling of COMSEC material, is applicable. Access to COMSEC information is restricted to US citizens holding final US Government security clearances and is not releasable to personnel granted reciprocal clearances. COMSEC information is not releasable to contractor employees who have been granted a reciprocal clearance.
Item 14K. This contract does require electronic processing of SCI.
If electronic processing of SCI is required, then the security provisions of ICD 503, DIAM 50-4 and AF MAN 14-304 and DoDM 5105.21-V1 apply and are part of this contract. No electronic processing will take place in the SCIF until Communications/EMSEC and Automated Information System (AIS) accreditation messages are on file within the facility. The equipment and AIS equipment the contractor is using are currently accredited for SCI operations.
Item 14L. The CSSO must coordinate with the SCI COR prior to subcontracting any portion of SCI efforts involved in this contract. A separate DD Form 254 for the subcontractor shall be processed and approved, and separate subcontractor billets shall be obtained before any work can be performed. Subcontractors cannot use the prime contractor’s SCI billets.
Item 14M. The contractor will not use references to SCI accesses, even by unclassified acronyms, in advertising, promotional efforts, or recruitment of employees.
Item 14N. The following activity is designated as the User Agency Special Security Office for SCI requirements in accordance with AFMAN 14-304 and DoDM 5105.21-V3.
AFLCMC/INHS
102 Barksdale Street Hanscom AFB, MA 01731-1801
Phone:
DSN 845-5990/5991/3807 Commercial: (781) 225-5990/5991/3807
Item 14O. The Point of Contact (POC) User Agency Special Security Office (SSO) for COR/CSSO coordination is identified in block 13 of the DD Form 254.
Item 14P. The signatory responsibility for Contract Monitor on this SCI continuation will be accepted and signed for on each sub-contract/project related to this parent DD Form 254. Those authorized signatories will be those specific program/project Program Manager (PM), AF Contracting Officer (CO) or Contracting’s Officer’s Representative (COR).
Item 15A. The Assistant Chief of Staff for Intelligence, Surveillance and Reconnaissance, Headquarters United States Air Force (HQ USAF/A2) has exclusive responsibility for all SCI classified material released or developed under this contract and held within the contractor’s SCIF. DIA is responsible for security inspection of all SCI and non-SCI classified material released to or developed under this contract and held within the contractor’s SCIF.
ATTACHMENT TO DD FORM 254 FOR CONTRACT NO: FA8307-19-R-0006
CONTRACT EXPIRATION DATE: 30 Sep 2021
DD Form 254, Reference Blocks 10a and 15 (COMSEC)
ATTACHMENT ___#2___
COMMUNICATIONS SECURITY (COMSEC)
Block 10a – A contractor who requires access to COMSEC material or information must submit a request to the appropriate Air Force or National Security Agency Central Office of Record through the contracting or program office. If applicable, mark box 10a “YES.” COMSEC information includes all material or information accountable thru the COMSEC Material Control System (CMCS) or not accountable thru CMCS, including all controlled cryptographic items (CCI).
If accountable COMSEC information or material is needed by the contractor ONLY in support of this contract and the work location is within CONUS, the contractor may seek to establish a COMSEC user account supported by the Host COMSEC office if desired. If a user account is established, advanced credentialing of COMSEC office personnel is required to facilitate official visits, inspections (including no-notice inspection) and other support as may be needed. The Host COMSEC office inspectors have sole inspection authority of all COMSEC user accounts and materials provided by the Host COMSEC account.
Block 15 – The Host COMSEC office inspectors have sole inspection authority of all COMSEC user accounts and materials provided by the Host COMSEC account.
General Guidance
Access to classified COMSEC information shall be restricted to U.S. citizens who have been granted a final security clearance by the U.S.
Government, have a valid need-to-know (as defined in the National Industrial Security Program Operating Manual), and have successfully completed a non-lifestyle, counterintelligence scope polygraph examination, when required by the U.S. Government or appropriate security office, administered in accordance with DoD or agency requirements and applicable law. Non-U.S. citizens, including immigrant aliens, are not eligible for access to classified COMSEC information. For access to some types of COMSEC information a Cryptographic Access briefing or COMSEC briefing may be required. (NSA Contractor accounts refer to NSA/CSS PM 3-16 Para 7 and 8 for briefings required under specific types of access.) Access to unclassified controlled cryptographic items (CCI) will be limited to U.S. Citizens who have a need for such access.
If a National Security Agency (NSA) Contractor COMSEC Account is established or already exists, NSA/CSS Policy Manual 3-16 and appropriate follow-on documents shall apply. If contractor personnel will have access to COMSEC information via an Air Force COMSEC user account, U.S.A.F. COMSEC regulations (i.e. AFMAN 17-1302-O), command COMSEC supplements (and appropriate follow-on documents) and guidance provided by the supporting AF COMSEC office regarding operation of Air Force COMSEC user accounts shall apply.
All individuals with access to COMSEC information via an AF COMSEC user account who:
• Have access to cryptographic media classified SECRET or above;
• Operate Key Generating equipment (e.g.: KG-83, KoK-22, Etc);
• Prepare, authenticate, or decode nuclear control orders (actual or exercise);
• Are responsible for keying cryptographic equipment to SECRET or above; or
• Are responsible for crypto engineering or designated installation technicians;
MUST be enrolled in the AF Cryptographic Access Program PRIOR to having such access.
Audit and inspection of NSA contractor COMSEC accounts shall be in accordance with NSA/CSS PM 3-16 Section XVII. Audit and Inspection of AF COMSEC user accounts shall be in accordance with AFMAN 17-1302-O. COMSEC and non-COMSEC inspections of AF user accounts will not be conducted concurrently.
DD Form 254 Reference Block 10e(1) – SCI
Attachment 3
USE OF SPECIAL INTELLIGENCE MARKINGS
1. Authorized Control Markings of Intelligence Information
a. "Dissemination and Extraction of Information Controlled by Originator (ORCON)".
This marking is used only on classified intelligence that clearly identifies or would reasonably permit ready identification of intelligence sources or methods that are particularly susceptible to countermeasures that would nullify or measurably reduce their effectiveness. It is used to enable the originator to maintain continuing knowledge and supervision of the further use of intelligence beyond the original dissemination. This control marking may not be used when an item of information will reasonably be protected by use of any other markings specified herein, or by the application of the "need-to-know" principle and safeguarding procedures of the security classification system.
b. "Not Releasable to Foreign Nationals (NOFORN)"
This control marking is used to identify classified intelligence material that may not be released in any form to foreign governments, foreign nationals, or non-US citizens without permission of the US Government originator, and then only when released in compliance with the National Disclosure Policy.
c. "Authorized for Release to (Name of country(s)/international organization"
This marking is used to identify classified intelligence material that the US Government Originator has predetermined to be releasable or has been released through established foreign disclosure channels to the indicated country(s) or organization.
2. Procedures Governing Use of Control Markings
a. Any recipient desiring to use intelligence in a manner contrary to the restrictions established by the control markings set forth above, shall obtain the advanced permission of the originating agency. Such permission applies only to the specific purposes agreed to by the originator and does not automatically apply to all recipients. Originator will ensure that prompt consideration is given to recipients' requests, with particular attention to reviewing and editing if necessary, sanitized or paraphrased versions to derive a text suitable for release subject to lesser or no control markings.
b. The control markings authorized above shall be shown on the title page, front cover, and other applicable pages of documents, incorporated in the text of electrical communications, shown on graphics, and associated (in full or abbreviated form) with data stored or processed in automatic data processing systems. The control markings also shall be indicated by parenthetical use of the markings abbreviations at the beginning or end of the appropriate portions. If the control markings apply to several or all portions, the document may be marked with a statement to this effect rather than marking each portion individually.
c. The control markings in paragraph one (1) shall be individually assigned at the time of preparation of intelligence products and used in conjunction with security classifications and other markings specified by EO 13526 and its implementing ISOO Directive. The markings shall be carried forward to any new format in which the same information is incorporated including oral and visual presentations.
DD Form 254 Reference Block 10e(2) – Non-SCI
Attachment 4
GENERAL INTELLIGENCE MATERIAL/FOREIGN DISCLOSURE
1. Special Requirements for General and Foreign Intelligence Material. In addition to the requirements and controls for classified material, the Director, Central Intelligence, sets up additional requirements and controls for intelligence in the possession of contractors. The originator of intelligence is responsible for determining the appropriate level of protection prescribed by classification and dissemination policy. The contractor must:
a. Maintain control of all intelligence materials released in his or her custody in accordance with DoD 5220.22-M, the National Industrial Security Program Operating Manual (NISPOM), dated 28 February 2006, incorporating Change 2, dated 18 May 2016, paragraphs 5-200, 201 and 202 for control. Contractor agrees that all intelligence material released, all reproductions and other material generated (including reproductions) are the property of the US Government.
b. Maintain control of all reproduced intelligence data in the same manner as the original.
c. Destroy intelligence materials in accordance with approved methods identified in the NISPOM.
d. Restrict access to those cleared individuals with a valid need-to-know on the prime contract.
Further dissemination to other contractors, subcontractors, or other government agencies and private individuals or organization is prohibited unless a valid need-to-know is authorized in writing by the Contracting Officer’s Representative (COR).
e. Not release intelligence data to foreign nationals or immigrant aliens, regardless of their security clearance or contract status, without advance written permission from the COR and the Foreign Disclosure Policy Office.
f. Ensure that each employee having access to intelligence material is fully aware of the special security requirements for this material.
2. Returning Intelligence to the Air Force. Contractors must return intelligence data to the COR at the termination or completion of a contract unless the COR has provided written approval for the contractor to retain for an additional two years. If retention is required beyond the two year period, the contractor must again request and receive written retention authority from the COR. If the COR grants retention authority, the COR must provide a copy of the written approval. This written documentation must be maintained in accordance with the NISPOM.
3. Release of Classified and Unclassified Intelligence Information to Foreign Government and Their Representatives. Any military activity or defense contractor receiving a request from a foreign government or a representative thereof, for intelligence data about this program, shall forward the request to the COR for coordination with the cognizant foreign disclosure office. Information released under Foreign Military Sales (FMS) must comply with the specific USAF disclosure guidance issued for the specific FMS customer.
CONTINUATION OF DD FORM 254 CONTRACTOR:
DD Form 254 Reference Block 10j – CUI Attachment 5
FOR OFFICIAL USE ONLY INFORMATION
1. FOR OFFICIAL USE ONLY INFORMATION:
a. FOUO is a dissemination control applied by DoD to unclassified information when disclosure to the public would reasonable be expected to cause harm to an interest protected by one or more of the Freedom of Information Act (FOIA) Exemptions 2 through 9.
b. Use of the above markings does not mean that the information cannot be released to the public, only that it must be reviewed by the Government prior to its release to determine whether a significant and legitimate government purpose is served by withholding the information or portions of it.
2. IDENTIFICATION MARKINGS:
a. Each document determined to contain FOUO information shall identify the originating agency or office. This information shall be clear and complete enough to allow someone receiving the document to contact the office if questions or problems about the designation or marking arise.
b. Documents shall be marked “For Official Use Only” at the bottom of the outside cover (if any), the title page, the first page and the outside of the back cover (if any).
c. Internal pages of the document that contain FOUO information shall be marked “For Official Use Only” at the bottom.
d. Subjects, titles, and each section, part, paragraph or similar portion of an FOUO document shall be marked to show that they contain information requiring protection.
e. Electronically transmitted messages, including e-mail, containing FOUO information shall be marked to show they contain information requiring protection.
f. When FOUO information is contained in media or material (including hardware and equipment) the requirement remains to identify the information that requires protection.
3. DISSEMINATION: Contractors may disseminate FOUO information to their employees and subcontractors who have a need for the information in connection with a classified contract.
4. STORAGE: During working hours, reasonable steps shall be taken to minimize the risk of access by unauthorized personnel. During non-working hours, FOUO information may be stored to preclude unauthorized access. Filing such material with other unclassified records in unlocked files or desks, is adequate when internal building security is provided during non-working hours. When such internal security control is not exercised, locked buildings or rooms will provide adequate after-hours protection or the material; can be stored in locked receptacles such as file cabinets, desks, or bookcases.
5. TRANSMISSION: FOUO information and material may be transmitted via first-class mail, parcel post or, for bulky shipments, via forth class mail. Electronic transmission of FOUO information shall be by approved secure communications systems or systems utilizing other protective measures such as Public Key Infrastructure (PKI). Transmission of FOUO by facsimile equipment is permitted, use cover sheets and consider the location of the sending and receiving machines to ensure authorized personnel are available to receive FOUO information. Discussion of FOUO material on the telephone is authorized if necessary for the performance of the contract.
6. DISPOSITION & DISCLOSURE: FOUO information may be destroyed by any means approved for the destruction of classified information or by any other means that would make it difficult to recognize or reconstruct. Unauthorized disclosure of FOUO information does not constitute a security violation but the releasing agency should be informed of any unauthorized disclosure. The unauthorized disclosure of FOUO information protected by the Privacy Act may result in criminal sanctions.
Attachment 6
FARS/DFARS/AFFARS
Cybersecurity and Program Security Resources As of: 13 April 2017
FARS PART 52 - Solicitation Provisions and Contract Clauses 52.204-02, Security Requirements (Aug 1996)
52.204-21, Basic Safeguarding of Contractor Information Systems (Jun 2016)
DFARS PART 252 - Solicitation Provisions and Contract Clauses 252.204.7000, Disclosure of Information (Oct 2016)
252.204-7005, Oral Attestation of Security Responsibilities (Nov 2001)
252.204-7008, Compliance with Safeguarding Covered Defense Information Controls (Oct 2016)
252.204-7009, Limitations on the Use or Disclosure of Third-Party Contractor Reported Cyber Incident Information (Oct 2016)
252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting (Oct 2016)
252.239.7000, Protection against Compromising Emanations (Jun 2004)
252.239.7001, Information Assurance Contractor Training and Certification (Jan 2008)
252.239.7008, Reuse Arrangements (Dec 1991)
252.239.7009, Representation of Use of Cloud Computing (Sep 2015)
252.239.7010, Cloud Computing Services (Oct 2016)
252.239.7016, Telecommunications Security Equipment, Devices, Techniques, and Services (Dec 1991)
AFFARS PART 5342 - Solicitation Provisions and Contract Clauses 5342.490, Contractor visits or performance on Air Force Installation (Jan 2017)
5342.490-1, 5342.490-2, AFFARS PART 5352 - Solicitation Provisions and Contract Clauses 5352.204-9000, Notification of Government Security Activity and Visitor Group Security Agreements (Jan 2017)
5352.215-9000, Facility Clearance (May 1996)
5352.242-9000, Contractor Access to Air Force Installations (Nov 2012)
5352.242-9001, Common Access Cards (CAC) for Contractor Personnel (Nov 2012)
ADP788C.tmp
SENSITIVE COMPARTMENTED INFORMATION (SCI)
ADPDE7B.tmp
DD Form 254 Reference Block 11l – Other.
SUBPART 5352.2—TEXTS OF PROVISIONS AND CLAUSE
5352.204-9000 Notification of Government Security Activity and Visitor Group Security Agreements.
DRAFT
SAMPLE
PREVIOUS EDITION IS OBSOLETE.
Page of AEM LiveCycle Designer
DD FORM 254, APR 2018
NEEDS DD67
DEPARTMENT OF DEFENSE
CONTRACT SECURITY CLASSIFICATION SPECIFICATION
(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)
OMB No. 0704-0567 OMB approval expires:
October 31, 2020 The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.
RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.
1. CLEARANCE AND SAFEGUARDING
2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)
3. THIS SPECIFICATION IS: (X and complete as applicable.)
a. ORIGINAL (Complete date in all cases.)
b. REVISED (Supersedes all previous specifications.)
4. IS THIS A FOLLOW-ON CONTRACT?
If yes, complete the following:
Classified material received or generated under
5. IS THIS A FINAL DD FORM 254?
If yes, complete the following:
6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)
7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor)
8. ACTUAL PERFORMANCE (Click button to add more locations.)
10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)
e. NATIONAL INTELLIGENCE INFORMATION:
11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)
12. PUBLIC RELEASE
Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)
13. SECURITY GUIDANCE
The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.
(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)
14. ADDITIONAL SECURITY REQUIREMENTS
Requirements, in addition to NISPOM requirements for classified information, are established for this contract.
If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)
15. INSPECTIONS
Elements of this contract are outside the inspection responsibility of the CSO.
If Yes, explain and identify specific areas and government activity responsible for inspections. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)
16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)
17. CERTIFICATION AND SIGNATURES
Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below. Upon digitally signing Item 17h, no changes can be made as the form will be locked.
18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL
9.0.0.2.20120627.2.874785 DD 254, DoD Contract Security Classification Specification List of Attachments [1] (All Files Must be Attached Prior to Signing, i.e., for any digital signature on the form) CES Atchs.pdf
| CurrentPage: |
| PageCount: |
| Classification: Unclassified |
| SerialNum: |
| a. Facility clearance level. Select one.: 0 |
| b. Level of safeguarding for classified information/material required at contractor facility. Select one.: 0 |
| Choose Yes or No: 0 |
| Choose Yes or No: 0 |
| Prime: |
| Choose Yes or No: 0 |
| Choose Yes or No: 0 |
| Sub: |
| Choose Yes or No: 0 |
| Choose Yes or No: 0 |
| Soli: |
| DueDate: |
| dateA: |
| RevisionNum: |
| dateB: |
| Final: |
| dateC: |
| No: 0 |
| No: 0 |
| No: 0 |
| No: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 1 |
| Yes: 1 |
| Enter your name here.: |
| ReqDated: |
| Enter your name here.: |
| Name: TBD |
| Name: TBD |
| Cage: N/A |
| CSO: TBD |
| CSO: TBD |
| CSO: N/A |
| addrow: |
| Removerow: |
| Click to delete a row: |
| Location: AFLCMC/HNC (SCI) |
230 Hall Blvd JBSA Lackland AFB, TX 78243
(OTHER LOCATIONS TO FOLLOW)
| Location: |
| Location: |
| Location: |
| Location: |
| Location: |
| Block9: The purpose of this Blanket Purchase Agreement is to enable automated tools, services, and standards for programs to develop, secure, deploy, and operate applications in a secure, flexible and interoperable fashion. Leveraging industry acquisition best practices leveraging a centralized vehicle for DevSecOps tools and services will enable rapid prototyping, real-time deployments and scalability and affords acquisition offices the ability to, shorten contract time-lines, and access innovative commercial practices. |
| a: 1 |
| a: 0 |
| a: 1 |
| f: 0 |
| f: 0 |
| f: 1 |
| b: 0 |
| b: 1 |
| b: 0 |
| g: 1 |
| g: 0 |
| c: 0 |
| c: 1 |
| c: 1 |
| h: 1 |
| h: 0 |
| d: 0 |
| d: 0 |
| d: 0 |
| i: 0 |
| i: 0 |
| SCI: 1 |
| NonSCI: 1 |
| j: 1 |
| j: 1 |
| k: 1 |
| k: 1 |
| Enter your name here.: TBD |
| Enter your name here.: Courier Authorization Approved |
| Enter your name here.: TBD |
| e: 0 |
| e: 0 |
| l: 1 |
| m: 1 |
| direct: 0 |
| thru: 1 |
| Enter your name here.: SEE ATTACHMENT |
| PublicAuthority: PUBLIC RELEASE OF SENSITIVE COMPARTMENTED INFORMATION (SCI) IS NOT AUTHORIZED. |
| AddSig: |
| RemoveSig: |
| text: The National Industrial Security Program Operating Manual (NISPOM), February 2006, Incorporation Change 2 May 18, 2016 applies. |
Contractor will comply with Risk Management Framework.
| attachmentsList: |
| AddAttachment: |
| ViewAttachment: |
| RemoveAttachment: |
| rep: |
| Sig: |
| Enter your name here.: TBD |
| GCAName: TBD |
| AAC: |
| Address: TBD |
| POCName: |
| Phone: |
| Email: |
| Title: Contracting Officer |
| Enter the date using the format DD-Mon-YYYY: |
File details come from the government source that posted it.