Attachment_3_-_DIB_Development_5th_Edition_-Labor_Category_Descriptions-Final.pdf

PDF 726 KB Posted

Attached to
DIB Development 5th Edition FINAL RFP FA873017R0024 Federal contract opportunity
Solicitation number
FA873017R0024
Issued by
Department of the Air Force Materiel Command Lifecycle Management Center Hanscom Air Force Base

About this file

Attachment 3- DIB Development 5th Edition Labor Category Descriptions- Final

View the file

Other files for this federal contract opportunity

Show all 16

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DEPARTMENT OF DEFENSE 1. CLEARANCE AND SAFEGUARDING

CONTRACT SECURITY CLASSIFICATION SPECIFICATION a. FACILITY CLEARANCE REQUIRED

(The requirements of the DoD Industrial Security Manual apply to all aspects of this effort)

b. LEVEL OF SAFEGUARDING REQUIRED

2. THIS SPECIFICATION IS FOR: (X and complete as applicable) 3. THIS SPECIFICATION IS: (X and complete as applicable)

a. PRIME CONTRACT NUMBER

a. ORIGINAL (Complete date in all cases) Date (YYYYMMDD)

b. SUBCONTRACT NUMBER

b. REVISED (Supersedes all previous specs)

Revision No.

Date (YYYYMMDD)

c. SOLICITATION OR OTHER NUMBER Due Date (YYYYMMDD)

c. FINAL (Complete Item 5 in all cases)

Date (YYYYMMDD)

4. IS THIS A FOLLOW-ON CONTRACT? YES NO. If Yes complete the following

Classified material received or generated under ____________________________ (Preceding Contract Number) is transferred to this follow-on contract.

5. IS THIS A FINAL DD FORM 254? YES NO. If Yes complete the following

In response to the contractor's request dated _______________, retention of the identified classified material is authorized for the period of ______________.

6. CONTRACTOR (Include Commercial and Government Entity ( CAGE) Code)

a. NAME, ADDRESS, AND ZIP CODE b. CAGE CODE c. COGNIZANT SECURITY OFFICE (Name, Address, and Zip Code)

7. SUBCONTRACTOR

a. NAME, ADDRESS, AND ZIP CODE b. CAGE CODE c. COGNIZANT SECURITY OFFICES ( Name, Address, and Zip Code)

8. ACTUAL PERFORMANCE

a. LOCATION b. CAGE CODE c. COGNIZANT SECURITY OFFICE (Name, Address, and Zip Code)

9. GENERAL IDENTIFICATION OF THIS PROCUREMENT

10. CONTRACTOR WILL REQUIRE ACCESS TO: YES NO 11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: YES NO

a. COMMUNICATIONS SECURITY (COMSEC)

INFORMATION

a. HAVE ACCESS TO CLASSIFIED INFORMATION ONLY AT ANOTHER

CONTRACTOR’S FACILITY OR A GOVERNMENT ACTIVITY

b. RESTRICTED DATA b. RECEIVE CLASSIFIED DOCUMENTS ONLY

c. CRITICAL NUCLEAR WEAPON DESIGN INFORMATION c. RECEIVE AND GENERATE CLASSIFIED MATERIAL

d. FORMERLY RESTRICTED DATA: d. FABRICATE, MODIFY, OR STORE CLASSIFIED HARDWARE

e. INTELLIGENCE INFORMATION: e. PERFORM SERVICES ONLY

(1) Sensitive Compartmented Information (SCI) f. HAVE ACCESS TO U.S. CLASSIFIED INFORMATION OUTSIDE THE U.S., PUERTO

RICO, U.S. POSSESSIONS AND TRUST TERRITORIES

(2) Non-SCI g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE TECHNICAL

INFORMATION CENTER (DTIC) OR OTHER SECONDARY DISTRIBUTION CENTER

f. SPECIAL ACCESS INFORMATION h. REQUIRE A COMSEC ACCOUNT

g. NATO INFORMATION NATO SECRET i. HAVE A TEMPEST REQUIREMENT

h. FOREIGN GOVERNMENT INFORMATION j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS

i. LIMITED DISSEMINATION INFORMATION k. BE AUTHORIZED TO USE THE DEFENSE COURIER SERVICE

j. FOR OFFICIAL USE ONLY INFORMATION l. OTHER (Specify).

k. OTHER Specify)

DD FORM 254, DEC 1999 PREVIOUS EDITION IS OBSOLETE

12. PUBLIC RELEASE. Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the industrial Security Manager or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public release shall be submitted for approval prior to release

Direct Through (Specify):

to the Directorate for Freedom of Information and Security Review, Office of the Assistant Secretary of Defense (Public Affairs)* for review.

In the case of non-DoD User Agencies, requests for disclosure shall be submitted to that agency.

13. SECURITY GUIDANCE. The security classification guidance needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes: to challenge the guidance or classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended. (Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any document/guides/extracts referenced herein. Add additional pages as needed to provide complete guidance.

14. ADDITIONAL SECURITY REQUIREMENTS. Requirements, in addition to ISM requirements, are established for this contract. (If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the cognizant security office. Use Item 13 if additional space is needed.)

Yes No

15. INSPECTIONS. Elements of this contract are outside the inspection responsibility of the cognizant security office. (If Yes, explain and identify specific areas or elements carved out and the activity responsible for inspections. Use Item 13 if additional space is needed.

Yes No

16. CERTIFICATION AND SIGNATURE. Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below.

a. TYPED NAME OF CERTIFYING OFFICIAL b. TITLE c. TELEPHONE (Include Area Code)

d. ADDRESS (Include ZIP Code) 17. REQUIRED DISTRIBUTION

a. CONTRACTOR

b. SUBCONTRACTOR

c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR

e. SIGNATURE

d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION

e. ADMINISTRATIVE CONTRACTING OFFICER

f. OTHERS AS NECESSARY

DD FORM 254 (BACK), DEC 1999

SullivanCa Highlight

DD Form 254 Reference Block 10e(2) – Non-SCI

ATTACHMENT 2

GENERAL INTELLIGENCE MATERIAL/FOREIGN DISCLOSURE

1. Special Requirements for General and Foreign Intelligence Material. In addition to the requirements and controls for classified material, the Director, Central Intelligence, sets up additional requirements and controls for intelligence in the possession of contractors. The contractor must:

a. Maintain control of all intelligence materials released in his or her custody in accordance with DoD 5220.22- M, the National Industrial Security Program Operating Manual (NISPOM), February 2006, paragraphs 5-200, 201 and 202 for control. Contractor agrees that all intelligence material released, all reproductions and other material generated (including reproductions) are the property of the US Government.

b. Maintain control of all reproduced intelligence data in the same manner as the original.

c. Destroy intelligence materials in accordance with approved methods identified in the NISPOM.

d. Restrict access to those individuals with a valid need-to-know who are actually providing services under the contract. Further dissemination to other contractors, subcontractors, or other government agencies and private individuals or organization is prohibited unless authorized in writing by the Contracting Officer’s Representative (COR) with prior approval of the Unit IN/SIO.

e. Not release intelligence data to foreign nationals or immigrant aliens, regardless of their security clearance or contract status, without advance written permission from the COR, Foreign Disclosure Policy Office and Unit IN/

SIO.

f. Ensure that each employee having access to intelligence material is fully aware of the special security requirements for this material.

2. Returning Intelligence to the Air Force. Contractors must return intelligence data to the COR at the termination or completion of a contract unless the COR has provided written approval for the contractor to retain for an additional two years. If retention is required beyond the two year period, the contractor must again request and receive written retention authority from the COR. If the COR grants retention authority, the COR must provide a copy of the written approval to the Unit IN/SIO.

3. Release of Classified and Unclassified Intelligence Information to Foreign Government and Their Representatives. Any military activity or defense contractor receiving a request from a foreign government or a representative thereof, for intelligence data about this program, shall forward the request to the Unit IN/SIO for coordination with the cognizant foreign disclosure office. Information released under Foreign Military Sales (FMS) must comply with the specific USAF disclosure guidance issued for the specific FMS customer.

FA8771-04-D-0004 RSCQ Rev 1.pdf
H94003-04-D-0004, CET 14-414.pdf
HK FA8771-04-D-0003 1
HK FA8771-04-D-0003 2
HK FA8771-04-D-0003 3
HK FA8771-04-D-0003 4
HK FA8771-04-D-0003 5
HK FA8771-04-D-0003 6
HK FA8771-04-D-0003 7
HK FA8771-04-D-0003 9
HK FA8771-04-D-0003 10
HK FA8771-04-D-0003 11
HK FA8771-04-D-0003 12
HK FA8771-04-D-0003 13
Blank Page
Blank Page
Blank Page
FA8771-04-D-0004 RSCQ Rev 1.pdf
H94003-04-D-0004, CET 14-414.pdf
HK FA8771-04-D-0003 1
HK FA8771-04-D-0003 2
HK FA8771-04-D-0003 3
HK FA8771-04-D-0003 4
HK FA8771-04-D-0003 5
HK FA8771-04-D-0003 6
HK FA8771-04-D-0003 7
HK FA8771-04-D-0003 9
HK FA8771-04-D-0003 10
HK FA8771-04-D-0003 11
HK FA8771-04-D-0003 12
HK FA8771-04-D-0003 13
Blank Page
Blank Page
Blank Page
FA8771-04-D-0004 RSCQ Rev 1.pdf
H94003-04-D-0004, CET 14-414.pdf
HK FA8771-04-D-0003 1
HK FA8771-04-D-0003 2
HK FA8771-04-D-0003 3
HK FA8771-04-D-0003 4
HK FA8771-04-D-0003 5
HK FA8771-04-D-0003 6
HK FA8771-04-D-0003 7
HK FA8771-04-D-0003 9
HK FA8771-04-D-0003 10
HK FA8771-04-D-0003 11
HK FA8771-04-D-0003 12
HK FA8771-04-D-0003 13
Blank Page
Blank Page
Blank Page
3b Date YYYYMMDD:
Text5: Contract # FA8730-17-R-0024

Contractor: TBD Text6: Item 13A. This contract requires additional security requirements established for Sensitive Compartmented Information (SCI) in accordance with (IAW) DoDM 5105.21-V1, V2, V3, and AFMAN 14-304.

AFMAN 14-304 and DoDM 5105.21-V1, V2, V3 provides the necessary guidance for physical, personnel, and information security measures and is part of the security specifications for this contract.

Item 13B. This contract will be administered under the following documents, with subsequent versions or changes.

(1) AFMAN 14-304

(2) DoDM 5105.21-V1, V2, V3

(3) Intelligence Community Directive (ICD) 705 standards

(4) Applicable Security Classification Guide, as dated.

Item 13C. Inquiries pertaining to classification guidance on SCI will be directed to the responsible Contracting Officer’s Representative (COR), indicated in the applicable Project Work Statements (PWS). Any SCI or SCI-derived material generated under this contract will be reviewed by the contract monitor for proper classification prior to final publication and distribution. The responsible Special Security Office as designated in Item 14H will provide assistance as required.

Item 14A. SCI data furnished to or generated by the contractor will require special security handling and controls beyond those in the National Industrial Security Program Operating Manual (NISPOM). These supplemental instructions will be furnished and/or made available to the contractor through the Sponsoring COR by the User Agency Special Security Office (AFLCMC/INHS). CORs and Contractor Special Security Officers (CSSOs) will comply with all requirements outlined in AFMAN 14-304 and DoDM 5105.21-V1, V2, V3. The CSSO will complete an annual self-inspection of all SCI related contract activity using the self-inspection checklist located in the DoDM 5105.21-V2. The self-inspection should take place in April of each year and a report of the self-inspection and all discrepancies noted will be forwarded to AFLCMC/INHS before the end of that month.

Item 14B. Contractor SCI billets are required to perform on this contract.

The contract Period of Performance and the expiration date are required / stated in item 13, in accordance with the contract identified in block 2 of the DD Form 254.

Item 14C. Names of contractor personnel requiring access to SCI will be submitted to the responsible COR for proper approval. Upon written approval by the contract monitor, forms requesting Single Scope Background Investigation (SSBI) will be prepared in accordance with the NISPOM and submitted to DSS.

Item 14D. The contractor will establish and maintain an access list of those employees working on this contract. A copy of this list will be furnished to the contract monitor and User Agency Special Security Office (AFLCMC/INHS).

Item 14E. The contractor will advise the User Agency Special Security Office (AFLCMC/INHS), through the SCI COR, immediately upon reassignment of personnel to other duties associated with this contract.

Text7: Contract # FA8730-17-R-0024 Contractor: TBD Text8: Item 14F. Release of Information: SCI shall not be released to contractor employees without specific release approval of the COR or the originator of the material when applicable. SCI with restrictive caveats (ORCON, PROPIN, etc.) will be released to contractors only when originator approval has been obtained. This approval shall be coordinated through the appropriate SSO based on approval and certification of “need-to-know” by the COR. SCI documentation, or other material concerning this contract will not be discussed with or released to any individual , subcontractor, agency (including Federal government agencies and employees), and contractor employees not working on the contract without prior approval from the COR.

Item 14G. Any SCI data released to or generated by the contractor in support of the contract remains the property of the DoD Department, agency, or command that released it. The contractor will maintain a record of all SCI released to their custody under this contract and upon completion/cancellation of the contract, must return all such materials to the supporting SSO identified in 14H or User Agency Special Security Office AFLCMC/INHS. This applies to all data and materials, including working papers and notes. The contractor will not reproduce any SCI related to this contract without the written permission of the COR. When such permission has been granted, the contractor will control and account for such reproductions in the same manner as pertains to originals. Reproduction of hard copy SCI documents in entirety is not permitted.

Item 14H. SCIF IDENTIFICATION AND SUPPORTING SSO IDENTIFICATION:

14H.a. IF A SCIF EXISTS: An accredited SCIF has been established by the contractor. The SCIF has been built IAW Intelligence Community Directive (ICD) 705 standards and an SCI accreditation message is on file within the SCIF. If the SCIF is accredited through other than HQ AFMC, a Co-Utilization Agreement (CUA) will be generated by COR. SCI material associated with this contract shall be separately stored and maintained only in such properly accredited facilities and in approved safes at the contract location. The supporting SSO for each facility is determined by the Government sponsor(s) of the contracted activity and not necessarily by the location of the facility. Once the supporting SSO is determined by the contractor or government sponsor they must coordinate with the User Agency Special Security Office (AFLCMC/INHS) for SCI requirements.

14H.b. IF A SCIF IS TO BE BUILT: A SCIF shall be built/accredited and maintained by the contractor IAW ICD 705 specifications and will not be operated as a SCIF until a SCI accreditation message from SSO DIA is on file within the facility. The contractor will nominate a CSSO and the supporting/responsible SSO will be determined based on the COR submittal of the mission requirements and outlined in the PWS(s). The responsible SSO determination will be coordinated with and approved by the User Agency Special Security Office (AFLCMC/INHS).

Item 14I. This contract does not require the use of Defense Courier Service (DCS); the supporting SSO will validate all DCS Form 10.

Item 14J. A COMSEC account is not required.

If a COMSEC account is required, the National Security Agency/Central Security Service (NSA/CSS) Policy Manual No. 3-16 dated 5 Aug 2005 for the handling of COMSEC material, is applicable. Access to COMSEC information is restricted to US citizens holding final US Government security clearances and is not releasable to personnel granted reciprocal clearances. COMSEC information is not releasable to contractor employees who have been granted a reciprocal clearance.

Text15: Contract # FA8730-17-R-0024 Contractor: TBD Text16: DD Form 254 Reference Block 10e(1) – SCI

ATTACHMENT 1

USE OF SPECIAL INTELLIGENCE MARKINGS

1. Authorized Control Markings of Intelligence Information

a. "Dissemination and Extraction of Information Controlled by Originator (ORCON)".

This marking is used only on classified intelligence that clearly identifies or would reasonably permit ready identification of intelligence sources or methods that are particularly susceptible to countermeasures that would nullify or measurably reduce their effectiveness. It is used to enable the originator to maintain continuing knowledge and supervision of the further use of intelligence beyond the original dissemination. This control marking may not be used when an item of information will reasonably be protected by use of any other markings specified herein, or by the application of the "need-to-know" principle and safeguarding procedures of the security classification system.

b. "Not Releasable to Foreign Nationals (NOFORN)"

This control marking is used to identify classified intelligence material that may not be released in any form to foreign governments, foreign nationals, or non-US citizens without permission of the US Government originator, and then only when released in compliance with the National Disclosure Policy.

c. "Authorized for Release to (Name of country(s)/international organization"

This marking is used to identify classified intelligence material that the US Government Originator has predetermined to be releasable or has been released through established foreign disclosure channels to the indicated country(s) or organization.

2. Procedures Governing Use of Control Markings

a. Any recipient desiring to use intelligence in a manner contrary to the restrictions established by the control markings set forth above, shall obtain the advanced permission of the originating agency. Such permission applies only to the specific purposes agreed to by the originator and does not automatically apply to all recipients. Originator will ensure that prompt consideration is given to recipients' requests, with particular attention to reviewing and editing if necessary, sanitized or paraphrased versions to derive a text suitable for release subject to lesser or no control markings.

b. The control markings authorized above shall be shown on the title page, front cover, and other applicable pages of documents, incorporated in the text of electrical communications, shown on graphics, and associated (in full or abbreviated form) with data stored or processed in automatic data processing systems. The control markings also shall be indicated by parenthetical use of the markings abbreviations at the beginning or end of the appropriate portions. If the control markings apply to several or all portions, the document may be marked with a statement to this effect rather than marking each portion individually.

c.The control markings in paragraph one (1) shall be individually assigned at the time of preparation of intelligence products and used in conjunction with security classifications and other markings specified by EO 13526 and its implementing ISOO Directive. The markings shall be carried forward to any new format in which the same information is incorporated including oral and visual presentations.

Text111: Contract # FA8730-17-R-0024

Text1111: Item 14K. This contract does require electronic processing of SCI.

If electronic processing of SCI is required, then the security provisions of ICD 503, DIAM 50-4 and AF MAN 14-304 and DoDM 5105.21-V1 apply and are part of this contract. No electronic processing will take place in the SCIF until Communications/EMSEC and Automated Information System (AIS) accreditation messages are on file within the facility. The equipment and AIS equipment the contractor is using are currently accredited for SCI operations.

Item 14L. The CSSO must coordinate with the SCI COR prior to subcontracting any portion of SCI efforts involved in this contract. A separate DD Form 254 for the subcontractor shall be processed and approved, and separate subcontractor billets shall be obtained before any work can be performed. Subcontractors cannot use the prime contractor’s SCI billets.

Item 14M. The contractor will not use references to SCI accesses, even by unclassified acronyms, in advertising, promotional efforts, or recruitment of employees.

Item 14N. The following activity is designated as the User Agency Special Security Office for SCI requirements in accordance with AFMAN 14-304 and DoDM 5105.21-V3.

AFLCMC/INHS

102 Barksdale Street Hanscom AFB, MA 01731-1801

Phone: DSN 845-5990/5991/3807 Commercial: (781) 225-5990/5991/3807

Item 14O. The User Agency Special Security Office (SSO) for coordination is:

_______________________________ Date: ______________

AFLCMC/INH, Hanscom AFB Special Security Office (SSO)

Item 14P. The signatory responsibility for Contract Monitor on this SCI continuation will be accepted and signed for on each sub-contract/project related to this parent DD Form 254. Those authorized signatories will be those specific program/project Program Manager (PM), AF Contracting Officer (CO) or Contracting’s Officer’s Representative (COR).

Item 15A. The Assistant Chief of Staff for Intelligence, Surveillance and Reconnaissance, Headquarters United States Air Force (HQ USAF/A2) has exclusive responsibility for all SCI classified material released or developed under this contract and held within the contractor’s SCIF. DIA is responsible for security inspection of all SCI and non-SCI classified material released to or developed under this contract and held within the contractor’s SCIF.

Text26: Contract # FA8730-17-R-0024 Contractor: TBD Text27: ATTACHMENT 5

PROGRAM PROTECTION PLAN (PPP)

1. The Contractor shall participate with the Government in the development of a Program Protection Plan (PPP), to include the identification of Critical Program Information (CPI), and shall also participate with the Government in determining countermeasures needed to safeguard the CPI throughout the acquisition process. The Contractor shall plan for and execute program protection in accordance with the PPP and program guidance.

2. A Program Protection Plan (PPP) and supporting annexes will be provided as Government Furnished Information (GFI). The contractor will follow guidance in the PPP and annexes for protection of Critical Program Information (CPI) identified in the PPP. The contractor will, as requested by the government, provide input to updates of the PPP and associated annexes. Any modifications or deviations to the PPP or annexes will be made in writing by the Program Manager (PM). Requests for clarification of the PPP or annexes will be made by the contractor to the PM not later than thirty (30) days from receipt of the PPP, its annexes, or updates thereof.

3. The contractor shall ensure that each contractor/ subcontractor employee completes Government furnished Program Protection awareness training; (a) prior to performing any contract/task order work, and (b) completes the specified fiscal year refresher course throughout the period of performance. This training is specific to the protection of Critical Program Information as supplied in the Program Protection Plan. The Government will provide the basic training plan to be tailored by each facility handling, storing, processing identified Critical Program Information.

4. The contractor/sub contractor shall maintain a listing by name and title of each contractor/subcontractor employee working under this contract/task order that has completed the required training. Any revisions to this listing as a result of staffing changes shall be included with the next required technical progress report submitted.

5. Additional annual inspections consisting of a review of contractor/subcontractor implementation of government furnished program protection plans is required. This is above and beyond Defense Security Service inspections. The purpose of the inspection is to ensure critical program information is substantially protected as required by the PPP.

6. The contractor/subcontractor shall encrypt using the Security Controls for Federal Information Systems and Organizations at (http://csrc.nist.gov/publications/PubsSPs.html) for government identified For Official Use Only Information and Critical Information identified in the Program Protection Plan.

1a FACILITY CLEARANCE REQUIRED: TOP SECRET
1b LEVEL OF SAFEGUARDING REQUIRED:
2a Check Box: Yes
2a Prime Contract Number: FA8730-17-R-0024
Check Box3a: Yes
3a Date YYYYMMDD:
2b Check Box: Off
2b Subcontract Number:
Check Box3b: Off
3b Revision No:
Check Box3c: Off
2c Check Box: Off
2c Solicitation or Other Number:
4 Yes Check Box: Off
3c Date YYYYMMDD:
4 No Check Box: Off
4 Preceding Contract Number:
5 Yes Check Box: Off
5 No Check Box: Yes
5 Date:
5 Period:
a NAME ADDRESS AND ZIP CODE: TBD
b CAGE CODE: TBD
c COGNIZANT SECURITY OFFICE Name Address and Zip Code: TBD
a NAME ADDRESS AND ZIP CODE_2: TBD
b CAGE CODE_2: TBD
c COGNIZANT SECURITY OFFICES Name Address and Zip Code: TBD
a LOCATION: TBD
b CAGE CODE_3: TBD
c COGNIZANT SECURITY OFFICE Name Address and Zip Code_2: TBD
9 GENERAL IDENTIFICATION OF THIS PROCUREMENT: Distributed Common Ground/Surface System (DCGS) Integration Backbone (DIB) Development 5th Edition
10a Yes: Off
10a No: Yes
11a Yes: Yes
11a No: Off
10k Other: Access to SIPRNet may be permitted as authorized by specific Statement of Work (SOW).
10b Yes: Off
10b No: Yes
11b Yes: Off
11b No: Yes
10c Yes: Off
10c No: Yes
11c Yes: Off
11c No: Yes
10d Yes: Off
10d No: Yes
11d Yes: Off
11d No: Yes
11e Yes: Off
11e No: Yes
10e(1) Yes: Yes
10e(1) No: Off
11f Yes: Off
11f No: Yes
10e(2) Yes: Yes
10e(2) No: Off
11g Yes: Yes
11g No: Off
10f Yes: Off
10f No: Yes
11h Yes: Off
11h No: Yes
10g Yes: Yes
10g No: Off
11i Yes: Yes
11i No: Off
10h Yes: Yes
10h No: Off
11j Yes: Yes
11j No: Off
10i Yes: Off
10i No: Yes
11k Yes: Off
11k No: Yes
10j Yes: Yes
10j No: Off
11l Other: Prior to classified AIS processing, the contractor will ensure that computer systems comply with Chapter 8 of the NISPOM
10k Yes: Yes
10k No: Off
11l Yes: Yes
11l No: Off
12 Direct: Off
12 Through: Yes
12 Public Release: **AFLCMC/HBBI program office in accordance with the process set forth by 66 ABG/PA**

**RELEASE OF SENSITIVE COMPARTMENTED INFORMATION (SCI) IS AUTHORIZED**

Text30: SEE CONTINUTATION PAGES

(1) The National Industrial Security Program Operating Manual (NISPOM), February 2006 and its supplements apply to all classified contract performance to include all provisions of E.O. 13526 (Classified National Security Information), dated December 29, 2009, regarding classification and marking guidance.

(2) Expiration Date of Contract: (Period of Performance subject to change)

(3) Program Manager: Emily Coppin, AFLCMC/HBBI, 11 Barksdale St., Bldg 1614, Hanscom AFB, MA 01731-1700, Comm (781) 225-1030, DSN 845-1030

(4) All contractual performance, training and security processing will be conducted at the facility located in 8a.

Security Manager: 66ABG/SCXS
66 ABG/SC: Security Manager
HNJS: Program Manager
66 ABG/IP: 66ABG/IP
14 Additional Security Requirements: Operations Security (OPSEC) requirements apply to this contract. OPSEC program managers will provide the appropriate critical information (CI) lists to the contractor under separate cover. Contractors conducting work will participate in the Installation OPSEC Program. Contractors will receive periodic training along with military and government civilian counterparts.
14 Yes Check Box: Yes
14 No Check Box: Off
15 Yes Check Box: Off
15 No Check Box: Yes
15 Inspections: Defense Security Service (DSS) is relieved of all industrial security inspections for contractor performance on the installation.

Inspections will be conducted according to the Contractor Visitor Group Security Agreement established between the Contractor and the Servicing Security Activity (SSA). The SSA for Hanscom AFB is 66ABG/IP, 102 Barksdale Street, Hanscom AFB, MA 01731-1801.

a TYPED NAME OF CERTIFYING OFFICIAL: Ms. Patricia J. Forest
b TITLE: Contracting Officer
16d Address: AFLCMC/HBBK

11 Barksdale St., Bldg 1614 Hanscom AFB, MA 01731

c TELEPHONE Include Area Code: (781) 225-9367
17a Check Box: Yes
17b Check Box: Off
17c Check Box: Yes
17d Check Box: Off
17e Check Box: Yes
17f Check Box: Yes
17f: 66 ABG/IP, AFLCMC/HBB
Text1: Contract # FA8730-17-R-0024

Contractor: TBD Text2: DD FORM 254, ADDITIONAL SECURITY GUIDANCE, BLOCKS, 8, 10 and 11

BLOCK 10. Contractor Will Require Access to:

Ref Block10e(1): Sensitive Compartmented Information (SCI). SCI requirements apply. See Attachment 1.

Ref Block 10e(2): Non-SCI. General Intelligence Material/Foreign Disclosure applies. See Attachment 2.

Ref Block 10g: NATO information. NATO. All appropriate contractor personnel be administered a NATO Briefing.

Ref Block 10h: Foreign Government Information. Access to FGI requires a final U.S. Government clearance at the appropriate level.

Ref Block 10j: For Official Use Only Information (FOUO). FOUO applies. See Attachment 3.

Ref Block 10k: Other. Access to SIPRNet may be permitted as authorized by specific Project Work Statements (PWS).

BLOCK 11: In Performing This Contract, The Contractor Will:

Ref Block 11a: Have Access to Classified Information Only at Another Contractor's Facility or at a Government Activity. Releasing contractor or Government activity will furnish complete classification guidance for the service to be performed. Contract performance is restricted to location listed in block 8a.

Ref Block 11g: Be Authorized to Use the Services of Defense Technical Information Center (DTIC) or other secondary distribution center. The contractor is authorized to use the services of DTIC and is required to prepare and process a DD Form 1540 - Registration for Scientific and Technical Information Services in accordance with the NISPOM. The contracting officer must be involved in certifying the need to know to DTIC

Ref Block 11i: Have TEMPEST Requirements. TEMPEST / EMSEC requirements apply. See Attachment 4.

Ref Block 11j: Have Operations Security (OPSEC) Requirements. OPSEC requirements apply. See block 14 for additional information. See Statement of Work for details.

Ref Block 11l: Other. Prior to classified AIS processing, the contractor will ensure that computer systems comply with Chapter 8 of the NISPOM.

Text17: Contract # FA8730-17-R-0024

Text18: DD Form 254 Reference Block 10j – FOUO

ATTACHMENT 3

FOR OFFICIAL USE ONLY INFORMATION

1. FOR OFFICIAL USE ONLY INFORMATION:

a. FOUO is a dissemination control applied by DoD to unclassified information when disclosure to the public would reasonable be expected to cause harm to an interest protected by one or more of the Freedom of Information Act (FOIA) Exemptions 2 through 9.

b. Use of the above markings does not mean that the information cannot be released to the public, only that it must be reviewed by the Government prior to its release to determine whether a significant and legitimate government purpose is served by withholding the information or portions of it.

2. IDENTIFICATION MARKINGS:

a. Each document determined to contain FOUO information shall identify the originating agency or office. This information shall be clear and complete enough to allow someone receiving the document to contact the office if questions or problems about the designation or marking arise.

b. Documents shall be marked “For Official Use Only” at the bottom of the outside cover (if any), the title page, the first page and the outside of the back cover (if any).

c. Internal pages of the document that contain FOUO information shall be marked “For Official Use Only” at the bottom.

d. Subjects, titles, and each section, part, paragraph or similar portion of an FOUO document shall be marked to show that they contain information requiring protection.

e. Electronically transmitted messages, including e-mail, containing FOUO information shall be marked to show they contain information requiring protection.

f. When FOUO information is contained in media or material (including hardware and equipment) the requirement remains to identify the information that requires protection.

3. DISSEMINATION: Contractors may disseminate FOUO information to their employees and subcontractors who have a need for the information in connection with a classified contract.

4. STORAGE: During working hours, reasonable steps shall be taken to minimize the risk of access by unauthorized personnel. During non-working hours, FOUO information may be stored to preclude unauthorized access. Filing such material with other unclassified records in unlocked files or desks, is adequate when internal building security is provided during non-working hours. When such internal security control is not exercised, locked buildings or rooms will provide adequate after-hours protection or the material; can be stored in locked receptacles such as file cabinets, desks, or bookcases.

5. TRANSMISSION: FOUO information and material may be transmitted via first-class mail, parcel post or, for bulky shipments, via forth class mail. Electronic transmission of FOUO information shall be by approved secure communications systems or systems utilizing other protective measures such as Public Key Infrastructure (PKI). Transmission of FOUO by facsimile equipment is permitted, use cover sheets and consider the location of the sending and receiving machines to ensure authorized personnel are available to receive FOUO information. Discussion of FOUO material on the telephone is authorized if necessary for the performance of the contract.

6. DISPOSITION & DISCLOSURE: FOUO information may be destroyed by any means approved for the destruction of classified information or by any other means that would make it difficult to recognize or reconstruct. Unauthorized disclosure of FOUO information does not constitute a security violation but the releasing agency should be informed of any unauthorized disclosure. The unauthorized disclosure of FOUO information protected by the Privacy Act may result in criminal sanctions.

Text19: Contract # FA8730-17-R-0024 Contractor: TBD Text20: DD Form 254 Reference Block 11i – Have TEMPEST Requirements

ATTACHMENT 4

EMMISSIONS SECURITY REQUIREMENTS

1. The contractor shall ensure that compromising emanations (EMSEC) conditions related to this contract are minimized. The following procedures relate to classified processing conducted within the US. Within NATO countries, prime contractors and sub-contractors using contractor or NATO-controlled equipment will adhere to NATO requirements for EMSEC procedures. Contractors operating US-only equipment, whether in a NATO-controlled facility or US-controlled facility, must comply with Air Force EMSEC procedures as specified by the cognizant EMSEC Manager.

2. For contracts which require the processing of classified information in a contractor facility, the contractor shall provide countermeasure assessment data to the Contracting Officer (CO), in the form of an EMSEC Countermeasures Assessment Request (ESAR). The ESAR shall provide only specific responses to the data required in paragraphs 4.1 - 4.4, below. The contractor's standard security plan is unacceptable as a "stand-alone" ESAR response. The ESAR information will be used to complete an EMSEC Assessment and Countermeasures Review of the contractor's facility, to be performed by the government EMSEC authority using current Air Force EMSEC directives.

3. The contractor will not process classified information until an ESAR is contractually submitted, the EMSEC Assessment and Countermeasures Review have been conducted, and the system has been accredited/approved by DSS in accordance with Chapter 8 of the NISPOM.

3.1 Recognizing that contractors utilize Information Systems (IS) for multiple contracts, ESAR assessments compiled and approved for a particular system under one AFLCMC contract are considered approved under other existing, follow-on and new AFLCMC contracts for that particular contractor, as long as no changes are made to the security profile of the IS. The approval(s) should be kept on file for all affected contracts.

3.2 Any requests for interim approval to process classified information, until ESAR information can be submitted and EMSEC procedures completed, must be approved by DSS. Such interim approval should not exceed 90 days.

4. When any of the information required in paragraphs 4.1 – 4.4 below changes (such as equipment, location or classification level), the contractor shall notify the contracting officer of the changes so an EMSEC Reassessment may be accomplished. The contractor shall submit to the System Program Office (SPO) a new ESAR, specifically identifying the configuration changes. It should be submitted at least thirty (30) days before the changes are projected to occur. The provisions of Paragraph 3 apply to these changes.

4.1. SYSTEM DESCRIPTION

4.1.1 SYSTEM/FACILITY: Full name and address of company submitting request and RFP/contract number and duration. Also provide a brief title identifying the overall system or facility (e-g. XYZ Missile words processing system, ABC aircraft interactive graphics system, etc.).

4.1.2 LOCATION: Provide the following information for the facility where processing will take place.

4.1.2.1. Identify the address (including city, state, zip code, facility, building and room number) where the system or facility is located. If the address is the same as 4.1.1., only indicate the building and room number where the equipment is located.

4.1.2.2. Make, title, and attach drawings/maps showing the inspectable space, Controlled Access Areas, and floor layout of the RED and BLACK equipment. The floor layout of the equipment (RED and BLACK) should include the locations of any transmitters, receivers, and cryptographic equipment, as well as RED and BLACK IS. The drawing may be free hand. Include the scale (roughly). Indicate on the map surrounding buildings to a distance of 200 meters. Identify significant occupants, organizations, and activities in the buildings within 200 meters. Identify significant occupants, organizations, and activities in the buildings within 200 meters.

Text22: Contract # FA8730-17-R-0024 Contractor: TBD Text23:

If the U.S. Government or the contractor identified in 4.1.1 above does not wholly occupy the building containing the RED equipment, identify and indicate the location of those other occupants.

4.1.2.2.1. Definition of Inspectable Space—The three-dimensional space surrounding equipment that processes classified or sensitive information within which TEMPEST exploitation is not considered practical, or where legal authority to identify or remove a potential TEMPEST exploitation exists.

4.1.2.2.2. Definition of Controlled Access Area (CAA)—The complete building or facility area under direct physical control within which unauthorized persons are denied unrestricted access and are either escorted by authorized persons or are under continuous physical or electronic surveillance.

4.2. RESPONSIBLE PERSONNEL:

4.2.1 INFORMATION SYSTEM SECURITY MANAGER (ISSM): Provide name, title, office symbol and telephone number. Include the same for the Company Appointed EMSEC (TEMPEST) Authority, if applicable.

4.2.2 SYSTEM CUSTODIAN: If different from above, provide name, title, and office symbol and telephone number.

4.3. OPERATIONAL RISK:

4.3.1 Identify the highest level of classified processing.

4.3.2 Provide an estimate of the total classified processing volume in a given measure of time. The estimate can be in hours per day, pages of classified generated per week, or megabytes or gigabytes processed per day/month. (e.g., 2 hrs/day, 15 pages/mo, or 320 mb/week), AND a percentage of total material processed for each level (e.g. 10% Top Secret; 55% Secret; 20% Confidential; 15% unclassified).

4.4 EQUIPMENT:

4.4.1 List the manufacturer and exact model number, nomenclature (terminal, disk drive, video system, etc.) and quantity of each equipment involved in classified processing. Do not provide a complete inventory of all the company's processing equipment.

4.4.2 List any encryption equipment (i.e., STE, KG-84, KG-194, etc.), that might be used for processing and transmission of classified information.

4.4.3. List any transmitters/transceivers (SATCOM, RF, UHF/VHF, WLAN, etc.) operating in the area (same room and adjacent rooms) of the equipment processing classified information, and indicate their approximate distance from the RED equipment.

5. EMSEC is applied on a case-by-case basis and further information may be required to complete the ESAR; should this be the case, the contractor shall provide this information to the contracting officer, PMO or SPO when requested.

6. Current requirements of AFI 33-214 Vol. 2 and AFI 33-203 dictate that the information used to complete the EMSEC Assessment and Countermeasures Review be validated annually. The ISSM shall certify annually to the PMO, SPO, or contracting officer that no changes to the information provided in paragraphs 4.1 through 4.4 of the ESAR have occurred.

7. The prime contractor shall ensure that this EMSEC requirement is provided to all subcontractors and/or vendors. The subcontractors and/or vendors shall comply with these EMSEC requirements when classified processing related to this contract is necessary. Subcontractors and/or vendors will provide their ESAR through the prime contractor to the government contracting officer.

8. WITH THE EXCEPTION OF 3.2 ABOVE, CLASSIFIED PROCESSING WILL NOT BE DONE UNTIL THE ABOVE PROCEDURES ARE COMPLIED WITH AND THE IS HAS BEEN ACREDITED BY THE DEFENSE SECURITY SERVICE (DSS).

9. If you have any questions feel free to contact Mr. Shawn Flaherty, Hanscom AFB EMSEC Manager.

Mailing Address: 66 ABG/SCXS SIPRNet: Shawn.Flaherty@hanscom.af.smil.mil 50 Hamilton Street Phone Number: (781) 225 - 0037 Hanscom AFB, MA 01731-1621 Fax Number: (781) 225 - 2133 E-Mail: Shawn.Flaherty.2@us.af.mil STE Number: (781) 225 - 2144

File details come from the government source that posted it. Updated .