DD Form 254 Solicitation_JBSA 27 August 2020.pdf
PDF 69 KB Posted
- Attached to
- Enterprise Data Loss Prevention (E-DLP) Federal contract opportunity
- Solicitation number
- FA877320R0003
About this file
This document contains a Contract Security Classification Specification and details of a federal contract opportunity for an Enterprise Data Loss Prevention Proof of Concept. The Air Force is seeking a vendor to conduct a Proof of Concept at Joint Base San Antonio that includes at least 100 users across multiple data owners and represents all main data egress points. The Proof of Concept will apply data loss prevention capabilities to data at rest, in transit, and in use both on-premises and in cloud applications and storage. It will also demonstrate the ability to aggregate and correlate alerting across multiple networks and classifications. Questions are due by 26 May 2020 and quotes are due by 16 June 2020. The 38th Contracting Squadron at Joint Base San Antonio is the contracting activity, with Evan Chapman and Master Sergeant James Constas as contracting points of contact.
View the file
Other files for this federal contract opportunity
Show all 28
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Please wait...
If this message is not eventually replaced by the proper contents of the document, your PDF viewer may not be able to display this type of document.
You can upgrade to the latest version of Adobe Reader for Windows®, Mac, or Linux® by visiting http://www.adobe.com/go/reader_download.
For more assistance with Adobe Reader visit http://www.adobe.com/go/acrreader.
Windows is either a registered trademark or a trademark of Microsoft Corporation in the United States and/or other countries. Mac is a trademark of Apple Inc., registered in the United States and other countries. Linux is the registered trademark of Linus Torvalds in the U.S. and other countries.
DRAFT
SAMPLE
PREVIOUS EDITION IS OBSOLETE.
Page of
DD FORM 254, MAY 2019
NEEDS DD67
DEPARTMENT OF DEFENSE
CONTRACT SECURITY CLASSIFICATION SPECIFICATION
(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)
OMB No. 0704-0567 OMB approval expires:
20220531 The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.
RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.
1. CLEARANCE AND SAFEGUARDING
2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)
3. THIS SPECIFICATION IS: (X and complete as applicable.)
a. ORIGINAL (Complete date in all cases.)
b. REVISED (Supersedes all previous specifications.)
4. IS THIS A FOLLOW-ON CONTRACT?
If yes, complete the following:
Classified material received or generated under
5. IS THIS A FINAL DD FORM 254?
If yes, complete the following:
6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)
7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor)
8. ACTUAL PERFORMANCE (Click button to add more locations.)
10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)
e. NATIONAL INTELLIGENCE INFORMATION:
11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)
12. PUBLIC RELEASE
Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)
13. SECURITY GUIDANCE
The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.
(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)
14. ADDITIONAL SECURITY REQUIREMENTS
Requirements, in addition to NISPOM requirements for classified information, are established for this contract.
If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)
15. INSPECTIONS
Elements of this contract are outside the inspection responsibility of the CSO.
If Yes, explain and identify specific areas and government activity responsible for inspections. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)
16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)
17. CERTIFICATION AND SIGNATURES
Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below. Upon digitally signing Item 17h, no changes can be made as the form will be locked.
18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL
9.0.0.2.20120627.2.874785 DD 254, DoD Contract Security Classification Specification whs.mc-alex.esd.mbx.formswebmaster@mail.mil
WHS
List of Attachments (All Files Must be Attached Prior to Signing, i.e., for any digital signature on the form)
| CurrentPage: |
| PageCount: |
| Classification: Unclassified |
| SerialNum: |
| a. Facility clearance level. Select one.: 2 |
| b. Level of safeguarding for classified information/material required at contractor facility. Select one.: 2 |
| Choose Yes or No: 0 |
| Choose Yes or No: 1 |
| Prime: |
| Choose Yes or No: 0 |
| Choose Yes or No: 0 |
| Sub: |
| Choose Yes or No: 1 |
| Choose Yes or No: 0 |
| Soli: FA8773-20-R-0003 |
| DueDate: 2020-06-16 |
| dateA: |
| RevisionNum: |
| dateB: |
| Final: |
| dateC: |
| No: 1 |
| No: 1 |
| No: 0 |
| No: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 1 |
| Yes: 1 |
| Enter your name here.: |
| ReqDated: |
| Enter your name here.: |
| Name: TBD |
| Cage: TBD |
| CSO: |
| addrow: |
| Removerow: |
| Click to delete a row: |
| Location: 561 NOS |
Bldg 1844 Peterson AFB, CO Location: 502 CS Bldg 1052 Joint Base San Antonio-Lackland, TX Location: Building 16000 Lackland AFB
| Block9: This procurement is for an Enterprise Data Loss Prevention (E-DLP) Proof of Concept (POC). The POC will include atleast 100 users, multiple data owners, and be representative of all the main egress points for data and apply DLP capabilities to data at rest on premises or in cloud applications and cloud storage, in transit, and in use. It will also include developing the requisite policies and ways to best organize and train our IT Airmen, data owners, and users to employ E-DLP capabilities. |
| a: 1 |
| a: 1 |
| a: 1 |
| f: 0 |
| f: 0 |
| f: 0 |
| b: 0 |
| b: 0 |
| b: 0 |
| g: 1 |
| g: 0 |
| c: 0 |
| c: 0 |
| c: 1 |
| h: 0 |
| h: 0 |
| d: 0 |
| d: 0 |
| d: 0 |
| i: 0 |
| i: 0 |
| SCI: 1 |
| NonSCI: 0 |
| j: 1 |
| j: 1 |
| k: 1 |
| k: 0 |
| Enter your name here.: SIPR AND JWICS ACCOUNTS REQUIRED |
| Enter your name here.: Ref blk 11m: AFFARS 5352.204-9000 notification of government security activity and VGSA |
| e: 1 |
| e: 0 |
| l: 1 |
| m: 1 |
| direct: 0 |
| thru: 1 |
| Enter your name here.: Public release of SCI and Collateral is NOT authorized |
| PublicAuthority: |
| AddSig: |
| RemoveSig: |
| text: Level of SCI Access: TS/SCI |
Primary COR: Captain Paul Raymond Alternate COR: Master Sargent James Constas
SEE ATTACHMENT FOR FURTHER GUIDANCE.
See additional pages for further security guidance and attachment for coordination signatures.
1. The following items apply to this contract.
GENERAL GUIDANCE:
The Contractor must:
• Maintain control for all classified material released to his or her custody.
• Not reproduce classified materials without the written permission of the releasing agency. If permission is granted, each copy will be controlled in the same manner as the original.
• Not destroy any classified without advance approval of the releasing agency.
• Restrict access to only those individuals who possess the required security clearance and who are actually providing services under the contract. Further dissemination to other contractors, subcontractors, other government agencies, and private individuals or an organization is prohibited unless authorized in writing by the releasing agency.
• Not release classified material to foreign nationals or immigrant aliens whether or not they are consultants, US contractors, or employees of the contractor, and regardless of the level of their security clearance, except with advance written permission from the originator.
• Ensure that each employee having access to the classified material is fully aware of the special security requirements for this material and maintains records in a manner that permits the contractor to furnish on demand the name of individuals who have access to the material in their custody.
• Upon completion or termination of the classified contract, or sooner, when the purpose of the release has been served, the contractor must return to the COR all classified material (furnished or generated), unless retention or destruction is authorized in writing by the originator of the classified, the Senior Intelligence Officer (SIO), or the releasing command.
• The contractor must obtain written approval from the SSO or the National Security Agency (NSA) to use facsimile equipment to transmit information related to any contract. This applies whether government or government derived, classified or unclassified, inside or outside the contractor's SCIF. The written approval may contain restrictions contractually binding on the contractor.
• For computer security direction, the Contractor shall comply with Joint DoDIIS/Cryptologic SCI Information Systems Security Standards for SCI AIS and AFI 33-200 for collateral AIS. This guidance will be used in its entirety or waivers must be obtained in writing from SSO.
• If work under the terms of this contract requires access to NSA systems, the contractor may be required to take a Counter Intelligence (CI) polygraph test.
ITEM 10:
Ref item 10a. COMSEC material/information may not be released to DoD contractors without CPSD approval. Contractor must forward requests for COMSEC material/information to the COMSEC officer through the program office. The contractor is governed by the DoD 5220.22-M National Industrial Security Program Operating Manual dated February 28, 2006 or as amended in the control and protection of COMSEC material/information. Access to COMSEC material by personnel is restricted to U.S. citizens holding final U.S. Government clearances. Such information is not releasable to personnel holding only reciprocal clearances.
Ref item 10e. SCI work will be done in an appropriately accredited SCI facility (SCIF).
10e(1). Contractor will require access to ICD 703, Protection of Classified National Intelligence, Including Sensitive Compartmented Information, dated 21 June 2013
10e(2). Contractor will require AFI 14-302, Control, Protection, And Dissemination Of Sensitive Compartmented Information and AFI 14-303, Release Of Intelligence To U.S. Contractors
Ref item 10g. Contractor personnel will be required NATO indoctrination in order to perform on this contract. Special briefings are required for access to NATO. Access to classified NATO information requires a final US government clearance at the appropriate level. Prior approval of the contracting activity is required for subcontracting.
Ref item 10j. Controlled Unclassified Information (CUI) and FOUO information provided under this contract shall be safeguarded as specified in the DoD 5200.1 Volume 4.
ITEM 11:
Ref item 11a. Contractor performance is restricted to (List performance locations to include org, address, building numbers), and travel as required by the government activity. Further detailed security classification guidance will be included within the Statement of Work or attached security guidance. Using activity will provide security classification guidance for performance of this contract.
Ref item 11j. Contractor personnel will comply with Air Force Instruction (AFI) 10-701, Operations Security, available on the Air Force’s e-publishing website [URL: http://www.e-publishing.af.mil/]. They will also participate in the assigned unit's OPSEC program, protect critical information identified in the 688 CW Critical Information and Indicators List (CIIL), and complete the Cyber Awareness Challenge v4.0 (ZZ133098) computer based training (CBT) module located on the Advanced Distributed Learning Service (ADLS) website [URL: https://golearn.adls.af.mil/kc/main/kc_frame.asp] upon assignment and annually thereafter.
Ref item 11l. DoD Components: Refer to DoDM 5200.01, Volume 4 when considering specific requirements to be imposed on the contractor for the protection of CUI.
Ref item 11m: AFFARS 5352.204-9000 notification of government security activity and visitor Group security agreements (Apr 2003) Applies. The contractor is authorized to access, view, possess, process and/or use classified information, information systems and only in government workspaces. The contractor personnel must work in DoD facilities and other CONUS/OCONUS sites as directed. Contractor personnel must have access to SCI documentation and data communications systems (e.g., JWICS) at government sites. The contractor shall meet with Government agency personnel at Government SCI facilities to discuss related security requirements.
| attachmentsList: |
| AddAttachment: |
| ViewAttachment: |
| RemoveAttachment: |
| rep: |
| Sig: |
| Enter your name here.: See SCI/Non-SCI Release of Intelligence Information (Attachments 1 and 2) for additional security requirements. Prior approval of the contracting activity is required for subcontracting. Access to intelligence information requires special briefings and a final U.S. Government clearance at the appropriate level. |
Ref Item 14. Provide the information requested by AFFARS 5352.204-9000, Notification of Government Security Activity Clause, and AFI 16-1406, Air Force Industrial Security Program, to the Information Protection Office (IPO). Refer to the contract document for these clauses. Shipments of classified or sensitive equipment shall be handled, transported, transmitted and protected IAW NISPOM, DoD 5220.22M and as specified by unit directives. The contractor shall execute a VGSA with the government.
1. All Sensitive Compartmented Information (SCI) and material will be handled according to special security requirements furnished by the responsible Special Security Office (SSO) designated in item 13.
2. E.O. 13526, Classified National Security Information, contains new classification, declassification, and marking requirements that are not found in the current DoD 5220.22M, National Industrial Security Program Operating Manual (NISPOM). Refer to E.O.13526 for guidance until the NISPOM is revised.
3. The contractor will follow all applicable security guidance related to the protection of classified information. Baseline guidance includes the National Industrial Security Program Operating Manual (NISPOM), DOD Overprint to the NISPOMSUP, applicable Program Security Directives (PSDs) and Security Classification Guides (SCGs) and Standard Operating Procedures. Task specific security classification guidance: Information Operations Security Classification Guide, dated 6 Aug 98, NSA/CSS Manual 1-52, dated 23 Nov 04 and Annex C to NSA/CSS 123-2, dated 24 Feb 98 will be used to include all revisions and changes thereto.
| Enter your name here.: While operating on an Air Force Installation, Industrial Security Reviews will be conducted by the Information Protection Office (IPO) |
| GCAName: 38th CONS/PKC |
| AAC: FA8773 |
| Address: 4004 Hilltop Road |
Tinker AFB, 73145
| Address: TBD |
| POCName: Evan J Chapman |
| Phone: 4057349981 |
| Email: evan.chapman.2@us.af.mil |
| Title: TBD |
| Enter the date using the format DD-Mon-YYYY: |
File details come from the government source that posted it. Updated .