14_Atch_06_DD254_(29_Apr_09).doc
DOC document 337 KB Posted
- Attached to
- GPS Advanced Control Segment (OCX) Blocks 1 & 2 Federal contract opportunity
- Solicitation number
- FA8807-09-R-0003
About this file
14_Atch_06_DD254_(29_Apr_09)
View the file
Other files for this federal contract opportunity
Show all 40
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
ATTACHMENT 6: CONTRACT SECURITY CLASSIFICATION SPECIFICATION (DD-254)
ATTACHMENT 6: CONTRACT SECURITY CLASSIFICATION SPECIFICATION (DD-254)
GPS Advanced Control Segment (OCX)
CONTRACT SECURITY CLASSIFICATION SPECIFICATION (DD-254)
Attachment 6 for
FA8807-09-R-0003
29 April 2009 [This page intentionally left blank]
| DEPARTMENT OF DEFENSE |
| 1. CLEARANCE AND SAFEGUARDING |
| CONTRACT SECURITY CLASSIFICATION SPECIFICATION |
| a. FACILITY CLEARANCE REQUIRED |
TOP SECRET
(The requirements of the DoD Industrial Security Manual apply to all security aspects of this effort.)
b. LEVEL OF SAFEGUARDING REQUIRED
TOP SECRET
| 2. THIS SPECIFICATION IS FOR: (X and complete as applicable) |
| 3. THIS SPECIFICATION IS: (X and complete as applicable) |
a. PRIME CONTRACT NUMBER
| X |
| a. ORIGINAL (Complete date in all cases) |
| Date (YYMMDD) |
090106
b. SUBCONTRACT NUMBER
b. REVISED (Supersedes all previous specs) Revision No.
Date (YYMMDD)
| X |
| c. SOLICITATION OR OTHER NUMBER |
FA8007-09-R-0003
Due Date (YYMMDD) 23 Mar 08
| c. FINAL (Complete item 5 in all cases) |
| Date (YYMMDD) |
4. IS THIS A FOLLOW-ON CONTRACT?
| YES |
| X |
| NO. If Yes, complete the following: |
5. IS THIS A FINAL DD FORM 254?
| YES |
| X |
| NO. If Yes, complete the following: |
6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)
a. NAME, ADDRESS, AND ZIP CODE
B. CAGE CODE
C. COGNIZANT SECURITY OFFICE (Name, Address, and Zip Code)
7. SUBCONTRACTOR
NAME, ADDRESS, AND ZIP CODE
B. CAGE CODE
C. COGNIZANT SECURITY OFFICE (Name, Address, and Zip Code)
8. ACTUAL PERFORMANCE
2.0 NAME, ADDRESS, AND ZIP CODE
B. CAGE CODE
C. COGNIZANT SECURITY OFFICE (Name, Address, and Zip Code)
9. GENERAL IDENTIFICATION OF THE PROCUREMENT
The GPS Advanced Controlled Segment (OCX) includes a new infrastructure with functionality that completes the Modernization ORD capabilities and is the foundation for adding GPS III CDD capabilities.
| 10. THIS CONTRACT WILL REQUIRE ACCESS TO: |
| YES |
| NO |
| 11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: |
| YES |
| NO |
| a. COMMUNICATIONS SECURITY (COMSEC) INFORMATION |
| X |
a. HAVE ACCESS TO CLASSIFIED INFORMATION ONLY AT ANOTHER CONTRACTOR’S
FACILITY OR A GOVERNMENT ACTIVITY
X
b. RESTRICTED DATA
| X |
| b. RECEIVE CLASSIFIED DOCUMENTS ONLY |
X
c. CRITICAL NUCLEAR WEAPON DESIGN INFORMATION
| X |
| c. RECEIVE AND GENERATE CLASSIFIED MATERIAL |
| X |
d. FORMERLY RESTRICTED DATA
| X |
| d. FABRICATE, MODIFY, OR STORE CLASSIFIED HARDWARE |
| X |
e. INTELLIGENCE INFORMATION:
e. PERFORM SERVICES ONLY
X
| (1) Sensitive Compartmented Information (SCI) |
| X |
f. HAVE ACCESS TO U.S. CLASSIFIED INFORMATION OUTSIDE THE U.S., PUERTO RICO, U.S. POSSESSIONS AND TRUST TERRITORIES
X
| (2) Non-SCI |
| X |
g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE TECHNICAL INFORMATION
CENTER (DTIC) OR OTHER SECONDARY DISTRIBUTION CENTER
X
| f. SPECIAL ACCESS INFORMATION |
| X |
| h. REQUIRE A COMSEC ACCOUNT |
| X |
g. NATO INFORMATION
| X |
| I. HAVE TEMPEST REQUIREMENTS |
| X |
h. FOREIGN GOVERNMENT INFORMATION
| X |
| j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS |
| X |
I. LIMITED DISSEMINATION INFORMATION
| X |
| k. BE AUTHORIZED TO USE THE DEFENSE COURIER SERVICE |
| X |
| j. FOR OFFICIAL USE ONLY INFORMATION |
| X |
l. OTHER (Specify):
X
k. OTHER (Specify)
X
| DD FORM 254, DEC 1999 |
| Previous editions are obsolete |
Computer Generated Form
12. PUBLIC RELEASE. Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the Industrial Security Manual or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for approval prior to release
| Direct |
| X |
| Through (Specify): GPSW/ENS and SMC/PA |
The contractor shall refer to the GPSW Program Protection Plan for procedures regarding the release of program information to the general public. Release of information must be coordinated and approved by GPSW/ENS and SMC/PA.
13. Security Guidance. The security classification guidance needed for this classified effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes: to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended. (Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. Add additional pages as needed to provide complete guidance.)
This DD254 supports Special Access Programs (SAP), Sensitive Compartmented Information (SCI) and Collateral programs. Please refer to the appropriate security provisions and documents outlined in Attachment A, Special Access Program (SAP), Sensitive Compartmented Information (SCI) and Attachment B, Collateral, for specific security guidance.
Project Officer: Moses Uribarri, Capt, GPAS/GPG, (310) 653-3944 Estimated Date of Completion: 4QRFY2012
Vernon Utley, GG-13, DAF Paul T. Conlon, GG-13, DAF Program Security Officer Special Security Officer
GPSW/ENS SMC/INS
| 14. ADDITIONAL SECURITY REQUIREMENTS. Requirements, in addition to ISM requirements, are established for this contract. (If Yes, identify the pertinent contracted clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the cognizant security office. Use Item 13 if additional space is needed.) |
| X |
| Yes |
No
Read Attachment A and B
| 15. INSPECTIONS. Elements of this contract are outside the inspection responsibility of the cognizant security office. (If Yes, explain and identify specific areas or elements carved out and the activity responsible for inspections. Use item 13 if additional space is needed.) |
| X |
| Yes |
No
The Defense Security Service is relieved of inspection responsibilities for all SAP and SCI activities associated with this SMC/GPSW contract. GPSW is designated as the CSA and has exclusive security responsibility for all SAP and SCI information/material released or developed under this contract and applicable subcontracts. Read Attachment A for security guidance on SAP/SCI information.
16. CERTIFICATION AND SIGNATURE. Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below.
a. TYPED NAME OF CERTIFYING OFFICIAL
Terry Schooley
b. TITLE
Contracting Officer
c. TELEPHONE (Include Area Code)
(310) 653-3174
| d. ADDRESS (Include Zip Code) |
| 17. REQUIRED DISTRIBUTION |
| GPSW/PK |
| X |
| a. CONTRACTOR |
483 N. Aviation Blvd.
El Segundo, CA 90245-2808
| X |
| b. SUBCONTRACTOR |
| X |
| c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR |
e. SIGNATURE
d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION
| X |
| e. ADMINISTRATIVE CONTRACTING OFFICER |
| X |
| f. OTHERS AS NECESSARY SMC/PIP & GPSW/ENS (PPO) |
DD FORM 254 (BACK), DEC 1999
GPS Advanced Controlled Segment (OCX)
CONTRACT SECURITY CLASSIFICATION
SPECIFICATION (DD FORM 254)
Attachment A Special Access Program (SAP) and
Sensitive Compartmented Information (SCI) to
FA8007-09-R-0003
DATE: 2 February 2009 DD 254 Attachments
Block 10a: Communications Security (COMSEC)
a. The prime contractor is authorized access to COMSEC and or CRYPTO information in performance of this contract. Additionally, this information may also be shared with their respective subcontractors whom they have an existing contractual relationship (i.e. issued DD Form 254). The prime contractor will comply with the following manuals for guidance: National Security Agency Central Security Service NSA/CSS Policy Manual No. 3-16, 5 Aug 05 and the NISPOM, 28 Feb 06.
b. NACSIM/NACSEM documents are not considered COMSEC controlled material. Additionally, cryptographic information/equipment shall be retained in a Contractor facility COMSEC account.
Block 10e(1): Intelligence Information – Sensitive Compartmented Information (SCI) and 10f: Special Access Information
a. Physical Security This contract requires access to Special Access Program (SAP) Information. The contractor must maintain the SAP information in a Special Access Program Facility (SAPF) in accordance with the necessary physical, personnel, and automated information security guidance outlined in ICD 503, Information Technology Systems Security Risk Management, Certification and Accreditation, dated 15 Sep 08, and DCID 6/9, Physical Security Standards for Sensitive Compartmented Information Facilities, dated 18 Nov 02. Contractor compliance with these directives is mandatory unless specifically waived. Pre-construction plans must be submitted and approved prior to starting any facility renovation.
b. Personnel Security The contractor shall nominate a Contract Special Security Officer (CSSO) and Alternate to the GPSW PSO for SAP/SCI eligibility. No contractor will be granted access to SAP/SCI information/material under this contract unless they are materially contributing to this effort and filling an assigned billet. The names of contractor personnel requiring access to SAP will be submitted to the GPSW Program Security Office (PSO). Upon receipt of a completed background investigation the CSSO will submit a billet request to the PSO for contractors performing SAP activities on this contract. The CSSO is responsible for establishing and maintaining a current access roster indicating access of active SAP/SCI briefed personnel on this contract. The CSSO will immediately notify the PSO upon the reassignment of personnel to duties not associated with this contract, to include termination.
c. Document Control SAP information/material furnished in support of this contract remains the property of the GPSW. The contractor shall maintain an active accountability of all SAP material received, produced, maintained, and disposed of that is in their custody. Upon completion or cancellation of the SAR portion of this contract, SAR data will be returned to the custody of the GPSW unless a follow-on contract specifies that material will be transferred to that contract. Inventories of SAP material will be conducted in accordance with Joint Air Force – Army – Navy (JAFAN) Manual 6/0, Special Access Program Security Manual, dated 29 May 08. Any supplemental instructions will be furnished and/or made available to the contractor through the GPSW PSO.
d. Release of Information SAR material concerning this contract will not be disclosed, discussed, or released to any individual not employed on this contract without specific written approval of the GPSW PSO.
(1) SAP material released to the contractor under this contract shall be stored and worked on only within the proposed facility and upon receipt of an approved physical security accreditation by GPSW.
(2) SAP information will be released to contractors only when originator approval has been obtained. The contractor may release such material to any contractor employee assigned to a billet and indoctrinated for SAP access under this contract and only when a need-to-know exists. The contractor shall not release this material to other contractors, subcontractors, or Federal Government agency employees unless the GPSW Program Security Officer (PSO) has granted prior written approval.
(3) An access certification to a GPSW contractor occupied SAPF does not constitute approval to release GPSW contractual material to other contractors, subcontractors, or federal government employees, GPSW PSO approval is required.
(4) SAP information/material will not be released to non-U.S. citizens.
(5) GPSW approval of an SMC contractor visit certification or permanent certification to another facility will constitute approval to discuss contractual information/material at the facility to be visited.
e. Reproduction of SAP Information
The contractor may reproduce any SAP related information to this contract at the discretion of the Contract Program Security Officer (CPSO), as long as the copies are controlled in the same way as the originals and they remain in the SAPF. No copies of SAP documents will be transferred to other contractors unless a contractual relationship has been established.
f. Sub-Contracting The CPSO shall obtain written approval from the GPSW PSO, via Contract Monitor, prior to issuing all DD Forms 254 to subcontractors for any portion of this SAP effort.
g. Public Release The contractor shall not make references to SAP even by unclassified acronyms, in advertising, promotional efforts, or recruitment for employees.
h. Other:
(1) This contract requires access to Special Access Information. All SAR work associated with this contract will be accomplished within an accredited Special Access Program Facility (SAPF) approved for SAR information or material in accordance with the necessary physical, personnel, and automated information security guidance outlined in Block 13. Contractor compliance with these directives is mandatory unless specifically waived.
(2) Inquiries pertaining to classification guidance for SAP will be directed to GPSW via the Program Security Office (PSO).
(3) The Contractor will comply with the GPSW Program Protection Plan.
(4) The Contractor will require access to classified information/material up to and including TOP SECRET and TOP SECRET/Special Access Required (SAR). All elements of this contract for SAR information or material are under the cognizance of the GPSW.
(5) The Contractor will establish and maintain an access list of all employees approved for access to SAR portions of the contract. A copy of the list will be furnished to the Program Security Officer (PSO). The Contractor will immediately inform the PSO of a SAR accessed employee’s reassignment to other duties not associated with this contract, to include termination.
(6) SAR information or material will be safeguarded in a manner that provides positive control by SAR accessed personnel only and within facilities approved by the PSO.
(7) Requests for interpretation of SAR information and its safeguarding requirements or additional classification guidance on SAR portions of the contract will be directed to the PSO.
(8) Upon completion/cancellation of the SAP activity, the contractor will comply with the provisions for contractual documents (i.e. SOW, etc), and JAFAN 6/0 for disposition of SAP material in their custody or call the PSO for direction.
Block 10e(2): Intelligence Information: Non-SCI
a. Provisions for the handling of Non-SCI or “Collateral” Intelligence by contractors is governed by Chapter 9, Section 3 of DoD 5220.22-M, National Industrial Security Program Operating Manual (NISPOM), dated 28 Feb 06. Particular emphasis is placed on the contractor(s) correctly understanding and heeding intelligence portion markings.
b. Prime contractor is authorized to share Non-SAP information with subcontractors given a valid contractual relationship exists and a DD Form 254 has been issued to the subcontractor.
c. As classified material, collateral intelligence will be afforded the same protections, safeguards and precautions required by any classified material unless special intelligence related handling instructions are additionally imposed. These basic safeguards are found in DoD 5200.1-R, Information Security Program and AFI 31-401, Information security Program Management. The disclosure or release of intelligence derived information, whether its status is collateral or SAP, is not authorized without the prior consent of the PSO and SMC/IN.
Block 10k: Other: Automated Information System (AIS) Comply with the Joint Air Force – Army – Navy (JAFAN) Manual 6/3, Protecting Special Access Program Information Within Information Systems, dated 15 Oct 04 and Joint Air Force – Army – Navy (JAFAN) Manual 6/3, Implementation Guide, dated Sep 06. The CPSO shall submit a Systems Security Plan.
Block 11d: Fabricate, Modify, or Store Classified Hardware
The Contractor is required to provide adequate storage to the level of Top Secret for classified hardware that, due to size or quantity, cannot otherwise be safeguarded in GSA approved storage containers.
Block 11g: Be Authorized To Use the Services of DTIC or Other Secondary Distribution Center
The contractor may access information provided by DTIC by complying with all established safeguards and following the registration procedures as set forth in JAFAN Manual 6/0, Special Access Program Security Manual, Section 10-300 thru 10-302, dated 29 May 08.
Block 11i: TEMPEST Requirements
This contract requires electronic processing of classified information and will be permitted only after Emission Security (EMSEC) requirements are met.
TEMPEST security measures must be considered if electronic processing of SAP is involved in accordance with NTISSAM 2-95. An approved Inspectable Space Determination is needed prior to approval of Automatic Information Systems.
Block 11j: Operations Security (OPSEC) Requirements
Contractor will comply with all Program Protection Plans/Security Classification/ Declassification Guides specified in the applicable DD Form 254. The contractor will accomplish the following minimum requirements in support of the OPSEC Program and protect OPSEC Critical Information. Items of Critical Information are those facts which individually or in the aggregate reveal sensitive details about SMC programs and contractor operations, and thus require protection from adversarial collection or exploitation.
Protect Critical Information and activities which could compromise classified information or operations, or degrade the planning and execution of military operations performed by the contractor in support of the mission. Such information may be marked FOR OFFICIAL USE ONLY, Privacy Act of 1974, COMPANY PROPRIETARY, Export Controlled, or otherwise designated as sensitive by the PSO.
Review items on the Critical Information List (CIL) as contained within the SMC OPSEC Plan and determine applicable to contractor operations. Include OPSEC as a part of the contracts ongoing security awareness program conducted in accordance with Chapter 3, Section 1, of the NISPOM or Chapter 3 of AFI 10-701, as applicable.
Block 11k: Defense Courier Service
This contract requires the use of the Defense Courier Service (DCS). The Contractor shall prepare and submit DCS Form 10 in original triplicate to the PSO for validation prior to their submittal to the appropriate DCS station.
Block 13: Security Guidance
The prime contractor and their respective subcontractors shall comply with the general security provisions of the following documents, including changes or revisions:
1. AFI 10-701, 18 Oct 07, Operations Security (OPSEC)
2. AFI 14-302, 18 Jan 94, Control, Protection, and Dissemination of Sensitive Compartmented Information
3. AFI 14-303, 1 Apr 99, Release of Intelligence to U.S. Contractor
4. AFI 31-401, 1 Nov 01, Information Security Program Management
5. Joint Air Force – Army – Navy (JAFAN) Manual 6/0, 29 May 08, Special Access Program Security Manual
6. Joint Air Force – Army – Navy (JAFAN) Manual 6/3, 15 Oct 04, Protecting Special Access Program Information Within Information Systems
7. Joint Air Force – Army – Navy (JAFAN) Manual 6/3, Sep 06, Implementation Guide
8. Joint Air Force – Army – Navy (JAFAN) Manual 6/4, 9 May 06, Special Access Program Tier Review Process
9. Joint Air Force – Army – Navy (JAFAN) Manual 6/9, 23 Mar 04, Physical Security Standards for Special Access Program Facilities
10. ICD 503, 15 Sep 08, Information Technology Systems Security Risk Management, Certification and Accreditation
11. DCID 6/9, 18 Nov 02, Physical Security Standards for Sensitive Compartmented Information Facilities
12. DoD 5105.21-M-1, 3 Aug 98, Sensitive Compartmented Information Administrative Security Manual
13. DoD 5200.1-R, 14 Jan 97, Information Security Program
14. DoD 5220.22-M, 28 Feb 06, National Industrial Security Program Operating Manual (NISPOM) and subsequent changes or revisions
15. DoDD 5200.39, 10 Sep 97, Security, Intelligence, and Counterintelligence Support to Acquisition Program Protection
16. DoDD 5210.50, 22 Jul 05, Unauthorized Disclosure of Classified Information to the Public
17. NSA/CSS Policy Manual No. 3-16, 5 Aug 05, National Security Agency/Central Security Service Policy Manual and changes or revisions
18. NTISSAM TEMPEST 2-95, 12 Dec 95, Amendment of 3 Feb 00, Red/Black Installation Guidance
19. JDCSISSS, Rev 4, 1 Jan 06, Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
20. (U) PATHWAY LACY Security Classification Guide, 26 Aug 05
21. (U) Lobo Ridge Security Classification Guide, Rev 2, Apr 02
22. (U) PATHWAY Brook-002 Security Classification Guide, 26 Aug 05
23. (U) PATHWAY Brook-003 Security Classification Guide, 26 Aug 05
24. Global Positioning System (GPS) Security Classification Guide (SCG), Dec 08
25. GPS Program Protection Plan, 15 Jun 06
26. Global Positioning Systems Wing (GPSW) Operation Security (OPSEC) Plan, 19 Feb 03 Block 14: Additional Security Requirements Test Plans
Refer to pertinent security classification guide for system test requirements. Ensure that a test plan identifying operational procedures is submitted to the GPSW PSO for approval prior to testing. Submit test plans 30 days prior to test.
Block 15: Inspections The Defense Security Service (DSS) is carved out as the Cognizant Security Agency (CSA) involving Security Compliance Inspection’s for SMC/GPSW SAP activities associated with this contract.
The inspection authority is as follows.
The Program Security Officer (PSO) is: GPSW/ENS, (310) 653-3739 483 North Aviation Blvd
El Segundo, CA 90245-4659
GPS Advanced Controlled Segment (OCX)
CONTRACT SECURITY CLASSIFICATION
SPECIFICATION (DD FORM 254)
Attachment B
Collateral Information to
FA8007-09-R-0003
DATE: 2 February 2009 Block 10e: Intelligence Information: Non-SCI
Provisions for the handling of Non-SCI or “Collateral” Intelligence by contractors is governed by Chapter 9, Section 3 of DoD 5220.22-M, National Industrial Security Program Operating Manual (NISPOM), 28 Feb 06. Particular emphasis is placed on the contractor(s) correctly understanding and heeding intelligence portion markings.
Block 10j: For Official Use Only (FOUO) Information will be handled as follows;
1. Description. “For Official Use Only (FOUO)” is a designation that is applied to unclassified information that may be exempt from mandatory release to the public under the Freedom of Information Act (FOIA). The FOIA specifies nine exemptions that may qualify certain information to be withheld from release to the public, if, by its disclosure, a foreseeable harm would occur. They are:
a. Information that is currently and properly classified.
b. Information that pertains solely to the internal rules and practices of the Agency. (This exemption has two profiles, "high" and "low." The "high" profile permits withholding of a document that, if released, would allow circumvention of an Agency rule, policy, or statute, thereby impeding the agency in the conduct of its mission. The "low" profile permits withholding if there is no public interest in the document, and it would be an administrative burden to process the request.)
c. Information specifically exempted by a statute establishing particular criteria for withholding. The language of the statute must clearly state that the information will not be disclosed.
d. Information such as trade secrets and commercial or financial information obtained from a company on a privileged or confidential basis that, if released, would result in competitive harm to the company, impair the Government's ability to obtain like information in the future, or protect the Government's interest in compliance with program effectiveness.
e. Inter-Agency memoranda that are deliberative in nature; this exemption is appropriate for internal documents that are part of the decision making process and contain subjective evaluations, opinions and recommendations.
f. Information, the release of which could reasonably be expected to constitute a clearly unwarranted invasion of the personal privacy of individuals.
g. Records or information compiled for law enforcement purposes that:
(1) Could reasonably be expected to interfere with law enforcement proceedings;
(2) Would deprive a person of a right to a fair trial or impartial adjudication;
(3) Could reasonably be expected to constitute an unwarranted invasion of the personal privacy of others;
(4) Disclose the identity of a confidential source;
(5) Disclose investigative techniques and procedures; or
(6) Could reasonably be expected to endanger the life or physical safety of any individual.
h. Certain records of agencies responsible for supervision of financial institutions.
i. Geological and geophysical information concerning wells.
2. General.
a. Information that is currently and properly classified shall be withheld from mandatory release under the first exemption of the Freedom of Information Act FOIA. “FOR OFFICIAL USE ONLY” (FOUO) is applied to information that may be exempt under one or more of the other eight exemptions. So, by definition, information shall be unclassified in order to be designated FOUO. If an item of classified information is declassified, it may be designated FOUO if it qualifies under one of the other exemptions of the FOIA. This means that:
(1) Information cannot be classified and FOUO at the same time. Therefore, classified documents containing FOUO information cannot bear an overall document marking of FOUO. However, portions or pages of a classified document, that contain only FOUO information will be marked as FOUO.
(2) Information that is declassified may be designated FOUO, only if it is believed to fit into one or more of the last eight exemptions (exemptions 2 through 9).
b. The FOIA provides that, for information to be exempt from mandatory release it must fit into one of the qualifying categories and there must be a legitimate Government purpose served by withholding it. Simply because information is marked FOUO does not mean it automatically qualifies for exemption. If a request for a record is received, the information must be reviewed to see if it meets this dual test. On the other hand, the absence of the FOUO marking does not automatically meant the information must be released. Some types of records (for example, personnel records) are not normally marked FOUO, but may still qualify for withholding under FOIA.
3. Marking.
a. Marking information FOUO does not automatically qualify it for exemption. If a request for a record is received, the information shall be reviewed to determine if it actually qualifies for exemption. Similarly, the absence of the FOUO marking does not automatically mean the information shall be released. Some types of records (for example, personnel records) are not normally marked FOUO, but may still be withheld under the FOIA. All DoD unclassified information must be reviewed before it is released to the public or to foreign governments and international organizations.
b. Information that has been determined to qualify for FOUO status should be indicated by markings when included in documents and similar material. Markings should be applied at the time documents are drafted, whenever possible, to promote proper protection of the information.
(1) Unclassified documents and material containing FOUO information shall be marked as follows:
a. Documents will be marked "FOR OFFICIAL USE ONLY" at the bottom of the front cover (if there is one), the title page (if there is one), the first page, and the outside of the back cover (if there is one).
b. Pages of the document that contain FOUO information shall be marked "FOR OFFICIAL USE ONLY" at the bottom.
c. Portion Marking FOUO Information. Subjects, titles and each section, part, paragraph, and similar portion of an FOUO document shall be marked to show that they contain information requiring protection. Use the parenthetical notation “(FOUO)” to identify information as For Official Use Only for this purpose. Place this notation immediately before the text.
d. Material other than paper documents (for example, slides, computer media, films, etc.) shall bear markings that alert the holder or viewer that the material contains FOUO information.
e. FOUO documents and material transmitted outside the Department of Defense must bear an expanded marking on the face of the document so that non-DoD holders understand the status of the information. A statement similar to this one should be used:
"This document contains information exempt from mandatory disclosure under the F0IA. Exemption(s) ______ apply."
(2) Classified documents and material containing FOUO information shall be marked as required by Chapter 4 of the NISPOM (or DoD 5200.1-R, Chapter 5, as applicable), with FOUO information identified as follows:
a. Overall markings on the document shall follow the rules in NSPOM Chapter 4 (or DoD 5200.1-R, Chapter 5). No special markings are required on the face of the document because it contains FOUO information.
b. Portions of the document shall be marked with their classification as required by NISPOM Chapter 4 (or DoD 5200.1-R, Chapter 5). If there are unclassified portions that contain FOUO information, they shall be marked with "FOUO" in parentheses at the beginning of the portion. Since FOUO information is, by definition, unclassified, the "FOUO" is an acceptable substitute for the normal "U."
c. Pages of the document that contain classified information shall be marked as required by NISPOM Chapter 4 (or DoD 5200.1-R, Chapter 5). Pages that contain FOUO information but no classified information will be marked "FOR OFFICIAL USE ONLY" at the top and bottom.
(3) Transmittal documents that have no classified material attached, but do have FOUO attachments shall be marked with a statement similar to this one:
"FOR OFFICIAL USE ONLY ATTACHMENT."
(4) Each part of electrically transmitted messages containing FOUO information shall be marked appropriately. Unclassified messages containing FOUO information shall contain the abbreviation "FOUO" before the beginning of the text.
4. Access to FOUO Information.
a. No person may have access to information designated as FOUO unless that person has been determined to have a valid need for such access in connection with the accomplishment of a lawful and authorized Government purpose.
b. The final responsibility for determining whether an individual has a valid need for access to information designated as FOUO rests with the individual who has authorized possession, knowledge or control of the information and not on the prospective recipient.
c. Information designated as FOUO may be disseminated within the DoD Components and between officials of DoD Components and DoD contractors, consultants, and grantees to conduct official business for the Department of Defense, provided that dissemination is not further controlled by a Distribution Statement.
d. DoD holders of information designated as FOUO are authorized to convey such information to officials in other Departments and Agencies of the Executive and Judicial Branches to fulfill a government function. If the information is covered by the Privacy Act, disclosure is only authorized if the requirements of DoD 5400.11-R are satisfied.
e. Release of FOUO information to Congress is governed by DoD Directive 5400.4. If the information is covered by the Privacy Act, disclosure is authorized if the requirements of DoD 5400.11-R are also satisfied.
f. DoD Directive 7650.1 governs release of FOUO information to the General Accounting Office (GAO). If the information is covered by the Privacy Act, disclosure is authorized if the requirements of DoD 5400.11-R are also satisfied.
5. Protection of FOUO Information
a. During working hours, reasonable steps shall be taken to minimize risk of access by unauthorized personnel. After working hours, store FOUO information in unlocked containers, desks or cabinets if Government or Government-contract building security is provided. If such building security is not provided, store the information in locked desks, file cabinets, bookcases, locked rooms, etc.
b. FOUO information and material may be transmitted via first class mail, parcel post or, for bulk shipments, via fourth class mail. Electronic transmission of FOUO information, e.g., voice, data or facsimile, e-mail, shall be by approved secure communications systems or systems utilizing other protective measures such as Public Key Infrastructure (PKI), whenever practical.
c. FOUO information may only be posted to DoD Web sites consistent with security and access requirements specified in Deputy Secretary of Defense Memorandum dated December 1998, Subject: “Web Site Administration”.
d. Record copies of FOUO documents shall be disposed of according to the Federal Records Act and the DoD Component records management directives. Non-record FOUO documents may be destroyed by any of the means approved for the destruction of classified information, or by any other means that would make it difficult to recognize or reconstruct the information.
6. Unauthorized Disclosure. The unauthorized disclosure of FOUO does not constitute an unauthorized disclosure of DoD information classified for security purposes. However, appropriate administrative action shall be taken to fix responsibility for unauthorized disclosure of FOUO whenever feasible, and appropriate disciplinary action shall be taken against those responsible. Unauthorized disclosure of FOUO information that is protected by the Privacy Act may also result in civil and criminal sanctions against responsible persons. The Military Department or other DoD Component that originated the FOUO information shall be informed of its unauthorized disclosure.
Block 11d: Fabricate, Modify, or Store Classified Hardware
The Contractor is required to provide adequate storage to the level of Top Secret for classified hardware that, due to size or quantity, cannot otherwise be safeguarded in GSA approved storage containers.
Block 11g: Be Authorized To Use the Services of DTIC or Other Secondary Distribution Center
The contractor may access information provided by DTIC by complying with all established safeguards and following the registration procedures as set forth in Chapter 11 Section 2 of the NISPOM (DoD 5220.22M).
Reference Block 11i: TEMPEST Requirements
TEMPEST security measures must be considered if electronic processing of classified information is involved in accordance with DoD 5105.21-M-1, Chapter 7 and Appendix I, and AFMAN 14-304, Chapter 7.
This contract requires electronic processing of classified information and will be permitted only after EMSEC requirements are met as specified in the following EMSEC guidance:
61 CS/SCBS EMSEC REQUIREMENTS FOR SYSTEMS PROCESSING CLASSIFIED NATIONAL SECURITY INFORMATION
The following guidance outlines Emission Security (EMSEC) requirements that government contractors must comply with prior to processing classified data. These requirements are established for processing DoD SECRET information, but higher than DoD SECRET may call for more stringent requirements.
The contractor shall ensure that EMSEC conditions related to this contract are minimized and that Red/Black Separation Requirements are implemented in accordance with Attachment 1.
EMSEC Red/Black Requirements
Countermeasure Application: These paragraphs discuss how to apply Red/Black Separation counter- measures and under what conditions they would not be required.
Keep RED and BLACK Signal Lines Separated.
Keeping RED signal lines about 6 inches away from BLACK signal lines will reduce coupling to a level low enough to prevent detection at great distances (over one mile). This separation may be reduced to two inches if the RED signal lines are shielded.
Keep RED Signal Lines Separated from BLACK Power Lines.
Keeping RED signal lines about 6 inches away from BLACK power lines will reduce coupling to a level low enough to prevent detection at great distances (over one mile). This separation may be reduced to two inches if the RED signal lines are shielded.
Keep RED Processors Separated from BLACK Telephones and Telephone Lines.
Keep non-EMSEC-approved printers at least 3 feet away from telephones. Do not use the telephone while printing classified information. Keep all non-EMSEC-approved equipment at least 3 feet away from telephone lines; two inches if the telephone lines are shielded.
EMSEC SEPARATION MATRIX
This matrix applies to the processing of Collateral Secret Information.
BLACK
RED
| Crypto Equipment |
| Unshielded Signal And Telephone Lines |
| Shielded Telephone Lines |
| Power Lines |
Crypto
Equipment
| 0 |
| 3 Feet |
| 2 Inches |
| 2 Inches |
| Unshielded Signal Lines |
| 6 Inches |
| 6 Inches |
| 2 Inches |
| 6 Inches |
Shielded Signal
Lines
| 2 Inches |
| 2 Inches |
| 2 Inches |
| 2 Inches |
| EMSEC Approved Equipment |
| 2 Inches |
| 6 Inches |
| 2 Inches |
| None |
| Non-EMSEC Approved Equipment |
| 3 Feet |
| 3 Feet |
| 2 Inches |
| None |
SPECIAL ITEM EMISSION REQUIREMENTS
Special Items. People may innocently introduce other radio devices, such as pagers, hand-held portable transceiver radios, cellular telephones, cordless telephones, and cordless microphones into the area processing classified national security information with disastrous results. Also, alarm systems may use radio transmitters to alert remotely located security or fire-fighting teams.
Hand-Held Radios. Hand-held radio transceivers used with intrabase radios (sometimes abbreviated IBR) and land mobile radios (sometimes abbreviated LMR) deserve special consideration because of their unique operational applications. A person may carry these devices into an area where classified national security information is processed. If the person is carrying such a device works in a facility and works near computer systems processing classified information, that person should either turn off the device and use the telephone or keep the device 2 meters from classified processors. No transmissions are allowed near classified processors when they are in operation. If the person carrying the device is a short-term visitor, it may not be necessary to turn off the radio if the visitor is moving about in the facility. However, transmissions near classified processors must be avoided.
Beepers and Pagers. Beepers and pagers deserve special consideration because of their unique operational applications. A person may carry these devices into an area near processors where classified national security information is being processed. If the person is carrying such a device works in the facility and works near computer systems processing classified information, that person should either turn off the pager device and use the telephone or keep the device 2 meters from classified processors. If the person carrying the device is a short-term visitor, it may not necessary to turn off the device if the visitor is moving about in the facility. If the pager device has a transmit capability, follow the instructions for hand-held radios.
Alarm Systems. The mode of operation of alarm systems radio frequency transmitters will determine their treatment. Any such transmitter with a continuous transmit mode or a high duty cycle (transmits most of the time) must meet the same separation requirements as all other transmitters (See para. 1.1). If they do not meet these requirements, exclude them from operating in the vicinity of computer systems processing classified national security information. Low duty cycle (transmits short bursts infrequently) systems are not considered hazards and require no special treatment.
Cellular Telephones. When a cellular telephone is used as an operational necessity, separate it at least 5 meters from RED processing equipment. If a cellular telephone is personal property, its use near computer systems processing classified national security information is prohibited. Disable cellular telephones from receiving calls or separate them 10 meters from RED processing equipment.
Cordless Telephones. When a radio frequency cordless telephone is used as an operational necessity, separate it 5 meters from RED processing equipment. When the cordless telephone is personal property, its use near computer systems processing classified national security information is prohibited. Disable personal cordless telephones from receiving calls or separate them 10 meters from RED processing equipment. There are no separation requirements for infrared cordless telephones.
Cordless Microphones.
Radio Frequency Cordless Microphones. When a radio frequency cordless microphone, encrypted or unencrypted, is used for broadcasting either classified national security information or unclassified information, separate it 10 meters from RED processing equipment. Use of unencrypted radio frequency cordless microphones for classified broadcasts is prohibited.
Infrared Cordless Microphones. Use of infrared cordless microphones for broadcasting classified national security information is permitted in suitably constructed and approved rooms. During classified use, doors to approved areas should be kept closed and windows should be covered with drapes or blinds.
Cordless Keyboards. When a radio frequency cordless keyboard is used, separate it 10 meters from RED processing equipment. Radio frequency cordless keyboards cannot be used to process classified national security information unless encrypted.
Wireless Local Area Networks. When a radio frequency wireless local area network is used, separate the transmitter and receiver units 10 meters from RED processing equipment.
Block 11j: Operations Security (OPSEC) Requirements
Contractor will comply with all Program Protection Plans/Security Classification/ Declassification Guides specified in the applicable DD Form 254. The contractor will accomplish the following minimum requirements in support of the OPSEC Program and protect OPSEC Critical Information. Items of Critical Information are those facts which individually or in the aggregate reveal sensitive details about SMC programs and contractor operations, and thus require protection from adversarial collection or exploitation.
Protect Critical Information and activities which could compromise classified information or operations, or degrade the planning and execution of military operations performed by the contractor in support of the mission. Such information may be marked FOR OFFICIAL USE ONLY, Privacy Act of 1974, COMPANY PROPRIETARY, Export Controlled, or otherwise designated as sensitive by the Program Security Office or SMC/PIP (OPSEC Manager).
Review items on the Critical Information List (CIL) as contained within the SMC OPSEC Plan and determine applicable to contractor operations. Include OPSEC as a part of the contracts ongoing security awareness program conducted in accordance with Chapter 3, Section 1, of the NISPOM or Chapter 3 of AFI 10-701, as applicable. Be responsive to the SMC OPSEC Program Manager on a non-interference basis.
Block 13: Security Guidance
The prime contractor and their respective subcontractors shall comply with the general security provisions of the following documents, including changes or revisions:
1. AFI 10-701, 18 Oct 07, Operations Security (OPSEC)
2. AFI 10-1101, 7 May 07, Operation Security (OPSEC)
3. AFI 14-303, 1 Apr 99, Release of Intelligence to U.S. Contractor
4. AFI 31-401, 1 Nov 05, Information Security Program Management,
5. AFI 33-204, Vol 1, 31 Oct 05, Communications and Information Emission Security
6. DoD 5200.1-R, 14 Jan 97, Information Security Program
7. DoD 5220.22-M, 28 Feb 06, National Industrial Security Program Operating Manual (NISPOM)
8. DoD 5400.4, 30 Jan 87, Provisions of Information to Congress
9. DoD 5400.7-R/AF Sup, 24 Jun 02, DoD Freedom Of Information Act Program
10. DoD 5400.11-R, 14 May 07, Department of Defense Privacy Program
11. DoD 7650.1, 11 Sep 97, General Accounting Office Access to Records
12. DoDD 5200.39, 10 Sep 97, Security, Intelligence, and Counterintelligence Support to Acquisition Program Protection
13. DoDD 5210.50, 22 Jul 05, Unauthorized Disclosure of Classified Information to the Public
14. GPS Program Protection Plan, 15 Jun 06
15. Global Positioning Systems Wing (GPSW) Operation Security (OPSEC) Plan, 19 Feb 03
16. Global Positioning System (GPS) Security Classification Guide (SCG), Dec 08 Abbreviations and Acronyms
AAZ
Administrative Assistant, Directorate Security/Special Programs Office
AFSPC
Air Force Space Command
AIS
Automated Information System
CDD
Capability Development Document
CIL
Critical Information List
COMSEC
Communication Security
CPI
Critical Program Information
CPSO
Contractor Program Security Officer
CRYPTO
Cryptographic Program Information
CSA
Cognizant Security Authority
Cognizant Security Agency
CSR
Critical System Resource
CSS
Central Security Service
CSSO
Contractor Special Security Officer
CUA
Co-Utilization Agreement
DAC
Designated Acquisition Commander
DCID
Director of Central Intelligence Directives
DCS
Defense Courier Service
DIA
Defense Intelligence Agency
DoD
Department of Defense
DSS
Defense Security Service
DTIC
Defense Technical Information Center
EMSEC
Emission Security
ENS
Engineering/Security
FGI
Foreign Government Information
FOIA
Freedom of Information Act
FOUO
For Official Use Only
GPS
Global Positioning System
GPSO
Government Program Security Office
GPSW
Global Positioning Systems Wing
GSA
Government Security Agency
HQ
Headquarters
ICD
Intelligence Community Directive
JAFAN
Joint Army, Air Force, Navy
JDCSISS
Joint DoD Intelligence Information System Cryptologic, SCI, Information
System Security Standard
NACSEM
National Communications Security Emanation Memorandum
NACSIM
National Agency Communications Security Information Memorandum
NISPOM
National Industrial Security Program Operating Manual
NSA
National Security Agency
NSA/CSS
National Security Agency/Central Security Service
OCX
GPS Advanced Controlled Segment
OPSEC
Operation Security
ORD
Operational Requirements Document
PA
Public Affairs
PIP
Program Integration Protection
PIPP
Program Protection Implementation Plan
PKI
Public Key Infrastructure
PPO
Program Protection Office
PPP
Program Protection Plan
PSO
Program Security Office
SAP
Special Access Program
SAR
Special Access Required
SCI
Sensitive Compartmented Information
SCG
Security Classification Guide
SCIF
Sensitive Compartment Information Facility
SMC
Space and Missile Systems Center
SSO
Special Security Officer
TA/CP
Technology Assessment/Control Plan
TEMPEST
Technical Electro-Magnetic Pulse Emanation Suppression Techniques
//FOR OFFICIAL USE ONLY//
Contract Security Classification Specification
FA8807-09-R-0003
File details come from the government source that posted it. Updated .