04_Attachment_2_EELV_Phase_2_DD254.pdf
PDF 77 KB Posted
- Attached to
- Evolved Expendable Launch Vehicle (EELV) Phase 2 Launch Service Procurement (LSP) Draft Request for Proposals (dRFP) Federal contract opportunity
- Solicitation number
- FA8811-19-R-0002
About this file
This document is a Department of Defense Contract Security Classification Specification (DD Form 254) for the Evolved Expendable Launch Vehicle (EELV) Phase 2 Launch Service Procurement. The specification requires access to classified information including communications security, restricted data, and formerly restricted data. It details security requirements for the contractor and any subcontractors performing work such as receiving, storing, and generating classified material. The contractor must also have access to controlled unclassified information and meet operations security requirements. Responses to the draft request for proposals are due by December 21, 2018 and should be submitted to the listed points of contact. The North American Industry Classification System code for this effort is 481212.
04 Attachment 2 EELV Phase 2 DD254
View the file
Other files for this federal contract opportunity
Show all 41
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Please wait...
If this message is not eventually replaced by the proper contents of the document, your PDF viewer may not be able to display this type of document.
You can upgrade to the latest version of Adobe Reader for Windows®, Mac, or Linux® by visiting http://www.adobe.com/go/reader_download.
For more assistance with Adobe Reader visit http://www.adobe.com/go/acrreader.
Windows is either a registered trademark or a trademark of Microsoft Corporation in the United States and/or other countries. Mac is a trademark of Apple Inc., registered in the United States and other countries. Linux is the registered trademark of Linus Torvalds in the U.S. and other countries.
DEPARTMENT OF DEFENSE
CONTRACT SECURITY CLASSIFICATION SPECIFICATION
(Please read Instructions BEFORE completing this application.) (The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)
OMB No. 0704-0567 OMB approval expires October 31, 2020 The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.
RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.
1. CLEARANCE AND SAFEGUARDING
2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)
3. THIS SPECIFICATION IS: (X and complete as applicable.)
a. LEVEL OF FACILITY SECURITY CLEARANCE (FCL) REQUIRED (See instructions.)
b. LEVEL OF SAFEGUARDING FOR CLASSIFIED INFORMATION/MATERIAL REQUIRED AT CONTRACTOR FACILITY
DUE DATE (YYYYMMDD)
c. SOLICITATION OR OTHER NUMBER
b. SUBCONTRACT NUMBER
a. PRIME CONTRACT NUMBER (See instructions.)
DATE (YYYYMMDD)
c. FINAL (Complete Item 5 in all cases.)
DATE (YYYYMMDD)
REVISION NO.
b. REVISED (Supersedes all previous specifications.)
DATE (YYYYMMDD)
a. ORIGINAL (Complete date in all cases.)
(Preceding Contract Number) is transferred to this follow-on contract.
Classified material received or generated under YES. If Yes, complete the following:
NO
4. IS THIS A FOLLOW-ON CONTRACT?
, retention of the classified material is authorized for the period of:
In response to the contractor's request dated YES. If Yes, complete the following:
NO
5. IS THIS A FINAL DD FORM 254?
c. COGNIZANT SECURITY OFFICE (CSO) (Name, Address, ZIP Code, Telephone)
b. CAGE CODE
a. NAME, ADDRESS, AND ZIP CODE
6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code.)
c. COGNIZANT SECURITY OFFICE(S) (CSOs) (Name, Address, ZIP Code, Telephone)
b. CAGE CODE
a. NAME, ADDRESS, AND ZIP CODE
7. SUBCONTRACTOR(S) (Click button to add more subcontractors.)
c. COGNIZANT SECURITY OFFICE(S) (CSOs) (Name, Address, ZIP Code, Telephone) (If applicable, see instructions.)
b. CAGE CODE (If applicable, see instructions.)
a. LOCATION(S) (For actual performance, see instructions.)
8. ACTUAL PERFORMANCE (Click button to add more locations.)
9. GENERAL UNCLASSIFIED DESCRIPTION OF THIS PROCUREMENT (Click here if more space is needed.)
10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)
a. COMMUNICATIONS SECURITY (COMSEC) INFORMATION
d. FORMERLY RESTRICTED DATA
c. CRITICAL NUCLEAR WEAPON DESIGN INFORMATION (CNWDI) (If CNWDI applies, RESTRICTED DATA must also be marked.)
b. RESTRICTED DATA
e. NATIONAL INTELLIGENCE INFORMATION:
f. SPECIAL ACCESS PROGRAM (SAP) INFORMATION
k. OTHER (Specify) (See instructions.)
j. CONTROLLED UNCLASSIFIED INFORMATION (CUI) (See instructions.)
i. ALTERNATIVE COMPENSATORY CONTROL MEASURES (ACCM) INFORMATION
h. FOREIGN GOVERMENT INFORMATION
g. NORTH ATLANTIC TREATY ORGANIZATION (NATO) INFORMATION
DD FORM 254, NOV 2017
PREVIOUS EDITION IS OBSOLETE.
Adobe LiveCycle Designer ES4 CLASSIFICATION (When filled in):
CLASSIFICATION (When filled in):
(1) Sensitive Compartmented Information (SCI)
(2) Non-SCI
11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)
a. HAVE ACCESS TO CLASSIFIED INFORMATION ONLY AT ANOTHER CONTRACTOR'S FACILITY OR A GOVERNMENT ACTIVITY (Applicable only if there is no access or storage required at contractor facility. See instructions.)
h. REQUIRE A COMSEC ACCOUNT
k. BE AUTHORIZED TO USE THE DEFENSE COURIER SERVICE (DCS)
j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS
i. HAVE A TEMPEST REQUIREMENT
b. RECEIVE AND STORE CLASSIFIED DOCUMENTS ONLY
c. RECEIVE, STORE, AND GENERATE CLASSIFIED INFORMATION OR MATERIAL
f. HAVE ACCESS TO U.S. CLASSIFIED INFORMATION OUTSIDE THE U.S., PUERTO RICO, U.S. POSSESSIONS AND TRUST TERRITORIES
g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE TECHNICAL INFORMATION CENTER (DTIC) OR OTHER SECONDARY DISTRIBUTION CENTER
e. PERFORM SERVICES ONLY
d. FABRICATE, MODIFY, OR STORE CLASSIFIED HARDWARE
l. RECEIVE, STORE, OR GENERATE CONTROLLED UNCLASSIFIED
INFORMATION (CUI).
(DoD Components: refer to DoDM 5200.01, Volume 4 only for specific CUI protection requirements. Non-DoD Components: see instructions.)
m. OTHER (Specify) (See instructions)
12. PUBLIC RELEASE. Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address.
(See instructions)
DIRECT
THROUGH (Specify)
PUBLIC RELEASE AUTHORITY:
13. SECURITY GUIDANCE. The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes;
to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended. (Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. Click button to add additional pages as needed to provide complete guidance.)
14. ADDITIONAL SECURITY REQUIREMENTS. Requirements, in addition to NISPOM requirements for classified information, are established for this contract.
Yes No (If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. Use Item 13 or click button if additional space is needed.)
15. INSPECTIONS. Elements of this contract are outside the inspection responsibility of the CSO.
(If Yes, explain and identify specific areas and government activity responsible for inspections. Click button or use Item 13 if additional space is needed.)
Yes No
e. POC TELEPHONE (Include Area Code.)
f. EMAIL ADDRESS (See instructions.)
b. ACTIVITY ADDRESS CODE (AAC) OF THE CONTRACTING OFFICE (See instructions.)
d. AAC OF THE CONTRACTING OFFICE (See instructions.)
e. CAGE CODE OF THE PRIME CONTRACTOR (See instructions.)
d. POC NAME (See instructions.)
c. ADDRESS (Include ZIP Code.)
a. GCA NAME
16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)
18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL
17. CERTIFICATION AND SIGNATURES. Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below.
a. TYPED NAME OF CERTIFYING OFFICIAL (Last, First, Middle Initial) (See instructions.)
f. TELEPHONE (Include Area Code.)
g. EMAIL ADDRESS (See instructions.)
i. SIGNATURE
h. DATE
b. TITLE
c. ADDRESS (Include ZIP Code.)
f. OTHERS AS NECESSARY (If more room is needed, continue in Item 13 or on additional page if necessary.)
e. ADMINISTRATIVE CONTRACTING OFFICER
d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION
c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR
b. SUBCONTRACTOR
a. CONTRACTOR
DD FORM 254 (BACK), NOV 2017
CLASSIFICATION (When filled in):
CLASSIFICATION (When filled in):
c. COGNIZANT SECURITY OFFICE(S) (Name, Address, ZIP Code, Telephone)
b. CAGE CODE
a. NAME, ADDRESS, AND ZIP CODE
7. SUBCONTRACTOR(S) (Continued)
c. COGNIZANT SECURITY OFFICE(S) (Name, Address, ZIP Code, Telephone)
b. CAGE CODE
a. NAME, ADDRESS, AND ZIP CODE
c. COGNIZANT SECURITY OFFICE(S) (Name, Address, ZIP Code, Telephone)
b. CAGE CODE
a. NAME, ADDRESS, AND ZIP CODE
c. COGNIZANT SECURITY OFFICE(S) (Name, Address, ZIP Code, Telephone)
b. CAGE CODE
a. NAME, ADDRESS, AND ZIP CODE
c. COGNIZANT SECURITY OFFICE(S) (Name, Address, ZIP Code, Telephone)
b. CAGE CODE
a. LOCATION(S) (For actual performance, see instructions.)
c. COGNIZANT SECURITY OFFICE(S) (Name, Address, ZIP Code, Telephone)
b. CAGE CODE
a. LOCATION(S) (For actual performance, see instructions.)
c. COGNIZANT SECURITY OFFICE(S) (Name, Address, ZIP Code, Telephone)
b. CAGE CODE
a. LOCATION(S) (For actual performance, see instructions.)
c. COGNIZANT SECURITY OFFICE(S) (Name, Address, ZIP Code, Telephone)
b. CAGE CODE
a. LOCATION(S) (For actual performance, see instructions.)
8. ACTUAL PERFORMANCE (Continued)
9. GENERAL UNCLASSIFIED IDENTIFICATION OF THIS PROCUREMENT (Continued)
DD FORM 254, NOV 2017
Pages of Continuation Page CLASSIFICATION (When filled in):
CLASSIFICATION (When filled in):
15. INSPECTIONS (Continued)
14. ADDITIONAL SECURITY REQUIREMENTS (Continued)
13. SECURITY GUIDANCE (Continued) Pages of Continuation Page
DD FORM 254, NOV 2017
CLASSIFICATION (When filled in):
CLASSIFICATION (When filled in):
Additional persons assisting with completion of form (signatures and titles) 9.0.0.2.20120627.2.874785
WHS/ESD/DD
DD 254, Nov 2017, "DoD Contract Security Classification Specification" Orig No No No No No
| a. Facility clearance level. Select one.: 1 |
| b. Level of safeguarding for classified information/material required at contractor facility. Select one.: 1 |
| 2.c. Due date (four digit year, two digit month, two digit day.: |
| 2.c. Solicitation or other number.: FA8811-19-R-0002 |
| Mark X if solicitation or other number.: Yes |
| 2.b. Subcontract number.: |
| Mark X if Subcontract.: Off |
| 2.a. Prime contract number.: |
| Date (4 digit year, 2 digit month, 2 digit day).: |
| Date (4 digit year, 2 digit month, 2 digit day).: |
| 3.b. If revised, revision number.: |
| Date (Complete in all cases) (4 digit year, 2 digit month, 2 digit day).: 20181203.00000000 |
| 12. Public Release. Proposed public releases shall be submitted for approval prior to release: X first box if Direct, second box if Through.: |
| 4. If yes: Classified material received or generated under. Enter the preceding contract number, (enter Preceding contract number) is transferred to this follow on contract.: |
| Retention of the classified material is authorized for the period of:: |
| 5. If yes, complete the following: In response to the contractors request dated:: |
| 6.c. Cognizant security office. (Name, address, and zip code).: TBD |
| 6.b. CAGE code.: TBD |
| 6. Contractor. a. Name, address, and zip code.: TBD |
| c. Cognizant security office. (Name, address, and zip code).: N/A |
| b. CAGE code.: N/A |
| 7. Subcontractor(s). a. Name, address, and zip code.: N/A |
| 8.c. Cognizant security office (Name, address, and zip code).: TBD |
| 8.b. CAGE code.: TBD |
| 8. Actual performance. a. Location.: TBD |
| 9. General unclassified description of this procurement.: The Evolved Expendable Launch Vehicle (EELV) Phase 2 Launch Service Procurement allows the Air Force to procure the necessary equipment and services in order to reliably launch National Security Space (NSS) space vehicles, placing payloads into their appropriate earth orbit. The Potential Manifest could include the listed missions: GPSIII-7/8/9/10/11/12/13, AFSPC-10/16/23/29/31/36/51/55/59/67/70/87/106, NROL-57/69/73/77/94/97, SBIRS G-6, SBIRS FO-1, STP-5. |
| 10. Contractor will require access to: X if COMSEC information.: Yes |
| X if restricted data.: Off |
| X if NATO information.: Off |
| X if other.: Off |
| X if CUI.: Yes |
| X if alternative compensatory control measures (ACCM) information.: Off |
| X if foreign government information.: Off |
| X if formerly restricted data.: Off |
| X if formerly restricted data.: Yes |
| X if formerly restricted data.: Yes |
| X if special access program (SAP) information.: Off |
| X if CNWDI.: Off |
| Specify other require;ments (see instructions).: See continuation page 6 |
| Button1: |
| Button2: |
| Classification (when filled in).: |
| CheckBox1: 0 |
| 11. In performing this contract, the contractor will: X if have access to classified information only at another contractor's facility or a government activity.: Off |
| X if receive and store classified documents only.: Off |
| X if require a COMSEC account.: Yes |
| X if be authorized to use the Defense Courier Service.: Yes |
| X if have access to CUI.: Yes |
| X if have OPSEC requirements.: Yes |
| X if have a TEMPEST requirement.: Yes |
| X if receive, store, and generate classified material.: Yes |
| X if have access to U.S. classified information outside the U.S., Puerto Rico, U.S. possessions and trust territories.: Off |
| X if authorized to use the services of DTIC or other secondary distribution center.: Yes |
| X if perform services only.: Yes |
| X if fabricate, modify, or store classified hardware.: Yes |
| X if other.: Yes |
| If through, specify.: SMC (ATTN: SMC/LE) |
483 N. Aviation Blvd, El Segundo, CA 90245 Public release authority:: SMC (ATTN: SMC/PA) 483 N. Aviation Blvd, El Segundo, CA 90245
13. Security guidance.: 1. The contractor shall protect Critical Program Information (CPI), technologies, security documents and systems as identified in the EELV Program Protection Plan (PPP) as well as identified in the contractor's Program Protection Implementation Plan (PPIP), as approved by the program office. The prime contractor will flow-down applicable CPI to any subcontractors with protection requirements as identified in its PPIP. Individual Space Vehicle classification guidance for launch services provided under this effort are contained in the following, all of which have been transmitted to the contractor, and are available in the EELV Program Office.
2. Current EELV SCG and any revisions (Unclass/FOUO) See Continuation Page 3
13. Security guidance.: 3. Contractor will follow Program Security Classification Guides and will be provided by the SV Government program office.
4. Contract Completion Date: TBD POC for collateral classified information is SMC/LEE
7a. (Subcontractors): The prime contractor shall submit to SMC/ENX and the Program Office Government Contracting Authority (GCA) all DD254s for subcontractor(s) for review and approval prior to subcontractors having access to classified information. If this is an update to the DD254 to an existing contract, the Prime contractor will provide to the GCA a copy of DD254s issued to subcontractors supporting this effort. Subcontractors are not authorized access to classified information, COMSEC or NATO information/task on this contract until approved by GCA.
10a. (Communications Security (COMSEC)):
In addition to the COMSEC requirements identified in the NISPOM, the Contractor shall comply with CNSS Policy No. 3, National Policy for Granting Access to U.S. Classified Cryptographic Information and AFMAN 17-1302-0, COMSEC Operations [if on-base contractor]. Personnel requiring COMSEC access shall be briefed IAW DoDM 5220.22, CNSSP No. 3, and AFMAN 17-1302-0. [if on-base contractor] contractor must forward requests for COMSEC material/information to the Government COMSEC custodian through the Contracting Officer. Access to COMSEC material or information is restricted to U.S. citizens holding FINAL government clearances and is not releasable to personnel holding only a reciprocal clearance. All contractor employees who require access to classified COMSEC information in the performance of their contractual duties shall be briefed prior to being granted access. The contractor shall maintain a record of all COMSEC briefings.
NACSIM/NACSEM documents are not considered COMSEC controlled material. Prior approval from the Contracting Officer is required in order for a Prime Contractor to grant COMSEC access to a subcontractor. The Prime Contractor should also notify the NSA Central Office of Record before negotiating or awarding subcontracts.
10e.1 (SCI):
See SCI Addendum in Additional Security Requirements
10e.2 (Non-SCI):
The Contractor shall handle non-SCI or "collateral" intelligence information IAW Chapter 9, Section 3 of DoD 5220.22-M, National Industrial Security Program Operations Manual (NISPOM), DoDM 5200.01-V1-V3, Information Security Program and AFI 16-1404, Air Force Information Security
13. Security guidance.: Program. Particular emphasis is placed on the contractor(s) correctly understanding and heeding intelligence portion markings. As classified material, the contractor shall afford collateral intelligence information the same protections, safeguards, and precautions required by any classified material required by DoDM 5200.01-Vl-V3, unless special intelligence related handling instructions are specifically imposed. The contractor shall always obtain prior consent of SMC/IN to the release of intelligence derived information, whether its status is collateral or SCI.
10j. (Controlled Unclassified Information):
CUI is the term which includes For Official Use Only, Unclassified Controlled Technical Information (UCTI), Unclassified Controlled Nuclear Information (UCNI) and many other designations. CUI information provided under this contract shall be managed and safeguarded IAW DoDM 5200.01, Volume 4, Controlled Unclassified Information (CUI).
11c. (Receive, Store, and Generate Classified Information or Material):
Classified material will be handled in accordance with DoDM 5200.01-V1-V3 and the NISPOM.
11d. (Fabricate, Modify, or Store Classified Hardware):
The Contractor is required to provide adequate storage for classified hardware up to and including the level indicated in block 1b. If the hardware is such a size and/or quantity that it cannot be safeguarded in an approved storage container, use of an approved ‘Closed Area’ will be required.
11e. (Perform Services Only) The contractor will be required to perform services only.
11g. (Be Authorized to use the services of Defense Technical Information Center (DTIC) or other secondary distribution center):
The contractor may access information provided by DTIC by complying with all established safeguards and following the registration procedures as set forth in Chapter 11 Section 2 of the NISPOM.
11h. (Require a COMSEC Account) (On-base contractors) The contractor will be required to establish and maintain a COMSEC user account following the procedures and requirements contained in Committee on National Security Systems (CNSS) Policy No. 3, National Policy for Granting Access to U.S. Classified Cryptographic Information and AFMAN 17-1302-0, Communications Security (COMSEC) Operations, the NISPOM, and installation COMSEC account procedures.
13. Security guidance.: (Off-base contractors) NSA account will be established for and maintained by contractor IAW Committee on National Security Systems (CNSS) Policy No. 3, National Policy for Granting Access to U.S. Classified Cryptographic Information. The Contractor will comply with the additional security requirements and the management of NSA information/material as defined in the manual.
11i. (Have a TEMPEST Requirements):
The contractor shall comply with TEMPEST requirements as directed by the Government Contracting Activity (GCA), Authorization Official (AO) in addition to having the system assessed and authorized to the necessary confidentiality impact level.
11j. (Have OPSEC Requirements):
The contractor shall accomplish the following minimum requirements in support of the government Operations Security (OPSEC) Program:
a. The contractor shall comply with the User Agency OPSEC Plan, and apply protective measures therein. Research and Development contractors (off-base) shall develop an OPSEC Plan in accordance with DoDM 5205.2 and include OPSEC as a part of their ongoing security awareness program conducted in accordance with Chapter 3, Section 1, of the National Industrial Security Operating Manual.
b. The contractor shall protect all unclassified information and activities, which could compromise classified information or operations, or degrade the planning and execution of military operations performed by the contractor in support of the mission. Contractor shall protect controlled unclassified information (CUI) and information identified in the SMC and SMC program office critical information list (CIL).
c. Disposition of Critical Information and CUI obtained or produced pursuant to this contract shall be shredded/degaussed to prevent reconstruction.
11k: (Authorized use of Defense Courier Service):
The Contractor shall comply with NISPOM for authorized use of Defense Courier Services and obtain Government Contracting Activity (GCA) authorization as required.
11l. (Receive, Store, or Generate Controlled Unclassified Information (CUI):
Protection of Unclassified DoD Information on Non-Government Information Systems: The Contractor must comply with the information safeguards as specified in DoDI 8582.01, Security of Unclassified DOD Information on Non-DOD Information Systems, CNSSP No. 18, National Policy on Classified Information Spillage, Chairman of The Joint Chiefs of Staff Instruction (CJCSI) 6510.01, Information Assurance and Support to Computer Network Defense (CND), and AF Manual 17-1301, Computer Security. The Contractor shall comply with DFAR Clauses related to the Disclosure of Information (DFAR 252.204-7000), Safeguarding Covered Defense Information and Cyber Incident Report (DFARS 252.204-7012 and DFAR Subpart 204.73)
13. Security guidance.: for the protection of unclassified controlled technical information. In line with this clause, NIST SP 800-171 provides guidance for the protection of Controlled Unclassified Information (CUI) on non-federal information systems.
Contractor shall apply security controls contained in NIST SP 800-171 for the protection of CUI on non-DoD information systems. CUI information will not be placed on publicly accessible web sites.
Definitions:
Adequate Security – Security commensurate with the risk and the magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of information (see OMB Circular A-130). Current means of achieving adequate security for Information Technology is to use DoD, CNSS and NIST guidance (see CNSSI No. 4009).
Non-Sensitive Information -- Information available in the public domain or DoD information that has been approved for public release.
Sensitive Information -- Information, the loss, misuse, or unauthorized access to or modification of, could adversely affect the national interest or the conduct of Federal programs, or the privacy to which individuals are entitled under Section 552a of title 5, United States Code, "The Privacy Act" but which has not been specifically authorized under criteria established by Executive order or an Act of Congress to be kept secret in the interest of national defense or foreign policy.
Security Incident Reporting: The contractor shall provide a report of loss or compromise of CUI to the cognizant Government Contracting Activity (GCA), Government Information System Security Manager (ISSM), and Authorization Official (AO).
11m. (Other):
The terms Cybersecurity, Information Systems, and Information Technology, as used in this clause, are defined in Committee on National Security Systems Instruction 4009. Cybersecurity is further defined in DODI 8500.01 and is incorporated herein by reference:
Information systems (IS) shall be engineered and managed to protect and defend information and information systems from cybersecurity risks, including the risks to confidentiality, integrity, non- repudiation, and authorization in accordance with current DoD policies, procedures, and statutes, to include: National Security Act, Clinger-Cohen Act, Committee on National Security Systems Policy No. 11, National Institute on Standards and Technology Special Publications Federal Information Processing Standards, DoD Instruction 8500.01, Cybersecurity, DoDI 8581.01, IA Policy for Space Systems Used by the DoD , NISPOM Defense Security Service, Industrial Security Field Operations (ISFO), Assessment and Authorization Manual.
Security Incident Reporting: In addition to the reporting requirements directed by the NISPOM, the contractor shall provide a concurrent report of loss or compromise of classified information to the cognizant Government Contracting Activity (GCA), Government Information System Security Manager (ISSM), and Authorizing Official (AO).
13. Security guidance.: Have Export Control Requirements Technology Transfer and Information Control and Arms Export Control: By law, the U.S. Government and contractors must comply with the provisions of the International Traffic in Arms Regulations (ITAR) and the Arms Control Act before exporting defense articles, technical data, or defense services controlled by the ITAR. All such information intended for public release, or disclosure to any foreign person or U.S. person residing in a foreign country shall be submitted to SMC/ENX Foreign Disclosure Office (FDO), through the appropriate Foreign Disclosure Focal Point (FCFP), for potential technology transfer and suitability for the release of technical information.
Unauthorized Disclosure: Government and contractor personnel must act to protect Technical Program design, development, or manufacturing data under their control from unauthorized disclosure to any foreign person or a U.S. person residing in a foreign country. Government and contractor organization must inform the U.S. State Department under the provision of the ITAR regarding any unauthorized disclosure.
------END OF SECTION -------
| 15. Inspections. X first box if yes, second box if no.: |
| 15. Inspections. X first box if yes, second box if no.: |
| 15. Inspection. If yes is checked, explain and identify specific areas or elements carved out and the activity responsible for inspections.: Contractors, while on Government/Military installations will comply with Base organizational security and/or protection requirements. The Defense |
Security Service is relieved of inspection responsibility while on Government/Military installation, unless requested.
15. Inspection. If yes is checked, explain and identify specific areas or elements carved out and the activity responsible for inspections.: The Defense Security Service is relieved of security inspection responsibility for contracts on government installations. The Commander retains cognizance over contracts on the installation. SMC/ENX staff is designated as member of the Wing Inspection Team and has inspection authority when assigned under SMC/IG.
-----END OF SECTION-----
| 14. Additional security requirements. If yes, identify.: See Continuation Page |
| 14. Additional security requirements. If yes, identify.: This contract requires access to Sensitive Compartmented Information (SCI). The following directives/manuals/instructions provide the necessary guidance for physical, personnel, information and information systems security measures and is part of the SCI security specification for the contract. |
DoD 5105.21 Vl, V2, V3, SCI Administrative Security Manual(s) AFMAN 14-304, Security, Use and Dissemination of SCI ICD 503 - Information Systems ICD and ICPGs 704 - Personnel Security ICD and ICS/Tech Specs 705 - Physical Security DCID 6/9 - Physical Security (for facilities accredited under 6/9 standards) JDCSISSS - Joint DoDIIS Cryptologic SCI Information Systems Security Standards DIAM 50-4 - Defense Intelligence Agency Manual NISPOM Supplement NIST 800-53 Rev 4
2. The COR must be a Government employee (military or civilian) who is appropriately cleared and SCI indoctrinated for all accesses required by the contract in order to verify the SCI contract deliverables and validate need-to-know. An alternate COR should be appointed to assist the COR whenever the primary COR is not available. Contact information of the Contract Officer Representative ( COR) for the SCI portion of this contract:
14. Additional security requirements. If yes, identify.: Primary COR Name: TBD Org: TBD Telephone: TBD Address: 483 N. Aviation Blvd, El Segundo, CA 90245 E-Mail: TBD
3. All DD Form 254s prepared for subcontracts involving access to SCI under this contract must be forwarded to the COR for approval and then to SMC/ INS SSO for review and concurrence prior to award of the subcontract. Inquiries pertaining to classification guidance on SCI will be directed to the COR listed in paragraph 2 above. SCI security management issues shall be directed to:
SMC/INS SSO
483. N. Aviation Blvd.
El Segundo, CA 90245
310-653-4351/4509, DSN 633-4351/4509
Unclassified e-mail: smc.ins.sso@us.af.mil JWICS e-mail: SMC_INS_SSO@af.ic.gov
14. Additional security requirements. If yes, identify.: 4. SCI access is subject to U.S. Government review and approval as outlined in the aforementioned SCI security guidance. Upon completion or cancellation of the contract, the SSO/CSSO will debrief all personnel not required for contract closeout and those positions will be disestablished.
5. Names of contractor personnel requiring access to SCI and justification for SCI access will be submitted for coordination and action to SMC/INS SSO after the COR’s approval/concurrence. Upon receipt of written approval from the COR, the Facility Security Officer (FSO) and/or Contractor Special Security Officer (CSSO) may submit the necessary forms to the Defense Security Service (DSS) for a Single Scope Background Investigation (SSBI) for those personnel nominated for SCI in accordance with the National Industrial Security Program Operating Manual (NISPOM).
6. The SSO/CSSO can grant access to only those who possess the necessary security clearance and who are actually providing services under the contract.
Further dissemination to other contractors, subcontractors, other government agencies, private individuals or organizations is prohibited unless authorized in writing by the releasing agency.
7. SCI materials furnished in support of this contract remains the property of the DoD department or command that released it. Upon completion or cancellation of the contract, all SCI materials furnished will be returned to the direct custody of the originator of the materials. The information management system employed by the contractor shall be capable of facilitating such retrieval and disposition in an expeditious manner.
8. Classified foreign intelligence materials must not be released to foreign nationals or immigrant aliens whether or not they are also consultants, U.S.
contractors, or employees of the contractor regardless of the level of their security clearance, except with advance written permission from the originator.
14. Additional security requirements. If yes, identify.: 9. Contractor personnel must maintain accountability for all intelligence (to include foreign intelligence) materials released to their custody.
10. Contractor personnel must not reproduce classified foreign intelligence without advance approval of the releasing agency. If permission is granted, each copy will be controlled in the same manner as the original. The CSSO must not destroy any classified foreign intelligence without advance approval of the releasing agency.
11. SCIF is not required.
11.3. Contact information for FSO/CSSO:
Primary FSO/CSSO Name: TBD Telephone: TBD E-Mail: TBD
12. Visits. The contractor will submit the written request for SCI visit certifications through the COR for approval of the visit. The certification must arrive at their servicing SSO (SMC/INS SSO) at least five business days prior to the visit.
14. Additional security requirements. If yes, identify.: 13. Information assurance and electronic processing; information security (computer) and network connectivity require accreditation of the equipment connectivity. If JWICS accounts are required, it must be identified in Block 11L (JWICS must be stated, not just a blanket statement of access to government AISs). If JWICS connectivity at a contractor site is required, the statement of work or statement of objectives must specify a continual ongoing requirement for access that cannot utilize other means of information transmission or exchange, and it must be annotated in Block 11L of the
DD254.
14. Reference Block 15. This contract requires access to SCI. If the Contractor has established a SCIF, DIA and its designees are responsible for all inspections of the contractor SCIF and SCI security management program for ensuring compliance with all SCI security regulations and policies. If a new SCIF must be established in accordance with this contracting effort, permission to build/accredit a SCIF must be requested through the COR and forwarded to the SSO. Special Security Officers reserve the right to conduct program reviews of AF SCI materials and SCI program management to ensure the protection of AF equities.
15. Contract estimated completion date: TBD Period of Performance (Base): TBD Option Years: TBD ----END OF SECTION----
| e. POC telephone number (include area code).: |
| f. Email address (see instructions).: |
| d. Activity address code of the contracting office.: |
| d. POC name (last, first, middle initial).: |
| d. Cognizant security office. (Name, address, and zip code).: 483 N. Aviation Blvd |
El Segundo, CA 90245
| 16.a. Government contracting authority (GCA) name.: SMC/LEK |
| 17.a. Typed name of government or contractor security official (last, first, middle initial).: |
| f. Telephone number (include area code).: |
| g. Email address (see instructions).: |
| b. Title.: Contracting Officer |
| c. Address (include ZIP Code).: 483 N. Aviation Blvd |
El Segundo, CA 90245
| h. Date signed.: |
| i. Signature (click to sign).: |
| Specify other distribution.: SMC/ENX, SMC/INS SSO |
| 17.f. Mark X if others as necessary.: Yes |
| 17.e. Mark X if administrative contracting officer.: Yes |
| 17.d. Mark X if U.S. activity responsible for overseas security administration.: Off |
| 17.c. Mark X if Cognizant Security Office for prime and subcontractor.: Yes |
| 17.b. Mark X if Subcontractor.: Off |
| 17. Required distribution. a. Mark X if Contractor.: Yes |
| b. Activity address code of the contracting office.: |
| e. CAGE code of the prime contractor.: |
| 9. General identification of this procurement.: |
| Total number of pages.: 7.00000000 |
| Page number of this page.: 3.00000000 |
| Page number of this page.: 4.00000000 |
| Page number of this page.: 5.00000000 |
| Page number of this page.: 6.00000000 |
| Page number of this page.: 7.00000000 |
| Button3: |
| Signature.: |
| Title.: Security Manager |
SMC/LEES
Title.: Acquisition Security Specialist
SMC/ENX
Title.: Special Security Office
SMC/INS SSO
| Title.: |
| Signature.: |
| Signature.: |
| Signature.: |
File details come from the government source that posted it. Updated .