03_DD_Form_254_Contract_Security.pdf
PDF 178 KB Posted
- Attached to
- Systems Engineering & Integration-2 (SE&I-2) FINAL Request for Proposal (RFP) Federal contract opportunity
- Solicitation number
- FA8811-20-R-0003
About this file
This draft request for proposals solicits systems engineering and integration services to support the Space and Missile Systems Center Launch Enterprise Directorate. Offerors are requested to provide continued SE&I services, including engineering, analysis, planning, and programmatic support. Interested parties must submit responses by 8 November 2019. Additionally, the agency plans to hold an industry day from 23-25 October 2019 to provide an opportunity for one-on-one vendor meetings; requests to attend must be submitted by 18 October 2019. Though not set aside for small businesses, the agency encourages responses from small and small disadvantaged businesses. The NAICS code for this effort is 541715 with a small business size standard of 1250 employees.
03_DD Form 254_Contract Security
View the file
Other files for this federal contract opportunity
Show all 50
Systems Engineering & Integration-2 (SE&I-2) FINAL Request for Proposal (RFP) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Please wait...
If this message is not eventually replaced by the proper contents of the document, your PDF viewer may not be able to display this type of document.
You can upgrade to the latest version of Adobe Reader for Windows®, Mac, or Linux® by visiting http://www.adobe.com/go/reader_download.
For more assistance with Adobe Reader visit http://www.adobe.com/go/acrreader.
Windows is either a registered trademark or a trademark of Microsoft Corporation in the United States and/or other countries. Mac is a trademark of Apple Inc., registered in the United States and other countries. Linux is the registered trademark of Linus Torvalds in the U.S. and other countries.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
SMC/INS SSO DD FORM 254 SCI ADDENDUM V4.0
Contract Number: ___________________________
This addendum must be filled out and attached to each DD Form 254 that requires SCI access. Also, blocks 14 and 15 must state “see attached SCI addendum V4.0”
1. Reference Block 14. This contract requires access to Sensitive Compartmented Information (SCI). The following orders/directives/manuals/instructions provide the necessary guidance for physical, personnel, information and information systems security measures and is part of the SCI security specification for the contract.
Executive Order 12333 – United States Intelligence Activities (AMMENDED by EO 13470, 2008)
Executive Order 13526 – Classified National Security Information (29 Dec 09) {replaced EO 12958}
ICD 503 - Information Systems
ICD and ICPGs 704 - Personnel Security
ICD and ICS/Tech Specs 705 - Physical Security
DCID 1/20P – Security Policy Concerning Travel and Assignment of Personnel with Access to SCI
DCID 6/1 – Security Policy for Sensitive Compartmented Information and Security Policy
DCID 6/9 - Physical Security (for facilities accredited under 6/9 standards)
DoDM 5105.21 V1, V2, V3 - SCI Administrative Security Manual(s)
DoDM 5200.01 V1, V2, V3, V4 – DoD Information Security
DoDM 5200.02 - Procedures for the DoD Personnel Security Program (PSP)
DoDM 5220.22 Volume 2 – National Industrial Security Program (NISP)
AFMAN 14-304 - Security, Use and Dissemination of SCI
AFMAN 16-1405 – Air Force Personnel Security Program
AFI 16-1404 – Air Force Information Security Program
AFI 16-1406 – Air Force Industrial Security Program
SMC/IN SSO Handbook
DIAM 50-4 - Defense Intelligence Agency Manual
NISPOM Supplement
NIST 800-53 Rev 4
2. The COR must be a Government employee (military or civilian) who is appropriately cleared and SCI indoctrinated for all accesses required by the contract in order to verify the SCI contract deliverables and validate need-to-know. An alternate COR should be appointed to assist the COR whenever the primary COR is not available. Contact information of the Contract Officer Representative (COR) for the SCI portion of this contract:
Primary COR
Alternate COR
Name: TBD
Name: TBD
Org: : TBD
Org: TBD
Telephone: 310-653-XXX
Telephone: 310-653-XXX
Address: 483 N. Aviation Blvd
El Segundo, CA 90245
Address: 483 N. Aviation Blvd El Segundo, CA 90245
E-Mail: XXX.XX@us.af.mil
E-mail: XXX.XX@us.af.mil
3. All DD Form 254s prepared for subcontracts involving access to SCI under this contract must be forwarded to the COR for approval and then to SMC/INS SSO for review and concurrence prior to award of the subcontract. Inquiries pertaining to classification guidance on SCI will be directed to the COR listed in paragraph 2 above. SMC/INS SSO is designated as the User Agency SSO for SCI requirements. SCI security management issues shall be directed to:
SMC/INS SSO
483. N. Aviation Blvd.
El Segundo, CA 90245
310-653-4351/4122, DSN 633-4351/4122
Unclassified e-mail: smc.ins.sso@us.af.mil
JWICS e-mail: SMC_INS_SSO@af.ic.gov
4. SCI access is subject to U.S. Government review and approval as outlined in the aforementioned SCI security guidance. Upon completion or cancellation of the contract, the SSO/CSSO will debrief all personnel not required for contract closeout and those positions will be disestablished.
5. All incidents affecting personnel, SCIFs, equipment, and material under SMC SSO cognizance will be reported to the SSO within 24 hours of incident discovery, to include Classified Message Incidents (CMIs) and adverse information of SCI indoctrinated personnel. The company will notify the SSO on the first duty day if the incident occurs on a weekend or holiday. In addition to policy, principles of risk management and risk based analysis are applied to incidents by the Senior Intelligence Officer (SIO) and Special Security Officer (SSO), which may include interim action to locally suspend access to SCI pending final resolution.
6. Names of contractor personnel requiring access to SCI and justification for SCI access will be submitted for coordination and action to SMC/INS SSO after the COR’s approval/concurrence. Upon receipt of written approval from the COR, the Facility Security Officer (FSO) and/or Contractor Special Security Officer (CSSO) may submit the necessary forms to the Defense Security Service (DSS) for a Single Scope Background Investigation (SSBI) or Tier 5 or 5R for those personnel nominated for SCI in accordance with the National Industrial Security Program Operating Manual (NISPOM).
7. The SSO/CSSO can grant access to only those who possess the necessary security clearance and who are actually providing services under the contract. Further dissemination to other contractors, sub-contractors, other government agencies, private individuals or organizations is prohibited unless authorized in writing by the releasing agency.
8. SCI materials furnished in support of this contract remains the property of the DoD department or command that released it. Upon completion or cancellation of the contract, all SCI materials furnished will be returned to the direct custody of the originator of the materials. The information management system employed by the contractor shall be capable of facilitating such retrieval and disposition in an expeditious manner.
9. Classified foreign intelligence materials must not be released to foreign nationals or immigrant aliens whether or not they are also consultants, U.S. contractors, or employees of the contractor regardless of the level of their security clearance, except with advance written permission from the originator.
10. Contractor personnel must maintain accountability for all intelligence (to include foreign intelligence) materials released to their custody.
11. Contractor personnel must not reproduce classified foreign intelligence without advance approval of the releasing agency. If permission is granted, each copy will be controlled in the same manner as the original. The CSSO must not destroy any classified foreign intelligence without advance approval of the releasing agency.
12. A SCIF meeting the physical security requirements in ICD 705 (or DCID 6/9 for facilities accredited before 26 May 2010) is required for this contracting effort. All SCI used for this contract shall be stored, handled, and maintained in an accredited SCIF, be it the local contractor SCIF or similarly SCI accredited facilities used by the contractor. Address of the SCIF for contract execution (if there are multiple facilities please list them in Block 8 of the DD254, or attachment, with the following information):
12.1. (FOUO)
Office Symbol and Company Name: TBD
Street Address (to include bldg. #):TBD
City, State, Zip Code: TBD
12.2. Contact information for FSO/CSSO:
Primary FSO/CSSO
Alternate FSO/CSSO
Name: TBD
Name: TBD
Telephone: TBD
Telephone: TBD
E-Mail: TBD
E-mail: TBD
13. Visits. The contractor will submit the written request for SCI visit certifications through the COR for approval of the visit. The certification must arrive at their servicing SSO (SMC/INS SSO) at least five business days prior to the visit.
14. Information assurance and electronic processing; information security (computer) and network connectivity require accreditation of the equipment connectivity. If JWICS accounts are required, it must be identified in Block 11m. (JWICS must be stated, not just a blanket statement of access to government AISs). If JWICS connectivity at a contractor site is required, the statement of work or statement of objectives must specify a continual ongoing requirement for access that cannot utilize other means of information transmission or exchange, and it must be annotated in Block 11m of the DD254.
15. Reference Block 15. This contract requires access to SCI. If the Contractor has established a SCIF, DIA and its designees are responsible for all inspections of the contractor SCIF and SCI security management program for ensuring compliance with all SCI security regulations and policies. SMC/INS SSO is designated as the inspection authority for SCI security requirements; Defense Security Service is relieved of SCI inspection responsibilities. If a new SCIF must be established in accordance with this contracting effort, permission to build/accredit a SCIF must be requested through the COR and forwarded to the SSO. Special Security Officers reserve the right to conduct program reviews of AF SCI materials and SCI program management to ensure the protection of AF equities.
16. Contract estimated completion date: TBD
Period of Performance (Base): TBD
Option Years: TBD
**Option years are not valid until executed by the government. For continued SCI access during option years, a current/signed SF 30, or revised 254, must be on file with SMC/INS SSO prior to the expiration of the current Period of Performance**
DRAFT
SAMPLE
PREVIOUS EDITION IS OBSOLETE.
Page of AEM LiveCycle Designer
DD FORM 254, APR 2018
NEEDS DD67
DEPARTMENT OF DEFENSE
CONTRACT SECURITY CLASSIFICATION SPECIFICATION
(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)
OMB No. 0704-0567 OMB approval expires:
October 31, 2020 The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.
RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.
1. CLEARANCE AND SAFEGUARDING
2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)
3. THIS SPECIFICATION IS: (X and complete as applicable.)
a. ORIGINAL (Complete date in all cases.)
b. REVISED (Supersedes all previous specifications.)
4. IS THIS A FOLLOW-ON CONTRACT?
If yes, complete the following:
Classified material received or generated under
5. IS THIS A FINAL DD FORM 254?
If yes, complete the following:
6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)
7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor)
8. ACTUAL PERFORMANCE (Click button to add more locations.)
10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)
e. NATIONAL INTELLIGENCE INFORMATION:
11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)
12. PUBLIC RELEASE
Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)
13. SECURITY GUIDANCE
The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.
(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)
14. ADDITIONAL SECURITY REQUIREMENTS
Requirements, in addition to NISPOM requirements for classified information, are established for this contract.
If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)
15. INSPECTIONS
Elements of this contract are outside the inspection responsibility of the CSO.
If Yes, explain and identify specific areas and government activity responsible for inspections. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)
16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)
17. CERTIFICATION AND SIGNATURES
Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below. Upon digitally signing Item 17h, no changes can be made as the form will be locked.
18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL
9.0.0.2.20120627.2.874785 DD 254, DoD Contract Security Classification Specification List of Attachments [1] (All Files Must be Attached Prior to Signing, i.e., for any digital signature on the form) SCI_Addendum_4.0_Generic.docx
| CurrentPage: |
| PageCount: |
| Classification: Unclassified |
| SerialNum: |
| a. Facility clearance level. Select one.: 1 |
| b. Level of safeguarding for classified information/material required at contractor facility. Select one.: 2 |
| Choose Yes or No: 0 |
| Choose Yes or No: 1 |
| Prime: |
| Choose Yes or No: 0 |
| Choose Yes or No: 0 |
| Sub: |
| Choose Yes or No: 1 |
| Choose Yes or No: 0 |
| Soli: TBD |
| DueDate: |
| dateA: 2019-02-01 |
| RevisionNum: |
| dateB: |
| Final: |
| dateC: |
| No: 1 |
| No: 1 |
| No: 0 |
| No: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 1 |
| Yes: 1 |
| Enter your name here.: |
| ReqDated: |
| Enter your name here.: |
| Name: TBD |
| Name: N/A |
| Name: Cunningham, Ashley, M., Capt |
| Cage: TBD |
| Cage: TBD |
| Cage: TBD |
| CSO: TBD |
| CSO: SMC/LE |
483 N. Aviation Blvd El Segundo, CA 90245
CSO: 45 SW/IP
1201 Edward H. White St.
Patrick AFB (CCAFS), FL 32925
CSO: 30 SW/IP
1031 California Blvd. Bldg 11777, RM C-110 Vandenberg AFB, CA 93437
CSO: HQ AFSPC
150 Vandenberg St Peterson AFB, CO 80914
| CSO: TBD |
| addrow: |
| Removerow: |
| Click to delete a row: |
| Location: Space and Missile Systems Center |
Launch Enterprise Directorate (SMC/LE) 483 N. Aviation Blvd El Segundo, CA 90245 Location: 45th Launch Group 15385 Samuel Phillips Parkway Patrick AFB (CCAFS), FL 32925 Location: 30th Launch Group Bldg 7015 Vandenberg AFB, CA 93437 Location: HQ AFSPC/SE 150 Vandenberg St Suite 1105 Peterson AFB, CO 80914
| Location: Contractor Information (TBD) |
| Block9: To provide Systems Engineering & Integration (SE&I) support to the Launch Enterprise Directorate (SMC/ECL) |
| a: 1 |
| a: 0 |
| a: 1 |
| f: 0 |
| f: 0 |
| f: 1 |
| b: 0 |
| b: 0 |
| b: 0 |
| g: 0 |
| g: 0 |
| c: 0 |
| c: 1 |
| c: 1 |
| h: 0 |
| h: 0 |
| d: 0 |
| d: 1 |
| d: 0 |
| i: 0 |
| i: 0 |
| SCI: 1 |
| NonSCI: 0 |
| j: 1 |
| j: 1 |
| k: 1 |
| k: 0 |
| Enter your name here.: SIPRNET and JWICS Access see block 13 |
| Enter your name here.: See SCI Addendum and comments in Block 13. |
| Enter your name here.: SMC/CIO, SMC/INS SSO |
| e: 0 |
| e: 1 |
| l: 1 |
| m: 1 |
| direct: 0 |
| thru: 1 |
| Enter your name here.: SMC (ATTN: SMC/LE) |
483 N. Aviation Blvd, El Segundo CA 90245 PublicAuthority: SMC (ATTN: SMC/PA) 483 N. Aviation Blvd, El Segundo CA 90245
| AddSig: |
| RemoveSig: |
| text: Space Missile Center, Launch Enterprise (SMC/LE) has determined that performance of this contract requires that the contractor, subcontractor(s), vendor(s), etc. (herein known as contractor), requires access to classified National Security Information (herein known as classified information). Classified information is Government information which requires protection in accordance with Executive Order 13526, Classified National Security Information, and supplementing directives. |
The Contractor shall abide by the requirements set forth in the DD Form 254, Contract Security Classification Specification, Included in the contract, and the National Industrial Security Program Operating Manual (NISPOM) for the protection of classified information at its cleared facility if applicable, as directed by the Defense Security Service.
Any firm or business under contract with the Air Force (AF), which requires access to classified information, will require a facility security clearance commensurate with the level of access required. Firms that do not possess a facility clearance, or the requisite level of facility clearance, will be sponsored for a Department of Defense facility clearance.
Personnel security- Contractor employees (to include applicant, temporaries, part-time and replacement employees) under the contract, needing access to sensitive but unclassified information and/or classified information must be U.S. Citizens and shall undergo a Security background Investigation. At a minimum requires a favorably adjudicated Tier-3 or Tier-3R investigation for those who access sensitive information and Tier-5/Tier-5R for those requiring TS/SCI. All background investigations will be processed through Defense Security Service and investigated by the Office of Personnel Management (OPM).
Visit Authorization Letter (VAL)/Visit Authorization Request (VAR)-The Contractor is required to submit a VAL/VAR for those individuals who require access to Controlled Unclassified Information (CUI) and classified information during performance on this contract. The VAL/VAR will be submitted via Joint Personnel Adjudication System (JPAS) to Security Management Office (SMO) code of LRSD. The VAL/VAR will be valid for a period not to exceed one year. If the requirements to access classified information no longer exists, or if access eligibility changes, SMC/LE Security will be notified immediately. The VAL/VAR must be submitted to SMC/LE Security in accordance with, and contain information as required by, Chapter 6 of the NISPOM.
Security Management- The contractor shall appoint a senior official to act as the Facility Security Officer. The individual will interface with SMC/LE security on all security matters, to include physical, personnel, industrial, information, program protection and cybersecurity and will protect all Government information and data accessed by the Contractor.
In the event classified information is inadvertently received by a contractor who does not hold an active security clearance at the appropriate level, a Government employee or Contractor with the appropriate security clearance equal to or higher than the classified information received, will take possession of the material and shall safeguard and store the information in accordance with standards set forth in the NISPOM. The inadvertent disclosure will be immediately reported to their supervisor and then to the designated SMC/LE Security Manager for action as appropriate.
The contractor shall protect Critical Program Information (CPI), technologies, security documents and systems as identified in the applicable Program Protection Plan (PPP) as well as identified in the contractor's Program Protection Implementation Plan (PPIP), as approved by the program office. Individual Space Vehicle classification guidance for launch services provided under this effort are contained in the following: (all of which have been transmitted to the contractor, and are available via SMC/LE)
- Current NSSL PPP and Security Classification Guide (SCG) any revisions
- Current NAVSTAR Global Positioning System Protection Guide and any revisions. Appendices A-E to SPG are not applicable to the NSSL contractor
- Current Protected MILSAT/Advanced Extremely High Frequency (AEHF) SCG
- Current NRO Launch Information Protection Guide (NRO Launch IPG)
- Current Wideband Global SATCOM (WGS) SCG
- Current SBIRS SCG
- Current DSP/SBIRS HEO Operations SCG
- Current Program Protection Plan (PPP) for SBIRS
- Current NSSL OPSEC Plans
Contract Completion Date: TBD
POC for collateral classified information is SMC/LE
7a. (Subcontractor): The prime contractor shall submit to SMC/CIO and the Program Office Government Contracting Authority (GCA) all DD254s for subcontractor(s) for review and approval prior to subcontractors having access to classified information. If this is an update to the DD254 of an existing contract, the Prime contractor will provide to the GCA a copy of DD254s issued to subcontractors supporting this effort. Subcontractors are not authorized access to classified information, COMSEC or NATO information/task on this contract until approved by GCA.
10e(1). SCI: See SCI addendum 4.0
10e(2). Non SCI: The contractor shall handle non-SCI or "collateral" intelligence information IAW Chapter 9, Section 3 of DoD 5220.22-M, National Industrial Security Program Operations Manual (NISPOM), DoDM 5200.01-V1-V3, Information Security Program and AFI 16-1404, Air Force Information Security.
10j. Controlled Unclassified Information: Controlled Unclassified Information (CUI) is the term which collectively refers to FOUO and Unclassified Controlled Nuclear Information (UCNI). CUI provided under this contract shall be managed and safeguarded IAW DoDM 5200.01, V4, Controlled Unclassified Information. UCNI is sensitive unclassified information subject to special handling as outlined in DoDD5210.83, DoD UNCI. The likelihood of your company coming in contact with UCNI is remote; however, if the situation does arise, employees will protect the information in the same manner as FOUO. Contact the company security office to obtain guidance from the cognizant security office.
11c. Receive, Store, and Generate Classified Material or material: The contractor requires access to collateral classified information. Any extracts must apply derivative classifications and markings consistent with the source documents. Use of "Multiple Sources" on the "Derived From" line necessitates compliance with the NISPOM, paragraph 4-208b.
11d. Fabricate, modify, or store classified Hardware: The Contractor is required to provide adequate storage for classified hardware up to and including the level of SECRET. If the hardware is such a size and/or quantity that it cannot be safeguarded in an approved storage container, use of an approved ‘Closed Area’ will be required. The Closed Areas need to meet the standards listed in the National Industrial Security Program Operating Manual (NISPOM Ch. 5). If there are no alarms, then the Closed Areas will have to be checked every 4 hours by contractor's security to ensure the integrity of the room.
11j. OPSEC: The contractor shall accomplish the following minimum requirements in support of the User Agency Operations Security (OPSEC) Program. If necessary, documents generated in response to DoDI 5200.39, Critical Program Information (CPI) Identification and Protection within Research, Development, Test and Evaluation (RDT&E), 28 May 2015, must comply with OPSEC measures if imposed by programs supported by the by the Government Agency .
OPSEC program shall be IAW DoDM 5205.2, dated 3 November 2008. Program OPSEC plans shall be coordinated with and approved by the User Agency and shall be imposed on subcontractors as appropriate. Program protection measures shall be approved by the User Agency and shall be applied at ALL locations where Critical Information is developed, produced, analyzed, maintained, transported, stored, tested, or used in training.” The contractor shall comply with the User Agency OPSEC Plan, and apply protective measures therein.
The contractor shall develop an OPSEC Plan in accordance with DoDM 5205.2. Include OPSEC as a part of their ongoing security awareness program conducted in accordance with Chapter 3, Section 1, of the National Industrial Security Operating Manual. Be responsive to the User Agency OPSEC Manager on a non-interference basis. Protect sensitive unclassified information and activities, which could compromise classified information or operations, or degrade the planning and execution of military operations performed by the contractor in support of the mission.
Sensitive unclassified information is that Information marked FOR OFFICIAL USE ONLY (FOUO), Privacy Act (PA) Of 1974, COMPANY PROPRIETARY, and as identified by the Air Force Program Office. Disposition of Critical Information, FOUO, and PA obtained or produced pursuant to this contract shall be shredded/degaussed to prevent reconstruction. Email transmission of Critical Information, FOUO, and PA obtained or produced pursuant to this contract will be encrypted or password protected. In addition, email containing FOUO and PA shall be marked in the subject line with (FOUO) or (PA). FOUO shall also be included at the beginning of the email with a non-disclosure statement.
11l. Receive, store, generate CUI : Protection of Unclassified DoD Information on Non-Government Information Systems: The Contractor must comply with the information safeguards as specified in DoDI 8582.01, Security of Unclassified DOD Information on Non-DOD Information Systems, CNSSP No. 18, National Policy on Classified Information Spillage, Chairman of The Joint Chiefs of Staff Instruction (CJCSI) 6510.01, Information Assurance and Support to Computer Network Defense (CND), and AF Manual 17-1301, Computer Security.
The Contractor shall comply with DFAR Clauses related to the Disclosure of Information (DFAR 252.204-7000), Safeguarding Covered Defense Information and Cyber Incident Report (DFARS 252.204-7012 and DFAR Subpart 204.73) for the protection of unclassified controlled technical information (UCTI).
In line with this clause, NIST SP 800-171 provides guidance for the protection of Controlled Unclassified Information (CUI) on non-federal information systems. Contractor shall apply security controls contained in NIST SP 800-171 for the protection of CUI on non-DoD information systems. CUI information will not be placed on publically accessible web sites.
Definitions:
Adequate Security – Security commensurate with the risk and the magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of information (see OMB Circular A-130). Current means of achieving adequate security for Information Technology is to use DoD, CNSS and NIST guidance (see CNSSI No. 4009).
Non-Sensitive Information – Information available in the public domain or DoD information that has been approved for public release
Sensitive Information – Information, the loss, misuse, or unauthorized access to or modification of, could adversely affect the national interest or the conduct of Federal programs, or the privacy to which individuals are entitled under Section 552a of title 5, United States Code, "The Privacy Act" but which has not been specifically authorized under criteria established by Executive order or an Act of Congress to be kept secret in the interest of national defense or foreign policy.
The terms Cybersecurity, Information Systems, and Information Technology, as used in this clause, are defined in Committee on National Security Systems Instruction 4009. Cybersecurity is further defined in DODI 8500.01 and is incorporated herein by reference:
Information systems (IS) shall be engineered and managed to protect and defend information and information systems from cybersecurity risks, including the risks to confidentiality, integrity, non- repudiation, and authorization in accordance with current DoD policies, procedures, and statutes, to include: National Security Act, Clinger-Cohen Act, Committee on National Security Systems Policy No. 11, National Institute on Standards and Technology Special Publications Federal Information Processing Standards, DoD Instruction 8500.01, Cybersecurity, DoDI 8581.01, IA Policy for Space Systems Used by the DoD , NISPOM Defense Security Service, Industrial Security Field Operations (ISFO), Assessment and Authorization Manual.
11m. (Other): SIPRNET access for Visitor Groups - The government will provide SIPRNET access to include e-mail and web browser. Contractors shall be held accountable for actions they initiate on the network and shall conduct business IAW USAF, SMC, and LAAFB instructions and policies. Sponsoring Government Contracting Activity (GCA) shall provide Cyber Security training prior to contractor access to SIPRNet services.
Access to government IS - Include these instructions if an on-base contractor will require access to government IS. The Contractor will require access to government systems to perform their contractual duties. Contractors requiring access to government systems must meet the requirements contained in Air Force Manual (AFI) 17-100, Air Force Information Technology (IT) Service Management, and all installation requirements.
Security Incident Reporting: In addition to the reporting requirements directed by the NISPOM, the contractor shall provide a concurrent report of loss or compromise of classified information to the cognizant Government Contracting Activity (GCA), Government Information System Security Manager (ISSM), and Government Security Manager.
Have Export Control Requirements : Technology Transfer and Information Control and Arms Export Control: By law, the U.S. Government and contractors must comply with the provisions of the International Traffic in Arms Regulations (ITAR) and the Arms Control Act before exporting defense articles, technical data, or defense services controlled by the ITAR. Such information that has been provided to the contractor by the Government for purposes of this contract and are intended for public release, or disclosure to any foreign person or U.S. person residing in a foreign country shall be submitted to SMC/LEE for processing through SMC/CIO Foreign Disclosure Office (FDO), through the appropriate Foreign Disclosure Focal Point (FCFP), for potential technology transfer and suitability for the release of technical information. Information that is subject to ITAR and not provided to the contractor by the Government for purposes of this contract shall be subject to the applicable export license from the U.S. Department of State.
Unauthorized Disclosure: Government and contractor personnel must act to protect Technical Program design, development, or manufacturing data under their control from unauthorized disclosure to any foreign person or a U.S. person residing in a foreign country. Government and contractor organization must inform the U.S. State Department under the provision of the ITAR regarding any unauthorized disclosure.
Visitor Group Security Agreement;
For activities at the Air Force installations identified in ITEM 8, the contractor is required by the host agency to enter into a VGSA in accordance with Air Force Instruction 31-601, Industrial Security and Air Force Instruction 31-101, Integrated Defense. The VGSA is executed with the contractor who requires or will have access to classified information or to sensitive unclassified information. The VGSA must address those security requirements and/or procedures that are unique to the installation for which the contractor will be held contractually liable.
| attachmentsList: |
| AddAttachment: |
| ViewAttachment: |
| RemoveAttachment: |
| rep: Marlene R. Torres, SMC/LEES |
Chief of Security
| Sig: |
| Enter your name here.: See SCI addendum. Contractor will require SIPRNET and JWICS access. |
| Enter your name here.: The Defense Security Service is relieved of security inspection responsibility for contract activities performed on military installations; the |
program office directorate and applicable location specific security offices will retain security cognizance over contractor operations located on military department installations/jurisdiction. See SCI addendum V4 for additional guidance.
For collateral:
The Defense Security Service is relieved of security inspection responsibility for contracts on government installations. The Commander retains cognizance over contracts on the installation. SMC/CIO staff is designated as member of the Wing Inspection Team and has inspection authority when assigned under SMC/IG.
| GCAName: SMC/ECLK |
| AAC: FA8811 |
| AAC: FA8811 |
| Address: 483 N. Aviation Blvd |
El Segundo, CA 90245 Address: 483 N. Aviation Blvd El Segundo, CA 90245
| POCName: Capt Ashley Cunningham |
| Phone: 3106533537 |
| Phone: 3106533537 |
| Email: ashley.cunningham.4@us.af.mil |
| Email: ashley.cunningham.4@us.af.mil |
| Title: Procurement Contracting Officer |
| Enter the date using the format DD-Mon-YYYY: |
File details come from the government source that posted it. Updated .