Attachment_2_-_DD_Form_254.pdf
PDF 875 KB Posted
- Attached to
- Test Operations and Support Federal contract opportunity
- Solicitation number
- FA9101-13-R-0100
About this file
Attachment 2 DD Form 254 Contract Security Classification Specification
View the file
Other files for this federal contract opportunity
Show all 50
Test Operations and Support has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Solicitation No. FA9101-13-R-0100 DD 254 – Contract Security Classification Specification Form Continuation
Test Operation and Sustainment-Solicitation
Reference Block 13:
International Security Requirements: Contract performance/tasking could require contact and involvement with foreign nationals and/or their representatives. Contractor must comply with export control laws, the NISPOM and any clauses in the contract and Statement of Work (SOW)/Performance Work Statement (PWS)
Additional security classification guidance will be provided, maintained and used by the contractor as required. Security classification guidance on information, hardware and equipment not included in security classification guides will be furnished to the contractor through the Administrative Contracting Officer (ACO) or authorized representative at the time the contractor is furnished information, hardware and equipment or when classification changes occur.
The Contractor shall accomplish all Information Assurance tasks identified in; AFPD 33-2, Information Assurance Program, and AFI 33-200, Information Assurance (IA) Management to include all tasks and directives identified therein including, but not limited to; AFSSI 300 Series
- COMSEC Equipment, AFSSI 400 Series - COMSEC Operation, AFSSI 700 Series EMSEC, and 8500 Series - IA Implementation, or their replacements. National and DoD level documents shall be used as mandatory directives in lieu of, or in addition to AF directives, as appropriate.
Reference Block 8.a.: Additionally, the prime contractor will support efforts at locations identified through other legal binding agreements such as but not limited to Letter Contracts, Technology Investment Agreements (TIA), and Statements of Capability (SOC) as determined necessary by AEDC Contracting Officer Representatives (COR) or Government Contracting Agencies (GCA).
Reference Block 10.a.: COMSEC material/information may not be released to DoD contractors without Air Force Cryptological Support Center (AFCSC) approval. Contractor must forward requests for COMSEC material/information to the COMSEC officer through the program office.
The contractor is governed by the DoD 5220.22-S COMSEC Supplement to the NISPOM in the control and protection of COMSEC material/information. Access to COMSEC material by personnel is restricted to U.S. citizens holding final U.S. Government clearances. Such information is not releasable to personnel holding only reciprocal clearances. See attachment 2.
Reference Block 10.b.: Access to RESTRICTED DATA requires a final U.S. Government clearance at the appropriate level.
Reference Block 10.c.: This contractor is permitted access to Critical Nuclear Weapons Design Information (CNWDI) in performance of this contract. The government program manager or designated representative will ensure the FSO is briefed for CNWDI.
Reference Block 10.d.: Access to FORMERLY RESTRICTED DATA requires a final U.S.
Government clearance at the appropriate level.
Reference Block 10.e.(1).: Contractor will require access to Director of Central Intelligence Directives (DCID’s) 1/7, 1/19, 6/6 and 6/1. See attachment 3.
Test Operation and Sustainment-Solicitation
Reference Block 10.e.(2).: Contractor will require AFI 14-302 (DCID 6/6) and AFI 14-303.
See attachment 5.
Reference Block 10.f.: Specific programs and SCGs for Special Access Programs (SAPs) and Special Access Requirement (SAR) programs supported under this contract are not listed in the DD 254; however the contractor may require access to SAP/SAR material from various programs. The AEDC OPR for special access required SCGs is AEDC/TST-OGV. The Joint Air Force, Army and Navy (JAFAN) Manual 6/0, SAP Security Manual Revision 1 is the authoritative SAP security manual and /or applicable SCGs along with other applicable DoD guidance as specified by AFOSI/PJ Program Security Officer (PSO) applies to this contract for special access requirements. All such SAP programs are carved out from DSS cognizance and may require additional clearances, investigations, document markings and other security requirements which may differ from those specified in DoD 5220.22-M/DoD 5200.1R. All classified automated information system processing will be conducted in accordance with JAFAN 6/3. JAFAN 6/9 will serve as the baseline for Physical Security of SAP facilities.
JAFAN 6/4 will serve as the baseline for the SAP Tier Review process. The contractor will keep a current list showing the location of containers, rooms and completely dedicated buildings that contain SAP program material carved out from DSS cognizance. The contractor will provide a copy of the list to the AFOSI/PJ PSO prior to subcontracting any portion of a SAR activity to include both classified and unclassified.
Reference Block 10.g.: The North Atlantic Treaty Organization (NATO) program will be managed, if needed, in accordance with DoDD 5100.55, United States Security Authority for North Atlantic Treaty Organization Affairs, (USSAN), USSAN 1-69, Implementation of NATO Security Procedures and AFI 31-406, Applying North Atlantic Treaty Organization (NATO) Protection Standards. Special briefings are required for access to NATO. Prior approval of the contracting activity is required for subcontracting. Access to classified NATO information requires a final U.S. Government clearance at the appropriate level and signature on AF Form 2583 on file.
Reference Block 10.h.: Foreign Government Information: Prior approval of the contracting activity is required for subcontracting. Access requires a final U.S. Government clearance at the appropriate level.
Reference Block 10.j.: For Official Use Only (FOUO) information provided under this contract shall be safeguarded as specified in DoDM 5200.01-V4, DoD Information Security Program:
Controlled Unclassified Information. Sensitive information is information that if lost, misused, compromised or accessed by unauthorized personnel could adversely affect U.S. national interest, the conduct of DoD programs, or the privacy of DoD personnel. It comes in many forms; personal data under the Privacy Act, personnel records, privileged data (chaplain and judge advocate records), investigative data, scientific and technical information (STINFO), export controlled data (critical technologies), proprietary data, or FOUO data. Sensitive information meets the criteria for exemption from mandatory public disclosure under the Freedom of Information Act (FOIA). Contractor shall comply with DoD 5400.7-R, Chapter 4 (FOIA). Sensitive information must be protected. During working hours, reasonable steps
Test Operation and Sustainment-Solicitation should be taken to minimize risk of access by unauthorized personnel. After working hours, sensitive information can be stored in unlocked containers, desks or cabinets if Government or Government-contract building security is provided. If Government or Government-contract building security is not provided after working hours, sensitive information shall be stored in locked desks, file cabinet, book cases, locked rooms, or similar items. Stored in a safe designed to secure classified information is not required. Sensitive records may be destroyed by any method that will prevent disclosure of contents or reconstruction of document. For paper items, cross-cut shredding is recommended. See attachment 6.
Reference Block 10.k.: Controlled Unclassified Information/Export Control:
Controlled Unclassified Information: Information which is exempt from public disclosure per DoDM 5200.01 Volume 4, and which is NOT releasable to foreign nationals. As instructed upon receipt of Contractor Defense Logistics Information Service (DLIS) Certification via Form DD Form 2345 or in accordance with the DoD Directives referenced above, the following handling requirements must be followed to protect this information, which is the property of the U.S.
Government. Protection requirements apply to entire documents or to extracted portions, to include electronic files (extracted materials must also be appropriately marked): a. PUBLIC RELEASE: withhold from public disclosure, b. AUTHORIZED RELEASE: release only to organizations authorized in the applicable Distribution Statement, c. CONTRACTOR ACCESS:
if contractors are authorized for access via the Distribution Statement, releasing activities must first ensure that the contractor has a valid DLIS certification on file. Distribution Limited materials should be released to (and, if mailed, addressed to) the “Contact” identified on the DLIS Certification Form DD2345 for contractor organizations. Contact DLIS at 1-800-352- 3572 or http://www.dlis.dla.mil/jcp/, d. EXPORT CONTROL: materials that are Distribution Limited can also export controlled. If so, an Export Control Warning Notice must be applied to affected materials, e. FOREIGN NATIONALS: do NOT release Distribution Limited materials to foreign nationals, f. ELECTRONIC TRANSFER: when transferring information electronically (to include Internet and telephone), use ONLY secure methods, (i.e., approved hardware or software encryption), g. MAILING OR SHIPPING: when mailing or shipping, do NOT reveal sensitivity of contents on outer wrapper, h. STORAGE DURING WORK HOURS:
store in out-of-sight location during working hours when unattended, i. STORAGE DURING NON-WORK HOURS: store in locked building, room, desk, file cabinet, etc. during non-working hours to prevent unauthorized access, j. NETWORK OR PC STORAGE: establish access-protected server shares if stored on networks (no PC hard drive storage unless PC is completely standalone); no foreign national access is authorized, to include system administrators, outsourced data services, etc., k. NETWORK PRINTERS: use of network printers requires immediate retrieval of printed material to ensure unauthorized access does not occur, l. MARKINGS: mark all derivatively created materials/information/media per the original markings, m. COPIES: all copies made of original materials must be marked - no waste or overruns left on copier equipment or printers, n. DESTRUCTION: to destroy, tear/shred into pieces and separate sufficiently to prevent reconstruction of the material and disclosure of contents, then place in regular trash or recycle receptacles, o. RETENTION: all information is to be destroyed upon completion of Official use unless authorized in writing otherwise, p.
COMPUTER MEDIA: mark computer media as it is created per original materials.
Test Operation and Sustainment-Solicitation
Export Control: Any item, technical data, or software furnished by the government in connection with this contract is supplied for use in the United States only. Contractor agrees to comply with all applicable U.S. Export Control laws and regulations, specifically including, but not limited to, the requirements of the Arms Export Control Act, 22 USC 2751 - 2794, including the International Traffic in Arms Regulation (ITAR), 22 CFR 120 - 130; the Export Administration Act, 50 USC app. 2401 - 2420, including the Export Administration Regulations (EAR), 15 CFR 730 - 774; the Atomic Energy Act of 1954 (AEA), as amended; and including the requirement for obtaining any export license or agreement, if applicable. Without limiting the foregoing, Contractor agrees that it will not transfer any Export Controlled item, data, or services, to include transfer to foreign persons employed by or associated with, or under contract to Contractor or Contractor's lower-tier suppliers, without the authority of an export license, agreement, or applicable exemption or exception. Contractor shall immediately notify the Government Contracting Agency (GCA) and Servicing Security Activity (SSA) if it transfers any Export Controlled item, data, or services to foreign persons. Diversion contrary to U.S.
export laws and regulations is prohibited.
Contractor shall immediately notify the GCA and the SSA if Contractor is, or becomes, listed in any Denied Parties List or if Contractor's export privileges are otherwise denied, suspended or revoked in whole or in part by any U.S. Government entity or agency.
If Contractor is engaged in the business of either exporting or manufacturing (whether exporting or not) defense articles or furnishing defense services, Contractor represents that it is registered with the Directorate of Defense Trade Controls, as required by the ITAR, and it maintains an effective export/import compliance program IAW the ITAR. The Contractor shall flow down the requirements of this clause to all subcontracts.
Reference Block 11.c.: The contractor requires access and storage up to TOP SECRET. Any extracts or use of such data requires the contractor to apply derivative classifications and markings consistent with the source documents and Executive Order 13526. Use of “Multiple Sources” on the “Derived From” line necessitates compliance with Executive Order 13526, NISPOM paragraph 4-208, and use of bibliography. Classification, declassification, and markings will be in accordance with EO 13526 and Information Security Oversight Office (ISOO) Implementation Directive entitled “Classified National Security Information Directive No. 1”, effective 25 Jun 10.
Reference Block 11.d.: Contractor may be required to fabricate, modify or store classified hardware up to TOP SECRET level that exceeds two cubic feet.
Reference Block 11.g.: The contractor is authorized to use the services of Defense Technical Information Center (DTIC) and is required to prepare and process a DD Form 1540, (Registration for Scientific and Technical Information Services) IAW the NISPOM. The GCA must be involved in certifying need-to-know to DTIC.
Reference Block 11.h.: Coordinate with PM for COMSEC accounts. See attachment 2.
Test Operation and Sustainment-Solicitation
Reference Block 11.i.: Contractors are required to comply with EMSEC (TEMPEST) requirements according to AFI 33-203. Contractor shall not implement specific EMSEC countermeasures nor shall they impose any EMSEC requirements on a subcontractor without prior approval of the GCA. See attachment 2.
Reference Block 11.j.: The contractor will follow OPSEC Program guidelines established in published plans. Coordinate with the Program/Project Manager to obtain copies of applicable plans and critical information list. The contractor will maintain an OPSEC program designed to continually educate all personnel, to include sub-contractors, on the AEDC OPSEC Plans and Critical Information Lists at least annually and upon request. See attachment 7.
Reference Block 11.k.: This contract requires the use of the Defense Courier Service. The GCA will request DCS services from the Commander, Defense Courier Service, ATTN:
Operations Division, Fort George G. Meade, MD 20755-5370.
Reference Block 11.l.: Contract may require access to sensitive unclassified government automated information systems (AIS) in categories IT-I, II, and III. As a minimum contractor employees must be the subject of a favorable Single Scope Background Investigation (SSIB) if granted access and performing in a category IT-I positions. As a minimum contractor personnel if granted access and performing in categories IT-II and III positions must be the subjects of a favorable National Agency check with Inquires (NACI). In the event the investigation is not adjudicated favorably unit commanders are responsible for suitability determinations. Reference AFI 31-501, and AFMC Sup 1, both publications can be found at http://www.e-publishing.af.mil.
Classified Automated Information systems (AIS) and Secret Internet Protocol Routable Network (SIPRNET). Any transfer or processing of classified or sensitive information via electronic methods (e.g., facsimile, telemetry, voice, and computer) must be protected by implementing an appropriate combination of countermeasures such as encryption devices and sound practices and procedures. For performance on AEDC the specific countermeasures used must be coordinated by the PM for approval.
Reference Block 12.: AF/XOIIS Washington DC 20330. No public release of Special Access Required (SAR) or SAR related material, regardless of classification, is authorized without approval from SAF/AQ through AFOSI/PJ.
Reference Block 14.: and copies of the DD Form 254 and Statement of work. See attached SCI and non-SCI Release of Intelligence Information for additional security requirements. Prior approval of the contracting activity is required for subcontracting. Access to intelligence information requires special briefings and a final U.S. Government clearance at the appropriate level.
The contractor will advise the SCI Contractor Monitor immediately upon reassignment of personnel to other duties not associated with this contract. Release of SCI documentation or other material concerning this contract will not be discussed with or released to any individual, subcontractor, agency (including Federal Government Agencies and employees), and contractor employees not working on this contract without prior approval from the COR. SCI data released to or generated by the contractor in support of this contract remains the property of the DoD
Test Operation and Sustainment-Solicitation
Department, agency and command that released it. The contractor will maintain a record of all SCI material released to his custody under this contract and upon completion/cancellation of the contract shall return material to the COR identified in Item 16a or document the proper destruction IAW applicable regulations/guidance. CSSO must coordinate with the COR prior to the subcontracting of any portion of the SCI effort involved in this contract. A separate DD Form 254 for the contractor shall be processed and approved and separate subcontractor billets shall be coordinated with the COR and the applicable SSO. The contractor will not use references to SCI accessed obtained under this contract (even by unclassified acronyms) in advertising, promotion efforts or in the recruitment of employees.
The Contractor shall establish and maintain an access list of all employees working on this contract. A copy of this list will be furnished to the SSA quarterly. The list should be categorized by company and total number of employees, number of employees working on classified contracts, number of NISPOM Visitor Groups, number of resident contractors working on unclassified efforts. Foreign contractors are not allowed to perform work under this contract.
Foreign contractors are not allowed to perform work under this contract.
When the contractor, in performance of the work under this contract, shall find that the requirements of any of the clauses of the contract are in conflict with security instructions issued to the contractor, the contractor shall call this to the attention of the SSA. The CO, or their duty authorized representative for security matters, shall: (1) Modify or rescind such security requirements, or (2) Issue to the contractor written instructions concerning compliance with the requirements of the clauses or provisions conflicting with such security requirements. Any wavier of compliance with the clauses or provisions of this contract issued by the SSA shall be in writing and approved in advanced. In the event a conflict occurs between various security manuals, the contractor will utilize the most restrictive guidance and immediately refer the matter to the cognizant security officer for resolution.
If and as required visitor group contractors are required to enter into a security agreement with the base Information Security Program Manager. Provide the information requested by the Notification of Government Security Activity Clause. AFFARS 5352.204.9000 and Visitor Group Security Agreement Clause, AFFARS 5352.204.9001 to the Servicing Security Activity
(SSA).
Test Operation and Sustainment-Solicitation
Attachment 1 to DD Form 254, COORDINATION
Coordinated by:
AEDC/TSD-IP
(Industrial Security) ___________________________________ ____________
AEDC/TSDIA ___________________________________ ____________
AEDC/TSDI ___________________________________ ____________
AEDC/XP2 (SSO) ___________________________________ ____________
AFOSI/PJ, PSO ___________________________________ ____________
FSO ___________________________________ ____________
AF Program/Project Manager ___________________________________ ____________
Chief, Information Protection ___________________________________ ____________
AEDC Government Security POCs:
Information Protection Office AEDC/TSD-IP 100 Kindle Drive, Suite B203
Arnold AFB TN 37389
Special Security Officer (SSO) AEDC/XP2
251 First Street Arnold AFB TN 37389
Computer Security/COMSEC AEDC/TSDI
100 Kindel Drive
Program/Project Manager AEDC/
Contract Monitor: AFTC/PZZ (Arnold)
100 Kindel Drive, Suite A-337
(Insert ACO’s Name) Date Administrative Contracting Officer
Attachment 2 to DD Form 254, COMSEC/EMSEC SECURITY (AKA TEMPEST)
COMSEC ACCESS AND/OR ACCOUNT
1. The contractor will establish a COMSEC Account with 11th Wing, Communications Squadron (CS), and Bolling AFB, Washington DC 20330.
2. The contractor is governed by AFKAG-I, AFKAG-2, and appropriate Air Force Systems Security Instructions/Manuals (AFSSI/AFSSM) or Air Force Instructions (AFI). Access to COMSEC material or information is restricted to US citizens holding final U.S. Government clearances and is not releasable to personnel holding only a reciprocal clearance. Personnel requiring COMSEC access shall be briefed in accordance with AFI 33-201, Vol 2 (COMSEC User Requirements). NOTE: The COMSEC briefing applies only to the use and control of cryptographic equipment and specialized COMSEC publications. NACSIM/NACSEM documents are not considered COMSEC material.
3. Contractors with access to “Secret Crypto” or higher levels must be briefed into the Cryptographic Access Program via the AFCOMSEC Form 9, Cryptographic Access Certificate, IAW AFI 33-201, Vol. 4. Contractors must be familiar and comply with the following publications--as applicable--AFI 33-201 Vol. 1, Communications Security; Vol. 2, COMSEC User Requirements; Vol. 3, Reporting COMSEC Deviations; Vol. 4, Cryptographic Access Program;
Vol. 5, Controlled Cryptographic Information (CCI); Vol. 9, Operational Instruction for Secure Voice Devices, and any applicable AF Systems Security Instructions (AFSSIs) that provide additional guidance for cryptographic equipment/CCIs held/keyed. Current AFSSIs may be obtained from your servicing base COMSEC manager.
4. Additionally, cryptographic information/equipment shall be retained in a contractor facility user COMSEC account in accordance with current guidelines.
5. The Air Force program/project manager shall designate the number of personnel requiring COMSEC access. The number will be limited to the minimum necessary and will be on a strict need-to-know basis.
6. When COMSEC support, including secure phone or other secure voice capabilities, is provided by an AF COMSEC Account, the contractor must comply with AFI 33-201, Vol 2 and Vol 9.
7. Contractors are not authorized to receipt for material transferred from CONUS contractor COMSEC accounts; COMSEC material support must come from the servicing base COMSEC manager.
8. Contractors must comply with all instructions provided by the servicing COMSEC manager and must maintain current training to access COMSEC material/information. Additionally, all contractors must immediately report any known or suspected deviations to their COMSEC Responsible Office or COMSEC manager for evaluation and up-channel reporting, if required.
9. Contact your servicing COMSEC manager at AEDC for additional assistance.
EMSEC SECURITY (AKA TEMPEST)
1. The contractor shall ensure that emissions security (EMSEC) conditions related to this contract are minimized.
2. Contractors located and performing off government installations and not connected to classified government networks must have their Information Systems (IS) accredited in accordance with the National Industrial Security Program Operating Manual (NISPOM), Chapter 8 by Defense Security Service (DSS) representatives. Classified processing shall not begin until specific written approval/authorization has been received from DSS.
3. Government furnished or contractor owned Information Systems operated by contractors on government installations will be accredited by the local government Designated Approval Authority (DAA). When government furnished or contractor owned Information Systems (IS) are used on government installations EMSEC aka TEMPEST countermeasures will be applied by the government supporting activity. Classified processing shall not begin until accreditation is completed by appropriate government personnel.
4. Contractor is required to provide copies of the written approval/authorization to appropriate government personnel upon request.
5. Problems encountered in obtaining the written approval/authorization for classified processing should be brought to the attention of the Government Contracting Activity (GCA) and Government Program Manager.
6. Use of any telecommunications system or device to include, but not limited to; cellular phones, hand-held radios, beepers/pagers, cordless telephones, cordless microphones, facsimile machines and computers constitutes consent to monitoring in accordance with AFI 33-219.
Test Operation and Sustainment-Solicitation
Attachment 3 to DD Form 254, RELEASE OF SENSITIVE COMPARTMENTED
INFORMATION (SCI) INTELLIGENCE INFORMATION TO U.S. CONTRACTORS
NUMBER OF SCI BILLETS AUTHORIZED: X
Contract Expiration Date: DD MM YYYY
1. Requirements for access to SCI:
a. All SCI will be handled in accordance with special security requirements, which will be furnished by the AEDC/XP2 Special Security Office. Specific security directives are provided in the DD 254 SCI addendum.
b. SCI will not be released to contractor employees without specific release approval of the originator of the material as outlined in governing directives and prior approval and certification of “need-to-know” by the designated Contracting Officer’s Representative
(COR).
c. Names of contracting personnel requiring access to SCI will be submitted to the COR for approval (the COR is identified on the DD Form 254 SCI Addendum). Upon receipt of written approval from the COR, the company security officer will submit request(s) for special background investigations in accordance with the NISPOM.
d. Inquiries pertaining to classification guidance on SCI will be directed through the CSSO to the COR.
e. SCI furnished in support of this contract remains the property of the Department of Defense (DoD) department, agency, or command originator. Upon completion or cancellation of the contract, SCI furnished will be returned to the direct custody of AEDC/XP2 Special Security Office, or destroyed IAW instructions outlined by the CM.
f. SCI will be stored and maintained only in properly accredited SCI facilities.
2. The Contracting Officer’s Representative (COR) will:
a. Monitor the day to day activities of the DoD SCI contracts and serve as a technical representative. The COR serves as a point of contact for the contractor security officer and the AEDC/XP2 Special Security Office.
b. Review the SCI product for contract applicability and determine that the product is required by the contractor to complete contractual obligations. Originator release authority is required on the product types below:
1) Documents bearing the control markings of ORCON, PROPIN.
2) GAMMA controlled documents
3) Any NSA/Special marked products
4) All categories as listed in DoD 5105.21-M-1
b. Prepare or review contractor billet/access requests to insure satisfactory justification (need-to-know) and completeness of required information.
c. Approve and coordinate visits for contractor employees through the AEDC/XP2 Special Security Office when such visits are conducted as part or the contract effort.
d. Maintain records of all SCI material provided to the contractor in support of the contract effort. By 15 January (Annually), provide the contractor, for inventory purposes, with a complete list of all documents transferred by contract number, organizational control number, copy number, and document title.
e. Determine dissemination of SCI studies or materials originated or developed by the contractor.
f. Within 30 days after completion of contract, provide written disposition instructions for all SCI material furnished to, or generated by, the contractor with an information copy to the AEDC/XP2 Special Security Office.
g. Review and forward all contractor requests to process SCI electronically to the AEDC/XP2 Special Security Office for coordination through appropriate SCI channels.
3. Requests for release of intelligence material to a contractor must be prepared by the COR and submitted to the AEDC/XP2 Special Security Office. This should be accomplished as soon as possible after the contract has been awarded. The request will be prepared and accompanied with a letter explaining the requirement and copies of the DD Form 254 and Statement of Work.
Test Operation and Sustainment-Solicitation
Attachment 4 to DD Form 254, SAMPLE SCI BILLET JUSTIFICATION
MEMORANDUM
MEMORANDUM TO AEDC/XP2 Special Security Office
FROM: (ORGANIZATION REQUESTING BILLETS/COR)
SUBJECT: Contractor SCI Billet Request
1. Request the following contractor SCI Billet(s) be approved for SCI access.
2. Contract information:
a. Proposed Number of Billets:
b. Name and Address of Company:
c. Location of Facilities where work is to be performed:
d. Contract number:
e. Date services start:
f. Date contract expires:
3. Specific location where work is to be performed:
4. Facility Security Officer/Contractor Special Security Officer: (Name and contact information)
5. Contract Officer Representative (COR): (Name and contact information)
6. Justification and need-to-know: (Must include the following information)
a. Description of position requiring access. (If positions are different, submit a justification for each position.)
b. Level of SCI access required: (identify required compartment access)
7. Detailed justification of why SCI information is needed to support the contract. (The justification for access will specifically identify the type of SCI data required, why the job cannot be performed without SCI and how the individual will use the information per DoD 5105.21-M- 1, Para E.1)
8. The DD Form 254 has been approved by AEDC/XP2 Special Security Office.
Must be signed by the Contractor Special Security Officer/Special Security Representative AND Endorsed by the AEDC Contracting Officer Representative.
Test Operation and Sustainment-Solicitation
Attachment 5 to DD Form 254, RELEASE OF NON-SENSITIVE COMPARTMENTED
INFORMATION (NON-SCI) INTELLIGENCE INFORMATION TO U.S.
CONTRACTORS
1. Requirements for access to non-SCI:
a. All intelligence material release to the contractor remains the property of the US Government and may be withdrawn at any time. Contractors must maintain accountability for all classified intelligence released into their custody.
b. The contractor must not reproduce intelligence material without the written permission of the originating agency though the AEDC/XP2 Special Security Office. If permission is granted, each copy shall be controlled in the same manner as the original.
c. The contractor must not destroy any intelligence material without advance approval or as specified by the COR or the AEDC/XP2 Special Security Office. (EXCEPTION: Classified waste shall be destroyed as soon as practicable in accordance with the provisions of the Industrial Security Program).
d. The contractor must restrict access to only those individuals who possess the necessary security clearance and who are actually providing services under the contract with a valid need to know. Further dissemination to other contractors, sub-contractors, other government agencies, private individuals or organizations is prohibited unless authorized in writing by the originating agency through the COR.
e. The contractor must ensure each employee having access to intelligence material is fully aware of the special security requirements for this material and shall maintain records in a manner that will permit the contractor to furnish, on demand, the names of individuals who have had access to this material in their custody.
f. Intelligence material must not be released to foreign nationals or immigrant aliens whether or not they are consultants, US contractors, or employees of the contractor and regardless of the level of their security clearance, except with advance written permission from the originator. Requests for release to foreign nationals shall be initially forwarded to the COR and shall include:
1) A copy of the proposed disclosure.
2) Full justification reflecting the benefits to US interests.
3) Name, nationality, particulars of clearance, and current access authorization of each proposed foreign national recipient.
g. Upon completion or termination of the classified contract, or sooner when the purpose of release has been served, the contractor will return all intelligence (furnished or generated) to the source from which received unless retention or other disposition instructions (see AFMAN 37-139) are authorized in writing by the CM.
Test Operation and Sustainment-Solicitation
h. The contractor must designate an individual who is working on the contract as custodian.
The designated custodian shall be responsible for receipting and accounting for all classified intelligence material received under this contract. This does not mean that the custodian must personally sign for all classified material. The inner wrapper of all classified material dispatched should be marked for the attention of a designated custodian and must not be opened by anyone not working directly on the contract.
i. Within 30 days after the final product is received and accepted by the procuring agency, classified intelligence materials released to or generated by the contractor, must be returned to the originating agency through the AEDC/XP2 Special Security Office unless written instructions authorizing destruction or retention are issued. Requests to retain material shall be directed to the COR for this contract in writing and must clearly indicate the justification for retention and identity of the specific document to be retained.
j. Classification, regrading, or declassification markings of documentation produced by the contractor shall be consistent with that applied to the information or documentation from which the new document was prepared. If a compilation of information or a complete analysis of a subject appears to require a security classification other than that of the source documentation, the contractor shall assign the tentative security classification and request instructions from the COR. Pending final determination, the material shall be safeguarded as required for its assigned or proposed classification, whichever is higher, until the classification, is changed or otherwise verified.
2. Intelligence material carries special markings. The following is a list of the authorized control markings of intelligence material:
a. “Dissemination and Extraction of Information Controlled by Originator (ORCON).” This marking is used, with a security classification, to enable a continuing knowledge and supervision by the originator of the use made of the information involved. This marking may be used on intelligence that clearly identifies, or would reasonably permit ready identification of an intelligence source or method, which is particularly susceptible to countermeasures that would nullify or measurably reduce its effectiveness. This marking may not be used when an item or information will reasonably be protected by the use of other markings specified herein, or by the application of the “need to know” principle and the safeguarding procedures of the security classification system.
b. “Authorized for Release to (name of Country (ies)/International Organization)” The above is abbreviated “REL TO ______.” This marking must be used when it is necessary to identify classified intelligence material the US government originator has predetermined to be releasable or has been released through established foreign disclosure channels to the indicated country (ies) or organization.
c. “NOT RELEASABLE TO FOREIGN NATIONALS-NOFORN (NF).” This marking is used to identify intelligence which an originator has determined falls under the criteria of DCID 6/7, “Intelligence Disclosure Policy,” and may not be provided in any form to foreign
Test Operation and Sustainment-Solicitation governments, international organizations, coalition partners, foreign nationals, or immigrant aliens without originator approval.
3. The following procedures govern the use of control markings.
a. Any recipient desiring to use intelligence in a manner contrary to restrictions established by the control marking set forth above shall obtain the advance permission of the originating agency through the COR. Such permission applies only to the specific purposes agreed to by the originator and does not automatically apply to all recipients. Originators shall ensure that prompt consideration is given to recipients requests in these regards, with particular attention to reviewing and editing, if necessary, sanitized or paraphrased versions to derive a text suitable for release subject to lesser or no control markings.
b. The control markings authorized above shall be shown on the title page, front cover, and other applicable pages of documents, incorporated in the text of electrical communications, shown on graphics and associated (in full or abbreviated form) with data stored or processed in automatic data processing systems. The control marking also shall be indicated by parenthetical use of the marking abbreviations at the beginning or end of the appropriate portions. If the control marking applies to several or all portions, the document must be marked with a statement to this effect rather than marking each section individually.
c. The control markings shall be individually assigned at the time of preparation of intelligence products and used in conjunction with security classifications and other marking specified by E.O. 12958 and it’s implementing security directives. The marking shall be carried forward to any new format in which the same information is incorporated including oral and visual presentations.
4. Request for release of intelligence information must be prepared by the COR and submitted to AEDC/XP2 Special Security Office. This should be accomplished as soon as possible after the contract has been awarded. The request will be prepared and accompanied with a letter explaining the requirements and copies of the DD Form 254 and Statement of Work.
Attachment 6 to DD Form 254, FOR OFFICIAL USE ONLY (FOUO)
FOUO is information that has not been given a security classification pursuant to the criteria of an Executive Order, but which may be withheld from the public because disclosure would cause a foreseeable harm to an interest protected by one or more Freedom of Information Act (FOIA) exemptions 2 through 9 [Ref: DoD 5400.7, Air Force Supplement, Chapter 4]. The following procedures will be used to protect FOR OFFICIAL USE ONLY (FOUO) material:
1. HANDLING: Access to FOUO material shall be limited to those employees needing the material to do their jobs. The FOUO marking is assigned to material created by a DoD user agency. FOUO is not a classification, but requires extra precaution to ensure it is not released to the public.
2. MARKING: Mark unclassified documents containing FOUO; “FOR OFFICIAL USE ONLY” at the bottom of each page and back cover (if any).
a. Do not apply FOUO labels to material that:
1) Is public domain, such as textbook or catalog information.
2) Has already been assigned a DoD distribution statement.
3) Is commercially owned.
b. In a classified document:
1) Mark individual paragraph that contains FOUO, but not classified material by placing “FOUO” at the beginning of the paragraph.
2) Mark top and bottom of each page that has both FOUO and classified material with the highest security classification of the material on that page.
3) Mark “FOUO” at the bottom of each page that has FOUO but not classified material.
4) If a classified document also contains FOUO material or if the classified material becomes FOUO when declassified, place the following statement on the bottom of the cover or the first page under the classification marking: “NOTE: If declassified, review the document to make sure material is not FOUO and not exempt under AFI 37-131 before public release.”
5) Mark other records such as computer print outs, photographs, films, tapes, or slides “FOR OFFICIAL USE ONLY” so the receiver or viewer knows the record contains FOUO material.
6) Mark each part of a message that contains FOUO material. Unclassified messages containing FOUO material must show the abbreviation “FOUO” before the text begins.
7) Ensure documents that transmit FOUO material call attention to any FOUO attachments.
8) FOUO material released to a contractor by a DoD user agency must have the following statement on the front page or cover: “THIS DOCUMENT CONTAINS MATERIAL
EXEMPT FROM MANDATORY DISCLOSURE UNDER THE FREEDOM OF
INFORMATION ACT. EXEMPTION(S) _________APPLY.”
3. STORAGE:
a. During normal duty hours, place FOUO material in an out-of-sight location, if your work area is accessible to persons who do not have a valid need for the material.
b. After normal duty hours, store FOUO material to prevent unauthorized access. File with other unclassified records in unlocked files or desks when internal building security is provided. When there is not internal security, locked buildings or rooms usually provide adequate after-hours protection.
c. For additional protection, store FOUO material in locked container such as file cabinets, desks, or bookcases. Expenditure of funds for security container or closed areas solely for the protection of FOUO material is prohibited.
4. TRANSMISSION:
a. FOUO documents and materials may be transmitted via first class mail, parcel post or-for bulk shipments-fourth class mail. Don’t reveal contents on outer wrapper (i.e., don’t mark FOUO on outside of package.
b. In the CONUS discussion of FOUO material on the telephone is authorized if necessary for the performance of the contract.
c. Electronic transmission of FOUO information (voice, data or facsimile) should be by approved secure communications systems whenever practical. Telefax ONLY after verifying the correct telefax number and that the recipient will be standing by at the receiving telefax machine. Apply tag and encrypt with government-approved encryption software prior to email (internet) transmission.
d. Operational critical FOUO information shall not be disclosed via non-secure means.
5. RELEASE: FOUO material shall not be released outside the contractor’s facility except to representatives of the DoD.
6. DESTRUCTION: When no longer needed, FOUO material shall be disposed of by a method that precludes its disclosure to unauthorized individuals. All information is to be destroyed after completion of Office Use requirement or returned to the releasing activity unless otherwise noted. Destroy by cross-cut shred or destroyed by tearing and separating pieces sufficiently to prevent reconstruction of the material and disclosure of contents, then place in regular trash or recycle bins.
Test Operation and Sustainment-Solicitation
Attachment 7 to DD Form 254, OPERATIONS SECURITY (OPSEC) REQUIREMENTS
REGARDING PROTECTION AND HANDLING OF CONTROLLED UNCLASSIFIED
INFORMATION (CUI)
1. Properly mark/identify all Controlled Unclassified Information (CUI) appropriately (distribution limitations, export controlled, FOUO, proprietary, etc.) per the source document or per instructions from the organization of ownership/control of the information – mark both printed and electronic media
2. Ensure locked protection for all CUI from unauthorized access
3. Need-to-know must be established prior to granting access to CUI information
4. Organizations must be certified with the Defense Logistics Information Services (DLIS) under the Joint Certification Program (JCP) before their employees can access CUI (contact your FSO for assistance regarding DLIS certification)
5. Where feasible, use secure communication methods and do not discuss CUI over an open, unsecured telephone line, to include cellular telephones and two-way radio communications.
Avoid providing unnecessary detail in a single communication (voice, electronic, etc.)
6. Where feasible, use secure communication methods and do not telefax CUI over an open unencrypted telefax machine (if secure methods are not available and organization of ownership for the information approves, verify the fax number and ensure the recipient is standing by at the receiving telefax machine)
7. CUI must be encrypted prior to transmission over computer lines via email, Internet, etc. – comply to the greatest extent possible – avoid providing too much detail, especially when unnecessary, in a single transmission
8. Destroy CUI by cross-cut shredding or burning, where possible; otherwise, destroy by any means that will prevent reconstruction of the material
9. Reproduce on standard office equipment that does not retain an image of the original and ensure all waste, etc. is properly retrieved and stored or destroyed
10. Do not place CUI material on an external web site or web page that is accessible to unauthorized personnel (CUI is not approved for release to the public)
11. Much U.S. technology has been stolen through legitimate means - retrieved from trash, communications interceptions, social engineering (people volunteering information to unauthorized personnel), carelessness in communicating (too much detail; unnecessary detail;
etc) open offices when unattended, and other public sources. Protect controlled unclassified information appropriately to ensure U.S. superiority economically, technologically and militarily!!!
12. Using Computer Hardware Not Owned by the Air Force
a. Specific government approval is required prior to processing controlled unclassified information using non-government owned hardware (computers) and/or software
b. Written approval for use will specify the conditions under which the computer system(s) must operate
c. The computer system(s) must employ current anti-virus software
d. For networked computer systems (including those with Internet connectivity), Government-owned controlled unclassified information must remain on removable media (don’t store/process on non-removable computer hard drives)
e. Government-owned controlled unclassified information must be marked and protected according to the sensitivity category in accordance with source materials, program directives or Industrial Security guidance
f. At the end of a contract/subcontract, government-owned controlled unclassified information must be permanently deleted or returned to the releasing activity
g. Measures must be in place to ensure no foreign national access to material associated with this contract/subcontract
13. What unclassified information requires protection?
a. ITAR Export – Controlled Distribution Limited Controlled Technology (has a distribution statement other than “A”)
b. For Official Use Only (FOUO – requires official government business need-to-know)
c. Proprietary – belongs to a commercial entity Competition Sensitive – government is competing between multiple contractors – temporary designation
d. Privacy Act Information – requires protection from unauthorized access (includes social security numbers, personal telephone numbers, etc.)
e. Program - specific Operations Security (OPSEC) Critical Information
NOTE: Do not assume that unmarked material can be considered public domain information.
When in doubt, protect.
14. Threat Sources
a. Presence of non-U.S. persons (foreign nationals)
Test Operation and Sustainment-Solicitation
b. Presence of visitors in workplace
c. Internet or other external connectivity to computer systems/networks
d. Disgruntled employees and ex-employees
e. Competitors
15. OPSEC Five-Step Process
a. Step #1: Identify critical information and indicators
b. Step #2: Analyze the threat
c. Step #3: Analyze vulnerabilities
d. Step #4: Assess the risks
e. Step #5: Apply appropriate countermeasures
| Attachment 2 - DD Form 254 |
| DD_FM _54-FA9101-13-R-0100_TOS_Con't |
File details come from the government source that posted it. Updated .