Exhibit_B_Data_Item_Descriptions.pdf

PDF 2 MB Posted

Attached to
Facility Support Services Federal contract opportunity
Solicitation number
FA9101-18-R-1000
Issued by
Department of the Air Force Materiel Command Test Center

About this file

Exhibit B Data Item Descriptions

View the file

Other files for this federal contract opportunity

Other files attached to Facility Support Services, newest first.
File Type Posted
Amendment_0001_SF30.pdf PDF
QandA_No._9.pdf PDF
QandA_No._7.pdf PDF
Exhibit_A_CDRLs.pdf PDF
Attachment_9,_Section_M_FRFP.pdf PDF
Attachment_2,_DD_254.pdf PDF
FSS_II_SF33.pdf PDF
Attachment_L-7,_Cross_Reference_Matrix.xlsx XLSX spreadsheet
Exhibit_D,_ASO_and_PSI_and_IGUA_CBA.pdf PDF
Attachment_L-1,_PPI_Tool.pdf PDF
Attachment_L-5,_Subcontractor_Consent_Letter.pdf PDF
Attachment_8,_Section_L_FRFP.pdf PDF
Attachment_1_PWS_9_Nov_18.pdf PDF
Attachment_3,_SCA_and_CBA_WDs.pdf PDF
Exhibit_C,_ASO_and_AEMTC_CBA.pdf PDF
QandA_No._6.pdf PDF
FSS_II_Notional_Acquisition_Schedule_-_Sep_2018.pdf PDF
Industry_Day_3_Panel_Cancellation.pdf PDF
Draft_Attachment_8,_Section_L_(UPDATE).pdf PDF
QandA_No._5.pdf PDF
Industry_Day_No._3_Agenda.pdf PDF
Industry_Day_No._3_Announcement.pdf PDF
QandA_No._4.pdf PDF
Attachment_2,_DD254.pdf PDF
Attachment_7,_USAF_Owned_Registered_Vehicles.pdf PDF
Attachment_3,_SCA_and_CBA_WDs.pdf PDF
Attachment_L-6,_Relevancy_Matrix.xlsx XLSX spreadsheet
Attachment_L-5,_Subcontractor_Consent_Letter.pdf PDF
Attachment_L-8,_Cost_Model.xlsx XLSX spreadsheet
Attachment_L-3,_PPQ_Cover_Letter.pdf PDF
FSS_II_dRFP_SF33.pdf PDF
Attachment_L-7,_Cross_Reference_Matrix.xlsx XLSX spreadsheet
Attachment_5,_ACES_FD_Property_Listing.pdf PDF
Attachment_L-4_Past_Performance_Client_Authorization_Letter.pdf PDF
Exhibit_D,_ASO_and_PSI_and_IGUA_CBA.pdf PDF
Exhibit_E,_ASO_and_URS_and_AEMTC_CBA.pdf PDF
FSS_II_dRFP_Cover_Letter.pdf PDF
Attachment_9,_Section_M.pdf PDF
FSS_II_Draft_PWS,_CDRLs_and_DIDs_Announcement.pdf PDF
FSS_II_Draft_Exhibit_A_Contract_Data_Requirements_List.pdf PDF
FSS_II_Draft_PWS_20_Jul_18.pdf PDF
Questions_and_Answers_No._2.pdf PDF
Request_for_Information_No._1.pdf PDF
Attachment_8_-_Industry_Day_No._2_Registration_Form.docx DOCX document
Attachment_7_-_Industry_Day_No._2_Agenda.pdf PDF
Attachment_8_-_Industry_Day_No._2_Registration_Form.pdf PDF
Attachment_6_FSS_II_Draft_PWS_13_Apr_18.pdf PDF
Sources_Sought_QandA_No._1.pdf PDF
Attachment_2_(Update)_-_Industry_Day_No._1_Announcement.pdf PDF
Attachment_2_-_Industry_Day_No._1_Announcement.pdf PDF
Show all 50

Facility Support Services has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

FA9101-18-R-1000

Exhibit B

Data I em Descriptions

DRAFT

DATA ITEM DESCRIPTION

Title: SPECIAL ACCESS PROGRAM (SAP) ACCREDITED AREA STANDARD OPERATING

PROCEDURE (SOP)

Number: OT-2018- Approval Date: 2018MMDD

AMSC Number: N/A Limitation: FA9101-18-R-1000

DTIC Applicable: No GIDEP Applicable: No

Preparing Activity: 10 (AEDC/TSD-IP) Project Number: N/A

Applicable Forms: N/A

Use/relationship: A written security SOP, prepared for the AEDC Government Special Access Program Security Officer (GSSO), provides instructions for proper protection, use, and dissemination of classified material by enforcing information, personnel, physical, communications, industrial, and IA security standards identified in the reference documents. The SAP Accredited Area SOP is a living document that will require periodic updates throughout the life of the accredited area.

This Data Item Description (DID) contains the format, content, an tended use information for the data product resulting from the work task described in the c ract Performance Work Statement (PWS). This DID is for one-time use for Arnold Engineering Development Complex (AEDC) solicitation FA9101-18-R-1000, AEDC Facilit upport Services (FSS).

Requirements:

1. Reference Documents. The applicable is of the documents cited herein, including their approval dates and dates of any applicable ame ents, notices, and revisions, shall be as specified in the contract.

2. Format. The SAP Accredited Area S P shall be prepared in electronic format and available to authorized users via electronic nd ha dcopy forms. The format shall comply with reference documents.

3. Content. The SAP Accr d Area OP content shall comply with all reference documents.

End of OT-2018-

DISTRIBUTION STATEMENT A. Approved for public release. Distribution is unlimited.

Title: SPECIAL ACCESS PROGRAM (SAP) CERTIFICATION AND ACCREDITATION

PACKAGE

Number: OT-2018- Approval Date: 2018MMDD

AMSC Number: N/A Limitation: FA9101-18-R-1000

DTIC Applicable: No GIDEP Applicable: No

Preparing Activity: 10 (AEDC/TSD-IP) Project Number: N/A

Applicable Forms: N/A

Use/relationship: An accreditation package, prepared for the AEDC Government Special Security Officer (GSSO), includes physical security and TEMPEST documentation for the establishment and accreditation of the accredited area. The accreditation package includes information to ensure the facility meets prescribed physical, technical, and personnel security standards identified in the reference documents. The accreditation package is a living document that will require periodic updates throughout the life of the accr ed area.

This Data Item Description (DID) contains the format, content, an tended use information for the data product resulting from the work task described in the c ract Performance Work Statement (PWS). This DID is for one-time use for Arnold Engineering Development Complex (AEDC) solicitation FA9101-18-R-1000, AEDC Facilit upport Services (FSS).

Requirements:

1. Reference Documents. The applicable is of the documents cited herein, including their approval dates and dates of any applicable ame ents, notices, and revisions, shall be as specified in the contract.

2. Format. The accreditation packag shall be prepared in electronic form and available to authorized users via electronic nd ha dcopy forms. The format shall comply with reference documents.

3. Content. The accreditat ntent all comply with all reference documents.

End of OT-2018-

Title: JOINT SPECIAL ACCESS PROGRAM IMPLEMENTATION GUIDE (JSIG) SYSTEM

AUTHORIZATION PACKAGE (SAP)

Number: DI-ADMN-81969 Approved Date: 20140807 AMSC Number: F9488 Limitation: N/A DTIC Applicable: No GIDEP Applicable: No Office of Primary Responsibility: 20 (AFRL/RYS) Applicable Forms: N/A Use/Relationship: The JSIG SAP is used to identify, control, and authorize a contractor’s proposed stand-alone computer systems and/or networks created and used during the performance of this contract. The contract Information System Security Officer (ISSO) or Information System Security Manager (ISSM) must submit the SAP documentation for a proposed system or network to the Authorizing Official (AO), Delegated Authorizing Official (DAO), or the Program Security Officer (PSO). The AO, D O, or the PSO must provide written approval of any new information system or network befor rocessing can begin.

a. The SAP describes the methods to: (1) identify systems, se ity responsibilities and requirements; (2) define overall security standard practice guidance and procedures; (3) identify potential problem areas and determine solut s; and (4) develop security awareness inputs into the overall system security process.

b. This Data Item Description (DID) defines he data requ ed to obtain information systems authorization in accordance with the JSIG. A of the JSIG can be obtained from the government program office.

c. This DID contains the format and ontent preparation instructions for the data product generated by the specific and di crete ask requ rements delineated in the contract.

Requirements:

1. Reference documents: Th pplic e issue of the documents cited herein, including their approval dates and d es of an applicable amendments, notices, and revisions, shall be as cited in the ASSIST at t time o he solicitation or contract.

a. Department of Defense ( D) JSIG

b. DoD JSIG Template Handbook.

c. Government Program Office Guidance.

(Copies of these documents are available from the Government Agency awarding the contract.)

2. Format: The JSIG SAP Documentation shall be presented in Microsoft Word formats outlined by the DoD JSIG, DoD JSIG Template Handbook and the Government Information Assurance Officer (IAO). The initially used format arrangement shall be used for all subsequent submissions.

3. Content: A JSIG system/network authorization package typically consists of:

a. Authorization Package Cover Letter.

DISTRIBUTION STATEMENT A. Approved for public release; distribution is unlimited.

Source: https://assist.dla.mil -- Downloaded: 2018-04-23T16:54Z

Check the source to verify that this is the current version before use.

DI-ADMN-81969

b. Authorization to Operate (ATO) Letter.

c. Security Assessment Report (SAR).

d. Risk Assessment Report (RAR).

e. System Security Plan (SSP).

f. Security Control Traceability Matrix (SCTM).

g. Plan of Action and Milestones (POA&M).

h. ISSO/ISSM Appointment Letter.

i. ISSO/ISSM 8570 Certification (per DoD 8570.01-M, Information Assurance Workforce Improvement Program).

(Copies of this document are available online at http://www.dtic.mil/whs/directives/index.html.)

j. General User’s Guide (GUG).

k. Privileged User’s Guide (PUG).

l. Software List.

m. Software Approval Forms for High-Risk.

n. Hardware List.

o. Any other supporting documentation required above documentation (facility accreditation, etc.)

3.1. An SSP will be developed and maintained for ach proposed stand-alone system or network.

3.2. If an approved Interagency Stand g Operating Procedure (IASOP) exists for previously authorized systems/networks, an will o the proposed system/network, submit a copy of the IASOP in addition to the item through o, above.

3.3. The SAP documentation be re ised when any modifications are made to any portion of the system, networ ersonn or documentation.

3.4. Classification of doc entation will be applied in accordance with security classification guides or classification tab . “Distribution Statement F. Further dissemination only as directed by (inserting controlling DoD office) (date of determination) or higher DoD authority.”

applies to this package.

4. End of DI-ADMN-81969.

Source: https://assist.dla.mil -- Downloaded: 2018-04-23T16:54Z

Title: DOD Information Assurance Certification and Accreditation Process (DIACAP) and

Risk Management Framework (RMF) Deliverable Data

Number: DI-MGMT-82000 Approval Date: 20151014

AMSC Number: 9594 Limitation:

DTIC Applicable: GIDEP Applicable:

Office of Primary Responsibility: AS Project Number: MGMT-2015-021

Applicable Forms:

Use/relationship: The DIACAP and RMF Deliverable Data will be used to satisfy the requirements of the DIACAP and/or RMF process.

This Data Item Description (DID) contains the format, content, and ended use information for the data product resulting from the work task described by the contract.

Requirements:

1. Format. The DIACAP and/or RMF artifacts shall be d vered in a format approved by the

Government’s Designated Accrediting Authority (DAA), A orizing Official (AO), or Information

Systems Security Manager (ISSM).

2. Content. The content of the DIACAP and/or RMF artif ts shall contain the necessary artifacts required by the DAA, AO, or ISSM to cessfully achieve Platform IT Risk Approval (PRA), Interim Authority to Test (IATT), Interim Authority to Operate (IATO), or Authority to Operate

(ATO).

2.1 Introduction. This section ll conta a narrative of the DIACAP/RMF package content.

2.1.1 IATT Request. The TT Request shall use the approved DAA, AO, or ISSM format. The

IATT Request shall identify ‘who’, ‘what’, ‘why’, ‘where’, ‘when’, and ‘how’ of the requested

Test event. IATT Request sha be delivered not less than 30 days prior to the start of the Test

Event.

2.1.2 Certification and Accreditation (C&A) or Security Plan. The C&A or Security Plan shall use the approved DAA, AO, or ISSM format. The C&A Plan shall contain at a minimum, System

Information, Mission Description, Concept of Operations (CONOPS), Environment, Operating and

Computing Environment, Physical Security Measures, Facilities Descriptions, Threat Analysis, System Architecture Description, Components, Configurations, Accreditation Boundaries, Connection Process Guide (CPG) Compliant Network Diagrams, External Interfaces and Data Flow, Internal Data Flow, Contingency Plan, Incident Response Plan, User Descriptions and Clearances, Security Roles, Hardware Lists, Software Lists, Ports, Protocols, and Services (PPS), Configuration

Management Plan, Information Assurance Vulnerability Management (IAVM) Plan, and C&A Tasks and Milestones. The C&A Plan shall be approved and signed by the ISSM, User Rep, Program

Manager (PM), and DAA or AO.

Source: https://assist.dla.mil -- Downloaded: 2018-04-23T17:18Z

DI-MGMT-82000

2.1.3 C&A Project Plan. The C&A Project Plan shall use the approved DAA, AO, or ISSM format.

The C&A Project Plan shall be approved and signed by the ISSM, Echelon II Representative, and

PM. The C&A Project Plan shall define the various C&A Tasks and Milestones needed to achieve

PRA, IATT, IATO, or ATO.

2.1.4 Collaboration Brief. The Collaboration Brief shall use the approved DAA, AO, or ISSM format. The Collaboration Brief is submitted with the DIACAP/RMF package and is used to describe the System and System Risk during the Collaboration meeting.

2.1.5 DIACAP Implementation Plan (DIP). The DIP shall use the approved DAA, AO, or ISSM format. The DIP shall be used during the DIP Concurrence meeting with the Echelon II, Navy CA, and ODAA. The DIP shall define which IA Controls (IACs) will be ‘Implemented’, ‘Inherited’, ‘Non-Compliant’, or ‘Not Applicable’. The DIP shall be approved by the DAA, AO, and ISSM prior to execution of the IA Test Plan.

2.1.6 PIT Implementation Plan (PIP). The PIP shall use the approved DAA, AO, or ISSM format.

The PIP shall be used during the PIT Concurrence meeting with the helon II, Navy CA, and

ODAA. The PIP shall define which IACs will be ‘Implemented’, ‘Inh ted’, ‘Non-Compliant’, or

‘Not Applicable’. The PIP shall be approved by the DAA AO, and ISSM rior to execution of the

IA Test Plan.

2.1.7 IA Test Plan. The IA Test Plan shall use the approve DAA, AO, or ISSM format. The IA

Test Plan shall define all required Vulnerability Scans, Securi y Technical Implementation Guides

(STIGs), Security Readiness Guides (SRGs), Sec C ntent Automation Protocol (SCAP) benchmarks, and IA Controls or Security Overlays to be plied to the System. The IA Test Plan shall be approved by the DAA, AO, and ISSM during the DIP or PIP Concurrence Meeting.

2.1.8 PIT Designation Request. PIT D signation Request shall use the approved DAA, AO, or

ISSM format. The PIT Designation R uest is the formal request to the DAA or AO that the System shall be designated as Platfo T (vers n Information System (IS)). The PIT Designation

Request shall be approved and a P T Designation Letter shall be signed by the DAA or AO prior to the execution of the IA T Plan.

2.1.9 PIT Determination Brief The PIT Determination Brief shall use the approved DAA, AO, or

ISSM format. The PIT Determination Brief shall be used in conjunction with the PIT Designation

Request to formally request the System be designated Platform IT (versus and Information System).

2.1.10 Plan of Action and Milestones (POA&M). The POA&M shall use the approved DAA, AO, or ISSM format. The POA&M shall be considered a ‘living’ document and shall regularly be updated throughout the entire lifecycle of the System through Decommission. The POA&M shall contain all Not Applicable IA Controls, All Non-Compliant IA Controls, and all Non-Compliant

Vulnerability Findings as identified in the Vulnerability Scans, STIGs, SRGs, and SCAP

Benchmarks. At a minimum, the POA&M shall be updated monthly.

2.1.11 Privacy Impact Assessment (PIA). The PIA shall use the approved DAA, AO, or ISSM format. The PIA shall be approved and signed by the ISSM, PM, and the Command PIA Officer.

2.1.12 Vulnerability Scans. In accordance with the approved IA Test Plan, the System shall be scanned using the approved vulnerability scanning tools as identified by the DAA, AO, or ISSM.

Source: https://assist.dla.mil -- Downloaded: 2018-04-23T17:18Z

DI-MGMT-82000

The vulnerability scanner shall be updated with the latest signatures and scanning engines prior to the execution of each vulnerability scan. At a minimum, vulnerability scans shall be conducted monthly against the System. Non-compliant findings shall be documented in the System POA&M on a minimum monthly basis. At a minimum, vulnerability scans shall be submitted electronically to the

ISSM or uploaded into the DIACAP/RMF package. Vulnerability scans shall be handled in accordance with the System’s classification level. Vulnerability reports shall be in a format approved by the DAA, AO, or ISSM.

2.1.13 STIGs, SRGs, SCAP Benchmarks. In accordance with the approved IA Test Plan, the

System shall be hardened using the required and approved STIGs, SRGs, and SCAP Benchmarks.

Non-compliant STIG, SRG, and SCAP Benchmark findings shall be documented in the System

POA&M on a minimum monthly basis. Updates to the STIGs, SRGs, and SCAP Benchmarks are released on a monthly, quarterly, and yearly basis. Updates to the STIGs, SRGs, and SCAP

Benchmarks shall be implemented into the System as they are released. Non-compliant STIG, SRG, and SCAP Benchmark findings shall be documented in the System POA&M on a minimum monthly basis. STIG, SRG, and SCAP Benchmark artifacts shall be provided in a format approved by the

DAA, AO, or ISSM. STIG, SRG, and SCAP Benchmark artifacts ll be handled in accordance with the System’s classification level. At a minimum, STIG, SRG, an SCAP Benchmarks shall be submitted electronically to the ISSM or uploaded into the DIACAP/RMF ckage on a minimum monthly basis.

2.1.14 Scorecard. The Scorecard shall use the approved D AO, or ISSM format. The

Scorecard shall be maintained and updated on a minimum mo ly basis.

2.1.15 Contingency Plan. The Contingency Plan shall u the approved DAA, AO, or ISSM format.

The Contingency Plan shall be submitted in conjunction with the System’s C&A Plan. The

Contingency Plan shall be approved and s ned by the PM, ISSM, and DAA or AO.

2.1.16 IAVM Plan. The IAVM Plan ll use the approved DAA, AO, or ISSM format. The IAVM

Plan shall be submitted in c j tion w the System’s C&A Plan. The IAVM Plan shall be approved and signed by the PM, I M, and DAA or AO.

2.1.17 Cyber Security Waiv Cyber Security Waivers shall use the approved DAA, AO, or ISSM format. All Cyber Security W ers shall be approved and signed by the ISSM, PM, and First Flag or Equivalent prior to submission to the DAA or AO.

END OF: DI-MGMT-82000

Source: https://assist.dla.mil -- Downloaded: 2018-04-23T17:18Z

Title: TEST SECURITY PLAN FOR COLLATERAL, SAP, CLASSIFIED AND COMMERCIAL

TEST

Number: OT-2018- Approval Date: 2018MMDD

AMSC Number: N/A Limitation: FA9101-18-R-1000

DTIC Applicable: No GIDEP Applicable: No

Preparing Activity: 10 (AEDC/TSD-IP) Project Number: N/A

Applicable Forms: N/A

Use/relationship: Test security plans will be prepared for all commercial, unclassified, and collateral classified research, development, test and evaluation (RDT&E) test programs conducted at Arnold Engineering Development Complex (AEDC). This plan will be used by all associated test team members and identifies all security requirements related to specific test efforts. The test security plan provides all employees supporting a test with test-specific security guidance and procedures. If necessary, it also contains a For n National Visitor Control Plan as an annex.

This Data Item Description (DID) contains the format, content, and in nded use information for the data product resulting from the work task des ribed in the contract Performance Work Statement (PWS). This DID is for one-time use for AE C solicitation FA9101-18-R-1000, AEDC Facility Support Services (FSS).

Requirements:

1. Reference documents. The applicable issue o documents cited herein, including their approval dates and dates of any applicable amendments, notices, and revisions, shall be as specified in the contract.

2. Format. The test security plan hall b prepared in electronic form and available to authorized users via electronic and hardcopy ms. Th ormat shall comply with reference documents.

3. Content. As a minimum, lan sh

a. Identify the test ogram a provide an overview of the test

b. Identify the custom pons r and test facility

c. Identify classification, cific local or customer guidance, related Security Classification Guides, and any Technical Assistance Agreements, Technology Control Plans

d. Identify Baseline Protection Requirements for Data and the test areas (Physical Space)

e. Identify the Risk Assessment Authorization (RAA), if required:

i. Identify any foreign national involvement and subsequent visitor control procedures

ii. Identify any CUI and specific guidance

iii. Identify any OPSEC concerns and provides and specific measures and/or guidance

iv. Identify any Critical Program Information (CPI) and specific Program Protection Plan requirements or guidance

Title: OPERATIONS SECURITY (OPSEC) PLAN

Number: DI-MGMT-80934C Approval Date: 20101213 AMSC Number: 9178 Limitation: N/A DTIC Applicable: No GIDEP Applicable: No Office of Primary Responsibility: NS/I925 Applicable forms: N/A

Use/Relationship: The OPSEC Plan is used to identify and monitor a contractor’s OPSEC activities during the performance of a contract. It is intended to be a living document that will require periodic updates throughout the life of the contract. The OPSEC plan; (1) Describes the OPSEC environment to include identification of critical information, the OPSEC threat and vulnerabilities an adversary might exploit to acquire critical info ation, (2) Documents the OPSEC risk analysis, (3) Identifies proposed and actual OPSEC m ures, (4) Defines and assigns specific OPSEC responsibilities and ties the OPSEC Plan to t contractor’s corporate OPSEC Program, and (5) Serves as a repository of the OPSEC history of the contract.

a. This Data Item Description (DID) contains the forma nd content preparation instructions for the data product generated by the specific and discrete ta requirements delineated in the contract.

b. This DID is applicable only when h contrac ing activity determines that the sensitivity of the contracted effort warrants OPSEC pr tections

c. The contractor’s implementation f the OPSEC Plan, approved by the contracting activity, is subject to joint audit and/or in ction the Defense Security Service and the contracting activity.

d. This DID supersedes DI MGMT 80934B.

Requirements:

1. Reference documents: The applicable issue of the documents cited herein, including their approval dates and dates of any applicable amendments, notices and revisions, shall be as specified in the contract.

a. “Applying OPSEC to U.S. Government Acquisitions and Contracts”. This document is available from the Interagency OPSEC Support Staff (IOSS) at the following web address:

www.ioss.gov.

b. Department of Defense Manual (DODM) 5205.02M, DOD Operations Security (OPSEC) Program Manual, dated November 3, 2008.

Source: https://assist.dla.mil -- Downloaded: 2014-07-02T18:58Z

DI-MGMT-80934C

c. Department of Defense Contract Security Classification Specification (DD 254). This document is included as a part of all Request for Proposals (RFP) and Contracts involving classified data.

d. Contract Data Requirements List (CDRL). This document is included as a part of all RFP and contracts containing data deliverable requirements.

e. National Industrial Security Program Operating Manual (NISPOM) 5220.22M, dated February 28. 2006.

2. Format: The OPSEC Plans shall be submitted in contractor determined format and, at a minimum, consist of the following sections listed in the Content Section below.

3. Content:

3.1 COVER PAGE

The cover page for an OPSEC Plan shall clearly present, at a minimum he following information:

1. Title of the Acquisition Program

2. Title of the Document (i.e. “Operations Security P n”)

3. Reference to the government contrac ber

4. Date of latest revision

5. Name, signature and title of he preparer of the OPSEC Plan

6. Name, signature and title of th approver of the OPSEC Plan.

7. Reference for whom th ocum t was prepared (Contracting activity)

8. Reference by whom the do ment was prepared (Corporation)

9. All appropriate dist tion o lassification statements

3.2 TABLE OF CONTEN S PAGE

The Table of Contents for an OPSEC Plan shall outline each section contained in the OPSEC Plan.

3.3 PREFACE PAGE

The purpose of the Preface is to provide a brief, unclassified, overview of the program and the need for OPSEC measures. The specific objectives of the contracted effort shall be introduced with reference to all strategic participants and partnerships required to make the program a success. The anticipated development of any innovative concepts or technologies shall also be introduced in the Preface.

The Preface shall reference all links between the OPSEC Plan and any corporate OPSEC Program(s). The Preface may conclude by referencing requirement documents such as the contract number, Contract Security Classification Specification (DD254), Contract Data

Source: https://assist.dla.mil -- Downloaded: 2014-07-02T18:58Z

Requirements List (DD1423) and any other pertinent guidance provided by the contracting activity. It shall also provide an OPSEC point of contact, with contact information, for additional guidance or assistance such as the OPSEC program manager or contractor program manager.

3.4 OPSEC PLAN INTRODUCTION

3.4.1 Purpose and Scope: The purpose of the OPSEC Plan shall be effectively communicated in this section and include a description of the scope of the OPSEC Plan (unique physical locations, subcontractors, suppliers, period of performance, etc.).

3.4.2 Authorities: The requirement to protect critical information shall be documented within this section. Documenting the requirement can be achieved by referencing the Corporate OPSEC Program (Policy) and Plan, DODM 5205.-2M, specific contract documents including the DD254 for contracts involving classified data, or other contracting activity specific guidance.

3.4.3 OPSEC Plan Major Activity Timeline: This s ction all include a list of all major OPSEC Plan activities such as quarterly OPSEC Working Gro Meetings, Annual Assessments, scheduled OPSEC awareness training, Sub-contractor OPSEC Assessments and Surveys, Threat and Vulnerability Reviews, etc. This ction shall also include scheduled OPSEC Plan reviews.

3.4.4 Responsibilities: The OPSEC P hall identify whom is responsible for the major activities described in the Plan. F example (not intended as an inclusive list):

The OPSEC Mana r sha b identified by name and include a list of duties that may inc de:

1. Coo dinate all PSEC policy responsibilities/ procedures within the program.

2. Revis e Prog am OPSEC Plan as necessary.

3. Convene d coordinate the annual Program OPSEC Assessment.

4. Disseminat updated threat information to program personnel.

5. Assist in the review of contract requirements for OPSEC considerations.

6. Conduct OPSEC briefing(s) upon customer approval of the plan.

7. Principal advisor to the Contractor Program Manager on all OPSEC matters.

8. Develop/Disseminate Program Critical Information List (CIL).

9. Promote OPSEC awareness within the program.

The Contractor Program Manager shall be identified by name and include a list of duties that may include:

1. Responsible for the overall implementation of the program/contract.

2. Ensure proper OPSEC procedures are implemented by program personnel.

3. Ensure all subcontractors and suppliers supporting the program develop and implement procedures in compliance with the Program OPSEC Plan.

Source: https://assist.dla.mil -- Downloaded: 2014-07-02T18:58Z

4. Remain cognizant of emerging OPSEC threats and vulnerabilities that may adversely impact upon the success of the program.

5. Actively participate in periodic Program OPSEC assessments.

6. Remain cognizant of any changes in critical information and communicate them to the Program OPSEC Manager.

7. Promote OPSEC awareness within the program.

A short description of the expectations and responsibilities of all program personnel (including subcontractors and suppliers) shall be provided and may typically include:

1. Remain compliant with all applicable OPSEC Plans.

2. Maintain an awareness of all applicable CIL.

3. Attend all OPSEC program briefings.

4. Timely reporting of any OPSEC concerns to the Contractor Program Manager and/or the Program OPSEC Manag

5. Generation of OPSEC Plans (sub-contrac ors or ppliers only).

3.4.5 Organizational OPSEC Communications and Interfaces: A description as to how the OPSEC Plan will be communicated to all personn upporting the program (hardcopy, via a webpage, briefings, etc.).

3.4.5.1 Internal: In this section OPSEC Plan shall identify all anticipated OPSEC interfaces internal to the corporation such as th senior corporate leadership, corporate OPSEC Working Group, OPSEC coordinators, p ogram personnel, etc.

3.4.5.2 External: this tion the OPSEC Plan shall identify all anticipated external points of contact such as th ontracting activity, Defense Contract Management Agency (DCMA), The Defen Securi y Service (DSS), Federal Bureau of Investigation (FBI) and local law enforcem nt and th primary role within the OPSEC program (i.e. DCMA audits acquisition management p ctices, DSS provides security oversight, FBI and law enforcement may provide threat data). S contractor and supplier OPSEC points of contact shall be similarly identified.

3.4.6 Marking, Handling and Distribution of Documents: This section shall provide a description of marking, handling, storage, access and transmission authorizations and procedures for any critical information provided to, or generated by, the contractor.

Reference to the program classification guide, Freedom of Information Act and any additional guidance provided by the contracting activity may be cited as applicable.

3.5 THREAT

3.5.1 General Threat: This section shall identify and demonstrate an understanding of the overall threat to program critical information throughout the anticipated duration of the contract/program. For example, an information systems program might note the following:

Source: https://assist.dla.mil -- Downloaded: 2014-07-02T18:58Z

DSS analysis of 2008 threat data shows, “Information systems, especially C4ISR related systems remained the primary sought-after technology for East Asia and Pacific Region countries. Direct requests (often via the Internet) and other suspicious Internet activity continued to be the preferred method of collection. Information systems are primary targets for Near East adversaries of the United States. Near East commercial entity activity indicates a growing collusion between commercial entities and government associated entities such as universities, public agencies and research and development centers. Adversaries using HUMINT and OSINT collection methods represent a significant threat to program critical information. i

The section shall conclude with a brief description of all identified intelligence collection methods that may be expected to be used by an adversary to acquire critical information.

Note: A general description of intelligence collection methods may be found in “Applying OPSEC to Government Acquisitions and Contracts” at www.ioss gov.

3.5.2 Program Detailed Threat: This section shall b simi to section 3.5.1 above referencing any known direct threats to acquisition specific elements ritical information within the program/contract. As complete a description of each threat as possible shall be provided while maintaining the overall plan classificat at the unclassified level. Since detailed threat information may derive from classified so es, reference to source documents as provided by the government contracting activity or other rep able source is permitted.

3.5.3 Threat Analysis: Each threat identified in sections 3.5.1 and 3.5.2 shall be analyzed to determine the level of thr to the corresponding critical information. The results of this analysis shall be presented in his se ion. A description of the specific threat analysis method used by the contractor to nti y h threat shall be included in this section.

Note: For additional guidance d a sam le threat analysis methodology see, “Applying OPSEC to Government Acqui ns and ntracts” at www.ioss.gov and DODM 5205.02.

3.5.4 Changes With Threat Environment: The Threat section shall conclude with a statement that addresses how new threat data is to be received and incorporated into the OPSEC Plan to ensure OPSEC risk remains in compliance with all applicable guidance.

3.6 CRITICAL INFORMATION

3.6.1 General: Critical information shall be identified within this section of the plan and a comprehensive program Critical Information List (CIL) shall be included.

3.6.2 Critical Information List: Guidance on the creation of a CIL is contained within “Applying OPSEC to Government Acquisitions and Contracts,” available at www.ioss.gov, DODM 5205.02M, or may be provided by the contracting activity. Ideally the CIL shall remain unclassified to facilitate wide internal distribution, but may provide reference to classified information as applicable.

3.7 VULNERABILITY

3.7.1 General: The Vulnerability section of the OPSEC Plan shall describe the analysis of activities (indicators) that point to OPSEC vulnerabilities an adversary can exploit to acquire critical information. This section shall contain a list of all identified OPSEC vulnerabilities.

3.7.2 List of OPSEC Vulnerabilities: Each vulnerability shall be described in sufficient detail as to communicate to the contracting activity the extent of the vulnerability. The Vulnerability List shall remain unclassified, but may provide reference to classified information if applicable. Reference to classified reports and other information shall include an unclassified description of the documentation (report title, number, etc.) and the source responsible for publication of the information.

Note: A list of typical OPSEC vulnerabilities which may require OPSEC measures may be found within “Applying OPSEC to Government Acquisitions and Contracts”, available at www.ioss.gov or may be provided by the contracting activity. T ese sample vulnerabilities are not all inclusive and the submitted vulnerability list shall be tailor to the specific acquisition or contract.

3.7.3 Vulnerability Analysis: Once potential program vulnerabilities have been identified, the magnitude of each vulnerability sh be determined using a consistent methodology identified and documented in this section of OPSEC Plan. The results of this analysis shall also be described in this section

Note: For additional guidance and a sample vulnerability methodology see, “Applying OPSEC to Government Acquisitions and Contr s” at www.ioss.gov and DODM 5205.0-2M.

3.8 RISK ASSESSMENT

3.8.1 General: The OP C risk of a program represents the probability of compromise of critical inform tion and he impact to the program/contract taking into account the threat and vulnera ties. he acceptable level of OPSEC risk (as determined by senior leadership, or the con cting activity) shall be described in this section in terms consistent with the selected OPSEC methodology.

3.8.2 Risk Assessment: The specific OPSEC risk shall be described in terms consistent with the OPSEC methodology selected for determining OPSEC threat and vulnerability.

The method, and the results of the assessment, shall be presented in this section. The conclusion of the risk assessment shall result in an ordinal ranking of OPSEC risk (highest to lowest).

Note: Additional guidance and a sample risk methodology are available in “Applying OPSEC to Government Acquisitions and Contracts” at www.ioss.gov and DODM 5205.0-2M.

3.9 OPSEC MEASURES

3.9.1 General: This section of the OPSEC Plan shall identify specific OPSEC

Source: https://assist.dla.mil -- Downloaded: 2014-07-02T18:58Z

Measures proposed for mitigating OPSEC risk to acceptable levels including the cost to implement each measure. A sampling of common OPSEC measures is available in “Applying OPSEC to Government Acquisitions and Contracts” at www.ioss.gov . This list is not to be considered exhaustive and is provided as guidance for the development of the program/contract specific list of potential OPSEC measures.

3.9.2 Residual Risk: This section shall contain an analysis of residual OPSEC risk, in terms consistent with the OPSEC methodology selected, as a result of implementation of each OPSEC measure presented in section 3.9.1. This section shall identify which OPSEC measures will be implemented and the rationale for those that will not.

3.10 OPSEC Program Chronology: This section shall document significant program OSPEC events throughout the lifecycle of the program. Significant events may include changes to the CIL, changes in program leadership or results of program assessments and surveys (including subcontractors). At a minimum, this section shall include a brief description of the event, date of occurrence, actions taken by the contractor and final disposition A known compromise of critical information need only be referenced in keeping with he in ded classification of this document.

Note: The history contained herein may be used by th gov rnment as a part of an OPSEC or security audit conducted by the contracting activity, DSS other authorized agency.

3.11 ACRONYMS: This section shall includ mplete list of acronyms used in the Program OPSEC Plan (i.e., CDRL – Contract Data Requiremen List, DID – Data Item Description, etc.).

3.12 REFERENCES: This section sha include a complete list of all references cited in the Program OPSEC Plan (i.e. DoD M nual 205 02-M, dated November 3, 2008, Contract Number, Corporate OPSEC Plan(s)/Program( etc.).

i The specific example p vided d rives from annual documentation produced by the Defense Security Service, Counterin ligence Office in 2009. Current assessments may be found at https://www.dss.mil/isp/count intell/count intell.html.

4. END OF DI-MGMT-80934C.

f. Provide data marking guidance, including distribution limitations, export control, and/or any dissemination markings to be included with classification marking

g. Provide all physical security and AIS requirements and a checklist on how to implement them; including detailed diagrams or drawings

h. Provide standard requirements for each test program (test photography, etc.).

i. Identify other Test, Industrial, Information, Personnel or Physical Security requirements

j. Provide a list of definitions, abbreviations, acronyms, terms, symbols, and notations used

k. Contain signature approval blocks (or electronic equivalent) for the Government Project Manager, Information Systems Security Officer, FSS Facility Security Officer and Servicing Security Activity (TSD-IP).

End of OT-2018-XXXXX

Title: STANDARD PRACTICE PROCEDURE (SPP)

Number: OT-2018- Approval Date: 2018MMDD

AMSC Number: N/A Limitation: FA9101-18-R-1000

DTIC Applicable: No GIDEP Applicable: No

Preparing Activity: 10 (AEDC/TSD-IP) Project Number: N/A

Applicable Forms: N/A

Use/relationship: SPP will be used to ensure effective implementation of the requirements of DOD 5220.22-M, National Industrial Security Operating Manual (NISPOM). The SPP will contain specific guidance for the contractor's operations and involvement with classified information at the contractor's facility/areas located at Arnold Engineering Development Complex (AEDC). The Contractor shall implement all applicable terms of the NISPOM at each of its established areas.

This DID contains the format, content, and intended use informat on for the data product resulting from the work task described in the contract Performance Work tatement (PWS). This DID is for one-time use for AEDC solicitation FA9101-18-R-1000, AEDC F ity Support Services (FSS).

Requirements:

1. Reference documents. The applicable issue of t do uments cited herein, including their approval dates and dates of any applicable amendm s, notices, and revisions, shall be as specified in the contract.

2. Format. The SPP shall be prepared in ele ic form and available to authorized users via electronic and hardcopy forms. The format shall comp with reference documents.

3. Content. The SPP content shall c ply with all reference documents including NISPOM, be consistent with the required level of d ail, consistent with task delineation, and address all security requirements in accorda e wi Government direction and applicable standards. The SPP shall contain signature appro l blocks for all FSS “Key Management Personnel” and Servicing Security Activity ( IP).

End of OT-2018-

Title: INFORMATION PROTECTION (IP) STANDARD OPERATING INSTRUCTION (SOI) /

STANDARD OPERATING PROCEDURE (SOP)

Number: OT-2018- Approval Date: 2018MMDD

AMSC Number: N/A Limitation: FA9101-18-R-1000

DTIC Applicable: No GIDEP Applicable: No

Preparing Activity: 10 (AEDC/TSD-IP) Project Number: N/A

Applicable Forms: N/A

Use/relationship: A written SOI/SOP provides instructions and guidance to ensure compliance with requirements contained in applicable National Industrial Security Program Operating Manual (NISPOM), Air Force, program, and other cognizant security agency directives for “Closed and Restricted” and Commercial Test Areas. The IP SOIs/SOPs are living documents that will require periodic updates throughout the life of the area.

This Data Item Description (DID) contains the format, content, and tended use information for the data product resulting from the work task described in the c ract Performance Work Statement (PWS). This DID is for one-time use for rnold Engineering Development Complex (AEDC) solicitation FA9101-18-R-1000, AEDC Facility upport Services (FSS).

Requirements:

1. Reference documents. The applicable iss of the documents cited herein, including their approval dates and dates of any applicable ame nts, notices, and revisions, shall be as specified in the contract.

2. Format. The SPP shall be prepared electronic form and available to authorized users via electronic and hardcopy forms. T format shall comply with reference documents.

3. Content. The security SOI/SOP tent shall:

a. Comply with all referenc ocum ts

b. Be consistent wi he requ ed level of detail, consistent with task delineation

c. Address all security uirements in accordance with Government direction and applicable standards

d. Include Entry / Exit Control procedures for use by owner / users or area custodians of established controlled or restricted areas

e. Include procedures for Installation Random Antiterrorism Measures (IRAMs) procedures within established controlled or restricted areas

f. Contain signature approval blocks for FSS Facility Security Officer and Servicing Security Activity (TSD-IP)

Title: BLOOD BORNE PATHOGENS (BPP)/EXPOSURE CONTROL PLAN

Number: OT-2018- Approval Date: 201806

AMSC Number: N/A Limitation: F A9101-18-R-1000

DTIC Applicable: No GIDEP Applicable: No

Preparing Activity: 10 (AEDC/TSD-SF) Project Number: N/A

Applicable Forms: N/A

Use/Relationship: The BPP/Exposure Control Plan will be used to outline the mandatory requirements for all security guards with the potential for exposure to BPP during the performance of their assigned duties.

This Data Item Description (DID) contains the format, content, d intended use information for the data product resulting from the work task described n the ntract Performance Work Statement (PWS). This DID is for one-time use for Arnold Engineer Development Complex (AEDC) solicitation FA9101-18-R-1000, AEDC Facility Support Services (FSS).

Requirements:

1. Reference documents. The applicable is of the documents cited herein, including their approval dates and dates of any applicable amen ts, notices, and revisions, shall be as specified in the contract.

2. Format. The contractor’s electronic ormat is acceptable.

3. Content. The plan shall be de available to all security guards and contain the exposure determination of personn (those reasonably anticipated, as a result of performing their day-to-day duties to h poten l skin, eye, mucous membrane contact with blood or other potentially infect us fluid r materials). This determination includes:

a. A list of all duty p itions n which personnel are likely to be exposed to contaminated material.

b. A list of all tasks and procedures, or groups of closely-related tasks and procedures, in which exposure may occur; tasks and procedures will be performed by personnel who handle contaminated material.

c. The methods available to prevent contact with blood and other potentially infectious fluids or materials.

d. Procedures for those who reasonably believe they have contacted a potentially infectious fluid or material.

e. Procedures for placing warning labels on containers or plastic bags containing blood or other potentially infectious material. Labels must comply with Occupational Safety and Health Agency (OSHA) Standard 1910.1030, Bloodborne Pathogens.

(Copies of this document are available online at https://www.osha.gov/law-regs.html.)

f. Procedures for keeping records of all incidents and occupational exposures per OSHA Standard 1910.1030.

g. Procedures for evaluating circumstances surrounding exposure incidents.

Title: HAZARDOUS COMMUNICATION PLAN

Number: OT-2018- Approval Date: 2018MMDD

AMSC Number: N/A Limitation: FA9101-18-R-1000

DTIC Applicable: No GIDEP Applicable: No

Preparing Activity: 10 (AEDC/TSD-SF) Project Number: N/A

Applicable Forms: N/A

Use/relationship: During execution of the contract, the contractor shall provide and maintain a Hazardous Communication Plan. This plan shall ensure supervisors and employees who handle, use, or are potentially exposed to hazardous chemicals in the course of official duties are provided information and training on the Air Force Hazardous Communication Program and the specific hazards in their work areas according to paragraph.

This Data Item Description (DID) contains the format, content, and intended use information for the data product resulting from the work task described in t contract Performance Work Statement (PWS). This DID is for one-time use for Arnold Engin ing Development Complex (AEDC) solicitation FA9101-18-R-1000, AEDC Facility Support Servi (FSS).

Requirements:

1. Reference documents. The applicable issue of th ocuments cited herein, including their approval dates and dates of any applicable amendment notices, and revisions, shall be as specified in the contract.

2. Format. The plan shall be prepared in .xls or .xl x mat.

3. Content. The content hall comply the requirements for a Hazardous Communication Plan per AFI 90-821, Hazard Communication and sha include the following data:

a. AEDC Safety, Health, an Enviro ental Standard A9, Hazard Communication.

b. Authorized Use Lis

c. Safety Data eets (SD )

(Copies of the above ar vailable online at http://www.e-publishing.af.mil/ and by email from AEDC/SE at aedc.se. orkflow@us.af.mil respectively.)

Title: FSS SECURITY SERVICES WORK INSTRUCTIONS

Number: OT-2018- Approval Date: 2018MMDD

AMSC Number: N/A Limitation: FA9101-18-R-1000

DTIC Applicable: No GIDEP Applicable: No

Preparing Activity: 10 (AEDC/TSD-SF) Project Number: N/A

Applicable Forms: N/A

Use/relationship: During execution of the contract, the contractor shall develop internal Work Instructions to cover day-to-day operations and responsibilities accounting for special contingencies and higher Force Protection Conditions (FPCONs). The Government shall be afforded the opportunity to review and comment prior to each update and/or publication of Work Instructions.

This Data Item Description (DID) contains the format, content, and intended use information for the data product resulting from the work task described in t contract Performance Work Statement (PWS). This DID is for one-time use for Arnold Engin ing Development Complex (AEDC) solicitation FA9101-18-R-1000, AEDC Facility Support Servi (FSS).

Requirements:

1. Reference documents. The applicable issue of th ocuments cited herein, including their approval dates and dates of any applicable amendment notices, and revisions, shall be as specified in the contract.

2. Format. Format will be in electronic .xls or .xlsx c atible format.

3. Content. The content shall c ly with the requirements for Security Services work instructions per the Arnold AFB Integra d Defense Plan (AAFB IDP 31-101), and shall include the elements listed below.

(Copies of this document are a lable by email from AEDC/TSD-SF at: aedc.tsd-sf.workflow@us.af.mil.)

a. Document Nu ber and opic

b. Approval Authori

c. Revision and Effecti e Date

d. Purpose

e. Scope of Application

f. References

g. Definitions

h. Introduction

i. Description of Revisions

j. Process (Step, Responsibility and Action)

k. Record

l. Flowcharts

m. Attachments

Title: FENCE LINE CHECK REPORT

Number: OT-2018- Approval Date: 2018MMDD

AMSC Number: N/A Limitation: FA9101-18-R-1000

DTIC Applicable: No GIDEP Applicable: No

Preparing Activity: 10 (AEDC/TSD-SF) Project Number: N/A

Applicable Forms: N/A

Use/relationship: During execution of the contract, the contractor shall provide a Mission Area (MA) Fence Line Check Report. The MA perimeter fence line shall be physically inspected in order to document and track all issues or concerns that could jeopardize the integrity of the structure.

This Data Item Description (DID) contains the format, content, and intended use information for the data product resulting from the work task described in the contract Performance Work Statement (PWS). This DID is for one-time use for Arnold Eng ering Development Complex (AEDC) solicitation FA9101-18-R-1000, AEDC Facility Support Se es (FSS).

Requirements:

1. Reference documents. The applicable issue of do uments cited herein, including their approval dates and dates of any applicable amendm s, notices, and revisions, shall be as specified in the contract.

2. Format. Format shall be in electronic .xls or compatible format.

3. Content. The content shall comply with the Arnold AFB Integrated Defense Plan (AAFB IDP 31-101) para C-7-1, 4, and shall incl he elements listed below.

(Copies of this document a avail ble by email from AEDC/TSD-SF at: aedc.tsd-sf.workflow@us.af.mil.)

a. Date/Time Check ducted

b. Personnel C ducting eck

c. Map Depicting C cerns Issues with Location Identified

d. Photos of Breaks/Openings, Vegetation Overgrowth, Erosion and Down Tress

e. Description of Concerns/Issues

f. Signage Condition and Placement

g. Any Signs of Attempted Intrusion

h. Any Information as Deemed Necessary

Title: QUICK REACTION CHECKLIST (QRC) NOTIFICATIONS

Number: OT-2018- Approval Date: 2018MMDD

AMSC Number: N/A Limitation: FA9101-18-R-1000

DTIC Applicable: No GIDEP Applicable: No

Preparing Activity: 10 (AEDC/TSD) Project Number: N/A

Applicable Forms: N/A

Use/relationship: QRC Checklist Notifications are used to provide the Government with information about activities/events/accidents/incidents/and etc. occurring on/off base that are affiliated with the base, personnel, equipment, etc. as reported to the Operations Center.

This Data Item Description (DID) contains the format, content, and intended use information for the data product resulting from the work task described in the contract Performance Work Statement (PWS). This DID is for one-time use for Arnold Eng neering Development Complex (AEDC) solicitation FA9101-18-R-1000, AED Facility Support Se ces (FSS).

Requirements:

1. Reference documents: None

2. Format: The Contractor’s electronic format is accep le.

3. Content: The report shall contain the following:

a. Time of activities/events

b. Summary of the activities/events

Title: DAILY EVENTS LOG

Number: OT-2018- Approval Date: 201806

AMSC Number: N/A Limitation: FA9101-18-R-1000

DTIC Applicable: No GIDEP Applicable: No

Preparing Activity: 10 (AEDC/TSD) Project Number: N/A

Applicable Forms: N/A

Use/Relationship: The Daily Events Log will be used to provide the Government with information concerning Operations, Maintenance, Information Management, and Support of the Arnold Engineering Development Complex (AEDC).

This Data Item Description (DID) contains the format, content, and intended use information for the data product resulting from the work task described in t contract Performance Work Statement (PWS). This DID is for one-time use for AEDC so citati FA9101-18-R-1000, AEDC Facility Support Services (FSS).

Requirements:

1. Reference documents. None.

2. Format. The contractor’s electronic format is acceptab

3. Content. The log shall contain the follow ng each event recorded: Date/time, author, and a summary of the event. The log documents all activities/events reported to AEDC Operations Center. The following tivities a e required to be reported to the Operations Center:

a. Test starts/stops (outage maj…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it.